From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f74.google.com (mail-oa1-f74.google.com [209.85.160.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 05B8A1F1522 for ; Tue, 28 Jan 2025 21:37:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738100235; cv=none; b=fx7U8MY8Erik6NMcJsEAf4LasTpCC6A4kjIB39iQtIFxC7cCx8U3HVZBHvWw6yzYDA67zBbKL1fAblMs6YuZeCmZ0CSE+L8x/SYWeMMpFhg9N1DavTwWkLYZgkPxG6lwTF4GG5Tm4EwMdfejSlhsH6WxDSAA1x0i4anv9XWpiqQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1738100235; c=relaxed/simple; bh=H3dJtC0a6qCKsLWlXHs1mbe3B6UOtbImo5pKDP5H/7o=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=tP6Gkax4V23r2KqbHdmaETJ4JFsP40XsZ7TcWyEpDGkpb4cxCOqrLdMgGNUDU4UdCxaFzN+qPWbZxFOxJTWOVWlKskFhgwZ3kkcu2tgxqqyOzFn9JG/P7gZfybZOrt3BSjdE3ymY+wjVwmIxoUtuNiZUu7nS1pt5hOLcO7EeUN0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--vannapurve.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=jv42h90Y; arc=none smtp.client-ip=209.85.160.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--vannapurve.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="jv42h90Y" Received: by mail-oa1-f74.google.com with SMTP id 586e51a60fabf-29e2bd938a1so9180378fac.3 for ; Tue, 28 Jan 2025 13:37:13 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1738100233; x=1738705033; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=8u2LNcB7II7HUojdsZOdJRA/x9pXhTfw5CSocrzmz7E=; b=jv42h90YdRlLGcp7XnA4m6IdKOgcrn9FKFK3rVfZiVhtoQjY1y0IAzHno0SizNVfI1 cX2GnJqWUYnGLzTw5PJT1vU9J1WRBYjWIlVuRdeWiXLLtO1SWkBa8HHgeKPpqJbni7ke +TRf31DYe/4odyHshcFagvxsBsaUBGPgvyf1QnnL8Ms/d7sDC9Ns3EwzQdyeQ6y25+Z5 rESXAeEob/V+aXqRXelgGoS/2un3KCBZv1JFOzemSf361WyEgZjNwtpTkooCRDg4zBkW /91cVtdaDgTIpSePGEwTyAtx1gXEuESbioKrhStyRaM8PS+zBL0F5yABljvzGZtAsbAv 6c5A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1738100233; x=1738705033; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=8u2LNcB7II7HUojdsZOdJRA/x9pXhTfw5CSocrzmz7E=; b=hpru8TK+NTj1QIq517iytmAPx6Rkp1dj4iRg7WGQntkG98Ok7bTGm7y+dNIiVKIOIv /wlSetstpS/IXqBUT0vsfhz8KX3mTfNiQm7pYBRA9JtI2GmiNgB1LEV4Xb8M5bPZ2Hku nims5r9IY6gzidAx1IQstREv6R9/qfog9L7E6xT3m+S+T5u5a8d6gAP4griMFAPMJy3+ et1+4nCRs7xVK9et5u8vOMvYWkCGZeKi773KZD+hh3BUcEl1pCzFDZljtSObLQWZpqfL dJ0t8ZaCXue76iSn/9IL6dIocjyaU9ktzNJZ1Z0E1XUj2qeN2T4v+Rxbzv1WGFzgrstW c0JQ== X-Forwarded-Encrypted: i=1; AJvYcCUkBTp1pmzLLJTMu3UbPm/gTdh6cv4DbMU05WZCtR6h0/s//u5BJqpDSlHnRZebOyM7AlZtwIW/b3db8GM=@vger.kernel.org X-Gm-Message-State: AOJu0Yw6R2G+0RgcXUSIlGyO/QMiogZMXIU+hJ8bfahs20GXNexFLT4u gj9fLpTM1RG7vhM0cXaWmMuBpSzlmU063Gl2j5EPXQ0bWPEoygBUp+7D4JxRMySvF7LLdmRZWaN tWUgHuOv/3Xpt6XmQDQ== X-Google-Smtp-Source: AGHT+IF80OmSEfqMWjcfumktyVkrWkO4QSQ7QLBvCiZJjhd5IKxO3deNkyj1SPTIbsvzCCXM4Hc0cASCnuPAU6R1 X-Received: from oabwh38.prod.google.com ([2002:a05:6871:a6a6:b0:29e:8f:7694]) (user=vannapurve job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6870:d88b:b0:29f:b7f1:d844 with SMTP id 586e51a60fabf-2b32ef658bamr469745fac.2.1738100232892; Tue, 28 Jan 2025 13:37:12 -0800 (PST) Date: Tue, 28 Jan 2025 21:36:52 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.48.1.262.g85cc9f2d1e-goog Message-ID: <20250128213652.1880545-1-vannapurve@google.com> Subject: [PATCH 1/1] x86/tdx: Route safe halt execution via tdx_safe_halt From: Vishal Annapurve To: x86@kernel.org, linux-kernel@vger.kernel.org Cc: pbonzini@redhat.com, seanjc@google.com, erdemaktas@google.com, ackerleytng@google.com, jxgao@google.com, sagis@google.com, oupton@google.com, pgonda@google.com, kirill@shutemov.name, dave.hansen@linux.intel.com, linux-coco@lists.linux.dev, chao.p.peng@linux.intel.com, isaku.yamahata@gmail.com, Vishal Annapurve Content-Type: text/plain; charset="UTF-8" Direct HLT instruction execution causes #VEs for TDX VMs which is routed to hypervisor via tdvmcall. This process renders HLT instruction execution inatomic, so any preceeding instructions like STI/MOV SS will end up enabling interrupts before the HLT instruction is routed to the hypervisor. This creates scenarios where interrupts could land during HLT instruction emulation without aborting halt operation leading to idefinite halt wait times. x86_idle is already upgraded to invoke tdx_safe_halt to avoid such scenarios, but it didn't cover pvnative_safe_halt which can be invoked using raw_safe_halt from call sites like acpi_safe_halt (acpi_pm subsystem). This patch upgrades the safe_halt executions to use tdx_safe_halt. To avoid future call sites which cause HLT instruction emulation with irqs enabled, add a warn and fail the HLT instruction emulation. Signed-off-by: Vishal Annapurve --- arch/x86/coco/tdx/tdx.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/arch/x86/coco/tdx/tdx.c b/arch/x86/coco/tdx/tdx.c index 0d9b090b4880..98b5f317596d 100644 --- a/arch/x86/coco/tdx/tdx.c +++ b/arch/x86/coco/tdx/tdx.c @@ -14,6 +14,7 @@ #include #include #include +#include #include #include #include @@ -380,6 +381,11 @@ static int handle_halt(struct ve_info *ve) { const bool irq_disabled = irqs_disabled(); + if (!irq_disabled) { + WARN(1, "HLT instruction emulation unsafe with irqs enabled\n"); + return -EIO; + } + if (__halt(irq_disabled)) return -EIO; @@ -1083,6 +1089,15 @@ void __init tdx_early_init(void) x86_platform.guest.enc_kexec_begin = tdx_kexec_begin; x86_platform.guest.enc_kexec_finish = tdx_kexec_finish; +#ifdef CONFIG_PARAVIRT_XXL + /* + * halt instruction execution is not atomic for TDX VMs as it generates + * #VEs, so otherwise "safe" halt invocations which cause interrupts to + * get enabled right after halt instruction don't work for TDX VMs. + */ + pv_ops.irq.safe_halt = tdx_safe_halt; +#endif + /* * TDX intercepts the RDMSR to read the X2APIC ID in the parallel * bringup low level code. That raises #VE which cannot be handled -- 2.48.1.262.g85cc9f2d1e-goog