From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.14]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5C82A2E5B0E; Thu, 25 Sep 2025 03:09:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.14 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1758769774; cv=none; b=C/G88qjitOgoGWZzp3sLsbbIsj50sAQ+1hf/K5t0AnYtDzKVVR1A/eUpR7+WjdcdQxsDmi/Hdrc4J2YdRg+LM782p1HtkD7wct6S+rjqA+xIbcQoPjdN8cSvRDgYEVjdLe7o3QMeY+a7vX/3PCy4lPYW8ZR48UT5FlgnLZ9pqYE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1758769774; c=relaxed/simple; bh=7RLxyX/YqC4IwCteU4/Lvp1B0zyCqaI9p16WZF75tEQ=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition; b=t2qgTgiluXzAIbGAF/QFJtWk95szYY4NFlkU5lLh+gR2LXd5PJWZg6/CIOD1lJDb41Bf+0NVP9TAW1XTXN52A722FQ0qgcOTPJhDNRFIU91AFYW4l6uv67scRRCVH/qC+1ObYE2uCnEHiXNZnWJnIKm+YNm0xD4IRC+6M/0RTsM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com; spf=pass smtp.mailfrom=linux.intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=fafSIXu2; arc=none smtp.client-ip=192.198.163.14 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="fafSIXu2" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1758769772; x=1790305772; h=date:from:to:cc:subject:message-id:mime-version; bh=7RLxyX/YqC4IwCteU4/Lvp1B0zyCqaI9p16WZF75tEQ=; b=fafSIXu2mPCrefd2NUH42goAe+enjfNrwDNOUN28t3b4OpDkASkIXWMw iL3JF/kJXjFWgNGmRvxahFns9Aut5Is1DtwU8HBzx+uo+qlMccjHf/Wq0 LHWGNnmdSgNxuljUzDMHLQWw0ELVtv6qOYSHGRItD4BFpljQpqOYrgFSW STZHfVQGDIuB6cMLX9Ylp0PYXsSPXHTK+9KCnl7hXFsTBbJWujztUEvcy eKlRXxsLcAL+SlqYxN2PNCOy/5LfxHmzI6ZSPVhKbWSz+Bmg/+vAl8Rrn mXget5xhUylzmQITpcH7y4+JpQ8oPFIQu0q5TD20F6XXU5evwjH0Iqtbv Q==; X-CSE-ConnectionGUID: UyCA8R5sRrmwgs4hsYfDAg== X-CSE-MsgGUID: 2BUKOb1jR/CdDj7JXI9Ytw== X-IronPort-AV: E=McAfee;i="6800,10657,11563"; a="61129740" X-IronPort-AV: E=Sophos;i="6.18,291,1751266800"; d="scan'208";a="61129740" Received: from orviesa002.jf.intel.com ([10.64.159.142]) by fmvoesa108.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 24 Sep 2025 20:09:24 -0700 X-CSE-ConnectionGUID: 3XEKF5w+QF2quu6sNpukmg== X-CSE-MsgGUID: OIHeV5LvT9Ku8DTMY/vDdQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.18,291,1751266800"; d="scan'208";a="207955386" Received: from aschofie-mobl2.amr.corp.intel.com (HELO desk) ([10.124.220.91]) by orviesa002-auth.jf.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 24 Sep 2025 20:09:23 -0700 Date: Wed, 24 Sep 2025 20:09:21 -0700 From: Pawan Gupta To: x86@kernel.org, "H. Peter Anvin" , Josh Poimboeuf , David Kaplan , Sean Christopherson , Paolo Bonzini Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Asit Mallick , Tao Zhang Subject: [PATCH 0/2] VMSCAPE optimization for BHI variant Message-ID: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> X-B4-Tracking: v=1; b=H4sIACKx1GgC/6tWKk4tykwtVrJSqFYqSi3LLM7MzwNyDHUUlJIzE vPSU3UzU4B8JSMDI1MDS0Mz3bLc4uTEglTdpIwk3RTzFBMzS0tz8zSjNCWgjoKi1LTMCrBp0Uo BjiHOHkqxtbUAfXXXh2QAAAA= X-Change-ID: 20250916-vmscape-bhb-d7d469977f2f X-Mailer: b4 0.14.2 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Hi All, These patches aim to improve the performance of a recent mitigation for VMSCAPE[1] vulnerability. This improvement is relevant for BHI variant of VMSCAPE that affect Alder Lake and newer processors. The current mitigation approach uses IBPB on kvm-exit-to-userspace for all affected range of CPUs. This is an overkill for CPUs that are only affected by the BHI variant. On such CPUs clearing the branch history is sufficient for VMSCAPE, and also more apt as the underlying issue is due to poisoned branch history. Roadmap: - First patch introduces clear_bhb_long_loop() for processors with larger branch history tables. - Second patch replaces IBPB on exit-to-userspace with branch history clearing sequence. Below is the iPerf data for transfer between guest and host, comparing IBPB and BHB-clear mitigation. BHB-clear shows performance improvement over IBPB in most cases. Platform: Emerald Rapids Baseline: vmscape=off (..._pN below mean N parallel connections) | iPerf user-net | IBPB | BHB Clear | |----------------|---------|-----------| | UDP 1-vCPU_p1 | -12.5% | 1.3% | | TCP 1-vCPU_p1 | -10.4% | -1.5% | | TCP 1-vCPU_p1 | -7.5% | -3.0% | | UDP 4-vCPU_p16 | -3.7% | -3.7% | | TCP 4-vCPU_p4 | -2.9% | -1.4% | | UDP 4-vCPU_p4 | -0.6% | 0.0% | | TCP 4-vCPU_p4 | 3.5% | 0.0% | | iPerf bridge-net | IBPB | BHB Clear | |------------------|---------|-----------| | UDP 1-vCPU_p1 | -9.4% | -0.4% | | TCP 1-vCPU_p1 | -3.9% | -0.5% | | UDP 4-vCPU_p16 | -2.2% | -3.8% | | TCP 4-vCPU_p4 | -1.0% | -1.0% | | TCP 4-vCPU_p4 | 0.5% | 0.5% | | UDP 4-vCPU_p4 | 0.0% | 0.9% | | TCP 1-vCPU_p1 | 0.0% | 0.9% | | iPerf vhost-net | IBPB | BHB Clear | |-----------------|---------|-----------| | UDP 1-vCPU_p1 | -4.3% | 1.0% | | TCP 1-vCPU_p1 | -3.8% | -0.5% | | TCP 1-vCPU_p1 | -2.7% | -0.7% | | UDP 4-vCPU_p16 | -0.7% | -2.2% | | TCP 4-vCPU_p4 | -0.4% | 0.8% | | UDP 4-vCPU_p4 | 0.4% | -0.7% | | TCP 4-vCPU_p4 | 0.0% | 0.6% | [1] https://comsec.ethz.ch/research/microarch/vmscape-exposing-and-exploiting-incomplete-branch-predictor-isolation-in-cloud-environments/ --- Pawan Gupta (2): x86/bhi: Add BHB clearing for CPUs with larger branch history x86/vmscape: Replace IBPB with branch history clear on exit to userspace Documentation/admin-guide/hw-vuln/vmscape.rst | 8 +++++ Documentation/admin-guide/kernel-parameters.txt | 4 ++- arch/x86/entry/entry_64.S | 47 ++++++++++++++++++------- arch/x86/include/asm/cpufeatures.h | 1 + arch/x86/include/asm/entry-common.h | 12 ++++--- arch/x86/include/asm/nospec-branch.h | 5 ++- arch/x86/kernel/cpu/bugs.c | 44 ++++++++++++++++------- arch/x86/kvm/x86.c | 5 +-- 8 files changed, 92 insertions(+), 34 deletions(-) --- base-commit: 4ea5af08590825c79ba2f146482ed54443e22c28 change-id: 20250916-vmscape-bhb-d7d469977f2f Best regards, -- Pawan From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f47.google.com (mail-ej1-f47.google.com [209.85.218.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3E42E86323 for ; Mon, 29 Sep 2025 05:12:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.47 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1759122728; cv=none; b=TY5RNJkcvH4dd22e6RLo7U07WFrxm2JloSTItCl7SvL51JjrfrqA/eR0KBm32BGQ4Sl9b4Z4SVA0zLJcGRqopULOWy7ynjcKsCQxag5mdO8K2BJPpY16hGFv9f3TIdPJuOiNbrT3S29dTZ+IJxR1Jcb4Wr1jkHy1FRBLVMhMfTg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1759122728; c=relaxed/simple; bh=0XTRWZOjXqYW6GqQmb1jA9TX+kNpX4Zm5F9lrOh6K5c=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type:Content-Disposition; b=HS8nKsUidnk7viY5MTX5GHAt03uWwiaf4fXOdNKvd/V76gw7dhEKHBEWY/J4na47sB5DS+v1v6/4oIZ1fN7aqfnpw/tUtpM2Kj/52ZwZge8215Fn4DlZ1/6FUWMNx+dmZUJMUvaSMF+6bW0RE0t+KGiPHAfd5yNpzrUDw7BUkxE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com; spf=pass smtp.mailfrom=ionos.com; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b=KmkKHAqe; arc=none smtp.client-ip=209.85.218.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=ionos.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ionos.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ionos.com header.i=@ionos.com header.b="KmkKHAqe" Received: by mail-ej1-f47.google.com with SMTP id a640c23a62f3a-b40884aeaf4so1450566b.0 for ; Sun, 28 Sep 2025 22:12:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ionos.com; s=google; t=1759122724; x=1759727524; darn=vger.kernel.org; h=content-transfer-encoding:content-disposition:mime-version :list-unsubscribe:list-subscribe:list-id:precedence:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to; bh=RyDjxJS1pH40ad63X5Di6by1390Eb9+O2bEzEpM7efE=; b=KmkKHAqe/oYSALsUWogPICpNF/GnQOKXUvJDupoSbx0Zam1LAQ0YmO5Qe557DE08M/ LkmcInUx7/BwH/5q0yMMX+4dOlwc0gJh1alKKu24+czwpjW9XaoD9Gs3vpDdWpYJQxow xkcBoNB+X+dAtPe3V8GhVPTTw1mkM1oosw6wbTKWjS4zef81YCHAp5QDteDMUsycFQ0q jIAVPZgqo0knm00e9IKOWlAY0v6vROOfk/ep4Ja+0VHlYMPIqu1eJMM6IEfRP545ZoNq oUFbT7DZr51N8H+GxWtlpZZyvMu8RxVoqe+hbrJ9ytV2IKLtIXHbwkgcjNtK1aswdLh3 3kuA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1759122724; x=1759727524; h=content-transfer-encoding:content-disposition:mime-version :list-unsubscribe:list-subscribe:list-id:precedence:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=RyDjxJS1pH40ad63X5Di6by1390Eb9+O2bEzEpM7efE=; b=KOUeg4UVI80dE7+AeTH2UMx4umfDLZAQPU0Zl2q9pTBA3kwz9sTNTQ3TFeTgdnYxfv kLELQ5UmgMdai+DnRD35ZBxIMUgXIFYTVPIgKQRRCipHVppMT402eG8pMVDg6i5NLRNX 8dD5kitH5X9wNYnHUzLdISO8Tykb5UX3LqB3cMMrJwTtW23hS6lJwbnOqXZAT6f4ZUVB R+Mw2IsyNqJZCkrZ+tM22GHcJeejlu5wEWItMfFKxWL3b6pocfIt0+VMPzU/74sJiQC5 M0oOxr/bKYRFFMNKGCWKz05LxxsAxkGy/LpkDmqFfDOfuql4pC0vk/8Tfu21lS0HqOtd DlJQ== X-Forwarded-Encrypted: i=1; AJvYcCWTa4NZwpSD6FEfUhuzp5BTFsm5r0YfPkg/9TxEIEB1npslh0IP16bwEB+7Tpz8aM5KpThVXyzXl8TmgS0=@vger.kernel.org X-Gm-Message-State: AOJu0YyMtC9EacG7sjM3pyzOYsrzO7nbRd0UVgBM6GY0bNtqlzOczTh1 KprOj194ByklPy0BgvoolfuYnlNkYZq/hRTx3RATMfmkUEx05Tyen7j8MoHR4IAGzGz6AX0XsW6 MYjb4dzY= X-Gm-Gg: ASbGncuFYHSZs860fG4MvOLuX83Cy2VBkqbRrVgk2GRCMbkAgY4rjm71vKnq4rQV6Hq NhdN20zJhduuH3oaX33T4bwGBp9aNcDcMg2KclDyGAmdwiFj19X/TExDBygSij+U7KRQ/bd3vZu X3LRmQ0cLVvvqwNmjt3+LirEf/jYN2JsQSrLTRz18cpzZBNVkNN38Q20o02J/cgNI/aFHA3VlO6 xH0fXuQdTREBqhDwcP5oIcbfjNkEWt5sqpUkQ87UknCa858zYBWAUtDT/wr7xOdHKrgerqaVECh pfL8eff3VZgqG2Bq7IenfOvXiUJ2taxFcZ18OYbiZnWsQnLhdRR8zn8UUOVldQzJH998NY1VPDN rKRH18aq9Eh+P4DDmHvXN5qGoBU4tAaWh6tCyFPNKw9Y= X-Google-Smtp-Source: AGHT+IGJrG5UeHbZ1lxXkb4X5YIcyHBYAq5V/R7Uf6AS3qWqMZLonPpzBVytosQVDGMiGJP+Qer4Ug== X-Received: by 2002:a17:907:96a1:b0:b04:7f7f:4d7a with SMTP id a640c23a62f3a-b34beca15e3mr841408166b.10.1759122724503; Sun, 28 Sep 2025 22:12:04 -0700 (PDT) Received: from lb02065.fritz.box ([2001:9e8:146c:c500:c2f7:bbda:f199:5aab]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-b3a835ca898sm420104466b.60.2025.09.28.22.12.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 28 Sep 2025 22:12:04 -0700 (PDT) From: Jack Wang To: pawan.kumar.gupta@linux.intel.com, x86@kernel.org, "H. Peter Anvin" , Josh Poimboeuf , David Kaplan , Sean Christopherson , Paolo Bonzini Cc: asit.k.mallick@intel.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org, tao1.zhang@intel.com Subject: [PATCH 0/2] VMSCAPE optimization for BHI variant Date: Mon, 29 Sep 2025 07:12:03 +0200 Message-ID: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> References: <20250924-vmscape-bhb-v1-0-da51f0e1934d@linux.intel.com> X-Change-ID: 20250916-vmscape-bhb-d7d469977f2f X-Mailer: b4 0.14.2 Precedence: bulk Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: 8bit Message-ID: <20250929051203.zjnRlX_Axh4TavzD2JP8w2uIfyHjPCUHU-twgXy-RMI@z> From: Pawan Gupta Hi Pawan, Thx for the patches, I tested them on our Intel SierraForest machine with fio 4k randread/randwrite from guest, qemu virtio-blk, noticed nice performance improvement comparing to the default IBPB before exit to userspace mitigation. eg with default IBPB mitigation fio gets 204k IOPS, with this new Clear BHB before exit to userspace gets 323k IOPS. Thx!