From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751307AbdE3Rqm (ORCPT ); Tue, 30 May 2017 13:46:42 -0400 Received: from mail-dm3nam03on0045.outbound.protection.outlook.com ([104.47.41.45]:39616 "EHLO NAM03-DM3-obe.outbound.protection.outlook.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1750912AbdE3Rqf (ORCPT ); Tue, 30 May 2017 13:46:35 -0400 Authentication-Results: google.com; dkim=none (message not signed) header.d=none;google.com; dmarc=none action=none header.from=amd.com; Subject: Re: [PATCH v5 28/32] x86/mm, kexec: Allow kexec to be used with SME To: , , , , , , , , , , CC: Thomas Gleixner , Rik van Riel , Brijesh Singh , Toshimitsu Kani , Arnd Bergmann , Jonathan Corbet , Matt Fleming , Joerg Roedel , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Konrad Rzeszutek Wilk , Andrey Ryabinin , Ingo Molnar , "Michael S. Tsirkin" , Andy Lutomirski , "H. Peter Anvin" , Borislav Petkov , Paolo Bonzini , Alexander Potapenko , Dave Young , Larry Woodman , Dmitry Vyukov References: <20170418211612.10190.82788.stgit@tlendack-t1.amdoffice.net> <20170418212121.10190.94885.stgit@tlendack-t1.amdoffice.net> <5927AC6E.8080209@redhat.com> From: Tom Lendacky Message-ID: Date: Tue, 30 May 2017 12:46:14 -0500 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.1.1 MIME-Version: 1.0 In-Reply-To: <5927AC6E.8080209@redhat.com> Content-Type: text/plain; charset="windows-1252"; format=flowed Content-Language: en-US Content-Transfer-Encoding: 7bit X-Originating-IP: [165.204.78.1] X-ClientProxiedBy: MWHPR15CA0028.namprd15.prod.outlook.com (10.173.226.142) To CY4PR12MB1141.namprd12.prod.outlook.com (10.168.163.149) X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CY4PR12MB1141: X-MS-Office365-Filtering-Correlation-Id: 4a25b7b5-22de-4449-6c1d-08d4a783cd96 X-MS-Office365-Filtering-HT: Tenant X-Microsoft-Antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001)(48565401081)(201703131423075)(201703031133081);SRVR:CY4PR12MB1141; X-Microsoft-Exchange-Diagnostics: 1;CY4PR12MB1141;3:EH2u/1kJQbPUZxUqYgVgIUP6PqKb+RPixpP7fYKo3nMTFAEWMqK9w4cqTTShK3SXb/7kWYphIhKN8PpGPMzOgxTAZB30GZZbBrN5b6gwpkh6mu5Tf0n+y27l6yGVgAtRmd6aZx/p80co4bASCinkt0p+3yek1UAaqGhf2BNpMD0BxvU5nTFchIi4/HHUTMgkgBwDC/VCYjAkMBHIdfi+AA3snON8h/yZGI8HiM/jY3UhRBaAUVNB/HB2kRet9usBxMJ/C0ofGGQi6RruNPZvu3VNVKvTCOdqiEP77WfwgIipFWZZWGKbJctFHsz7oMCWURS8ujR1yPxrEKJgS89ACa4KXbbloGkCkgiTWYlN7g8=;25:AbK/3X2ePjmc5hlQBgbGiArrY1LFKNDJ9hXo3v7snQLySuPLFg1RuFK0oQIZ09rKpDkt5JNNR1jYT9YV15Pm3jYFPf15C7PhKX80uhsoO+NlBIStJwDr92cPcK5U78mkPlIlTr0TE6ctCNw6dKSBccyjCBZTBmHlLTjDWCqs+xl4V/yFI5zj0wijjTgVYwcGPHk2511L01TWKumbU+i5jNVQSXUg9lR9jEul5Eo4SWNNj9+ab31bsWsN0o+NxcfiKYCZn+4yse7TPMtP/7p0hF1VdUVk1rRjZpaRKPJIDZvref4JZgoQMnjEJlfHmSVZUcz7dPzvO09gIYRpJCLMCU0IULzUdG/NKqZWemeoSIj/ZulUwEy0luY+6z1X2SgES5phBNQZ+RZKhH+/HBoa2cD0ISNE5/bCMhCq57U1MsTdttcitb4QrwvKkZ8huiqLqWltCK8Jn1j6gKeFrAvfofIJEibwNTVHS9hs6mptMz4= X-Microsoft-Exchange-Diagnostics: 1;CY4PR12MB1141;31:p2s7z2dc6Xfch6fcRjXNCQOmiwRK4QaZNd8meHDjazz3gA8/MNRMXPVpEYGQmr+6djXDDVzW+/CgZOirW7r2S0ngfGWlgll4sSUsCqQ9VbRbh6HdXXnE5HJqLsyjYdC1p99YYmITbvCm4mbVLI893x2ZE1AHPg6VLm6+QlB40aDdnQJG946Ojgt9wgrgI3FwGHXnNW5N3HK7naLatiXJruHNBBNde7S74DSsQCR/oII=;20:8kUXwfnP7l0CTSp1hQ9lL0Nfc/eh2xnXhs5JeOdyhe72PhQO/7lNraklp90lXCIEIJ00hCi2e24RtrbRG9Le4Pt9AVIewSn/xLoWnuSt60yw/mcJoq82dOf86a3AriyQp01empAlcnvWw0ZdsmRcIAC0M0HQa17bsMDuKsuXPXUX4x6Zoj4W4sxOh/5U2lmCQj7NYYgGHx0+s0mDmbVg/syuF4Zo7Jv9GPVVd/7bt83KYbMznvFkzXZD5C8AHlZtFmuH2m1orkc4bmxRGWKOqB6ubNO5x3WWt6v21M2F1D03t1ltPkjA0t3mXVGMreiBRRbK3I4l7XaPu8L3FclsEgLJReU1dmww+9IGT3Rag1jQvvcPK054SoTJirRYiWJp9zBVBzUztGm63/KB1YjDKa1BU4yEgMTRDWRdr0k64/51uYGSx0DUq1r9u75rk1ZgmGVRSSz7vFJpm3Lxg3ND+vagLPK+mhOEuaJGRP60fxY6/qxryYPyiyGEdWf/VSFq X-Microsoft-Antispam-PRVS: X-Exchange-Antispam-Report-Test: UriScan:(767451399110)(258649278758335); X-Exchange-Antispam-Report-CFA-Test: BCL:0;PCL:0;RULEID:(6040450)(601004)(2401047)(5005006)(8121501046)(3002001)(93006095)(93001095)(10201501046)(6055026)(6041248)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123562025)(20161123555025)(20161123558100)(20161123560025)(6072148);SRVR:CY4PR12MB1141;BCL:0;PCL:0;RULEID:;SRVR:CY4PR12MB1141; X-Microsoft-Exchange-Diagnostics: 1;CY4PR12MB1141;4:g+EV+CXOnWbn6hOkzs3UAZLmknJISNKeXZIUUuz/kw46fMG9M+AwKEynORjtCjzN2LWJywx+DF6A64uYxc1wA6INvaywI0oOyEd10+8Qs87Q6uWu8El7bjraucMZEdb5OVt2TeGkMTBq2U0axj70rHAtCnOqFxa1PZzCLGwsx/+37PCl/vkWuLev9Fck5n2zKicezqhtxEuz9/UEuMogu8/Br6kKyQv6SRpF+I6cif9WbQGsQRy6jvYBE45NfMf7KZrAQcH8ZxJNWj4h47QRult++QBR8adfrH0R8orBdF/CnPAci8gYBDMo+A0xa32YH9I/aOuoqPjbE73AeIS3N/rWgBXQESInXA0NIK7ZEaH9SPQbioVOToSI6h2cE2IwfptifMUX5UacGHHOOVCqBwC4Y4F9tFgZqFDyo7iigsGEPutObEWfssJQnf2L7qvovOj374KvzsJIc9KR1xVnEOohbds9JOB4YLdlMu5ec7IPXivoKuO+iQ4sG5HPyk33q1Fi9u5qSWSzYsIHL1GCqZHIVDQ1T7rmS4Z5Md0MxPScd94c8v7UxUmOQ0cAksnE0XcnBxo1BElGCtdWjQMk2jPMdvU2RCsf3whiVb9PZ2HTShQVGTScSNbEPoeiIUv/5W3N6/rgBrKtCFruWZuCgHRAVW2LK+t2p/GO3FuJx3kCqN2O+bxJ1mwskdQDP1ZbPXXzhi3I4zTvo23SX43r09nBvS7P1lglaTkdE9z/DLX3cu+ZsiDSDQQ69GN+PwICX1rwlRG/dCPOCOHQoHJIQAg1jklWmDfU4AEV4eTMlVtanJYSiy578bqSrNnVs8xZQftXQ7hUbE8c3UuYqIjRoDNhXAneW09SJxIwToGfT0Lm+JxFLayF9KzplQdULbW/ X-Forefront-PRVS: 032334F434 X-Forefront-Antispam-Report: SFV:NSPM;SFS:(10009020)(4630300001)(6009001)(6049001)(39400400002)(39850400002)(39410400002)(39860400002)(39450400003)(39840400002)(377454003)(24454002)(2201001)(50986999)(76176999)(5660300001)(4001350100001)(6666003)(2950100002)(86362001)(575784001)(31696002)(229853002)(6116002)(36756003)(66066001)(31686004)(4326008)(81166006)(25786009)(53546009)(189998001)(83506001)(8676002)(1720100001)(42186005)(3846002)(230700001)(23746002)(7736002)(305945005)(47776003)(2906002)(65826007)(90366009)(7406005)(33646002)(7416002)(64126003)(478600001)(77096006)(72206003)(54906002)(6306002)(6246003)(6486002)(38730400002)(966005)(54356999)(53936002)(19273905006)(921003)(1121003)(563064011);DIR:OUT;SFP:1101;SCL:1;SRVR:CY4PR12MB1141;H:[10.236.64.250];FPR:;SPF:None;MLV:sfv;LANG:en; X-Microsoft-Exchange-Diagnostics: =?Windows-1252?Q?1;CY4PR12MB1141;23:g5zSdYNsTwbtvS2zu9MTaosOmvTu5KAf/Q4Sz?= =?Windows-1252?Q?BMx9ax+fTD8n60IIJ637gn44b0trqXra+/pZjh0j+6SuryX7PfJZqBpR?= =?Windows-1252?Q?O1JOefBBcnkCmiHc14cu8stYhDeKP/Tf+Z2TBgJpke0ERbO9x58QTsJB?= =?Windows-1252?Q?udM5B4e/HBBqqAeTMMOnxRwVI0gWAkWQQDcjfjdiNy6E6mk9TxmJ5wKk?= =?Windows-1252?Q?ZArNs5bPmH6093LbXhGgRHfp+RMVba0RrPzPZdTbrM2/K0Xlj1qUtA//?= =?Windows-1252?Q?+v00X8moNPC5wRyjq5sWIo8pAv8UU/pM397MiANIgxeDKyybdE3G1DUU?= =?Windows-1252?Q?P59NYcayYTEfoH567RidRzAMPfE2Grw5FAdX7Oh4jbLlU0c6IYIJDZBA?= =?Windows-1252?Q?jF+qqLOmJiHG5q+B6Lrz6MEyxIVPWZMwYTQv2W6oZPwj4zkGGGEp1XN3?= =?Windows-1252?Q?98joqsgVVQJBFTyyVj2DUQ9m/ha4Yrhw+iMmSJ1D9K9ZDonYT8Z6eett?= =?Windows-1252?Q?2vj7UC5u9w/vt2ufZAhDYGSHhLbvYCibeL5MgwOO9qWG8Eofj3oYIXs2?= =?Windows-1252?Q?tYmRsaH7vJ0DftjvfCEVo4Jbd/b1j9ebD/UMchANjdK8nyNSjRK707ZC?= =?Windows-1252?Q?edFMC2nFwm2zrLoIxQ7BmhWywNsmiTZ9/o4P3ajtGDxLm1kK8G5ljFA7?= =?Windows-1252?Q?2aT8YYWd4veLMXrsLk3WSVTAi4MELpotarKcOSgu8OLiIaiOFXrN1nd1?= =?Windows-1252?Q?wd9muQNac0pttznSb7jwCTQIeBCi6jubTmhyWyOVjzdbZFlHikar1GzL?= =?Windows-1252?Q?vnIKzOVmQ4eJQ7Ffz0Y1UtPEdbHP37xaA+WQvM51JYoHmXW0iL1OyFAH?= =?Windows-1252?Q?CNgXQWtWPdp2TvczQCuyUXeXE6fn8BPIbadkvFX5arU11NOTyimY2Ctm?= =?Windows-1252?Q?YIm/7ZwtEA62wQ1WNZi+qACHPxd3+euf+/x43rYsj65VgCgI/xispsei?= =?Windows-1252?Q?91uLkimotifexyOIj/le+BlQ0FxYgswnvD7kCuzNwJpRfKq9fsR5fRof?= =?Windows-1252?Q?CmFFD5+6KRERfJ1QRMJygZN+5DfPVSF93w8vllrcbfCbs00wuY4/twmS?= =?Windows-1252?Q?2gQDFZtDtcFnw+H1zcSJn7kZ3LmLMYpR0qytC5PhrvKQxEpulTioRrZ6?= =?Windows-1252?Q?/DQfrcoeKazxUdzDBa1CVppIbghE0isiI7ug3ltJrlDk3UY9xxu920E0?= =?Windows-1252?Q?CaXakFj5VIhfjQdo1RR839ojXeA09Semvs06MCTSM+7xtHOPWFj9r0Fr?= =?Windows-1252?Q?GQ9VPKQywneMsb+B5i7qR+ciHkUThFt96Vfl/JJ5yTpA8bjpb5h1nHHt?= =?Windows-1252?Q?3lheG+zy8df5NZNOiTJvEr99K/KRKveYn9EEX6kLCGiAlElgRo6jsJWT?= =?Windows-1252?Q?73a9srmc5UYcUUaaog6DfZ6Sao58IxvdmlPea3gblrfKR3TAAyU2FxU5?= =?Windows-1252?Q?LI9orQN4JHb401tfdZHt6roRMGGTNi663p2L8P1j83+2vx6LOrI/GR1i?= =?Windows-1252?Q?Nmbm26eVDnyYj3RsbZ8L/Zf5BfHbaOZBLn0IsGqz0ng8yAbbPa9pFnVP?= =?Windows-1252?Q?F3EUfIRpJg2lcAX1tp4vw7JN6BQAOFxNorB1uzmTmJ/?= X-Microsoft-Exchange-Diagnostics: 1;CY4PR12MB1141;6:ys9FXjlA0rSNUd+9ZIHmnU4D/UzY9XDrRasdgLnyQqn/LgFIk1GMLN9Z0rGR/5zMRrUp4QVRBsSF6RcX3YA55orAO192/hT8UUHwgx0fJbeLQ5Ercp6MoMi9l2QQA16VOKh2NpWwr0kIqFofRu7yLSGokhkNEkDPcKOQyxHnY/KLwR7As3I+ZNQLhUZqHxETnjHu+W29HP4GV2V7v5YkKpb8sAgtjyQ44LpF+ak+5ckYcYaum0QCoy4ZC+ZToH3MY/eLbb4wElsBKpkKv2CSLNOTCcx/RB12YViVnG3kxJ+Ah7J493Z4SsR4Y13B/ZJayAA1o7J4I8pbC/CnqVaTcOBg+SX6WFvHH7RCjlBESt/6IRnnW2a+ItPWPwjV53ezBzy49g7bFGcMk6/i/4yznNv5/Y+lMHQgV2oXNP23v5kZ4AaBEAltV/ovC6+rT57pWfQnBKyJuVXHpDw6xfFbtOkgAvtTauLuDAWq7dafsfE/joGPlI8/2Egq+nHLivX7tF0eGuQAov/yv13Qdz+0ZPTYaqfkERn3+5i2Byb1yXY=;5:e0mGyb38hItFRk4Q1Uf+HAMm8yrEkPtt0BLrlrCpvF4912smVua8LVZAa6iOrLMC6x6rRhxMCjpTqKxq3PrtfMxpt87tNh/aDbhiJCTsvjPbc0IQ8h9aEg08rmHuUj6T/RwQ14WNXoqx02AqufWl4g==;24:zedRi70Fu6nRrmbdy4KOiwB+fvbDcO8hlBLSlav7vcpEJC1eOJ+3heuPjcb512tDcXnK97wzoojTpVtkv8txsc1cU6v6CEnqJOPfuVFSHCs= SpamDiagnosticOutput: 1:99 SpamDiagnosticMetadata: NSPM X-Microsoft-Exchange-Diagnostics: 1;CY4PR12MB1141;7:KJhmPHzEpiNClBcdNxClhzuI4PqbIYCcUEBH7AmSOG24E56N9mfl50QMct0deHMz0+2oSwohrMgZZ6Y8icMRdZDQPrRqPkz6JnaMY5TRhXs3ktMetLA3jptDvJcQiJP/9wmbfsZKA+cXftmbj2Kq2HDmxQ3UU6rjQ6HRH+BrDhFPkO6331wcEbjt7Ey8ji8YjIv/86WPciRPYV9gZzbA4P+Lvlr18JaC/wNximNdH7Z2aW0S/1IOqWg2pbcdE55vKlnhfzJ7pWc2cTUg1sWQm2MyhjtBKT9n7md316pVW4Jv3ziIVibXGFdPnfx1t2ZbtEWKhf3PKhtFycxUnqZ3+Q==;20:Bz/s4iCDeTb0V5nfjEQ1yeEU9BQhuXY3F6K/kDLvR+8oS1v1olMwg4WQ3t1LDMJYoYnLUZXHiDXZJaEHLDhBiSmvj30kOuWlRKk7MBMWPgH4fPT9oFbzMTD26jyUWao5d24DuNgtdp+EfgtbqMIVkuCS2XOvAEU/S8g2dDHSqYILONnd0I+N6kFC5C+/gccFGVKwtc4A4glJItTO5LPG4DqAEDQpKh+tJrcuWRxs72/AJLaYN79iGBQz+vJjFN4F X-OriginatorOrg: amd.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 30 May 2017 17:46:21.5636 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR12MB1141 Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 5/25/2017 11:17 PM, Xunlei Pang wrote: > On 04/19/2017 at 05:21 AM, Tom Lendacky wrote: >> Provide support so that kexec can be used to boot a kernel when SME is >> enabled. >> >> Support is needed to allocate pages for kexec without encryption. This >> is needed in order to be able to reboot in the kernel in the same manner >> as originally booted. > > Hi Tom, > > Looks like kdump will break, I didn't see the similar handling for kdump cases, see kernel: > kimage_alloc_crash_control_pages(), kimage_load_crash_segment(), etc. > > We need to support kdump with SME, kdump kernel/initramfs/purgatory/elfcorehdr/etc > are all loaded into the reserved memory(see crashkernel=X) by userspace kexec-tools. > I think a straightforward way would be to mark the whole reserved memory range without > encryption before loading all the kexec segments for kdump, I guess we can handle this > easily in arch_kexec_unprotect_crashkres(). Yes, that would work. > > Moreover, now that "elfcorehdr=X" is left as decrypted, it needs to be remapped to the > encrypted data. This is an area that I'm not familiar with, so I don't completely understand the flow in regards to where/when/how the ELF headers are copied and what needs to be done. Can you elaborate a bit on this? Thanks, Tom > > Regards, > Xunlei > >> >> Additionally, when shutting down all of the CPUs we need to be sure to >> flush the caches and then halt. This is needed when booting from a state >> where SME was not active into a state where SME is active (or vice-versa). >> Without these steps, it is possible for cache lines to exist for the same >> physical location but tagged both with and without the encryption bit. This >> can cause random memory corruption when caches are flushed depending on >> which cacheline is written last. >> >> Signed-off-by: Tom Lendacky >> --- >> arch/x86/include/asm/init.h | 1 + >> arch/x86/include/asm/irqflags.h | 5 +++++ >> arch/x86/include/asm/kexec.h | 8 ++++++++ >> arch/x86/include/asm/pgtable_types.h | 1 + >> arch/x86/kernel/machine_kexec_64.c | 35 +++++++++++++++++++++++++++++++++- >> arch/x86/kernel/process.c | 26 +++++++++++++++++++++++-- >> arch/x86/mm/ident_map.c | 11 +++++++---- >> include/linux/kexec.h | 14 ++++++++++++++ >> kernel/kexec_core.c | 7 +++++++ >> 9 files changed, 101 insertions(+), 7 deletions(-) >> >> diff --git a/arch/x86/include/asm/init.h b/arch/x86/include/asm/init.h >> index 737da62..b2ec511 100644 >> --- a/arch/x86/include/asm/init.h >> +++ b/arch/x86/include/asm/init.h >> @@ -6,6 +6,7 @@ struct x86_mapping_info { >> void *context; /* context for alloc_pgt_page */ >> unsigned long pmd_flag; /* page flag for PMD entry */ >> unsigned long offset; /* ident mapping offset */ >> + unsigned long kernpg_flag; /* kernel pagetable flag override */ >> }; >> >> int kernel_ident_mapping_init(struct x86_mapping_info *info, pgd_t *pgd_page, >> diff --git a/arch/x86/include/asm/irqflags.h b/arch/x86/include/asm/irqflags.h >> index ac7692d..38b5920 100644 >> --- a/arch/x86/include/asm/irqflags.h >> +++ b/arch/x86/include/asm/irqflags.h >> @@ -58,6 +58,11 @@ static inline __cpuidle void native_halt(void) >> asm volatile("hlt": : :"memory"); >> } >> >> +static inline __cpuidle void native_wbinvd_halt(void) >> +{ >> + asm volatile("wbinvd; hlt" : : : "memory"); >> +} >> + >> #endif >> >> #ifdef CONFIG_PARAVIRT >> diff --git a/arch/x86/include/asm/kexec.h b/arch/x86/include/asm/kexec.h >> index 70ef205..e8183ac 100644 >> --- a/arch/x86/include/asm/kexec.h >> +++ b/arch/x86/include/asm/kexec.h >> @@ -207,6 +207,14 @@ struct kexec_entry64_regs { >> uint64_t r15; >> uint64_t rip; >> }; >> + >> +extern int arch_kexec_post_alloc_pages(void *vaddr, unsigned int pages, >> + gfp_t gfp); >> +#define arch_kexec_post_alloc_pages arch_kexec_post_alloc_pages >> + >> +extern void arch_kexec_pre_free_pages(void *vaddr, unsigned int pages); >> +#define arch_kexec_pre_free_pages arch_kexec_pre_free_pages >> + >> #endif >> >> typedef void crash_vmclear_fn(void); >> diff --git a/arch/x86/include/asm/pgtable_types.h b/arch/x86/include/asm/pgtable_types.h >> index ce8cb1c..0f326f4 100644 >> --- a/arch/x86/include/asm/pgtable_types.h >> +++ b/arch/x86/include/asm/pgtable_types.h >> @@ -213,6 +213,7 @@ enum page_cache_mode { >> #define PAGE_KERNEL __pgprot(__PAGE_KERNEL | _PAGE_ENC) >> #define PAGE_KERNEL_RO __pgprot(__PAGE_KERNEL_RO | _PAGE_ENC) >> #define PAGE_KERNEL_EXEC __pgprot(__PAGE_KERNEL_EXEC | _PAGE_ENC) >> +#define PAGE_KERNEL_EXEC_NOENC __pgprot(__PAGE_KERNEL_EXEC) >> #define PAGE_KERNEL_RX __pgprot(__PAGE_KERNEL_RX | _PAGE_ENC) >> #define PAGE_KERNEL_NOCACHE __pgprot(__PAGE_KERNEL_NOCACHE | _PAGE_ENC) >> #define PAGE_KERNEL_LARGE __pgprot(__PAGE_KERNEL_LARGE | _PAGE_ENC) >> diff --git a/arch/x86/kernel/machine_kexec_64.c b/arch/x86/kernel/machine_kexec_64.c >> index 085c3b3..11c0ca9 100644 >> --- a/arch/x86/kernel/machine_kexec_64.c >> +++ b/arch/x86/kernel/machine_kexec_64.c >> @@ -86,7 +86,7 @@ static int init_transition_pgtable(struct kimage *image, pgd_t *pgd) >> set_pmd(pmd, __pmd(__pa(pte) | _KERNPG_TABLE)); >> } >> pte = pte_offset_kernel(pmd, vaddr); >> - set_pte(pte, pfn_pte(paddr >> PAGE_SHIFT, PAGE_KERNEL_EXEC)); >> + set_pte(pte, pfn_pte(paddr >> PAGE_SHIFT, PAGE_KERNEL_EXEC_NOENC)); >> return 0; >> err: >> free_transition_pgtable(image); >> @@ -114,6 +114,7 @@ static int init_pgtable(struct kimage *image, unsigned long start_pgtable) >> .alloc_pgt_page = alloc_pgt_page, >> .context = image, >> .pmd_flag = __PAGE_KERNEL_LARGE_EXEC, >> + .kernpg_flag = _KERNPG_TABLE_NOENC, >> }; >> unsigned long mstart, mend; >> pgd_t *level4p; >> @@ -597,3 +598,35 @@ void arch_kexec_unprotect_crashkres(void) >> { >> kexec_mark_crashkres(false); >> } >> + >> +int arch_kexec_post_alloc_pages(void *vaddr, unsigned int pages, gfp_t gfp) >> +{ >> + int ret; >> + >> + if (sme_active()) { >> + /* >> + * If SME is active we need to be sure that kexec pages are >> + * not encrypted because when we boot to the new kernel the >> + * pages won't be accessed encrypted (initially). >> + */ >> + ret = set_memory_decrypted((unsigned long)vaddr, pages); >> + if (ret) >> + return ret; >> + >> + if (gfp & __GFP_ZERO) >> + memset(vaddr, 0, pages * PAGE_SIZE); >> + } >> + >> + return 0; >> +} >> + >> +void arch_kexec_pre_free_pages(void *vaddr, unsigned int pages) >> +{ >> + if (sme_active()) { >> + /* >> + * If SME is active we need to reset the pages back to being >> + * an encrypted mapping before freeing them. >> + */ >> + set_memory_encrypted((unsigned long)vaddr, pages); >> + } >> +} >> diff --git a/arch/x86/kernel/process.c b/arch/x86/kernel/process.c >> index 0bb8842..f4e5de6 100644 >> --- a/arch/x86/kernel/process.c >> +++ b/arch/x86/kernel/process.c >> @@ -24,6 +24,7 @@ >> #include >> #include >> #include >> +#include >> #include >> #include >> #include >> @@ -355,8 +356,25 @@ bool xen_set_default_idle(void) >> return ret; >> } >> #endif >> + >> void stop_this_cpu(void *dummy) >> { >> + bool do_wbinvd_halt = false; >> + >> + if (kexec_in_progress && boot_cpu_has(X86_FEATURE_SME)) { >> + /* >> + * If we are performing a kexec and the processor supports >> + * SME then we need to clear out cache information before >> + * halting. With kexec, going from SME inactive to SME active >> + * requires clearing cache entries so that addresses without >> + * the encryption bit set don't corrupt the same physical >> + * address that has the encryption bit set when caches are >> + * flushed. Perform a wbinvd followed by a halt to achieve >> + * this. >> + */ >> + do_wbinvd_halt = true; >> + } >> + >> local_irq_disable(); >> /* >> * Remove this CPU: >> @@ -365,8 +383,12 @@ void stop_this_cpu(void *dummy) >> disable_local_APIC(); >> mcheck_cpu_clear(this_cpu_ptr(&cpu_info)); >> >> - for (;;) >> - halt(); >> + for (;;) { >> + if (do_wbinvd_halt) >> + native_wbinvd_halt(); >> + else >> + halt(); >> + } >> } >> >> /* >> diff --git a/arch/x86/mm/ident_map.c b/arch/x86/mm/ident_map.c >> index 04210a2..2c9fd3e 100644 >> --- a/arch/x86/mm/ident_map.c >> +++ b/arch/x86/mm/ident_map.c >> @@ -20,6 +20,7 @@ static void ident_pmd_init(struct x86_mapping_info *info, pmd_t *pmd_page, >> static int ident_pud_init(struct x86_mapping_info *info, pud_t *pud_page, >> unsigned long addr, unsigned long end) >> { >> + unsigned long kernpg_flag = info->kernpg_flag ? : _KERNPG_TABLE; >> unsigned long next; >> >> for (; addr < end; addr = next) { >> @@ -39,7 +40,7 @@ static int ident_pud_init(struct x86_mapping_info *info, pud_t *pud_page, >> if (!pmd) >> return -ENOMEM; >> ident_pmd_init(info, pmd, addr, next); >> - set_pud(pud, __pud(__pa(pmd) | _KERNPG_TABLE)); >> + set_pud(pud, __pud(__pa(pmd) | kernpg_flag)); >> } >> >> return 0; >> @@ -48,6 +49,7 @@ static int ident_pud_init(struct x86_mapping_info *info, pud_t *pud_page, >> static int ident_p4d_init(struct x86_mapping_info *info, p4d_t *p4d_page, >> unsigned long addr, unsigned long end) >> { >> + unsigned long kernpg_flag = info->kernpg_flag ? : _KERNPG_TABLE; >> unsigned long next; >> >> for (; addr < end; addr = next) { >> @@ -67,7 +69,7 @@ static int ident_p4d_init(struct x86_mapping_info *info, p4d_t *p4d_page, >> if (!pud) >> return -ENOMEM; >> ident_pud_init(info, pud, addr, next); >> - set_p4d(p4d, __p4d(__pa(pud) | _KERNPG_TABLE)); >> + set_p4d(p4d, __p4d(__pa(pud) | kernpg_flag)); >> } >> >> return 0; >> @@ -76,6 +78,7 @@ static int ident_p4d_init(struct x86_mapping_info *info, p4d_t *p4d_page, >> int kernel_ident_mapping_init(struct x86_mapping_info *info, pgd_t *pgd_page, >> unsigned long pstart, unsigned long pend) >> { >> + unsigned long kernpg_flag = info->kernpg_flag ? : _KERNPG_TABLE; >> unsigned long addr = pstart + info->offset; >> unsigned long end = pend + info->offset; >> unsigned long next; >> @@ -104,14 +107,14 @@ int kernel_ident_mapping_init(struct x86_mapping_info *info, pgd_t *pgd_page, >> if (result) >> return result; >> if (IS_ENABLED(CONFIG_X86_5LEVEL)) { >> - set_pgd(pgd, __pgd(__pa(p4d) | _KERNPG_TABLE)); >> + set_pgd(pgd, __pgd(__pa(p4d) | kernpg_flag)); >> } else { >> /* >> * With p4d folded, pgd is equal to p4d. >> * The pgd entry has to point to the pud page table in this case. >> */ >> pud_t *pud = pud_offset(p4d, 0); >> - set_pgd(pgd, __pgd(__pa(pud) | _KERNPG_TABLE)); >> + set_pgd(pgd, __pgd(__pa(pud) | kernpg_flag)); >> } >> } >> >> diff --git a/include/linux/kexec.h b/include/linux/kexec.h >> index d419d0e..1c76e3b 100644 >> --- a/include/linux/kexec.h >> +++ b/include/linux/kexec.h >> @@ -383,6 +383,20 @@ static inline void *boot_phys_to_virt(unsigned long entry) >> return phys_to_virt(boot_phys_to_phys(entry)); >> } >> >> +#ifndef arch_kexec_post_alloc_pages >> +static inline int arch_kexec_post_alloc_pages(void *vaddr, unsigned int pages, >> + gfp_t gfp) >> +{ >> + return 0; >> +} >> +#endif >> + >> +#ifndef arch_kexec_pre_free_pages >> +static inline void arch_kexec_pre_free_pages(void *vaddr, unsigned int pages) >> +{ >> +} >> +#endif >> + >> #else /* !CONFIG_KEXEC_CORE */ >> struct pt_regs; >> struct task_struct; >> diff --git a/kernel/kexec_core.c b/kernel/kexec_core.c >> index bfe62d5..bb5e7e3 100644 >> --- a/kernel/kexec_core.c >> +++ b/kernel/kexec_core.c >> @@ -38,6 +38,7 @@ >> #include >> #include >> #include >> +#include >> >> #include >> #include >> @@ -315,6 +316,9 @@ static struct page *kimage_alloc_pages(gfp_t gfp_mask, unsigned int order) >> count = 1 << order; >> for (i = 0; i < count; i++) >> SetPageReserved(pages + i); >> + >> + arch_kexec_post_alloc_pages(page_address(pages), count, >> + gfp_mask); >> } >> >> return pages; >> @@ -326,6 +330,9 @@ static void kimage_free_pages(struct page *page) >> >> order = page_private(page); >> count = 1 << order; >> + >> + arch_kexec_pre_free_pages(page_address(page), count); >> + >> for (i = 0; i < count; i++) >> ClearPageReserved(page + i); >> __free_pages(page, order); >> >> >> _______________________________________________ >> kexec mailing list >> kexec@lists.infradead.org >> http://lists.infradead.org/mailman/listinfo/kexec >