From: Pierre Morel <pmorel@linux.ibm.com>
To: Halil Pasic <pasic@linux.ibm.com>
Cc: Christian Borntraeger <borntraeger@de.ibm.com>,
Tony Krowiak <akrowiak@linux.ibm.com>,
alex.williamson@redhat.com, cohuck@redhat.com,
linux-kernel@vger.kernel.org, linux-s390@vger.kernel.org,
kvm@vger.kernel.org, frankja@linux.ibm.com, david@redhat.com,
schwidefsky@de.ibm.com, heiko.carstens@de.ibm.com,
freude@linux.ibm.com, mimu@linux.ibm.com
Subject: Re: [PATCH v4 1/7] s390: ap: kvm: add PQAP interception for AQIC
Date: Fri, 1 Mar 2019 13:10:37 +0100 [thread overview]
Message-ID: <e70df42f-f9d7-b566-a3d7-2dc3f717d352@linux.ibm.com> (raw)
In-Reply-To: <20190228175132.0b5b6424@oc2783563651>
On 28/02/2019 17:51, Halil Pasic wrote:
> On Thu, 28 Feb 2019 15:12:16 +0100
> Pierre Morel <pmorel@linux.ibm.com> wrote:
>
>> On 28/02/2019 13:39, Halil Pasic wrote:
>>> On Thu, 28 Feb 2019 10:42:23 +0100
>>> Christian Borntraeger <borntraeger@de.ibm.com> wrote:
> [..]
>>>> Correct?
>>>
>>> IMHO mostly.
>>>
>>> I also doing the facility checks in kvm is easier, and I think this is
>>> something we can change later if needed without any major trouble.
>>>
>>> There are a couple of things I would do differently than Pierre does:
>>> 1) Do the PGM_PRIVILEGED_OP before the fc == 3 check.
>>
>> Idea was not to modify existing behavior for fc != 3
>>
>> Also Christian already proposed to handle all FC codes. So in this idea,
>> this must be done as you say.
>>
>>>
>>> 2) Do the test_kvm_facility(vcpu->kvm, 65) check in the context of fc ==
>>> 3. I.e. decide if this hook is about pqap or just about pqap aqic and
>>> make the code convey that decision to its reader.
>>>
>>> 3) I would most probably test if the queue is available by looking at the
>>> masks in CRYCB here. If not AP_RESPONSE_Q_NOT_AVAIL is what we need.
>>
>> This I do not agree with, it is typically the responsibility of the part
>> in charge of the virtualization to do this, also the vfio_driver.
>>
>
> See at 4) regarding the details. My guess is you disagree with checking
> CRYCB explicitly but don't digress with AP_RESPONSE_Q_NOT_AVAIL if APCB
> does not authorize the queue. Your idea was to infer APCB all zero from
> the fact that pqap_hook is NULL.
>
> If my assumption is right, then yes we can have an implicit coarse check
> here and a fine grained check in the client code (vfio_ap).
>
>>>
>>> 4) If we have APIE and queues authorized by the CRYCB (i.e. we have a
>>> vfio_ap module loaded an an mdev associated with the kvm) the callback
>>> not set (!(vcpu->kvm->arch.crypto.pqap_hook)) is a BUG!
>>
>> I do not agree with this either, the maintainers ;) will not allow this.
>
> After an offline discussion we came to the conclusion that I did not
> understand your code.
>
> Your train of thought was:
>
> !(vcpu->kvm->arch.crypto.pqap_hook) _implies_ APCB all zero (i.e. the
> masks in the CRYCB
>
> This is *why* you respond with AP_RESPONSE_Q_NOT_AVAIL.
>
> However if that is the case I would like that spelled out in a code
> comment at least. Furthermore setting pqap_hook and APCB needs to happen
> in the right sequence. Means client code (vfio_ap) may only set APCB
> after the qpap_hook has been set. Currently we have a race there (as
> you first do kvm_arch_crypto_set_masks and only then
> kvm->arch.crypto.pqap_hook. Furthermore I guess
> kvm->arch.crypto.pqap_hook needs to be set with the kvm lock held, which
> does not seem to be the case.
Yes, that is right.
This part (setting/resetting hook and CRYCB will be modified for the
reason you mention and also to correctly handle the order of releasing
KVM and VFIO, as you and Christian mentioned.
>
>>
>>> In that case
>>> lying that the queue is not available does not seem right. BTW this
>>> is something Pierre changed since the last version quietly (I can't
>>> recall a mention in the change log or somebody asking for this). If
>>> we want to be very pedantic about this bug scenario our best bet is
>>> probably response code 6.
>>
>>
>> RC 06 means "Invalid address of AP-queue notification byte"
>>
>> So you must have think about another code or I do not understand at
>> all what you mean.
>>
>
> I did not assume you decided to ignore the possibility of a programming
> error (which you at least technically did commit yourself) for what I
> described as a BUG.
>
> My train of thought was, if we are very pedantic we can make things work
> with degraded functionality in that case. I.e. without AP interrupts.
> For that we need to tell the guest something like: yes your queue is
> fine and there and all that but AQCI setup interrupts did not work. And
> RC 06 is the only RC I see being suitable to convey that.
>
> Detect and handle if the client code does not hold up their end of the
> bargain or just ignore the possibility is a design decision. But at least
> you should spell out your expectations against the client code.
>
> Regards,
> Halil
>
I prefer to comment the obligation for the vfio_driver to register the
callback instead to add code complexity for which will eventually go
deeper and deeper.
Thanks,
Pierre
--
Pierre Morel
Linux/KVM/QEMU in Böblingen - Germany
next prev parent reply other threads:[~2019-03-01 12:10 UTC|newest]
Thread overview: 79+ messages / expand[flat|nested] mbox.gz Atom feed top
2019-02-22 15:29 [PATCH v4 0/7] vfio: ap: AP Queue Interrupt Control Pierre Morel
2019-02-22 15:29 ` [PATCH v4 1/7] s390: ap: kvm: add PQAP interception for AQIC Pierre Morel
2019-02-25 18:36 ` Tony Krowiak
2019-02-26 11:47 ` Pierre Morel
2019-02-26 15:47 ` Tony Krowiak
2019-02-27 8:09 ` Pierre Morel
2019-02-27 9:13 ` Cornelia Huck
2019-02-27 10:16 ` Pierre Morel
2019-02-27 18:00 ` Tony Krowiak
2019-02-28 9:42 ` Christian Borntraeger
2019-02-28 11:03 ` Christian Borntraeger
2019-02-28 11:22 ` Cornelia Huck
2019-02-28 13:16 ` Pierre Morel
2019-02-28 13:52 ` Cornelia Huck
2019-02-28 14:14 ` Pierre Morel
2019-03-01 12:03 ` Pierre Morel
2019-03-01 12:05 ` Christian Borntraeger
2019-03-01 12:36 ` Cornelia Huck
2019-03-01 15:32 ` Pierre Morel
2019-02-28 13:10 ` Pierre Morel
2019-02-28 15:36 ` Tony Krowiak
2019-02-28 12:39 ` Halil Pasic
2019-02-28 14:12 ` Pierre Morel
2019-02-28 16:51 ` Halil Pasic
2019-03-01 12:10 ` Pierre Morel [this message]
2019-02-28 15:43 ` Tony Krowiak
2019-02-28 13:23 ` Pierre Morel
2019-02-28 13:44 ` Christian Borntraeger
2019-02-28 13:47 ` Pierre Morel
2019-02-28 14:07 ` Halil Pasic
2019-02-28 14:13 ` Pierre Morel
2019-02-28 15:45 ` Tony Krowiak
2019-02-28 15:35 ` Tony Krowiak
2019-03-01 8:42 ` Christian Borntraeger
2019-02-28 8:31 ` Christian Borntraeger
2019-02-22 15:29 ` [PATCH v4 2/7] s390: ap: new vfio_ap_queue structure Pierre Morel
2019-02-26 16:10 ` Tony Krowiak
2019-02-27 8:40 ` Pierre Morel
2019-02-27 20:35 ` Tony Krowiak
2019-02-22 15:29 ` [PATCH v4 3/7] s390: ap: associate a ap_vfio_queue and a matrix mdev Pierre Morel
2019-02-26 18:14 ` Tony Krowiak
2019-02-27 9:29 ` Pierre Morel
2019-02-27 20:14 ` Tony Krowiak
2019-02-27 9:32 ` Cornelia Huck
2019-02-27 10:21 ` Pierre Morel
2019-02-27 10:44 ` Pierre Morel
2019-02-27 20:53 ` Tony Krowiak
2019-03-04 2:09 ` Halil Pasic
2019-03-04 10:19 ` Pierre Morel
2019-03-05 22:17 ` Tony Krowiak
2019-03-12 21:39 ` Tony Krowiak
2019-03-13 10:19 ` Pierre Morel
2019-02-22 15:29 ` [PATCH v4 4/7] vfio: ap: register IOMMU VFIO notifier Pierre Morel
2019-02-27 9:42 ` Cornelia Huck
2019-02-27 10:22 ` Pierre Morel
2019-02-28 8:23 ` Christian Borntraeger
2019-02-28 8:48 ` Pierre Morel
2019-02-28 16:55 ` Halil Pasic
2019-03-01 7:51 ` Christian Borntraeger
2019-02-22 15:29 ` [PATCH v4 5/7] s390: ap: implement PAPQ AQIC interception in kernel Pierre Morel
2019-02-26 18:23 ` Tony Krowiak
2019-02-27 9:54 ` Pierre Morel
2019-02-27 18:17 ` Tony Krowiak
2019-02-27 18:18 ` Tony Krowiak
2019-02-28 20:20 ` Christian Borntraeger
2019-03-01 9:35 ` Pierre Morel
2019-03-04 1:57 ` Halil Pasic
2019-03-04 9:47 ` Pierre Morel
2019-02-22 15:29 ` [PATCH v4 6/7] s390: ap: Cleanup on removing the AP device Pierre Morel
2019-02-26 18:27 ` Tony Krowiak
2019-02-27 9:58 ` Pierre Morel
2019-03-04 13:02 ` Cornelia Huck
2019-03-08 22:43 ` Tony Krowiak
2019-03-11 8:31 ` Pierre Morel
2019-03-12 21:53 ` Tony Krowiak
2019-03-13 10:15 ` Pierre Morel
2019-02-22 15:30 ` [PATCH v4 7/7] s390: ap: kvm: Enable PQAP/AQIC facility for the guest Pierre Morel
2019-02-28 15:08 ` [PATCH v4 0/7] vfio: ap: AP Queue Interrupt Control Halil Pasic
2019-03-01 9:40 ` Pierre Morel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e70df42f-f9d7-b566-a3d7-2dc3f717d352@linux.ibm.com \
--to=pmorel@linux.ibm.com \
--cc=akrowiak@linux.ibm.com \
--cc=alex.williamson@redhat.com \
--cc=borntraeger@de.ibm.com \
--cc=cohuck@redhat.com \
--cc=david@redhat.com \
--cc=frankja@linux.ibm.com \
--cc=freude@linux.ibm.com \
--cc=heiko.carstens@de.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=mimu@linux.ibm.com \
--cc=pasic@linux.ibm.com \
--cc=schwidefsky@de.ibm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®