From: "Radim Krčmář" <rkrcmar@redhat.com>
To: Paolo Bonzini <pbonzini@redhat.com>
Cc: Nadav Amit <nadav.amit@gmail.com>,
Linux Kernel Mailing List <linux-kernel@vger.kernel.org>,
kvm list <kvm@vger.kernel.org>,
Wanpeng Li <wanpeng.li@linux.intel.com>,
Nadav Amit <namit@cs.technion.ac.il>,
hpa@linux.intel.com, Fenghua Yu <fenghua.yu@intel.com>
Subject: Re: [CFT PATCH v2 2/2] KVM: x86: support XSAVES usage in the host
Date: Wed, 3 Dec 2014 19:45:38 +0100 [thread overview]
Message-ID: <20141203184537.GA27128@potion.brq.redhat.com> (raw)
In-Reply-To: <547F1D84.9040505@redhat.com>
2014-12-03 15:26+0100, Paolo Bonzini:
>
>
> On 03/12/2014 15:23, Nadav Amit wrote:
> > I think it is better just to replace the last line with:
> >
> > *(u64 *)(dest + XSAVE_HDR_OFFSET) = xsave->xsave_hdr.xstate_bv
Yeah, or we can use this value for xstate_bv to save some copying too,
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 19e5e8f..ba2b7bd 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3137,7 +3137,7 @@ static int kvm_vcpu_ioctl_x86_set_debugregs(struct kvm_vcpu *vcpu,
static void fill_xsave(u8 *dest, struct kvm_vcpu *vcpu)
{
struct xsave_struct *xsave = &vcpu->arch.guest_fpu.state->xsave;
- u64 xstate_bv = vcpu->arch.guest_supported_xcr0 | XSTATE_FPSSE;
+ u64 xstate_bv = xsave->xsave_hdr.xstate_bv;
u64 valid;
/*
> Right, this matches
>
> u64 xstate_bv = *(u64 *)(src + XSAVE_HDR_OFFSET);
> ...
> xsave->xsave_hdr.xstate_bv = xstate_bv;
>
> in load_xsave.
Btw, we don't care about crashers from userspace?
---8<---
KVM: x86: prevent #GP with malicious xsave
XRSTORS throws #GP when XSTATE_BV isn't a subset of XCOMP_BV.
Make it so.
SDM: XRSTORS Exceptions
#GP If a bit in the XCOMP_BV field in the XSAVE header is 0 and the
corresponding bit in the XSTATE_BV field is 1.
(Also in SDM: 13.11 OPERATION OF XRSTORS)
Signed-off-by: Radim Krčmář <rkrcmar@redhat.com>
---
arch/x86/kvm/x86.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index ca26681..19e5e8f 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -3184,8 +3184,10 @@ static void load_xsave(struct kvm_vcpu *vcpu, u8 *src)
/* Set XSTATE_BV and possibly XCOMP_BV. */
xsave->xsave_hdr.xstate_bv = xstate_bv;
- if (cpu_has_xsaves)
+ if (cpu_has_xsaves) {
xsave->xsave_hdr.xcomp_bv = host_xcr0 | XSTATE_COMPACTION_ENABLED;
+ xsave->xsave_hdr.xstate_bv &= xsave->xsave_hdr.xcomp_bv;
+ }
/*
* Copy each region from the non-compacted offset to the
--
2.2.0
next prev parent reply other threads:[~2014-12-03 18:45 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2014-11-24 16:43 [CFT PATCH v2 0/2] KVM: support XSAVES usage in the host Paolo Bonzini
2014-11-24 16:43 ` [CFT PATCH v2 1/2] kvm: x86: mask out XSAVES Paolo Bonzini
2014-11-24 16:43 ` [CFT PATCH v2 2/2] KVM: x86: support XSAVES usage in the host Paolo Bonzini
2014-11-26 12:07 ` Radim Krčmář
2014-11-26 13:13 ` Paolo Bonzini
2014-11-26 13:53 ` Radim Krčmář
2014-11-26 13:57 ` Paolo Bonzini
2014-11-26 14:42 ` Radim Krčmář
2014-11-26 16:26 ` Paolo Bonzini
2014-11-26 17:31 ` Radim Krčmář
2014-12-03 14:23 ` Nadav Amit
2014-12-03 14:26 ` Paolo Bonzini
2014-12-03 18:45 ` Radim Krčmář [this message]
2014-12-04 13:43 ` Paolo Bonzini
2014-12-04 13:52 ` Radim Krčmář
2014-11-25 10:13 ` [CFT PATCH v2 0/2] KVM: " Wanpeng Li
2014-11-25 10:36 ` Paolo Bonzini
2014-11-25 14:05 ` Nadav Amit
2014-11-25 14:17 ` Paolo Bonzini
2014-11-25 14:50 ` Nadav Amit
2014-11-26 1:24 ` Wanpeng Li
2014-11-26 9:00 ` Nadav Amit
2014-11-26 8:47 ` Wanpeng Li
2014-11-26 12:54 ` Paolo Bonzini
2014-12-02 5:16 ` Wanpeng Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20141203184537.GA27128@potion.brq.redhat.com \
--to=rkrcmar@redhat.com \
--cc=fenghua.yu@intel.com \
--cc=hpa@linux.intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nadav.amit@gmail.com \
--cc=namit@cs.technion.ac.il \
--cc=pbonzini@redhat.com \
--cc=wanpeng.li@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.