mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Christian Borntraeger <borntraeger@de.ibm.com>
To: Pierre Morel <pmorel@linux.ibm.com>, david@redhat.com
Cc: linux-kernel@vger.kernel.org, cohuck@redhat.com,
	linux-s390@vger.kernel.org, kvm@vger.kernel.org,
	frankja@linux.ibm.com, akrowiak@linux.ibm.com,
	schwidefsky@de.ibm.com, heiko.carstens@de.ibm.com
Subject: Re: [PATCH v3 2/3] KVM: s390: vsie: Do the CRYCB validation first
Date: Thu, 23 Aug 2018 13:17:47 +0200	[thread overview]
Message-ID: <b7c0b0eb-c750-caeb-41b5-d6593791a6ef@de.ibm.com> (raw)
In-Reply-To: <1535019956-23539-3-git-send-email-pmorel@linux.ibm.com>



On 08/23/2018 12:25 PM, Pierre Morel wrote:
> When entering the SIE the CRYCB validation better
> be done independently of the instruction's
> availability.

Maybe something like

We need to handle the validity checks for the crycb, no matter what the
settings for the keywrappings are. So lets move the keywrapping checks
after we have done the validy checks.

?

> 
> Signed-off-by: Pierre Morel <pmorel@linux.ibm.com>
> ---
>  arch/s390/kvm/vsie.c | 11 ++++++-----
>  1 file changed, 6 insertions(+), 5 deletions(-)
> 
> diff --git a/arch/s390/kvm/vsie.c b/arch/s390/kvm/vsie.c
> index 12b9707..38ea5da 100644
> --- a/arch/s390/kvm/vsie.c
> +++ b/arch/s390/kvm/vsie.c
> @@ -161,17 +161,18 @@ static int shadow_crycb(struct kvm_vcpu *vcpu, struct vsie_page *vsie_page)
>  	/* format-1 is supported with message-security-assist extension 3 */
>  	if (!test_kvm_facility(vcpu->kvm, 76))
>  		return 0;
> -	/* we may only allow it if enabled for guest 2 */
> -	ecb3_flags = scb_o->ecb3 & vcpu->arch.sie_block->ecb3 &
> -		     (ECB3_AES | ECB3_DEA);
> -	if (!ecb3_flags)
> -		return 0;
> 
>  	if ((crycb_addr & PAGE_MASK) != ((crycb_addr + 128) & PAGE_MASK))
>  		return set_validity_icpt(scb_s, 0x003CU);
>  	else if (!crycb_addr)
>  		return set_validity_icpt(scb_s, 0x0039U);
> 
> +	/* we may only allow it if enabled for guest 2 */
> +	ecb3_flags = scb_o->ecb3 & vcpu->arch.sie_block->ecb3 &
> +		     (ECB3_AES | ECB3_DEA);
> +	if (!ecb3_flags)
> +		return 0;
> +
>  	/* copy only the wrapping keys */
>  	if (read_guest_real(vcpu, crycb_addr + 72,
>  			    vsie_page->crycb.dea_wrapping_key_mask, 56))
> 


  reply	other threads:[~2018-08-23 11:17 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-08-23 10:25 [PATCH v3 0/3] KVM: s390: vsie: Consolidate CRYCB validation Pierre Morel
2018-08-23 10:25 ` [PATCH v3 1/3] KVM: s390: vsie: copy wrapping keys to right place Pierre Morel
2018-08-23 11:07   ` Christian Borntraeger
2018-08-23 11:19     ` David Hildenbrand
2018-08-23 11:41       ` Pierre Morel
2018-08-23 12:43         ` Christian Borntraeger
2018-08-23 12:48           ` Pierre Morel
2018-08-23 13:12   ` Christian Borntraeger
2018-08-23 13:13     ` David Hildenbrand
2018-08-23 10:25 ` [PATCH v3 2/3] KVM: s390: vsie: Do the CRYCB validation first Pierre Morel
2018-08-23 11:17   ` Christian Borntraeger [this message]
2018-08-23 11:19     ` David Hildenbrand
2018-08-23 11:42       ` Pierre Morel
2018-08-23 11:39     ` Pierre Morel
2018-08-23 13:43   ` Janosch Frank
2018-08-23 10:25 ` [PATCH v3 3/3] KVM: s390: vsie: Make use of CRYCB FORMAT2 clear Pierre Morel
2018-08-23 11:05   ` Janosch Frank
2018-08-23 11:21     ` David Hildenbrand
2018-08-23 11:33       ` Janosch Frank
2018-08-23 11:47         ` Pierre Morel
2018-08-23 11:53           ` Janosch Frank
2018-08-23 12:03             ` David Hildenbrand
2018-08-23 12:11               ` Janosch Frank
2018-08-23 11:40       ` Pierre Morel
2018-08-23 13:16 ` [PATCH v3 0/3] KVM: s390: vsie: Consolidate CRYCB validation Janosch Frank

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b7c0b0eb-c750-caeb-41b5-d6593791a6ef@de.ibm.com \
    --to=borntraeger@de.ibm.com \
    --cc=akrowiak@linux.ibm.com \
    --cc=cohuck@redhat.com \
    --cc=david@redhat.com \
    --cc=frankja@linux.ibm.com \
    --cc=heiko.carstens@de.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=pmorel@linux.ibm.com \
    --cc=schwidefsky@de.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®