All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kishen Maloor <kishen.maloor@intel.com>
To: qemu-devel@nongnu.org
Cc: pbonzini@redhat.com, zhao1.liu@intel.com, kvm@vger.kernel.org,
	sohil.mehta@intel.com, xiaoyao.li@intel.com,
	binbin.wu@linux.intel.com, farrah.chen@intel.com,
	kishen.maloor@intel.com
Subject: [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration
Date: Tue, 25 Aug 2026 20:57:30 -0700	[thread overview]
Message-ID: <20260826035734.114685-2-kishen.maloor@intel.com> (raw)
In-Reply-To: <20260826035734.114685-1-kishen.maloor@intel.com>

From: Isaku Yamahata <isaku.yamahata@intel.com>

Linear Address Space Separation (LASS) is a security feature that
prevents a class of side-channel attacks relying on speculative
accesses across the user/kernel boundary. Paging, along with SMEP
and SMAP, already provides mode-based access protection, but
enforcing it requires a page walk whose timing can leak the
layout of kernel memory.

LASS applies the equivalent protections during linear-address
pre-processing, before any page walk. Given the usual partitioning of
the linear address space into a user half (bit 63 clear) and a
supervisor half (bit 63 set), an access targeting the opposite half is
rejected on the basis of bit 63 alone, raising a #GP. LASS is enabled
via CR4.LASS[bit 27] and applies only in IA-32e mode.

Feature bit:
  CPUID.(EAX=7,ECX=1):EAX[6]

A CPUID_7_1_EAX_LASS macro was previously added in commit 31df29c532a9
("i386/tdx: Add supported CPUID bits related to TD Attributes"), but the
bit was left unnamed in feature_word_info[FEAT_7_1_EAX]. Add the "lass"
feature name to expose it via -cpu host, -cpu max, or an explicit +lass.

Exposing LASS to a guest also requires KVM support: KVM must validate
the CPUID bit and CR4.LASS, and enforce LASS violations in its
instruction emulator.

LASS is not implemented in TCG, so the bit is not added to
TCG_7_1_EAX_FEATURES.

More details can be found in the Intel 64 and IA-32 Architectures
Software Developer's Manual, Volume 3A, Section 4.3,
"Linear-Address-Space Separation (LASS)".

Signed-off-by: Isaku Yamahata <isaku.yamahata@intel.com>
[kishen: rewrote commit message, rebased]
Signed-off-by: Kishen Maloor <kishen.maloor@intel.com>
---
KVM support for LASS is currently under review:
https://lore.kernel.org/kvm/20260806011536.4172258-1-sohil.mehta@intel.com/

 target/i386/cpu.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/target/i386/cpu.c b/target/i386/cpu.c
index 5805d33ab9..5496e9475b 100644
--- a/target/i386/cpu.c
+++ b/target/i386/cpu.c
@@ -1243,7 +1243,7 @@ FeatureWordInfo feature_word_info[FEATURE_WORDS] = {
         .type = CPUID_FEATURE_WORD,
         .feat_names = {
             "sha512", "sm3", "sm4", NULL,
-            "avx-vnni", "avx512-bf16", NULL, "cmpccxadd",
+            "avx-vnni", "avx512-bf16", "lass", "cmpccxadd",
             NULL, NULL, "fzrm", "fsrs",
             "fsrc", NULL, NULL, NULL,
             NULL, "fred", "lkgs", "wrmsrns",
-- 
2.47.1



  reply	other threads:[~2026-08-26  3:36 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26  3:57 [PATCH 0/5] target/i386: Add support for LASS Kishen Maloor
2026-08-26  3:57 ` Kishen Maloor [this message]
2026-09-02 10:14   ` [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration Zhao Liu
2026-08-26  3:57 ` [PATCH 2/5] target/i386: Add LASS support in CR4 Kishen Maloor
2026-09-02 10:16   ` Zhao Liu
2026-08-26  3:57 ` [PATCH 3/5] target/i386: Introduce DiamondRapids-v3 to enable LASS Kishen Maloor
2026-09-02 10:16   ` Zhao Liu
2026-08-26  3:57 ` [PATCH 4/5] target/i386: Introduce SierraForest-v7 " Kishen Maloor
2026-09-02 10:17   ` Zhao Liu
2026-08-26  3:57 ` [PATCH 5/5] target/i386: Introduce ClearwaterForest-v5 " Kishen Maloor
2026-09-02 10:17   ` Zhao Liu
2026-08-27  3:07 ` [PATCH 0/5] target/i386: Add support for LASS Chen, Farrah
2026-09-01 16:08 ` Sohil Mehta
2026-09-02  2:40 ` Binbin Wu

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260826035734.114685-2-kishen.maloor@intel.com \
    --to=kishen.maloor@intel.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=farrah.chen@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=sohil.mehta@intel.com \
    --cc=xiaoyao.li@intel.com \
    --cc=zhao1.liu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.