<!DOCTYPE html>
<html lang="en" data-content_root="../../">
<head>
<meta charset="utf-8" />
<meta name="viewport" content="width=device-width, initial-scale=1.0" /><meta name="viewport" content="width=device-width, initial-scale=1" />
<title>DEXCR (Dynamic Execution Control Register) — The Linux Kernel documentation</title>
<link rel="stylesheet" type="text/css" href="../../_static/pygments.css?v=fa44fd50" />
<link rel="stylesheet" type="text/css" href="../../_static/alabaster.css?v=3918102e" />
<script src="../../_static/documentation_options.js?v=5929fcd5"></script>
<script src="../../_static/doctools.js?v=9bcbadda"></script>
<script src="../../_static/sphinx_highlight.js?v=dc90522c"></script>
<link rel="index" title="Index" href="../../genindex.html" />
<link rel="search" title="Search" href="../../search.html" />
<link rel="next" title="DSCR (Data Stream Control Register)" href="dscr.html" />
<link rel="prev" title="DAWR issues on POWER9" href="dawr-power9.html" />
<link rel="stylesheet" href="../../_static/custom.css" type="text/css" />
</head><body>
<div class="document">
<div class="sphinxsidebar" role="navigation" aria-label="Main">
<div class="sphinxsidebarwrapper">
<p class="logo"><a href="../../index.html">
<img class="logo" src="../../_static/logo.svg" alt="Logo of The Linux Kernel"/>
</a></p>
<h1 class="logo"><a href="../../index.html">The Linux Kernel</a></h1>
<p class="blurb">6.18.50</p>
<search id="searchbox" style="display: none" role="search">
<h3 id="searchlabel">Quick search</h3>
<div class="searchformwrapper">
<form class="search" action="../../search.html" method="get">
<input type="text" name="q" aria-labelledby="searchlabel" autocomplete="off" autocorrect="off" autocapitalize="off" spellcheck="false"/>
<input type="submit" value="Go" />
</form>
</div>
</search>
<script>document.getElementById('searchbox').style.display = "block"</script>
<p>
<h3 class="kernel-toc-contents">Contents</h3>
<input type="checkbox" class="kernel-toc-toggle" id = "kernel-toc-toggle" checked>
<label class="kernel-toc-title" for="kernel-toc-toggle"></label>
<div class="kerneltoc" id="kerneltoc">
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../process/development-process.html">Development process</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/submitting-patches.html">Submitting patches</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/code-of-conduct.html">Code of conduct</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../maintainer/index.html">Maintainer handbook</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../process/index.html">All development-process docs</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../core-api/index.html">Core API</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../driver-api/index.html">Driver APIs</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../subsystem-apis.html">Subsystems</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../locking/index.html">Locking</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../process/license-rules.html">Licensing rules</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../doc-guide/index.html">Writing documentation</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../dev-tools/index.html">Development tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../dev-tools/testing-overview.html">Testing guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../kernel-hacking/index.html">Hacking guide</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../trace/index.html">Tracing</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../fault-injection/index.html">Fault injection</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../livepatch/index.html">Livepatching</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../rust/index.html">Rust</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../admin-guide/index.html">Administration</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../kbuild/index.html">Build system</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../admin-guide/reporting-issues.html">Reporting issues</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../tools/index.html">Userspace tools</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../userspace-api/index.html">Userspace API</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../firmware-guide/index.html">Firmware</a></li>
<li class="toctree-l1"><a class="reference internal" href="../../devicetree/index.html">Firmware and Devicetree</a></li>
</ul>
<ul class="current">
<li class="toctree-l1 current"><a class="reference internal" href="../index.html">CPU architectures</a><ul class="current">
<li class="toctree-l2"><a class="reference internal" href="../arc/index.html">ARC architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../arm/index.html">ARM Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../arm64/index.html">ARM64 Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../loongarch/index.html">LoongArch Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../m68k/index.html">m68k Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../mips/index.html">MIPS-specific Documentation</a></li>
<li class="toctree-l2"><a class="reference internal" href="../nios2/index.html">Nios II Specific Documentation</a></li>
<li class="toctree-l2"><a class="reference internal" href="../openrisc/index.html">OpenRISC Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../parisc/index.html">PA-RISC Architecture</a></li>
<li class="toctree-l2 current"><a class="reference internal" href="index.html">powerpc</a><ul class="current">
<li class="toctree-l3"><a class="reference internal" href="associativity.html">NUMA resource associativity</a></li>
<li class="toctree-l3"><a class="reference internal" href="booting.html">DeviceTree Booting</a></li>
<li class="toctree-l3"><a class="reference internal" href="bootwrapper.html">The PowerPC boot wrapper</a></li>
<li class="toctree-l3"><a class="reference internal" href="cpu_families.html">CPU Families</a></li>
<li class="toctree-l3"><a class="reference internal" href="cpu_features.html">CPU Features</a></li>
<li class="toctree-l3"><a class="reference internal" href="dawr-power9.html">DAWR issues on POWER9</a></li>
<li class="toctree-l3 current"><a class="current reference internal" href="#">DEXCR (Dynamic Execution Control Register)</a></li>
<li class="toctree-l3"><a class="reference internal" href="dscr.html">DSCR (Data Stream Control Register)</a></li>
<li class="toctree-l3"><a class="reference internal" href="eeh-pci-error-recovery.html">PCI Bus EEH Error Recovery</a></li>
<li class="toctree-l3"><a class="reference internal" href="elf_hwcaps.html">POWERPC ELF HWCAPs</a></li>
<li class="toctree-l3"><a class="reference internal" href="elfnote.html">ELF Note PowerPC Namespace</a></li>
<li class="toctree-l3"><a class="reference internal" href="firmware-assisted-dump.html">Firmware-Assisted Dump</a></li>
<li class="toctree-l3"><a class="reference internal" href="htm.html">HTM (Hardware Trace Macro)</a></li>
<li class="toctree-l3"><a class="reference internal" href="hvcs.html">HVCS IBM “Hypervisor Virtual Console Server” Installation Guide</a></li>
<li class="toctree-l3"><a class="reference internal" href="imc.html">IMC (In-Memory Collection Counters)</a></li>
<li class="toctree-l3"><a class="reference internal" href="isa-versions.html">CPU to ISA Version Mapping</a></li>
<li class="toctree-l3"><a class="reference internal" href="kaslr-booke32.html">KASLR for Freescale BookE32</a></li>
<li class="toctree-l3"><a class="reference internal" href="mpc52xx.html">Linux 2.6.x on MPC52xx family</a></li>
<li class="toctree-l3"><a class="reference internal" href="kvm-nested.html">Nested KVM on POWER</a></li>
<li class="toctree-l3"><a class="reference internal" href="papr_hcalls.html">Hypercall Op-codes (hcalls)</a></li>
<li class="toctree-l3"><a class="reference internal" href="pci_iov_resource_on_powernv.html">PCI Express I/O Virtualization Resource on Powerenv</a></li>
<li class="toctree-l3"><a class="reference internal" href="pmu-ebb.html">PMU Event Based Branches</a></li>
<li class="toctree-l3"><a class="reference internal" href="ptrace.html">Ptrace</a></li>
<li class="toctree-l3"><a class="reference internal" href="qe_firmware.html">Freescale QUICC Engine Firmware Uploading</a></li>
<li class="toctree-l3"><a class="reference internal" href="syscall64-abi.html">Power Architecture 64-bit Linux system call ABI</a></li>
<li class="toctree-l3"><a class="reference internal" href="transactional_memory.html">Transactional Memory support</a></li>
<li class="toctree-l3"><a class="reference internal" href="ultravisor.html">Protected Execution Facility</a></li>
<li class="toctree-l3"><a class="reference internal" href="vas-api.html">Virtual Accelerator Switchboard (VAS) userspace API</a></li>
<li class="toctree-l3"><a class="reference internal" href="vcpudispatch_stats.html">VCPU Dispatch Statistics</a></li>
<li class="toctree-l3"><a class="reference internal" href="vmemmap_dedup.html">Device DAX</a></li>
<li class="toctree-l3"><a class="reference internal" href="vpa-dtl.html">DTL (Dispatch Trace Log)</a></li>
<li class="toctree-l3"><a class="reference internal" href="features.html">Feature status on powerpc architecture</a></li>
</ul>
</li>
<li class="toctree-l2"><a class="reference internal" href="../riscv/index.html">RISC-V architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../s390/index.html">s390 Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../sh/index.html">SuperH Interfaces Guide</a></li>
<li class="toctree-l2"><a class="reference internal" href="../sparc/index.html">Sparc Architecture</a></li>
<li class="toctree-l2"><a class="reference internal" href="../x86/index.html">x86-specific Documentation</a></li>
<li class="toctree-l2"><a class="reference internal" href="../xtensa/index.html">Xtensa Architecture</a></li>
</ul>
</li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../staging/index.html">Unsorted documentation</a></li>
</ul>
<ul>
<li class="toctree-l1"><a class="reference internal" href="../../translations/index.html">Translations</a></li>
</ul>
</div>
<script type="text/javascript"> <!--
var sbar = document.getElementsByClassName("sphinxsidebar")[0];
let currents = document.getElementsByClassName("current")
if (currents.length) {
sbar.scrollTop = currents[currents.length - 1].offsetTop;
}
--> </script>
<div role="note" aria-label="source link">
<h3>This Page</h3>
<ul class="this-page-menu">
<li><a href="../../_sources/arch/powerpc/dexcr.rst.txt"
rel="nofollow">Show Source</a></li>
</ul>
</div>
</div>
</div>
<div class="documentwrapper">
<div class="bodywrapper">
<div class="body" role="main">
<section id="dexcr-dynamic-execution-control-register">
<h1>DEXCR (Dynamic Execution Control Register)<a class="headerlink" href="#dexcr-dynamic-execution-control-register" title="Link to this heading">¶</a></h1>
<section id="overview">
<h2>Overview<a class="headerlink" href="#overview" title="Link to this heading">¶</a></h2>
<p>The DEXCR is a privileged special purpose register (SPR) introduced in
PowerPC ISA 3.1B (Power10) that allows per-cpu control over several dynamic
execution behaviours. These behaviours include speculation (e.g., indirect
branch target prediction) and enabling return-oriented programming (ROP)
protection instructions.</p>
<p>The execution control is exposed in hardware as up to 32 bits (‘aspects’) in
the DEXCR. Each aspect controls a certain behaviour, and can be set or cleared
to enable/disable the aspect. There are several variants of the DEXCR for
different purposes:</p>
<dl class="simple">
<dt>DEXCR</dt><dd><p>A privileged SPR that can control aspects for userspace and kernel space</p>
</dd>
<dt>HDEXCR</dt><dd><p>A hypervisor-privileged SPR that can control aspects for the hypervisor and
enforce aspects for the kernel and userspace.</p>
</dd>
<dt>UDEXCR</dt><dd><p>An optional ultravisor-privileged SPR that can control aspects for the ultravisor.</p>
</dd>
</dl>
<p>Userspace can examine the current DEXCR state using a dedicated SPR that
provides a non-privileged read-only view of the userspace DEXCR aspects.
There is also an SPR that provides a read-only view of the hypervisor enforced
aspects, which ORed with the userspace DEXCR view gives the effective DEXCR
state for a process.</p>
</section>
<section id="configuration">
<h2>Configuration<a class="headerlink" href="#configuration" title="Link to this heading">¶</a></h2>
<section id="prctl">
<h3>prctl<a class="headerlink" href="#prctl" title="Link to this heading">¶</a></h3>
<p>A process can control its own userspace DEXCR value using the
<code class="docutils literal notranslate"><span class="pre">PR_PPC_GET_DEXCR</span></code> and <code class="docutils literal notranslate"><span class="pre">PR_PPC_SET_DEXCR</span></code> pair of
<em class="manpage">prctl(2)</em> commands. These calls have the form:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>prctl(PR_PPC_GET_DEXCR, unsigned long which, 0, 0, 0);
prctl(PR_PPC_SET_DEXCR, unsigned long which, unsigned long ctrl, 0, 0);
</pre></div>
</div>
<p>The possible ‘which’ and ‘ctrl’ values are as follows. Note there is no relation
between the ‘which’ value and the DEXCR aspect’s index.</p>
<table class="docutils align-default">
<thead>
<tr class="row-odd"><th class="head"><p><code class="docutils literal notranslate"><span class="pre">prctl()</span></code> which</p></th>
<th class="head"><p>Aspect name</p></th>
<th class="head"><p>Aspect index</p></th>
</tr>
</thead>
<tbody>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_SBHE</span></code></p></td>
<td><p>Speculative Branch Hint Enable (SBHE)</p></td>
<td><p>0</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_IBRTPD</span></code></p></td>
<td><p>Indirect Branch Recurrent Target Prediction Disable (IBRTPD)</p></td>
<td><p>3</p></td>
</tr>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_SRAPD</span></code></p></td>
<td><p>Subroutine Return Address Prediction Disable (SRAPD)</p></td>
<td><p>4</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_NPHIE</span></code></p></td>
<td><p>Non-Privileged Hash Instruction Enable (NPHIE)</p></td>
<td><p>5</p></td>
</tr>
</tbody>
</table>
<table class="docutils align-default">
<thead>
<tr class="row-odd"><th class="head"><p><code class="docutils literal notranslate"><span class="pre">prctl()</span></code> ctrl</p></th>
<th class="head"><p>Meaning</p></th>
</tr>
</thead>
<tbody>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_EDITABLE</span></code></p></td>
<td><p>This aspect can be configured with PR_PPC_SET_DEXCR (get only)</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_SET</span></code></p></td>
<td><p>This aspect is set / set this aspect</p></td>
</tr>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_CLEAR</span></code></p></td>
<td><p>This aspect is clear / clear this aspect</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_SET_ONEXEC</span></code></p></td>
<td><p>This aspect will be set after exec / set this aspect after exec</p></td>
</tr>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_CLEAR_ONEXEC</span></code></p></td>
<td><p>This aspect will be clear after exec / clear this aspect after exec</p></td>
</tr>
</tbody>
</table>
<p>Note that</p>
<ul>
<li><p>which is a plain value, not a bitmask. Aspects must be worked with individually.</p></li>
<li><p>ctrl is a bitmask. <code class="docutils literal notranslate"><span class="pre">PR_PPC_GET_DEXCR</span></code> returns both the current and onexec
configuration. For example, <code class="docutils literal notranslate"><span class="pre">PR_PPC_GET_DEXCR</span></code> may return
<code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_EDITABLE</span> <span class="pre">|</span> <span class="pre">PR_PPC_DEXCR_CTRL_SET</span> <span class="pre">|</span>
<span class="pre">PR_PPC_DEXCR_CTRL_CLEAR_ONEXEC</span></code>. This would indicate the aspect is currently
set, it will be cleared when you run exec, and you can change this with the
<code class="docutils literal notranslate"><span class="pre">PR_PPC_SET_DEXCR</span></code> prctl.</p></li>
<li><p>The set/clear terminology refers to setting/clearing the bit in the DEXCR.
For example:</p>
<div class="highlight-none notranslate"><div class="highlight"><pre><span></span>prctl(PR_PPC_SET_DEXCR, PR_PPC_DEXCR_IBRTPD, PR_PPC_DEXCR_CTRL_SET, 0, 0);
</pre></div>
</div>
<p>will set the IBRTPD aspect bit in the DEXCR, causing indirect branch prediction
to be disabled.</p>
</li>
<li><p>The status returned by <code class="docutils literal notranslate"><span class="pre">PR_PPC_GET_DEXCR</span></code> represents what value the process
would like applied. It does not include any alternative overrides, such as if
the hypervisor is enforcing the aspect be set. To see the true DEXCR state
software should read the appropriate SPRs directly.</p></li>
<li><p>The aspect state when starting a process is copied from the parent’s state on
<em class="manpage">fork(2)</em>. The state is reset to a fixed value on
<em class="manpage">execve(2)</em>. The PR_PPC_SET_DEXCR <code class="xref c c-func broken_xref docutils literal notranslate"><span class="pre">prctl()</span></code> can control both of these
values.</p></li>
<li><p>The <code class="docutils literal notranslate"><span class="pre">*_ONEXEC</span></code> controls do not change the current process’s DEXCR.</p></li>
</ul>
<p>Use <code class="docutils literal notranslate"><span class="pre">PR_PPC_SET_DEXCR</span></code> with one of <code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_SET</span></code> or
<code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_CLEAR</span></code> to edit a given aspect.</p>
<p>Common error codes for both getting and setting the DEXCR are as follows:</p>
<table class="docutils align-default">
<thead>
<tr class="row-odd"><th class="head"><p>Error</p></th>
<th class="head"><p>Meaning</p></th>
</tr>
</thead>
<tbody>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">EINVAL</span></code></p></td>
<td><p>The DEXCR is not supported by the kernel.</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">ENODEV</span></code></p></td>
<td><p>The aspect is not recognised by the kernel or not supported by the
hardware.</p></td>
</tr>
</tbody>
</table>
<p><code class="docutils literal notranslate"><span class="pre">PR_PPC_SET_DEXCR</span></code> may also report the following error codes:</p>
<table class="docutils align-default">
<thead>
<tr class="row-odd"><th class="head"><p>Error</p></th>
<th class="head"><p>Meaning</p></th>
</tr>
</thead>
<tbody>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">EINVAL</span></code></p></td>
<td><p>The ctrl value contains unrecognised flags.</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">EINVAL</span></code></p></td>
<td><p>The ctrl value contains mutually conflicting flags (e.g.,
<code class="docutils literal notranslate"><span class="pre">PR_PPC_DEXCR_CTRL_SET</span> <span class="pre">|</span> <span class="pre">PR_PPC_DEXCR_CTRL_CLEAR</span></code>)</p></td>
</tr>
<tr class="row-even"><td><p><code class="docutils literal notranslate"><span class="pre">EPERM</span></code></p></td>
<td><p>This aspect cannot be modified with <code class="xref c c-func broken_xref docutils literal notranslate"><span class="pre">prctl()</span></code> (check for the
PR_PPC_DEXCR_CTRL_EDITABLE flag with PR_PPC_GET_DEXCR).</p></td>
</tr>
<tr class="row-odd"><td><p><code class="docutils literal notranslate"><span class="pre">EPERM</span></code></p></td>
<td><p>The process does not have sufficient privilege to perform the operation.
For example, clearing NPHIE on exec is a privileged operation (a process
can still clear its own NPHIE aspect without privileges).</p></td>
</tr>
</tbody>
</table>
<p>This interface allows a process to control its own DEXCR aspects, and also set
the initial DEXCR value for any children in its process tree (up to the next
child to use an <code class="docutils literal notranslate"><span class="pre">*_ONEXEC</span></code> control). This allows fine-grained control over the
default value of the DEXCR, for example allowing containers to run with different
default values.</p>
</section>
</section>
<section id="coredump-and-ptrace">
<h2>coredump and ptrace<a class="headerlink" href="#coredump-and-ptrace" title="Link to this heading">¶</a></h2>
<p>The userspace values of the DEXCR and HDEXCR (in this order) are exposed under
<code class="docutils literal notranslate"><span class="pre">NT_PPC_DEXCR</span></code>. These are each 64 bits and readonly, and are intended to
assist with core dumps. The DEXCR may be made writable in future. The top 32
bits of both registers (corresponding to the non-userspace bits) are masked off.</p>
<p>If the kernel config <code class="docutils literal notranslate"><span class="pre">CONFIG_CHECKPOINT_RESTORE</span></code> is enabled, then
<code class="docutils literal notranslate"><span class="pre">NT_PPC_HASHKEYR</span></code> is available and exposes the HASHKEYR value of the process
for reading and writing. This is a tradeoff between increased security and
checkpoint/restore support: a process should normally have no need to know its
secret key, but restoring a process requires setting its original key. The key
therefore appears in core dumps, and an attacker may be able to retrieve it from
a coredump and effectively bypass ROP protection on any threads that share this
key (potentially all threads from the same parent that have not run <code class="docutils literal notranslate"><span class="pre">exec()</span></code>).</p>
</section>
</section>
</div>
</div>
</div>
<div class="clearer"></div>
</div>
<div class="footer">
©The kernel development community.
|
Powered by <a href="https://www.sphinx-doc.org/">Sphinx 8.1.3</a>
& <a href="https://alabaster.readthedocs.io">Alabaster 0.7.16</a>
|
<a href="../../_sources/arch/powerpc/dexcr.rst.txt"
rel="nofollow">Page source</a>
</div>
</body>
</html>