All of lore.kernel.org
 help / color / mirror / Atom feed
From: Kim Phillips <kim.phillips@amd.com>
To: <linux-kernel@vger.kernel.org>, <x86@kernel.org>,
	<linux-coco@lists.linux.dev>, <kvm@vger.kernel.org>
Cc: Sean Christopherson <seanjc@google.com>,
	Paolo Bonzini <pbonzini@redhat.com>,
	K Prateek Nayak <kprateek.nayak@amd.com>,
	"Nikunj A Dadhania" <nikunj@amd.com>,
	Tom Lendacky <thomas.lendacky@amd.com>,
	"Michael Roth" <michael.roth@amd.com>,
	Borislav Petkov <borislav.petkov@amd.com>,
	Borislav Petkov <bp@alien8.de>, Naveen Rao <naveen.rao@amd.com>,
	David Kaplan <david.kaplan@amd.com>,
	Pawan Gupta <pawan.kumar.gupta@linux.intel.com>,
	"Dave Hansen" <dave.hansen@linux.intel.com>,
	Kim Phillips <kim.phillips@amd.com>,
	Nathan Fontenot <nathan.fontenot@amd.com>
Subject: [PATCH v5 0/8] Add SEV-SNP BTB Isolation and IBPB-on-Entry guest features
Date: Wed, 26 Aug 2026 17:35:02 -0500	[thread overview]
Message-ID: <20260826223510.3669875-1-kim.phillips@amd.com> (raw)

This series advertises two SEV-SNP guest-selectable side-channel
protections through KVM's vmsa_features ABI -- BTB Isolation
(SEV_FEATURES bit 7) and IBPB-on-Entry (SEV_FEATURES bit 21) -- along
with SVM_SEV_FEAT_SNP_ACTIVE, and fixes two x86 mitigation-selection
bugs that stand in the way.

The cpu/bugs patches come first because they are prerequisites, not
drive-by cleanups:

  - Patch 1 fixes spectre_v2=eibrs silently selecting retpolines instead
    of AutoIBRS on SNP hosts.  Commit acaa4b5c4c85 ("x86/speculation: Do
    not enable Automatic IBRS if SEV-SNP is enabled") suppressed AutoIBRS
    by never setting X86_FEATURE_IBRS_ENHANCED, which also disabled the
    explicit spectre_v2=eibrs request.  Set the feature bit and move the
    SNP-prefers-retpoline decision into the default/auto case, where it
    belongs.

  - Patch 2 allows spectre_v2=ibrs on non-Intel vendors.  BTB Isolation
    uses legacy SPEC_CTRL.IBRS toggling to optimize the SNP VM
    exit-to-re-entry path, so AMD needs to be able to select it.  It also
    makes EFER.AUTOIBRS explicitly track the selected mitigation, which
    matters across kexec since head_64.S preserves incoming EFER bits.

Patches 3-6 are small width/ABI cleanups and the SNP_ACTIVE and
SNP-only-feature-mask groundwork, and patches 7-8 add IBPB-on-Entry and
BTB Isolation themselves.

Note that BTB Isolation is advertised unconditionally on SNP-capable
parts.  That is deliberate: the APM defines it as architecturally
present on every SEV-SNP-capable processor, so unlike IBPB-on-Entry
there is no host enumeration bit to gate on.  Patch 8 spells this out.

Changes since v4:
  https://lore.kernel.org/all/20260804235611.4053375-1-kim.phillips@amd.com/

 - Patch 1 ("x86/bugs: Allow forcing Automatic IBRS with SNP active
   using spectre_v2=eibrs"): only prefer retpoline over AutoIBRS on SNP
   hosts when CONFIG_MITIGATION_RETPOLINE is actually built in.  This
   folds v4's patch 3 into the same condition and avoids the
   select-then-fall-back ping pong.  Suggested in review:
   https://lore.kernel.org/all/lctyimdlenyb5kvfxarzajs2ggzkwn4yehxu233lojynqwa7ej@wjur3lh6szlr/

 - Patch 2 ("x86/bugs: Allow spectre_v2=ibrs on x86 vendors other than
   Intel"): move the EFER.AUTOIBRS kexec cleanup out of
   spectre_v2_apply_mitigation() and up to the top of
   cpu_select_mitigations(), next to the existing SPEC_CTRL kexec
   cleanup, so stale state is dropped before mitigation selection rather
   than during it.  spectre_v2_apply_mitigation() now only sets the bit,
   which keeps it much closer to its original shape.  Suggested in
   review:
   https://lore.kernel.org/all/ga63o6nf7xebndlo66qqasjx7axpopyph7ilkwhvx3enfaqs4w@r4qfr6eo6kcw/

 - Subject prefix fixes, per review:
   https://lore.kernel.org/all/20260818232204.GBaoTpHK8k7wD9mMk4@fat_crate.local/
   The two x86 patches go from "cpu/bugs:" to "x86/bugs:" to match the
   tip tree convention.  Patch 3 goes from "KVM: SEV:" to "KVM: SVM:",
   since it only touches arch/x86/include/asm/svm.h.

 - Tag cleanup, per review:
   https://lore.kernel.org/all/20260818232204.GBaoTpHK8k7wD9mMk4@fat_crate.local/
   Dropped Cc: stable@kernel.org from both x86/bugs patches.  Patch 2
   drops its Fixes: too -- it enables spectre_v2=ibrs on a vendor that
   never had a use for the option rather than fixing a bug anyone is
   hitting, so neither tag was right.  Patch 1 drops the kernel test
   robot Reported-by:/Closes: pair; that report was against an earlier
   posting of this patch rather than against upstream, so there was
   nothing there for it to close.  The part of patch 1 that is genuinely
   -stable material -- an SNP host with CONFIG_MITIGATION_RETPOLINE=n
   booting with Spectre v2 unmitigated -- will be sent separately as a
   minimal backport once this lands.

 - Dropped v4's patch 3 ("cpu/bugs: Fall back to AutoIBRS when retpoline
   unavailable on SNP CPUs").  Its fallback is now subsumed by the
   CONFIG_MITIGATION_RETPOLINE test above.

 - Dropped v4's patch 1 ("x86/bugs: Only log missing retpoline when it's
   actually the missing mitigation").  After the rework above this
   series no longer needs it, but it still fixes a real spurious
   "no mitigation available!" on Intel + RETBleed with
   CONFIG_MITIGATION_IBRS_ENTRY=y, CONFIG_MITIGATION_RETPOLINE=n and
   spectre_v2=auto, where spectre_v2_update_mitigation() afterwards
   promotes SPECTRE_V2_NONE to SPECTRE_V2_IBRS.  Being posted separately
   as a standalone fix:
   https://lore.kernel.org/lkml/20260826222228.3668418-1-kim.phillips@amd.com/

 - Added Tom's Reviewed-by to patch 8

Kim Phillips (8):
  x86/bugs: Allow forcing Automatic IBRS with SNP active using
    spectre_v2=eibrs
  x86/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel
  KVM: SVM: Define SVM_SEV_FEAT_* flags using BIT_ULL()
  KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition
  KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a
    single mask
  KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE
  KVM: SEV: Add support for IBPB-on-Entry
  KVM: SEV: Add support for SNP BTB Isolation

 arch/x86/Kconfig                              |  7 ++-
 arch/x86/include/asm/cpufeatures.h            |  1 +
 arch/x86/include/asm/svm.h                    | 17 ++++--
 arch/x86/kernel/cpu/bugs.c                    | 59 ++++++++++++++-----
 arch/x86/kernel/cpu/common.c                  |  6 +-
 arch/x86/kvm/svm/sev.c                        | 21 ++++++-
 tools/arch/x86/include/asm/cpufeatures.h      |  1 +
 .../selftests/kvm/x86/sev_init2_tests.c       | 20 +++++--
 8 files changed, 96 insertions(+), 36 deletions(-)


base-commit: ec8477a492cb24f2c334847c8734ca56c7ffdd29
-- 
2.43.0


             reply	other threads:[~2026-08-26 22:35 UTC|newest]

Thread overview: 22+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26 22:35 Kim Phillips [this message]
2026-08-26 22:35 ` [PATCH v5 1/8] x86/bugs: Allow forcing Automatic IBRS with SNP active using spectre_v2=eibrs Kim Phillips
2026-08-27  4:32   ` Pawan Gupta
2026-09-03  4:03   ` Borislav Petkov
2026-09-18 23:00     ` Kim Phillips
2026-09-24  1:45       ` Borislav Petkov
2026-09-24 18:45         ` Kim Phillips
2026-09-25 16:47           ` Borislav Petkov
2026-09-26  2:14             ` Kim Phillips
2026-08-26 22:35 ` [PATCH v5 2/8] x86/bugs: Allow spectre_v2=ibrs on x86 vendors other than Intel Kim Phillips
2026-08-27  4:33   ` Pawan Gupta
2026-09-09 21:01   ` Borislav Petkov
2026-09-18 23:01     ` Kim Phillips
2026-09-30  3:06       ` Borislav Petkov
2026-09-30 19:50         ` Kim Phillips
2026-10-01  0:12           ` Borislav Petkov
2026-08-26 22:35 ` [PATCH v5 3/8] KVM: SVM: Define SVM_SEV_FEAT_* flags using BIT_ULL() Kim Phillips
2026-08-26 22:35 ` [PATCH v5 4/8] KVM: selftests: sev_init2: Use BIT_ULL for VMSA feature bit definition Kim Phillips
2026-08-26 22:35 ` [PATCH v5 5/8] KVM: SEV: Disallow setting SNP-only features for non-SNP guests via a single mask Kim Phillips
2026-08-26 22:35 ` [PATCH v5 6/8] KVM: SEV: Advertise SVM_SEV_FEAT_SNP_ACTIVE Kim Phillips
2026-08-26 22:35 ` [PATCH v5 7/8] KVM: SEV: Add support for IBPB-on-Entry Kim Phillips
2026-08-26 22:35 ` [PATCH v5 8/8] KVM: SEV: Add support for SNP BTB Isolation Kim Phillips

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260826223510.3669875-1-kim.phillips@amd.com \
    --to=kim.phillips@amd.com \
    --cc=borislav.petkov@amd.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=david.kaplan@amd.com \
    --cc=kprateek.nayak@amd.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=michael.roth@amd.com \
    --cc=nathan.fontenot@amd.com \
    --cc=naveen.rao@amd.com \
    --cc=nikunj@amd.com \
    --cc=pawan.kumar.gupta@linux.intel.com \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    --cc=thomas.lendacky@amd.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.