From patchwork Mon Oct 16 13:27:34 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Roth X-Patchwork-Id: 13423397 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id C7278CDB465 for ; Mon, 16 Oct 2023 13:49:34 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 6A5758D009E; Mon, 16 Oct 2023 09:49:34 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 655D38D0001; Mon, 16 Oct 2023 09:49:34 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 4FCBD8D009E; Mon, 16 Oct 2023 09:49:34 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0016.hostedemail.com [216.40.44.16]) by kanga.kvack.org (Postfix) with ESMTP id 40BA28D0001 for ; Mon, 16 Oct 2023 09:49:34 -0400 (EDT) Received: from smtpin10.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id 03407B5AA0 for ; Mon, 16 Oct 2023 13:49:33 +0000 (UTC) X-FDA: 81351457068.10.F8862BA Received: from NAM12-MW2-obe.outbound.protection.outlook.com (mail-mw2nam12on2072.outbound.protection.outlook.com [40.107.244.72]) by imf05.hostedemail.com (Postfix) with ESMTP id 8743D100017 for ; Mon, 16 Oct 2023 13:49:30 +0000 (UTC) Authentication-Results: imf05.hostedemail.com; dkim=pass header.d=amd.com header.s=selector1 header.b="lIuD16s/"; spf=pass (imf05.hostedemail.com: domain of Michael.Roth@amd.com designates 40.107.244.72 as permitted sender) smtp.mailfrom=Michael.Roth@amd.com; arc=pass ("microsoft.com:s=arcselector9901:i=1"); dmarc=pass (policy=quarantine) header.from=amd.com ARC-Seal: i=2; s=arc-20220608; d=hostedemail.com; t=1697464171; a=rsa-sha256; cv=pass; b=BpFJB9ZReYzTjAVQfQucDPAzx4FJtapgnPuSBRSGBo4hORc2lK91CzrSrtLTl4WxoDJOd3 ytGx/tJJ4mejyda2G1MCI0EoyartjQPLPt/bni5Pe5HkNLAsKGf3Ws8UZkPv1kwsz8jQ8R YU1i9PV4LDLqbdcl6Kg7sJ7t3mPyYHQ= ARC-Authentication-Results: i=2; imf05.hostedemail.com; dkim=pass header.d=amd.com header.s=selector1 header.b="lIuD16s/"; spf=pass (imf05.hostedemail.com: domain of Michael.Roth@amd.com designates 40.107.244.72 as permitted sender) smtp.mailfrom=Michael.Roth@amd.com; arc=pass ("microsoft.com:s=arcselector9901:i=1"); dmarc=pass (policy=quarantine) header.from=amd.com ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1697464171; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=70mqkiCj04QYAqaioqMmcv5wp7tH073pBX3KBUuoK/8=; b=fh/xclMqwcF/07orbHY0qUSIDhSUCQmPHU5yiTkoQmVX+gx2NzPk0mDXUzH0xq43Yu406y Tjwnh8vHbQS+SD5NVYroFCsh31Q6bM9JKaccXGCs9phXyQsnW7Lr85VnASz0AdNdb/agrC utQJ+FKnidKTjLOax9m+RJwFD0cLoJ0= ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=D7Jh2FyYiWbDm77vWQfKp/3OGov0pRFGDZlP+jgTcejUGbAWOFuwlhG/ejjVr3c+CmUT5JT2bl2HOboHMB2vcbFXCBoUvK7vbT5XKK3R0uEA0UNz/AH0je0D8nk6bruyhS0rS0bq4axiQ9UIH5SD/qJaHkliEsRM24o5dyU3MyqIJ6XuGF5ZhwzGJ8Le5TSZcQJEgD/X+kRBSIoSE3VN3sNvscnhpSnKRuuabWq8weQLSExN8f9Fy+7W8qm7VMsHnqxJvNInKj6tVz5XqLcI6GFTyiXg2QDYitLx4Nk0uLEWhNXWPZfFGWuWH3QtMqdc5lGetUPaEFs0GDx2ILe6WQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=70mqkiCj04QYAqaioqMmcv5wp7tH073pBX3KBUuoK/8=; b=eWcw49WlSht7JrUX5nkBiZ0DDfe9aI1ElbvuJNOOYLsBSLzkNcWPzQ8mP3ELSzlgR0nq046idjj7IOEfZicu2OPAJHy+6FxaZJoG6jSlDN2Sc30ZSe2zqEChUJEn4G1bVs11yiPW1G0NJs6TUaZBtD+D2x1O7KSkfbp+XDn6R/fxpDbBUwQnQg25x2cy2gfqS9+FfdDyd9Ux42F1ZhXrI2G/I4Tq69jFR2E0VC/4W1rEKn4/zqxtxIy5HvR/TTuihRoBj7IBOUZXo/X+RwNUJ71pBtteIh6RPGYjcbnVbbSmZVsFTfu2UFt9TLWm1ukXveoaj1ikrsVxvTqCgVI0pg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=vger.kernel.org smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amd.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=70mqkiCj04QYAqaioqMmcv5wp7tH073pBX3KBUuoK/8=; b=lIuD16s/Tk5Jy45POllgVh3kdtMjxp6tcZD7JuOKucqbbTfiOMvRS/7UTuddQbbsnOVphR64SAIIsS7mi4ZXPUHVcPw5BGPWRUt4coODXcc/OSkPSqfNyDcQBD4Mli+Wr8ixyb4VeZWlN/Ogw8LATP2GHAJ8LwTDHjmDC3IIs78= Received: from BL1PR13CA0399.namprd13.prod.outlook.com (2603:10b6:208:2c2::14) by CH3PR12MB7521.namprd12.prod.outlook.com (2603:10b6:610:143::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6886.35; Mon, 16 Oct 2023 13:49:25 +0000 Received: from MN1PEPF0000F0E0.namprd04.prod.outlook.com (2603:10b6:208:2c2:cafe::c0) by BL1PR13CA0399.outlook.office365.com (2603:10b6:208:2c2::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6907.17 via Frontend Transport; Mon, 16 Oct 2023 13:49:25 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 165.204.84.17) smtp.mailfrom=amd.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=amd.com; Received-SPF: Pass (protection.outlook.com: domain of amd.com designates 165.204.84.17 as permitted sender) receiver=protection.outlook.com; client-ip=165.204.84.17; helo=SATLEXMB04.amd.com; pr=C Received: from SATLEXMB04.amd.com (165.204.84.17) by MN1PEPF0000F0E0.mail.protection.outlook.com (10.167.242.38) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.20.6838.22 via Frontend Transport; Mon, 16 Oct 2023 13:49:02 +0000 Received: from localhost (10.180.168.240) by SATLEXMB04.amd.com (10.181.40.145) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) id 15.1.2507.27; Mon, 16 Oct 2023 08:48:56 -0500 From: Michael Roth To: CC: , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , , Kim Phillips Subject: [PATCH v10 05/50] x86/speculation: Do not enable Automatic IBRS if SEV SNP is enabled Date: Mon, 16 Oct 2023 08:27:34 -0500 Message-ID: <20231016132819.1002933-6-michael.roth@amd.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20231016132819.1002933-1-michael.roth@amd.com> References: <20231016132819.1002933-1-michael.roth@amd.com> MIME-Version: 1.0 X-Originating-IP: [10.180.168.240] X-ClientProxiedBy: SATLEXMB03.amd.com (10.181.40.144) To SATLEXMB04.amd.com (10.181.40.145) X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: MN1PEPF0000F0E0:EE_|CH3PR12MB7521:EE_ X-MS-Office365-Filtering-Correlation-Id: f336c685-3899-4420-41de-08dbce4eb560 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0; X-Microsoft-Antispam-Message-Info: aU/qkVmNuf514+nCEYgHmKIUkCsZhGPuIPrIPQXM5GHs/1Rv2Kgq4dV6rY3TEYTk3JL+0G/7O7GZpzFqzbzk8xxjSj3JVwNpgBJQ7qk8IlQKXFE9oWo6AZAvrAiM+BeM1yspL+qFm3xMIDKnHqQjTyGKg8YPJzKcjKGODM5s4hmE7HGQF8q1hX2ktv6YSWgJMs8keFYnvlJQ8z+F3lCZysqfRY6Kbm5U28RBhc5VU8JHINiwYSCjipg1jrW+VFAth/zkwDvc7CYX48qLsjIkwtI2bYuY+Ln2xQTpYu6zetWZd83qxdMpLbqVxw0jvCQMgRHVH7QrPJdI59VnPXLgq2NDHRbQU62d4qQJ5Di320iuFfR4+2vH1j46j0s3uQCMP4aXIWOyYKWZIYLRY4Fb+/lQ0WtgPrxXadEEt3W1sLkt3uovQFCs4gIVqII/PwkSiatc3WrVFjhbi0aZZJzAtnCRNSjwv+Ukh3tm/H/ckBE96soRZbvEO6jnnKQdjztRSonwW1EfXT39sLs+1xSdu4DFrSqd91LlYN+5yxoUKy/4fViEfu3a66wQdORpk3pXq3Y7CITI4VSuC/l0yiQK/qalSE4N6vGKD+HWYLs5U/yaQsdbFU3SA7iGZW9epjiBgOEf9OAnxu7LR0luwU9c23ecjX1l/+UaHf8+dzp0u/v+Dx59/c2fwBBqXidBm5/S5CuuWNNa9xTLMt8MyRhDqK3d2/T6AnBuQ50aTNmD8n4lOq+GZdebdTgZAN2DEo0TvZnElHDaizsc/2YwLdrplg== X-Forefront-Antispam-Report: CIP:165.204.84.17;CTRY:US;LANG:en;SCL:1;SRV:;IPV:CAL;SFV:NSPM;H:SATLEXMB04.amd.com;PTR:InfoDomainNonexistent;CAT:NONE;SFS:(13230031)(4636009)(39860400002)(346002)(376002)(396003)(136003)(230922051799003)(64100799003)(1800799009)(186009)(82310400011)(451199024)(46966006)(36840700001)(40470700004)(478600001)(54906003)(70206006)(70586007)(6666004)(6916009)(47076005)(16526019)(26005)(1076003)(41300700001)(336012)(2616005)(316002)(426003)(7416002)(8676002)(8936002)(4326008)(2906002)(7406005)(5660300002)(44832011)(36756003)(81166007)(86362001)(36860700001)(83380400001)(82740400003)(356005)(40480700001)(40460700003)(36900700001);DIR:OUT;SFP:1101; X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 16 Oct 2023 13:49:02.1467 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: f336c685-3899-4420-41de-08dbce4eb560 X-MS-Exchange-CrossTenant-Id: 3dd8961f-e488-4e60-8e11-a82d994e183d X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=3dd8961f-e488-4e60-8e11-a82d994e183d;Ip=[165.204.84.17];Helo=[SATLEXMB04.amd.com] X-MS-Exchange-CrossTenant-AuthSource: MN1PEPF0000F0E0.namprd04.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH3PR12MB7521 X-Rspamd-Server: rspam08 X-Rspamd-Queue-Id: 8743D100017 X-Stat-Signature: rhsi6rrrgdn1xmjszbfk5z5fzshp3agi X-Rspam-User: X-HE-Tag: 1697464170-842287 X-HE-Meta: U2FsdGVkX18v0U6TaGVTDrvEnuImoQutkPuGb6yRNZUWKUl3ZQ1DIN6RM99kHHgPa+jI7lPWojFU633dPiEIwS4I4FDMLwLjpEqNPf06EBGM82Q+9YDOybq50AZMFS7HuiF7uAMNhuptYf+xy6Fcugi4ejlKBZ13YhDCHGlC0zrNTneIIDoOcpf9pCIFHlST6tL5SyEm68TSO9YAC4AMNSvDv8FXoJmQT4XxoJrCBoitctrL+KVmPMOHWoTH+83Er3bTcv/r3Loyg5h2tlNFmbyCcPk9QEM6M34K2GGm9+4JkrEk1yHltj50ETOr4JneJWNyJAwh4YAZ1Rc9KDekf2xy2h/odqEC8mI0/s3gTL05Tu7S+Ykcl/38wu498Bn2f6zWyvJEE4+Adt8LmAEyvJ3umonmQprfLgHBYD21z4T2x8A9U9ojhoytPE6qpwwPZv99XtH6grn/KwmsoZdQZkkvvkcZvtHf22vnZeTvauh3UbCB/Uj5m/fYJIDvsHggFOz9aibhkA1J/9u+k2YxqZ4F9cBbwE5zk/kl0b+PasukGtTafb3TBAFT/0UubgHAiwFp2+gIYMzWaQ9ZOKipeJhlA0s3l2UgdCoksLQOVIg0Mf+8rqM7Sn4Q6Ym/R2W/fhPRoRCvMAdpAvljZGOAVeWE4KudNF31J0gUa+UqCPTfr8XdGQ3xNSKQB+1mFQO1hxS3Cth77yU5E41egYNrdfYPNaPD2y55pCmBuLwVf7PQh0rhARxUZ2FObQ2qW/y7zhgkQhfuBr/Xt71UaD1J99IOwa2aY8NMPFVgC3iyym83kkQ7a2C9JtDVMO+lSjQPPFHe2TuFbXBTgUWdQHEpSWc9MLn/DqChCk5Cu800pQNSJpOqKCRhvwv+ethW736j1w9xlPTuM6FWyigYp9jinStaPNrR/2BBHlgwq/HPQRSH5rKh9PQH2a5egaBAl0TRhoG50bQsDSygG5okOcF Hb+ZwMnJ n+LAVF+qECSpsWqjZcUodErWglAI1598WEDlEaZfwwjvQ4jQSNw9QDDHtGgstwaFSEDz8ZBVibgZF+SVdNVQV+nhVCOiXI4qOyYkB1jKGYn/tElwzGzacBThjMzvEGu7CjL0OMyL2lGV0Ywt6CMJQryAYolHfOU50dJ2Ch+rSrBx/ko6zcx4jnBQPDq5BtWD39G6q5/swiaDIatrkfEbAebU2tycFVei/afmvMMRUEcXy2jTljyWOWzENNcfTImLkVfQdIWOn9Yn7H/b9DLzKaEWNWl3Cl+O9vvVtUdHBJqZLM90pKBckz8Iour5Zv0MkGiMMYfAVsGRdZ18= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000004, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: From: Kim Phillips Without SEV-SNP, Automatic IBRS protects only the kernel. But when SEV-SNP is enabled, the Automatic IBRS protection umbrella widens to all host-side code, including userspace. This protection comes at a cost: reduced userspace indirect branch performance. To avoid this performance loss, don't use Automatic IBRS on SEV-SNP hosts. Fall back to retpolines instead. Signed-off-by: Kim Phillips [mdr: squash in changes from review discussion] Signed-off-by: Michael Roth Acked-by: Borislav Petkov (AMD) Acked-by: Dave Hansen --- arch/x86/kernel/cpu/common.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/arch/x86/kernel/cpu/common.c b/arch/x86/kernel/cpu/common.c index 382d4e6b848d..11fae89b799e 100644 --- a/arch/x86/kernel/cpu/common.c +++ b/arch/x86/kernel/cpu/common.c @@ -1357,8 +1357,13 @@ static void __init cpu_set_bug_bits(struct cpuinfo_x86 *c) /* * AMD's AutoIBRS is equivalent to Intel's eIBRS - use the Intel feature * flag and protect from vendor-specific bugs via the whitelist. + * + * Don't use AutoIBRS when SNP is enabled because it degrades host + * userspace indirect branch performance. */ - if ((ia32_cap & ARCH_CAP_IBRS_ALL) || cpu_has(c, X86_FEATURE_AUTOIBRS)) { + if ((ia32_cap & ARCH_CAP_IBRS_ALL) || + (cpu_has(c, X86_FEATURE_AUTOIBRS) && + !cpu_feature_enabled(X86_FEATURE_SEV_SNP))) { setup_force_cpu_cap(X86_FEATURE_IBRS_ENHANCED); if (!cpu_matches(cpu_vuln_whitelist, NO_EIBRS_PBRSB) && !(ia32_cap & ARCH_CAP_PBRSB_NO))