With our central processor units we developed a process model where each process was isolated memory wise from each other. And then went on to destroy that model with threads... but I digress. This process isolation culture was probably born from shared systems where each user needs to be isolated from each other. but has served us well with in providing robust single user systems. and has proved critical with the move back to shared cloud computing.
Graphical processing units hove no concept of memory isolation. and have no culture of wanting it. They were high performance units for a single user only. At this point trying to introduce isolation levels would probably be a lost cause. Many people would be very unhappy at the performance hit that would be required.
But yeah a GPU in a shared environment spooks me as well.
From the description given, I assume this is using timing differences to tell the size of each compressed tile, which gives you info on it's contents. This is certainly not helped by the ability for an apparently untrusted iframe to apply a transform to a target that the security model would normally disallow reading pixels from, amplifying the data from this side channel. Without that it's "just" another sidechannel attack.
All of us are walking around with bullshit information in our heads 24/7/365.
Most of the driver has also been moved into user space at least on Windows and MacOS I’m not fully versed in the state of the user vs kernel space display drivers on Linux these days.
https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
https://learn.microsoft.com/en-us/windows-hardware/drivers/d...
For clarity applications that don’t know how to use virtual memory will still operate under segmented mode where they’ll access the physical memory directly however under Windows at least these days and for a while now even the segmented mode is emulated you’ll need to run your engine on bare metal completely to access physical memory directly via segment addressing.