Thread (116 messages) 116 messages, 15 authors, 2022-07-25

Re: [PATCH v5 00/13] KVM: mm: fd-based approach for supporting KVM guest private memory

From: Andy Lutomirski <luto@kernel.org>
Date: 2022-06-10 19:18:52
Also in: kvm, linux-fsdevel, linux-mm, lkml, qemu-devel

On Mon, Apr 25, 2022 at 1:31 PM Sean Christopherson [off-list ref] wrote:
On Mon, Apr 25, 2022, Andy Lutomirski wrote:
quoted

On Mon, Apr 25, 2022, at 6:40 AM, Chao Peng wrote:
quoted
On Sun, Apr 24, 2022 at 09:59:37AM -0700, Andy Lutomirski wrote:
quoted
quoted
quoted
2. Bind the memfile to a VM (or at least to a VM technology).  Now it's in
the initial state appropriate for that VM.

For TDX, this completely bypasses the cases where the data is prepopulated
and TDX can't handle it cleanly.
I believe TDX can handle this cleanly, TDH.MEM.PAGE.ADD doesn't require that the
source and destination have different HPAs.  There's just no pressing need to
support such behavior because userspace is highly motivated to keep the initial
image small for performance reasons, i.e. burning a few extra pages while building
the guest is a non-issue.
Following up on this, rather belatedly.  After re-reading the docs,
TDX can populate guest memory using TDH.MEM.PAGE.ADD, but see Intel®
TDX Module Base Spec v1.5, section 2.3, step D.4 substeps 1 and 2
here:

https://www.intel.com/content/dam/develop/external/us/en/documents/intel-tdx-module-1.5-base-spec-348549001.pdf

For each TD page:

1. The host VMM specifies a TDR as a parameter and calls the
TDH.MEM.PAGE.ADD function. It copies the contents from the TD
image page into the target TD page which is encrypted with the TD
ephemeral key. TDH.MEM.PAGE.ADD also extends the TD
measurement with the page GPA.

2. The host VMM extends the TD measurement with the contents of
the new page by calling the TDH.MR.EXTEND function on each 256-
byte chunk of the new TD page.

So this is a bit like SGX.  There is a specific series of operations
that have to be done in precisely the right order to reproduce the
intended TD measurement.  Otherwise the guest will boot and run until
it tries to get a report and then it will have a hard time getting
anyone to believe its report.

So I don't think the host kernel can get away with host userspace just
providing pre-populated memory.  Userspace needs to tell the host
kernel exactly what sequence of adds, extends, etc to perform and in
what order, and the host kernel needs to do precisely what userspace
asks it to do.  "Here's the contents of memory" doesn't cut it unless
the tooling that builds the guest image matches the exact semantics
that the host kernel provides.

--Andy
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help