From patchwork Wed Nov 29 17:21:20 2017 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Levin, Alexander \(Sasha Levin\)" X-Patchwork-Id: 120037 Delivered-To: patch@linaro.org Received: by 10.140.22.227 with SMTP id 90csp3346179qgn; Wed, 29 Nov 2017 09:42:06 -0800 (PST) X-Google-Smtp-Source: AGs4zMYoaqbllAwsr2RVncGmjIsIFN4Qp0baXsMsZQNJoc/gYLk0ae6UlrzGhzjoMm+Cv4SYLm8k X-Received: by 10.98.215.19 with SMTP id b19mr3742820pfh.94.1511977325925; Wed, 29 Nov 2017 09:42:05 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1511977325; cv=none; d=google.com; s=arc-20160816; b=SEYbXT/iVpHU7zUgyiDPEu4wNOkrbIDmu97/PpoXubGudsdx31QglhvjOjg3OG41Ar baVJ4PmfquUOjA6FUTQIE2XQQf8KmwAg8EUbow/ggzf3zog7BqLaQ46TEElu1hLu7Y/F 4IJIcz2JUl/qTZuYb8+9a47Dah0BuOMjUCRdVRfwWTuUTgVYL6pO2VCAFyn2q+J2BaSx e0qOgqNRCnNZ45AyIzA8j4iGmwQzAwVr1O3MshzT+uJVl8l2UU0OA+yT88NhzaB0/M8u jo2xQLrTjtLJ5R5BZT1ANzO0p8+F7SH5PBDeJvkyK1axZ55+xo/NBUmP23pN4OMWvUe/ lnNw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:content-transfer-encoding :content-language:accept-language:in-reply-to:references:message-id :date:thread-index:thread-topic:subject:to:cc:from:dkim-signature :dkim-signature:dkim-signature:arc-authentication-results; bh=Ahxgf2Ps2JgVHoRHc06HehYssx4Rh4bk2jdV/3nDV5o=; b=HOPabtKIXUvnjH/Yl+eyoUajsCguIgrEOFh5ONwLbM9PT8hkjk8WvMaK4/suFbfnvz A8nUgl7P3OkSId0HiiFTEooskffLDmrBQEbbTW8WsUE3YBdpiyUKkW6oJkThJk9FXYAl 5GS6lkxEeCnm0sh8davgXz5s9Il6o8rDEuJynlEPUAZ9Bfqou88oSQby4097RfEAgqFj vXiQkHq4TPqRzp4KikVbzoH0BIYo4gwaQi23ka/1uF3qvAEM4gU3rX6VZoehWnryk93R P/J7nkP9RBxFobGYaXMDHE3DG0z3s8Mi3gN2+9kLko/3vk8Z0xVPkP9CfLo+saNMH7sP WsQw== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@verizon.com header.s=corp header.b=SNMQeufO; dkim=fail header.i=@verizon.com header.s=corp header.b=dLTubST1; dkim=fail header.i=@verizon.com header.s=corp header.b=d3PnrMjq; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=NONE dis=NONE) header.from=verizon.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id q62si1705231pfd.99.2017.11.29.09.42.05; Wed, 29 Nov 2017 09:42:05 -0800 (PST) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@verizon.com header.s=corp header.b=SNMQeufO; dkim=fail header.i=@verizon.com header.s=corp header.b=dLTubST1; dkim=fail header.i=@verizon.com header.s=corp header.b=d3PnrMjq; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=QUARANTINE sp=NONE dis=NONE) header.from=verizon.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S934842AbdK2RmD (ORCPT + 28 others); Wed, 29 Nov 2017 12:42:03 -0500 Received: from fldsmtpe03.verizon.com ([140.108.26.142]:46306 "EHLO fldsmtpe03.verizon.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1754100AbdK2RWx (ORCPT ); Wed, 29 Nov 2017 12:22:53 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1511976173; x=1543512173; h=from:cc:to:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=0jzyeUxil33jrO0VR4r0Yu68z377VtxAFwAVISkQZXY=; b=SNMQeufO1IyP1ug+25dA4GGUh8PTkrAY2KKyoCAgk6wkr7L6Dig008Xc JE2LBjaMIfEjFWfcJP2foDO9IDE74bpDwWekRZrSDwGKIHz3KwPRegfps D8CDkvr0AZL7HfVJmWwXmwtxobleFTm5xqN63IBWIFFuZL5f9vtkbGmh1 g=; Received: from unknown (HELO fldsmtpi03.verizon.com) ([166.68.71.145]) by fldsmtpe03.verizon.com with ESMTP; 29 Nov 2017 17:22:50 +0000 Received: from rogue-10-255-192-101.rogue.vzwcorp.com (HELO apollo.verizonwireless.com) ([10.255.192.101]) by fldsmtpi03.verizon.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 29 Nov 2017 17:22:04 +0000 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1511976141; x=1543512141; h=from:cc:to:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=0jzyeUxil33jrO0VR4r0Yu68z377VtxAFwAVISkQZXY=; b=dLTubST1FMPdIMYgxtYIoHjCsedeyvczPkDJKGqjCApdjB2dzsVdKB9X ZAfEGjgVNL367UoaeI63FUG/GZo6yCPTkMOu7W/IvBWU1d3swlnnJJXDh qu/iKHTN5U5Z36C/1ET5sOdffPWSMxK1Uqz0lcpnHJEhlM6kBG/+j7q73 I=; Received: from mariner.tdc.vzwcorp.com (HELO eris.verizonwireless.com) ([10.254.88.84]) by apollo.verizonwireless.com with ESMTP/TLS/DHE-RSA-AES256-SHA; 29 Nov 2017 12:22:02 -0500 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=verizon.com; i=@verizon.com; q=dns/txt; s=corp; t=1511976122; x=1543512122; h=to:subject:date:message-id:references:in-reply-to: content-transfer-encoding:mime-version:from:cc; bh=0jzyeUxil33jrO0VR4r0Yu68z377VtxAFwAVISkQZXY=; b=d3PnrMjq7u1T4RJguDyY2eSaTxMMjhzaABi7PmDSmn0+ffJNtJrcgODp nvavgafcwyDASnihuhqS2oQ5YhHDM7S6cW2aRURmuiqAD2a7wbPpU6Pk2 SpLGisn6oBBXUuAXVOhy57Oal9X6sVInjLpJ5aKcA3YrjCaPiZXI7AWM+ c=; From: alexander.levin@verizon.com Cc: Mark Rutland , Dave Martin , Suzuki K Poulose , Marc Zyngier , alexander.levin@verizon.com X-Host: mariner.tdc.vzwcorp.com Received: from ohtwi1exh003.uswin.ad.vzwcorp.com ([10.144.218.45]) by eris.verizonwireless.com with ESMTP/TLS/AES128-SHA256; 29 Nov 2017 17:22:02 +0000 Received: from OMZP1LUMXCA14.uswin.ad.vzwcorp.com (144.8.22.189) by OHTWI1EXH003.uswin.ad.vzwcorp.com (10.144.218.45) with Microsoft SMTP Server (TLS) id 14.3.248.2; Wed, 29 Nov 2017 12:22:02 -0500 Received: from OMZP1LUMXCA17.uswin.ad.vzwcorp.com (144.8.22.195) by OMZP1LUMXCA14.uswin.ad.vzwcorp.com (144.8.22.189) with Microsoft SMTP Server (TLS) id 15.0.1263.5; Wed, 29 Nov 2017 11:22:01 -0600 Received: from OMZP1LUMXCA17.uswin.ad.vzwcorp.com ([144.8.22.195]) by OMZP1LUMXCA17.uswin.ad.vzwcorp.com ([144.8.22.195]) with mapi id 15.00.1263.000; Wed, 29 Nov 2017 11:22:01 -0600 To: "linux-kernel@vger.kernel.org" , "stable@vger.kernel.org" Subject: [PATCH AUTOSEL for 4.9 31/52] arm: KVM: Survive unknown traps from guests Thread-Topic: [PATCH AUTOSEL for 4.9 31/52] arm: KVM: Survive unknown traps from guests Thread-Index: AQHTaTZ4GSkLFM5URE29Zwi+I0meVg== Date: Wed, 29 Nov 2017 17:21:20 +0000 Message-ID: <20171129172100.28819-31-alexander.levin@verizon.com> References: <20171129172100.28819-1-alexander.levin@verizon.com> In-Reply-To: <20171129172100.28819-1-alexander.levin@verizon.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-exchange-messagesentrepresentingtype: 1 x-ms-exchange-transport-fromentityheader: Hosted x-originating-ip: [10.144.60.250] MIME-Version: 1.0 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org From: Mark Rutland [ Upstream commit f050fe7a9164945dd1c28be05bf00e8cfb082ccf ] Currently we BUG() if we see a HSR.EC value we don't recognise. As configurable disables/enables are added to the architecture (controlled by RES1/RES0 bits respectively), with associated synchronous exceptions, it may be possible for a guest to trigger exceptions with classes that we don't recognise. While we can't service these exceptions in a manner useful to the guest, we can avoid bringing down the host. Per ARM DDI 0406C.c, all currently unallocated HSR EC encodings are reserved, and per ARM DDI 0487A.k_iss10775, page G6-4395, EC values within the range 0x00 - 0x2c are reserved for future use with synchronous exceptions, and EC values within the range 0x2d - 0x3f may be used for either synchronous or asynchronous exceptions. The patch makes KVM handle any unknown EC by injecting an UNDEFINED exception into the guest, with a corresponding (ratelimited) warning in the host dmesg. We could later improve on this with with a new (opt-in) exit to the host userspace. Cc: Dave Martin Cc: Suzuki K Poulose Reviewed-by: Christoffer Dall Signed-off-by: Mark Rutland Signed-off-by: Marc Zyngier Signed-off-by: Sasha Levin --- arch/arm/include/asm/kvm_arm.h | 1 + arch/arm/kvm/handle_exit.c | 19 ++++++++++++------- 2 files changed, 13 insertions(+), 7 deletions(-) -- 2.11.0 diff --git a/arch/arm/include/asm/kvm_arm.h b/arch/arm/include/asm/kvm_arm.h index e22089fb44dc..a3f0b3d50089 100644 --- a/arch/arm/include/asm/kvm_arm.h +++ b/arch/arm/include/asm/kvm_arm.h @@ -209,6 +209,7 @@ #define HSR_EC_IABT_HYP (0x21) #define HSR_EC_DABT (0x24) #define HSR_EC_DABT_HYP (0x25) +#define HSR_EC_MAX (0x3f) #define HSR_WFI_IS_WFE (_AC(1, UL) << 0) diff --git a/arch/arm/kvm/handle_exit.c b/arch/arm/kvm/handle_exit.c index 066b6d4508ce..42f5daf715d0 100644 --- a/arch/arm/kvm/handle_exit.c +++ b/arch/arm/kvm/handle_exit.c @@ -79,7 +79,19 @@ static int kvm_handle_wfx(struct kvm_vcpu *vcpu, struct kvm_run *run) return 1; } +static int kvm_handle_unknown_ec(struct kvm_vcpu *vcpu, struct kvm_run *run) +{ + u32 hsr = kvm_vcpu_get_hsr(vcpu); + + kvm_pr_unimpl("Unknown exception class: hsr: %#08x\n", + hsr); + + kvm_inject_undefined(vcpu); + return 1; +} + static exit_handle_fn arm_exit_handlers[] = { + [0 ... HSR_EC_MAX] = kvm_handle_unknown_ec, [HSR_EC_WFI] = kvm_handle_wfx, [HSR_EC_CP15_32] = kvm_handle_cp15_32, [HSR_EC_CP15_64] = kvm_handle_cp15_64, @@ -98,13 +110,6 @@ static exit_handle_fn kvm_get_exit_handler(struct kvm_vcpu *vcpu) { u8 hsr_ec = kvm_vcpu_trap_get_class(vcpu); - if (hsr_ec >= ARRAY_SIZE(arm_exit_handlers) || - !arm_exit_handlers[hsr_ec]) { - kvm_err("Unknown exception class: hsr: %#08x\n", - (unsigned int)kvm_vcpu_get_hsr(vcpu)); - BUG(); - } - return arm_exit_handlers[hsr_ec]; }