From: Juergen Gross <jgross@suse.com>
To: Dave Hansen <dave.hansen@intel.com>,
"Kirill A. Shutemov" <kirill.shutemov@linux.intel.com>
Cc: linux-kernel@vger.kernel.org, x86@kernel.org,
linux-coco@lists.linux.dev,
Dave Hansen <dave.hansen@linux.intel.com>,
Thomas Gleixner <tglx@linutronix.de>,
Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
"H. Peter Anvin" <hpa@zytor.com>
Subject: Re: [PATCH] x86/kvm/tdx: Save %rbp in TDX_MODULE_CALL
Date: Fri, 17 May 2024 17:48:11 +0200 [thread overview]
Message-ID: <86ca805d-7ed7-47dd-8228-5e19fbade53f@suse.com> (raw)
In-Reply-To: <6df4fb48-9947-46ec-af5a-66fa06d6a83b@intel.com>
[-- Attachment #1.1.1: Type: text/plain, Size: 1953 bytes --]
On 17.05.24 17:43, Dave Hansen wrote:
> On 5/17/24 08:27, Jürgen Groß wrote:
>> On 17.05.24 17:16, Dave Hansen wrote:
>>> On 5/17/24 07:44, Juergen Gross wrote:
>>>> Just another data point: Before using this machine I was testing on
>>>> another one with older firmware. That one really didn't support
>>>> NOM_RBP_MOD
>>>> and I needed to build the kernel with CONFIG_FRAME_POINTER enabled to
>>>> get
>>>> past the check you are mentioning above.
>>>
>>> For all intents and purposes, the modules that intentionally clobber RBP
>>> don't support Linux. If buggy modules are accidentally clobbering RBP,
>>> we can debate how much the kernel should bend over to accommodate them,
>>> but my preference would be to ignore them.
>>>
>>> I'd much rather put a deny list in the kernel than try to tolerate RBP
>>> clobbering universally.
>>
>> Would you be fine with adding a new X86_FEATURE (or BUG?) allowing
>> to switch RBP save/restore via ALTERNATIVE, controlled by a command
>> line option?
>>
>> Or maybe by adding a new CONFIG_TDX_MODULE_CAN_CLOBBER_RBP (probably
>> using a shorter name) option?
>
> As a last resort maybe.
>
>> TBH I'm slightly puzzled that the firmware I'm using could make it
>> outside Intel. I'm fearing this might happen again.
>
> You're puzzled that the firmware is either old buggy or both? Huh.
>
> Intel ships all kinds of crazy pre-production stuff as development
> platforms. Let's make sure we know what you've got before we go tearing
> up mainline for it.
>
> Because if the options are:
>
> 1. Maintain code in mainline until the day I die^Wretire
>
> or
>
> 2. Get Jürgen a BIOS update so he stops sending patches
>
> .. it's kinda an easy choice. ;)
>
:-)
Is the BIOS version printed at boot enough to see what I have?
[ 0.000000] DMI: Intel Corporation D50DNP/D50DNP, BIOS
SE5C7411.86B.9535.D04.2312270518 12/27/2023
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3743 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
next prev parent reply other threads:[~2024-05-17 15:48 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-05-17 12:14 [PATCH] x86/kvm/tdx: Save %rbp in TDX_MODULE_CALL Juergen Gross
2024-05-17 13:55 ` Kirill A. Shutemov
2024-05-17 14:08 ` Juergen Gross
2024-05-17 14:39 ` Kirill A. Shutemov
2024-05-17 14:41 ` Kirill A. Shutemov
2024-05-17 14:44 ` Juergen Gross
2024-05-17 15:16 ` Dave Hansen
2024-05-17 15:27 ` Jürgen Groß
2024-05-17 15:43 ` Dave Hansen
2024-05-17 15:48 ` Juergen Gross [this message]
2024-05-17 15:52 ` Dave Hansen
2024-05-17 15:58 ` Juergen Gross
2024-05-17 16:48 ` Dave Hansen
2024-05-20 11:54 ` Huang, Kai
2024-05-23 5:56 ` Jürgen Groß
2024-05-23 10:30 ` Huang, Kai
2024-05-23 12:26 ` Huang, Kai
2024-05-23 12:43 ` Jürgen Groß
2024-05-23 22:34 ` Huang, Kai
2024-05-23 23:28 ` Huang, Kai
2024-05-24 5:46 ` Jürgen Groß
2024-05-17 16:12 ` Sean Christopherson
2024-05-17 16:34 ` Dave Hansen
2024-05-17 17:01 ` Kirill A. Shutemov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=86ca805d-7ed7-47dd-8228-5e19fbade53f@suse.com \
--to=jgross@suse.com \
--cc=bp@alien8.de \
--cc=dave.hansen@intel.com \
--cc=dave.hansen@linux.intel.com \
--cc=hpa@zytor.com \
--cc=kirill.shutemov@linux.intel.com \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.