From patchwork Fri Mar 1 10:14:09 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gerd Hoffmann X-Patchwork-Id: 208749 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:a05:7301:2097:b0:108:e6aa:91d0 with SMTP id gs23csp978454dyb; Fri, 1 Mar 2024 02:14:53 -0800 (PST) X-Forwarded-Encrypted: i=3; AJvYcCW02sEvkmupN68gxynv6uSXCgd/2zvpj8V+0zPixijoRxdg2PbUJgdXLWnq5yj6lKQpVD7NCC5i3Sd3ofb+YlP4GKh7GQ== X-Google-Smtp-Source: AGHT+IF/77gV+e8aLqpuIVL/d0ZvHDIMqEgps9IpCK0HHC4P74MNlfTXWv35W77UZMMGRZR/K/we X-Received: by 2002:a17:906:e96:b0:a3f:3470:6055 with SMTP id p22-20020a1709060e9600b00a3f34706055mr826642ejf.37.1709288092982; Fri, 01 Mar 2024 02:14:52 -0800 (PST) ARC-Seal: i=2; a=rsa-sha256; t=1709288092; cv=pass; d=google.com; s=arc-20160816; b=s+25D3k5zcJh++ezXaSnd7vJPJsBOfjBJh5yfLa6HtWyluhpRw3RWF5isUX+UGMGcP GR6t34dDfE6sqsAHJo9/NtPB32+BUKpoUEx/U9TCp6QesjPKRHWFKp9KFF1EtU+EI4kA E1MQr3XPjff7X807j34JpJy4JY0X2AtU/l7PY3zPz1C02t62+hyXrqQhWktOAFyvfbA5 2rwkz0AUEsBIQCD8GstOjSqQm4/n+8U9et9qWmGphNuoiQDqKivNcdNzqU4rMUF7H35E kmucpe4e5ntK4GX6Q5a0d5Mob4yuj5fm8lMzYRp5Qif5ukpb+FrUTIwPj3HAEJIdDSKq YzEQ== ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:list-unsubscribe :list-subscribe:list-id:precedence:references:in-reply-to:message-id :date:subject:cc:to:from:dkim-signature; bh=8s8i3ItjA9wi3+gOCrDxEDREoSwFyWHMRuQO27hhEhI=; fh=8dvwZjTintHRZSEO4im4OT7nSZJf1h7yo1mdwcT0Sxs=; b=03ljrQr0O6KhAqGKuUwaKsvfQhGwpEaZcZUJwqXhA5jlL+SA1A2G47NqhMxneWSWxB rx3TCNEzfzNEXRo6OGlvuPPf7YFpOVa5D1DBMc+E3Z2dFOzc3DycxaFYRCMYLJTpp6ES JoVBUFePKI4axPrh35GMrk4LjP3v1znC6UZezhUBtQ4slIh8R7s9lvV4nh+L5otkrsfc QY2VviamMpPbOBLLd407fDzs6590ogCq1ZiTythdvfPYqmJxyzeZIdJiyQ/p/5hppTU5 C/RXK9x+xS5Av1TKC8nWkoBvPCBwkp+wun6w3mIUWwPo0WKsOrV+dmzz10iAoDk+DABj rZMA==; dara=google.com ARC-Authentication-Results: i=2; mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=LFw+Y0w0; arc=pass (i=1 spf=pass spfdomain=redhat.com dkim=pass dkdomain=redhat.com dmarc=pass fromdomain=redhat.com); spf=pass (google.com: domain of linux-kernel+bounces-88242-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-88242-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: from am.mirrors.kernel.org (am.mirrors.kernel.org. [147.75.80.249]) by mx.google.com with ESMTPS id v25-20020a1709060b5900b00a4450b86a58si1059871ejg.144.2024.03.01.02.14.52 for (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 01 Mar 2024 02:14:52 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel+bounces-88242-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) client-ip=147.75.80.249; Authentication-Results: mx.google.com; dkim=pass header.i=@redhat.com header.s=mimecast20190719 header.b=LFw+Y0w0; arc=pass (i=1 spf=pass spfdomain=redhat.com dkim=pass dkdomain=redhat.com dmarc=pass fromdomain=redhat.com); spf=pass (google.com: domain of linux-kernel+bounces-88242-ouuuleilei=gmail.com@vger.kernel.org designates 147.75.80.249 as permitted sender) smtp.mailfrom="linux-kernel+bounces-88242-ouuuleilei=gmail.com@vger.kernel.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=redhat.com Received: from smtp.subspace.kernel.org (wormhole.subspace.kernel.org [52.25.139.140]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by am.mirrors.kernel.org (Postfix) with ESMTPS id 788DB1F24667 for ; Fri, 1 Mar 2024 10:14:52 +0000 (UTC) Received: from localhost.localdomain (localhost.localdomain [127.0.0.1]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 3BD606A8D4; Fri, 1 Mar 2024 10:14:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="LFw+Y0w0" Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C0227482C1 for ; Fri, 1 Mar 2024 10:14:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709288059; cv=none; b=RaJaGbWKl0mP73C8klTxLIMdlOVwUte3jtuGatHn3jyKuMsBLvcd10kkI/FIllhKx5M9yQyh6Vdz7Ifl7aMYhQBoHBCozSZf6yzekL1Wefq1hh/i0G/lY3ZkGBXUPFnzQ8/s2igaHafbKxvmo3c2jTdWBlYwxEp99Vb9xlVpa2A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1709288059; c=relaxed/simple; bh=sND8jhV+K31Cz2knDCDV+qPQDZGZA9Xo2gOcAqB/Ihk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=o0TUPBcgtHu4fo2amigbLPAen3C9pUuP36keV2JXe1GIZfWqHeqAYoue3CIYxLKLq9sHGJ4X5wGXuI+pVpCx5prHGk4dhZmvFGj4RA6cACFJRfltOKYnpVsd+B02mL/6lB4wvPHtHRCP5NMXCIMQ07SkU9geYi+10vEJa17Xa7c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=LFw+Y0w0; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1709288056; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=8s8i3ItjA9wi3+gOCrDxEDREoSwFyWHMRuQO27hhEhI=; b=LFw+Y0w0hJfgELuRZEednBm9tLxacgYYRxEzEenyGYwdQ3fsbgbReZ2+OnOE4pxHrbsvIB 7M4jWKTaIn9JCdrooHriobTg6dWRN8CLOjaPuLfES/pu5uQh6DdWUGXpbJYQJML8voSpvw XUK8EdLr+SKyMM86h5/4ERhepnHFna4= Received: from mimecast-mx02.redhat.com (mimecast-mx02.redhat.com [66.187.233.88]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-629-c4D56yyKOrai0fd5slYOSg-1; Fri, 01 Mar 2024 05:14:15 -0500 X-MC-Unique: c4D56yyKOrai0fd5slYOSg-1 Received: from smtp.corp.redhat.com (int-mx04.intmail.prod.int.rdu2.redhat.com [10.11.54.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mimecast-mx02.redhat.com (Postfix) with ESMTPS id EDBD68B39A1; Fri, 1 Mar 2024 10:14:14 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.39.192.121]) by smtp.corp.redhat.com (Postfix) with ESMTPS id 8859920229D6; Fri, 1 Mar 2024 10:14:14 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 11E471801492; Fri, 1 Mar 2024 11:14:11 +0100 (CET) From: Gerd Hoffmann To: kvm@vger.kernel.org Cc: Gerd Hoffmann , Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org (maintainer:X86 ARCHITECTURE (32-BIT AND 64-BIT)), "H. Peter Anvin" , linux-kernel@vger.kernel.org (open list:X86 ARCHITECTURE (32-BIT AND 64-BIT)) Subject: [PATCH 3/3] kvm/svm: limit guest_phys_bits to 48 in 4-level paging mode Date: Fri, 1 Mar 2024 11:14:09 +0100 Message-ID: <20240301101410.356007-4-kraxel@redhat.com> In-Reply-To: <20240301101410.356007-1-kraxel@redhat.com> References: <20240301101410.356007-1-kraxel@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Scanned-By: MIMEDefang 3.4.1 on 10.11.54.4 X-getmail-retrieved-from-mailbox: INBOX X-GMAIL-THRID: 1792318471148900473 X-GMAIL-MSGID: 1792318471148900473 If the host runs in 4-level paging mode NPT is restricted to 4 paging levels too. Adjust kvm_caps.guest_phys_bits accordingly. Signed-off-by: Gerd Hoffmann --- arch/x86/kvm/svm/svm.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c index e90b429c84f1..8c3e2e3bd468 100644 --- a/arch/x86/kvm/svm/svm.c +++ b/arch/x86/kvm/svm/svm.c @@ -5229,6 +5229,11 @@ static __init int svm_hardware_setup(void) get_npt_level(), PG_LEVEL_1G); pr_info("Nested Paging %sabled\n", npt_enabled ? "en" : "dis"); + if (npt_enabled && + get_npt_level() == PT64_ROOT_4LEVEL && + kvm_caps.guest_phys_bits > 48) + kvm_caps.guest_phys_bits = 48; + /* Setup shadow_me_value and shadow_me_mask */ kvm_mmu_set_me_spte_mask(sme_me_mask, sme_me_mask);