All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jan Beulich <jbeulich@suse.com>
To: Abdelkareem Abdelsaamad <abdelkareem.abdelsaamad@citrix.com>
Cc: andrew.cooper3@citrix.com, roger@xenproject.org,
	jason.andryuk@amd.com, teddy.astie@vates.tech,
	xen-devel@lists.xenproject.org
Subject: Re: [PATCH v4] x86/nSVM: Check injected event consistency
Date: Tue, 22 Sep 2026 08:17:03 +0200	[thread overview]
Message-ID: <2be442bd-6f1c-4790-ba57-a98c481ab07f@suse.com> (raw)
In-Reply-To: <20260921170757.3244601-1-abdelkareem.abdelsaamad@citrix.com>

On 21.09.2026 19:07, Abdelkareem Abdelsaamad wrote:
> On 07.09.2026 08:36, Jan Beulich wrote:
>> On 06.09.2026 15:22, Abdelkareem Abdelsaamad wrote:
>>>>>> @@ -320,6 +320,44 @@ void svm_vmcb_dump(const char *from, const struct vmcb_struct *vmcb)
>>>>>>      svm_dump_sel("  TR", &vmcb->tr);
>>>>>>  }
>>>>>>  
>>>>>> +static bool is_valid_injected_exception_vector(const struct vmcb_struct *vmcb,
>>>>>> +    uint8_t vmcb_injected_vector)
>>>>>> +{
>>>>>> +    switch ( vmcb_injected_vector )
>>>>>> +    {
>>>>>> +    case X86_EXC_DE:
>>>>>> +    case X86_EXC_DB:
>>>>>> +    case X86_EXC_BP:
>>>>>> +    case X86_EXC_UD:
>>>>>> +    case X86_EXC_NM:
>>>>>> +    case X86_EXC_DF:
>>>>>> +    case X86_EXC_TS:
>>>>>> +    case X86_EXC_NP:
>>>>>> +    case X86_EXC_SS:
>>>>>> +    case X86_EXC_GP:
>>>>>> +    case X86_EXC_PF:
>>>>>> +    case X86_EXC_MF:
>>>>>> +    case X86_EXC_AC:
>>>>>> +    case X86_EXC_MC:
>>>>>
>>>>> Is #MC valid to inject without CR4.MCE set?
>>>> The testing I performed (see previous comment) does not show that set CR4.MCE
>>>> is required for the valid injection.
>>>>>> +    case X86_EXC_XM:
>>>>>
>>>>> As before: Doesn't #XM (AMD: #XF) require CR4.OSXMMEXCPT to be set?
>>>> The testing I performed (see previous comment) does not show that set CR4.MCE
>>>> is required for the valid injection.
>>> I meant ..does not show that set CR4.OSXMMEXCPT is required.
>>>>>
>>>>> Again as before: Is #SX really permitted without any constraints? You did
>>>>> reply to both comments on v3, but that outcome isn't reflected here. The
>>>>> more that what you said there could equally apply ...
>>>> The testing I performed (see the first comment) does not show that set CR4.MCE
>>>> is required for the valid injection.
>>> I meant ..does not show that any CR4 bit is required.
>>
>> And I didn't mention CR4. I intentionally said "without any constraints".
> I believe the Security Exception (Vector 30) is architecturally valid on AMD
> Naples (EPYC 7001) and Rome (EPYC 7002) platforms. Event injection of vector 30
> then does not require specific guest enablement I am aware of.
IOW another one of those cases where an unaware guest can be sent an exception
which may end up killing that guest? Hmm... Not your fault of course, yet still
problematic. May want making explicit in the description (maybe even a code
comment) then, I think.

Jan


  reply	other threads:[~2026-09-22  6:17 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-23 16:11 [PATCH v4] x86/nSVM: Check injected event consistency Abdelkareem Abdelsaamad
2026-08-26 13:33 ` Jan Beulich
2026-09-06 13:11   ` Abdelkareem Abdelsaamad
2026-09-06 13:22     ` Abdelkareem Abdelsaamad
2026-09-07  6:36       ` Jan Beulich
2026-09-21 17:07         ` Abdelkareem Abdelsaamad
2026-09-22  6:17           ` Jan Beulich [this message]
2026-09-07  6:50     ` Jan Beulich
     [not found] <v4-586da975-bd71-4305-a17e-cd5ba35995a4@suse.com>
2026-09-21 15:50 ` Abdelkareem Abdelsaamad
2026-09-21 16:01   ` Jan Beulich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2be442bd-6f1c-4790-ba57-a98c481ab07f@suse.com \
    --to=jbeulich@suse.com \
    --cc=abdelkareem.abdelsaamad@citrix.com \
    --cc=andrew.cooper3@citrix.com \
    --cc=jason.andryuk@amd.com \
    --cc=roger@xenproject.org \
    --cc=teddy.astie@vates.tech \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.