On Tue, Jul 14, 2026 at 11:58:24AM -0700, Pawan Gupta wrote:
> Hi,
> 
> These backports harden BPF JIT against spectre-v2 class of attacks. Without
> a predictor flush, execution of new BPF program may use stale prediction
> left behind by the freed one.
> 
> To avoid this, issue an IBPB flush on all CPUs on JIT program allocation.
> The flush is conditional to spectre-v2 mitigation applied.
> 
> Patch 1-2: Adds the predictor flush hook and enables it on x86 via IBPB.
> 
>         bpf: Support for hardening against JIT spraying
>         x86/bugs: Enable IBPB flush on BPF JIT allocation
> 
> Patch 3-6: Narrow the flush to only unprivileged JIT allocations
>          to avoid redundant flushes. Also adds pack-selection changes
>          that minimizes flushes.
> 
>         bpf: Restrict JIT predictor flush to cBPF
>         bpf: Skip redundant IBPB in pack allocator
>         bpf: Prefer packs that won't trigger an IBPB flush on allocation
>         bpf: Prefer dirty packs for eBPF allocations
> 
> This one is mostly similar to 6.18:
> 
>   
> https://lore.kernel.org/all/20260713-cbpf-jit-spray-hardening-6-18-y-v1-0-755f60c55...@linux.intel.com/

There is no active 6.16.y kernel branch, so why is this being sent to
us?

confused,

greg k-h

Reply via email to