x86/startup_64: Drop long return to initial_code pointer
authorArd Biesheuvel <ardb@kernel.org>
Mon, 29 Jan 2024 18:05:06 +0000 (19:05 +0100)
committerBorislav Petkov (AMD) <bp@alien8.de>
Wed, 31 Jan 2024 17:31:21 +0000 (18:31 +0100)
Since

  866b556efa12 ("x86/head/64: Install startup GDT")

the primary startup sequence sets the code segment register (CS) to
__KERNEL_CS before calling into the startup code shared between primary
and secondary boot.

This means a simple indirect call is sufficient here.

Signed-off-by: Ard Biesheuvel <ardb@kernel.org>
Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de>
Link: https://lore.kernel.org/r/20240129180502.4069817-24-ardb+git@google.com
arch/x86/kernel/head_64.S

index d4918d03efb4b7765bff35d3e5f28a8c3a2bc99d..bfbac50dbe69eafad92b4d46925ed952566b377d 100644 (file)
@@ -428,39 +428,10 @@ SYM_INNER_LABEL(secondary_startup_64_no_verify, SYM_L_GLOBAL)
        movq    %r15, %rdi
 
 .Ljump_to_C_code:
-       /*
-        * Jump to run C code and to be on a real kernel address.
-        * Since we are running on identity-mapped space we have to jump
-        * to the full 64bit address, this is only possible as indirect
-        * jump.  In addition we need to ensure %cs is set so we make this
-        * a far return.
-        *
-        * Note: do not change to far jump indirect with 64bit offset.
-        *
-        * AMD does not support far jump indirect with 64bit offset.
-        * AMD64 Architecture Programmer's Manual, Volume 3: states only
-        *      JMP FAR mem16:16 FF /5 Far jump indirect,
-        *              with the target specified by a far pointer in memory.
-        *      JMP FAR mem16:32 FF /5 Far jump indirect,
-        *              with the target specified by a far pointer in memory.
-        *
-        * Intel64 does support 64bit offset.
-        * Software Developer Manual Vol 2: states:
-        *      FF /5 JMP m16:16 Jump far, absolute indirect,
-        *              address given in m16:16
-        *      FF /5 JMP m16:32 Jump far, absolute indirect,
-        *              address given in m16:32.
-        *      REX.W + FF /5 JMP m16:64 Jump far, absolute indirect,
-        *              address given in m16:64.
-        */
-       pushq   $.Lafter_lret   # put return address on stack for unwinder
        xorl    %ebp, %ebp      # clear frame pointer
-       movq    initial_code(%rip), %rax
-       pushq   $__KERNEL_CS    # set correct cs
-       pushq   %rax            # target address in negative space
-       lretq
-.Lafter_lret:
-       ANNOTATE_NOENDBR
+       ANNOTATE_RETPOLINE_SAFE
+       callq   *initial_code(%rip)
+       ud2
 SYM_CODE_END(secondary_startup_64)
 
 #include "verify_cpu.S"