From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.ozlabs.org (lists.ozlabs.org [112.213.38.117]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 9BB32CCD199 for ; Fri, 17 Oct 2025 00:34:36 +0000 (UTC) Received: from boromir.ozlabs.org (localhost [127.0.0.1]) by lists.ozlabs.org (Postfix) with ESMTP id 4cnm566Vm7z3d8x; Fri, 17 Oct 2025 11:33:14 +1100 (AEDT) Authentication-Results: lists.ozlabs.org; arc=none smtp.remote-ip="2607:f8b0:4864:20::1049" ARC-Seal: i=1; a=rsa-sha256; d=lists.ozlabs.org; s=201707; t=1760661194; cv=none; b=HoCZQzCgjalBvQXk5ZHPfJaD29tQXr/WvYZ3DU5GofNtETAp8EEX/psZwHMj4MRdOPmjpPQmTzPk+/EWml9T/L0z5UQv610apWzZ++DJLGgmJN3DrDFaCxQ45+AK6CDEC1aQgCa1oMzyDRgv4hhgpMr1FVKN/WA61sQyu0EsHyrLkyu5hg8pbTjZ1/a/dU/o4FkKHFRMW9Z94SagRznbWWAXKyNDp0XsV71YD/LJ9fnSpqM7Y3io+MXLw+0J9blBteyvX+tFwtPXU2KC+RgojtQyFGg+RHIkYkzuWzWFSBRpLTLdzjm9g9pwPYSNjS/aUxzOcMKBec8Le3MJ1/PrHA== ARC-Message-Signature: i=1; a=rsa-sha256; d=lists.ozlabs.org; s=201707; t=1760661194; c=relaxed/relaxed; bh=yGJSKqxu0aNpKU4CMPi7Ju9DUaCLFSD0JC8SLGhbfdI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=WvPRTEBsd8Ggtw36wCAkONcb5pYctuqgUHGUhqP1gHVsAy09Ce62IETM46lD5Lqlar0QQg+Lk2TlssSF8xPVFMgtJdwkgyqCLVE94taYMUiVLEnM2POjTiV4+Mdw/IAMG3GeKjN3PojcbUTr4wZn9JWCPrBHghQsn0rMncL+Dg3TJfLHwPrFS3HbkyFYLcyXnnAUc3IVrtAur8VeG++whUiSPwkfg7sZIvG3irKzSliyAP6BEaM60+c/8c22oeJCacWWh2lQE7XZ+kT6/wRaauF6fJzdV+INGg3YZ1HYI62GS3hZ19Ntvh4Yei7epiZF7hloHbft/ppdfDRlSnBoug== ARC-Authentication-Results: i=1; lists.ozlabs.org; dmarc=pass (p=reject dis=none) header.from=google.com; dkim=pass (2048-bit key; unprotected) header.d=google.com header.i=@google.com header.a=rsa-sha256 header.s=20230601 header.b=IRi+sfJR; dkim-atps=neutral; spf=pass (client-ip=2607:f8b0:4864:20::1049; helo=mail-pj1-x1049.google.com; envelope-from=3yi7xaaykdpktfbokdhpphmf.dpnmjovyqqd-efwmjtut.p0mbct.psh@flex--seanjc.bounces.google.com; receiver=lists.ozlabs.org) smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: lists.ozlabs.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=google.com header.i=@google.com header.a=rsa-sha256 header.s=20230601 header.b=IRi+sfJR; dkim-atps=neutral Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=flex--seanjc.bounces.google.com (client-ip=2607:f8b0:4864:20::1049; helo=mail-pj1-x1049.google.com; envelope-from=3yi7xaaykdpktfbokdhpphmf.dpnmjovyqqd-efwmjtut.p0mbct.psh@flex--seanjc.bounces.google.com; receiver=lists.ozlabs.org) Received: from mail-pj1-x1049.google.com (mail-pj1-x1049.google.com [IPv6:2607:f8b0:4864:20::1049]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4cnm562pSWz3dBr for ; Fri, 17 Oct 2025 11:33:14 +1100 (AEDT) Received: by mail-pj1-x1049.google.com with SMTP id 98e67ed59e1d1-32eb18b5500so2174594a91.2 for ; Thu, 16 Oct 2025 17:33:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1760661193; x=1761265993; darn=lists.ozlabs.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=yGJSKqxu0aNpKU4CMPi7Ju9DUaCLFSD0JC8SLGhbfdI=; b=IRi+sfJR8H9zUnw/5OOYHsSafkTEWvMPk4gEv9zCMszO8zQwD5T6HYD/IrsOfjPmxn zN/EVbhwKXRvQ3IbQFQaPscMt5n/SqhXPf1dq1KWuStLlD6ehwavYqIzJ6aOsGNonrnC 1K690WRg9sleBrSSirTorY/IdPu97azUS80K1KsCc9eF3+UahRiylD22B+ZvqdI5lPPk nt1jBUS3rwrZ333h/1ofjmnJiom9OjGcles3fli1CclpSv/vNv7DSKRUd+PfbBc1ZjtL H6om/UIaLmL+g9OTyr6nRTj6l/RmKuB4NOd+283kLdcFbXtS3l0dDCsnlDJ3jAnvNkEX DW9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1760661193; x=1761265993; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=yGJSKqxu0aNpKU4CMPi7Ju9DUaCLFSD0JC8SLGhbfdI=; b=SUfgiEDNb+EkjYVIvuT5mlOVeCe8Ssb3CbY6sEWAgbmJN/Nz6r4s5Ck2d9HjArjAc6 UPpYowN2owGZ/nayo2q/LDJNMzzHDGrKLocyQihykuNmKVodI6he7KvToVGDjV7Jp3vH GCYHNQF25weVYDf5ysjvY8h4JeU9ZF449a+t6EOu3nQc4zMI8y+QiFKzidFBzHa0Sq12 vMr8GYVBXqpigmq02Yktka4Y0R/ymY/it/tk7FoGXAfyKJoT5YfuytXt3zqfCgpIk3tg IeUSAVvsa5QphQVc7QncqDHkMkAX+t3aPRsTbasdB3oR1bTZnQoHLvabW7VzRI+vJN3D zeiQ== X-Forwarded-Encrypted: i=1; AJvYcCXQr5fSPcMrf+VJ22pTaxfEw/Fu394sdTPmtgTMU0WtYaLCafQ9wdXQReA8vO50jWN3Rm3/c+MTLxtnEtU=@lists.ozlabs.org X-Gm-Message-State: AOJu0YyPfIVBjQpEW3n9XQGScZWRgsJhS/FkTipSnA+la2jJdATvUuOU O6V7sW8VUcwweH2IQZK5v3JT0HuQYK/9mz0XV85CmkUXAbl6vIAL0QVQ5CWsFy57cuXB3h6YQYN n/tFNfw== X-Google-Smtp-Source: AGHT+IHjaZ2dKb3gnqjzbrezKxoV9F/Lq4sC9R35D07gH2vTOnVl3FqHgnrEtTPEkkZOYMNEYP5euQorQsk= X-Received: from pjtu8.prod.google.com ([2002:a17:90a:c888:b0:32b:58d1:a610]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4c05:b0:339:ec9c:b275 with SMTP id 98e67ed59e1d1-33bcf84e181mr2234528a91.6.1760661192796; Thu, 16 Oct 2025 17:33:12 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 16 Oct 2025 17:32:32 -0700 In-Reply-To: <20251017003244.186495-1-seanjc@google.com> X-Mailing-List: linuxppc-dev@lists.ozlabs.org List-Id: List-Help: List-Owner: List-Post: List-Archive: , List-Subscribe: , , List-Unsubscribe: Precedence: list Mime-Version: 1.0 References: <20251017003244.186495-1-seanjc@google.com> X-Mailer: git-send-email 2.51.0.858.gf9c4a03a3a-goog Message-ID: <20251017003244.186495-15-seanjc@google.com> Subject: [PATCH v3 14/25] KVM: TDX: Bug the VM if extended the initial measurement fails From: Sean Christopherson To: Marc Zyngier , Oliver Upton , Tianrui Zhao , Bibo Mao , Huacai Chen , Madhavan Srinivasan , Anup Patel , Paul Walmsley , Palmer Dabbelt , Albert Ou , Christian Borntraeger , Janosch Frank , Claudio Imbrenda , Sean Christopherson , Paolo Bonzini , "Kirill A. Shutemov" Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, kvm@vger.kernel.org, loongarch@lists.linux.dev, linux-mips@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org, x86@kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org, Ira Weiny , Kai Huang , Michael Roth , Yan Zhao , Vishal Annapurve , Rick Edgecombe , Ackerley Tng , Binbin Wu Content-Type: text/plain; charset="UTF-8" WARN and terminate the VM if TDH_MR_EXTEND fails, as extending the measurement should fail if and only if there is a KVM bug, or if the S-EPT mapping is invalid, and it should be impossible for the S-EPT mappings to be removed between kvm_tdp_mmu_map_private_pfn() and tdh_mr_extend(). Holding slots_lock prevents zaps due to memslot updates, filemap_invalidate_lock() prevents zaps due to guest_memfd PUNCH_HOLE, and all usage of kvm_zap_gfn_range() is mutually exclusive with S-EPT entries that can be used for the initial image. The call from sev.c is obviously mutually exclusive, TDX disallows KVM_X86_QUIRK_IGNORE_GUEST_PAT so same goes for kvm_noncoherent_dma_assignment_start_or_stop, and while __kvm_set_or_clear_apicv_inhibit() can likely be tripped while building the image, the APIC page has its own non-guest_memfd memslot and so can't be used for the initial image, which means that too is mutually exclusive. Opportunistically switch to "goto" to jump around the measurement code, partly to make it clear that KVM needs to bail entirely if extending the measurement fails, partly in anticipation of reworking how and when TDH_MEM_PAGE_ADD is done. Fixes: d789fa6efac9 ("KVM: TDX: Handle vCPU dissociation") Signed-off-by: Yan Zhao Signed-off-by: Sean Christopherson --- arch/x86/kvm/vmx/tdx.c | 24 ++++++++++++++++-------- 1 file changed, 16 insertions(+), 8 deletions(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index c37591730cc5..f4bab75d3ffb 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -3151,14 +3151,22 @@ static int tdx_gmem_post_populate(struct kvm *kvm, gfn_t gfn, kvm_pfn_t pfn, KVM_BUG_ON(atomic64_dec_return(&kvm_tdx->nr_premapped) < 0, kvm); - if (arg->flags & KVM_TDX_MEASURE_MEMORY_REGION) { - for (i = 0; i < PAGE_SIZE; i += TDX_EXTENDMR_CHUNKSIZE) { - err = tdh_mr_extend(&kvm_tdx->td, gpa + i, &entry, - &level_state); - if (err) { - ret = -EIO; - break; - } + if (!(arg->flags & KVM_TDX_MEASURE_MEMORY_REGION)) + goto out; + + /* + * Note, MR.EXTEND can fail if the S-EPT mapping is somehow removed + * between mapping the pfn and now, but slots_lock prevents memslot + * updates, filemap_invalidate_lock() prevents guest_memfd updates, + * mmu_notifier events can't reach S-EPT entries, and KVM's internal + * zapping flows are mutually exclusive with S-EPT mappings. + */ + for (i = 0; i < PAGE_SIZE; i += TDX_EXTENDMR_CHUNKSIZE) { + err = tdh_mr_extend(&kvm_tdx->td, gpa + i, &entry, &level_state); + if (KVM_BUG_ON(err, kvm)) { + pr_tdx_error_2(TDH_MR_EXTEND, err, entry, level_state); + ret = -EIO; + goto out; } } -- 2.51.0.858.gf9c4a03a3a-goog