From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Fabiano Rosas <farosas@suse.de>, Fabian Vogt <fvogt@suse.de>
Subject: [PULL 12/17] target/i386: Expose IBPB-BRTYPE and SBPB CPUID bits to the guest
Date: Wed, 11 Sep 2024 14:33:37 +0200 [thread overview]
Message-ID: <20240911123342.339482-13-pbonzini@redhat.com> (raw)
In-Reply-To: <20240911123342.339482-1-pbonzini@redhat.com>
From: Fabiano Rosas <farosas@suse.de>
According to AMD's Speculative Return Stack Overflow whitepaper (link
below), the hypervisor should synthesize the value of IBPB_BRTYPE and
SBPB CPUID bits to the guest.
Support for this is already present in the kernel with commit
e47d86083c66 ("KVM: x86: Add SBPB support") and commit 6f0f23ef76be
("KVM: x86: Add IBPB_BRTYPE support").
Add support in QEMU to expose the bits to the guest OS.
host:
# cat /sys/devices/system/cpu/vulnerabilities/spec_rstack_overflow
Mitigation: Safe RET
before (guest):
$ cpuid -l 0x80000021 -1 -r
0x80000021 0x00: eax=0x00000045 ebx=0x00000000 ecx=0x00000000 edx=0x00000000
^
$ cat /sys/devices/system/cpu/vulnerabilities/spec_rstack_overflow
Vulnerable: Safe RET, no microcode
after (guest):
$ cpuid -l 0x80000021 -1 -r
0x80000021 0x00: eax=0x18000045 ebx=0x00000000 ecx=0x00000000 edx=0x00000000
^
$ cat /sys/devices/system/cpu/vulnerabilities/spec_rstack_overflow
Mitigation: Safe RET
Reported-by: Fabian Vogt <fvogt@suse.de>
Link: https://www.amd.com/content/dam/amd/en/documents/corporate/cr/speculative-return-stack-overflow-whitepaper.pdf
Signed-off-by: Fabiano Rosas <farosas@suse.de>
Link: https://lore.kernel.org/r/20240805202041.5936-1-farosas@suse.de
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
target/i386/cpu.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/target/i386/cpu.c b/target/i386/cpu.c
index 31f287cae05..ff227a8c5c8 100644
--- a/target/i386/cpu.c
+++ b/target/i386/cpu.c
@@ -1221,8 +1221,8 @@ FeatureWordInfo feature_word_info[FEATURE_WORDS] = {
NULL, NULL, NULL, NULL,
NULL, NULL, NULL, NULL,
NULL, NULL, NULL, NULL,
- NULL, NULL, NULL, NULL,
- NULL, NULL, NULL, NULL,
+ NULL, NULL, NULL, "sbpb",
+ "ibpb-brtype", NULL, NULL, NULL,
},
.cpuid = { .eax = 0x80000021, .reg = R_EAX, },
.tcg_features = 0,
--
2.46.0
next prev parent reply other threads:[~2024-09-11 12:37 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-09-11 12:33 [PULL 00/17] Misc patches for 2024-09-11 Paolo Bonzini
2024-09-11 12:33 ` [PULL 01/17] target/i386: Delete duplicated macro definition CR4_FRED_MASK Paolo Bonzini
2024-09-11 12:33 ` [PULL 02/17] target/i386: Add VMX control bits for nested FRED support Paolo Bonzini
2024-09-11 12:33 ` [PULL 03/17] target/i386: Raise the highest index value used for any VMCS encoding Paolo Bonzini
2024-09-11 12:33 ` [PULL 04/17] tests/unit: remove block layer code from test-nested-aio-poll Paolo Bonzini
2024-09-11 12:33 ` [PULL 05/17] hw/i386/pc: Add a description for the i8042 property Paolo Bonzini
2024-09-11 12:33 ` [PULL 06/17] kvm/i386: make kvm_filter_msr() and related definitions private to kvm module Paolo Bonzini
2024-09-11 12:33 ` [PULL 07/17] kvm/i386: fix return values of is_host_cpu_intel() Paolo Bonzini
2024-09-11 12:33 ` [PULL 08/17] kvm: replace fprintf with error_report()/printf() in kvm_init() Paolo Bonzini
2024-09-11 12:33 ` [PULL 09/17] kvm/i386: refactor kvm_arch_init and split it into smaller functions Paolo Bonzini
2024-09-11 12:33 ` [PULL 10/17] kvm/i386: replace identity_base variable with a constant Paolo Bonzini
2024-09-11 12:33 ` [PULL 11/17] kvm: refactor core virtual machine creation into its own function Paolo Bonzini
2024-09-11 12:33 ` Paolo Bonzini [this message]
2024-09-11 12:33 ` [PULL 13/17] hw: Remove unused inclusion of hw/char/serial.h Paolo Bonzini
2024-09-11 12:33 ` [PULL 14/17] hw/char/serial.h: Extract serial-isa.h Paolo Bonzini
2024-09-11 12:33 ` [PULL 15/17] hw/char: Extract serial-mm Paolo Bonzini
2024-09-11 12:33 ` [PULL 16/17] virtio-9p: remove virtfs-proxy-helper Paolo Bonzini
2024-09-11 12:57 ` Christian Schoenebeck via
2024-09-11 15:31 ` Paolo Bonzini
2024-09-11 12:33 ` [PULL 17/17] minikconf: print error entirely on stderr Paolo Bonzini
2024-09-12 15:17 ` [PULL 00/17] Misc patches for 2024-09-11 Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240911123342.339482-13-pbonzini@redhat.com \
--to=pbonzini@redhat.com \
--cc=farosas@suse.de \
--cc=fvogt@suse.de \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.