From: Sean Christopherson <seanjc@google.com>
To: Peter Zijlstra <peterz@infradead.org>
Cc: Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, Paolo Bonzini <pbonzini@redhat.com>,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
Andrew Cooper <Andrew.Cooper3@citrix.com>,
Kai Huang <kai.huang@intel.com>, Chao Gao <chao.gao@intel.com>
Subject: Re: [PATCH v4 05/19] x86/reboot: Assert that IRQs are disabled when turning off virtualization
Date: Mon, 24 Jul 2023 14:41:21 -0700 [thread overview]
Message-ID: <ZL7wAXyF5A8i5He7@google.com> (raw)
In-Reply-To: <20230724211949.GG3745454@hirez.programming.kicks-ass.net>
On Mon, Jul 24, 2023, Peter Zijlstra wrote:
> On Fri, Jul 21, 2023 at 01:18:45PM -0700, Sean Christopherson wrote:
> > Assert that IRQs are disabled when turning off virtualization in an
> > emergency. KVM enables hardware via on_each_cpu(), i.e. could re-enable
> > hardware if a pending IPI were delivered after disabling virtualization.
> >
> > Remove a misleading comment from emergency_reboot_disable_virtualization()
> > about "just" needing to guarantee the CPU is stable (see above).
> >
> > Reviewed-by: Kai Huang <kai.huang@intel.com>
> > Signed-off-by: Sean Christopherson <seanjc@google.com>
> > ---
> > arch/x86/kernel/reboot.c | 8 +++++++-
> > 1 file changed, 7 insertions(+), 1 deletion(-)
> >
> > diff --git a/arch/x86/kernel/reboot.c b/arch/x86/kernel/reboot.c
> > index 48ad2d1ff83d..4cad7183b89e 100644
> > --- a/arch/x86/kernel/reboot.c
> > +++ b/arch/x86/kernel/reboot.c
> > @@ -532,7 +532,6 @@ static inline void nmi_shootdown_cpus_on_restart(void);
> >
> > static void emergency_reboot_disable_virtualization(void)
> > {
> > - /* Just make sure we won't change CPUs while doing this */
> > local_irq_disable();
> >
> > /*
> > @@ -821,6 +820,13 @@ void cpu_emergency_disable_virtualization(void)
> > {
> > cpu_emergency_virt_cb *callback;
> >
> > + /*
> > + * IRQs must be disabled as KVM enables virtualization in hardware via
> > + * function call IPIs, i.e. IRQs need to be disabled to guarantee
> > + * virtualization stays disabled.
> > + */
> > + lockdep_assert_irqs_disabled();
> > +
> > rcu_read_lock();
> > callback = rcu_dereference(cpu_emergency_virt_callback);
> > if (callback)
>
> Strictly speaking you don't need rcu_read_lock() when IRQs are already
> disabled, but since this is non-performance critical code, it might be
> best to keep it super obvious. IOW, carry on.
Ha! IIRC, I even had a patch to drop the explicit rcu_read_lock(), but decided
I didn't want to tie the use of cpu_emergency_virt_callback to KVM's behavior of
enabling virtualization via IPIs.
next prev parent reply other threads:[~2023-07-24 21:41 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-07-21 20:18 [PATCH v4 00/19] x86/reboot: KVM: Clean up "emergency" virt code Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 01/19] x86/reboot: VMCLEAR active VMCSes before emergency reboot Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 02/19] x86/reboot: Harden virtualization hooks for " Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 03/19] x86/reboot: KVM: Handle VMXOFF in KVM's reboot callback Sean Christopherson
2023-07-24 23:57 ` Huang, Kai
2023-07-21 20:18 ` [PATCH v4 04/19] x86/reboot: KVM: Disable SVM during reboot via virt/KVM " Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 05/19] x86/reboot: Assert that IRQs are disabled when turning off virtualization Sean Christopherson
2023-07-24 21:19 ` Peter Zijlstra
2023-07-24 21:41 ` Sean Christopherson [this message]
2023-07-21 20:18 ` [PATCH v4 06/19] x86/reboot: Hoist "disable virt" helpers above "emergency reboot" path Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 07/19] x86/reboot: Disable virtualization during reboot iff callback is registered Sean Christopherson
2023-07-24 23:57 ` Huang, Kai
2023-07-21 20:18 ` [PATCH v4 08/19] x86/reboot: Expose VMCS crash hooks if and only if KVM_{INTEL,AMD} is enabled Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 09/19] x86/virt: KVM: Open code cpu_has_vmx() in KVM VMX Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 10/19] x86/virt: KVM: Move VMXOFF helpers into " Sean Christopherson
2023-07-28 9:08 ` Xu Yilun
2023-07-28 9:43 ` Huang, Kai
2023-07-21 20:18 ` [PATCH v4 11/19] KVM: SVM: Make KVM_AMD depend on CPU_SUP_AMD or CPU_SUP_HYGON Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 12/19] x86/virt: Drop unnecessary check on extended CPUID level in cpu_has_svm() Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 13/19] x86/virt: KVM: Open code cpu_has_svm() into kvm_is_svm_supported() Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 14/19] KVM: SVM: Check that the current CPU supports SVM in kvm_is_svm_supported() Sean Christopherson
2023-07-24 21:21 ` Peter Zijlstra
2023-07-24 21:40 ` Sean Christopherson
2023-07-25 9:16 ` Peter Zijlstra
2023-07-27 16:39 ` Sean Christopherson
2023-07-24 22:29 ` Dmitry Torokhov
2023-07-24 23:53 ` Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 15/19] KVM: VMX: Ensure CPU is stable when probing basic VMX support Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 16/19] x86/virt: KVM: Move "disable SVM" helper into KVM SVM Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 17/19] KVM: x86: Force kvm_rebooting=true during emergency reboot/crash Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 18/19] KVM: SVM: Use "standard" stgi() helper when disabling SVM Sean Christopherson
2023-07-21 20:18 ` [PATCH v4 19/19] KVM: VMX: Skip VMCLEAR logic during emergency reboots if CR4.VMXE=0 Sean Christopherson
2023-07-25 3:51 ` Huang, Kai
2023-07-25 18:15 ` Sean Christopherson
2023-07-25 22:20 ` Huang, Kai
2023-08-04 0:40 ` [PATCH v4 00/19] x86/reboot: KVM: Clean up "emergency" virt code Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ZL7wAXyF5A8i5He7@google.com \
--to=seanjc@google.com \
--cc=Andrew.Cooper3@citrix.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=kai.huang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome