Re: [tip:x86/asm] x86/umip: Add emulation code for UMIP instructions

From: Denys Vlasenko
Date: Wed Nov 08 2017 - 12:09:43 EST


On 11/08/2017 05:57 PM, Linus Torvalds wrote:
On Wed, Nov 8, 2017 at 8:53 AM, Denys Vlasenko <dvlasenk@xxxxxxxxxx> wrote:
We can postpone enabling UMIP by default by a year or so.
By this time, new Wine will be on majority of users' machines.

So you are suggesting we run unnecessarily insecure, only in order to
not do the emulation that we already have the code for and that the
patch implements?

We ran insecure in this way for ~25 years.

Why?

To avoid having to maintain more obscure, rarely executed code.