mirror of
https://github.com/torvalds/linux.git
synced 2024-11-10 22:21:40 +00:00
KVM: SVM: Never reject emulation due to SMAP errata for !SEV guests
Always signal that emulation is possible for !SEV guests regardless of
whether or not the CPU provided a valid instruction byte stream. KVM can
read all guest state (memory and registers) for !SEV guests, i.e. can
fetch the code stream from memory even if the CPU failed to do so because
of the SMAP errata.
Fixes: 05d5a48635
("KVM: SVM: Workaround errata#1096 (insn_len maybe zero on SMAP violation)")
Cc: stable@vger.kernel.org
Cc: Tom Lendacky <thomas.lendacky@amd.com>
Cc: Brijesh Singh <brijesh.singh@amd.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Reviewed-by: Liam Merwick <liam.merwick@oracle.com>
Message-Id: <20220120010719.711476-2-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
This commit is contained in:
parent
47c28d436f
commit
55467fcd55
@ -4258,8 +4258,13 @@ static bool svm_can_emulate_instruction(struct kvm_vcpu *vcpu, void *insn, int i
|
|||||||
bool smep, smap, is_user;
|
bool smep, smap, is_user;
|
||||||
unsigned long cr4;
|
unsigned long cr4;
|
||||||
|
|
||||||
|
/* Emulation is always possible when KVM has access to all guest state. */
|
||||||
|
if (!sev_guest(vcpu->kvm))
|
||||||
|
return true;
|
||||||
|
|
||||||
/*
|
/*
|
||||||
* When the guest is an SEV-ES guest, emulation is not possible.
|
* Emulation is impossible for SEV-ES guests as KVM doesn't have access
|
||||||
|
* to guest register state.
|
||||||
*/
|
*/
|
||||||
if (sev_es_guest(vcpu->kvm))
|
if (sev_es_guest(vcpu->kvm))
|
||||||
return false;
|
return false;
|
||||||
@ -4319,9 +4324,6 @@ static bool svm_can_emulate_instruction(struct kvm_vcpu *vcpu, void *insn, int i
|
|||||||
smap = cr4 & X86_CR4_SMAP;
|
smap = cr4 & X86_CR4_SMAP;
|
||||||
is_user = svm_get_cpl(vcpu) == 3;
|
is_user = svm_get_cpl(vcpu) == 3;
|
||||||
if (smap && (!smep || is_user)) {
|
if (smap && (!smep || is_user)) {
|
||||||
if (!sev_guest(vcpu->kvm))
|
|
||||||
return true;
|
|
||||||
|
|
||||||
pr_err_ratelimited("KVM: SEV Guest triggered AMD Erratum 1096\n");
|
pr_err_ratelimited("KVM: SEV Guest triggered AMD Erratum 1096\n");
|
||||||
kvm_make_request(KVM_REQ_TRIPLE_FAULT, vcpu);
|
kvm_make_request(KVM_REQ_TRIPLE_FAULT, vcpu);
|
||||||
}
|
}
|
||||||
|
Loading…
Reference in New Issue
Block a user