[PATCH v4 0/7] KVM: x86: Add LASS virtualization support

Sohil Mehta posted 7 patches 1 month, 4 weeks ago
arch/x86/include/asm/kvm-x86-ops.h            |   1 +
arch/x86/include/asm/kvm_host.h               |   2 +
arch/x86/kvm/cpuid.c                          |   1 +
arch/x86/kvm/emulate.c                        |  28 ++-
arch/x86/kvm/kvm_emulate.h                    |   4 +-
arch/x86/kvm/regs.h                           |   4 +-
arch/x86/kvm/vmx/main.c                       |   1 +
arch/x86/kvm/vmx/nested.c                     |  11 +-
arch/x86/kvm/vmx/sgx.c                        |   3 +-
arch/x86/kvm/vmx/vmx.c                        |  51 ++++-
arch/x86/kvm/vmx/vmx.h                        |   3 +
arch/x86/kvm/x86.c                            |   9 +-
tools/testing/selftests/kvm/Makefile.kvm      |   1 +
.../selftests/kvm/include/x86/processor.h     |   2 +
tools/testing/selftests/kvm/x86/lass_test.c   |  56 +++++
.../selftests/kvm/x86/set_sregs_test.c        |   3 +
tools/testing/selftests/x86/Makefile          |   3 +-
tools/testing/selftests/x86/lass.c            | 196 ++++++++++++++++++
18 files changed, 363 insertions(+), 16 deletions(-)
create mode 100644 tools/testing/selftests/kvm/x86/lass_test.c
create mode 100644 tools/testing/selftests/x86/lass.c
[PATCH v4 0/7] KVM: x86: Add LASS virtualization support
Posted by Sohil Mehta 1 month, 4 weeks ago
Linear Address Space Separation (LASS) is a security feature that blocks
accesses across the user/kernel boundary based on bit 63 of the linear
address alone, before any page walk is performed. Host support for LASS
has been merged [1][2]. This series adds the KVM virtualization support.

Patches
-------
The previous version of the LASS KVM series (v3) was posted as part of
the combined LAM and LASS KVM series. The LAM patches from that series,
along with the emulator flag cleanups that LASS depended on, were merged
separately. The remaining LASS patches went unposted for some time while
the host support was being merged.

I have refreshed the patches and rebased them onto the latest
kvm-x86/next branch. This iteration is marked as v4 to keep a sense of
continuity.

v3: https://lore.kernel.org/lkml/20230913124227.12574-1-binbin.wu@linux.intel.com/

Changes in v4
-------------
- Rebased the patches onto kvm-x86/next (7.2-rc2 based)
- Reorganized the patches and reworded the changelogs
- Switched to gva_t for the LASS address parameter throughout
- Advertised LASS with X86_64_F() so it isn't exposed on 32-bit
- Exempted branch targets from LAM untagging
- Added emulator TSS I/O bitmap cleanup
- Added basic KVM and x86 selftests

Background
----------
The host support series [3] covers the motivation, base enforcement
mechanism, kernel toggling of RFLAGS and CR4.LASS, and the userspace
exception notifications. Here's a brief summary of the SDM bits [4] that
affects KVM support.

When LASS is enabled, the CPU applies a violation check using bit 63 to
every access to a linear address prior to page walks. A user-mode access
to a supervisor address, or a supervisor-mode access to a user address,
typically raises #GP (or #SS in rare cases) instead of a #PF that
SMAP/SMEP alone would produce. LASS takes effect only in IA-32e mode.

Enforcement for supervisor-mode data accesses additionally requires SMAP
to be enabled, and is suppressed for explicit accesses when RFLAGS.AC=1.
Linear addresses used for TLB invalidation (INVLPG, INVPCID, INVVPID)
are not subject to LASS. Unlike canonicality checks, LASS only applies
to code fetches and not branch targets.

Note, LASS is now part of the SDM instead of the ISE. There are minor
changes to the wording but nothing substantial. It also includes a
clarification that the relative ordering of LASS and canonicality checks
is not defined and cannot be determined by software.

KVM support
-----------
KVM must apply the same LASS violation checks as hardware during
instruction emulation so that emulated accesses behave the same way.

Patch 1-4: Enhance the emulator to handle LASS violation checks.
Patch   5: Guest CPUID and CR4 handling. Expose LASS to userspace.
Patch 6-7: Basic KVM and x86 selftest for LASS.

Though functional, the tests in patches 6 and 7 are fairly limited and
mainly for reference and discussion.

Testing
-------
1. Basic enumeration and enabling in guest and nested environment.
2. LASS enforcement tests (userspace + LKDTM + test kernel module)
 - Userspace access to kernel address (read, write, instr fetch)
 - Kernel access to user address (read, write, instr fetch)
 - RFLAGS.AC=1 suppression (read, write)
 - FEP tests for the above cases

KVM selftests and kvm-unit-tests run guest code in the lower half at
CPL0, so enabling CR4.LASS makes the next instruction fetch a violation
and triple-faults the guest. We are evaluating if the infrastructure can
be enhanced to test LASS enforcement.

Links
-----
[1]: https://lore.kernel.org/lkml/20251201231537.736899-1-dave.hansen@linux.intel.com/
[2]: https://lore.kernel.org/lkml/20260413154235.1543087-1-dave.hansen@linux.intel.com/
[3]: https://lore.kernel.org/all/20251118182911.2983253-1-sohil.mehta@intel.com/
[4]: "Linear-Address Pre-Processing", Intel SDM (June 2026), Vol 3, Chapter 4.

Previous versions
v3: https://lore.kernel.org/lkml/20230913124227.12574-1-binbin.wu@linux.intel.com/
v2: https://lore.kernel.org/all/20230718131844.5706-1-guang.zeng@intel.com/
v1: https://lore.kernel.org/all/20230601142309.6307-1-guang.zeng@intel.com/
v0: https://lore.kernel.org/lkml/20230420133724.11398-1-guang.zeng@intel.com/

Binbin Wu (1):
  KVM: x86: Add an emulator flag to differentiate branch targets from
    fetches

Sohil Mehta (3):
  KVM: x86: Use linear_read_system() to read the TSS I/O bitmap
  KVM: selftests: Add coverage for LASS CPUID and CR4 handling
  selftests/x86: Add a userspace test for LASS enforcement

Zeng Guang (3):
  KVM: x86: Add LASS violation checks during instruction emulation
  KVM: VMX: Implement LASS violation check
  KVM: x86: Virtualize LASS and advertise support to userspace

 arch/x86/include/asm/kvm-x86-ops.h            |   1 +
 arch/x86/include/asm/kvm_host.h               |   2 +
 arch/x86/kvm/cpuid.c                          |   1 +
 arch/x86/kvm/emulate.c                        |  28 ++-
 arch/x86/kvm/kvm_emulate.h                    |   4 +-
 arch/x86/kvm/regs.h                           |   4 +-
 arch/x86/kvm/vmx/main.c                       |   1 +
 arch/x86/kvm/vmx/nested.c                     |  11 +-
 arch/x86/kvm/vmx/sgx.c                        |   3 +-
 arch/x86/kvm/vmx/vmx.c                        |  51 ++++-
 arch/x86/kvm/vmx/vmx.h                        |   3 +
 arch/x86/kvm/x86.c                            |   9 +-
 tools/testing/selftests/kvm/Makefile.kvm      |   1 +
 .../selftests/kvm/include/x86/processor.h     |   2 +
 tools/testing/selftests/kvm/x86/lass_test.c   |  56 +++++
 .../selftests/kvm/x86/set_sregs_test.c        |   3 +
 tools/testing/selftests/x86/Makefile          |   3 +-
 tools/testing/selftests/x86/lass.c            | 196 ++++++++++++++++++
 18 files changed, 363 insertions(+), 16 deletions(-)
 create mode 100644 tools/testing/selftests/kvm/x86/lass_test.c
 create mode 100644 tools/testing/selftests/x86/lass.c


base-commit: 2dfab80a305700a45bd947350dae253ba4e30c41
-- 
2.43.0
Re: [PATCH v4 0/7] KVM: x86: Add LASS virtualization support
Posted by Chen, Farrah 1 month ago
On 8/6/2026 9:15 AM, Sohil Mehta wrote:
> Linear Address Space Separation (LASS) is a security feature that blocks
> accesses across the user/kernel boundary based on bit 63 of the linear
> address alone, before any page walk is performed. Host support for LASS
> has been merged [1][2]. This series adds the KVM virtualization support.
>  
I tested this series on Clearwater Forest (CWF), running a KVM guest 
with -cpu host. Exposing LASS to the guest also requires the QEMU 
support linked below. With both series applied, LASS is correctly 
enumerated in the guest, and the LASS functional tests pass with 
vsyscall=none/xonly/emulate.

QEMU changes to expose LASS to guests:
https://lore.kernel.org/all/20260826035734.114685-1-kishen.maloor@intel.com/

Tested-by: Farrah Chen <farrah.chen@intel.com>
Re: [PATCH v4 0/7] KVM: x86: Add LASS virtualization support
Posted by Kishen Maloor 1 month, 1 week ago
On 8/5/26 6:15 PM, Sohil Mehta wrote:
> Linear Address Space Separation (LASS) is a security feature that blocks
> accesses across the user/kernel boundary based on bit 63 of the linear
> address alone, before any page walk is performed. Host support for LASS
> has been merged [1][2]. This series adds the KVM virtualization support.
>
I tested this series on Sierra Forest, using the QEMU support linked
below to expose LASS to the guest.

Covered:

- Guest enumeration of LASS and enabling of CR4.LASS.
- User accesses to supervisor addresses on hardware and under
  the forced emulation prefix.
- Supervisor accesses to user addresses from a guest kernel module under
  the forced emulation prefix: reads and writes, RFLAGS.AC suppression,
  SMAP=0 behavior, implicit descriptor-table accesses, and violations at
  a branch target.
- Nested VMX: VMCLEAR with a low operand address, taking a #GP at
  RFLAGS.AC=0 and completing at AC=1, via get_vmx_mem_address() ->
  vmx_is_lass_violation().

Not covered: the TSS I/O bitmap paths in patch 2, and ENCLS.

QEMU changes to expose LASS to guests:
https://lore.kernel.org/all/20260826035734.114685-1-kishen.maloor@intel.com/

Tested-by: Kishen Maloor <kishen.maloor@intel.com>