Path: csiph.com!2.eu.feeder.erje.net!feeder.erje.net!1.eu.feeder.erje.net!news.unit0.net!news.panservice.it!diesel.cu.mi.it!bofh.it!news.nic.it!robomod From: Wanpeng Li Newsgroups: linux.kernel Subject: Re: [PATCH v2 2/3] KVM: VMX: Fix enable VPID even if INVVPID is not exposed in vmx capability Date: Tue, 21 Mar 2017 10:00:02 +0100 Message-ID: References: Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-transfer-encoding; bh=8+fp/mC1VlBVMc+UvMeyw+mOK/ahBbyi26UqKOv2SlU=; b=UWd5BAFn9ukE75baI1pCsY3nmuiThrvw/G9/PM7AexzDLz6XhC0aD9aIfZPFycXse9 Am2iFfzT6zwTc5EFbl+Gbvc0WUFY4vLpak9A77FCDuVk1r0d5adxfSWAOmdIDnnJEMak FSdvJJFApAFnuWpd2SsGAfPk9Q9hWrxHT1/5jw3ioqo0cVHJdKoho3RAmg+FwUUTNG+s QCDtIAzEpKVTJ4ejVb/HVRfSopkumOKYxU3Nplelui3zDhujHf8WXZT3mPRgTXjduzPw GjsLBo+7rfR9pZhko/cEa6CoFM8jWB045oBumlQskP5NvWPaFe1g4HvQ4dNokHCRzGMG 0T8w== X-Google-Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-transfer-encoding; bh=8+fp/mC1VlBVMc+UvMeyw+mOK/ahBbyi26UqKOv2SlU=; b=IQ4EfVhbd1vNpDUsb5zTGRyGW37doEDPuu6+k2WauBeJZ2DbSBNTNhsHIsu+8gTdx6 GBLcg707pP+Y3yUGl1dLCkZjeM3bNyeOdcifWoUP4vKCV1dgc4NOe2lXWz2o31REYvGY O7R/aYoL9CMikN4Ie9+1a2nMSqeTL4z6gFs1PtLJBN5cjtggBnKiQf7Y5bQmyryQCJJP zkXngGQKWltqab0A82p91yJVxRsP20NpCwaUr9seL1HTPcDu/1V68G5/8jY3LuAZq4OK P1+R5kKE95Veh8WXsyBSvTv8Id9az6wuoZA2WzjfM0eTeJkZm2kt6XGX8DfYGTVofnNd CVaA== X-Gm-Message-State: AFeK/H3G67RX2xPU8zOeiZ+1l7ZTKKsia12UIwnvZ6twcTNLxA9DnmIHI8w9M+u8Lbn2aBLHwoLA9gxdmk75/A== X-Received: by 10.223.139.154 with SMTP id o26mr27988960wra.56.1490086725832; Tue, 21 Mar 2017 01:58:45 -0700 (PDT) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable Sender: robomod@news.nic.it List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Approved: robomod@news.nic.it Lines: 111 Organization: linux.* mail to news gateway X-Original-Cc: "linux-kernel@vger.kernel.org" , kvm , Paolo Bonzini , =?UTF-8?B?UmFkaW0gS3LEjW3DocWZ?= , Wanpeng Li X-Original-Date: Tue, 21 Mar 2017 16:58:45 +0800 X-Original-Message-ID: X-Original-References: <1490069935-6232-1-git-send-email-wanpeng.li@hotmail.com> <1490069935-6232-2-git-send-email-wanpeng.li@hotmail.com> <6b112918-a785-bf87-71c4-8649915e7772@redhat.com> X-Original-Sender: linux-kernel-owner@vger.kernel.org Xref: csiph.com linux.kernel:1605441 2017-03-21 16:50 GMT+08:00 David Hildenbrand : > On 21.03.2017 05:18, Wanpeng Li wrote: >> From: Wanpeng Li >> >> This can be reproduced by running L2 on L1, and disable VPID on L0 if w/= o >> commit "KVM: nVMX: Fix nested VPID vmx exec control", the L2 crash as be= low: >> >> KVM: entry failed, hardware error 0x7 >> EAX=3D00000000 EBX=3D00000000 ECX=3D00000000 EDX=3D000306c3 >> ESI=3D00000000 EDI=3D00000000 EBP=3D00000000 ESP=3D00000000 >> EIP=3D0000fff0 EFL=3D00000002 [-------] CPL=3D0 II=3D0 A20=3D1 SMM=3D0 H= LT=3D0 >> ES =3D0000 00000000 0000ffff 00009300 >> CS =3Df000 ffff0000 0000ffff 00009b00 >> SS =3D0000 00000000 0000ffff 00009300 >> DS =3D0000 00000000 0000ffff 00009300 >> FS =3D0000 00000000 0000ffff 00009300 >> GS =3D0000 00000000 0000ffff 00009300 >> LDT=3D0000 00000000 0000ffff 00008200 >> TR =3D0000 00000000 0000ffff 00008b00 >> GDT=3D 00000000 0000ffff >> IDT=3D 00000000 0000ffff >> CR0=3D60000010 CR2=3D00000000 CR3=3D00000000 CR4=3D00000000 >> DR0=3D0000000000000000 DR1=3D0000000000000000 DR2=3D0000000000000000 DR3= =3D0000000000000000 >> DR6=3D00000000ffff0ff0 DR7=3D0000000000000400 >> EFER=3D0000000000000000 >> >> Reference SDM 30.3 INVVPID: >> >> Protected Mode Exceptions >> #UD >> - If not in VMX operation. >> - If the logical processor does not support VPIDs (IA32_VMX_PROCBASED_= CTLS2[37]=3D0). >> - If the logical processor supports VPIDs (IA32_VMX_PROCBASED_CTLS2[37= ]=3D1) but does >> not support the INVVPID instruction (IA32_VMX_EPT_VPID_CAP[32]=3D0). >> >> So we should check both VPID enable bit in vmx exec control and INVVPID = support bit >> in vmx capability MSRs to enable VPID. This patch adds the guarantee to = not enable VPID >> if INVVPID is not exposed in vmx capability MSRs. >> > > Makes sense to me. Wonder how many systems are out there that have VPID > but not INVVPID? Or will this never happen on real hardware? At least this will not happen on the real hardware on my hands. > >> Cc: Paolo Bonzini >> Cc: Radim Kr=C4=8Dm=C3=A1=C5=99 >> Signed-off-by: Wanpeng Li >> --- >> arch/x86/kvm/vmx.c | 9 ++++++++- >> 1 file changed, 8 insertions(+), 1 deletion(-) >> >> diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c >> index 06d8080..b310214 100644 >> --- a/arch/x86/kvm/vmx.c >> +++ b/arch/x86/kvm/vmx.c >> @@ -1239,6 +1239,11 @@ static inline bool cpu_has_vmx_invvpid_global(voi= d) >> return vmx_capability.vpid & VMX_VPID_EXTENT_GLOBAL_CONTEXT_BIT; >> } >> >> +static inline bool cpu_has_vmx_invvpid(void) >> +{ >> + return vmx_capability.vpid & VMX_VPID_INVVPID_BIT; >> +} >> + >> static inline bool cpu_has_vmx_ept(void) >> { >> return vmcs_config.cpu_based_2nd_exec_ctrl & >> @@ -6519,8 +6524,10 @@ static __init int hardware_setup(void) >> if (boot_cpu_has(X86_FEATURE_NX)) >> kvm_enable_efer_bits(EFER_NX); >> >> - if (!cpu_has_vmx_vpid()) >> + if (!cpu_has_vmx_vpid() || >> + !(cpu_has_vmx_invvpid())) > > This indentation looks weird. Can't this be fit into one line? The same as cpu_has_vmx_ept_4levels(). > >> enable_vpid =3D 0; >> + > > unrelated change To make the vpid codes more clear. Please refer to other callees in hardware_setup(). > >> if (!cpu_has_vmx_shadow_vmcs()) >> enable_shadow_vmcs =3D 0; >> if (enable_shadow_vmcs) >> > > > -- > > Thanks, > > David