From: Zhao Liu <zhao1.liu@intel.com>
To: Kishen Maloor <kishen.maloor@intel.com>
Cc: qemu-devel@nongnu.org, pbonzini@redhat.com, kvm@vger.kernel.org,
sohil.mehta@intel.com, xiaoyao.li@intel.com,
binbin.wu@linux.intel.com, farrah.chen@intel.com
Subject: Re: [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration
Date: Wed, 2 Sep 2026 18:14:47 +0800 [thread overview]
Message-ID: <apf3FycK5uWh+yq5@intel.com> (raw)
In-Reply-To: <20260826035734.114685-2-kishen.maloor@intel.com>
On Tue, Aug 25, 2026 at 08:57:30PM -0700, Kishen Maloor wrote:
> Date: Tue, 25 Aug 2026 20:57:30 -0700
> From: Kishen Maloor <kishen.maloor@intel.com>
> Subject: [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration
> X-Mailer: git-send-email 2.47.1
>
> From: Isaku Yamahata <isaku.yamahata@intel.com>
>
> Linear Address Space Separation (LASS) is a security feature that
> prevents a class of side-channel attacks relying on speculative
> accesses across the user/kernel boundary. Paging, along with SMEP
> and SMAP, already provides mode-based access protection, but
> enforcing it requires a page walk whose timing can leak the
> layout of kernel memory.
>
> LASS applies the equivalent protections during linear-address
> pre-processing, before any page walk. Given the usual partitioning of
> the linear address space into a user half (bit 63 clear) and a
> supervisor half (bit 63 set), an access targeting the opposite half is
> rejected on the basis of bit 63 alone, raising a #GP. LASS is enabled
> via CR4.LASS[bit 27] and applies only in IA-32e mode.
>
> Feature bit:
> CPUID.(EAX=7,ECX=1):EAX[6]
>
> A CPUID_7_1_EAX_LASS macro was previously added in commit 31df29c532a9
> ("i386/tdx: Add supported CPUID bits related to TD Attributes"), but the
> bit was left unnamed in feature_word_info[FEAT_7_1_EAX]. Add the "lass"
> feature name to expose it via -cpu host, -cpu max, or an explicit +lass.
>
> Exposing LASS to a guest also requires KVM support: KVM must validate
> the CPUID bit and CR4.LASS, and enforce LASS violations in its
> instruction emulator.
>
> LASS is not implemented in TCG, so the bit is not added to
> TCG_7_1_EAX_FEATURES.
>
> More details can be found in the Intel 64 and IA-32 Architectures
> Software Developer's Manual, Volume 3A, Section 4.3,
> "Linear-Address-Space Separation (LASS)".
>
> Signed-off-by: Isaku Yamahata <isaku.yamahata@intel.com>
> [kishen: rewrote commit message, rebased]
> Signed-off-by: Kishen Maloor <kishen.maloor@intel.com>
> ---
> KVM support for LASS is currently under review:
> https://lore.kernel.org/kvm/20260806011536.4172258-1-sohil.mehta@intel.com/
>
> target/i386/cpu.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
Reviewed-by: Zhao Liu <zhao1.liu@intel.com>
next prev parent reply other threads:[~2026-09-02 10:15 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 3:57 [PATCH 0/5] target/i386: Add support for LASS Kishen Maloor
2026-08-26 3:57 ` [PATCH 1/5] target/i386: Add support for LASS in CPUID enumeration Kishen Maloor
2026-09-02 10:14 ` Zhao Liu [this message]
2026-08-26 3:57 ` [PATCH 2/5] target/i386: Add LASS support in CR4 Kishen Maloor
2026-09-02 10:16 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 3/5] target/i386: Introduce DiamondRapids-v3 to enable LASS Kishen Maloor
2026-09-02 10:16 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 4/5] target/i386: Introduce SierraForest-v7 " Kishen Maloor
2026-09-02 10:17 ` Zhao Liu
2026-08-26 3:57 ` [PATCH 5/5] target/i386: Introduce ClearwaterForest-v5 " Kishen Maloor
2026-09-02 10:17 ` Zhao Liu
2026-08-27 3:07 ` [PATCH 0/5] target/i386: Add support for LASS Chen, Farrah
2026-09-01 16:08 ` Sohil Mehta
2026-09-02 2:40 ` Binbin Wu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apf3FycK5uWh+yq5@intel.com \
--to=zhao1.liu@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=farrah.chen@intel.com \
--cc=kishen.maloor@intel.com \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=sohil.mehta@intel.com \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.