From nobody Thu May 9 23:14:06 2024 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1710229842; cv=none; d=zohomail.com; s=zohoarc; b=D5qStyl08kiSiuo+9cfN9j2p3E3HgokAXEjWbqfYN4Z+Y1MZqV6Ce9hLIm9oKtl/S/ypTD3mfWhSk0nmkCU5rBIzXQVgs0uH+15UIwg87v1Wrm8nteJe6vwQnNmHYKY+glvNPU51+57WhUYytxlxqobA99imehlZLq99U4ofASM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1710229842; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=hf0i2X5ZaQ7uy+Izd/1iXlQf71HB4eo5q05CggoYeWk=; b=M0b+JQRLud0o1aVkRmn33fLPXBHcj/ClFweDaNMZEgHuvv9dHwHoKePgI3DjF4ck/LrkFJ/F/EPvCcwYwbMLySRqYSXzEHO1cBn4ERLQp+TvsiIGgMW3eo4yo0popBqDcR8Va2r6zveCDsWtGzBSs//TPgnlKUjU5JH9cE8TIsw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1710229842173319.6696578200332; Tue, 12 Mar 2024 00:50:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1rjwtv-0000YS-MR; Tue, 12 Mar 2024 03:50:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rjwtu-0000YK-C1 for qemu-devel@nongnu.org; Tue, 12 Mar 2024 03:50:18 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1rjwts-00030h-0z for qemu-devel@nongnu.org; Tue, 12 Mar 2024 03:50:18 -0400 Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-61-uem3J4rIPXSvQBPuOtbhWg-1; Tue, 12 Mar 2024 03:49:16 -0400 Received: from smtp.corp.redhat.com (int-mx07.intmail.prod.int.rdu2.redhat.com [10.11.54.7]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id 28AAE1018985; Tue, 12 Mar 2024 07:49:16 +0000 (UTC) Received: from virt-mtcollins-01.lab.eng.rdu2.redhat.com (virt-mtcollins-01.lab.eng.rdu2.redhat.com [10.8.1.196]) by smtp.corp.redhat.com (Postfix) with ESMTP id 1D92D1C060A4; Tue, 12 Mar 2024 07:49:16 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1710229815; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=hf0i2X5ZaQ7uy+Izd/1iXlQf71HB4eo5q05CggoYeWk=; b=ClxIsoezJTZxTPv6QxSix936JudMRBKYkpwIuJr6I9iFaqOTiq2d+38CP+mFL6YAhfyEEA iAzfbSFq0Ux821FPFS4dalY5w2CX8dSBm97KzXIB7ITNsh9xrncW8v5oLH9lasDtHZgKjB 5tRtCFIVQ6c96IGEPUsPBrpZ5N6AbWA= X-MC-Unique: uem3J4rIPXSvQBPuOtbhWg-1 From: Shaoqin Huang To: qemu-arm@nongnu.org Cc: Eric Auger , Shaoqin Huang , Peter Maydell , Paolo Bonzini , Thomas Huth , Laurent Vivier , qemu-devel@nongnu.org, kvm@vger.kernel.org Subject: [PATCH v8] arm/kvm: Enable support for KVM_ARM_VCPU_PMU_V3_FILTER Date: Tue, 12 Mar 2024 03:48:49 -0400 Message-Id: <20240312074849.71475-1-shahuang@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.11.54.7 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=shahuang@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -30 X-Spam_score: -3.1 X-Spam_bar: --- X-Spam_report: (-3.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.029, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1710229843019100001 Content-Type: text/plain; charset="utf-8" The KVM_ARM_VCPU_PMU_V3_FILTER provides the ability to let the VMM decide which PMU events are provided to the guest. Add a new option `kvm-pmu-filter` as -cpu sub-option to set the PMU Event Filtering. Without the filter, all PMU events are exposed from host to guest by default. The usage of the new sub-option can be found from the updated document (docs/system/arm/cpu-features.rst). Here is an example which shows how to use the PMU Event Filtering, when we launch a guest by use kvm, add such command line: # qemu-system-aarch64 \ -accel kvm \ -cpu host,kvm-pmu-filter=3D"D:0x11-0x11" Since the first action is deny, we have a global allow policy. This filters out the cycle counter (event 0x11 being CPU_CYCLES). And then in guest, use the perf to count the cycle: # perf stat sleep 1 Performance counter stats for 'sleep 1': 1.22 msec task-clock # 0.001 CPUs ut= ilized 1 context-switches # 820.695 /sec 0 cpu-migrations # 0.000 /sec 55 page-faults # 45.138 K/sec cycles 1128954 instructions 227031 branches # 186.323 M/sec 8686 branch-misses # 3.83% of all = branches 1.002492480 seconds time elapsed 0.001752000 seconds user 0.000000000 seconds sys As we can see, the cycle counter has been disabled in the guest, but other pmu events do still work. Signed-off-by: Shaoqin Huang --- v7->v8: - Add qtest for kvm-pmu-filter. - Do the kvm-pmu-filter syntax checking up-front in the kvm_pmu_filter_se= t() function. And store the filter information at there. When kvm_pmu_filter_= get() reconstitute it. v6->v7: - Check return value of sscanf. - Improve the check condition. v5->v6: - Commit message improvement. - Remove some unused code. - Collect Reviewed-by, thanks Sebastian. - Use g_auto(Gstrv) to replace the gchar **. [Eric] v4->v5: - Change the kvm-pmu-filter as a -cpu sub-option. [Eric] - Comment tweak. [Gavin] - Rebase to the latest branch. v3->v4: - Fix the wrong check for pmu_filter_init. [Sebastian] - Fix multiple alignment issue. [Gavin] - Report error by warn_report() instead of error_report(), and don't use abort() since the PMU Event Filter is an add-on and best-effort feature. [Gavin] - Add several missing { } for single line of code. [Gavin] - Use the g_strsplit() to replace strtok(). [Gavin] v2->v3: - Improve commits message, use kernel doc wording, add more explaination = on filter example, fix some typo error. [Eric] - Add g_free() in kvm_arch_set_pmu_filter() to prevent memory leak. [Eric] - Add more precise error message report. [Eric] - In options doc, add pmu-filter rely on KVM_ARM_VCPU_PMU_V3_FILTER suppo= rt in KVM. [Eric] v1->v2: - Add more description for allow and deny meaning in=20 commit message. [Sebastian] - Small improvement. [Sebastian] --- docs/system/arm/cpu-features.rst | 23 +++++++ target/arm/arm-qmp-cmds.c | 2 +- target/arm/cpu.h | 3 + target/arm/kvm.c | 115 +++++++++++++++++++++++++++++++ tests/qtest/arm-cpu-features.c | 51 ++++++++++++++ 5 files changed, 193 insertions(+), 1 deletion(-) diff --git a/docs/system/arm/cpu-features.rst b/docs/system/arm/cpu-feature= s.rst index a5fb929243..f3930f34b3 100644 --- a/docs/system/arm/cpu-features.rst +++ b/docs/system/arm/cpu-features.rst @@ -204,6 +204,29 @@ the list of KVM VCPU features and their descriptions. the guest scheduler behavior and/or be exposed to the guest userspace. =20 +``kvm-pmu-filter`` + By default kvm-pmu-filter is disabled. This means that by default all PMU + events will be exposed to guest. + + KVM implements PMU Event Filtering to prevent a guest from being able to + sample certain events. It depends on the KVM_ARM_VCPU_PMU_V3_FILTER + attribute supported in KVM. It has the following format: + + kvm-pmu-filter=3D"{A,D}:start-end[;{A,D}:start-end...]" + + The A means "allow" and D means "deny", start is the first event of the + range and the end is the last one. The first registered range defines + the global policy (global ALLOW if the first action is DENY, global DENY + if the first action is ALLOW). The start and end only support hexadecimal + format. For example: + + kvm-pmu-filter=3D"A:0x11-0x11;A:0x23-0x3a;D:0x30-0x30" + + Since the first action is allow, we have a global deny policy. It + will allow event 0x11 (the cycle counter), events 0x23 to 0x3a are + also allowed except the event 0x30 which is denied, and all the other + events are denied. + TCG VCPU Features =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D =20 diff --git a/target/arm/arm-qmp-cmds.c b/target/arm/arm-qmp-cmds.c index 2250cd7ddf..36df2e4820 100644 --- a/target/arm/arm-qmp-cmds.c +++ b/target/arm/arm-qmp-cmds.c @@ -94,7 +94,7 @@ static const char *cpu_model_advertised_features[] =3D { "sve128", "sve256", "sve384", "sve512", "sve640", "sve768", "sve896", "sve1024", "sve1152", "sve1280", "sve1408", "sve1536", "sve1664", "sve1792", "sve1920", "sve2048", - "kvm-no-adjvtime", "kvm-steal-time", + "kvm-no-adjvtime", "kvm-steal-time", "kvm-pmu-filter", "pauth", "pauth-impdef", "pauth-qarma3", NULL }; diff --git a/target/arm/cpu.h b/target/arm/cpu.h index 63f31e0d98..b810a80e67 100644 --- a/target/arm/cpu.h +++ b/target/arm/cpu.h @@ -948,6 +948,9 @@ struct ArchCPU { =20 /* KVM steal time */ OnOffAuto kvm_steal_time; + + /* KVM PMU Filter */ + GArray *kvm_pmu_filter; #endif /* CONFIG_KVM */ =20 /* Uniprocessor system with MP extensions */ diff --git a/target/arm/kvm.c b/target/arm/kvm.c index 81813030a5..7f62fad029 100644 --- a/target/arm/kvm.c +++ b/target/arm/kvm.c @@ -496,6 +496,72 @@ static void kvm_steal_time_set(Object *obj, bool value= , Error **errp) ARM_CPU(obj)->kvm_steal_time =3D value ? ON_OFF_AUTO_ON : ON_OFF_AUTO_= OFF; } =20 +static char *kvm_pmu_filter_get(Object *obj, Error **errp) +{ + ARMCPU *cpu =3D ARM_CPU(obj); + g_autoptr(GString) pmu_filter =3D g_string_new(NULL); + struct kvm_pmu_event_filter *filter; + char action; + int i; + + if (!cpu->kvm_pmu_filter) { + return NULL; + } + + for (i =3D 0; i < cpu->kvm_pmu_filter->len; i++) { + filter =3D &g_array_index(cpu->kvm_pmu_filter, + struct kvm_pmu_event_filter, i); + if (i) { + g_string_append_c(pmu_filter, ';'); + } + action =3D filter->action =3D=3D KVM_PMU_EVENT_ALLOW ? 'A' : 'D'; + g_string_append_printf(pmu_filter, "%c:0x%hx-0x%hx", action, + filter->base_event, + filter->base_event + filter->nevents - 1); + } + + return g_strdup(pmu_filter->str); +} + +static void kvm_pmu_filter_set(Object *obj, const char *pmu_filter, + Error **errp) +{ + ARMCPU *cpu =3D ARM_CPU(obj); + struct kvm_pmu_event_filter filter; + g_auto(GStrv) event_filters; + int i; + + if (cpu->kvm_pmu_filter) { + g_array_free(cpu->kvm_pmu_filter, true); + } + + cpu->kvm_pmu_filter =3D g_array_new(false, false, + sizeof(struct kvm_pmu_event_filter)); + + event_filters =3D g_strsplit(pmu_filter, ";", -1); + for (i =3D 0; event_filters[i]; i++) { + unsigned short start =3D 0, end =3D 0; + char act; + + if (sscanf(event_filters[i], "%c:%hx-%hx", &act, &start, &end) != =3D 3) { + warn_report("Skipping invalid PMU filter %s", event_filters[i]= ); + continue; + } + + if ((act !=3D 'A' && act !=3D 'D') || start > end) { + warn_report("Skipping invalid PMU filter %s", event_filters[i]= ); + continue; + } + + filter.base_event =3D start; + filter.nevents =3D end - start + 1; + filter.action =3D (act =3D=3D 'A') ? KVM_PMU_EVENT_ALLOW : + KVM_PMU_EVENT_DENY; + + g_array_append_vals(cpu->kvm_pmu_filter, &filter, 1); + } +} + /* KVM VCPU properties should be prefixed with "kvm-". */ void kvm_arm_add_vcpu_properties(ARMCPU *cpu) { @@ -517,6 +583,12 @@ void kvm_arm_add_vcpu_properties(ARMCPU *cpu) kvm_steal_time_set); object_property_set_description(obj, "kvm-steal-time", "Set off to disable KVM steal time."); + + object_property_add_str(obj, "kvm-pmu-filter", kvm_pmu_filter_get, + kvm_pmu_filter_set); + object_property_set_description(obj, "kvm-pmu-filter", + "PMU Event Filtering description for " + "guest PMU. (default: NULL, disabled)"= ); } =20 bool kvm_arm_pmu_supported(void) @@ -1706,6 +1778,47 @@ static bool kvm_arm_set_device_attr(ARMCPU *cpu, str= uct kvm_device_attr *attr, return true; } =20 +static void kvm_arm_pmu_filter_init(ARMCPU *cpu) +{ + static bool pmu_filter_init; + struct kvm_device_attr attr =3D { + .group =3D KVM_ARM_VCPU_PMU_V3_CTRL, + .attr =3D KVM_ARM_VCPU_PMU_V3_FILTER, + }; + int i; + + /* + * The filter only needs to be initialized through one vcpu ioctl and = it + * will affect all other vcpu in the vm. + * It can be referred from kernel commit d7eec2360e3 ("KVM: arm64: Add= PMU + * event filtering infrastructure"): + * Note that although the ioctl is per-vcpu, the map of allowed events= is + * global to the VM (it can be setup from any vcpu until the vcpu PMU = is + * initialized). + */ + if (pmu_filter_init) { + return; + } else { + pmu_filter_init =3D true; + } + + if (!cpu->kvm_pmu_filter) { + return; + } + if (kvm_vcpu_ioctl(CPU(cpu), KVM_HAS_DEVICE_ATTR, &attr)) { + error_report("KVM doesn't support the PMU Event Filter!"); + return; + } + + for (i =3D 0; i < cpu->kvm_pmu_filter->len; i++) { + attr.addr =3D (uint64_t)&g_array_index(cpu->kvm_pmu_filter, + struct kvm_pmu_event_filter, = i); + if (!kvm_arm_set_device_attr(cpu, &attr, "PMU_V3_FILTER")) { + break; + } + } +} + void kvm_arm_pmu_init(ARMCPU *cpu) { struct kvm_device_attr attr =3D { @@ -1716,6 +1829,8 @@ void kvm_arm_pmu_init(ARMCPU *cpu) if (!cpu->has_pmu) { return; } + + kvm_arm_pmu_filter_init(cpu); if (!kvm_arm_set_device_attr(cpu, &attr, "PMU")) { error_report("failed to init PMU"); abort(); diff --git a/tests/qtest/arm-cpu-features.c b/tests/qtest/arm-cpu-features.c index a8a4c668ad..60a5e32eb8 100644 --- a/tests/qtest/arm-cpu-features.c +++ b/tests/qtest/arm-cpu-features.c @@ -127,6 +127,17 @@ static bool resp_get_feature(QDict *resp, const char *= feature) return qdict_get_bool(props, feature); } =20 +static const char *resp_get_feature_str(QDict *resp, const char *feature) +{ + QDict *props; + + g_assert(resp); + g_assert(resp_has_props(resp)); + props =3D resp_get_props(resp); + g_assert(qdict_get(props, feature)); + return qdict_get_str(props, feature); +} + #define assert_has_feature(qts, cpu_type, feature) \ ({ \ QDict *_resp =3D do_query_no_props(qts, cpu_type); \ @@ -156,6 +167,18 @@ static bool resp_get_feature(QDict *resp, const char *= feature) g_assert(qdict_get_bool(_props, feature) =3D=3D (expected_value)); = \ }) =20 +#define resp_assert_feature_str(resp, feature, expected_value) \ +({ \ + QDict *_props; \ + \ + g_assert(_resp); \ + g_assert(resp_has_props(_resp)); \ + _props =3D resp_get_props(_resp); \ + g_assert(qdict_get(_props, feature)); \ + g_assert_cmpstr(qdict_get_str(_props, feature), \ + =3D=3D, (expected_value)); = \ +}) + #define assert_feature(qts, cpu_type, feature, expected_value) \ ({ \ QDict *_resp; \ @@ -177,6 +200,17 @@ static bool resp_get_feature(QDict *resp, const char *= feature) qobject_unref(_resp); \ }) =20 +#define assert_set_feature_str(qts, cpu_type, feature, value) \ +({ \ + const char *_fmt =3D "{ %s: %s }"; \ + QDict *_resp; \ + \ + _resp =3D do_query(qts, cpu_type, _fmt, feature, value); \ + g_assert(_resp); \ + resp_assert_feature_str(_resp, feature, value); \ + qobject_unref(_resp); \ +}) + #define assert_has_feature_enabled(qts, cpu_type, feature) \ assert_feature(qts, cpu_type, feature, true) =20 @@ -461,6 +495,7 @@ static void test_query_cpu_model_expansion(const void *= data) =20 assert_has_not_feature(qts, "max", "kvm-no-adjvtime"); assert_has_not_feature(qts, "max", "kvm-steal-time"); + assert_has_not_feature(qts, "max", "kvm-pmu-filter"); =20 if (g_str_equal(qtest_get_arch(), "aarch64")) { assert_has_feature_enabled(qts, "max", "aarch64"); @@ -508,6 +543,7 @@ static void test_query_cpu_model_expansion_kvm(const vo= id *data) assert_set_feature(qts, "host", "kvm-no-adjvtime", false); =20 if (g_str_equal(qtest_get_arch(), "aarch64")) { + const char *kvm_supports_pmu_filter; bool kvm_supports_steal_time; bool kvm_supports_sve; char max_name[8], name[8]; @@ -546,15 +582,29 @@ static void test_query_cpu_model_expansion_kvm(const = void *data) * because this instance of KVM doesn't support them. Test that the * features are present, and, when enabled, issue further tests. */ + assert_has_feature(qts, "host", "kvm-pmu-filter"); assert_has_feature(qts, "host", "kvm-steal-time"); assert_has_feature(qts, "host", "sve"); =20 resp =3D do_query_no_props(qts, "host"); + kvm_supports_pmu_filter =3D resp_get_feature_str(resp, "kvm-pmu-fi= lter"); kvm_supports_steal_time =3D resp_get_feature(resp, "kvm-steal-time= "); kvm_supports_sve =3D resp_get_feature(resp, "sve"); vls =3D resp_get_sve_vls(resp); qobject_unref(resp); =20 + if (kvm_supports_pmu_filter) { + assert_set_feature_str(qts, "host", "kvm-pmu-filter", ""); + assert_set_feature_str(qts, "host", "kvm-pmu-filter", + "A:0x11-0x11"); + assert_set_feature_str(qts, "host", "kvm-pmu-filter", + "D:0x11-0x11"); + assert_set_feature_str(qts, "host", "kvm-pmu-filter", + "A:0x11-0x11;A:0x12-0x20"); + assert_set_feature_str(qts, "host", "kvm-pmu-filter", + "D:0x11-0x11;A:0x12-0x20;D:0x12-0x15"); + } + if (kvm_supports_steal_time) { /* If we have steal-time then we should be able to toggle it. = */ assert_set_feature(qts, "host", "kvm-steal-time", false); @@ -622,6 +672,7 @@ static void test_query_cpu_model_expansion_kvm(const vo= id *data) assert_has_not_feature(qts, "host", "pmu"); assert_has_not_feature(qts, "host", "sve"); assert_has_not_feature(qts, "host", "kvm-steal-time"); + assert_has_not_feature(qts, "host", "kvm-pmu-filter"); } =20 qtest_quit(qts); --=20 2.40.1