mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>
To: x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
	Josh Poimboeuf <jpoimboe@kernel.org>,
	David Kaplan <david.kaplan@amd.com>,
	Sean Christopherson <seanjc@google.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
	Asit Mallick <asit.k.mallick@intel.com>,
	Tao Zhang <tao1.zhang@intel.com>
Subject: [PATCH 0/2] VMSCAPE optimization for BHI variant
Date: Wed, 24 Sep 2025 20:09:21 -0700	[thread overview]
Message-ID: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> (raw)

Hi All,

These patches aim to improve the performance of a recent mitigation for
VMSCAPE[1] vulnerability. This improvement is relevant for BHI variant of
VMSCAPE that affect Alder Lake and newer processors.

The current mitigation approach uses IBPB on kvm-exit-to-userspace for all
affected range of CPUs. This is an overkill for CPUs that are only affected
by the BHI variant. On such CPUs clearing the branch history is sufficient
for VMSCAPE, and also more apt as the underlying issue is due to poisoned
branch history.

Roadmap:

- First patch introduces clear_bhb_long_loop() for processors with larger
  branch history tables.
- Second patch replaces IBPB on exit-to-userspace with branch history
  clearing sequence.

Below is the iPerf data for transfer between guest and host, comparing IBPB
and BHB-clear mitigation. BHB-clear shows performance improvement over IBPB
in most cases.

Platform: Emerald Rapids
Baseline: vmscape=off

(..._pN below mean N parallel connections)

| iPerf user-net | IBPB    | BHB Clear |
|----------------|---------|-----------|
| UDP 1-vCPU_p1  | -12.5%  |   1.3%    |
| TCP 1-vCPU_p1  | -10.4%  |  -1.5%    |
| TCP 1-vCPU_p1  | -7.5%   |  -3.0%    |
| UDP 4-vCPU_p16 | -3.7%   |  -3.7%    |
| TCP 4-vCPU_p4  | -2.9%   |  -1.4%    |
| UDP 4-vCPU_p4  | -0.6%   |   0.0%    |
| TCP 4-vCPU_p4  |  3.5%   |   0.0%    |

| iPerf bridge-net | IBPB    | BHB Clear |
|------------------|---------|-----------|
| UDP 1-vCPU_p1    | -9.4%   |  -0.4%    |
| TCP 1-vCPU_p1    | -3.9%   |  -0.5%    |
| UDP 4-vCPU_p16   | -2.2%   |  -3.8%    |
| TCP 4-vCPU_p4    | -1.0%   |  -1.0%    |
| TCP 4-vCPU_p4    |  0.5%   |   0.5%    |
| UDP 4-vCPU_p4    |  0.0%   |   0.9%    |
| TCP 1-vCPU_p1    |  0.0%   |   0.9%    |

| iPerf vhost-net | IBPB    | BHB Clear |
|-----------------|---------|-----------|
| UDP 1-vCPU_p1   | -4.3%   |   1.0%    |
| TCP 1-vCPU_p1   | -3.8%   |  -0.5%    |
| TCP 1-vCPU_p1   | -2.7%   |  -0.7%    |
| UDP 4-vCPU_p16  | -0.7%   |  -2.2%    |
| TCP 4-vCPU_p4   | -0.4%   |   0.8%    |
| UDP 4-vCPU_p4   |  0.4%   |  -0.7%    |
| TCP 4-vCPU_p4   |  0.0%   |   0.6%    |

[1] https://comsec.ethz.ch/research/microarch/vmscape-exposing-and-exploiting-incomplete-branch-predictor-isolation-in-cloud-environments/

---
Pawan Gupta (2):
      x86/bhi: Add BHB clearing for CPUs with larger branch history
      x86/vmscape: Replace IBPB with branch history clear on exit to userspace

 Documentation/admin-guide/hw-vuln/vmscape.rst   |  8 +++++
 Documentation/admin-guide/kernel-parameters.txt |  4 ++-
 arch/x86/entry/entry_64.S                       | 47 ++++++++++++++++++-------
 arch/x86/include/asm/cpufeatures.h              |  1 +
 arch/x86/include/asm/entry-common.h             | 12 ++++---
 arch/x86/include/asm/nospec-branch.h            |  5 ++-
 arch/x86/kernel/cpu/bugs.c                      | 44 ++++++++++++++++-------
 arch/x86/kvm/x86.c                              |  5 +--
 8 files changed, 92 insertions(+), 34 deletions(-)
---
base-commit: 4ea5af08590825c79ba2f146482ed54443e22c28
change-id: 20250916-vmscape-bhb-d7d469977f2f

Best regards,
-- 
Pawan


WARNING: multiple messages have this Message-ID
From: Jack Wang <jinpu.wang@ionos.com>
To: pawan.kumar.gupta@linux.intel.com, x86@kernel.org,
	"H. Peter Anvin" <hpa@zytor.com>,
	Josh Poimboeuf <jpoimboe@kernel.org>,
	David Kaplan <david.kaplan@amd.com>,
	Sean Christopherson <seanjc@google.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Cc: asit.k.mallick@intel.com, kvm@vger.kernel.org,
	linux-kernel@vger.kernel.org, tao1.zhang@intel.com
Subject: [PATCH 0/2] VMSCAPE optimization for BHI variant
Date: Mon, 29 Sep 2025 07:12:03 +0200	[thread overview]
Message-ID: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> (raw)
Message-ID: <20250929051203.zjnRlX_Axh4TavzD2JP8w2uIfyHjPCUHU-twgXy-RMI@z> (raw)
In-Reply-To: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com>

From: Pawan Gupta <pawan.kumar.gupta@linux.intel.com>

Hi Pawan,

Thx for the patches, I tested them on our Intel SierraForest machine with fio
4k randread/randwrite from guest, qemu virtio-blk, noticed nice performance
improvement comparing to the default IBPB before exit to userspace mitigation.
eg with default IBPB mitigation fio gets 204k IOPS, with this new Clear BHB before exit to userspace 
gets 323k IOPS.

Thx!

             reply	other threads:[~2025-09-25  3:09 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-25  3:09 Pawan Gupta [this message]
2025-09-25  3:09 ` [PATCH 1/2] x86/bhi: Add BHB clearing for CPUs with larger branch history Pawan Gupta
2025-09-25 17:54   ` Jim Mattson
2025-09-25 20:49     ` Pawan Gupta
2025-09-25  3:09 ` [PATCH 2/2] x86/vmscape: Replace IBPB with branch history clear on exit to userspace Pawan Gupta
2025-09-25 18:14   ` Kaplan, David
2025-09-25 22:02     ` Pawan Gupta
2025-09-25 22:26       ` Pawan Gupta
2025-09-26 13:39       ` Kaplan, David
2025-09-26 16:14         ` Pawan Gupta
2025-09-29  5:12 ` [PATCH 0/2] VMSCAPE optimization for BHI variant Jack Wang
2025-09-30  1:22 ` Pawan Gupta
2025-10-01  8:12   ` Jinpu Wang

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com \
    --to=pawan.kumar.gupta@linux.intel.com \
    --cc=asit.k.mallick@intel.com \
    --cc=david.kaplan@amd.com \
    --cc=hpa@zytor.com \
    --cc=jpoimboe@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    --cc=tao1.zhang@intel.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®