From: Binbin Wu <binbin.wu@linux.intel.com>
To: Kishen Maloor <kishen.maloor@intel.com>, qemu-devel@nongnu.org
Cc: pbonzini@redhat.com, zhao1.liu@intel.com, kvm@vger.kernel.org,
sohil.mehta@intel.com, xiaoyao.li@intel.com,
farrah.chen@intel.com
Subject: Re: [PATCH 0/5] target/i386: Add support for LASS
Date: Wed, 2 Sep 2026 10:40:21 +0800 [thread overview]
Message-ID: <12100e0f-0730-4f12-81db-5e9dd18fef79@linux.intel.com> (raw)
In-Reply-To: <20260826035734.114685-1-kishen.maloor@intel.com>
On 8/26/2026 11:57 AM, Kishen Maloor wrote:
> This series adds QEMU support for Linear Address Space Separation (LASS) [1],
> an Intel security feature that prevents a class of side-channel attacks
> relying on speculative accesses across the user/kernel boundary. Paging,
> along with SMEP and SMAP, already provides mode-based access protection,
> but enforcing it requires a page walk whose timing can leak the layout of
> kernel memory. LASS applies the equivalent protections during
> linear-address pre-processing: given the usual partitioning of the linear
> address space into a user half (bit 63 clear) and a supervisor half
> (bit 63 set), an access targeting the opposite half is rejected on the
> basis of bit 63 alone, before any page walk.
>
> This series enumerates the LASS CPUID bit, recognizes CR4.LASS,
> and exposes LASS on the relevant Intel CPU models via new versioned models.
> LASS is not emulated by TCG.
>
> Exposing LASS to a guest also requires KVM support: KVM must validate
> the CPUID bit and CR4.LASS, and enforce LASS violations in its
> instruction emulator. That enabling is currently under review [2].
>
> Tested with a Linux guest on LASS-capable hardware: LASS is enumerated and
> CR4.LASS is set under KVM, and not enumerated under TCG.
>
> [1] Intel 64 and IA-32 Architectures Software Developer's Manual, Volume 3A,
> Section 4.3, "Linear-Address-Space Separation (LASS)".
> [2] https://lore.kernel.org/kvm/20260806011536.4172258-1-sohil.mehta@intel.com/
>
> Isaku Yamahata (2):
> target/i386: Add support for LASS in CPUID enumeration
> target/i386: Add LASS support in CR4
>
> Kishen Maloor (3):
> target/i386: Introduce DiamondRapids-v3 to enable LASS
> target/i386: Introduce SierraForest-v7 to enable LASS
> target/i386: Introduce ClearwaterForest-v5 to enable LASS
Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
>
> target/i386/cpu.c | 26 +++++++++++++++++++++++++-
> target/i386/cpu.h | 7 ++++++-
> target/i386/helper.c | 4 ++++
> 3 files changed, 35 insertions(+), 2 deletions(-)
>
prev parent reply other threads:[~2026-09-02 2:41 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 3:57 [PATCH 0/5] target/i386: Add support for LASS Kishen Maloor
2026-08-26 3:57 ` [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration Kishen Maloor
2026-09-02 10:14 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 2/5] target/i386: Add LASS support in CR4 Kishen Maloor
2026-09-02 10:16 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 3/5] target/i386: Introduce DiamondRapids-v3 to enable LASS Kishen Maloor
2026-09-02 10:16 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 4/5] target/i386: Introduce SierraForest-v7 " Kishen Maloor
2026-09-02 10:17 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 5/5] target/i386: Introduce ClearwaterForest-v5 " Kishen Maloor
2026-09-02 10:17 ` Zhao Liu
2026-08-27 3:07 ` [PATCH 0/5] target/i386: Add support for LASS Chen, Farrah
2026-09-01 16:08 ` Sohil Mehta
2026-09-02 2:40 ` Binbin Wu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=12100e0f-0730-4f12-81db-5e9dd18fef79@linux.intel.com \
--to=binbin.wu@linux.intel.com \
--cc=farrah.chen@intel.com \
--cc=kishen.maloor@intel.com \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=sohil.mehta@intel.com \
--cc=xiaoyao.li@intel.com \
--cc=zhao1.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.