From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 666FCC54EE9 for ; Mon, 19 Sep 2022 18:10:34 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229563AbiISSKc (ORCPT ); Mon, 19 Sep 2022 14:10:32 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:60238 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229908AbiISSKE (ORCPT ); Mon, 19 Sep 2022 14:10:04 -0400 Received: from mail-oa1-x2e.google.com (mail-oa1-x2e.google.com [IPv6:2001:4860:4864:20::2e]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 12E9BBE12 for ; Mon, 19 Sep 2022 11:09:40 -0700 (PDT) Received: by mail-oa1-x2e.google.com with SMTP id 586e51a60fabf-11eab59db71so525003fac.11 for ; Mon, 19 Sep 2022 11:09:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date; bh=kinTjsTMKWd+HF2A95PNPhp0ZSHokoUBxlIlduG7fRs=; b=Z9n+eNdWdh71NGqMwqlMdnGMkR+MfqHA3wiPVazUKLvvgnHURhbyz5tXcX8OndG0jF URQm5pcCEx33iQRKI5zFPbEgH51JFbW9BaAXYNFjgA5EPgMkmh2V98Civxgd5idJUz4q N8bx3Ufnvv5tXmdkiuZqMFqLzJ5RWk/VVEmZ/5r6upWFCH9p4MHsGu5NNqC6soqW2oB3 lwtV5aFIKP1Mk+gChIWcM5JW1eZiH3puViRgtakqwSp1UjXFmmBx/jq37EYsyjSMOtet U0hoQISnRKXADaLvG+0m5BWoyOYnTaFmXyNvfsj2FyDAvW8FK+lchT/JgcpwM3NoIZ2G iDaA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date; bh=kinTjsTMKWd+HF2A95PNPhp0ZSHokoUBxlIlduG7fRs=; b=jhzwrNFJ8I7GJ0HgocijNB0tye2W/GzsIc52e+XMkUHHo0/m8AXOt/rsFxqCtjxKs7 ly88t7WeBAfKMlUQO37i6GMPGgi/i5MHBECF5Bj1SiFzIUP/xH8W1i8dSjfVs1d4jIdr /YUwjFImRi1/ddbtcETOwt6zhoBmJIYxWRjDmbBwtOV3R4pWAPtIE1BwBhX0NdzTU5mo kl0e/6Th6GvJsuI3fwRBzTQZsJ/d3QKn9GYm25h9abR3AcFtYrXLtL0dFrrWZnO5qDeI 3kTLfTd6n1Mx77TjnPrgueXYIZct4j4x4awpG/r8BnFBGiiB+Rai+c2QLZAzsQLHdgO3 tkaQ== X-Gm-Message-State: ACgBeo00MumIcQ/p3ncLoRSDvH8FxhxauVlVhggtvg3CjRtHCg92W/kl C16jTO93Zg82s7yODG5C05PZoGEp89B1/P1WUxCeBg== X-Google-Smtp-Source: AA6agR5DN+7DnOIoUE61op1nJjTuN8PFxR6X8cvIHEmjOifcEhIIHF7V7R8Ea8/MENkIhjW/tg4kd/FPe8WCOTlndv0= X-Received: by 2002:a05:6870:580c:b0:12a:f136:a8f5 with SMTP id r12-20020a056870580c00b0012af136a8f5mr15703777oap.269.1663610979201; Mon, 19 Sep 2022 11:09:39 -0700 (PDT) MIME-Version: 1.0 References: <20220916045832.461395-1-jmattson@google.com> <20220916045832.461395-3-jmattson@google.com> In-Reply-To: From: Jim Mattson Date: Mon, 19 Sep 2022 11:09:28 -0700 Message-ID: Subject: Re: [PATCH 2/5] KVM: svm: Disallow EFER.LMSLE on hardware that doesn't support it To: Borislav Petkov Cc: Sean Christopherson , Avi Kivity , Babu Moger , "Chang S. Bae" , Dave Hansen , "H. Peter Anvin" , Ingo Molnar , Joerg Roedel , Josh Poimboeuf , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Paolo Bonzini , Pawan Gupta , Peter Zijlstra , Thomas Gleixner , Wyes Karny , x86@kernel.org Content-Type: text/plain; charset="UTF-8" Precedence: bulk List-ID: X-Mailing-List: kvm@vger.kernel.org On Sun, Sep 18, 2022 at 12:04 PM Borislav Petkov wrote: > > On Fri, Sep 16, 2022 at 10:33:29PM +0000, Sean Christopherson wrote: > > ... > > Either way, KVM appears to be carrying a half-baked "fix" for a buggy guest that's > > long since gone. So like we did in commit 8805875aa473 ("Revert "KVM: nVMX: Do not > > expose MPX VMX controls when guest MPX disabled""), I think we should just revert > > the "fix". > > If, as message 0/5 says, setting this bit so that SLE11 Xen 4.0 boots as > a nested hypervisor is the use case, then sure, unconditional NO_LSMLE > and we all should go on with our lives. Fantastic! That's what I'll do in V2.