From: Sean Christopherson <seanjc@google.com>
To: Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: "H. Peter Anvin" <hpa@zytor.com>,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
Andrew Cooper <Andrew.Cooper3@citrix.com>
Subject: [PATCH 08/16] x86/reboot: Disable virtualization during reboot iff callback is registered
Date: Thu, 1 Dec 2022 23:26:47 +0000 [thread overview]
Message-ID: <20221201232655.290720-9-seanjc@google.com> (raw)
In-Reply-To: <20221201232655.290720-1-seanjc@google.com>
Attempt to disable virtualization during an emergency reboot if and only
if there is a registered virt callback, i.e. iff a hypervisor (KVM) is
active. If there's no active hypervisor, then the CPU can't be operating
with VMX or SVM enabled (barring an egregious bug).
Note, IRQs are disabled, which prevents KVM from coming along and enabling
virtualization after the fact.
Signed-off-by: Sean Christopherson <seanjc@google.com>
---
arch/x86/kernel/reboot.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)
diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c
index a006ddaa1405..e0dd1b00ba01 100644
--- a/arch/x86/kernel/reboot.c
+++ b/arch/x86/kernel/reboot.c
@@ -22,7 +22,6 @@
#include <asm/reboot_fixups.h>
#include <asm/reboot.h>
#include <asm/pci_x86.h>
-#include <asm/virtext.h>
#include <asm/cpu.h>
#include <asm/nmi.h>
#include <asm/smp.h>
@@ -570,7 +569,6 @@ void cpu_emergency_disable_virtualization(void)
callback();
rcu_read_unlock();
}
-#endif /* CONFIG_KVM_INTEL || CONFIG_KVM_AMD */
static void emergency_reboot_disable_virtualization(void)
{
@@ -587,7 +585,7 @@ static void emergency_reboot_disable_virtualization(void)
* Do the NMI shootdown even if virtualization is off on _this_ CPU, as
* other CPUs may have virtualization enabled.
*/
- if (cpu_has_vmx() || cpu_has_svm(NULL)) {
+ if (rcu_access_pointer(cpu_emergency_virt_callback)) {
/* Safely force _this_ CPU out of VMX/SVM operation. */
cpu_emergency_disable_virtualization();
@@ -595,6 +593,9 @@ static void emergency_reboot_disable_virtualization(void)
nmi_shootdown_cpus_on_restart();
}
}
+#else
+static void emergency_reboot_disable_virtualization(void) { }
+#endif /* CONFIG_KVM_INTEL || CONFIG_KVM_AMD */
void __attribute__((weak)) mach_reboot_fixups(void)
--
2.39.0.rc0.267.gcb52ba06e7-goog
next prev parent reply other threads:[~2022-12-01 23:28 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-12-01 23:26 [PATCH 00/16] x86/reboot: KVM: Clean up "emergency" virt code Sean Christopherson
2022-12-01 23:26 ` [PATCH 01/16] x86/reboot: VMCLEAR active VMCSes before emergency reboot Sean Christopherson
2022-12-01 23:26 ` [PATCH 02/16] x86/reboot: Expose VMCS crash hooks if and only if KVM_INTEL is enabled Sean Christopherson
2022-12-01 23:26 ` [PATCH 03/16] x86/reboot: Harden virtualization hooks for emergency reboot Sean Christopherson
2022-12-01 23:26 ` [PATCH 04/16] x86/reboot: Assert that IRQs are disabled when turning off virtualization Sean Christopherson
2022-12-01 23:26 ` [PATCH 05/16] x86/reboot: KVM: Handle VMXOFF in KVM's reboot callback Sean Christopherson
2022-12-01 23:26 ` [PATCH 06/16] x86/reboot: KVM: Disable SVM during reboot via virt/KVM " Sean Christopherson
2022-12-01 23:26 ` [PATCH 07/16] x86/reboot: Hoist "disable virt" helpers above "emergency reboot" path Sean Christopherson
2022-12-01 23:26 ` Sean Christopherson [this message]
2022-12-01 23:26 ` [PATCH 09/16] x86/virt: KVM: Open code cpu_has_vmx() in KVM VMX Sean Christopherson
2022-12-01 23:26 ` [PATCH 10/16] x86/virt: KVM: Move VMXOFF helpers into " Sean Christopherson
2022-12-01 23:26 ` [PATCH 11/16] KVM: SVM: Make KVM_AMD depend on CPU_SUP_AMD or CPU_SUP_HYGON Sean Christopherson
2022-12-01 23:26 ` [PATCH 12/16] x86/virt: Drop unnecessary check on extended CPUID level in cpu_has_svm() Sean Christopherson
2022-12-01 23:26 ` [PATCH 13/16] x86/virt: KVM: Open code cpu_has_svm() into kvm_is_svm_supported() Sean Christopherson
2022-12-01 23:26 ` [PATCH 14/16] x86/virt: KVM: Move "disable SVM" helper into KVM SVM Sean Christopherson
2022-12-01 23:26 ` [PATCH 15/16] KVM: x86: Force kvm_rebooting=true during emergency reboot/crash Sean Christopherson
2022-12-01 23:26 ` [PATCH 16/16] KVM: SVM: Use "standard" stgi() helper when disabling SVM Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20221201232655.290720-9-seanjc@google.com \
--to=seanjc@google.com \
--cc=Andrew.Cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®