From: Kishen Maloor <kishen.maloor@intel.com>
To: Sohil Mehta <sohil.mehta@intel.com>, <kvm@vger.kernel.org>,
<x86@kernel.org>
Cc: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
"H . Peter Anvin" <hpa@zytor.com>, Shuah Khan <shuah@kernel.org>,
Binbin Wu <binbin.wu@linux.intel.com>,
Peter Zijlstra <peterz@infradead.org>,
"Chang S . Bae" <chang.seok.bae@intel.com>,
Kai Huang <kai.huang@intel.com>,
Fuad Tabba <fuad.tabba@linux.dev>, Chao Gao <chao.gao@intel.com>,
Yosry Ahmed <yosry@kernel.org>,
Claudio Imbrenda <imbrenda@linux.ibm.com>,
David Matlack <dmatlack@google.com>,
Bala-Vignesh-Reddy <reddybalavignesh9979@gmail.com>,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
<linux-kernel@vger.kernel.org>, <linux-kselftest@vger.kernel.org>
Subject: Re: [PATCH v4 0/7] KVM: x86: Add LASS virtualization support
Date: Tue, 25 Aug 2026 20:50:14 -0700 [thread overview]
Message-ID: <5d04e5d6-6a8f-4bc1-afe9-195310bae909@intel.com> (raw)
In-Reply-To: <20260806011536.4172258-1-sohil.mehta@intel.com>
On 8/5/26 6:15 PM, Sohil Mehta wrote:
> Linear Address Space Separation (LASS) is a security feature that blocks
> accesses across the user/kernel boundary based on bit 63 of the linear
> address alone, before any page walk is performed. Host support for LASS
> has been merged [1][2]. This series adds the KVM virtualization support.
>
I tested this series on Sierra Forest, using the QEMU support linked
below to expose LASS to the guest.
Covered:
- Guest enumeration of LASS and enabling of CR4.LASS.
- User accesses to supervisor addresses on hardware and under
the forced emulation prefix.
- Supervisor accesses to user addresses from a guest kernel module under
the forced emulation prefix: reads and writes, RFLAGS.AC suppression,
SMAP=0 behavior, implicit descriptor-table accesses, and violations at
a branch target.
- Nested VMX: VMCLEAR with a low operand address, taking a #GP at
RFLAGS.AC=0 and completing at AC=1, via get_vmx_mem_address() ->
vmx_is_lass_violation().
Not covered: the TSS I/O bitmap paths in patch 2, and ENCLS.
QEMU changes to expose LASS to guests:
https://lore.kernel.org/all/20260826035734.114685-1-kishen.maloor@intel.com/
Tested-by: Kishen Maloor <kishen.maloor@intel.com>
prev parent reply other threads:[~2026-08-26 3:50 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 1:15 [PATCH v4 0/7] KVM: x86: Add LASS virtualization support Sohil Mehta
2026-08-06 1:15 ` [PATCH v4 1/7] KVM: x86: Add an emulator flag to differentiate branch targets from fetches Sohil Mehta
2026-08-06 1:15 ` [PATCH v4 2/7] KVM: x86: Use linear_read_system() to read the TSS I/O bitmap Sohil Mehta
2026-08-19 3:19 ` Binbin Wu
2026-08-19 5:03 ` Sohil Mehta
2026-08-19 5:21 ` H. Peter Anvin
2026-08-19 5:26 ` Binbin Wu
2026-08-06 1:15 ` [PATCH v4 3/7] KVM: x86: Add LASS violation checks during instruction emulation Sohil Mehta
2026-08-19 5:58 ` Binbin Wu
2026-08-06 1:15 ` [PATCH v4 4/7] KVM: VMX: Implement LASS violation check Sohil Mehta
2026-08-06 1:52 ` sashiko-bot
2026-08-07 1:42 ` Sohil Mehta
2026-08-19 8:49 ` Binbin Wu
2026-08-06 1:15 ` [PATCH v4 5/7] KVM: x86: Virtualize LASS and advertise support to userspace Sohil Mehta
2026-08-19 9:01 ` Binbin Wu
2026-08-06 1:15 ` [PATCH v4 6/7] KVM: selftests: Add coverage for LASS CPUID and CR4 handling Sohil Mehta
2026-08-20 6:01 ` Binbin Wu
2026-08-06 1:15 ` [PATCH v4 7/7] selftests/x86: Add a userspace test for LASS enforcement Sohil Mehta
2026-08-20 6:36 ` Binbin Wu
2026-08-26 3:50 ` Kishen Maloor [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5d04e5d6-6a8f-4bc1-afe9-195310bae909@intel.com \
--to=kishen.maloor@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=chang.seok.bae@intel.com \
--cc=chao.gao@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=dmatlack@google.com \
--cc=fuad.tabba@linux.dev \
--cc=hpa@zytor.com \
--cc=imbrenda@linux.ibm.com \
--cc=kai.huang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=reddybalavignesh9979@gmail.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=shuah@kernel.org \
--cc=sohil.mehta@intel.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
--cc=yosry@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.