From patchwork Thu May 9 07:54:22 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Yang, Weijiang" X-Patchwork-Id: 13659516 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.8]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CDDDC13C801; Thu, 9 May 2024 07:55:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.8 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715241304; cv=none; b=kIusQJo1BkcKuBPMLpI/crWJWokocuoOn9mEh1f3KSn0zRB+0+ewHQpSvK/901M2F5ACbFOnkzBKlU72DwYqtUWZ9jef5c0QCbnfCreZunisdgN8FgF0t9/UXcICZyp5ibEngeJpEx6Y40vdel7PBa2W0d/SWpjJAqNXdNf8CMQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715241304; c=relaxed/simple; bh=GGccQTnqC8mHfE/l4F8QBhIaWm7K3vpcGZGfxrd99yA=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=qTcJm4+AtT226+u6TTWcTefZXci7cdFWYO2PyLcU9gYJzMGY9BjXbcwTQAyZDCTcVL+/+RPGJpC/vW6vF0ZobwJiFVPEru44JzdyfhlRYWo0kdgeQgQuA1UGNk+fpd+0hRxxHbHLFYhOhwvYP8oqI5ohMQlwKcidx/z9B2HV2pI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=dVxppJly; arc=none smtp.client-ip=192.198.163.8 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="dVxppJly" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1715241303; x=1746777303; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=GGccQTnqC8mHfE/l4F8QBhIaWm7K3vpcGZGfxrd99yA=; b=dVxppJlyaILOqt8W9e6t6FDiorLunSsTQh7mwdZahuFHsSleBWlRj8a2 dsnuFQAOaFPc9JW7yYnz0G1lGCI/5C7mZnhM1qKJ8Iap98xqWQ3XiWD0A dO4cutmPSo3sRbBwatp5SY8TepYQ+P7fYAGneSb6vbOv6yS0Slgwn+Z9x Se2dUwb1Wb/SFmgXi102/rp2bv/FlHV2GQOZUBK/Zg19GZzKjlF+TFDLE s2oZkADWu2jUIVb4mqKCLcSouJEHxSvlOn3brNFdTNMEBC9rAOu/z6gkx EWMCEsTuISBqoLz4REkvxOONt9R4lvyNnq8m2pgPO/vOHmgwIjHsRzEpl w==; X-CSE-ConnectionGUID: 4Tjlv7miQVizlyWp646h8g== X-CSE-MsgGUID: ZMhEEs4dSNu3/pAxmHqZwg== X-IronPort-AV: E=McAfee;i="6600,9927,11067"; a="28658406" X-IronPort-AV: E=Sophos;i="6.08,147,1712646000"; d="scan'208";a="28658406" Received: from orviesa009.jf.intel.com ([10.64.159.149]) by fmvoesa102.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 May 2024 00:55:02 -0700 X-CSE-ConnectionGUID: ozw2ceddTjKooZFGha8IMA== X-CSE-MsgGUID: IGR/x8u5R+CIeSIGQBrLAw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.08,147,1712646000"; d="scan'208";a="29268231" Received: from 984fee00a5ca.jf.intel.com ([10.165.9.183]) by orviesa009-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 May 2024 00:55:02 -0700 From: Yang Weijiang To: seanjc@google.com, pbonzini@redhat.com, mlevitsk@redhat.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Yang Weijiang Subject: [RFC PATCH 1/2] KVM: x86: Introduce KVM_{G,S}ET_ONE_REG uAPIs support Date: Thu, 9 May 2024 00:54:22 -0700 Message-ID: <20240509075423.156858-1-weijiang.yang@intel.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Enable KVM_{G,S}ET_ONE_REG uAPIs so that userspace can access HW MSR or KVM synthetic MSR throught it. In CET KVM series [*], KVM "steals" an MSR from PV MSR space and access it via KVM_{G,S}ET_MSRs uAPIs, but the approach pollutes PV MSR space and hides the difference of synthetic MSRs and normal HW defined MSRs. Now carve out a separate room in KVM-customized MSR address space for synthetic MSRs. The synthetic MSRs are not exposed to userspace via KVM_GET_MSR_INDEX_LIST, instead userspace complies with KVM's setup and composes the uAPI params. KVM synthetic MSR indices start from 0 and increase linearly. Userspace caller should tag MSR type correctly in order to access intended HW or synthetic MSR. [*]: https://lore.kernel.org/all/20240219074733.122080-18-weijiang.yang@intel.com/ Suggested-by: Sean Christopherson Signed-off-by: Yang Weijiang --- arch/x86/include/uapi/asm/kvm.h | 10 ++++++ arch/x86/kvm/x86.c | 62 +++++++++++++++++++++++++++++++++ 2 files changed, 72 insertions(+) diff --git a/arch/x86/include/uapi/asm/kvm.h b/arch/x86/include/uapi/asm/kvm.h index ef11aa4cab42..ca2a47a85fa1 100644 --- a/arch/x86/include/uapi/asm/kvm.h +++ b/arch/x86/include/uapi/asm/kvm.h @@ -410,6 +410,16 @@ struct kvm_xcrs { __u64 padding[16]; }; +#define KVM_X86_REG_MSR (1 << 2) +#define KVM_X86_REG_SYNTHETIC_MSR (1 << 3) + +struct kvm_x86_reg_id { + __u32 index; + __u8 type; + __u8 rsvd; + __u16 rsvd16; +}; + #define KVM_SYNC_X86_REGS (1UL << 0) #define KVM_SYNC_X86_SREGS (1UL << 1) #define KVM_SYNC_X86_EVENTS (1UL << 2) diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index 91478b769af0..d0054c52f24b 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -2244,6 +2244,31 @@ static int do_set_msr(struct kvm_vcpu *vcpu, unsigned index, u64 *data) return kvm_set_msr_ignored_check(vcpu, index, *data, true); } +static int kvm_get_one_msr(struct kvm_vcpu *vcpu, u32 msr, u64 __user *value) +{ + u64 val; + int r; + + r = do_get_msr(vcpu, msr, &val); + if (r) + return r; + + if (put_user(val, value)) + return -EFAULT; + + return 0; +} + +static int kvm_set_one_msr(struct kvm_vcpu *vcpu, u32 msr, u64 __user *value) +{ + u64 val; + + if (get_user(val, value)) + return -EFAULT; + + return do_set_msr(vcpu, msr, &val); +} + #ifdef CONFIG_X86_64 struct pvclock_clock { int vclock_mode; @@ -5859,6 +5884,11 @@ static int kvm_vcpu_ioctl_enable_cap(struct kvm_vcpu *vcpu, } } +static int kvm_translate_synthetic_msr(u32 *index) +{ + return 0; +} + long kvm_arch_vcpu_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg) { @@ -5976,6 +6006,38 @@ long kvm_arch_vcpu_ioctl(struct file *filp, srcu_read_unlock(&vcpu->kvm->srcu, idx); break; } + case KVM_GET_ONE_REG: + case KVM_SET_ONE_REG: { + struct kvm_x86_reg_id *id; + struct kvm_one_reg reg; + u64 __user *value; + + r = -EFAULT; + if (copy_from_user(®, argp, sizeof(reg))) + break; + + r = -EINVAL; + id = (struct kvm_x86_reg_id *)®.id; + if (id->rsvd || id->rsvd16) + break; + + if (id->type != KVM_X86_REG_MSR && + id->type != KVM_X86_REG_SYNTHETIC_MSR) + break; + + if (id->type == KVM_X86_REG_SYNTHETIC_MSR) { + r = kvm_translate_synthetic_msr(&id->index); + if (r) + break; + } + + value = u64_to_user_ptr(reg.addr); + if (ioctl == KVM_GET_ONE_REG) + r = kvm_get_one_msr(vcpu, id->index, value); + else + r = kvm_set_one_msr(vcpu, id->index, value); + break; + } case KVM_TPR_ACCESS_REPORTING: { struct kvm_tpr_access_ctl tac; From patchwork Thu May 9 07:54:23 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Yang, Weijiang" X-Patchwork-Id: 13659517 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.8]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 27673149C57; Thu, 9 May 2024 07:55:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.8 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715241306; cv=none; b=IF338GXerhfYRTYtNY9L3eRzku3szJ/Ie8/bJAVn9GGfYD6lT9gSsqvHSjqDKvXEhJ9WjseJDN8eh1s8Cab7OEfYiz6GRprwhPT3GpuobHHVLmT1ybZ4+eBSaxc6FrJt5BszGQUGTLsp2Bik0G4gUYmeWWFSO8DsnjqPJIlmfM8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1715241306; c=relaxed/simple; bh=h4H3AtpMz9WPnsicHUMxE6jo8aseXELd2qgCjjZMN78=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=iNFSfMpx938yXwAd3Dm+BUrS60tQXGVG38SgFi5N18JMDi2oUGPp0p/7fqyJoJPyC7E38wJlL9XVllJX37IEiTvOThYgBD+Eems6NVp+pMONRonlQsq6vIdVd8z/cZ3yId5ABh1FHu/daDhdcKzQQ6wagXctbLD2leE3Us6KZ9Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=JwsfaD/l; arc=none smtp.client-ip=192.198.163.8 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="JwsfaD/l" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1715241305; x=1746777305; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=h4H3AtpMz9WPnsicHUMxE6jo8aseXELd2qgCjjZMN78=; b=JwsfaD/l3UwABalxCYHqTIHFicRQxiUJJhTz/OlWe/Ad9NMvItXoqVIb 4uBi3KG0jlnTHwoZ4i0RB2X0SxF8wpAJxd/Bkf92ZH9hCBHasn6bfSKE3 k79MnAIxvVn27hRIFYjPVWawHo7nhket87lkS6WcP1o0fxh1iIqAVy9E9 5HBMohYhuTL1gR3uKdyKK2KKD56dkkdsUG4Vx9bO2kQs0kO0OvXyXBjHJ y8ALC5BuaiLoC1XVQ/Jcb+2vMnbIUSgRs28+kpgvLRK7zKu4E8uGmsZNC w/Ekmja4bAE3Lun1FQu3OtAGTsK/yk37dWmY2tcF891eYYN9DU5iSSdO0 g==; X-CSE-ConnectionGUID: xpxvqZduSo6yAfzS788etg== X-CSE-MsgGUID: kQfCRb+8Rc6B5opKuhGAvw== X-IronPort-AV: E=McAfee;i="6600,9927,11067"; a="28658409" X-IronPort-AV: E=Sophos;i="6.08,147,1712646000"; d="scan'208";a="28658409" Received: from orviesa009.jf.intel.com ([10.64.159.149]) by fmvoesa102.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 May 2024 00:55:02 -0700 X-CSE-ConnectionGUID: sko8dQaKSA2vWHqsfgWe/A== X-CSE-MsgGUID: aEqM31FzSjeX5jJvX8yaMw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.08,147,1712646000"; d="scan'208";a="29268233" Received: from 984fee00a5ca.jf.intel.com ([10.165.9.183]) by orviesa009-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 09 May 2024 00:55:02 -0700 From: Yang Weijiang To: seanjc@google.com, pbonzini@redhat.com, mlevitsk@redhat.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org Cc: Yang Weijiang Subject: [RFC PATCH 2/2] KVM: x86: Enable guest SSP read/write interface with new uAPIs Date: Thu, 9 May 2024 00:54:23 -0700 Message-ID: <20240509075423.156858-2-weijiang.yang@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20240509075423.156858-1-weijiang.yang@intel.com> References: <20240509075423.156858-1-weijiang.yang@intel.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Enable guest shadow stack pointer(SSP) access interface with new uAPIs. CET guest SSP is HW register which has corresponding VMCS field to save /restore guest values when VM-{Exit,Entry} happens. KVM handles SSP as a synthetic MSR for userspace access. Use a translation helper to set up mapping for SSP synthetic index and KVM-internal MSR index so that userspace doesn't need to take care of KVM's management for synthetic MSRs and avoid conflicts. Suggested-by: Sean Christopherson Signed-off-by: Yang Weijiang --- arch/x86/include/uapi/asm/kvm.h | 3 +++ arch/x86/kvm/x86.c | 7 +++++++ arch/x86/kvm/x86.h | 10 ++++++++++ 3 files changed, 20 insertions(+) diff --git a/arch/x86/include/uapi/asm/kvm.h b/arch/x86/include/uapi/asm/kvm.h index ca2a47a85fa1..81c8d9ea2e58 100644 --- a/arch/x86/include/uapi/asm/kvm.h +++ b/arch/x86/include/uapi/asm/kvm.h @@ -420,6 +420,9 @@ struct kvm_x86_reg_id { __u16 rsvd16; }; +/* KVM synthetic MSR index staring from 0 */ +#define MSR_KVM_GUEST_SSP 0 + #define KVM_SYNC_X86_REGS (1UL << 0) #define KVM_SYNC_X86_SREGS (1UL << 1) #define KVM_SYNC_X86_EVENTS (1UL << 2) diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index d0054c52f24b..a970bd26ce2c 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -5886,6 +5886,13 @@ static int kvm_vcpu_ioctl_enable_cap(struct kvm_vcpu *vcpu, static int kvm_translate_synthetic_msr(u32 *index) { + switch (*index) { + case MSR_KVM_GUEST_SSP: + *index = MSR_KVM_INTERNAL_GUEST_SSP; + break; + default: + return -EINVAL; + } return 0; } diff --git a/arch/x86/kvm/x86.h b/arch/x86/kvm/x86.h index a8b71803777b..6ac86a75aedc 100644 --- a/arch/x86/kvm/x86.h +++ b/arch/x86/kvm/x86.h @@ -57,6 +57,16 @@ void kvm_spurious_fault(void); #define KVM_SVM_DEFAULT_PLE_WINDOW_MAX USHRT_MAX #define KVM_SVM_DEFAULT_PLE_WINDOW 3000 +/* + * KVM's internal, non-ABI indices for synthetic MSRs. The values themselves + * are arbitrary and have no meaning, the only requirement is that they don't + * conflict with "real" MSRs that KVM supports. Use values at the uppper end + * of KVM's reserved paravirtual MSR range to minimize churn, i.e. these values + * will be usable until KVM exhausts its supply of paravirtual MSR indices. + */ + +#define MSR_KVM_INTERNAL_GUEST_SSP 0x4b564dff + static inline unsigned int __grow_ple_window(unsigned int val, unsigned int base, unsigned int modifier, unsigned int max) {