mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Avi Kivity <avi@redhat.com>
To: kvm@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, Eduardo Habkost <ehabkost@redhat.com>
Subject: [PATCH 28/44] x86: disable VMX on all CPUs on reboot
Date: Tue,  9 Dec 2008 22:22:43 +0200	[thread overview]
Message-ID: <1228854179-23002-29-git-send-email-avi@redhat.com> (raw)
In-Reply-To: <1228854179-23002-1-git-send-email-avi@redhat.com>

From: Eduardo Habkost <ehabkost@redhat.com>

On emergency_restart, we may need to use an NMI to disable virtualization
on all CPUs. We do that using nmi_shootdown_cpus() if VMX is enabled.

Note: With this patch, we will run the NMI stuff only when the CPU where
emergency_restart() was called has VMX enabled. This should work on most
cases because KVM enables VMX on all CPUs, but we may miss the small
window where KVM is doing that. Also, I don't know if all code using
VMX out there always enable VMX on all CPUs like KVM does. We have two
other alternatives for that:

a) Have an API that all code that enables VMX on any CPU should use
   to tell the kernel core that it is going to enable VMX on the CPUs.
b) Always call nmi_shootdown_cpus() if the CPU supports VMX. This is
   a bit intrusive and more risky, as it would run nmi_shootdown_cpus()
   on emergency_reboot() even on systems where virtualization is never
   enabled.

Finding a proper point to hook the nmi_shootdown_cpus() call isn't
trivial, as the non-emergency machine_restart() (that doesn't need the
NMI tricks) uses machine_emergency_restart() directly.

The solution to make this work without adding a new function or argument
to machine_ops was setting a 'reboot_emergency' flag that tells if
native_machine_emergency_restart() needs to do the virt cleanup or not.

Signed-off-by: Eduardo Habkost <ehabkost@redhat.com>
Signed-off-by: Avi Kivity <avi@redhat.com>
---
 arch/x86/kernel/reboot.c |   62 ++++++++++++++++++++++++++++++++++++++++++++-
 1 files changed, 60 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c
index 0b0d15c..9050491 100644
--- a/arch/x86/kernel/reboot.c
+++ b/arch/x86/kernel/reboot.c
@@ -12,6 +12,7 @@
 #include <asm/proto.h>
 #include <asm/reboot_fixups.h>
 #include <asm/reboot.h>
+#include <asm/virtext.h>
 
 #ifdef CONFIG_X86_32
 # include <linux/dmi.h>
@@ -39,6 +40,12 @@ int reboot_force;
 static int reboot_cpu = -1;
 #endif
 
+/* This is set if we need to go through the 'emergency' path.
+ * When machine_emergency_restart() is called, we may be on
+ * an inconsistent state and won't be able to do a clean cleanup
+ */
+static int reboot_emergency;
+
 /* reboot=b[ios] | s[mp] | t[riple] | k[bd] | e[fi] [, [w]arm | [c]old]
    warm   Don't set the cold reboot flag
    cold   Set the cold reboot flag
@@ -363,6 +370,48 @@ static inline void kb_wait(void)
 	}
 }
 
+static void vmxoff_nmi(int cpu, struct die_args *args)
+{
+	cpu_emergency_vmxoff();
+}
+
+/* Use NMIs as IPIs to tell all CPUs to disable virtualization
+ */
+static void emergency_vmx_disable_all(void)
+{
+	/* Just make sure we won't change CPUs while doing this */
+	local_irq_disable();
+
+	/* We need to disable VMX on all CPUs before rebooting, otherwise
+	 * we risk hanging up the machine, because the CPU ignore INIT
+	 * signals when VMX is enabled.
+	 *
+	 * We can't take any locks and we may be on an inconsistent
+	 * state, so we use NMIs as IPIs to tell the other CPUs to disable
+	 * VMX and halt.
+	 *
+	 * For safety, we will avoid running the nmi_shootdown_cpus()
+	 * stuff unnecessarily, but we don't have a way to check
+	 * if other CPUs have VMX enabled. So we will call it only if the
+	 * CPU we are running on has VMX enabled.
+	 *
+	 * We will miss cases where VMX is not enabled on all CPUs. This
+	 * shouldn't do much harm because KVM always enable VMX on all
+	 * CPUs anyway. But we can miss it on the small window where KVM
+	 * is still enabling VMX.
+	 */
+	if (cpu_has_vmx() && cpu_vmx_enabled()) {
+		/* Disable VMX on this CPU.
+		 */
+		cpu_vmxoff();
+
+		/* Halt and disable VMX on the other CPUs */
+		nmi_shootdown_cpus(vmxoff_nmi);
+
+	}
+}
+
+
 void __attribute__((weak)) mach_reboot_fixups(void)
 {
 }
@@ -371,6 +420,9 @@ static void native_machine_emergency_restart(void)
 {
 	int i;
 
+	if (reboot_emergency)
+		emergency_vmx_disable_all();
+
 	/* Tell the BIOS if we want cold or warm reboot */
 	*((unsigned short *)__va(0x472)) = reboot_mode;
 
@@ -462,13 +514,19 @@ void native_machine_shutdown(void)
 #endif
 }
 
+static void __machine_emergency_restart(int emergency)
+{
+	reboot_emergency = emergency;
+	machine_ops.emergency_restart();
+}
+
 static void native_machine_restart(char *__unused)
 {
 	printk("machine restart\n");
 
 	if (!reboot_force)
 		machine_shutdown();
-	machine_emergency_restart();
+	__machine_emergency_restart(0);
 }
 
 static void native_machine_halt(void)
@@ -507,7 +565,7 @@ void machine_shutdown(void)
 
 void machine_emergency_restart(void)
 {
-	machine_ops.emergency_restart();
+	__machine_emergency_restart(1);
 }
 
 void machine_restart(char *cmd)
-- 
1.6.0.3


  parent reply	other threads:[~2008-12-09 20:28 UTC|newest]

Thread overview: 45+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-12-09 20:22 [PATCH 00/44] KVM Updates for 2.6.29 (part 2 of 3) Avi Kivity
2008-12-09 20:22 ` [PATCH 01/44] KVM: ppc: adjust vcpu types to support 64-bit cores Avi Kivity
2008-12-09 20:22 ` [PATCH 02/44] KVM: ppc: fix set regs to take care of msr change Avi Kivity
2008-12-09 20:22 ` [PATCH 03/44] KVM: ppc: optimize kvm stat handling Avi Kivity
2008-12-09 20:22 ` [PATCH 04/44] KVM: ppc: optimize find first bit Avi Kivity
2008-12-09 20:22 ` [PATCH 05/44] KVM: ppc: optimize irq delivery path Avi Kivity
2008-12-09 20:22 ` [PATCH 06/44] KVM: ppc: improve trap emulation Avi Kivity
2008-12-09 20:22 ` [PATCH 07/44] KVM: Fix cpuid leaf 0xb loop termination Avi Kivity
2008-12-09 20:22 ` [PATCH 08/44] KVM: Fix cpuid iteration on multiple leaves per eac Avi Kivity
2008-12-09 20:22 ` [PATCH 09/44] KVM: ensure that memslot userspace addresses are page-aligned Avi Kivity
2008-12-09 20:22 ` [PATCH 10/44] KVM: ppc: fix Kconfig constraints Avi Kivity
2008-12-09 20:22 ` [PATCH 11/44] KVM: ia64: Remove some macro definitions in asm-offsets.c Avi Kivity
2008-12-09 20:22 ` [PATCH 12/44] KVM: Fix kernel allocated memory slot Avi Kivity
2008-12-09 20:22 ` [PATCH 13/44] KVM: ppc: use MMUCR accessor to obtain TID Avi Kivity
2008-12-09 20:22 ` [PATCH 14/44] KVM: ppc: use prefetchable mappings for guest memory Avi Kivity
2008-12-09 20:22 ` [PATCH 15/44] KVM: ppc: fix userspace mapping invalidation on context switch Avi Kivity
2008-12-09 20:22 ` [PATCH 16/44] Merge branch 'x86/crashdump' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/linux-2.6-tip Avi Kivity
2008-12-09 20:22 ` [PATCH 17/44] KVM: VMX: move vmx.h to include/asm Avi Kivity
2008-12-09 20:22 ` [PATCH 18/44] KVM: SVM: move svm.h " Avi Kivity
2008-12-09 20:22 ` [PATCH 19/44] KVM: VMX: move ASM_VMX_* definitions from asm/kvm_host.h to asm/vmx.h Avi Kivity
2008-12-09 20:22 ` [PATCH 20/44] KVM: VMX: move cpu_has_kvm_support() to an inline on asm/virtext.h Avi Kivity
2008-12-09 20:22 ` [PATCH 21/44] x86: asm/virtext.h: add cpu_vmxoff() inline function Avi Kivity
2008-12-09 20:22 ` [PATCH 22/44] KVM: VMX: extract kvm_cpu_vmxoff() from hardware_disable() Avi Kivity
2008-12-09 20:22 ` [PATCH 23/44] x86: cpu_emergency_vmxoff() function Avi Kivity
2008-12-09 20:22 ` [PATCH 24/44] KVM: SVM: move has_svm() code to asm/virtext.h Avi Kivity
2008-12-09 20:22 ` [PATCH 25/44] KVM: SVM: move svm_hardware_disable() " Avi Kivity
2008-12-09 20:22 ` [PATCH 26/44] x86: cpu_emergency_svm_disable() function Avi Kivity
2008-12-09 20:22 ` [PATCH 27/44] kdump: forcibly disable VMX and SVM on machine_crash_shutdown() Avi Kivity
2008-12-09 20:22 ` Avi Kivity [this message]
2008-12-09 20:22 ` [PATCH 29/44] KVM: ia64: Define printk function for kvm-intel module Avi Kivity
2008-12-09 20:22 ` [PATCH 30/44] KVM: ia64: Add some debug points to provide crash infomation Avi Kivity
2008-12-09 20:22 ` [PATCH 31/44] KVM: ia64: Add handler for crashed vmm Avi Kivity
2008-12-09 20:22 ` [PATCH 32/44] KVM: ia64: Clean up vmm_ivt.S using tab to indent every line Avi Kivity
2008-12-09 20:22 ` [PATCH 33/44] KVM: VMX: Conditionally request interrupt window after injecting irq Avi Kivity
2008-12-09 20:22 ` [PATCH 34/44] x86: KVM guest: sign kvmclock as paravirt Avi Kivity
2008-12-09 20:22 ` [PATCH 35/44] KVM: Move ack notifier register and IRQ sourcd ID request Avi Kivity
2008-12-09 20:22 ` [PATCH 36/44] KVM: Separate update irq to a single function Avi Kivity
2008-12-09 20:22 ` [PATCH 37/44] KVM: Replace irq_requested with more generic irq_requested_type Avi Kivity
2008-12-09 20:22 ` [PATCH 38/44] KVM: Clean up assigned_device_update_irq Avi Kivity
2008-12-09 20:22 ` [PATCH 39/44] KVM: Add fields for MSI device assignment Avi Kivity
2008-12-09 20:22 ` [PATCH 40/44] KVM: Export ioapic_get_delivery_bitmask Avi Kivity
2008-12-09 20:22 ` [PATCH 41/44] KVM: Add assigned_device_msi_dispatch() Avi Kivity
2008-12-09 20:22 ` [PATCH 42/44] KVM: Enable MSI for device assignment Avi Kivity
2008-12-09 20:22 ` [PATCH 43/44] KVM: MSI to INTx translate Avi Kivity
2008-12-09 20:22 ` [PATCH 44/44] KVM: MMU: optimize set_spte for page sync Avi Kivity

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1228854179-23002-29-git-send-email-avi@redhat.com \
    --to=avi@redhat.com \
    --cc=ehabkost@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®