From: Jason Andryuk <jason.andryuk@amd.com>
To: Grygorii Strashko <grygorii_strashko@epam.com>,
"xen-devel@lists.xenproject.org" <xen-devel@lists.xenproject.org>
Cc: "Jan Beulich" <jbeulich@suse.com>,
"Andrew Cooper" <andrew.cooper3@citrix.com>,
"Roger Pau Monné" <roger.pau@citrix.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Alejandro Vallejo" <alejandro.garciavallejo@amd.com>
Subject: Re: [XEN][PATCH v2 4/4] x86: pvh: allow to disable 32-bit interface support
Date: Tue, 2 Dec 2025 14:56:12 -0500 [thread overview]
Message-ID: <d1c1df48-a498-4ce5-8340-33755720101e@amd.com> (raw)
In-Reply-To: <20251119192916.1009549-5-grygorii_strashko@epam.com>
On 2025-11-19 14:30, Grygorii Strashko wrote:
> From: Grygorii Strashko <grygorii_strashko@epam.com>
>
> For x86 Xen safety certification only PVH Gusts are selected to be allowed
s/Gusts/Guests/
> which are started by using direct Direct Kernel Boot only. There is also an
s/direct Direct/direct/
> assumption that x86 Guest's (OS) early boot code (which is running not in
> 64-bit mode) does not access Xen interfaces (hypercalls, shared_info, ..).
>
> In this case the Xen HVM 32-bit COMPAT interface become unused and leaves
> gaps in terms of coverage.
>
> Hence now all prerequisite changes are in place, introduce a
> CONFIG_HVM_COMPAT option through which HVM(PVH) 32-bit interface support on
> 64-bit Xen can be disabled.
>
> By default, CONFIG_HVM_COMPAT is ("y") enabled and accessible only in
> EXPERT mode.
>
> Signed-off-by: Grygorii Strashko <grygorii_strashko@epam.com>
> ---
> changes in v2:
> - fix format and move above HVM_FEP
>
> xen/arch/x86/hvm/Kconfig | 19 ++++++++++++++++++-
> 1 file changed, 18 insertions(+), 1 deletion(-)
>
> diff --git a/xen/arch/x86/hvm/Kconfig b/xen/arch/x86/hvm/Kconfig
> index c323d767e77c..88090f5b3965 100644
> --- a/xen/arch/x86/hvm/Kconfig
> +++ b/xen/arch/x86/hvm/Kconfig
> @@ -2,7 +2,6 @@ menuconfig HVM
> bool "HVM support"
> depends on !PV_SHIM_EXCLUSIVE
> default !PV_SHIM
> - select COMPAT
> select IOREQ_SERVER
> select MEM_ACCESS_ALWAYS_ON
> help
> @@ -35,6 +34,24 @@ config INTEL_VMX
> If your system includes a processor with Intel VT-x support, say Y.
> If in doubt, say Y.
>
> +config HVM_COMPAT
> + bool "HVM 32-bit hypercalls interface support" if EXPERT
Maybe "HVM 32-bit compat hypercall support" to get "compat" in the
user-visible text?
> + select COMPAT
> + default y
> + help
> + The HVM 32-bit interface must be enabled for HVM domains to be able to
> + make hypercalls in 32bit mode. Non-PVH domains unconditionally need this
> + option so that hvmloader may issue hypercalls in 32bit mode.
> +
> + The HVM 32-bit interface can be disabled if:
> + - Only PVH domains are used
> + - Guests (OS) are started by using direct Direct Kernel Boot
> + - Guests (OS) are 64-bit and Guest early boot code, which is running not
> + in 64-bit mode, does not access Xen interfaces
> + (hypercalls, shared_info, ..)
> +
> + If unsure, say Y.
> +
Maybe something like:
"""
Support HVM hypercalls from 32-bit code. Hypercalls from 64-bit code
are always supported.
Disabling 32-bit compat hypercalls reduces the hypervisor binary size.
HVM guests require the 32-bit hvmloader, so they cannot run with this
disabled. i.e. Xen will only run 64-bit PVH guests with this disabled.
If unsure, say Y.
"""
While what you wrote is correct, I tried to rephrase to highlight the
the implications.
Regards,
Jason
> config HVM_FEP
> bool "HVM Forced Emulation Prefix support (UNSUPPORTED)" if UNSUPPORTED
> default DEBUG
next prev parent reply other threads:[~2025-12-02 19:56 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-19 19:30 [XEN][PATCH v2 0/4] x86: pvh: allow to disable 32-bit (COMPAT) interface support Grygorii Strashko
2025-11-19 19:30 ` [XEN][PATCH v2 1/4] x86: hvm: dm: factor out compat code under ifdefs Grygorii Strashko
2025-11-19 19:30 ` [XEN][PATCH v2 2/4] x86: hvm: compat: introduce is_hcall_compat() helper Grygorii Strashko
2025-12-02 18:41 ` Jason Andryuk
2025-11-19 19:30 ` [XEN][PATCH v2 3/4] x86: hvm: factor out COMPAT code under ifdefs Grygorii Strashko
2025-12-02 19:26 ` Jason Andryuk
2025-12-04 18:39 ` Grygorii Strashko
2025-12-04 18:47 ` Grygorii Strashko
2025-12-18 16:47 ` Jürgen Groß
2025-11-19 19:30 ` [XEN][PATCH v2 4/4] x86: pvh: allow to disable 32-bit interface support Grygorii Strashko
2025-12-02 19:56 ` Jason Andryuk [this message]
2025-12-18 16:20 ` [XEN][PATCH v2 0/4] x86: pvh: allow to disable 32-bit (COMPAT) " Grygorii Strashko
2025-12-18 16:33 ` Jan Beulich
2025-12-19 0:33 ` Stefano Stabellini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=d1c1df48-a498-4ce5-8340-33755720101e@amd.com \
--to=jason.andryuk@amd.com \
--cc=alejandro.garciavallejo@amd.com \
--cc=andrew.cooper3@citrix.com \
--cc=grygorii_strashko@epam.com \
--cc=jbeulich@suse.com \
--cc=roger.pau@citrix.com \
--cc=sstabellini@kernel.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.