From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Cyrus-Session-Id: sloti22d1t05-3480010-1516872356-2-14212962376544533476 X-Sieve: CMU Sieve 3.0 X-Spam-known-sender: no X-Spam-score: 0.0 X-Spam-hits: BAYES_00 -1.9, HEADER_FROM_DIFFERENT_DOMAINS 0.25, RCVD_IN_DNSWL_HI -5, T_RP_MATCHES_RCVD -0.01, LANGUAGES en, BAYES_USED global, SA_VERSION 3.4.0 X-Spam-source: IP='209.132.180.67', Host='vger.kernel.org', Country='US', FromHeader='com', MailFrom='org' X-Spam-charsets: plain='UTF-8' X-Resolved-to: greg@kroah.com X-Delivered-to: greg@kroah.com X-Mail-from: stable-owner@vger.kernel.org ARC-Seal: i=1; a=rsa-sha256; cv=none; d=messagingengine.com; s=arctest; t=1516872355; b=MGR+y5HTL+kSUkJy0IrYLZqbJVIwtJ0mIp81i15Y1CddPEz elqX5y+T9PMelGz3Orq79CdkZeoHtqe7MmWHSd5QamzYN6uk0Km4rqWBgRPO47FG nPJgPJt0aeS9qiyWpscxkF8m5s6qyLP0TEVPL702s1MgMHgyvQ+NR5MuEWoK5JtB 636ovQTcJxvyCT2iXlPJLOhZQ8U5qgQxShWgY+0T44X3WL/hPb3bPyUjSEq7XYeo 0Q/wQrR5UXF/gPcsb+ARaVGP9XX6IPJrnmppwokdND/LLLykHTqQ8IQHl+f4L8YP 8s49riNM/KRlhooMzoJIy7VrFW56yMRs4K1rXVA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=mime-version:message-id:date:from:to:cc :subject:content-type:content-transfer-encoding:sender:list-id; s=arctest; t=1516872355; bh=KfjfnuYCSkwzvp+YXX6ynVXW4f56oqk8QN0 RxrAavgM=; b=IOsJJF843Zxo9efe68b5dq3I61BGS/ipdl5/nEPZRiqkG/VBX31 mEoHpcskDqv1e0AWAgVuq4SErnU7tNSxCpnXgb3ObSgylHYEk2hJ0eV0UDYdgnWD o0zR7klJpPyHWBEF3lXd6uFbfXEsGy/SMP4kzQmPpqi1Psd+SKKM/q4Uk1M6llJd wqp8RKDe2PXAQz0DOrEuKtyAUfwttovHmpUVtB7rB3Ne3TjgT3vkwB7eUBW8FZ3O ZsZoKTviaIZZTo8USasFD66t95ncE1fCzGyNWaPyGgpX5lOVNqaYZLrn867RSa/r dvMmqge1YRBfhVzFLocpATC1SqX3RfbVVbw== ARC-Authentication-Results: i=1; mx5.messagingengine.com; arc=none (no signatures found); dkim=pass (2048-bit rsa key sha256) header.d=oracle.com header.i=@oracle.com header.b=Es53RDOK x-bits=2048 x-keytype=rsa x-algorithm=sha256 x-selector=corp-2017-10-26; dmarc=pass (p=none,has-list-id=yes,d=none) header.from=oracle.com; iprev=pass policy.iprev=209.132.180.67 (vger.kernel.org); spf=none smtp.mailfrom=stable-owner@vger.kernel.org smtp.helo=vger.kernel.org; x-aligned-from=fail; x-ptr=pass x-ptr-helo=vger.kernel.org x-ptr-lookup=vger.kernel.org; x-return-mx=pass smtp.domain=vger.kernel.org smtp.result=pass smtp_org.domain=kernel.org smtp_org.result=pass smtp_is_org_domain=no header.domain=oracle.com header.result=pass header_is_org_domain=yes Authentication-Results: mx5.messagingengine.com; arc=none (no signatures found); dkim=pass (2048-bit rsa key sha256) header.d=oracle.com header.i=@oracle.com header.b=Es53RDOK x-bits=2048 x-keytype=rsa x-algorithm=sha256 x-selector=corp-2017-10-26; dmarc=pass (p=none,has-list-id=yes,d=none) header.from=oracle.com; iprev=pass policy.iprev=209.132.180.67 (vger.kernel.org); spf=none smtp.mailfrom=stable-owner@vger.kernel.org smtp.helo=vger.kernel.org; x-aligned-from=fail; x-ptr=pass x-ptr-helo=vger.kernel.org x-ptr-lookup=vger.kernel.org; x-return-mx=pass smtp.domain=vger.kernel.org smtp.result=pass smtp_org.domain=kernel.org smtp_org.result=pass smtp_is_org_domain=no header.domain=oracle.com header.result=pass header_is_org_domain=yes Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751633AbeAYJZb (ORCPT ); Thu, 25 Jan 2018 04:25:31 -0500 Received: from userp2130.oracle.com ([156.151.31.86]:42082 "EHLO userp2130.oracle.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751735AbeAYJZ0 (ORCPT ); Thu, 25 Jan 2018 04:25:26 -0500 MIME-Version: 1.0 Message-ID: <4693d8ab-1c86-44b6-b24f-009ee8766c1e@default> Date: Thu, 25 Jan 2018 01:25:18 -0800 (PST) From: Liran Alon To: Cc: , , , , Subject: Re: [PATCH AUTOSEL for 4.14 006/100] KVM: nVMX/nSVM: Don't intercept #UD when running L2 X-Mailer: Zimbra on Oracle Beehive Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline X-Proofpoint-Virus-Version: vendor=nai engine=5900 definitions=8784 signatures=668655 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 suspectscore=1 malwarescore=0 phishscore=0 bulkscore=0 spamscore=0 mlxscore=0 mlxlogscore=999 adultscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.0.1-1711220000 definitions=main-1801250130 Sender: stable-owner@vger.kernel.org X-Mailing-List: stable@vger.kernel.org X-getmail-retrieved-from-mailbox: INBOX X-Mailing-List: linux-kernel@vger.kernel.org List-ID: ----- Alexander.Levin@microsoft.com wrote: > From: Liran Alon >=20 > [ Upstream commit ac9b305caa0df6f5b75d294e4b86c1027648991e ] >=20 > When running L2, #UD should be intercepted by L1 or just forwarded > directly to L2. It should not reach L0 x86 emulator. > Therefore, set intercept for #UD only based on L1 exception-bitmap. >=20 > Also add WARN_ON_ONCE() on L0 #UD intercept handlers to make sure > it is never reached while running L2. >=20 > This improves commit ae1f57670703 ("KVM: nVMX: Do not emulate #UD > while > in guest mode") by removing an unnecessary exit from L2 to L0 on #UD > when L1 doesn't intercept it. >=20 > In addition, SVM L0 #UD intercept handler doesn't handle correctly > the > case it is raised from L2. In this case, it should forward the #UD to > guest instead of x86 emulator. As done in VMX #UD intercept handler. > This commit fixes this issue as-well. >=20 > Signed-off-by: Liran Alon > Reviewed-by: Nikita Leshenko > Reviewed-by: Konrad Rzeszutek Wilk > Signed-off-by: Konrad Rzeszutek Wilk > Reviewed-by: Paolo Bonzini > Reviewed-by: Wanpeng Li > Signed-off-by: Radim Kr=C4=8Dm=C3=A1=C5=99 > Signed-off-by: Sasha Levin > --- > arch/x86/kvm/svm.c | 9 ++++++++- > arch/x86/kvm/vmx.c | 9 ++++----- > 2 files changed, 12 insertions(+), 6 deletions(-) >=20 > diff --git a/arch/x86/kvm/svm.c b/arch/x86/kvm/svm.c > index 6a8284f72328..c8be4e6d365b 100644 > --- a/arch/x86/kvm/svm.c > +++ b/arch/x86/kvm/svm.c > @@ -362,6 +362,7 @@ static void recalc_intercepts(struct vcpu_svm > *svm) > { > =09struct vmcb_control_area *c, *h; > =09struct nested_state *g; > +=09u32 h_intercept_exceptions; > =20 > =09mark_dirty(svm->vmcb, VMCB_INTERCEPTS); > =20 > @@ -372,9 +373,14 @@ static void recalc_intercepts(struct vcpu_svm > *svm) > =09h =3D &svm->nested.hsave->control; > =09g =3D &svm->nested; > =20 > +=09/* No need to intercept #UD if L1 doesn't intercept it */ > +=09h_intercept_exceptions =3D > +=09=09h->intercept_exceptions & ~(1U << UD_VECTOR); > + > =09c->intercept_cr =3D h->intercept_cr | g->intercept_cr; > =09c->intercept_dr =3D h->intercept_dr | g->intercept_dr; > -=09c->intercept_exceptions =3D h->intercept_exceptions | > g->intercept_exceptions; > +=09c->intercept_exceptions =3D > +=09=09h_intercept_exceptions | g->intercept_exceptions; > =09c->intercept =3D h->intercept | g->intercept; > } > =20 > @@ -2189,6 +2195,7 @@ static int ud_interception(struct vcpu_svm > *svm) > { > =09int er; > =20 > +=09WARN_ON_ONCE(is_guest_mode(&svm->vcpu)); > =09er =3D emulate_instruction(&svm->vcpu, EMULTYPE_TRAP_UD); > =09if (er =3D=3D EMULATE_USER_EXIT) > =09=09return 0; > diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c > index ef16cf0f7cfd..36628ed362d8 100644 > --- a/arch/x86/kvm/vmx.c > +++ b/arch/x86/kvm/vmx.c > @@ -1891,7 +1891,7 @@ static void update_exception_bitmap(struct > kvm_vcpu *vcpu) > { > =09u32 eb; > =20 > -=09eb =3D (1u << PF_VECTOR) | (1u << UD_VECTOR) | (1u << MC_VECTOR) | > +=09eb =3D (1u << PF_VECTOR) | (1u << MC_VECTOR) | > =09 (1u << DB_VECTOR) | (1u << AC_VECTOR); > =09if ((vcpu->guest_debug & > =09 (KVM_GUESTDBG_ENABLE | KVM_GUESTDBG_USE_SW_BP)) =3D=3D > @@ -1909,6 +1909,8 @@ static void update_exception_bitmap(struct > kvm_vcpu *vcpu) > =09 */ > =09if (is_guest_mode(vcpu)) > =09=09eb |=3D get_vmcs12(vcpu)->exception_bitmap; > +=09else > +=09=09eb |=3D 1u << UD_VECTOR; > =20 > =09vmcs_write32(EXCEPTION_BITMAP, eb); > } > @@ -5919,10 +5921,7 @@ static int handle_exception(struct kvm_vcpu > *vcpu) > =09=09return 1; /* already handled by vmx_vcpu_run() */ > =20 > =09if (is_invalid_opcode(intr_info)) { > -=09=09if (is_guest_mode(vcpu)) { > -=09=09=09kvm_queue_exception(vcpu, UD_VECTOR); > -=09=09=09return 1; > -=09=09} > +=09=09WARN_ON_ONCE(is_guest_mode(vcpu)); > =09=09er =3D emulate_instruction(vcpu, EMULTYPE_TRAP_UD); > =09=09if (er =3D=3D EMULATE_USER_EXIT) > =09=09=09return 0; > --=20 > 2.11.0 Just wanted stable maintainers to note that Jim, Paolo & myself decided eve= ntually to revert this commit along with commit ae1f57670703 on upstream KV= M. However, it is true that this commit makes commit ae1f57670703 more comp= lete. Therefore we have 2 options here: 1) Apply this backport and sometime in the future also apply the reverts of= both these commits with Paolo's commit which reverts them. 2) Don't apply this backport but do revert commit ae1f57670703. -Liran