From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 8739ACD4942 for ; Thu, 21 Sep 2023 03:28:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:Content-Type: Content-Transfer-Encoding:List-Subscribe:List-Help:List-Post:List-Archive: List-Unsubscribe:List-Id:In-Reply-To:From:References:Cc:To:Subject: MIME-Version:Date:Message-ID:Reply-To:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: List-Owner; bh=MFMssf6IYkXYwEhoolpg1r/w2JEEtehoXlKKvuISCvI=; b=PYLayq8rB3NwlC zWqqg8GwIFuvBS+Ek9dgoguzslqtLPcKoetwFB+bxSkA0Iv7geL5+Ghlf3FtBADhdzG3KsGDnG6Da PmHgzlv8vz7nq98VoLZ8UmAks7AxH+MMxN2SCAinx8L0n7esRF5DAMjZ4mztjsjbXCaPvlfu8bSwl jWmZnSiagoREUOT9l7cMLVHVaUSPLMgcZtTtuJCzIwSzFbK6fKLruc886OYH0p4/m9/fks3+ax7rq +8sFu21ietywMpYhrJw2v46phn4g8FCYLl6JhBsseO16HppusPTX//E8gIbAK34hCEC3THqJNOJIN 8g7VgaUo7yPhRgfdUh4g==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.96 #2 (Red Hat Linux)) id 1qjAMW-004uSy-0u; Thu, 21 Sep 2023 03:28:20 +0000 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by bombadil.infradead.org with esmtps (Exim 4.96 #2 (Red Hat Linux)) id 1qjAMU-004uSD-09 for linux-arm-kernel@lists.infradead.org; Thu, 21 Sep 2023 03:28:19 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1695266896; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0v2JG/s7PIc0vGKodtM+Q59Y9VnGkq0n4Wh8qBqHuOY=; b=Kc26MZ1wPbp8WDtR2ze0PWWJ/5KGrhGs/HkVO+VkgG0s5EyfTVlzG5QmUhkRRf+2LI9apy UuMA+hMA+W9t0XyZJDrRkCFtV/mY0eIHXZtjN+2FOrgirHzdbkUpmTRaBUYeTGc6DgWW8V 7YNezBc0lvDXsdzApaXTZw4+HiLnYLk= Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-39-ka4dpW_DPcKtzrDjvyDIuQ-1; Wed, 20 Sep 2023 23:28:13 -0400 X-MC-Unique: ka4dpW_DPcKtzrDjvyDIuQ-1 Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-274a28033b2so313238a91.2 for ; Wed, 20 Sep 2023 20:28:13 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1695266892; x=1695871692; h=content-transfer-encoding:in-reply-to:from:references:cc:to :content-language:subject:user-agent:mime-version:date:message-id :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=0v2JG/s7PIc0vGKodtM+Q59Y9VnGkq0n4Wh8qBqHuOY=; b=WUPwWXP9LwCsp9rvXF2/r1C13FXSs3G94BGI1GH7dbFMxRdrER//XRr+oTT4Qxzmsi 9NLAShsg1fi5RJqLKik7rCO/hCrhPC4it1qtFBpzwXJhgirLdMDpHwVASM0edoqwO9zP pCBLtOnPISvsV0s0059AduMpc3pe6iXHafLWd/akDgtm2HcO+yn/UiW4JiyjQ/M16HDV P6tmy6ubcm5YvOUn9WFiQasp2VqxaV5pVq5CrELvOJAtpsiXYD2uRqdmzDzrXe068Pgv m1IkbdFrN5yhf1xTCs+4aW2vaFqIKSTsY+5/Z41VBaiC+XVLfs3M7OcWmnNUYxjC7oNE TRfA== X-Gm-Message-State: AOJu0Yx+gCu5Y8qOhD1SLV2QxoDr92VheA6Jsx4nU6QYSBMqdxR7J5Dq HGHTEKWVdZX6J9hW02yD4DGRcqww5GDzzTIDWnk10YTV8tzdtKIpFu46u6UqJfp2Kf2T6mJGnEY eNECDfO08wqI+2hoa4s4Tb5aRQv+mWVidQRA= X-Received: by 2002:a17:90b:60f:b0:271:9237:a07f with SMTP id gb15-20020a17090b060f00b002719237a07fmr4640848pjb.32.1695266892206; Wed, 20 Sep 2023 20:28:12 -0700 (PDT) X-Google-Smtp-Source: AGHT+IGdTGDV/U1WxJZGqkf4/kI8P6PMbKZALx0spzejxrzMvccw2t9wWS0So2gleLrmzMbpuDGdXw== X-Received: by 2002:a17:90b:60f:b0:271:9237:a07f with SMTP id gb15-20020a17090b060f00b002719237a07fmr4640832pjb.32.1695266891888; Wed, 20 Sep 2023 20:28:11 -0700 (PDT) Received: from ?IPV6:2001:8003:e5b0:9f00:dbbc:1945:6e65:ec5? ([2001:8003:e5b0:9f00:dbbc:1945:6e65:ec5]) by smtp.gmail.com with ESMTPSA id j8-20020a17090a31c800b0027360359b70sm287885pjf.48.2023.09.20.20.28.07 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 20 Sep 2023 20:28:11 -0700 (PDT) Message-ID: Date: Thu, 21 Sep 2023 13:28:06 +1000 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.12.0 Subject: Re: [PATCH 2/2] KVM: arm64: Avoid soft lockups due to I-cache maintenance To: Oliver Upton , kvmarm@lists.linux.dev Cc: kvm@vger.kernel.org, Marc Zyngier , James Morse , Suzuki K Poulose , Zenghui Yu , Will Deacon , Catalin Marinas , linux-arm-kernel@lists.infradead.org References: <20230920080133.944717-1-oliver.upton@linux.dev> <20230920080133.944717-3-oliver.upton@linux.dev> From: Gavin Shan In-Reply-To: <20230920080133.944717-3-oliver.upton@linux.dev> X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Language: en-US X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20230920_202818_154920_D5C67464 X-CRM114-Status: GOOD ( 25.53 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Transfer-Encoding: 7bit Content-Type: text/plain; charset="us-ascii"; Format="flowed" Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On 9/20/23 18:01, Oliver Upton wrote: > Gavin reports of soft lockups on his Ampere Altra Max machine when > backing KVM guests with hugetlb pages. Upon further investigation, it > was found that the system is unable to keep up with parallel I-cache > invalidations done by KVM's stage-2 fault handler. > > This is ultimately an implementation problem. I-cache maintenance > instructions are available at EL0, so nothing stops a malicious > userspace from hammering a system with CMOs and cause it to fall over. > "Fixing" this problem in KVM is nothing more than slapping a bandage > over a much deeper problem. > > Anyway, the kernel already has a heuristic for limiting TLB > invalidations to avoid soft lockups. Reuse that logic to limit I-cache > CMOs done by KVM to map executable pages on systems without FEAT_DIC. > While at it, restructure __invalidate_icache_guest_page() to improve > readability and squeeze our new condition into the existing branching > structure. > > Link: https://lore.kernel.org/kvmarm/20230904072826.1468907-1-gshan@redhat.com/ > Signed-off-by: Oliver Upton > --- > arch/arm64/include/asm/kvm_mmu.h | 37 ++++++++++++++++++++++++++------ > 1 file changed, 31 insertions(+), 6 deletions(-) > Reviewed-by: Gavin Shan Tested-by: Gavin Shan > diff --git a/arch/arm64/include/asm/kvm_mmu.h b/arch/arm64/include/asm/kvm_mmu.h > index 96a80e8f6226..a425ecdd7be0 100644 > --- a/arch/arm64/include/asm/kvm_mmu.h > +++ b/arch/arm64/include/asm/kvm_mmu.h > @@ -224,16 +224,41 @@ static inline void __clean_dcache_guest_page(void *va, size_t size) > kvm_flush_dcache_to_poc(va, size); > } > > +static inline size_t __invalidate_icache_max_range(void) > +{ > + u8 iminline; > + u64 ctr; > + > + asm volatile(ALTERNATIVE_CB("movz %0, #0\n" > + "movk %0, #0, lsl #16\n" > + "movk %0, #0, lsl #32\n" > + "movk %0, #0, lsl #48\n", > + ARM64_ALWAYS_SYSTEM, > + kvm_compute_final_ctr_el0) > + : "=r" (ctr)); > + > + iminline = SYS_FIELD_GET(CTR_EL0, IminLine, ctr) + 2; > + return MAX_DVM_OPS << iminline; > +} > + > static inline void __invalidate_icache_guest_page(void *va, size_t size) > { > - if (icache_is_aliasing()) { > - /* any kind of VIPT cache */ > + /* > + * VPIPT I-cache maintenance must be done from EL2. See comment in the > + * nVHE flavor of __kvm_tlb_flush_vmid_ipa(). > + */ > + if (icache_is_vpipt() && read_sysreg(CurrentEL) != CurrentEL_EL2) > + return; > + > + /* > + * Blow the whole I-cache if it is aliasing (i.e. VIPT) or the > + * invalidation range exceeds our arbitrary limit on invadations by > + * cache line. > + */ > + if (icache_is_aliasing() || size > __invalidate_icache_max_range()) > icache_inval_all_pou(); > - } else if (read_sysreg(CurrentEL) != CurrentEL_EL1 || > - !icache_is_vpipt()) { > - /* PIPT or VPIPT at EL2 (see comment in __kvm_tlb_flush_vmid_ipa) */ > + else > icache_inval_pou((unsigned long)va, (unsigned long)va + size); > - } > } > > void kvm_set_way_flush(struct kvm_vcpu *vcpu); _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel