Received: by 10.192.165.148 with SMTP id m20csp4491170imm; Tue, 8 May 2018 09:15:00 -0700 (PDT) X-Google-Smtp-Source: AB8JxZob9t8tIk1jgDSn6Q9V8KnLkPdlke18UhVQfuq6wZDyNSepz+vNGN2VDLqosCP0u9D4EKs4 X-Received: by 2002:a17:902:b582:: with SMTP id a2-v6mr14598797pls.371.1525796100226; Tue, 08 May 2018 09:15:00 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1525796100; cv=none; d=google.com; s=arc-20160816; b=j8B6yHCui/7wF0ppsuiXy+kj1A4RKzhIK7tPERcIidJxeRQMRdbW7V+B6XfDnuvmLO mNVQhzpxoXnhYcCGk77CZY2mHrY0TM+q/i3XbXGIReaGnXSdREqBskenCQBDZQV5xAom PtecCWSFpOt7Ax2PeHkzP9CaAE20aXXIlbxf6vP9cIivVC6mYUBrm5JjH3Mxg488JPtT QWofKEy6T2phlZ5R409bnLPPCptT4EuosTuhYF72heYAoA4JQt3LCjwRefDH+lEaN2LN 45jlxcGJ6NylzyuwOopJr3eflKafhtocJDbfFhPL8YbSZLcylkyc9X9g2QrL/jmfaf9O 9rxQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding :content-language:in-reply-to:mime-version:user-agent:date :message-id:autocrypt:openpgp:from:references:cc:to:subject :arc-authentication-results; bh=zqkORTS0RNj68tBpfhX4vbFM/ZfDOepTshmuWMF2IHg=; b=q78V0599XjK3mHK58hpNYJX+019bOolC34TDUpsRvQ3T4e45v6dvxQl2P9PnXdiigC bh9UcysFZbA4/a/kVPslaryxriUtFju/eIPnEs8wyKoN983c1ScpIb3D5G2oWN+jw8O4 VMrb10hkj2iKRKfW0T4jOhmpkSezc4wrvYMosn/da+LzYA80oyhh9gowflYkVqud3SwV qMaXxczSkwH9vrVizc5ilCOTGVdLFkw/2Vw4OtB2/VBe+oXcC4bWhKsPHavo9E1UDCT3 bPdzOAQ0CFPEEKXEaATdpNt+GB9zEbMnK6on1OZpl9FbzzIy3Nsi6gQJlnib3HiaZ7BS RFYQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id p5-v6si22974115plk.537.2018.05.08.09.14.45; Tue, 08 May 2018 09:15:00 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755237AbeEHQOP (ORCPT + 99 others); Tue, 8 May 2018 12:14:15 -0400 Received: from mx3-rdu2.redhat.com ([66.187.233.73]:45542 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S932726AbeEHQOM (ORCPT ); Tue, 8 May 2018 12:14:12 -0400 Received: from smtp.corp.redhat.com (int-mx05.intmail.prod.int.rdu2.redhat.com [10.11.54.5]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id A1F5E402335F; Tue, 8 May 2018 16:14:11 +0000 (UTC) Received: from [10.36.116.179] (ovpn-116-179.ams2.redhat.com [10.36.116.179]) by smtp.corp.redhat.com (Postfix) with ESMTPS id E6809AFD52; Tue, 8 May 2018 16:14:09 +0000 (UTC) Subject: Re: [PATCH 0/3] KVM: VMX: Allow to disable ioport intercept per-VM by userspace To: Wanpeng Li , LKML , kvm Cc: =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Tim Shearer , Liran Alon References: <1523943962-25415-1-git-send-email-wanpengli@tencent.com> From: Paolo Bonzini Openpgp: preference=signencrypt Autocrypt: addr=pbonzini@redhat.com; prefer-encrypt=mutual; keydata= xsEhBFRCcBIBDqDGsz4K0zZun3jh+U6Z9wNGLKQ0kSFyjN38gMqU1SfP+TUNQepFHb/Gc0E2 CxXPkIBTvYY+ZPkoTh5xF9oS1jqI8iRLzouzF8yXs3QjQIZ2SfuCxSVwlV65jotcjD2FTN04 hVopm9llFijNZpVIOGUTqzM4U55sdsCcZUluWM6x4HSOdw5F5Utxfp1wOjD/v92Lrax0hjiX DResHSt48q+8FrZzY+AUbkUS+Jm34qjswdrgsC5uxeVcLkBgWLmov2kMaMROT0YmFY6A3m1S P/kXmHDXxhe23gKb3dgwxUTpENDBGcfEzrzilWueOeUWiOcWuFOed/C3SyijBx3Av/lbCsHU Vx6pMycNTdzU1BuAroB+Y3mNEuW56Yd44jlInzG2UOwt9XjjdKkJZ1g0P9dwptwLEgTEd3Fo UdhAQyRXGYO8oROiuh+RZ1lXp6AQ4ZjoyH8WLfTLf5g1EKCTc4C1sy1vQSdzIRu3rBIjAvnC tGZADei1IExLqB3uzXKzZ1BZ+Z8hnt2og9hb7H0y8diYfEk2w3R7wEr+Ehk5NQsT2MPI2QBd wEv1/Aj1DgUHZAHzG1QN9S8wNWQ6K9DqHZTBnI1hUlkp22zCSHK/6FwUCuYp1zcAEQEAAc0f UGFvbG8gQm9uemluaSA8Ym9uemluaUBnbnUub3JnPsLBTQQTAQIAIwUCVEJ7AwIbAwcLCQgH AwIBBhUIAgkKCwQWAgMBAh4BAheAAAoJEH4VEAzNNmmxNcwOniaZVLsuy1lW/ntYCA0Caz0i sHpmecK8aWlvL9wpQCk4GlOX9L1emyYXZPmzIYB0IRqmSzAlZxi+A2qm9XOxs5gJ2xqMEXX5 FMtUH3kpkWWJeLqe7z0EoQdUI4EG988uv/tdZyqjUn2XJE+K01x7r3MkUSFz/HZKZiCvYuze VlS0NTYdUt5jBXualvAwNKfxEkrxeHjxgdFHjYWhjflahY7TNRmuqPM/Lx7wAuyoDjlYNE40 Z+Kun4/KjMbjgpcF4Nf3PJQR8qXI6p3so2qsSn91tY7DFSJO6v2HwFJkC2jU95wxfNmTEUZc znXahYbVOwCDJRuPrE5GKFd/XJU9u5hNtr/uYipHij01WXal2cce1S5mn1/HuM1yo1u8xdHy IupCd57EWI948e8BlhpujUCU2tzOb2iYS0kpmJ9/oLVZrOcSZCcCl2P0AaCAsj59z2kwQS9D du0WxUs8waso0Qq6tDEHo8yLCOJDzSz4oojTtWe4zsulVnWV+wu70AioemAT8S6JOtlu60C5 dHgQUD1Tp+ReXpDKXmjbASJx4otvW0qah3o6JaqO79tbDqIvncu3tewwp6c85uZd48JnIOh3 utBAu684nJakbbvZUGikJfxd887ATQRUQnHuAQgAx4dxXO6/Zun0eVYOnr5GRl76+2UrAAem Vv9Yfn2PbDIbxXqLff7oyVJIkw4WdhQIIvvtu5zH24iYjmdfbg8iWpP7NqxUQRUZJEWbx2CR wkMHtOmzQiQ2tSLjKh/cHeyFH68xjeLcinR7jXMrHQK+UCEw6jqi1oeZzGvfmxarUmS0uRuf fAb589AJW50kkQK9VD/9QC2FJISSUDnRC0PawGSZDXhmvITJMdD4TjYrePYhSY4uuIV02v02 8TVAaYbIhxvDY0hUQE4r8ZbGRLn52bEzaIPgl1p/adKfeOUeMReg/CkyzQpmyB1TSk8lDMxQ zCYHXAzwnGi8WU9iuE1P0wARAQABwsEzBBgBAgAJBQJUQnHuAhsMAAoJEH4VEAzNNmmxp1EO oJy0uZggJm7gZKeJ7iUpeX4eqUtqelUw6gU2daz2hE/jsxsTbC/w5piHmk1H1VWDKEM4bQBT uiJ0bfo55SWsUNN+c9hhIX+Y8LEe22izK3w7mRpvGcg+/ZRG4DEMHLP6JVsv5GMpoYwYOmHn plOzCXHvmdlW0i6SrMsBDl9rw4AtIa6bRwWLim1lQ6EM3PWifPrWSUPrPcw4OLSwFk0CPqC4 HYv/7ZnASVkR5EERFF3+6iaaVi5OgBd81F1TCvCX2BEyIDRZLJNvX3TOd5FEN+lIrl26xecz 876SvcOb5SL5SKg9/rCBufdPSjojkGFWGziHiFaYhbuI2E+NfWLJtd+ZvWAAV+O0d8vFFSvr iy9enJ8kxJwhC0ECbSKFY+W1eTIhMD3aeAKY90drozWEyHhENf4l/V+Ja5vOnW+gCDQkGt2Y 1lJAPPSIqZKvHzGShdh8DduC0U3xYkfbGAUvbxeepjgzp0uEnBXfPTy09JGpgWbg0w91GyfT /ujKaGd4vxG2Ei+MMNDmS1SMx7wu0evvQ5kT9NPzyq8R2GIhVSiAd2jioGuTjX6AZCFv3ToO 53DliFMkVTecLptsXaesuUHgL9dKIfvpm+rNXRn9wAwGjk0X/A== Message-ID: Date: Tue, 8 May 2018 18:14:07 +0200 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 2.79 on 10.11.54.5 X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.5.16 (mx1.redhat.com [10.11.55.6]); Tue, 08 May 2018 16:14:11 +0000 (UTC) X-Greylist: inspected by milter-greylist-4.5.16 (mx1.redhat.com [10.11.55.6]); Tue, 08 May 2018 16:14:11 +0000 (UTC) for IP:'10.11.54.5' DOMAIN:'int-mx05.intmail.prod.int.rdu2.redhat.com' HELO:'smtp.corp.redhat.com' FROM:'pbonzini@redhat.com' RCPT:'' Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 08/05/2018 09:55, Wanpeng Li wrote: > 2018-04-17 13:45 GMT+08:00 Wanpeng Li : >> Tim Shearer reported that "There is a guest which is running a packet >> forwarding app based on the DPDK (dpdk.org). The packet receive routine >> writes to 0xc070 using glibc's "outw_p" function which does an additional >> write to I/O port 0x80. It does this write for every packet that's >> received, causing a flood of KVM userspace context switches". He uses >> mpstat to observe a CPU performing L2 packet forwarding on a pinned >> guest vCPU, the guest time is 95 percent when allowing I/O port 0x80 >> bypass, however, it is 65.78 percent when I/O port 0x80 bypss is >> disabled. >> >> This patchset introduces per-VM I/O permission bitmaps, the userspace >> can disable the ioport intercept when they are more concern the >> performance than the security. >> >> Cc: Paolo Bonzini >> Cc: Radim Krčmář >> Cc: Tim Shearer >> Cc: Liran Alon >> > > Hi Paolo, > > Did you send the patch to glibc or the patchset still can be considered? I haven't, but I'm still not sure about the usefulness of these patches. Paolo > > Regards, > Wanpeng Li > >> Wanpeng Li (3): >> KVM: VMX: Introduce per-VM I/O permission bitmaps >> KVM: X86: Allow userspace to disable ioport intercept >> KVM: VMX: Allow I/O port 0x80 bypass when userspace prefer >> >> Documentation/virtual/kvm/api.txt | 11 +++++++++++ >> arch/x86/include/asm/kvm_host.h | 2 ++ >> arch/x86/kvm/vmx.c | 41 ++++++++++++++++++++++++++++++++++++--- >> arch/x86/kvm/x86.c | 5 +++++ >> include/uapi/linux/kvm.h | 1 + >> 5 files changed, 57 insertions(+), 3 deletions(-) >> >> -- >> 2.7.4 >>