All of lore.kernel.org
 help / color / mirror / Atom feed
From: Marc Zyngier <maz@kernel.org>
To: James Clark <james.clark@arm.com>
Cc: Oliver Upton <oliver.upton@linux.dev>,
	coresight@lists.linaro.org, linux-arm-kernel@lists.infradead.org,
	kvmarm@lists.linux.dev, broonie@kernel.org,
	suzuki.poulose@arm.com, acme@kernel.org,
	James Morse <james.morse@arm.com>,
	Zenghui Yu <yuzenghui@huawei.com>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Will Deacon <will@kernel.org>, Mike Leach <mike.leach@linaro.org>,
	Leo Yan <leo.yan@linaro.org>,
	Alexander Shishkin <alexander.shishkin@linux.intel.com>,
	Anshuman Khandual <anshuman.khandual@arm.com>,
	Rob Herring <robh@kernel.org>,
	Miguel Luis <miguel.luis@oracle.com>,
	Jintack Lim <jintack.lim@linaro.org>,
	Ard Biesheuvel <ardb@kernel.org>,
	Mark Rutland <mark.rutland@arm.com>,
	Arnd Bergmann <arnd@arndb.de>,
	Vincent Donnefort <vdonnefort@google.com>,
	Kristina Martsenko <kristina.martsenko@arm.com>,
	Fuad Tabba <tabba@google.com>, Joey Gouly <joey.gouly@arm.com>,
	Akihiko Odaki <akihiko.odaki@daynix.com>,
	Jing Zhang <jingzhangos@google.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v4 2/7] arm64: KVM: Use shared area to pass PMU event state to hypervisor
Date: Mon, 05 Feb 2024 15:50:12 +0000	[thread overview]
Message-ID: <861q9q7vwr.wl-maz@kernel.org> (raw)
In-Reply-To: <c773393c-221e-edd1-00b7-0ce6a2481c15@arm.com>

On Mon, 05 Feb 2024 15:37:34 +0000,
James Clark <james.clark@arm.com> wrote:
> 
> 
> 
> On 05/02/2024 14:52, Marc Zyngier wrote:
> > On Mon, 05 Feb 2024 14:17:10 +0000,
> > James Clark <james.clark@arm.com> wrote:
> >>
> >> On 05/02/2024 13:21, Oliver Upton wrote:
> >>> On Mon, Feb 05, 2024 at 01:15:36PM +0000, Marc Zyngier wrote:
> >>>> On Mon, 05 Feb 2024 13:04:51 +0000,
> >>>> Oliver Upton <oliver.upton@linux.dev> wrote:
> >>>>>
> >>>>> Unless someone has strong opinions about making this work in protected
> >>>>> mode, I am happy to see tracing support limited to the 'normal' nVHE
> >>>>> configuration. The protected feature as a whole is just baggage until
> >>>>> upstream support is completed.
> >>>>
> >>>> Limiting tracing to non-protected mode is a must IMO. Allowing tracing
> >>>> when pKVM is enabled is a sure way to expose secrets that should
> >>>> stay... secret. The only exception I can think of is when
> >>>> CONFIG_NVHE_EL2_DEBUG is enabled, at which point all bets are off.
> >>>
> >>> Zero argument there :) I left off the "and PMU" part of what I was
> >>> saying, because that was a feature that semi-worked in protected mode
> >>> before VM/VCPU shadowing support landed.
> >>>
> >>
> >> In that case I can hide all this behind CONFIG_NVHE_EL2_DEBUG for pKVM.
> >> This will also have the effect of disabling PMU again for pKVM because I
> >> moved that into this new shared area.
> > 
> > I'm not sure what you have in mind, but dropping PMU support for
> > non-protected guests when protected-mode is enabled is not an
> > acceptable outcome.
> > 
> > Hiding the trace behind a debug option is fine as this is a global
> > setting that has no userspace impact, but impacting guests isn't.
> > 
> > 	M.
> > 
> 
> Hmmm in that case if there's currently no way to distinguish between
> normal VMs and pVMs in protected-mode then what I was thinking of
> probably won't work.

Have you looked? kvm_vm_is_protected() has been in for a while, even
if that's not a lot. The upcoming code will flesh this helper out,

	M.

-- 
Without deviation from the norm, progress is not possible.

WARNING: multiple messages have this Message-ID (diff)
From: Marc Zyngier <maz@kernel.org>
To: James Clark <james.clark@arm.com>
Cc: Oliver Upton <oliver.upton@linux.dev>,
	coresight@lists.linaro.org, linux-arm-kernel@lists.infradead.org,
	kvmarm@lists.linux.dev, broonie@kernel.org,
	suzuki.poulose@arm.com, acme@kernel.org,
	James Morse <james.morse@arm.com>,
	Zenghui Yu <yuzenghui@huawei.com>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Will Deacon <will@kernel.org>, Mike Leach <mike.leach@linaro.org>,
	Leo Yan <leo.yan@linaro.org>,
	Alexander Shishkin <alexander.shishkin@linux.intel.com>,
	Anshuman Khandual <anshuman.khandual@arm.com>,
	Rob Herring <robh@kernel.org>,
	Miguel Luis <miguel.luis@oracle.com>,
	Jintack Lim <jintack.lim@linaro.org>,
	Ard Biesheuvel <ardb@kernel.org>,
	Mark Rutland <mark.rutland@arm.com>,
	Arnd Bergmann <arnd@arndb.de>,
	Vincent Donnefort <vdonnefort@google.com>,
	Kristina Martsenko <kristina.martsenko@arm.com>,
	Fuad Tabba <tabba@google.com>, Joey Gouly <joey.gouly@arm.com>,
	Akihiko Odaki <akihiko.odaki@daynix.com>,
	Jing Zhang <jingzhangos@google.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH v4 2/7] arm64: KVM: Use shared area to pass PMU event state to hypervisor
Date: Mon, 05 Feb 2024 15:50:12 +0000	[thread overview]
Message-ID: <861q9q7vwr.wl-maz@kernel.org> (raw)
In-Reply-To: <c773393c-221e-edd1-00b7-0ce6a2481c15@arm.com>

On Mon, 05 Feb 2024 15:37:34 +0000,
James Clark <james.clark@arm.com> wrote:
> 
> 
> 
> On 05/02/2024 14:52, Marc Zyngier wrote:
> > On Mon, 05 Feb 2024 14:17:10 +0000,
> > James Clark <james.clark@arm.com> wrote:
> >>
> >> On 05/02/2024 13:21, Oliver Upton wrote:
> >>> On Mon, Feb 05, 2024 at 01:15:36PM +0000, Marc Zyngier wrote:
> >>>> On Mon, 05 Feb 2024 13:04:51 +0000,
> >>>> Oliver Upton <oliver.upton@linux.dev> wrote:
> >>>>>
> >>>>> Unless someone has strong opinions about making this work in protected
> >>>>> mode, I am happy to see tracing support limited to the 'normal' nVHE
> >>>>> configuration. The protected feature as a whole is just baggage until
> >>>>> upstream support is completed.
> >>>>
> >>>> Limiting tracing to non-protected mode is a must IMO. Allowing tracing
> >>>> when pKVM is enabled is a sure way to expose secrets that should
> >>>> stay... secret. The only exception I can think of is when
> >>>> CONFIG_NVHE_EL2_DEBUG is enabled, at which point all bets are off.
> >>>
> >>> Zero argument there :) I left off the "and PMU" part of what I was
> >>> saying, because that was a feature that semi-worked in protected mode
> >>> before VM/VCPU shadowing support landed.
> >>>
> >>
> >> In that case I can hide all this behind CONFIG_NVHE_EL2_DEBUG for pKVM.
> >> This will also have the effect of disabling PMU again for pKVM because I
> >> moved that into this new shared area.
> > 
> > I'm not sure what you have in mind, but dropping PMU support for
> > non-protected guests when protected-mode is enabled is not an
> > acceptable outcome.
> > 
> > Hiding the trace behind a debug option is fine as this is a global
> > setting that has no userspace impact, but impacting guests isn't.
> > 
> > 	M.
> > 
> 
> Hmmm in that case if there's currently no way to distinguish between
> normal VMs and pVMs in protected-mode then what I was thinking of
> probably won't work.

Have you looked? kvm_vm_is_protected() has been in for a while, even
if that's not a lot. The upcoming code will flesh this helper out,

	M.

-- 
Without deviation from the norm, progress is not possible.

_______________________________________________
linux-arm-kernel mailing list
linux-arm-kernel@lists.infradead.org
http://lists.infradead.org/mailman/listinfo/linux-arm-kernel

  reply	other threads:[~2024-02-05 15:50 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-01-04 16:27 [PATCH v4 0/7] kvm/coresight: Support exclude guest and exclude host James Clark
2024-01-04 16:27 ` James Clark
2024-01-04 16:27 ` [PATCH v4 1/7] arm64: KVM: Fix renamed function in comment James Clark
2024-01-04 16:27   ` James Clark
2024-01-04 16:58   ` Suzuki K Poulose
2024-01-04 16:58     ` Suzuki K Poulose
2024-01-04 16:27 ` [PATCH v4 2/7] arm64: KVM: Use shared area to pass PMU event state to hypervisor James Clark
2024-01-04 16:27   ` James Clark
2024-01-05  9:40   ` Suzuki K Poulose
2024-01-05  9:40     ` Suzuki K Poulose
2024-02-01 16:14   ` James Clark
2024-02-01 16:14     ` James Clark
2024-02-02 22:00   ` Oliver Upton
2024-02-02 22:00     ` Oliver Upton
2024-02-05 12:16     ` James Clark
2024-02-05 12:16       ` James Clark
2024-02-05 13:04       ` Oliver Upton
2024-02-05 13:04         ` Oliver Upton
2024-02-05 13:15         ` Marc Zyngier
2024-02-05 13:15           ` Marc Zyngier
2024-02-05 13:21           ` Oliver Upton
2024-02-05 13:21             ` Oliver Upton
2024-02-05 14:16             ` Marc Zyngier
2024-02-05 14:16               ` Marc Zyngier
2024-02-05 14:17             ` James Clark
2024-02-05 14:17               ` James Clark
2024-02-05 14:52               ` Marc Zyngier
2024-02-05 14:52                 ` Marc Zyngier
2024-02-05 15:37                 ` James Clark
2024-02-05 15:37                   ` James Clark
2024-02-05 15:50                   ` Marc Zyngier [this message]
2024-02-05 15:50                     ` Marc Zyngier
2024-02-05 16:38                     ` Oliver Upton
2024-02-05 16:38                       ` Oliver Upton
2024-01-04 16:27 ` [PATCH v4 3/7] arm64/sysreg/tools: Move TRFCR definitions to sysreg James Clark
2024-01-04 16:27   ` James Clark
2024-01-05  9:18   ` Suzuki K Poulose
2024-01-05  9:18     ` Suzuki K Poulose
2024-01-05  9:59     ` James Clark
2024-01-05  9:59       ` James Clark
2024-01-04 16:27 ` [PATCH v4 4/7] arm64: KVM: Add iflag for FEAT_TRF James Clark
2024-01-04 16:27   ` James Clark
2024-01-04 16:27 ` [PATCH v4 5/7] arm64: KVM: Add interface to set guest value for TRFCR register James Clark
2024-01-04 16:27   ` James Clark
2024-01-05  9:20   ` Suzuki K Poulose
2024-01-05  9:20     ` Suzuki K Poulose
2024-01-04 16:27 ` [PATCH v4 6/7] arm64: KVM: Write TRFCR value on guest switch with nVHE James Clark
2024-01-04 16:27   ` James Clark
2024-01-05  9:50   ` Suzuki K Poulose
2024-01-05  9:50     ` Suzuki K Poulose
2024-01-05 10:05     ` James Clark
2024-01-05 10:05       ` James Clark
2024-01-04 16:27 ` [PATCH v4 7/7] coresight: Pass guest TRFCR value to KVM James Clark
2024-01-04 16:27   ` James Clark
2024-01-05  9:55   ` Suzuki K Poulose
2024-01-05  9:55     ` Suzuki K Poulose

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=861q9q7vwr.wl-maz@kernel.org \
    --to=maz@kernel.org \
    --cc=acme@kernel.org \
    --cc=akihiko.odaki@daynix.com \
    --cc=alexander.shishkin@linux.intel.com \
    --cc=anshuman.khandual@arm.com \
    --cc=ardb@kernel.org \
    --cc=arnd@arndb.de \
    --cc=broonie@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=coresight@lists.linaro.org \
    --cc=james.clark@arm.com \
    --cc=james.morse@arm.com \
    --cc=jingzhangos@google.com \
    --cc=jintack.lim@linaro.org \
    --cc=joey.gouly@arm.com \
    --cc=kristina.martsenko@arm.com \
    --cc=kvmarm@lists.linux.dev \
    --cc=leo.yan@linaro.org \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mark.rutland@arm.com \
    --cc=miguel.luis@oracle.com \
    --cc=mike.leach@linaro.org \
    --cc=oliver.upton@linux.dev \
    --cc=robh@kernel.org \
    --cc=suzuki.poulose@arm.com \
    --cc=tabba@google.com \
    --cc=vdonnefort@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.