From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1F172C43334 for ; Thu, 16 Jun 2022 15:28:51 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S233352AbiFPP2u (ORCPT ); Thu, 16 Jun 2022 11:28:50 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:38254 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1377889AbiFPP2r (ORCPT ); Thu, 16 Jun 2022 11:28:47 -0400 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 247D62DAAE for ; Thu, 16 Jun 2022 08:28:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1655393325; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XskGf25OAiPtPSUK4BxcnPczRA0Oydi/igOaaTpXUSQ=; b=bdDBnxXql2SOny0hceigHtBqaMQQEQeNGOv8yJdKDVIWqxcdrE0YHy2hAdDU1Lib9mWMOc FFLTWBu+k2XFHJyfRYAMiqO9A2R+2RQ3Pgu6hlVnpkyNS//GIrTuPKXnWknevWxw3NU+3j EJFnXXN5KfVdQRTyOCYv/RfDszXny8I= Received: from mail-ej1-f72.google.com (mail-ej1-f72.google.com [209.85.218.72]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id us-mta-73-BnyuoktHN_SaLjW42qgQeA-1; Thu, 16 Jun 2022 11:28:43 -0400 X-MC-Unique: BnyuoktHN_SaLjW42qgQeA-1 Received: by mail-ej1-f72.google.com with SMTP id kf3-20020a17090776c300b0070d149300e9so755929ejc.15 for ; Thu, 16 Jun 2022 08:28:43 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:message-id:date:mime-version:user-agent :content-language:to:cc:references:from:subject:in-reply-to :content-transfer-encoding; bh=XskGf25OAiPtPSUK4BxcnPczRA0Oydi/igOaaTpXUSQ=; b=FJK65J+aOj/BgAJ3zV48EpH1Lh41t5TS8wnGYR5BQcHAVj6HV8+lHwNMaeUHt7nudi hKI7i2IvXivMN8rFFoJek4aDugcOVfG5cxDVk4D98IcXUrz3uEdf+bQlvBnZ6gHHRJlS piiOruUGGv6/g/qYkktllwHy3IX96DjdNIoIrgxE+MxCc4wy1YI03RpOI91ugyADST/U +G7yBeDpamVsFwg86sHsKptuKTDgguLNGReeZZupGWEtzUJiGDXMC+pBfe2UPjBkPQM8 Isn+JrhnNo5Rp06EqAuG2LOgX/4q3Q5YjwWrINFbQ2ICSVbtdCz5A7HOEGRaKM6+ns69 MFyg== X-Gm-Message-State: AJIora/53l9lZsiZyqDBeu78tVhrtyOWsWEqMPdCh1hrmL6nruUf/4a+ /I72dyHo+v23YpwEtFVd5bCH7NFOQW6lv9MJpspwT+c0d6ZH5rAG0F3OP0UeDBenXz/tog/q68f yHhpvYZ3yLopO2SV5ilCoYwvn X-Received: by 2002:a17:906:7a4a:b0:712:c6d:46df with SMTP id i10-20020a1709067a4a00b007120c6d46dfmr5085391ejo.314.1655393322558; Thu, 16 Jun 2022 08:28:42 -0700 (PDT) X-Google-Smtp-Source: AGRyM1vJsE6d4JZOi53Tz2XAP/rgRHZ/OSAOnXOCoxVH7wTJZGlMIVUlbi95yyig9j53CDCfTpb6Jw== X-Received: by 2002:a17:906:7a4a:b0:712:c6d:46df with SMTP id i10-20020a1709067a4a00b007120c6d46dfmr5085361ejo.314.1655393322317; Thu, 16 Jun 2022 08:28:42 -0700 (PDT) Received: from ?IPV6:2001:b07:6468:f312:9af8:e5f5:7516:fa89? ([2001:b07:6468:f312:9af8:e5f5:7516:fa89]) by smtp.googlemail.com with ESMTPSA id w12-20020a056402268c00b0042aaaf3f41csm2083977edd.4.2022.06.16.08.28.40 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 16 Jun 2022 08:28:41 -0700 (PDT) Message-ID: <8a38488d-fb6e-72f9-3529-b098a97d8c97@redhat.com> Date: Thu, 16 Jun 2022 17:28:40 +0200 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Thunderbird/91.10.0 Content-Language: en-US To: Peter Zijlstra Cc: Yang Weijiang , seanjc@google.com, x86@kernel.org, kvm@vger.kernel.org, linux-kernel@vger.kernel.org, rick.p.edgecombe@intel.com References: <20220616084643.19564-1-weijiang.yang@intel.com> <62d4f7f0-e7b2-83ad-a2c7-a90153129da2@redhat.com> From: Paolo Bonzini Subject: Re: [PATCH 00/19] Refresh queued CET virtualization series In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 6/16/22 16:18, Peter Zijlstra wrote: > On Thu, Jun 16, 2022 at 12:21:20PM +0200, Paolo Bonzini wrote: >> On 6/16/22 12:12, Peter Zijlstra wrote: >>> Do I understand this right in that a host without X86_KERNEL_IBT cannot >>> run a guest with X86_KERNEL_IBT on? That seems unfortunate, since that >>> was exactly what I did while developing the X86_KERNEL_IBT patches. >>> >>> I'm thinking that if the hardware supports it, KVM should expose it, >>> irrespective of the host kernel using it. >> >> For IBT in particular, I think all processor state is only loaded and stored >> at vmentry/vmexit (does not need XSAVES), so it should be feasible. > > That would be the S_CET stuff, yeah, that's VMCS managed. The U_CET > stuff is all XSAVE though. What matters is whether XFEATURE_MASK_USER_SUPPORTED includes XFEATURE_CET_USER. If you build with !X86_KERNEL_IBT, KVM can still rely on the FPU state for U_CET state, and S_CET is saved/restored via the VMCS independent of X86_KERNEL_IBT. Paolo > But funny thing, CPUID doesn't enumerate {U,S}_CET separately. It *does* > enumerate IBT and SS separately, but for each IBT/SS you have to > implement both U and S. > > That was a problem with the first series, which only implemented support > for U_CET while advertising IBT and SS (very much including S_CET), and > still is a problem with this series because S_SS is missing while > advertised.