mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Tom Lendacky <thomas.lendacky@amd.com>
To: Sean Christopherson <seanjc@google.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
	Naveen N Rao <naveen@kernel.org>,
	Kim Phillips <kim.phillips@amd.com>,
	Alexey Kardashevskiy <aik@amd.com>
Subject: Re: [PATCH 00/10] KVM: SVM: Attempt to cleanup SEV_FEATURES
Date: Mon, 24 Feb 2025 18:02:29 -0600	[thread overview]
Message-ID: <81949e94-9b7f-0b04-d673-cbc16fc646a5@amd.com> (raw)
In-Reply-To: <a9d70abe-d229-81cb-4d9a-6106cef612a4@amd.com>

On 2/20/25 16:51, Tom Lendacky wrote:
> On 2/18/25 19:26, Sean Christopherson wrote:
>> This is a hastily thrown together series, barely above RFC, to try and
>> address the worst of the issues that arise with guest controlled SEV
>> features (thanks AP creation)[1].
>>
>> In addition to the initial flaws with DebugSwap, I came across a variety
>> of issues when trying to figure out how best to handle SEV features in
>> general.  E.g. AFAICT, KVM doesn't guard against userspace manually making
>> a vCPU RUNNABLE after it has been DESTROYED (or after a failed CREATE).
>>
>> This is essentially compile-tested only, as I don't have easy access to a
>> system with SNP enabled.  I ran the SEV-ES selftests, but that's not much
>> in the way of test coverage.
>>
>> AMD folks, I would greatly appreciate reviews, testing, and most importantly,
>> confirmation that all of this actually works the way I think it does.
> 
> A quick test of a 64 vCPU SNP guest booted successfully, so that's a
> good start. I'll take a closer look at these patches over the next few days.

Everything looks good. I'm going to try messing around with the
DebugSwap feature bit just to try some of those odd cases and make sure
everything does what it is supposed to. Should have results in a day or two.

Thanks,
Tom

> 
> Thanks,
> Tom
> 
>>
>> [1] https://lore.kernel.org/all/Z7TSef290IQxQhT2@google.com
>>
>> Sean Christopherson (10):
>>   KVM: SVM: Save host DR masks but NOT DRs on CPUs with DebugSwap
>>   KVM: SVM: Don't rely on DebugSwap to restore host DR0..DR3
>>   KVM: SVM: Terminate the VM if a SEV-ES+ guest is run with an invalid
>>     VMSA
>>   KVM: SVM: Don't change target vCPU state on AP Creation VMGEXIT error
>>   KVM: SVM: Require AP's "requested" SEV_FEATURES to match KVM's view
>>   KVM: SVM: Simplify request+kick logic in SNP AP Creation handling
>>   KVM: SVM: Use guard(mutex) to simplify SNP AP Creation error handling
>>   KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa
>>   KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates
>>   KVM: SVM: Invalidate "next" SNP VMSA GPA even on failure
>>
>>  arch/x86/kvm/svm/sev.c | 218 +++++++++++++++++++----------------------
>>  arch/x86/kvm/svm/svm.c |   7 +-
>>  arch/x86/kvm/svm/svm.h |   2 +-
>>  3 files changed, 106 insertions(+), 121 deletions(-)
>>
>>
>> base-commit: fed48e2967f402f561d80075a20c5c9e16866e53

  reply	other threads:[~2025-02-25  0:02 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-19  1:26 Sean Christopherson
2025-02-19  1:26 ` [PATCH 01/10] KVM: SVM: Save host DR masks but NOT DRs on CPUs with DebugSwap Sean Christopherson
2025-02-24 19:38   ` Tom Lendacky
2025-02-25  2:22   ` Kim Phillips
2025-02-25 14:12     ` Tom Lendacky
2025-02-19  1:26 ` [PATCH 02/10] KVM: SVM: Don't rely on DebugSwap to restore host DR0..DR3 Sean Christopherson
2025-02-24 20:32   ` Tom Lendacky
2025-02-24 22:32     ` Sean Christopherson
2025-02-19  1:26 ` [PATCH 03/10] KVM: SVM: Terminate the VM if a SEV-ES+ guest is run with an invalid VMSA Sean Christopherson
2025-02-24 21:03   ` Tom Lendacky
2025-02-24 22:55     ` Sean Christopherson
2025-02-24 23:55       ` Tom Lendacky
2025-02-25  0:54         ` Sean Christopherson
2025-02-25  1:20           ` Sean Christopherson
2025-02-25 14:42           ` Tom Lendacky
2025-02-19  1:26 ` [PATCH 04/10] KVM: SVM: Don't change target vCPU state on AP Creation VMGEXIT error Sean Christopherson
2025-02-24 21:31   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 05/10] KVM: SVM: Require AP's "requested" SEV_FEATURES to match KVM's view Sean Christopherson
2025-02-24 21:46   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 06/10] KVM: SVM: Simplify request+kick logic in SNP AP Creation handling Sean Christopherson
2025-02-19  6:19   ` Gupta, Pankaj
2025-02-24 21:48   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 07/10] KVM: SVM: Use guard(mutex) to simplify SNP AP Creation error handling Sean Christopherson
2025-02-24 21:49   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 08/10] KVM: SVM: Mark VMCB dirty before processing incoming snp_vmsa_gpa Sean Christopherson
2025-02-24 21:58   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 09/10] KVM: SVM: Use guard(mutex) to simplify SNP vCPU state updates Sean Christopherson
2025-02-24 22:57   ` Tom Lendacky
2025-02-19  1:27 ` [PATCH 10/10] KVM: SVM: Invalidate "next" SNP VMSA GPA even on failure Sean Christopherson
2025-02-25  0:00   ` Tom Lendacky
2025-02-20 22:51 ` [PATCH 00/10] KVM: SVM: Attempt to cleanup SEV_FEATURES Tom Lendacky
2025-02-25  0:02   ` Tom Lendacky [this message]
2025-02-25  2:21     ` Kim Phillips

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=81949e94-9b7f-0b04-d673-cbc16fc646a5@amd.com \
    --to=thomas.lendacky@amd.com \
    --cc=aik@amd.com \
    --cc=kim.phillips@amd.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=naveen@kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®