From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.8 required=3.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_HELO_NONE,SPF_PASS autolearn=no autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 867F4C433E1 for ; Fri, 19 Jun 2020 12:59:04 +0000 (UTC) Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 5FCCF208C7 for ; Fri, 19 Jun 2020 12:59:04 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 5FCCF208C7 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=cert.pl Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1jmGbT-0006Fy-QS; Fri, 19 Jun 2020 12:58:43 +0000 Received: from all-amaz-eas1.inumbo.com ([34.197.232.57] helo=us1-amaz-eas2.inumbo.com) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1jmGbR-0006Ft-Rb for xen-devel@lists.xenproject.org; Fri, 19 Jun 2020 12:58:41 +0000 X-Inumbo-ID: 9672a1f8-b22c-11ea-bb7c-12813bfff9fa Received: from bagnar.nask.net.pl (unknown [195.187.242.196]) by us1-amaz-eas2.inumbo.com (Halon) with ESMTPS id 9672a1f8-b22c-11ea-bb7c-12813bfff9fa; Fri, 19 Jun 2020 12:58:36 +0000 (UTC) Received: from bagnar.nask.net.pl (unknown [172.16.9.10]) by bagnar.nask.net.pl (Postfix) with ESMTP id 9C973A3285; Fri, 19 Jun 2020 14:58:35 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by bagnar.nask.net.pl (Postfix) with ESMTP id 90327A2EC5; Fri, 19 Jun 2020 14:58:34 +0200 (CEST) Received: from bagnar.nask.net.pl ([127.0.0.1]) by localhost (bagnar.nask.net.pl [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id QE3FnZ5m0wSX; Fri, 19 Jun 2020 14:58:34 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by bagnar.nask.net.pl (Postfix) with ESMTP id D760CA3285; Fri, 19 Jun 2020 14:58:33 +0200 (CEST) X-Virus-Scanned: amavisd-new at bagnar.nask.net.pl Received: from bagnar.nask.net.pl ([127.0.0.1]) by localhost (bagnar.nask.net.pl [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id w1LIOBKjBj8d; Fri, 19 Jun 2020 14:58:33 +0200 (CEST) Received: from belindir.nask.net.pl (belindir-ext.nask.net.pl [195.187.242.210]) by bagnar.nask.net.pl (Postfix) with ESMTP id B1154A2EC5; Fri, 19 Jun 2020 14:58:33 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by belindir.nask.net.pl (Postfix) with ESMTP id 9FA7622599; Fri, 19 Jun 2020 14:58:03 +0200 (CEST) Received: from belindir.nask.net.pl ([127.0.0.1]) by localhost (belindir.nask.net.pl [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id WVRasQth4Gm2; Fri, 19 Jun 2020 14:57:58 +0200 (CEST) Received: from localhost (localhost [127.0.0.1]) by belindir.nask.net.pl (Postfix) with ESMTP id 338EA22537; Fri, 19 Jun 2020 14:57:58 +0200 (CEST) X-Virus-Scanned: amavisd-new at belindir.nask.net.pl Received: from belindir.nask.net.pl ([127.0.0.1]) by localhost (belindir.nask.net.pl [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id HTVcf9ezIggt; Fri, 19 Jun 2020 14:57:58 +0200 (CEST) Received: from belindir.nask.net.pl (belindir.nask.net.pl [172.16.10.10]) by belindir.nask.net.pl (Postfix) with ESMTP id 16B152254F; Fri, 19 Jun 2020 14:57:58 +0200 (CEST) Date: Fri, 19 Jun 2020 14:57:57 +0200 (CEST) From: =?utf-8?Q?Micha=C5=82_Leszczy=C5=84ski?= To: Jan Beulich Message-ID: <893375527.10199950.1592571477991.JavaMail.zimbra@cert.pl> In-Reply-To: References: <20200619115823.22243-1-andrew.cooper3@citrix.com> <1417373854.10164826.1592568614663.JavaMail.zimbra@cert.pl> Subject: Re: [PATCH for-4.14] x86/msr: Disallow access to Processor Trace MSRs MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable X-Originating-IP: [172.16.10.10] X-Mailer: Zimbra 8.6.0_GA_1194 (ZimbraWebClient - GC83 (Win)/8.6.0_GA_1194) Thread-Topic: x86/msr: Disallow access to Processor Trace MSRs Thread-Index: THc0AA/6//Z2X6lhwGGVbYcd5iRAcA== X-BeenThere: xen-devel@lists.xenproject.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Cc: Paul Durrant , Andrew Cooper , Roger Pau =?utf-8?Q?Monn=C3=A9?= , Wei Liu , Xen-devel Errors-To: xen-devel-bounces@lists.xenproject.org Sender: "Xen-devel" ----- 19 cze 2020 o 14:49, Jan Beulich jbeulich@suse.com napisa=C5=82(a): > On 19.06.2020 14:10, Micha=C5=82 Leszczy=C5=84ski wrote: >> ----- 19 cze 2020 o 13:58, Andrew Cooper andrew.cooper3@citrix.com napis= a=C5=82(a): >>=20 >>> We do not expose the feature to guests, so should disallow access to th= e >>> respective MSRs. >>> >>> Signed-off-by: Andrew Cooper >>> --- >>> CC: Jan Beulich >>> CC: Wei Liu >>> CC: Roger Pau Monn=C3=A9 >>> CC: Paul Durrant >>> CC: Micha=C5=82 Leszczy=C5=84ski >>> >>> Paul: For 4.14. This needs backporting to older trees as well. >>> >>> Micha=C5=82: CC'ing, just to keep you in the loop. Xen has some dubiou= s default >>> MSR semantics which we're still in the middle of untangling in a backwa= rds >>> compatible way. Patches like this will eventually not be necessary, bu= t they >>> are for now. >>=20 >>=20 >> As for external IPT monitoring, it would be best if the VM would think >> that IPT is simply not supported at all by the underlying hypervisor. >=20 > This is already the case, isn't it? Yet not reporting a feature may > not keep a guest from trying to access the respective MSRs. >=20 > Jan Okay, understood :) ml