Received: by 2002:a05:6358:11c7:b0:104:8066:f915 with SMTP id i7csp1849737rwl; Fri, 24 Mar 2023 17:02:27 -0700 (PDT) X-Google-Smtp-Source: AKy350YUN3Kw1ar3I+u1Qjz2NntPqebCxRnutuXmvD9ibk6DyKhDNUJkBiU5BGsADuPP/76mVwXV X-Received: by 2002:a17:906:b74f:b0:92d:591f:6586 with SMTP id fx15-20020a170906b74f00b0092d591f6586mr4885459ejb.34.1679702547692; Fri, 24 Mar 2023 17:02:27 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1679702547; cv=none; d=google.com; s=arc-20160816; b=dQTrqRwRvfSNJ99bW1yJNX8gkExse0tLNfqIxHmGMhdTAs/T2n/7qK8wwoOxL81NfV WvsXhCnRM8lY5KxUPMm+49P27pZma485AvyYcwujBlsqKj111cysFxe3FHTHUYd9zxQw GHZmDKoUFIzKomGDgRq7wwkXAkDuiKo6/mP9HPAN2Mtvem+bNlrHktJWaz/C9gjSKTL4 ZP6kYLa4jEjrietDnLRft48h4UGRYoiIch5N8rvTuNsuAKns1oNW3lmxYb3skYjapNsm E1G3pwbjEflWbC+rovoAgu+GjpPGy84nMT+lhxtD89Th9aXr5ixVAQyMSRbhgQcVBNXV At6w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:cc:to:subject :message-id:date:from:in-reply-to:references:mime-version :dkim-signature; bh=iHpidQtSUhq3zpSTOAjO5JszMuIBlCwSY/IIVCS13Og=; b=V3CjRztO99WQplL9ebSfEZN/TDOgO1HUKyt17GRueT/fEMXGweBr48SqvLRIPEu4Fo rm7RJz/XwUYGKkdg1sY0dUGIVONIGE/34nT/iDrGJHDA9qVIcpVro83YT4x2q3pjsGS3 QStHwgqzUBQUQKu+G/eQrCpHJ8RdvMQqeHoDB/6bxY2e7xwKMINzBdkkAsUVsM3opJ3Q +IoxHZt0ZUYZm8JwpvPe2wgWaouV5D1FTSjilNas8IrBm3xrEJkYlf0xur2gKWXETrxZ /qA2C2Q1FTD90NPcnSyWXYOTiqF8W3oRLw1hGsz1FPDynKkWJWOSIbb6lXmyzN9QxDIk FVgQ== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=OAMSGtUv; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id a4-20020a170906274400b009210b2fcdf4si21441671ejd.528.2023.03.24.17.01.23; Fri, 24 Mar 2023 17:02:27 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20210112 header.b=OAMSGtUv; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231985AbjCXXkW (ORCPT + 99 others); Fri, 24 Mar 2023 19:40:22 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45372 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231766AbjCXXkU (ORCPT ); Fri, 24 Mar 2023 19:40:20 -0400 Received: from mail-oi1-x233.google.com (mail-oi1-x233.google.com [IPv6:2607:f8b0:4864:20::233]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 92762113CF for ; Fri, 24 Mar 2023 16:40:19 -0700 (PDT) Received: by mail-oi1-x233.google.com with SMTP id bk5so2443521oib.6 for ; Fri, 24 Mar 2023 16:40:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20210112; t=1679701219; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=iHpidQtSUhq3zpSTOAjO5JszMuIBlCwSY/IIVCS13Og=; b=OAMSGtUvcgKwUCSlAKFsRCZIQZO/KMvaklqg44VZjnuRh+tIRYjgzQGOEAW2IigUv3 lDxzy8GKkQ/C80ZAgD+Nh4W6lWwi/DSPoD6mE9ylrrybRA8nODH6anAXXCzwOhUehhW7 Q3j4s7HGCB3ETtSVwEAUoQt/rFECW8YR8jVibgjmB6CMuou0GnE21WDrABxSz7Z+nU40 Lct9J/ShRIsvbRxteaypiQUSXkJg2HNx5f3k8RQlUkI4eaBkzFadRlsH0LpCI72l2LE5 Utnw/kYBhuNamQ9r4ZmEsEYgxZ6a7GW3piX8R4yy/ANoCgH0CjHUHsFWj88gwQwN8b00 C1Kw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; t=1679701219; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=iHpidQtSUhq3zpSTOAjO5JszMuIBlCwSY/IIVCS13Og=; b=7W1I7h/S3oFzv3sp1fANkDxRLhE7dOia9XZ7OL9OS1eXgVYPzAUqIWOCQRUbn7ZkqZ H7EFsZcHkZgN//lZi5r1b3bzV2awZiQ6HNimL7/KT3cXkHJEBUeFgP3RlRsnHMYYGmsL 2IEjy1LiZKBFPO6f0BWiI66cMtGDYIyfiduvgzHTM7X1vY0hwV41jKP6VrT4qJCdBJep QfIpqxAVeL5PE7FJZ8KNYWgO4d3P2Sa421w7fuFmI8ZCxlGPHOVuwTW3APO59l61cGJj 4D7E34QAWXlju3zNXRnVfZeGJSQqvRth+hfWYoAB4PQiHDIj0ksPJO1V+ya9/H+Gfn/v wcEA== X-Gm-Message-State: AO0yUKVNTgS84JpJawE07ASgVV+Xtm1JvfRrXBHrhxpyckuNhfF1F3Zq creF2e04Or2ScNL2PPKx3Raki0MqMYGiivOv6VSOfg== X-Received: by 2002:a54:4710:0:b0:384:4e2d:81ea with SMTP id k16-20020a544710000000b003844e2d81eamr1128565oik.9.1679701218769; Fri, 24 Mar 2023 16:40:18 -0700 (PDT) MIME-Version: 1.0 References: <20230301185838.21659-1-itazur@amazon.com> <20230301185838.21659-2-itazur@amazon.com> In-Reply-To: From: Jim Mattson Date: Fri, 24 Mar 2023 16:40:06 -0700 Message-ID: Subject: Re: [PATCH v2 1/1] KVM: x86: Propagate AMD-specific IBRS bits to guests To: Sean Christopherson Cc: Takahiro Itazuri , kvm@vger.kernel.org, Paolo Bonzini , linux-kernel@vger.kernel.org, Takahiro Itazuri Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Spam-Status: No, score=-15.7 required=5.0 tests=DKIMWL_WL_MED,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,ENV_AND_HDR_SPF_MATCH, RCVD_IN_DNSWL_NONE,SPF_HELO_NONE,SPF_PASS,USER_IN_DEF_DKIM_WL, USER_IN_DEF_SPF_WL autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On Fri, Mar 24, 2023 at 2:16=E2=80=AFPM Sean Christopherson wrote: > > On Wed, Mar 01, 2023, Takahiro Itazuri wrote: > > VMMs retrieve supported CPUID features via KVM_GET_SUPPORTED_CPUID to > > construct CPUID information to be passed to KVM_SET_CPUID2. Most CPUID > > feature bits related to speculative attacks are propagated from host > > CPUID. AMD processors have AMD-specific IBRS related bits in CPUID > > Fn8000_0008_EBX (ref: AMD64 Architecture Programmer's Manual Volume 3: > > General-Purpose and System Instructions) and some bits are not > > propagated to guests. > > > > Enable propagation of these bits to guests, so that guests can see the > > same security information as the host without VMM action. Usually, I can count on Sean for the semantic nitpick: This propagates bits only to the userspace VMM. They may make it to the guest. They may not.