lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <6d817749-cb61-4406-9dfe-b8a0ef333a85@linux.intel.com>
Date: Thu, 13 Feb 2025 16:55:24 +0800
From: Binbin Wu <binbin.wu@...ux.intel.com>
To: Chao Gao <chao.gao@...el.com>
Cc: pbonzini@...hat.com, seanjc@...gle.com, kvm@...r.kernel.org,
 rick.p.edgecombe@...el.com, kai.huang@...el.com, adrian.hunter@...el.com,
 reinette.chatre@...el.com, xiaoyao.li@...el.com, tony.lindgren@...el.com,
 isaku.yamahata@...el.com, yan.y.zhao@...el.com, linux-kernel@...r.kernel.org
Subject: Re: [PATCH v2 08/17] KVM: TDX: Complete interrupts after TD exit



On 2/13/2025 4:20 PM, Chao Gao wrote:
>> +static void tdx_complete_interrupts(struct kvm_vcpu *vcpu)
>> +{
>> +	/* Avoid costly SEAMCALL if no NMI was injected. */
>> +	if (vcpu->arch.nmi_injected) {
>> +		/*
>> +		 * No need to request KVM_REQ_EVENT because PEND_NMI is still
>> +		 * set if NMI re-injection needed.  No other event types need
>> +		 * to be handled because TDX doesn't support injection of
>> +		 * exception, SMI or interrupt (via event injection).
>> +		 */
>> +		vcpu->arch.nmi_injected = td_management_read8(to_tdx(vcpu),
>> +							      TD_VCPU_PEND_NMI);
>> +	}
> Why does KVM care whether/when an NMI is injected by the TDX module?
>
> I think we can simply set nmi_injected to false unconditionally here, or even in
> tdx_inject_nmi(). From KVM's perspective, NMI injection is complete right after
> writing to PEND_NMI. It is the TDX module that should inject the NMI at the
> right time and do the re-injection.
Yes, it can/should be cleared unconditionally here.

Previously (v19 and before), nmi_injected will impact the limit of pending nmi.
Now, we don't care the limit of pending nmi because more pending NMIs will be
collapsed to the one pending in the TDX module.

Will update it.
Thanks!

>
>
>> +}
>> +


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ