Received: by 2002:ab2:6309:0:b0:1fb:d597:ff75 with SMTP id s9csp36902lqt; Wed, 5 Jun 2024 16:22:46 -0700 (PDT) X-Forwarded-Encrypted: i=3; AJvYcCXpnPogoOiBbAxu6BjCm8DxUQB0+gXnO3cch8vdR36VQ+ZQVR0CeZpjzjv4jk5t6ehXBb2Ecb4WnjRz/YxH88VIKMkOaQSLAUs4y+QrAw== X-Google-Smtp-Source: AGHT+IFNGa42hFmVNIzLd/MNq/6RS5Yfm8brKDb8nXNOcWjpL9wTYWUQ7xngAU4OhtrraZ5mGoaH X-Received: by 2002:a17:902:b714:b0:1f4:8a01:285c with SMTP id d9443c01a7336-1f6b8f07596mr9981825ad.24.1717629765937; Wed, 05 Jun 2024 16:22:45 -0700 (PDT) ARC-Seal: i=2; a=rsa-sha256; t=1717629765; cv=pass; d=google.com; s=arc-20160816; b=h6lBt9gVaLr9FPWrGyW8jx+nKO5pJAXbkCJ7SZkhDltDDJDW3YvjJNxbwCZB37Hsbf u5ZPxWco/QGSfSfvp8GbUaCSqpeUDvY4wHfe5mPIliVt/o5Z1Fa4rO+NFSWT8z+W8tVp uSLVjvs9ljXOWHKvjfdRc3JHiVAvD4ehv8TwqGFx36NWtae7SZ4tWAxJvmFvK1+lqRLZ GdbQDJTg38HIFzMubakZEF2XQM+hu/GmwuFKe2fWXs9QrvaETiJeDbHKpAKi5SrbGwmH g3MAtzxGAyPiYvYs8HYnb2z4M+lNiYMAGFEsiQ2eVX7LDtwWDHrWr1ChpEJeF8vF+jTb QkKg== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=cc:to:from:subject:message-id:references:mime-version :list-unsubscribe:list-subscribe:list-id:precedence:in-reply-to:date :reply-to:dkim-signature; bh=fogQWPs5nieObQ0xgx1BEa2/fnrhPHybbu4f2xGt2Gw=; fh=d96ppYB8SsPLuH840kRFC0enwv1ssUoG6fdO1ztsAHE=; b=kYeADdBs6RxSqzTd5Mflxq+LYNFzjyOtTyxxhHEvRJcDavzz3HhuWr4CLeax0NtFBU Ur/Sg9HGvUFQsT3H6Dde9HHr8xXlKtJSzKS3ZLvcN/l+HmtYM8zP041L/GW5dDd8wmbS R7B1Gon0sqAoJoWmh17u3TqKPQ+S8DBIZavcKluTo8rWvUTDgYdny0UAhir0YdEukcLb Zv4ge8K5meM0LOKuytbqqgQ+rdYBdedx/UYprBTrnk87jD+2fY4Lf3L0dR82LUx13PaC WA0Gy/FBRktdMQeUecg5B23sJf0qmrK5GvfE0tluh4La/dc9OVIT4zrzxay8ZUAgT9sQ 1f2g==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=B4QS+F4v; arc=pass (i=1 spf=pass spfdomain=flex--seanjc.bounces.google.com dkim=pass dkdomain=google.com dmarc=pass fromdomain=google.com); spf=pass (google.com: domain of linux-kernel+bounces-203402-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-203402-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Return-Path: Received: from sv.mirrors.kernel.org (sv.mirrors.kernel.org. [139.178.88.99]) by mx.google.com with ESMTPS id d9443c01a7336-1f6bd7d5f6asi1260705ad.279.2024.06.05.16.22.45 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Jun 2024 16:22:45 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel+bounces-203402-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) client-ip=139.178.88.99; Authentication-Results: mx.google.com; dkim=pass header.i=@google.com header.s=20230601 header.b=B4QS+F4v; arc=pass (i=1 spf=pass spfdomain=flex--seanjc.bounces.google.com dkim=pass dkdomain=google.com dmarc=pass fromdomain=google.com); spf=pass (google.com: domain of linux-kernel+bounces-203402-linux.lists.archive=gmail.com@vger.kernel.org designates 139.178.88.99 as permitted sender) smtp.mailfrom="linux-kernel+bounces-203402-linux.lists.archive=gmail.com@vger.kernel.org"; dmarc=pass (p=REJECT sp=REJECT dis=NONE) header.from=google.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by sv.mirrors.kernel.org (Postfix) with ESMTPS id 89A0D28241E for ; Wed, 5 Jun 2024 23:22:45 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id A8BD1168C07; Wed, 5 Jun 2024 23:19:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="B4QS+F4v" Received: from mail-yb1-f202.google.com (mail-yb1-f202.google.com [209.85.219.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 57F4917E8E0 for ; Wed, 5 Jun 2024 23:19:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717629582; cv=none; b=Gglx7l0IBT04eA8MfKW1G6M9hUVjpbkmaj7y3JuZvNC8SalPuQEeu3ytHxI/i/BdQJla7JyO9IhX1JQlQm9B+o8PL2yxOYZjBVH1ky8E9ULNk3ZBa0P37x0FEQo3gbH1H75sFA2bnGjtODe01PCt7a4hiGlj+L01x/Ke8eDDiv8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1717629582; c=relaxed/simple; bh=m+g0SZx3U4yfgg2ZJiCqAqn/IhUW6hBzAmPzCOMr/Nk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=UyCnQFWspJ0WvtyR+HidVVOCKXSmTS7OmuwJwhOMds2AiSAYa+zZaInbk67ct2j0JTxMQM0OUEgjQBqJaUB3TzsLhV4juys/uNVYpHXOLykuhIUq8/G5INhQ+B+JqiVIA9rOpy7xJgk4DYnRF3N+dCJ3szJW0yL1B1SHA+u6v7k= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=B4QS+F4v; arc=none smtp.client-ip=209.85.219.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Received: by mail-yb1-f202.google.com with SMTP id 3f1490d57ef6-dfa7a8147c3so608327276.3 for ; Wed, 05 Jun 2024 16:19:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1717629580; x=1718234380; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=fogQWPs5nieObQ0xgx1BEa2/fnrhPHybbu4f2xGt2Gw=; b=B4QS+F4vYzLi9qjNVcKG3/1odMbcmjRvnB037IAIYJ2QZGrr3Mkyhew0mKft15xpV8 u05DyZQFlf/QbrSr0OBcwnbJ03/ujFrlqAcQU0altn804zmmYyZP5+7YlkfAi21can/+ 5TeY1M8+R5N90yOhLcXBNANOgw+2cq4kLFwrzKDOsEiF8nj2OpuwuSWYRc8sCAVAW34d 6FecIvc9fV9HerD+7iB58ROxPKKhmEhe5UZ17CroTl8Esv4W9wkIj28MIuIA44xtejrc XiX7J7GcLLzvCexlPn+V3LmWlvYfPAz+vcnzH/q1mAdG7tThTDJHV4odTdvq0qSQsaxj EcYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1717629580; x=1718234380; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=fogQWPs5nieObQ0xgx1BEa2/fnrhPHybbu4f2xGt2Gw=; b=b9jCIkJgm8ULboOk9AQhxqOcqvU22JlJqdNWkVaZCUTaJZggj0/RGZ0UlY32RJAZpo VQalKV2wla1f3YB54DHMGymewifOicBqNXRWS2oZa4uvgbYjB2YZLuu8IzWDUm3apA8N ylHMYywTzfodFkk83AWVMO+sV+pQ3QlkVlNTvUGlZBLK9HqPsC2EzOL48BS6Quf8J6/3 biS8VcUlxFnq4184WVinr+dpKetL888n7sooG3bBQZPCQYT7OtZwQEZteGpl+9zHsy4G 3so6yomfFZzpYVs30e6PUdQ7QnljG6ql+jdXema5lofh65KpNejku03+bIGDeLnohSJS zVIw== X-Gm-Message-State: AOJu0YwCSVnM6VN8upa08iswhKgaazU0bahg4dLfLMg41fMGB6MhpDeo yFh5uevcXB81ZT5qPcBRMrm+byPFuQmwzvDU8ZauL4RqtNJY85VzZvUxoFysx0hRRvTb4N73FkE C7Q== X-Received: from zagreus.c.googlers.com ([fda3:e722:ac3:cc00:7f:e700:c0a8:5c37]) (user=seanjc job=sendgmr) by 2002:a05:6902:2b93:b0:dfa:b352:824c with SMTP id 3f1490d57ef6-dfacac6e1a6mr1150612276.7.1717629580377; Wed, 05 Jun 2024 16:19:40 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 5 Jun 2024 16:19:18 -0700 In-Reply-To: <20240605231918.2915961-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20240605231918.2915961-1-seanjc@google.com> X-Mailer: git-send-email 2.45.1.467.gbab1589fc0-goog Message-ID: <20240605231918.2915961-11-seanjc@google.com> Subject: [PATCH v8 10/10] KVM: nVMX: Use macros and #defines in vmx_restore_vmx_misc() From: Sean Christopherson To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Sean Christopherson , Paolo Bonzini , Andy Lutomirski , Peter Zijlstra Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Xiaoyao Li , Kai Huang , Jim Mattson , Shan Kang , Xin Li , Zhao Liu Content-Type: text/plain; charset="UTF-8" From: Xin Li Use macros in vmx_restore_vmx_misc() instead of open coding everything using BIT_ULL() and GENMASK_ULL(). Opportunistically split feature bits and reserved bits into separate variables, and add a comment explaining the subset logic (it's not immediately obvious that the set of feature bits is NOT the set of _supported_ feature bits). Cc: Shan Kang Cc: Kai Huang Signed-off-by: Xin Li [sean: split to separate patch, write changelog, drop #defines] Reviewed-by: Xiaoyao Li Reviewed-by: Kai Huang Reviewed-by: Zhao Liu Signed-off-by: Sean Christopherson --- arch/x86/kvm/vmx/nested.c | 27 ++++++++++++++++++++------- 1 file changed, 20 insertions(+), 7 deletions(-) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 623e8fcbf427..4e3a2303fd9c 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -1344,16 +1344,29 @@ vmx_restore_control_msr(struct vcpu_vmx *vmx, u32 msr_index, u64 data) static int vmx_restore_vmx_misc(struct vcpu_vmx *vmx, u64 data) { - const u64 feature_and_reserved_bits = - /* feature */ - BIT_ULL(5) | GENMASK_ULL(8, 6) | BIT_ULL(14) | BIT_ULL(15) | - BIT_ULL(28) | BIT_ULL(29) | BIT_ULL(30) | - /* reserved */ - GENMASK_ULL(13, 9) | BIT_ULL(31); + const u64 feature_bits = VMX_MISC_SAVE_EFER_LMA | + VMX_MISC_ACTIVITY_HLT | + VMX_MISC_ACTIVITY_SHUTDOWN | + VMX_MISC_ACTIVITY_WAIT_SIPI | + VMX_MISC_INTEL_PT | + VMX_MISC_RDMSR_IN_SMM | + VMX_MISC_VMWRITE_SHADOW_RO_FIELDS | + VMX_MISC_VMXOFF_BLOCK_SMI | + VMX_MISC_ZERO_LEN_INS; + + const u64 reserved_bits = BIT_ULL(31) | GENMASK_ULL(13, 9); + u64 vmx_misc = vmx_control_msr(vmcs_config.nested.misc_low, vmcs_config.nested.misc_high); - if (!is_bitwise_subset(vmx_misc, data, feature_and_reserved_bits)) + BUILD_BUG_ON(feature_bits & reserved_bits); + + /* + * The incoming value must not set feature bits or reserved bits that + * aren't allowed/supported by KVM. Fields, i.e. multi-bit values, are + * explicitly checked below. + */ + if (!is_bitwise_subset(vmx_misc, data, feature_bits | reserved_bits)) return -EINVAL; if ((vmx->nested.msrs.pinbased_ctls_high & -- 2.45.1.467.gbab1589fc0-goog