From: Paolo Bonzini <pbonzini@redhat.com>
To: Jim Mattson <jmattson@google.com>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
nathan@kernel.org, thomas.lendacky@amd.com,
andrew.cooper3@citrix.com, peterz@infradead.org,
seanjc@google.com, stable@vger.kernel.org
Subject: Re: [PATCH 7/8] KVM: SVM: move MSR_IA32_SPEC_CTRL save/restore to assembly
Date: Mon, 7 Nov 2022 20:08:13 +0100 [thread overview]
Message-ID: <81f7dc5c-c45d-76fc-d9e8-4f3f65c29c12@redhat.com> (raw)
In-Reply-To: <CALMp9eRDehmWC1gZmSjxjwCvm4VXf_FnR-MiFkHxkTn4_DJ4aA@mail.gmail.com>
On 11/7/22 19:45, Jim Mattson wrote:
>> +.macro RESTORE_GUEST_SPEC_CTRL
>> + /* No need to do anything if SPEC_CTRL is unset or V_SPEC_CTRL is set */
>> + ALTERNATIVE_2 "jmp 999f", \
>> + "", X86_FEATURE_MSR_SPEC_CTRL, \
>> + "jmp 999f", X86_FEATURE_V_SPEC_CTRL
>> +
>> + /*
>> + * SPEC_CTRL handling: if the guest's SPEC_CTRL value differs from the
>> + * host's, write the MSR.
>> + *
>> + * IMPORTANT: To avoid RSB underflow attacks and any other nastiness,
>> + * there must not be any returns or indirect branches between this code
>> + * and vmentry.
>> + */
>> + movl SVM_spec_ctrl(%_ASM_DI), %eax
>> + cmp PER_CPU_VAR(x86_spec_ctrl_current), %eax
>> + je 999f
>> + mov $MSR_IA32_SPEC_CTRL, %ecx
>> + xor %edx, %edx
>> + wrmsr
>> +999:
>> +
>> +.endm
>> +
>> +.macro RESTORE_HOST_SPEC_CTRL
>> + /* No need to do anything if SPEC_CTRL is unset or V_SPEC_CTRL is set */
>> + ALTERNATIVE_2 "jmp 999f", \
>> + "", X86_FEATURE_MSR_SPEC_CTRL, \
>> + "jmp 999f", X86_FEATURE_V_SPEC_CTRL
>> +
>> + mov $MSR_IA32_SPEC_CTRL, %ecx
>> +
>> + /*
>> + * Load the value that the guest had written into MSR_IA32_SPEC_CTRL,
>> + * if it was not intercepted during guest execution.
>> + */
>> + cmpb $0, (%_ASM_SP)
>> + jnz 998f
>> + rdmsr
>> + movl %eax, SVM_spec_ctrl(%_ASM_DI)
>> +998:
>> +
>> + /* Now restore the host value of the MSR if different from the guest's. */
>> + movl PER_CPU_VAR(x86_spec_ctrl_current), %eax
>> + cmp SVM_spec_ctrl(%_ASM_DI), %eax
>> + je 999f
>> + xor %edx, %edx
>> + wrmsr
>> +999:
>> +
>> +.endm
>> +
>> +
>
> It seems unfortunate to have the unconditional branches in the more
> common cases.
One way to do it could be something like
.macro RESTORE_HOST_SPEC_CTRL
ALTERNATIVE_2 "", \
"jmp 900f", X86_FEATURE_MSR_SPEC_CTRL, \
"", X86_FEATURE_V_SPEC_CTRL \
901:
.endm
.macro RESTORE_SPEC_CTRL_BODY \
800:
/* restore guest spec ctrl ... */
jmp 801b
900:
/* save guest spec ctrl + restore host ... */
jmp 901b
.endm
The cmp/je pair can also jump back to 801b/901b.
What do you think? I'll check if objtool is happy and if so include it
in v2.
Paolo
next prev parent reply other threads:[~2022-11-07 19:10 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-11-07 14:54 [PATCH 0/8] KVM: SVM: fixes for vmentry code Paolo Bonzini
2022-11-07 14:54 ` [PATCH 1/8] KVM: SVM: extract VMCB accessors to a new file Paolo Bonzini
2022-11-07 17:08 ` Sean Christopherson
2022-11-07 17:36 ` Paolo Bonzini
2022-11-07 18:14 ` Sean Christopherson
2022-11-07 18:51 ` Paolo Bonzini
2022-11-08 8:52 ` Paolo Bonzini
2022-11-07 14:54 ` [PATCH 2/8] KVM: SVM: replace regs argument of __svm_vcpu_run with vcpu_svm Paolo Bonzini
2022-11-07 17:10 ` Sean Christopherson
2022-11-07 17:22 ` Paolo Bonzini
2022-11-07 14:54 ` [PATCH 3/8] KVM: SVM: adjust register allocation for __svm_vcpu_run Paolo Bonzini
2022-11-07 14:54 ` [PATCH 4/8] KVM: SVM: move guest vmsave/vmload to assembly Paolo Bonzini
2022-11-07 15:23 ` Peter Zijlstra
2022-11-07 15:40 ` Paolo Bonzini
2022-11-07 15:32 ` Andrew Cooper
2022-11-07 15:37 ` Paolo Bonzini
2022-11-07 15:47 ` Andrew Cooper
2022-11-07 14:54 ` [PATCH 5/8] KVM: SVM: retrieve VMCB from assembly Paolo Bonzini
2022-11-07 14:54 ` [PATCH 6/8] KVM: SVM: restore host save area " Paolo Bonzini
2022-11-07 14:54 ` [PATCH 7/8] KVM: SVM: move MSR_IA32_SPEC_CTRL save/restore to assembly Paolo Bonzini
2022-11-07 18:45 ` Jim Mattson
2022-11-07 19:08 ` Paolo Bonzini [this message]
2022-11-09 21:23 ` Jim Mattson
2022-11-07 14:54 ` [PATCH 8/8] x86, KVM: remove unnecessary argument to x86_virt_spec_ctrl and callers Paolo Bonzini
2022-11-07 15:33 ` [PATCH 0/8] KVM: SVM: fixes for vmentry code Peter Zijlstra
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=81f7dc5c-c45d-76fc-d9e8-4f3f65c29c12@redhat.com \
--to=pbonzini@redhat.com \
--cc=andrew.cooper3@citrix.com \
--cc=jmattson@google.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nathan@kernel.org \
--cc=peterz@infradead.org \
--cc=seanjc@google.com \
--cc=stable@vger.kernel.org \
--cc=thomas.lendacky@amd.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®