From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F168721CFE0 for ; Thu, 9 Jan 2025 15:38:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.44 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736437123; cv=none; b=uAFcfA+4ghvKV8IiDxm/W2HHunFSDoHejeK2BPq8+XMjW7z0ZA3lE02CRsssOX0T59twpgXV/G/4mut4aO8w9/oLKyQcS2RhXD/4hAnz2isfJoCSngf2xe9k/6mQkTxsr+uzu3wbf0InI+uho6ndX6bb8RpcxUuaBJqj3zClFW0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1736437123; c=relaxed/simple; bh=LFdktPPjXhLTQhmFfmtdllkEcEDeVDSJl9EsWALqWCI=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=Y12irE993gnH3CZDvxw0mYRNcWmDMT0hgTS9uwgSWlQirJIbVSezD2Y1yg6FyKeN6jjbPxz9bPAYwG65vPww0wikpXu7PnUrB+7f6tjtJf3RFPgsPJeOVUtzrOLGL9JGeiY6K442tE05EiifWEDovgfPJUsczsm4yfIOX4pKi3w= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com; spf=pass smtp.mailfrom=suse.com; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b=M6FjxVlj; arc=none smtp.client-ip=209.85.128.44 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=suse.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=suse.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=suse.com header.i=@suse.com header.b="M6FjxVlj" Received: by mail-wm1-f44.google.com with SMTP id 5b1f17b1804b1-436202dd7f6so13422305e9.0 for ; Thu, 09 Jan 2025 07:38:39 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=suse.com; s=google; t=1736437118; x=1737041918; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=yLy325AUOiqV6ZCCFMYvVTZpyhigu94q9qDp0u9niZc=; b=M6FjxVljXfbrj5v8Hha8J7dWXianUb6zQcea9urEBT35qGQYqSgbsvLSrjiQ9HlGQa 6nZsDBOU7w3lZTYbtd/glK9evlt2cH/+U/NqxV8L+0zv9XuMs3bpASR1+iRf3g7n7GDX tv+9FcByK9aIQzmw48RYjoURGQxbH85cCPY4ObMOABMCQYIZpSe3qInJMiV8lBj5Q0cA jx+SsFQb5Hv4bXha42mE0I/NY/ObtI+EBjV4Xz73OoHU857WJLiJDEl6OI6zCOjTtk6q rq0xTz5BontvtO1qX/qutR6az9FOPQOpKWxKY9K+CpID1x1K3OhREbIpm9hq7ijtfTaz cSSw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1736437118; x=1737041918; h=content-transfer-encoding:in-reply-to:content-language:from :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=yLy325AUOiqV6ZCCFMYvVTZpyhigu94q9qDp0u9niZc=; b=fpYIgrXEH6S0oiZI8K19ryVyAFNZ9uOObwY8ycQ6ixJHqgdGpZl9yTJbag47kGLZwR l6NA6xx5ZXurzDPzA8JAwt72oEiQgBC3TIpch/Oc7aE8XNVYhn3elXr+R1u8++JAEoGS J4o0O8CLl+W/KLl/mb9pqY2v503S4/0MZCzBg4iW0S1KYpx6YKN0lwhHu63kZ0QpbDjF MlGcqtTxNtlT5ZRfBSbPejRIio04rGndGKQfTWfIZKnYmu4UmzQWnfQZmDD9wtxL300t tlHhgXK6oBaQLNd5mfupndmMfkBThLozuG0Yx4wJQar3NImXAasCbLtnXJjXZbblt87n oBLA== X-Forwarded-Encrypted: i=1; AJvYcCW0dYKQv5sQxVMwwS6VLAF7uDvcRrAe49q0+jR+7VqCVDH+AlZ80ywVMby8ltRY9kopOId2dYQBCM35/Ls=@vger.kernel.org X-Gm-Message-State: AOJu0Yx+90cKqbZ11xEWZh7oJus0907AUTsEbuKpSJEfLgpoNkvgWeTa NG6IKtjsTO/l0AJaLHU8/O/JxAyEDW+NUSjORylR7B8AJ1ky9bpe83Fp7eZOdbg= X-Gm-Gg: ASbGncuSVyWVN/37FZlM7f7Gva9gfwYLuPZsdy3pYlka+B05bvNgKqmL+87Cvbh6Uuz A3yWb3CyGASjekD/glFuh58GnhCF5B+1AuwJCFgxlhlwYkB4oxplxoVxM43GscRwwtb2EhzanVi bmi4Y5GX8fN8PBLVZRqrS6Eh9T6t3+XfPVyp/rG4ayp91AbbaYdRsxjjsIqzK5D+7569e5y79nQ uBHGMZFcH3tQK+/4T04Eywrt93qMqMF6CiJw16cLRZS5/d+0PM7eMIWV7XfBQ== X-Google-Smtp-Source: AGHT+IEiniSHvExZnT2lQmtb7twwNs+mSHQUVNaNPEf+nv+GbFJKHMawc6EzKMGwxqNYmMel3oSjnQ== X-Received: by 2002:adf:a19b:0:b0:38a:88a0:2235 with SMTP id ffacd0b85a97d-38a88a02276mr5145562f8f.37.1736437118231; Thu, 09 Jan 2025 07:38:38 -0800 (PST) Received: from [192.168.0.20] ([212.21.159.176]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-436e9e03ffcsm24419325e9.20.2025.01.09.07.38.37 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 09 Jan 2025 07:38:38 -0800 (PST) Message-ID: <5d1d421c-3123-455e-aba1-1baf7f12e89e@suse.com> Date: Thu, 9 Jan 2025 17:38:36 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH 01/16] KVM: TDX: Add support for find pending IRQ in a protected local APIC To: Binbin Wu , pbonzini@redhat.com, seanjc@google.com, kvm@vger.kernel.org Cc: rick.p.edgecombe@intel.com, kai.huang@intel.com, adrian.hunter@intel.com, reinette.chatre@intel.com, xiaoyao.li@intel.com, tony.lindgren@linux.intel.com, isaku.yamahata@intel.com, yan.y.zhao@intel.com, chao.gao@intel.com, linux-kernel@vger.kernel.org References: <20241209010734.3543481-1-binbin.wu@linux.intel.com> <20241209010734.3543481-2-binbin.wu@linux.intel.com> From: Nikolay Borisov Content-Language: en-US In-Reply-To: <20241209010734.3543481-2-binbin.wu@linux.intel.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 9.12.24 г. 3:07 ч., Binbin Wu wrote: > From: Sean Christopherson > > Add flag and hook to KVM's local APIC management to support determining > whether or not a TDX guest as a pending IRQ. For TDX vCPUs, the virtual > APIC page is owned by the TDX module and cannot be accessed by KVM. As a > result, registers that are virtualized by the CPU, e.g. PPR, cannot be > read or written by KVM. To deliver interrupts for TDX guests, KVM must > send an IRQ to the CPU on the posted interrupt notification vector. And > to determine if TDX vCPU has a pending interrupt, KVM must check if there > is an outstanding notification. > > Return "no interrupt" in kvm_apic_has_interrupt() if the guest APIC is > protected to short-circuit the various other flows that try to pull an > IRQ out of the vAPIC, the only valid operation is querying _if_ an IRQ is > pending, KVM can't do anything based on _which_ IRQ is pending. > > Intentionally omit sanity checks from other flows, e.g. PPR update, so as > not to degrade non-TDX guests with unnecessary checks. A well-behaved KVM > and userspace will never reach those flows for TDX guests, but reaching > them is not fatal if something does go awry. > > Note, this doesn't handle interrupts that have been delivered to the vCPU > but not yet recognized by the core, i.e. interrupts that are sitting in > vmcs.GUEST_INTR_STATUS. Querying that state requires a SEAMCALL and will > be supported in a future patch. > > Signed-off-by: Sean Christopherson > Signed-off-by: Isaku Yamahata > Signed-off-by: Binbin Wu > --- > TDX interrupts breakout: > - Dropped vt_protected_apic_has_interrupt() with KVM_BUG_ON(), wire in > tdx_protected_apic_has_interrupt() directly. (Rick) > - Add {} on else in vt_hardware_setup() > --- > arch/x86/include/asm/kvm-x86-ops.h | 1 + > arch/x86/include/asm/kvm_host.h | 1 + > arch/x86/kvm/irq.c | 3 +++ > arch/x86/kvm/lapic.c | 3 +++ > arch/x86/kvm/lapic.h | 2 ++ > arch/x86/kvm/vmx/main.c | 3 +++ > arch/x86/kvm/vmx/tdx.c | 6 ++++++ > arch/x86/kvm/vmx/x86_ops.h | 2 ++ > 8 files changed, 21 insertions(+) > > diff --git a/arch/x86/include/asm/kvm-x86-ops.h b/arch/x86/include/asm/kvm-x86-ops.h > index ec1b1b39c6b3..d5faaaee6ac0 100644 > --- a/arch/x86/include/asm/kvm-x86-ops.h > +++ b/arch/x86/include/asm/kvm-x86-ops.h > @@ -114,6 +114,7 @@ KVM_X86_OP_OPTIONAL(pi_start_assignment) > KVM_X86_OP_OPTIONAL(apicv_pre_state_restore) > KVM_X86_OP_OPTIONAL(apicv_post_state_restore) > KVM_X86_OP_OPTIONAL_RET0(dy_apicv_has_pending_interrupt) > +KVM_X86_OP_OPTIONAL(protected_apic_has_interrupt) > KVM_X86_OP_OPTIONAL(set_hv_timer) > KVM_X86_OP_OPTIONAL(cancel_hv_timer) > KVM_X86_OP(setup_mce) > diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h > index 37dc7edef1ca..32c7d58a5d68 100644 > --- a/arch/x86/include/asm/kvm_host.h > +++ b/arch/x86/include/asm/kvm_host.h > @@ -1811,6 +1811,7 @@ struct kvm_x86_ops { > void (*apicv_pre_state_restore)(struct kvm_vcpu *vcpu); > void (*apicv_post_state_restore)(struct kvm_vcpu *vcpu); > bool (*dy_apicv_has_pending_interrupt)(struct kvm_vcpu *vcpu); > + bool (*protected_apic_has_interrupt)(struct kvm_vcpu *vcpu); > > int (*set_hv_timer)(struct kvm_vcpu *vcpu, u64 guest_deadline_tsc, > bool *expired); > diff --git a/arch/x86/kvm/irq.c b/arch/x86/kvm/irq.c > index 63f66c51975a..f0644d0bbe11 100644 > --- a/arch/x86/kvm/irq.c > +++ b/arch/x86/kvm/irq.c > @@ -100,6 +100,9 @@ int kvm_cpu_has_interrupt(struct kvm_vcpu *v) > if (kvm_cpu_has_extint(v)) > return 1; > > + if (lapic_in_kernel(v) && v->arch.apic->guest_apic_protected) > + return static_call(kvm_x86_protected_apic_has_interrupt)(v); > + > return kvm_apic_has_interrupt(v) != -1; /* LAPIC */ > } > EXPORT_SYMBOL_GPL(kvm_cpu_has_interrupt); > diff --git a/arch/x86/kvm/lapic.c b/arch/x86/kvm/lapic.c > index 65412640cfc7..684777c2f0a4 100644 > --- a/arch/x86/kvm/lapic.c > +++ b/arch/x86/kvm/lapic.c > @@ -2920,6 +2920,9 @@ int kvm_apic_has_interrupt(struct kvm_vcpu *vcpu) > if (!kvm_apic_present(vcpu)) > return -1; > > + if (apic->guest_apic_protected) > + return -1; > + > __apic_update_ppr(apic, &ppr); > return apic_has_interrupt_for_ppr(apic, ppr); > } > diff --git a/arch/x86/kvm/lapic.h b/arch/x86/kvm/lapic.h > index 1b8ef9856422..82355faf8c0d 100644 > --- a/arch/x86/kvm/lapic.h > +++ b/arch/x86/kvm/lapic.h > @@ -65,6 +65,8 @@ struct kvm_lapic { > bool sw_enabled; > bool irr_pending; > bool lvt0_in_nmi_mode; > + /* Select registers in the vAPIC cannot be read/written. */ > + bool guest_apic_protected; Can't this member be eliminated and instead is_td_vcpu() used as it stands currently that member is simply a proxy value for "is this a tdx vcpu"?