Received: by 10.223.164.221 with SMTP id h29csp330816wrb; Tue, 24 Oct 2017 00:56:06 -0700 (PDT) X-Google-Smtp-Source: ABhQp+QE/akmhVqauJvG2T8YgwvLhJ+duN17TTg1dlbMJHeOnc8ZSHhxK6nXFRLWcAvmI3npJHF6 X-Received: by 10.99.64.3 with SMTP id n3mr13975260pga.357.1508831766564; Tue, 24 Oct 2017 00:56:06 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1508831766; cv=none; d=google.com; s=arc-20160816; b=ZBya4yYGKAp0RWKutQYQ1i+RUmPpfkWI6uE8GxxgX7UPvYxRx8KAO4e8W8DMoLAGWf QjV8C/W8hR/jRUCZ2drY55/qx9iH9HRp6YNeFwI0bBaXQC38Rg7Ay4Ks63pTAcnOrNEF 0xBdy1zWYo2VfJP7AQ2QBs4p/fjwBELnF9uopj2GWsubPbSusB4xm+4bL+I7Gju/QxRa fZmkJWjr97hARIvNIT6UgP+4W9wSci1LmlR5eZ1z0qoypMIzKFCZkwdkPrwUQ2rcLdDH mJKM15tt5pfBJ8ZhxH+Gr2hvOgsxdS9Vtj3pjxd0EcwPig2zpoRwjtXAp3ewh08AJvkF cC4g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:user-agent:in-reply-to :content-transfer-encoding:content-disposition:mime-version :references:mail-followup-to:message-id:subject:cc:to:from:date :arc-authentication-results; bh=7yySBXGuu0+Dj0mX5+fmt7ghfBpYZkrrGv2RGCF7TCc=; b=x/Cr3S1PTUyN0b92u1jshPcwBqUZBeM19Arwl63ufRgihQeK5I6v528GjkOf9sGJQj pRgApj5OJGYDyGGRdKlIijytkb5syih8zE9zbOo7FiDwDFZDsfYtVz+RXFGtErTbydh8 sAGkF2Aart71ZFBrcN6J62kQbGx6jWaWjOBxKG9IT3Le98Jwivy1+Uw9cc4IYtjZXrYJ oB/JhVhN1HVSPIkYyF6cuwxhZy+Gb3oo/IT30JKmuSlH914aXnH1RPivqykSRFE9fYSZ oISrVyTPUJ4eNF+upaAJgsg4OB2pKs+2EEnmCXTLDv9hYNMgEHzGiKMBk+FKPC9RzkHH vbLg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id j189si6593008pfc.262.2017.10.24.00.55.52; Tue, 24 Oct 2017 00:56:06 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1751620AbdJXHz2 (ORCPT + 99 others); Tue, 24 Oct 2017 03:55:28 -0400 Received: from mga01.intel.com ([192.55.52.88]:41156 "EHLO mga01.intel.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751323AbdJXHzZ (ORCPT ); Tue, 24 Oct 2017 03:55:25 -0400 Received: from fmsmga003.fm.intel.com ([10.253.24.29]) by fmsmga101.fm.intel.com with ESMTP/TLS/DHE-RSA-AES256-GCM-SHA384; 24 Oct 2017 00:55:25 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="5.43,427,1503385200"; d="scan'208";a="913072262" Received: from linux.intel.com ([10.54.29.200]) by FMSMGA003.fm.intel.com with ESMTP; 24 Oct 2017 00:52:08 -0700 Received: from dazhang1-ssd.sh.intel.com (unknown [10.239.48.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by linux.intel.com (Postfix) with ESMTPS id 38D5F5802BA; Tue, 24 Oct 2017 00:52:02 -0700 (PDT) Date: Tue, 24 Oct 2017 15:52:33 +0800 From: Yi Zhang To: Mihai =?utf-8?B?RG9uyJt1?= Cc: Paolo Bonzini , Jim Mattson , kvm list , LKML , Radim =?utf-8?B?S3LEjW3DocWZ?= , Alex Williamson Subject: Re: [PATCH RFC 00/10] Intel EPT-Based Sub-page Write Protection Support. Message-ID: <20171024075232.GA34879@dazhang1-ssd.sh.intel.com> Mail-Followup-To: Mihai =?utf-8?B?RG9uyJt1?= , Paolo Bonzini , Jim Mattson , kvm list , LKML , Radim =?utf-8?B?S3LEjW3DocWZ?= , Alex Williamson References: <250725286.12444082.1507929205754.JavaMail.zimbra@redhat.com> <20171016000841.GB66870@dazhang1-ssd.sh.intel.com> <96efaece-306c-cde3-06d6-553505612136@redhat.com> <1508335998.3230.118.camel@bitdefender.com> <20171020084715.GG88002@dazhang1-ssd.sh.intel.com> <1508519207.29329.67.camel@bitdefender.com> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <1508519207.29329.67.camel@bitdefender.com> User-Agent: Mutt/1.5.24 (2015-08-30) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 2017-10-20 at 20:06:47 +0300, Mihai Donțu wrote: > On Fri, 2017-10-20 at 16:47 +0800, Yi Zhang wrote: > > Could you mind to provide more information and history about your > > investigation? > > We are using VMI to secure certain parts of a guest kernel in memory > (like prevent a certain data structure from being overriten). However, > it sometimes happens for that part to be placed in the same page with > other data, of no interest to us, that gets written frequently. This > makes using the EPT problematic (a 4k page is just too big and > generates too many violations). However, SPP (with its 128 bytes > granularity) is ideal here. > > > > Also, if Intel doesn't have a specific use case for it that requires > > > separate access to SPP control, then maybe we can fold it into the VMI > > > API we are working on? > > > > That's totally Excellent as we really don't have a specific user case at > > this time. > > OK. We will spend some time thinking at a proper way of exposing SPP > with the VMI API. > > For example, we now work on implementing something similar to this: > > kvm_set_page_access( struct kvm *kvm, gfn_t gfn, u8 access ); > > The simplest approach would be to add something like: > > kvm_set_sub_page_access( struct kvm *kvm, gfn_t gfn, u32 mask ); > > where every bit from 'mask' indicates the write-allowed state of every > 128-byte subpage. Got it, seems very compatible with current implementation by us. > > > BTW, I have already submit the SPP implementation draft in Xen side. > > when you got some time, you can take a look at if that match your > > requirement. > > I believe my colleague Răzvan Cojocaru has already commented on that > patch set. :-) Oh, yes, pls send my best thanks to him. > > -- > Mihai Donțu > From 1581797115103788402@xxx Fri Oct 20 17:08:02 +0000 2017 X-GM-THRID: 1581152810958355510 X-Gmail-Labels: Inbox,Category Forums