Received: by 2002:a05:6a10:83d0:0:0:0:0 with SMTP id o16csp76320pxh; Thu, 7 Apr 2022 14:29:00 -0700 (PDT) X-Google-Smtp-Source: ABdhPJy0ylQqB3n0Ip86jvYr4fk36N3BKJX0l3aPLIOczy1CYESF1jiBJQO3BVemmAl4s2SZN2o3 X-Received: by 2002:a05:6a00:4007:b0:4fa:9505:8ac0 with SMTP id by7-20020a056a00400700b004fa95058ac0mr16123584pfb.67.1649366940578; Thu, 07 Apr 2022 14:29:00 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1649366940; cv=none; d=google.com; s=arc-20160816; b=kaB/yFiIkoDAHbQiR0IvYZgAFuIqgJJP8WIhynqtB3WIvSbGvGiFJOUswZDkBVYAvk TLbeKbnsVxoYQP+pQqJSfpmKjGkGqubOL6BwwG7fxIiABGPN0UtrLIWnYE3I1TChwVKa 9UCiKWqHSItyboDZT8HcgW3tehyHRxNA5GBZPHo+A71M/MBNPzCS2OTFPZlaOSRtvMDK fBla91UHt4F2iIL9LbHrSd/X+7RzIfsBzYVQeIIeg6/PUtWBZMPgasPhOfrvYwlHN4ek NLV7T6Zx9wEA+QwE2s71LkPD9cOZkTrnyOMmFK62xbvR8GoaZm6jAmDdO03ANsAHZB1Z NAxw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:cc:to:from:subject:mime-version:message-id:date :dkim-signature; bh=Ku8/xhQuY+DnaUKfaV/zzEU2U1z2wt3bXsnqQqFqkqc=; b=pJwCzV9ANz/Kg3V5Iq5yc+snKm/3K5jgd/zPkxGrpc6/Y8xb4dqdtJTpChPGVNzAwp xNzxISXbEape2H/pN9/1Vf2S21aEIpWl6J32k36+smTKPZDruBp+yKa5aIxB90hq/Zzs FQQv4jstPodDX7HeYBXNFCeHkoVEmxAREdx9aMzlmqwUrsgC1XnfNXCQM2xF+03cBGWJ rY+VOkdP/3uISjvLZfDmxWLocK3lE1sGkfyZZREvVrTyEsiJXAf3HkC3VWMl1SEXr1n5 SO0MfNJ2SREHxMlgqfrQjXXU7MNit1YsiWyKNHFxqEjdI5Rz2M9hBLO6y9Ad5l27DkW1 +g9w== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=M3ZS8Aiq; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from lindbergh.monkeyblade.net (lindbergh.monkeyblade.net. [23.128.96.19]) by mx.google.com with ESMTPS id m20-20020a17090a7f9400b001cb30817076si1060437pjl.184.2022.04.07.14.29.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 07 Apr 2022 14:29:00 -0700 (PDT) Received-SPF: softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) client-ip=23.128.96.19; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=M3ZS8Aiq; spf=softfail (google.com: domain of transitioning linux-kernel-owner@vger.kernel.org does not designate 23.128.96.19 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id BA4B7488E06; Thu, 7 Apr 2022 13:32:48 -0700 (PDT) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229803AbiDGUdi (ORCPT + 99 others); Thu, 7 Apr 2022 16:33:38 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:36276 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229923AbiDGUdW (ORCPT ); Thu, 7 Apr 2022 16:33:22 -0400 Received: from mail-pj1-x1049.google.com (mail-pj1-x1049.google.com [IPv6:2607:f8b0:4864:20::1049]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id E3DC3320DA1 for ; Thu, 7 Apr 2022 13:18:41 -0700 (PDT) Received: by mail-pj1-x1049.google.com with SMTP id oo16-20020a17090b1c9000b001c6d21e8c04so6413392pjb.4 for ; Thu, 07 Apr 2022 13:18:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; h=date:message-id:mime-version:subject:from:to:cc; bh=Ku8/xhQuY+DnaUKfaV/zzEU2U1z2wt3bXsnqQqFqkqc=; b=M3ZS8Aiq4mZdEltM4TPvQxBlNDtZ5ARAyG4HJSf7KbrTU9eEooYFvgfOobSIGlllyi CE02YilAIANO7ovsSumaS3UAoN/fZBTfzlEOZIaX/CXkYe74UAH5vZzcrGwRIFwwALCq DZC4F6uzVaWWgV8M6b2y1Noxmjm1vFrdoNbqzkXUwV29S0QFkbL2NL4Klv0EZvKVXpAd UwgqmZwO5sKsSv8HpkhpLuUG0Qi2YVssaT0issL/qLqJuYMvUb3HPtOTLXh0UxS9HdOi B9OyKC3dQ9xz7PUO9RmbRRvA9WqciG8SdgAksytDfEgdDCmFhyBSrWT1uGXykoWyhlIw Dp/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=Ku8/xhQuY+DnaUKfaV/zzEU2U1z2wt3bXsnqQqFqkqc=; b=UYvoVXIj2JJeO9I8L/FhOn8AhZ8S11d8k6tjf0GYqmFKzvwl5kniQHoSi9/JRJL8BH z5E+CeceiUVoCGUFwDjCILtsPHkgkBpG3PWvWTAHfM3v+cdI7x2FUiIX4RM/LWjm69+W p6RLWONP3bpf32HrHAMHb9IZjDhK2EQZb8tKu5LQu004SPK4m27JTP/a4Aw/FaCTbnIe FZXubStU1BJSkHDmjCKuzgqH57xxPpekoyP0mulMfDE6lz8f7NzePp1CPYiLOZrHCxrs 9g5h4oCAXQkJb3sjXsp17ERx+z9q1cMjLAOKf5ej5Y7Wx9XUmm/Z7nbiIeVuqrFBCsUa jS9w== X-Gm-Message-State: AOAM530qvueaI55MGVxJ4hCSHheqnvX0/Vzgrqp1Ko2RPeQbIlLT2YoT a9KeRZa4rz4YhIZ6GodD6MfMhOvMRYU= X-Received: from pgonda1.kir.corp.google.com ([2620:15c:29:203:469d:83b1:de7b:c47f]) (user=pgonda job=sendgmr) by 2002:a17:903:1251:b0:156:9d8e:1077 with SMTP id u17-20020a170903125100b001569d8e1077mr15375452plh.116.1649362721388; Thu, 07 Apr 2022 13:18:41 -0700 (PDT) Date: Thu, 7 Apr 2022 13:18:38 -0700 Message-Id: <20220407201838.715024-1-pgonda@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.35.1.1178.g4f1659d476-goog Subject: [PATCH v4] KVM, SEV: Add KVM_EXIT_SHUTDOWN metadata for SEV-ES From: Peter Gonda To: kvm@vger.kernel.org Cc: Peter Gonda , Sean Christopherson , Paolo Bonzini , linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" X-Spam-Status: No, score=-9.5 required=5.0 tests=BAYES_00,DKIMWL_WL_MED, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,RDNS_NONE,SPF_HELO_NONE,T_SCC_BODY_TEXT_LINE, URIBL_BLOCKED,USER_IN_DEF_DKIM_WL autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org SEV-ES guests can request termination using the GHCB's MSR protocol. See AMD's GHCB spec section '4.1.13 Termination Request'. Currently when a guest does this the userspace VMM sees an KVM_EXIT_UNKNOWN (-EVINAL) return code from KVM_RUN. By adding a KVM_EXIT_SHUTDOWN_ENTRY to kvm_run struct the userspace VMM can clearly see the guest has requested a SEV-ES termination including the termination reason code set and reason code. Suggested-by: Sean Christopherson Suggested-by: Paolo Bonzini Cc: kvm@vger.kernel.org Cc: linux-kernel@vger.kernel.org Signed-off-by: Peter Gonda --- V4 * Updated to Sean and Paolo's suggestion of reworking the kvm_run.system_event struct to ndata and data fields to fix the padding. V3 * Add Documentation/ update. * Updated other KVM_EXIT_SHUTDOWN exits to clear ndata and set reason to KVM_SHUTDOWN_REQ. V2 * Add KVM_CAP_EXIT_SHUTDOWN_REASON check for KVM_CHECK_EXTENSION. Tested by making an SEV-ES guest call sev_es_terminate() with hardcoded reason code set and reason code and then observing the codes from the userspace VMM in the kvm_run.shutdown.data fields. --- arch/x86/kvm/svm/sev.c | 9 +++++++-- include/uapi/linux/kvm.h | 5 ++++- 2 files changed, 11 insertions(+), 3 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 75fa6dd268f0..1a080f3f09d8 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2735,8 +2735,13 @@ static int sev_handle_vmgexit_msr_protocol(struct vcpu_svm *svm) pr_info("SEV-ES guest requested termination: %#llx:%#llx\n", reason_set, reason_code); - ret = -EINVAL; - break; + vcpu->run->exit_reason = KVM_EXIT_SYSTEM_EVENT; + vcpu->run->system_event.type = KVM_SYSTEM_EVENT_SEV_TERM | + KVM_SYSTEM_EVENT_NDATA_VALID; + vcpu->run->system_event.ndata = 1; + vcpu->run->system_event.data[1] = control->ghcb_gpa; + + return 0; } default: /* Error, keep GHCB MSR value as-is */ diff --git a/include/uapi/linux/kvm.h b/include/uapi/linux/kvm.h index 8616af85dc5d..dd1d8167e71f 100644 --- a/include/uapi/linux/kvm.h +++ b/include/uapi/linux/kvm.h @@ -444,8 +444,11 @@ struct kvm_run { #define KVM_SYSTEM_EVENT_SHUTDOWN 1 #define KVM_SYSTEM_EVENT_RESET 2 #define KVM_SYSTEM_EVENT_CRASH 3 +#define KVM_SYSTEM_EVENT_SEV_TERM 4 +#define KVM_SYSTEM_EVENT_NDATA_VALID (1u << 31) __u32 type; - __u64 flags; + __u32 ndata; + __u64 data[16]; } system_event; /* KVM_EXIT_S390_STSI */ struct { -- 2.35.1.1178.g4f1659d476-goog