Received: by 2002:a05:7412:a9a8:b0:f9:92ae:e617 with SMTP id o40csp14988rdh; Wed, 20 Dec 2023 14:23:08 -0800 (PST) X-Google-Smtp-Source: AGHT+IFPeCj7EsvVeCCeqwB1aB14YqPL991oAoHB+4od51phxeZM8dyW8GCGSRZlAEyvQPMzs8I/ X-Received: by 2002:a05:6a20:4322:b0:194:503d:1ab1 with SMTP id h34-20020a056a20432200b00194503d1ab1mr458661pzk.70.1703110988720; Wed, 20 Dec 2023 14:23:08 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1703110988; cv=none; d=google.com; s=arc-20160816; b=hyLRMBeS5E5SShETXYQ1bFS9JiYf9WnrCePIx2tmpAu4JImSyOw1mBhETtiokDUwvA 0tg2ew8Lrbwep5yM5/o8Fu5rbk/243u4RrOz6AUD1pemfuqOEE8PkzeJD/olYjrGImqH dE5cO8g/rwMKMWJYoO2wqbxHneqYsZWePEHTk9Ecs0isptkQkBsN+PvwwIzc/uv7XGfR pVtJ1+5uoSxqZt/YpQdiqOWs0a5v7IWxljuF9f1yVxKFXGY3Vs8rzlN3nWX2hYW9amXp bo1t2aNDg3/EXY65yLMGd0Ftv1j37CBpOYuWE3l6gvldJMI1E5b1sx2qivlcMNEbfVNm SBwQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:list-unsubscribe:list-subscribe :list-id:precedence:dkim-signature; bh=cd33Ad4E3sDi+/mK+pgctceQNxWnpSl3sfJKpANu8NM=; fh=QYJP1mSWAhLtWTvwNQ+5qSmNOkH56+RQZ591YNHiA6A=; b=bk4ugAHLSQsmJnCq2HU1nlPdckwpJszNGSjrpXM+VcnOH3NGuLP+GvjeiWOvmPQVqr oPQngd+8ok1eUgr8ylwixeIf7HTAtVCnpoJPLr9VTf5MNB0JZF4FnwRJv9BjtNbgANiv Bh2ZNoHOs5aNz4GbQt/O+Q+2YdgDTtRBYUR9tE4RuGvl+Yfi2cLKhbROdyxfirBpdSl5 ZSagfXPNlhhqZIbqxWgjWMVu2bDksMpyf2myHS2b5Iv/jmYs3XZoDjnAaKQlIUl6xt6F bP319ZG8qo5azl00DZtBW1kR9Te3sIHoHRNI4vSRRURjkwgODp1pzY4NqVfQl7I63txs 33Gw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=nL3Ovklg; spf=pass (google.com: domain of linux-kernel+bounces-7507-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:40f1:3f00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-7507-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from sy.mirrors.kernel.org (sy.mirrors.kernel.org. [2604:1380:40f1:3f00::1]) by mx.google.com with ESMTPS id a22-20020a637056000000b005c663eae379si429153pgn.269.2023.12.20.14.23.08 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 20 Dec 2023 14:23:08 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-7507-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:40f1:3f00::1 as permitted sender) client-ip=2604:1380:40f1:3f00::1; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=nL3Ovklg; spf=pass (google.com: domain of linux-kernel+bounces-7507-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:40f1:3f00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-7507-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sy.mirrors.kernel.org (Postfix) with ESMTPS id 08CEEB22B08 for ; Wed, 20 Dec 2023 22:23:02 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 255D74B15A; Wed, 20 Dec 2023 22:22:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nL3Ovklg" X-Original-To: linux-kernel@vger.kernel.org Received: from mail-ed1-f46.google.com (mail-ed1-f46.google.com [209.85.208.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C589D4B13D for ; Wed, 20 Dec 2023 22:22:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=google.com Received: by mail-ed1-f46.google.com with SMTP id 4fb4d7f45d1cf-548ae9a5eeaso747a12.1 for ; Wed, 20 Dec 2023 14:22:44 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1703110963; x=1703715763; darn=vger.kernel.org; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=cd33Ad4E3sDi+/mK+pgctceQNxWnpSl3sfJKpANu8NM=; b=nL3OvklgjrFqezX5i4S6uXKUPs8B62I7DaY7FckHRNPlHKVpwr5zzvYBipZiJ7Td6/ hK+DiNpLnbm25qDi8yCatG8Dhmcl3KvJldOAO94oOkXYWS7zECEhYr3Pk/DZo7bkSmOr a8Cuy3keZp/opISlpHqThi3QlbXpYjlwv8Y4XrtLdTJpByrdKxWIJJQU84VWZkv7AN10 0Jj0K5P2nG9kDHtRdClbYpt0fouRw7KTE1FvgiCSAOzclVl2gCucWA5YXRS34qOMjJRB wH84HTLgw8FMAbbf3E9mpkPYCjLZmTN7BwzwZ04nRVVxJ6BuCu00cKjeJS8ukVMLIIyu 0G7w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1703110963; x=1703715763; h=content-transfer-encoding:cc:to:subject:message-id:date:from :in-reply-to:references:mime-version:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=cd33Ad4E3sDi+/mK+pgctceQNxWnpSl3sfJKpANu8NM=; b=KIx2ZQrXOeDVAsQY7MOvo6zOEe3JDwSvAo9y9tq4wxaxQcEXiF/9Gs1pjG/r581Jz8 FjfRzMBObw8fuEgiil+S93h8rh+qsEukPRwjy6t0ndWY8acuyeXtAFH1vRaztbsO/tB2 tmERuaejdgAz6Yg+AbYGYUVkRJtfjk4e5md4+Awg9Q/4O3Kotj01ApaswbdJVVwhgvrg zPpn2BX4oz3Yy0DFliHBL4tvdJpKpPPhvAYxO8uXnOs9wDEgO4iKl3ipdvZhJG0YXWbo XSW2GWgiFor8xlh391rXyfVjLfsizyl9rLERSnt6oD2hSHADEn/i1+/xtGRbIV3TSp2o m3qg== X-Gm-Message-State: AOJu0YwDFYvs0BeQ4h0fMhXLelELHR4+uuYF5JTREIIQ7VAFB6lW34Lu vAODxf4MGATOTeX50kP5r+Upeo1gTYP/pk83IiW/a81AuTVf X-Received: by 2002:a50:cd84:0:b0:553:5578:2fc9 with SMTP id p4-20020a50cd84000000b0055355782fc9mr4839edi.5.1703110962976; Wed, 20 Dec 2023 14:22:42 -0800 (PST) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 References: <1c12f378af7de16d7895f8badb18c3b1715e9271.1699936040.git.isaku.yamahata@intel.com> <938efd3cfcb25d828deab0cc0ba797177cc69602.camel@redhat.com> <20231219014045.GA2639779@ls.amr.corp.intel.com> <20231219081104.GB2639779@ls.amr.corp.intel.com> In-Reply-To: From: Jim Mattson Date: Wed, 20 Dec 2023 14:22:28 -0800 Message-ID: Subject: Re: [PATCH v2 1/3] KVM: x86: Make the hardcoded APIC bus frequency vm variable To: Sean Christopherson Cc: Isaku Yamahata , Maxim Levitsky , isaku.yamahata@intel.com, kvm@vger.kernel.org, linux-kernel@vger.kernel.org, isaku.yamahata@gmail.com, Paolo Bonzini , erdemaktas@google.com, Vishal Annapurve Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Wed, Dec 20, 2023 at 2:07=E2=80=AFPM Sean Christopherson wrote: > > On Tue, Dec 19, 2023, Isaku Yamahata wrote: > > On Mon, Dec 18, 2023 at 07:53:45PM -0800, Jim Mattson wrote: > > > > There are several options to address this. > > > > 1. Make the KVM able to configure APIC bus frequency (This patch). > > > > Pros: It resembles the existing hardware. The recent Intel CPUs > > > > adapts 25MHz. > > > > Cons: Require the VMM to emulate the APIC timer at 25MHz. > > > > 2. Make the TDX architecture enumerate CPUID 0x15 to configurable > > > > frequency or not enumerate it. > > > > Pros: Any APIC bus frequency is allowed. > > > > Cons: Deviation from the real hardware. > > I don't buy this as a valid Con. TDX is one gigantic deviation from real= hardware, > and since TDX obviously can't guarantee the APIC timer is emulated at the= correct > frequency, there can't possibly be any security benefits. If this were t= ruly a > Con that anyone cared about, we would have gotten patches to "fix" KVM a = long time > ago. > > If the TDX module wasn't effectively hardware-defined software, i.e. was = actually > able to adapt at the speed of software, then fixing this in TDX would be = a complete > no-brainer. > > The KVM uAPI required to play nice is relatively minor, so I'm not totall= y opposed > to adding it. But I totally agree with Jim that forcing KVM to change 13= + years > of behavior just because someone at Intel decided that 25MHz was a good n= umber is > ridiculous. > > > > > 3. Make the TDX guest kernel use 1GHz when it's running on KVM. > > > > Cons: The kernel ignores CPUID leaf 0x15. > > > > > > 4. Change CPUID.15H under TDX to report the crystal clock frequency a= s 1 GHz. > > > Pro: This has been the virtual APIC frequency for KVM guests for 13 y= ears. > > > Pro: This requires changing only one hard-coded constant in TDX. > > > > > > I see no compelling reason to complicate KVM with support for > > > configurable APIC frequencies, and I see no advantages to doing so. > > > > Because TDX isn't specific to KVM, it should work with other VMM techno= logies. > > If we'd like to go for this route, the frequency would be configurable.= What > > frequency should be acceptable securely is obscure. 25MHz has long his= tory with > > the real hardware. I am curious how many other hypervisors either offer a configurable APIC frequency or happened to also land on 25 MHz.