From: Avi Kivity <avi@redhat.com>
To: Joerg Roedel <joerg.roedel@amd.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>, kvm@vger.kernel.org
Subject: Re: [PATCH 12/13] KVM: SVM: Add checks for IO instructions
Date: Mon, 28 Mar 2011 14:28:12 +0200 [thread overview]
Message-ID: <4D907EDC.1050607@redhat.com> (raw)
In-Reply-To: <1301309210-11120-13-git-send-email-joerg.roedel@amd.com>
On 03/28/2011 12:46 PM, Joerg Roedel wrote:
> This patch adds code to check for IOIO intercepts on
> instructions decoded by the KVM instruction emulator.
>
>
> @@ -3926,6 +3926,10 @@ static struct __x86_intercept {
> [x86_intercept_iret] = PRE_EX(SVM_EXIT_IRET),
> [x86_intercept_icebp] = PRE_EX(SVM_EXIT_ICEBP),
> [x86_intercept_hlt] = POST_EX(SVM_EXIT_HLT),
> + [x86_intercept_in] = POST_EX(SVM_EXIT_IOIO),
> + [x86_intercept_ins] = POST_EX(SVM_EXIT_IOIO),
> + [x86_intercept_out] = POST_EX(SVM_EXIT_IOIO),
> + [x86_intercept_outs] = POST_EX(SVM_EXIT_IOIO),
> };
The spec indicates we need to check the TSS and IOPL based permissions
before the intercept (vmx agrees). With the code as is, it happens
afterwards.
One way to do this is to have an ExtraChecks bit in the opcode::flags.
Then opcode::u.xcheck->perms() is the pre-intercept check and
opcode::u.xcheck->execute() is the post-intercept execution. Should
work for monitor/mwait/rdtsc(p)/rdpmc/other crap x86 throws at us.
--
error compiling committee.c: too many arguments to function
next prev parent reply other threads:[~2011-03-28 12:28 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-03-28 10:46 [PATCH 0/13] KVM: Make the instruction emulator aware of Nested Virtualization v3 Joerg Roedel
2011-03-28 10:46 ` [PATCH 01/13] KVM: x86 emulator: add framework for instruction intercepts Joerg Roedel
2011-03-28 10:46 ` [PATCH 02/13] KVM: x86 emulator: add SVM intercepts Joerg Roedel
2011-03-28 10:46 ` [PATCH 03/13] KVM: X86: Don't write-back cpu-state on X86EMUL_INTERCEPTED Joerg Roedel
2011-03-28 10:46 ` [PATCH 04/13] KVM: X86: Add x86 callback for intercept check Joerg Roedel
2011-03-28 10:46 ` [PATCH 05/13] KVM: SVM: Add intercept check for emulated cr accesses Joerg Roedel
2011-03-28 10:46 ` [PATCH 06/13] KVM: SVM: Add intercept check for accessing dr registers Joerg Roedel
2011-03-28 10:46 ` [PATCH 07/13] KVM: SVM: Add intercept checks for descriptor table accesses Joerg Roedel
2011-03-28 12:35 ` Avi Kivity
2011-03-28 13:56 ` Roedel, Joerg
2011-03-28 14:34 ` Avi Kivity
2011-03-28 10:46 ` [PATCH 08/13] KVM: SVM: Add intercept checks for SVM instructions Joerg Roedel
2011-03-28 12:08 ` Avi Kivity
2011-03-28 12:18 ` Roedel, Joerg
2011-03-28 10:46 ` [PATCH 09/13] KVM: SVM: Add intercept checks for remaining group7 instructions Joerg Roedel
2011-03-28 12:15 ` Avi Kivity
2011-03-28 10:46 ` [PATCH 10/13] KVM: SVM: Add intercept checks for remaining twobyte instructions Joerg Roedel
2011-03-28 12:29 ` Avi Kivity
2011-03-28 10:46 ` [PATCH 11/13] KVM: SVM: Add intercept checks for one-byte instructions Joerg Roedel
2011-03-28 10:46 ` [PATCH 12/13] KVM: SVM: Add checks for IO instructions Joerg Roedel
2011-03-28 12:28 ` Avi Kivity [this message]
2011-03-31 7:14 ` Roedel, Joerg
2011-03-31 9:18 ` Avi Kivity
2011-03-31 9:42 ` Roedel, Joerg
2011-03-31 10:03 ` Avi Kivity
2011-03-31 10:28 ` Roedel, Joerg
2011-03-28 10:46 ` [PATCH 13/13] KVM: SVM: Remove nested sel_cr0_write handling code Joerg Roedel
-- strict thread matches above, loose matches on Subject: below --
2011-03-25 9:29 [PATCH 0/13] KVM: Make the instruction emulator aware of Nested Virtualization v2 Joerg Roedel
2011-03-25 9:29 ` [PATCH 12/13] KVM: SVM: Add checks for IO instructions Joerg Roedel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4D907EDC.1050607@redhat.com \
--to=avi@redhat.com \
--cc=joerg.roedel@amd.com \
--cc=kvm@vger.kernel.org \
--cc=mtosatti@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).