On 05/02/18 15:03, Arnd Bergmann wrote: Snipping deleted code to make things clearer:
> + if (cmd > ARRAY_SIZE(physdevop_len)) > + return -ENOSYS; > > + len = physdevop_len[cmd]; > + memcpy(&op.u, arg, len); You'll want an array_nospec() or whatever its called these days. This code is SP1-leaky. Userspace controls cmd and can retrieve len by timing how many adjacent cache lines were pulled in my memcpy(). ~Andrew _______________________________________________ Xen-devel mailing list Xen-devel@lists.xenproject.org https://lists.xenproject.org/mailman/listinfo/xen-devel