Intel® ISA Extensions
Use hardware-based isolation and memory encryption to provide more code protection in your solutions.
Announcements
This community is designed for sharing of public information. Please do not share Intel or third-party confidential information here.
1058 Discussions

How to enable MPK in Intel Xeon Gold processors?

Xie__Mengyao
Beginner
679 Views

I would like to use Intel MPK (memory protection keys) feature.

According to a paper: ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK), I buy a server with Intel Xeon Gold 6142 2.6GHz CPU. But I found there is no PKU feature in my server. (I run cat /proc/cpuinfo | grep pku and found nothing).

So, how to enable MPK in Intel Xeon Gold processors?

20190814221230 (1).jpg

0 Kudos
1 Reply
McCalpinJohn
Black Belt
679 Views

This may depend on your Linux kernel revision.   According to https://kernelnewbies.org/Linux_3.19 initial support was first added in the 3.19 kernel, while https://www.phoronix.com/scan.php?page=news_item&px=Linux-4.9-Mem-Protection-Keys suggests that support is not complete until the 4.9 kernel.

The "cpuid" program available at http://www.etallen.com/cpuid.html does a good job of parsing the output of the CPUID instruction.  On my Xeon Gold 6152, the cpuid program reports that the MPX and PKU features are supported, and the kernel (CentOS 7.6, 3.10.0-957.5.1.el7.x86_64) reports the "mpx" and "pku" extensions have been pack-ported to this kernel.

Reply