From: "Huang, Kai" <kai.huang@intel.com>
To: "seanjc@google.com" <seanjc@google.com>,
"Gao, Chao" <chao.gao@intel.com>
Cc: "dave.hansen@linux.intel.com" <dave.hansen@linux.intel.com>,
"x86@kernel.org" <x86@kernel.org>, "bp@alien8.de" <bp@alien8.de>,
"mingo@redhat.com" <mingo@redhat.com>,
"tglx@linutronix.de" <tglx@linutronix.de>,
"hpa@zytor.com" <hpa@zytor.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Subject: Re: [PATCH] KVM: VMX: Flush shadow VMCS on emergency reboot
Date: Mon, 14 Apr 2025 12:15:23 +0000 [thread overview]
Message-ID: <616212d3261c3c3213bced1fdb6b2f0982c55928.camel@intel.com> (raw)
In-Reply-To: <Z_lKE-GjP3WQrdkR@google.com>
On Fri, 2025-04-11 at 09:57 -0700, Sean Christopherson wrote:
> > >
> > > On a very related topic, doesn't SPR+ now flush the VMCS caches on VMXOFF? If
> >
> > Actually this behavior is not publicly documented.
>
> Well shoot. That should probably be remedied. Even if the behavior is guaranteed
> only on CPUs that support SEAM, _that_ detail should be documented. I'm not
> holding my breath on Intel allowing third party code in SEAM, but the mode _is_
> documented in the SDM, and so IMO, the SDM should also document how things like
> clearing the VMCS cache are supposed to work when there are VMCSes that "untrusted"
> software may not be able to access.
>
> > > that's going to be the architectural behavior going forward, will that behavior
> > > be enumerated to software? Regardless of whether there's software enumeration,
> > > I would like to have the emergency disable path depend on that behavior. In part
> > > to gain confidence that SEAM VMCSes won't screw over kdump, but also in light of
> > > this bug.
> >
> > I don't understand how we can gain confidence that SEAM VMCSes won't screw
> > over kdump.
>
> If KVM relies on VMXOFF to purge the VMCS cache, then it gives a measure of
> confidence that running TDX VMs won't leave behind SEAM VMCSes in the cache. KVM
> can't easily clear SEAM VMCSs, but IIRC, the memory can be "forcefully" reclaimed
> by paving over it with MOVDIR64B, at which point having VMCS cache entries for
> the memory would be problematic.
I am not sure why we need to use MOVDIR64B to clear SEAM VMCSes in kdump?
Regardless of whether we do that or not, IIUC there is no harm even we still
have SEAM VMCS cache entries in kdump:
They are associated with TDX private KeyID(s). Sudden write back of them
doesn't matter because when reading them from /proc/vmcore they are garbage
anyway. And IIUC no machine check (due to TD bit mismatch) will happen either.
next prev parent reply other threads:[~2025-04-14 12:15 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-03-24 14:08 Chao Gao
2025-03-31 23:17 ` Huang, Kai
2025-04-10 21:55 ` Sean Christopherson
2025-04-11 8:46 ` Chao Gao
2025-04-11 16:57 ` Sean Christopherson
2025-04-14 6:24 ` Xiaoyao Li
2025-04-14 12:15 ` Huang, Kai [this message]
2025-04-14 13:18 ` Chao Gao
2025-04-15 1:03 ` Sean Christopherson
2025-04-15 1:55 ` Chao Gao
2025-10-08 23:01 ` Sean Christopherson
2025-10-09 5:36 ` Chao Gao
2025-10-10 1:16 ` dan.j.williams
2025-10-10 21:22 ` VMXON for TDX (was: Re: [PATCH] KVM: VMX: Flush shadow VMCS on emergency reboot) Sean Christopherson
2025-05-02 21:51 ` [PATCH] KVM: VMX: Flush shadow VMCS on emergency reboot Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=616212d3261c3c3213bced1fdb6b2f0982c55928.camel@intel.com \
--to=kai.huang@intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®