From: Paolo Bonzini <pbonzini@redhat.com>
To: Yang Weijiang <weijiang.yang@intel.com>,
seanjc@google.com, jmattson@google.com, kvm@vger.kernel.org,
linux-kernel@vger.kernel.org
Cc: yu.c.zhang@linux.intel.com
Subject: Re: [PATCH v15 00/14] Introduce support for guest CET feature
Date: Wed, 3 Feb 2021 13:40:00 +0100 [thread overview]
Message-ID: <f98faaa8-8bc5-9ba7-c4e1-33f8a890e1e3@redhat.com> (raw)
In-Reply-To: <20210203113421.5759-1-weijiang.yang@intel.com>
On 03/02/21 12:34, Yang Weijiang wrote:
> Control-flow Enforcement Technology (CET) provides protection against
> Return/Jump-Oriented Programming (ROP/JOP) attack. There're two CET
> subfeatures: Shadow Stack (SHSTK) and Indirect Branch Tracking (IBT).
> SHSTK is to prevent ROP and IBT is to prevent JOP.
>
> Several parts in KVM have been updated to provide guest CET support, including:
> CPUID/XSAVES settings, MSR passthrough, user-space MSR access interface,
> vmentry/vmexit config, nested VM etc. These patches are dependent on CET
> kernel patches for XSAVES support and CET definitions, e.g., MSR and related
> feature flags.
>
> CET kernel patches: refer to [1], [2].
>
> Previous CET KVM patches: refer to [3].
>
> CET QEMU patches: refer to [4].
>
> CET KVM unit-test patch: refer to [5].
>
> [1]: CET Shadow Stack patches v18:
> https://lkml.kernel.org/linux-api/20210127212524.10188-1-yu-cheng.yu@intel.com/
>
> [2]: Indirect Branch Tracking patches v18:
> https://lkml.kernel.org/linux-api/20210127213028.11362-1-yu-cheng.yu@intel.com/
>
> [3]: CET KVM patches v14:
> https://lkml.kernel.org/kvm/20201106011637.14289-1-weijiang.yang@intel.com/
>
> [4]: CET QEMU patches:
> https://patchwork.ozlabs.org/project/qemu-devel/patch/20201013051935.6052-2-weijiang.yang@intel.com/
>
> [5]: CET KVM unit-test patch:
> https://patchwork.kernel.org/project/kvm/patch/20200506082110.25441-12-weijiang.yang@intel.com/
>
> Changes in v15:
> - Changed patches per Paolo's review feedback on v14.
> - Added a new patch for GUEST_SSP save/restore in guest SMM case.
> - Fixed guest call-trace issue due to CET MSR interception.
> - Removed unnecessary guest CET state cleanup in VMCS.
> - Rebased patches to 5.11-rc6.
>
>
> Sean Christopherson (2):
> KVM: x86: Report XSS as an MSR to be saved if there are supported
> features
> KVM: x86: Load guest fpu state when accessing MSRs managed by XSAVES
>
> Yang Weijiang (12):
> KVM: x86: Refresh CPUID on writes to MSR_IA32_XSS
> KVM: x86: Add #CP support in guest exception dispatch
> KVM: VMX: Introduce CET VMCS fields and flags
> KVM: x86: Add fault checks for CR4.CET
> KVM: VMX: Emulate reads and writes to CET MSRs
> KVM: VMX: Add a synthetic MSR to allow userspace VMM to access
> GUEST_SSP
> KVM: x86: Report CET MSRs as to-be-saved if CET is supported
> KVM: x86: Enable CET virtualization for VMX and advertise CET to
> userspace
> KVM: VMX: Pass through CET MSRs to the guest when supported
> KVM: nVMX: Add helper to check the vmcs01 MSR bitmap for MSR
> pass-through
> KVM: nVMX: Enable CET support for nested VMX
> KVM: x86: Save/Restore GUEST_SSP to/from SMRAM
>
> arch/x86/include/asm/kvm_host.h | 4 +-
> arch/x86/include/asm/vmx.h | 8 ++
> arch/x86/include/uapi/asm/kvm.h | 1 +
> arch/x86/include/uapi/asm/kvm_para.h | 1 +
> arch/x86/kvm/cpuid.c | 26 +++-
> arch/x86/kvm/emulate.c | 11 ++
> arch/x86/kvm/vmx/capabilities.h | 5 +
> arch/x86/kvm/vmx/nested.c | 57 ++++++--
> arch/x86/kvm/vmx/vmcs12.c | 6 +
> arch/x86/kvm/vmx/vmcs12.h | 14 +-
> arch/x86/kvm/vmx/vmx.c | 202 ++++++++++++++++++++++++++-
> arch/x86/kvm/x86.c | 67 ++++++++-
> arch/x86/kvm/x86.h | 10 +-
> 13 files changed, 387 insertions(+), 25 deletions(-)
>
Queued, though not for 5.12 unless the bare metal support is there too.
Paolo
prev parent reply other threads:[~2021-02-03 12:41 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-02-03 11:34 [PATCH v15 00/14] Introduce support for guest CET feature Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 01/14] KVM: x86: Report XSS as an MSR to be saved if there are supported features Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 02/14] KVM: x86: Refresh CPUID on writes to MSR_IA32_XSS Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 03/14] KVM: x86: Load guest fpu state when accessing MSRs managed by XSAVES Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 04/14] KVM: x86: Add #CP support in guest exception dispatch Yang Weijiang
2021-02-03 21:46 ` Sean Christopherson
2021-02-04 7:22 ` Yang Weijiang
2021-02-04 8:28 ` Paolo Bonzini
2021-02-04 8:24 ` Paolo Bonzini
2021-02-04 16:42 ` Sean Christopherson
2021-02-04 17:29 ` Paolo Bonzini
2021-02-03 11:34 ` [PATCH v15 05/14] KVM: VMX: Introduce CET VMCS fields and flags Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 06/14] KVM: x86: Add fault checks for CR4.CET Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 07/14] KVM: VMX: Emulate reads and writes to CET MSRs Yang Weijiang
2021-02-03 11:57 ` Paolo Bonzini
2021-02-03 12:50 ` Yang Weijiang
2022-05-18 15:55 ` John Allen
2022-05-18 16:16 ` Sean Christopherson
2022-05-19 8:49 ` Yang, Weijiang
2021-02-03 11:34 ` [PATCH v15 08/14] KVM: VMX: Add a synthetic MSR to allow userspace VMM to access GUEST_SSP Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 09/14] KVM: x86: Report CET MSRs as to-be-saved if CET is supported Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 10/14] KVM: x86: Enable CET virtualization for VMX and advertise CET to userspace Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 11/14] KVM: VMX: Pass through CET MSRs to the guest when supported Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 12/14] KVM: nVMX: Add helper to check the vmcs01 MSR bitmap for MSR pass-through Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 13/14] KVM: nVMX: Enable CET support for nested VMX Yang Weijiang
2021-02-03 11:34 ` [PATCH v15 14/14] KVM: x86: Save/Restore GUEST_SSP to/from SMRAM Yang Weijiang
2021-02-03 12:07 ` Paolo Bonzini
2021-02-03 12:59 ` Yang Weijiang
2021-02-03 12:40 ` Paolo Bonzini [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f98faaa8-8bc5-9ba7-c4e1-33f8a890e1e3@redhat.com \
--to=pbonzini@redhat.com \
--cc=jmattson@google.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=seanjc@google.com \
--cc=weijiang.yang@intel.com \
--cc=yu.c.zhang@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox