From: "Zhang, Cathy" <cathy.zhang@intel.com>
To: Jarkko Sakkinen <jarkko@kernel.org>
Cc: "linux-sgx@vger.kernel.org" <linux-sgx@vger.kernel.org>,
"x86@kernel.org" <x86@kernel.org>,
"Chatre, Reinette" <reinette.chatre@intel.com>,
"Hansen, Dave" <dave.hansen@intel.com>,
"Raj, Ashok" <ashok.raj@intel.com>,
"Peng, Chao P" <chao.p.peng@intel.com>,
"Zhong, Yang" <yang.zhong@intel.com>
Subject: RE: [PATCH v4 2/9] x86/sgx: Save enclave pointer for VA page
Date: Sun, 24 Apr 2022 02:31:12 +0000 [thread overview]
Message-ID: <5f05bfb3613841a2bf2d0fc99999e5e1@intel.com> (raw)
In-Reply-To: <YmGAfiiog/NRHIvq@kernel.org>
> -----Original Message-----
> From: Jarkko Sakkinen <jarkko@kernel.org>
> Sent: Friday, April 22, 2022 12:04 AM
> To: Zhang, Cathy <cathy.zhang@intel.com>
> Cc: linux-sgx@vger.kernel.org; x86@kernel.org; Chatre, Reinette
> <reinette.chatre@intel.com>; Hansen, Dave <dave.hansen@intel.com>; Raj,
> Ashok <ashok.raj@intel.com>; Peng, Chao P <chao.p.peng@intel.com>;
> Zhong, Yang <yang.zhong@intel.com>
> Subject: Re: [PATCH v4 2/9] x86/sgx: Save enclave pointer for VA page
>
> On Thu, Apr 21, 2022 at 07:03:19PM +0800, Cathy Zhang wrote:
> > Tearing down all enclaves is required by SGX SVN update, which
> > involves running the ENCLS[EREMOVE] instruction on every EPC page.
> > This (tearing down all enclaves) should be coordinated with any
> > enclaves that may be in the process of existing and thus already be
> > running ENCLS[EREMOVE] as part of enclave release.
> >
> > In support of this coordination, it is required to know which enclave
> > owns each in-use EPC page. It is already possible to locate the owning
> > enclave of SECS and regular pages but not for VA pages.
> >
> > Make the following changes for VA pages' location:
> > 1) Make epc->owner type-agnostic by changing its type to 'void *'. So,
> > besides "struct sgx_encl_page", it can have other types, like
> > "struct sgx_va_page".
> > 2) Save the enclave pointer for each VA page to support locating its
> > owning enclave.
> >
> > Note: to track 2T EPC memory, this scheme of tracking will use
> > additional 8M memory.
> >
> > Signed-off-by: Cathy Zhang <cathy.zhang@intel.com>
> >
> > ---
> > Changes since v3:
> > - Squash patch "x86/sgx: Provide VA page non-NULL owner" and
> > "x86/sgx: Save enclave pointer for VA page". Update commit log.
> > (Suggested by Jarkko Sakkinen)
> > ---
> > arch/x86/kernel/cpu/sgx/encl.h | 4 ++--
> > arch/x86/kernel/cpu/sgx/sgx.h | 2 +-
> > arch/x86/kernel/cpu/sgx/encl.c | 5 +++--
> > arch/x86/kernel/cpu/sgx/ioctl.c | 3 ++-
> > 4 files changed, 8 insertions(+), 6 deletions(-)
> >
> > diff --git a/arch/x86/kernel/cpu/sgx/encl.h
> > b/arch/x86/kernel/cpu/sgx/encl.h index 7cdc351bc273..59fbd4ed5c64
> > 100644
> > --- a/arch/x86/kernel/cpu/sgx/encl.h
> > +++ b/arch/x86/kernel/cpu/sgx/encl.h
> > @@ -76,6 +76,7 @@ struct sgx_va_page {
> > struct sgx_epc_page *epc_page;
> > DECLARE_BITMAP(slots, SGX_VA_SLOT_COUNT);
> > struct list_head list;
> > + struct sgx_encl *encl;
> > };
> >
> > struct sgx_backing {
> > @@ -112,8 +113,7 @@ int sgx_encl_get_backing(struct sgx_encl *encl,
> > unsigned long page_index, void sgx_encl_put_backing(struct
> > sgx_backing *backing, bool do_write); int
> sgx_encl_test_and_clear_young(struct mm_struct *mm,
> > struct sgx_encl_page *page);
> > -
>
> This line removal is not related to the patch.
Yes, added back.
>
> > -struct sgx_epc_page *sgx_alloc_va_page(void);
> > +struct sgx_epc_page *sgx_alloc_va_page(struct sgx_va_page *va_page);
> > unsigned int sgx_alloc_va_slot(struct sgx_va_page *va_page); void
> > sgx_free_va_slot(struct sgx_va_page *va_page, unsigned int offset);
> > bool sgx_va_page_full(struct sgx_va_page *va_page); diff --git
> > a/arch/x86/kernel/cpu/sgx/sgx.h b/arch/x86/kernel/cpu/sgx/sgx.h index
> > d7a1490d90bb..f8ed9deac18b 100644
> > --- a/arch/x86/kernel/cpu/sgx/sgx.h
> > +++ b/arch/x86/kernel/cpu/sgx/sgx.h
> > @@ -33,7 +33,7 @@ struct sgx_epc_page {
> > unsigned int section;
> > u16 flags;
> > u16 poison;
> > - struct sgx_encl_page *owner;
> > + void *owner;
> > struct list_head list;
> > };
> >
> > diff --git a/arch/x86/kernel/cpu/sgx/encl.c
> > b/arch/x86/kernel/cpu/sgx/encl.c index 68c8d65a8dee..c0725111cc25
> > 100644
> > --- a/arch/x86/kernel/cpu/sgx/encl.c
> > +++ b/arch/x86/kernel/cpu/sgx/encl.c
> > @@ -753,6 +753,7 @@ int sgx_encl_test_and_clear_young(struct
> mm_struct
> > *mm,
> >
> > /**
> > * sgx_alloc_va_page() - Allocate a Version Array (VA) page
> > + * @va_page: struct sgx_va_page connected to this VA page
> > *
> > * Allocate a free EPC page and convert it to a Version Array (VA) page.
> > *
> > @@ -760,12 +761,12 @@ int sgx_encl_test_and_clear_young(struct
> mm_struct *mm,
> > * a VA page,
> > * -errno otherwise
> > */
> > -struct sgx_epc_page *sgx_alloc_va_page(void)
> > +struct sgx_epc_page *sgx_alloc_va_page(struct sgx_va_page *va_page)
> > {
> > struct sgx_epc_page *epc_page;
> > int ret;
> >
> > - epc_page = sgx_alloc_epc_page(NULL, true);
> > + epc_page = sgx_alloc_epc_page(va_page, true);
> > if (IS_ERR(epc_page))
> > return ERR_CAST(epc_page);
> >
> > diff --git a/arch/x86/kernel/cpu/sgx/ioctl.c
> > b/arch/x86/kernel/cpu/sgx/ioctl.c index a4df72f715d7..b77343eb2d49
> > 100644
> > --- a/arch/x86/kernel/cpu/sgx/ioctl.c
> > +++ b/arch/x86/kernel/cpu/sgx/ioctl.c
> > @@ -30,7 +30,8 @@ static struct sgx_va_page *sgx_encl_grow(struct
> sgx_encl *encl)
> > if (!va_page)
> > return ERR_PTR(-ENOMEM);
> >
> > - va_page->epc_page = sgx_alloc_va_page();
> > + va_page->encl = encl;
> > + va_page->epc_page = sgx_alloc_va_page(va_page);
> > if (IS_ERR(va_page->epc_page)) {
> > err = ERR_CAST(va_page->epc_page);
> > kfree(va_page);
> > --
> > 2.17.1
> >
>
> BR, Jarkko
next prev parent reply other threads:[~2022-04-24 2:31 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-04-21 11:03 [PATCH v4 0/9] Support microcode updates affecting SGX Cathy Zhang
2022-04-21 11:03 ` [PATCH v4 1/9] x86/sgx: Introduce mechanism to prevent new initializations of EPC pages Cathy Zhang
2022-04-21 16:02 ` Jarkko Sakkinen
2022-04-24 2:27 ` Zhang, Cathy
2022-04-25 14:00 ` Jarkko Sakkinen
2022-04-21 11:03 ` [PATCH v4 2/9] x86/sgx: Save enclave pointer for VA page Cathy Zhang
2022-04-21 16:04 ` Jarkko Sakkinen
2022-04-24 2:31 ` Zhang, Cathy [this message]
2022-04-21 11:03 ` [PATCH v4 3/9] x86/sgx: Keep record for SGX VA and Guest page type Cathy Zhang
2022-04-21 11:03 ` [PATCH v4 4/9] x86/sgx: Save the size of each EPC section Cathy Zhang
2022-04-21 11:03 ` [PATCH v4 5/9] x86/sgx: Forced EPC page zapping for EUPDATESVN Cathy Zhang
2022-04-21 16:07 ` Jarkko Sakkinen
2022-04-24 2:32 ` Zhang, Cathy
2022-04-21 11:03 ` [PATCH v4 6/9] x86/sgx: Define error codes for ENCLS[EUPDATESVN] Cathy Zhang
2022-04-21 11:03 ` [PATCH v4 7/9] x86/sgx: Implement ENCLS[EUPDATESVN] Cathy Zhang
2022-04-21 11:03 ` [PATCH v4 8/9] x86/cpu: Call ENCLS[EUPDATESVN] procedure in microcode update Cathy Zhang
2022-04-21 12:07 ` Borislav Petkov
2022-04-24 2:18 ` Zhang, Cathy
2022-04-21 11:03 ` [PATCH v4 9/9] x86/sgx: Call ENCLS[EUPDATESVN] during SGX initialization Cathy Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5f05bfb3613841a2bf2d0fc99999e5e1@intel.com \
--to=cathy.zhang@intel.com \
--cc=ashok.raj@intel.com \
--cc=chao.p.peng@intel.com \
--cc=dave.hansen@intel.com \
--cc=jarkko@kernel.org \
--cc=linux-sgx@vger.kernel.org \
--cc=reinette.chatre@intel.com \
--cc=x86@kernel.org \
--cc=yang.zhong@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox