Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 99318eca authored by Konrad Rzeszutek Wilk's avatar Konrad Rzeszutek Wilk Committed by Greg Kroah-Hartman
Browse files

x86/KVM/VMX: Expose SPEC_CTRL Bit(2) to the guest



commit da39556f66f5cfe8f9c989206974f1cb16ca5d7c upstream

Expose the CPUID.7.EDX[31] bit to the guest, and also guard against various
combinations of SPEC_CTRL MSR values.

The handling of the MSR (to take into account the host value of SPEC_CTRL
Bit(2)) is taken care of in patch:

  KVM/SVM/VMX/x86/spectre_v2: Support the combination of guest and host IBRS

Signed-off-by: default avatarKonrad Rzeszutek Wilk <konrad.wilk@oracle.com>
Signed-off-by: default avatarThomas Gleixner <tglx@linutronix.de>
Reviewed-by: default avatarIngo Molnar <mingo@kernel.org>

[dwmw2: Handle 4.9 guest CPUID differences, rename
        guest_cpu_has_ibrs() → guest_cpu_has_spec_ctrl()]
Signed-off-by: default avatarDavid Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
parent f854434b
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -382,7 +382,7 @@ static inline int __do_cpuid_ent(struct kvm_cpuid_entry2 *entry, u32 function,

	/* cpuid 7.0.edx*/
	const u32 kvm_cpuid_7_0_edx_x86_features =
		F(SPEC_CTRL) | F(ARCH_CAPABILITIES);
		F(SPEC_CTRL) | F(RDS) | F(ARCH_CAPABILITIES);

	/* all calls to cpuid_count() should be made on the same cpu */
	get_cpu();
+2 −2
Original line number Diff line number Diff line
@@ -171,7 +171,7 @@ static inline bool guest_cpuid_has_ibpb(struct kvm_vcpu *vcpu)
	return best && (best->edx & bit(X86_FEATURE_SPEC_CTRL));
}

static inline bool guest_cpuid_has_ibrs(struct kvm_vcpu *vcpu)
static inline bool guest_cpuid_has_spec_ctrl(struct kvm_vcpu *vcpu)
{
	struct kvm_cpuid_entry2 *best;

@@ -179,7 +179,7 @@ static inline bool guest_cpuid_has_ibrs(struct kvm_vcpu *vcpu)
	if (best && (best->ebx & bit(X86_FEATURE_IBRS)))
		return true;
	best = kvm_find_cpuid_entry(vcpu, 7, 0);
	return best && (best->edx & bit(X86_FEATURE_SPEC_CTRL));
	return best && (best->edx & (bit(X86_FEATURE_SPEC_CTRL) | bit(X86_FEATURE_RDS)));
}

static inline bool guest_cpuid_has_arch_capabilities(struct kvm_vcpu *vcpu)
+2 −2
Original line number Diff line number Diff line
@@ -3545,7 +3545,7 @@ static int svm_get_msr(struct kvm_vcpu *vcpu, struct msr_data *msr_info)
		break;
	case MSR_IA32_SPEC_CTRL:
		if (!msr_info->host_initiated &&
		    !guest_cpuid_has_ibrs(vcpu))
		    !guest_cpuid_has_spec_ctrl(vcpu))
			return 1;

		msr_info->data = svm->spec_ctrl;
@@ -3643,7 +3643,7 @@ static int svm_set_msr(struct kvm_vcpu *vcpu, struct msr_data *msr)
		break;
	case MSR_IA32_SPEC_CTRL:
		if (!msr->host_initiated &&
		    !guest_cpuid_has_ibrs(vcpu))
		    !guest_cpuid_has_spec_ctrl(vcpu))
			return 1;

		/* The STIBP bit doesn't fault even if it's not advertised */
+3 −3
Original line number Diff line number Diff line
@@ -3020,7 +3020,7 @@ static int vmx_get_msr(struct kvm_vcpu *vcpu, struct msr_data *msr_info)
		break;
	case MSR_IA32_SPEC_CTRL:
		if (!msr_info->host_initiated &&
		    !guest_cpuid_has_ibrs(vcpu))
		    !guest_cpuid_has_spec_ctrl(vcpu))
			return 1;

		msr_info->data = to_vmx(vcpu)->spec_ctrl;
@@ -3137,11 +3137,11 @@ static int vmx_set_msr(struct kvm_vcpu *vcpu, struct msr_data *msr_info)
		break;
	case MSR_IA32_SPEC_CTRL:
		if (!msr_info->host_initiated &&
		    !guest_cpuid_has_ibrs(vcpu))
		    !guest_cpuid_has_spec_ctrl(vcpu))
			return 1;

		/* The STIBP bit doesn't fault even if it's not advertised */
		if (data & ~(SPEC_CTRL_IBRS | SPEC_CTRL_STIBP))
		if (data & ~(SPEC_CTRL_IBRS | SPEC_CTRL_STIBP | SPEC_CTRL_RDS))
			return 1;

		vmx->spec_ctrl = data;