Received: by 2002:a05:6a10:2726:0:0:0:0 with SMTP id ib38csp32286pxb; Wed, 30 Mar 2022 22:06:49 -0700 (PDT) X-Google-Smtp-Source: ABdhPJxudJtGp79IoWvTt5ZA0K7BOdtlFZroWAryalsBy4VQjbu0WqSOcPeP4fs0kcKVA6jXpZn0 X-Received: by 2002:a17:902:e80e:b0:154:1e0a:ca3f with SMTP id u14-20020a170902e80e00b001541e0aca3fmr3633196plg.64.1648703209611; Wed, 30 Mar 2022 22:06:49 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1648703209; cv=none; d=google.com; s=arc-20160816; b=u568LQKACj1JCCMaSIOMGpJP86g2k37eDOuwqM1wr0VANo9DamNeEqMhbP0ajvIdOn 8X8CaJOKgcM1GqP4AtjjOapb22OOgky7IiBwchav5E3QDwlRlezjXHUvws0nnf8/VNZ9 dmEngtgYyqacPm9Z8813G58BWIGXXw5Nt4r/wyt9GxxpRKsuyP/CwoqIs8RWwP8zBni7 Uopds2bqrMSq75pkKCJb/xLbRRSJk/vho8E/hENktGL6gWruTdVWS5jcy9fpSnvYSCvC wisb5MNh93b8SeR8vLpPh44eVgip5vQul/gVkgrWnlesa1H8+t7BSX5WX0O6qIiVfLCf lUUA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:in-reply-to:content-disposition:mime-version :references:message-id:subject:cc:to:from:date:dkim-signature; bh=1t7ZTcfgKbtCrh+Z8QzaoA6bXs0GJ9EG7KZ7T9mNkyo=; b=Ckjzk31ENufOXXg2V3lzXJI4LaD2rgzCG2Q2g2O8HCeOAzsgpjcQw4Ie+DbgeJlRGC 2vP6fK19Oa9Tw/NxWmotPr0eK6v58c9Sv+SG9ClVw5RTxf51Z6w8JevxTtglq/K6wQP3 t4TdWI90XK7pYObiRevuNYkgGP+vDwep0VVoUZxkuKH46g06v/sgYi9DF8unVoZHMMCg NV6mETXvq9u5quZTC76UZ5OHEsFV1e6Eloo/4/rzzvR0vMS2K29zwb1l298PvcpPREMn HWAIt8Q33BdeRCEmzNDDhdIl2paUi23jX2Oc5sC5K1TZ6gV0nQE9N1RCUyPK4Y3SjI3q bNKg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=Qnc0FbV8; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [2620:137:e000::1:18]) by mx.google.com with ESMTPS id mw1-20020a17090b4d0100b001bf6715212dsi2384509pjb.104.2022.03.30.22.06.49 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 30 Mar 2022 22:06:49 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) client-ip=2620:137:e000::1:18; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=Qnc0FbV8; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:18 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 1778527D546; Wed, 30 Mar 2022 20:41:15 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1349637AbiC3SEA (ORCPT + 99 others); Wed, 30 Mar 2022 14:04:00 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:36646 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1349634AbiC3SD7 (ORCPT ); Wed, 30 Mar 2022 14:03:59 -0400 Received: from mail-pj1-x102c.google.com (mail-pj1-x102c.google.com [IPv6:2607:f8b0:4864:20::102c]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 6D785103BBC for ; Wed, 30 Mar 2022 11:02:12 -0700 (PDT) Received: by mail-pj1-x102c.google.com with SMTP id bx5so21461153pjb.3 for ; Wed, 30 Mar 2022 11:02:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=date:from:to:cc:subject:message-id:references:mime-version :content-disposition:in-reply-to; bh=1t7ZTcfgKbtCrh+Z8QzaoA6bXs0GJ9EG7KZ7T9mNkyo=; b=Qnc0FbV8QW9nWNUOQwd6/VL3i7W1mRJNkjUHl2lrMu1esd+LZ8H5X7HdBuqE7iT02e BbcHWea0WsPYpgJZd1t1tLzqf8zAvoF3JrXkRfv9Qf3rD2plPb0pqBL5YozYI77OG0Jm inbNIW+pd/UC9m0MMRX5dl4x1tcS3hmOwxrJ4YkrTT5Aj+AxPnQqC/Y5C7rMYG2TDUit X54n5lQR9HCBt53ElkMeirueeHikr967anl32qZ9taBIT/irIR0uxCOODF/WHJq42sSz x0r6FrOV5tSe3kvftlYtWDC2qhaSyLTsI12TACUxUfsVxe9ZR6dOZi4IqSXRpqQc9wCD IQpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:from:to:cc:subject:message-id:references :mime-version:content-disposition:in-reply-to; bh=1t7ZTcfgKbtCrh+Z8QzaoA6bXs0GJ9EG7KZ7T9mNkyo=; b=WHqMqu/DmVhuH5qT1udM260biPdfViaPaims0hB7I9+Xax4Z3U4NY0MPys+zvOg3Q4 wu+4jPLN3T5rSPFgtk4LMKoefyg6GE/ccbPtskXc4pXI8U46aoAEduEXx6c3cbqHHv2t S6QM2YNF50jqMtGCFXj2FK9NNQkVuQkZUNHOIjMH3++J262TsrXX2MfUoEF3z7vafKaH bNMKmH3SJSUaG1Cqmr3dQrb/E5py7RGL8bZRLC//M3sN7gwz31LDu+R4pwFz8UaOYHFz KmaL9kVp9Et7ZlkaBUb5VjiXKTjKVYUH1Rm7LWmWX3WvKsR0Fmryvm97vA+evEcNzjlw UmwA== X-Gm-Message-State: AOAM532K9MEsTyomKvqcavKnJLxS3jtms7oFViWmatUzJaiA/Mq40/AO s++ifNP4tyAoeYz9fgBRenoZxw== X-Received: by 2002:a17:902:7c0d:b0:155:d507:3cf0 with SMTP id x13-20020a1709027c0d00b00155d5073cf0mr501879pll.103.1648663331634; Wed, 30 Mar 2022 11:02:11 -0700 (PDT) Received: from google.com (157.214.185.35.bc.googleusercontent.com. [35.185.214.157]) by smtp.gmail.com with ESMTPSA id be11-20020a056a001f0b00b004fb29215dd9sm14648311pfb.30.2022.03.30.11.02.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 30 Mar 2022 11:02:11 -0700 (PDT) Date: Wed, 30 Mar 2022 18:02:07 +0000 From: Sean Christopherson To: Ben Gardon Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Paolo Bonzini , Peter Xu , David Matlack , Jim Mattson , David Dunn , Jing Zhang , Junaid Shahid Subject: Re: [PATCH v3 10/11] KVM: x86/MMU: Require reboot permission to disable NX hugepages Message-ID: References: <20220330174621.1567317-1-bgardon@google.com> <20220330174621.1567317-11-bgardon@google.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20220330174621.1567317-11-bgardon@google.com> X-Spam-Status: No, score=-9.5 required=5.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RDNS_NONE,SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE, USER_IN_DEF_DKIM_WL autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Wed, Mar 30, 2022, Ben Gardon wrote: > Ensure that the userspace actor attempting to disable NX hugepages has > permission to reboot the system. Since disabling NX hugepages would > allow a guest to crash the system, it is similar to reboot permissions. This patch needs to be squashed with the patch that introduces the capability, otherwise you're introdcuing a bug and then fixing it in the same series.