From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-11.5 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_SIGNED,DKIM_VALID,INCLUDES_PATCH,MAILING_LIST_MULTI,SIGNED_OFF_BY, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_SANE_1 autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 8E01DC4363A for ; Wed, 21 Oct 2020 07:58:55 +0000 (UTC) Received: from merlin.infradead.org (merlin.infradead.org [205.233.59.134]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id 07B9822249 for ; Wed, 21 Oct 2020 07:58:54 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=lists.infradead.org header.i=@lists.infradead.org header.b="LGWhsJHL"; dkim=fail reason="signature verification failed" (1024-bit key) header.d=kernel.org header.i=@kernel.org header.b="ji7HDYJj" DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org 07B9822249 Authentication-Results: mail.kernel.org; dmarc=fail (p=none dis=none) header.from=kernel.org Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=merlin.20170209; h=Sender:Content-Transfer-Encoding: Content-Type:Cc:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:References:Message-ID: Subject:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=o1PElqxB+nerxTFBnvv/zEN72MqLUic35/vJRUtBjT0=; b=LGWhsJHL64Let/nQZVFmo4ME2 tZXeTji8abjyM67sdOI+T38yeG9/7a1doMGS620xC6ZYomtJplxBxnd11flKMeaZexzBQ4QVvQcaK 8n9GOekxIQW+TlAPryVTtGIm7bLfyPMzL0+L9Zptm0xjqadcW7yYXBd7nHrjTrlCgCWvJOJB/xw1g t5vxHhLPkww9vIIaZicq8qpH7JZJs7wkE8Zl61NhaydSidtuJQLZYvm/7haN9ffwlP+/nE61isiGv 37MQj1ZCLlq8ujrfYg8IPDWN6hZECJdoiM9LFevaArq3r/4Z5uxD6claAWHHVFkxHZvYYeG9Q0ppJ j73y3wvEQ==; Received: from localhost ([::1] helo=merlin.infradead.org) by merlin.infradead.org with esmtp (Exim 4.92.3 #3 (Red Hat Linux)) id 1kV901-00037W-6g; Wed, 21 Oct 2020 07:57:33 +0000 Received: from mail.kernel.org ([198.145.29.99]) by merlin.infradead.org with esmtps (Exim 4.92.3 #3 (Red Hat Linux)) id 1kV8zx-00036o-Jx for linux-arm-kernel@lists.infradead.org; Wed, 21 Oct 2020 07:57:31 +0000 Received: from willie-the-truck (236.31.169.217.in-addr.arpa [217.169.31.236]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPSA id ECA8221D7B; Wed, 21 Oct 2020 07:57:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=default; t=1603267048; bh=AG9fzN7g/HY9laxy/IIlnlyD/w5Knt/uexy8j19ZYvs=; h=Date:From:To:Cc:Subject:References:In-Reply-To:From; b=ji7HDYJjdgiMu7qPmGUBeo8pD8UFwOy4KTQiyeMxbMaL9wQEdQIekWc9yU4a4llSV 0h6f6tZ5xRM7Z5MdkgvI0QutpnjSyl4DzVPc1RgenX6DfHIJbJitWn7150eIJW7/tl WmRyQEMntTL9GEV4t68dCaye1iD1UBQAI+Fk/AD8= Date: Wed, 21 Oct 2020 08:57:23 +0100 From: Will Deacon To: Stephen Boyd Subject: Re: [PATCH 1/2] arm64: ARM_SMCCC_ARCH_WORKAROUND_1 doesn't return SMCCC_RET_NOT_REQUIRED Message-ID: <20201021075722.GA17230@willie-the-truck> References: <20201020214544.3206838-1-swboyd@chromium.org> <20201020214544.3206838-2-swboyd@chromium.org> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20201020214544.3206838-2-swboyd@chromium.org> User-Agent: Mutt/1.10.1 (2018-07-13) X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20201021_035729_888544_34DE08C9 X-CRM114-Status: GOOD ( 29.46 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Catalin Marinas , linux-kernel@vger.kernel.org, stable@vger.kernel.org, Steven Price , Andre Przywara , Marc Zyngier , linux-arm-kernel@lists.infradead.org Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Tue, Oct 20, 2020 at 02:45:43PM -0700, Stephen Boyd wrote: > According to the SMCCC spec (7.5.2 Discovery) the > ARM_SMCCC_ARCH_WORKAROUND_1 function id only returns 0, 1, and > SMCCC_RET_NOT_SUPPORTED corresponding to "workaround required", > "workaround not required but implemented", and "who knows, you're on > your own" respectively. For kvm hypercalls (hvc), we've implemented this > function id to return SMCCC_RET_NOT_SUPPORTED, 1, and > SMCCC_RET_NOT_REQUIRED. The SMCCC_RET_NOT_REQUIRED return value is not a > thing for this function id, and is probably copy/pasted from the > SMCCC_ARCH_WORKAROUND_2 function id that does support it. > > Clean this up by returning 0, 1, and SMCCC_RET_NOT_SUPPORTED > appropriately. Changing this exposes the problem that > spectre_v2_get_cpu_fw_mitigation_state() assumes a > SMCCC_RET_NOT_SUPPORTED return value means we are vulnerable, but really > it means we have no idea and should assume we can't do anything about > mitigation. Put another way, it better be unaffected because it can't be > mitigated in the firmware (in this case kvm) as the call isn't > implemented! > > Cc: Andre Przywara > Cc: Steven Price > Cc: Marc Zyngier > Cc: stable@vger.kernel.org > Fixes: c118bbb52743 ("arm64: KVM: Propagate full Spectre v2 workaround state to KVM guests") > Fixes: 73f381660959 ("arm64: Advertise mitigation of Spectre-v2, or lack thereof") > Signed-off-by: Stephen Boyd > --- > > This will require a slightly different backport to stable kernels, but > at least it looks like this is a problem given that this return value > isn't valid per the spec and we've been going around it by returning > something invalid for some time. > > arch/arm64/kernel/proton-pack.c | 3 +-- > arch/arm64/kvm/hypercalls.c | 2 +- > 2 files changed, 2 insertions(+), 3 deletions(-) > > diff --git a/arch/arm64/kernel/proton-pack.c b/arch/arm64/kernel/proton-pack.c > index 68b710f1b43f..00bd54f63f4f 100644 > --- a/arch/arm64/kernel/proton-pack.c > +++ b/arch/arm64/kernel/proton-pack.c > @@ -149,10 +149,9 @@ static enum mitigation_state spectre_v2_get_cpu_fw_mitigation_state(void) > case SMCCC_RET_SUCCESS: > return SPECTRE_MITIGATED; > case SMCCC_ARCH_WORKAROUND_RET_UNAFFECTED: > + case SMCCC_RET_NOT_SUPPORTED: /* Good luck w/ the Gatekeeper of Gozer */ > return SPECTRE_UNAFFECTED; Hmm, I'm not sure this is correct. The SMCCC spec is terrifically unhelpful: NOT_SUPPORTED: Either: * None of the PEs in the system require firmware mitigation for CVE-2017-5715. * The system contains at least 1 PE affected by CVE-2017-5715 that has no firmware mitigation available. * The firmware does not provide any information about whether firmware mitigation is required. so we can't tell whether the thing is vulnerable or not in this case, and have to assume that it is. > default: > - fallthrough; > - case SMCCC_RET_NOT_SUPPORTED: > return SPECTRE_VULNERABLE; > } > } > diff --git a/arch/arm64/kvm/hypercalls.c b/arch/arm64/kvm/hypercalls.c > index 9824025ccc5c..868486957808 100644 > --- a/arch/arm64/kvm/hypercalls.c > +++ b/arch/arm64/kvm/hypercalls.c > @@ -31,7 +31,7 @@ int kvm_hvc_call_handler(struct kvm_vcpu *vcpu) > val = SMCCC_RET_SUCCESS; > break; > case SPECTRE_UNAFFECTED: > - val = SMCCC_RET_NOT_REQUIRED; > + val = SMCCC_RET_NOT_SUPPORTED; Which means we need to return SMCCC_ARCH_WORKAROUND_RET_UNAFFECTED here, I suppose? Will _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel