From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f201.google.com (mail-pf1-f201.google.com [209.85.210.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E99E400162 for ; Fri, 15 May 2026 19:21:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778872874; cv=none; b=fwfQVR/XRsyrISGf5kHKP/tZpFcG9iuLk+r2cnreIXUFQOXUSVzmNeS+9XpRvZQuqPw86C/VnXpMrnSnKLkF2PK0vHZ7u2DgpzBJfF/Z0gZhCdroJp+FSf3iCT0r//LJxlbhRUwD+EZCrEIAhfeJiQ400LimbADV3uy5I18q6+I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1778872874; c=relaxed/simple; bh=7fNZAyvHkd4hTsuWucV5ADSCdPdtVNOHGfWpS1jSTro=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RydGo9s3yO1jmdT3Z7Ygilqaz4qjbTfZsRMF36Gh8BwQOUcBVZFfd8/Aak0/PAaqB+YpOpIf4wYoD4vkj8h+0K0a7KSRyCxqWTKIIiGv9sK7UcIJ3sPdz/3Cyu7qDS8Xde7VR9xaFXhECGsHeJTXh6VqJEuVFGuX5mRpNSIoAos= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=oVHVF2BY; arc=none smtp.client-ip=209.85.210.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="oVHVF2BY" Received: by mail-pf1-f201.google.com with SMTP id d2e1a72fcca58-8386367b23cso111149b3a.3 for ; Fri, 15 May 2026 12:21:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1778872871; x=1779477671; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=HRAsSS8xU7yGk1K8a9fV0Bzp4HNJreTB4TmSZ4FXvc4=; b=oVHVF2BYlX76Y+d7LcjozAnixTwMgfDODWxvgpdYfY2UUzLJsJPOlV8lQ+IjKrG2LA zrvnqjFfSTyc3zpx/yevDZLIzNHZ6dDIgoWXRlXK7GijtDO992XLcCwvaM2g9imFTQ6l U1iniYxYclV9gZjVhBUnExG6SrazXxpfr/OLtCzZAmNsw+F/nh1Zn2fNgqDn5hQuh3QJ 8wPeaVfyBTq8gDox+SbNuhSF2mQRpRN7SoK+i0BcX4Da6e/RpJs+j7esxatDoOD1AwKB fsdJroPPCq/erWa2nUBsJTe7AsqMrAVW0kpT6OpA005oDbggec+OHV258SqESRrIaJlK Z39A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1778872871; x=1779477671; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=HRAsSS8xU7yGk1K8a9fV0Bzp4HNJreTB4TmSZ4FXvc4=; b=OjUzdrOdZ15ZvxucfZCTvxM39ibPCVpwka6ISV6rIMqJqFV/COvulYLVA7focAvTyI xAWNw3I8K9Dkvogz2oVAyIg7ltPUVZWh0oXeW8MphMU7nk8wP9b77rIcAqjmnOSGd4+T 9BmWs8T6pUsUt5WxxdL88HKpN5gTMSi/t/hhG6SEAd7M5wXBhxA7h3Zacg6OtW4R/Lsd ejvAEZLtjNobCVxOOSMKw1DTX5v123Ua7qgyYOcsmUO0GFhHb+1owQJjPiu4nyVS7kmy FlunCR+pWv5JPO04pstJ/nWlw26p7euXFXMEdi0CmCgQ+pZQnFsCfrOKavKRf9SW5iWj lSAA== X-Forwarded-Encrypted: i=1; AFNElJ8ZBtnqOggxKSVs8rfF6hpKzgxrUCGC8hIPDhKH7bMDgndamUvSbPvcwyBsLBaxFIzSFpc=@vger.kernel.org X-Gm-Message-State: AOJu0YyGA2QOL9/ACj22xtDjWY/2tkLZEMbW2v8FTBLHRLIr1qPFj29Q l99esuntTvSxB9cjCKTJJNYyLAADlSeBCcWsyWp8ZwVE8i9iDHTet3Ba3+gpArKOFhPL2asTFMy 5kD+HhQ== X-Received: from pfdc5.prod.google.com ([2002:aa7:8c05:0:b0:82f:a75b:f7fa]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:ab0d:b0:839:e27c:6cce with SMTP id d2e1a72fcca58-83f33d97d9amr5480931b3a.37.1778872871152; Fri, 15 May 2026 12:21:11 -0700 (PDT) Reply-To: Sean Christopherson Date: Fri, 15 May 2026 12:19:33 -0700 In-Reply-To: <20260515191942.1892718-1-seanjc@google.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260515191942.1892718-1-seanjc@google.com> X-Mailer: git-send-email 2.54.0.563.g4f69b47b94-goog Message-ID: <20260515191942.1892718-33-seanjc@google.com> Subject: [PATCH v3 32/41] x86/tsc: Rejects attempts to override TSC calibration with lesser routine From: Sean Christopherson To: Kiryl Shutsemau , Paolo Bonzini , Sean Christopherson , "K. Y. Srinivasan" , Haiyang Zhang , Wei Liu , Dexuan Cui , Long Li , Ajay Kaher , Alexey Makhalov , Jan Kiszka , Dave Hansen , Andy Lutomirski , Peter Zijlstra , Juergen Gross , Daniel Lezcano , Thomas Gleixner , John Stultz Cc: Rick Edgecombe , Vitaly Kuznetsov , Broadcom internal kernel review list , Boris Ostrovsky , Stephen Boyd , x86@kernel.org, linux-coco@lists.linux.dev, kvm@vger.kernel.org, linux-hyperv@vger.kernel.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, xen-devel@lists.xenproject.org, Michael Kelley , Tom Lendacky , Nikunj A Dadhania , Thomas Gleixner , David Woodhouse Content-Type: text/plain; charset="UTF-8" When registering a TSC frequency calibration routine, sanity check that the incoming routine is as robust as the outgoing routine, and reject the incoming routine if the sanity check fails. Because native calibration routines only mark the TSC frequency as known and reliable when they actually run, the effective progression of capabilities is: None (native) => Known and maybe Reliable (PV) => Known and Reliable (CoCo). Violating that progression for a PV override is relatively benign, but messing up the progression when CoCo is involved is more problematic, as it likely means a trusted source of information (hardware/firmware) is being discarded in favor of a less trusted source (hypervisor). Signed-off-by: Sean Christopherson --- arch/x86/kernel/tsc.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/arch/x86/kernel/tsc.c b/arch/x86/kernel/tsc.c index 98bef1d06fa9..7a261214fa3e 100644 --- a/arch/x86/kernel/tsc.c +++ b/arch/x86/kernel/tsc.c @@ -1319,8 +1319,13 @@ void tsc_register_calibration_routines(unsigned long (*calibrate_tsc)(void), if (properties & TSC_FREQUENCY_KNOWN) setup_force_cpu_cap(X86_FEATURE_TSC_KNOWN_FREQ); + else if (WARN_ON(boot_cpu_has(X86_FEATURE_TSC_KNOWN_FREQ))) + return; + if (properties & TSC_RELIABLE) setup_force_cpu_cap(X86_FEATURE_TSC_RELIABLE); + else if (WARN_ON(boot_cpu_has(X86_FEATURE_TSC_RELIABLE))) + return; x86_platform.calibrate_tsc = calibrate_tsc; if (calibrate_cpu) -- 2.54.0.563.g4f69b47b94-goog