From: Maxim Levitsky <mlevitsk@redhat.com>
To: kvm@vger.kernel.org
Cc: Thomas Gleixner <tglx@linutronix.de>,
Wanpeng Li <wanpengli@tencent.com>,
Joerg Roedel <joro@8bytes.org>, "H. Peter Anvin" <hpa@zytor.com>,
Jim Mattson <jmattson@google.com>,
Sean Christopherson <seanjc@google.com>,
Ingo Molnar <mingo@redhat.com>,
Paolo Bonzini <pbonzini@redhat.com>,
Vitaly Kuznetsov <vkuznets@redhat.com>,
x86@kernel.org (maintainer:X86 ARCHITECTURE (32-BIT AND 64-BIT)),
Borislav Petkov <bp@alien8.de>,
linux-kernel@vger.kernel.org (open list:X86 ARCHITECTURE (32-BIT
AND 64-BIT)), Maxim Levitsky <mlevitsk@redhat.com>
Subject: [PATCH 0/2] KVM: SMM fixes for nVMX
Date: Thu, 26 Aug 2021 12:57:48 +0300 [thread overview]
Message-ID: <20210826095750.1650467-1-mlevitsk@redhat.com> (raw)
Those are two patches that fix SMM entries while nested guests
are active and either EPT or unrestricted guest mode is disabled
(EPT disables the later)
1. First patch makes sure that we don't run vmx_handle_exit_irqoff
when we emulate a handful of real mode smm instructions.
When in emulation mode, vmx exit reason is not updated,
and thus this function uses outdated values and crashes.
2. Second patch works around an incorrect restore of segment
registers upon entry to nested guest from SMM.
When entering the nested guest from SMM we enter real mode,
and from it straight to nested guest, and in particular
once we restore L2's CR0, enter_pmode is called which
'restores' the segment registers from real mode segment
cache.
Normally this isn't a problem since after we finish entering
the nested guest, we restore all its registers from SMRAM,
but for the brief period when L2's segment registers are not up to date,
we trip 'vmx_guest_state_valid' check for non unrestricted guest mode, even
though it will be later valid.
Note that I still am able to crash L1 by migrating a VM with a
nested guest running and smm load, on VMX.
This even happens with normal stock settings of ept=1,unrestricted_guest=1
and will soon be investigated.
Best regards,
Maxim Levitsky
Maxim Levitsky (2):
KVM: VMX: avoid running vmx_handle_exit_irqoff in case of emulation
VMX: nSVM: enter protected mode prior to returning to nested guest
from SMM
arch/x86/kvm/vmx/vmx.c | 10 ++++++++++
1 file changed, 10 insertions(+)
--
2.26.3
next reply other threads:[~2021-08-26 9:58 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-08-26 9:57 Maxim Levitsky [this message]
2021-08-26 9:57 ` [PATCH 1/2] KVM: VMX: avoid running vmx_handle_exit_irqoff in case of emulation Maxim Levitsky
2021-08-26 16:01 ` Sean Christopherson
2021-08-30 12:27 ` Maxim Levitsky
2021-09-06 10:09 ` Paolo Bonzini
2021-09-06 21:07 ` Maxim Levitsky
2021-09-07 6:50 ` Paolo Bonzini
2021-08-26 9:57 ` [PATCH 2/2] VMX: nSVM: enter protected mode prior to returning to nested guest from SMM Maxim Levitsky
2021-08-26 16:23 ` Sean Christopherson
2021-08-30 12:45 ` Maxim Levitsky
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20210826095750.1650467-1-mlevitsk@redhat.com \
--to=mlevitsk@redhat.com \
--cc=bp@alien8.de \
--cc=hpa@zytor.com \
--cc=jmattson@google.com \
--cc=joro@8bytes.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=vkuznets@redhat.com \
--cc=wanpengli@tencent.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®