From nobody Mon Sep 28 04:08:10 2026 Received: from CH5PR02CU005.outbound.protection.outlook.com (mail-northcentralusazon11012061.outbound.protection.outlook.com [40.107.200.61]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 69C103AC0E4; Wed, 26 Aug 2026 22:35:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.107.200.61 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783744; cv=fail; b=SN6qU2X/pZamnss2N6WsE6etw+xTGtHWZe5Zq350J5uMkR1BRiKYW2SKc8h0DeKYf/c5URzzqXz+B6UAGyaBsevRsxEikQ4npAQjEZctU1V1pokBL1uLUxfEDhWf4wUTKzxoL2QiERE+bzOYRntz1+aknm9KAn4Xpk+p3HruXt8= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783744; c=relaxed/simple; bh=UEir/nSH3bO1W46kCmG9FpD6R1R/brtHQGRJbDZmI7A=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=uTR866sTFyW45hPYNKtzC8Yk8ARKj+o8c1m7/ET8fkWFN750olVJ5h89EH1IvjOcGPzjrK3g+9dXMV/a8vN5zcGYUm6Ol2CHBQy6CEb6v6u1TwvzmkTZFcagNF2YQJAdIa7On2ggB6Dt42UlmhSwgBO/8E0MtG2+SPBTjrLXVfI= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=Mp2vcOmb; arc=fail smtp.client-ip=40.107.200.61 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="Mp2vcOmb" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=hG+FprFR9R4QK9gWEa7Ch6RY9uSKklGxakiZpzfKJ1AfXsiVjdFWWzq/FiS2k7X+qPob70738SzeD2tDxO4b+AoCpo9zqWKEuvZ7GS5ZBBVJqgL2lFLedNdpYmrcqOCcohnPwVkmYyR5nzIGzpb+HRIQgzZCmS7mUyLR81VTa+SG9qL9ob1kUBI90pLn8P+w0fXYSnEQOvkKFMCurmH90ZqFSHOn9k+PkAFDIp1K/4YdVyRQ2ORyv5qKxX3KOlHupsYpn2ENOkYyJISCrHGcfwzN5nut9HMpqOWHzBSHwfUYic3K0+/DflDhWDDPnW8JrQxafWJocJYKLpfXe4zykA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=MCJlwxfxiP4kCiaL3StqA6BJ4EyfxLwIgXExO2RsrqA=; b=aMEWjY9QKKbO2rdDWfpNRHu0osD8oLACjTnkOAr4vPKvI9m3bl9o5pvBHU0oYsEya5fiT4RX1z7KO8PpAVAr63ETTzy7xO6PwrW3gXE+jdQa0uyTfIQ9tGDu/LOaCeEAipGKHzbeqb23mpCvhPu9wiVpdKpDEMUgYnTfRhdEyL75Y/1ZfJ0aKcbXI1tQxsNw7YKlyTysWmG+zWKatd57rlUYSfuVROBzzjakpjl6dOisoDBjv03duDOP/DrgblcPjoMiJQvEJ4x8j9PVnX2mI8KeqpKRnR3jQ8EgbJHCZSqhVQZr5l0vQFkO55DUNm/UDfaAU6ZhxEWDwNCId2bViA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=MCJlwxfxiP4kCiaL3StqA6BJ4EyfxLwIgXExO2RsrqA=; b=Mp2vcOmb/O9SNFKUZU25OByrBpOvP3T31VFD1PPnwqn79rL9/NcXeKhS1una3IPcCHQ6OCgwMq3uUZBmTf4NvOertWPyJMttCWxdaYKO7kRYXI9PLOftzhDGkhTZv27NNLO1ZliMbqjVFWgFmsme8mCxwn+EYQmaOEhvIsMBnKg= Received: from BL1PR13CA0006.namprd13.prod.outlook.com (2603:10b6:208:256::11) by MN2PR12MB4271.namprd12.prod.outlook.com (2603:10b6:208:1d7::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.7; Wed, 26 Aug 2026 22:35:39 +0000 Received: from BN3PEPF00022BBE.namprd04.prod.outlook.com (2603:10b6:208:256:cafe::69) by BL1PR13CA0006.outlook.office365.com (2603:10b6:208:256::11) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.6 via Frontend Transport; Wed, 26 Aug 2026 22:35:39 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBE.mail.protection.outlook.com (10.167.248.119) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:35:39 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:35:37 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 1/8] x86/bugs: Allow forcing Automatic IBRS with SNP active using spectre_v2=eibrs Date: Wed, 26 Aug 2026 17:35:03 -0500 Message-ID: <20260826223510.3669875-2-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBE:EE_|MN2PR12MB4271:EE_ X-MS-Office365-Filtering-Correlation-Id: 797bc31f-797b-45c9-f029-08df03c25ad6 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|82310400026|376014|36860700016|1800799024|11063799006|10067099003|6133799003|56012099006|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: 8FuIYIDv0T2v8L6pqKgUjwVfkaiPEUAPQfFZVu/Pg3vH7e5uopUjxtLf5ncdkDKmmaaVPPphoixN7QpwxOyHLRCJt05PqH6kyAcABLDRlPxhzJ23mqAtGoib5uKqFXnNB9X5rAgkfEr0ua2C1mV7QjMS6GPC9emGow8Zy+HSVE6kHpQavfV/ql9YimCn7T/51Wtb/GsqnYMbwVVZbX2DrFB6eSblPKTn1DWBXXD0ZJjcwIcP/x1wrvYy5cvxcURQnptnIL5hAjjp/CFWGHBI9zHv762L9x5Fid51rjJ++xi3c6dBlfaEZKSfklc0ThoGsg0rlKxaLG9+1f08GJlNpabsfJT7yR2406bhfnRvk6h8Uqmv8Ec53hdhkEQVBH9j7Fj0cnEV0GXImdEscdaYMM3wVICjbuVCQUD/tN50Q1qOnIsQ2EEuo8uGiByzPC4JFPpw3jBObTU2ZUgCQbkXmo6o9HsArE38VvSrGqkRjzZAR42dAtlN2g6YOyX5+icc/rGR3v2Qjk7jJN/JG5724pPqXELGJalK2z37xGvRNUqlyABlN89bMqmUBSAmqWZ04C+n4yzlzbdlMBFafAKceV8JIYbz4AqXh5hViuXLlJvXa0/7tjzKToemTIN0O/4RM5Iiyz77IMiwZtvDge9ahTJCeDphkxP1zeLD26kenpZY4BRDqlu+l2dN94YvJfj/S4YgJxBHoCzLXPdRwkmMsw== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(23010399003)(82310400026)(376014)(36860700016)(1800799024)(11063799006)(10067099003)(6133799003)(56012099006)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 9YVNFW+W5j1NAPhjIrHRvwtKUqb8o10F2Ql46ehkomWIsx16OE970FQIycnPolBdeQ7JOgUVCBtb0zeT0wc1gUodMbyrkcSXIUfpZSyF8XzCZ67ZUjmTzvV8yTGpM+T4qFG2je6RBPGxLDP63U/lGtmhxFPl5dXk5JNt8dvZ8WppM7mf+1FPWKEt4TQHnKSq03HzMIKu6O7W3Ozhe8FLHlCZ5W/foYphF1TBnDR88l80DPfYMK5ONPM8es49pB+rR1Q6eIjU0V+1cB8TB1wE6jYFQdPuQ9sGeCYAdERgaNQU1CBz7kXudIoWnIM/yNXhi4pstL5lFz0rm21Kw2Y570Wl8nZAFD4SiJBCkLaGumhdQynntoL2cHpltWMYDY95puZBPwF7hwecoQTnUaztYK5FkFmwsUT2cimP82I4hchC+Tby8v1VlP/lMMMIF3eU X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:35:39.0749 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 797bc31f-797b-45c9-f029-08df03c25ad6 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBE.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR12MB4271 Content-Type: text/plain; charset="utf-8" spectre_v2=3Deibrs currently enables retpolines when SNP is enabled, instead of AutoIBRS (EIBRS) because the commit that disabled AutoIBRS if SNP is enabled stopped short of enabling X86_FEATURE_IBRS_ENHANCED. Change the logic to enable X86_FEATURE_IBRS_ENHANCED, and move the decision to switch to retpolines in the default/"auto" case in spectre_v2_select_mitigation(). This allows the existing spectre_v2=3Deibrs logic to work as intended. Condition that switch on CONFIG_MITIGATION_RETPOLINE being built in. Otherwise spectre_v2_select_retpoline() returns SPECTRE_V2_NONE and an SNP host with AutoIBRS available would be left completely unmitigated against Spectre v2 in the default/auto case, which is worse than the userspace indirect branch performance loss AutoIBRS costs. Also emit a performance loss warning for using AutoIBRS with SNP enabled. AutoIBRS is activated for all three eIBRS modes via spectre_v2_in_eibrs_mode(), so use that helper to cover spectre_v2=3Deibrs, spectre_v2=3Deibrs,lfence, and spectre_v2=3Deibrs,retpoline uniformly. Word the warning in terms of the eIBRS mitigation enabling AutoIBRS, rather than naming AutoIBRS as the selected mitigation, so it reads correctly for the ,lfence and ,retpoline variants where another component is also active. Fixes: acaa4b5c4c85 ("x86/speculation: Do not enable Automatic IBRS if SEV-= SNP is enabled") Reported-by: Tom Lendacky Cc: Borislav Petkov (AMD) Cc: Pawan Gupta Cc: Dave Hansen Cc: Sean Christopherson Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 Reviewed-by: Pawan Gupta --- arch/x86/kernel/cpu/bugs.c | 15 ++++++++++++++- arch/x86/kernel/cpu/common.c | 6 +----- 2 files changed, 15 insertions(+), 6 deletions(-) diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index 56eac5611c31..48eb1872af18 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -1672,6 +1672,7 @@ static inline bool retpoline_seq_enabled(void) { retu= rn false; } #define SPECTRE_V2_LFENCE_MSG "WARNING: LFENCE mitigation is not recommend= ed for this CPU, data leaks possible!\n" #define SPECTRE_V2_EIBRS_EBPF_MSG "WARNING: Unprivileged eBPF is enabled w= ith eIBRS on, data leaks possible via Spectre v2 BHB attacks!\n" #define SPECTRE_V2_EIBRS_LFENCE_EBPF_SMT_MSG "WARNING: Unprivileged eBPF i= s enabled with eIBRS+LFENCE mitigation and SMT, data leaks possible via Spe= ctre v2 BHB attacks!\n" +#define SPECTRE_V2_EIBRS_SNP_PERF_MSG "WARNING: eIBRS mitigation enables A= utoIBRS on SEV-SNP enabled CPU, this may cause performance loss\n" #define SPECTRE_V2_IBRS_PERF_MSG "WARNING: IBRS mitigation selected on Enh= anced IBRS CPU, this may cause unnecessary performance loss\n" =20 #ifdef CONFIG_BPF_SYSCALL @@ -2194,7 +2195,15 @@ static void __init spectre_v2_select_mitigation(void) break; fallthrough; case SPECTRE_V2_CMD_FORCE: - if (boot_cpu_has(X86_FEATURE_IBRS_ENHANCED)) { + /* + * Prefer retpoline when SNP is enabled because AutoIBRS + * degrades host userspace indirect branch performance. Only + * do so if retpoline is actually built in, otherwise AutoIBRS + * is better than leaving the system unmitigated. + */ + if (boot_cpu_has(X86_FEATURE_IBRS_ENHANCED) && + !(boot_cpu_has(X86_FEATURE_SEV_SNP) && + IS_ENABLED(CONFIG_MITIGATION_RETPOLINE))) { spectre_v2_enabled =3D SPECTRE_V2_EIBRS; break; } @@ -2286,6 +2295,10 @@ static void __init spectre_v2_apply_mitigation(void) } } =20 + if (spectre_v2_in_eibrs_mode(spectre_v2_enabled) && + boot_cpu_has(X86_FEATURE_SEV_SNP)) + pr_warn(SPECTRE_V2_EIBRS_SNP_PERF_MSG); + switch (spectre_v2_enabled) { case SPECTRE_V2_NONE: return; diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c index c7352827f491..c568d74282a8 100644 --- a/arch/x86/kernel/cpu/common.c +++ b/arch/x86/kernel/cpu/common.c @@ -1496,13 +1496,9 @@ static void __init cpu_set_bug_bits(struct cpuinfo_x= 86 *c) /* * AMD's AutoIBRS is equivalent to Intel's eIBRS - use the Intel feature * flag and protect from vendor-specific bugs via the whitelist. - * - * Don't use AutoIBRS when SNP is enabled because it degrades host - * userspace indirect branch performance. */ if ((x86_arch_cap_msr & ARCH_CAP_IBRS_ALL) || - (cpu_has(c, X86_FEATURE_AUTOIBRS) && - !cpu_feature_enabled(X86_FEATURE_SEV_SNP))) { + cpu_has(c, X86_FEATURE_AUTOIBRS)) { setup_force_cpu_cap(X86_FEATURE_IBRS_ENHANCED); if (!cpu_matches(cpu_vuln_whitelist, NO_EIBRS_PBRSB) && !(x86_arch_cap_msr & ARCH_CAP_PBRSB_NO)) --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from SN4PR2101CU001.outbound.protection.outlook.com (mail-southcentralusazon11012017.outbound.protection.outlook.com [40.93.195.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C5BE1282F21; Wed, 26 Aug 2026 22:36:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.93.195.17 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783762; cv=fail; b=NWAl0ZAAxtUwwPwt8F2UKUczkxCWzK8Q4iDPLuk9FVS8owL9pT5rx/1pLuOBZVJvbS2PY+HLP8t3yT4EszA7TQSMLmrgzNF9xu9UWm1lrQKZHJmL/Ag1CIyKYgQtDE4x7pPt4E32YR8q4HEW7I/6tlxzzDAifUrBV9SzKkPOPXA= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783762; c=relaxed/simple; bh=Xve535GNuHbgDwzKurttal/ADXobYUY61d6wJ1aLC5E=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=O1BwbxKDJy/06TNPT5qdb1ztTckcKFeQEBa7k7zIF8UcIBcQiwXE9nBuK45GtFvcK9c0qr5lDe+ZfkYBtihNGRRD5Pkg3mdOL8OIaP21o/vKGHdpfZIO1aylbZ0SSND1N0oqpSGJN7rPvZQp79aI2FICsT0floIdOo3MouFUF/A= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=zUruKPes; arc=fail smtp.client-ip=40.93.195.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="zUruKPes" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=aAdDRUZhyY6LuUlGIFdr+fwHMVJEZj78g97jipB613WOKr9Xg0Eh9HzCg78YHgCdFtvMSp+79h3XXHDdGTjKmd+AIGzj6IuqTSC2iCQy03Jis0pIujG0oJrQ9MQ7UXM5YUkziV5G7R5KGZatEeFwibAw0qTfU7oygSRDfwJj9jEO6BmwTxZzUeLh7L+dHtxbyxzBX3yeUHAGp2yqUTtnKC5wPST4U4YsyI3dtGPZPhPMJ/c67HBPzEkcLItC2OwSSRWpE9B49qWc6LtzPPTboaZ3S9QbxWTHQdLwuauf2TW9i6k5xpmHxsDRTsrYSAtQHZRvNR0OYupmLh+OdIlG7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=2SabmJBjtvEqPvdS3M58fLOHsMAiWgTF+dwWVG5awNE=; b=o0xYRbo+eB6JNyXOObOyAFTB5DtBTaxFIdM2ivDJfSMSt76Sp6zBdw+Jq8p3WVne94HfNydqoGh6EJM85vXooAYfpl2IAPFPbRK5toYrmkQB7Tel9FzUimxdAzpnVTIivGR5mnsMLlRqnjLtyJRjNzzmPOHSSK9pkO7pmsSzrvmZuWaLm+a/ji+SKnnFoAf1s9wY6cN9taTb/AeYgvPnYL+uZjhVg1YbD7q6sVihuE+WYnoVxmDin/PY0FAqXZevruCUny3WldeFJ/k9TTw4AL9E0cXBOijMJYjmZhJd4l2rCYzeUBeotP/VYoeqwzfst+MVvm0cLVaR7YcWplPhJA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2SabmJBjtvEqPvdS3M58fLOHsMAiWgTF+dwWVG5awNE=; b=zUruKPesKSG87NXqbsFFHgS3cIttuHbVYCrBujXFwS9LgXsSriJ8f00E25tNqrtVJ2cnFLDe7AtdG0GQaUiOGbSo/2QanlbPzqfXpr1wTvCwQ8wUdTt+wwG8Uglg7/KK6XchNV3s9HhunbmBgZZ44PnMie4vmd7KQCSUX1EzK3g= Received: from BN0PR04CA0087.namprd04.prod.outlook.com (2603:10b6:408:ea::32) by DM6PR12MB4433.namprd12.prod.outlook.com (2603:10b6:5:2a1::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.339.12; Wed, 26 Aug 2026 22:35:56 +0000 Received: from BN3PEPF00022BC1.namprd04.prod.outlook.com (2603:10b6:408:ea:cafe::63) by BN0PR04CA0087.outlook.office365.com (2603:10b6:408:ea::32) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.10 via Frontend Transport; Wed, 26 Aug 2026 22:35:56 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BC1.mail.protection.outlook.com (10.167.248.120) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:35:56 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:35:54 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 2/8] x86/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel Date: Wed, 26 Aug 2026 17:35:04 -0500 Message-ID: <20260826223510.3669875-3-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BC1:EE_|DM6PR12MB4433:EE_ X-MS-Office365-Filtering-Correlation-Id: 7424f6b7-cd4e-462c-88a6-08df03c264ee X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|82310400026|1800799024|36860700016|376014|23010399003|56012099006|10067099003|5023799004|11063799006|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: 7lkb8rZBCnRpQGWOW86rwYM1nDTN3DQGJTQanLgUHQOi3RHHyR+8dQUBwO6Ymg8DG6/HQlZ1PleKeIp8y1EP1cf63Cd3kMHKalhrDi8wkYwCbLy9oUhGKf2CbF+Zo/OCeMJqU5p9Q4Zd1aJ0JlySpge9hpe50olalB6+N+rizG6zls8JShwXd/UnlA14cFz9PlvHZyKyKcyniwMrc1IUNfAA2vXGjswWtQGqjuqW7VmJdNitC2oFaJZ/Lj8ewO3AyXzId1HMtBG1hR1ukEfW5GzUUDtnWyAXK/L9OKovb8vNPoV7Ky4DGB2BcmubqMsqy3GPc/YipleVYHrD0GfeVXNQ79LRW8zIgvbJykuRykYw3Bwps/4bu6/V4n4MEHGQyMrzxoroXCs5GBO8ix1STl6NJWx04qn6kkPNSQv7+xnBf9wYN2pSz/PJhvYxuCrz2dISYMVsbx+IVWREBM5i1i41TM8jodHblvqWOKHhdwSCmz3Hik/iKh2sOeE7AjaSVf+Prxd+GS5uxm6Uhqcq6apOqsQqVJROb8XIcPnMCKL1H43OpyQRhtYNUofueMRLayf6lsGvaMqkUiVBterS3VJUL4Tww089BznGkU6voBVUUpmvXt/zTb2jp2p4vlPBKCeo4cTLWixhogSn7qe8JR3VAlsFejCeZrjhEtVac16VkTRSX/h3nS+CXJhV9iLwnWI098zD6yC1CyI6sqUcQg== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(82310400026)(1800799024)(36860700016)(376014)(23010399003)(56012099006)(10067099003)(5023799004)(11063799006)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: C1w30POt13Zv4da0LxbQfDd912dsyx/KYV7ftc9QRFJVeFG1CfHrUArWGLSM2Xu5wqIvHn6hjRQ8JgiqulKRvvIoFKzh2Cz0AkU+ZocN/8LVyuBkZf1BUYNdOsfDZBkgVRf5890yu+KVUE01qRSbThS3i4DKkTsc6p4+I2Pxer1WEbGMYZ6YhdzPsIAOwMdxny9MIQ8jjeacITnj7/LgJyAl7hyPbBT6dg6dgvlohQ+5zim3fUrGwwv9EXekIg8FZd5mDO+TzlZ6ki+dF7qxGk1vlRsFGzyWEBDaznd6Jo+k/VR24/pCGugmFQXvGljLkFqOobEiH0mztiNsA1v9+2JaPNjO2e8Hf6gu/oAo5De8E7KCV6CAFmUr0y7daIa2mGbMqkNe2ichV5T7l/Sg5OeSbe8d5kYdrrOjgu+035uw0WsfG+fa/zycf8Ijm6bJ X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:35:56.0055 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 7424f6b7-cd4e-462c-88a6-08df03c264ee X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BC1.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM6PR12MB4433 Content-Type: text/plain; charset="utf-8" Prepare for legacy IBRS toggling on AMD, where the BTB Isolation SEV-SNP feature uses it to optimize the VM exit-to-re-entry path. Commit 7c693f54c873 ("x86/speculation: Add spectre_v2=3Dibrs option to support Kernel IBRS") restricted the option to Intel because that was the only vendor that needed it at the time; nothing about the mechanism is Intel-specific. Keep the IBRS-trumps-retbleed logic in retbleed_update_mitigation() Intel-only. Legacy SPEC_CTRL.IBRS does not mitigate AMD's Branch Type Confusion RETBleed variant (RET prediction uses the Return Address Predictor, not the indirect branch predictors IBRS restricts), so letting SPECTRE_V2_IBRS trump retbleed on AMD would silently drop the UNRET/IBPB mitigation that does cover it. On AMD the decoupling is total: retbleed mitigation selection never consults spectre_v2=3D, so spectre_v2=3Dibrs neither adds nor removes RETBleed coverage. A kernel built without MITIGATION_UNRET_ENTRY and MITIGATION_IBPB_ENTRY already reports RETBleed as "Vulnerable" via the retbleed sysfs node and boot log regardless of the spectre_v2=3D value, so there is no silent gap in the spectre_v2=3Dibrs path to warn about -- and a warning there would wrongly imply the Intel-style IBRS/RETBleed coupling exists on AMD. Also drop CPU_SUP_INTEL from CONFIG_MITIGATION_IBRS_ENTRY's depends line: the IBRS_ENTER/IBRS_EXIT macros are vendor-neutral, and the Intel-only restriction would silently redirect spectre_v2=3Dibrs to AUTO on AMD-only kernels. In spectre_v2_apply_mitigation(), route AutoIBRS-capable CPUs to EFER.AUTOIBRS only for the eIBRS modes. Previously any IBRS mode used EFER.AUTOIBRS when the CPU had AutoIBRS, which was unreachable while spectre_v2=3Dibrs was Intel-only, but would now hand spectre_v2=3Dibrs the always-on AutoIBRS behaviour instead of the toggleable SPEC_CTRL.IBRS the option asks for. Finally, clear EFER.AUTOIBRS at the top of cpu_select_mitigations(), alongside the existing SPEC_CTRL kexec cleanup. head_64.S preserves incoming EFER bits, so a kexec from a kernel that ran in AutoIBRS mode carries the bit into the new kernel; without an explicit clear the CPU stays in AutoIBRS mode while sysfs reports e.g. "Mitigation: IBRS" or a retpoline mode, diverging from the actual hardware state. On a normal cold boot the bit is already clear, so the msr_clear_bit() is a no-op there. Clearing on the boot CPU suffices for APs, since it precedes the init_real_mode() EFER snapshot used by the AP trampoline. Reported-by: Tom Lendacky Cc: Pawan Gupta Cc: Borislav Petkov (AMD) Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 Reviewed-by: Pawan Gupta --- arch/x86/Kconfig | 7 +++--- arch/x86/kernel/cpu/bugs.c | 44 +++++++++++++++++++++++++++----------- 2 files changed, 35 insertions(+), 16 deletions(-) diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig index 15fd9ec5ecac..b9a7ddef4cba 100644 --- a/arch/x86/Kconfig +++ b/arch/x86/Kconfig @@ -2496,12 +2496,13 @@ config MITIGATION_IBPB_ENTRY =20 config MITIGATION_IBRS_ENTRY bool "Enable IBRS on kernel entry" - depends on CPU_SUP_INTEL && X86_64 + depends on X86_64 default y help Compile the kernel with support for the spectre_v2=3Dibrs mitigation. - This mitigates both spectre_v2 and retbleed at great cost to - performance. + This mitigates spectre_v2 at great cost to performance. On Intel, + it also mitigates retbleed. On AMD/Hygon, retbleed mitigation + requires MITIGATION_UNRET_ENTRY or MITIGATION_IBPB_ENTRY. =20 config MITIGATION_SRSO bool "Mitigate speculative RAS overflow on AMD" diff --git a/arch/x86/kernel/cpu/bugs.c b/arch/x86/kernel/cpu/bugs.c index 48eb1872af18..08780e0d37ec 100644 --- a/arch/x86/kernel/cpu/bugs.c +++ b/arch/x86/kernel/cpu/bugs.c @@ -1305,7 +1305,14 @@ static void __init retbleed_update_mitigation(void) =20 /* * Let IBRS trump all on Intel without affecting the effects of the - * retbleed=3D cmdline option except for call depth based stuffing + * retbleed=3D cmdline option except for call depth based stuffing. + * + * On AMD/Hygon, legacy SPEC_CTRL.IBRS toggling does not mitigate the + * Branch Type Confusion RETBleed variant: RET prediction comes from + * the Return Address Predictor, not the restricted indirect branch + * predictors that IBRS controls. So keep this Intel-only and leave + * AMD's software return-thunk mitigation (UNRET/IBPB) in place even + * when spectre_v2=3Dibrs is selected. */ if (boot_cpu_data.x86_vendor =3D=3D X86_VENDOR_INTEL) { switch (spectre_v2_enabled) { @@ -2166,11 +2173,6 @@ static void __init spectre_v2_select_mitigation(void) spectre_v2_cmd =3D SPECTRE_V2_CMD_AUTO; } =20 - if (spectre_v2_cmd =3D=3D SPECTRE_V2_CMD_IBRS && boot_cpu_data.x86_vendor= !=3D X86_VENDOR_INTEL) { - pr_err("IBRS selected but not Intel CPU. Switching to AUTO select\n"); - spectre_v2_cmd =3D SPECTRE_V2_CMD_AUTO; - } - if (spectre_v2_cmd =3D=3D SPECTRE_V2_CMD_IBRS && !boot_cpu_has(X86_FEATUR= E_IBRS)) { pr_err("IBRS selected but CPU doesn't have IBRS. Switching to AUTO selec= t\n"); spectre_v2_cmd =3D SPECTRE_V2_CMD_AUTO; @@ -2286,13 +2288,18 @@ static void __init spectre_v2_apply_mitigation(void) if (spectre_v2_enabled =3D=3D SPECTRE_V2_EIBRS && unprivileged_ebpf_enabl= ed()) pr_err(SPECTRE_V2_EIBRS_EBPF_MSG); =20 - if (spectre_v2_in_ibrs_mode(spectre_v2_enabled)) { - if (boot_cpu_has(X86_FEATURE_AUTOIBRS)) { - msr_set_bit(MSR_EFER, _EFER_AUTOIBRS); - } else { - x86_spec_ctrl_base |=3D SPEC_CTRL_IBRS; - update_spec_ctrl(x86_spec_ctrl_base); - } + /* + * On AutoIBRS-capable CPUs, eIBRS is enabled through EFER.AUTOIBRS + * rather than SPEC_CTRL.IBRS. Legacy spectre_v2=3Dibrs keeps using + * SPEC_CTRL.IBRS even there, as it needs to be toggled on kernel + * entry/exit. + */ + if (spectre_v2_in_eibrs_mode(spectre_v2_enabled) && + boot_cpu_has(X86_FEATURE_AUTOIBRS)) { + msr_set_bit(MSR_EFER, _EFER_AUTOIBRS); + } else if (spectre_v2_in_ibrs_mode(spectre_v2_enabled)) { + x86_spec_ctrl_base |=3D SPEC_CTRL_IBRS; + update_spec_ctrl(x86_spec_ctrl_base); } =20 if (spectre_v2_in_eibrs_mode(spectre_v2_enabled) && @@ -3297,6 +3304,17 @@ void __init cpu_select_mitigations(void) x86_spec_ctrl_base &=3D ~SPEC_CTRL_MITIGATIONS_MASK; } =20 + /* + * Likewise for EFER.AUTOIBRS: head_64.S preserves the incoming EFER + * bits, so a kexec from a kernel that ran in AutoIBRS mode carries the + * bit into this one. Clear it and let the mitigation selection below + * rediscover it. This also runs before init_real_mode() snapshots + * EFER for the AP trampoline, so APs inherit whatever this kernel + * settles on rather than the previous kernel's choice. + */ + if (cpu_feature_enabled(X86_FEATURE_AUTOIBRS)) + msr_clear_bit(MSR_EFER, _EFER_AUTOIBRS); + x86_arch_cap_msr =3D x86_read_arch_cap_msr(); =20 cpu_print_attack_vectors(); --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from DM5PR21CU001.outbound.protection.outlook.com (mail-centralusazon11011011.outbound.protection.outlook.com [52.101.62.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 98B7E48665E; Wed, 26 Aug 2026 22:36:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.62.11 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783779; cv=fail; b=By4NhAq/AiDM/vgpcwwqcQLZlhsK8KzkeLrA9gpVYTyAnMUXcMoS7DLp20qtDZyVSKGkkt/cd4PsX61xLyXCML7FsTkYHhCKGgrrToAnvIgU2t6dJHI7NJE/uPJmm2fZ19ZpR7lsjdx8FOpfP5r2YUf+GFAMhnQDup8BLkeBGNY= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783779; c=relaxed/simple; bh=vcOHw70gqx1utuf+a7+PmYUbcvELyPEmzScXy7/i4VU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Yc5A25wPjUplJzFsQnj80Nr1AydAry6w6onJiA+c7fSm2WMuvy1xn6hoGA1uVE9H3i92mu2n0ANULiFrDF3CHGeG+qLrotw7gEZ8ClgZus4LVVfwt9EfE4Kpa85sT2aLgaHZfmL1SMJR9C8SI2hIGcvb3MnIG7fQx200KkCjw+8= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=XVRVh95F; arc=fail smtp.client-ip=52.101.62.11 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="XVRVh95F" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=vXSc5Y+JwFXo8PSDdH1yq6p9FoFs/FLLskvWTWVsoQuURnnfxBwB1BFo8nuG5h6naJZjPbxd8HJ9Kxbale08rUH2UTBr8EgHRr3pJgvRglOLmjBcysbEZAZDdz3VfaduSFzFSx39/KsWA3FY2l9oGVOfBH+v0i4r8z+526JyW7HJc8AwTlUO0EcJP/ys485uN7+1uyJjhY8bfP8kwNw0HSYzgZcrfu2CsJKeZuY5ar/EYElUmSgqdW+g5BX2hQLjAOpf7/1o6BIeJeWyksUsWRpyl1bey+6O5GUpLNghm9cv/tWVZds3dIAV23+cuPxToZ3ko0O0WkiaKEhmyioBrw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=a4zLir7r4cUE9wikPfOL7fM/empip98R+ra1pTfITR8=; b=OIDDJfQRUnCwaSW0J/cdZGnTKkETzjkbms01ps/bAGjkDiahWXSMOQcHw/6yOAoSNhaENvLfytqQQ745Qy3KorM3btM57lORv1bOntCL+Cr1TUQ0q7AyVK+pE1T7RkXhG3r+WNSE7UQFYQ36nmDWV/UMcMJrfSszPqqyZHrHgQN5T5URKRVlnCCRSTxIWAX2zJjnSUk8SPjJXw8Xng6gxBlLeztqNMR9OGo5c6q7RI/HGwHcfqsVEjwlgltm/H/9q6Xu1ofpVc9U/I+JPQHvyv+CM0sP9Q9ZS8Z0lnK6mUYMKrkeeXjTb7b1UZ4StreomVnemxDYku0pk0+USCxM/A== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=a4zLir7r4cUE9wikPfOL7fM/empip98R+ra1pTfITR8=; b=XVRVh95FueSM8J1dq6UXcO//SPAzOEstyHmUj8fmsp9iViXtXHIhO/rRhnAgD/TbdMw1LKE0kXS2ZOG46eblBK+zgVeSbvfS51m/IZrx5DU2UC7XgassuwTd8FclV5A2lQQkufSnwRL+zTC8F4kLoaMn3hMX+y6P0M6wmy68uWw= Received: from BL1PR13CA0005.namprd13.prod.outlook.com (2603:10b6:208:256::10) by CYYPR12MB8704.namprd12.prod.outlook.com (2603:10b6:930:c2::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.7; Wed, 26 Aug 2026 22:36:07 +0000 Received: from BN3PEPF00022BBE.namprd04.prod.outlook.com (2603:10b6:208:256:cafe::2e) by BL1PR13CA0005.outlook.office365.com (2603:10b6:208:256::10) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.7 via Frontend Transport; Wed, 26 Aug 2026 22:36:07 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBE.mail.protection.outlook.com (10.167.248.119) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:36:07 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:36:06 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 3/8] KVM: SVM: Define SVM_SEV_FEAT_* flags using BIT_ULL() Date: Wed, 26 Aug 2026 17:35:05 -0500 Message-ID: <20260826223510.3669875-4-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBE:EE_|CYYPR12MB8704:EE_ X-MS-Office365-Filtering-Correlation-Id: c259622f-11fc-45ce-2d1b-08df03c26ba9 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|82310400026|23010399003|36860700016|376014|56012099006|10067099003|11063799006|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: F90OU/awg53ZLVnk2RmbyxhpUAMAyAvTEOtfi471TjgunI2fkIlc2l4HwZ48cJ5G++CzQSTPzdFKrT+SgtPUGX7Nj1aTkVzUl5ZvAIaFTndznVsdnyT8oLSHHKeAqNHn4C5XDg2oUVtGigpUn0a+Rf9UAGm6A9fpt6TUETBybWF4KMDzPlOrucgzk2Kmp7vTIsTaO+PwY7DcUkWGlkK/uHnXQleSO5UJYXUBbtKPNTly6bC/Ohn6VSCNSe/m8tUU1lgWkazx5lGWit7dlEOsa9Rf44e4RL/nEaDAiR2RdHhFSFeZ0k5iEQ6I8L+/Qd0CtA5btbBSZJbkqR922DpYzvrVcCCCiRNlvEItuUrq60ImT+1je8KW+b35B/N+E07ATTgq5Igp+AtOcLutaIhdn0vPLTErivfcQjKyTW2me9evldF+GU9KbFGlN8NhxcpJZMFcNyrniyurrIY5RfWCSTBFelAVeiGQ+5Ustyi4hl7/1MJrQ6TzPiI6Zhuv/SgFpwY2B3fzuUmJZnUpVOfgzI0/ZSS+VpG2FGKOcL9XVVs2ugTl3ntHdZ4inIrpHCWYkExUbGriyFUUkCp1NQRNBG4FzKfMMXQ137WJaSsmOoo1Tkf/Jpc8M6m3BnpP5Pwo6Hu4MNo+EEdt/IenIFGbmkm0fcumpkUMjjTB2/owiHhaUpltXmv7CqJCmVEpbnKa5p7Z0xMDdcMO1iBrwR11iw== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(1800799024)(82310400026)(23010399003)(36860700016)(376014)(56012099006)(10067099003)(11063799006)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: RF0Yf4boEjviSObrR7Dww5pqhFG7D4dJv9vLdAaG3QUIeRBQDOfBThkPrfwVOjmjXakN6ssfBzL4/r3SS3JMgn7XttTePe7MvfT6yO/vZpMs/fo10IRwZvPyCPcIZH8syv3c4TWIAXRXLMshAD4zustrYHE4ikEXMjmoMQaeZuyWLvWj/HEltzhWAVN/JScq6o8SQIQcJL8/ld9EFcHnP5I+XRZCowsiPhbdUK4+s11Wf4tfxos4AHKGzXiAWVfqACP1q0zS9XSi8Zgk3Tg5kukaCgCbThFHKzPMci5TJToiJAg35IX294Vn2nTHkWmre7YQW2Vv+UEAumWe5tO54Y/vaJneM38dzeSdrl+VrEiV8DHLPolcKD+wwPjbYx/2iHf/eSbDcnmss+IYHfVrks0KEAXEElUMoyNG+cWb6pzsp1D387+NgsiKCHILX9DU X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:36:07.2985 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: c259622f-11fc-45ce-2d1b-08df03c26ba9 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBE.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CYYPR12MB8704 Content-Type: text/plain; charset="utf-8" The VMSA's SEV_FEATURES field is 64 bits wide: struct sev_es_save_area's sev_features is u64, as are the VMCB allowed_sev_features/guest_sev_features controls and KVM's vmsa_features / sev_supported_vmsa_features tracking. Define the SVM_SEV_FEAT_* flags with BIT_ULL() instead of BIT() to match that width. No functional change on x86-64, where unsigned long is already 64 bits and every flag defined today is below bit 32. It makes the flag type match the architectural field, keeps composite masks such as the upcoming SVM_SEV_FEAT_SNP_ONLY_MASK 64-bit, and avoids a latent trap should a future flag land above bit 31. The adjacent VMCB_ALLOWED_SEV_FEATURES_VALID already uses BIT_ULL(63). Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 --- arch/x86/include/asm/svm.h | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h index aa63431ba92c..52c900bf7e20 100644 --- a/arch/x86/include/asm/svm.h +++ b/arch/x86/include/asm/svm.h @@ -305,11 +305,11 @@ static_assert((AVIC_MAX_PHYSICAL_ID & AVIC_PHYSICAL_M= AX_INDEX_MASK) =3D=3D AVIC_MAX_ static_assert((X2AVIC_MAX_PHYSICAL_ID & AVIC_PHYSICAL_MAX_INDEX_MASK) =3D= =3D X2AVIC_MAX_PHYSICAL_ID); static_assert((X2AVIC_4K_MAX_PHYSICAL_ID & AVIC_PHYSICAL_MAX_INDEX_MASK) = =3D=3D X2AVIC_4K_MAX_PHYSICAL_ID); =20 -#define SVM_SEV_FEAT_SNP_ACTIVE BIT(0) -#define SVM_SEV_FEAT_RESTRICTED_INJECTION BIT(3) -#define SVM_SEV_FEAT_ALTERNATE_INJECTION BIT(4) -#define SVM_SEV_FEAT_DEBUG_SWAP BIT(5) -#define SVM_SEV_FEAT_SECURE_TSC BIT(9) +#define SVM_SEV_FEAT_SNP_ACTIVE BIT_ULL(0) +#define SVM_SEV_FEAT_RESTRICTED_INJECTION BIT_ULL(3) +#define SVM_SEV_FEAT_ALTERNATE_INJECTION BIT_ULL(4) +#define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) +#define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) =20 #define VMCB_ALLOWED_SEV_FEATURES_VALID BIT_ULL(63) =20 --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from PH7PR06CU001.outbound.protection.outlook.com (mail-westus3azon11010011.outbound.protection.outlook.com [52.101.201.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B23EF282F21; Wed, 26 Aug 2026 22:36:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.201.11 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783787; cv=fail; b=NHK6LkYXNwWnJODg4jwrZYKk9+EdIduuZp5kAr/d5mbX+R2Unlo0BQqirwnODhHZNUJUikO74kRCUSE+rXh4NaQBWWFcZuj5+WJ4Gq7C7frrhKXCoTI9Nivo3+OBJS827zhnRUToE11Dga/T8E6o6GVIuhzFAHHIcr4fnPj21NM= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783787; c=relaxed/simple; bh=aWvriXNidefYQynXjKnhbYLGmpPRDzSmIU0xlCVGr3M=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Nr9AXkVZJFBx5bWIZlzwhRyUlTlJcl4eoC21igFqvb2D1Q6rLqecokTnzy3bkEsqrjJ+dSRnkC4wOz39p+4LxcQYM1/xkv4fU1VTumNcBvNV3JwTg2EpBhLOKVA359XMQxL+rbIDjbA4N43Ls40Q4RYpkSiKvzR4/mi2UolcXQY= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=KwIFKCIb; arc=fail smtp.client-ip=52.101.201.11 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="KwIFKCIb" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Nd5dhpRPAEqdZ830GF0VOHRDBaMRekU3SKEse88sdTQFlnT/ZzTUj1xHQJn2b3tL9HCzS06ZwFAfi8WDuk/PSwkSJrscgUo6Uwt7/w5EtJOAzYiHsJQNmtdGFFdN05mfkG98X8/f3EoLQYrr24HxpqmRvag0agS7p8/Q/AmoxWaqvtVkaAUTNLA+wOle77hMN2qBeCHnHc8mPIyciOIifikq8dLT7aQnDj3/SH8IfVeWAFIf3ujhsKk9qwGpHaht4ny7l+RwEvtjJaSRH1dvgIeBdsPFIuALzcos8kDqgBuBc8AzwqJl85Y1mY5kis7k5XPrZvK6wHxGrMPkOVaBUQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=YB5rLgaTanf6qlCmfnrSZiBCl9rseusyK9gCsuNrORw=; b=hAdGJPVpoD/oTkNH3KNo1jZ9Immq5L8MZ4saN4Z7UiNAci/Jc+j57arNGJMEbyYedEqyA/UlMFbasx+HjLJVpYYK1jHFcJfEJKNnAkYQ5NBnsLq/psn18/CtDSl8Gvc9Lr1D0S3GmSd4QaOxEwBEjGJBu6dPBgtCNsz+c8dYsZPy5dEIQnyp0oMVA6rkMcfGO7wXJDna/HUvEgQkv4BQ1tSUCoK5nC6Rw0QfN1VI+VfdMMt3/yU+wOHd+o/4ibFMZxNxZhnBY7jor6vBgg06jf0ajKpQgI/QeLUVubU+2OVutXVjxnLzmx4EY10DG1BQEVDZCtugNrvSDhD6V9txiA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=YB5rLgaTanf6qlCmfnrSZiBCl9rseusyK9gCsuNrORw=; b=KwIFKCIbpNfTaFebRZH2pzZEK6gxlGsWCsStklI09hP+1piymJWRunYCU72nmnUii6pRQBKKQoUFvLGI+WGx+Ha8ejPZnLolHlon3QytyzB0QUcqos3Ppl72V2Wv2/vAqZKCqvzmbBr85iqySf2mS9JqF3x9PEie8zYonrda6KA= Received: from MN2PR11CA0019.namprd11.prod.outlook.com (2603:10b6:208:23b::24) by DS0PR12MB8525.namprd12.prod.outlook.com (2603:10b6:8:159::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.8; Wed, 26 Aug 2026 22:36:19 +0000 Received: from BN3PEPF00022BBB.namprd04.prod.outlook.com (2603:10b6:208:23b:cafe::4c) by MN2PR11CA0019.outlook.office365.com (2603:10b6:208:23b::24) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.8 via Frontend Transport; Wed, 26 Aug 2026 22:36:19 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBB.mail.protection.outlook.com (10.167.248.122) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:36:19 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:36:17 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 4/8] KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition Date: Wed, 26 Aug 2026 17:35:06 -0500 Message-ID: <20260826223510.3669875-5-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBB:EE_|DS0PR12MB8525:EE_ X-MS-Office365-Filtering-Correlation-Id: 7123ce0b-3f47-4068-f43c-08df03c272ab X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|82310400026|36860700016|23010399003|376014|1800799024|10067099003|56012099006|5023799004|11063799006|6133799003|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: W7DFy9C0SCYE+yHzDVBCPW/eJwu6J5ZJDafy1jTkMHjq6bo9f/JLSPkIidCIVnawx1uMyK9laJqnifNMQn+6IhTQI7a+30W58zVyv80wrlEGs9gKXusrRe0hYSA6TjJKRAQ0F6JysaUnPxjUWKPeTVkdLI8AfOEqmmgEQ2kafs/QaUVhfFOxXqzseiCFi/k8C5dFdED/ViBU8s3fKl6KIFO3sr3SvUqXSmqxQWnyLTJ1caBub5XzCrptEv/8y1lvDnnZMyfVd/DysvPLWDWz1cZmTfK+cNvCi+YFJrsZ5Ita4SPY93LvP3qg1XROReXBDUwt2a4la/yT/wonnuyWXPMoxUbcB0hVCCbr398p4iTdmbutWwP6/dDGqrva+W9JIeRCoFMAoKyRV9PhE5MoS45yrob1hiYYmFHBtLN9HPZ1MCw5TjxqPVL4yyANfJHquqE6qZ2mVlvnO4bejriBb2LkUlrhpM5QPBVcbjLxsTTSJADLekKhpTNaJYSEU4mk7lBVVvlJCVZkaFeLC3GMJtG3o2z9dnPz+mH3ApwCPjvYHhQGB48p1qj123dq5cum/z2l3KO9zAuLZGIAc4ARAdwiWsg0ouE4oFF2+98ksay2rM18NqaNMfFdThnnPmODjVPUCEJFRCwpNaCclIWvXcTvp4hCLSNr6WJgtB6ceOhZItqkW38QN4XKIe13KvuxYKfbd+nYqJzJOYZN+lt3TA== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(82310400026)(36860700016)(23010399003)(376014)(1800799024)(10067099003)(56012099006)(5023799004)(11063799006)(6133799003)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 8JqTKEFNDsDBFhI545IlOtH829ryHl4WFrjlvIS5URoVFAhLygyeJKwEGRNINKKz8qWmDEuFmX/t/ahEC6S33itzgsC5Ul35n/U6OEYlx4AK3pG3pWU0mN1xDpSHjl7rFA1ftBaLIMr62xlY9zBHr6gFKVZ05CGYI1/pkU2rLy8QjuSFuqx7xzpgQYyMuZb35k17AnUEIrpqwMkwj0HhuCw4TckNh0MEbuuOcXxIeo0MzGe+oIy0z2j3wIoewycTzUQAPA0teO99L37sH2lXKKJHOcO+jubN/h9nA4KyhxGKcj2KlISJXgbLVCd2jZqxncVAYBEt1gqQx5IFfsoFEYiXw1Q/POGnDgp86/NO8AUF4TjAAbwmusvC62EBdAJd8/H96TMQbJt9iJmS6OgLoM2tlNThbRfXikYgfS/3bt3WYES97XrhPlJvDjmP09Uy X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:36:19.0596 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 7123ce0b-3f47-4068-f43c-08df03c272ab X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBB.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR12MB8525 Content-Type: text/plain; charset="utf-8" SVM_SEV_FEAT_DEBUG_SWAP was defined as 32u, a 32-bit unsigned literal. The kernel's supported_vmsa_features is a u64 and uses BIT(5) for this feature. Redefine the selftest macro with BIT_ULL(5) to match that 64-bit semantic and the BIT_ULL(n) form used by the additional feature bits introduced later in this series, so every feature-bit definition in the file is uniformly 64-bit wide. The value is unchanged (0x20); this is a width/consistency cleanup only. Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 --- tools/testing/selftests/kvm/x86/sev_init2_tests.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tools/testing/selftests/kvm/x86/sev_init2_tests.c b/tools/test= ing/selftests/kvm/x86/sev_init2_tests.c index 87bff4fbb7ed..61a94c6eec27 100644 --- a/tools/testing/selftests/kvm/x86/sev_init2_tests.c +++ b/tools/testing/selftests/kvm/x86/sev_init2_tests.c @@ -13,7 +13,7 @@ #include "svm_util.h" #include "kselftest.h" =20 -#define SVM_SEV_FEAT_DEBUG_SWAP 32u +#define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) =20 /* * Some features may have hidden dependencies, or may only work --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from SJ2PR03CU001.outbound.protection.outlook.com (mail-westusazon11012000.outbound.protection.outlook.com [52.101.43.0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E34C236D9E7; Wed, 26 Aug 2026 22:36:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.43.0 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783804; cv=fail; b=QPztAuQFLg8CizHknbkzl8MM+Af5+GR/BzVvdqmMDCxKdOn+UnImwvCtjM3MF+955aTWVAtOHVGjUxqXpLZ94559JakQSB8ScBdZ/uFLmc3ftOK/sgnTKfj6DNlFkWMzYdKKdvH9GIXZ2iiuiAucORt4RpcB8AaZAB9Wk1fJb3w= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783804; c=relaxed/simple; bh=UcQSjmWeg2yjNeGuVQm1U4pxV+nR5aPWp00GaJttdVc=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=i6xULTLu8bQjoTrWSQCeP3nN7Yd4XfPmM2nnurnq9Ua3kkTGygq3d5B540xVNwbTS+u+BIdyOwRzTGQG/cqIenJrvqXax8xke6G4Bvo5LJwhISkKZMosLRgC+PgczdrsELkxCAJp4imR62S9clAisq2x9BQtHAV4Q0eQYyH4mSQ= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=bXZkqo+i; arc=fail smtp.client-ip=52.101.43.0 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="bXZkqo+i" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=Xojp4DT0TSY0w+NgqXTGuY2hntHUGnJzLBGA+O0i8H8z3T1mNnn56zykpwGkG1E2E/t2m5YvkwRgvut2hwwUagp0o0hym0p1iU7+lXw9Ro9fXGcLTP5rH0rSSf6mxmGMWnjF5tbgVuT5UqmaeTjuPLCfgjFmTeuEegBf47hWt/m5hGnZMvQvc/14ZaNxd8MDpWltiJ2G4SwDNn8vMSGqI04cOccWvtPLdFhEJkuRc1PvG9ohyRmAzRggYHL6Glc3M6WZLlzSQ1pVZHfa0vIlZg73mFbbGxVMHHpxSze7xnc3/a7mv/pnVihuQwQXU9LGS/SVVmlECvSu0qmO5QXNSQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=nOwYcv2dgarSXC7nejodzdwI3rDT1autW39QPQETgEQ=; b=VFefasTiGFHr8UlspZlEb1GUs2nPEdcDJpFvGD0KeCd9dHSQ144pZzVyFbNwAZSk6LkXAi3VysoxcgbVjLixGm9QD/ns+A2//gIpAgOHBbZgqa6MbZawJETzQxTXrxIbc2Y9uuPdv1DX2ZgHkaP38sr3QX9M9vQPK5AVpl79XEDb0k5zXLgagDNSNVcJFmarFGRYymB2YYdd0Uj8TKWwOQRLWOuxu6y7z1yD8p7l/0yxNUwqAKCjLaD+oNt9YpDHuSZDFXhJfStxLQWdXIbloBaftFKsCF1hgWfpyG8vHiGwLv9CUES8Q9EREgr+Ukc+rCL7+ybHb7hrEoMRd7eMzg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nOwYcv2dgarSXC7nejodzdwI3rDT1autW39QPQETgEQ=; b=bXZkqo+i0795LiHs371lmtRkMBwnlKds5UJ2JQTL9hyWokuaZDYGNgvXpetDOgBx4BMknciN0RbpzYCQBORVMiWEKD1NF7/YxLUEnztE9Pkt4YMr8SJHjAyQ4Kz3+nJgji3LO8wly/N9weGxR00sqxXndnv+LRzJAvDPPyNvHUU= Received: from BN0PR04CA0064.namprd04.prod.outlook.com (2603:10b6:408:ea::9) by BN3PR12MB9596.namprd12.prod.outlook.com (2603:10b6:408:2cb::12) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.10; Wed, 26 Aug 2026 22:36:36 +0000 Received: from BN3PEPF00022BC1.namprd04.prod.outlook.com (2603:10b6:408:ea:cafe::45) by BN0PR04CA0064.outlook.office365.com (2603:10b6:408:ea::9) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.10 via Frontend Transport; Wed, 26 Aug 2026 22:36:36 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BC1.mail.protection.outlook.com (10.167.248.120) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:36:36 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:36:34 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 5/8] KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a single mask Date: Wed, 26 Aug 2026 17:35:07 -0500 Message-ID: <20260826223510.3669875-6-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BC1:EE_|BN3PR12MB9596:EE_ X-MS-Office365-Filtering-Correlation-Id: 333cf665-24e7-426d-0ae7-08df03c27cde X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|82310400026|376014|36860700016|1800799024|23010399003|13003099007|6133799003|11063799006|56012099006|10067099003|5023799004|18002099003|22082099003; X-Microsoft-Antispam-Message-Info: 80iR/0i6y0XkZn1/H/U5czAjk1HMvmHGXGFn2RLKA89XxiNkjSYR5I0Hefda748pobl21HLXwBfM5hT4szKZ6O6NSo9jUGFCtZXIdk3zWz4DTR1F1WOSAJCaSvuA7rmZ1RnCjbIGHvns2FeZGSsSsaYeFfB8LvMIZhjzx/b1lLsX1TU6LXiGaUcYZkXlTCsppzDRNLSrruu9apBpYu4VCUJYfktBlKsaByEYdUmCkfSIe6EQGTkWQfAXR+Ip/WVkyHEkl/bZ03XRnZzbanOZKR8UfLrxIIVwvuTm/qyC2oaukTLVTZN4Vbtp7svo06EUKDyfa6BdvuExk2WuiVJPDciHFGw9r4+lX4HRrhXgCww7tiQDSJMKlqJeLprxGhc0C8rim1pJVMs1ng2xh8ukkrAGPCyTyZr4D+oENLmiHwWOqzyDmwc3YodsuYwTCObgBoGh+6Gqz4BGKCWxRcB6lCa8eKfP06Dx5ETVZg7poRsL/2rZ7JCEq51PzTG+v93PT64GObRSBOAKnjnSliI0zNHaKc6RTgldxp/Zyz9FdbwAlU1kzcCaEzTnVpuCbJz9M8cyaawmzlg4Jmj3+iNYPk7uT8oDXewVZnJjlm9taDzRjSp3wdjur5iMwO9OykFoAMohw6ZoMbqC1Xv7DJLE/E5uZBFRjhOM+BB1RiShrKfVgKGsh5QT8m7KfGhrrO3nvzOEN14ynGF+lrTu75ok7Q== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(82310400026)(376014)(36860700016)(1800799024)(23010399003)(13003099007)(6133799003)(11063799006)(56012099006)(10067099003)(5023799004)(18002099003)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: O37pqazBe4/wJwC1sCrYqY+iDyFruYLqfUEQ9vIm+4aP/utpWOmKjhyOavKk5gLEij57khyrSQWoqxYIPqpjpFvwQX16hdEjYvlznQxf75cmNa4uFP7cgrVmXVhXAMkJFBTVBrDcc/2NidPJaRJ+pCLneYHb1czLLai+MWKZZTMG233iKysh1ZULLjXepzqpLjhJbR8/n+Bs9POSnZzoAq3FxAuHk+O/IcSiJU185JQA3tYrQM7w0ty6YRQuC+EM5cB5KKdJBJWsgY4hRXrycP4C9PfWahfSfQ6YWCWd0Nifpp/eLkIwji09hNEsF5fAsJ6SPfRIP3h1gbNRmitQyoUyGYIey40c8bxLKExnjqx6MNmKMeBMN5z9v5NetwfG8eWSqW9GP8xlrDUMGUf71Dxp3QSECcts3Jm62vumU9JgxE5G7B7EmpY+VAACkyyh X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:36:36.1603 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 333cf665-24e7-426d-0ae7-08df03c27cde X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BC1.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR12MB9596 Content-Type: text/plain; charset="utf-8" As SNP-only features get added, adding them to the valid_vmsa_features mask in __sev_guest_init() often gets neglected. Add SVM_SEV_FEAT_SNP_ONLY_MASK to help group these common features together. Also establish SNP_ONLY_FEATURES in the sev_init2 selftest as the corresponding mask for features that must be rejected for non-SNP guests, populate it with SVM_SEV_FEAT_SECURE_TSC, and exercise the rejection path by masking those bits out of the features passed for SEV-ES guests. Define the selftest's SNP_ONLY_FEATURES as ULL so future bits can use BIT_ULL() there without truncation against the u64 supported_vmsa_features. Suggested-by: Sean Christopherson Cc: Borislav Petkov (AMD) Link: https://lore.kernel.org/kvm/aaWog_UjW-M3412C@google.com/ Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 --- arch/x86/include/asm/svm.h | 2 ++ arch/x86/kvm/svm/sev.c | 2 +- tools/testing/selftests/kvm/x86/sev_init2_tests.c | 12 +++++++----- 3 files changed, 10 insertions(+), 6 deletions(-) diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h index 52c900bf7e20..a206a0ed2c58 100644 --- a/arch/x86/include/asm/svm.h +++ b/arch/x86/include/asm/svm.h @@ -311,6 +311,8 @@ static_assert((X2AVIC_4K_MAX_PHYSICAL_ID & AVIC_PHYSICA= L_MAX_INDEX_MASK) =3D=3D X2AV #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) =20 +#define SVM_SEV_FEAT_SNP_ONLY_MASK (SVM_SEV_FEAT_SECURE_TSC) + #define VMCB_ALLOWED_SEV_FEATURES_VALID BIT_ULL(63) =20 struct vmcb_seg { diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 5705723f1f41..3c9483733865 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -506,7 +506,7 @@ static int __sev_guest_init(struct kvm *kvm, struct kvm= _sev_cmd *argp, return -EINVAL; =20 if (!snp_active) - valid_vmsa_features &=3D ~SVM_SEV_FEAT_SECURE_TSC; + valid_vmsa_features &=3D ~SVM_SEV_FEAT_SNP_ONLY_MASK; =20 if (data->vmsa_features & ~valid_vmsa_features) return -EINVAL; diff --git a/tools/testing/selftests/kvm/x86/sev_init2_tests.c b/tools/test= ing/selftests/kvm/x86/sev_init2_tests.c index 61a94c6eec27..8269f146b1f5 100644 --- a/tools/testing/selftests/kvm/x86/sev_init2_tests.c +++ b/tools/testing/selftests/kvm/x86/sev_init2_tests.c @@ -14,16 +14,18 @@ #include "kselftest.h" =20 #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) +#define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) + +/* Features valid only for SNP guests, rejected for SEV-ES and below. */ +#define SNP_ONLY_FEATURES (SVM_SEV_FEAT_SECURE_TSC) =20 /* * Some features may have hidden dependencies, or may only work * for certain VM types. Err on the side of safety and don't * expect that all supported features can be passed one by one * to KVM_SEV_INIT2. - * - * (Well, right now there's only one...) */ -#define KNOWN_FEATURES SVM_SEV_FEAT_DEBUG_SWAP +#define KNOWN_FEATURES (SVM_SEV_FEAT_DEBUG_SWAP | SNP_ONLY_FEATURES) =20 int kvm_fd; u64 supported_vmsa_features; @@ -108,7 +110,7 @@ void test_features(u32 vm_type, u64 supported_features) if (!(supported_features & BIT_ULL(i))) test_init2_invalid(vm_type, &(struct kvm_sev_init){ .vmsa_features =3D BIT_ULL(i) }, - "unknown feature"); + "unknown or unsupported feature for VM type"); else if (KNOWN_FEATURES & BIT_ULL(i)) test_init2(vm_type, &(struct kvm_sev_init){ .vmsa_features =3D BIT_ULL(i) }); @@ -157,7 +159,7 @@ int main(int argc, char *argv[]) =20 test_features(KVM_X86_SEV_VM, 0); if (have_sev_es) - test_features(KVM_X86_SEV_ES_VM, supported_vmsa_features); + test_features(KVM_X86_SEV_ES_VM, supported_vmsa_features & ~SNP_ONLY_FEA= TURES); if (have_snp) test_features(KVM_X86_SNP_VM, supported_vmsa_features); =20 --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from CO1PR03CU002.outbound.protection.outlook.com (mail-westus2azon11010040.outbound.protection.outlook.com [52.101.46.40]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7BE9430F526; Wed, 26 Aug 2026 22:36:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.46.40 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783812; cv=fail; b=LZ+bfNS+UuEz6TsWBz7VfOBsQQeXfcaI+l1l44r/MW2IQ4HdKWV0WKmlLDuWGNZCXyVSmQwuvrw2+8G32HxYioBBoXpDQWJViCWcjYYKvQORFzg+7xZEuMsYaioJdAQf63gJVYES6/2fEFH7ZiWSmpNaSK16AMiVvIqA52JOUuY= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783812; c=relaxed/simple; bh=mHWDinEStA5n+jjIO80R4zYCrc+Da4MMYvkorM74lpU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=dCtL8cotZ6VfnXYIN6a7oBAlPwb6GsdyvA+3DxeB+M/2AbM/q6UPWSNy3Bzp8TQ/wcOkGpNF+llmTBTu7Wg1Mzq94gUG02uPMvvsIWh5QTYOR/k27jxBFuCsNqdhIVh9EvQ1L0SpZLYvQ6viAHByq+2F6JVfFeqKIm7/RLypzSo= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=BdDP1jnx; arc=fail smtp.client-ip=52.101.46.40 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="BdDP1jnx" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=SjSoV1ypybNwh1bqIGzTr47++DjAhbRA6kRveGKgUUg6Ne8Zl4YLjzUHoIYnopQyronpeUJB0QiNrKx3ruZqurEtYFt38cvEcaachC3QKSnFmAP0Y5nmXokiT7RfxSeDQxeUDYNIvasU6rslcH/oO+vcEYAn+uMqg2LhVO6bB4CRbA33P47NM2O3f5FX0j5bMgTdW9cYlT/Sv0XtaN0qUzTHNwmcCX9FGUoS1xinSTNmS3Bt2uBMEeqSXknfUuYnV8thCVIucfRU3QZAxAKceuHFG/GO4YExgvVi2oimCnYtnu2XSYeSgoAuwtiNZc50oSHEGn47/FX2s1l/kFMxUg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=6iY2igYwOVI9hazyzs4pvu2KE/JKrXh4BctQmHgGYDw=; b=A26xG7VfTCuROyD7VYDEDlkqZL6wsVGUFCW+wnhatIlfN5qVONCA4C/HowQhbXcRWpVrU72qI1S7fZpeUB472AeDLdgA+i5BvodX1Z5ukGiTqrZSQrYo1r4x7L1STvl5SXkuMt2Ccwnsa72AmVTn1YYRWTp5mdVJGpLJShABFG92Y05N+FrR5uFsRbhAQBqkrOIhhx6U4bXzTkpPeLR82LJWCK89xpyNHridgoXUaaTeRcCAKZTlo3W1vfoE4G/6+y1Z1Mrs3hDSIHQHAdpuZNuAb7/HH/m9wlQAEhpFTQpcwV+mYKE+2XAuNslRhiRqVqyJhGytgw7tH3GjdAs/Hg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=6iY2igYwOVI9hazyzs4pvu2KE/JKrXh4BctQmHgGYDw=; b=BdDP1jnxsdi8RmnE46JpWMePqvESqap7lr0CYr4ZTAHysmw7FSEUzsaHcfpgns9V2zrT/3ajOAFO2ES2+n2sJJNacDZdpaq5m6Plc0d2o0lcgZLerLT9+J/8ZvAA8Z1qzmaOGi/jGTydWlTBNzhMaHLn678+nsaUKWmbBDXuAYg= Received: from BN9PR03CA0882.namprd03.prod.outlook.com (2603:10b6:408:13c::17) by IA5PR12MB999302.namprd12.prod.outlook.com (2603:10b6:208:605::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.339.12; Wed, 26 Aug 2026 22:36:47 +0000 Received: from BN3PEPF00022BBF.namprd04.prod.outlook.com (2603:10b6:408:13c:cafe::23) by BN9PR03CA0882.outlook.office365.com (2603:10b6:408:13c::17) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.8 via Frontend Transport; Wed, 26 Aug 2026 22:36:47 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBF.mail.protection.outlook.com (10.167.248.121) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:36:47 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:36:46 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 6/8] KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE Date: Wed, 26 Aug 2026 17:35:08 -0500 Message-ID: <20260826223510.3669875-7-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBF:EE_|IA5PR12MB999302:EE_ X-MS-Office365-Filtering-Correlation-Id: 20875495-62c6-44c0-9d7a-08df03c28391 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|36860700016|376014|1800799024|23010399003|82310400026|56012099006|10067099003|6133799003|22082099003|5023799004|11063799006|18002099003|13003099007; X-Microsoft-Antispam-Message-Info: bip8wRgwXg97Yoiavm77GPG+HAEVaASdA4+fCvfHGH3SZdQ7m7nIHY/+GQLxKPhxDKcls6fZaEq35m0kdunY0UGlHe6wy/oitDmyKfnttopiVShUte/TLJssxRBzfT7cGc3cE+/tvr7cg1m6HNnyWPAtXJa9v78dTmhpVCCESVNYwg2n/Ikp2I1LZ1zZqMkYhu+x6Iw1GP5dRjeoVOlXlreR+/g5XryEa98wi4IGeodGcLoKBtP3FjG8fXUBZWoyitHCxD2LiLz40nGYqhS7MXhi7dmgNhdYhIqkHVlCbcoHdelIKaA465EgFlDsctIkx+itiH2aeKdWDZY0UoADU3rob8Y8w9UMCcYpOTC4HR9jZ2Qkdxwp25ZiKoU18uTrm9r5GmMTLROy4VAkhC7Ix0gEuqK8ClQTQ8/V0xJboD8u5nDzGHsOa3Nuv3kCM4pJ+eR000VbDVFMfJFJXmKZ4Nd8d5FmHF4QFwE90l7aWbcAACQDvoecJag7Onk7w7vvAQYffNyrudZv6C7mmWv4u4yS5BKfV74itgfQI7iyBqa6/RIwepL2OyOglM+ZH8ooZzb8uBm/eEGj/EnPbXLNeRoe+ue9k/RETou4+NxYGdPq1NtEF5osf6bO0IxzyfkVZXDG/gIeMwHQG4x5laaZ1KorQFWHK3JOUdRRyeYM+VHPpS926Lm/kFYAMYwugGUE9aEl4uG8pKR6PFt3j31XZg== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(36860700016)(376014)(1800799024)(23010399003)(82310400026)(56012099006)(10067099003)(6133799003)(22082099003)(5023799004)(11063799006)(18002099003)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: eQN4O4uxG85uVnHVSdLxkJ2VwfnVEhuz86O49wgcNWRw7XeX4LMVV4KWU7YxWP0ctGSwIk0WaniTk89MvXeYJYcz+Rsac/rVFJUn4g3tPvJEd8xVdvvePiQaEvLfBp4KWMI2udlMIgkEaqWeSjAdvU+r6iMT5ML1Je7xm4J5C5Xw+NIXVehuV3FRpFEbDIhB4HCU7RjkRfTwxnltzOQ1HhXAE1uSTf72ahNS082ZnAqD1QnG4x/ZF7CyP2V+pcKFBRB23eEEaSwMYF6TEhhE3GSQ9MpYL2VzeAXMq12nijHbWln4o+z2u7DqGqtcBL+NImgkHtn5ioGdeJOmb6dHm7KB5tUVZb3nCIRdLbHA2qqvYgqN8+Y+BKHuhcK6K1mk0ZdAKV3ttr5RK6hLATOGVnGnPamR0ECm4Ru1yz9O5ucqJ7KLoooaIS0xIT4gFAFa X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:36:47.4553 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 20875495-62c6-44c0-9d7a-08df03c28391 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBF.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: IA5PR12MB999302 Content-Type: text/plain; charset="utf-8" Allow userspace to set the feature in kvm_sev_init.vmsa_features. KVM still needs to set the flag for backwards compatibility, but disallowing SVM_SEV_FEAT_SNP_ACTIVE for an SNP guest is "bizarre." Suggested-by: Sean Christopherson Cc: Borislav Petkov (AMD) Link: https://lore.kernel.org/kvm/aaWog_UjW-M3412C@google.com/ Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 --- arch/x86/include/asm/svm.h | 3 ++- arch/x86/kvm/svm/sev.c | 8 ++++++-- tools/testing/selftests/kvm/x86/sev_init2_tests.c | 4 +++- 3 files changed, 11 insertions(+), 4 deletions(-) diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h index a206a0ed2c58..facabba26a91 100644 --- a/arch/x86/include/asm/svm.h +++ b/arch/x86/include/asm/svm.h @@ -311,7 +311,8 @@ static_assert((X2AVIC_4K_MAX_PHYSICAL_ID & AVIC_PHYSICA= L_MAX_INDEX_MASK) =3D=3D X2AV #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) =20 -#define SVM_SEV_FEAT_SNP_ONLY_MASK (SVM_SEV_FEAT_SECURE_TSC) +#define SVM_SEV_FEAT_SNP_ONLY_MASK (SVM_SEV_FEAT_SNP_ACTIVE | \ + SVM_SEV_FEAT_SECURE_TSC) =20 #define VMCB_ALLOWED_SEV_FEATURES_VALID BIT_ULL(63) =20 diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 3c9483733865..6cfb7496415e 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -3257,8 +3257,12 @@ void __init sev_hardware_setup(void) cpu_feature_enabled(X86_FEATURE_NO_NESTED_DATA_BP)) sev_supported_vmsa_features |=3D SVM_SEV_FEAT_DEBUG_SWAP; =20 - if (sev_snp_enabled && tsc_khz && cpu_feature_enabled(X86_FEATURE_SNP_SEC= URE_TSC)) - sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SECURE_TSC; + if (sev_snp_enabled) { + sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SNP_ACTIVE; + + if (tsc_khz && cpu_feature_enabled(X86_FEATURE_SNP_SECURE_TSC)) + sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SECURE_TSC; + } } =20 void sev_hardware_unsetup(void) diff --git a/tools/testing/selftests/kvm/x86/sev_init2_tests.c b/tools/test= ing/selftests/kvm/x86/sev_init2_tests.c index 8269f146b1f5..d70482e07141 100644 --- a/tools/testing/selftests/kvm/x86/sev_init2_tests.c +++ b/tools/testing/selftests/kvm/x86/sev_init2_tests.c @@ -13,11 +13,13 @@ #include "svm_util.h" #include "kselftest.h" =20 +#define SVM_SEV_FEAT_SNP_ACTIVE BIT_ULL(0) #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) =20 /* Features valid only for SNP guests, rejected for SEV-ES and below. */ -#define SNP_ONLY_FEATURES (SVM_SEV_FEAT_SECURE_TSC) +#define SNP_ONLY_FEATURES (SVM_SEV_FEAT_SNP_ACTIVE | \ + SVM_SEV_FEAT_SECURE_TSC) =20 /* * Some features may have hidden dependencies, or may only work --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from PH7PR06CU001.outbound.protection.outlook.com (mail-westus3azon11010009.outbound.protection.outlook.com [52.101.201.9]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CFF2B40C5C0; Wed, 26 Aug 2026 22:37:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.201.9 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783829; cv=fail; b=VNoQhVSx8yEltcTtVw1W5hKr4v46Nswe5nsQ+DdcP1H0/52lAOPoiDyylbyJQIrQrmIM6CE1I6Anh2/8cT18/s55edEcCSITOm3Z7bSJeGMux89iix8pTOhaR0SnpGIYbZaiPmfAeK3XPPtQ9FHA2zcG22R5YRL969ZE6LU2XPQ= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783829; c=relaxed/simple; bh=Dm9IUn+69u8PYBpjkKZi/pGOncuJ1Md9ZP9WaYsFMzY=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=CDU5yII9wvJ+Voc8Yfo+rowcanKhNaQ8oo2CIBQx6+zg98rO8Wv1VNpdSDxGDFmQqNMH2vJblnrnj/gSIkAt97kBzsLSS0YpPWcRUYPqc2B47CFnUqrdHRl3vijHUd8lR1j7JigKmzu4o44yz6vExlvUMfCt4cPlK3/F0z9ju/g= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=Syiyhjjl; arc=fail smtp.client-ip=52.101.201.9 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="Syiyhjjl" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=E1z3UN0wDycltHzMlLnpuWH6aElkBQDALfWmqB76hMhUUnrTyZXVmLY7BVEjppOAdeYl68ezvk39rmP7t7Cw5zPlpqknjYSz3tz0VHfCQ3fYYmlILfbfqdqpZsjrzy+C86Cv+k+kh3Z/DaUwydZV3cLrEE0CuWQaI/y0A1eADBuZ1VZW+4wNB9ShX05QNCLWr6H0qQNQ7ujiPLo3TDyo5DuGDY8rZCT0Y7R/RI4c4MtH+m5D5mHjP+V/4NV5WzOQEvxD1vu2VhSART3wWnijr/jdgKsgwEsZBkp9vK1KQcvSUeuYgWG2EvDAnvW8ejRUBr6EPwUd6TtYyTb/NUjoMw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=s84QPhetN/pr1206/GW+mpXaSGe7qTDGkkQ+USrIh8k=; b=pGu2HCkajor28PirfK84RpL5HOzJ9dALFSbBdgqiYoHbvpYh7+bjsg9jTpauNMmP6Tty3VufEOq4ule8//SidZmRAUQGAPC85fuAFaqUFZ5knf3ZEDWnLu8NLqdyW8TQFUKa8Ucy4pwIH4YjzYZ8dtWUZS+jWjre6kShVajGYYN7DCU1KyDFCyLFwEh4SHeG/pIOchyEorFctvwKBiK0WUIssJSabHY3+7OypcqtmgyqiCl0savf3/OH2HxfbCVCpIKR+oKRJMuVgGRnoSA5396NKsiDxS2UzPuqie/tBtIt50c59uGfOZy9VgbGbON04SQ0MEC3v3c0Ch/tUFdk/w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=s84QPhetN/pr1206/GW+mpXaSGe7qTDGkkQ+USrIh8k=; b=Syiyhjjlo5OtG0VDJFrJi7EmveZhxA5NA6AflO/n+PZ95mB/Jvih2ex53MogTtsqa9/ZwXcakLw5k9aVmQk1CMrS604ciLA5uuur3Yv1pmGb27prFtiBdpTeg5wlUyFmhYX1H2eFkah4Ks+7UKYYyptbOlyXD1wnSdbb/KMwh2Y= Received: from MN2PR11CA0004.namprd11.prod.outlook.com (2603:10b6:208:23b::9) by DS0PR12MB7873.namprd12.prod.outlook.com (2603:10b6:8:142::15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.7; Wed, 26 Aug 2026 22:36:59 +0000 Received: from BN3PEPF00022BBB.namprd04.prod.outlook.com (2603:10b6:208:23b:cafe::4d) by MN2PR11CA0004.outlook.office365.com (2603:10b6:208:23b::9) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.360.8 via Frontend Transport; Wed, 26 Aug 2026 22:36:59 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBB.mail.protection.outlook.com (10.167.248.122) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:36:59 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:36:57 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 7/8] KVM: SEV: Add support for IBPB-on-Entry Date: Wed, 26 Aug 2026 17:35:09 -0500 Message-ID: <20260826223510.3669875-8-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBB:EE_|DS0PR12MB7873:EE_ X-MS-Office365-Filtering-Correlation-Id: 8e3b7632-6408-4e26-f9dc-08df03c28abf X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|36860700016|23010399003|376014|82310400026|10067099003|5023799004|11063799006|56012099006|6133799003|22082099003|18002099003|13003099007; X-Microsoft-Antispam-Message-Info: AnPCnBwB8ByEyUdEqikcrc7Qd3a7AOvIPw8YKgwA1sXB4NyWXgz8wpQ1pH5plA8N+G92SjZ7rdQ5Bdx2wlm9VjitTbCXLFvOAuXFpUwyfZyNhI+myOvlVqPUd+vwHwc4CbzTbtQwH61SI5iFSQTgxK1SD8bzsKmicwladAfvA58lRtNncrvfFMTZJYVskk/DiOigGa1kFUsX26bEpJJJS5qklSVemfV/cJZrH7pd2ba9Qi3ApZJ+CX7+FPc4bZuBo4dl+tWyPUar591RgEJpT3EcSRXKRrQa2a0gVLRPLYUP7L5iM1E7V2YTXN4e3dH4jOKwPq4XxnGf79glhaQkGE/hU/Ex5vKhPvN5XVKK+2ytkol2/FxeMP9I/n+mHiChRpvG4PRxx6AxQZr7v/a7wpaJLJlbgwY/gthZuCEbze/sZWzPGCFGxW/P0uDrS2/uB0wtHkjf7LAwooeIuFO2Lkf8obhBz8GVvlnwh+oMgo74gi2HoBVE6wM5CGZuRjGunqmlZV6UZQoZ03zZMzLFzefTgSplDPyz2x8jfejogEnKZN1VJ97wC9x8ep49DD99/1b3lcKApWTAfsb74q/UjYOS1NEybUlfPGDevaaML7yZReLyTEA7FLKpl1mRvnlgom09l1WBNTjCSVy20dg0tBm5zrrrRp1cwKXFcgCtLHd4B5npaUszk95g/ICmB6p4jOboN2+pMsuNJt1URCu/nA== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(1800799024)(36860700016)(23010399003)(376014)(82310400026)(10067099003)(5023799004)(11063799006)(56012099006)(6133799003)(22082099003)(18002099003)(13003099007);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: VhbDgCQRAbO8UApbItpMcOp1MPIewxaSHOOyUnTpTSntU9huPkeD1XlRlJVWcWaPX8l2CghJjrO18mkxtc7yrYQqvD2a1g8YJ3mGdKUR/XeklPBminEu2McjYBPRalSLIHOmiRlWDMQ73AHkssEwW4/fFQ9UgGSyMi9vRajU5yz40W2IMy8scaIU6PyyXAQ4BM5+/0KIQ+LigIkUCB3RvrnvrSFePBGapfxJf7ZDmdSfINg/RKUdt9Mpdf/zloR4yMApgyTiHli4F3R6PwIindVvPQqpFmKwzELtNAdPxdJt+hht2vG2wDlzDHy85eXkg38DmGAaH3CR99cjwpkifg+tvbn4AkMduL+FEkxGuIxYkAPljjWOX3BfPchTn4R2+T5+zLuh+WWvFxJJ5SPvRvXdKh8Spl/nTOrUczDRKIcvAEyJeVO+Lw0voSOsdPJD X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:36:59.4530 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 8e3b7632-6408-4e26-f9dc-08df03c28abf X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBB.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR12MB7873 Content-Type: text/plain; charset="utf-8" AMD EPYC 5th generation and above processors support IBPB-on-Entry for SNP guests, while 3rd and 4th generation processors can via microcode patches. By invoking an Indirect Branch Prediction Barrier (IBPB) on VMRUN, old indirect branch predictions are prevented from influencing indirect branches within the guest. SNP guests may choose to enable IBPB-on-Entry by setting SEV_FEATURES bit 21 (IbpbOnEntry). Host support for IBPB on Entry is indicated by CPUID Fn8000_001F_EAX[IbpbOnEntry], bit 31. If supported, indicate support for IBPB on Entry in sev_supported_vmsa_features bit 21 (IbpbOnEntry). Also add SVM_SEV_FEAT_IBPB_ON_ENTRY to the sev_init2 selftest's SNP_ONLY_FEATURES and KNOWN_FEATURES to validate it is accepted for SNP guests and rejected for SEV-ES. For more info, refer to page 615, Section 15.36.17 "Side-Channel Protection", AMD64 Architecture Programmer's Manual Volume 2: System Programming Part 2, Pub. 24593 Rev. 3.42 - March 2024 (see Link). Link: https://bugzilla.kernel.org/attachment.cgi?id=3D306250 Cc: Sean Christopherson Cc: Borislav Petkov (AMD) Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 --- arch/x86/include/asm/cpufeatures.h | 1 + arch/x86/include/asm/svm.h | 4 +++- arch/x86/kvm/svm/sev.c | 3 +++ tools/arch/x86/include/asm/cpufeatures.h | 1 + tools/testing/selftests/kvm/x86/sev_init2_tests.c | 4 +++- 5 files changed, 11 insertions(+), 2 deletions(-) diff --git a/arch/x86/include/asm/cpufeatures.h b/arch/x86/include/asm/cpuf= eatures.h index f70ee74b5f92..3aad2b53f59b 100644 --- a/arch/x86/include/asm/cpufeatures.h +++ b/arch/x86/include/asm/cpufeatures.h @@ -472,6 +472,7 @@ #define X86_FEATURE_ALLOWED_SEV_FEATURES (19*32+27) /* Allowed SEV Feature= s */ #define X86_FEATURE_SVSM (19*32+28) /* "svsm" SVSM present */ #define X86_FEATURE_HV_INUSE_WR_ALLOWED (19*32+30) /* Allow Write to in-us= e hypervisor-owned pages */ +#define X86_FEATURE_SNP_IBPB_ON_ENTRY (19*32+31) /* SEV-SNP IBPB on VM Ent= ry */ =20 /* AMD-defined Extended Feature 2 EAX, CPUID level 0x80000021 (EAX), word = 20 */ #define X86_FEATURE_NO_NESTED_DATA_BP (20*32+ 0) /* No Nested Data Breakpo= ints */ diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h index facabba26a91..9d8107824d10 100644 --- a/arch/x86/include/asm/svm.h +++ b/arch/x86/include/asm/svm.h @@ -310,9 +310,11 @@ static_assert((X2AVIC_4K_MAX_PHYSICAL_ID & AVIC_PHYSIC= AL_MAX_INDEX_MASK) =3D=3D X2AV #define SVM_SEV_FEAT_ALTERNATE_INJECTION BIT_ULL(4) #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) +#define SVM_SEV_FEAT_IBPB_ON_ENTRY BIT_ULL(21) =20 #define SVM_SEV_FEAT_SNP_ONLY_MASK (SVM_SEV_FEAT_SNP_ACTIVE | \ - SVM_SEV_FEAT_SECURE_TSC) + SVM_SEV_FEAT_SECURE_TSC | \ + SVM_SEV_FEAT_IBPB_ON_ENTRY) =20 #define VMCB_ALLOWED_SEV_FEATURES_VALID BIT_ULL(63) =20 diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 6cfb7496415e..20a761cf3491 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -3262,6 +3262,9 @@ void __init sev_hardware_setup(void) =20 if (tsc_khz && cpu_feature_enabled(X86_FEATURE_SNP_SECURE_TSC)) sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SECURE_TSC; + + if (cpu_feature_enabled(X86_FEATURE_SNP_IBPB_ON_ENTRY)) + sev_supported_vmsa_features |=3D SVM_SEV_FEAT_IBPB_ON_ENTRY; } } =20 diff --git a/tools/arch/x86/include/asm/cpufeatures.h b/tools/arch/x86/incl= ude/asm/cpufeatures.h index 6547c0aee45b..634cd09366da 100644 --- a/tools/arch/x86/include/asm/cpufeatures.h +++ b/tools/arch/x86/include/asm/cpufeatures.h @@ -460,6 +460,7 @@ #define X86_FEATURE_ALLOWED_SEV_FEATURES (19*32+27) /* Allowed SEV Feature= s */ #define X86_FEATURE_SVSM (19*32+28) /* "svsm" SVSM present */ #define X86_FEATURE_HV_INUSE_WR_ALLOWED (19*32+30) /* Allow Write to in-us= e hypervisor-owned pages */ +#define X86_FEATURE_SNP_IBPB_ON_ENTRY (19*32+31) /* SEV-SNP IBPB on VM Ent= ry */ =20 /* AMD-defined Extended Feature 2 EAX, CPUID level 0x80000021 (EAX), word = 20 */ #define X86_FEATURE_NO_NESTED_DATA_BP (20*32+ 0) /* No Nested Data Breakpo= ints */ diff --git a/tools/testing/selftests/kvm/x86/sev_init2_tests.c b/tools/test= ing/selftests/kvm/x86/sev_init2_tests.c index d70482e07141..f2f97dca3935 100644 --- a/tools/testing/selftests/kvm/x86/sev_init2_tests.c +++ b/tools/testing/selftests/kvm/x86/sev_init2_tests.c @@ -16,10 +16,12 @@ #define SVM_SEV_FEAT_SNP_ACTIVE BIT_ULL(0) #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) +#define SVM_SEV_FEAT_IBPB_ON_ENTRY BIT_ULL(21) =20 /* Features valid only for SNP guests, rejected for SEV-ES and below. */ #define SNP_ONLY_FEATURES (SVM_SEV_FEAT_SNP_ACTIVE | \ - SVM_SEV_FEAT_SECURE_TSC) + SVM_SEV_FEAT_SECURE_TSC | \ + SVM_SEV_FEAT_IBPB_ON_ENTRY) =20 /* * Some features may have hidden dependencies, or may only work --=20 2.43.0 From nobody Mon Sep 28 04:08:10 2026 Received: from PH7PR06CU001.outbound.protection.outlook.com (mail-westus3azon11010002.outbound.protection.outlook.com [52.101.201.2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4D6B830F526; Wed, 26 Aug 2026 22:37:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.201.2 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783854; cv=fail; b=LPlFi/PcsFXAJeP8yuV4+DHzNU3xI7elWQw/0np169KErOWBNZkGcDqDoLdD47dLOGxD42qKR3HnSs82WlT+3p0DgcYv3noTn6MV3pySFBzllJqg9RTNcIJqbZfiBGbavZhlieb0+chMvojLYw4DLWMIP/3PfvlIihNDvlKTXRw= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787783854; c=relaxed/simple; bh=asezm175rtd01o9eZITQjJI7P91atktw+cHQyRAyrs4=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Fqfbtreqm/5xX3EOd5L0CvOvR6VP4e5BVAVSG9x9hsVACt7BfdOoFm0KRFuQ2Brgoc5rRb9OHM7C45bGqqXy8oPZ72jRx6kr74NcomWNszg+jePCVNI56RqmO7ez41JtfhiuH8XKOw8p/tec/BZCBgSb+fBuZ8yYsaO2VINqHc8= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com; spf=fail smtp.mailfrom=amd.com; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b=0N0AMXJq; arc=fail smtp.client-ip=52.101.201.2 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=amd.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=amd.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=amd.com header.i=@amd.com header.b="0N0AMXJq" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=p/BC3CaVlSmCTfS+B9DUfq/ZmOPtnEHBCCxCcn/nenC+qz5C62d4WxJ58o3hZR25oHxmibEE10eWohNUqIzfPeQVFv0x3zCC8H7Fj5qu3AfqRLWG2O5EbKJlUe8J1vDzQJq9uPxZX8yaAzKfzgt1aOYtnwfWb4b3DOfA+Rc0wrKf0cjB8Sr8nRh30+xg78SDkvjGUOHFcK6IMb4qIBpYIHVFRFlnstDe5x1f+Fc3cPj2zWit9IRthu7rDpuKKojJ1tA1AtEeRaBormvPg/XUWEN58Say/uykpswAB8pcdYiUDJz3OfNxDbUAzoeBCevx1uYTwNFGRGMZpAMH7FzhNA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Cy3YV3tMRp0D9ZfksLXoCCJQ9M3ffgSV5ZXq58HbhKc=; b=vfDpM6Nxx00ruMcvOVq9hiFAtbLuWf4amT3Za1RkyrgU0ocX1/LKSOolYsh2EUietQnI03YTndenZjOUIjUm1YRlO4RDEEvj1tS6GCliACWbcQbkL84APeChjx8lcOMT+u5S5e73p4SJPd2bqQEJd+sxhdLqUSLZtCWPrTOQL0MMdHm1jyssernhBOqEKRlanHPPB+aAnQCeuvW6dvnL1HN/Mna/dZ8cknmFNVzVycOrkRuNMbEPipREmsI0hvvxjzu2cDjL/zdAxwje92rIU/tlBVjVn19jbkhn19BPdPYf9uZf+20hcZak1ZOMkRaBm1LxCghHpUlzvwUMqShl4g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=softfail (sender ip is 149.199.90.133) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=fail (p=quarantine sp=quarantine pct=100) action=quarantine header.from=amd.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Cy3YV3tMRp0D9ZfksLXoCCJQ9M3ffgSV5ZXq58HbhKc=; b=0N0AMXJqY7v9TcmDdt/VemhsrEJG5ueyHNV7VqzK1LvmfrTsqbjpSjdgTMYN1tH9nGyrQnbII1ANRvd5QGUPupBy5SiO61GAj19MfUwKRSMogxqdUgdwFpurFCYv/A9a82HOBydG0BDa3FQyRq7VarB/c+z/P2wiMM+3fhixbJU= Received: from MN2PR22CA0017.namprd22.prod.outlook.com (2603:10b6:208:238::22) by SA5PPF7D510B798.namprd12.prod.outlook.com (2603:10b6:80f:fc04::8d0) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.6; Wed, 26 Aug 2026 22:37:11 +0000 Received: from BN3PEPF00022BBA.namprd04.prod.outlook.com (2603:10b6:208:238:cafe::c) by MN2PR22CA0017.outlook.office365.com (2603:10b6:208:238::22) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.339.12 via Frontend Transport; Wed, 26 Aug 2026 22:37:10 +0000 X-MS-Exchange-Authentication-Results: spf=softfail (sender IP is 149.199.90.133) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=fail action=quarantine header.from=amd.com; Received-SPF: SoftFail (protection.outlook.com: domain of transitioning amd.com discourages use of 149.199.90.133 as permitted sender) Received: from satlexmb07.amd.com (149.199.90.133) by BN3PEPF00022BBA.mail.protection.outlook.com (10.167.248.116) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.360.3 via Frontend Transport; Wed, 26 Aug 2026 22:37:10 +0000 Received: from dryer.amd.com (10.180.168.240) by satlexmb07.amd.com (10.181.42.216) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.45; Wed, 26 Aug 2026 17:37:09 -0500 From: Kim Phillips To: , , , CC: Sean Christopherson , Paolo Bonzini , K Prateek Nayak , "Nikunj A Dadhania" , Tom Lendacky , "Michael Roth" , Borislav Petkov , Borislav Petkov , Naveen Rao , David Kaplan , Pawan Gupta , "Dave Hansen" , Kim Phillips , Nathan Fontenot Subject: [PATCH v5 8/8] KVM: SEV: Add support for SNP BTB Isolation Date: Wed, 26 Aug 2026 17:35:10 -0500 Message-ID: <20260826223510.3669875-9-kim.phillips@amd.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260826223510.3669875-1-kim.phillips@amd.com> References: <20260826223510.3669875-1-kim.phillips@amd.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: satlexmb07.amd.com (10.181.42.216) To satlexmb07.amd.com (10.181.42.216) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF00022BBA:EE_|SA5PPF7D510B798:EE_ X-MS-Office365-Filtering-Correlation-Id: 42cb55a5-6f07-463d-99c0-08df03c2916c X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|36860700016|376014|1800799024|23010399003|82310400026|10067099003|56012099006|5023799004|11063799006|6133799003|3023799007|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: owjGQTRPl18prqow93c9lLw3IeUc2ykmYzQuKZti8GSgGs6rHb5oUVnH0OyaVuQ+k32LFYUjE1FzOw+GuyLNud5Tm4Ka5l2kkqr3zj/nh4cxoVGfXgi01vHv8xfvc641srRBVRScBK+CcOGIYS5tsYqpEyZFoUDOtX9XeuK/qwoM6JIN3WDCpvHnwL4Al1R+TzbN/a+UqJ11PwJxFrtnVDTslwYE0ukGZsllBvRxAvokKC3Zr7yM07ZL8CWUs7sDp9T2PmzmkRksVR/gPK568yv8UbzqAOLJ8tt6eHrtqGvxN1S+dBIwnGnQtCJ4rUKt7teRBTMDfO+DpZTkSYWlFhSShj52PeQnNkWyXnU9buBQ3tZzltwkALZDLgGRqRNMxHoWIE/6uB39BcyKK2claIVWSmyN35F/qthfb08tQuDuw3YCLTaWJUS7wsk0PQlnl5COeagRUXpCmI46viXmPo/S9biw9YlsteO+5fJIP3g5D1GqcL97dX4Bkha+uRO/e6Jqgz/qT5/Om7QdGzhHoH9biTR8yYEfNCXbJg3IWLNfOmR20AQuMtiIF94qpdDCCGOnVYamXLaKERzKlaJcPfKg9FPr8Z6+zVFCyoPhhHcISwbWj64ikNyZSo9B0RwCKz2iX9B92WM4qJQb3apuYQ== X-Forefront-Antispam-Report: CIP:149.199.90.133;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:satlexmb07.amd.com;PTR:unknown-90-133.xilinx.com;CAT:NONE;SFS:(13230040)(36860700016)(376014)(1800799024)(23010399003)(82310400026)(10067099003)(56012099006)(5023799004)(11063799006)(6133799003)(3023799007)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: 0l1i/xHntxIXJYVqc8AWVGpimRD8nft91oSiiDbVXm3Q7i/6pibFhDNtoM21/2ZKZeRt9JY96CfzMSJFKf6QZ5dEOpa119FUdnLV7eVTD7Ug5jSb0990fOMvPfY6vJZUe+wLdq/L0aAv6+PtuW9qP/NnpUPkAusz09qGdeZZ7XrCsogEtJSTaE9sLjLoC8f/f/Ov4cYW8gKlWLXgbI66Qa/kWFOk7wDZJQPgnEDPqcYjPhHkA9CZFTqgEEsQuPGhlDbS9d81arODQHGy5CkelWG+Yvkutluiux6Knfsp1wjZqtHHuUgAa+BqZp5/YmvzentiK+oL5Mt30TRQ+eN5cHHgXtU/jGpUquD+DtFZQdE0EhcJEd0Md6WCdvw3j1sgjFAGfyreCf37ln2+Ixm7uBx7fbswGDRfshHx5wqqoN7y1RoAw0PygRvRNvgPQwFH X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 26 Aug 2026 22:37:10.6482 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 42cb55a5-6f07-463d-99c0-08df03c2916c X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[149.199.90.133];Helo=[satlexmb07.amd.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF00022BBA.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA5PPF7D510B798 Content-Type: text/plain; charset="utf-8" Advertise support for BTB Isolation via SEV_VMSA_FEATURES when SNP is enabled. BTB Isolation is an optional feature that can be enabled by the guest to ensure its guest Branch Target Buffers (BTBs) are not affected by any context outside that guest. SNP-active guests may choose to enable the Branch Target Buffer Isolation mode through SEV_FEATURES bit 7 (BTBIsolation). Unlike the sibling features advertised here (Secure TSC, IBPB-on-Entry), BTB Isolation is advertised unconditionally. This is deliberate, not an oversight: the AMD64 APM (Vol. 2, Section 15.36.17 "Side-Channel Protection") defines BTB Isolation as architecturally present on every SEV-SNP-capable processor. There is therefore no host enumeration bit for it (no CPUID leaf or MSR capability), by design -- unlike IBPB-on-Entry, whose host support is enumerated via CPUID Fn8000_001F[IbpbOnEntry] bit 31 precisely because it is not universal. A per-feature host gate is thus neither possible nor meaningful; if SNP is supported, BTB Isolation is present. Nor does the guest have to take the host's word for it. SEV_FEATURES is written into the VMSA by sev_es_sync_vmsa() and measured by SNP_LAUNCH_UPDATE with SNP_PAGE_TYPE_VMSA, so bit 7 is covered by the launch measurement and appears in the attestation report. At runtime the guest can additionally read the active state from SEV_STATUS bit 9 (MSR_AMD64_SNP_BTB_ISOLATION, dumped as "BTBIsol" by sev_status_feat_names[] in arch/x86/coco/sev/core.c). A guest requiring BTB Isolation can therefore confirm it is active rather than trusting what the host advertised. Also add SVM_SEV_FEAT_BTB_ISOLATION to the sev_init2 selftest's SNP_ONLY_FEATURES and KNOWN_FEATURES to validate it is accepted for SNP guests and rejected for SEV-ES. For more info, refer to page 615, Section 15.36.17 "Side-Channel Protection", AMD64 Architecture Programmer's Manual Volume 2: System Programming Part 2, Pub. 24593 Rev. 3.42 - March 2024 (see Link). Link: https://bugzilla.kernel.org/attachment.cgi?id=3D306250 Cc: Sean Christopherson Cc: Borislav Petkov (AMD) Signed-off-by: Kim Phillips Assisted-by: ClaudeCode:claude-opus-4-7 Reviewed-by: Tom Lendacky --- arch/x86/include/asm/svm.h | 2 ++ arch/x86/kvm/svm/sev.c | 8 ++++++++ tools/testing/selftests/kvm/x86/sev_init2_tests.c | 2 ++ 3 files changed, 12 insertions(+) diff --git a/arch/x86/include/asm/svm.h b/arch/x86/include/asm/svm.h index 9d8107824d10..0da2234b71c6 100644 --- a/arch/x86/include/asm/svm.h +++ b/arch/x86/include/asm/svm.h @@ -309,10 +309,12 @@ static_assert((X2AVIC_4K_MAX_PHYSICAL_ID & AVIC_PHYSI= CAL_MAX_INDEX_MASK) =3D=3D X2AV #define SVM_SEV_FEAT_RESTRICTED_INJECTION BIT_ULL(3) #define SVM_SEV_FEAT_ALTERNATE_INJECTION BIT_ULL(4) #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) +#define SVM_SEV_FEAT_BTB_ISOLATION BIT_ULL(7) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) #define SVM_SEV_FEAT_IBPB_ON_ENTRY BIT_ULL(21) =20 #define SVM_SEV_FEAT_SNP_ONLY_MASK (SVM_SEV_FEAT_SNP_ACTIVE | \ + SVM_SEV_FEAT_BTB_ISOLATION | \ SVM_SEV_FEAT_SECURE_TSC | \ SVM_SEV_FEAT_IBPB_ON_ENTRY) =20 diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 20a761cf3491..53cc6d043883 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -3260,6 +3260,14 @@ void __init sev_hardware_setup(void) if (sev_snp_enabled) { sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SNP_ACTIVE; =20 + /* + * Unlike Secure TSC and IBPB-on-Entry below, BTB Isolation has + * no host enumeration bit to gate on: the APM defines it as + * architecturally present on every SEV-SNP-capable processor. + * If SNP is supported, BTB Isolation is available. + */ + sev_supported_vmsa_features |=3D SVM_SEV_FEAT_BTB_ISOLATION; + if (tsc_khz && cpu_feature_enabled(X86_FEATURE_SNP_SECURE_TSC)) sev_supported_vmsa_features |=3D SVM_SEV_FEAT_SECURE_TSC; =20 diff --git a/tools/testing/selftests/kvm/x86/sev_init2_tests.c b/tools/test= ing/selftests/kvm/x86/sev_init2_tests.c index f2f97dca3935..3f592e245a66 100644 --- a/tools/testing/selftests/kvm/x86/sev_init2_tests.c +++ b/tools/testing/selftests/kvm/x86/sev_init2_tests.c @@ -15,11 +15,13 @@ =20 #define SVM_SEV_FEAT_SNP_ACTIVE BIT_ULL(0) #define SVM_SEV_FEAT_DEBUG_SWAP BIT_ULL(5) +#define SVM_SEV_FEAT_BTB_ISOLATION BIT_ULL(7) #define SVM_SEV_FEAT_SECURE_TSC BIT_ULL(9) #define SVM_SEV_FEAT_IBPB_ON_ENTRY BIT_ULL(21) =20 /* Features valid only for SNP guests, rejected for SEV-ES and below. */ #define SNP_ONLY_FEATURES (SVM_SEV_FEAT_SNP_ACTIVE | \ + SVM_SEV_FEAT_BTB_ISOLATION | \ SVM_SEV_FEAT_SECURE_TSC | \ SVM_SEV_FEAT_IBPB_ON_ENTRY) =20 --=20 2.43.0