Received: by 2002:a17:90a:9307:0:0:0:0 with SMTP id p7csp3961080pjo; Tue, 3 Mar 2020 10:08:17 -0800 (PST) X-Google-Smtp-Source: ADFU+vvuT91GAqVNRigIYf8I6Bbx/JgA4kJWGTxadfdRkLdg9M3ZXDUC3yU5viBJixzBZp9pFHKA X-Received: by 2002:a9d:7a56:: with SMTP id z22mr4064453otm.201.1583258897266; Tue, 03 Mar 2020 10:08:17 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1583258897; cv=none; d=google.com; s=arc-20160816; b=N5A5q2uAXG/420vpI0RlSNeJ3T9qP+/CljjKQUlb3fF/NmlF5CeM+d3x+dGi4Vpl9L crqL+XRuMjI9RUtYTROBkvafBNn17zv5w6kHeRLWXwG1nfs5gnIDaMDcnkYXAKF6CH53 HtWszyvksh/FPpJfpPMklqnmdI1V3EaJxqCwkegltiUwt0RS1k9jSABGiFTeGc/+6yPN 2lWMg+nnDHf246bvmQDxkJVGVWVCsdbv56C4L0dYkLezHTzLwhMIjbRTsWN3HVmOwkU4 GOP8XJqlxBu0pKlgUD+aSACzmCTD2/KxS5dLNK0cuPXhaSaOjEMz5flG96dzvdciBKlR X4gA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-transfer-encoding:mime-version :user-agent:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=I27j8WUCXS4inzO8djlt0OB92bPqJhqwOd3Wgeruh3Y=; b=ph5+7Ch7kf8O1/Mjpw3SqwfnV7+FMsWx3X0IT3rdD0Mrutajifk79BRuNKksFOwpCJ 7/PIIcMQ658uyPvr5lHyrdn4+z6WmI/rVJOFE+Rde/9y+2x17LCb+k4a0XD9MBiEDEdR QPFjV4GhSVgeDqs9d5Nxq5e3/vgQEGrMQKr8etKh1WXMMbPZnchtAmI9zMpSZNGRrv65 sMNN9DdcZsvdQnWpKP34ABHHiyPOd+utrXGgFqMQ0T86DAPT5zRGa7CzxNaQShNLf1xK 8d32KKjlnYVjGRn0z11mWc9B6VUrdGxS7ZV00t5I4nEOY2m+80xg4zX4w09Cq9L0TKb+ zUyw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=zl9UwJG+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id t5si3940129otc.315.2020.03.03.10.08.05; Tue, 03 Mar 2020 10:08:17 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@kernel.org header.s=default header.b=zl9UwJG+; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S2388320AbgCCSHO (ORCPT + 99 others); Tue, 3 Mar 2020 13:07:14 -0500 Received: from mail.kernel.org ([198.145.29.99]:36590 "EHLO mail.kernel.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1732662AbgCCRzL (ORCPT ); Tue, 3 Mar 2020 12:55:11 -0500 Received: from localhost (83-86-89-107.cable.dynamic.v4.ziggo.nl [83.86.89.107]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id 8D538206D5; Tue, 3 Mar 2020 17:55:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1583258111; bh=+mchgu3W1Zhiq9EjAEp+MD9MvnwX3VIu2UILJKHK1ww=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=zl9UwJG+Z40Cce0RHVFglY1L3X7wl6ioSdUyg7nvaqJBHi1Udhfu7i48wkXLNKOQ3 ydrkRSbMaX0xuHRRYXK3cpdnF6MaDPyZEoxveWsowCn06rbCnu0eNwIA7/cpcBQxe5 Nm5Lb/9MnSLkBPHGs7WSngU+P3vp9G5zJ+oz0DMU= From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Jan Kiszka , Paolo Bonzini , Jim Mattson , Oliver Upton Subject: [PATCH 5.4 075/152] KVM: VMX: check descriptor table exits on instruction emulation Date: Tue, 3 Mar 2020 18:42:53 +0100 Message-Id: <20200303174311.022080640@linuxfoundation.org> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20200303174302.523080016@linuxfoundation.org> References: <20200303174302.523080016@linuxfoundation.org> User-Agent: quilt/0.66 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Oliver Upton commit 86f7e90ce840aa1db407d3ea6e9b3a52b2ce923c upstream. KVM emulates UMIP on hardware that doesn't support it by setting the 'descriptor table exiting' VM-execution control and performing instruction emulation. When running nested, this emulation is broken as KVM refuses to emulate L2 instructions by default. Correct this regression by allowing the emulation of descriptor table instructions if L1 hasn't requested 'descriptor table exiting'. Fixes: 07721feee46b ("KVM: nVMX: Don't emulate instructions in guest mode") Reported-by: Jan Kiszka Cc: stable@vger.kernel.org Cc: Paolo Bonzini Cc: Jim Mattson Signed-off-by: Oliver Upton Signed-off-by: Paolo Bonzini Signed-off-by: Greg Kroah-Hartman --- arch/x86/kvm/vmx/vmx.c | 15 +++++++++++++++ 1 file changed, 15 insertions(+) --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -7165,6 +7165,7 @@ static int vmx_check_intercept_io(struct else intercept = nested_vmx_check_io_bitmaps(vcpu, port, size); + /* FIXME: produce nested vmexit and return X86EMUL_INTERCEPTED. */ return intercept ? X86EMUL_UNHANDLEABLE : X86EMUL_CONTINUE; } @@ -7194,6 +7195,20 @@ static int vmx_check_intercept(struct kv case x86_intercept_outs: return vmx_check_intercept_io(vcpu, info); + case x86_intercept_lgdt: + case x86_intercept_lidt: + case x86_intercept_lldt: + case x86_intercept_ltr: + case x86_intercept_sgdt: + case x86_intercept_sidt: + case x86_intercept_sldt: + case x86_intercept_str: + if (!nested_cpu_has2(vmcs12, SECONDARY_EXEC_DESC)) + return X86EMUL_CONTINUE; + + /* FIXME: produce nested vmexit and return X86EMUL_INTERCEPTED. */ + break; + /* TODO: check more intercepts... */ default: break;