mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v3 0/2] Restrict devmem for confidential VMs
@ 2025-04-17 19:11 Dan Williams
  2025-04-17 19:12 ` [PATCH v3 1/2] x86/devmem: Remove duplicate range_is_allowed() definition Dan Williams
                   ` (3 more replies)
  0 siblings, 4 replies; 21+ messages in thread
From: Dan Williams @ 2025-04-17 19:11 UTC (permalink / raw)
  To: dave.hansen
  Cc: Kirill Shutemov, Vishal Annapurve, Kees Cook, stable, x86,
	Nikolay Borisov, Naveen N Rao, Ingo Molnar, linux-kernel,
	linux-coco

Changes since v2 [1]:
* Drop the new x86_platform_op and just use
  cc_platform_has(CC_ATTR_GUEST_MEM_ENCRYPT) directly where needed
  (Naveen)
* Make the restriction identical to lockdown and stop playing games with
  devmem_is_allowed()
* Ensure that CONFIG_IO_STRICT_DEVMEM is enabled to avoid conflicting
  mappings for userspace mappings of PCI MMIO.

The original response to Nikolay's report of an SEPT violation triggered
by /dev/mem access to private memory was "let's just turn off /dev/mem".

After some machinations of x86_platform_ops to block a subset of
problematic access, spelunking the history of devmem_is_allowed()
returning "2" to enable some compatibility benefits while blocking
access, and discovering that userspace depends buggy kernel behavior for
mmap(2) of the first 1MB of memory on x86, the proposal has circled back
to "disable /dev/mem".

Require both STRICT_DEVMEM and IO_STRICT_DEVMEM for x86 confidential
guests to close /dev/mem hole while still allowing for userspace
mapping of PCI MMIO as long as the kernel and userspace are not mapping
the range at the same time.

The range_is_allowed() cleanup is not strictly necessary, but might as
well close a 17 year-old "TODO".

---

Dan Williams (2):
      x86/devmem: Remove duplicate range_is_allowed() definition
      x86/devmem: Drop /dev/mem access for confidential guests


 arch/x86/Kconfig          |    4 ++++
 arch/x86/mm/pat/memtype.c |   31 ++++---------------------------
 drivers/char/mem.c        |   27 +++++++++------------------
 include/linux/io.h        |   21 +++++++++++++++++++++
 4 files changed, 38 insertions(+), 45 deletions(-)

base-commit: 0af2f6be1b4281385b618cb86ad946eded089ac8

^ permalink raw reply	[flat|nested] 21+ messages in thread

end of thread, other threads:[~2025-05-07  5:44 UTC | newest]

Thread overview: 21+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-04-17 19:11 [PATCH v3 0/2] Restrict devmem for confidential VMs Dan Williams
2025-04-17 19:12 ` [PATCH v3 1/2] x86/devmem: Remove duplicate range_is_allowed() definition Dan Williams
2025-04-17 19:30   ` Dave Hansen
2025-04-17 19:12 ` [PATCH v3 2/2] x86/devmem: Drop /dev/mem access for confidential guests Dan Williams
2025-04-17 19:33   ` Dave Hansen
2025-04-17 22:31   ` kernel test robot
2025-04-17 23:24   ` kernel test robot
2025-04-18 20:04   ` [PATCH v4 " Dan Williams
2025-04-22 13:38     ` Nikolay Borisov
2025-04-23 17:18     ` Naveen N Rao
2025-04-23 20:36       ` Dan Williams
2025-04-24  6:35         ` Naveen N Rao
2025-04-28 15:53     ` Dave Hansen
2025-04-28 16:30       ` Jianxiong Gao
2025-04-28 16:36         ` Dave Hansen
2025-05-07  5:44   ` [PATCH v3 " kernel test robot
2025-04-22 14:09 ` [PATCH v3 0/2] Restrict devmem for confidential VMs Nikolay Borisov
2025-04-28 15:50 ` Dave Hansen
2025-04-28 22:48   ` Dan Williams
2025-04-29  0:37     ` Dave Hansen
2025-04-30 15:41     ` Suzuki K Poulose

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®