From: Maxim Levitsky <email@example.com> To: Sean Christopherson <firstname.lastname@example.org> Cc: Jim Mattson <email@example.com>, Paolo Bonzini <firstname.lastname@example.org>, Vitaly Kuznetsov <email@example.com>, Wanpeng Li <firstname.lastname@example.org>, Joerg Roedel <email@example.com>, kvm list <firstname.lastname@example.org>, LKML <email@example.com>, Xiaoyao Li <firstname.lastname@example.org>, Reiji Watanabe <email@example.com> Subject: Re: [PATCH 03/15] KVM: SVM: Inject #UD on RDTSCP when it should be disabled in the guest Date: Tue, 11 May 2021 15:34:00 +0300 [thread overview] Message-ID: <firstname.lastname@example.org> (raw) In-Reply-To: <YJlluzMze2IfUM6S@google.com> On Mon, 2021-05-10 at 16:56 +0000, Sean Christopherson wrote: > On Mon, May 10, 2021, Maxim Levitsky wrote: > > On Tue, 2021-05-04 at 14:58 -0700, Jim Mattson wrote: > > > On Tue, May 4, 2021 at 2:57 PM Paolo Bonzini <email@example.com> wrote: > > > > On 04/05/21 23:53, Sean Christopherson wrote: > > > > > > Does the right thing happen here if the vCPU is in guest mode when > > > > > > userspace decides to toggle the CPUID.80000001H:EDX.RDTSCP bit on or > > > > > > off? > > > > > I hate our terminology. By "guest mode", do you mean running the vCPU, or do > > > > > you specifically mean running in L2? > > > > > > > > > > > > > Guest mode should mean L2. > > > > > > > > (I wonder if we should have a capability that says "KVM_SET_CPUID2 can > > > > only be called prior to KVM_RUN"). > > > > > > It would certainly make it easier to reason about potential security issues. > > > > > I vote too for this. > > Alternatively, what about adding KVM_VCPU_RESET to let userspace explicitly > pull RESET#, and defining that ioctl() to freeze the vCPU model? I.e. after > userspace resets the vCPU, KVM_SET_CPUID (and any other relevant ioctls() is > disallowed. I vote even stronger for this! I recently created what Paulo called an 'evil' test to stress KVM related bugs in nested migration by simulating a nested migration with a vCPU reset, followed by reload of all of its state including nested state. It is ugly since as you say I have to manually load the reset state, and thus using 'KVM_VCPU_RESET' ioctl instead would make this test much more cleaner and even more 'evil'. Best regards, Maxim Levitsky > > Lack of proper RESET emulation is annoying, e.g. userspace has to manually stuff > EDX after vCPU creation to get the right value at RESET. A dedicated ioctl() > would kill two birds with one stone, without having to add yet another "2" > ioctl(). >
next prev parent reply other threads:[~2021-05-11 12:34 UTC|newest] Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top 2021-05-04 17:17 [PATCH 00/15] KVM: x86: RDPID/RDTSCP fixes and uret MSR cleanups Sean Christopherson 2021-05-04 17:17 ` [PATCH 01/15] KVM: VMX: Do not adverise RDPID if ENABLE_RDTSCP control is unsupported Sean Christopherson 2021-05-04 17:37 ` Jim Mattson 2021-05-04 17:53 ` Jim Mattson 2021-05-04 18:14 ` Sean Christopherson 2021-05-05 3:04 ` Reiji Watanabe 2021-05-10 8:03 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 02/15] KVM: x86: Emulate RDPID only if RDTSCP is supported Sean Christopherson 2021-05-04 17:50 ` Jim Mattson 2021-05-05 3:51 ` Reiji Watanabe 2021-05-05 8:01 ` Paolo Bonzini 2021-05-10 8:08 ` Maxim Levitsky 2021-05-10 17:20 ` Sean Christopherson 2021-05-11 12:32 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 03/15] KVM: SVM: Inject #UD on RDTSCP when it should be disabled in the guest Sean Christopherson 2021-05-04 21:45 ` Jim Mattson 2021-05-04 21:53 ` Sean Christopherson 2021-05-04 21:56 ` Jim Mattson 2021-05-04 22:10 ` Sean Christopherson 2021-05-04 22:24 ` Jim Mattson 2021-05-04 21:57 ` Paolo Bonzini 2021-05-04 21:58 ` Jim Mattson 2021-05-10 8:08 ` Maxim Levitsky 2021-05-10 16:56 ` Sean Christopherson 2021-05-11 12:34 ` Maxim Levitsky [this message] 2021-05-18 10:59 ` Paolo Bonzini 2021-05-18 19:24 ` Sean Christopherson 2021-05-05 4:26 ` Reiji Watanabe 2021-05-10 8:08 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 04/15] KVM: x86: Move RDPID emulation intercept to its own enum Sean Christopherson 2021-05-04 23:24 ` Jim Mattson 2021-05-10 8:14 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 05/15] KVM: VMX: Disable preemption when probing user return MSRs Sean Christopherson 2021-05-04 23:36 ` Jim Mattson 2021-05-10 8:18 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 06/15] KVM: SVM: Probe and load MSR_TSC_AUX regardless of RDTSCP support in host Sean Christopherson 2021-05-10 8:20 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 07/15] KVM: x86: Add support for RDPID without RDTSCP Sean Christopherson 2021-05-10 8:20 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 08/15] KVM: VMX: Configure list of user return MSRs at module init Sean Christopherson 2021-05-10 8:23 ` Maxim Levitsky 2021-05-10 15:13 ` Sean Christopherson 2021-05-11 12:34 ` Maxim Levitsky 2021-05-11 20:10 ` Sean Christopherson 2021-05-04 17:17 ` [PATCH 09/15] KVM: VMX: Use flag to indicate "active" uret MSRs instead of sorting list Sean Christopherson 2021-05-08 3:31 ` Reiji Watanabe 2021-05-10 16:43 ` Sean Christopherson 2021-05-10 17:55 ` Reiji Watanabe 2021-05-10 8:25 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 10/15] KVM: VMX: Use common x86's uret MSR list as the one true list Sean Christopherson 2021-05-10 8:25 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 11/15] KVM: VMX: Disable loading of TSX_CTRL MSR the more conventional way Sean Christopherson 2021-05-05 8:49 ` Paolo Bonzini 2021-05-05 15:36 ` Sean Christopherson 2021-05-05 15:50 ` Paolo Bonzini 2021-05-10 8:26 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 12/15] KVM: x86: Export the number of uret MSRs to vendor modules Sean Christopherson 2021-05-10 8:27 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 13/15] KVM: x86: Move uret MSR slot management to common x86 Sean Christopherson 2021-05-10 8:28 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 14/15] KVM: x86: Tie Intel and AMD behavior for MSR_TSC_AUX to guest CPU model Sean Christopherson 2021-05-10 8:29 ` Maxim Levitsky 2021-05-10 16:50 ` Sean Christopherson 2021-05-10 17:11 ` Jim Mattson 2021-05-11 12:34 ` Maxim Levitsky 2021-05-04 17:17 ` [PATCH 15/15] KVM: x86: Hide RDTSCP and RDPID if MSR_TSC_AUX probing failed Sean Christopherson 2021-05-10 8:29 ` Maxim Levitsky 2021-05-05 8:51 ` [PATCH 00/15] KVM: x86: RDPID/RDTSCP fixes and uret MSR cleanups Paolo Bonzini
Reply instructions: You may reply publicly to this message via plain-text email using any one of the following methods: * Save the following mbox file, import it into your mail client, and reply-to-all from there: mbox Avoid top-posting and favor interleaved quoting: https://en.wikipedia.org/wiki/Posting_style#Interleaved_style * Reply using the --to, --cc, and --in-reply-to switches of git-send-email(1): git send-email \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --firstname.lastname@example.org \ --email@example.com \ --subject='Re: [PATCH 03/15] KVM: SVM: Inject #UD on RDTSCP when it should be disabled in the guest' \ /path/to/YOUR_REPLY https://kernel.org/pub/software/scm/git/docs/git-send-email.html * If your mail client supports setting the In-Reply-To header via mailto: links, try the mailto: link
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for NNTP newsgroup(s).