From: Andra Paraschiv <andraprs@amazon.com>
To: <linux-kernel@vger.kernel.org>
Cc: Anthony Liguori <aliguori@amazon.com>,
Benjamin Herrenschmidt <benh@kernel.crashing.org>,
Colm MacCarthaigh <colmmacc@amazon.com>,
"David Duncan" <davdunc@amazon.com>,
Bjoern Doebel <doebel@amazon.de>,
"David Woodhouse" <dwmw@amazon.co.uk>,
Frank van der Linden <fllinden@amazon.com>,
Alexander Graf <graf@amazon.de>,
Greg KH <gregkh@linuxfoundation.org>,
"Karen Noel" <knoel@redhat.com>,
Martin Pohlack <mpohlack@amazon.de>, Matt Wilson <msw@amazon.com>,
Paolo Bonzini <pbonzini@redhat.com>,
Balbir Singh <sblbir@amazon.com>,
Stefano Garzarella <sgarzare@redhat.com>,
"Stefan Hajnoczi" <stefanha@redhat.com>,
Stewart Smith <trawets@amazon.com>,
"Uwe Dannowski" <uwed@amazon.de>,
Vitaly Kuznetsov <vkuznets@redhat.com>, <kvm@vger.kernel.org>,
<ne-devel-upstream@amazon.com>,
Andra Paraschiv <andraprs@amazon.com>
Subject: [PATCH v5 07/18] nitro_enclaves: Init misc device providing the ioctl interface
Date: Wed, 15 Jul 2020 22:45:29 +0300 [thread overview]
Message-ID: <20200715194540.45532-8-andraprs@amazon.com> (raw)
In-Reply-To: <20200715194540.45532-1-andraprs@amazon.com>
The Nitro Enclaves driver provides an ioctl interface to the user space
for enclave lifetime management e.g. enclave creation / termination and
setting enclave resources such as memory and CPU.
This ioctl interface is mapped to a Nitro Enclaves misc device.
Signed-off-by: Andra Paraschiv <andraprs@amazon.com>
---
Changelog
v4 -> v5
* Update the size of the NE CPU pool string from 4096 to 512 chars.
v3 -> v4
* Use dev_err instead of custom NE log pattern.
* Remove the NE CPU pool init during kernel module loading, as the CPU
pool is now setup at runtime, via a sysfs file for the kernel
parameter.
* Add minimum enclave memory size definition.
v2 -> v3
* Remove the GPL additional wording as SPDX-License-Identifier is
already in place.
* Remove the WARN_ON calls.
* Remove linux/bug and linux/kvm_host includes that are not needed.
* Remove "ratelimited" from the logs that are not in the ioctl call
paths.
* Remove file ops that do nothing for now - open and release.
v1 -> v2
* Add log pattern for NE.
* Update goto labels to match their purpose.
* Update ne_cpu_pool data structure to include the global mutex.
* Update NE misc device mode to 0660.
* Check if the CPU siblings are included in the NE CPU pool, as full CPU
cores are given for the enclave(s).
---
drivers/virt/nitro_enclaves/ne_misc_dev.c | 123 ++++++++++++++++++++++
drivers/virt/nitro_enclaves/ne_pci_dev.c | 11 ++
2 files changed, 134 insertions(+)
create mode 100644 drivers/virt/nitro_enclaves/ne_misc_dev.c
diff --git a/drivers/virt/nitro_enclaves/ne_misc_dev.c b/drivers/virt/nitro_enclaves/ne_misc_dev.c
new file mode 100644
index 000000000000..62c9a70c5cf3
--- /dev/null
+++ b/drivers/virt/nitro_enclaves/ne_misc_dev.c
@@ -0,0 +1,123 @@
+// SPDX-License-Identifier: GPL-2.0
+/*
+ * Copyright 2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
+ */
+
+/**
+ * Enclave lifetime management driver for Nitro Enclaves (NE).
+ * Nitro is a hypervisor that has been developed by Amazon.
+ */
+
+#include <linux/anon_inodes.h>
+#include <linux/capability.h>
+#include <linux/cpu.h>
+#include <linux/device.h>
+#include <linux/file.h>
+#include <linux/hugetlb.h>
+#include <linux/list.h>
+#include <linux/miscdevice.h>
+#include <linux/mm.h>
+#include <linux/mman.h>
+#include <linux/module.h>
+#include <linux/mutex.h>
+#include <linux/nitro_enclaves.h>
+#include <linux/pci.h>
+#include <linux/poll.h>
+#include <linux/slab.h>
+#include <linux/types.h>
+
+#include "ne_misc_dev.h"
+#include "ne_pci_dev.h"
+
+/**
+ * Size for max 128 CPUs, for now, in a cpu-list string, comma separated.
+ * The NE CPU pool includes CPUs from a single NUMA node.
+ */
+#define NE_CPUS_SIZE (512)
+
+#define NE_EIF_LOAD_OFFSET (8 * 1024UL * 1024UL)
+
+#define NE_MIN_ENCLAVE_MEM_SIZE (64 * 1024UL * 1024UL)
+
+#define NE_MIN_MEM_REGION_SIZE (2 * 1024UL * 1024UL)
+
+/*
+ * TODO: Update logic to create new sysfs entries instead of using
+ * a kernel parameter e.g. if multiple sysfs files needed.
+ */
+static const struct kernel_param_ops ne_cpu_pool_ops = {
+ .get = param_get_string,
+};
+
+static char ne_cpus[NE_CPUS_SIZE];
+static struct kparam_string ne_cpus_arg = {
+ .maxlen = sizeof(ne_cpus),
+ .string = ne_cpus,
+};
+
+module_param_cb(ne_cpus, &ne_cpu_pool_ops, &ne_cpus_arg, 0644);
+/* https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html#cpu-lists */
+MODULE_PARM_DESC(ne_cpus, "<cpu-list> - CPU pool used for Nitro Enclaves");
+
+/* CPU pool used for Nitro Enclaves. */
+struct ne_cpu_pool {
+ /* Available CPU cores in the pool. */
+ cpumask_var_t *avail_cores;
+
+ /* The size of the available cores array. */
+ unsigned int avail_cores_size;
+
+ struct mutex mutex;
+
+ /* NUMA node of the CPUs in the pool. */
+ int numa_node;
+};
+
+static struct ne_cpu_pool ne_cpu_pool;
+
+static long ne_ioctl(struct file *file, unsigned int cmd, unsigned long arg)
+{
+ switch (cmd) {
+ case NE_GET_API_VERSION:
+ return NE_API_VERSION;
+
+ default:
+ return -ENOTTY;
+ }
+
+ return 0;
+}
+
+static const struct file_operations ne_fops = {
+ .owner = THIS_MODULE,
+ .llseek = noop_llseek,
+ .unlocked_ioctl = ne_ioctl,
+};
+
+struct miscdevice ne_misc_dev = {
+ .minor = MISC_DYNAMIC_MINOR,
+ .name = "nitro_enclaves",
+ .fops = &ne_fops,
+ .mode = 0660,
+};
+
+static int __init ne_init(void)
+{
+ mutex_init(&ne_cpu_pool.mutex);
+
+ return pci_register_driver(&ne_pci_driver);
+}
+
+static void __exit ne_exit(void)
+{
+ pci_unregister_driver(&ne_pci_driver);
+}
+
+/* TODO: Handle actions such as reboot, kexec. */
+
+module_init(ne_init);
+module_exit(ne_exit);
+
+MODULE_AUTHOR("Amazon.com, Inc. or its affiliates");
+MODULE_DESCRIPTION("Nitro Enclaves Driver");
+MODULE_LICENSE("GPL v2");
diff --git a/drivers/virt/nitro_enclaves/ne_pci_dev.c b/drivers/virt/nitro_enclaves/ne_pci_dev.c
index e12a8f8bf0be..1208f303272e 100644
--- a/drivers/virt/nitro_enclaves/ne_pci_dev.c
+++ b/drivers/virt/nitro_enclaves/ne_pci_dev.c
@@ -499,6 +499,13 @@ static int ne_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id)
goto teardown_msix;
}
+ rc = misc_register(&ne_misc_dev);
+ if (rc < 0) {
+ dev_err(&pdev->dev, "Error in misc dev register [rc=%d]\n", rc);
+
+ goto disable_ne_pci_dev;
+ }
+
atomic_set(&ne_pci_dev->cmd_reply_avail, 0);
init_waitqueue_head(&ne_pci_dev->cmd_reply_wait_q);
INIT_LIST_HEAD(&ne_pci_dev->enclaves_list);
@@ -508,6 +515,8 @@ static int ne_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id)
return 0;
+disable_ne_pci_dev:
+ ne_pci_dev_disable(pdev);
teardown_msix:
ne_teardown_msix(pdev);
iounmap_pci_bar:
@@ -527,6 +536,8 @@ static void ne_pci_remove(struct pci_dev *pdev)
{
struct ne_pci_dev *ne_pci_dev = pci_get_drvdata(pdev);
+ misc_deregister(&ne_misc_dev);
+
ne_pci_dev_disable(pdev);
ne_teardown_msix(pdev);
--
2.20.1 (Apple Git-117)
Amazon Development Center (Romania) S.R.L. registered office: 27A Sf. Lazar Street, UBC5, floor 2, Iasi, Iasi County, 700045, Romania. Registered in Romania. Registration number J22/2621/2005.
next prev parent reply other threads:[~2020-07-15 19:47 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-07-15 19:45 [PATCH v5 00/18] Add support for Nitro Enclaves Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 01/18] nitro_enclaves: Add ioctl interface definition Andra Paraschiv
2020-07-16 8:30 ` Stefan Hajnoczi
2020-07-16 9:30 ` Paraschiv, Andra-Irina
2020-07-21 12:12 ` Greg KH
2020-07-22 8:27 ` Paraschiv, Andra-Irina
2020-07-22 9:57 ` Greg KH
2020-07-23 9:23 ` Paraschiv, Andra-Irina
2020-07-23 10:54 ` Greg KH
2020-07-23 18:21 ` Paraschiv, Andra-Irina
2020-07-23 23:04 ` Alexander Graf
2020-07-24 9:06 ` Paraschiv, Andra-Irina
2020-07-15 19:45 ` [PATCH v5 02/18] nitro_enclaves: Define the PCI device interface Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 03/18] nitro_enclaves: Define enclave info for internal bookkeeping Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 04/18] nitro_enclaves: Init PCI device driver Andra Paraschiv
2020-07-20 14:24 ` Alexander Graf
2020-07-21 6:20 ` Paraschiv, Andra-Irina
2020-07-15 19:45 ` [PATCH v5 05/18] nitro_enclaves: Handle PCI device command requests Andra Paraschiv
2020-07-21 10:17 ` Alexander Graf
2020-07-22 8:14 ` Paraschiv, Andra-Irina
2020-07-15 19:45 ` [PATCH v5 06/18] nitro_enclaves: Handle out-of-band PCI device events Andra Paraschiv
2020-07-15 19:45 ` Andra Paraschiv [this message]
2020-07-15 19:45 ` [PATCH v5 08/18] nitro_enclaves: Add logic for creating an enclave VM Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 09/18] nitro_enclaves: Add logic for setting an enclave vCPU Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 10/18] nitro_enclaves: Add logic for getting the enclave image load info Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 11/18] nitro_enclaves: Add logic for setting an enclave memory region Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 12/18] nitro_enclaves: Add logic for starting an enclave Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 13/18] nitro_enclaves: Add logic for terminating " Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 14/18] nitro_enclaves: Add Kconfig for the Nitro Enclaves driver Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 15/18] nitro_enclaves: Add Makefile " Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 16/18] nitro_enclaves: Add sample for ioctl interface usage Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 17/18] nitro_enclaves: Add overview documentation Andra Paraschiv
2020-07-15 19:45 ` [PATCH v5 18/18] MAINTAINERS: Add entry for the Nitro Enclaves driver Andra Paraschiv
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200715194540.45532-8-andraprs@amazon.com \
--to=andraprs@amazon.com \
--cc=aliguori@amazon.com \
--cc=benh@kernel.crashing.org \
--cc=colmmacc@amazon.com \
--cc=davdunc@amazon.com \
--cc=doebel@amazon.de \
--cc=dwmw@amazon.co.uk \
--cc=fllinden@amazon.com \
--cc=graf@amazon.de \
--cc=gregkh@linuxfoundation.org \
--cc=knoel@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mpohlack@amazon.de \
--cc=msw@amazon.com \
--cc=ne-devel-upstream@amazon.com \
--cc=pbonzini@redhat.com \
--cc=sblbir@amazon.com \
--cc=sgarzare@redhat.com \
--cc=stefanha@redhat.com \
--cc=trawets@amazon.com \
--cc=uwed@amazon.de \
--cc=vkuznets@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.