From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-9.6 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,NICE_REPLY_A,SPF_HELO_NONE,SPF_PASS, USER_AGENT_SANE_1 autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id A3755C4727E for ; Wed, 23 Sep 2020 16:59:46 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by mail.kernel.org (Postfix) with ESMTP id 5488B20BED for ; Wed, 23 Sep 2020 16:59:46 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="GM1e3aHk" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726647AbgIWQ7p (ORCPT ); Wed, 23 Sep 2020 12:59:45 -0400 Received: from us-smtp-2.mimecast.com ([205.139.110.61]:44375 "EHLO us-smtp-delivery-1.mimecast.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1726424AbgIWQ7o (ORCPT ); Wed, 23 Sep 2020 12:59:44 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1600880382; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=vmVARHYAsE9tPU6eUJfulnvnl82Jvse1QKnk4N0AG3M=; b=GM1e3aHkSxWv0Km+LIQqjMbxOt7O1ur7EOdtVsv7NGrj9lYR2trI1oswdgDEwONWoAm4Lr BpFgI9DcCXWYrLkgI6GN7lsGuZB3QPyE18JvfPGBTW/EFFGP7UVUM7liZ6SAvkYbPuulEp onYuvbe21BA3XbXakGeiLfRrDn2oV/M= Received: from mail-wr1-f71.google.com (mail-wr1-f71.google.com [209.85.221.71]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-182-7u79O3-pPWqNdX4-_n2xBw-1; Wed, 23 Sep 2020 12:59:40 -0400 X-MC-Unique: 7u79O3-pPWqNdX4-_n2xBw-1 Received: by mail-wr1-f71.google.com with SMTP id l9so64340wrq.20 for ; Wed, 23 Sep 2020 09:59:40 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=vmVARHYAsE9tPU6eUJfulnvnl82Jvse1QKnk4N0AG3M=; b=XJyfcZx4m7QBiOPj/uQUg8kDhvh+7dADaEA3lIo4gor4i0A2mq5asgrYQwo43jjzZI UK9BWCQMASuyk/ofkxKSIfWUuK18eye7OgmW4SkA7blnDYs8ZR7CnqIs1SbHO23rlD4l GzDh11kYUBT4iMyf728h5E+ionV7l/c03xVmOT3nbAhBqe80bhzMaO4bpAKPtdHZT/lj txzt7YUpCO0VCgjEvWFOw030699JO24IC8sJh02Umk/lwNx/0ScN7orfkm5MuASBXhzc PlOTYrPtFW+JKLVMsK6cGESqVNQCf+1jLcw3xiNC4DkOo+QXZt8h3dDP/78B03F7xiyH Dk6Q== X-Gm-Message-State: AOAM530O/Isqcf2u6RO86apNex7I2go/EDqx3PEJMN/VSmXJrRsWqrKf zAEddINeKFEzepv7Nv8ddncBjx0HSRKYRI3SdTH/Bm/1wknr9VNXXBB6BtOSMys56K+7TPgGqmt Xa1SrQkYGkYsYgqRb11HW79Uk X-Received: by 2002:adf:dd82:: with SMTP id x2mr609816wrl.419.1600880378592; Wed, 23 Sep 2020 09:59:38 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxCuDHXBEAcHyIB5Vvs3lEyQ6sVJqsATi+lSmVZHEx6qix26/NPEU4yz7D8Ev4AcSVYp4csdA== X-Received: by 2002:adf:dd82:: with SMTP id x2mr609777wrl.419.1600880378347; Wed, 23 Sep 2020 09:59:38 -0700 (PDT) Received: from ?IPv6:2001:b07:6468:f312:15f1:648d:7de6:bad9? ([2001:b07:6468:f312:15f1:648d:7de6:bad9]) by smtp.gmail.com with ESMTPSA id x10sm401353wmi.37.2020.09.23.09.59.36 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 23 Sep 2020 09:59:37 -0700 (PDT) Subject: Re: [PATCH] KVM: SVM: Mark SEV launch secret pages as dirty. To: Sean Christopherson , Cfir Cohen Cc: "kvm @ vger . kernel . org" , Lendacky Thomas , Singh Brijesh , Grimm Jon , David Rientjes , Vitaly Kuznetsov , Wanpeng Li , Jim Mattson , Joerg Roedel , Thomas Gleixner , Ingo Molnar , Borislav Petkov , "H . Peter Anvin" , x86@kernel.org, linux-kernel@vger.kernel.org References: <20200807012303.3769170-1-cfir@google.com> <20200919045505.GC21189@sjchrist-ice> From: Paolo Bonzini Message-ID: <5ac77c46-88b4-df45-4f02-72adfb096262@redhat.com> Date: Wed, 23 Sep 2020 18:59:36 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.11.0 MIME-Version: 1.0 In-Reply-To: <20200919045505.GC21189@sjchrist-ice> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 19/09/20 06:55, Sean Christopherson wrote: > Side topic, while I love the comment (I do, honestly) regarding in-place > encryption, this is the fourth? instance of the same 4-line comment (6 lines > if you count the /* and */. Maybe it's time to do something like > > /* LAUNCH_SECRET does in-place encryption, see sev_clflush_pages(). */ > > and then have the main comment in sev_clflush_pages(). With the addition of > X86_FEATURE_SME_COHERENT, there's even a fantastic location for the comment: Two of the three instances are a bit different though. What about this which at least shortens the comment to 2 fewer lines: diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index bb0e89c79a04..7b11546e65ba 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -446,10 +446,8 @@ static int sev_launch_update_data(struct kvm *kvm, struct kvm_sev_cmd *argp) } /* - * The LAUNCH_UPDATE command will perform in-place encryption of the - * memory content (i.e it will write the same memory region with C=1). - * It's possible that the cache may contain the data with C=0, i.e., - * unencrypted so invalidate it first. + * Flush before LAUNCH_UPDATE encrypts pages in place, in case the cache + * contains the data that was written unencrypted. */ sev_clflush_pages(inpages, npages); @@ -805,10 +803,8 @@ static int sev_dbg_crypt(struct kvm *kvm, struct kvm_sev_cmd *argp, bool dec) } /* - * The DBG_{DE,EN}CRYPT commands will perform {dec,en}cryption of the - * memory content (i.e it will write the same memory region with C=1). - * It's possible that the cache may contain the data with C=0, i.e., - * unencrypted so invalidate it first. + * Flush before DBG_{DE,EN}CRYPT reads or modifies the pages, flush the + * destination too in case the cache contains its current data. */ sev_clflush_pages(src_p, 1); sev_clflush_pages(dst_p, 1); @@ -870,10 +866,8 @@ static int sev_launch_secret(struct kvm *kvm, struct kvm_sev_cmd *argp) return PTR_ERR(pages); /* - * The LAUNCH_SECRET command will perform in-place encryption of the - * memory content (i.e it will write the same memory region with C=1). - * It's possible that the cache may contain the data with C=0, i.e., - * unencrypted so invalidate it first. + * Flush before LAUNCH_SECRET encrypts pages in place, in case the cache + * contains the data that was written unencrypted. */ sev_clflush_pages(pages, n);