From nobody Fri Jul 24 21:52:36 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 56D713F4DDA for ; Thu, 23 Jul 2026 21:13:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784841192; cv=none; b=d3Ludla3nUvPIoxyIYrlBY6a5mibMaLD/ANm51it3st5RliQeNMRtelNp3NdqltUcK4AjFCTMXDbFxaPCXpa/2Rqo7t3CWG2I2C/TG4My3xP+aW2NBfDQW3/tMtliEpB0yyrih3RreO4Y9s/PowLOsSQUt29Rzonx9ChT3RmKqk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784841192; c=relaxed/simple; bh=1hWFHI4JRAs2hc0cg9v1/a4IQrHF/pLOqVLIAa8AbXE=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=lGL+vbIAI5+06SA9wmb7g/MK7EbKJ3fM3YmnPmDM4I0UMUbIEtBKpXmm7Zwwbb5Y419l1l87eXL/CkvPg+fbG4LD8nuaOAPEARlVjXzoxDQv+0NWXKaLXI+2E1lwOWF02S+jBm0Lh/JCN3UoRvANQ3iUL1TaI8SqhC9aMHFSkpg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=gkfNJMKE; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="gkfNJMKE" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-84885a4fcabso1289523b3a.3 for ; Thu, 23 Jul 2026 14:13:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784841188; x=1785445988; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:from:to:cc:subject:date:message-id:reply-to:content-type; bh=xHl5tfP5m5/e8XYPelSgAqtF3SsvtJLfy9mGWsHBD80=; b=gkfNJMKEo6uJiRdWYBz8f0aBrOFCFY42yuxSMiCuik5Sx+3eeylsbShPPCd9YQGEfC LqqWw7QZ3lKiVsZVDNOiDmMPjJ0w4hxW4AFl5FoxUaHEJ59lCQg4X+vPcGG3ECM3r/6b zXFSbsWtvhB0SwXmh41wsaJCLzMzTT7uCslx0MJ1LfKGfQzaAjuARdoDvXRZlZ2r2dET xCc9eKOmI2UTiMk+XIXkYwrdTN34Np9u9ptkZeaCEJqSwr/4SL91eYfzTCojqUXALZjo zMkj1dn0LGZQR6Izx6mOyZvuDp0kMOCkZelRV73iu/1VR+p8tClns4kImLQ9j2wHDRgj bwRg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784841188; x=1785445988; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=xHl5tfP5m5/e8XYPelSgAqtF3SsvtJLfy9mGWsHBD80=; b=j9FR5EOLDABwWuHtFOSByHpiISiUb9lISNbUhXwKmYVNSCCYSTePyZTw3ks8jvdJ0C vDLSm79dYOuKoSa3+Wt7LJ4pdRQv6vmZIBQMY/B+Jz1e0pdjQ9P6+/76BQ4Xj3ayq3FA ofaCne4aimkMd5cLvfVR8nLpiCmRa/3m4R7BR8FWmm1FXTthNYJHf7j/LBKczZlR5lK9 YFqZVN0bY8boT4i8c0FpqgZQJiTWUg9UWsvtDmxreh3xC+p98ZTo+FVtKP3SdvaPnmxQ pJi+1mrbNXhOOTt46pxmm+pOUlcaMco2vfzZ7MR7yejsSWLxI/efffuUAd7EVWaGmv7e Rwfg== X-Forwarded-Encrypted: i=1; AHgh+RrAktq8HGXArASMDe++Xg5gjGhFOAGqYoifD2LsRHxSNfo92vLVqZ/zzGvT/Xc2KIRMyY47JIbvxMKm914=@vger.kernel.org X-Gm-Message-State: AOJu0YwBkEXD33bKLBLnCTrF0CMkkGwPfyQaVYjxbdGhQ/2lZR5NLzcS qOISoNC2iclnMWksZD+Ca9yz/OZMGbFP2PcxjH5MQYbcS6mUOrM2Mo21EqYjeLHhdOmZ/N6QL8x nZYZJTg== X-Received: from pfwz7.prod.google.com ([2002:a05:6a00:1d87:b0:847:87ec:2a9f]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:2d82:b0:848:5935:2e11 with SMTP id d2e1a72fcca58-84e2bb1e85amr5266272b3a.48.1784841187864; Thu, 23 Jul 2026 14:13:07 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 23 Jul 2026 14:13:06 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260723211306.75397-1-seanjc@google.com> Subject: [PATCH v2] KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Michael Roth Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When {de,en}crypting memory of an SEV or SEV-ES guest on an SNP-enabled host via a temporary buffer, allocate a full 4KiB page for the buffer to ensure the page containing the buffer is wholly owned by KVM, i.e. won't be concurrently allocated and accessed by other kernel code while KVM is using the buffer to {de,en}crypt memory. On SNP-enabled platforms, when sending SEV/SEV-ES commands that trigger firmware writes to memory, the to-be-written page(s) must be (temporarily) assigned to Firmware (as required by the SNP architecture, to guard against using such commands as gadgets to attack SNP guests). See snp_map_cmd_buf_desc() and friends. Unfortunately, transferring ownership of a page to Firmware makes the page inaccessible to software, and thus writes generate RMP #PF violations. If KVM uses a sub-page allocation for its temporary buffer, some other actor in the kernel can allocate and use the other portions of the page, and thus trigger unexpected (and seemingly spurious) RMP #PF violations due to software attempting to access a Firmware-owned page. BUG: unable to handle page fault for address: ffff906ae30f0300 #PF: supervisor write access in kernel mode #PF: error_code(0x80000003) - RMP violation PGD 6b1b80d067 P4D 6b1b80d067 PUD 100231e2063 PMD 10055a88063 PTE 8000010= 0630f0163 SEV-SNP: PFN 0x100630f0 unassigned, dumping non-zero entries in 2M PFN re= gion: [0x10063000 - 0x10063200] Oops: Oops: 0003 [#1] SMP CPU: 70 UID: 0 PID: 10658 Comm: svw_WaiterThrea Tainted: G U W O = 7.1.0-smp--c22293789940-seanjc-next #1 PREEMPTLAZY Tainted: [U]=3DUSER, [W]=3DWARN, [O]=3DOOT_MODULE Hardware name: Google, Inc. = Arcadia_IT_80/Arcadia_IT_80, BIOS 34.86.0-102 01/25/2026 RIP: 0010:memset+0xf/0x20 Call Trace: __kvmalloc_node_noprof+0x2a4/0x710 do_getxattr+0x4e/0x130 path_getxattrat+0x125/0x1b0 do_syscall_64+0x10a/0x480 entry_SYSCALL_64_after_hwframe+0x4b/0x53 RIP: 0033:0x7f3a22cb6daa Modules linked in: kvm_amd kvm irqbypass vfat fat ccp k10temp sha3 libsha= 3 i2c_piix4 gq(O) cdc_acm xhci_pci xhci_hcd gsmi: Log Shutdown Reason 0x03 CR2: ffff906ae30f0300 ---[ end trace 0000000000000000 ]--- RIP: 0010:memset+0xf/0x20 Kernel panic - not syncing: Fatal exception Kernel Offset: 0x39e00000 from 0xffffffff81000000 (relocation range: 0xff= ffffff80000000-0xffffffffbfffffff) gsmi: Log Shutdown Reason 0x02 Fixes: 4c735bf1bc22 ("KVM: SEV: Allocate only as many bytes as needed for t= emp crypt buffers") Cc: stable@vger.kernel.org Cc: Michael Roth Debugged-by: Michael Roth Signed-off-by: Sean Christopherson --- v2: Use __get_free_page() to ensure it really is a full page. [Sashiko] v1: https://lore.kernel.org/all/20260723002547.7BF971F000E9@smtp.kernel.org arch/x86/kvm/svm/sev.c | 23 +++++++++++++++++++++-- 1 file changed, 21 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 74fb15551e83..803bd39695fd 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -1280,9 +1280,28 @@ static void *sev_dbg_crypt_slow_alloc(struct page *p= age, unsigned long __va, if (WARN_ON_ONCE((*pa & PAGE_MASK) !=3D ((*pa + *nr_bytes - 1) & PAGE_MAS= K))) return NULL; =20 + /* + * If SNP is enabled, i.e. the RMP is active, allocate a full page to + * prevent concurrent accesses to the page. As required by firmware, + * the PSP driver updates the RMP to temporarily transfer ownership of + * the page to Firmware while the {DE,EN}CRYPT operation is in-progress, + * and so concurrent software accesses to the page will encounter + * seemingly spurious RMP #PF violations + */ + if (cc_platform_has(CC_ATTR_HOST_SEV_SNP)) + return (void *)__get_free_page(GFP_KERNEL); + return kmalloc(*nr_bytes, GFP_KERNEL); } =20 +static void sev_dbg_crypt_slow_free(void *buf) +{ + if (cc_platform_has(CC_ATTR_HOST_SEV_SNP)) + free_page((unsigned long)buf); + else + kfree(buf); +} + static int sev_dbg_decrypt_slow(struct kvm *kvm, unsigned long src, struct page *src_p, unsigned long dst, unsigned int len, int *err) @@ -1304,7 +1323,7 @@ static int sev_dbg_decrypt_slow(struct kvm *kvm, unsi= gned long src, if (copy_to_user((void __user *)dst, buf + (src & 15), len)) r =3D -EFAULT; out: - kfree(buf); + sev_dbg_crypt_slow_free(buf); return r; } =20 @@ -1337,7 +1356,7 @@ static int sev_dbg_encrypt_slow(struct kvm *kvm, unsi= gned long src, r =3D sev_issue_dbg_cmd(kvm, __sme_set(__pa(buf)), dst_pa, nr_bytes, KVM_SEV_DBG_ENCRYPT, err); out: - kfree(buf); + sev_dbg_crypt_slow_free(buf); return r; } =20 base-commit: a204badd8432f93b7e862e7dac6db0fe3d65f370 --=20 2.55.0.229.g6434b31f56-goog