public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
From: Juergen Gross <jgross@suse.com>
To: "Michael Kelley (LINUX)" <mikelley@microsoft.com>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
	"x86@kernel.org" <x86@kernel.org>
Cc: "lists@nerdbynature.de" <lists@nerdbynature.de>,
	"torvalds@linux-foundation.org" <torvalds@linux-foundation.org>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Andy Lutomirski <luto@kernel.org>,
	Peter Zijlstra <peterz@infradead.org>,
	Thomas Gleixner <tglx@linutronix.de>,
	Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
	"H. Peter Anvin" <hpa@zytor.com>
Subject: Re: [PATCH v2 7/8] x86/mm: only check uniform after calling mtrr_type_lookup()
Date: Thu, 16 Feb 2023 06:22:17 +0100	[thread overview]
Message-ID: <174040b7-1a9f-ce7b-e615-c5d1521bcebd@suse.com> (raw)
In-Reply-To: <BYAPR21MB1688180BD889936A9B7CCDE3D7A39@BYAPR21MB1688.namprd21.prod.outlook.com>


[-- Attachment #1.1.1: Type: text/plain, Size: 4902 bytes --]

On 15.02.23 20:38, Michael Kelley (LINUX) wrote:
> From: Juergen Gross <jgross@suse.com> Sent: Wednesday, February 15, 2023 5:40 AM
>>
>> On 13.02.23 02:08, Michael Kelley (LINUX) wrote:
>>> From: Juergen Gross <jgross@suse.com> Sent: Wednesday, February 8, 2023 11:22
>> PM
>>>>
>>>> Today pud_set_huge() and pmd_set_huge() test for the MTRR type to be
>>>> WB or INVALID after calling mtrr_type_lookup(). Those tests can be
>>>> dropped, as the only reason to not use a large mapping would be
>>>> uniform being 0. Any MTRR type can be accepted as long as it applies
>>>> to the whole memory range covered by the mapping, as the alternative
>>>> would only be to map the same region with smaller pages instead using
>>>> the same PAT type as for the large mapping.
>>>>
>>>> Suggested-by: Linus Torvalds <torvalds@linux-foundation.org>
>>>> Signed-off-by: Juergen Gross <jgross@suse.com>
>>>> ---
>>>>    arch/x86/mm/pgtable.c | 6 ++----
>>>>    1 file changed, 2 insertions(+), 4 deletions(-)
>>>>
>>>> diff --git a/arch/x86/mm/pgtable.c b/arch/x86/mm/pgtable.c
>>>> index e4f499eb0f29..7b9c5443d176 100644
>>>> --- a/arch/x86/mm/pgtable.c
>>>> +++ b/arch/x86/mm/pgtable.c
>>>> @@ -721,8 +721,7 @@ int pud_set_huge(pud_t *pud, phys_addr_t addr, pgprot_t
>> prot)
>>>>    	u8 mtrr, uniform;
>>>>
>>>>    	mtrr = mtrr_type_lookup(addr, addr + PUD_SIZE, &uniform);
>>>> -	if ((mtrr != MTRR_TYPE_INVALID) && (!uniform) &&
>>>> -	    (mtrr != MTRR_TYPE_WRBACK))
>>>> +	if (!uniform)
>>>>    		return 0;
>>>>
>>>>    	/* Bail out if we are we on a populated non-leaf entry: */
>>>> @@ -748,8 +747,7 @@ int pmd_set_huge(pmd_t *pmd, phys_addr_t addr,
>> pgprot_t prot)
>>>>    	u8 mtrr, uniform;
>>>>
>>>>    	mtrr = mtrr_type_lookup(addr, addr + PMD_SIZE, &uniform);
>>>> -	if ((mtrr != MTRR_TYPE_INVALID) && (!uniform) &&
>>>> -	    (mtrr != MTRR_TYPE_WRBACK)) {
>>>> +	if (!uniform) {
>>>>    		pr_warn_once("%s: Cannot satisfy [mem %#010llx-%#010llx] with a
>> huge-page mapping due to MTRR override.\n",
>>>>    			     __func__, addr, addr + PMD_SIZE);
>>>
>>> I'm seeing this warning trigger in a normal Hyper-V guest (i.e., *not* an
>>> SEV-SNP Confidential VM).  The original filtering here based on
>>> MTRR_TYPE_WRBACK appears to be hiding a bug in mtrr_type_lookup_variable()
>>> where it incorrectly thinks an address range matches two different variable
>>> MTRRs, and hence clears "uniform".
>>>
>>> Here are the variable MTRRs in the normal Hyper-V guest with 32 GiBytes
>>> of memory:
>>>
>>> [    0.043592] MTRR variable ranges enabled:
>>> [    0.048308]   0 base 000000000000 mask FFFF00000000 write-back
>>> [    0.057450]   1 base 000100000000 mask FFF000000000 write-back
>>
>> I've read the SDM chapter for MTRRs again. Doesn't #1 violate the requirements
>> for MTRR settings? The SDM says:
>>
>>     For ranges greater than 4 KBytes, each range must be of length 2^n and its
>>     base address must be aligned on a 2^n boundary, where n is a value equal to
>>     or greater than 12. The base-address alignment value cannot be less than its
>>     length. For example, an 8-KByte range cannot be aligned on a 4-KByte boundary.
>>     It must be aligned on at least an 8-KByte boundary.
>>
>> This makes the reasoning below wrong.
> 
> Argh.  It sure looks like you are right.  I just assumed the MTRRs coming from
> Hyper-V were good.  Shame on me. :-(

I assumed the same, as I didn't see any flaw in your reasoning before. :-)

> I've ping'ed the Hyper-V team to see what they say.  But it's hard to see how
> they could argue that these MTRRs are correctly formed.  The Intel spec is
> unambiguous.
> 
> Even if Hyper-V agrees that the MTRRs are wrong, a fix will take time to
> propagate.  In the meantime, it seems like the Linux mitigations could be
> any of the following:
> 
> 1) Keep the test for WB in pud_set_huge() and pmd_set_huge()
> 
> 2) Remove the test, but have "uniform" set to 1 when multiple MTRRs are
>      matched but all have the same caching type, which you proposed to
>      solve Rick Edgecombe's problem.  This is likely to paper over the
>      problem I saw with the Hyper-V MTRRs because the incorrectly matching
>      MTRRs would all be WB.
> 
> 3) In *all* Hyper-V VMs (not just Confidential VMs), disable X86_FEATURE_MTRR
>      and use the new override to set the default type to WB.   Hopefully we don't
>      have to do this, but I can submit a separate patch if it becomes necessary.

4) Sanitize MTRRs in mtrr_cleanup(), resulting in MTRR#1 in your example to
    be modified to start at 0 (which would not really help to solve the
    multiple match you are seeing, but I'm about to solve that one, too, as
    the multiple MTRR match is allowed in the specs, but not really handled
    correctly in mtrr_type_lookup()).


Juergen

[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3149 bytes --]

[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]

  reply	other threads:[~2023-02-16  5:28 UTC|newest]

Thread overview: 65+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2023-02-09  7:22 [PATCH v2 0/8] x86/mtrr: fix handling with PAT but without MTRR Juergen Gross
2023-02-09  7:22 ` [PATCH v2 1/8] x86/mtrr: split off physical address size calculation Juergen Gross
2023-02-11 10:08   ` Borislav Petkov
2023-02-13  6:19     ` Juergen Gross
2023-02-09  7:22 ` [PATCH v2 2/8] x86/mtrr: support setting MTRR state for software defined MTRRs Juergen Gross
2023-02-13  1:07   ` Michael Kelley (LINUX)
2023-02-13  6:27     ` Juergen Gross
2023-02-13  6:43       ` Michael Kelley (LINUX)
2023-02-13 11:39   ` Borislav Petkov
2023-02-13 14:07     ` Juergen Gross
2023-02-13 15:03       ` Borislav Petkov
2023-02-13 15:11         ` Borislav Petkov
2023-02-13 15:18           ` Juergen Gross
2023-02-13 15:40             ` Borislav Petkov
2023-02-13 15:44               ` Juergen Gross
2023-02-13 18:53                 ` Borislav Petkov
2023-02-14  7:04                   ` Juergen Gross
2023-02-14  8:58                     ` Borislav Petkov
2023-02-14  9:02                       ` Juergen Gross
2023-02-14  9:10                         ` Borislav Petkov
2023-02-14  9:17                           ` Juergen Gross
2023-02-14  9:32                             ` Borislav Petkov
2023-02-13 15:27           ` Dave Hansen
2023-02-13 15:38             ` Juergen Gross
2023-02-13 15:36         ` Juergen Gross
2023-02-13 18:43           ` Borislav Petkov
2023-02-14  7:01             ` Juergen Gross
2023-02-14  0:45       ` Kirill A. Shutemov
2023-02-16  9:32     ` Juergen Gross
2023-02-16 11:02       ` Jeremi Piotrowski
2023-02-16 11:25       ` Borislav Petkov
2023-02-16 12:19         ` Juergen Gross
2023-02-16 12:29           ` Borislav Petkov
2023-02-16 16:04             ` Michael Kelley (LINUX)
2023-02-16 11:07     ` Jeremi Piotrowski
2023-02-16 11:27       ` Borislav Petkov
2023-02-09  7:22 ` [PATCH v2 3/8] x86/hyperv: set MTRR state when running as SEV-SNP Hyper-V guest Juergen Gross
2023-02-13  1:07   ` Michael Kelley (LINUX)
2023-02-13  6:28     ` Juergen Gross
2023-02-09  7:22 ` [PATCH v2 4/8] x86/xen: set MTRR state when running as Xen PV initial domain Juergen Gross
2023-02-09  7:22 ` [PATCH v2 5/8] x86/mtrr: revert commit 90b926e68f50 Juergen Gross
2023-02-10 18:59   ` Linux regression tracking (Thorsten Leemhuis)
2023-02-13  6:07     ` Juergen Gross
2023-02-13 11:46       ` Christian Kujau
2023-02-13 16:23         ` Juergen Gross
2023-02-13 17:01           ` Michael Kelley (LINUX)
2023-02-13 17:24             ` Juergen Gross
2023-02-13 22:54           ` Christian Kujau
2023-02-14  7:13             ` Juergen Gross
2023-02-09  7:22 ` [PATCH v2 6/8] x86/mtrr: don't let mtrr_type_lookup() return MTRR_TYPE_INVALID Juergen Gross
2023-02-09  7:22 ` [PATCH v2 7/8] x86/mm: only check uniform after calling mtrr_type_lookup() Juergen Gross
2023-02-11  0:06   ` Edgecombe, Rick P
2023-02-13  6:08     ` Juergen Gross
2023-02-13  1:08   ` Michael Kelley (LINUX)
2023-02-13  6:35     ` Juergen Gross
2023-02-15 13:40     ` Juergen Gross
2023-02-15 19:38       ` Michael Kelley (LINUX)
2023-02-16  5:22         ` Juergen Gross [this message]
2023-02-09  7:22 ` [PATCH v2 8/8] x86/mtrr: drop sanity check in mtrr_type_lookup_fixed() Juergen Gross
2023-02-11  0:06 ` [PATCH v2 0/8] x86/mtrr: fix handling with PAT but without MTRR Edgecombe, Rick P
2023-02-13  6:12   ` Juergen Gross
2023-02-13 18:21     ` Edgecombe, Rick P
2023-02-15  8:25       ` Juergen Gross
2023-02-15 23:22         ` Linus Torvalds
2023-02-16  5:35           ` Juergen Gross

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=174040b7-1a9f-ce7b-e615-c5d1521bcebd@suse.com \
    --to=jgross@suse.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lists@nerdbynature.de \
    --cc=luto@kernel.org \
    --cc=mikelley@microsoft.com \
    --cc=mingo@redhat.com \
    --cc=peterz@infradead.org \
    --cc=tglx@linutronix.de \
    --cc=torvalds@linux-foundation.org \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox