mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jarkko Sakkinen <jarkko@kernel.org>
To: Paolo Bonzini <pbonzini@redhat.com>,
	linux-kernel@vger.kernel.org, kvm@vger.kernel.org
Cc: dave.hansen@linux.intel.com, seanjc@google.com, x86@kernel.org,
	yang.zhong@intel.com
Subject: Re: [PATCH v2 1/2] x86: sgx_vepc: extract sgx_vepc_remove_page
Date: Tue, 12 Oct 2021 19:53:45 +0300	[thread overview]
Message-ID: <7a456461cd1a23f5b8a3116d44e5b94db5f68826.camel@kernel.org> (raw)
In-Reply-To: <20211012105708.2070480-2-pbonzini@redhat.com>

On Tue, 2021-10-12 at 06:57 -0400, Paolo Bonzini wrote:
> For bare-metal SGX on real hardware, the hardware provides guarantees
> SGX state at reboot.  For instance, all pages start out uninitialized.
> The vepc driver provides a similar guarantee today for freshly-opened
> vepc instances, but guests such as Windows expect all pages to be in
> uninitialized state on startup, including after every guest reboot.
> 
> One way to do this is to simply close and reopen the /dev/sgx_vepc file
> descriptor and re-mmap the virtual EPC.  However, this is problematic
> because it prevents sandboxing the userspace (for example forbidding
> open() after the guest starts; this is doable with heavy use of SCM_RIGHTS
> file descriptor passing).
> 
> In order to implement this, we will need a ioctl that performs
> EREMOVE on all pages mapped by a /dev/sgx_vepc file descriptor:
> other possibilities, such as closing and reopening the device,
> are racy.
> 
> Start the implementation by creating a separate function with just
> the __eremove wrapper.
> 
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
> ---
>         v1->v2: keep WARN in sgx_vepc_free_page
> 
>  arch/x86/kernel/cpu/sgx/virt.c | 12 +++++++-----
>  1 file changed, 7 insertions(+), 5 deletions(-)
> 
> diff --git a/arch/x86/kernel/cpu/sgx/virt.c b/arch/x86/kernel/cpu/sgx/virt.c
> index 64511c4a5200..59cdf3f742ac 100644
> --- a/arch/x86/kernel/cpu/sgx/virt.c
> +++ b/arch/x86/kernel/cpu/sgx/virt.c
> @@ -111,10 +111,8 @@ static int sgx_vepc_mmap(struct file *file, struct vm_area_struct *vma)
>         return 0;
>  }
>  
> -static int sgx_vepc_free_page(struct sgx_epc_page *epc_page)
> +static int sgx_vepc_remove_page(struct sgx_epc_page *epc_page)
>  {
> -       int ret;
> -
>         /*
>          * Take a previously guest-owned EPC page and return it to the
>          * general EPC page pool.
> @@ -124,7 +122,12 @@ static int sgx_vepc_free_page(struct sgx_epc_page *epc_page)
>          * case that a guest properly EREMOVE'd this page, a superfluous
>          * EREMOVE is harmless.
>          */
> -       ret = __eremove(sgx_get_epc_virt_addr(epc_page));
> +       return __eremove(sgx_get_epc_virt_addr(epc_page));
> +}
> +
> +static int sgx_vepc_free_page(struct sgx_epc_page *epc_page)
> +{
> +       int ret = sgx_vepc_remove_page(epc_page);
>         if (ret) {
>                 /*
>                  * Only SGX_CHILD_PRESENT is expected, which is because of
> @@ -144,7 +147,6 @@ static int sgx_vepc_free_page(struct sgx_epc_page *epc_page)
>         }
>  
>         sgx_free_epc_page(epc_page);
> -
>         return 0;
>  }
>  

Reviewed-by: Jarkko Sakkinen <jarkko@kernel.org>

/Jarkko


  reply	other threads:[~2021-10-12 16:53 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-10-12 10:57 [PATCH v2 0/2] x86: sgx_vepc: implement ioctl to EREMOVE all pages Paolo Bonzini
2021-10-12 10:57 ` [PATCH v2 1/2] x86: sgx_vepc: extract sgx_vepc_remove_page Paolo Bonzini
2021-10-12 16:53   ` Jarkko Sakkinen [this message]
2021-10-13 12:56   ` [tip: x86/sgx] x86/sgx/virt: Extract sgx_vepc_remove_page() tip-bot2 for Paolo Bonzini
2021-10-14 22:10   ` [PATCH v2 1/2] x86: sgx_vepc: extract sgx_vepc_remove_page Dave Hansen
2021-10-12 10:57 ` [PATCH v2 2/2] x86: sgx_vepc: implement SGX_IOC_VEPC_REMOVE ioctl Paolo Bonzini
2021-10-12 16:57   ` Jarkko Sakkinen
2021-10-12 17:03     ` Paolo Bonzini
2021-10-12 17:43       ` Jarkko Sakkinen
2021-10-13 12:56   ` [tip: x86/sgx] x86/sgx/virt: Implement " tip-bot2 for Paolo Bonzini
2021-10-14 22:14   ` [PATCH v2 2/2] x86: sgx_vepc: implement " Dave Hansen
2021-10-15 22:29   ` Sean Christopherson
2021-10-16  7:14     ` Paolo Bonzini
2021-10-13  6:54 ` [PATCH v2 0/2] x86: sgx_vepc: implement ioctl to EREMOVE all pages Borislav Petkov
2021-10-13  7:15   ` Paolo Bonzini
2021-10-13  7:38     ` Borislav Petkov
2021-10-14 12:21 ` Yang Zhong

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=7a456461cd1a23f5b8a3116d44e5b94db5f68826.camel@kernel.org \
    --to=jarkko@kernel.org \
    --cc=dave.hansen@linux.intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    --cc=x86@kernel.org \
    --cc=yang.zhong@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

Powered by JetHome