From: Kim Phillips <kim.phillips@amd.com>
To: <linux-kernel@vger.kernel.org>, <kvm@vger.kernel.org>,
<linux-coco@lists.linux.dev>, <x86@kernel.org>
Cc: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>,
K Prateek Nayak <kprateek.nayak@amd.com>,
"Nikunj A Dadhania" <nikunj@amd.com>,
Tom Lendacky <thomas.lendacky@amd.com>,
"Michael Roth" <michael.roth@amd.com>,
Borislav Petkov <borislav.petkov@amd.com>,
Borislav Petkov <bp@alien8.de>, Naveen Rao <naveen.rao@amd.com>,
David Kaplan <david.kaplan@amd.com>,
Pawan Gupta <pawan.kumar.gupta@linux.intel.com>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
Kim Phillips <kim.phillips@amd.com>
Subject: [PATCH v4 00/10] KVM: SEV: Add support for IBPB-on-Entry and BTB Isolation
Date: Tue, 4 Aug 2026 18:56:01 -0500 [thread overview]
Message-ID: <20260804235611.4053375-1-kim.phillips@amd.com> (raw)
IBPB-on-Entry and BTB Isolation are supplemental Spectre V2 mitigations
available to SNP guests.
Patch 1 fixes a misleading no-spectre-v2-mitigation error when the kernel isn't
compiled with retpolines, but a user can still select AutoIBRS, for example.
Patch 2 fixes a longstanding bug where users weren't able
to force Automatic IBRS on SNP enabled machines using spectre_v2=eibrs.
Patch 3 allows AutoIBRS to be used on a kernel compiled without retpolines.
Patch 4 fixes another longstanding bug where users couldn't
select legacy / toggling SPEC_CTRL[IBRS] on AMD systems. Users of
the BTB Isolation feature may use IBRS to mitigate possible
performance degradation caused by BTB Isolation.
Patches 5, 6, 7 and 8 deal with code refactoring as a result of
Sean's review of the v2 IBPB-on-Entry series: an SNP-only feature
mask.
Patch 9 adds support for IBPB-on-Entry.
Patch 10 adds support for BTB Isolation.
Based on tip/master (currently fd0ece3c0826):
https://git.kernel.org/pub/scm/linux/kernel/git/tip/tip
This v4 series now also available here:
https://github.com/AMDESE/linux/tree/btb-isol-latest
Advance qemu bits (to add feature on/off switches) available here:
https://github.com/AMDESE/qemu/tree/btb-isol-latest
Qemu bits will be posted upstream once kernel bits are merged.
They depend on Naveen Rao's "target/i386: SEV: Add support for
enabling VMSA SEV features":
https://lore.kernel.org/qemu-devel/cover.1761648149.git.naveen@kernel.org/
v4:
- Ran Sashiko in a loop until all(?) its comments were addressed (Boris)
v3:
- https://lore.kernel.org/kvm/20260402202558.195005-1-kim.phillips@amd.com/
- Merged IBPB-on-Entry and BTB Isolation into single patchseries
- Addressed comments from Sean Christopherson, Pawan Gupta, kernel test robot
- Simplified unnecessarily complicated logic in spectre_v2=eibrs-with-SNP fix
- Reworded, rebased features on top of new SNP_ONLY_MASK etc. changes
v2:
[IBPB-on-Entry]
- https://lore.kernel.org/kvm/20260203222405.4065706-1-kim.phillips@amd.com/
- Change first patch's title (Nikunj)
- Add reviews-by (Nikunj, Tom)
- Change second patch's description to more generally explain what the patch does (Boris)
- Add new, third patch renaming SNP_FEATURES_PRESENT->SNP_FEATURES_IMPL
[BTB Isolation]
- https://lore.kernel.org/kvm/20260311130611.2201214-1-kim.phillips@amd.com/
- Patch 1/3:
- Address Dave Hansen's comment to adhere to using the IBRS_ENHANCED
Intel feature flag also for AutoIBRS.
v1:
[IBPB-on-Entry] https://lore.kernel.org/kvm/20260126224205.1442196-1-kim.phillips@amd.com/
[BTB Isolation] https://lore.kernel.org/kvm/20260224180157.725159-1-kim.phillips@amd.com/
Kim Phillips (10):
x86/bugs: Only log missing retpoline when it's actually the missing
mitigation
cpu/bugs: Allow forcing Automatic IBRS with SNP active using
spectre_v2=eibrs
cpu/bugs: Fall back to AutoIBRS when retpoline unavailable on SNP CPUs
cpu/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel
KVM: SEV: Define SVM_SEV_FEAT_* flags using BIT_ULL()
KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition
KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a
single mask
KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE
KVM: SEV: Add support for IBPB-on-Entry
KVM: SEV: Add support for SNP BTB Isolation
arch/x86/Kconfig | 7 +-
arch/x86/include/asm/cpufeatures.h | 1 +
arch/x86/include/asm/svm.h | 17 +++--
arch/x86/kernel/cpu/bugs.c | 71 ++++++++++++++-----
arch/x86/kernel/cpu/common.c | 6 +-
arch/x86/kvm/svm/sev.c | 18 ++++-
tools/arch/x86/include/asm/cpufeatures.h | 1 +
.../selftests/kvm/x86/sev_init2_tests.c | 20 ++++--
8 files changed, 103 insertions(+), 38 deletions(-)
base-commit: fd0ece3c082632334ded22076932b302a048c7de
--
2.43.0
next reply other threads:[~2026-08-04 23:56 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 23:56 Kim Phillips [this message]
2026-08-04 23:56 ` [PATCH v4 01/10] x86/bugs: Only log missing retpoline when it's actually the missing mitigation Kim Phillips
2026-08-05 0:44 ` Borislav Petkov
2026-08-05 14:51 ` Kim Phillips
2026-08-05 22:49 ` Borislav Petkov
2026-08-06 20:12 ` Kim Phillips
2026-08-07 5:44 ` Borislav Petkov
2026-08-10 23:21 ` Kim Phillips
2026-08-11 0:48 ` Borislav Petkov
2026-08-04 23:56 ` [PATCH v4 02/10] cpu/bugs: Allow forcing Automatic IBRS with SNP active using spectre_v2=eibrs Kim Phillips
2026-08-04 23:56 ` [PATCH v4 03/10] cpu/bugs: Fall back to AutoIBRS when retpoline unavailable on SNP CPUs Kim Phillips
2026-08-04 23:56 ` [PATCH v4 04/10] cpu/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel Kim Phillips
2026-08-04 23:56 ` [PATCH v4 05/10] KVM: SEV: Define SVM_SEV_FEAT_* flags using BIT_ULL() Kim Phillips
2026-08-04 23:56 ` [PATCH v4 06/10] KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition Kim Phillips
2026-08-04 23:56 ` [PATCH v4 07/10] KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a single mask Kim Phillips
2026-08-04 23:56 ` [PATCH v4 08/10] KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE Kim Phillips
2026-08-04 23:56 ` [PATCH v4 09/10] KVM: SEV: Add support for IBPB-on-Entry Kim Phillips
2026-08-04 23:56 ` [PATCH v4 10/10] KVM: SEV: Add support for SNP BTB Isolation Kim Phillips
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804235611.4053375-1-kim.phillips@amd.com \
--to=kim.phillips@amd.com \
--cc=borislav.petkov@amd.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=david.kaplan@amd.com \
--cc=kprateek.nayak@amd.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=michael.roth@amd.com \
--cc=naveen.rao@amd.com \
--cc=nikunj@amd.com \
--cc=pawan.kumar.gupta@linux.intel.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=thomas.lendacky@amd.com \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.