[MODERATED] Re: [PATCH v8 3/5] NX 3

mark gross <[email protected]> Fri, 1 Nov 2019 13:36:33 -0700
Newsgroups org.kernel.lore.historical-speck
Message-ID <20191101203633.GA9829@u1904>
On Fri, Nov 01, 2019 at 01:51:27PM -0500, speck for Tyler Hicks wrote:
> On 2019-11-01 11:38:15, speck for mark gross wrote:
> > On Fri, Nov 01, 2019 at 08:07:27AM +0100, speck for Paolo Bonzini wrote:
> > > On 01/11/19 01:24, speck for Pawan Gupta wrote:
> > > > On Fri, Nov 01, 2019 at 12:33:45AM +0100, speck for Paolo Bonzini wrote:
> > > >> From: Paolo Bonzini <[email protected]>
> > > >> Subject: [PATCH v8 3/5] kvm: mmu: ITLB_MULTIHIT mitigation
> > > >>  
> > > >> +	kvm.nx_huge_pages=
> > > >> +			[KVM] Controls the sw workaround for bug
> > > >> +			X86_BUG_ITLB_MULTIHIT.
> > > >> +			force	: Always deploy workaround.
> > > >> +			off	: Default. Never deploy workaround.
> > > > 
> > > > off is not the default in the code, so the default should be "auto" here.
> > > > 
> > > >> +			auto	: Deploy workaround based on presence of
> > > >> +				  X86_BUG_ITLB_MULTIHIT.
> > > > 
> > > > Also mitigations=off is not disabling this mitigation. Below patch does
> > > > that when mitigations=off and kvm.nx_huge_pages=auto.
> > > > 
> > > > ---
> > > > From: Pawan Gupta <[email protected]>
> > > > Date: Wed, 30 Oct 2019 21:28:24 -0700
> > > > Subject: [PATCH] kvm: x86: mmu: Apply global mitigations knob to ITLB_MULTIHIT
> > > > 
> > > > Problem: The global mitigation knob mitigations=off does not turn off
> > > > X86_BUG_ITLB_MULTIHIT mitigation.
> > > > 
> > > > Fix: Turn off the mitigation when ITLB_MULTIHIT mitigation mode is
> > > > "auto" and mitigations are turned off globally via cmdline
> > > > mitigations=off.
> > > > 
> > > > Signed-off-by: Pawan Gupta <[email protected]>
> > > 
> > > Thanks, I'll post v9 soon.  Are you going to post backports as bundles
> > > on top of Thomas's?
> > > 
> > > Paolo
> > We (I) have attempted the backports of this and quicly hit issues with the page
> > zapping changes do to code flux in the upstream.  My troubles started with with
> > 5.2 and 4.19. 
> 
> Is this due to the lack of kvm_mmu_zap_all_fast()? I believe that Paolo
> and others said in an older thread that
> kvm_mmu_invalidate_zap_all_pages() could be used instead.
> 
> That's what I've been planning to do in Ubuntu but I haven't had a
> chance to test it yet.
> 
> Tyler

I missed that comment.  I'll retry my backporting using your recomendation
above.

--mark

> 
> > I have reached out to an internal resource who is more knowledgable
> > with KVM mm files to assist with that aspect of the backport.  The
> > engineer was at a confrence this week and we hope to make more
> > progress next week once he is back.
> > 
> > --mark
> >