From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f202.google.com (mail-pl1-f202.google.com [209.85.214.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B0EAF402B9F for ; Fri, 29 May 2026 15:08:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780067309; cv=none; b=SY/BQALxAQ3asEaNNb0Vr3vDcRdVKN/yLcMAIx6J4E/eMsWqOg6tTbLlntrlbnW/JVWXUf3ehzSEkUoyOBKNCm2ZQBMV5h4tLH5G9zt6k3wrl7CGqNzFxBHeBBYkHfoBU3uolGwIxYTZ1Udp+Qe3I+2GhLqKAWPNurTNBDGMmLc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780067309; c=relaxed/simple; bh=fmtwqTBYkb6t5vw+7MpnJ0D/yvZROFNekcfkLoS9uAw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=s8HS0VFYB+a9+iDlsLBHYIMYHdEADgB1JOdYLG6U9skbaB7hJrkkQEvOX2yyIwHDIXgZRKHOeYoh7voCJvXp6tMYBkbbrKiug8itlooVGQaAqunFuWVtOSiye5eplN8i2chxCVq26CyKnGAHpi0+Su2A/OlJkfwYVXPVyyrf4kU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=rdHixLCX; arc=none smtp.client-ip=209.85.214.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="rdHixLCX" Received: by mail-pl1-f202.google.com with SMTP id d9443c01a7336-2bd6aeb3637so313114615ad.2 for ; Fri, 29 May 2026 08:08:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1780067307; x=1780672107; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=2eZ/5/NHYtlqNBUgYS8sS/KxrmMqlqE8QNmqFczaR90=; b=rdHixLCX61dil2+0N2A/tYy0wy2Yn191b+ZzoDAovSyX7g0g184O6J8KCPwJNMWEnh BoV+hHTMxc1vkcjeAVOHbZnoZhokpyiBvvK16SfbGYJ3QjyhErPpBNxztr+KRPvm8euw A3hX+ECenN+bpU+oZxgue0Lu3SYC51/edAT2wkFoFp5bBGW7IDqVfmkWtamHkRrSCcGU cB3t687aMts2gVKeSYWgyOPDlP1fwYXDs2borjN64W61oAHhxOEZcsvmnng7FAO00+du aiGPJ6NDbZGEqBQGAmoZqNR8CX1oJjMC0PZxRE8bRSs7bZtz6ASc3Gejy3Ja05UOk1Hz oTrg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780067307; x=1780672107; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=2eZ/5/NHYtlqNBUgYS8sS/KxrmMqlqE8QNmqFczaR90=; b=N278OzmNnuU9xHTpyY5ktNOU1LxL/1NmhyUzx6iP2rgluA5ElTlNWk6jaciwKBfFBa JWXQZq+SumhM3Tl6y5b3xSyyDKRkr3LSH3dZmhPjYjTqruVel7BvCcNL5MtTLLTZBfbx jEa+ZPK3sLus+69mTDLOE4pzdImFP7QxuNyo91tt5BR85VzPAQzIewrHGrR6GqS953+Y hee/7RKB86cQxJdpCyJfwkmNV9ru02h7KtFco8EltFZ9UNYq7K936/2pvxQd/D5e1L2L 7FnR7UVwM2jZMgDV1B48V+ZvqPZf4YRD0J4h4Kj6Mw1iAkwsGe2tntjMjwbndNZpfUgE fiPg== X-Forwarded-Encrypted: i=1; AFNElJ9JiwLBq5V+tVezkE63CevmLk7SRQ61MiJxg3iht3Qbxl90Qh8xha1FZL/kBKfCf+CMXSJoGWM73PZaj0o=@vger.kernel.org X-Gm-Message-State: AOJu0Yy7tJIOfLv3dO7QSvqWrPXOiC32pL7nektkb79jgVQ5w9sSIZYc SoykF/N1LMKmkyR0b8NkRxTGnrrUhUakpDBM/BdKtHfaqfIJkOXauQmaDbaM4OAK5Pl65A9t/Sn l5LLo3g== X-Received: from plau10.prod.google.com ([2002:a17:903:304a:b0:2ba:67f8:6257]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:c94c:b0:2bf:604:d5ad with SMTP id d9443c01a7336-2bf368904abmr2085275ad.37.1780067306314; Fri, 29 May 2026 08:08:26 -0700 (PDT) Reply-To: Sean Christopherson Date: Fri, 29 May 2026 08:08:24 -0700 In-Reply-To: <20260529144435.704127-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260529144435.704127-1-seanjc@google.com> X-Mailer: git-send-email 2.54.0.823.g6e5bcc1fc9-goog Message-ID: <20260529150824.714934-1-seanjc@google.com> Subject: [PATCH v4 43/47] x86/paravirt: Plumb a return code into __paravirt_set_sched_clock() From: Sean Christopherson To: Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Kiryl Shutsemau , Sean Christopherson , "K . Y . Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li , Ajay Kaher , Alexey Makhalov , Jan Kiszka , Andy Lutomirski , Peter Zijlstra , Juergen Gross , Daniel Lezcano , John Stultz Cc: "H . Peter Anvin" , Rick Edgecombe , Vitaly Kuznetsov , Broadcom internal kernel review list , Boris Ostrovsky , Stephen Boyd , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, linux-hyperv@vger.kernel.org, virtualization@lists.linux.dev, xen-devel@lists.xenproject.org, David Woodhouse , Tom Lendacky , Nikunj A Dadhania , David Woodhouse , Michael Kelley , Thomas Gleixner Content-Type: text/plain; charset="UTF-8" Add a return code to __paravirt_set_sched_clock() so that the kernel can reject attempts to use a PV sched_clock without breaking the caller. E.g. when running as a CoCo VM with a secure TSC, using a PV clock is generally undesirable. Note, kvmclock is the only PV clock that does anything "extra" beyond simply registering itself as sched_clock, i.e. is the only caller that needs to check the new return value. Reviewed-by: David Woodhouse Signed-off-by: Sean Christopherson --- arch/x86/include/asm/timer.h | 6 +++--- arch/x86/kernel/kvmclock.c | 9 ++++++--- arch/x86/kernel/tsc.c | 5 +++-- 3 files changed, 12 insertions(+), 8 deletions(-) diff --git a/arch/x86/include/asm/timer.h b/arch/x86/include/asm/timer.h index 96ae7feac47c..ca5c95d48c03 100644 --- a/arch/x86/include/asm/timer.h +++ b/arch/x86/include/asm/timer.h @@ -14,14 +14,14 @@ extern int no_timer_check; extern bool using_native_sched_clock(void); #ifdef CONFIG_PARAVIRT -void __init __paravirt_set_sched_clock(u64 (*func)(void), bool stable, - void (*save)(void), void (*restore)(void)); +int __init __paravirt_set_sched_clock(u64 (*func)(void), bool stable, + void (*save)(void), void (*restore)(void)); static __always_inline void paravirt_set_sched_clock(u64 (*func)(void), void (*save)(void), void (*restore)(void)) { - __paravirt_set_sched_clock(func, true, save, restore); + (void)__paravirt_set_sched_clock(func, true, save, restore); } #endif diff --git a/arch/x86/kernel/kvmclock.c b/arch/x86/kernel/kvmclock.c index 73fabfac2bc9..1336c24f59cf 100644 --- a/arch/x86/kernel/kvmclock.c +++ b/arch/x86/kernel/kvmclock.c @@ -310,10 +310,13 @@ static int kvmclock_setup_percpu(unsigned int cpu) static __init void kvm_sched_clock_init(bool stable) { + /* Ensure the offset is configured before making kvmclock visible! */ kvm_sched_clock_offset = kvm_clock_read(); - __paravirt_set_sched_clock(kvm_sched_clock_read, stable, - kvm_save_sched_clock_state, - kvm_restore_sched_clock_state); + + if (__paravirt_set_sched_clock(kvm_sched_clock_read, stable, + kvm_save_sched_clock_state, + kvm_restore_sched_clock_state)) + return; /* * The BSP's clock is managed via dedicated sched_clock save/restore diff --git a/arch/x86/kernel/tsc.c b/arch/x86/kernel/tsc.c index 6da0a3ac05c2..7bcf757bf551 100644 --- a/arch/x86/kernel/tsc.c +++ b/arch/x86/kernel/tsc.c @@ -280,8 +280,8 @@ bool using_native_sched_clock(void) return static_call_query(pv_sched_clock) == native_sched_clock; } -void __init __paravirt_set_sched_clock(u64 (*func)(void), bool stable, - void (*save)(void), void (*restore)(void)) +int __init __paravirt_set_sched_clock(u64 (*func)(void), bool stable, + void (*save)(void), void (*restore)(void)) { if (!stable) clear_sched_clock_stable(); @@ -289,6 +289,7 @@ void __init __paravirt_set_sched_clock(u64 (*func)(void), bool stable, static_call_update(pv_sched_clock, func); x86_platform.save_sched_clock_state = save; x86_platform.restore_sched_clock_state = restore; + return 0; } #else u64 sched_clock_noinstr(void) __attribute__((alias("native_sched_clock"))); -- 2.54.0.823.g6e5bcc1fc9-goog