Commit 127d0b8f authored by Vitaly Kuznetsov's avatar Vitaly Kuznetsov Committed by Zheng Zengkai
Browse files

x86/kvm: Teardown PV features on boot CPU as well

mainline inclusion
from mainline-v5.13-rc2
commit 8b79feff
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I990AA
CVE: CVE-2021-47112

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8b79feffeca28c5459458fe78676b081e87c93a4



---------------------------

Various PV features (Async PF, PV EOI, steal time) work through memory
shared with hypervisor and when we restore from hibernation we must
properly teardown all these features to make sure hypervisor doesn't
write to stale locations after we jump to the previously hibernated kernel
(which can try to place anything there). For secondary CPUs the job is
already done by kvm_cpu_down_prepare(), register syscore ops to do
the same for boot CPU.

Signed-off-by: default avatarVitaly Kuznetsov <vkuznets@redhat.com>
Message-Id: <20210414123544.1060604-3-vkuznets@redhat.com>
Signed-off-by: default avatarPaolo Bonzini <pbonzini@redhat.com>
Signed-off-by: default avatarZheng Zengkai <zhengzengkai@huawei.com>
parent 7875dd00
Loading
Loading
Loading
Loading
+41 −16
Original line number Diff line number Diff line
@@ -37,6 +37,7 @@
#include <linux/debugfs.h>
#include <linux/nmi.h>
#include <linux/swait.h>
#include <linux/syscore_ops.h>
#include <asm/timer.h>
#include <asm/cpu.h>
#include <asm/traps.h>
@@ -444,6 +445,25 @@ static void __init sev_map_percpu_data(void)
	}
}

static void kvm_guest_cpu_offline(void)
{
	kvm_disable_steal_time();
	if (kvm_para_has_feature(KVM_FEATURE_PV_EOI))
		wrmsrl(MSR_KVM_PV_EOI_EN, 0);
	kvm_pv_disable_apf();
	apf_task_wake_all();
}

static int kvm_cpu_online(unsigned int cpu)
{
	unsigned long flags;

	local_irq_save(flags);
	kvm_guest_cpu_init();
	local_irq_restore(flags);
	return 0;
}

#ifdef CONFIG_SMP
#define KVM_IPI_CLUSTER_SIZE	(2 * BITS_PER_LONG)

@@ -560,31 +580,34 @@ static void __init kvm_smp_prepare_boot_cpu(void)
	kvm_spinlock_init();
}

static void kvm_guest_cpu_offline(void)
static int kvm_cpu_down_prepare(unsigned int cpu)
{
	kvm_disable_steal_time();
	if (kvm_para_has_feature(KVM_FEATURE_PV_EOI))
		wrmsrl(MSR_KVM_PV_EOI_EN, 0);
	kvm_pv_disable_apf();
	apf_task_wake_all();
}
	unsigned long flags;

static int kvm_cpu_online(unsigned int cpu)
{
	local_irq_disable();
	kvm_guest_cpu_init();
	local_irq_enable();
	local_irq_save(flags);
	kvm_guest_cpu_offline();
	local_irq_restore(flags);
	return 0;
}

static int kvm_cpu_down_prepare(unsigned int cpu)
#endif

static int kvm_suspend(void)
{
	local_irq_disable();
	kvm_guest_cpu_offline();
	local_irq_enable();

	return 0;
 }
#endif

static void kvm_resume(void)
{
	kvm_cpu_online(raw_smp_processor_id());
}

static struct syscore_ops kvm_syscore_ops = {
	.suspend	= kvm_suspend,
	.resume		= kvm_resume,
};

static void __init kvm_apf_trap_init(void)
{
@@ -659,6 +682,8 @@ static void __init kvm_guest_init(void)
	kvm_guest_cpu_init();
#endif

	register_syscore_ops(&kvm_syscore_ops);

	/*
	 * Hard lockup detection is enabled by default. Disable it, as guests
	 * can get false positives too easily, for example if the host is