From patchwork Wed Nov 23 01:14:39 2016 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: David Matlack X-Patchwork-Id: 9442433 Return-Path: Received: from mail.wl.linuxfoundation.org (pdx-wl-mail.web.codeaurora.org [172.30.200.125]) by pdx-korg-patchwork.web.codeaurora.org (Postfix) with ESMTP id E039760237 for ; Wed, 23 Nov 2016 01:16:56 +0000 (UTC) Received: from mail.wl.linuxfoundation.org (localhost [127.0.0.1]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id D37B620499 for ; Wed, 23 Nov 2016 01:16:56 +0000 (UTC) Received: by mail.wl.linuxfoundation.org (Postfix, from userid 486) id C7DE020747; Wed, 23 Nov 2016 01:16:56 +0000 (UTC) X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on pdx-wl-mail.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-6.8 required=2.0 tests=BAYES_00, DKIM_ADSP_CUSTOM_MED, DKIM_SIGNED, RCVD_IN_DNSWL_HI, T_DKIM_INVALID autolearn=ham version=3.3.1 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.wl.linuxfoundation.org (Postfix) with ESMTP id 55BAF20499 for ; Wed, 23 Nov 2016 01:16:56 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756320AbcKWBQn (ORCPT ); Tue, 22 Nov 2016 20:16:43 -0500 Received: from mail-pg0-f42.google.com ([74.125.83.42]:34538 "EHLO mail-pg0-f42.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1756141AbcKWBQK (ORCPT ); Tue, 22 Nov 2016 20:16:10 -0500 Received: by mail-pg0-f42.google.com with SMTP id x23so13292759pgx.1 for ; Tue, 22 Nov 2016 17:14:56 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=from:to:cc:subject:date:message-id:in-reply-to:references; bh=Adaded8OjxPHVu1HNw1YNb4LQhJR/ztSCkm9H0qHZp8=; b=amaVoahRHcXghce33OQo6lZzC11dIdcq4olivVkaCkUhZKJ6H9m8UWVHUzx1ESn+PF mZR0OqHBxI2AcNmMkM2io8Gz38z9uokmbXFTTq51xlY2tJF3OrkhIv8/2G87WnLHUzuN nIxKcr0UZPbGJDd+9XCm2eKUO1H+hCReCOUDqjljLCyEZf7nGJO3nvHDYjN3VVk37CK7 UpcqpdWfHTof2i1jBRWDTN8sVEIsYBUAFVXlBqMmoa8/1KbDjyXWUe13DK74XIpXU9vU DrB8u5uCgF4rJprU/L+MS/FkAORzoAxAUyTR/UqyJP08iXiqt14L3No/jr37qwy/LVwN 5WTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references; bh=Adaded8OjxPHVu1HNw1YNb4LQhJR/ztSCkm9H0qHZp8=; b=cgMjUQ3IbNzcv/v/ldrZTnSvx98hDWwOiHSersR0Wyi/ic/u1b0tokaW/wrvdHBpl7 qZ+zfOkMd2ZwX2x2NtozaEmJ2S4bIrftkm8THWUFTvP99Gp2V8Lt1y32sEAfkgjrl9t8 yi8qMHoGXhm6U7h3ZujrRxPTAROhHWYcBmSkhgHIkanjGSNiDFuKSq4rAUwMnmCy+40Q Ej4Ez1NNPTqeAv7z4MU9cWm2+nbiv4OArwWLB6Di56GNhRSfP9H1RaFdkMyAqVNOR0Wf j461b6JHO+ylCLn71ucoQ6Lr6zdoBR2kZwMCTLa4V2fgX0ihRz8GOI7q/5eFnG4vGA7g t5iA== X-Gm-Message-State: AKaTC032BeTYjKNbI45ol7d2Ki/h0DrK3z7G6DAm6Cg+JSra7LSIE0zQ8AT9SCALAkslEVQE X-Received: by 10.84.215.137 with SMTP id l9mr1186651pli.21.1479863696294; Tue, 22 Nov 2016 17:14:56 -0800 (PST) Received: from dmatlack.sea.corp.google.com ([100.100.206.65]) by smtp.gmail.com with ESMTPSA id c8sm47849356pfe.15.2016.11.22.17.14.55 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Tue, 22 Nov 2016 17:14:55 -0800 (PST) From: David Matlack To: kvm@vger.kernel.org Cc: linux-kernel@vger.kernel.org, jmattson@google.com, rkrcmar@redhat.com, pbonzini@redhat.com, David Matlack Subject: [PATCH 3/4] KVM: nVMX: accurate emulation of MSR_IA32_CR{0, 4}_FIXED1 Date: Tue, 22 Nov 2016 17:14:39 -0800 Message-Id: <1479863680-117511-4-git-send-email-dmatlack@google.com> X-Mailer: git-send-email 2.8.0.rc3.226.g39d4020 In-Reply-To: <1479863680-117511-1-git-send-email-dmatlack@google.com> References: <1479863680-117511-1-git-send-email-dmatlack@google.com> Sender: kvm-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: kvm@vger.kernel.org X-Virus-Scanned: ClamAV using ClamSMTP Set MSR_IA32_CR{0,4}_FIXED1 to match the CPU's MSRs. In addition, MSR_IA32_CR4_FIXED1 should reflect the available CR4 bits according to CPUID. Whenever guest CPUID is updated by userspace, regenerate MSR_IA32_CR4_FIXED1 to match it. Signed-off-by: David Matlack --- Note: "x86/cpufeature: Add User-Mode Instruction Prevention definitions" has not hit kvm/master yet so the macros for X86_CR4_UMIP and X86_FEATURE_UMIP are not available. arch/x86/kvm/vmx.c | 54 +++++++++++++++++++++++++++++++++++++++++++++++++++--- 1 file changed, 51 insertions(+), 3 deletions(-) diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c index a2a5ad8..ac5d9c0 100644 --- a/arch/x86/kvm/vmx.c +++ b/arch/x86/kvm/vmx.c @@ -2852,16 +2852,18 @@ static void nested_vmx_setup_ctls_msrs(struct vcpu_vmx *vmx) vmx->nested.nested_vmx_basic |= VMX_BASIC_INOUT; /* - * These MSRs specify bits which the guest must keep fixed (on or off) + * These MSRs specify bits which the guest must keep fixed on * while L1 is in VMXON mode (in L1's root mode, or running an L2). * We picked the standard core2 setting. */ #define VMXON_CR0_ALWAYSON (X86_CR0_PE | X86_CR0_PG | X86_CR0_NE) #define VMXON_CR4_ALWAYSON X86_CR4_VMXE vmx->nested.nested_vmx_cr0_fixed0 = VMXON_CR0_ALWAYSON; - vmx->nested.nested_vmx_cr0_fixed1 = -1ULL; vmx->nested.nested_vmx_cr4_fixed0 = VMXON_CR4_ALWAYSON; - vmx->nested.nested_vmx_cr4_fixed1 = -1ULL; + + /* These MSRs specify bits which the guest must keep fixed off. */ + rdmsrl(MSR_IA32_VMX_CR0_FIXED1, vmx->nested.nested_vmx_cr0_fixed1); + rdmsrl(MSR_IA32_VMX_CR4_FIXED1, vmx->nested.nested_vmx_cr4_fixed1); /* highest index: VMX_PREEMPTION_TIMER_VALUE */ vmx->nested.nested_vmx_vmcs_enum = 0x2e; @@ -9580,6 +9582,49 @@ static void vmcs_set_secondary_exec_control(u32 new_ctl) (new_ctl & ~mask) | (cur_ctl & mask)); } +/* + * Generate MSR_IA32_VMX_CR4_FIXED1 according to CPUID. Only set bits + * (indicating "allowed-1") if they are supported in the guest's CPUID. + */ +static void nested_vmx_cr4_fixed1_update(struct kvm_vcpu *vcpu) +{ + struct vcpu_vmx *vmx = to_vmx(vcpu); + struct kvm_cpuid_entry2 *entry; + +#define update(_cr4_mask, _reg, _cpuid_mask) do { \ + if (entry && (entry->_reg & (_cpuid_mask))) \ + vmx->nested.nested_vmx_cr4_fixed1 |= (_cr4_mask); \ +} while (0) + + vmx->nested.nested_vmx_cr4_fixed1 = X86_CR4_PCE; + + entry = kvm_find_cpuid_entry(vcpu, 0x1, 0); + update(X86_CR4_VME, edx, bit(X86_FEATURE_VME)); + update(X86_CR4_PVI, edx, bit(X86_FEATURE_VME)); + update(X86_CR4_TSD, edx, bit(X86_FEATURE_TSC)); + update(X86_CR4_DE, edx, bit(X86_FEATURE_DE)); + update(X86_CR4_PSE, edx, bit(X86_FEATURE_PSE)); + update(X86_CR4_PAE, edx, bit(X86_FEATURE_PAE)); + update(X86_CR4_MCE, edx, bit(X86_FEATURE_MCE)); + update(X86_CR4_PGE, edx, bit(X86_FEATURE_PGE)); + update(X86_CR4_OSFXSR, edx, bit(X86_FEATURE_FXSR)); + update(X86_CR4_OSXMMEXCPT, edx, bit(X86_FEATURE_XMM)); + update(X86_CR4_VMXE, ecx, bit(X86_FEATURE_VMX)); + update(X86_CR4_SMXE, ecx, bit(X86_FEATURE_SMX)); + update(X86_CR4_PCIDE, ecx, bit(X86_FEATURE_PCID)); + update(X86_CR4_OSXSAVE, ecx, bit(X86_FEATURE_XSAVE)); + + entry = kvm_find_cpuid_entry(vcpu, 0x7, 0); + update(X86_CR4_FSGSBASE, ebx, bit(X86_FEATURE_FSGSBASE)); + update(X86_CR4_SMEP, ebx, bit(X86_FEATURE_SMEP)); + update(X86_CR4_SMAP, ebx, bit(X86_FEATURE_SMAP)); + update(X86_CR4_PKE, ecx, bit(X86_FEATURE_PKU)); + /* TODO: Use X86_CR4_UMIP and X86_FEATURE_UMIP macros */ + update(bit(11), ecx, bit(2)); + +#undef update +} + static void vmx_cpuid_update(struct kvm_vcpu *vcpu) { struct kvm_cpuid_entry2 *best; @@ -9621,6 +9666,9 @@ static void vmx_cpuid_update(struct kvm_vcpu *vcpu) else to_vmx(vcpu)->msr_ia32_feature_control_valid_bits &= ~FEATURE_CONTROL_VMXON_ENABLED_OUTSIDE_SMX; + + if (nested_vmx_allowed(vcpu)) + nested_vmx_cr4_fixed1_update(vcpu); } static void vmx_set_supported_cpuid(u32 func, struct kvm_cpuid_entry2 *entry)