From nobody Tue May 21 23:20:42 2024 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1650529700; cv=none; d=zohomail.com; s=zohoarc; b=Bej3HgnPUNcC5LqRIHe2+ha5PuiY5u4YoFbAhv21cAUV43AF9V5vcW0ISpqdJ79u7avQbiRdrLGtHqosqMKe6Wr0AasVE5uo4adVKCrfWo6/nG1MRmsWy3kqIsPH7dha/80o1AJy8ECN9Ciz6BD07PR5/6eGcIuPmIqxdWAqoRQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1650529700; h=Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:To; bh=tSwMvSyN4P13/Czu00VOSrauLQZcRb2DgQ/0u2LlBmA=; b=XY2J+5GigAZFyf4d3ra8ZtNQ1Q3xf/KQLv65t4TmgpVws804nvlaH2ysokyzchY5cnjonuZASvltB+cTJB7If0mR3yqMxhQUMy4AVfS3qAPnWhibsjJqXdDTnsr2f6495fHdzDj2h8NLTC9cRc8PtzuXUz6Geh1qkfKbwN5IumI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1650529700896462.7115462870961; Thu, 21 Apr 2022 01:28:20 -0700 (PDT) Received: from localhost ([::1]:48438 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nhSAl-0001vv-JN for importer@patchew.org; Thu, 21 Apr 2022 04:28:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:33780) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLY-0005rh-Ok for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:27 -0400 Received: from mga02.intel.com ([134.134.136.20]:61331) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLV-0007W2-RR for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:24 -0400 Received: from orsmga006.jf.intel.com ([10.7.209.51]) by orsmga101.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:18 -0700 Received: from chenyi-pc.sh.intel.com ([10.239.159.73]) by orsmga006-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:14 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1650526521; x=1682062521; h=from:to:cc:subject:date:message-id:in-reply-to: references; bh=SK6DfUD1Elhz4wP8ubWVI6Kmk8qCznEz0nRUM7R0eFk=; b=jUMeni0iJd4UyVdQASXJci2drIZr8+wVSlcELEZ08BE8yDIJN62JyiYk DOxhYbkuP6+zxUXFtJAAkkweXLeKcLnjepAbznyZBlpeeeZPsdqZCwsqz 5YLc8XG4emVjyKLWLb9WAcU8g2WNKnbvSO8GD4rbveWGmpPuI1HvahYGT 414/4mwoY1l5WAVG1ztKes5H5TccJLDYOejhnZqYxBL19wY66St4Olxpe +//2bo3208ns4n7CcruKA022x9pFFu1vjaYJItnqLHYj+UFv6NBnSO0A8 lfNe3gs4sdDFf+zYEIaKgYjmXc/PS4EN3Y5mDAafKcsQlHxGgyencF0Lw A==; X-IronPort-AV: E=McAfee;i="6400,9594,10323"; a="251582551" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="251582551" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="530155145" From: Chenyi Qiang To: Paolo Bonzini , Sean Christopherson , Richard Henderson , Eduardo Habkost , Marcelo Tosatti , Xiaoyao Li Subject: [PATCH v3 1/3] linux-header: update linux header Date: Thu, 21 Apr 2022 15:40:26 +0800 Message-Id: <20220421074028.18196-2-chenyi.qiang@intel.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20220421074028.18196-1-chenyi.qiang@intel.com> References: <20220421074028.18196-1-chenyi.qiang@intel.com> Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=134.134.136.20; envelope-from=chenyi.qiang@intel.com; helo=mga02.intel.com X-Spam_score_int: -44 X-Spam_score: -4.5 X-Spam_bar: ---- X-Spam_report: (-4.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.082, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: qemu-devel@nongnu.org, kvm@vger.kernel.org, Chenyi Qiang Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1650529702682100001 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" This linux-header update is only a reference to include some definitions related to notify VM exit. Signed-off-by: Chenyi Qiang --- linux-headers/asm-x86/kvm.h | 4 +++- linux-headers/linux/kvm.h | 10 ++++++++++ 2 files changed, 13 insertions(+), 1 deletion(-) diff --git a/linux-headers/asm-x86/kvm.h b/linux-headers/asm-x86/kvm.h index bf6e96011d..41541561ed 100644 --- a/linux-headers/asm-x86/kvm.h +++ b/linux-headers/asm-x86/kvm.h @@ -325,6 +325,7 @@ struct kvm_reinject_control { #define KVM_VCPUEVENT_VALID_SHADOW 0x00000004 #define KVM_VCPUEVENT_VALID_SMM 0x00000008 #define KVM_VCPUEVENT_VALID_PAYLOAD 0x00000010 +#define KVM_VCPUEVENT_VALID_TRIPLE_FAULT 0x00000020 =20 /* Interrupt shadow states */ #define KVM_X86_SHADOW_INT_MOV_SS 0x01 @@ -359,7 +360,8 @@ struct kvm_vcpu_events { __u8 smm_inside_nmi; __u8 latched_init; } smi; - __u8 reserved[27]; + __u8 triple_fault_pending; + __u8 reserved[26]; __u8 exception_has_payload; __u64 exception_payload; }; diff --git a/linux-headers/linux/kvm.h b/linux-headers/linux/kvm.h index d232feaae9..67c0f6a938 100644 --- a/linux-headers/linux/kvm.h +++ b/linux-headers/linux/kvm.h @@ -270,6 +270,7 @@ struct kvm_xen_exit { #define KVM_EXIT_X86_BUS_LOCK 33 #define KVM_EXIT_XEN 34 #define KVM_EXIT_RISCV_SBI 35 +#define KVM_EXIT_NOTIFY 36 =20 /* For KVM_EXIT_INTERNAL_ERROR */ /* Emulate instruction failed. */ @@ -487,6 +488,11 @@ struct kvm_run { unsigned long args[6]; unsigned long ret[2]; } riscv_sbi; + /* KVM_EXIT_NOTIFY */ + struct { +#define KVM_NOTIFY_CONTEXT_INVALID (1 << 0) + __u32 flags; + } notify; /* Fix the size of the union. */ char padding[256]; }; @@ -1134,6 +1140,7 @@ struct kvm_ppc_resize_hpt { #define KVM_CAP_VM_GPA_BITS 207 #define KVM_CAP_XSAVE2 208 #define KVM_CAP_SYS_ATTRIBUTES 209 +#define KVM_CAP_X86_NOTIFY_VMEXIT 215 =20 #ifdef KVM_CAP_IRQ_ROUTING =20 @@ -2051,4 +2058,7 @@ struct kvm_stats_desc { /* Available with KVM_CAP_XSAVE2 */ #define KVM_GET_XSAVE2 _IOR(KVMIO, 0xcf, struct kvm_xsave) =20 +#define KVM_X86_NOTIFY_VMEXIT_ENABLED (1ULL << 0) +#define KVM_X86_NOTIFY_VMEXIT_USER (1ULL << 1) + #endif /* __LINUX_KVM_H */ --=20 2.17.1 From nobody Tue May 21 23:20:42 2024 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1650529323; cv=none; d=zohomail.com; s=zohoarc; b=Lo5p70dYruRsz9VRd8Pkn1cV0CDZVarTrFmcjvu0w2sgpB4yN3gtqgfKyVgAyXh0LMrkmVi03zX6rfybYiQ7KKpTn7iU7JAlRK2Z2CgNpqUAUyJhwGlaNYLXv7BLTIMlm2cICmM9X+x2jN/i8GOMuU2K7Xo1qnqWEmVkfpZm47w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1650529323; h=Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:To; bh=6lHbYil1qY9+YRbU8i4TaQS8LqXy3Eg+XOUIYx6EpE0=; b=ak4ex3c9dOvTr8xfzERtiV//nGkFXH5fbdNO50+OFPCYAUutjhlpuxNmBwr+lxmALZeTyBNYKoHJUl06+sAtZvJiY261irRmNw/Cawgt5pilZUgs0m0sMKMqeyv8PGwhKDXJ2MeKd8n+Fjv/uvmhP18GtoGQiCq0dN0LqkiGzlU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1650529323713816.632115009117; Thu, 21 Apr 2022 01:22:03 -0700 (PDT) Received: from localhost ([::1]:38552 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nhS4f-0003Mz-LC for importer@patchew.org; Thu, 21 Apr 2022 04:22:01 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:33758) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLX-0005rf-PC for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:27 -0400 Received: from mga02.intel.com ([134.134.136.20]:61327) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLV-0007Vh-RQ for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:23 -0400 Received: from orsmga006.jf.intel.com ([10.7.209.51]) by orsmga101.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:20 -0700 Received: from chenyi-pc.sh.intel.com ([10.239.159.73]) by orsmga006-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:17 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1650526521; x=1682062521; h=from:to:cc:subject:date:message-id:in-reply-to: references; bh=iiCAR1Rfqc66iGGWY17iyr5Co4ZAZLinh3HQEEGKipA=; b=UPjbLZfgEVhZhFHHYXzO/DS/i3Z4ekUMKrNodaDwLCk26/pZhyG9FBIc 4zAiTps4TGpANVuaTBsUoRmBmT8dBqyuoj1QvCEdfl2uSFwBJHgERZDJk pI2D2ZtIjw05AaYaPxxUZs5ZOlotTbkrnLjHeO/bUxod0x/KyOixzjfHF mIRdm3Un5aCW4ygmJg0Cc6LhlddsDELOTNSgc+OwF0rBCUNmQz2u62ExT VXmSGrlvh/9m1k/eLbwUxg3Szevcaf1BtkPaz+xBwLPsc7vp76lhhPQGE eYjIrUq81JCdHvSCPOUMerH47WxXaok9ZWTdAXg+7aWWi9djRb0n94vxG w==; X-IronPort-AV: E=McAfee;i="6400,9594,10323"; a="251582566" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="251582566" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="530155163" From: Chenyi Qiang To: Paolo Bonzini , Sean Christopherson , Richard Henderson , Eduardo Habkost , Marcelo Tosatti , Xiaoyao Li Subject: [PATCH v3 2/3] i386: kvm: Save&restore triple fault event Date: Thu, 21 Apr 2022 15:40:27 +0800 Message-Id: <20220421074028.18196-3-chenyi.qiang@intel.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20220421074028.18196-1-chenyi.qiang@intel.com> References: <20220421074028.18196-1-chenyi.qiang@intel.com> Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=134.134.136.20; envelope-from=chenyi.qiang@intel.com; helo=mga02.intel.com X-Spam_score_int: -44 X-Spam_score: -4.5 X-Spam_bar: ---- X-Spam_report: (-4.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.082, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: qemu-devel@nongnu.org, kvm@vger.kernel.org, Chenyi Qiang Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1650529325752100001 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" For the direct triple faults, i.e. hardware detected and KVM morphed to VM-Exit, KVM will never lose them. But for triple faults sythesized by KVM, e.g. the RSM path, if KVM exits to userspace before the request is serviced, userspace could migrate the VM and lose the triple fault. A new flag KVM_VCPUEVENT_VALID_TRIPLE_FAULT is defined to signal that the event.triple_fault_pending field contains a valid state. Signed-off-by: Chenyi Qiang --- target/i386/cpu.c | 1 + target/i386/cpu.h | 1 + target/i386/kvm/kvm.c | 8 +++++++- 3 files changed, 9 insertions(+), 1 deletion(-) diff --git a/target/i386/cpu.c b/target/i386/cpu.c index cb6b5467d0..276058d52e 100644 --- a/target/i386/cpu.c +++ b/target/i386/cpu.c @@ -5998,6 +5998,7 @@ static void x86_cpu_reset(DeviceState *dev) env->exception_has_payload =3D false; env->exception_payload =3D 0; env->nmi_injected =3D false; + env->triple_fault_pending =3D false; #if !defined(CONFIG_USER_ONLY) /* We hard-wire the BSP to the first CPU. */ apic_designate_bsp(cpu->apic_state, s->cpu_index =3D=3D 0); diff --git a/target/i386/cpu.h b/target/i386/cpu.h index 982c532353..a2a9423747 100644 --- a/target/i386/cpu.h +++ b/target/i386/cpu.h @@ -1701,6 +1701,7 @@ typedef struct CPUArchState { uint8_t has_error_code; uint8_t exception_has_payload; uint64_t exception_payload; + bool triple_fault_pending; uint32_t ins_len; uint32_t sipi_vector; bool tsc_valid; diff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c index 9cf8e03669..bd44a02f51 100644 --- a/target/i386/kvm/kvm.c +++ b/target/i386/kvm/kvm.c @@ -4099,7 +4099,9 @@ static int kvm_put_vcpu_events(X86CPU *cpu, int level) } =20 if (level >=3D KVM_PUT_RESET_STATE) { - events.flags |=3D KVM_VCPUEVENT_VALID_NMI_PENDING; + events.flags |=3D KVM_VCPUEVENT_VALID_NMI_PENDING | + KVM_VCPUEVENT_VALID_TRIPLE_FAULT; + events.triple_fault_pending =3D env->triple_fault_pending; if (env->mp_state =3D=3D KVM_MP_STATE_SIPI_RECEIVED) { events.flags |=3D KVM_VCPUEVENT_VALID_SIPI_VECTOR; } @@ -4174,6 +4176,10 @@ static int kvm_get_vcpu_events(X86CPU *cpu) } } =20 + if (events.flags & KVM_VCPUEVENT_VALID_TRIPLE_FAULT) { + env->triple_fault_pending =3D events.triple_fault_pending; + } + env->sipi_vector =3D events.sipi_vector; =20 return 0; --=20 2.17.1 From nobody Tue May 21 23:20:42 2024 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1650527553; cv=none; d=zohomail.com; s=zohoarc; b=oIoixvgWkYEy58t/zWDk34EmaRDsxB/XvPfW4VVaaRAeWqX8RouuQVbWiMIVNkZsdZXhYXE5GaUv3cjcgSVNLlLyQzk1JpHReszChDuUWjuiTpDYmzVc5eypRa3XQzvnsNh+kBbrulcnoRpwJA3gp1Q8zS2SwX4uR+AhbBU2Esg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1650527553; h=Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:To; bh=Ew5oR0h9a7wD/aMdAdQ5Bos6b3nIvkWAieug3yswU1w=; b=DYXlhQa00uNRHIqnoQ6+m8PRU3uFzXQ7poRm4aEgjqqI0JFertpswCCIQS8hVgY7o4AAM5I0DEJ1niH8TKjAwTwoSBRrw3Q/oauFcgfe7kH1W4RfBfD6ER2RMZqPhYR6SzWqMMW6hblACcyr4kr2P/B1oK8q1OVbzy5J77Dl0Ec= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1650527553405176.49613393028756; Thu, 21 Apr 2022 00:52:33 -0700 (PDT) Received: from localhost ([::1]:52494 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1nhRc8-0007KI-7I for importer@patchew.org; Thu, 21 Apr 2022 03:52:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:33790) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLa-0005rl-6n for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:27 -0400 Received: from mga02.intel.com ([134.134.136.20]:61327) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1nhRLX-0007Vh-Qz for qemu-devel@nongnu.org; Thu, 21 Apr 2022 03:35:25 -0400 Received: from orsmga006.jf.intel.com ([10.7.209.51]) by orsmga101.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:23 -0700 Received: from chenyi-pc.sh.intel.com ([10.239.159.73]) by orsmga006-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 21 Apr 2022 00:35:20 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1650526523; x=1682062523; h=from:to:cc:subject:date:message-id:in-reply-to: references; bh=qS+hlINTeiepYlBeX2Vr+HSMQ/0589/gEPfau+PqV9I=; b=bnOoMuXWFGqqO2JzSJn5EQt2eGJuBbldN5U8sgr3Dgh1eto4KdO5ZqI2 rER5dnga3dxHUTR/UElk3M511ENYncpk/Khn9h1Mzj2zQjsvXFXMXvMl3 L7x410Lw7/sPgWVkqvIq4uuMtmFlEPUbiMPzIMTEejLpLgK+NErlq6ooq +FG/uK8NnK+j1M70GPUcpTalQZtMcnjBU1ef8k2SrjPDQ1BemkVq70rai aJiAPGYnstJ35/7XHdFda8744CGv2W10lgSqGmXA+a5+lsJoT9Evagxvy 9kxEQ7YojzJ4BqQhDvHoz84UWrXjw5D8mqXPZ+deyJU/UDkTEB3rf5tME Q==; X-IronPort-AV: E=McAfee;i="6400,9594,10323"; a="251582571" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="251582571" X-IronPort-AV: E=Sophos;i="5.90,278,1643702400"; d="scan'208";a="530155190" From: Chenyi Qiang To: Paolo Bonzini , Sean Christopherson , Richard Henderson , Eduardo Habkost , Marcelo Tosatti , Xiaoyao Li Subject: [PATCH v3 3/3] i386: Add notify VM exit support Date: Thu, 21 Apr 2022 15:40:28 +0800 Message-Id: <20220421074028.18196-4-chenyi.qiang@intel.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20220421074028.18196-1-chenyi.qiang@intel.com> References: <20220421074028.18196-1-chenyi.qiang@intel.com> Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=134.134.136.20; envelope-from=chenyi.qiang@intel.com; helo=mga02.intel.com X-Spam_score_int: -44 X-Spam_score: -4.5 X-Spam_bar: ---- X-Spam_report: (-4.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.082, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: qemu-devel@nongnu.org, kvm@vger.kernel.org, Chenyi Qiang Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1650527554762100001 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" There are cases that malicious virtual machine can cause CPU stuck (due to event windows don't open up), e.g., infinite loop in microcode when nested #AC (CVE-2015-5307). No event window means no event (NMI, SMI and IRQ) can be delivered. It leads the CPU to be unavailable to host or other VMs. Notify VM exit is introduced to mitigate such kind of attacks, which will generate a VM exit if no event window occurs in VM non-root mode for a specified amount of time (notify window). A new KVM capability KVM_CAP_X86_NOTIFY_VMEXIT is exposed to user space so that the user can query the capability and set the expected notify window when creating VMs. The format of the argument when enabling this capability is as follows: Bit 63:32 - notify window specified in qemu command Bit 31:0 - some flags (e.g. KVM_X86_NOTIFY_VMEXIT_ENABLED is set to enable the feature.) Because there are some concerns, e.g. a notify VM exit may happen with VM_CONTEXT_INVALID set in exit qualification (no cases are anticipated that would set this bit), which means VM context is corrupted. To avoid the false positive and a well-behaved guest gets killed, make this feature disabled by default. Users can enable the feature by a new machine property: qemu -machine notify_vmexit=3Don,notify_window=3D0 ... A new KVM exit reason KVM_EXIT_NOTIFY is defined for notify VM exit. If it happens with VM_INVALID_CONTEXT, hypervisor exits to user space to inform the fatal case. Then user space can inject a SHUTDOWN event to the target vcpu. This is implemented by injecting a sythesized triple fault event. Signed-off-by: Chenyi Qiang --- hw/i386/x86.c | 45 +++++++++++++++++++++++++++++++ include/hw/i386/x86.h | 5 ++++ target/i386/kvm/kvm.c | 62 +++++++++++++++++++++++++++++-------------- 3 files changed, 92 insertions(+), 20 deletions(-) diff --git a/hw/i386/x86.c b/hw/i386/x86.c index 4cf107baea..a82f959cb9 100644 --- a/hw/i386/x86.c +++ b/hw/i386/x86.c @@ -1296,6 +1296,37 @@ static void machine_set_sgx_epc(Object *obj, Visitor= *v, const char *name, qapi_free_SgxEPCList(list); } =20 +static bool x86_machine_get_notify_vmexit(Object *obj, Error **errp) +{ + X86MachineState *x86ms =3D X86_MACHINE(obj); + + return x86ms->notify_vmexit; +} + +static void x86_machine_set_notify_vmexit(Object *obj, bool value, Error *= *errp) +{ + X86MachineState *x86ms =3D X86_MACHINE(obj); + + x86ms->notify_vmexit =3D value; +} + +static void x86_machine_get_notify_window(Object *obj, Visitor *v, + const char *name, void *opaque, Error **er= rp) +{ + X86MachineState *x86ms =3D X86_MACHINE(obj); + uint32_t notify_window =3D x86ms->notify_window; + + visit_type_uint32(v, name, ¬ify_window, errp); +} + +static void x86_machine_set_notify_window(Object *obj, Visitor *v, + const char *name, void *opaque, Error **err= p) +{ + X86MachineState *x86ms =3D X86_MACHINE(obj); + + visit_type_uint32(v, name, &x86ms->notify_window, errp); +} + static void x86_machine_initfn(Object *obj) { X86MachineState *x86ms =3D X86_MACHINE(obj); @@ -1306,6 +1337,8 @@ static void x86_machine_initfn(Object *obj) x86ms->oem_id =3D g_strndup(ACPI_BUILD_APPNAME6, 6); x86ms->oem_table_id =3D g_strndup(ACPI_BUILD_APPNAME8, 8); x86ms->bus_lock_ratelimit =3D 0; + x86ms->notify_vmexit =3D false; + x86ms->notify_window =3D 0; } =20 static void x86_machine_class_init(ObjectClass *oc, void *data) @@ -1361,6 +1394,18 @@ static void x86_machine_class_init(ObjectClass *oc, = void *data) NULL, NULL); object_class_property_set_description(oc, "sgx-epc", "SGX EPC device"); + + object_class_property_add(oc, X86_MACHINE_NOTIFY_WINDOW, "uint32_t", + x86_machine_get_notify_window, + x86_machine_set_notify_window, NULL, NULL); + object_class_property_set_description(oc, X86_MACHINE_NOTIFY_WINDOW, + "Set the notify window required by notify VM exit"); + + object_class_property_add_bool(oc, X86_MACHINE_NOTIFY_VMEXIT, + x86_machine_get_notify_vmexit, + x86_machine_set_notify_vmexit); + object_class_property_set_description(oc, X86_MACHINE_NOTIFY_VMEXIT, + "Enable notify VM exit"); } =20 static const TypeInfo x86_machine_info =3D { diff --git a/include/hw/i386/x86.h b/include/hw/i386/x86.h index 916cc325ee..571ee8b667 100644 --- a/include/hw/i386/x86.h +++ b/include/hw/i386/x86.h @@ -80,6 +80,9 @@ struct X86MachineState { * which means no limitation on the guest's bus locks. */ uint64_t bus_lock_ratelimit; + + bool notify_vmexit; + uint32_t notify_window; }; =20 #define X86_MACHINE_SMM "smm" @@ -87,6 +90,8 @@ struct X86MachineState { #define X86_MACHINE_OEM_ID "x-oem-id" #define X86_MACHINE_OEM_TABLE_ID "x-oem-table-id" #define X86_MACHINE_BUS_LOCK_RATELIMIT "bus-lock-ratelimit" +#define X86_MACHINE_NOTIFY_VMEXIT "notify-vmexit" +#define X86_MACHINE_NOTIFY_WINDOW "notify-window" =20 #define TYPE_X86_MACHINE MACHINE_TYPE_NAME("x86") OBJECT_DECLARE_TYPE(X86MachineState, X86MachineClass, X86_MACHINE) diff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c index bd44a02f51..01dbdef8b2 100644 --- a/target/i386/kvm/kvm.c +++ b/target/i386/kvm/kvm.c @@ -2344,6 +2344,10 @@ int kvm_arch_init(MachineState *ms, KVMState *s) int ret; struct utsname utsname; Error *local_err =3D NULL; + X86MachineState *x86ms; + + assert(object_dynamic_cast(OBJECT(ms), TYPE_X86_MACHINE)); + x86ms =3D X86_MACHINE(ms); =20 /* * Initialize SEV context, if required @@ -2439,8 +2443,7 @@ int kvm_arch_init(MachineState *ms, KVMState *s) } =20 if (kvm_check_extension(s, KVM_CAP_X86_SMM) && - object_dynamic_cast(OBJECT(ms), TYPE_X86_MACHINE) && - x86_machine_is_smm_enabled(X86_MACHINE(ms))) { + x86_machine_is_smm_enabled(x86ms)) { smram_machine_done.notify =3D register_smram_listener; qemu_add_machine_init_done_notifier(&smram_machine_done); } @@ -2468,25 +2471,34 @@ int kvm_arch_init(MachineState *ms, KVMState *s) } } =20 - if (object_dynamic_cast(OBJECT(ms), TYPE_X86_MACHINE)) { - X86MachineState *x86ms =3D X86_MACHINE(ms); + if (x86ms->bus_lock_ratelimit > 0) { + ret =3D kvm_check_extension(s, KVM_CAP_X86_BUS_LOCK_EXIT); + if (!(ret & KVM_BUS_LOCK_DETECTION_EXIT)) { + error_report("kvm: bus lock detection unsupported"); + return -ENOTSUP; + } + ret =3D kvm_vm_enable_cap(s, KVM_CAP_X86_BUS_LOCK_EXIT, 0, + KVM_BUS_LOCK_DETECTION_EXIT); + if (ret < 0) { + error_report("kvm: Failed to enable bus lock detection cap: %s= ", + strerror(-ret)); + return ret; + } + ratelimit_init(&bus_lock_ratelimit_ctrl); + ratelimit_set_speed(&bus_lock_ratelimit_ctrl, + x86ms->bus_lock_ratelimit, BUS_LOCK_SLICE_TIME= ); + } =20 - if (x86ms->bus_lock_ratelimit > 0) { - ret =3D kvm_check_extension(s, KVM_CAP_X86_BUS_LOCK_EXIT); - if (!(ret & KVM_BUS_LOCK_DETECTION_EXIT)) { - error_report("kvm: bus lock detection unsupported"); - return -ENOTSUP; - } - ret =3D kvm_vm_enable_cap(s, KVM_CAP_X86_BUS_LOCK_EXIT, 0, - KVM_BUS_LOCK_DETECTION_EXIT); - if (ret < 0) { - error_report("kvm: Failed to enable bus lock detection cap= : %s", - strerror(-ret)); - return ret; - } - ratelimit_init(&bus_lock_ratelimit_ctrl); - ratelimit_set_speed(&bus_lock_ratelimit_ctrl, - x86ms->bus_lock_ratelimit, BUS_LOCK_SLICE_= TIME); + if (x86ms->notify_vmexit && kvm_check_extension(s, KVM_CAP_X86_NOTIFY_= VMEXIT)) { + uint64_t notify_window_flags =3D ((uint64_t)x86ms->notify_window <= < 32) | + KVM_X86_NOTIFY_VMEXIT_ENABLED | + KVM_X86_NOTIFY_VMEXIT_USER; + ret =3D kvm_vm_enable_cap(s, KVM_CAP_X86_NOTIFY_VMEXIT, 0, + notify_window_flags); + if (ret < 0) { + error_report("kvm: Failed to enable notify vmexit cap: %s", + strerror(-ret)); + return ret; } } =20 @@ -4926,6 +4938,7 @@ int kvm_arch_handle_exit(CPUState *cs, struct kvm_run= *run) X86CPU *cpu =3D X86_CPU(cs); uint64_t code; int ret; + struct kvm_vcpu_events events =3D {}; =20 switch (run->exit_reason) { case KVM_EXIT_HLT: @@ -4981,6 +4994,15 @@ int kvm_arch_handle_exit(CPUState *cs, struct kvm_ru= n *run) /* already handled in kvm_arch_post_run */ ret =3D 0; break; + case KVM_EXIT_NOTIFY: + ret =3D 0; + if (run->notify.flags & KVM_NOTIFY_CONTEXT_INVALID) { + warn_report("KVM: invalid context due to notify vmexit"); + events.flags |=3D KVM_VCPUEVENT_VALID_TRIPLE_FAULT; + events.triple_fault_pending =3D true; + ret =3D kvm_vcpu_ioctl(cs, KVM_SET_VCPU_EVENTS, &events); + } + break; default: fprintf(stderr, "KVM: unknown exit reason %d\n", run->exit_reason); ret =3D -1; --=20 2.17.1