From: Marc Zyngier <maz@kernel.org> Date: 2021-05-20 12:23:52
It looks like we have tolerated creating mixed-width VMs since...
forever. However, that was never the intention, and we'd rather
not have to support that pointless complexity.
Forbid such a setup by making sure all the vcpus have the same
register width.
Reported-by: Steven Price <steven.price@arm.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
---
arch/arm64/kvm/reset.c | 28 ++++++++++++++++++++++++----
1 file changed, 24 insertions(+), 4 deletions(-)
@@ -166,6 +166,25 @@ static int kvm_vcpu_enable_ptrauth(struct kvm_vcpu *vcpu)return0;}+staticboolvcpu_allowed_register_width(structkvm_vcpu*vcpu)+{+structkvm_vcpu*tmp;+inti;++/* Check that the vcpus are either all 32bit or all 64bit */+kvm_for_each_vcpu(i,tmp,vcpu->kvm){+boolw;++w=test_bit(KVM_ARM_VCPU_EL1_32BIT,tmp->arch.features);+w^=test_bit(KVM_ARM_VCPU_EL1_32BIT,vcpu->arch.features);++if(w)+returnfalse;+}++returntrue;+}+/***kvm_reset_vcpu-setscoreregistersandsys_regstoresetvalue*@vcpu:TheVCPUpointer
@@ -217,13 +236,14 @@ int kvm_reset_vcpu(struct kvm_vcpu *vcpu)}}+if(!vcpu_allowed_register_width(vcpu)){+ret=-EINVAL;+gotoout;+}+switch(vcpu->arch.target){default:if(test_bit(KVM_ARM_VCPU_EL1_32BIT,vcpu->arch.features)){-if(!cpus_have_const_cap(ARM64_HAS_32BIT_EL1)){-ret=-EINVAL;-gotoout;-}pstate=VCPU_RESET_PSTATE_SVC;}else{pstate=VCPU_RESET_PSTATE_EL1;
--
2.30.2
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
From: Mark Rutland <mark.rutland@arm.com> Date: 2021-05-20 12:46:37
On Thu, May 20, 2021 at 01:22:53PM +0100, Marc Zyngier wrote:
quoted hunk
It looks like we have tolerated creating mixed-width VMs since...
forever. However, that was never the intention, and we'd rather
not have to support that pointless complexity.
Forbid such a setup by making sure all the vcpus have the same
register width.
Reported-by: Steven Price <steven.price@arm.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
---
arch/arm64/kvm/reset.c | 28 ++++++++++++++++++++++++----
1 file changed, 24 insertions(+), 4 deletions(-)
@@ -166,6 +166,25 @@ static int kvm_vcpu_enable_ptrauth(struct kvm_vcpu *vcpu)return0;}+staticboolvcpu_allowed_register_width(structkvm_vcpu*vcpu)+{+structkvm_vcpu*tmp;+inti;++/* Check that the vcpus are either all 32bit or all 64bit */+kvm_for_each_vcpu(i,tmp,vcpu->kvm){+boolw;++w=test_bit(KVM_ARM_VCPU_EL1_32BIT,tmp->arch.features);+w^=test_bit(KVM_ARM_VCPU_EL1_32BIT,vcpu->arch.features);++if(w)+returnfalse;+}
I think this is wrong for a single-cpu VM. In that case, the loop will
have a single iteration, and tmp == vcpu, so w must be 0 regardless of
the value of arch.features.
IIUC that doesn't prevent KVM_ARM_VCPU_EL1_32BIT being set when we don't
have the ARM64_HAS_32BIT_EL1 cap, unless that's checked elsewhere?
How about something like:
| static bool vcpu_allowed_register_width(struct kvm_vcpu *vcpu)
| {
| bool is_32bit = vcpu_features_32bit(vcpu);
| struct kvm_vcpu *tmp;
| int i;
|
| if (!cpus_have_const_cap(ARM64_HAS_32BIT_EL1) && is_32bit)
| return false;
|
| kvm_for_each_vcpu(i, tmp, vcpu->kvm) {
| if (is_32bit != vcpu_features_32bit(tmp))
| return false;
| }
|
| return true;
| }
... with a helper in <asm/kvm_emulate.h> like:
| static bool vcpu_features_32bit(struct kvm_vcpu *vcpu)
| {
| return test_bit(KVM_ARM_VCPU_EL1_32BIT, vcpu->arch.features);
| }
... or
| static inline bool vcpu_has_feature(struct kvm_vcpu *vcpu, int feature)
| {
| return test_bit(feature, vcpu->arch.features);
| }
... so that we can avoid the line splitting required by the length of
the test_bit() expression?
Thanks,
Mark.
quoted hunk
+
+ return true;
+}
+
/**
* kvm_reset_vcpu - sets core registers and sys_regs to reset value
* @vcpu: The VCPU pointer
@@ -217,13 +236,14 @@ int kvm_reset_vcpu(struct kvm_vcpu *vcpu) } }+ if (!vcpu_allowed_register_width(vcpu)) {+ ret = -EINVAL;+ goto out;+ }+ switch (vcpu->arch.target) { default: if (test_bit(KVM_ARM_VCPU_EL1_32BIT, vcpu->arch.features)) {- if (!cpus_have_const_cap(ARM64_HAS_32BIT_EL1)) {- ret = -EINVAL;- goto out;- } pstate = VCPU_RESET_PSTATE_SVC; } else { pstate = VCPU_RESET_PSTATE_EL1;
--
2.30.2
_______________________________________________
kvmarm mailing list
kvmarm@lists.cs.columbia.edu
https://lists.cs.columbia.edu/mailman/listinfo/kvmarm
From: Marc Zyngier <maz@kernel.org> Date: 2021-05-20 12:59:40
On Thu, 20 May 2021 13:44:34 +0100,
Mark Rutland [off-list ref] wrote:
On Thu, May 20, 2021 at 01:22:53PM +0100, Marc Zyngier wrote:
quoted
It looks like we have tolerated creating mixed-width VMs since...
forever. However, that was never the intention, and we'd rather
not have to support that pointless complexity.
Forbid such a setup by making sure all the vcpus have the same
register width.
Reported-by: Steven Price <steven.price@arm.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
---
arch/arm64/kvm/reset.c | 28 ++++++++++++++++++++++++----
1 file changed, 24 insertions(+), 4 deletions(-)
@@ -166,6 +166,25 @@ static int kvm_vcpu_enable_ptrauth(struct kvm_vcpu *vcpu)return0;}+staticboolvcpu_allowed_register_width(structkvm_vcpu*vcpu)+{+structkvm_vcpu*tmp;+inti;++/* Check that the vcpus are either all 32bit or all 64bit */+kvm_for_each_vcpu(i,tmp,vcpu->kvm){+boolw;++w=test_bit(KVM_ARM_VCPU_EL1_32BIT,tmp->arch.features);+w^=test_bit(KVM_ARM_VCPU_EL1_32BIT,vcpu->arch.features);++if(w)+returnfalse;+}
I think this is wrong for a single-cpu VM. In that case, the loop will
have a single iteration, and tmp == vcpu, so w must be 0 regardless of
the value of arch.features.
I don't immediately see what is wrong with a single-cpu VM. 'w' will
be zero indeed, and we'll return that this is allowed. After all, each
VM starts by being a single-CPU VM.
But of course...
IIUC that doesn't prevent KVM_ARM_VCPU_EL1_32BIT being set when we don't
have the ARM64_HAS_32BIT_EL1 cap, unless that's checked elsewhere?
... I mistakenly removed the check against ARM64_HAS_32BIT_EL1...
How about something like:
| static bool vcpu_allowed_register_width(struct kvm_vcpu *vcpu)
| {
| bool is_32bit = vcpu_features_32bit(vcpu);
| struct kvm_vcpu *tmp;
| int i;
|
| if (!cpus_have_const_cap(ARM64_HAS_32BIT_EL1) && is_32bit)
| return false;
|
| kvm_for_each_vcpu(i, tmp, vcpu->kvm) {
| if (is_32bit != vcpu_features_32bit(tmp))
| return false;
| }
|
| return true;
| }
... with a helper in <asm/kvm_emulate.h> like:
| static bool vcpu_features_32bit(struct kvm_vcpu *vcpu)
| {
| return test_bit(KVM_ARM_VCPU_EL1_32BIT, vcpu->arch.features);
| }
... or
| static inline bool vcpu_has_feature(struct kvm_vcpu *vcpu, int feature)
| {
| return test_bit(feature, vcpu->arch.features);
| }
... so that we can avoid the line splitting required by the length of
the test_bit() expression?
Yup, looks OK to me (with a preference for the latter).
Thanks,
M.
--
Without deviation from the norm, progress is not possible.
_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel
From: Mark Rutland <mark.rutland@arm.com> Date: 2021-05-20 14:07:32
On Thu, May 20, 2021 at 01:58:55PM +0100, Marc Zyngier wrote:
On Thu, 20 May 2021 13:44:34 +0100,
Mark Rutland [off-list ref] wrote:
quoted
On Thu, May 20, 2021 at 01:22:53PM +0100, Marc Zyngier wrote:
quoted
It looks like we have tolerated creating mixed-width VMs since...
forever. However, that was never the intention, and we'd rather
not have to support that pointless complexity.
Forbid such a setup by making sure all the vcpus have the same
register width.
Reported-by: Steven Price <steven.price@arm.com>
Signed-off-by: Marc Zyngier <maz@kernel.org>
Cc: stable@vger.kernel.org
---
arch/arm64/kvm/reset.c | 28 ++++++++++++++++++++++++----
1 file changed, 24 insertions(+), 4 deletions(-)
@@ -166,6 +166,25 @@ static int kvm_vcpu_enable_ptrauth(struct kvm_vcpu *vcpu)return0;}+staticboolvcpu_allowed_register_width(structkvm_vcpu*vcpu)+{+structkvm_vcpu*tmp;+inti;++/* Check that the vcpus are either all 32bit or all 64bit */+kvm_for_each_vcpu(i,tmp,vcpu->kvm){+boolw;++w=test_bit(KVM_ARM_VCPU_EL1_32BIT,tmp->arch.features);+w^=test_bit(KVM_ARM_VCPU_EL1_32BIT,vcpu->arch.features);++if(w)+returnfalse;+}
I think this is wrong for a single-cpu VM. In that case, the loop will
have a single iteration, and tmp == vcpu, so w must be 0 regardless of
the value of arch.features.
I don't immediately see what is wrong with a single-cpu VM. 'w' will
be zero indeed, and we'll return that this is allowed. After all, each
VM starts by being a single-CPU VM.
Sorry; I should have been clearer. I had assumed that this was trying to
rely on a difference across vcpus implicitly providing an equivalent of
the removed check for the KVM_ARM_VCPU_EL1_32BIT cap. I guess from the
below that was not the case. :)
Thanks,
Mark.
But of course...
quoted
IIUC that doesn't prevent KVM_ARM_VCPU_EL1_32BIT being set when we don't
have the ARM64_HAS_32BIT_EL1 cap, unless that's checked elsewhere?
... I mistakenly removed the check against ARM64_HAS_32BIT_EL1...
quoted
How about something like:
| static bool vcpu_allowed_register_width(struct kvm_vcpu *vcpu)
| {
| bool is_32bit = vcpu_features_32bit(vcpu);
| struct kvm_vcpu *tmp;
| int i;
|
| if (!cpus_have_const_cap(ARM64_HAS_32BIT_EL1) && is_32bit)
| return false;
|
| kvm_for_each_vcpu(i, tmp, vcpu->kvm) {
| if (is_32bit != vcpu_features_32bit(tmp))
| return false;
| }
|
| return true;
| }
... with a helper in <asm/kvm_emulate.h> like:
| static bool vcpu_features_32bit(struct kvm_vcpu *vcpu)
| {
| return test_bit(KVM_ARM_VCPU_EL1_32BIT, vcpu->arch.features);
| }
... or
| static inline bool vcpu_has_feature(struct kvm_vcpu *vcpu, int feature)
| {
| return test_bit(feature, vcpu->arch.features);
| }
... so that we can avoid the line splitting required by the length of
the test_bit() expression?
Yup, looks OK to me (with a preference for the latter).
Thanks,
M.
--
Without deviation from the norm, progress is not possible.