From: Kai Huang <kai.huang@intel.com>
To: Borislav Petkov <bp@alien8.de>
Cc: kvm@vger.kernel.org, linux-sgx@vger.kernel.org, x86@kernel.org,
linux-kernel@vger.kernel.org, seanjc@google.com,
jarkko@kernel.org, luto@kernel.org, dave.hansen@intel.com,
rick.p.edgecombe@intel.com, haitao.huang@intel.com,
pbonzini@redhat.com, tglx@linutronix.de, mingo@redhat.com,
hpa@zytor.com
Subject: Re: [PATCH v3 13/25] x86/sgx: Add helpers to expose ECREATE and EINIT to KVM
Date: Wed, 7 Apr 2021 08:33:15 +1200 [thread overview]
Message-ID: <20210407083315.b3f7527e931fe6c1f4bfc553@intel.com> (raw)
In-Reply-To: <20210406170858.GN17806@zn.tnic>
On Tue, 6 Apr 2021 19:08:58 +0200 Borislav Petkov wrote:
> On Tue, Apr 06, 2021 at 09:41:52PM +1200, Kai Huang wrote:
> > > Ok, I'll make the changes and you can redo the KVM rest ontop.
> > >
> >
> > Thank you!
>
> I.e., something like this:
Looks good. I'll update KVM part patches based on this one.
Thanks.
>
> ---
> From: Sean Christopherson <sean.j.christopherson@intel.com>
> Date: Fri, 19 Mar 2021 20:23:08 +1300
> Subject: [PATCH] x86/sgx: Add helpers to expose ECREATE and EINIT to KVM
>
> The host kernel must intercept ECREATE to impose policies on guests, and
> intercept EINIT to be able to write guest's virtual SGX_LEPUBKEYHASH MSR
> values to hardware before running guest's EINIT so it can run correctly
> according to hardware behavior.
>
> Provide wrappers around __ecreate() and __einit() to hide the ugliness
> of overloading the ENCLS return value to encode multiple error formats
> in a single int. KVM will trap-and-execute ECREATE and EINIT as part
> of SGX virtualization, and reflect ENCLS execution result to guest by
> setting up guest's GPRs, or on an exception, injecting the correct fault
> based on return value of __ecreate() and __einit().
>
> Use host userspace addresses (provided by KVM based on guest physical
> address of ENCLS parameters) to execute ENCLS/EINIT when possible.
> Accesses to both EPC and memory originating from ENCLS are subject to
> segmentation and paging mechanisms. It's also possible to generate
> kernel mappings for ENCLS parameters by resolving PFN but using
> __uaccess_xx() is simpler.
>
> [ bp: Return early if the __user memory accesses fail. ]
>
> Signed-off-by: Sean Christopherson <sean.j.christopherson@intel.com>
> Signed-off-by: Kai Huang <kai.huang@intel.com>
> Signed-off-by: Borislav Petkov <bp@suse.de>
> Acked-by: Jarkko Sakkinen <jarkko@kernel.org>
> Link: https://lkml.kernel.org/r/20e09daf559aa5e9e680a0b4b5fba940f1bad86e.1616136308.git.kai.huang@intel.com
> ---
> arch/x86/include/asm/sgx.h | 7 ++
> arch/x86/kernel/cpu/sgx/virt.c | 117 +++++++++++++++++++++++++++++++++
> 2 files changed, 124 insertions(+)
>
> diff --git a/arch/x86/include/asm/sgx.h b/arch/x86/include/asm/sgx.h
> index 3b025afec0a7..954042e04102 100644
> --- a/arch/x86/include/asm/sgx.h
> +++ b/arch/x86/include/asm/sgx.h
> @@ -365,4 +365,11 @@ struct sgx_sigstruct {
> * comment!
> */
>
> +#ifdef CONFIG_X86_SGX_KVM
> +int sgx_virt_ecreate(struct sgx_pageinfo *pageinfo, void __user *secs,
> + int *trapnr);
> +int sgx_virt_einit(void __user *sigstruct, void __user *token,
> + void __user *secs, u64 *lepubkeyhash, int *trapnr);
> +#endif
> +
> #endif /* _ASM_X86_SGX_H */
> diff --git a/arch/x86/kernel/cpu/sgx/virt.c b/arch/x86/kernel/cpu/sgx/virt.c
> index 259cc46ad78c..7d221eac716a 100644
> --- a/arch/x86/kernel/cpu/sgx/virt.c
> +++ b/arch/x86/kernel/cpu/sgx/virt.c
> @@ -257,3 +257,120 @@ int __init sgx_vepc_init(void)
>
> return misc_register(&sgx_vepc_dev);
> }
> +
> +/**
> + * sgx_virt_ecreate() - Run ECREATE on behalf of guest
> + * @pageinfo: Pointer to PAGEINFO structure
> + * @secs: Userspace pointer to SECS page
> + * @trapnr: trap number injected to guest in case of ECREATE error
> + *
> + * Run ECREATE on behalf of guest after KVM traps ECREATE for the purpose
> + * of enforcing policies of guest's enclaves, and return the trap number
> + * which should be injected to guest in case of any ECREATE error.
> + *
> + * Return:
> + * - 0: ECREATE was successful.
> + * - <0: on error.
> + */
> +int sgx_virt_ecreate(struct sgx_pageinfo *pageinfo, void __user *secs,
> + int *trapnr)
> +{
> + int ret;
> +
> + /*
> + * @secs is an untrusted, userspace-provided address. It comes from
> + * KVM and is assumed to be a valid pointer which points somewhere in
> + * userspace. This can fault and call SGX or other fault handlers when
> + * userspace mapping @secs doesn't exist.
> + *
> + * Add a WARN() to make sure @secs is already valid userspace pointer
> + * from caller (KVM), who should already have handled invalid pointer
> + * case (for instance, made by malicious guest). All other checks,
> + * such as alignment of @secs, are deferred to ENCLS itself.
> + */
> + if (WARN_ON_ONCE(!access_ok(secs, PAGE_SIZE)))
> + return -EINVAL;
> +
> + __uaccess_begin();
> + ret = __ecreate(pageinfo, (void *)secs);
> + __uaccess_end();
> +
> + if (encls_faulted(ret)) {
> + *trapnr = ENCLS_TRAPNR(ret);
> + return -EFAULT;
> + }
> +
> + /* ECREATE doesn't return an error code, it faults or succeeds. */
> + WARN_ON_ONCE(ret);
> + return 0;
> +}
> +EXPORT_SYMBOL_GPL(sgx_virt_ecreate);
> +
> +static int __sgx_virt_einit(void __user *sigstruct, void __user *token,
> + void __user *secs)
> +{
> + int ret;
> +
> + /*
> + * Make sure all userspace pointers from caller (KVM) are valid.
> + * All other checks deferred to ENCLS itself. Also see comment
> + * for @secs in sgx_virt_ecreate().
> + */
> +#define SGX_EINITTOKEN_SIZE 304
> + if (WARN_ON_ONCE(!access_ok(sigstruct, sizeof(struct sgx_sigstruct)) ||
> + !access_ok(token, SGX_EINITTOKEN_SIZE) ||
> + !access_ok(secs, PAGE_SIZE)))
> + return -EINVAL;
> +
> + __uaccess_begin();
> + ret = __einit((void *)sigstruct, (void *)token, (void *)secs);
> + __uaccess_end();
> +
> + return ret;
> +}
> +
> +/**
> + * sgx_virt_einit() - Run EINIT on behalf of guest
> + * @sigstruct: Userspace pointer to SIGSTRUCT structure
> + * @token: Userspace pointer to EINITTOKEN structure
> + * @secs: Userspace pointer to SECS page
> + * @lepubkeyhash: Pointer to guest's *virtual* SGX_LEPUBKEYHASH MSR values
> + * @trapnr: trap number injected to guest in case of EINIT error
> + *
> + * Run EINIT on behalf of guest after KVM traps EINIT. If SGX_LC is available
> + * in host, SGX driver may rewrite the hardware values at wish, therefore KVM
> + * needs to update hardware values to guest's virtual MSR values in order to
> + * ensure EINIT is executed with expected hardware values.
> + *
> + * Return:
> + * - 0: EINIT was successful.
> + * - <0: on error.
> + */
> +int sgx_virt_einit(void __user *sigstruct, void __user *token,
> + void __user *secs, u64 *lepubkeyhash, int *trapnr)
> +{
> + int ret;
> +
> + if (!cpu_feature_enabled(X86_FEATURE_SGX_LC)) {
> + ret = __sgx_virt_einit(sigstruct, token, secs);
> + } else {
> + preempt_disable();
> +
> + sgx_update_lepubkeyhash(lepubkeyhash);
> +
> + ret = __sgx_virt_einit(sigstruct, token, secs);
> + preempt_enable();
> + }
> +
> + /* Propagate up the error from the WARN_ON_ONCE in __sgx_virt_einit() */
> + if (ret == -EINVAL)
> + return ret;
> +
> + if (encls_faulted(ret)) {
> + *trapnr = ENCLS_TRAPNR(ret);
> + return -EFAULT;
> + }
> +
> + return ret;
> +}
> +EXPORT_SYMBOL_GPL(sgx_virt_einit);
> --
> 2.29.2
>
> --
> Regards/Gruss,
> Boris.
>
> https://people.kernel.org/tglx/notes-about-netiquette
next prev parent reply other threads:[~2021-04-06 20:33 UTC|newest]
Thread overview: 124+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-03-19 7:29 [PATCH v3 00/25] KVM SGX virtualization support Kai Huang
2021-03-19 7:22 ` [PATCH v3 01/25] x86/cpufeatures: Make SGX_LC feature bit depend on SGX bit Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Kai Huang
2021-03-19 7:22 ` [PATCH v3 02/25] x86/cpufeatures: Add SGX1 and SGX2 sub-features Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:22 ` [PATCH v3 03/25] x86/sgx: Wipe out EREMOVE from sgx_free_epc_page() Kai Huang
2021-03-22 18:16 ` Borislav Petkov
2021-03-22 18:56 ` Sean Christopherson
2021-03-22 19:11 ` Paolo Bonzini
2021-03-22 20:43 ` Kai Huang
2021-03-23 16:40 ` Paolo Bonzini
2021-03-22 19:15 ` Borislav Petkov
2021-03-22 19:37 ` Sean Christopherson
2021-03-22 20:36 ` Kai Huang
2021-03-22 21:06 ` Borislav Petkov
2021-03-22 22:06 ` Kai Huang
2021-03-22 22:37 ` Borislav Petkov
2021-03-22 23:16 ` Kai Huang
2021-03-23 15:45 ` Sean Christopherson
2021-03-23 16:06 ` Borislav Petkov
2021-03-23 16:21 ` Sean Christopherson
2021-03-23 16:32 ` Borislav Petkov
2021-03-23 16:51 ` Sean Christopherson
2021-03-24 9:38 ` Kai Huang
2021-03-24 10:09 ` Paolo Bonzini
2021-03-24 10:48 ` Kai Huang
2021-03-24 11:24 ` Paolo Bonzini
2021-03-24 23:23 ` Kai Huang
2021-03-24 23:39 ` Paolo Bonzini
2021-03-24 23:46 ` Kai Huang
2021-03-25 8:42 ` Borislav Petkov
2021-03-25 9:38 ` Kai Huang
2021-03-25 16:52 ` Borislav Petkov
2021-03-24 9:28 ` Jarkko Sakkinen
2021-03-23 16:38 ` Paolo Bonzini
2021-03-23 17:02 ` Sean Christopherson
2021-03-23 17:06 ` Paolo Bonzini
2021-03-23 17:16 ` Sean Christopherson
2021-03-23 18:16 ` Borislav Petkov
2021-03-24 9:26 ` Jarkko Sakkinen
2021-03-22 22:23 ` Kai Huang
2021-03-25 9:30 ` [PATCH v4 " Kai Huang
2021-03-26 19:48 ` Jarkko Sakkinen
2021-03-26 20:38 ` Kai Huang
2021-03-26 21:39 ` Jarkko Sakkinen
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Kai Huang
2021-03-19 7:22 ` [PATCH v3 04/25] x86/sgx: Add SGX_CHILD_PRESENT hardware error code Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:22 ` [PATCH v3 05/25] x86/sgx: Introduce virtual EPC for use by KVM guests Kai Huang
2021-03-25 9:36 ` Kai Huang
2021-03-26 15:03 ` Borislav Petkov
2021-03-26 15:17 ` Dave Hansen
2021-03-26 15:29 ` Borislav Petkov
2021-03-26 15:35 ` Dave Hansen
2021-03-26 17:02 ` Borislav Petkov
2021-03-31 1:10 ` Kai Huang
2021-03-31 6:44 ` Boris Petkov
2021-03-31 6:51 ` Kai Huang
2021-03-31 7:44 ` Boris Petkov
2021-03-31 8:53 ` Kai Huang
2021-03-31 12:20 ` Kai Huang
2021-04-01 18:31 ` Borislav Petkov
2021-04-01 23:38 ` Kai Huang
2021-04-01 9:45 ` Kai Huang
2021-04-01 9:42 ` [PATCH v4 " Kai Huang
2021-04-05 9:01 ` [PATCH v3 " Borislav Petkov
2021-04-05 21:46 ` Kai Huang
2021-04-06 8:28 ` Borislav Petkov
2021-04-06 9:04 ` Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:22 ` [PATCH v3 06/25] x86/cpu/intel: Allow SGX virtualization without Launch Control support Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 07/25] x86/sgx: Initialize virtual EPC driver even when SGX driver is disabled Kai Huang
2021-04-02 9:48 ` Borislav Petkov
2021-04-02 11:08 ` Kai Huang
2021-04-02 11:22 ` Borislav Petkov
2021-04-02 11:38 ` Kai Huang
2021-04-02 15:42 ` Sean Christopherson
2021-04-02 19:08 ` Kai Huang
2021-04-02 19:19 ` Borislav Petkov
2021-04-02 19:30 ` Sean Christopherson
2021-04-02 19:46 ` Borislav Petkov
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Kai Huang
2021-03-19 7:23 ` [PATCH v3 08/25] x86/sgx: Expose SGX architectural definitions to the kernel Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 09/25] x86/sgx: Move ENCLS leaf definitions to sgx.h Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 10/25] x86/sgx: Add SGX2 ENCLS leaf definitions (EAUG, EMODPR and EMODT) Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 11/25] x86/sgx: Add encls_faulted() helper Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 12/25] x86/sgx: Add helper to update SGX_LEPUBKEYHASHn MSRs Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Kai Huang
2021-03-19 7:23 ` [PATCH v3 13/25] x86/sgx: Add helpers to expose ECREATE and EINIT to KVM Kai Huang
2021-04-05 9:07 ` Borislav Petkov
2021-04-05 21:44 ` Kai Huang
2021-04-06 7:40 ` Borislav Petkov
2021-04-06 8:59 ` Kai Huang
2021-04-06 9:09 ` Borislav Petkov
2021-04-06 9:24 ` Kai Huang
2021-04-06 9:32 ` Borislav Petkov
2021-04-06 9:41 ` Kai Huang
2021-04-06 17:08 ` Borislav Petkov
2021-04-06 20:33 ` Kai Huang [this message]
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 14/25] x86/sgx: Move provisioning device creation out of SGX driver Kai Huang
2021-04-07 10:03 ` [tip: x86/sgx] " tip-bot2 for Sean Christopherson
2021-03-19 7:23 ` [PATCH v3 15/25] KVM: x86: Export kvm_mmu_gva_to_gpa_{read,write}() for SGX (VMX) Kai Huang
2021-03-19 7:23 ` [PATCH v3 16/25] KVM: x86: Define new #PF SGX error code bit Kai Huang
2021-03-19 7:23 ` [PATCH v3 17/25] KVM: x86: Add support for reverse CPUID lookup of scattered features Kai Huang
2021-03-19 7:23 ` [PATCH v3 18/25] KVM: x86: Add reverse-CPUID lookup support for scattered SGX features Kai Huang
2021-03-19 7:23 ` [PATCH v3 19/25] KVM: VMX: Add basic handling of VM-Exit from SGX enclave Kai Huang
2021-03-19 7:23 ` [PATCH v3 20/25] KVM: VMX: Frame in ENCLS handler for SGX virtualization Kai Huang
2021-03-19 7:23 ` [PATCH v3 21/25] KVM: VMX: Add SGX ENCLS[ECREATE] handler to enforce CPUID restrictions Kai Huang
2021-03-19 7:23 ` [PATCH v3 22/25] KVM: VMX: Add emulation of SGX Launch Control LE hash MSRs Kai Huang
2021-03-19 7:23 ` [PATCH v3 23/25] KVM: VMX: Add ENCLS[EINIT] handler to support SGX Launch Control (LC) Kai Huang
2021-03-19 7:23 ` [PATCH v3 24/25] KVM: VMX: Enable SGX virtualization for SGX1, SGX2 and LC Kai Huang
2021-03-19 7:24 ` [PATCH v3 25/25] KVM: x86: Add capability to grant VM access to privileged SGX attribute Kai Huang
2021-03-19 14:52 ` [PATCH v3 00/25] KVM SGX virtualization support Jarkko Sakkinen
2021-03-22 10:03 ` Kai Huang
2021-03-22 10:31 ` Borislav Petkov
2021-03-26 22:46 ` Jarkko Sakkinen
2021-03-28 21:01 ` Huang, Kai
2021-03-31 23:23 ` Jarkko Sakkinen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210407083315.b3f7527e931fe6c1f4bfc553@intel.com \
--to=kai.huang@intel.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=haitao.huang@intel.com \
--cc=hpa@zytor.com \
--cc=jarkko@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-sgx@vger.kernel.org \
--cc=luto@kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).