From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752871AbeBZMRA (ORCPT ); Mon, 26 Feb 2018 07:17:00 -0500 Received: from mx3-rdu2.redhat.com ([66.187.233.73]:34634 "EHLO mx1.redhat.com" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1752353AbeBZMQ6 (ORCPT ); Mon, 26 Feb 2018 07:16:58 -0500 Subject: Re: [PATCH] KVM: X86: Allow userspace to define the microcode version To: Borislav Petkov Cc: Wanpeng Li , LKML , kvm , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= References: <20180226094148.GA15539@pd.tnic> <20180226104921.GA4377@pd.tnic> <20180226111630.GB4377@pd.tnic> <20180226113000.GC4377@pd.tnic> <20180226114409.GD4377@pd.tnic> <46cecef2-b0fb-b0c2-bbf3-983328d52763@redhat.com> <20180226121509.GE4377@pd.tnic> From: Paolo Bonzini Message-ID: <24cd527d-5287-f0be-ffe8-eab341bf1d94@redhat.com> Date: Mon, 26 Feb 2018 13:16:56 +0100 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.6.0 MIME-Version: 1.0 In-Reply-To: <20180226121509.GE4377@pd.tnic> Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org On 26/02/2018 13:15, Borislav Petkov wrote: > On Mon, Feb 26, 2018 at 12:54:52PM +0100, Paolo Bonzini wrote: >> I don't understand how one thing follows from the other. How are writes >> to 0x8B related to having a virtualized microcode loaded (which is a >> concept that actually makes no sense at all)? > > I'm questioning the whole idea. 0x8b is the MSR which gives you the > microcode revision. Most CPUs don't even allow writing to it, AFAICT. > (SDM says "may prevent writing" on VM transitions.) > > So how is that host-initiated write to 0x8b is even going to work, in > reality? kvm module writes the microcode version in there? How does the > admin work around that? In this context, "host-initiated" write means written by KVM userspace with ioctl(KVM_SET_MSR). It generally happens only on VM startup, reset or live migration. Thanks, Paolo >> It has already been fixed for a few months, and fixing it is indeed the >> right thing to do independent of this patch. > > Yap. >