lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date:   Thu, 16 May 2019 16:25:13 +0800
From:   Luwei Kang <luwei.kang@...el.com>
To:     linux-kernel@...r.kernel.org, kvm@...r.kernel.org
Cc:     tglx@...utronix.de, mingo@...hat.com, bp@...en8.de, hpa@...or.com,
        x86@...nel.org, pbonzini@...hat.com, rkrcmar@...hat.com,
        Luwei Kang <luwei.kang@...el.com>
Subject: [PATCH v1 5/6] KVM: VMX: Intel PT configration context switch using XSAVES/XRSTORS

This patch add the support of using XSAVES/XRSTORS to
do the Intel processor trace context switch.

Because of native driver didn't set the XSS[bit8] to enabled
the PT state in xsave area, so this patch only set this bit
before XSAVE/XRSTORS intstuction executtion and restore the
original value after.

The flag "initialized" need to be cleared when PT is change
from enabled to disabled. Guest may modify PT MSRs when PT
is disabled and they are only saved in variables.
We need to reload these value to HW manual when PT is enabled.

Signed-off-by: Luwei Kang <luwei.kang@...el.com>
---
 arch/x86/kvm/vmx/vmx.c | 80 ++++++++++++++++++++++++++++++++++++++++----------
 1 file changed, 65 insertions(+), 15 deletions(-)

diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
index 4691665..d323e6b 100644
--- a/arch/x86/kvm/vmx/vmx.c
+++ b/arch/x86/kvm/vmx/vmx.c
@@ -1002,33 +1002,83 @@ static inline void pt_save_msr(struct pt_state *ctx, u32 addr_range)
 
 static void pt_guest_enter(struct vcpu_vmx *vmx)
 {
+	struct pt_desc *desc;
+	int err;
+
 	if (pt_mode == PT_MODE_SYSTEM)
 		return;
 
-	/*
-	 * GUEST_IA32_RTIT_CTL is already set in the VMCS.
-	 * Save host state before VM entry.
-	 */
-	rdmsrl(MSR_IA32_RTIT_CTL, vmx->pt_desc->host_ctx->rtit_ctl);
-	if (vmx->pt_desc->guest_ctx->rtit_ctl & RTIT_CTL_TRACEEN) {
-		wrmsrl(MSR_IA32_RTIT_CTL, 0);
-		pt_save_msr(vmx->pt_desc->host_ctx, vmx->pt_desc->addr_range);
-		pt_load_msr(vmx->pt_desc->guest_ctx, vmx->pt_desc->addr_range);
+	desc = vmx->pt_desc;
+
+	rdmsrl(MSR_IA32_RTIT_CTL, desc->host_ctx->rtit_ctl);
+
+	if (desc->guest_ctx->rtit_ctl & RTIT_CTL_TRACEEN) {
+		if (likely(desc->pt_xsave)) {
+			wrmsrl(MSR_IA32_XSS, host_xss | XFEATURE_MASK_PT);
+			/*
+			 * XSAVES instruction will clears the TeaceEn after
+			 * saving the value of RTIT_CTL and before saving any
+			 * other PT state.
+			 */
+			XSTATE_XSAVE(&desc->host_xs->state.xsave,
+						XFEATURE_MASK_PT, 0, err);
+			/*
+			 * Still need to load the guest PT state manual if
+			 * PT stste not populated in xsave area.
+			 */
+			if (desc->guest_xs->initialized)
+				XSTATE_XRESTORE(&desc->guest_xs->state.xsave,
+						XFEATURE_MASK_PT, 0);
+			else
+				pt_load_msr(desc->guest_ctx, desc->addr_range);
+
+			wrmsrl(MSR_IA32_XSS, host_xss);
+		} else {
+			if (desc->host_ctx->rtit_ctl & RTIT_CTL_TRACEEN)
+				wrmsrl(MSR_IA32_RTIT_CTL, 0);
+
+			pt_save_msr(desc->host_ctx, desc->addr_range);
+			pt_load_msr(desc->guest_ctx, desc->addr_range);
+		}
 	}
 }
 
 static void pt_guest_exit(struct vcpu_vmx *vmx)
 {
+	struct pt_desc *desc;
+	int err;
+
 	if (pt_mode == PT_MODE_SYSTEM)
 		return;
 
-	if (vmx->pt_desc->guest_ctx->rtit_ctl & RTIT_CTL_TRACEEN) {
-		pt_save_msr(vmx->pt_desc->guest_ctx, vmx->pt_desc->addr_range);
-		pt_load_msr(vmx->pt_desc->host_ctx, vmx->pt_desc->addr_range);
-	}
+	desc = vmx->pt_desc;
+
+	if (desc->guest_ctx->rtit_ctl & RTIT_CTL_TRACEEN) {
+		if (likely(desc->pt_xsave)) {
+			wrmsrl(MSR_IA32_XSS, host_xss | XFEATURE_MASK_PT);
+			/*
+			 * Save guest state. TraceEn is 0 before and after
+			 * XSAVES instruction because RTIT_CTL will be cleared
+			 * on VM-exit (VM Exit control bit25).
+			 */
+			XSTATE_XSAVE(&desc->guest_xs->state.xsave,
+						XFEATURE_MASK_PT, 0, err);
+			desc->guest_xs->initialized = 1;
+			/*
+			 * Resume host PT state and PT may enabled after this
+			 * instruction if host PT is enabled before VM-entry.
+			 */
+			XSTATE_XRESTORE(&desc->host_xs->state.xsave,
+						XFEATURE_MASK_PT, 0);
+			wrmsrl(MSR_IA32_XSS, host_xss);
+		} else {
+			pt_save_msr(desc->guest_ctx, desc->addr_range);
+			pt_load_msr(desc->host_ctx, desc->addr_range);
 
-	/* Reload host state (IA32_RTIT_CTL will be cleared on VM exit). */
-	wrmsrl(MSR_IA32_RTIT_CTL, vmx->pt_desc->host_ctx->rtit_ctl);
+			wrmsrl(MSR_IA32_RTIT_CTL, desc->host_ctx->rtit_ctl);
+		}
+	} else if (desc->host_ctx->rtit_ctl & RTIT_CTL_TRACEEN)
+		wrmsrl(MSR_IA32_RTIT_CTL, desc->host_ctx->rtit_ctl);
 }
 
 static int pt_init(struct vcpu_vmx *vmx)
-- 
1.8.3.1

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ