Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1369949
| From | Andy Lutomirski <luto@kernel.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH v5 0/9] Improve non-"safe" MSR access failure handling |
| Date | 2016-04-02 16:10 +0200 |
| Message-ID | <rjups-4TG-5@gated-at.bofh.it> (permalink) |
| Organization | linux.* mail to news gateway |
There are two parts here:
***** FIRST PART: EARLY EXCEPTIONS *****
The first few patches move some early panic code into C, add pt_regs
to early exception handling, and make fancy exception handlers work early.
***** SECOND PART: MSRs *****
Setting CONFIG_PARAVIRT=y has an unintended side effect: it silently
turns all rdmsr and wrmsr operations into the safe variants without
any checks that the operations actually succeed.
With CONFIG_PARAVIRT=n, unchecked MSR failures OOPS and probably
cause boot to fail if they happen before init starts.
Neither behavior is very good, and it's particularly unfortunate that
the behavior changes depending on CONFIG_PARAVIRT.
In particular, KVM guests might be unwittingly depending on the
PARAVIRT=y behavior because CONFIG_KVM_GUEST currently depends on
CONFIG_PARAVIRT, and, because accesses in that case are completely
unchecked, we wouldn't even see a warning.
This series changes the native behavior, regardless of
CONFIG_PARAVIRT. A non-"safe" MSR failure will give an informative
warning once and will be fixed up -- native_read_msr will return
zero, and both reads and writes will continue where they left off.
If panic_on_oops is set, they will still OOPS and panic.
By using the shiny new custom exception handler infrastructure,
there should be no overhead on the success paths.
I didn't change the behavior on Xen, but, with this series applied,
it would be straightforward for the Xen maintainers to make the
corresponding change -- knowledge of whether the access is "safe" is
now propagated into the pvops.
Doing this is probably a prerequisite to sanely decoupling
CONFIG_KVM_GUEST and CONFIG_PARAVIRT, which would probably make
Arjan and the rest of the Clear Containers people happy :)
There's also room to reduce the code size of the "safe" variants
using custom exception handlers in the future.
Changes from v4:
- Fix a missing \n (Joe Perches)
- No more panic_on_oops
- Works early
Changes from v3:
- WARN_ONCE instead of WARN (Ingo)
- In the warning text, s/unsafe/unchecked/ (Ingo, sort of)
Changes from earlier versions: lots of changes!
Andy Lutomirski (9):
x86/head: Pass a real pt_regs and trapnr to early_fixup_exception
x86/head: Move the early NMI fixup into C
x86/head: Move early exception panic code into early_fixup_exception
x86/traps: Enable all exception handler callbacks early
x86/paravirt: Add _safe to the read_msr and write_msr PV hooks
x86/msr: Carry on after a non-"safe" MSR access fails
x86/paravirt: Add paravirt_{read,write}_msr
x86/paravirt: Make "unsafe" MSR accesses unsafe even if PARAVIRT=y
x86/msr: Set the return value to zero when native_rdmsr_safe fails
arch/x86/include/asm/msr.h | 20 ++++--
arch/x86/include/asm/paravirt.h | 45 +++++++------
arch/x86/include/asm/paravirt_types.h | 14 ++--
arch/x86/include/asm/uaccess.h | 2 +-
arch/x86/kernel/head_32.S | 116 ++++++++++++++--------------------
arch/x86/kernel/head_64.S | 95 ++++++++--------------------
arch/x86/kernel/paravirt.c | 6 +-
arch/x86/mm/extable.c | 64 +++++++++++++++----
arch/x86/xen/enlighten.c | 27 +++++++-
9 files changed, 208 insertions(+), 181 deletions(-)
--
2.5.5
Back to linux.kernel | Previous | Next — Next in thread | Find similar | Unroll thread
[PATCH v5 0/9] Improve non-"safe" MSR access failure handling Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[PATCH v5 5/9] x86/paravirt: Add _safe to the read_msr and write_msr PV hooks Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
Re: [PATCH v5 5/9] x86/paravirt: Add _safe to the read_msr and write_msr PV hooks Borislav Petkov <bp@alien8.de> - 2016-04-03 10:50 +0200
Re: [PATCH v5 5/9] x86/paravirt: Add _safe to the read_msr and write_msr PV hooks Andy Lutomirski <luto@amacapital.net> - 2016-04-03 15:30 +0200
Re: [PATCH v5 5/9] x86/paravirt: Add _safe to the read_msr and write_msr PV hooks Borislav Petkov <bp@alien8.de> - 2016-04-03 16:10 +0200
[tip:x86/asm] x86/paravirt: Add _safe to the read_ms()r and write_msr() PV callbacks tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 8/9] x86/paravirt: Make "unsafe" MSR accesses unsafe even if PARAVIRT=y Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[tip:x86/asm] x86/paravirt: Make "unsafe" MSR accesses unsafe even if PARAVIRT=y tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 2/9] x86/head: Move the early NMI fixup into C Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[tip:x86/asm] x86/head: Move the early NMI fixup into C tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Borislav Petkov <bp@alien8.de> - 2016-04-02 20:40 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Andy Lutomirski <luto@amacapital.net> - 2016-04-02 22:20 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Borislav Petkov <bp@alien8.de> - 2016-04-02 22:50 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Andy Lutomirski <luto@amacapital.net> - 2016-04-02 23:00 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Jan Kara <jack@suse.cz> - 2016-04-04 14:00 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Peter Zijlstra <peterz@infradead.org> - 2016-04-04 14:50 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Arjan van de Ven <arjan@linux.intel.com> - 2016-04-04 17:40 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Andy Lutomirski <luto@amacapital.net> - 2016-04-04 17:40 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Peter Zijlstra <peterz@infradead.org> - 2016-04-04 18:10 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Borislav Petkov <bp@alien8.de> - 2016-04-04 21:40 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Andy Lutomirski <luto@amacapital.net> - 2016-04-04 23:40 +0200
Re: [PATCH v5 3/9] x86/head: Move early exception panic code into early_fixup_exception Borislav Petkov <bp@alien8.de> - 2016-04-04 23:50 +0200
[tip:x86/asm] x86/head: Move early exception panic code into early_fixup_exception() tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 7/9] x86/paravirt: Add paravirt_{read,write}_msr Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
Re: [Xen-devel] [PATCH v5 7/9] x86/paravirt: Add paravirt_{read, write}_msr David Vrabel <david.vrabel@citrix.com> - 2016-04-04 18:40 +0200
Re: [Xen-devel] [PATCH v5 7/9] x86/paravirt: Add paravirt_{read, write}_msr Andy Lutomirski <luto@amacapital.net> - 2016-04-04 18:50 +0200
[tip:x86/asm] x86/paravirt: Add paravirt_{read,write}_msr() tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 1/9] x86/head: Pass a real pt_regs and trapnr to early_fixup_exception Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[tip:x86/asm] x86/head: Pass a real pt_regs and trapnr to early_fixup_exception() tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 6/9] x86/msr: Carry on after a non-"safe" MSR access fails Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[tip:x86/asm] x86/msr: Carry on after a non-"safe" MSR access fails tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
[PATCH v5 9/9] x86/msr: Set the return value to zero when native_rdmsr_safe fails Andy Lutomirski <luto@kernel.org> - 2016-04-02 16:10 +0200
[tip:x86/asm] x86/msr: Set the return value to zero when native_rdmsr_safe() fails tip-bot for Andy Lutomirski <tipbot@zytor.com> - 2016-04-13 13:50 +0200
Re: [PATCH v5 0/9] Improve non-"safe" MSR access failure handling Linus Torvalds <torvalds@linux-foundation.org> - 2016-04-02 16:30 +0200
Re: [PATCH v5 0/9] Improve non-"safe" MSR access failure handling Andy Lutomirski <luto@amacapital.net> - 2016-04-02 17:20 +0200
Re: [PATCH v5 0/9] Improve non-"safe" MSR access failure handling Linus Torvalds <torvalds@linux-foundation.org> - 2016-04-02 17:30 +0200
Re: [PATCH v5 0/9] Improve non-"safe" MSR access failure handling Borislav Petkov <bp@alien8.de> - 2016-04-04 18:30 +0200
Re: [Xen-devel] [PATCH v5 0/9] Improve non-"safe" MSR access failure handling Boris Ostrovsky <boris.ostrovsky@oracle.com> - 2016-04-05 17:40 +0200
csiph-web