android_kernel_motorola_sm6375/arch
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Sean Christopherson e40bde8a28 KVM: nVMX: Snapshot pre-VM-Enter DEBUGCTL for !nested_run_pending case
commit 764643a6be07445308e492a528197044c801b3ba upstream.

If a nested run isn't pending, snapshot vmcs01.GUEST_IA32_DEBUGCTL
irrespective of whether or not VM_ENTRY_LOAD_DEBUG_CONTROLS is set in
vmcs12.  When restoring nested state, e.g. after migration, without a
nested run pending, prepare_vmcs02() will propagate
nested.vmcs01_debugctl to vmcs02, i.e. will load garbage/zeros into
vmcs02.GUEST_IA32_DEBUGCTL.

If userspace restores nested state before MSRs, then loading garbage is a
non-issue as loading DEBUGCTL will also update vmcs02.  But if usersepace
restores MSRs first, then KVM is responsible for propagating L2's value,
which is actually thrown into vmcs01, into vmcs02.

Restoring L2 MSRs into vmcs01, i.e. loading all MSRs before nested state
is all kinds of bizarre and ideally would not be supported.  Sadly, some
VMMs do exactly that and rely on KVM to make things work.

Note, there's still a lurking SMM bug, as propagating vmcs01's DEBUGCTL
to vmcs02 across RSM may corrupt L2's DEBUGCTL.  But KVM's entire VMX+SMM
emulation is flawed as SMI+RSM should not toouch _any_ VMCS when use the
"default treatment of SMIs", i.e. when not using an SMI Transfer Monitor.

Link: https://lore.kernel.org/all/Yobt1XwOfb5M6Dfa@google.com
Fixes: 8fcc4b5923 ("kvm: nVMX: Introduce KVM_CAP_NESTED_STATE")
Cc: stable@vger.kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-Id: <20220614215831.3762138-3-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2022-08-25 11:17:19 +02:00
..
alpha tty: the rest, stop using tty_schedule_flip() 2022-07-29 17:14:19 +02:00
arc
arm ARM: crypto: comment out gcc warning that breaks clang builds 2022-08-03 11:59:41 +02:00
arm64 locking/refcount: Consolidate implementations of refcount_t 2022-07-29 17:14:17 +02:00
c6x
csky
h8300
hexagon
ia64 ia64: define get_cycles macro for arch-override 2022-06-22 14:11:14 +02:00
m68k m68k: use fallback for random_get_entropy() instead of zero 2022-06-22 14:11:15 +02:00
microblaze
mips MIPS: Remove repetitive increase irq_err_count 2022-06-29 08:58:46 +02:00
nds32
nios2 nios2: use fallback for random_get_entropy() instead of zero 2022-06-22 14:11:15 +02:00
openrisc
parisc parisc: Enable ARCH_HAS_STRICT_MODULE_RWX 2022-06-29 08:58:48 +02:00
powerpc powerpc/powernv: delay rng platform device creation until later in boot 2022-07-12 16:30:47 +02:00
riscv riscv: add as-options for modules with assembly compontents 2022-07-29 17:14:08 +02:00
s390 s390/archrandom: prevent CPACF trng invocations in interrupt context 2022-08-03 11:59:37 +02:00
sh
sparc sparc: use fallback for random_get_entropy() instead of zero 2022-06-22 14:11:15 +02:00
um um: use fallback for random_get_entropy() instead of zero 2022-06-22 14:11:15 +02:00
unicore32
x86 KVM: nVMX: Snapshot pre-VM-Enter DEBUGCTL for !nested_run_pending case 2022-08-25 11:17:19 +02:00
xtensa xtensa: Fix refcount leak bug in time.c 2022-06-29 08:58:48 +02:00
.gitignore
Kconfig locking/refcount: Consolidate implementations of refcount_t 2022-07-29 17:14:17 +02:00