Received: by 2002:a05:7208:9594:b0:7e:5202:c8b4 with SMTP id gs20csp1353629rbb; Mon, 26 Feb 2024 06:51:57 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCVeivRbQOfrOY/8+8OX9e1K9KBqY6Th0frv/k5kay/zMcfW5wfZNKjQMUxHCyI8QmGu3GO5zb0WVI+v18V5rO1IuvTec1Wjsv49NZd4aQ== X-Google-Smtp-Source: AGHT+IGzWTEg7GI2Dqb4CvZYCmftJzMMBCskFCplzOF0/ZgQi8KY2bnWV5oUHC80BGyuR9S4o0RL X-Received: by 2002:ac8:5a82:0:b0:42e:76fe:60cc with SMTP id c2-20020ac85a82000000b0042e76fe60ccmr8596075qtc.9.1708959116567; Mon, 26 Feb 2024 06:51:56 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1708959116; cv=pass; d=google.com; s=arc-20160816; b=UNmhgMjBiVQ7uQycRIrZvJJkuXaW5rh9kz98hygtIsXe2w+SNy2zzYXOX5DlT0WJax nSn01iE0DeoSCWWceG5fRAInFvOIQfOePpCXhIEbjd087eN5nOB5nB0NjPxcwzq/hb1O 4nhjd9vlagXibqNfXH5hh2lNvmZsANejn31zDpMGMpBPQUP52zDZL6Z3XxHiZjw/D7SH 5W9NRbsdOFxZN4Jf0w18zWodPAU7woliy7VA9sNYr9g2C4qVrhrAFVVpJ/M6Gq0s+lmc EEvlpxGia8qmXoCA4eHlFHF2JyQbBdd2obqNGNKndCxyndoEyoecJ8tHZ1uQdEP8fBMr 69oA== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature; bh=ruju1XhRDDaW6b1WJ3BMmV9hOYmSG+m9SE28NxmRmbc=; fh=q+kQMBUHvWu6LBabHEbsaRlHvD/s/NhEy8/+ntQsPPw=; b=ZV0l6ATS2tIz1G9TaJfAauBFhmJhCobwJ0bDjr43nfBcD2p9mJ45CgwkVVBK6POWgF g327+gxaFxdn/1WhCOXQ0i06xv64ou3HijY9eLiNVVXGKvkUuO6WEIU/ZgcDfmUrXkI9 i1PWAgLyWLHNypSSdi8M3eyU8JiNIVe4s3sydl5qlQf1ce4X7SG+usrp0WBh7OLFGHwr BgzKw39kxDSBD2bKW2zuHbAZ9mCKFsEvYD1mtz9CfgTU/wuzZDVC6+kRsn2fhaiQUfZh 7YBr/uSjeuyGjBd3sbLYB71jOWAoWvrdH1DuHyuXlVIrm0aNzkp/EpxyNq6uqEQGC/5r cc5Q==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=BcY5fNCO; arc=pass (i=1 spf=pass spfdomain=gmail.com dkim=pass dkdomain=gmail.com dmarc=pass fromdomain=gmail.com); spf=pass (google.com: domain of linux-kernel+bounces-81686-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-81686-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from ny.mirrors.kernel.org (ny.mirrors.kernel.org. [2604:1380:45d1:ec00::1]) by mx.google.com with ESMTPS id h18-20020ac85152000000b0042e7a3e4a03si4012924qtn.8.2024.02.26.06.51.56 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 26 Feb 2024 06:51:56 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-81686-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) client-ip=2604:1380:45d1:ec00::1; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20230601 header.b=BcY5fNCO; arc=pass (i=1 spf=pass spfdomain=gmail.com dkim=pass dkdomain=gmail.com dmarc=pass fromdomain=gmail.com); spf=pass (google.com: domain of linux-kernel+bounces-81686-linux.lists.archive=gmail.com@vger.kernel.org designates 2604:1380:45d1:ec00::1 as permitted sender) smtp.mailfrom="linux-kernel+bounces-81686-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ny.mirrors.kernel.org (Postfix) with ESMTPS id 474721C23499 for ; Mon, 26 Feb 2024 14:51:56 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 2BC6613A263; Mon, 26 Feb 2024 14:36:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="BcY5fNCO" Received: from mail-pl1-f173.google.com (mail-pl1-f173.google.com [209.85.214.173]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D366513A24B; Mon, 26 Feb 2024 14:36:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.173 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708958210; cv=none; b=mAic7tQJamEvk2mUX4yXWLu8evAynvgsBjjpNLqcyqxnvbZy6L4x8b3kctTewg5oAc4CyILsH7CoNlZqm4oU7t3dw+VgE8cqyXIqL+qtfZnmoduFmJBD1L1iciQ0uEc4VNb8jmIQrDwdXqKQvPvoTE8uokePNQLKD9mxxJCnK9c= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1708958210; c=relaxed/simple; bh=Ck1F5Gy12w7sgnoP3E6l6/tEBdI4swyAdKim2OPHJkU=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=q01tUHmz1uz9lemeYdA1o33qHOx3YTQ+nVIq0Vh+OKs9oKPwmJ5wn+9ReGIawmt2tA4m7wK/8zZJ3FIcuXkb8qDBrIKW5GEu4mNBCVXsCuhNkrBa14caoBPsbWOl4Op5wC+7Z3mkxORjOtPUOLgXZqxDM9yWyBYTLqP4Y9pj6w4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=BcY5fNCO; arc=none smtp.client-ip=209.85.214.173 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pl1-f173.google.com with SMTP id d9443c01a7336-1dc96f64c10so9032825ad.1; Mon, 26 Feb 2024 06:36:48 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1708958208; x=1709563008; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=ruju1XhRDDaW6b1WJ3BMmV9hOYmSG+m9SE28NxmRmbc=; b=BcY5fNCO7iH1NAuaKAnSOMKpaH94O9SyXnF1k6O5byIUZ/TY1tiGwDQROgXk0OTRp8 CHdXOLqY9uJgYm6JQYAkgYlZ7XBd/hcsbB5RMM0pP4JgmkZDb6kWekx9fFezbzB1h1Lt bnRASG2/nu9dVfe32vdrX0Wxq/KbywZRMTKiafgylBoWp/kTYxh0NtSIWpTO93vBvuux 2WtRd6INLd7QIcXWof+az/WSD33M61MWFYBPVmc8GJd8fMGA1Wlg/E/Pk5ZDwslCNYo/ Z1BNxPpv0uMLksNXdH1p2Vfna98S8PcpAia7WLVSv6nWjiD9PKk/HzPcbgUYZCw/jUPp +18g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1708958208; x=1709563008; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=ruju1XhRDDaW6b1WJ3BMmV9hOYmSG+m9SE28NxmRmbc=; b=WMj0LQRLx8Qg2wB/m79h6rgin7iJ6rZeChf072Bxq4Xiijdk/FWxGqC1HM7/k+SnIm CMDUgtMKLyluFbs5TbJmp2TPqgd2VVdMpTgxQ/gW199tqVWF/blTwG/BxRR6fhe0XU3E Kb81Fq58J0+iSC3qI2ZOtmQ5EGl+Pnrrs79uvLFt/skZhuqWX46rxMkRJzEzFE7ny/7g 3aH2wlMZnw9zvv+7Ug+ptLagBASl6RrLNTn6SND8AWU7pMB/HePRi4t1f5I4xLosv7hj 4Ub3uM1+KJWd6EW6Q5FFJ3gvP4uzp7ySkB8Zz+4NhrlIsmlJT8CvPnDbs64R0jUSUkTP ALGw== X-Forwarded-Encrypted: i=1; AJvYcCVIMGBO1ACj2Jbh/Gpgsy+JsELC5OFTriEx9fYmdvvYPHXiC4ojitChfwC2ZDpKCUSD556ylW3RG8p5lkSk0uHomCF7 X-Gm-Message-State: AOJu0YzMXJmVh9/SwSSTuyxzVKrivN+iD4Rj7hmJO6vg7lFVNXUFLNh7 5Gl+F/JoJW0ShDru9mdW7p/WfK/5zybdW1m9+Wg//0rPSzbNwikiltI8xiMt X-Received: by 2002:a17:902:d4c7:b0:1dc:94f6:3326 with SMTP id o7-20020a170902d4c700b001dc94f63326mr4099780plg.18.1708958207963; Mon, 26 Feb 2024 06:36:47 -0800 (PST) Received: from localhost ([47.88.5.130]) by smtp.gmail.com with ESMTPSA id d5-20020a170902b70500b001dcabe7a182sm1219740pls.161.2024.02.26.06.36.47 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Mon, 26 Feb 2024 06:36:47 -0800 (PST) From: Lai Jiangshan To: linux-kernel@vger.kernel.org Cc: Lai Jiangshan , Hou Wenlong , Linus Torvalds , Peter Zijlstra , Sean Christopherson , Thomas Gleixner , Borislav Petkov , Ingo Molnar , kvm@vger.kernel.org, Paolo Bonzini , x86@kernel.org, Kees Cook , Juergen Gross , Dave Hansen , "H. Peter Anvin" Subject: [RFC PATCH 40/73] KVM: x86/PVM: Handle hypercall for loading GS selector Date: Mon, 26 Feb 2024 22:35:57 +0800 Message-Id: <20240226143630.33643-41-jiangshanlai@gmail.com> X-Mailer: git-send-email 2.19.1.6.gb485710b In-Reply-To: <20240226143630.33643-1-jiangshanlai@gmail.com> References: <20240226143630.33643-1-jiangshanlai@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Lai Jiangshan SWAPGS is not supported in PVM, so the native load_gs_index() cannot be used in the guest. Therefore, a hypercall is introduced to load the GS selector into the GS segment register, and the resulting GS base is returned to the guest. This is prepared for supporting 32-bit processes. Signed-off-by: Lai Jiangshan Signed-off-by: Hou Wenlong --- arch/x86/kvm/pvm/pvm.c | 71 ++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 71 insertions(+) diff --git a/arch/x86/kvm/pvm/pvm.c b/arch/x86/kvm/pvm/pvm.c index ad08643c098a..ee55e99fb204 100644 --- a/arch/x86/kvm/pvm/pvm.c +++ b/arch/x86/kvm/pvm/pvm.c @@ -1528,6 +1528,75 @@ static int handle_hc_invlpg(struct kvm_vcpu *vcpu, unsigned long addr) return 1; } +/* + * Hypercall: PVM_HC_LOAD_GS + * Load %gs with the selector %rdi and load the resulted base address + * into RAX. + * + * If %rdi is an invalid selector (including RPL != 3), NULL selector + * will be used instead. + * + * Return the resulted GS BASE in vCPU's RAX. + */ +static int handle_hc_load_gs(struct kvm_vcpu *vcpu, unsigned short sel) +{ + struct vcpu_pvm *pvm = to_pvm(vcpu); + unsigned long guest_kernel_gs_base; + + /* Use NULL selector if RPL != 3. */ + if (sel != 0 && (sel & 3) != 3) + sel = 0; + + /* Protect the guest state on the hardware. */ + preempt_disable(); + + /* + * Switch to the guest state because the CPU is going to set the %gs to + * the guest value. Save the original guest MSR_GS_BASE if it is + * already the guest state. + */ + if (!pvm->loaded_cpu_state) + pvm_prepare_switch_to_guest(vcpu); + else + __save_gs_base(pvm); + + /* + * Load sel into %gs, which also changes the hardware MSR_KERNEL_GS_BASE. + * + * Before load_gs_index(sel): + * hardware %gs: old gs index + * hardware MSR_KERNEL_GS_BASE: guest MSR_GS_BASE + * + * After load_gs_index(sel); + * hardware %gs: resulted %gs, @sel or NULL + * hardware MSR_KERNEL_GS_BASE: resulted GS BASE + * + * The resulted %gs is the new guest %gs and will be saved into + * pvm->segments[VCPU_SREG_GS].selector later when the CPU is + * switching to host or the guest %gs is read (pvm_get_segment()). + * + * The resulted hardware MSR_KERNEL_GS_BASE will be returned via RAX + * to the guest and the hardware MSR_KERNEL_GS_BASE, which represents + * the guest MSR_GS_BASE when in VM-Exit state, is restored back to + * the guest MSR_GS_BASE. + */ + load_gs_index(sel); + + /* Get the resulted guest MSR_KERNEL_GS_BASE. */ + rdmsrl(MSR_KERNEL_GS_BASE, guest_kernel_gs_base); + + /* Restore the guest MSR_GS_BASE into the hardware MSR_KERNEL_GS_BASE. */ + __load_gs_base(pvm); + + /* Finished access to the guest state on the hardware. */ + preempt_enable(); + + /* Return RAX with the resulted GS BASE. */ + kvm_rax_write(vcpu, guest_kernel_gs_base); + + return 1; +} + /* * Hypercall: PVM_HC_RDMSR * Write MSR. @@ -1604,6 +1673,8 @@ static int handle_exit_syscall(struct kvm_vcpu *vcpu) return handle_hc_flush_tlb_current_kernel_user(vcpu); case PVM_HC_TLB_INVLPG: return handle_hc_invlpg(vcpu, a0); + case PVM_HC_LOAD_GS: + return handle_hc_load_gs(vcpu, a0); case PVM_HC_RDMSR: return handle_hc_rdmsr(vcpu, a0); case PVM_HC_WRMSR: -- 2.19.1.6.gb485710b