Re: [PATCH 6.18 0019/1611] iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19
Usama Arif <[email protected]>
| Newsgroups | dev.linux.lists.patches,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Tue, 21 Jul 2026 17:02:15 +0200 Greg Kroah-Hartman <[email protected]> wrote: > 6.18-stable review patch. If anyone has any objections, please let me know. > > ------------------ > > From: Vasant Hegde <[email protected]> > > [ Upstream commit 1f44aab79bac31f459422dfb213e907bb386509c ] > > Due to CVE-2023-20585, the PPR log buffer must use the maximum supported > size (512K) on Genoa (Family 0x19, model >= 0x10) systems when SNP is > enabled, to mitigate a potential security vulnerability. Note that Family > 0x19 models below 0x10 (Milan) do not support PPR when SNP is enabled. > Hence the PPR log size increase is only applied for model >= 0x10. > All other systems continue to use the default PPR log buffer size (8K). > > Apply the errata fix by making the following changes: > > - Introduce global new variable (amd_iommu_pprlog_size) to have PPR log buffer > size. Adjust variable size for Genoa family. > > - Extend 'amd_iommu_apply_erratum_snp()' to also set the PPR log buffer > size to maximum for Family 0x19 model >= 0x10 when SNP is enabled. > > - Rename PPR_* macros to make it more readable. > > Link: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3016.html > Cc: Borislav Petkov <[email protected]> > Cc: Suravee Suthikulpanit <[email protected]> > Cc: Joerg Roedel <[email protected]> > Signed-off-by: Vasant Hegde <[email protected]> > Tested-by: Dheeraj Kumar Srivastava <[email protected]> > Signed-off-by: Joerg Roedel <[email protected]> > Signed-off-by: Sasha Levin <[email protected]> > --- > drivers/iommu/amd/amd_iommu.h | 1 + > drivers/iommu/amd/amd_iommu_types.h | 11 ++++++----- > drivers/iommu/amd/init.c | 13 ++++++++++++- > drivers/iommu/amd/ppr.c | 8 +++++--- > 4 files changed, 24 insertions(+), 9 deletions(-) > Hi, I have raised this in [1] but also raising it here, this series seems to break kexec on Milan hosts. kexec starts working on SNP hosts once we do: Revert "iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19" Revert "iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19" on top 6.18.43 release. [1] https://lore.kernel.org/all/[email protected]/ > diff --git a/drivers/iommu/amd/amd_iommu.h b/drivers/iommu/amd/amd_iommu.h > index 57d7f3faa98c6e..ef397c5a2c4ab2 100644 > --- a/drivers/iommu/amd/amd_iommu.h > +++ b/drivers/iommu/amd/amd_iommu.h > @@ -12,6 +12,7 @@ > #include "amd_iommu_types.h" > > extern int amd_iommu_evtlog_size; > +extern int amd_iommu_pprlog_size; > > irqreturn_t amd_iommu_int_thread(int irq, void *data); > irqreturn_t amd_iommu_int_thread_evtlog(int irq, void *data); > diff --git a/drivers/iommu/amd/amd_iommu_types.h b/drivers/iommu/amd/amd_iommu_types.h > index bdd6c38ddfec9b..2494b1958117b2 100644 > --- a/drivers/iommu/amd/amd_iommu_types.h > +++ b/drivers/iommu/amd/amd_iommu_types.h > @@ -257,11 +257,12 @@ > #define EVTLOG_LEN_MASK_MAX (0xFULL << EVTLOG_SIZE_SHIFT) > > /* Constants for PPR Log handling */ > -#define PPR_LOG_ENTRIES 512 > -#define PPR_LOG_SIZE_SHIFT 56 > -#define PPR_LOG_SIZE_512 (0x9ULL << PPR_LOG_SIZE_SHIFT) > -#define PPR_ENTRY_SIZE 16 > -#define PPR_LOG_SIZE (PPR_ENTRY_SIZE * PPR_LOG_ENTRIES) > +#define PPRLOG_ENTRY_SIZE 0x10 > +#define PPRLOG_SIZE_SHIFT 56 > +#define PPRLOG_SIZE_DEF SZ_8K /* 512 entries */ > +#define PPRLOG_LEN_MASK_DEF (0x9ULL << PPRLOG_SIZE_SHIFT) > +#define PPRLOG_SIZE_MAX SZ_512K /* 32K entries */ > +#define PPRLOG_LEN_MASK_MAX (0xFULL << PPRLOG_SIZE_SHIFT) > > /* PAGE_SERVICE_REQUEST PPR Log Buffer Entry flags */ > #define PPR_FLAG_EXEC 0x002 /* Execute permission requested */ > diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c > index 64964bb5ce0d36..6e5efc340c83e4 100644 > --- a/drivers/iommu/amd/init.c > +++ b/drivers/iommu/amd/init.c > @@ -133,6 +133,7 @@ struct ivhd_entry { > } __attribute__((packed)); > > int amd_iommu_evtlog_size = EVTLOG_SIZE_DEF; > +int amd_iommu_pprlog_size = PPRLOG_SIZE_DEF; > > /* > * An AMD IOMMU memory definition structure. It defines things like exclusion > @@ -3411,6 +3412,16 @@ static void amd_iommu_apply_erratum_snp(void) > amd_iommu_evtlog_size = EVTLOG_SIZE_MAX; > pr_info("Applying erratum: Increase Event log size to 0x%x\n", > amd_iommu_evtlog_size); > + > + /* > + * Set PPR log buffer size to max. > + * (Family 0x19, model < 0x10 doesn't support PPR when SNP is enabled). > + */ > + if (boot_cpu_data.x86_model >= 0x10) { > + amd_iommu_pprlog_size = PPRLOG_SIZE_MAX; > + pr_info("Applying erratum: Increase PPR log size to 0x%x\n", > + amd_iommu_pprlog_size); > + } > #endif > } > > @@ -4071,7 +4082,7 @@ int amd_iommu_snp_disable(void) > if (ret) > return ret; > > - ret = iommu_make_shared(iommu->ppr_log, PPR_LOG_SIZE); > + ret = iommu_make_shared(iommu->ppr_log, amd_iommu_pprlog_size); > if (ret) > return ret; > > diff --git a/drivers/iommu/amd/ppr.c b/drivers/iommu/amd/ppr.c > index e6767c057d01fa..1f8d2823bea42c 100644 > --- a/drivers/iommu/amd/ppr.c > +++ b/drivers/iommu/amd/ppr.c > @@ -20,7 +20,7 @@ > int __init amd_iommu_alloc_ppr_log(struct amd_iommu *iommu) > { > iommu->ppr_log = iommu_alloc_4k_pages(iommu, GFP_KERNEL | __GFP_ZERO, > - PPR_LOG_SIZE); > + amd_iommu_pprlog_size); > return iommu->ppr_log ? 0 : -ENOMEM; > } > > @@ -33,7 +33,9 @@ void amd_iommu_enable_ppr_log(struct amd_iommu *iommu) > > iommu_feature_enable(iommu, CONTROL_PPR_EN); > > - entry = iommu_virt_to_phys(iommu->ppr_log) | PPR_LOG_SIZE_512; > + entry = iommu_virt_to_phys(iommu->ppr_log); > + entry |= (amd_iommu_pprlog_size == PPRLOG_SIZE_DEF) ? > + PPRLOG_LEN_MASK_DEF : PPRLOG_LEN_MASK_MAX; > > memcpy_toio(iommu->mmio_base + MMIO_PPR_LOG_OFFSET, > &entry, sizeof(entry)); > @@ -201,7 +203,7 @@ void amd_iommu_poll_ppr_log(struct amd_iommu *iommu) > raw[0] = raw[1] = 0UL; > > /* Update head pointer of hardware ring-buffer */ > - head = (head + PPR_ENTRY_SIZE) % PPR_LOG_SIZE; > + head = (head + PPRLOG_ENTRY_SIZE) % amd_iommu_pprlog_size; > writel(head, iommu->mmio_base + MMIO_PPR_HEAD_OFFSET); > > /* Handle PPR entry */ > -- > 2.53.0 > > > >