From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752539AbdJTChR (ORCPT ); Thu, 19 Oct 2017 22:37:17 -0400 Received: from mail-bl2nam02on0077.outbound.protection.outlook.com ([104.47.38.77]:40268 "EHLO NAM02-BL2-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752335AbdJTCf4 (ORCPT ); Thu, 19 Oct 2017 22:35:56 -0400 Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=brijesh.singh@amd.com; From: Brijesh Singh To: kvm@vger.kernel.org Cc: bp@alien8.de, Brijesh Singh , Thomas Gleixner , Ingo Molnar , "H. Peter Anvin" , Paolo Bonzini , =?UTF-8?q?Radim=20Kr=C4=8Dm=C3=A1=C5=99?= , Joerg Roedel , Borislav Petkov , Tom Lendacky , x86@kernel.org, linux-kernel@vger.kernel.org Subject: [Part2 PATCH v6 35/38] KVM: SVM: Pin guest memory when SEV is active Date: Thu, 19 Oct 2017 21:34:10 -0500 Message-Id: <20171020023413.122280-36-brijesh.singh@amd.com> X-Mailer: git-send-email 2.9.5 In-Reply-To: <20171020023413.122280-1-brijesh.singh@amd.com> References: <20171020023413.122280-1-brijesh.singh@amd.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Originating-IP: [165.204.78.1] X-ClientProxiedBy: MWHPR1701CA0020.namprd17.prod.outlook.com (10.172.58.30) To SN1PR12MB0157.namprd12.prod.outlook.com (10.162.3.144) X-MS-PublicTrafficType: Email X-MS-Office365-Filtering-Correlation-Id: 0c71e891-3cce-4442-45dc-08d5176343fb X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(48565401081)(4534020)(4602075)(4627075)(201703031133081)(201702281549075)(2017052603199);SRVR:SN1PR12MB0157; X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0157;3:HvV5HtygORQuTMmg4hBEaKxaUIocVZmPbiM7txUtmXEsuYgLDXEtMpEmkZ2zAiOOEuLU0ZvEiq/gbiFcMP+infYmGofsEn+omC9+PIMAnQ/KnmXKm8xMqwIDZqaixhtKb8GLI1lgj5TO5udNBTaUdsancHYTcqKAdLY6DcMRY4a/hQoyMREN6bc+ZUAeVQFmFztyYqjdDkiyVhwMtpLrXSEe2J2ZgzySUm0jWEwC5NOdM7xyyhptdE6xMja1dyzE;25:No9YHEwaQRlZRf4NVojUBmhIGT0ar299eRp4u3yxM0UNcvz+rTXyJMqI3AGBrW0HFDIsGKoSLsJjDtyd3QDZ6fuJmDL4TwXIe9jR0iKbCyV9J5ZYd6Yt3woEWEPHuSNF4xkTzz6fRVIlfErPum0FOxCGWFm8EkyXqDLtOqI5iqlg8yhhMoS9DqYVP2C3HcxpWPtLHVzRAMQrkl+lSgUC9ybAUgqJYSZ6rethfBVNmcA2lO6n+DKeqU4+BOhSmBz7joBiyvitZqpch0yda6VrTMHelCXXjxmNVvP0HuI5XbAntZYIWdDgG0Ac14nm5xTaNUVHafHkxNJDghddTwKGAA==;31:tjUWYsXSh6ST8hikIiMC83X5h7ZwlmzIDjZmizPemfDmYgrx8ET6y11z7cMD7AqkEqC/cD6w3m4WkLmrfXZLBp0C+AYKZJxoY36EC3yTZ8VZzFoEkInId9qFNXsoQcf0dIlUvUfrWXZQ4HY0b9evXj9bPQmPxbNE3sXY5MUMdWUVFsnw/+ZCTToCDR9perxekjs8QpGb3+wOprgwAExyq4DEp+CIZcmuk4Y+mhFwTRw= X-MS-TrafficTypeDiagnostic: SN1PR12MB0157: X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0157;20:9cg4hfNh4XDcKTPgLSg6ALKd6RaH+8zpsrg2KrNiEULu+N23k/tNJkIuh7qb6QWxCn9k66LAo+3OAnXy48arBZkA3Jx76j1I2WSvtE7uGPXHfv3zDscTFR4eotqtFEJcfOb7SCuc0Y04/6M257/zNCRYHuFXyq2mE41h4ELSGRw/Y3SFD2RH8qjw8RrNWpUoZ6m7BoaIBbLzydT2ijI7DvGevhS5zNiwwxLFpcEUK1/Ve3em9uKu/v8w+U6L6Vt9XtymAEr3fPQC4gmuciRZx5njijkF2JIej8SaoPbRWSEC1Kh2oBuR7YLN1/SVBIfHfAnQ+WaKHARSkH1M8hz4sYjXq7qazaaTvEY0/ETL35+/Y9L6Z/6veFjGswejISuXIqQC/1KpzlLbVuCKLV6yhQXj4GPYxgQ4p3aOSDGeraUpxLPw0rulJL+zFJ9yf00Tw0aPEayNQNDwq9lKclzGIjnkS6v9p19AhtbhLOIcS8Dn7sLaysyYeoZHRcutSuor;4:mUB98TgtH3FTThM7u77eyTMvO2KGO9N4VzSyvuGJyAhsoQ9H3znmFpQR5ojjuGnBc2SPI+1Ocxt4wyNy35qNY3EQapPwir2ryqpmKqHBBhxbUzEX8/cGj7oTdcICDGnRbivIghvVUaplC+HVx9rVOpq65Hy7wgPx/d7UwGDtKKr2lH9TXHtzAApkOxP2OHTvx637VwFugzd9muCt+hbyydDVFMn7Wg/Mp0C57ZIihB+YZrc6UZ5Lh0xr6TXf73gPeVvFV9+P9W9LCtHZtlu1GmgLKmUdUkiw3qSYrh6j8LXDJ00q1k282e7vAbb4L7Yq+9t6GBx5KnMT92RBAdZ8dg== X-Exchange-Antispam-Report-Test: UriScan:(9452136761055)(767451399110); X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(6040450)(2401047)(8121501046)(5005006)(3231020)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(3002001)(6055026)(6041248)(20161123555025)(20161123564025)(20161123558100)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123560025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095);SRVR:SN1PR12MB0157;BCL:0;PCL:0;RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095);SRVR:SN1PR12MB0157; X-Forefront-PRVS: 0466CA5A45 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(6009001)(346002)(376002)(39860400002)(199003)(189002)(36756003)(7736002)(68736007)(50466002)(1076002)(478600001)(4326008)(16526018)(316002)(53936002)(6486002)(86362001)(305945005)(53416004)(54906003)(50226002)(2351001)(106356001)(101416001)(81166006)(105586002)(8676002)(2361001)(76176999)(2870700001)(2906002)(50986999)(6916009)(23676002)(66066001)(47776003)(6666003)(97736004)(6116002)(2950100002)(189998001)(8936002)(3846002)(33646002)(81156014)(7416002)(5660300001)(25786009);DIR:OUT;SFP:1101;SCL:1;SRVR:SN1PR12MB0157;H:ubuntu-010236106000.amd.com;FPR:;SPF:None;PTR:InfoNoRecords;A:1;MX:1;LANG:en; X-Microsoft-Exchange-Diagnostics: =?utf-8?B?MTtTTjFQUjEyTUIwMTU3OzIzOkJGZW1uNHp4SUdEM3FIZXY4RkhWSFprYnhK?= =?utf-8?B?elZSM3FTQlVNSjJtNlNqMmtUOWduYjlwSzgvM1lIZDdaUVo3b2M1d0ZzVVps?= =?utf-8?B?enRjOEtrbmhPOVI4Rko1aHl2b1JMRCtQekVqM0tKY0RBbUpFU3BXTloyTXhY?= =?utf-8?B?aGVBSXRoVUNkTVZxWXkvL0lIdUUwNkhWMDJyNDVPZDFXekhzbWpoemtmR09S?= =?utf-8?B?Vjdvb2RPclhMODhWTExsVzZyMkNva2lCa1RrV01tVVZ6c0czSVN5YStLOSta?= =?utf-8?B?L0RuaTFyWEduNFl4ajk1NThBZk94dFRYdnh4U0VxbWlzdERlRElJNmg1Q1dY?= =?utf-8?B?OGxUL1lUQmMxbE4veFNhWkVmamMrUHRPYkxzWHlNSTh6NjJ4VEtMTXlEVUVu?= =?utf-8?B?K09Oa2VXMnVqZDhFcXFpY0krYjJPWUdXQk5jbGVYV0F3cGQ2OHZZQURSUjZJ?= =?utf-8?B?SEFzUzM3ZXU4ZE1LeDFOc1phZmwxMmZUeS9McHlUS3NjRnA1cHFFMzQwTkdR?= =?utf-8?B?bEs5Y1I4NlNoZWZJZll6T3F6T0EvZ0RmdW1sem82UldpTFlsaUhOMytZaVc0?= =?utf-8?B?Q1c4WWFCV3lJZ25LVXdQbCtia2FoUDRCRzY5ZDlZUFdWeSsrdHNrYTNCcmFx?= =?utf-8?B?U0hEbVBqbzMxbCt2c09lUFlQVHcvTlRDLzhaVnJUWHdnVUc0anhKYXVlMTVB?= =?utf-8?B?UWswdGU2a094WE5EUGJsM2pTSnZIdW1WR0szVTRkeG1OaXplcG1hWmppM3Ro?= =?utf-8?B?dUFZbGJIMDJZRmZyTDZMT3NZRTNEUGkxajRoYmtMQTRZT2xJcy9WVVYzZk5X?= =?utf-8?B?cHMycU1WQjd4RVh5aS8rQkJoOFgyKzdRTElhYXBac2YrWXdaN3RqTzQzVnRs?= =?utf-8?B?cmZoaTlSb21lRUliWkI0ZlllS0VnekNWYmZiY3V2SWtDK3Y4RGdBc0R6aWFV?= =?utf-8?B?V3lWN0dnZWF4dkd5RjY0S0JwTjVxbFpOYlV0dlVTVmQ1YjZpM283bVF1NzVz?= =?utf-8?B?V3NJdmRKcDRGRVJWczBhbHZVOWNoSUczYWlQWjl4Ujl4VGdRbyt3cGlxcDJY?= =?utf-8?B?bWhDY0k0bS8xdmpxNWpRWXI4OVp0NGtxMERtb0hpK3dBeGNUU2RPTXRVZkdV?= =?utf-8?B?TzhydGtGeGkrNjhseXFQYnpveVVYbmtXRWR6b3loUHZzai9SQzdpREh6N1R6?= =?utf-8?B?TDdTY1ZUanozejBucS9DaWwwUXRMQXJDck9rQ3dUSUhEVExKSzNMWU40UUJp?= =?utf-8?B?SEh3R0FIYWZuVDBHYlpMVm9DNitNNHRWYk9ZMUdiU1B6YVV2bGxDR3lOR1Ev?= =?utf-8?B?MGltTmxJYk5OQWk3b1ZEdFFsSzVLYTFScDFpT0ZXT3U5WFhzSzFPWmVYTC8v?= =?utf-8?B?dG5iNUw0UXVVL1ptd1gxRXhXcWc5bWZyZUhQTC9NMDNMU09SeFpIWlFCaEdY?= =?utf-8?B?Qm5VSHZWcHNPUE9VSzhUUHdZenF4MnBGNVdYRmJJNXQ2SERVck5lelRuMzI4?= =?utf-8?Q?GFl3CaYwnDx59vXuiDi6TU2eKW7BHoY9cMPiwTPyQ9opSa?= X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0157;6:uhBtiq7idcP/rI8m3BrAxB/0rtOnNJnZKge3Wtga7kv1cvGhZgBCgbUyz/QoDgIplLUnHGLp/KTCqVuJWJtyMGapgi96AxIIBHYzILSGlCqlUS1M4Z421Pz3ACZA9rXb+A2s4rOqkFVOlYvh/KUWofuJwTPVBX0IaOKPGK8YkNHWAlQnPP4F1EDNYx0byOUJiv9ESZfNNDSemhYWRT0WEBDOBQWYX+pmmMo01O2Q88ZHF5hINqsO+PrRUbhpEnrSzzHnkN83Vx4mKGL1HpS2x/p43U7Xye8nTXx+6i2xsZUr+n6aHs/dqQP3KPfZ0ec3lQPm9Mbg14BLgBuKWZIlDw==;5:XA0LvH8z2EaMCgq9hXGfAH9ulHp2bHXKInnGB+qwQl2mgN/C2Fh7Uk6L/LPyv+uR3psdygwstC19oyNEcDwyUzBZWjTI1MImv5NZno10Yf5AmotGQ2CFQ7MvqsXFN38RuUejdrz8zWIwosUtxUFJRg==;24:OgGM7Vcjczqm8QZhN1D3GGJwjfyVcd+sjyAxVKuUuUAMpo0O1TiZ5MgLouACnpm/O0jgeHmegJhSCA+Cm1ZDq3cmtetIbh3Jp2V9x2KQGes=;7:nN4qIAuMLkf6Qd35HFjZiO9mRduKI4H+JAw3gbIEbtIWDndldXZN4g5EI/Dt1Vx5GUGH0z20S803jXSr+5BYrkTba/6YynbYQDpDHY1sxzt3A491Otpn3vo1qD1ZLeejxSzVR4VA/Xl427ONTFEqWSBf240p1Ez7zt3NJJycOz5S6XyNtWYBuq9uFZZrmsREOAqM4Bn6mYWpBSh2z3BpO/Qo4HK+1FVUt+xSd1KwpvY= SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;SN1PR12MB0157;20:kb4c+hB2YBMH3/5tkgBT/IIPfSYwEH4nj/4NdBUt9yHfD0GwvMsoVeQlWSt8X0Q9vsLBUKz4Angk5Ahvh2HU8/db4ccXKuRiajACJx9/EuWZ/gotPnEn9yhzcJxgO6k3jjdpNOySzXx5bGUQm6UaoJI3aQwVt9st2aEGqFsxROPKxeIZuQMSsLSUe/HAQPYa0jm/tsNvvDxh40wKBXp67JQz0Mt3zf1vQSBDAsUZRjVWn/On0mYGkK9Uw8GSPDHO X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Oct 2017 02:35:43.5503 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 0c71e891-3cce-4442-45dc-08d5176343fb X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR12MB0157 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org The SEV memory encryption engine uses a tweak such that two identical plaintext pages at different location will have different ciphertext. So swapping or moving ciphertext of two pages will not result in plaintext being swapped. Relocating (or migrating) physical backing pages for a SEV guest will require some additional steps. The current SEV key management spec does not provide commands to swap or migrate (move) ciphertext pages. For now, we pin the guest memory registered through KVM_MEMORY_ENCRYPT_REGISTER_REGION ioctl. Cc: Thomas Gleixner Cc: Ingo Molnar Cc: "H. Peter Anvin" Cc: Paolo Bonzini Cc: "Radim Krčmář" Cc: Joerg Roedel Cc: Borislav Petkov Cc: Tom Lendacky Cc: x86@kernel.org Cc: kvm@vger.kernel.org Cc: linux-kernel@vger.kernel.org Signed-off-by: Brijesh Singh --- arch/x86/include/asm/kvm_host.h | 1 + arch/x86/kvm/svm.c | 112 ++++++++++++++++++++++++++++++++++++++++ 2 files changed, 113 insertions(+) diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h index 924ce807c76c..0458f494f5e4 100644 --- a/arch/x86/include/asm/kvm_host.h +++ b/arch/x86/include/asm/kvm_host.h @@ -753,6 +753,7 @@ struct kvm_sev_info { unsigned int handle; /* SEV firmware handle */ int fd; /* SEV device fd */ unsigned long pages_locked; /* Number of pages locked */ + struct list_head regions_list; /* List of registered regions */ }; struct kvm_arch { diff --git a/arch/x86/kvm/svm.c b/arch/x86/kvm/svm.c index c72ec87868bb..af218e11f23d 100644 --- a/arch/x86/kvm/svm.c +++ b/arch/x86/kvm/svm.c @@ -334,6 +334,14 @@ static unsigned int max_sev_asid; static unsigned long *sev_asid_bitmap; #define __sme_page_pa(x) __sme_set(page_to_pfn(x) << PAGE_SHIFT) +struct enc_region { + struct list_head list; + unsigned long npages; + struct page **pages; + unsigned long uaddr; + unsigned long size; +}; + static inline bool svm_sev_enabled(void) { return max_sev_asid; @@ -1625,13 +1633,42 @@ static void sev_clflush_pages(struct page *pages[], unsigned long npages) } } +static void __unregister_enc_region(struct kvm *kvm, + struct enc_region *region) +{ + /* + * The guest may change the memory encryption attribute from C=0 -> C=1 + * or vice versa for this memory range. Lets make sure caches are + * flushed to ensure that guest data gets written into memory with + * correct C-bit. + */ + sev_clflush_pages(region->pages, region->npages); + + sev_unpin_memory(kvm, region->pages, region->npages); + list_del(®ion->list); + kfree(region); +} + static void sev_vm_destroy(struct kvm *kvm) { struct kvm_sev_info *sev = &kvm->arch.sev_info; + struct list_head *head = &sev->regions_list; + struct list_head *pos, *q; if (!sev_guest(kvm)) return; + /* + * if userspace was terminated before unregistering the memory regions + * then lets unpin all the registered memory. + */ + if (!list_empty(head)) { + list_for_each_safe(pos, q, head) { + __unregister_enc_region(kvm, + list_entry(pos, struct enc_region, list)); + } + } + sev_unbind_asid(kvm, sev->handle); sev_platform_shutdown(NULL); sev_asid_free(kvm); @@ -5685,6 +5722,7 @@ static int sev_guest_init(struct kvm *kvm, struct kvm_sev_cmd *argp) sev->active = true; sev->asid = asid; + INIT_LIST_HEAD(&sev->regions_list); return 0; @@ -6427,6 +6465,78 @@ static int svm_mem_enc_op(struct kvm *kvm, void __user *argp) return r; } +static int svm_register_enc_region(struct kvm *kvm, + struct kvm_enc_region *range) +{ + struct kvm_sev_info *sev = &kvm->arch.sev_info; + struct enc_region *region; + int ret = 0; + + if (!sev_guest(kvm)) + return -ENOTTY; + + region = kzalloc(sizeof(*region), GFP_KERNEL); + if (!region) + return -ENOMEM; + + region->pages = sev_pin_memory(kvm, range->addr, range->size, ®ion->npages, 1); + if (!region->pages) { + ret = -ENOMEM; + goto e_free; + } + + /* + * The guest may change the memory encryption attribute from C=0 -> C=1 + * or vice versa for this memory range. Lets make sure caches are + * flushed to ensure that guest data gets written into memory with + * correct C-bit. + */ + sev_clflush_pages(region->pages, region->npages); + + region->uaddr = range->addr; + region->size = range->size; + list_add_tail(®ion->list, &sev->regions_list); + return ret; + +e_free: + kfree(region); + return ret; +} + +static struct enc_region * +find_enc_region(struct kvm *kvm, struct kvm_enc_region *range) +{ + struct kvm_sev_info *sev = &kvm->arch.sev_info; + struct list_head *head = &sev->regions_list; + struct enc_region *i; + + list_for_each_entry(i, head, list) { + if (i->uaddr == range->addr && + i->size == range->size) + return i; + } + + return NULL; +} + + +static int svm_unregister_enc_region(struct kvm *kvm, + struct kvm_enc_region *range) +{ + struct enc_region *region; + + if (!sev_guest(kvm)) + return -ENOTTY; + + region = find_enc_region(kvm, range); + if (!region) + return -EINVAL; + + __unregister_enc_region(kvm, region); + + return 0; +} + static struct kvm_x86_ops svm_x86_ops __ro_after_init = { .cpu_has_kvm_support = has_svm, .disabled_by_bios = is_disabled, @@ -6539,6 +6649,8 @@ static struct kvm_x86_ops svm_x86_ops __ro_after_init = { .setup_mce = svm_setup_mce, .mem_enc_op = svm_mem_enc_op, + .mem_enc_reg_region = svm_register_enc_region, + .mem_enc_unreg_region = svm_unregister_enc_region, }; static int __init svm_init(void) -- 2.9.5