Skip to content

Commit 1e80fdc

Browse files
committed
KVM: SVM: Pin guest memory when SEV is active
The SEV memory encryption engine uses a tweak such that two identical plaintext pages at different location will have different ciphertext. So swapping or moving ciphertext of two pages will not result in plaintext being swapped. Relocating (or migrating) physical backing pages for a SEV guest will require some additional steps. The current SEV key management spec does not provide commands to swap or migrate (move) ciphertext pages. For now, we pin the guest memory registered through KVM_MEMORY_ENCRYPT_REG_REGION ioctl. Cc: Thomas Gleixner <[email protected]> Cc: Ingo Molnar <[email protected]> Cc: "H. Peter Anvin" <[email protected]> Cc: Paolo Bonzini <[email protected]> Cc: "Radim Krčmář" <[email protected]> Cc: Joerg Roedel <[email protected]> Cc: Borislav Petkov <[email protected]> Cc: Tom Lendacky <[email protected]> Cc: [email protected] Cc: [email protected] Cc: [email protected] Signed-off-by: Brijesh Singh <[email protected]>
1 parent 9f5b5b9 commit 1e80fdc

File tree

2 files changed

+133
-0
lines changed

2 files changed

+133
-0
lines changed

arch/x86/include/asm/kvm_host.h

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -753,6 +753,7 @@ struct kvm_sev_info {
753753
unsigned int handle; /* SEV firmware handle */
754754
int fd; /* SEV device fd */
755755
unsigned long pages_locked; /* Number of pages locked */
756+
struct list_head regions_list; /* List of registered regions */
756757
};
757758

758759
struct kvm_arch {

arch/x86/kvm/svm.c

Lines changed: 132 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -335,6 +335,14 @@ static unsigned int min_sev_asid;
335335
static unsigned long *sev_asid_bitmap;
336336
#define __sme_page_pa(x) __sme_set(page_to_pfn(x) << PAGE_SHIFT)
337337

338+
struct enc_region {
339+
struct list_head list;
340+
unsigned long npages;
341+
struct page **pages;
342+
unsigned long uaddr;
343+
unsigned long size;
344+
};
345+
338346
static inline bool svm_sev_enabled(void)
339347
{
340348
return max_sev_asid;
@@ -1649,13 +1657,46 @@ static void sev_clflush_pages(struct page *pages[], unsigned long npages)
16491657
}
16501658
}
16511659

1660+
static void __unregister_enc_region_locked(struct kvm *kvm,
1661+
struct enc_region *region)
1662+
{
1663+
/*
1664+
* The guest may change the memory encryption attribute from C=0 -> C=1
1665+
* or vice versa for this memory range. Lets make sure caches are
1666+
* flushed to ensure that guest data gets written into memory with
1667+
* correct C-bit.
1668+
*/
1669+
sev_clflush_pages(region->pages, region->npages);
1670+
1671+
sev_unpin_memory(kvm, region->pages, region->npages);
1672+
list_del(&region->list);
1673+
kfree(region);
1674+
}
1675+
16521676
static void sev_vm_destroy(struct kvm *kvm)
16531677
{
16541678
struct kvm_sev_info *sev = &kvm->arch.sev_info;
1679+
struct list_head *head = &sev->regions_list;
1680+
struct list_head *pos, *q;
16551681

16561682
if (!sev_guest(kvm))
16571683
return;
16581684

1685+
mutex_lock(&kvm->lock);
1686+
1687+
/*
1688+
* if userspace was terminated before unregistering the memory regions
1689+
* then lets unpin all the registered memory.
1690+
*/
1691+
if (!list_empty(head)) {
1692+
list_for_each_safe(pos, q, head) {
1693+
__unregister_enc_region_locked(kvm,
1694+
list_entry(pos, struct enc_region, list));
1695+
}
1696+
}
1697+
1698+
mutex_unlock(&kvm->lock);
1699+
16591700
sev_unbind_asid(kvm, sev->handle);
16601701
sev_asid_free(kvm);
16611702
}
@@ -5814,6 +5855,7 @@ static int sev_guest_init(struct kvm *kvm, struct kvm_sev_cmd *argp)
58145855

58155856
sev->active = true;
58165857
sev->asid = asid;
5858+
INIT_LIST_HEAD(&sev->regions_list);
58175859

58185860
return 0;
58195861

@@ -6516,6 +6558,94 @@ static int svm_mem_enc_op(struct kvm *kvm, void __user *argp)
65166558
return r;
65176559
}
65186560

6561+
static int svm_register_enc_region(struct kvm *kvm,
6562+
struct kvm_enc_region *range)
6563+
{
6564+
struct kvm_sev_info *sev = &kvm->arch.sev_info;
6565+
struct enc_region *region;
6566+
int ret = 0;
6567+
6568+
if (!sev_guest(kvm))
6569+
return -ENOTTY;
6570+
6571+
region = kzalloc(sizeof(*region), GFP_KERNEL);
6572+
if (!region)
6573+
return -ENOMEM;
6574+
6575+
region->pages = sev_pin_memory(kvm, range->addr, range->size, &region->npages, 1);
6576+
if (!region->pages) {
6577+
ret = -ENOMEM;
6578+
goto e_free;
6579+
}
6580+
6581+
/*
6582+
* The guest may change the memory encryption attribute from C=0 -> C=1
6583+
* or vice versa for this memory range. Lets make sure caches are
6584+
* flushed to ensure that guest data gets written into memory with
6585+
* correct C-bit.
6586+
*/
6587+
sev_clflush_pages(region->pages, region->npages);
6588+
6589+
region->uaddr = range->addr;
6590+
region->size = range->size;
6591+
6592+
mutex_lock(&kvm->lock);
6593+
list_add_tail(&region->list, &sev->regions_list);
6594+
mutex_unlock(&kvm->lock);
6595+
6596+
return ret;
6597+
6598+
e_free:
6599+
kfree(region);
6600+
return ret;
6601+
}
6602+
6603+
static struct enc_region *
6604+
find_enc_region(struct kvm *kvm, struct kvm_enc_region *range)
6605+
{
6606+
struct kvm_sev_info *sev = &kvm->arch.sev_info;
6607+
struct list_head *head = &sev->regions_list;
6608+
struct enc_region *i;
6609+
6610+
list_for_each_entry(i, head, list) {
6611+
if (i->uaddr == range->addr &&
6612+
i->size == range->size)
6613+
return i;
6614+
}
6615+
6616+
return NULL;
6617+
}
6618+
6619+
6620+
static int svm_unregister_enc_region(struct kvm *kvm,
6621+
struct kvm_enc_region *range)
6622+
{
6623+
struct enc_region *region;
6624+
int ret;
6625+
6626+
mutex_lock(&kvm->lock);
6627+
6628+
if (!sev_guest(kvm)) {
6629+
ret = -ENOTTY;
6630+
goto failed;
6631+
}
6632+
6633+
region = find_enc_region(kvm, range);
6634+
if (!region) {
6635+
ret = -EINVAL;
6636+
goto failed;
6637+
}
6638+
6639+
__unregister_enc_region_locked(kvm, region);
6640+
6641+
mutex_unlock(&kvm->lock);
6642+
return 0;
6643+
6644+
failed:
6645+
mutex_unlock(&kvm->lock);
6646+
return ret;
6647+
}
6648+
65196649
static struct kvm_x86_ops svm_x86_ops __ro_after_init = {
65206650
.cpu_has_kvm_support = has_svm,
65216651
.disabled_by_bios = is_disabled,
@@ -6633,6 +6763,8 @@ static struct kvm_x86_ops svm_x86_ops __ro_after_init = {
66336763
.enable_smi_window = enable_smi_window,
66346764

66356765
.mem_enc_op = svm_mem_enc_op,
6766+
.mem_enc_reg_region = svm_register_enc_region,
6767+
.mem_enc_unreg_region = svm_unregister_enc_region,
66366768
};
66376769

66386770
static int __init svm_init(void)

0 commit comments

Comments
 (0)