| From 2d25e1a5b314a3032494bd6e2f53892e2ea77b28 Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 4 Sep 2023 22:04:47 -0700 |
| Subject: x86/srso: Don't probe microcode in a guest |
| MIME-Version: 1.0 |
| Content-Type: text/plain; charset=UTF-8 |
| Content-Transfer-Encoding: 8bit |
| |
| From: Josh Poimboeuf <jpoimboe@kernel.org> |
| |
| [ Upstream commit 02428d0366a27c2f33bc4361eb10467777804f29 ] |
| |
| To support live migration, the hypervisor sets the "lowest common |
| denominator" of features. Probing the microcode isn't allowed because |
| any detected features might go away after a migration. |
| |
| As Andy Cooper states: |
| |
| "Linux must not probe microcode when virtualised. What it may see |
| instantaneously on boot (owing to MSR_PRED_CMD being fully passed |
| through) is not accurate for the lifetime of the VM." |
| |
| Rely on the hypervisor to set the needed IBPB_BRTYPE and SBPB bits. |
| |
| Fixes: 1b5277c0ea0b ("x86/srso: Add SRSO_NO support") |
| Suggested-by: Andrew Cooper <andrew.cooper3@citrix.com> |
| Signed-off-by: Josh Poimboeuf <jpoimboe@kernel.org> |
| Signed-off-by: Ingo Molnar <mingo@kernel.org> |
| Signed-off-by: Borislav Petkov (AMD) <bp@alien8.de> |
| Reviewed-by: Andrew Cooper <andrew.cooper3@citrix.com> |
| Acked-by: Borislav Petkov (AMD) <bp@alien8.de> |
| Link: https://lore.kernel.org/r/3938a7209606c045a3f50305d201d840e8c834c7.1693889988.git.jpoimboe@kernel.org |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| arch/x86/kernel/cpu/amd.c | 2 +- |
| 1 file changed, 1 insertion(+), 1 deletion(-) |
| |
| diff --git a/arch/x86/kernel/cpu/amd.c b/arch/x86/kernel/cpu/amd.c |
| index b08af929135d9..28e77c5d6484a 100644 |
| --- a/arch/x86/kernel/cpu/amd.c |
| +++ b/arch/x86/kernel/cpu/amd.c |
| @@ -767,7 +767,7 @@ static void early_init_amd(struct cpuinfo_x86 *c) |
| if (cpu_has(c, X86_FEATURE_TOPOEXT)) |
| smp_num_siblings = ((cpuid_ebx(0x8000001e) >> 8) & 0xff) + 1; |
| |
| - if (!cpu_has(c, X86_FEATURE_IBPB_BRTYPE)) { |
| + if (!cpu_has(c, X86_FEATURE_HYPERVISOR) && !cpu_has(c, X86_FEATURE_IBPB_BRTYPE)) { |
| if (c->x86 == 0x17 && boot_cpu_has(X86_FEATURE_AMD_IBPB)) |
| setup_force_cpu_cap(X86_FEATURE_IBPB_BRTYPE); |
| else if (c->x86 >= 0x19 && !wrmsrl_safe(MSR_IA32_PRED_CMD, PRED_CMD_SBPB)) { |
| -- |
| 2.40.1 |
| |