From e6a2a4be1a79b96491638b343da3b0b4b03a0370 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= Date: Sun, 10 Aug 2025 13:49:10 +0200 Subject: [PATCH] Update to 4.19.3 Drop patches included upstream already. --- ...r-Remove-bespoke-service-B.UNEVALEFF.patch | 50 -- ...ot-use-c-E-compiler-options-together.patch | 40 -- 0305-xen-lib-Introduce-SHA2-256.patch | 342 ------------ ...m-extra-SHA2-checks-on-AMD-Fam17h-19.patch | 444 --------------- ...-AMD-digest-checks-to-cover-Zen5-CPU.patch | 66 --- ...86-MTRR-hook-mtrr_bp_restore-back-up.patch | 71 --- ...-another-crash-after-failed-domU-cre.patch | 81 --- ...not-do-vm_event_op-for-an-invalid-do.patch | 39 -- ...u-Validate-CPUID-leaf-0x2-EDX-output.patch | 46 -- ...rq-initialize-irq-desc-in-create_irq.patch | 55 -- 0314-include-sort-wildcard-.-results.patch | 47 -- ...n-rangeset-fix-incorrect-subtraction.patch | 48 -- ...epeat-count-upon-nested-lin-phys-fai.patch | 50 -- ...-also-clip-repetition-count-for-STOS.patch | 35 -- ...oid-UB-shifts-in-XENMEM_exchange-han.patch | 38 -- ...karound-several-MONITOR-MWAIT-errata.patch | 135 ----- ...emove-N-from-the-linker-command-line.patch | 159 ------ ...Support-replacements-when-a-feature-.patch | 93 ---- ...Remove-use-of-the-Xen-hypercall_page.patch | 333 ----------- ...ign-__x86_indirect_thunk_-to-mitigat.patch | 55 -- ...ign-the-RETs-in-clear_bhb_loops-to-m.patch | 77 --- ...uce-place_ret-to-abstract-away-raw-0.patch | 525 ------------------ ...6-thunk-Build-Xen-with-Return-Thunks.patch | 404 -------------- ...nthesise-ITS_NO-to-guests-on-unaffec.patch | 170 ------ ...-.debug_str_offsets-in-DWARF2_DEBUG_.patch | 39 -- ...-UB-shifts-in-FLDENV-FRSTOR-handling.patch | 85 --- ...don-t-leave-stale-statistics-pointer.patch | 43 -- ...spec-ctrl-Support-Intel-s-new-PB-OPT.patch | 202 ------- ...T_FLUSH_CACHE-to-flush-all-pCPU-cach.patch | 64 --- ...onstrain-creator-domain-ID-assertion.patch | 41 -- ...lation-of-RDSEED-with-older-toolchai.patch | 57 -- ...tion-of-wb-no-invd-to-flush-all-pCPU.patch | 46 -- ...dling-of-BAR-overlaps-with-non-hole-.patch | 179 ------ ...try-failure-on-ADL-SPR-with-shadow-g.patch | 43 -- 0338-x86-pv-Fix-breakpoint-reporting.patch | 45 -- ...bxl-Only-access-legacy-altp2m-on-HVM.patch | 59 -- ...ck-size-of-PMSTAT_get_pxstat-buffers.patch | 96 ---- ...id-potential-buffer-overrun-and-leak.patch | 52 -- ...-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch | 35 -- ...-extable-registration-in-invoke_stub.patch | 54 -- ...e-pxstat-buffers-are-correctly-sized.patch | 87 --- ...try-get_pxstat-if-data-is-incomplete.patch | 85 --- ...fzero-init-padding-bits-all-to-gcc15.patch | 44 -- ...licy-Fix-handling-of-leaf-0x80000021.patch | 59 -- ...eposition-cpu_has_-lfence_dispatch-n.patch | 45 -- ...nitor-mwait-wrappers-into-cpu-idle.c.patch | 107 ---- ...e-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch | 140 ----- ...86-mwait-idle-disable-IBRS-during-lo.patch | 82 --- ...implify-logic-in-guest_common_defaul.patch | 68 --- ...e-Remove-broken-MWAIT-implementation.patch | 187 ------- ...correct-smp_mb-in-mwait_idle_with_hi.patch | 53 -- ...-force_mwait_ipi_wakeup-to-X86_BUG_M.patch | 83 --- ...rk-arch_skip_send_event_check-into-a.patch | 115 ---- ...nt-a-new-MWAIT-IPI-elision-algorithm.patch | 159 ------ ...gy-x86-mwait-idle-enable-interrupts-.patch | 87 --- ...earrange-guest_common_-_feature_adju.patch | 136 ----- ...nfrastructure-for-CPUID-leaf-0x80000.patch | 130 ----- ...-x86-ucode-Digests-for-TSA-microcode.patch | 307 ---------- ...ge-VERW-and-MONITOR-in-mwait_idle_wi.patch | 145 ----- ...itigate-Transitive-Scheduler-Attacks.patch | 324 ----------- archlinux/PKGBUILD.in | 1 - rel | 2 +- version | 2 +- xen.spec.in | 60 -- 64 files changed, 2 insertions(+), 7049 deletions(-) delete mode 100644 0303-automation-eclair-Remove-bespoke-service-B.UNEVALEFF.patch delete mode 100644 0304-tools-libxl-do-not-use-c-E-compiler-options-together.patch delete mode 100644 0305-xen-lib-Introduce-SHA2-256.patch delete mode 100644 0306-x86-ucode-Perform-extra-SHA2-checks-on-AMD-Fam17h-19.patch delete mode 100644 0307-x86-ucode-Extend-AMD-digest-checks-to-cover-Zen5-CPU.patch delete mode 100644 0309-x86-MTRR-hook-mtrr_bp_restore-back-up.patch delete mode 100644 0310-sched-null-avoid-another-crash-after-failed-domU-cre.patch delete mode 100644 0311-xen-vm_event-do-not-do-vm_event_op-for-an-invalid-do.patch delete mode 100644 0312-x86-cpu-Validate-CPUID-leaf-0x2-EDX-output.patch delete mode 100644 0313-xen-x86-irq-initialize-irq-desc-in-create_irq.patch delete mode 100644 0314-include-sort-wildcard-.-results.patch delete mode 100644 0315-xen-rangeset-fix-incorrect-subtraction.patch delete mode 100644 0316-x86-HVM-update-repeat-count-upon-nested-lin-phys-fai.patch delete mode 100644 0317-x86emul-also-clip-repetition-count-for-STOS.patch delete mode 100644 0318-compat-memory-avoid-UB-shifts-in-XENMEM_exchange-han.patch delete mode 100644 0319-x86-intel-workaround-several-MONITOR-MWAIT-errata.patch delete mode 100644 0320-xen-remove-N-from-the-linker-command-line.patch delete mode 100644 0321-x86-alternative-Support-replacements-when-a-feature-.patch delete mode 100644 0322-x86-guest-Remove-use-of-the-Xen-hypercall_page.patch delete mode 100644 0323-x86-thunk-Mis-align-__x86_indirect_thunk_-to-mitigat.patch delete mode 100644 0324-x86-thunk-Mis-align-the-RETs-in-clear_bhb_loops-to-m.patch delete mode 100644 0325-x86-stubs-Introduce-place_ret-to-abstract-away-raw-0.patch delete mode 100644 0326-x86-thunk-Build-Xen-with-Return-Thunks.patch delete mode 100644 0327-x86-spec-ctrl-Synthesise-ITS_NO-to-guests-on-unaffec.patch delete mode 100644 0328-xen-link-Include-.debug_str_offsets-in-DWARF2_DEBUG_.patch delete mode 100644 0329-x86emul-avoid-UB-shifts-in-FLDENV-FRSTOR-handling.patch delete mode 100644 0330-cpufreq-don-t-leave-stale-statistics-pointer.patch delete mode 100644 0331-x86-spec-ctrl-Support-Intel-s-new-PB-OPT.patch delete mode 100644 0332-x86-pv-fix-MMUEXT_FLUSH_CACHE-to-flush-all-pCPU-cach.patch delete mode 100644 0333-x86-IRQ-constrain-creator-domain-ID-assertion.patch delete mode 100644 0334-x86-emul-Fix-emulation-of-RDSEED-with-older-toolchai.patch delete mode 100644 0335-x86-pv-fix-emulation-of-wb-no-invd-to-flush-all-pCPU.patch delete mode 100644 0336-x86-vpci-fix-handling-of-BAR-overlaps-with-non-hole-.patch delete mode 100644 0337-x86-vmx-Fix-VMEntry-failure-on-ADL-SPR-with-shadow-g.patch delete mode 100644 0338-x86-pv-Fix-breakpoint-reporting.patch delete mode 100644 0339-tools-libxl-Only-access-legacy-altp2m-on-HVM.patch delete mode 100644 0340-x86-pmstat-Check-size-of-PMSTAT_get_pxstat-buffers.patch delete mode 100644 0341-cpufreq-Avoid-potential-buffer-overrun-and-leak.patch delete mode 100644 0342-xenalyze-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch delete mode 100644 0343-x86-emul-Fix-extable-registration-in-invoke_stub.patch delete mode 100644 0344-libxc-PM-Ensure-pxstat-buffers-are-correctly-sized.patch delete mode 100644 0345-libxc-PM-Retry-get_pxstat-if-data-is-incomplete.patch delete mode 100644 0346-xen-build-pass-fzero-init-padding-bits-all-to-gcc15.patch delete mode 100644 0347-x86-cpu-policy-Fix-handling-of-leaf-0x80000021.patch delete mode 100644 0500-x86-cpufeature-Reposition-cpu_has_-lfence_dispatch-n.patch delete mode 100644 0501-x86-idle-Move-monitor-mwait-wrappers-into-cpu-idle.c.patch delete mode 100644 0502-x86-idle-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch delete mode 100644 0503-Revert-part-of-x86-mwait-idle-disable-IBRS-during-lo.patch delete mode 100644 0504-x86-cpu-policy-Simplify-logic-in-guest_common_defaul.patch delete mode 100644 0505-x86-idle-Remove-broken-MWAIT-implementation.patch delete mode 100644 0506-x86-idle-Drop-incorrect-smp_mb-in-mwait_idle_with_hi.patch delete mode 100644 0507-x86-idle-Convert-force_mwait_ipi_wakeup-to-X86_BUG_M.patch delete mode 100644 0508-xen-softirq-Rework-arch_skip_send_event_check-into-a.patch delete mode 100644 0509-x86-idle-Implement-a-new-MWAIT-IPI-elision-algorithm.patch delete mode 100644 0510-x86-idle-Fix-buggy-x86-mwait-idle-enable-interrupts-.patch delete mode 100644 0511-x86-cpu-policy-Rearrange-guest_common_-_feature_adju.patch delete mode 100644 0512-x86-cpu-policy-Infrastructure-for-CPUID-leaf-0x80000.patch delete mode 100644 0513-x86-ucode-Digests-for-TSA-microcode.patch delete mode 100644 0514-x86-idle-Rearrange-VERW-and-MONITOR-in-mwait_idle_wi.patch delete mode 100644 0515-x86-spec-ctrl-Mitigate-Transitive-Scheduler-Attacks.patch diff --git a/0303-automation-eclair-Remove-bespoke-service-B.UNEVALEFF.patch b/0303-automation-eclair-Remove-bespoke-service-B.UNEVALEFF.patch deleted file mode 100644 index 4c62c7d0..00000000 --- a/0303-automation-eclair-Remove-bespoke-service-B.UNEVALEFF.patch +++ /dev/null @@ -1,50 +0,0 @@ -From cfea30c0084e1b57e9a7fc90d32ef1eb40c7e186 Mon Sep 17 00:00:00 2001 -From: Nicola Vetrini -Date: Thu, 10 Apr 2025 21:32:14 +0200 -Subject: [PATCH] automation/eclair: Remove bespoke service B.UNEVALEFF - -The Eclair runners in GitlabCI have been update. This service is now -included, and redefining results in an error. - -No functional change. - -Signed-off-by: Nicola Vetrini -Acked-by: Andrew Cooper -(cherry picked from commit a43b0a770bdcf3933634c860049e4bd65854e472) ---- - automation/eclair_analysis/ECLAIR/B.UNEVALEFF.ecl | 10 ---------- - automation/eclair_analysis/ECLAIR/analysis.ecl | 1 - - 2 files changed, 11 deletions(-) - delete mode 100644 automation/eclair_analysis/ECLAIR/B.UNEVALEFF.ecl - -diff --git a/automation/eclair_analysis/ECLAIR/B.UNEVALEFF.ecl b/automation/eclair_analysis/ECLAIR/B.UNEVALEFF.ecl -deleted file mode 100644 -index fa249b8e3625..000000000000 ---- a/automation/eclair_analysis/ECLAIR/B.UNEVALEFF.ecl -+++ /dev/null -@@ -1,10 +0,0 @@ ---clone_service=MC3A2.R13.6,B.UNEVALEFF -- ---config=B.UNEVALEFF,summary="The operand of the `alignof' and `typeof' operators shall not contain any expression which has potential side effects" ---config=B.UNEVALEFF,stmt_child_matcher= --{"stmt(node(utrait_expr)&&operator(alignof))", expr, 0, "stmt(any())", {}}, --{"stmt(node(utrait_type)&&operator(alignof))", type, 0, "stmt(any())", {}}, --{"stmt(node(utrait_expr)&&operator(preferred_alignof))", expr, 0, "stmt(any())", {}}, --{"stmt(node(utrait_type)&&operator(preferred_alignof))", type, 0, "stmt(any())", {}}, --{"type(node(typeof_expr))", expr, 0, "stmt(any())", {}}, --{"type(node(typeof_type))", type, 0, "stmt(any())", {}} -diff --git a/automation/eclair_analysis/ECLAIR/analysis.ecl b/automation/eclair_analysis/ECLAIR/analysis.ecl -index 824283a989c1..8326156b389e 100644 ---- a/automation/eclair_analysis/ECLAIR/analysis.ecl -+++ b/automation/eclair_analysis/ECLAIR/analysis.ecl -@@ -52,7 +52,6 @@ their Standard Library equivalents." - -eval_file=adopted.ecl - -eval_file=out_of_scope.ecl - ---eval_file=B.UNEVALEFF.ecl - -eval_file=deviations.ecl - -eval_file=call_properties.ecl - -eval_file=tagging.ecl --- -2.49.0 - diff --git a/0304-tools-libxl-do-not-use-c-E-compiler-options-together.patch b/0304-tools-libxl-do-not-use-c-E-compiler-options-together.patch deleted file mode 100644 index 99a45ca2..00000000 --- a/0304-tools-libxl-do-not-use-c-E-compiler-options-together.patch +++ /dev/null @@ -1,40 +0,0 @@ -From 2389f0a3b2c36737e99e942cff3da2cf33050831 Mon Sep 17 00:00:00 2001 -From: Roger Pau Monne -Date: Mon, 7 Apr 2025 13:09:38 +0200 -Subject: [PATCH] tools/libxl: do not use `-c -E` compiler options together -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -It makes no sense to request for preprocessor only output and also request -object file generation. Fix the _libxl.api-for-check target to only use --E (preprocessor output). - -Also Clang 20.0 reports an error if both options are used. - -Reported-by: Andrew Cooper -Fixes: 2862bf5b6c81 ('libxl: enforce prohibitions of internal callers') -Signed-off-by: Roger Pau Monné -Acked-by: Andrew Cooper -Acked-by: Anthony PERARD -(cherry picked from commit a235f856e4bbd270b085590e1f5fc9599234dcdf) ---- - tools/libs/light/Makefile | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/tools/libs/light/Makefile b/tools/libs/light/Makefile -index 37e4d1670986..b690d921593d 100644 ---- a/tools/libs/light/Makefile -+++ b/tools/libs/light/Makefile -@@ -195,7 +195,7 @@ libxl.api-ok: check-libxl-api-rules _libxl.api-for-check - touch $@ - - _libxl.api-for-check: $(XEN_INCLUDE)/libxl.h -- $(CC) $(CPPFLAGS) $(CFLAGS) -c -E $< $(APPEND_CFLAGS) \ -+ $(CC) $(CPPFLAGS) $(CFLAGS) -E $< $(APPEND_CFLAGS) \ - -DLIBXL_EXTERNAL_CALLERS_ONLY=LIBXL_EXTERNAL_CALLERS_ONLY \ - >$@.new - mv -f $@.new $@ --- -2.49.0 - diff --git a/0305-xen-lib-Introduce-SHA2-256.patch b/0305-xen-lib-Introduce-SHA2-256.patch deleted file mode 100644 index 306ae009..00000000 --- a/0305-xen-lib-Introduce-SHA2-256.patch +++ /dev/null @@ -1,342 +0,0 @@ -From 3cc6a924d78f32b98790db274379ff5f9e946225 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Fri, 13 Dec 2024 14:34:00 +0000 -Subject: [PATCH] xen/lib: Introduce SHA2-256 -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -A future change will need to calculate SHA2-256 digests. Introduce an -implementation in lib/, derived from Trenchboot which itself is derived from -Linux. - -In order to be useful to other architectures, it is careful with endianness -and misaligned accesses as well as being more MISRA friendly, but is only -wired up for x86 in the short term. - -Signed-off-by: Andrew Cooper -Acked-by: Roger Pau Monné -(cherry picked from commit 372af524411f5a013bcb0b117073d8d07c026563) - -Xen: CI fix from XSN-2 - - * Add U suffix to the K[] table to fix MISRA Rule 7.2 violations. - -Fixes: 372af524411f ("xen/lib: Introduce SHA2-256") -Signed-off-by: Andrew Cooper -Reviewed-by: Stefano Stabellini -(cherry picked from commit 15fe2eb5f1bac8a212c0ba3d6dfe60d1fdf851cf) ---- - xen/include/xen/sha2.h | 15 +++ - xen/lib/Makefile | 1 + - xen/lib/sha2-256.c | 264 +++++++++++++++++++++++++++++++++++++++++ - 3 files changed, 280 insertions(+) - create mode 100644 xen/include/xen/sha2.h - create mode 100644 xen/lib/sha2-256.c - -diff --git a/xen/include/xen/sha2.h b/xen/include/xen/sha2.h -new file mode 100644 -index 000000000000..47d97fbf0194 ---- /dev/null -+++ b/xen/include/xen/sha2.h -@@ -0,0 +1,15 @@ -+/* SPDX-License-Identifier: GPL-2.0-or-later */ -+/* -+ * SHA2-256: https://csrc.nist.gov/pubs/fips/180-2/upd1/final -+ */ -+#ifndef XEN_SHA2_H -+#define XEN_SHA2_H -+ -+#include -+ -+#define SHA2_256_DIGEST_SIZE 32 -+ -+void sha2_256_digest(uint8_t digest[SHA2_256_DIGEST_SIZE], -+ const void *msg, size_t len); -+ -+#endif /* XEN_SHA2_H */ -diff --git a/xen/lib/Makefile b/xen/lib/Makefile -index a48541596470..03e33baaa016 100644 ---- a/xen/lib/Makefile -+++ b/xen/lib/Makefile -@@ -16,6 +16,7 @@ lib-y += memset.o - lib-y += muldiv64.o - lib-y += parse-size.o - lib-y += rbtree.o -+lib-$(CONFIG_X86) += sha2-256.o - lib-y += sort.o - lib-y += strcasecmp.o - lib-y += strchr.o -diff --git a/xen/lib/sha2-256.c b/xen/lib/sha2-256.c -new file mode 100644 -index 000000000000..19e8252188f7 ---- /dev/null -+++ b/xen/lib/sha2-256.c -@@ -0,0 +1,264 @@ -+/* SPDX-License-Identifier: GPL-2.0-or-later */ -+/* -+ * SHA2-256: https://csrc.nist.gov/pubs/fips/180-2/upd1/final -+ * -+ * Originally derived from Linux. Modified substantially to optimise for size -+ * and Xen's expected usecases. -+ */ -+#include -+#include -+#include -+#include -+ -+struct sha2_256_state { -+ uint32_t state[SHA2_256_DIGEST_SIZE / sizeof(uint32_t)]; -+ uint8_t buf[64]; -+ size_t count; /* Byte count. */ -+}; -+ -+static uint32_t choose(uint32_t x, uint32_t y, uint32_t z) -+{ -+ return z ^ (x & (y ^ z)); -+} -+ -+static uint32_t majority(uint32_t x, uint32_t y, uint32_t z) -+{ -+ return (x & y) | (z & (x | y)); -+} -+ -+static uint32_t e0(uint32_t x) -+{ -+ return ror32(x, 2) ^ ror32(x, 13) ^ ror32(x, 22); -+} -+ -+static uint32_t e1(uint32_t x) -+{ -+ return ror32(x, 6) ^ ror32(x, 11) ^ ror32(x, 25); -+} -+ -+static uint32_t s0(uint32_t x) -+{ -+ return ror32(x, 7) ^ ror32(x, 18) ^ (x >> 3); -+} -+ -+static uint32_t s1(uint32_t x) -+{ -+ return ror32(x, 17) ^ ror32(x, 19) ^ (x >> 10); -+} -+ -+static uint32_t blend(uint32_t W[16], unsigned int i) -+{ -+#define W(i) W[(i) & 15] -+ -+ return W(i) += s1(W(i - 2)) + W(i - 7) + s0(W(i - 15)); -+ -+#undef W -+} -+ -+static const uint32_t K[] = { -+ 0x428a2f98U, 0x71374491U, 0xb5c0fbcfU, 0xe9b5dba5U, -+ 0x3956c25bU, 0x59f111f1U, 0x923f82a4U, 0xab1c5ed5U, -+ 0xd807aa98U, 0x12835b01U, 0x243185beU, 0x550c7dc3U, -+ 0x72be5d74U, 0x80deb1feU, 0x9bdc06a7U, 0xc19bf174U, -+ 0xe49b69c1U, 0xefbe4786U, 0x0fc19dc6U, 0x240ca1ccU, -+ 0x2de92c6fU, 0x4a7484aaU, 0x5cb0a9dcU, 0x76f988daU, -+ 0x983e5152U, 0xa831c66dU, 0xb00327c8U, 0xbf597fc7U, -+ 0xc6e00bf3U, 0xd5a79147U, 0x06ca6351U, 0x14292967U, -+ 0x27b70a85U, 0x2e1b2138U, 0x4d2c6dfcU, 0x53380d13U, -+ 0x650a7354U, 0x766a0abbU, 0x81c2c92eU, 0x92722c85U, -+ 0xa2bfe8a1U, 0xa81a664bU, 0xc24b8b70U, 0xc76c51a3U, -+ 0xd192e819U, 0xd6990624U, 0xf40e3585U, 0x106aa070U, -+ 0x19a4c116U, 0x1e376c08U, 0x2748774cU, 0x34b0bcb5U, -+ 0x391c0cb3U, 0x4ed8aa4aU, 0x5b9cca4fU, 0x682e6ff3U, -+ 0x748f82eeU, 0x78a5636fU, 0x84c87814U, 0x8cc70208U, -+ 0x90befffaU, 0xa4506cebU, 0xbef9a3f7U, 0xc67178f2U, -+}; -+ -+static void sha2_256_transform(uint32_t *state, const void *_input) -+{ -+ const uint32_t *input = _input; -+ uint32_t a, b, c, d, e, f, g, h, t1, t2; -+ uint32_t W[16]; -+ unsigned int i; -+ -+ for ( i = 0; i < 16; i++ ) -+ W[i] = get_unaligned_be32(&input[i]); -+ -+ a = state[0]; b = state[1]; c = state[2]; d = state[3]; -+ e = state[4]; f = state[5]; g = state[6]; h = state[7]; -+ -+ for ( i = 0; i < 16; i += 8 ) -+ { -+ t1 = h + e1(e) + choose(e, f, g) + K[i + 0] + W[i + 0]; -+ t2 = e0(a) + majority(a, b, c); d += t1; h = t1 + t2; -+ t1 = g + e1(d) + choose(d, e, f) + K[i + 1] + W[i + 1]; -+ t2 = e0(h) + majority(h, a, b); c += t1; g = t1 + t2; -+ t1 = f + e1(c) + choose(c, d, e) + K[i + 2] + W[i + 2]; -+ t2 = e0(g) + majority(g, h, a); b += t1; f = t1 + t2; -+ t1 = e + e1(b) + choose(b, c, d) + K[i + 3] + W[i + 3]; -+ t2 = e0(f) + majority(f, g, h); a += t1; e = t1 + t2; -+ t1 = d + e1(a) + choose(a, b, c) + K[i + 4] + W[i + 4]; -+ t2 = e0(e) + majority(e, f, g); h += t1; d = t1 + t2; -+ t1 = c + e1(h) + choose(h, a, b) + K[i + 5] + W[i + 5]; -+ t2 = e0(d) + majority(d, e, f); g += t1; c = t1 + t2; -+ t1 = b + e1(g) + choose(g, h, a) + K[i + 6] + W[i + 6]; -+ t2 = e0(c) + majority(c, d, e); f += t1; b = t1 + t2; -+ t1 = a + e1(f) + choose(f, g, h) + K[i + 7] + W[i + 7]; -+ t2 = e0(b) + majority(b, c, d); e += t1; a = t1 + t2; -+ } -+ -+ for ( ; i < 64; i += 8 ) -+ { -+ t1 = h + e1(e) + choose(e, f, g) + K[i + 0] + blend(W, i + 0); -+ t2 = e0(a) + majority(a, b, c); d += t1; h = t1 + t2; -+ t1 = g + e1(d) + choose(d, e, f) + K[i + 1] + blend(W, i + 1); -+ t2 = e0(h) + majority(h, a, b); c += t1; g = t1 + t2; -+ t1 = f + e1(c) + choose(c, d, e) + K[i + 2] + blend(W, i + 2); -+ t2 = e0(g) + majority(g, h, a); b += t1; f = t1 + t2; -+ t1 = e + e1(b) + choose(b, c, d) + K[i + 3] + blend(W, i + 3); -+ t2 = e0(f) + majority(f, g, h); a += t1; e = t1 + t2; -+ t1 = d + e1(a) + choose(a, b, c) + K[i + 4] + blend(W, i + 4); -+ t2 = e0(e) + majority(e, f, g); h += t1; d = t1 + t2; -+ t1 = c + e1(h) + choose(h, a, b) + K[i + 5] + blend(W, i + 5); -+ t2 = e0(d) + majority(d, e, f); g += t1; c = t1 + t2; -+ t1 = b + e1(g) + choose(g, h, a) + K[i + 6] + blend(W, i + 6); -+ t2 = e0(c) + majority(c, d, e); f += t1; b = t1 + t2; -+ t1 = a + e1(f) + choose(f, g, h) + K[i + 7] + blend(W, i + 7); -+ t2 = e0(b) + majority(b, c, d); e += t1; a = t1 + t2; -+ } -+ -+ state[0] += a; state[1] += b; state[2] += c; state[3] += d; -+ state[4] += e; state[5] += f; state[6] += g; state[7] += h; -+} -+ -+static void sha2_256_init(struct sha2_256_state *s) -+{ -+ *s = (struct sha2_256_state){ -+ .state = { -+ 0x6a09e667UL, -+ 0xbb67ae85UL, -+ 0x3c6ef372UL, -+ 0xa54ff53aUL, -+ 0x510e527fUL, -+ 0x9b05688cUL, -+ 0x1f83d9abUL, -+ 0x5be0cd19UL, -+ }, -+ }; -+} -+ -+static void sha2_256_update(struct sha2_256_state *s, const void *msg, -+ size_t len) -+{ -+ unsigned int partial = s->count & 63; -+ -+ s->count += len; -+ -+ if ( (partial + len) >= 64 ) -+ { -+ if ( partial ) -+ { -+ unsigned int rem = 64 - partial; -+ -+ /* Fill the partial block. */ -+ memcpy(s->buf + partial, msg, rem); -+ msg += rem; -+ len -= rem; -+ -+ sha2_256_transform(s->state, s->buf); -+ partial = 0; -+ } -+ -+ for ( ; len >= 64; msg += 64, len -= 64 ) -+ sha2_256_transform(s->state, msg); -+ } -+ -+ /* Remaining data becomes partial. */ -+ memcpy(s->buf + partial, msg, len); -+} -+ -+static void sha2_256_final(struct sha2_256_state *s, void *_dst) -+{ -+ uint32_t *dst = _dst; -+ unsigned int i, partial = s->count & 63; -+ -+ /* Start padding */ -+ s->buf[partial++] = 0x80; -+ -+ if ( partial > 56 ) -+ { -+ /* Need one extra block - pad to 64 */ -+ memset(s->buf + partial, 0, 64 - partial); -+ sha2_256_transform(s->state, s->buf); -+ partial = 0; -+ } -+ /* Pad to 56 */ -+ memset(s->buf + partial, 0, 56 - partial); -+ -+ /* Append the bit count */ -+ put_unaligned_be64((uint64_t)s->count << 3, &s->buf[56]); -+ sha2_256_transform(s->state, s->buf); -+ -+ /* Store state in digest */ -+ for ( i = 0; i < 8; i++ ) -+ put_unaligned_be32(s->state[i], &dst[i]); -+} -+ -+void sha2_256_digest(uint8_t digest[SHA2_256_DIGEST_SIZE], -+ const void *msg, size_t len) -+{ -+ struct sha2_256_state s; -+ -+ sha2_256_init(&s); -+ sha2_256_update(&s, msg, len); -+ sha2_256_final(&s, digest); -+} -+ -+#ifdef CONFIG_SELF_TESTS -+ -+#include -+#include -+ -+static const struct test { -+ const char *msg; -+ uint8_t digest[SHA2_256_DIGEST_SIZE]; -+} tests[] __initconst = { -+ { -+ .msg = "abc", -+ .digest = { -+ 0xba, 0x78, 0x16, 0xbf, 0x8f, 0x01, 0xcf, 0xea, -+ 0x41, 0x41, 0x40, 0xde, 0x5d, 0xae, 0x22, 0x23, -+ 0xb0, 0x03, 0x61, 0xa3, 0x96, 0x17, 0x7a, 0x9c, -+ 0xb4, 0x10, 0xff, 0x61, 0xf2, 0x00, 0x15, 0xad, -+ }, -+ }, -+ { -+ .msg = "abcdbcdecdefdefgefghfghighijhijkijkljklmklmnlmnomnopnopq", -+ .digest = { -+ 0x24, 0x8d, 0x6a, 0x61, 0xd2, 0x06, 0x38, 0xb8, -+ 0xe5, 0xc0, 0x26, 0x93, 0x0c, 0x3e, 0x60, 0x39, -+ 0xa3, 0x3c, 0xe4, 0x59, 0x64, 0xff, 0x21, 0x67, -+ 0xf6, 0xec, 0xed, 0xd4, 0x19, 0xdb, 0x06, 0xc1, -+ }, -+ }, -+}; -+ -+static void __init __constructor test_sha2_256(void) -+{ -+ for ( unsigned int i = 0; i < ARRAY_SIZE(tests); ++i ) -+ { -+ const struct test *t = &tests[i]; -+ uint8_t res[SHA2_256_DIGEST_SIZE] = {}; -+ -+ sha2_256_digest(res, t->msg, strlen(t->msg)); -+ -+ if ( memcmp(res, t->digest, sizeof(t->digest)) == 0 ) -+ continue; -+ -+ panic("%s() msg '%s' failed\n" -+ " expected %" STR(SHA2_256_DIGEST_SIZE) "phN\n" -+ " got %" STR(SHA2_256_DIGEST_SIZE) "phN\n", -+ __func__, t->msg, t->digest, res); -+ } -+} -+#endif /* CONFIG_SELF_TESTS */ --- -2.49.0 - diff --git a/0306-x86-ucode-Perform-extra-SHA2-checks-on-AMD-Fam17h-19.patch b/0306-x86-ucode-Perform-extra-SHA2-checks-on-AMD-Fam17h-19.patch deleted file mode 100644 index 41584fac..00000000 --- a/0306-x86-ucode-Perform-extra-SHA2-checks-on-AMD-Fam17h-19.patch +++ /dev/null @@ -1,444 +0,0 @@ -From 56d85952addb47f7341ad5d5d67aab002c7e7118 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Fri, 13 Dec 2024 14:34:00 +0000 -Subject: [PATCH] x86/ucode: Perform extra SHA2 checks on AMD Fam17h/19h - microcode -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Collisions have been found in the microcode signing algorithm used by AMD -Fam17h/19h CPUs, and now anyone can sign their own. - -For more details, see: - https://bughunters.google.com/blog/5424842357473280/zen-and-the-art-of-microcode-hacking - https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html - -As a stopgap mitigation, check the digest of patches against a table of blobs -with known provenance. These are all Fam17h and Fam19h blobs included in -linux-firwmare at the time of writing, specifically: - - https://git.kernel.org/firmware/linux-firmware/c/48bb90cceb882cab8e9ab692bc5779d3bf3a13b8 - -This checks can be opted out of by booting with ucode=no-digest-check, but -doing so is not recommended. - -Signed-off-by: Andrew Cooper -Acked-by: Roger Pau Monné -(cherry picked from commit 630e8875ab368b97cc7231aaf3809e3d7d5687e1) - -Xen: CI fix from XSN-2 - - * Add cf_check annotation to cmp_patch_id() used by bsearch(). - -Fixes: 630e8875ab36 ("x86/ucode: Perform extra SHA2 checks on AMD Fam17h/19h microcode") -Signed-off-by: Andrew Cooper -Reviewed-by: Stefano Stabellini -(cherry picked from commit 15fe2eb5f1bac8a212c0ba3d6dfe60d1fdf851cf) ---- - docs/misc/xen-command-line.pandoc | 10 +- - .../x86/cpu/microcode/amd-patch-digests.c | 226 ++++++++++++++++++ - xen/arch/x86/cpu/microcode/amd.c | 66 ++++- - xen/arch/x86/cpu/microcode/core.c | 3 + - xen/arch/x86/cpu/microcode/private.h | 2 + - 5 files changed, 304 insertions(+), 3 deletions(-) - create mode 100644 xen/arch/x86/cpu/microcode/amd-patch-digests.c - -diff --git a/docs/misc/xen-command-line.pandoc b/docs/misc/xen-command-line.pandoc -index ff10ff9f658e..559fb21c5bc9 100644 ---- a/docs/misc/xen-command-line.pandoc -+++ b/docs/misc/xen-command-line.pandoc -@@ -2671,10 +2671,10 @@ performance. - Alternatively, selecting `tsx=1` will re-enable TSX at the users own risk. - - ### ucode --> `= List of [ | scan=, nmi=, allow-same= ]` -+> `= List of [ | scan=, nmi=, allow-same=, digest-check= ]` - - Applicability: x86 -- Default: `nmi` -+ Default: `nmi,digest-check` - - Controls for CPU microcode loading. For early loading, this parameter can - specify how and where to find the microcode update blob. For late loading, -@@ -2708,6 +2708,12 @@ trying to reload the same version. Many CPUs will actually reload microcode - of the same version, and this allows for easy testing of the late microcode - loading path. - -+The `digest-check=` option is active by default and controls whether to -+perform additional authenticity checks. Collisions in the signature algorithm -+used by AMD Fam17h/19h processors have been found. Xen contains a table of -+digests of microcode patches with known-good provenance, and will block -+loading of patches that do not match. -+ - ### unrestricted_guest (Intel) - > `= ` - -diff --git a/xen/arch/x86/cpu/microcode/amd-patch-digests.c b/xen/arch/x86/cpu/microcode/amd-patch-digests.c -new file mode 100644 -index 000000000000..d32761226712 ---- /dev/null -+++ b/xen/arch/x86/cpu/microcode/amd-patch-digests.c -@@ -0,0 +1,226 @@ -+/* Generated from linux-firmware. */ -+{ -+ .patch_id = 0x0800126f, -+ .digest = { -+ 0x2b, 0x5a, 0xf2, 0x9c, 0xdd, 0xd2, 0x7f, 0xec, -+ 0xec, 0x96, 0x09, 0x57, 0xb0, 0x96, 0x29, 0x8b, -+ 0x2e, 0x26, 0x91, 0xf0, 0x49, 0x33, 0x42, 0x18, -+ 0xdd, 0x4b, 0x65, 0x5a, 0xd4, 0x15, 0x3d, 0x33, -+ }, -+}, -+{ -+ .patch_id = 0x0800820d, -+ .digest = { -+ 0x68, 0x98, 0x83, 0xcd, 0x22, 0x0d, 0xdd, 0x59, -+ 0x73, 0x2c, 0x5b, 0x37, 0x1f, 0x84, 0x0e, 0x67, -+ 0x96, 0x43, 0x83, 0x0c, 0x46, 0x44, 0xab, 0x7c, -+ 0x7b, 0x65, 0x9e, 0x57, 0xb5, 0x90, 0x4b, 0x0e, -+ }, -+}, -+{ -+ .patch_id = 0x0830107c, -+ .digest = { -+ 0x21, 0x64, 0xde, 0xfb, 0x9f, 0x68, 0x96, 0x47, -+ 0x70, 0x5c, 0xe2, 0x8f, 0x18, 0x52, 0x6a, 0xac, -+ 0xa4, 0xd2, 0x2e, 0xe0, 0xde, 0x68, 0x66, 0xc3, -+ 0xeb, 0x1e, 0xd3, 0x3f, 0xbc, 0x51, 0x1d, 0x38, -+ }, -+}, -+{ -+ .patch_id = 0x0860010d, -+ .digest = { -+ 0x86, 0xb6, 0x15, 0x83, 0xbc, 0x3b, 0x9c, 0xe0, -+ 0xb3, 0xef, 0x1d, 0x99, 0x84, 0x35, 0x15, 0xf7, -+ 0x7c, 0x2a, 0xc6, 0x42, 0xdb, 0x73, 0x07, 0x5c, -+ 0x7d, 0xc3, 0x02, 0xb5, 0x43, 0x06, 0x5e, 0xf8, -+ }, -+}, -+{ -+ .patch_id = 0x08608108, -+ .digest = { -+ 0x14, 0xfe, 0x57, 0x86, 0x49, 0xc8, 0x68, 0xe2, -+ 0x11, 0xa3, 0xcb, 0x6e, 0xff, 0x6e, 0xd5, 0x38, -+ 0xfe, 0x89, 0x1a, 0xe0, 0x67, 0xbf, 0xc4, 0xcc, -+ 0x1b, 0x9f, 0x84, 0x77, 0x2b, 0x9f, 0xaa, 0xbd, -+ }, -+}, -+{ -+ .patch_id = 0x08701034, -+ .digest = { -+ 0xc3, 0x14, 0x09, 0xa8, 0x9c, 0x3f, 0x8d, 0x83, -+ 0x9b, 0x4c, 0xa5, 0xb7, 0x64, 0x8b, 0x91, 0x5d, -+ 0x85, 0x6a, 0x39, 0x26, 0x1e, 0x14, 0x41, 0xa8, -+ 0x75, 0xea, 0xa6, 0xf9, 0xc9, 0xd1, 0xea, 0x2b, -+ }, -+}, -+{ -+ .patch_id = 0x08a0000a, -+ .digest = { -+ 0x73, 0x31, 0x26, 0x22, 0xd4, 0xf9, 0xee, 0x3c, -+ 0x07, 0x06, 0xe7, 0xb9, 0xad, 0xd8, 0x72, 0x44, -+ 0x33, 0x31, 0xaa, 0x7d, 0xc3, 0x67, 0x0e, 0xdb, -+ 0x47, 0xb5, 0xaa, 0xbc, 0xf5, 0xbb, 0xd9, 0x20, -+ }, -+}, -+{ -+ .patch_id = 0x0a00107a, -+ .digest = { -+ 0x5f, 0x92, 0xca, 0xff, 0xc3, 0x59, 0x22, 0x5f, -+ 0x02, 0xa0, 0x91, 0x3b, 0x4a, 0x45, 0x10, 0xfd, -+ 0x19, 0xe1, 0x8a, 0x6d, 0x9a, 0x92, 0xc1, 0x3f, -+ 0x75, 0x78, 0xac, 0x78, 0x03, 0x1d, 0xdb, 0x18, -+ }, -+}, -+{ -+ .patch_id = 0x0a0011d5, -+ .digest = { -+ 0xed, 0x69, 0x89, 0xf4, 0xeb, 0x64, 0xc2, 0x13, -+ 0xe0, 0x51, 0x1f, 0x03, 0x26, 0x52, 0x7d, 0xb7, -+ 0x93, 0x5d, 0x65, 0xca, 0xb8, 0x12, 0x1d, 0x62, -+ 0x0d, 0x5b, 0x65, 0x34, 0x69, 0xb2, 0x62, 0x21, -+ }, -+}, -+{ -+ .patch_id = 0x0a001238, -+ .digest = { -+ 0x72, 0xf7, 0x4b, 0x0c, 0x7d, 0x58, 0x65, 0xcc, -+ 0x00, 0xcc, 0x57, 0x16, 0x68, 0x16, 0xf8, 0x2a, -+ 0x1b, 0xb3, 0x8b, 0xe1, 0xb6, 0x83, 0x8c, 0x7e, -+ 0xc0, 0xcd, 0x33, 0xf2, 0x8d, 0xf9, 0xef, 0x59, -+ }, -+}, -+{ -+ .patch_id = 0x0a00820c, -+ .digest = { -+ 0xa8, 0x0c, 0x81, 0xc0, 0xa6, 0x00, 0xe7, 0xf3, -+ 0x5f, 0x65, 0xd3, 0xb9, 0x6f, 0xea, 0x93, 0x63, -+ 0xf1, 0x8c, 0x88, 0x45, 0xd7, 0x82, 0x80, 0xd1, -+ 0xe1, 0x3b, 0x8d, 0xb2, 0xf8, 0x22, 0x03, 0xe2, -+ }, -+}, -+{ -+ .patch_id = 0x0a101148, -+ .digest = { -+ 0x20, 0xd5, 0x6f, 0x40, 0x4a, 0xf6, 0x48, 0x90, -+ 0xc2, 0x93, 0x9a, 0xc2, 0xfd, 0xac, 0xef, 0x4f, -+ 0xfa, 0xc0, 0x3d, 0x92, 0x3c, 0x6d, 0x01, 0x08, -+ 0xf1, 0x5e, 0xb0, 0xde, 0xb4, 0x98, 0xae, 0xc4, -+ }, -+}, -+{ -+ .patch_id = 0x0a101248, -+ .digest = { -+ 0xed, 0x3b, 0x95, 0xa6, 0x68, 0xa7, 0x77, 0x3e, -+ 0xfc, 0x17, 0x26, 0xe2, 0x7b, 0xd5, 0x56, 0x22, -+ 0x2c, 0x1d, 0xef, 0xeb, 0x56, 0xdd, 0xba, 0x6e, -+ 0x1b, 0x7d, 0x64, 0x9d, 0x4b, 0x53, 0x13, 0x75, -+ }, -+}, -+{ -+ .patch_id = 0x0a108108, -+ .digest = { -+ 0xed, 0xc2, 0xec, 0xa1, 0x15, 0xc6, 0x65, 0xe9, -+ 0xd0, 0xef, 0x39, 0xaa, 0x7f, 0x55, 0x06, 0xc6, -+ 0xf5, 0xd4, 0x3f, 0x7b, 0x14, 0xd5, 0x60, 0x2c, -+ 0x28, 0x1e, 0x9c, 0x59, 0x69, 0x99, 0x4d, 0x16, -+ }, -+}, -+{ -+ .patch_id = 0x0a20102d, -+ .digest = { -+ 0xf9, 0x6e, 0xf2, 0x32, 0xd3, 0x0f, 0x5f, 0x11, -+ 0x59, 0xa1, 0xfe, 0xcc, 0xcd, 0x9b, 0x42, 0x89, -+ 0x8b, 0x89, 0x2f, 0xb5, 0xbb, 0x82, 0xef, 0x23, -+ 0x8c, 0xe9, 0x19, 0x3e, 0xcc, 0x3f, 0x7b, 0xb4, -+ }, -+}, -+{ -+ .patch_id = 0x0a201210, -+ .digest = { -+ 0xe8, 0x6d, 0x51, 0x6a, 0x8e, 0x72, 0xf3, 0xfe, -+ 0x6e, 0x16, 0xbc, 0x62, 0x59, 0x40, 0x17, 0xe9, -+ 0x6d, 0x3d, 0x0e, 0x6b, 0xa7, 0xac, 0xe3, 0x68, -+ 0xf7, 0x55, 0xf0, 0x13, 0xbb, 0x22, 0xf6, 0x41, -+ }, -+}, -+{ -+ .patch_id = 0x0a404107, -+ .digest = { -+ 0xbb, 0x04, 0x4e, 0x47, 0xdd, 0x5e, 0x26, 0x45, -+ 0x1a, 0xc9, 0x56, 0x24, 0xa4, 0x4c, 0x82, 0xb0, -+ 0x8b, 0x0d, 0x9f, 0xf9, 0x3a, 0xdf, 0xc6, 0x81, -+ 0x13, 0xbc, 0xc5, 0x25, 0xe4, 0xc5, 0xc3, 0x99, -+ }, -+}, -+{ -+ .patch_id = 0x0a500011, -+ .digest = { -+ 0x23, 0x3d, 0x70, 0x7d, 0x03, 0xc3, 0xc4, 0xf4, -+ 0x2b, 0x82, 0xc6, 0x05, 0xda, 0x80, 0x0a, 0xf1, -+ 0xd7, 0x5b, 0x65, 0x3a, 0x7d, 0xab, 0xdf, 0xa2, -+ 0x11, 0x5e, 0x96, 0x7e, 0x71, 0xe9, 0xfc, 0x74, -+ }, -+}, -+{ -+ .patch_id = 0x0a601209, -+ .digest = { -+ 0x66, 0x48, 0xd4, 0x09, 0x05, 0xcb, 0x29, 0x32, -+ 0x66, 0xb7, 0x9a, 0x76, 0xcd, 0x11, 0xf3, 0x30, -+ 0x15, 0x86, 0xcc, 0x5d, 0x97, 0x0f, 0xc0, 0x46, -+ 0xe8, 0x73, 0xe2, 0xd6, 0xdb, 0xd2, 0x77, 0x1d, -+ }, -+}, -+{ -+ .patch_id = 0x0a704107, -+ .digest = { -+ 0xf3, 0xc6, 0x58, 0x26, 0xee, 0xac, 0x3f, 0xd6, -+ 0xce, 0xa1, 0x72, 0x47, 0x3b, 0xba, 0x2b, 0x93, -+ 0x2a, 0xad, 0x8e, 0x6b, 0xea, 0x9b, 0xb7, 0xc2, -+ 0x64, 0x39, 0x71, 0x8c, 0xce, 0xe7, 0x41, 0x39, -+ }, -+}, -+{ -+ .patch_id = 0x0a705206, -+ .digest = { -+ 0x8d, 0xc0, 0x76, 0xbd, 0x58, 0x9f, 0x8f, 0xa4, -+ 0x12, 0x9d, 0x21, 0xfb, 0x48, 0x21, 0xbc, 0xe7, -+ 0x67, 0x6f, 0x04, 0x18, 0xae, 0x20, 0x87, 0x4b, -+ 0x03, 0x35, 0xe9, 0xbe, 0xfb, 0x06, 0xdf, 0xfc, -+ }, -+}, -+{ -+ .patch_id = 0x0a708007, -+ .digest = { -+ 0x6b, 0x76, 0xcc, 0x78, 0xc5, 0x8a, 0xa3, 0xe3, -+ 0x32, 0x2d, 0x79, 0xe4, 0xc3, 0x80, 0xdb, 0xb2, -+ 0x07, 0xaa, 0x3a, 0xe0, 0x57, 0x13, 0x72, 0x80, -+ 0xdf, 0x92, 0x73, 0x84, 0x87, 0x3c, 0x73, 0x93, -+ }, -+}, -+{ -+ .patch_id = 0x0a70c005, -+ .digest = { -+ 0x88, 0x5d, 0xfb, 0x79, 0x64, 0xd8, 0x46, 0x3b, -+ 0x4a, 0x83, 0x8e, 0x77, 0x7e, 0xcf, 0xb3, 0x0f, -+ 0x1f, 0x1f, 0xf1, 0x97, 0xeb, 0xfe, 0x56, 0x55, -+ 0xee, 0x49, 0xac, 0xe1, 0x8b, 0x13, 0xc5, 0x13, -+ }, -+}, -+{ -+ .patch_id = 0x0aa00116, -+ .digest = { -+ 0xe8, 0x4c, 0x2c, 0x88, 0xa1, 0xac, 0x24, 0x63, -+ 0x65, 0xe5, 0xaa, 0x2d, 0x16, 0xa9, 0xc3, 0xf5, -+ 0xfe, 0x1d, 0x5e, 0x65, 0xc7, 0xaa, 0x92, 0x4d, -+ 0x91, 0xee, 0x76, 0xbb, 0x4c, 0x66, 0x78, 0xc9, -+ }, -+}, -+{ -+ .patch_id = 0x0aa00215, -+ .digest = { -+ 0x55, 0xd3, 0x28, 0xcb, 0x87, 0xa9, 0x32, 0xe9, -+ 0x4e, 0x85, 0x4b, 0x7c, 0x6b, 0xd5, 0x7c, 0xd4, -+ 0x1b, 0x51, 0x71, 0x3a, 0x0e, 0x0b, 0xdc, 0x9b, -+ 0x68, 0x2f, 0x46, 0xee, 0xfe, 0xc6, 0x6d, 0xef, -+ }, -+}, -diff --git a/xen/arch/x86/cpu/microcode/amd.c b/xen/arch/x86/cpu/microcode/amd.c -index 31fbd326e552..e17c60fe3bee 100644 ---- a/xen/arch/x86/cpu/microcode/amd.c -+++ b/xen/arch/x86/cpu/microcode/amd.c -@@ -16,7 +16,9 @@ - - #include - #include -+#include - #include /* TODO: Fix asm/tlbflush.h breakage */ -+#include - - #include - -@@ -91,6 +93,59 @@ static struct { - uint16_t id; - } equiv __read_mostly; - -+static const struct patch_digest { -+ uint32_t patch_id; -+ uint8_t digest[SHA2_256_DIGEST_SIZE]; -+} patch_digests[] = { -+#include "amd-patch-digests.c" -+}; -+ -+static int cf_check cmp_patch_id(const void *key, const void *elem) -+{ -+ const struct patch_digest *pd = elem; -+ uint32_t patch_id = *(uint32_t *)key; -+ -+ if ( patch_id == pd->patch_id ) -+ return 0; -+ else if ( patch_id < pd->patch_id ) -+ return -1; -+ return 1; -+} -+ -+static bool check_digest(const struct container_microcode *mc) -+{ -+ const struct microcode_patch *patch = mc->patch; -+ const struct patch_digest *pd; -+ uint8_t digest[SHA2_256_DIGEST_SIZE]; -+ -+ /* Only Fam17h/19h are known to need extra checks. Skip other families. */ -+ if ( boot_cpu_data.x86 < 0x17 || boot_cpu_data.x86 > 0x19 || -+ !opt_digest_check ) -+ return true; -+ -+ pd = bsearch(&patch->patch_id, patch_digests, ARRAY_SIZE(patch_digests), -+ sizeof(struct patch_digest), cmp_patch_id); -+ if ( !pd ) -+ { -+ printk(XENLOG_WARNING "No digest found for patch_id %08x\n", -+ patch->patch_id); -+ return false; -+ } -+ -+ sha2_256_digest(digest, patch, mc->len); -+ -+ if ( memcmp(digest, pd->digest, sizeof(digest)) ) -+ { -+ printk(XENLOG_WARNING "Patch %08x SHA256 mismatch:\n" -+ " expected %" STR(SHA2_256_DIGEST_SIZE) "phN\n" -+ " got %" STR(SHA2_256_DIGEST_SIZE) "phN\n", -+ patch->patch_id, pd->digest, digest); -+ return false; -+ } -+ -+ return true; -+} -+ - static void cf_check collect_cpu_info(void) - { - struct cpu_signature *csig = &this_cpu(cpu_sig); -@@ -394,7 +449,8 @@ static struct microcode_patch *cf_check cpu_request_microcode( - * one with higher revision. - */ - if ( (microcode_fits(mc->patch) != MIS_UCODE) && -- (!saved || (compare_header(mc->patch, saved) == NEW_UCODE)) ) -+ (!saved || (compare_header(mc->patch, saved) == NEW_UCODE)) && -+ check_digest(mc) ) - { - saved = mc->patch; - saved_size = mc->len; -@@ -449,6 +505,14 @@ static const struct microcode_ops __initconst_cf_clobber amd_ucode_ops = { - - void __init ucode_probe_amd(struct microcode_ops *ops) - { -+ if ( !opt_digest_check && -+ boot_cpu_data.x86 >= 0x17 && boot_cpu_data.x86 <= 0x19 ) -+ { -+ printk(XENLOG_WARNING -+ "Microcode patch additional digest checks disabled"); -+ add_taint(TAINT_CPU_OUT_OF_SPEC); -+ } -+ - if ( boot_cpu_data.x86 < 0x10 ) - return; - -diff --git a/xen/arch/x86/cpu/microcode/core.c b/xen/arch/x86/cpu/microcode/core.c -index 655bc41e076d..cae3d1ee3d2a 100644 ---- a/xen/arch/x86/cpu/microcode/core.c -+++ b/xen/arch/x86/cpu/microcode/core.c -@@ -99,6 +99,7 @@ static bool __initdata ucode_scan; - static bool ucode_in_nmi = true; - - bool __read_mostly opt_ucode_allow_same; -+bool __ro_after_init opt_digest_check = true; - - /* Protected by microcode_mutex */ - static struct microcode_patch *microcode_cache; -@@ -128,6 +129,8 @@ static int __init cf_check parse_ucode(const char *s) - ucode_in_nmi = val; - else if ( (val = parse_boolean("allow-same", s, ss)) >= 0 ) - opt_ucode_allow_same = val; -+ else if ( (val = parse_boolean("digest-check", s, ss)) >= 0 ) -+ opt_digest_check = val; - else if ( !ucode_mod_forced ) /* Not forced by EFI */ - { - if ( (val = parse_boolean("scan", s, ss)) >= 0 ) -diff --git a/xen/arch/x86/cpu/microcode/private.h b/xen/arch/x86/cpu/microcode/private.h -index da556fe5060a..ef134724d8fe 100644 ---- a/xen/arch/x86/cpu/microcode/private.h -+++ b/xen/arch/x86/cpu/microcode/private.h -@@ -60,6 +60,8 @@ struct microcode_ops { - const struct microcode_patch *new, const struct microcode_patch *old); - }; - -+extern bool opt_digest_check; -+ - /* - * Microcode loading falls into one of 3 states. - * - No support at all --- -2.49.0 - diff --git a/0307-x86-ucode-Extend-AMD-digest-checks-to-cover-Zen5-CPU.patch b/0307-x86-ucode-Extend-AMD-digest-checks-to-cover-Zen5-CPU.patch deleted file mode 100644 index e591c154..00000000 --- a/0307-x86-ucode-Extend-AMD-digest-checks-to-cover-Zen5-CPU.patch +++ /dev/null @@ -1,66 +0,0 @@ -From 465ccf84e382d367833924cc9fb44eb1580f2337 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 8 Apr 2025 17:09:15 +0100 -Subject: [PATCH] x86/ucode: Extend AMD digest checks to cover Zen5 CPUs -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -AMD have updated the SB-7033 advisory to include Zen5 CPUs. Extend the digest -check to cover Zen5 too. - -In practice, cover everything until further notice. - -Observant readers may be wondering where the update to the digest list is. At -the time of writing, no Zen5 patches are available via a verifiable channel. - -Link: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7033.html -Fixes: 630e8875ab36 ("x86/ucode: Perform extra SHA2 checks on AMD Fam17h/19h microcode") -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit b63951467e964bcc927f823fc943e40069fac0c9) - -x86/ucode: Extend warning about disabling digest check too - -This was missed by accident. - -Fixes: b63951467e96 ("x86/ucode: Extend AMD digest checks to cover Zen5 CPUs") -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit 59bb316ea89e7f9461690fe00547d7d2af96321d) ---- - xen/arch/x86/cpu/microcode/amd.c | 11 +++++++---- - 1 file changed, 7 insertions(+), 4 deletions(-) - -diff --git a/xen/arch/x86/cpu/microcode/amd.c b/xen/arch/x86/cpu/microcode/amd.c -index e17c60fe3bee..4f236e439929 100644 ---- a/xen/arch/x86/cpu/microcode/amd.c -+++ b/xen/arch/x86/cpu/microcode/amd.c -@@ -118,8 +118,12 @@ static bool check_digest(const struct container_microcode *mc) - const struct patch_digest *pd; - uint8_t digest[SHA2_256_DIGEST_SIZE]; - -- /* Only Fam17h/19h are known to need extra checks. Skip other families. */ -- if ( boot_cpu_data.x86 < 0x17 || boot_cpu_data.x86 > 0x19 || -+ /* -+ * Zen1 thru Zen5 CPUs are known to use a weak signature algorithm on -+ * microcode updates. Mitigate by checking the digest of the patch -+ * against a list of known provenance. -+ */ -+ if ( boot_cpu_data.x86 < 0x17 || - !opt_digest_check ) - return true; - -@@ -505,8 +509,7 @@ static const struct microcode_ops __initconst_cf_clobber amd_ucode_ops = { - - void __init ucode_probe_amd(struct microcode_ops *ops) - { -- if ( !opt_digest_check && -- boot_cpu_data.x86 >= 0x17 && boot_cpu_data.x86 <= 0x19 ) -+ if ( !opt_digest_check && boot_cpu_data.x86 >= 0x17 ) - { - printk(XENLOG_WARNING - "Microcode patch additional digest checks disabled"); --- -2.49.0 - diff --git a/0309-x86-MTRR-hook-mtrr_bp_restore-back-up.patch b/0309-x86-MTRR-hook-mtrr_bp_restore-back-up.patch deleted file mode 100644 index 47a80153..00000000 --- a/0309-x86-MTRR-hook-mtrr_bp_restore-back-up.patch +++ /dev/null @@ -1,71 +0,0 @@ -From ae562bee695b84240f35739374a013a1520b93e5 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 29 Apr 2025 11:52:22 +0200 -Subject: [PATCH] x86/MTRR: hook mtrr_bp_restore() back up -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Unlike stated in the offending commit's description, -load_system_tables() wasn't the only thing left to retain from the -earlier restore_rest_processor_state(). Note that MTRR state was still -reloaded via mtrr_aps_sync_end(), but that happens quite a bit later in -the resume process. - -While there also do Misra-related tidying for the function itself: The -function being used from assembly only means it doesn't need to have a -declaration, but wants to be asmlinkage. - -Fixes: 4304ff420e51 ("x86/S3: Drop {save,restore}_rest_processor_state() completely") -Reported-by: Roger Pau Monné -Signed-off-by: Jan Beulich -Acked-by: Roger Pau Monné -master commit: 0414dedd6fde1a1c5c5e38dcbef4dad506e1398c -master date: 2025-04-03 09:39:13 +0200 ---- - xen/arch/x86/acpi/wakeup_prot.S | 2 ++ - xen/arch/x86/cpu/mtrr/main.c | 2 +- - xen/arch/x86/include/asm/mtrr.h | 1 - - 3 files changed, 3 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/acpi/wakeup_prot.S b/xen/arch/x86/acpi/wakeup_prot.S -index 3855ff1ddb94..66f799339913 100644 ---- a/xen/arch/x86/acpi/wakeup_prot.S -+++ b/xen/arch/x86/acpi/wakeup_prot.S -@@ -124,6 +124,8 @@ ENTRY(s3_resume) - mov STACK_CPUINFO_FIELD(cr4)(%rbx), %rax - mov %rax, %cr4 - -+ call mtrr_bp_restore -+ - .Lsuspend_err: - pop %r15 - pop %r14 -diff --git a/xen/arch/x86/cpu/mtrr/main.c b/xen/arch/x86/cpu/mtrr/main.c -index 0a44ebbcb04f..516c8478c6e3 100644 ---- a/xen/arch/x86/cpu/mtrr/main.c -+++ b/xen/arch/x86/cpu/mtrr/main.c -@@ -609,7 +609,7 @@ void mtrr_aps_sync_end(void) - hold_mtrr_updates_on_aps = 0; - } - --void mtrr_bp_restore(void) -+void asmlinkage mtrr_bp_restore(void) - { - mtrr_set_all(); - } -diff --git a/xen/arch/x86/include/asm/mtrr.h b/xen/arch/x86/include/asm/mtrr.h -index 36dac0a775a3..48b59d2620c8 100644 ---- a/xen/arch/x86/include/asm/mtrr.h -+++ b/xen/arch/x86/include/asm/mtrr.h -@@ -66,7 +66,6 @@ extern uint8_t pat_type_2_pte_flags(uint8_t pat_type); - extern int hold_mtrr_updates_on_aps; - extern void mtrr_aps_sync_begin(void); - extern void mtrr_aps_sync_end(void); --extern void mtrr_bp_restore(void); - - extern bool mtrr_var_range_msr_set(struct domain *d, struct mtrr_state *m, - uint32_t msr, uint64_t msr_content); --- -2.49.0 - diff --git a/0310-sched-null-avoid-another-crash-after-failed-domU-cre.patch b/0310-sched-null-avoid-another-crash-after-failed-domU-cre.patch deleted file mode 100644 index b25f08ae..00000000 --- a/0310-sched-null-avoid-another-crash-after-failed-domU-cre.patch +++ /dev/null @@ -1,81 +0,0 @@ -From f6b37861bcc4e6ce51d366268861c4590e6951e3 Mon Sep 17 00:00:00 2001 -From: Stewart Hildebrand -Date: Tue, 29 Apr 2025 11:53:16 +0200 -Subject: [PATCH] sched/null: avoid another crash after failed domU creation - -The following sequence of events may lead a debug build of Xen to crash -when using the null scheduler: - -1. domain creation (e.g. d1) failed due to bad configuration -2. complete_domain_destroy() was deferred -3. domain creation (e.g. d2) succeeds - -At this point, d2 is running, while the zombie d1 is not fully cleaned -up: - -(XEN) Online Cpus: 0-3 -(XEN) Cpupool 0: -(XEN) Cpus: 0-3 -(XEN) Scheduling granularity: cpu, 1 CPU per sched-resource -(XEN) Scheduler: null Scheduler (null) -(XEN) cpus_free = 3 -(XEN) Domain info: -(XEN) Domain: 0 -(XEN) 1: [0.0] pcpu=0 -(XEN) 2: [0.1] pcpu=1 -(XEN) Domain: 1 -(XEN) 3: [1.0] pcpu=2 -(XEN) Domain: 2 -(XEN) 4: [2.0] pcpu=2 - -4. complete_domain_destroy() gets called for d1 and triggers the -following: - -(XEN) Xen call trace: -(XEN) [<00000a0000322ed4>] null.c#unit_deassign+0x2d8/0xb70 (PC) -(XEN) [<00000a000032457c>] null.c#null_unit_remove+0x670/0xba8 (LR) -(XEN) [<00000a000032457c>] null.c#null_unit_remove+0x670/0xba8 -(XEN) [<00000a0000336404>] sched_destroy_vcpu+0x354/0x8fc -(XEN) [<00000a0000227324>] domain.c#complete_domain_destroy+0x11c/0x49c -(XEN) [<00000a000029fbd0>] rcupdate.c#rcu_do_batch+0x94/0x3d0 -(XEN) [<00000a00002a10c0>] rcupdate.c#__rcu_process_callbacks+0x160/0x5f4 -(XEN) [<00000a00002a1e60>] rcupdate.c#rcu_process_callbacks+0xcc/0x1b0 -(XEN) [<00000a00002a3460>] softirq.c#__do_softirq+0x1f4/0x3d8 -(XEN) [<00000a00002a37c4>] do_softirq+0x14/0x1c -(XEN) [<00000a0000465260>] traps.c#check_for_pcpu_work+0x30/0xb8 -(XEN) [<00000a000046bb08>] leave_hypervisor_to_guest+0x28/0x198 -(XEN) [<00000a0000409c84>] entry.o#guest_sync_slowpath+0xac/0xd8 -(XEN) -(XEN) **************************************** -(XEN) Panic on CPU 0: -(XEN) Assertion 'npc->unit == unit' failed at common/sched/null.c:383 -(XEN) **************************************** - -Fix by skipping unit_deassign() when the unit to be removed does not -match the pcpu's currently assigned unit. - -Fixes: c2eae2614c8f ("sched/null: avoid crash after failed domU creation") -Signed-off-by: Stewart Hildebrand -Reviewed-by: Juergen Gross -master commit: 54fe207f29f86c4226a62a4dd289f10d9d2abc40 -master date: 2025-04-07 12:17:31 +0200 ---- - xen/common/sched/null.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/xen/common/sched/null.c b/xen/common/sched/null.c -index 7e31440e5b84..c8e327e3cdd0 100644 ---- a/xen/common/sched/null.c -+++ b/xen/common/sched/null.c -@@ -557,7 +557,7 @@ static void cf_check null_unit_remove( - - cpu = sched_unit_master(unit); - npc = get_sched_res(cpu)->sched_priv; -- if ( npc->unit ) -+ if ( npc->unit == unit ) - unit_deassign(prv, unit); - - out: --- -2.49.0 - diff --git a/0311-xen-vm_event-do-not-do-vm_event_op-for-an-invalid-do.patch b/0311-xen-vm_event-do-not-do-vm_event_op-for-an-invalid-do.patch deleted file mode 100644 index 64ca8b13..00000000 --- a/0311-xen-vm_event-do-not-do-vm_event_op-for-an-invalid-do.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 3721c345b9637ef564932539689e99338c8b2187 Mon Sep 17 00:00:00 2001 -From: Volodymyr Babchuk -Date: Tue, 29 Apr 2025 11:53:56 +0200 -Subject: [PATCH] xen: vm_event: do not do vm_event_op for an invalid domain - -A privileged domain can issue XEN_DOMCTL_vm_event_op with -op->domain == DOMID_INVALID. In this case vm_event_domctl() -function will get NULL as the first parameter and this will -cause hypervisor panic, as it tries to derefer this pointer. - -Fix the issue by checking if valid domain is passed in. - -Fixes: 48b84249459f ("xen/vm-event: Drop unused u_domctl parameter from vm_event_domctl()") -Signed-off-by: Volodymyr Babchuk -Acked-by: Tamas K Lengyel -master commit: 6a884750f3b86a45ee5ffbd825c346fcbce86080 -master date: 2025-04-08 09:36:38 +0200 ---- - xen/common/vm_event.c | 4 ++++ - 1 file changed, 4 insertions(+) - -diff --git a/xen/common/vm_event.c b/xen/common/vm_event.c -index fbf1aa08481f..1666ff615f35 100644 ---- a/xen/common/vm_event.c -+++ b/xen/common/vm_event.c -@@ -600,6 +600,10 @@ int vm_event_domctl(struct domain *d, struct xen_domctl_vm_event_op *vec) - return 0; - } - -+ /* All other subops need to target a real domain. */ -+ if ( unlikely(d == NULL) ) -+ return -ESRCH; -+ - rc = xsm_vm_event_control(XSM_PRIV, d, vec->mode, vec->op); - if ( rc ) - return rc; --- -2.49.0 - diff --git a/0312-x86-cpu-Validate-CPUID-leaf-0x2-EDX-output.patch b/0312-x86-cpu-Validate-CPUID-leaf-0x2-EDX-output.patch deleted file mode 100644 index a45adf6e..00000000 --- a/0312-x86-cpu-Validate-CPUID-leaf-0x2-EDX-output.patch +++ /dev/null @@ -1,46 +0,0 @@ -From 7abb2300fd43294fe827eec4c680bf6dce0bd1f4 Mon Sep 17 00:00:00 2001 -From: "Ahmed S. Darwish" -Date: Tue, 29 Apr 2025 11:54:35 +0200 -Subject: [PATCH] x86/cpu: Validate CPUID leaf 0x2 EDX output - -CPUID leaf 0x2 emits one-byte descriptors in its four output registers -EAX, EBX, ECX, and EDX. For these descriptors to be valid, the most -significant bit (MSB) of each register must be clear. - -Leaf 0x2 parsing at intel.c only validated the MSBs of EAX, EBX, and -ECX, but left EDX unchecked. - -Validate EDX's most-significant bit as well. - -Fixes: 1aa6feb63bfd ("Port CPU setup code from Linux 2.6") -Signed-off-by: Ahmed S. Darwish -Signed-off-by: Ingo Molnar -Link: https://lore.kernel.org/r/20250304085152.51092-3-darwi@linutronix.de - -Use ARRAY_SIZE() though. - -Origin: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 1881148215c6 -Signed-off-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: a47b44a8f0a58a6015faf6465921cd203f0b51d1 -master date: 2025-04-08 09:37:38 +0200 ---- - xen/arch/x86/cpu/intel_cacheinfo.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/xen/arch/x86/cpu/intel_cacheinfo.c b/xen/arch/x86/cpu/intel_cacheinfo.c -index 9cfb759be030..e88faa7545bc 100644 ---- a/xen/arch/x86/cpu/intel_cacheinfo.c -+++ b/xen/arch/x86/cpu/intel_cacheinfo.c -@@ -186,7 +186,7 @@ void init_intel_cacheinfo(struct cpuinfo_x86 *c) - cpuid(2, ®s[0], ®s[1], ®s[2], ®s[3]); - - /* If bit 31 is set, this is an unknown format */ -- for ( j = 0 ; j < 3 ; j++ ) { -+ for ( j = 0; j < ARRAY_SIZE(regs); j++ ) { - if ( regs[j] >> 31 ) - regs[j] = 0; - } --- -2.49.0 - diff --git a/0313-xen-x86-irq-initialize-irq-desc-in-create_irq.patch b/0313-xen-x86-irq-initialize-irq-desc-in-create_irq.patch deleted file mode 100644 index 88883cbf..00000000 --- a/0313-xen-x86-irq-initialize-irq-desc-in-create_irq.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 3450fe0dd9b57364f305dcf90176ab31a3dbc0bb Mon Sep 17 00:00:00 2001 -From: Volodymyr Babchuk -Date: Tue, 29 Apr 2025 11:54:59 +0200 -Subject: [PATCH] xen: x86: irq: initialize irq desc in create_irq() -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -While building xen with GCC 14.2.1 with "-fcondition-coverage" option -or with "-Og", the compiler produces a false positive warning: - - arch/x86/irq.c: In function ‘create_irq’: - arch/x86/irq.c:281:11: error: ‘desc’ may be used uninitialized [-Werror=maybe-uninitialized] - 281 | ret = init_one_irq_desc(desc); - | ^~~~~~~~~~~~~~~~~~~~~~~ - arch/x86/irq.c:269:22: note: ‘desc’ was declared here - 269 | struct irq_desc *desc; - | ^~~~ - cc1: all warnings being treated as errors - make[2]: *** [Rules.mk:252: arch/x86/irq.o] Error 1 - -While we have signed/unsigned comparison both in "for" loop and in -"if" statement, this still can't lead to use of uninitialized "desc", -as either loop will be executed at least once, or the function will -return early. So this is a clearly false positive warning due to a -bug [1] in GCC. - -Initialize "desc" with NULL to make GCC happy. - -[1] https://gcc.gnu.org/bugzilla/show_bug.cgi?id=119665 - -Signed-off-by: Volodymyr Babchuk -Reviewed-by: Jan Beulich -master commit: 7a4484d90b3003171f1700e424ad45b931200ba6 -master date: 2025-04-08 09:40:39 +0200 ---- - xen/arch/x86/irq.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/xen/arch/x86/irq.c b/xen/arch/x86/irq.c -index 0001e93ba8ac..ce390b04226f 100644 ---- a/xen/arch/x86/irq.c -+++ b/xen/arch/x86/irq.c -@@ -261,7 +261,7 @@ void __init clear_irq_vector(int irq) - int create_irq(nodeid_t node, bool grant_access) - { - int irq, ret; -- struct irq_desc *desc; -+ struct irq_desc *desc = NULL ; /* gcc14 -Og or -fcondition-coverage */ - - for (irq = nr_irqs_gsi; irq < nr_irqs; irq++) - { --- -2.49.0 - diff --git a/0314-include-sort-wildcard-.-results.patch b/0314-include-sort-wildcard-.-results.patch deleted file mode 100644 index a61c98be..00000000 --- a/0314-include-sort-wildcard-.-results.patch +++ /dev/null @@ -1,47 +0,0 @@ -From 593c4377789c239ebce1f2c79164367d70f3b278 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 29 Apr 2025 11:55:16 +0200 -Subject: [PATCH] include: sort $(wildcard ...) results - -The order of items is stored in .*.chk.cmd, and hence variations between -how items are ordered would result in re-invocation of the checking rule -during "make install-xen" despite that already having successfully run -earlier on. The difference can become noticable when building (as non- -root) and installing (as root) use different GNU make versions: In 3.82 -the sorting was deliberately undone, just for it to be restored in 4.3. - -Signed-off-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: ff835bbc8096a14ed1bffa235e25848c993f7240 -master date: 2025-04-10 10:56:29 +0200 ---- - xen/include/Makefile | 6 +++--- - 1 file changed, 3 insertions(+), 3 deletions(-) - -diff --git a/xen/include/Makefile b/xen/include/Makefile -index 2e61b50139d7..33f069f4175b 100644 ---- a/xen/include/Makefile -+++ b/xen/include/Makefile -@@ -41,8 +41,8 @@ cppflags-$(CONFIG_X86) += -m32 - - endif - --public-$(CONFIG_X86) := $(wildcard $(srcdir)/public/arch-x86/*.h $(srcdir)/public/arch-x86/*/*.h) --public-$(CONFIG_ARM) := $(wildcard $(srcdir)/public/arch-arm/*.h $(srcdir)/public/arch-arm/*/*.h) -+public-$(CONFIG_X86) := $(sort $(wildcard $(srcdir)/public/arch-x86/*.h $(srcdir)/public/arch-x86/*/*.h)) -+public-$(CONFIG_ARM) := $(sort $(wildcard $(srcdir)/public/arch-arm/*.h $(srcdir)/public/arch-arm/*/*.h)) - - .PHONY: all - all: $(addprefix $(obj)/,$(headers-y) $(headers-n)) -@@ -130,7 +130,7 @@ all: $(obj)/headers.chk $(obj)/headers99.chk $(obj)/headers++.chk - - public-hdrs-path := $(srcdir)/public - --public-list-headers = $(wildcard $1/*.h $1/*/*.h) -+public-list-headers = $(sort $(wildcard $1/*.h $1/*/*.h)) - public-filter-headers = $(filter-out $(addprefix $(public-hdrs-path)/, $($1-filter)), $($1)) - - public-headers := $(call public-list-headers, $(public-hdrs-path)) $(public-y) --- -2.49.0 - diff --git a/0315-xen-rangeset-fix-incorrect-subtraction.patch b/0315-xen-rangeset-fix-incorrect-subtraction.patch deleted file mode 100644 index b25f04b1..00000000 --- a/0315-xen-rangeset-fix-incorrect-subtraction.patch +++ /dev/null @@ -1,48 +0,0 @@ -From c7e5683085466b378347f9fa68010c7778cc8e4d Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Tue, 29 Apr 2025 11:55:34 +0200 -Subject: [PATCH] xen/rangeset: fix incorrect subtraction -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Given the following rangset operation: - -{ [0, 1], [4, 5] } - { [3, 4] } - -The current rangeset logic will output a rangeset: - -{ [0, 2], [5, 5] } - -This is incorrect, and also has the undesirable property of being bogus in -a way that the resulting rangeset is expanded. - -Fix this by making sure the bounds are correctly checked before modifying -the previous range. - -Fixes: 484a058c4828 ('Add auto-destructing per-domain rangeset data structure...') -Signed-off-by: Roger Pau Monné -Reviewed-by: Jan Beulich -master commit: e118fc98e7ae652a188d227bd7ea22f132724150 -master date: 2025-04-11 12:20:10 +0200 ---- - xen/common/rangeset.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/xen/common/rangeset.c b/xen/common/rangeset.c -index b75590f90744..e75871039087 100644 ---- a/xen/common/rangeset.c -+++ b/xen/common/rangeset.c -@@ -227,7 +227,8 @@ int rangeset_remove_range( - - if ( x->s < s ) - { -- x->e = s - 1; -+ if ( x->e >= s ) -+ x->e = s - 1; - x = next_range(r, x); - } - --- -2.49.0 - diff --git a/0316-x86-HVM-update-repeat-count-upon-nested-lin-phys-fai.patch b/0316-x86-HVM-update-repeat-count-upon-nested-lin-phys-fai.patch deleted file mode 100644 index 6f2aa506..00000000 --- a/0316-x86-HVM-update-repeat-count-upon-nested-lin-phys-fai.patch +++ /dev/null @@ -1,50 +0,0 @@ -From 7ffef37f55317ffcd01840a2302dfe1c02e0c064 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 29 Apr 2025 11:56:25 +0200 -Subject: [PATCH] x86/HVM: update repeat count upon nested lin->phys failure - -For the X86EMUL_EXCEPTION case the repeat count must be correctly -propagated back. Since for the recursive invocation we use a local -helper variable, its value needs copying to the caller's one. - -While there also correct the off-by-1 range in the comment ahead of the -function (strictly speaking for the "DF set" case we'd need to put -another, different range there as well). - -Fixes: 53f87c03b4ea ("x86emul: generalize exception handling for rep_* hooks") -Reported-by: Manuel Andreas -Signed-off-by: Jan Beulich -Reviewed-by: Andrew Cooper -master commit: c07b16fd6e47782ebf1ee767cd07c1e2b4140f47 -master date: 2025-04-17 10:01:19 +0200 ---- - xen/arch/x86/hvm/emulate.c | 5 ++++- - 1 file changed, 4 insertions(+), 1 deletion(-) - -diff --git a/xen/arch/x86/hvm/emulate.c b/xen/arch/x86/hvm/emulate.c -index f4b9352c3915..03e40ab9ff71 100644 ---- a/xen/arch/x86/hvm/emulate.c -+++ b/xen/arch/x86/hvm/emulate.c -@@ -826,7 +826,7 @@ static void hvmemul_unmap_linear_addr( - - /* - * Convert addr from linear to physical form, valid over the range -- * [addr, addr + *reps * bytes_per_rep]. *reps is adjusted according to -+ * [addr, addr + *reps * bytes_per_rep). *reps is adjusted according to - * the valid computed range. It is always >0 when X86EMUL_OKAY is returned. - * @pfec indicates the access checks to be performed during page-table walks. - */ -@@ -866,7 +866,10 @@ static int hvmemul_linear_to_phys( - int rc = hvmemul_linear_to_phys( - addr, &_paddr, bytes_per_rep, &one_rep, pfec, hvmemul_ctxt); - if ( rc != X86EMUL_OKAY ) -+ { -+ *reps = one_rep; - return rc; -+ } - pfn = _paddr >> PAGE_SHIFT; - } - else if ( (pfn = paging_gva_to_gfn(curr, addr, &pfec)) == gfn_x(INVALID_GFN) ) --- -2.49.0 - diff --git a/0317-x86emul-also-clip-repetition-count-for-STOS.patch b/0317-x86emul-also-clip-repetition-count-for-STOS.patch deleted file mode 100644 index fd9784c7..00000000 --- a/0317-x86emul-also-clip-repetition-count-for-STOS.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 9466bb1dc863485aee14808f787c95daa926490b Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 29 Apr 2025 11:56:44 +0200 -Subject: [PATCH] x86emul: also clip repetition count for STOS - -Like MOVS, INS, and OUTS, STOS also has a special purpose hook, where -the hook function may legitimately have the same expectation as to the -request not straddling address space start/end. - -Fixes: 5dfe4aa4eeb6 ("x86_emulate: Do not request emulation of REP instructions beyond the") -Reported-by: Fabian Specht -Signed-off-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: 8c5636b6c87777e6c2e4ffae28bffe1cfc189bfd -master date: 2025-04-22 11:24:20 +0200 ---- - xen/arch/x86/x86_emulate/x86_emulate.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/xen/arch/x86/x86_emulate/x86_emulate.c b/xen/arch/x86/x86_emulate/x86_emulate.c -index 3d837f7e9efa..b1d192cbbf1e 100644 ---- a/xen/arch/x86/x86_emulate/x86_emulate.c -+++ b/xen/arch/x86/x86_emulate/x86_emulate.c -@@ -2217,7 +2217,7 @@ x86_emulate( - - dst.bytes = src.bytes; - dst.mem.seg = x86_seg_es; -- dst.mem.off = truncate_ea(_regs.r(di)); -+ dst.mem.off = truncate_ea_and_reps(_regs.r(di), nr_reps, dst.bytes); - if ( (nr_reps == 1) || !ops->rep_stos || - ((rc = ops->rep_stos(&src.val, - dst.mem.seg, dst.mem.off, dst.bytes, --- -2.49.0 - diff --git a/0318-compat-memory-avoid-UB-shifts-in-XENMEM_exchange-han.patch b/0318-compat-memory-avoid-UB-shifts-in-XENMEM_exchange-han.patch deleted file mode 100644 index bbcb057f..00000000 --- a/0318-compat-memory-avoid-UB-shifts-in-XENMEM_exchange-han.patch +++ /dev/null @@ -1,38 +0,0 @@ -From e2adda16e010d23b9b790f0be4de9c6e6c2793f1 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 29 Apr 2025 11:57:07 +0200 -Subject: [PATCH] compat/memory: avoid UB shifts in XENMEM_exchange handling - -Add an early basic check, yielding the same error code as the more -thorough one the main handler would produce. - -Fixes: b8a7efe8528a ("Enable compatibility mode operation for HYPERVISOR_memory_op") -Reported-by: Manuel Andreas -Signed-off-by: Jan Beulich -Reviewed-by: Jason Andryuk -Reviewed-by: Andrew Cooper -master commit: 560c51be8f6a88cde43c0a7c8be60158b5725982 -master date: 2025-04-22 11:25:23 +0200 ---- - xen/common/compat/memory.c | 5 +++++ - 1 file changed, 5 insertions(+) - -diff --git a/xen/common/compat/memory.c b/xen/common/compat/memory.c -index 45e5fb0e5d75..e3eb3c01a118 100644 ---- a/xen/common/compat/memory.c -+++ b/xen/common/compat/memory.c -@@ -161,6 +161,11 @@ int compat_memory_op(unsigned int cmd, XEN_GUEST_HANDLE_PARAM(void) arg) - if ( copy_from_guest(&cmp.xchg, arg, 1) ) - return -EFAULT; - -+ /* Early coarse check, as max_order() isn't available here. */ -+ if ( cmp.xchg.in.extent_order >= 32 || -+ cmp.xchg.out.extent_order >= 32 ) -+ return -EPERM; -+ - order_delta = cmp.xchg.out.extent_order - cmp.xchg.in.extent_order; - /* Various sanity checks. */ - if ( (cmp.xchg.nr_exchanged > cmp.xchg.in.nr_extents) || --- -2.49.0 - diff --git a/0319-x86-intel-workaround-several-MONITOR-MWAIT-errata.patch b/0319-x86-intel-workaround-several-MONITOR-MWAIT-errata.patch deleted file mode 100644 index 5ecac8d6..00000000 --- a/0319-x86-intel-workaround-several-MONITOR-MWAIT-errata.patch +++ /dev/null @@ -1,135 +0,0 @@ -From 0f74a33deae06ebba8c5c998d74c1e3dfd46d6ea Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Tue, 29 Apr 2025 11:57:31 +0200 -Subject: [PATCH] x86/intel: workaround several MONITOR/MWAIT errata -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -There are several errata on Intel regarding the usage of the MONITOR/MWAIT -instructions, all having in common that stores to the monitored region -might not wake up the CPU. - -Fix them by forcing the sending of an IPI for the affected models. - -The Ice Lake issue has been reproduced internally on XenServer hardware, -and the fix does seem to prevent it. The symptom was APs getting stuck in -the idle loop immediately after bring up, which in turn prevented the BSP -from making progress. This would happen before the watchdog was -initialized, and hence the whole system would get stuck. - -Signed-off-by: Roger Pau Monné -Acked-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: 4aae4452efeee3d3bba092b875e37d1e7c8f6db9 -master date: 2025-04-23 16:12:25 +0200 ---- - xen/arch/x86/acpi/cpu_idle.c | 6 ++++++ - xen/arch/x86/cpu/intel.c | 36 +++++++++++++++++++++++++++++++- - xen/arch/x86/include/asm/mwait.h | 3 +++ - 3 files changed, 44 insertions(+), 1 deletion(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 52808f980993..d0607d8a6952 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -453,8 +453,14 @@ void cpuidle_wakeup_mwait(cpumask_t *mask) - cpumask_andnot(mask, mask, &target); - } - -+/* Force sending of a wakeup IPI regardless of mwait usage. */ -+bool __ro_after_init force_mwait_ipi_wakeup; -+ - bool arch_skip_send_event_check(unsigned int cpu) - { -+ if ( force_mwait_ipi_wakeup ) -+ return false; -+ - /* - * This relies on softirq_pending() and mwait_wakeup() to access data - * on the same cache line. -diff --git a/xen/arch/x86/cpu/intel.c b/xen/arch/x86/cpu/intel.c -index bb9c6220de80..74d10c93d839 100644 ---- a/xen/arch/x86/cpu/intel.c -+++ b/xen/arch/x86/cpu/intel.c -@@ -8,6 +8,7 @@ - #include - #include - #include -+#include - #include - #include - #include -@@ -368,7 +369,6 @@ static void probe_c3_errata(const struct cpuinfo_x86 *c) - INTEL_FAM6_MODEL(0x25), - { } - }; --#undef INTEL_FAM6_MODEL - - /* Serialized by the AP bringup code. */ - if ( max_cstate > 1 && (c->apicid & (c->x86_num_siblings - 1)) && -@@ -380,6 +380,38 @@ static void probe_c3_errata(const struct cpuinfo_x86 *c) - } - } - -+/* -+ * APL30: One use of the MONITOR/MWAIT instruction pair is to allow a logical -+ * processor to wait in a sleep state until a store to the armed address range -+ * occurs. Due to this erratum, stores to the armed address range may not -+ * trigger MWAIT to resume execution. -+ * -+ * ICX143: Under complex microarchitectural conditions, a monitor that is armed -+ * with the MWAIT instruction may not be triggered, leading to a processor -+ * hang. -+ * -+ * LNL030: Problem P-cores may not exit power state Core C6 on monitor hit. -+ * -+ * Force the sending of an IPI in those cases. -+ */ -+static void __init probe_mwait_errata(void) -+{ -+ static const struct x86_cpu_id __initconst models[] = { -+ INTEL_FAM6_MODEL(INTEL_FAM6_ATOM_GOLDMONT), /* APL30 */ -+ INTEL_FAM6_MODEL(INTEL_FAM6_ICELAKE_X), /* ICX143 */ -+ INTEL_FAM6_MODEL(INTEL_FAM6_LUNARLAKE_M), /* LNL030 */ -+ { } -+ }; -+#undef INTEL_FAM6_MODEL -+ -+ if ( boot_cpu_has(X86_FEATURE_MONITOR) && x86_match_cpu(models) ) -+ { -+ printk(XENLOG_WARNING -+ "Forcing IPI MWAIT wakeup due to CPU erratum\n"); -+ force_mwait_ipi_wakeup = true; -+ } -+} -+ - /* - * P4 Xeon errata 037 workaround. - * Hardware prefetcher may cause stale data to be loaded into the cache. -@@ -406,6 +438,8 @@ static void Intel_errata_workarounds(struct cpuinfo_x86 *c) - __set_bit(X86_FEATURE_CLFLUSH_MONITOR, c->x86_capability); - - probe_c3_errata(c); -+ if (system_state < SYS_STATE_smp_boot) -+ probe_mwait_errata(); - } - - -diff --git a/xen/arch/x86/include/asm/mwait.h b/xen/arch/x86/include/asm/mwait.h -index 9298f987c435..1f1e39775b99 100644 ---- a/xen/arch/x86/include/asm/mwait.h -+++ b/xen/arch/x86/include/asm/mwait.h -@@ -13,6 +13,9 @@ - - #define MWAIT_ECX_INTERRUPT_BREAK 0x1 - -+/* Force sending of a wakeup IPI regardless of mwait usage. */ -+extern bool force_mwait_ipi_wakeup; -+ - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx); - bool mwait_pc10_supported(void); - --- -2.49.0 - diff --git a/0320-xen-remove-N-from-the-linker-command-line.patch b/0320-xen-remove-N-from-the-linker-command-line.patch deleted file mode 100644 index 41772669..00000000 --- a/0320-xen-remove-N-from-the-linker-command-line.patch +++ /dev/null @@ -1,159 +0,0 @@ -From cd0fa8381d3389f21305df7b726e7da3b56e1b3c Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Tue, 29 Apr 2025 11:58:03 +0200 -Subject: [PATCH] xen: remove -N from the linker command line -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -It's unclear why -N is being used in the first place. It was added by -commit 4676bbf96dc8 back in 2002 without any justification. - -When building a PE image it's actually detrimental to forcefully set the -.text section as writable. The GNU LD man page contains the following -warning regarding the -N option: - -> Note: Although a writable text section is allowed for PE-COFF targets, it -> does not conform to the format specification published by Microsoft. - -Remove the usage of -N uniformly on all architectures, assuming that the -addition was simply done as a copy and paste of the original x86 linking -rune. - -Signed-off-by: Roger Pau Monné -Reviewed-by: Andrew Cooper -Reviewed-by: Oleksii Kurochko -Acked-by: Julien Grall -master commit: d444763f8ca556d0a67a4b933be303d346baef02 -master date: 2025-04-23 16:12:25 +0200 ---- - xen/arch/arm/Makefile | 6 +++--- - xen/arch/ppc/Makefile | 6 +++--- - xen/arch/riscv/Makefile | 2 +- - xen/arch/x86/Makefile | 12 ++++++------ - 4 files changed, 13 insertions(+), 13 deletions(-) - -diff --git a/xen/arch/arm/Makefile b/xen/arch/arm/Makefile -index 45dc29ea53c3..940de246b587 100644 ---- a/xen/arch/arm/Makefile -+++ b/xen/arch/arm/Makefile -@@ -97,19 +97,19 @@ ifeq ($(CONFIG_ARM_64),y) - endif - - $(TARGET)-syms: $(objtree)/prelink.o $(obj)/xen.lds -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< \ - $(objtree)/common/symbols-dummy.o -o $(dot-target).0 - $(NM) -pa --format=sysv $(dot-target).0 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).0.S - $(MAKE) $(build)=$(@D) $(dot-target).0.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< \ - $(dot-target).0.o -o $(dot-target).1 - $(NM) -pa --format=sysv $(dot-target).1 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).1.S - $(MAKE) $(build)=$(@D) $(dot-target).1.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) \ - $(dot-target).1.o -o $@ - $(NM) -pa --format=sysv $@ \ - | $(objtree)/tools/symbols --all-symbols --xensyms --sysv --sort \ -diff --git a/xen/arch/ppc/Makefile b/xen/arch/ppc/Makefile -index 71feb5e2c41f..b9d61a785615 100644 ---- a/xen/arch/ppc/Makefile -+++ b/xen/arch/ppc/Makefile -@@ -11,19 +11,19 @@ $(TARGET): $(TARGET)-syms - cp -f $< $@ - - $(TARGET)-syms: $(objtree)/prelink.o $(obj)/xen.lds -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< \ - $(objtree)/common/symbols-dummy.o -o $(dot-target).0 - $(NM) -pa --format=sysv $(dot-target).0 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).0.S - $(MAKE) $(build)=$(@D) $(dot-target).0.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< \ - $(dot-target).0.o -o $(dot-target).1 - $(NM) -pa --format=sysv $(dot-target).1 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).1.S - $(MAKE) $(build)=$(@D) $(dot-target).1.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) \ - $(dot-target).1.o -o $@ - $(NM) -pa --format=sysv $@ \ - | $(objtree)/tools/symbols --all-symbols --xensyms --sysv --sort \ -diff --git a/xen/arch/riscv/Makefile b/xen/arch/riscv/Makefile -index 1ed1a8369b5d..28b5809dac7f 100644 ---- a/xen/arch/riscv/Makefile -+++ b/xen/arch/riscv/Makefile -@@ -11,7 +11,7 @@ $(TARGET): $(TARGET)-syms - $(OBJCOPY) -O binary -S $< $@ - - $(TARGET)-syms: $(objtree)/prelink.o $(obj)/xen.lds -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) -o $@ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) -o $@ - $(NM) -pa --format=sysv $@ \ - | $(objtree)/tools/symbols --all-symbols --xensyms --sysv --sort \ - > $@.map -diff --git a/xen/arch/x86/Makefile b/xen/arch/x86/Makefile -index d902fb7accd9..c1e64278ce85 100644 ---- a/xen/arch/x86/Makefile -+++ b/xen/arch/x86/Makefile -@@ -137,19 +137,19 @@ $(TARGET): $(TARGET)-syms $(efi-y) $(obj)/boot/mkelf32 - CFLAGS-$(XEN_BUILD_EFI) += -DXEN_BUILD_EFI - - $(TARGET)-syms: $(objtree)/prelink.o $(obj)/xen.lds -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) \ - $(objtree)/common/symbols-dummy.o -o $(dot-target).0 - $(NM) -pa --format=sysv $(dot-target).0 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).0.S - $(MAKE) $(build)=$(@D) $(dot-target).0.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) \ - $(dot-target).0.o -o $(dot-target).1 - $(NM) -pa --format=sysv $(dot-target).1 \ - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort $(syms-warn-dup-y) \ - > $(dot-target).1.S - $(MAKE) $(build)=$(@D) $(dot-target).1.o -- $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds -N $< $(build_id_linker) \ -+ $(LD) $(XEN_LDFLAGS) -T $(obj)/xen.lds $< $(build_id_linker) \ - $(orphan-handling-y) $(dot-target).1.o -o $@ - $(NM) -pa --format=sysv $@ \ - | $(objtree)/tools/symbols --all-symbols --xensyms --sysv --sort \ -@@ -210,7 +210,7 @@ ifeq ($(CONFIG_DEBUG_INFO),y) - $(if $(filter --strip-debug,$(EFI_LDFLAGS)),echo,:) "Will strip debug info from $(@F)" - endif - $(foreach base, $(VIRT_BASE) $(ALT_BASE), \ -- $(LD) $(call EFI_LDFLAGS,$(base)) -T $(obj)/efi.lds -N $< $(relocs-dummy) \ -+ $(LD) $(call EFI_LDFLAGS,$(base)) -T $(obj)/efi.lds $< $(relocs-dummy) \ - $(objtree)/common/symbols-dummy.o $(note_file_option) \ - -o $(dot-target).$(base).0 &&) : - $(MKRELOC) $(foreach base,$(VIRT_BASE) $(ALT_BASE),$(dot-target).$(base).0) \ -@@ -220,7 +220,7 @@ endif - > $(dot-target).0s.S - $(MAKE) $(build)=$(@D) .$(@F).0r.o .$(@F).0s.o - $(foreach base, $(VIRT_BASE) $(ALT_BASE), \ -- $(LD) $(call EFI_LDFLAGS,$(base)) -T $(obj)/efi.lds -N $< \ -+ $(LD) $(call EFI_LDFLAGS,$(base)) -T $(obj)/efi.lds $< \ - $(dot-target).0r.o $(dot-target).0s.o $(note_file_option) \ - -o $(dot-target).$(base).1 &&) : - $(MKRELOC) $(foreach base,$(VIRT_BASE) $(ALT_BASE),$(dot-target).$(base).1) \ -@@ -229,7 +229,7 @@ endif - | $(objtree)/tools/symbols $(all_symbols) --sysv --sort \ - > $(dot-target).1s.S - $(MAKE) $(build)=$(@D) .$(@F).1r.o .$(@F).1s.o -- $(LD) $(call EFI_LDFLAGS,$(VIRT_BASE)) -T $(obj)/efi.lds -N $< \ -+ $(LD) $(call EFI_LDFLAGS,$(VIRT_BASE)) -T $(obj)/efi.lds $< \ - $(dot-target).1r.o $(dot-target).1s.o $(orphan-handling-y) \ - $(note_file_option) -o $@ - $(NM) -pa --format=sysv $@ \ --- -2.49.0 - diff --git a/0321-x86-alternative-Support-replacements-when-a-feature-.patch b/0321-x86-alternative-Support-replacements-when-a-feature-.patch deleted file mode 100644 index ed80bdc5..00000000 --- a/0321-x86-alternative-Support-replacements-when-a-feature-.patch +++ /dev/null @@ -1,93 +0,0 @@ -From 246ed397e3dd3008808db7bff2e73c18e9a2cb81 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Mon, 21 Apr 2025 15:52:56 +0100 -Subject: [PATCH] x86/alternative: Support replacements when a feature is not - present - -Use the top bit of a->cpuid to express inverted polarity. This requires -stripping the top bit back out when performing the sanity checks. - -Despite only being used once, create a replace boolean to express the decision -more clearly in _apply_alternatives(). - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 328ed39c59e0af06d594f5e64a52b57aa0b02340) ---- - xen/arch/x86/alternative.c | 14 +++++++++++--- - xen/arch/x86/include/asm/alternative.h | 9 ++++++++- - 2 files changed, 19 insertions(+), 4 deletions(-) - -diff --git a/xen/arch/x86/alternative.c b/xen/arch/x86/alternative.c -index 1ba35cb9ede9..88c90044c20d 100644 ---- a/xen/arch/x86/alternative.c -+++ b/xen/arch/x86/alternative.c -@@ -197,6 +197,8 @@ static int init_or_livepatch _apply_alternatives(struct alt_instr *start, - uint8_t *repl = ALT_REPL_PTR(a); - uint8_t buf[MAX_PATCH_LEN]; - unsigned int total_len = a->orig_len + a->pad_len; -+ unsigned int feat = a->cpuid & ~ALT_FLAG_NOT; -+ bool inv = a->cpuid & ALT_FLAG_NOT, replace; - - if ( a->repl_len > total_len ) - { -@@ -214,11 +216,11 @@ static int init_or_livepatch _apply_alternatives(struct alt_instr *start, - return -ENOSPC; - } - -- if ( a->cpuid >= NCAPINTS * 32 ) -+ if ( feat >= NCAPINTS * 32 ) - { - printk(XENLOG_ERR - "Alt for %ps, feature %#x outside of featureset range %#x\n", -- ALT_ORIG_PTR(a), a->cpuid, NCAPINTS * 32); -+ ALT_ORIG_PTR(a), feat, NCAPINTS * 32); - return -ERANGE; - } - -@@ -243,8 +245,14 @@ static int init_or_livepatch _apply_alternatives(struct alt_instr *start, - continue; - } - -+ /* -+ * Should a replacement be performed? Most replacements have positive -+ * polarity, but we support negative polarity too. -+ */ -+ replace = boot_cpu_has(feat) ^ inv; -+ - /* If there is no replacement to make, see about optimising the nops. */ -- if ( !boot_cpu_has(a->cpuid) ) -+ if ( !replace ) - { - /* Origin site site already touched? Don't nop anything. */ - if ( base->priv ) -diff --git a/xen/arch/x86/include/asm/alternative.h b/xen/arch/x86/include/asm/alternative.h -index 69555d781ef9..89b7bdcb82e5 100644 ---- a/xen/arch/x86/include/asm/alternative.h -+++ b/xen/arch/x86/include/asm/alternative.h -@@ -1,6 +1,13 @@ - #ifndef __X86_ALTERNATIVE_H__ - #define __X86_ALTERNATIVE_H__ - -+/* -+ * Common to both C and ASM. Express a replacement when a feature is not -+ * available. -+ */ -+#define ALT_FLAG_NOT (1 << 15) -+#define ALT_NOT(x) (ALT_FLAG_NOT | (x)) -+ - #ifdef __ASSEMBLY__ - #include - #else -@@ -11,7 +18,7 @@ - struct __packed alt_instr { - int32_t orig_offset; /* original instruction */ - int32_t repl_offset; /* offset to replacement instruction */ -- uint16_t cpuid; /* cpuid bit set for replacement */ -+ uint16_t cpuid; /* cpuid bit set for replacement (top bit is polarity) */ - uint8_t orig_len; /* length of original instruction */ - uint8_t repl_len; /* length of new instruction */ - uint8_t pad_len; /* length of build-time padding */ --- -2.49.0 - diff --git a/0322-x86-guest-Remove-use-of-the-Xen-hypercall_page.patch b/0322-x86-guest-Remove-use-of-the-Xen-hypercall_page.patch deleted file mode 100644 index 765550ef..00000000 --- a/0322-x86-guest-Remove-use-of-the-Xen-hypercall_page.patch +++ /dev/null @@ -1,333 +0,0 @@ -From 4da237fe92689fbbb865b47311b3215f40787547 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Mon, 21 Apr 2025 10:34:02 +0100 -Subject: [PATCH] x86/guest: Remove use of the Xen hypercall_page -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -In order to protect against ITS, Xen needs to start using return thunks. -Therefore the advice in XSA-466 becomes relevant, and the hypercall_page needs -to be removed. - -Implement early_hypercall(), with infrastructure to figure out the correct -instruction on first use. Use ALTERNATIVE()s to result in inline hypercalls, -including the ALT_NOT() form so we only need a single synthetic feature bit. - -No overall change. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit ef30ffe0a0f79313c00720793c475c45a9e490ff) ---- - xen/arch/x86/guest/xen/Makefile | 2 +- - xen/arch/x86/guest/xen/hypercall.S | 50 ++++++++++++++ - xen/arch/x86/guest/xen/hypercall_page.S | 76 ---------------------- - xen/arch/x86/guest/xen/xen.c | 48 ++++++++++++-- - xen/arch/x86/include/asm/cpufeatures.h | 1 + - xen/arch/x86/include/asm/guest/xen-hcall.h | 24 ++++--- - 6 files changed, 112 insertions(+), 89 deletions(-) - create mode 100644 xen/arch/x86/guest/xen/hypercall.S - delete mode 100644 xen/arch/x86/guest/xen/hypercall_page.S - -diff --git a/xen/arch/x86/guest/xen/Makefile b/xen/arch/x86/guest/xen/Makefile -index 26fb4b1007c0..8b3250aa8886 100644 ---- a/xen/arch/x86/guest/xen/Makefile -+++ b/xen/arch/x86/guest/xen/Makefile -@@ -1,4 +1,4 @@ --obj-y += hypercall_page.o -+obj-bin-y += hypercall.init.o - obj-y += xen.o - - obj-bin-$(CONFIG_PVH_GUEST) += pvh-boot.init.o -diff --git a/xen/arch/x86/guest/xen/hypercall.S b/xen/arch/x86/guest/xen/hypercall.S -new file mode 100644 -index 000000000000..05e429794cc4 ---- /dev/null -+++ b/xen/arch/x86/guest/xen/hypercall.S -@@ -0,0 +1,50 @@ -+/* SPDX-License-Identifier: GPL-2.0-or-later */ -+ -+#include -+ -+ .section .init.text, "ax", @progbits -+ -+ /* -+ * Used during early boot, before alternatives have run and inlined -+ * the appropriate instruction. Called using the hypercall ABI. -+ */ -+FUNC(early_hypercall) -+ cmpb $0, early_hypercall_insn(%rip) -+ jl .L_setup -+ je 1f -+ -+ vmmcall -+ ret -+ -+1: vmcall -+ ret -+ -+.L_setup: -+ /* -+ * When setting up the first time around, all registers need -+ * preserving. Save the non-callee-saved ones. -+ */ -+ push %r11 -+ push %r10 -+ push %r9 -+ push %r8 -+ push %rdi -+ push %rsi -+ push %rdx -+ push %rcx -+ push %rax -+ -+ call early_hypercall_setup -+ -+ pop %rax -+ pop %rcx -+ pop %rdx -+ pop %rsi -+ pop %rdi -+ pop %r8 -+ pop %r9 -+ pop %r10 -+ pop %r11 -+ -+ jmp early_hypercall -+END(early_hypercall) -diff --git a/xen/arch/x86/guest/xen/hypercall_page.S b/xen/arch/x86/guest/xen/hypercall_page.S -deleted file mode 100644 -index 7ab55fc1f6e6..000000000000 ---- a/xen/arch/x86/guest/xen/hypercall_page.S -+++ /dev/null -@@ -1,76 +0,0 @@ --#include --#include --#include -- -- .section ".text.page_aligned", "ax", @progbits -- --DATA(hypercall_page, PAGE_SIZE) -- /* Poisoned with `ret` for safety before hypercalls are set up. */ -- .fill PAGE_SIZE, 1, 0xc3 --END(hypercall_page) -- --/* -- * Identify a specific hypercall in the hypercall page -- * @param name Hypercall name. -- */ --#define DECLARE_HYPERCALL(name) \ -- .globl HYPERCALL_ ## name; \ -- .type HYPERCALL_ ## name, STT_FUNC; \ -- .size HYPERCALL_ ## name, 32; \ -- .set HYPERCALL_ ## name, hypercall_page + __HYPERVISOR_ ## name * 32 -- --DECLARE_HYPERCALL(set_trap_table) --DECLARE_HYPERCALL(mmu_update) --DECLARE_HYPERCALL(set_gdt) --DECLARE_HYPERCALL(stack_switch) --DECLARE_HYPERCALL(set_callbacks) --DECLARE_HYPERCALL(fpu_taskswitch) --DECLARE_HYPERCALL(sched_op_compat) --DECLARE_HYPERCALL(platform_op) --DECLARE_HYPERCALL(set_debugreg) --DECLARE_HYPERCALL(get_debugreg) --DECLARE_HYPERCALL(update_descriptor) --DECLARE_HYPERCALL(memory_op) --DECLARE_HYPERCALL(multicall) --DECLARE_HYPERCALL(update_va_mapping) --DECLARE_HYPERCALL(set_timer_op) --DECLARE_HYPERCALL(event_channel_op_compat) --DECLARE_HYPERCALL(xen_version) --DECLARE_HYPERCALL(console_io) --DECLARE_HYPERCALL(physdev_op_compat) --DECLARE_HYPERCALL(grant_table_op) --DECLARE_HYPERCALL(vm_assist) --DECLARE_HYPERCALL(update_va_mapping_otherdomain) --DECLARE_HYPERCALL(iret) --DECLARE_HYPERCALL(vcpu_op) --DECLARE_HYPERCALL(set_segment_base) --DECLARE_HYPERCALL(mmuext_op) --DECLARE_HYPERCALL(xsm_op) --DECLARE_HYPERCALL(nmi_op) --DECLARE_HYPERCALL(sched_op) --DECLARE_HYPERCALL(callback_op) --DECLARE_HYPERCALL(xenoprof_op) --DECLARE_HYPERCALL(event_channel_op) --DECLARE_HYPERCALL(physdev_op) --DECLARE_HYPERCALL(hvm_op) --DECLARE_HYPERCALL(sysctl) --DECLARE_HYPERCALL(domctl) --DECLARE_HYPERCALL(kexec_op) --DECLARE_HYPERCALL(argo_op) --DECLARE_HYPERCALL(xenpmu_op) -- --DECLARE_HYPERCALL(arch_0) --DECLARE_HYPERCALL(arch_1) --DECLARE_HYPERCALL(arch_2) --DECLARE_HYPERCALL(arch_3) --DECLARE_HYPERCALL(arch_4) --DECLARE_HYPERCALL(arch_5) --DECLARE_HYPERCALL(arch_6) --DECLARE_HYPERCALL(arch_7) -- --/* -- * Local variables: -- * tab-width: 8 -- * indent-tabs-mode: nil -- * End: -- */ -diff --git a/xen/arch/x86/guest/xen/xen.c b/xen/arch/x86/guest/xen/xen.c -index 7484b3f73ad3..2c30db05dfa7 100644 ---- a/xen/arch/x86/guest/xen/xen.c -+++ b/xen/arch/x86/guest/xen/xen.c -@@ -26,7 +26,6 @@ - bool __read_mostly xen_guest; - - uint32_t __read_mostly xen_cpuid_base; --extern char hypercall_page[]; - static struct rangeset *mem; - - DEFINE_PER_CPU(unsigned int, vcpu_id); -@@ -35,6 +34,50 @@ static struct vcpu_info *vcpu_info; - static unsigned long vcpu_info_mapped[BITS_TO_LONGS(NR_CPUS)]; - DEFINE_PER_CPU(struct vcpu_info *, vcpu_info); - -+/* -+ * Which instruction to use for early hypercalls: -+ * < 0 setup -+ * 0 vmcall -+ * > 0 vmmcall -+ */ -+int8_t __initdata early_hypercall_insn = -1; -+ -+/* -+ * Called once during the first hypercall to figure out which instruction to -+ * use. Error handling options are limited. -+ */ -+void asmlinkage __init early_hypercall_setup(void) -+{ -+ BUG_ON(early_hypercall_insn != -1); -+ -+ if ( !boot_cpu_data.x86_vendor ) -+ { -+ unsigned int eax, ebx, ecx, edx; -+ -+ cpuid(0, &eax, &ebx, &ecx, &edx); -+ -+ boot_cpu_data.x86_vendor = x86_cpuid_lookup_vendor(ebx, ecx, edx); -+ } -+ -+ switch ( boot_cpu_data.x86_vendor ) -+ { -+ case X86_VENDOR_INTEL: -+ case X86_VENDOR_CENTAUR: -+ case X86_VENDOR_SHANGHAI: -+ early_hypercall_insn = 0; -+ setup_force_cpu_cap(X86_FEATURE_USE_VMCALL); -+ break; -+ -+ case X86_VENDOR_AMD: -+ case X86_VENDOR_HYGON: -+ early_hypercall_insn = 1; -+ break; -+ -+ default: -+ BUG(); -+ } -+} -+ - static void __init find_xen_leaves(void) - { - uint32_t eax, ebx, ecx, edx, base; -@@ -337,9 +380,6 @@ const struct hypervisor_ops *__init xg_probe(void) - if ( !xen_cpuid_base ) - return NULL; - -- /* Fill the hypercall page. */ -- wrmsrl(cpuid_ebx(xen_cpuid_base + 2), __pa(hypercall_page)); -- - xen_guest = true; - - return &ops; -diff --git a/xen/arch/x86/include/asm/cpufeatures.h b/xen/arch/x86/include/asm/cpufeatures.h -index ba3df174b76e..9e3ed21c026d 100644 ---- a/xen/arch/x86/include/asm/cpufeatures.h -+++ b/xen/arch/x86/include/asm/cpufeatures.h -@@ -42,6 +42,7 @@ XEN_CPUFEATURE(XEN_SHSTK, X86_SYNTH(26)) /* Xen uses CET Shadow Stacks * - XEN_CPUFEATURE(XEN_IBT, X86_SYNTH(27)) /* Xen uses CET Indirect Branch Tracking */ - XEN_CPUFEATURE(IBPB_ENTRY_PV, X86_SYNTH(28)) /* MSR_PRED_CMD used by Xen for PV */ - XEN_CPUFEATURE(IBPB_ENTRY_HVM, X86_SYNTH(29)) /* MSR_PRED_CMD used by Xen for HVM */ -+XEN_CPUFEATURE(USE_VMCALL, X86_SYNTH(30)) /* Use VMCALL instead of VMMCALL */ - - /* Bug words follow the synthetic words. */ - #define X86_NR_BUG 1 -diff --git a/xen/arch/x86/include/asm/guest/xen-hcall.h b/xen/arch/x86/include/asm/guest/xen-hcall.h -index 665b472d05ac..96004dec9909 100644 ---- a/xen/arch/x86/include/asm/guest/xen-hcall.h -+++ b/xen/arch/x86/include/asm/guest/xen-hcall.h -@@ -30,9 +30,11 @@ - ({ \ - long res, tmp__; \ - asm volatile ( \ -- "call hypercall_page + %c[offset]" \ -+ ALTERNATIVE_2("call early_hypercall", \ -+ "vmmcall", ALT_NOT(X86_FEATURE_USE_VMCALL), \ -+ "vmcall", X86_FEATURE_USE_VMCALL) \ - : "=a" (res), "=D" (tmp__) ASM_CALL_CONSTRAINT \ -- : [offset] "i" (hcall * 32), \ -+ : "0" (hcall), \ - "1" ((long)(a1)) \ - : "memory" ); \ - (type)res; \ -@@ -42,10 +44,12 @@ - ({ \ - long res, tmp__; \ - asm volatile ( \ -- "call hypercall_page + %c[offset]" \ -+ ALTERNATIVE_2("call early_hypercall", \ -+ "vmmcall", ALT_NOT(X86_FEATURE_USE_VMCALL), \ -+ "vmcall", X86_FEATURE_USE_VMCALL) \ - : "=a" (res), "=D" (tmp__), "=S" (tmp__) \ - ASM_CALL_CONSTRAINT \ -- : [offset] "i" (hcall * 32), \ -+ : "0" (hcall), \ - "1" ((long)(a1)), "2" ((long)(a2)) \ - : "memory" ); \ - (type)res; \ -@@ -55,10 +59,12 @@ - ({ \ - long res, tmp__; \ - asm volatile ( \ -- "call hypercall_page + %c[offset]" \ -+ ALTERNATIVE_2("call early_hypercall", \ -+ "vmmcall", ALT_NOT(X86_FEATURE_USE_VMCALL), \ -+ "vmcall", X86_FEATURE_USE_VMCALL) \ - : "=a" (res), "=D" (tmp__), "=S" (tmp__), "=d" (tmp__) \ - ASM_CALL_CONSTRAINT \ -- : [offset] "i" (hcall * 32), \ -+ : "0" (hcall), \ - "1" ((long)(a1)), "2" ((long)(a2)), "3" ((long)(a3)) \ - : "memory" ); \ - (type)res; \ -@@ -69,10 +75,12 @@ - long res, tmp__; \ - register long _a4 asm ("r10") = ((long)(a4)); \ - asm volatile ( \ -- "call hypercall_page + %c[offset]" \ -+ ALTERNATIVE_2("call early_hypercall", \ -+ "vmmcall", ALT_NOT(X86_FEATURE_USE_VMCALL), \ -+ "vmcall", X86_FEATURE_USE_VMCALL) \ - : "=a" (res), "=D" (tmp__), "=S" (tmp__), "=d" (tmp__), \ - "=&r" (tmp__) ASM_CALL_CONSTRAINT \ -- : [offset] "i" (hcall * 32), \ -+ : "0" (hcall), \ - "1" ((long)(a1)), "2" ((long)(a2)), "3" ((long)(a3)), \ - "4" (_a4) \ - : "memory" ); \ --- -2.49.0 - diff --git a/0323-x86-thunk-Mis-align-__x86_indirect_thunk_-to-mitigat.patch b/0323-x86-thunk-Mis-align-__x86_indirect_thunk_-to-mitigat.patch deleted file mode 100644 index 8c4f9b55..00000000 --- a/0323-x86-thunk-Mis-align-__x86_indirect_thunk_-to-mitigat.patch +++ /dev/null @@ -1,55 +0,0 @@ -From 545eba29ac798305e2c5cb1fe5112771b6890907 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Mon, 7 Apr 2025 17:15:50 +0200 -Subject: [PATCH] x86/thunk: (Mis)align __x86_indirect_thunk_* to mitigate ITS - -The Indirect Target Selection speculative vulnerability means that indirect -branches (including RETs) are unsafe when in the first half of a cacheline. - -Arrange for __x86_indirect_thunk_* to always be in the second half. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Jan Beulich -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit d293cc9da9021a51915e058acd1f05e83a462aa9) ---- - xen/arch/x86/indirect-thunk.S | 14 ++++++++++++++ - 1 file changed, 14 insertions(+) - -diff --git a/xen/arch/x86/indirect-thunk.S b/xen/arch/x86/indirect-thunk.S -index fd5493c22b16..c4b978d67b8e 100644 ---- a/xen/arch/x86/indirect-thunk.S -+++ b/xen/arch/x86/indirect-thunk.S -@@ -11,6 +11,10 @@ - - #include - -+/* Alignment is dealt with explicitly here; override the respective macro. */ -+#undef SYM_ALIGN -+#define SYM_ALIGN(align...) -+ - .macro IND_THUNK_RETPOLINE reg:req - call 1f - int3 -@@ -35,6 +39,16 @@ - .macro GEN_INDIRECT_THUNK reg:req - .section .text.__x86_indirect_thunk_\reg, "ax", @progbits - -+ /* -+ * The Indirect Target Selection speculative vulnerability means that -+ * indirect branches (including RETs) are unsafe when in the first -+ * half of a cacheline. Arrange for them to be in the second half. -+ * -+ * Align to 64, then skip 32. -+ */ -+ .balign 64 -+ .fill 32, 1, 0xcc -+ - FUNC(__x86_indirect_thunk_\reg) - ALTERNATIVE_2 __stringify(IND_THUNK_RETPOLINE \reg), \ - __stringify(IND_THUNK_LFENCE \reg), X86_FEATURE_IND_THUNK_LFENCE, \ --- -2.49.0 - diff --git a/0324-x86-thunk-Mis-align-the-RETs-in-clear_bhb_loops-to-m.patch b/0324-x86-thunk-Mis-align-the-RETs-in-clear_bhb_loops-to-m.patch deleted file mode 100644 index bd7c3e64..00000000 --- a/0324-x86-thunk-Mis-align-the-RETs-in-clear_bhb_loops-to-m.patch +++ /dev/null @@ -1,77 +0,0 @@ -From 556ca37970cd992a113936cf66076caf2dcf4b09 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Mon, 5 May 2025 14:27:01 +0100 -Subject: [PATCH] x86/thunk: (Mis)align the RETs in clear_bhb_loops() to - mitigate ITS -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The Indirect Target Selection speculative vulnerability means that indirect -branches (including RETs) are unsafe when in the first half of a cacheline. - -clear_bhb_loops() has a precise layout of branches. The alignment for -performance cause the RETs to always be in an unsafe position, and converting -those to return thunks changes the branching pattern. While such a conversion -is believed to be safe, clear_bhb_loops() is also a performance-relevant -fastpath, so (mis)align the RETs to be in a safe position. - -No functional change. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit c0db07031a41ff892f57756b7e2b4ef98df72588) ---- - xen/arch/x86/bhb-thunk.S | 17 ++++++++++++----- - 1 file changed, 12 insertions(+), 5 deletions(-) - -diff --git a/xen/arch/x86/bhb-thunk.S b/xen/arch/x86/bhb-thunk.S -index 678c00c5d06f..52625f4e2c17 100644 ---- a/xen/arch/x86/bhb-thunk.S -+++ b/xen/arch/x86/bhb-thunk.S -@@ -50,7 +50,12 @@ END(clear_bhb_tsx) - * ret - * - * The CALL/RETs are necessary to prevent the Loop Stream Detector from -- * interfering. The alignment is for performance and not safety. -+ * interfering. -+ * -+ * The .balign's are for performance, but they cause the RETs to be in unsafe -+ * positions with respect to Indirect Target Selection. The .skips are to -+ * move the RETs into ITS-safe positions, rather than using the slowpath -+ * through __x86_return_thunk. - * - * The "short" sequence (5 and 5) is for CPUs prior to Alder Lake / Sapphire - * Rapids (i.e. Cores prior to Golden Cove and/or Gracemont). -@@ -66,12 +71,14 @@ FUNC(clear_bhb_loops) - jmp 5f - int3 - -- .align 64 -+ .balign 64 -+ .skip 32 - (.Lr1 - 1f), 0xcc - 1: call 2f -- ret -+.Lr1: ret - int3 - -- .align 64 -+ .balign 64 -+ .skip 32 - 18 /* (.Lr2 - 2f) but Clang IAS doesn't like this */, 0xcc - 2: ALTERNATIVE "mov $5, %eax", "mov $7, %eax", X86_SPEC_BHB_LOOPS_LONG - - 3: jmp 4f -@@ -83,7 +90,7 @@ FUNC(clear_bhb_loops) - sub $1, %ecx - jnz 1b - -- ret -+.Lr2: ret - 5: - /* - * The Intel sequence has an LFENCE here. The purpose is to ensure --- -2.49.0 - diff --git a/0325-x86-stubs-Introduce-place_ret-to-abstract-away-raw-0.patch b/0325-x86-stubs-Introduce-place_ret-to-abstract-away-raw-0.patch deleted file mode 100644 index ae6553c3..00000000 --- a/0325-x86-stubs-Introduce-place_ret-to-abstract-away-raw-0.patch +++ /dev/null @@ -1,525 +0,0 @@ -From 20719483154f9635d888ae7e12adb2985852758c Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Sun, 4 May 2025 22:44:42 +0100 -Subject: [PATCH] x86/stubs: Introduce place_ret() to abstract away raw 0xc3's -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The Indirect Target Selection speculative vulnerability means that indirect -branches (including RETs) are unsafe when in the first half of a cacheline. -This means it's not safe for logic using the stubs to write raw 0xc3's. - -Introduce place_ret() which, for now, writes a raw 0xc3 but will contain -additional logic when return thunks are in use. - -stub_selftest() doesn't strictly need to be converted as they only run on -boot, but doing so gets us a partial test of place_ret() too. - -No functional change. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit 2eb1132f796386e4524fb25dd0ed349e14ca35dd) ---- - tools/tests/x86_emulator/x86-emulate.h | 6 +++ - xen/arch/x86/Makefile | 6 +-- - xen/arch/x86/alternative.c | 14 ++++++ - xen/arch/x86/extable.c | 11 +++-- - xen/arch/x86/include/asm/alternative.h | 2 + - xen/arch/x86/pv/emul-priv-op.c | 5 +- - xen/arch/x86/x86_emulate/fpu.c | 18 +++++--- - xen/arch/x86/x86_emulate/x86_emulate.c | 64 +++++++++++++------------- - 8 files changed, 77 insertions(+), 49 deletions(-) - -diff --git a/tools/tests/x86_emulator/x86-emulate.h b/tools/tests/x86_emulator/x86-emulate.h -index 8f8accfe3e70..946aaa9d660b 100644 ---- a/tools/tests/x86_emulator/x86-emulate.h -+++ b/tools/tests/x86_emulator/x86-emulate.h -@@ -68,6 +68,12 @@ - - #define is_canonical_address(x) (((int64_t)(x) >> 47) == ((int64_t)(x) >> 63)) - -+static inline void *place_ret(void *ptr) -+{ -+ *(uint8_t *)ptr = 0xc3; -+ return ptr + 1; -+} -+ - extern uint32_t mxcsr_mask; - extern struct cpu_policy cp; - -diff --git a/xen/arch/x86/Makefile b/xen/arch/x86/Makefile -index c1e64278ce85..a7e5a82689de 100644 ---- a/xen/arch/x86/Makefile -+++ b/xen/arch/x86/Makefile -@@ -11,9 +11,7 @@ obj-$(CONFIG_PV) += pv/ - obj-y += x86_64/ - obj-y += x86_emulate/ - --alternative-y := alternative.init.o --alternative-$(CONFIG_LIVEPATCH) := --obj-bin-y += $(alternative-y) -+obj-y += alternative.o - obj-y += apic.o - obj-y += bhb-thunk.o - obj-y += bitops.o -@@ -41,7 +39,7 @@ obj-y += hypercall.o - obj-y += i387.o - obj-y += i8259.o - obj-y += io_apic.o --obj-$(CONFIG_LIVEPATCH) += alternative.o livepatch.o -+obj-$(CONFIG_LIVEPATCH) += livepatch.o - obj-y += msi.o - obj-y += msr.o - obj-$(CONFIG_INDIRECT_THUNK) += indirect-thunk.o -diff --git a/xen/arch/x86/alternative.c b/xen/arch/x86/alternative.c -index 88c90044c20d..ec451d962c10 100644 ---- a/xen/arch/x86/alternative.c -+++ b/xen/arch/x86/alternative.c -@@ -137,6 +137,20 @@ void init_or_livepatch add_nops(void *insns, unsigned int len) - } - } - -+/* -+ * Place a return at @ptr. @ptr must be in the writable alias of a stub. -+ * -+ * Returns the next position to write into the stub. -+ */ -+void *place_ret(void *ptr) -+{ -+ uint8_t *p = ptr; -+ -+ *p++ = 0xc3; -+ -+ return p; -+} -+ - /* - * text_poke - Update instructions on a live kernel or non-executed code. - * @addr: address to modify -diff --git a/xen/arch/x86/extable.c b/xen/arch/x86/extable.c -index 705cf9eb94ca..1572efa69a00 100644 ---- a/xen/arch/x86/extable.c -+++ b/xen/arch/x86/extable.c -@@ -151,20 +151,20 @@ search_exception_table(const struct cpu_user_regs *regs, unsigned long *stub_ra) - int __init cf_check stub_selftest(void) - { - static const struct { -- uint8_t opc[8]; -+ uint8_t opc[7]; - uint64_t rax; - union stub_exception_token res; - } tests[] __initconst = { - #define endbr64 0xf3, 0x0f, 0x1e, 0xfa -- { .opc = { endbr64, 0x0f, 0xb9, 0xc3, 0xc3 }, /* ud1 */ -+ { .opc = { endbr64, 0x0f, 0xb9, 0x90 }, /* ud1 */ - .res.fields.trapnr = X86_EXC_UD }, -- { .opc = { endbr64, 0x90, 0x02, 0x00, 0xc3 }, /* nop; add (%rax),%al */ -+ { .opc = { endbr64, 0x90, 0x02, 0x00 }, /* nop; add (%rax),%al */ - .rax = 0x0123456789abcdef, - .res.fields.trapnr = X86_EXC_GP }, -- { .opc = { endbr64, 0x02, 0x04, 0x04, 0xc3 }, /* add (%rsp,%rax),%al */ -+ { .opc = { endbr64, 0x02, 0x04, 0x04 }, /* add (%rsp,%rax),%al */ - .rax = 0xfedcba9876543210UL, - .res.fields.trapnr = X86_EXC_SS }, -- { .opc = { endbr64, 0xcc, 0xc3, 0xc3, 0xc3 }, /* int3 */ -+ { .opc = { endbr64, 0xcc, 0x90, 0x90 }, /* int3 */ - .res.fields.trapnr = X86_EXC_BP }, - #undef endbr64 - }; -@@ -183,6 +183,7 @@ int __init cf_check stub_selftest(void) - - memset(ptr, 0xcc, STUB_BUF_SIZE / 2); - memcpy(ptr, tests[i].opc, ARRAY_SIZE(tests[i].opc)); -+ place_ret(ptr + ARRAY_SIZE(tests[i].opc)); - unmap_domain_page(ptr); - - asm volatile ( "INDIRECT_CALL %[stb]\n" -diff --git a/xen/arch/x86/include/asm/alternative.h b/xen/arch/x86/include/asm/alternative.h -index 89b7bdcb82e5..841a63ebf1b6 100644 ---- a/xen/arch/x86/include/asm/alternative.h -+++ b/xen/arch/x86/include/asm/alternative.h -@@ -30,6 +30,8 @@ struct __packed alt_instr { - #define ALT_REPL_PTR(a) __ALT_PTR(a, repl_offset) - - extern void add_nops(void *insns, unsigned int len); -+void *place_ret(void *ptr); -+ - /* Similar to alternative_instructions except it can be run with IRQs enabled. */ - extern int apply_alternatives(struct alt_instr *start, struct alt_instr *end); - extern void alternative_instructions(void); -diff --git a/xen/arch/x86/pv/emul-priv-op.c b/xen/arch/x86/pv/emul-priv-op.c -index 70150c272276..ff5d1c9f8634 100644 ---- a/xen/arch/x86/pv/emul-priv-op.c -+++ b/xen/arch/x86/pv/emul-priv-op.c -@@ -76,7 +76,6 @@ static io_emul_stub_t *io_emul_stub_setup(struct priv_op_ctxt *ctxt, u8 opcode, - 0x41, 0x5c, /* pop %r12 */ - 0x5d, /* pop %rbp */ - 0x5b, /* pop %rbx */ -- 0xc3, /* ret */ - }; - - const struct stubs *this_stubs = &this_cpu(stubs); -@@ -126,11 +125,13 @@ static io_emul_stub_t *io_emul_stub_setup(struct priv_op_ctxt *ctxt, u8 opcode, - - APPEND_CALL(save_guest_gprs); - APPEND_BUFF(epilogue); -+ p = place_ret(p); - - /* Build-time best effort attempt to catch problems. */ - BUILD_BUG_ON(STUB_BUF_SIZE / 2 < - (sizeof(prologue) + sizeof(epilogue) + 10 /* 2x call */ + -- MAX(3 /* default stub */, IOEMUL_QUIRK_STUB_BYTES))); -+ MAX(3 /* default stub */, IOEMUL_QUIRK_STUB_BYTES) + -+ 1 /* ret */)); - /* Runtime confirmation that we haven't clobbered an adjacent stub. */ - BUG_ON(STUB_BUF_SIZE / 2 < (p - ctxt->io_emul_stub)); - -diff --git a/xen/arch/x86/x86_emulate/fpu.c b/xen/arch/x86/x86_emulate/fpu.c -index 480d87965705..03612d00a2ce 100644 ---- a/xen/arch/x86/x86_emulate/fpu.c -+++ b/xen/arch/x86/x86_emulate/fpu.c -@@ -32,36 +32,42 @@ static inline bool fpu_check_write(void) - - #define emulate_fpu_insn_memdst(opc, ext, arg) \ - do { \ -+ void *_p = get_stub(stub); \ - /* ModRM: mod=0, reg=ext, rm=0, i.e. a (%rax) operand */ \ - *insn_bytes = 2; \ -- memcpy(get_stub(stub), \ -- ((uint8_t[]){ opc, ((ext) & 7) << 3, 0xc3 }), 3); \ -+ memcpy(_p, ((uint8_t[]){ opc, ((ext) & 7) << 3 }), 2); _p += 2; \ -+ place_ret(_p); \ - invoke_stub("", "", "+m" (arg) : "a" (&(arg))); \ - put_stub(stub); \ - } while (0) - - #define emulate_fpu_insn_memsrc(opc, ext, arg) \ - do { \ -+ void *_p = get_stub(stub); \ - /* ModRM: mod=0, reg=ext, rm=0, i.e. a (%rax) operand */ \ -- memcpy(get_stub(stub), \ -- ((uint8_t[]){ opc, ((ext) & 7) << 3, 0xc3 }), 3); \ -+ memcpy(_p, ((uint8_t[]){ opc, ((ext) & 7) << 3 }), 2); _p += 2; \ -+ place_ret(_p); \ - invoke_stub("", "", "=m" (dummy) : "m" (arg), "a" (&(arg))); \ - put_stub(stub); \ - } while (0) - - #define emulate_fpu_insn_stub(bytes...) \ - do { \ -+ void *_p = get_stub(stub); \ - unsigned int nr_ = sizeof((uint8_t[]){ bytes }); \ -- memcpy(get_stub(stub), ((uint8_t[]){ bytes, 0xc3 }), nr_ + 1); \ -+ memcpy(_p, ((uint8_t[]){ bytes }), nr_); _p += nr_; \ -+ place_ret(_p); \ - invoke_stub("", "", "=m" (dummy) : "i" (0)); \ - put_stub(stub); \ - } while (0) - - #define emulate_fpu_insn_stub_eflags(bytes...) \ - do { \ -+ void *_p = get_stub(stub); \ - unsigned int nr_ = sizeof((uint8_t[]){ bytes }); \ - unsigned long tmp_; \ -- memcpy(get_stub(stub), ((uint8_t[]){ bytes, 0xc3 }), nr_ + 1); \ -+ memcpy(_p, ((uint8_t[]){ bytes }), nr_); _p += nr_; \ -+ place_ret(_p); \ - invoke_stub(_PRE_EFLAGS("[eflags]", "[mask]", "[tmp]"), \ - _POST_EFLAGS("[eflags]", "[mask]", "[tmp]"), \ - [eflags] "+g" (regs->eflags), [tmp] "=&r" (tmp_) \ -diff --git a/xen/arch/x86/x86_emulate/x86_emulate.c b/xen/arch/x86/x86_emulate/x86_emulate.c -index b1d192cbbf1e..f40709682484 100644 ---- a/xen/arch/x86/x86_emulate/x86_emulate.c -+++ b/xen/arch/x86/x86_emulate/x86_emulate.c -@@ -1396,7 +1396,7 @@ x86_emulate( - stb[3] = 0x91; - stb[4] = evex.opmsk << 3; - insn_bytes = 5; -- stb[5] = 0xc3; -+ place_ret(&stb[5]); - - invoke_stub("", "", "+m" (op_mask) : "a" (&op_mask)); - -@@ -3627,7 +3627,7 @@ x86_emulate( - } - opc[1] = (modrm & 0x38) | 0xc0; - insn_bytes = EVEX_PFX_BYTES + 2; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_EVEX(opc, evex); - invoke_stub("", "", "=g" (dummy) : "a" (src.val)); -@@ -3694,7 +3694,7 @@ x86_emulate( - insn_bytes = PFX_BYTES + 2; - copy_REX_VEX(opc, rex_prefix, vex); - } -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - ea.reg = decode_gpr(&_regs, modrm_reg); - invoke_stub("", "", "=a" (*ea.reg) : "c" (mmvalp), "m" (*mmvalp)); -@@ -3768,7 +3768,7 @@ x86_emulate( - insn_bytes = PFX_BYTES + 2; - copy_REX_VEX(opc, rex_prefix, vex); - } -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - _regs.eflags &= ~EFLAGS_MASK; - invoke_stub("", -@@ -4004,7 +4004,7 @@ x86_emulate( - opc[1] = modrm & 0xc7; - insn_bytes = PFX_BYTES + 2; - simd_0f_to_gpr: -- opc[insn_bytes - PFX_BYTES] = 0xc3; -+ place_ret(&opc[insn_bytes - PFX_BYTES]); - - generate_exception_if(ea.type != OP_REG, X86_EXC_UD); - -@@ -4401,7 +4401,7 @@ x86_emulate( - vex.w = 0; - opc[1] = modrm & 0x38; - insn_bytes = PFX_BYTES + 2; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_REX_VEX(opc, rex_prefix, vex); - invoke_stub("", "", "+m" (src.val) : "a" (&src.val)); -@@ -4438,7 +4438,7 @@ x86_emulate( - evex.w = 0; - opc[1] = modrm & 0x38; - insn_bytes = EVEX_PFX_BYTES + 2; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_EVEX(opc, evex); - invoke_stub("", "", "+m" (src.val) : "a" (&src.val)); -@@ -4633,7 +4633,7 @@ x86_emulate( - #endif /* X86EMUL_NO_SIMD */ - - simd_0f_reg_only: -- opc[insn_bytes - PFX_BYTES] = 0xc3; -+ place_ret(&opc[insn_bytes - PFX_BYTES]); - - copy_REX_VEX(opc, rex_prefix, vex); - invoke_stub("", "", [dummy_out] "=g" (dummy) : [dummy_in] "i" (0) ); -@@ -4967,7 +4967,7 @@ x86_emulate( - if ( !mode_64bit() ) - vex.w = 0; - opc[1] = modrm & 0xf8; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_VEX(opc, vex); - ea.reg = decode_gpr(&_regs, modrm_rm); -@@ -5010,7 +5010,7 @@ x86_emulate( - if ( !mode_64bit() ) - vex.w = 0; - opc[1] = modrm & 0xc7; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_VEX(opc, vex); - invoke_stub("", "", "=a" (dst.val) : [dummy] "i" (0)); -@@ -5040,7 +5040,7 @@ x86_emulate( - opc = init_prefixes(stub); - opc[0] = b; - opc[1] = modrm; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_VEX(opc, vex); - _regs.eflags &= ~EFLAGS_MASK; -@@ -5608,7 +5608,7 @@ x86_emulate( - if ( !mode_64bit() ) - vex.w = 0; - opc[1] = modrm & 0xc7; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_REX_VEX(opc, rex_prefix, vex); - invoke_stub("", "", "=a" (ea.val) : [dummy] "i" (0)); -@@ -5726,7 +5726,7 @@ x86_emulate( - opc[1] &= 0x38; - } - insn_bytes = PFX_BYTES + 2; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - if ( vex.opcx == vex_none ) - { - /* Cover for extra prefix byte. */ -@@ -6006,7 +6006,7 @@ x86_emulate( - pvex->b = !mode_64bit() || (vex.reg >> 3); - opc[1] = 0xc0 | (~vex.reg & 7); - pvex->reg = 0xf; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "=a" (ea.val) : [dummy] "i" (0)); - put_stub(stub); -@@ -6290,7 +6290,7 @@ x86_emulate( - evex.w = 0; - opc[1] = modrm & 0xf8; - insn_bytes = EVEX_PFX_BYTES + 2; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - copy_EVEX(opc, evex); - invoke_stub("", "", "=g" (dummy) : "a" (src.val)); -@@ -6389,7 +6389,7 @@ x86_emulate( - pvex->b = 1; - opc[1] = (modrm_reg & 7) << 3; - pvex->reg = 0xf; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "=m" (*mmvalp) : "a" (mmvalp)); - -@@ -6459,7 +6459,7 @@ x86_emulate( - pvex->b = 1; - opc[1] = (modrm_reg & 7) << 3; - pvex->reg = 0xf; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "+m" (*mmvalp) : "a" (mmvalp)); - -@@ -6515,7 +6515,7 @@ x86_emulate( - pevex->b = 1; - opc[1] = (modrm_reg & 7) << 3; - pevex->RX = 1; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "=m" (*mmvalp) : "a" (mmvalp)); - -@@ -6580,7 +6580,7 @@ x86_emulate( - pevex->b = 1; - opc[1] = (modrm_reg & 7) << 3; - pevex->RX = 1; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "+m" (*mmvalp) : "a" (mmvalp)); - -@@ -6594,7 +6594,7 @@ x86_emulate( - opc[2] = 0x90; - /* Use (%rax) as source. */ - opc[3] = evex.opmsk << 3; -- opc[4] = 0xc3; -+ place_ret(&opc[4]); - - invoke_stub("", "", "+m" (op_mask) : "a" (&op_mask)); - put_stub(stub); -@@ -6688,7 +6688,7 @@ x86_emulate( - pevex->b = 1; - opc[1] = (modrm_reg & 7) << 3; - pevex->RX = 1; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "=m" (*mmvalp) : "a" (mmvalp)); - -@@ -6766,7 +6766,7 @@ x86_emulate( - opc[2] = 0x90; - /* Use (%rax) as source. */ - opc[3] = evex.opmsk << 3; -- opc[4] = 0xc3; -+ place_ret(&opc[4]); - - invoke_stub("", "", "+m" (op_mask) : "a" (&op_mask)); - put_stub(stub); -@@ -6848,7 +6848,7 @@ x86_emulate( - pevex->r = !mode_64bit() || !(state->sib_index & 0x08); - pevex->R = !mode_64bit() || !(state->sib_index & 0x10); - pevex->RX = 1; -- opc[2] = 0xc3; -+ place_ret(&opc[2]); - - invoke_stub("", "", "=m" (index) : "a" (&index)); - put_stub(stub); -@@ -7058,7 +7058,7 @@ x86_emulate( - pvex->reg = 0xf; /* rAX */ - buf[3] = b; - buf[4] = 0x09; /* reg=rCX r/m=(%rCX) */ -- buf[5] = 0xc3; -+ place_ret(&buf[5]); - - src.reg = decode_vex_gpr(vex.reg, &_regs, ctxt); - emulate_stub([dst] "=&c" (dst.val), "[dst]" (&src.val), "a" (*src.reg)); -@@ -7094,7 +7094,7 @@ x86_emulate( - pvex->reg = 0xf; /* rAX */ - buf[3] = b; - buf[4] = (modrm & 0x38) | 0x01; /* r/m=(%rCX) */ -- buf[5] = 0xc3; -+ place_ret(&buf[5]); - - dst.reg = decode_vex_gpr(vex.reg, &_regs, ctxt); - emulate_stub("=&a" (dst.val), "c" (&src.val)); -@@ -7335,7 +7335,7 @@ x86_emulate( - evex.w = vex.w = 0; - opc[1] = modrm & 0x38; - opc[2] = imm1; -- opc[3] = 0xc3; -+ place_ret(&opc[3]); - if ( vex.opcx == vex_none ) - { - /* Cover for extra prefix byte. */ -@@ -7502,7 +7502,7 @@ x86_emulate( - insn_bytes = PFX_BYTES + 3; - copy_VEX(opc, vex); - } -- opc[3] = 0xc3; -+ place_ret(&opc[3]); - - /* Latch MXCSR - we may need to restore it below. */ - invoke_stub("stmxcsr %[mxcsr]", "", -@@ -7748,7 +7748,7 @@ x86_emulate( - } - opc[2] = imm1; - insn_bytes = PFX_BYTES + 3; -- opc[3] = 0xc3; -+ place_ret(&opc[3]); - if ( vex.opcx == vex_none ) - { - /* Cover for extra prefix byte. */ -@@ -8094,7 +8094,7 @@ x86_emulate( - pxop->reg = 0xf; /* rAX */ - buf[3] = b; - buf[4] = (modrm & 0x38) | 0x01; /* r/m=(%rCX) */ -- buf[5] = 0xc3; -+ place_ret(&buf[5]); - - dst.reg = decode_vex_gpr(vex.reg, &_regs, ctxt); - emulate_stub([dst] "=&a" (dst.val), "c" (&src.val)); -@@ -8203,7 +8203,7 @@ x86_emulate( - buf[3] = b; - buf[4] = 0x09; /* reg=rCX r/m=(%rCX) */ - *(uint32_t *)(buf + 5) = imm1; -- buf[9] = 0xc3; -+ place_ret(&buf[9]); - - emulate_stub([dst] "=&c" (dst.val), "[dst]" (&src.val)); - -@@ -8293,12 +8293,12 @@ x86_emulate( - BUG(); - if ( evex_encoded() ) - { -- opc[insn_bytes - EVEX_PFX_BYTES] = 0xc3; -+ place_ret(&opc[insn_bytes - EVEX_PFX_BYTES]); - copy_EVEX(opc, evex); - } - else - { -- opc[insn_bytes - PFX_BYTES] = 0xc3; -+ place_ret(&opc[insn_bytes - PFX_BYTES]); - copy_REX_VEX(opc, rex_prefix, vex); - } - --- -2.49.0 - diff --git a/0326-x86-thunk-Build-Xen-with-Return-Thunks.patch b/0326-x86-thunk-Build-Xen-with-Return-Thunks.patch deleted file mode 100644 index ba83b992..00000000 --- a/0326-x86-thunk-Build-Xen-with-Return-Thunks.patch +++ /dev/null @@ -1,404 +0,0 @@ -From 58ab9fcc3f80ee6eeb7f6db4ca922f79a84e18b8 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Mon, 7 Apr 2025 17:15:17 +0200 -Subject: [PATCH] x86/thunk: Build Xen with Return Thunks -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The Indirect Target Selection speculative vulnerability means that indirect -branches (including RETs) are unsafe when in the first half of a cacheline. - -In order to mitigate this, build with return thunks and arrange for -__x86_return_thunk to be (mis)aligned in the same manner as -__x86_indirect_thunk_* so the RET instruction is placed in a safe location. - -place_ret() needs to conditionally emit JMP __x86_return_thunk instead of RET. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Jan Beulich -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit afcb4a06c740f7f71d2e9746c9d147c38a6e6c90) ---- - xen/arch/x86/Kconfig | 5 +++++ - xen/arch/x86/Makefile | 1 + - xen/arch/x86/acpi/wakeup_prot.S | 2 +- - xen/arch/x86/alternative.c | 31 +++++++++++++++++++++++++++- - xen/arch/x86/arch.mk | 3 +++ - xen/arch/x86/bhb-thunk.S | 2 +- - xen/arch/x86/clear_page.S | 4 +++- - xen/arch/x86/copy_page.S | 4 +++- - xen/arch/x86/efi/check.c | 3 +++ - xen/arch/x86/include/asm/asm-defns.h | 6 ++++++ - xen/arch/x86/indirect-thunk.S | 24 +++++++++++++++++++++ - xen/arch/x86/pv/emul-priv-op.c | 2 +- - xen/arch/x86/pv/gpr_switch.S | 4 ++-- - xen/arch/x86/spec_ctrl.c | 3 +++ - xen/arch/x86/x86_64/compat/entry.S | 6 +++--- - xen/arch/x86/x86_64/entry.S | 2 +- - xen/arch/x86/xen.lds.S | 1 + - xen/common/Kconfig | 11 ++++++++++ - 18 files changed, 102 insertions(+), 12 deletions(-) - -diff --git a/xen/arch/x86/Kconfig b/xen/arch/x86/Kconfig -index 7e03e4bc5546..4542ea8408c7 100644 ---- a/xen/arch/x86/Kconfig -+++ b/xen/arch/x86/Kconfig -@@ -37,9 +37,14 @@ config ARCH_DEFCONFIG - default "arch/x86/configs/x86_64_defconfig" - - config CC_HAS_INDIRECT_THUNK -+ # GCC >= 8 or Clang >= 6 - def_bool $(cc-option,-mindirect-branch-register) || \ - $(cc-option,-mretpoline-external-thunk) - -+config CC_HAS_RETURN_THUNK -+ # GCC >= 8 or Clang >= 15 -+ def_bool $(cc-option,-mfunction-return=thunk-extern) -+ - config HAS_AS_CET_SS - # binutils >= 2.29 or LLVM >= 6 - def_bool $(as-instr,wrssq %rax$(comma)0;setssbsy) -diff --git a/xen/arch/x86/Makefile b/xen/arch/x86/Makefile -index a7e5a82689de..27806a81aca8 100644 ---- a/xen/arch/x86/Makefile -+++ b/xen/arch/x86/Makefile -@@ -43,6 +43,7 @@ obj-$(CONFIG_LIVEPATCH) += livepatch.o - obj-y += msi.o - obj-y += msr.o - obj-$(CONFIG_INDIRECT_THUNK) += indirect-thunk.o -+obj-$(CONFIG_RETURN_THUNK) += indirect-thunk.o - obj-$(CONFIG_PV) += ioport_emulate.o - obj-y += irq.o - obj-$(CONFIG_KEXEC) += machine_kexec.o -diff --git a/xen/arch/x86/acpi/wakeup_prot.S b/xen/arch/x86/acpi/wakeup_prot.S -index 66f799339913..97bd676aaee2 100644 ---- a/xen/arch/x86/acpi/wakeup_prot.S -+++ b/xen/arch/x86/acpi/wakeup_prot.S -@@ -133,7 +133,7 @@ ENTRY(s3_resume) - pop %r12 - pop %rbx - pop %rbp -- ret -+ RET - - .data - .align 16 -diff --git a/xen/arch/x86/alternative.c b/xen/arch/x86/alternative.c -index ec451d962c10..1b71ae959abe 100644 ---- a/xen/arch/x86/alternative.c -+++ b/xen/arch/x86/alternative.c -@@ -137,16 +137,45 @@ void init_or_livepatch add_nops(void *insns, unsigned int len) - } - } - -+void nocall __x86_return_thunk(void); -+ - /* - * Place a return at @ptr. @ptr must be in the writable alias of a stub. - * -+ * When CONFIG_RETURN_THUNK is active, this may be a JMP __x86_return_thunk -+ * instead, depending on the safety of @ptr with respect to Indirect Target -+ * Selection. -+ * - * Returns the next position to write into the stub. - */ - void *place_ret(void *ptr) - { -+ unsigned long addr = (unsigned long)ptr; - uint8_t *p = ptr; - -- *p++ = 0xc3; -+ /* -+ * When Return Thunks are used, if a RET would be unsafe at this location -+ * with respect to Indirect Target Selection (i.e. if addr is in the first -+ * half of a cacheline), insert a JMP __x86_return_thunk instead. -+ * -+ * The displacement needs to be relative to the executable alias of the -+ * stub, not to @ptr which is the writeable alias. -+ */ -+ if ( IS_ENABLED(CONFIG_RETURN_THUNK) && !(addr & 0x20) ) -+ { -+ long stub_va = (this_cpu(stubs.addr) & PAGE_MASK) + (addr & ~PAGE_MASK); -+ long disp = (long)__x86_return_thunk - (stub_va + 5); -+ -+ BUG_ON((int32_t)disp != disp); -+ -+ *p++ = 0xe9; -+ *(int32_t *)p = disp; -+ p += 4; -+ } -+ else -+ { -+ *p++ = 0xc3; -+ } - - return p; - } -diff --git a/xen/arch/x86/arch.mk b/xen/arch/x86/arch.mk -index b88d097a844b..85d3e7cbfeeb 100644 ---- a/xen/arch/x86/arch.mk -+++ b/xen/arch/x86/arch.mk -@@ -46,6 +46,9 @@ CFLAGS-$(CONFIG_CC_IS_GCC) += -fno-jump-tables - CFLAGS-$(CONFIG_CC_IS_CLANG) += -mretpoline-external-thunk - endif - -+# Compile with return thunk support if selected. -+CFLAGS-$(CONFIG_RETURN_THUNK) += -mfunction-return=thunk-extern -+ - # Disable the addition of a .note.gnu.property section to object files when - # livepatch support is enabled. The contents of that section can change - # depending on the instructions used, and livepatch-build-tools doesn't know -diff --git a/xen/arch/x86/bhb-thunk.S b/xen/arch/x86/bhb-thunk.S -index 52625f4e2c17..7f92201a3cbb 100644 ---- a/xen/arch/x86/bhb-thunk.S -+++ b/xen/arch/x86/bhb-thunk.S -@@ -23,7 +23,7 @@ FUNC(clear_bhb_tsx) - 0: .byte 0xc6, 0xf8, 0 /* xabort $0 */ - int3 - 1: -- ret -+ RET - END(clear_bhb_tsx) - - /* -diff --git a/xen/arch/x86/clear_page.S b/xen/arch/x86/clear_page.S -index d6c076f1d8bc..dc3c3c26bfb7 100644 ---- a/xen/arch/x86/clear_page.S -+++ b/xen/arch/x86/clear_page.S -@@ -1,6 +1,8 @@ - .file __FILE__ - - #include -+ -+#include - #include - - FUNC(clear_page_sse2) -@@ -16,5 +18,5 @@ FUNC(clear_page_sse2) - jnz 0b - - sfence -- ret -+ RET - END(clear_page_sse2) -diff --git a/xen/arch/x86/copy_page.S b/xen/arch/x86/copy_page.S -index c3c436545bac..e43e5370c815 100644 ---- a/xen/arch/x86/copy_page.S -+++ b/xen/arch/x86/copy_page.S -@@ -1,6 +1,8 @@ - .file __FILE__ - - #include -+ -+#include - #include - - #define src_reg %rsi -@@ -41,5 +43,5 @@ FUNC(copy_page_sse2) - movnti tmp4_reg, 3*WORD_SIZE(dst_reg) - - sfence -- ret -+ RET - END(copy_page_sse2) -diff --git a/xen/arch/x86/efi/check.c b/xen/arch/x86/efi/check.c -index 9e473faad3c9..23ba30abf330 100644 ---- a/xen/arch/x86/efi/check.c -+++ b/xen/arch/x86/efi/check.c -@@ -3,6 +3,9 @@ int __attribute__((__ms_abi__)) test(int i) - return i; - } - -+/* In case -mfunction-return is in use. */ -+void __x86_return_thunk(void) {}; -+ - /* - * Populate an array with "addresses" of relocatable and absolute values. - * This is to probe ld for (a) emitting base relocations at all and (b) not -diff --git a/xen/arch/x86/include/asm/asm-defns.h b/xen/arch/x86/include/asm/asm-defns.h -index 32d6b4491063..97ebe21298a2 100644 ---- a/xen/arch/x86/include/asm/asm-defns.h -+++ b/xen/arch/x86/include/asm/asm-defns.h -@@ -58,6 +58,12 @@ - .endif - .endm - -+#ifdef CONFIG_RETURN_THUNK -+# define RET jmp __x86_return_thunk -+#else -+# define RET ret -+#endif -+ - #ifdef CONFIG_XEN_IBT - # define ENDBR64 endbr64 - #else -diff --git a/xen/arch/x86/indirect-thunk.S b/xen/arch/x86/indirect-thunk.S -index c4b978d67b8e..26dad15f12c9 100644 ---- a/xen/arch/x86/indirect-thunk.S -+++ b/xen/arch/x86/indirect-thunk.S -@@ -15,6 +15,8 @@ - #undef SYM_ALIGN - #define SYM_ALIGN(align...) - -+#ifdef CONFIG_INDIRECT_THUNK -+ - .macro IND_THUNK_RETPOLINE reg:req - call 1f - int3 -@@ -62,3 +64,25 @@ END(__x86_indirect_thunk_\reg) - .irp reg, ax, cx, dx, bx, bp, si, di, 8, 9, 10, 11, 12, 13, 14, 15 - GEN_INDIRECT_THUNK reg=r\reg - .endr -+ -+#endif /* CONFIG_INDIRECT_THUNK */ -+ -+#ifdef CONFIG_RETURN_THUNK -+ .section .text.entry.__x86_return_thunk, "ax", @progbits -+ -+ /* -+ * The Indirect Target Selection speculative vulnerability means that -+ * indirect branches (including RETs) are unsafe when in the first -+ * half of a cacheline. Arrange for them to be in the second half. -+ * -+ * Align to 64, then skip 32. -+ */ -+ .balign 64 -+ .fill 32, 1, 0xcc -+ -+FUNC(__x86_return_thunk) -+ ret -+ int3 /* Halt straight-line speculation */ -+END(__x86_return_thunk) -+ -+#endif /* CONFIG_RETURN_THUNK */ -diff --git a/xen/arch/x86/pv/emul-priv-op.c b/xen/arch/x86/pv/emul-priv-op.c -index ff5d1c9f8634..295d847ea24c 100644 ---- a/xen/arch/x86/pv/emul-priv-op.c -+++ b/xen/arch/x86/pv/emul-priv-op.c -@@ -131,7 +131,7 @@ static io_emul_stub_t *io_emul_stub_setup(struct priv_op_ctxt *ctxt, u8 opcode, - BUILD_BUG_ON(STUB_BUF_SIZE / 2 < - (sizeof(prologue) + sizeof(epilogue) + 10 /* 2x call */ + - MAX(3 /* default stub */, IOEMUL_QUIRK_STUB_BYTES) + -- 1 /* ret */)); -+ (IS_ENABLED(CONFIG_RETURN_THUNK) ? 5 : 1) /* ret */)); - /* Runtime confirmation that we haven't clobbered an adjacent stub. */ - BUG_ON(STUB_BUF_SIZE / 2 < (p - ctxt->io_emul_stub)); - -diff --git a/xen/arch/x86/pv/gpr_switch.S b/xen/arch/x86/pv/gpr_switch.S -index 5409ad3b1447..362b5d241623 100644 ---- a/xen/arch/x86/pv/gpr_switch.S -+++ b/xen/arch/x86/pv/gpr_switch.S -@@ -26,7 +26,7 @@ FUNC(load_guest_gprs) - movq UREGS_r15(%rdi), %r15 - movq UREGS_rcx(%rdi), %rcx - movq UREGS_rdi(%rdi), %rdi -- ret -+ RET - END(load_guest_gprs) - - /* Save guest GPRs. Parameter on the stack above the return address. */ -@@ -48,5 +48,5 @@ FUNC(save_guest_gprs) - movq %rbx, UREGS_rbx(%rdi) - movq %rdx, UREGS_rdx(%rdi) - movq %rcx, UREGS_rcx(%rdi) -- ret -+ RET - END(save_guest_gprs) -diff --git a/xen/arch/x86/spec_ctrl.c b/xen/arch/x86/spec_ctrl.c -index 35351044f901..019a0a81f4a7 100644 ---- a/xen/arch/x86/spec_ctrl.c -+++ b/xen/arch/x86/spec_ctrl.c -@@ -569,6 +569,9 @@ static void __init print_details(enum ind_thunk thunk) - #ifdef CONFIG_INDIRECT_THUNK - " INDIRECT_THUNK" - #endif -+#ifdef CONFIG_RETURN_THUNK -+ " RETURN_THUNK" -+#endif - #ifdef CONFIG_SHADOW_PAGING - " SHADOW_PAGING" - #endif -diff --git a/xen/arch/x86/x86_64/compat/entry.S b/xen/arch/x86/x86_64/compat/entry.S -index a99646c0cd4e..18f46c78cfbe 100644 ---- a/xen/arch/x86/x86_64/compat/entry.S -+++ b/xen/arch/x86/x86_64/compat/entry.S -@@ -180,7 +180,7 @@ FUNC(cr4_pv32_restore) - or cr4_pv32_mask(%rip), %rax - mov %rax, %cr4 - mov %rax, (%rcx) -- ret -+ RET - 0: - #ifndef NDEBUG - /* Check that _all_ of the bits intended to be set actually are. */ -@@ -198,7 +198,7 @@ FUNC(cr4_pv32_restore) - 1: - #endif - xor %eax, %eax -- ret -+ RET - END(cr4_pv32_restore) - - FUNC(compat_syscall) -@@ -329,7 +329,7 @@ __UNLIKELY_END(compat_bounce_null_selector) - xor %eax, %eax - mov %ax, TRAPBOUNCE_cs(%rdx) - mov %al, TRAPBOUNCE_flags(%rdx) -- ret -+ RET - - .section .fixup,"ax" - .Lfx13: -diff --git a/xen/arch/x86/x86_64/entry.S b/xen/arch/x86/x86_64/entry.S -index 9b0cdb76408b..eb62e7c329bd 100644 ---- a/xen/arch/x86/x86_64/entry.S -+++ b/xen/arch/x86/x86_64/entry.S -@@ -604,7 +604,7 @@ __UNLIKELY_END(create_bounce_frame_bad_bounce_ip) - xor %eax, %eax - mov %rax, TRAPBOUNCE_eip(%rdx) - mov %al, TRAPBOUNCE_flags(%rdx) -- ret -+ RET - - .pushsection .fixup, "ax", @progbits - # Numeric tags below represent the intended overall %rsi adjustment. -diff --git a/xen/arch/x86/xen.lds.S b/xen/arch/x86/xen.lds.S -index 9a1dfe1b340a..506993867502 100644 ---- a/xen/arch/x86/xen.lds.S -+++ b/xen/arch/x86/xen.lds.S -@@ -82,6 +82,7 @@ SECTIONS - . = ALIGN(PAGE_SIZE); - _stextentry = .; - *(.text.entry) -+ *(.text.entry.*) - . = ALIGN(PAGE_SIZE); - _etextentry = .; - -diff --git a/xen/common/Kconfig b/xen/common/Kconfig -index 565ceda741b9..da0fa7527643 100644 ---- a/xen/common/Kconfig -+++ b/xen/common/Kconfig -@@ -130,6 +130,17 @@ config INDIRECT_THUNK - When enabled, indirect branches are implemented using a new construct - called "retpoline" that prevents speculation. - -+config RETURN_THUNK -+ bool "Out-of-line Returns" -+ depends on CC_HAS_RETURN_THUNK -+ default INDIRECT_THUNK -+ help -+ Compile Xen with out-of-line returns. -+ -+ This allows Xen to mitigate a variety of speculative vulnerabilities -+ by choosing a hardware-dependent instruction sequence to implement -+ function returns safely. -+ - config SPECULATIVE_HARDEN_ARRAY - bool "Speculative Array Hardening" - default y --- -2.49.0 - diff --git a/0327-x86-spec-ctrl-Synthesise-ITS_NO-to-guests-on-unaffec.patch b/0327-x86-spec-ctrl-Synthesise-ITS_NO-to-guests-on-unaffec.patch deleted file mode 100644 index e553a3d7..00000000 --- a/0327-x86-spec-ctrl-Synthesise-ITS_NO-to-guests-on-unaffec.patch +++ /dev/null @@ -1,170 +0,0 @@ -From 27135987a5865baf140f92da06f9caa65630402d Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 9 May 2024 17:43:47 +0100 -Subject: [PATCH] x86/spec-ctrl: Synthesise ITS_NO to guests on unaffected - hardware -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -It is easier to express feature word 17 in terms of word 16 + [32, 64) as -that's how the layout is given in documentation. - -This is part of XSA-469 / CVE-2024-28956 - -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit f6042f38e621525feff86bb101dc751d2d87cff8) ---- - xen/arch/x86/include/asm/cpufeature.h | 1 + - xen/arch/x86/spec_ctrl.c | 86 +++++++++++++++++++++ - xen/include/public/arch-x86/cpufeatureset.h | 3 +- - xen/tools/gen-cpuid.py | 2 +- - 4 files changed, 90 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/include/asm/cpufeature.h b/xen/arch/x86/include/asm/cpufeature.h -index 9bc553681f4a..1729ba0c3097 100644 ---- a/xen/arch/x86/include/asm/cpufeature.h -+++ b/xen/arch/x86/include/asm/cpufeature.h -@@ -216,6 +216,7 @@ static inline bool boot_cpu_has(unsigned int feat) - #define cpu_has_gds_no boot_cpu_has(X86_FEATURE_GDS_NO) - #define cpu_has_rfds_no boot_cpu_has(X86_FEATURE_RFDS_NO) - #define cpu_has_rfds_clear boot_cpu_has(X86_FEATURE_RFDS_CLEAR) -+#define cpu_has_its_no boot_cpu_has(X86_FEATURE_ITS_NO) - - /* Synthesized. */ - #define cpu_has_arch_perfmon boot_cpu_has(X86_FEATURE_ARCH_PERFMON) -diff --git a/xen/arch/x86/spec_ctrl.c b/xen/arch/x86/spec_ctrl.c -index 019a0a81f4a7..94cdbd521c4d 100644 ---- a/xen/arch/x86/spec_ctrl.c -+++ b/xen/arch/x86/spec_ctrl.c -@@ -1781,6 +1781,90 @@ static void __init bhi_calculations(void) - } - } - -+/* -+ * https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/indirect-target-selection.html -+ */ -+static void __init its_calculations(void) -+{ -+ /* -+ * Indirect Target Selection is a Branch Prediction bug whereby certain -+ * indirect branches (including RETs) get predicted using a direct branch -+ * target, rather than a suitable indirect target, bypassing hardware -+ * isolation protections. -+ * -+ * ITS affects Core (but not Atom) processors starting from the -+ * introduction of eIBRS, up to but not including Golden Cove cores -+ * (checked here with BHI_CTRL). -+ * -+ * The ITS_NO feature is not expected to be enumerated by hardware, and is -+ * only for VMMs to synthesise for guests. -+ * -+ * ITS comes in 3 flavours: -+ * -+ * 1) Across-IBPB. Indirect branches after the IBPB can be controlled -+ * by direct targets which existed prior to the IBPB. This is -+ * addressed in the IPU 2025.1 microcode drop, and has no other -+ * software interaction. -+ * -+ * 2) Guest/Host. Indirect branches in the VMM can be controlled by -+ * direct targets from the guest. This applies equally to PV guests -+ * (Ring3) and HVM guests (VMX), and applies to all Skylake-uarch -+ * cores with eIBRS. -+ * -+ * 3) Intra-mode. Indirect branches in the VMM can be controlled by -+ * other execution in the same mode. -+ */ -+ -+ /* -+ * If we can see ITS_NO, or we're virtualised, do nothing. We are or may -+ * migrate somewhere unsafe. -+ */ -+ if ( cpu_has_its_no || cpu_has_hypervisor ) -+ return; -+ -+ /* ITS is only known to affect Intel processors at this time. */ -+ if ( boot_cpu_data.x86_vendor != X86_VENDOR_INTEL ) -+ return; -+ -+ /* -+ * ITS does not exist on: -+ * - non-Family 6 CPUs -+ * - those without eIBRS -+ * - those with BHI_CTRL -+ * but we still need to synthesise ITS_NO. -+ */ -+ if ( boot_cpu_data.x86 != 6 || !cpu_has_eibrs || -+ boot_cpu_has(X86_FEATURE_BHI_CTRL) ) -+ goto synthesise; -+ -+ switch ( boot_cpu_data.x86_model ) -+ { -+ /* These Skylake-uarch cores suffer cases #2 and #3. */ -+ case INTEL_FAM6_SKYLAKE_X: -+ case INTEL_FAM6_KABYLAKE_L: -+ case INTEL_FAM6_KABYLAKE: -+ case INTEL_FAM6_COMETLAKE: -+ case INTEL_FAM6_COMETLAKE_L: -+ return; -+ -+ /* These Sunny/Willow/Cypress Cove cores suffer case #3. */ -+ case INTEL_FAM6_ICELAKE_X: -+ case INTEL_FAM6_ICELAKE_D: -+ case INTEL_FAM6_ICELAKE_L: -+ case INTEL_FAM6_TIGERLAKE_L: -+ case INTEL_FAM6_TIGERLAKE: -+ case INTEL_FAM6_ROCKETLAKE: -+ return; -+ -+ default: -+ break; -+ } -+ -+ /* Platforms remaining are not believed to be vulnerable to ITS. */ -+ synthesise: -+ setup_force_cpu_cap(X86_FEATURE_ITS_NO); -+} -+ - void spec_ctrl_init_domain(struct domain *d) - { - bool pv = is_pv_domain(d); -@@ -2331,6 +2415,8 @@ void __init init_speculation_mitigations(void) - - bhi_calculations(); - -+ its_calculations(); -+ - print_details(thunk); - - /* -diff --git a/xen/include/public/arch-x86/cpufeatureset.h b/xen/include/public/arch-x86/cpufeatureset.h -index 9c98e4992861..4d9e468af653 100644 ---- a/xen/include/public/arch-x86/cpufeatureset.h -+++ b/xen/include/public/arch-x86/cpufeatureset.h -@@ -365,7 +365,8 @@ XEN_CPUFEATURE(GDS_NO, 16*32+26) /*A No Gather Data Sampling */ - XEN_CPUFEATURE(RFDS_NO, 16*32+27) /*A No Register File Data Sampling */ - XEN_CPUFEATURE(RFDS_CLEAR, 16*32+28) /*!A| Register File(s) cleared by VERW */ - --/* Intel-defined CPU features, MSR_ARCH_CAPS 0x10a.edx, word 17 */ -+/* Intel-defined CPU features, MSR_ARCH_CAPS 0x10a.edx, word 17 (express in terms of word 16) */ -+XEN_CPUFEATURE(ITS_NO, 16*32+62) /*!A No Indirect Target Selection */ - - #endif /* XEN_CPUFEATURE */ - -diff --git a/xen/tools/gen-cpuid.py b/xen/tools/gen-cpuid.py -index 601eec608983..dc33ca3181b1 100755 ---- a/xen/tools/gen-cpuid.py -+++ b/xen/tools/gen-cpuid.py -@@ -51,7 +51,7 @@ def parse_definitions(state): - r"\s+/\*([\w!|]*) .*$") - - word_regex = re.compile( -- r"^/\* .* word (\d*) \*/$") -+ r"^/\* .* word (\d*) .*\*/$") - last_word = -1 - - this = sys.modules[__name__] --- -2.49.0 - diff --git a/0328-xen-link-Include-.debug_str_offsets-in-DWARF2_DEBUG_.patch b/0328-xen-link-Include-.debug_str_offsets-in-DWARF2_DEBUG_.patch deleted file mode 100644 index b4883000..00000000 --- a/0328-xen-link-Include-.debug_str_offsets-in-DWARF2_DEBUG_.patch +++ /dev/null @@ -1,39 +0,0 @@ -From 294bea99c9e21f89c288f96647695455058a0055 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 13 May 2025 13:57:37 +0200 -Subject: [PATCH] xen/link: Include .debug_str_offsets in DWARF2_DEBUG_SECTIONS - -Building Xen with Clang-17 yields the following warning: - - ld: warning: orphan section `.debug_str_offsets' from `prelink.o' being placed in section `.debug_str_offsets' - ld: ./.xen.efi.0xffff82d040000000.0:/4: section below image base - ld: ./.xen.efi.0xffff82d040000000.1:/4: section below image base - ld: warning: orphan section `.debug_str_offsets' from `prelink.o' being placed in section `.debug_str_offsets' - ld: xen.efi:/4: section below image base - -Set the alignment to 4 as it holds 4-byte values, despite the fact that Clang -appears to only use 1. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -master commit: a88b99300aedea103884b4ef8c66a5a94206feb5 -master date: 2025-04-28 19:46:46 +0100 ---- - xen/include/xen/xen.lds.h | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/xen/include/xen/xen.lds.h b/xen/include/xen/xen.lds.h -index a17810bb286f..acc1e332fbca 100644 ---- a/xen/include/xen/xen.lds.h -+++ b/xen/include/xen/xen.lds.h -@@ -50,6 +50,7 @@ - DECL_DEBUG2(.debug_info, .gnu.linkonce.wi.*, 1) \ - DECL_DEBUG(.debug_types, 1) \ - DECL_DEBUG(.debug_str, 1) \ -+ DECL_DEBUG(.debug_str_offsets, 4) \ - DECL_DEBUG2(.debug_line, .debug_line.*, 1) \ - DECL_DEBUG(.debug_line_str, 1) \ - DECL_DEBUG(.debug_names, 4) \ --- -2.49.0 - diff --git a/0329-x86emul-avoid-UB-shifts-in-FLDENV-FRSTOR-handling.patch b/0329-x86emul-avoid-UB-shifts-in-FLDENV-FRSTOR-handling.patch deleted file mode 100644 index 1341580d..00000000 --- a/0329-x86emul-avoid-UB-shifts-in-FLDENV-FRSTOR-handling.patch +++ /dev/null @@ -1,85 +0,0 @@ -From f33ff85f21e301157522c89b1ae74262138b5c40 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 13 May 2025 13:58:17 +0200 -Subject: [PATCH] x86emul: avoid UB shifts in FLDENV/FRSTOR handling - -16-bit quantities, no matter whether expressed as uint16_t or as -bitfield, will be promoted to plain int before doing any arithmetic on -them. Shifting such values by 16 will therefore shift into the sign bit, -which is UB if that bit becomes set. To account for all reads and all -writes accessing opposite members of the same union, introduce yet more -local variables to reduce the shift counts to 12. - -Fixes: be55ed744ed8 ("x86emul: support FLDENV and FRSTOR") -Reported-by: Fabian Specht -Signed-off-by: Jan Beulich -Reviewed-by: Jason Andryuk -master commit: d00fc019b6eba68bd7f2186a6427e5a005ce989f -master date: 2025-04-30 08:46:21 +0200 ---- - xen/arch/x86/x86_emulate/blk.c | 36 +++++++++++++++++++--------------- - 1 file changed, 20 insertions(+), 16 deletions(-) - -diff --git a/xen/arch/x86/x86_emulate/blk.c b/xen/arch/x86/x86_emulate/blk.c -index e790f4f90056..fe0122ddc611 100644 ---- a/xen/arch/x86/x86_emulate/blk.c -+++ b/xen/arch/x86/x86_emulate/blk.c -@@ -81,17 +81,19 @@ int x86_emul_blk( - if ( !s->rex_prefix ) - { - /* Convert 32-bit real/vm86 to 32-bit prot format. */ -- unsigned int fip = fpstate.env.mode.real.fip_lo + -- (fpstate.env.mode.real.fip_hi << 16); -- unsigned int fdp = fpstate.env.mode.real.fdp_lo + -- (fpstate.env.mode.real.fdp_hi << 16); -+ unsigned int fip = fpstate.env.mode.real.fip_lo & 0xf; -+ unsigned int fcs = (fpstate.env.mode.real.fip_lo >> 4) | -+ (fpstate.env.mode.real.fip_hi << 12); -+ unsigned int fdp = fpstate.env.mode.real.fdp_lo & 0xf; -+ unsigned int fds = (fpstate.env.mode.real.fdp_lo >> 4) | -+ (fpstate.env.mode.real.fdp_hi << 12); - unsigned int fop = fpstate.env.mode.real.fop; - -- fpstate.env.mode.prot.fip = fip & 0xf; -- fpstate.env.mode.prot.fcs = fip >> 4; -+ fpstate.env.mode.prot.fip = fip; -+ fpstate.env.mode.prot.fcs = fcs; - fpstate.env.mode.prot.fop = fop; -- fpstate.env.mode.prot.fdp = fdp & 0xf; -- fpstate.env.mode.prot.fds = fdp >> 4; -+ fpstate.env.mode.prot.fdp = fdp; -+ fpstate.env.mode.prot.fds = fds; - } - - if ( bytes == sizeof(fpstate.env) ) -@@ -121,17 +123,19 @@ int x86_emul_blk( - else - { - /* Convert 16-bit real/vm86 to 32-bit prot format. */ -- unsigned int fip = env->mode.real.fip_lo + -- (env->mode.real.fip_hi << 16); -- unsigned int fdp = env->mode.real.fdp_lo + -- (env->mode.real.fdp_hi << 16); -+ unsigned int fip = env->mode.real.fip_lo & 0xf; -+ unsigned int fcs = (env->mode.real.fip_lo >> 4) | -+ (env->mode.real.fip_hi << 12); -+ unsigned int fdp = env->mode.real.fdp_lo & 0xf; -+ unsigned int fds = (env->mode.real.fdp_lo >> 4) | -+ (env->mode.real.fdp_hi << 12); - unsigned int fop = env->mode.real.fop; - -- fpstate.env.mode.prot.fip = fip & 0xf; -- fpstate.env.mode.prot.fcs = fip >> 4; -+ fpstate.env.mode.prot.fip = fip; -+ fpstate.env.mode.prot.fcs = fcs; - fpstate.env.mode.prot.fop = fop; -- fpstate.env.mode.prot.fdp = fdp & 0xf; -- fpstate.env.mode.prot.fds = fdp >> 4; -+ fpstate.env.mode.prot.fdp = fdp; -+ fpstate.env.mode.prot.fds = fds; - } - - if ( bytes == sizeof(*env) ) --- -2.49.0 - diff --git a/0330-cpufreq-don-t-leave-stale-statistics-pointer.patch b/0330-cpufreq-don-t-leave-stale-statistics-pointer.patch deleted file mode 100644 index f7adf2a3..00000000 --- a/0330-cpufreq-don-t-leave-stale-statistics-pointer.patch +++ /dev/null @@ -1,43 +0,0 @@ -From 2b92925c6d8bc6dae1bd09255413ef9de5d79af6 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Tue, 13 May 2025 13:58:33 +0200 -Subject: [PATCH] cpufreq: don't leave stale statistics pointer - -Error paths of cpufreq_statistic_init() correctly free the base -structure pointer, but the per-CPU variable would still hold it, mis- -guiding e.g. cpufreq_statistic_update(). Defer installing of the pointer -there until the structure was fully populated. - -Fixes: 755af07edba1 ("x86/cpufreq: don't use static array for large per-CPU data structures") -Signed-off-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: a1ce987411f61dbf5fe64bba0cd3d36d7cc0311f -master date: 2025-04-30 08:47:49 +0200 ---- - xen/drivers/cpufreq/utility.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/xen/drivers/cpufreq/utility.c b/xen/drivers/cpufreq/utility.c -index e690a484f18f..d9caf31aa2db 100644 ---- a/xen/drivers/cpufreq/utility.c -+++ b/xen/drivers/cpufreq/utility.c -@@ -113,7 +113,6 @@ int cpufreq_statistic_init(unsigned int cpu) - spin_unlock(cpufreq_statistic_lock); - return -ENOMEM; - } -- per_cpu(cpufreq_statistic_data, cpu) = pxpt; - - pxpt->u.trans_pt = xzalloc_array(uint64_t, count * count); - if (!pxpt->u.trans_pt) { -@@ -139,6 +138,8 @@ int cpufreq_statistic_init(unsigned int cpu) - pxpt->prev_state_wall = NOW(); - pxpt->prev_idle_wall = get_cpu_idle_time(cpu); - -+ per_cpu(cpufreq_statistic_data, cpu) = pxpt; -+ - spin_unlock(cpufreq_statistic_lock); - - return 0; --- -2.49.0 - diff --git a/0331-x86-spec-ctrl-Support-Intel-s-new-PB-OPT.patch b/0331-x86-spec-ctrl-Support-Intel-s-new-PB-OPT.patch deleted file mode 100644 index f0a724f7..00000000 --- a/0331-x86-spec-ctrl-Support-Intel-s-new-PB-OPT.patch +++ /dev/null @@ -1,202 +0,0 @@ -From 4876425ce7f6b7224c499ac3f0f895362c81a4b1 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 15 May 2025 09:06:28 +0200 -Subject: [PATCH] x86/spec-ctrl: Support Intel's new PB-OPT - -In IPU 2025.2 (May 2025), Intel have released an alternative mitigation for a -prior security issue (SA-00982) on Sapphire and Emerald Rapids CPUs. - -Intel suggest that certain workloads will benefit from using the alternative -mode. This can be selected by booting with `spec-ctrl=ibpb-alt`. - -https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/cpuid-enumeration-and-architectural-msrs.html -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -master commit: 5873740e41acb8593f92623ddd03caebda2718f6 -master date: 2025-05-13 14:49:12 +0100 ---- - docs/misc/xen-command-line.pandoc | 6 ++++- - xen/arch/x86/acpi/power.c | 1 + - xen/arch/x86/cpu/intel.c | 28 +++++++++++++++++++++ - xen/arch/x86/include/asm/cpufeature.h | 1 + - xen/arch/x86/include/asm/msr-index.h | 3 +++ - xen/arch/x86/include/asm/processor.h | 3 +++ - xen/arch/x86/smpboot.c | 1 + - xen/arch/x86/spec_ctrl.c | 7 ++++++ - xen/include/public/arch-x86/cpufeatureset.h | 1 + - 9 files changed, 50 insertions(+), 1 deletion(-) - -diff --git a/docs/misc/xen-command-line.pandoc b/docs/misc/xen-command-line.pandoc -index 559fb21c5bc9..99cc60a061ef 100644 ---- a/docs/misc/xen-command-line.pandoc -+++ b/docs/misc/xen-command-line.pandoc -@@ -2406,7 +2406,7 @@ By default SSBD will be mitigated at runtime (i.e `ssbd=runtime`). - > {ibrs,ibpb,ssbd,psfd, - > eager-fpu,l1d-flush,branch-harden,srb-lock, - > unpriv-mmio,gds-mit,div-scrub,lock-harden, --> bhi-dis-s,bp-spec-reduce}= ]` -+> bhi-dis-s,bp-spec-reduce,ibpb-alt}= ]` - - Controls for speculative execution sidechannel mitigations. By default, Xen - will pick the most appropriate mitigations based on compiled in support, -@@ -2562,6 +2562,10 @@ bp-spec-reduce when available, as it is preferable to using `ibpb-entry=hvm` - to mitigate SRSO for HVM guests, and because it is a prerequisite to advertise - SRSO_U/S_NO to PV guests. - -+On Sappire and Emerald Rapids CPUs with May 2025 microcode or later, the -+`ibpb-alt=` option can be used to switch to the alternative mitigation for -+Intel SA-00982. Intel suggest that some workloads will benefit from this. -+ - ### sync_console - > `= ` - -diff --git a/xen/arch/x86/acpi/power.c b/xen/arch/x86/acpi/power.c -index 610937f42e95..01cdaf9052c8 100644 ---- a/xen/arch/x86/acpi/power.c -+++ b/xen/arch/x86/acpi/power.c -@@ -299,6 +299,7 @@ static int enter_state(u32 state) - } - - update_mcu_opt_ctrl(); -+ update_pb_opt_ctrl(); - - /* - * This should be before restoring CR4, but that is earlier in asm and -diff --git a/xen/arch/x86/cpu/intel.c b/xen/arch/x86/cpu/intel.c -index 74d10c93d839..f03eedcc2511 100644 ---- a/xen/arch/x86/cpu/intel.c -+++ b/xen/arch/x86/cpu/intel.c -@@ -49,6 +49,34 @@ void __init set_in_mcu_opt_ctrl(uint32_t mask, uint32_t val) - update_mcu_opt_ctrl(); - } - -+static uint32_t __ro_after_init pb_opt_ctrl_mask; -+static uint32_t __ro_after_init pb_opt_ctrl_val; -+ -+void update_pb_opt_ctrl(void) -+{ -+ uint32_t mask = pb_opt_ctrl_mask, lo, hi; -+ -+ if ( !mask ) -+ return; -+ -+ rdmsr(MSR_PB_OPT_CTRL, lo, hi); -+ -+ lo &= ~mask; -+ lo |= pb_opt_ctrl_val; -+ -+ wrmsr(MSR_PB_OPT_CTRL, lo, hi); -+} -+ -+void __init set_in_pb_opt_ctrl(uint32_t mask, uint32_t val) -+{ -+ pb_opt_ctrl_mask |= mask; -+ -+ pb_opt_ctrl_val &= ~mask; -+ pb_opt_ctrl_val |= (val & mask); -+ -+ update_pb_opt_ctrl(); -+} -+ - /* - * Processors which have self-snooping capability can handle conflicting - * memory type across CPUs by snooping its own cache. However, there exists -diff --git a/xen/arch/x86/include/asm/cpufeature.h b/xen/arch/x86/include/asm/cpufeature.h -index 1729ba0c3097..6dbe6dfe0990 100644 ---- a/xen/arch/x86/include/asm/cpufeature.h -+++ b/xen/arch/x86/include/asm/cpufeature.h -@@ -216,6 +216,7 @@ static inline bool boot_cpu_has(unsigned int feat) - #define cpu_has_gds_no boot_cpu_has(X86_FEATURE_GDS_NO) - #define cpu_has_rfds_no boot_cpu_has(X86_FEATURE_RFDS_NO) - #define cpu_has_rfds_clear boot_cpu_has(X86_FEATURE_RFDS_CLEAR) -+#define cpu_has_pb_opt_ctrl boot_cpu_has(X86_FEATURE_PB_OPT_CTRL) - #define cpu_has_its_no boot_cpu_has(X86_FEATURE_ITS_NO) - - /* Synthesized. */ -diff --git a/xen/arch/x86/include/asm/msr-index.h b/xen/arch/x86/include/asm/msr-index.h -index 22d9e76e5521..6f2c3147e343 100644 ---- a/xen/arch/x86/include/asm/msr-index.h -+++ b/xen/arch/x86/include/asm/msr-index.h -@@ -56,6 +56,9 @@ - #define MSR_MISC_PACKAGE_CTRL 0x000000bc - #define PGK_CTRL_ENERGY_FILTER_EN (_AC(1, ULL) << 0) - -+#define MSR_PB_OPT_CTRL 0x000000bf -+#define PB_OPT_IBPB_ALT (_AC(1, ULL) << 0) -+ - #define MSR_CORE_CAPABILITIES 0x000000cf - #define CORE_CAPS_SPLITLOCK_DETECT (_AC(1, ULL) << 5) - -diff --git a/xen/arch/x86/include/asm/processor.h b/xen/arch/x86/include/asm/processor.h -index c26ef9090c3a..c709d337c9b9 100644 ---- a/xen/arch/x86/include/asm/processor.h -+++ b/xen/arch/x86/include/asm/processor.h -@@ -510,6 +510,9 @@ void tsx_init(void); - void update_mcu_opt_ctrl(void); - void set_in_mcu_opt_ctrl(uint32_t mask, uint32_t val); - -+void update_pb_opt_ctrl(void); -+void set_in_pb_opt_ctrl(uint32_t mask, uint32_t val); -+ - enum ap_boot_method { - AP_BOOT_NORMAL, - AP_BOOT_SKINIT, -diff --git a/xen/arch/x86/smpboot.c b/xen/arch/x86/smpboot.c -index 0a89f22a3980..386e6a0849d1 100644 ---- a/xen/arch/x86/smpboot.c -+++ b/xen/arch/x86/smpboot.c -@@ -378,6 +378,7 @@ void asmlinkage start_secondary(void *unused) - info->last_spec_ctrl = default_xen_spec_ctrl; - } - update_mcu_opt_ctrl(); -+ update_pb_opt_ctrl(); - - tsx_init(); /* Needs microcode. May change HLE/RTM feature bits. */ - -diff --git a/xen/arch/x86/spec_ctrl.c b/xen/arch/x86/spec_ctrl.c -index 94cdbd521c4d..fa444caabb09 100644 ---- a/xen/arch/x86/spec_ctrl.c -+++ b/xen/arch/x86/spec_ctrl.c -@@ -85,6 +85,8 @@ static int8_t __initdata opt_gds_mit = -1; - static int8_t __initdata opt_div_scrub = -1; - bool __ro_after_init opt_bp_spec_reduce = true; - -+static bool __initdata opt_ibpb_alt; -+ - static int __init cf_check parse_spec_ctrl(const char *s) - { - const char *ss; -@@ -367,6 +369,8 @@ static int __init cf_check parse_spec_ctrl(const char *s) - opt_div_scrub = val; - else if ( (val = parse_boolean("bp-spec-reduce", s, ss)) >= 0 ) - opt_bp_spec_reduce = val; -+ else if ( (val = parse_boolean("ibpb-alt", s, ss)) >= 0 ) -+ opt_ibpb_alt = val; - else - rc = -EINVAL; - -@@ -2509,6 +2513,9 @@ void __init init_speculation_mitigations(void) - wrmsrl(MSR_SPEC_CTRL, val); - info->last_spec_ctrl = val; - } -+ -+ if ( cpu_has_pb_opt_ctrl ) -+ set_in_pb_opt_ctrl(PB_OPT_IBPB_ALT, opt_ibpb_alt); - } - - static void __init __maybe_unused build_assertions(void) -diff --git a/xen/include/public/arch-x86/cpufeatureset.h b/xen/include/public/arch-x86/cpufeatureset.h -index 4d9e468af653..3a2b646f0268 100644 ---- a/xen/include/public/arch-x86/cpufeatureset.h -+++ b/xen/include/public/arch-x86/cpufeatureset.h -@@ -366,6 +366,7 @@ XEN_CPUFEATURE(RFDS_NO, 16*32+27) /*A No Register File Data Sampling - XEN_CPUFEATURE(RFDS_CLEAR, 16*32+28) /*!A| Register File(s) cleared by VERW */ - - /* Intel-defined CPU features, MSR_ARCH_CAPS 0x10a.edx, word 17 (express in terms of word 16) */ -+XEN_CPUFEATURE(PB_OPT_CTRL, 16*32+32) /* MSR_PB_OPT_CTRL.IBPB_ALT */ - XEN_CPUFEATURE(ITS_NO, 16*32+62) /*!A No Indirect Target Selection */ - - #endif /* XEN_CPUFEATURE */ --- -2.49.0 - diff --git a/0332-x86-pv-fix-MMUEXT_FLUSH_CACHE-to-flush-all-pCPU-cach.patch b/0332-x86-pv-fix-MMUEXT_FLUSH_CACHE-to-flush-all-pCPU-cach.patch deleted file mode 100644 index d4fbac59..00000000 --- a/0332-x86-pv-fix-MMUEXT_FLUSH_CACHE-to-flush-all-pCPU-cach.patch +++ /dev/null @@ -1,64 +0,0 @@ -From e9e2f3277190bd5635d9f4ecee867772868f960a Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Thu, 15 May 2025 09:06:52 +0200 -Subject: [PATCH] x86/pv: fix MMUEXT_FLUSH_CACHE to flush all pCPU caches -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The implementation of MMUEXT_FLUSH_CACHE is bogus, as it doesn't account to -flush the cache of any previous pCPU where the current vCPU might have run, -and hence is likely to not work as expected. - -Fix this by resorting to use the same logic as MMUEXT_FLUSH_CACHE_GLOBAL, -which will be correct in all cases. - -Adjust MMUEXT_FLUSH_CACHE_GLOBAL return code in case cache flush is not -permitted for the domain to use -EACCES instead of -EINVAL, as that's more -accurate and also matches the error code used by MMUEXT_FLUSH_CACHE. - -Fixes: 8e90e37e6db8 ("Fix WBINVD by adding a new hypercall.") -Signed-off-by: Roger Pau Monné -Acked-by: Jan Beulich -master commit: bbaea9878bf6d11f6f336710148dbbd26e927cfd -master date: 2025-05-13 19:43:48 +0200 ---- - xen/arch/x86/mm.c | 15 ++++++--------- - 1 file changed, 6 insertions(+), 9 deletions(-) - -diff --git a/xen/arch/x86/mm.c b/xen/arch/x86/mm.c -index c3e15a029b48..9861efbef9d8 100644 ---- a/xen/arch/x86/mm.c -+++ b/xen/arch/x86/mm.c -@@ -3795,14 +3795,11 @@ long do_mmuext_op( - break; - - case MMUEXT_FLUSH_CACHE: -- if ( unlikely(currd != pg_owner) ) -- rc = -EPERM; -- else if ( unlikely(!cache_flush_permitted(currd)) ) -- rc = -EACCES; -- else -- wbinvd(); -- break; -- -+ /* -+ * Dirty pCPU caches where the current vCPU has been scheduled are -+ * not tracked, and hence we need to resort to a global cache -+ * flush for correctness. -+ */ - case MMUEXT_FLUSH_CACHE_GLOBAL: - if ( unlikely(currd != pg_owner) ) - rc = -EPERM; -@@ -3819,7 +3816,7 @@ long do_mmuext_op( - flush_mask(mask, FLUSH_CACHE); - } - else -- rc = -EINVAL; -+ rc = -EACCES; - break; - - case MMUEXT_SET_LDT: --- -2.49.0 - diff --git a/0333-x86-IRQ-constrain-creator-domain-ID-assertion.patch b/0333-x86-IRQ-constrain-creator-domain-ID-assertion.patch deleted file mode 100644 index a7fbde73..00000000 --- a/0333-x86-IRQ-constrain-creator-domain-ID-assertion.patch +++ /dev/null @@ -1,41 +0,0 @@ -From 43aeacff8695850ee26ee038159b1f88f5e69fdf Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Thu, 15 May 2025 09:07:06 +0200 -Subject: [PATCH] x86/IRQ: constrain creator-domain-ID assertion -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -If init_one_irq_desc() fails, ->arch.creator_domid won't be set to the -expected value, and hence the assertion may trigger. Limit it to just -the success case of that function call. - -Fixes: 92d9101eab ("x86: allow stubdom access to irq created for msi") -Reported-by: Marek Marczykowski-Górecki -Signed-off-by: Jan Beulich -Reviewed-by: Roger Pau Monné -master commit: d7127e06f617ed89eefe17a9ac954032863032d5 -master date: 2025-05-14 11:00:00 +0200 ---- - xen/arch/x86/irq.c | 4 ++-- - 1 file changed, 2 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/irq.c b/xen/arch/x86/irq.c -index ce390b04226f..296a3cd08b17 100644 ---- a/xen/arch/x86/irq.c -+++ b/xen/arch/x86/irq.c -@@ -285,9 +285,9 @@ int create_irq(nodeid_t node, bool grant_access) - mask = NULL; - } - ret = assign_irq_vector(irq, mask); -- } - -- ASSERT(desc->arch.creator_domid == DOMID_INVALID); -+ ASSERT(desc->arch.creator_domid == DOMID_INVALID); -+ } - - if (ret < 0) - { --- -2.49.0 - diff --git a/0334-x86-emul-Fix-emulation-of-RDSEED-with-older-toolchai.patch b/0334-x86-emul-Fix-emulation-of-RDSEED-with-older-toolchai.patch deleted file mode 100644 index 17176615..00000000 --- a/0334-x86-emul-Fix-emulation-of-RDSEED-with-older-toolchai.patch +++ /dev/null @@ -1,57 +0,0 @@ -From bcdb61a2462e9546df194269ae4b0854b9af8885 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 26 Jun 2025 08:46:14 +0200 -Subject: [PATCH] x86/emul: Fix emulation of RDSEED with older toolchains - -This is reported as a MISRA R16.3 (missing break) violation, but turns out to -be substantially more complicated than expected. - -In commit a8fe4ec5320a ("x86emul: support RDRAND/RDSEED"), the switch() -statement had a default case going to cannot_emulate, with both the case 6 and -case 7 labels being fully within #ifdef HAVE_GAS_RD{RAND,SEED}. - -Therefore, when the toolchain didn't understand the RDRAND/RDSEED -instructions, attempts to emulate them suffered #UD. (In principle, this is a -problem as there's no interlock to prevent RDRAND/RDSEED being advertised to -the guest, but as instructions with only register encodings, they can only -legitimately be emulated when VM Introspection is in use.) - -In commit 58f1bba44033 ("x86emul: support RDPID"), case 7 was taken outside of -HAVE_GAS_RDSEED, meaning that emulating an RDSEED instruction no longer hit -the default case when the toolchain was too old. - -Instead, it would fall out of the switch statement and be completed normally, -behaving as a NOP to the guest. - -Retrofit a "return X86EMUL_UNIMPLEMENTED" in the case that the toolchain -doesn't know the RDRAND instruction, matching how RDRAND work. - -Note that this has been fixed differently in Xen 4.21. Commit -05bf9f1f0f52 ("x86/emulate: Remove HAVE_AS_RDRAND and HAVE_AS_RDSEED") has -removed the problematic condition due to the toolchain baseline upgrade. - -Fixes: 58f1bba44033 ("x86emul: support RDPID") -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -master commit: ddec00769cd80a44b412281d8b52482e4e20c2e5 -master date: 2025-05-16 21:34:19 +0100 ---- - xen/arch/x86/x86_emulate/0fc7.c | 2 ++ - 1 file changed, 2 insertions(+) - -diff --git a/xen/arch/x86/x86_emulate/0fc7.c b/xen/arch/x86/x86_emulate/0fc7.c -index 5268d5cafd7b..2b6b444bab94 100644 ---- a/xen/arch/x86/x86_emulate/0fc7.c -+++ b/xen/arch/x86/x86_emulate/0fc7.c -@@ -102,6 +102,8 @@ int x86emul_0fc7(struct x86_emulate_state *s, - if ( carry ) - regs->eflags |= X86_EFLAGS_CF; - break; -+#else -+ return X86EMUL_UNIMPLEMENTED; - #endif - } - } --- -2.49.0 - diff --git a/0335-x86-pv-fix-emulation-of-wb-no-invd-to-flush-all-pCPU.patch b/0335-x86-pv-fix-emulation-of-wb-no-invd-to-flush-all-pCPU.patch deleted file mode 100644 index a0c911a6..00000000 --- a/0335-x86-pv-fix-emulation-of-wb-no-invd-to-flush-all-pCPU.patch +++ /dev/null @@ -1,46 +0,0 @@ -From a71c40d335d4b4d1f8c294b3a6ed66f7c887560a Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Thu, 26 Jun 2025 08:46:34 +0200 -Subject: [PATCH] x86/pv: fix emulation of wb{,no}invd to flush all pCPU caches -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -The current emulation of wb{,no}invd is bogus for PV guests: it will only -flush the current pCPU cache, without taking into account pCPUs where the -vCPU had run previously. Resort to flushing the cache on all host pCPUs to -make it correct. - -Fixes: 799fed0a7cc5 ("Priv-op emulation in Xen, for RDMSR/WRMSR/WBINVD") -Signed-off-by: Roger Pau Monné -Reviewed-by: Jan Beulich -[backport: no FLUSH_CACHE_WRITEBACK] -master commit: b0f8bf86057b8f01fb4e48b506805d3818600f76 -master date: 2025-05-20 16:35:52 +0200 ---- - xen/arch/x86/pv/emul-priv-op.c | 6 ++---- - 1 file changed, 2 insertions(+), 4 deletions(-) - -diff --git a/xen/arch/x86/pv/emul-priv-op.c b/xen/arch/x86/pv/emul-priv-op.c -index 295d847ea24c..a21d4995191c 100644 ---- a/xen/arch/x86/pv/emul-priv-op.c -+++ b/xen/arch/x86/pv/emul-priv-op.c -@@ -1198,13 +1198,11 @@ static int cf_check cache_op( - if ( !cache_flush_permitted(current->domain) ) - /* - * Non-physdev domain attempted WBINVD; ignore for now since -- * newer linux uses this in some start-of-day timing loops. -+ * Linux uses this in some start-of-day code. - */ - ; -- else if ( op == x86emul_wbnoinvd /* && cpu_has_wbnoinvd */ ) -- wbnoinvd(); - else -- wbinvd(); -+ flush_all(FLUSH_CACHE); - - return X86EMUL_OKAY; - } --- -2.49.0 - diff --git a/0336-x86-vpci-fix-handling-of-BAR-overlaps-with-non-hole-.patch b/0336-x86-vpci-fix-handling-of-BAR-overlaps-with-non-hole-.patch deleted file mode 100644 index f62fe6ab..00000000 --- a/0336-x86-vpci-fix-handling-of-BAR-overlaps-with-non-hole-.patch +++ /dev/null @@ -1,179 +0,0 @@ -From ded45876e4ab3d873139b36782ed7321b64cd08b Mon Sep 17 00:00:00 2001 -From: =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= -Date: Thu, 26 Jun 2025 08:46:48 +0200 -Subject: [PATCH] x86/vpci: fix handling of BAR overlaps with non-hole regions -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -For once the message printed when a BAR overlaps with a non-hole regions is -not accurate on x86. While the BAR won't be mapped by the vPCI logic, it -is quite likely overlapping with a reserved region in the memory map, and -already mapped as by default all reserved regions are identity mapped in -the p2m. Avoid printing the warning message in modify_bars(), and instead -print a more lax message in the x86 implementation of pci_check_bar() to -note the current BAR position overlaps with non-hole region(s). - -Secondly, when an overlap is detected the BAR 'enabled' field is not set, -hence other vPCI code that depends on it like vPCI MSI-X handling won't -function properly, as it sees the BAR as disabled, even when memory -decoding is enabled for the device and the BAR is likely mapped in the -p2m. Change the handling of BARs that overlap non-hole regions to instead -remove any overlapped regions from the rangeset, so the resulting ranges to -map just contain the hole regions. This requires introducing a new -pci_sanitize_bar_memory() that's implemented per-arch and sanitizes the -address range to add to the p2m. - -For x86 pci_sanitize_bar_memory() removes any regions present in the host -memory map, for ARM this is currently left as a dummy handler to not change -existing behavior. - -Ultimately the above changes should fix the vPCI MSI-X handlers not working -correctly when the BAR that contains the MSI-X table overlaps with a -non-hole region, as then the 'enabled' BAR bit won't be set and the MSI-X -traps won't handle accesses as expected. - -Reported-by: Stefano Stabellini -Fixes: 53d9133638c3 ('pci: do not disable memory decoding for devices') -Signed-off-by: Roger Pau Monné -Tested-by: Victor M Lira -Reviewed-by: Jan Beulich -Acked-by: Julien Grall - -x86/vpci: fix off-by-one in pci_sanitize_bar_memory() - -rangeset_remove_range() uses inclusive ranges, and hence the end of the -range should be calculated using PFN_DOWN(), not PFN_UP(). - -Fixes: 4acab25a9300 ('x86/vpci: fix handling of BAR overlaps with non-hole regions') -Signed-off-by: Roger Pau Monné -Acked-by: Andrew Cooper -master commit: 4acab25a9300ba69a3c1441491470bd65af52d0f -master date: 2025-05-21 18:29:55 +0200 -master commit: 7ab4b392b78b5ac1c7a1fb1d085637526e67521a -master date: 2025-05-22 16:17:12 +0200 ---- - xen/arch/arm/include/asm/pci.h | 3 ++ - xen/arch/x86/include/asm/pci.h | 13 +++------ - xen/arch/x86/pci.c | 50 ++++++++++++++++++++++++++++++++++ - xen/drivers/vpci/header.c | 9 ++++++ - 4 files changed, 66 insertions(+), 9 deletions(-) - -diff --git a/xen/arch/arm/include/asm/pci.h b/xen/arch/arm/include/asm/pci.h -index 7f77226c9bbf..1605ec660d0b 100644 ---- a/xen/arch/arm/include/asm/pci.h -+++ b/xen/arch/arm/include/asm/pci.h -@@ -128,6 +128,9 @@ int pci_host_bridge_mappings(struct domain *d); - - bool pci_check_bar(const struct pci_dev *pdev, mfn_t start, mfn_t end); - -+static inline int pci_sanitize_bar_memory(struct rangeset *r) -+{ return 0; } -+ - #else /*!CONFIG_HAS_PCI*/ - - struct pci_dev; -diff --git a/xen/arch/x86/include/asm/pci.h b/xen/arch/x86/include/asm/pci.h -index fd5480d67d43..bed99437cc3b 100644 ---- a/xen/arch/x86/include/asm/pci.h -+++ b/xen/arch/x86/include/asm/pci.h -@@ -57,14 +57,9 @@ static always_inline bool is_pci_passthrough_enabled(void) - - void arch_pci_init_pdev(struct pci_dev *pdev); - --static inline bool pci_check_bar(const struct pci_dev *pdev, -- mfn_t start, mfn_t end) --{ -- /* -- * Check if BAR is not overlapping with any memory region defined -- * in the memory map. -- */ -- return is_memory_hole(start, end); --} -+bool pci_check_bar(const struct pci_dev *pdev, mfn_t start, mfn_t end); -+ -+struct rangeset; -+int pci_sanitize_bar_memory(struct rangeset *r); - - #endif /* __X86_PCI_H__ */ -diff --git a/xen/arch/x86/pci.c b/xen/arch/x86/pci.c -index 97b792e578f1..26bb7f6a3c3a 100644 ---- a/xen/arch/x86/pci.c -+++ b/xen/arch/x86/pci.c -@@ -98,3 +98,53 @@ int pci_conf_write_intercept(unsigned int seg, unsigned int bdf, - - return rc; - } -+ -+bool pci_check_bar(const struct pci_dev *pdev, mfn_t start, mfn_t end) -+{ -+ /* -+ * Check if BAR is not overlapping with any memory region defined -+ * in the memory map. -+ */ -+ if ( !is_memory_hole(start, end) ) -+ gdprintk(XENLOG_WARNING, -+ "%pp: BAR at [%"PRI_mfn", %"PRI_mfn"] not in memory map hole\n", -+ &pdev->sbdf, mfn_x(start), mfn_x(end)); -+ -+ /* -+ * Unconditionally return true, pci_sanitize_bar_memory() will remove any -+ * non-hole regions. -+ */ -+ return true; -+} -+ -+/* Remove overlaps with any ranges defined in the host memory map. */ -+int pci_sanitize_bar_memory(struct rangeset *r) -+{ -+ unsigned int i; -+ -+ for ( i = 0; i < e820.nr_map; i++ ) -+ { -+ const struct e820entry *entry = &e820.map[i]; -+ int rc; -+ -+ if ( !entry->size ) -+ continue; -+ -+ rc = rangeset_remove_range(r, PFN_DOWN(entry->addr), -+ PFN_DOWN(entry->addr + entry->size - 1)); -+ if ( rc ) -+ return rc; -+ } -+ -+ return 0; -+} -+ -+/* -+ * Local variables: -+ * mode: C -+ * c-file-style: "BSD" -+ * c-basic-offset: 4 -+ * tab-width: 4 -+ * indent-tabs-mode: nil -+ * End: -+ */ -diff --git a/xen/drivers/vpci/header.c b/xen/drivers/vpci/header.c -index ef6c965c081c..1f48f2aac64e 100644 ---- a/xen/drivers/vpci/header.c -+++ b/xen/drivers/vpci/header.c -@@ -394,6 +394,15 @@ static int modify_bars(const struct pci_dev *pdev, uint16_t cmd, bool rom_only) - return rc; - } - } -+ -+ rc = pci_sanitize_bar_memory(bar->mem); -+ if ( rc ) -+ { -+ gprintk(XENLOG_WARNING, -+ "%pp: failed to sanitize BAR#%u memory: %d\n", -+ &pdev->sbdf, i, rc); -+ return rc; -+ } - } - - /* Remove any MSIX regions if present. */ --- -2.49.0 - diff --git a/0337-x86-vmx-Fix-VMEntry-failure-on-ADL-SPR-with-shadow-g.patch b/0337-x86-vmx-Fix-VMEntry-failure-on-ADL-SPR-with-shadow-g.patch deleted file mode 100644 index f6281dc4..00000000 --- a/0337-x86-vmx-Fix-VMEntry-failure-on-ADL-SPR-with-shadow-g.patch +++ /dev/null @@ -1,43 +0,0 @@ -From a24e1cda35deb36be8efae49058d50d2840384b8 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 26 Jun 2025 08:47:29 +0200 -Subject: [PATCH] x86/vmx: Fix VMEntry failure on ADL/SPR with shadow guests -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -Paging Writeable depends on EPT so must be disabled in non-EPT guests like the -other EPT dependent features. Otherwise, VMEntry fails with bad control -state. - -Drop a piece of trailing whitepsace in context. - -Fixes: ff10aa9d8f90 ("x86: Add Support for Paging-Write Feature") -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -master commit: d779e3f98c2a765aae57f6ab4b0257413c12ac97 -master date: 2025-05-27 12:21:38 +0100 ---- - xen/arch/x86/hvm/vmx/vmcs.c | 4 +++- - 1 file changed, 3 insertions(+), 1 deletion(-) - -diff --git a/xen/arch/x86/hvm/vmx/vmcs.c b/xen/arch/x86/hvm/vmx/vmcs.c -index 9b6dc51f36ab..aa7911089acc 100644 ---- a/xen/arch/x86/hvm/vmx/vmcs.c -+++ b/xen/arch/x86/hvm/vmx/vmcs.c -@@ -1148,9 +1148,11 @@ static int construct_vmcs(struct vcpu *v) - else - { - v->arch.hvm.vmx.secondary_exec_control &= -- ~(SECONDARY_EXEC_ENABLE_EPT | -+ ~(SECONDARY_EXEC_ENABLE_EPT | - SECONDARY_EXEC_UNRESTRICTED_GUEST | - SECONDARY_EXEC_ENABLE_INVPCID); -+ v->arch.hvm.vmx.tertiary_exec_control &= -+ ~(TERTIARY_EXEC_EPT_PAGING_WRITE); - vmexit_ctl &= ~(VM_EXIT_SAVE_GUEST_PAT | - VM_EXIT_LOAD_HOST_PAT); - vmentry_ctl &= ~VM_ENTRY_LOAD_GUEST_PAT; --- -2.49.0 - diff --git a/0338-x86-pv-Fix-breakpoint-reporting.patch b/0338-x86-pv-Fix-breakpoint-reporting.patch deleted file mode 100644 index be395a46..00000000 --- a/0338-x86-pv-Fix-breakpoint-reporting.patch +++ /dev/null @@ -1,45 +0,0 @@ -From ee8ae3a2802a1a5d69ccc1ffe223c98dc09a9361 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 26 Jun 2025 08:47:41 +0200 -Subject: [PATCH] x86/pv: Fix breakpoint reporting -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -x86_merge_dr6() is not a no-op when 0 is passed in; it will discard the -previously latched breakpoint bits. - -The combination of do_debug()'s manual call to x86_merge_dr6() for external -debuggers, and pv_inject_DB() calling pv_inject_event(), results in two -x86_merge_dr6() calls. - -Feed the same pending_dbg in the second time. This makes pv_inject_event()'s -update of dr6 effectively a no-op, retaining the correct breakpoint bits. - -Fixes: db39fa4b27ea ("x86/pv: Fix merging of new status bits into %dr6") -Reported-by: Manuel Bouyer -Signed-off-by: Andrew Cooper -Tested-by: Manuel Bouyer -Acked-by: Roger Pau Monné -master commit: d965e2ee07c56c341d8896852550914d87ea5374 -master date: 2025-05-27 12:21:38 +0100 ---- - xen/arch/x86/traps.c | 2 +- - 1 file changed, 1 insertion(+), 1 deletion(-) - -diff --git a/xen/arch/x86/traps.c b/xen/arch/x86/traps.c -index ae573ee4c044..af90d8b27d9f 100644 ---- a/xen/arch/x86/traps.c -+++ b/xen/arch/x86/traps.c -@@ -2040,7 +2040,7 @@ void asmlinkage do_debug(struct cpu_user_regs *regs) - return; - } - -- pv_inject_DB(0 /* N/A, already merged */); -+ pv_inject_DB(dr6 ^ X86_DR6_DEFAULT); - } - - void asmlinkage do_entry_CP(struct cpu_user_regs *regs) --- -2.49.0 - diff --git a/0339-tools-libxl-Only-access-legacy-altp2m-on-HVM.patch b/0339-tools-libxl-Only-access-legacy-altp2m-on-HVM.patch deleted file mode 100644 index 3e1d7b34..00000000 --- a/0339-tools-libxl-Only-access-legacy-altp2m-on-HVM.patch +++ /dev/null @@ -1,59 +0,0 @@ -From e02b039b64738f04ec9283b5840f5b004026c782 Mon Sep 17 00:00:00 2001 -From: Jason Andryuk -Date: Thu, 26 Jun 2025 08:47:53 +0200 -Subject: [PATCH] tools/libxl: Only access legacy altp2m on HVM - -Only access the HVM union b_info->u.hvm on HVM guests. The union -access is not guarded, so this reads and sets the default even on -non-HVM guests. Usually this doesn't matter as PV and PVH unions are -smaller and zero-initialized, but the zero default will be re-written as -a -1 boolean. Generally, it could incorrectly set b_info->altp2m -through aliased data. - -Fixes: 0291089f6ea8 ("xen: enable altp2m at create domain domctl") -Signed-off-by: Jason Andryuk -Acked-by: Anthony PERARD -master commit: 01dfd25509cc44011e83677e989dc7f55e2657d5 -master date: 2025-06-02 10:31:21 +0200 ---- - tools/libs/light/libxl_x86.c | 24 +++++++++++++----------- - 1 file changed, 13 insertions(+), 11 deletions(-) - -diff --git a/tools/libs/light/libxl_x86.c b/tools/libs/light/libxl_x86.c -index 60643d6f5376..872b39739d8f 100644 ---- a/tools/libs/light/libxl_x86.c -+++ b/tools/libs/light/libxl_x86.c -@@ -804,17 +804,19 @@ int libxl__arch_domain_build_info_setdefault(libxl__gc *gc, - libxl_defbool_setdefault(&b_info->acpi, true); - libxl_defbool_setdefault(&b_info->arch_x86.msr_relaxed, false); - -- /* -- * The config parameter "altp2m" replaces the parameter "altp2mhvm". -- * For legacy reasons, both parameters are accepted on x86 HVM guests. -- * -- * If the legacy field info->u.hvm.altp2m is set, activate altp2m. -- * Otherwise set altp2m based on the field info->altp2m. -- */ -- libxl_defbool_setdefault(&b_info->u.hvm.altp2m, false); -- if (b_info->altp2m == LIBXL_ALTP2M_MODE_DISABLED && -- libxl_defbool_val(b_info->u.hvm.altp2m)) -- b_info->altp2m = libxl_defbool_val(b_info->u.hvm.altp2m); -+ if (b_info->type == LIBXL_DOMAIN_TYPE_HVM) { -+ /* -+ * The config parameter "altp2m" replaces the parameter "altp2mhvm". -+ * For legacy reasons, both parameters are accepted on x86 HVM guests. -+ * -+ * If the legacy field info->u.hvm.altp2m is set, activate altp2m. -+ * Otherwise set altp2m based on the field info->altp2m. -+ */ -+ libxl_defbool_setdefault(&b_info->u.hvm.altp2m, false); -+ if (b_info->altp2m == LIBXL_ALTP2M_MODE_DISABLED && -+ libxl_defbool_val(b_info->u.hvm.altp2m)) -+ b_info->altp2m = libxl_defbool_val(b_info->u.hvm.altp2m); -+ } - - return 0; - } --- -2.49.0 - diff --git a/0340-x86-pmstat-Check-size-of-PMSTAT_get_pxstat-buffers.patch b/0340-x86-pmstat-Check-size-of-PMSTAT_get_pxstat-buffers.patch deleted file mode 100644 index d3dbbe70..00000000 --- a/0340-x86-pmstat-Check-size-of-PMSTAT_get_pxstat-buffers.patch +++ /dev/null @@ -1,96 +0,0 @@ -From 81ffb56a23c66f323e062c417dedfd66bb0aa4fd Mon Sep 17 00:00:00 2001 -From: Ross Lagerwall -Date: Thu, 26 Jun 2025 08:48:35 +0200 -Subject: [PATCH] x86/pmstat: Check size of PMSTAT_get_pxstat buffers - -Check that the total number of states passed in and hence the size of -buffers is sufficient to avoid writing more than the caller has -allocated. - -The interface is not explicit about whether getpx.total is expected to -be set by the caller in this case but since it is always set in -libxenctrl it seems reasonable to check it and make it explicit. - -Fixes: c06a7db0c547 ("X86 and IA64: Update cpufreq statistic logic for supporting both x86 and ia64") -Signed-off-by: Ross Lagerwall -Reviewed-by: Jan Beulich - -# Commit fb16c7411d6e1278155c144fd3310a12f2efbf5e -# Date 2025-06-18 09:25:09 +0200 -# Author Jan Beulich -# Committer Jan Beulich -x86/pmstat: correct PMSTAT_get_pxstat buffer size checking - -min(pmpt->perf.state_count, op->u.getpx.total) == op->u.getpx.total can -be expressed differently as pmpt->perf.state_count >= op->u.getpx.total. -Copying when the two are equal is fine; (partial) copying when the state -count is larger than the number of array elements that a buffer was -allocated to hold is what - as per the comment - we mean to avoid. Drop -the use of min() again, but retain its effect for the subsequent copying -from pxpt->u.pt. - -Fixes: aa70996a6896 ("x86/pmstat: Check size of PMSTAT_get_pxstat buffers") -Reported-by: Andrew Cooper -Signed-off-by: Jan Beulich -Reviewed-by: Ross Lagerwall -master commit: aa70996a6896dfc9de60f60540098b7d3ac3fb4f -master date: 2025-06-11 11:05:42 +0200 -master commit: fb16c7411d6e1278155c144fd3310a12f2efbf5e -master date: 2025-06-18 09:25:09 +0200 ---- - xen/drivers/acpi/pmstat.c | 8 +++++++- - xen/include/public/sysctl.h | 15 +++++++++++++-- - 2 files changed, 20 insertions(+), 3 deletions(-) - -diff --git a/xen/drivers/acpi/pmstat.c b/xen/drivers/acpi/pmstat.c -index f607bc110f0a..1b18ee378d10 100644 ---- a/xen/drivers/acpi/pmstat.c -+++ b/xen/drivers/acpi/pmstat.c -@@ -103,8 +103,14 @@ int do_get_pm_info(struct xen_sysctl_get_pmstat *op) - - cpufreq_residency_update(op->cpuid, pxpt->u.cur); - -+ /* -+ * Avoid partial copying of 2-D array, whereas partial copying of a -+ * simple vector (further down) is deemed okay. -+ */ - ct = pmpt->perf.state_count; -- if ( copy_to_guest(op->u.getpx.trans_pt, pxpt->u.trans_pt, ct*ct) ) -+ if ( ct > op->u.getpx.total ) -+ ct = op->u.getpx.total; -+ else if ( copy_to_guest(op->u.getpx.trans_pt, pxpt->u.trans_pt, ct * ct) ) - { - spin_unlock(cpufreq_statistic_lock); - ret = -EFAULT; -diff --git a/xen/include/public/sysctl.h b/xen/include/public/sysctl.h -index 3a6e7d48f02e..a0ddd1dbf5b7 100644 ---- a/xen/include/public/sysctl.h -+++ b/xen/include/public/sysctl.h -@@ -205,11 +205,22 @@ typedef struct pm_px_val pm_px_val_t; - DEFINE_XEN_GUEST_HANDLE(pm_px_val_t); - - struct pm_px_stat { -- uint8_t total; /* total Px states */ -+ /* -+ * IN: Number of elements in pt, number of rows/columns in trans_pt -+ * (PMSTAT_get_pxstat) -+ * OUT: total Px states (PMSTAT_get_max_px, PMSTAT_get_pxstat) -+ */ -+ uint8_t total; - uint8_t usable; /* usable Px states */ - uint8_t last; /* last Px state */ - uint8_t cur; /* current Px state */ -- XEN_GUEST_HANDLE_64(uint64) trans_pt; /* Px transition table */ -+ /* -+ * OUT: Px transition table. This should have total * total elements. -+ * As it is a 2-D array, this will not be copied if input total is -+ * less than output total. (PMSTAT_get_pxstat) -+ */ -+ XEN_GUEST_HANDLE_64(uint64) trans_pt; -+ /* OUT: This should have total elements (PMSTAT_get_pxstat) */ - XEN_GUEST_HANDLE_64(pm_px_val_t) pt; - }; - --- -2.49.0 - diff --git a/0341-cpufreq-Avoid-potential-buffer-overrun-and-leak.patch b/0341-cpufreq-Avoid-potential-buffer-overrun-and-leak.patch deleted file mode 100644 index b87ebacd..00000000 --- a/0341-cpufreq-Avoid-potential-buffer-overrun-and-leak.patch +++ /dev/null @@ -1,52 +0,0 @@ -From 2b82a9d8819accb0c50953176e8a4153acaf0980 Mon Sep 17 00:00:00 2001 -From: Ross Lagerwall -Date: Thu, 26 Jun 2025 08:49:06 +0200 -Subject: [PATCH] cpufreq: Avoid potential buffer overrun and leak - -If set_px_pminfo is called a second time with a larger state_count than -the first call, calls to PMSTAT_get_pxstat will read beyond the end of -the pt and trans_pt buffers allocated in cpufreq_statistic_init() since -they would have been allocated with the original state_count. - -Secondly, the states array leaks on each subsequent call of -set_px_pminfo. - -Fix both these issues by ignoring subsequent calls to set_px_pminfo if -it completed successfully previously. Return success rather than an -error to avoid errors in the dom0 kernel log when reloading the -xen_acpi_processor module. - -At the same time, fix a leak of the states array on error. - -Signed-off-by: Ross Lagerwall -Reviewed-by: Jan Beulich -master commit: 2f36bef3d8478f304f262fffeca543de480872a4 -master date: 2025-06-11 11:06:24 +0200 ---- - xen/drivers/cpufreq/cpufreq.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/xen/drivers/cpufreq/cpufreq.c b/xen/drivers/cpufreq/cpufreq.c -index 8659ad3aee51..3bdf86a52aeb 100644 ---- a/xen/drivers/cpufreq/cpufreq.c -+++ b/xen/drivers/cpufreq/cpufreq.c -@@ -510,7 +510,7 @@ int set_px_pminfo(uint32_t acpi_id, struct xen_processor_performance *perf) - } - } - -- if ( perf->flags & XEN_PX_PSS ) -+ if ( perf->flags & XEN_PX_PSS && !pxpt->states ) - { - /* capability check */ - if ( perf->state_count <= 1 ) -@@ -527,6 +527,7 @@ int set_px_pminfo(uint32_t acpi_id, struct xen_processor_performance *perf) - } - if ( copy_from_guest(pxpt->states, perf->states, perf->state_count) ) - { -+ XFREE(pxpt->states); - ret = -EFAULT; - goto out; - } --- -2.49.0 - diff --git a/0342-xenalyze-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch b/0342-xenalyze-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch deleted file mode 100644 index a719d168..00000000 --- a/0342-xenalyze-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch +++ /dev/null @@ -1,35 +0,0 @@ -From 4d6ddd30eed61a8c27f9f7d91d3a3b341640e498 Mon Sep 17 00:00:00 2001 -From: Gang Ji -Date: Thu, 26 Jun 2025 08:49:19 +0200 -Subject: [PATCH] xenalyze: Add 2 missed VCPUOPs in vcpu_op_str - -The 2 missed ones are: register_runstate_phys_area and -register_vcpu_time_phys_area. - -Fixes: d5df44275e7a ("domain: introduce GADDR based runstate area registration alternative") -Fixes: 60e544a8c58f ("x86: introduce GADDR based secondary time area registration alternative") -Signed-off-by: Gang Ji -Reviewed-by: Andrew Cooper -master commit: ed939591e4c6ccf794395fc78cd358aa24a94ed8 -master date: 2025-06-11 11:08:11 +0200 ---- - tools/xentrace/xenalyze.c | 3 ++- - 1 file changed, 2 insertions(+), 1 deletion(-) - -diff --git a/tools/xentrace/xenalyze.c b/tools/xentrace/xenalyze.c -index adc96dd7e419..1c13682aaa45 100644 ---- a/tools/xentrace/xenalyze.c -+++ b/tools/xentrace/xenalyze.c -@@ -6513,7 +6513,8 @@ static const char *vcpu_op_str[] = { - "register_runstate_memory_area", "set_periodic_timer", - "stop_periodic_timer", "set_singleshot_timer", "stop_singleshot_timer", - "register_vcpu_info", "send_nmi", "get_physid", -- "register_vcpu_time_memory_area", -+ "register_vcpu_time_memory_area", "register_runstate_phys_area", -+ "register_vcpu_time_phys_area", - }; - - static const char *sched_op_str[] = { --- -2.49.0 - diff --git a/0343-x86-emul-Fix-extable-registration-in-invoke_stub.patch b/0343-x86-emul-Fix-extable-registration-in-invoke_stub.patch deleted file mode 100644 index 333a27e0..00000000 --- a/0343-x86-emul-Fix-extable-registration-in-invoke_stub.patch +++ /dev/null @@ -1,54 +0,0 @@ -From f830240555e9522958e1ebedca1413d5d8f33345 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 15 May 2025 19:01:33 +0100 -Subject: [PATCH] x86/emul: Fix extable registration in invoke_stub() - -For exception recovery in the stubs, the registered address for fixup is the -return address of the CALL entering the stub. - -In invoke_stub(), the '.Lret%=:' label is the wrong side of the 'post' -parameter. The 'post' parameter is non-empty in cases where the arithmetic -flags of the operation need recovering. - -Split the line to separate 'pre' and 'post', making it more obvious that the -return address label was in the wrong position. - -However, in the case that an exception did occur, we want to skip 'post' as -it's logically part of the operation which had already failed. Therefore, add -a new skip label and use that for the exception recovery path. - -This is XSA-470 / CVE-2025-27465 - -Fixes: 79903e50dba9 ("x86emul: catch exceptions occurring in stubs") -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit b9f83119750ffa0e2e925d74e6e5f38925094883) ---- - xen/arch/x86/x86_emulate/private.h | 7 +++++-- - 1 file changed, 5 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/x86_emulate/private.h b/xen/arch/x86/x86_emulate/private.h -index 0fa26ba00aa5..2582f017bb0b 100644 ---- a/xen/arch/x86/x86_emulate/private.h -+++ b/xen/arch/x86/x86_emulate/private.h -@@ -704,12 +704,15 @@ struct stub_exn { - stub_exn.info = (union stub_exception_token) { .raw = ~0 }; \ - stub_exn.line = __LINE__; /* Utility outweighs livepatching cost */ \ - block_speculation(); /* SCSB */ \ -- asm volatile ( pre "\n\tINDIRECT_CALL %[stub]\n\t" post "\n" \ -+ asm volatile ( pre "\n\t" \ -+ "INDIRECT_CALL %[stub]\n" \ - ".Lret%=:\n\t" \ -+ post "\n\t" \ -+ ".Lskip%=:\n\t" \ - ".pushsection .fixup,\"ax\"\n" \ - ".Lfix%=:\n\t" \ - "pop %[exn]\n\t" \ -- "jmp .Lret%=\n\t" \ -+ "jmp .Lskip%=\n\t" \ - ".popsection\n\t" \ - _ASM_EXTABLE(.Lret%=, .Lfix%=) \ - : [exn] "+g" (stub_exn.info) ASM_CALL_CONSTRAINT, \ --- -2.49.0 - diff --git a/0344-libxc-PM-Ensure-pxstat-buffers-are-correctly-sized.patch b/0344-libxc-PM-Ensure-pxstat-buffers-are-correctly-sized.patch deleted file mode 100644 index ce63694c..00000000 --- a/0344-libxc-PM-Ensure-pxstat-buffers-are-correctly-sized.patch +++ /dev/null @@ -1,87 +0,0 @@ -From 395f34d11275dedac2bb80e880edc574b453f3f7 Mon Sep 17 00:00:00 2001 -From: Ross Lagerwall -Date: Mon, 7 Jul 2025 11:35:11 +0200 -Subject: [PATCH] libxc/PM: Ensure pxstat buffers are correctly sized - -xc_pm_get_pxstat() requires the caller to allocate the pt and trans_pt -buffers but then calls xc_pm_get_max_px() to determine how big they are -(and hence how much Xen will copy into them). This is susceptible to -races if xc_pm_get_max_px() changes so avoid the problem by requiring -the caller to also pass in the size of the buffers. - -Suggested-by: Jan Beulich -Signed-off-by: Ross Lagerwall -Reviewed-by: Anthony PERARD -master commit: de6a05a8a0d5090f1cdb9b5449b034afcbe7a208 -master date: 2025-06-11 11:06:45 +0200 ---- - tools/libs/ctrl/xc_pm.c | 22 ++++++++++------------ - tools/misc/xenpm.c | 1 + - 2 files changed, 11 insertions(+), 12 deletions(-) - -diff --git a/tools/libs/ctrl/xc_pm.c b/tools/libs/ctrl/xc_pm.c -index b27b45c3dc14..a9d2e29212c0 100644 ---- a/tools/libs/ctrl/xc_pm.c -+++ b/tools/libs/ctrl/xc_pm.c -@@ -45,36 +45,34 @@ int xc_pm_get_max_px(xc_interface *xch, int cpuid, int *max_px) - int xc_pm_get_pxstat(xc_interface *xch, int cpuid, struct xc_px_stat *pxpt) - { - struct xen_sysctl sysctl = {}; -- /* Sizes unknown until xc_pm_get_max_px */ -- DECLARE_NAMED_HYPERCALL_BOUNCE(trans, pxpt->trans_pt, 0, XC_HYPERCALL_BUFFER_BOUNCE_BOTH); -- DECLARE_NAMED_HYPERCALL_BOUNCE(pt, pxpt->pt, 0, XC_HYPERCALL_BUFFER_BOUNCE_BOTH); -+ DECLARE_NAMED_HYPERCALL_BOUNCE(trans, pxpt->trans_pt, -+ pxpt->total * pxpt->total * sizeof(uint64_t), -+ XC_HYPERCALL_BUFFER_BOUNCE_BOTH); -+ DECLARE_NAMED_HYPERCALL_BOUNCE(pt, pxpt->pt, -+ pxpt->total * sizeof(struct xc_px_val), -+ XC_HYPERCALL_BUFFER_BOUNCE_BOTH); - -- int max_px, ret; -+ int ret; - - if ( !pxpt->trans_pt || !pxpt->pt ) - { - errno = EINVAL; - return -1; - } -- if ( (ret = xc_pm_get_max_px(xch, cpuid, &max_px)) != 0) -- return ret; -- -- HYPERCALL_BOUNCE_SET_SIZE(trans, max_px * max_px * sizeof(uint64_t)); -- HYPERCALL_BOUNCE_SET_SIZE(pt, max_px * sizeof(struct xc_px_val)); - - if ( xc_hypercall_bounce_pre(xch, trans) ) -- return ret; -+ return -1; - - if ( xc_hypercall_bounce_pre(xch, pt) ) - { - xc_hypercall_bounce_post(xch, trans); -- return ret; -+ return -1; - } - - sysctl.cmd = XEN_SYSCTL_get_pmstat; - sysctl.u.get_pmstat.type = PMSTAT_get_pxstat; - sysctl.u.get_pmstat.cpuid = cpuid; -- sysctl.u.get_pmstat.u.getpx.total = max_px; -+ sysctl.u.get_pmstat.u.getpx.total = pxpt->total; - set_xen_guest_handle(sysctl.u.get_pmstat.u.getpx.trans_pt, trans); - set_xen_guest_handle(sysctl.u.get_pmstat.u.getpx.pt, pt); - -diff --git a/tools/misc/xenpm.c b/tools/misc/xenpm.c -index db658ebaddd5..de319329e6b0 100644 ---- a/tools/misc/xenpm.c -+++ b/tools/misc/xenpm.c -@@ -319,6 +319,7 @@ static int get_pxstat_by_cpuid(xc_interface *xc_handle, int cpuid, struct xc_px_ - if ( !pxstat) - return -EINVAL; - -+ pxstat->total = max_px_num; - pxstat->trans_pt = malloc(max_px_num * max_px_num * - sizeof(uint64_t)); - if ( !pxstat->trans_pt ) --- -2.49.0 - diff --git a/0345-libxc-PM-Retry-get_pxstat-if-data-is-incomplete.patch b/0345-libxc-PM-Retry-get_pxstat-if-data-is-incomplete.patch deleted file mode 100644 index f8aa8087..00000000 --- a/0345-libxc-PM-Retry-get_pxstat-if-data-is-incomplete.patch +++ /dev/null @@ -1,85 +0,0 @@ -From 44584a7bd11585010203aa30135b32ab6cbf60a5 Mon Sep 17 00:00:00 2001 -From: Ross Lagerwall -Date: Mon, 7 Jul 2025 11:35:26 +0200 -Subject: [PATCH] libxc/PM: Retry get_pxstat if data is incomplete - -If the total returned by Xen is more than the number of elements -allocated, it means that the buffer was too small and so the data is -incomplete. Retry to get all the data. - -Signed-off-by: Ross Lagerwall -Reviewed-by: Anthony PERARD -master commit: 1ff7f87e8f4ffff97901126927549ae7b7a7340d -master date: 2025-06-11 11:07:00 +0200 ---- - tools/misc/xenpm.c | 49 +++++++++++++++++++++++++++++----------------- - 1 file changed, 31 insertions(+), 18 deletions(-) - -diff --git a/tools/misc/xenpm.c b/tools/misc/xenpm.c -index de319329e6b0..d5387f5f0693 100644 ---- a/tools/misc/xenpm.c -+++ b/tools/misc/xenpm.c -@@ -312,29 +312,42 @@ static int get_pxstat_by_cpuid(xc_interface *xc_handle, int cpuid, struct xc_px_ - int ret = 0; - int max_px_num = 0; - -- ret = xc_pm_get_max_px(xc_handle, cpuid, &max_px_num); -- if ( ret ) -- return -errno; -- - if ( !pxstat) - return -EINVAL; - -- pxstat->total = max_px_num; -- pxstat->trans_pt = malloc(max_px_num * max_px_num * -- sizeof(uint64_t)); -- if ( !pxstat->trans_pt ) -- return -ENOMEM; -- pxstat->pt = malloc(max_px_num * sizeof(struct xc_px_val)); -- if ( !pxstat->pt ) -+ for ( ; ; ) - { -- free(pxstat->trans_pt); -- return -ENOMEM; -- } -+ ret = xc_pm_get_max_px(xc_handle, cpuid, &max_px_num); -+ if ( ret ) -+ return -errno; - -- ret = xc_pm_get_pxstat(xc_handle, cpuid, pxstat); -- if( ret ) -- { -- ret = -errno; -+ pxstat->total = max_px_num; -+ pxstat->trans_pt = malloc(max_px_num * max_px_num * -+ sizeof(uint64_t)); -+ if ( !pxstat->trans_pt ) -+ return -ENOMEM; -+ pxstat->pt = malloc(max_px_num * sizeof(struct xc_px_val)); -+ if ( !pxstat->pt ) -+ { -+ free(pxstat->trans_pt); -+ return -ENOMEM; -+ } -+ -+ ret = xc_pm_get_pxstat(xc_handle, cpuid, pxstat); -+ if ( ret ) -+ { -+ ret = -errno; -+ free(pxstat->trans_pt); -+ free(pxstat->pt); -+ pxstat->trans_pt = NULL; -+ pxstat->pt = NULL; -+ break; -+ } -+ -+ if ( pxstat->total <= max_px_num ) -+ break; -+ -+ /* get_max_px changed under our feet so the data is incomplete. */ - free(pxstat->trans_pt); - free(pxstat->pt); - pxstat->trans_pt = NULL; --- -2.49.0 - diff --git a/0346-xen-build-pass-fzero-init-padding-bits-all-to-gcc15.patch b/0346-xen-build-pass-fzero-init-padding-bits-all-to-gcc15.patch deleted file mode 100644 index 929f7c5c..00000000 --- a/0346-xen-build-pass-fzero-init-padding-bits-all-to-gcc15.patch +++ /dev/null @@ -1,44 +0,0 @@ -From 79ec6818da8b19660e2636400793f768f959eb09 Mon Sep 17 00:00:00 2001 -From: Jan Beulich -Date: Mon, 7 Jul 2025 11:35:48 +0200 -Subject: [PATCH] xen/build: pass -fzero-init-padding-bits=all to gcc15 - -See the respective bullet point in the Caveats section of -https://gcc.gnu.org/gcc-15/changes.html. - -While I'm unaware of us currently relying on the pre-gcc15 behavior, -let's still play safe and retain what unknowingly we may have been -relying upon. - -According to my observations, on x86 generated code changes -- somewhere deep in modify_bars(), presumably from the struct map_data - initializer in apply_map() (a new MOVQ), -- in vpci_process_pending(), apparently again from the struct map_data - initializer (and again a new MOVQ), -- near the top of find_cpio_data(), presumably from the struct cpio_data - initializer (a MOVW changing to a MOVQ). - -Requested-by: Andrew Cooper -Signed-off-by: Jan Beulich -Acked-by: Andrew Cooper -master commit: 86da14178db4f40b5652e96c332d9858ca23df06 -master date: 2025-07-01 11:23:59 +0200 ---- - xen/Makefile | 1 + - 1 file changed, 1 insertion(+) - -diff --git a/xen/Makefile b/xen/Makefile -index a346568743ce..3c3110bada36 100644 ---- a/xen/Makefile -+++ b/xen/Makefile -@@ -393,6 +393,7 @@ endif - CFLAGS-$(CONFIG_CC_SPLIT_SECTIONS) += -ffunction-sections -fdata-sections - - CFLAGS += -nostdinc -fno-builtin -fno-common -+$(call cc-option-add,CFLAGS,CC,-fzero-init-padding-bits=all) - CFLAGS += -Werror -Wredundant-decls -Wwrite-strings -Wno-pointer-arith - CFLAGS += -Wdeclaration-after-statement -Wuninitialized - $(call cc-option-add,CFLAGS,CC,-Wvla) --- -2.49.0 - diff --git a/0347-x86-cpu-policy-Fix-handling-of-leaf-0x80000021.patch b/0347-x86-cpu-policy-Fix-handling-of-leaf-0x80000021.patch deleted file mode 100644 index d50d95ee..00000000 --- a/0347-x86-cpu-policy-Fix-handling-of-leaf-0x80000021.patch +++ /dev/null @@ -1,59 +0,0 @@ -From ab248a130e3625ac68a51d10fae15ae8d67e05fd Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Mon, 7 Jul 2025 11:35:57 +0200 -Subject: [PATCH] x86/cpu-policy: Fix handling of leaf 0x80000021 - -When support was originally introduced, ebx, ecx and edx were reserved and -should have been zeroed in recalculate_misc() to avoid leaking into guests. - -Since then, fields have been added into ebx. Guests can't load microcode, so -shouldn't see ucode_size, and while in principle we do want to support larger -RAP sizes in guests, virtualising this for guests depends on AMD procuding any -official documentation for ERAPS, which is long overdue and with no ETA. - -This patch will cause a difference in guests on Zen5 CPUs, but as the main -ERAPS feature is hidden, guests should be ignoring the rap_size field too. - -Fixes: e9b4fe263649 ("x86/cpuid: support LFENCE always serialising CPUID bit") -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -master commit: 10dc35c516f7b9224590a7a4e2722bbfd70fa87a -master date: 2025-07-02 18:25:03 +0100 ---- - xen/arch/x86/cpu-policy.c | 3 +++ - xen/include/xen/lib/x86/cpu-policy.h | 5 ++++- - 2 files changed, 7 insertions(+), 1 deletion(-) - -diff --git a/xen/arch/x86/cpu-policy.c b/xen/arch/x86/cpu-policy.c -index 52caad51627e..787785c41ae3 100644 ---- a/xen/arch/x86/cpu-policy.c -+++ b/xen/arch/x86/cpu-policy.c -@@ -326,6 +326,9 @@ static void recalculate_misc(struct cpu_policy *p) - p->extd.raw[0x1e] = EMPTY_LEAF; /* TopoExt APIC ID/Core/Node */ - p->extd.raw[0x1f] = EMPTY_LEAF; /* SEV */ - p->extd.raw[0x20] = EMPTY_LEAF; /* Platform QoS */ -+ p->extd.raw[0x21].b = 0; -+ p->extd.raw[0x21].c = 0; -+ p->extd.raw[0x21].d = 0; - break; - } - } -diff --git a/xen/include/xen/lib/x86/cpu-policy.h b/xen/include/xen/lib/x86/cpu-policy.h -index d26012c6da78..753ac78114da 100644 ---- a/xen/include/xen/lib/x86/cpu-policy.h -+++ b/xen/include/xen/lib/x86/cpu-policy.h -@@ -325,7 +325,10 @@ struct cpu_policy - uint32_t e21a; - struct { DECL_BITFIELD(e21a); }; - }; -- uint32_t /* b */:32, /* c */:32, /* d */:32; -+ uint16_t ucode_size; /* Units of 16 bytes */ -+ uint8_t rap_size; /* Units of 8 entries */ -+ uint8_t :8; -+ uint32_t /* c */:32, /* d */:32; - }; - } extd; - --- -2.49.0 - diff --git a/0500-x86-cpufeature-Reposition-cpu_has_-lfence_dispatch-n.patch b/0500-x86-cpufeature-Reposition-cpu_has_-lfence_dispatch-n.patch deleted file mode 100644 index 3c707f15..00000000 --- a/0500-x86-cpufeature-Reposition-cpu_has_-lfence_dispatch-n.patch +++ /dev/null @@ -1,45 +0,0 @@ -From f116c072cdba28185fed33d2c7d05a7e56528733 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 10 Sep 2024 20:59:37 +0100 -Subject: [PATCH] x86/cpufeature: Reposition cpu_has_{lfence_dispatch,nscb} - -LFENCE_DISPATCH used to be a synthetic feature, but was given a real CPUID bit -by AMD. The define wasn't moved when this was changed. - -NSCB has always been a real CPUID bit, and was misplaced when introduced in -the synthetic block alongside LFENCE_DISPATCH. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 6a039b050071eba644ab414d76ac5d5fc9e067a5) ---- - xen/arch/x86/include/asm/cpufeature.h | 6 ++++-- - 1 file changed, 4 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/include/asm/cpufeature.h b/xen/arch/x86/include/asm/cpufeature.h -index 6dbe6dfe0990..5e1090a5470b 100644 ---- a/xen/arch/x86/include/asm/cpufeature.h -+++ b/xen/arch/x86/include/asm/cpufeature.h -@@ -194,6 +194,10 @@ static inline bool boot_cpu_has(unsigned int feat) - #define cpu_has_avx512_bf16 boot_cpu_has(X86_FEATURE_AVX512_BF16) - #define cpu_has_avx_ifma boot_cpu_has(X86_FEATURE_AVX_IFMA) - -+/* CPUID level 0x80000021.eax */ -+#define cpu_has_lfence_dispatch boot_cpu_has(X86_FEATURE_LFENCE_DISPATCH) -+#define cpu_has_nscb boot_cpu_has(X86_FEATURE_NSCB) -+ - /* CPUID level 0x00000007:1.edx */ - #define cpu_has_avx_vnni_int8 boot_cpu_has(X86_FEATURE_AVX_VNNI_INT8) - #define cpu_has_avx_ne_convert boot_cpu_has(X86_FEATURE_AVX_NE_CONVERT) -@@ -223,8 +227,6 @@ static inline bool boot_cpu_has(unsigned int feat) - #define cpu_has_arch_perfmon boot_cpu_has(X86_FEATURE_ARCH_PERFMON) - #define cpu_has_cpuid_faulting boot_cpu_has(X86_FEATURE_CPUID_FAULTING) - #define cpu_has_aperfmperf boot_cpu_has(X86_FEATURE_APERFMPERF) --#define cpu_has_lfence_dispatch boot_cpu_has(X86_FEATURE_LFENCE_DISPATCH) --#define cpu_has_nscb boot_cpu_has(X86_FEATURE_NSCB) - #define cpu_has_xen_lbr boot_cpu_has(X86_FEATURE_XEN_LBR) - #define cpu_has_xen_shstk (IS_ENABLED(CONFIG_XEN_SHSTK) && \ - boot_cpu_has(X86_FEATURE_XEN_SHSTK)) --- -2.49.0 - diff --git a/0501-x86-idle-Move-monitor-mwait-wrappers-into-cpu-idle.c.patch b/0501-x86-idle-Move-monitor-mwait-wrappers-into-cpu-idle.c.patch deleted file mode 100644 index 06e088cd..00000000 --- a/0501-x86-idle-Move-monitor-mwait-wrappers-into-cpu-idle.c.patch +++ /dev/null @@ -1,107 +0,0 @@ -From 0c7f6dc97e653122351fddb7fad878427b45decd Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Apr 2025 14:59:01 +0100 -Subject: [PATCH] x86/idle: Move monitor()/mwait() wrappers into cpu-idle.c - -They're not used by any other translation unit, so shouldn't live in -asm/processor.h, which is included almost everywhere. - -Our new toolchain baseline knows the MONITOR/MWAIT instructions, so use them -directly rather than using raw hex. - -Change the hint/extention parameters from long to int. They're specified to -remain 32bit operands even 64-bit mode. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 61e10fc28ccddff7c72c14acec56dc7ef2b155d1) ---- - xen/arch/x86/acpi/cpu_idle.c | 21 +++++++++++++++++---- - xen/arch/x86/include/asm/processor.h | 17 ----------------- - 2 files changed, 17 insertions(+), 21 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index d0607d8a6952..45a3140bdc26 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -59,6 +59,19 @@ - - /*#define DEBUG_PM_CX*/ - -+static always_inline void monitor( -+ const void *addr, unsigned int ecx, unsigned int edx) -+{ -+ asm volatile ( "monitor" -+ :: "a" (addr), "c" (ecx), "d" (edx) ); -+} -+ -+static always_inline void mwait(unsigned int eax, unsigned int ecx) -+{ -+ asm volatile ( "mwait" -+ :: "a" (eax), "c" (ecx) ); -+} -+ - #define GET_HW_RES_IN_NS(msr, val) \ - do { rdmsrl(msr, val); val = tsc_ticks2ns(val); } while( 0 ) - #define GET_MC6_RES(val) GET_HW_RES_IN_NS(0x664, val) -@@ -482,7 +495,7 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - mb(); - } - -- __monitor(monitor_addr, 0, 0); -+ monitor(monitor_addr, 0, 0); - smp_mb(); - - /* -@@ -496,7 +509,7 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - cpumask_set_cpu(cpu, &cpuidle_mwait_flags); - - spec_ctrl_enter_idle(info); -- __mwait(eax, ecx); -+ mwait(eax, ecx); - spec_ctrl_exit_idle(info); - - cpumask_clear_cpu(cpu, &cpuidle_mwait_flags); -@@ -927,9 +940,9 @@ void cf_check acpi_dead_idle(void) - */ - mb(); - clflush(mwait_ptr); -- __monitor(mwait_ptr, 0, 0); -+ monitor(mwait_ptr, 0, 0); - mb(); -- __mwait(cx->address, 0); -+ mwait(cx->address, 0); - } - } - else if ( (current_cpu_data.x86_vendor & -diff --git a/xen/arch/x86/include/asm/processor.h b/xen/arch/x86/include/asm/processor.h -index c709d337c9b9..c02566a915bd 100644 ---- a/xen/arch/x86/include/asm/processor.h -+++ b/xen/arch/x86/include/asm/processor.h -@@ -319,23 +319,6 @@ static always_inline void set_in_cr4 (unsigned long mask) - write_cr4(read_cr4() | mask); - } - --static always_inline void __monitor(const void *eax, unsigned long ecx, -- unsigned long edx) --{ -- /* "monitor %eax,%ecx,%edx;" */ -- asm volatile ( -- ".byte 0x0f,0x01,0xc8;" -- : : "a" (eax), "c" (ecx), "d"(edx) ); --} -- --static always_inline void __mwait(unsigned long eax, unsigned long ecx) --{ -- /* "mwait %eax,%ecx;" */ -- asm volatile ( -- ".byte 0x0f,0x01,0xc9;" -- : : "a" (eax), "c" (ecx) ); --} -- - #define IOBMP_BYTES 8192 - #define IOBMP_INVALID_OFFSET 0x8000 - --- -2.49.0 - diff --git a/0502-x86-idle-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch b/0502-x86-idle-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch deleted file mode 100644 index 062db32b..00000000 --- a/0502-x86-idle-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch +++ /dev/null @@ -1,140 +0,0 @@ -From 735eb8c4248f2ffd2a510928ead5968244c990a5 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Apr 2025 15:55:29 +0100 -Subject: [PATCH] x86/idle: Remove MFENCEs for CLFLUSH_MONITOR - -Commit 48d32458bcd4 ("x86, idle: add barriers to CLFLUSH workaround") was -inherited from Linux and added MFENCEs around the AAI65 errata fix. - -The SDM now states: - - Executions of the CLFLUSH instruction are ordered with respect to each - other and with respect to writes, locked read-modify-write instructions, - and fence instructions[1]. - -with footnote 1 reading: - - Earlier versions of this manual specified that executions of the CLFLUSH - instruction were ordered only by the MFENCE instruction. All processors - implementing the CLFLUSH instruction also order it relative to the other - operations enumerated above. - -I.e. the MFENCEs came about because of an incorrect statement in the SDM. - -The Spec Update (no longer available on Intel's website) simply says "issue a -CLFLUSH", with no mention of MFENCEs. - -As this erratum is specific to Intel, it's fine to remove the the MFENCEs; AMD -CPUs of a similar vintage do sport otherwise-unordered CLFLUSHs. - -Move the feature bit into the BUG range (rather than FEATURE), and move the -workaround into monitor() itself. - -The erratum check itself must use setup_force_cpu_cap(). It needs activating -if any CPU needs it, not if all of them need it. - -Fixes: 48d32458bcd4 ("x86, idle: add barriers to CLFLUSH workaround") -Fixes: 96d1b237ae9b ("x86/Intel: work around Xeon 7400 series erratum AAI65") -Link: https://web.archive.org/web/20090219054841/http://download.intel.com/design/xeon/specupdt/32033601.pdf -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit f77ef3443542a2c2bbd59ee66178287d4fa5b43f) ---- - xen/arch/x86/acpi/cpu_idle.c | 22 +++------------------- - xen/arch/x86/cpu/intel.c | 3 ++- - xen/arch/x86/include/asm/cpufeatures.h | 3 ++- - 3 files changed, 7 insertions(+), 21 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 45a3140bdc26..41d771d8f395 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -62,6 +62,9 @@ - static always_inline void monitor( - const void *addr, unsigned int ecx, unsigned int edx) - { -+ alternative_input("", "clflush (%[addr])", X86_BUG_CLFLUSH_MONITOR, -+ [addr] "a" (addr)); -+ - asm volatile ( "monitor" - :: "a" (addr), "c" (ecx), "d" (edx) ); - } -@@ -488,13 +491,6 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - s_time_t expires = per_cpu(timer_deadline, cpu); - const void *monitor_addr = &mwait_wakeup(cpu); - -- if ( boot_cpu_has(X86_FEATURE_CLFLUSH_MONITOR) ) -- { -- mb(); -- clflush(monitor_addr); -- mb(); -- } -- - monitor(monitor_addr, 0, 0); - smp_mb(); - -@@ -929,19 +925,7 @@ void cf_check acpi_dead_idle(void) - - while ( 1 ) - { -- /* -- * 1. The CLFLUSH is a workaround for erratum AAI65 for -- * the Xeon 7400 series. -- * 2. The WBINVD is insufficient due to the spurious-wakeup -- * case where we return around the loop. -- * 3. Unlike wbinvd, clflush is a light weight but not serializing -- * instruction, hence memory fence is necessary to make sure all -- * load/store visible before flush cache line. -- */ -- mb(); -- clflush(mwait_ptr); - monitor(mwait_ptr, 0, 0); -- mb(); - mwait(cx->address, 0); - } - } -diff --git a/xen/arch/x86/cpu/intel.c b/xen/arch/x86/cpu/intel.c -index f03eedcc2511..57258220e822 100644 ---- a/xen/arch/x86/cpu/intel.c -+++ b/xen/arch/x86/cpu/intel.c -@@ -446,6 +446,7 @@ static void __init probe_mwait_errata(void) - * - * Xeon 7400 erratum AAI65 (and further newer Xeons) - * MONITOR/MWAIT may have excessive false wakeups -+ * https://web.archive.org/web/20090219054841/http://download.intel.com/design/xeon/specupdt/32033601.pdf - */ - static void Intel_errata_workarounds(struct cpuinfo_x86 *c) - { -@@ -463,7 +464,7 @@ static void Intel_errata_workarounds(struct cpuinfo_x86 *c) - - if (c->x86 == 6 && cpu_has_clflush && - (c->x86_model == 29 || c->x86_model == 46 || c->x86_model == 47)) -- __set_bit(X86_FEATURE_CLFLUSH_MONITOR, c->x86_capability); -+ setup_force_cpu_cap(X86_BUG_CLFLUSH_MONITOR); - - probe_c3_errata(c); - if (system_state < SYS_STATE_smp_boot) -diff --git a/xen/arch/x86/include/asm/cpufeatures.h b/xen/arch/x86/include/asm/cpufeatures.h -index 9e3ed21c026d..84c93292c80c 100644 ---- a/xen/arch/x86/include/asm/cpufeatures.h -+++ b/xen/arch/x86/include/asm/cpufeatures.h -@@ -19,7 +19,7 @@ XEN_CPUFEATURE(ARCH_PERFMON, X86_SYNTH( 3)) /* Intel Architectural PerfMon - XEN_CPUFEATURE(TSC_RELIABLE, X86_SYNTH( 4)) /* TSC is known to be reliable */ - XEN_CPUFEATURE(XTOPOLOGY, X86_SYNTH( 5)) /* cpu topology enum extensions */ - XEN_CPUFEATURE(CPUID_FAULTING, X86_SYNTH( 6)) /* cpuid faulting */ --XEN_CPUFEATURE(CLFLUSH_MONITOR, X86_SYNTH( 7)) /* clflush reqd with monitor */ -+/* Bit 7 unused */ - XEN_CPUFEATURE(APERFMPERF, X86_SYNTH( 8)) /* APERFMPERF */ - XEN_CPUFEATURE(MFENCE_RDTSC, X86_SYNTH( 9)) /* MFENCE synchronizes RDTSC */ - XEN_CPUFEATURE(XEN_SMEP, X86_SYNTH(10)) /* SMEP gets used by Xen itself */ -@@ -52,6 +52,7 @@ XEN_CPUFEATURE(USE_VMCALL, X86_SYNTH(30)) /* Use VMCALL instead of VMMCAL - #define X86_BUG_NULL_SEG X86_BUG( 1) /* NULL-ing a selector preserves the base and limit. */ - #define X86_BUG_CLFLUSH_MFENCE X86_BUG( 2) /* MFENCE needed to serialise CLFLUSH */ - #define X86_BUG_IBPB_NO_RET X86_BUG( 3) /* IBPB doesn't flush the RSB/RAS */ -+#define X86_BUG_CLFLUSH_MONITOR X86_BUG( 4) /* MONITOR requires CLFLUSH */ - - #define X86_SPEC_NO_LFENCE_ENTRY_PV X86_BUG(16) /* (No) safety LFENCE for SPEC_CTRL_ENTRY_PV. */ - #define X86_SPEC_NO_LFENCE_ENTRY_INTR X86_BUG(17) /* (No) safety LFENCE for SPEC_CTRL_ENTRY_INTR. */ --- -2.49.0 - diff --git a/0503-Revert-part-of-x86-mwait-idle-disable-IBRS-during-lo.patch b/0503-Revert-part-of-x86-mwait-idle-disable-IBRS-during-lo.patch deleted file mode 100644 index 6508105a..00000000 --- a/0503-Revert-part-of-x86-mwait-idle-disable-IBRS-during-lo.patch +++ /dev/null @@ -1,82 +0,0 @@ -From b4e26e03b8c2ea30eb5956e6132034b138637917 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 24 Jun 2025 15:20:52 +0100 -Subject: [PATCH] Revert part of "x86/mwait-idle: disable IBRS during long - idle" - -Most of the patch (handling of CPUIDLE_FLAG_IBRS) is fine, but the -adjustements to mwait_idle() are not; spec_ctrl_enter_idle() does more than -just alter MSR_SPEC_CTRL.IBRS. - -The only reason this doesn't need an XSA is because the unconditional -spec_ctrl_{enter,exit}_idle() in mwait_idle_with_hints() were left unaltered, -and thus the MWAIT remained properly protected. - -There (would have been) two problems. In the ibrs_disable (== deep C) case: - - * On entry, VERW and RSB-stuffing are architecturally skipped. - * On exit, there's a branch crossing the WRMSR which reinstates the - speculative safety for indirect branches. - -All this change did was double up the expensive operations in the deep C case, -and fail to optimise the intended case. - -I have an idea of how to plumb this more nicely, but it requires larger -changes to legacy IBRS handling to not make spec_ctrl_enter_idle() vulnerable -in other ways. In the short term, simply take out the perf hit. - -Fixes: 08acdf9a2615 ("x86/mwait-idle: disable IBRS during long idle") -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 07d7163334a7507d329958b19d976be769580999) ---- - xen/arch/x86/cpu/mwait-idle.c | 12 ++---------- - 1 file changed, 2 insertions(+), 10 deletions(-) - -diff --git a/xen/arch/x86/cpu/mwait-idle.c b/xen/arch/x86/cpu/mwait-idle.c -index ae6987117169..182518528a6e 100644 ---- a/xen/arch/x86/cpu/mwait-idle.c -+++ b/xen/arch/x86/cpu/mwait-idle.c -@@ -891,7 +891,6 @@ static const struct cpuidle_state snr_cstates[] = { - static void cf_check mwait_idle(void) - { - unsigned int cpu = smp_processor_id(); -- struct cpu_info *info = get_cpu_info(); - struct acpi_processor_power *power = processor_powers[cpu]; - struct acpi_processor_cx *cx = NULL; - unsigned int next_state; -@@ -918,6 +917,8 @@ static void cf_check mwait_idle(void) - pm_idle_save(); - else - { -+ struct cpu_info *info = get_cpu_info(); -+ - spec_ctrl_enter_idle(info); - safe_halt(); - spec_ctrl_exit_idle(info); -@@ -944,11 +945,6 @@ static void cf_check mwait_idle(void) - if ((cx->type >= 3) && errata_c6_workaround()) - cx = power->safe_state; - -- if (cx->ibrs_disable) { -- ASSERT(!cx->irq_enable_early); -- spec_ctrl_enter_idle(info); -- } -- - #if 0 /* XXX Can we/do we need to do something similar on Xen? */ - /* - * leave_mm() to avoid costly and often unnecessary wakeups -@@ -980,10 +976,6 @@ static void cf_check mwait_idle(void) - - /* Now back in C0. */ - update_idle_stats(power, cx, before, after); -- -- if (cx->ibrs_disable) -- spec_ctrl_exit_idle(info); -- - local_irq_enable(); - - TRACE_TIME(TRC_PM_IDLE_EXIT, cx->type, after, --- -2.49.0 - diff --git a/0504-x86-cpu-policy-Simplify-logic-in-guest_common_defaul.patch b/0504-x86-cpu-policy-Simplify-logic-in-guest_common_defaul.patch deleted file mode 100644 index b777133c..00000000 --- a/0504-x86-cpu-policy-Simplify-logic-in-guest_common_defaul.patch +++ /dev/null @@ -1,68 +0,0 @@ -From 00dce34e0cc56d53a0bef5921c13362152bcec5b Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Fri, 27 Jun 2025 14:46:01 +0100 -Subject: [PATCH] x86/cpu-policy: Simplify logic in - guest_common_default_feature_adjustments() - -For features which are unconditionally set in the max policies, making the -default policy to match the host can be done with a conditional clear. - -This is simpler than the unconditional clear, conditional set currently -performed. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 30f8fed68f3c2e63594ff9202b3d05b971781e36) ---- - xen/arch/x86/cpu-policy.c | 25 ++++++++++--------------- - 1 file changed, 10 insertions(+), 15 deletions(-) - -diff --git a/xen/arch/x86/cpu-policy.c b/xen/arch/x86/cpu-policy.c -index 787785c41ae3..e34cba189c75 100644 ---- a/xen/arch/x86/cpu-policy.c -+++ b/xen/arch/x86/cpu-policy.c -@@ -515,17 +515,14 @@ static void __init guest_common_default_feature_adjustments(uint32_t *fs) - * reasons, so reset the default policy back to the host values in - * case we're unaffected. - */ -- __clear_bit(X86_FEATURE_MD_CLEAR, fs); -- if ( cpu_has_md_clear ) -- __set_bit(X86_FEATURE_MD_CLEAR, fs); -+ if ( !cpu_has_md_clear ) -+ __clear_bit(X86_FEATURE_MD_CLEAR, fs); - -- __clear_bit(X86_FEATURE_FB_CLEAR, fs); -- if ( cpu_has_fb_clear ) -- __set_bit(X86_FEATURE_FB_CLEAR, fs); -+ if ( !cpu_has_fb_clear ) -+ __clear_bit(X86_FEATURE_FB_CLEAR, fs); - -- __clear_bit(X86_FEATURE_RFDS_CLEAR, fs); -- if ( cpu_has_rfds_clear ) -- __set_bit(X86_FEATURE_RFDS_CLEAR, fs); -+ if ( !cpu_has_rfds_clear ) -+ __clear_bit(X86_FEATURE_RFDS_CLEAR, fs); - - /* - * The Gather Data Sampling microcode mitigation (August 2023) has an -@@ -545,13 +542,11 @@ static void __init guest_common_default_feature_adjustments(uint32_t *fs) - * Topology information is at the toolstack's discretion so these are - * unconditionally set in max, but pick a default which matches the host. - */ -- __clear_bit(X86_FEATURE_HTT, fs); -- if ( cpu_has_htt ) -- __set_bit(X86_FEATURE_HTT, fs); -+ if ( !cpu_has_htt ) -+ __clear_bit(X86_FEATURE_HTT, fs); - -- __clear_bit(X86_FEATURE_CMP_LEGACY, fs); -- if ( cpu_has_cmp_legacy ) -- __set_bit(X86_FEATURE_CMP_LEGACY, fs); -+ if ( !cpu_has_cmp_legacy ) -+ __clear_bit(X86_FEATURE_CMP_LEGACY, fs); - - /* - * On certain hardware, speculative or errata workarounds can result in --- -2.49.0 - diff --git a/0505-x86-idle-Remove-broken-MWAIT-implementation.patch b/0505-x86-idle-Remove-broken-MWAIT-implementation.patch deleted file mode 100644 index 971639da..00000000 --- a/0505-x86-idle-Remove-broken-MWAIT-implementation.patch +++ /dev/null @@ -1,187 +0,0 @@ -From 00ce6be7b716315d971250b05dccff1ee3cc808f Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Jul 2025 15:51:53 +0100 -Subject: [PATCH] x86/idle: Remove broken MWAIT implementation -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -cpuidle_wakeup_mwait() is a TOCTOU race. The cpumask_and() sampling -cpuidle_mwait_flags can take a arbitrary period of time, and there's no -guarantee that the target CPUs are still in MWAIT when writing into -mwait_wakeup(cpu). - -The consequence of the race is that we'll fail to IPI certain targets. Also, -there's no guarantee that mwait_idle_with_hints() will raise a TIMER_SOFTIRQ -on it's way out. - -The fundamental bug is that the "in_mwait" variable needs to be in the -monitored line, and not in a separate cpuidle_mwait_flags variable, in order -to do this in a race-free way. - -Arranging to fix this while keeping the old implementation is prohibitive, so -strip the current one out in order to implement the new one cleanly. In the -interim, this causes IPIs to be used unconditionally which is safe albeit -suboptimal. - -Fixes: 3d521e933e1b ("cpuidle: mwait on softirq_pending & remove wakeup ipis") -Fixes: 1adb34ea846d ("CPUIDLE: re-implement mwait wakeup process") -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit 3faf0866a33070b926ab78e6298290403f85e76c) ---- - xen/arch/x86/acpi/cpu_idle.c | 48 ++++-------------------------- - xen/arch/x86/hpet.c | 2 -- - xen/arch/x86/include/asm/hardirq.h | 9 +++--- - xen/include/xen/cpuidle.h | 2 -- - xen/include/xen/irq_cpustat.h | 1 - - 5 files changed, 9 insertions(+), 53 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 41d771d8f395..4ed1878e262c 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -448,27 +448,6 @@ static int __init cf_check cpu_idle_key_init(void) - } - __initcall(cpu_idle_key_init); - --/* -- * The bit is set iff cpu use monitor/mwait to enter C state -- * with this flag set, CPU can be waken up from C state -- * by writing to specific memory address, instead of sending an IPI. -- */ --static cpumask_t cpuidle_mwait_flags; -- --void cpuidle_wakeup_mwait(cpumask_t *mask) --{ -- cpumask_t target; -- unsigned int cpu; -- -- cpumask_and(&target, mask, &cpuidle_mwait_flags); -- -- /* CPU is MWAITing on the cpuidle_mwait_wakeup flag. */ -- for_each_cpu(cpu, &target) -- mwait_wakeup(cpu) = 0; -- -- cpumask_andnot(mask, mask, &target); --} -- - /* Force sending of a wakeup IPI regardless of mwait usage. */ - bool __ro_after_init force_mwait_ipi_wakeup; - -@@ -477,42 +456,25 @@ bool arch_skip_send_event_check(unsigned int cpu) - if ( force_mwait_ipi_wakeup ) - return false; - -- /* -- * This relies on softirq_pending() and mwait_wakeup() to access data -- * on the same cache line. -- */ -- smp_mb(); -- return !!cpumask_test_cpu(cpu, &cpuidle_mwait_flags); -+ return false; - } - - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - { - unsigned int cpu = smp_processor_id(); -- s_time_t expires = per_cpu(timer_deadline, cpu); -- const void *monitor_addr = &mwait_wakeup(cpu); -+ const unsigned int *this_softirq_pending = &softirq_pending(cpu); - -- monitor(monitor_addr, 0, 0); -+ monitor(this_softirq_pending, 0, 0); - smp_mb(); - -- /* -- * Timer deadline passing is the event on which we will be woken via -- * cpuidle_mwait_wakeup. So check it now that the location is armed. -- */ -- if ( (expires > NOW() || expires == 0) && !softirq_pending(cpu) ) -+ if ( !*this_softirq_pending ) - { - struct cpu_info *info = get_cpu_info(); - -- cpumask_set_cpu(cpu, &cpuidle_mwait_flags); -- - spec_ctrl_enter_idle(info); - mwait(eax, ecx); - spec_ctrl_exit_idle(info); -- -- cpumask_clear_cpu(cpu, &cpuidle_mwait_flags); - } -- -- if ( expires <= NOW() && expires > 0 ) -- raise_softirq(TIMER_SOFTIRQ); - } - - static void acpi_processor_ffh_cstate_enter(struct acpi_processor_cx *cx) -@@ -913,7 +875,7 @@ void cf_check acpi_dead_idle(void) - - if ( cx->entry_method == ACPI_CSTATE_EM_FFH ) - { -- void *mwait_ptr = &mwait_wakeup(smp_processor_id()); -+ void *mwait_ptr = &softirq_pending(smp_processor_id()); - - /* - * Cache must be flushed as the last operation before sleeping. -diff --git a/xen/arch/x86/hpet.c b/xen/arch/x86/hpet.c -index 2f54d3188966..84f820fef605 100644 ---- a/xen/arch/x86/hpet.c -+++ b/xen/arch/x86/hpet.c -@@ -187,8 +187,6 @@ static void evt_do_broadcast(cpumask_t *mask) - if ( __cpumask_test_and_clear_cpu(cpu, mask) ) - raise_softirq(TIMER_SOFTIRQ); - -- cpuidle_wakeup_mwait(mask); -- - if ( !cpumask_empty(mask) ) - cpumask_raise_softirq(mask, TIMER_SOFTIRQ); - } -diff --git a/xen/arch/x86/include/asm/hardirq.h b/xen/arch/x86/include/asm/hardirq.h -index 342361cb6fdd..f3e93cc9b507 100644 ---- a/xen/arch/x86/include/asm/hardirq.h -+++ b/xen/arch/x86/include/asm/hardirq.h -@@ -5,11 +5,10 @@ - #include - - typedef struct { -- unsigned int __softirq_pending; -- unsigned int __local_irq_count; -- unsigned int nmi_count; -- unsigned int mce_count; -- bool __mwait_wakeup; -+ unsigned int __softirq_pending; -+ unsigned int __local_irq_count; -+ unsigned int nmi_count; -+ unsigned int mce_count; - } __cacheline_aligned irq_cpustat_t; - - #include /* Standard mappings for irq_cpustat_t above */ -diff --git a/xen/include/xen/cpuidle.h b/xen/include/xen/cpuidle.h -index 705d0c1135f0..120e354fe340 100644 ---- a/xen/include/xen/cpuidle.h -+++ b/xen/include/xen/cpuidle.h -@@ -92,8 +92,6 @@ extern struct cpuidle_governor *cpuidle_current_governor; - bool cpuidle_using_deep_cstate(void); - void cpuidle_disable_deep_cstate(void); - --extern void cpuidle_wakeup_mwait(cpumask_t *mask); -- - #define CPUIDLE_DRIVER_STATE_START 1 - - extern void menu_get_trace_data(u32 *expected, u32 *pred); -diff --git a/xen/include/xen/irq_cpustat.h b/xen/include/xen/irq_cpustat.h -index b9629f25c266..5f039b4b9a76 100644 ---- a/xen/include/xen/irq_cpustat.h -+++ b/xen/include/xen/irq_cpustat.h -@@ -24,6 +24,5 @@ extern irq_cpustat_t irq_stat[]; - /* arch independent irq_stat fields */ - #define softirq_pending(cpu) __IRQ_STAT((cpu), __softirq_pending) - #define local_irq_count(cpu) __IRQ_STAT((cpu), __local_irq_count) --#define mwait_wakeup(cpu) __IRQ_STAT((cpu), __mwait_wakeup) - - #endif /* __irq_cpustat_h */ --- -2.49.0 - diff --git a/0506-x86-idle-Drop-incorrect-smp_mb-in-mwait_idle_with_hi.patch b/0506-x86-idle-Drop-incorrect-smp_mb-in-mwait_idle_with_hi.patch deleted file mode 100644 index a1350d95..00000000 --- a/0506-x86-idle-Drop-incorrect-smp_mb-in-mwait_idle_with_hi.patch +++ /dev/null @@ -1,53 +0,0 @@ -From b0396e465f330c4d6e1c489ad329589a70cf5bf9 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Jul 2025 18:13:27 +0100 -Subject: [PATCH] x86/idle: Drop incorrect smp_mb() in mwait_idle_with_hints() -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -With the recent simplifications, it becomes obvious that smp_mb() isn't the -right barrier. Strictly speaking, MONITOR is ordered as a load, but smp_rmb() -isn't correct either, as this only pertains to local ordering. All we need is -a compiler barrier(). - -Merge the barier() into the monitor() itself, along with an explantion. - -No functional change. - -Signed-off-by: Andrew Cooper -Acked-by: Roger Pau Monné -(cherry picked from commit e7710dd843ba9d204f6ee2973d6120c1984958a6) ---- - xen/arch/x86/acpi/cpu_idle.c | 7 +++++-- - 1 file changed, 5 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 4ed1878e262c..a4a6f8694373 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -65,8 +65,12 @@ static always_inline void monitor( - alternative_input("", "clflush (%[addr])", X86_BUG_CLFLUSH_MONITOR, - [addr] "a" (addr)); - -+ /* -+ * The memory clobber is a compiler barrier. Subseqeunt reads from the -+ * monitored cacheline must not be reordered over MONITOR. -+ */ - asm volatile ( "monitor" -- :: "a" (addr), "c" (ecx), "d" (edx) ); -+ :: "a" (addr), "c" (ecx), "d" (edx) : "memory" ); - } - - static always_inline void mwait(unsigned int eax, unsigned int ecx) -@@ -465,7 +469,6 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - const unsigned int *this_softirq_pending = &softirq_pending(cpu); - - monitor(this_softirq_pending, 0, 0); -- smp_mb(); - - if ( !*this_softirq_pending ) - { --- -2.49.0 - diff --git a/0507-x86-idle-Convert-force_mwait_ipi_wakeup-to-X86_BUG_M.patch b/0507-x86-idle-Convert-force_mwait_ipi_wakeup-to-X86_BUG_M.patch deleted file mode 100644 index 77d6cdd2..00000000 --- a/0507-x86-idle-Convert-force_mwait_ipi_wakeup-to-X86_BUG_M.patch +++ /dev/null @@ -1,83 +0,0 @@ -From 41b38d5b4fa5407d9cce1dec3b5261f8907cf61d Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Jul 2025 21:40:51 +0100 -Subject: [PATCH] x86/idle: Convert force_mwait_ipi_wakeup to X86_BUG_MONITOR -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -We're going to want alternative-patch based on it. - -No functional change. - -Signed-off-by: Andrew Cooper -Acked-by: Roger Pau Monné -(cherry picked from commit b0ca0f93f47c43f8984981137af07ca3d161e3ec) ---- - xen/arch/x86/acpi/cpu_idle.c | 6 ------ - xen/arch/x86/cpu/intel.c | 2 +- - xen/arch/x86/include/asm/cpufeatures.h | 1 + - xen/arch/x86/include/asm/mwait.h | 3 --- - 4 files changed, 2 insertions(+), 10 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index a4a6f8694373..c42ffb244e8b 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -452,14 +452,8 @@ static int __init cf_check cpu_idle_key_init(void) - } - __initcall(cpu_idle_key_init); - --/* Force sending of a wakeup IPI regardless of mwait usage. */ --bool __ro_after_init force_mwait_ipi_wakeup; -- - bool arch_skip_send_event_check(unsigned int cpu) - { -- if ( force_mwait_ipi_wakeup ) -- return false; -- - return false; - } - -diff --git a/xen/arch/x86/cpu/intel.c b/xen/arch/x86/cpu/intel.c -index 57258220e822..dbf17be1287f 100644 ---- a/xen/arch/x86/cpu/intel.c -+++ b/xen/arch/x86/cpu/intel.c -@@ -436,7 +436,7 @@ static void __init probe_mwait_errata(void) - { - printk(XENLOG_WARNING - "Forcing IPI MWAIT wakeup due to CPU erratum\n"); -- force_mwait_ipi_wakeup = true; -+ setup_force_cpu_cap(X86_BUG_MONITOR); - } - } - -diff --git a/xen/arch/x86/include/asm/cpufeatures.h b/xen/arch/x86/include/asm/cpufeatures.h -index 84c93292c80c..56231b00f15d 100644 ---- a/xen/arch/x86/include/asm/cpufeatures.h -+++ b/xen/arch/x86/include/asm/cpufeatures.h -@@ -53,6 +53,7 @@ XEN_CPUFEATURE(USE_VMCALL, X86_SYNTH(30)) /* Use VMCALL instead of VMMCAL - #define X86_BUG_CLFLUSH_MFENCE X86_BUG( 2) /* MFENCE needed to serialise CLFLUSH */ - #define X86_BUG_IBPB_NO_RET X86_BUG( 3) /* IBPB doesn't flush the RSB/RAS */ - #define X86_BUG_CLFLUSH_MONITOR X86_BUG( 4) /* MONITOR requires CLFLUSH */ -+#define X86_BUG_MONITOR X86_BUG( 5) /* MONITOR doesn't always notice writes (force IPIs) */ - - #define X86_SPEC_NO_LFENCE_ENTRY_PV X86_BUG(16) /* (No) safety LFENCE for SPEC_CTRL_ENTRY_PV. */ - #define X86_SPEC_NO_LFENCE_ENTRY_INTR X86_BUG(17) /* (No) safety LFENCE for SPEC_CTRL_ENTRY_INTR. */ -diff --git a/xen/arch/x86/include/asm/mwait.h b/xen/arch/x86/include/asm/mwait.h -index 1f1e39775b99..9298f987c435 100644 ---- a/xen/arch/x86/include/asm/mwait.h -+++ b/xen/arch/x86/include/asm/mwait.h -@@ -13,9 +13,6 @@ - - #define MWAIT_ECX_INTERRUPT_BREAK 0x1 - --/* Force sending of a wakeup IPI regardless of mwait usage. */ --extern bool force_mwait_ipi_wakeup; -- - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx); - bool mwait_pc10_supported(void); - --- -2.49.0 - diff --git a/0508-xen-softirq-Rework-arch_skip_send_event_check-into-a.patch b/0508-xen-softirq-Rework-arch_skip_send_event_check-into-a.patch deleted file mode 100644 index 2ae3488a..00000000 --- a/0508-xen-softirq-Rework-arch_skip_send_event_check-into-a.patch +++ /dev/null @@ -1,115 +0,0 @@ -From 76bce69ed742f72c50c8e26588a5cf8f3d13959f Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Jul 2025 21:04:17 +0100 -Subject: [PATCH] xen/softirq: Rework arch_skip_send_event_check() into - arch_set_softirq() -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -x86 is the only architecture wanting an optimisation here, but the -test_and_set_bit() is a store into the monitored line (i.e. will wake up the -target) and, prior to the removal of the broken IPI-elision algorithm, was -racy, causing unnecessary IPIs to be sent. - -To do this in a race-free way, the store to the monited line needs to also -sample the status of the target in one atomic action. Implement a new arch -helper with different semantics; to make the softirq pending and decide about -IPIs together. For now, implement the default helper. It will be overridden -by x86 in a subsequent change. - -No functional change. - -Signed-off-by: Andrew Cooper -Reviewed-by: Roger Pau Monné -(cherry picked from commit b473e5e212e445d3c193c1c83b52b129af571b19) ---- - xen/arch/x86/acpi/cpu_idle.c | 5 ----- - xen/arch/x86/include/asm/softirq.h | 2 -- - xen/common/softirq.c | 8 ++------ - xen/include/xen/softirq.h | 16 ++++++++++++++++ - 4 files changed, 18 insertions(+), 13 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index c42ffb244e8b..489d894c2f66 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -452,11 +452,6 @@ static int __init cf_check cpu_idle_key_init(void) - } - __initcall(cpu_idle_key_init); - --bool arch_skip_send_event_check(unsigned int cpu) --{ -- return false; --} -- - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - { - unsigned int cpu = smp_processor_id(); -diff --git a/xen/arch/x86/include/asm/softirq.h b/xen/arch/x86/include/asm/softirq.h -index 415ee866c79d..e4b194f069fb 100644 ---- a/xen/arch/x86/include/asm/softirq.h -+++ b/xen/arch/x86/include/asm/softirq.h -@@ -9,6 +9,4 @@ - #define HVM_DPCI_SOFTIRQ (NR_COMMON_SOFTIRQS + 4) - #define NR_ARCH_SOFTIRQS 5 - --bool arch_skip_send_event_check(unsigned int cpu); -- - #endif /* __ASM_SOFTIRQ_H__ */ -diff --git a/xen/common/softirq.c b/xen/common/softirq.c -index bee4a82009c3..626c47de82ac 100644 ---- a/xen/common/softirq.c -+++ b/xen/common/softirq.c -@@ -94,9 +94,7 @@ void cpumask_raise_softirq(const cpumask_t *mask, unsigned int nr) - raise_mask = &per_cpu(batch_mask, this_cpu); - - for_each_cpu(cpu, mask) -- if ( !test_and_set_bit(nr, &softirq_pending(cpu)) && -- cpu != this_cpu && -- !arch_skip_send_event_check(cpu) ) -+ if ( !arch_set_softirq(nr, cpu) && cpu != this_cpu ) - __cpumask_set_cpu(cpu, raise_mask); - - if ( raise_mask == &send_mask ) -@@ -107,9 +105,7 @@ void cpu_raise_softirq(unsigned int cpu, unsigned int nr) - { - unsigned int this_cpu = smp_processor_id(); - -- if ( test_and_set_bit(nr, &softirq_pending(cpu)) -- || (cpu == this_cpu) -- || arch_skip_send_event_check(cpu) ) -+ if ( arch_set_softirq(nr, cpu) || cpu == this_cpu ) - return; - - if ( !per_cpu(batching, this_cpu) || in_irq() ) -diff --git a/xen/include/xen/softirq.h b/xen/include/xen/softirq.h -index 33d6f2ecd223..5c2361865b49 100644 ---- a/xen/include/xen/softirq.h -+++ b/xen/include/xen/softirq.h -@@ -21,6 +21,22 @@ enum { - - #define NR_SOFTIRQS (NR_COMMON_SOFTIRQS + NR_ARCH_SOFTIRQS) - -+/* -+ * Ensure softirq @nr is pending on @cpu. Return true if an IPI can be -+ * skipped, false if the IPI cannot be skipped. -+ */ -+#ifndef arch_set_softirq -+static always_inline bool arch_set_softirq(unsigned int nr, unsigned int cpu) -+{ -+ /* -+ * Try to set the softirq pending. If we set the bit (i.e. the old bit -+ * was 0), we're responsible to send the IPI. If the softirq was already -+ * pending (i.e. the old bit was 1), no IPI is needed. -+ */ -+ return test_and_set_bit(nr, &softirq_pending(cpu)); -+} -+#endif -+ - typedef void (*softirq_handler)(void); - - void do_softirq(void); --- -2.49.0 - diff --git a/0509-x86-idle-Implement-a-new-MWAIT-IPI-elision-algorithm.patch b/0509-x86-idle-Implement-a-new-MWAIT-IPI-elision-algorithm.patch deleted file mode 100644 index 1d528429..00000000 --- a/0509-x86-idle-Implement-a-new-MWAIT-IPI-elision-algorithm.patch +++ /dev/null @@ -1,159 +0,0 @@ -From 39abd23d8bc3af172d3d706a123d830be8fc08f2 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 1 Jul 2025 21:26:24 +0100 -Subject: [PATCH] x86/idle: Implement a new MWAIT IPI-elision algorithm -MIME-Version: 1.0 -Content-Type: text/plain; charset=UTF-8 -Content-Transfer-Encoding: 8bit - -In order elide IPIs, we must be able to identify whether a target CPU is in -MWAIT at the point it is woken up. i.e. the store to wake it up must also -identify the state. - -Create a new in_mwait variable beside __softirq_pending, so we can use a -CMPXCHG to set the softirq while also observing the status safely. Implement -an x86 version of arch_pend_softirq() which does this. - -In mwait_idle_with_hints(), advertise in_mwait, with an explanation of -precisely what it means. X86_BUG_MONITOR can be accounted for simply by not -advertising in_mwait. - -Signed-off-by: Andrew Cooper -Acked-by: Roger Pau Monné -(cherry picked from commit 3e0bc4b50350bd357304fd79a5dc0472790dba91) ---- - xen/arch/x86/acpi/cpu_idle.c | 20 ++++++++++++- - xen/arch/x86/include/asm/hardirq.h | 14 ++++++++- - xen/arch/x86/include/asm/softirq.h | 48 ++++++++++++++++++++++++++++++ - 3 files changed, 80 insertions(+), 2 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 489d894c2f66..176df1ed174f 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -455,7 +455,21 @@ __initcall(cpu_idle_key_init); - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - { - unsigned int cpu = smp_processor_id(); -- const unsigned int *this_softirq_pending = &softirq_pending(cpu); -+ irq_cpustat_t *stat = &irq_stat[cpu]; -+ const unsigned int *this_softirq_pending = &stat->__softirq_pending; -+ -+ /* -+ * By setting in_mwait, we promise to other CPUs that we'll notice changes -+ * to __softirq_pending without being sent an IPI. We achieve this by -+ * either not going to sleep, or by having hardware notice on our behalf. -+ * -+ * Some errata exist where MONITOR doesn't work properly, and the -+ * workaround is to force the use of an IPI. Cause this to happen by -+ * simply not advertising ourselves as being in_mwait. -+ */ -+ alternative_io("movb $1, %[in_mwait]", -+ "", X86_BUG_MONITOR, -+ [in_mwait] "=m" (stat->in_mwait)); - - monitor(this_softirq_pending, 0, 0); - -@@ -467,6 +481,10 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - mwait(eax, ecx); - spec_ctrl_exit_idle(info); - } -+ -+ alternative_io("movb $0, %[in_mwait]", -+ "", X86_BUG_MONITOR, -+ [in_mwait] "=m" (stat->in_mwait)); - } - - static void acpi_processor_ffh_cstate_enter(struct acpi_processor_cx *cx) -diff --git a/xen/arch/x86/include/asm/hardirq.h b/xen/arch/x86/include/asm/hardirq.h -index f3e93cc9b507..1647cff04dc8 100644 ---- a/xen/arch/x86/include/asm/hardirq.h -+++ b/xen/arch/x86/include/asm/hardirq.h -@@ -5,7 +5,19 @@ - #include - - typedef struct { -- unsigned int __softirq_pending; -+ /* -+ * The layout is important. Any CPU can set bits in __softirq_pending, -+ * but in_mwait is a status bit owned by the CPU. softirq_mwait_raw must -+ * cover both, and must be in a single cacheline. -+ */ -+ union { -+ struct { -+ unsigned int __softirq_pending; -+ bool in_mwait; -+ }; -+ uint64_t softirq_mwait_raw; -+ }; -+ - unsigned int __local_irq_count; - unsigned int nmi_count; - unsigned int mce_count; -diff --git a/xen/arch/x86/include/asm/softirq.h b/xen/arch/x86/include/asm/softirq.h -index e4b194f069fb..55b65c9747b1 100644 ---- a/xen/arch/x86/include/asm/softirq.h -+++ b/xen/arch/x86/include/asm/softirq.h -@@ -1,6 +1,8 @@ - #ifndef __ASM_SOFTIRQ_H__ - #define __ASM_SOFTIRQ_H__ - -+#include -+ - #define NMI_SOFTIRQ (NR_COMMON_SOFTIRQS + 0) - #define TIME_CALIBRATE_SOFTIRQ (NR_COMMON_SOFTIRQS + 1) - #define VCPU_KICK_SOFTIRQ (NR_COMMON_SOFTIRQS + 2) -@@ -9,4 +11,50 @@ - #define HVM_DPCI_SOFTIRQ (NR_COMMON_SOFTIRQS + 4) - #define NR_ARCH_SOFTIRQS 5 - -+/* -+ * Ensure softirq @nr is pending on @cpu. Return true if an IPI can be -+ * skipped, false if the IPI cannot be skipped. -+ * -+ * We use a CMPXCHG covering both __softirq_pending and in_mwait, in order to -+ * set softirq @nr while also observing in_mwait in a race-free way. -+ */ -+static always_inline bool arch_set_softirq(unsigned int nr, unsigned int cpu) -+{ -+ uint64_t *ptr = &irq_stat[cpu].softirq_mwait_raw; -+ uint64_t prev, old, new; -+ unsigned int softirq = 1U << nr; -+ -+ old = ACCESS_ONCE(*ptr); -+ -+ for ( ;; ) -+ { -+ if ( old & softirq ) -+ /* Softirq already pending, nothing to do. */ -+ return true; -+ -+ new = old | softirq; -+ -+ prev = cmpxchg(ptr, old, new); -+ if ( prev == old ) -+ break; -+ -+ old = prev; -+ } -+ -+ /* -+ * We have caused the softirq to become pending. If in_mwait was set, the -+ * target CPU will notice the modification and act on it. -+ * -+ * We can't access the in_mwait field nicely, so use some BUILD_BUG_ON()'s -+ * to cross-check the (1UL << 32) opencoding. -+ */ -+ BUILD_BUG_ON(sizeof(irq_stat[0].softirq_mwait_raw) != 8); -+ BUILD_BUG_ON((offsetof(irq_cpustat_t, in_mwait) - -+ offsetof(irq_cpustat_t, softirq_mwait_raw)) != 4); -+ -+ return new & (1UL << 32) /* in_mwait */; -+ -+} -+#define arch_set_softirq arch_set_softirq -+ - #endif /* __ASM_SOFTIRQ_H__ */ --- -2.49.0 - diff --git a/0510-x86-idle-Fix-buggy-x86-mwait-idle-enable-interrupts-.patch b/0510-x86-idle-Fix-buggy-x86-mwait-idle-enable-interrupts-.patch deleted file mode 100644 index aae704ff..00000000 --- a/0510-x86-idle-Fix-buggy-x86-mwait-idle-enable-interrupts-.patch +++ /dev/null @@ -1,87 +0,0 @@ -From 67bb8f699dfaea3f6de0d7110b22b1bdfc2d838a Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Wed, 2 Jul 2025 14:51:38 +0100 -Subject: [PATCH] x86/idle: Fix buggy "x86/mwait-idle: enable interrupts before - C1 on Xeons" - -The check of this_softirq_pending must be performed with irqs disabled, but -this property was broken by an attempt to optimise entry/exit latency. - -Commit c227233ad64c in Linux (which we copied into Xen) was fixed up by -edc8fc01f608 in Linux, which we have so far missed. - -Going to sleep without waking on interrupts is nonsensical outside of -play_dead(), so overload this to select between two possible MWAITs, the -second using the STI shadow to cover MWAIT for exactly the same reason as we -do in safe_halt(). - -Fixes: b17e0ec72ede ("x86/mwait-idle: enable interrupts before C1 on Xeons") -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 9b0f0f6e235618c2764e925b58c4bfe412730ced) ---- - xen/arch/x86/acpi/cpu_idle.c | 16 +++++++++++++++- - xen/arch/x86/cpu/mwait-idle.c | 8 ++------ - 2 files changed, 17 insertions(+), 7 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 176df1ed174f..69857a58ef5a 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -79,6 +79,13 @@ static always_inline void mwait(unsigned int eax, unsigned int ecx) - :: "a" (eax), "c" (ecx) ); - } - -+static always_inline void sti_mwait_cli(unsigned int eax, unsigned int ecx) -+{ -+ /* STI shadow covers MWAIT. */ -+ asm volatile ( "sti; mwait; cli" -+ :: "a" (eax), "c" (ecx) ); -+} -+ - #define GET_HW_RES_IN_NS(msr, val) \ - do { rdmsrl(msr, val); val = tsc_ticks2ns(val); } while( 0 ) - #define GET_MC6_RES(val) GET_HW_RES_IN_NS(0x664, val) -@@ -473,12 +480,19 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - - monitor(this_softirq_pending, 0, 0); - -+ ASSERT(!local_irq_is_enabled()); -+ - if ( !*this_softirq_pending ) - { - struct cpu_info *info = get_cpu_info(); - - spec_ctrl_enter_idle(info); -- mwait(eax, ecx); -+ -+ if ( ecx & MWAIT_ECX_INTERRUPT_BREAK ) -+ mwait(eax, ecx); -+ else -+ sti_mwait_cli(eax, ecx); -+ - spec_ctrl_exit_idle(info); - } - -diff --git a/xen/arch/x86/cpu/mwait-idle.c b/xen/arch/x86/cpu/mwait-idle.c -index 182518528a6e..3c63f0d45a11 100644 ---- a/xen/arch/x86/cpu/mwait-idle.c -+++ b/xen/arch/x86/cpu/mwait-idle.c -@@ -962,12 +962,8 @@ static void cf_check mwait_idle(void) - - update_last_cx_stat(power, cx, before); - -- if (cx->irq_enable_early) -- local_irq_enable(); -- -- mwait_idle_with_hints(cx->address, MWAIT_ECX_INTERRUPT_BREAK); -- -- local_irq_disable(); -+ mwait_idle_with_hints(cx->address, -+ cx->irq_enable_early ? 0 : MWAIT_ECX_INTERRUPT_BREAK); - - after = alternative_call(cpuidle_get_tick); - --- -2.49.0 - diff --git a/0511-x86-cpu-policy-Rearrange-guest_common_-_feature_adju.patch b/0511-x86-cpu-policy-Rearrange-guest_common_-_feature_adju.patch deleted file mode 100644 index 8357a954..00000000 --- a/0511-x86-cpu-policy-Rearrange-guest_common_-_feature_adju.patch +++ /dev/null @@ -1,136 +0,0 @@ -From d45dfbcbc6797d038eca754aa2fe19d0b93a67b4 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Fri, 27 Jun 2025 17:19:19 +0100 -Subject: [PATCH] x86/cpu-policy: Rearrange - guest_common_*_feature_adjustments() - -Turn the if()s into switch()es, as we're going to need AMD sections. - -Move the RTM adjustments into the Intel section, where they ought to live. - -No functional change. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 7c5025394dafe4b788ff9e1afc688f6becab9300) ---- - xen/arch/x86/cpu-policy.c | 69 +++++++++++++++++++++------------------ - 1 file changed, 37 insertions(+), 32 deletions(-) - -diff --git a/xen/arch/x86/cpu-policy.c b/xen/arch/x86/cpu-policy.c -index e34cba189c75..af2b4d7fa000 100644 ---- a/xen/arch/x86/cpu-policy.c -+++ b/xen/arch/x86/cpu-policy.c -@@ -415,8 +415,9 @@ static void __init guest_common_default_leaves(struct cpu_policy *p) - - static void __init guest_common_max_feature_adjustments(uint32_t *fs) - { -- if ( boot_cpu_data.x86_vendor == X86_VENDOR_INTEL ) -+ switch ( boot_cpu_data.x86_vendor ) - { -+ case X86_VENDOR_INTEL: - /* - * MSR_ARCH_CAPS is just feature data, and we can offer it to guests - * unconditionally, although limit it to Intel systems as it is highly -@@ -461,6 +462,22 @@ static void __init guest_common_max_feature_adjustments(uint32_t *fs) - boot_cpu_data.x86_model == INTEL_FAM6_SKYLAKE_X && - raw_cpu_policy.feat.clwb ) - __set_bit(X86_FEATURE_CLWB, fs); -+ -+ /* -+ * To mitigate Native-BHI, one option is to use a TSX Abort on capable -+ * systems. This is safe even if RTM has been disabled for other -+ * reasons via MSR_TSX_{CTRL,FORCE_ABORT}. However, a guest kernel -+ * doesn't get to know this type of information. -+ * -+ * Therefore the meaning of RTM_ALWAYS_ABORT has been adjusted, to -+ * instead mean "XBEGIN won't fault". This is enough for a guest -+ * kernel to make an informed choice WRT mitigating Native-BHI. -+ * -+ * If RTM-capable, we can run a VM which has seen RTM_ALWAYS_ABORT. -+ */ -+ if ( test_bit(X86_FEATURE_RTM, fs) ) -+ __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); -+ break; - } - - /* -@@ -472,27 +489,13 @@ static void __init guest_common_max_feature_adjustments(uint32_t *fs) - */ - __set_bit(X86_FEATURE_HTT, fs); - __set_bit(X86_FEATURE_CMP_LEGACY, fs); -- -- /* -- * To mitigate Native-BHI, one option is to use a TSX Abort on capable -- * systems. This is safe even if RTM has been disabled for other reasons -- * via MSR_TSX_{CTRL,FORCE_ABORT}. However, a guest kernel doesn't get to -- * know this type of information. -- * -- * Therefore the meaning of RTM_ALWAYS_ABORT has been adjusted, to instead -- * mean "XBEGIN won't fault". This is enough for a guest kernel to make -- * an informed choice WRT mitigating Native-BHI. -- * -- * If RTM-capable, we can run a VM which has seen RTM_ALWAYS_ABORT. -- */ -- if ( test_bit(X86_FEATURE_RTM, fs) ) -- __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); - } - - static void __init guest_common_default_feature_adjustments(uint32_t *fs) - { -- if ( boot_cpu_data.x86_vendor == X86_VENDOR_INTEL ) -+ switch ( boot_cpu_data.x86_vendor ) - { -+ case X86_VENDOR_INTEL: - /* - * IvyBridge client parts suffer from leakage of RDRAND data due to SRBDS - * (XSA-320 / CVE-2020-0543), and won't be receiving microcode to -@@ -536,6 +539,23 @@ static void __init guest_common_default_feature_adjustments(uint32_t *fs) - boot_cpu_data.x86_model == INTEL_FAM6_SKYLAKE_X && - raw_cpu_policy.feat.clwb ) - __clear_bit(X86_FEATURE_CLWB, fs); -+ -+ /* -+ * On certain hardware, speculative or errata workarounds can result -+ * in TSX being placed in "force-abort" mode, where it doesn't -+ * actually function as expected, but is technically compatible with -+ * the ISA. -+ * -+ * Do not advertise RTM to guests by default if it won't actually -+ * work. Instead, advertise RTM_ALWAYS_ABORT indicating that TSX -+ * Aborts are safe to use, e.g. for mitigating Native-BHI. -+ */ -+ if ( rtm_disabled ) -+ { -+ __clear_bit(X86_FEATURE_RTM, fs); -+ __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); -+ } -+ break; - } - - /* -@@ -547,21 +567,6 @@ static void __init guest_common_default_feature_adjustments(uint32_t *fs) - - if ( !cpu_has_cmp_legacy ) - __clear_bit(X86_FEATURE_CMP_LEGACY, fs); -- -- /* -- * On certain hardware, speculative or errata workarounds can result in -- * TSX being placed in "force-abort" mode, where it doesn't actually -- * function as expected, but is technically compatible with the ISA. -- * -- * Do not advertise RTM to guests by default if it won't actually work. -- * Instead, advertise RTM_ALWAYS_ABORT indicating that TSX Aborts are safe -- * to use, e.g. for mitigating Native-BHI. -- */ -- if ( rtm_disabled ) -- { -- __clear_bit(X86_FEATURE_RTM, fs); -- __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); -- } - } - - static void __init guest_common_feature_adjustments(uint32_t *fs) --- -2.49.0 - diff --git a/0512-x86-cpu-policy-Infrastructure-for-CPUID-leaf-0x80000.patch b/0512-x86-cpu-policy-Infrastructure-for-CPUID-leaf-0x80000.patch deleted file mode 100644 index 4623ad34..00000000 --- a/0512-x86-cpu-policy-Infrastructure-for-CPUID-leaf-0x80000.patch +++ /dev/null @@ -1,130 +0,0 @@ -From 04f7239699d12703dedb2aae06c1199a42218e27 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Tue, 10 Sep 2024 19:55:15 +0100 -Subject: [PATCH] x86/cpu-policy: Infrastructure for CPUID leaf 0x80000021.ecx - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 6e3c3cea091b3eacd85543af2ee7f33acab65a17) ---- - tools/libs/light/libxl_cpuid.c | 1 + - tools/misc/xen-cpuid.c | 1 + - xen/arch/x86/cpu-policy.c | 1 - - xen/arch/x86/cpu/common.c | 4 +++- - xen/include/public/arch-x86/cpufeatureset.h | 2 ++ - xen/include/xen/lib/x86/cpu-policy.h | 7 ++++++- - xen/lib/x86/cpuid.c | 2 ++ - 7 files changed, 15 insertions(+), 3 deletions(-) - -diff --git a/tools/libs/light/libxl_cpuid.c b/tools/libs/light/libxl_cpuid.c -index 063fe86eb72f..f738e17b19e4 100644 ---- a/tools/libs/light/libxl_cpuid.c -+++ b/tools/libs/light/libxl_cpuid.c -@@ -342,6 +342,7 @@ int libxl_cpuid_parse_config(libxl_cpuid_policy_list *policy, const char* str) - CPUID_ENTRY(0x00000007, 1, CPUID_REG_EDX), - MSR_ENTRY(0x10a, CPUID_REG_EAX), - MSR_ENTRY(0x10a, CPUID_REG_EDX), -+ CPUID_ENTRY(0x80000021, NA, CPUID_REG_ECX), - #undef MSR_ENTRY - #undef CPUID_ENTRY - }; -diff --git a/tools/misc/xen-cpuid.c b/tools/misc/xen-cpuid.c -index 4c4593528dfe..8e36b8e69600 100644 ---- a/tools/misc/xen-cpuid.c -+++ b/tools/misc/xen-cpuid.c -@@ -37,6 +37,7 @@ static const struct { - { "CPUID 0x00000007:1.edx", "7d1" }, - { "MSR_ARCH_CAPS.lo", "m10Al" }, - { "MSR_ARCH_CAPS.hi", "m10Ah" }, -+ { "CPUID 0x80000021.ecx", "e21c" }, - }; - - #define COL_ALIGN "24" -diff --git a/xen/arch/x86/cpu-policy.c b/xen/arch/x86/cpu-policy.c -index af2b4d7fa000..f40b25c91681 100644 ---- a/xen/arch/x86/cpu-policy.c -+++ b/xen/arch/x86/cpu-policy.c -@@ -327,7 +327,6 @@ static void recalculate_misc(struct cpu_policy *p) - p->extd.raw[0x1f] = EMPTY_LEAF; /* SEV */ - p->extd.raw[0x20] = EMPTY_LEAF; /* Platform QoS */ - p->extd.raw[0x21].b = 0; -- p->extd.raw[0x21].c = 0; - p->extd.raw[0x21].d = 0; - break; - } -diff --git a/xen/arch/x86/cpu/common.c b/xen/arch/x86/cpu/common.c -index ff4cd2289797..d4d21da9c560 100644 ---- a/xen/arch/x86/cpu/common.c -+++ b/xen/arch/x86/cpu/common.c -@@ -479,7 +479,9 @@ static void generic_identify(struct cpuinfo_x86 *c) - if (c->extended_cpuid_level >= 0x80000008) - c->x86_capability[FEATURESET_e8b] = cpuid_ebx(0x80000008); - if (c->extended_cpuid_level >= 0x80000021) -- c->x86_capability[FEATURESET_e21a] = cpuid_eax(0x80000021); -+ cpuid(0x80000021, -+ &c->x86_capability[FEATURESET_e21a], &tmp, -+ &c->x86_capability[FEATURESET_e21c], &tmp); - - /* Intel-defined flags: level 0x00000007 */ - if (c->cpuid_level >= 7) { -diff --git a/xen/include/public/arch-x86/cpufeatureset.h b/xen/include/public/arch-x86/cpufeatureset.h -index 3a2b646f0268..03acd49387aa 100644 ---- a/xen/include/public/arch-x86/cpufeatureset.h -+++ b/xen/include/public/arch-x86/cpufeatureset.h -@@ -369,6 +369,8 @@ XEN_CPUFEATURE(RFDS_CLEAR, 16*32+28) /*!A| Register File(s) cleared by V - XEN_CPUFEATURE(PB_OPT_CTRL, 16*32+32) /* MSR_PB_OPT_CTRL.IBPB_ALT */ - XEN_CPUFEATURE(ITS_NO, 16*32+62) /*!A No Indirect Target Selection */ - -+/* AMD-defined CPU features, CPUID level 0x80000021.ecx, word 18 */ -+ - #endif /* XEN_CPUFEATURE */ - - /* Clean up from a default include. Close the enum (for C). */ -diff --git a/xen/include/xen/lib/x86/cpu-policy.h b/xen/include/xen/lib/x86/cpu-policy.h -index 753ac78114da..ae0db6f3e16f 100644 ---- a/xen/include/xen/lib/x86/cpu-policy.h -+++ b/xen/include/xen/lib/x86/cpu-policy.h -@@ -22,6 +22,7 @@ - #define FEATURESET_7d1 15 /* 0x00000007:1.edx */ - #define FEATURESET_m10Al 16 /* 0x0000010a.eax */ - #define FEATURESET_m10Ah 17 /* 0x0000010a.edx */ -+#define FEATURESET_e21c 18 /* 0x80000021.ecx */ - - struct cpuid_leaf - { -@@ -328,7 +329,11 @@ struct cpu_policy - uint16_t ucode_size; /* Units of 16 bytes */ - uint8_t rap_size; /* Units of 8 entries */ - uint8_t :8; -- uint32_t /* c */:32, /* d */:32; -+ union { -+ uint32_t e21c; -+ struct { DECL_BITFIELD(e21c); }; -+ }; -+ uint32_t /* d */:32; - }; - } extd; - -diff --git a/xen/lib/x86/cpuid.c b/xen/lib/x86/cpuid.c -index eb7698dc7325..6298d051f2a6 100644 ---- a/xen/lib/x86/cpuid.c -+++ b/xen/lib/x86/cpuid.c -@@ -81,6 +81,7 @@ void x86_cpu_policy_to_featureset( - fs[FEATURESET_7d1] = p->feat._7d1; - fs[FEATURESET_m10Al] = p->arch_caps.lo; - fs[FEATURESET_m10Ah] = p->arch_caps.hi; -+ fs[FEATURESET_e21c] = p->extd.e21c; - } - - void x86_cpu_featureset_to_policy( -@@ -104,6 +105,7 @@ void x86_cpu_featureset_to_policy( - p->feat._7d1 = fs[FEATURESET_7d1]; - p->arch_caps.lo = fs[FEATURESET_m10Al]; - p->arch_caps.hi = fs[FEATURESET_m10Ah]; -+ p->extd.e21c = fs[FEATURESET_e21c]; - } - - void x86_cpu_policy_recalc_synth(struct cpu_policy *p) --- -2.49.0 - diff --git a/0513-x86-ucode-Digests-for-TSA-microcode.patch b/0513-x86-ucode-Digests-for-TSA-microcode.patch deleted file mode 100644 index 2522a12e..00000000 --- a/0513-x86-ucode-Digests-for-TSA-microcode.patch +++ /dev/null @@ -1,307 +0,0 @@ -From 0ce518bf52027a52a8da5cb7fb0464a502c3cfa5 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Fri, 27 Sep 2024 11:28:39 +0100 -Subject: [PATCH] x86/ucode: Digests for TSA microcode - -AMD are releasing microcode for TSA, so extend the known-provenance list with -their hashes. These were produced before the remediation of the microcode -signature issues (the entrysign vulnerability), so can be OS-loaded on -out-of-date firmware. - -Include an off-by-default check for the sorted-ness of patch_digests[]. It's -not worth running generally under SELF_TESTS, but is useful when editing the -digest list. - -This is part of XSA-471 / CVE-2024-36350 / CVE-2024-36357. - -Signed-off-by: Andrew Cooper -Acked-by: Jan Beulich -(cherry picked from commit a8708ea8bd4eefa7b4d0d04c5b775d264bdae14c) ---- - .../x86/cpu/microcode/amd-patch-digests.c | 144 ++++++++++++++++++ - xen/arch/x86/cpu/microcode/amd.c | 15 ++ - 2 files changed, 159 insertions(+) - -diff --git a/xen/arch/x86/cpu/microcode/amd-patch-digests.c b/xen/arch/x86/cpu/microcode/amd-patch-digests.c -index d32761226712..d2c4e0178a1e 100644 ---- a/xen/arch/x86/cpu/microcode/amd-patch-digests.c -+++ b/xen/arch/x86/cpu/microcode/amd-patch-digests.c -@@ -80,6 +80,15 @@ - 0x0d, 0x5b, 0x65, 0x34, 0x69, 0xb2, 0x62, 0x21, - }, - }, -+{ -+ .patch_id = 0x0a0011d7, -+ .digest = { -+ 0x35, 0x07, 0xcd, 0x40, 0x94, 0xbc, 0x81, 0x6b, -+ 0xfc, 0x61, 0x56, 0x1a, 0xe2, 0xdb, 0x96, 0x12, -+ 0x1c, 0x1c, 0x31, 0xb1, 0x02, 0x6f, 0xe5, 0xd2, -+ 0xfe, 0x1b, 0x04, 0x03, 0x2c, 0x8f, 0x4c, 0x36, -+ }, -+}, - { - .patch_id = 0x0a001238, - .digest = { -@@ -89,6 +98,15 @@ - 0xc0, 0xcd, 0x33, 0xf2, 0x8d, 0xf9, 0xef, 0x59, - }, - }, -+{ -+ .patch_id = 0x0a00123b, -+ .digest = { -+ 0xef, 0xa1, 0x1e, 0x71, 0xf1, 0xc3, 0x2c, 0xe2, -+ 0xc3, 0xef, 0x69, 0x41, 0x7a, 0x54, 0xca, 0xc3, -+ 0x8f, 0x62, 0x84, 0xee, 0xc2, 0x39, 0xd9, 0x28, -+ 0x95, 0xa7, 0x12, 0x49, 0x1e, 0x30, 0x71, 0x72, -+ }, -+}, - { - .patch_id = 0x0a00820c, - .digest = { -@@ -98,6 +116,15 @@ - 0xe1, 0x3b, 0x8d, 0xb2, 0xf8, 0x22, 0x03, 0xe2, - }, - }, -+{ -+ .patch_id = 0x0a00820d, -+ .digest = { -+ 0xf9, 0x2a, 0xc0, 0xf4, 0x9e, 0xa4, 0x87, 0xa4, -+ 0x7d, 0x87, 0x00, 0xfd, 0xab, 0xda, 0x19, 0xca, -+ 0x26, 0x51, 0x32, 0xc1, 0x57, 0x91, 0xdf, 0xc1, -+ 0x05, 0xeb, 0x01, 0x7c, 0x5a, 0x95, 0x21, 0xb7, -+ }, -+}, - { - .patch_id = 0x0a101148, - .digest = { -@@ -107,6 +134,15 @@ - 0xf1, 0x5e, 0xb0, 0xde, 0xb4, 0x98, 0xae, 0xc4, - }, - }, -+{ -+ .patch_id = 0x0a10114c, -+ .digest = { -+ 0x9e, 0xb6, 0xa2, 0xd9, 0x87, 0x38, 0xc5, 0x64, -+ 0xd8, 0x88, 0xfa, 0x78, 0x98, 0xf9, 0x6f, 0x74, -+ 0x39, 0x90, 0x1b, 0xa5, 0xcf, 0x5e, 0xb4, 0x2a, -+ 0x02, 0xff, 0xd4, 0x8c, 0x71, 0x8b, 0xe2, 0xc0, -+ }, -+}, - { - .patch_id = 0x0a101248, - .digest = { -@@ -116,6 +152,15 @@ - 0x1b, 0x7d, 0x64, 0x9d, 0x4b, 0x53, 0x13, 0x75, - }, - }, -+{ -+ .patch_id = 0x0a10124c, -+ .digest = { -+ 0x29, 0xea, 0xf1, 0x2c, 0xb2, 0xe4, 0xef, 0x90, -+ 0xa4, 0xcd, 0x1d, 0x86, 0x97, 0x17, 0x61, 0x46, -+ 0xfc, 0x22, 0xcb, 0x57, 0x75, 0x19, 0xc8, 0xcc, -+ 0x0c, 0xf5, 0xbc, 0xac, 0x81, 0x9d, 0x9a, 0xd2, -+ }, -+}, - { - .patch_id = 0x0a108108, - .digest = { -@@ -125,6 +170,15 @@ - 0x28, 0x1e, 0x9c, 0x59, 0x69, 0x99, 0x4d, 0x16, - }, - }, -+{ -+ .patch_id = 0x0a108109, -+ .digest = { -+ 0x85, 0xb4, 0xbd, 0x7c, 0x49, 0xa7, 0xbd, 0xfa, -+ 0x49, 0x36, 0x80, 0x81, 0xc5, 0xb7, 0x39, 0x1b, -+ 0x9a, 0xaa, 0x50, 0xde, 0x9b, 0xe9, 0x32, 0x35, -+ 0x42, 0x7e, 0x51, 0x4f, 0x52, 0x2c, 0x28, 0x59, -+ }, -+}, - { - .patch_id = 0x0a20102d, - .digest = { -@@ -134,6 +188,15 @@ - 0x8c, 0xe9, 0x19, 0x3e, 0xcc, 0x3f, 0x7b, 0xb4, - }, - }, -+{ -+ .patch_id = 0x0a20102e, -+ .digest = { -+ 0xbe, 0x1f, 0x32, 0x04, 0x0d, 0x3c, 0x9c, 0xdd, -+ 0xe1, 0xa4, 0xbf, 0x76, 0x3a, 0xec, 0xc2, 0xf6, -+ 0x11, 0x00, 0xa7, 0xaf, 0x0f, 0xe5, 0x02, 0xc5, -+ 0x54, 0x3a, 0x1f, 0x8c, 0x16, 0xb5, 0xff, 0xbe, -+ }, -+}, - { - .patch_id = 0x0a201210, - .digest = { -@@ -143,6 +206,15 @@ - 0xf7, 0x55, 0xf0, 0x13, 0xbb, 0x22, 0xf6, 0x41, - }, - }, -+{ -+ .patch_id = 0x0a201211, -+ .digest = { -+ 0x69, 0xa1, 0x17, 0xec, 0xd0, 0xf6, 0x6c, 0x95, -+ 0xe2, 0x1e, 0xc5, 0x59, 0x1a, 0x52, 0x0a, 0x27, -+ 0xc4, 0xed, 0xd5, 0x59, 0x1f, 0xbf, 0x00, 0xff, -+ 0x08, 0x88, 0xb5, 0xe1, 0x12, 0xb6, 0xcc, 0x27, -+ }, -+}, - { - .patch_id = 0x0a404107, - .digest = { -@@ -152,6 +224,15 @@ - 0x13, 0xbc, 0xc5, 0x25, 0xe4, 0xc5, 0xc3, 0x99, - }, - }, -+{ -+ .patch_id = 0x0a404108, -+ .digest = { -+ 0x69, 0x67, 0x43, 0x06, 0xf8, 0x0c, 0x62, 0xdc, -+ 0xa4, 0x21, 0x30, 0x4f, 0x0f, 0x21, 0x2c, 0xcb, -+ 0xcc, 0x37, 0xf1, 0x1c, 0xc3, 0xf8, 0x2f, 0x19, -+ 0xdf, 0x53, 0x53, 0x46, 0xb1, 0x15, 0xea, 0x00, -+ }, -+}, - { - .patch_id = 0x0a500011, - .digest = { -@@ -161,6 +242,15 @@ - 0x11, 0x5e, 0x96, 0x7e, 0x71, 0xe9, 0xfc, 0x74, - }, - }, -+{ -+ .patch_id = 0x0a500012, -+ .digest = { -+ 0xeb, 0x74, 0x0d, 0x47, 0xa1, 0x8e, 0x09, 0xe4, -+ 0x93, 0x4c, 0xad, 0x03, 0x32, 0x4c, 0x38, 0x16, -+ 0x10, 0x39, 0xdd, 0x06, 0xaa, 0xce, 0xd6, 0x0f, -+ 0x62, 0x83, 0x9d, 0x8e, 0x64, 0x55, 0xbe, 0x63, -+ }, -+}, - { - .patch_id = 0x0a601209, - .digest = { -@@ -170,6 +260,15 @@ - 0xe8, 0x73, 0xe2, 0xd6, 0xdb, 0xd2, 0x77, 0x1d, - }, - }, -+{ -+ .patch_id = 0x0a60120a, -+ .digest = { -+ 0x0c, 0x8b, 0x3d, 0xfd, 0x52, 0x52, 0x85, 0x7d, -+ 0x20, 0x3a, 0xe1, 0x7e, 0xa4, 0x21, 0x3b, 0x7b, -+ 0x17, 0x86, 0xae, 0xac, 0x13, 0xb8, 0x63, 0x9d, -+ 0x06, 0x01, 0xd0, 0xa0, 0x51, 0x9a, 0x91, 0x2c, -+ }, -+}, - { - .patch_id = 0x0a704107, - .digest = { -@@ -179,6 +278,15 @@ - 0x64, 0x39, 0x71, 0x8c, 0xce, 0xe7, 0x41, 0x39, - }, - }, -+{ -+ .patch_id = 0x0a704108, -+ .digest = { -+ 0xd7, 0x55, 0x15, 0x2b, 0xfe, 0xc4, 0xbc, 0x93, -+ 0xec, 0x91, 0xa0, 0xae, 0x45, 0xb7, 0xc3, 0x98, -+ 0x4e, 0xff, 0x61, 0x77, 0x88, 0xc2, 0x70, 0x49, -+ 0xe0, 0x3a, 0x1d, 0x84, 0x38, 0x52, 0xbf, 0x5a, -+ }, -+}, - { - .patch_id = 0x0a705206, - .digest = { -@@ -188,6 +296,15 @@ - 0x03, 0x35, 0xe9, 0xbe, 0xfb, 0x06, 0xdf, 0xfc, - }, - }, -+{ -+ .patch_id = 0x0a705208, -+ .digest = { -+ 0x30, 0x1d, 0x55, 0x24, 0xbc, 0x6b, 0x5a, 0x19, -+ 0x0c, 0x7d, 0x1d, 0x74, 0xaa, 0xd1, 0xeb, 0xd2, -+ 0x16, 0x62, 0xf7, 0x5b, 0xe1, 0x1f, 0x18, 0x11, -+ 0x5c, 0xf0, 0x94, 0x90, 0x26, 0xec, 0x69, 0xff, -+ }, -+}, - { - .patch_id = 0x0a708007, - .digest = { -@@ -197,6 +314,15 @@ - 0xdf, 0x92, 0x73, 0x84, 0x87, 0x3c, 0x73, 0x93, - }, - }, -+{ -+ .patch_id = 0x0a708008, -+ .digest = { -+ 0x08, 0x6e, 0xf0, 0x22, 0x4b, 0x8e, 0xc4, 0x46, -+ 0x58, 0x34, 0xe6, 0x47, 0xa2, 0x28, 0xfd, 0xab, -+ 0x22, 0x3d, 0xdd, 0xd8, 0x52, 0x9e, 0x1d, 0x16, -+ 0xfa, 0x01, 0x68, 0x14, 0x79, 0x3e, 0xe8, 0x6b, -+ }, -+}, - { - .patch_id = 0x0a70c005, - .digest = { -@@ -206,6 +332,15 @@ - 0xee, 0x49, 0xac, 0xe1, 0x8b, 0x13, 0xc5, 0x13, - }, - }, -+{ -+ .patch_id = 0x0a70c008, -+ .digest = { -+ 0x0f, 0xdb, 0x37, 0xa1, 0x10, 0xaf, 0xd4, 0x21, -+ 0x94, 0x0d, 0xa4, 0xa2, 0xe9, 0x86, 0x6c, 0x0e, -+ 0x85, 0x7c, 0x36, 0x30, 0xa3, 0x3a, 0x78, 0x66, -+ 0x18, 0x10, 0x60, 0x0d, 0x78, 0x3d, 0x44, 0xd0, -+ }, -+}, - { - .patch_id = 0x0aa00116, - .digest = { -@@ -224,3 +359,12 @@ - 0x68, 0x2f, 0x46, 0xee, 0xfe, 0xc6, 0x6d, 0xef, - }, - }, -+{ -+ .patch_id = 0x0aa00216, -+ .digest = { -+ 0x79, 0xfb, 0x5b, 0x9f, 0xb6, 0xe6, 0xa8, 0xf5, -+ 0x4e, 0x7c, 0x4f, 0x8e, 0x1d, 0xad, 0xd0, 0x08, -+ 0xc2, 0x43, 0x7c, 0x8b, 0xe6, 0xdb, 0xd0, 0xd2, -+ 0xe8, 0x39, 0x26, 0xc1, 0xe5, 0x5a, 0x48, 0xf1, -+ }, -+}, -diff --git a/xen/arch/x86/cpu/microcode/amd.c b/xen/arch/x86/cpu/microcode/amd.c -index 4f236e439929..f25d74fccba2 100644 ---- a/xen/arch/x86/cpu/microcode/amd.c -+++ b/xen/arch/x86/cpu/microcode/amd.c -@@ -521,3 +521,18 @@ void __init ucode_probe_amd(struct microcode_ops *ops) - - *ops = amd_ucode_ops; - } -+ -+#if 0 /* Manual CONFIG_SELF_TESTS */ -+static void __init __constructor test_digests_sorted(void) -+{ -+ for ( unsigned int i = 1; i < ARRAY_SIZE(patch_digests); ++i ) -+ { -+ if ( patch_digests[i - 1].patch_id < patch_digests[i].patch_id ) -+ continue; -+ -+ panic("patch_digests[] not sorted: %08x >= %08x\n", -+ patch_digests[i - 1].patch_id, -+ patch_digests[i].patch_id); -+ } -+} -+#endif /* CONFIG_SELF_TESTS */ --- -2.49.0 - diff --git a/0514-x86-idle-Rearrange-VERW-and-MONITOR-in-mwait_idle_wi.patch b/0514-x86-idle-Rearrange-VERW-and-MONITOR-in-mwait_idle_wi.patch deleted file mode 100644 index 1747de3e..00000000 --- a/0514-x86-idle-Rearrange-VERW-and-MONITOR-in-mwait_idle_wi.patch +++ /dev/null @@ -1,145 +0,0 @@ -From 4f8a624a3fd63f3819411d2caca12d1efcadd279 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Wed, 2 Apr 2025 03:18:59 +0100 -Subject: [PATCH] x86/idle: Rearrange VERW and MONITOR in - mwait_idle_with_hints() - -In order to mitigate TSA, Xen will need to issue VERW before going idle. - -On AMD CPUs, the VERW scrubbing side effects cancel an active MONITOR, causing -the MWAIT to exit without entering an idle state. Therefore the VERW must be -ahead of MONITOR. - -Split spec_ctrl_enter_idle() in two and allow the VERW aspect to be handled -separately. While adjusting, update a stale comment concerning MSBDS; more -issues have been mitigated using VERW since it was written. - -By moving VERW earlier, it is ahead of the determination of whether to go -idle. We can't move the check on softirq_pending (for correctness reasons), -but we can duplicate it earlier as a best effort attempt to skip the -speculative overhead. - -This is part of XSA-471 / CVE-2024-36350 / CVE-2024-36357. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 01429bbb0a6152281d2fdf26cd122ecdd1234d53) ---- - xen/arch/x86/acpi/cpu_idle.c | 19 +++++++++++--- - xen/arch/x86/include/asm/spec_ctrl.h | 39 ++++++++++++++++------------ - 2 files changed, 39 insertions(+), 19 deletions(-) - -diff --git a/xen/arch/x86/acpi/cpu_idle.c b/xen/arch/x86/acpi/cpu_idle.c -index 69857a58ef5a..1045d87eed12 100644 ---- a/xen/arch/x86/acpi/cpu_idle.c -+++ b/xen/arch/x86/acpi/cpu_idle.c -@@ -462,9 +462,18 @@ __initcall(cpu_idle_key_init); - void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - { - unsigned int cpu = smp_processor_id(); -+ struct cpu_info *info = get_cpu_info(); - irq_cpustat_t *stat = &irq_stat[cpu]; - const unsigned int *this_softirq_pending = &stat->__softirq_pending; - -+ /* -+ * Heuristic: if we're definitely not going to idle, bail early as the -+ * speculative safety can be expensive. This is a performance -+ * consideration not a correctness issue. -+ */ -+ if ( *this_softirq_pending ) -+ return; -+ - /* - * By setting in_mwait, we promise to other CPUs that we'll notice changes - * to __softirq_pending without being sent an IPI. We achieve this by -@@ -478,15 +487,19 @@ void mwait_idle_with_hints(unsigned int eax, unsigned int ecx) - "", X86_BUG_MONITOR, - [in_mwait] "=m" (stat->in_mwait)); - -+ /* -+ * On AMD systems, side effects from VERW cancel MONITOR, causing MWAIT to -+ * wake up immediately. Therefore, VERW must come ahead of MONITOR. -+ */ -+ __spec_ctrl_enter_idle_verw(info); -+ - monitor(this_softirq_pending, 0, 0); - - ASSERT(!local_irq_is_enabled()); - - if ( !*this_softirq_pending ) - { -- struct cpu_info *info = get_cpu_info(); -- -- spec_ctrl_enter_idle(info); -+ __spec_ctrl_enter_idle(info, false /* VERW handled above */); - - if ( ecx & MWAIT_ECX_INTERRUPT_BREAK ) - mwait(eax, ecx); -diff --git a/xen/arch/x86/include/asm/spec_ctrl.h b/xen/arch/x86/include/asm/spec_ctrl.h -index 077225418956..6724d3812029 100644 ---- a/xen/arch/x86/include/asm/spec_ctrl.h -+++ b/xen/arch/x86/include/asm/spec_ctrl.h -@@ -115,8 +115,22 @@ static inline void init_shadow_spec_ctrl_state(void) - info->verw_sel = __HYPERVISOR_DS32; - } - -+static always_inline void __spec_ctrl_enter_idle_verw(struct cpu_info *info) -+{ -+ /* -+ * Flush/scrub structures which are statically partitioned between active -+ * threads. Otherwise data of ours (of unknown sensitivity) will become -+ * available to our sibling when we go idle. -+ * -+ * Note: VERW must be encoded with a memory operand, as it is only that -+ * form with side effects. -+ */ -+ alternative_input("", "verw %[sel]", X86_FEATURE_SC_VERW_IDLE, -+ [sel] "m" (info->verw_sel)); -+} -+ - /* WARNING! `ret`, `call *`, `jmp *` not safe after this call. */ --static always_inline void spec_ctrl_enter_idle(struct cpu_info *info) -+static always_inline void __spec_ctrl_enter_idle(struct cpu_info *info, bool verw) - { - uint32_t val = 0; - -@@ -135,21 +149,8 @@ static always_inline void spec_ctrl_enter_idle(struct cpu_info *info) - "a" (val), "c" (MSR_SPEC_CTRL), "d" (0)); - barrier(); - -- /* -- * Microarchitectural Store Buffer Data Sampling: -- * -- * On vulnerable systems, store buffer entries are statically partitioned -- * between active threads. When entering idle, our store buffer entries -- * are re-partitioned to allow the other threads to use them. -- * -- * Flush the buffers to ensure that no sensitive data of ours can be -- * leaked by a sibling after it gets our store buffer entries. -- * -- * Note: VERW must be encoded with a memory operand, as it is only that -- * form which causes a flush. -- */ -- alternative_input("", "verw %[sel]", X86_FEATURE_SC_VERW_IDLE, -- [sel] "m" (info->verw_sel)); -+ if ( verw ) /* Expected to be const-propagated. */ -+ __spec_ctrl_enter_idle_verw(info); - - /* - * Cross-Thread Return Address Predictions: -@@ -167,6 +168,12 @@ static always_inline void spec_ctrl_enter_idle(struct cpu_info *info) - : "rax", "rcx"); - } - -+/* WARNING! `ret`, `call *`, `jmp *` not safe after this call. */ -+static always_inline void spec_ctrl_enter_idle(struct cpu_info *info) -+{ -+ __spec_ctrl_enter_idle(info, true /* VERW */); -+} -+ - /* WARNING! `ret`, `call *`, `jmp *` not safe before this call. */ - static always_inline void spec_ctrl_exit_idle(struct cpu_info *info) - { --- -2.49.0 - diff --git a/0515-x86-spec-ctrl-Mitigate-Transitive-Scheduler-Attacks.patch b/0515-x86-spec-ctrl-Mitigate-Transitive-Scheduler-Attacks.patch deleted file mode 100644 index c66c8afd..00000000 --- a/0515-x86-spec-ctrl-Mitigate-Transitive-Scheduler-Attacks.patch +++ /dev/null @@ -1,324 +0,0 @@ -From 5e9a7f0afad6e5761d8c08862939d409ce1bd758 Mon Sep 17 00:00:00 2001 -From: Andrew Cooper -Date: Thu, 29 Aug 2024 17:36:11 +0100 -Subject: [PATCH] x86/spec-ctrl: Mitigate Transitive Scheduler Attacks - -TSA affects AMD Fam19h CPUs (Zen3 and 4 microarchitectures). - -Three new CPUID bits have been defined. Two (TSA_SQ_NO and TSA_L1_NO) -indicate that the system is unaffected, and must be synthesised by Xen on -unaffected parts to date. - -A third new bit indicates that VERW now has a flushing side effect. Xen -must synthesise this bit on affected systems based on microcode version. -As with other VERW-based flushing features, VERW_CLEAR needs OR-ing across -a resource pool, and guests which have seen it can safely migrate in. - -This is part of XSA-471 / CVE-2024-36350 / CVE-2024-36357. - -Signed-off-by: Andrew Cooper -Reviewed-by: Jan Beulich -(cherry picked from commit 578b34adb1cc149dfeeb2491f84eed43fcd1ee2f) ---- - xen/arch/x86/cpu-policy.c | 22 ++++ - xen/arch/x86/hvm/svm/entry.S | 2 + - xen/arch/x86/include/asm/cpufeature.h | 5 + - xen/arch/x86/spec_ctrl.c | 114 +++++++++++++++++--- - xen/include/public/arch-x86/cpufeatureset.h | 3 + - 5 files changed, 134 insertions(+), 12 deletions(-) - -diff --git a/xen/arch/x86/cpu-policy.c b/xen/arch/x86/cpu-policy.c -index f40b25c91681..c594f05ea9b2 100644 ---- a/xen/arch/x86/cpu-policy.c -+++ b/xen/arch/x86/cpu-policy.c -@@ -477,6 +477,17 @@ static void __init guest_common_max_feature_adjustments(uint32_t *fs) - if ( test_bit(X86_FEATURE_RTM, fs) ) - __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); - break; -+ -+ case X86_VENDOR_AMD: -+ /* -+ * This bit indicates that the VERW instruction may have gained -+ * scrubbing side effects. With pooling, it means "you might migrate -+ * somewhere where scrubbing is necessary", and may need exposing on -+ * unaffected hardware. This is fine, because the VERW instruction -+ * has been around since the 286. -+ */ -+ __set_bit(X86_FEATURE_VERW_CLEAR, fs); -+ break; - } - - /* -@@ -555,6 +566,17 @@ static void __init guest_common_default_feature_adjustments(uint32_t *fs) - __set_bit(X86_FEATURE_RTM_ALWAYS_ABORT, fs); - } - break; -+ -+ case X86_VENDOR_AMD: -+ /* -+ * This bit indicate that the VERW instruction may have gained -+ * scrubbing side effects. The max policy has it set for migration -+ * reasons, so reset the default policy back to the host value in case -+ * we're unaffected. -+ */ -+ if ( !cpu_has_verw_clear ) -+ __clear_bit(X86_FEATURE_VERW_CLEAR, fs); -+ break; - } - - /* -diff --git a/xen/arch/x86/hvm/svm/entry.S b/xen/arch/x86/hvm/svm/entry.S -index 91edb3345938..610c64bf4c97 100644 ---- a/xen/arch/x86/hvm/svm/entry.S -+++ b/xen/arch/x86/hvm/svm/entry.S -@@ -99,6 +99,8 @@ __UNLIKELY_END(nsvm_hap) - pop %rsi - pop %rdi - -+ SPEC_CTRL_COND_VERW /* Req: %rsp=eframe Clob: efl */ -+ - vmrun - - SAVE_ALL -diff --git a/xen/arch/x86/include/asm/cpufeature.h b/xen/arch/x86/include/asm/cpufeature.h -index 5e1090a5470b..ad50e5356a49 100644 ---- a/xen/arch/x86/include/asm/cpufeature.h -+++ b/xen/arch/x86/include/asm/cpufeature.h -@@ -196,6 +196,7 @@ static inline bool boot_cpu_has(unsigned int feat) - - /* CPUID level 0x80000021.eax */ - #define cpu_has_lfence_dispatch boot_cpu_has(X86_FEATURE_LFENCE_DISPATCH) -+#define cpu_has_verw_clear boot_cpu_has(X86_FEATURE_VERW_CLEAR) - #define cpu_has_nscb boot_cpu_has(X86_FEATURE_NSCB) - - /* CPUID level 0x00000007:1.edx */ -@@ -223,6 +224,10 @@ static inline bool boot_cpu_has(unsigned int feat) - #define cpu_has_pb_opt_ctrl boot_cpu_has(X86_FEATURE_PB_OPT_CTRL) - #define cpu_has_its_no boot_cpu_has(X86_FEATURE_ITS_NO) - -+/* CPUID level 0x80000021.ecx */ -+#define cpu_has_tsa_sq_no boot_cpu_has(X86_FEATURE_TSA_SQ_NO) -+#define cpu_has_tsa_l1_no boot_cpu_has(X86_FEATURE_TSA_L1_NO) -+ - /* Synthesized. */ - #define cpu_has_arch_perfmon boot_cpu_has(X86_FEATURE_ARCH_PERFMON) - #define cpu_has_cpuid_faulting boot_cpu_has(X86_FEATURE_CPUID_FAULTING) -diff --git a/xen/arch/x86/spec_ctrl.c b/xen/arch/x86/spec_ctrl.c -index fa444caabb09..ef198c221139 100644 ---- a/xen/arch/x86/spec_ctrl.c -+++ b/xen/arch/x86/spec_ctrl.c -@@ -492,7 +492,7 @@ custom_param("pv-l1tf", parse_pv_l1tf); - - static void __init print_details(enum ind_thunk thunk) - { -- unsigned int _7d0 = 0, _7d2 = 0, e8b = 0, e21a = 0, max = 0, tmp; -+ unsigned int _7d0 = 0, _7d2 = 0, e8b = 0, e21a = 0, e21c = 0, max = 0, tmp; - uint64_t caps = 0; - - /* Collect diagnostics about available mitigations. */ -@@ -503,7 +503,7 @@ static void __init print_details(enum ind_thunk thunk) - if ( boot_cpu_data.extended_cpuid_level >= 0x80000008U ) - cpuid(0x80000008U, &tmp, &e8b, &tmp, &tmp); - if ( boot_cpu_data.extended_cpuid_level >= 0x80000021U ) -- cpuid(0x80000021U, &e21a, &tmp, &tmp, &tmp); -+ cpuid(0x80000021U, &e21a, &tmp, &e21c, &tmp); - if ( cpu_has_arch_caps ) - rdmsrl(MSR_ARCH_CAPABILITIES, caps); - -@@ -513,7 +513,7 @@ static void __init print_details(enum ind_thunk thunk) - * Hardware read-only information, stating immunity to certain issues, or - * suggestions of which mitigation to use. - */ -- printk(" Hardware hints:%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s\n", -+ printk(" Hardware hints:%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s\n", - (caps & ARCH_CAPS_RDCL_NO) ? " RDCL_NO" : "", - (caps & ARCH_CAPS_EIBRS) ? " EIBRS" : "", - (caps & ARCH_CAPS_RSBA) ? " RSBA" : "", -@@ -538,10 +538,12 @@ static void __init print_details(enum ind_thunk thunk) - (e8b & cpufeat_mask(X86_FEATURE_IBPB_RET)) ? " IBPB_RET" : "", - (e21a & cpufeat_mask(X86_FEATURE_IBPB_BRTYPE)) ? " IBPB_BRTYPE" : "", - (e21a & cpufeat_mask(X86_FEATURE_SRSO_NO)) ? " SRSO_NO" : "", -- (e21a & cpufeat_mask(X86_FEATURE_SRSO_US_NO)) ? " SRSO_US_NO" : ""); -+ (e21a & cpufeat_mask(X86_FEATURE_SRSO_US_NO)) ? " SRSO_US_NO" : "", -+ (e21c & cpufeat_mask(X86_FEATURE_TSA_SQ_NO)) ? " TSA_SQ_NO" : "", -+ (e21c & cpufeat_mask(X86_FEATURE_TSA_L1_NO)) ? " TSA_L1_NO" : ""); - - /* Hardware features which need driving to mitigate issues. */ -- printk(" Hardware features:%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s\n", -+ printk(" Hardware features:%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s%s\n", - (e8b & cpufeat_mask(X86_FEATURE_IBPB)) || - (_7d0 & cpufeat_mask(X86_FEATURE_IBRSB)) ? " IBPB" : "", - (e8b & cpufeat_mask(X86_FEATURE_IBRS)) || -@@ -561,7 +563,8 @@ static void __init print_details(enum ind_thunk thunk) - (caps & ARCH_CAPS_GDS_CTRL) ? " GDS_CTRL" : "", - (caps & ARCH_CAPS_RFDS_CLEAR) ? " RFDS_CLEAR" : "", - (e21a & cpufeat_mask(X86_FEATURE_SBPB)) ? " SBPB" : "", -- (e21a & cpufeat_mask(X86_FEATURE_SRSO_MSR_FIX)) ? " SRSO_MSR_FIX" : ""); -+ (e21a & cpufeat_mask(X86_FEATURE_SRSO_MSR_FIX)) ? " SRSO_MSR_FIX" : "", -+ (e21a & cpufeat_mask(X86_FEATURE_VERW_CLEAR)) ? " VERW_CLEAR" : ""); - - /* Compiled-in support which pertains to mitigations. */ - if ( IS_ENABLED(CONFIG_INDIRECT_THUNK) || IS_ENABLED(CONFIG_SHADOW_PAGING) || -@@ -1545,6 +1548,77 @@ static void __init rfds_calculations(void) - setup_force_cpu_cap(X86_FEATURE_RFDS_NO); - } - -+/* -+ * Transient Scheduler Attacks -+ * -+ * https://www.amd.com/content/dam/amd/en/documents/resources/bulletin/technical-guidance-for-mitigating-transient-scheduler-attacks.pdf -+ */ -+static void __init tsa_calculations(void) -+{ -+ unsigned int curr_rev, min_rev; -+ -+ /* TSA is only known to affect AMD processors at this time. */ -+ if ( boot_cpu_data.x86_vendor != X86_VENDOR_AMD ) -+ return; -+ -+ /* If we're virtualised, don't attempt to synthesise anything. */ -+ if ( cpu_has_hypervisor ) -+ return; -+ -+ /* -+ * According to the whitepaper, some Fam1A CPUs (Models 0x00...0x4f, -+ * 0x60...0x7f) are not vulnerable but don't enumerate TSA_{SQ,L1}_NO. If -+ * we see either enumerated, assume both are correct ... -+ */ -+ if ( cpu_has_tsa_sq_no || cpu_has_tsa_l1_no ) -+ return; -+ -+ /* -+ * ... otherwise, synthesise them. CPUs other than Fam19 (Zen3/4) are -+ * stated to be not vulnerable. -+ */ -+ if ( boot_cpu_data.x86 != 0x19 ) -+ { -+ setup_force_cpu_cap(X86_FEATURE_TSA_SQ_NO); -+ setup_force_cpu_cap(X86_FEATURE_TSA_L1_NO); -+ return; -+ } -+ -+ /* -+ * Fam19 CPUs get VERW_CLEAR with new enough microcode, but must -+ * synthesise the CPUID bit. -+ */ -+ curr_rev = this_cpu(cpu_sig).rev; -+ switch ( curr_rev >> 8 ) -+ { -+ case 0x0a0011: min_rev = 0x0a0011d7; break; -+ case 0x0a0012: min_rev = 0x0a00123b; break; -+ case 0x0a0082: min_rev = 0x0a00820d; break; -+ case 0x0a1011: min_rev = 0x0a10114c; break; -+ case 0x0a1012: min_rev = 0x0a10124c; break; -+ case 0x0a1081: min_rev = 0x0a108109; break; -+ case 0x0a2010: min_rev = 0x0a20102e; break; -+ case 0x0a2012: min_rev = 0x0a201211; break; -+ case 0x0a4041: min_rev = 0x0a404108; break; -+ case 0x0a5000: min_rev = 0x0a500012; break; -+ case 0x0a6012: min_rev = 0x0a60120a; break; -+ case 0x0a7041: min_rev = 0x0a704108; break; -+ case 0x0a7052: min_rev = 0x0a705208; break; -+ case 0x0a7080: min_rev = 0x0a708008; break; -+ case 0x0a70c0: min_rev = 0x0a70c008; break; -+ case 0x0aa002: min_rev = 0x0aa00216; break; -+ default: -+ printk(XENLOG_WARNING -+ "Unrecognised CPU %02x-%02x-%02x, ucode 0x%08x for TSA mitigation\n", -+ boot_cpu_data.x86, boot_cpu_data.x86_model, -+ boot_cpu_data.x86_mask, curr_rev); -+ return; -+ } -+ -+ if ( curr_rev >= min_rev ) -+ setup_force_cpu_cap(X86_FEATURE_VERW_CLEAR); -+} -+ - static bool __init cpu_has_gds(void) - { - /* -@@ -2238,6 +2312,7 @@ void __init init_speculation_mitigations(void) - * https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/intel-analysis-microarchitectural-data-sampling.html - * https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/processor-mmio-stale-data-vulnerabilities.html - * https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/register-file-data-sampling.html -+ * https://www.amd.com/content/dam/amd/en/documents/resources/bulletin/technical-guidance-for-mitigating-transient-scheduler-attacks.pdf - * - * Relevant ucodes: - * -@@ -2270,9 +2345,18 @@ void __init init_speculation_mitigations(void) - * - * - March 2023, for RFDS. Enumerate RFDS_CLEAR to mean that VERW now - * scrubs non-architectural entries from certain register files. -+ * -+ * - July 2025, for TSA. Introduces VERW side effects to mitigate -+ * TSA_{SQ/L1}. Xen must synthesise the VERW_CLEAR feature based on -+ * microcode version. -+ * -+ * Note, these microcode updates were produced before the remediation of -+ * the microcode signature issues, and are included in the firwmare -+ * updates fixing the entrysign vulnerability from ~December 2024. - */ - mds_calculations(); - rfds_calculations(); -+ tsa_calculations(); - - /* - * Parts which enumerate FB_CLEAR are those with now-updated microcode -@@ -2304,21 +2388,27 @@ void __init init_speculation_mitigations(void) - * MLPDS/MFBDS when SMT is enabled. - */ - if ( opt_verw_pv == -1 ) -- opt_verw_pv = cpu_has_useful_md_clear || cpu_has_rfds_clear; -+ opt_verw_pv = (cpu_has_useful_md_clear || cpu_has_rfds_clear || -+ cpu_has_verw_clear); - - if ( opt_verw_hvm == -1 ) -- opt_verw_hvm = cpu_has_useful_md_clear || cpu_has_rfds_clear; -+ opt_verw_hvm = (cpu_has_useful_md_clear || cpu_has_rfds_clear || -+ cpu_has_verw_clear); - - /* -- * If SMT is active, and we're protecting against MDS or MMIO stale data, -+ * If SMT is active, and we're protecting against any of: -+ * - MSBDS -+ * - MMIO stale data -+ * - TSA-SQ - * we need to scrub before going idle as well as on return to guest. - * Various pipeline resources are repartitioned amongst non-idle threads. - * -- * We don't need to scrub on idle for RFDS. There are no affected cores -- * which support SMT, despite there being affected cores in hybrid systems -- * which have SMT elsewhere in the platform. -+ * We don't need to scrub on idle for: -+ * - RFDS (no SMT affected cores) -+ * - TSA-L1 (utags never shared between threads) - */ - if ( ((cpu_has_useful_md_clear && (opt_verw_pv || opt_verw_hvm)) || -+ (cpu_has_verw_clear && !cpu_has_tsa_sq_no) || - opt_verw_mmio) && hw_smt_enabled ) - setup_force_cpu_cap(X86_FEATURE_SC_VERW_IDLE); - -diff --git a/xen/include/public/arch-x86/cpufeatureset.h b/xen/include/public/arch-x86/cpufeatureset.h -index 03acd49387aa..4ea6d95c7ac6 100644 ---- a/xen/include/public/arch-x86/cpufeatureset.h -+++ b/xen/include/public/arch-x86/cpufeatureset.h -@@ -302,6 +302,7 @@ XEN_CPUFEATURE(AVX_IFMA, 10*32+23) /*A AVX-IFMA Instructions */ - XEN_CPUFEATURE(NO_NEST_BP, 11*32+ 0) /*A No Nested Data Breakpoints */ - XEN_CPUFEATURE(FS_GS_NS, 11*32+ 1) /*S| FS/GS base MSRs non-serialising */ - XEN_CPUFEATURE(LFENCE_DISPATCH, 11*32+ 2) /*A LFENCE always serializing */ -+XEN_CPUFEATURE(VERW_CLEAR, 11*32+ 5) /*!A| VERW clears microarchitectural buffers */ - XEN_CPUFEATURE(NSCB, 11*32+ 6) /*A Null Selector Clears Base (and limit too) */ - XEN_CPUFEATURE(AUTO_IBRS, 11*32+ 8) /*S Automatic IBRS */ - XEN_CPUFEATURE(AMD_FSRS, 11*32+10) /*A Fast Short REP STOSB */ -@@ -370,6 +371,8 @@ XEN_CPUFEATURE(PB_OPT_CTRL, 16*32+32) /* MSR_PB_OPT_CTRL.IBPB_ALT */ - XEN_CPUFEATURE(ITS_NO, 16*32+62) /*!A No Indirect Target Selection */ - - /* AMD-defined CPU features, CPUID level 0x80000021.ecx, word 18 */ -+XEN_CPUFEATURE(TSA_SQ_NO, 18*32+ 1) /*A No Store Queue Transitive Scheduler Attacks */ -+XEN_CPUFEATURE(TSA_L1_NO, 18*32+ 2) /*A No L1D Transitive Scheduler Attacks */ - - #endif /* XEN_CPUFEATURE */ - --- -2.49.0 - diff --git a/archlinux/PKGBUILD.in b/archlinux/PKGBUILD.in index 54915dce..21728c92 100644 --- a/archlinux/PKGBUILD.in +++ b/archlinux/PKGBUILD.in @@ -14,7 +14,6 @@ makedepends=(wget make gcc patch git iasl pkg-config openssl pixman python-setup provides=('xen-qubes-vm-essentials') _patches=( - 0320-xen-remove-N-from-the-linker-command-line.patch 0629-python-avoid-conflicting-_FORTIFY_SOURCE-values.patch 1000-Do-not-access-network-during-the-build.patch 1001-hotplug-store-block-params-for-cleanup.patch diff --git a/rel b/rel index b8626c4c..d00491fd 100644 --- a/rel +++ b/rel @@ -1 +1 @@ -4 +1 diff --git a/version b/version index fe93d347..11533fcc 100644 --- a/version +++ b/version @@ -1 +1 @@ -4.19.2 +4.19.3 diff --git a/xen.spec.in b/xen.spec.in index bc3366e5..210c5f6f 100644 --- a/xen.spec.in +++ b/xen.spec.in @@ -100,68 +100,8 @@ Patch0203: 0203-xen.efi.build.patch Patch0300: 0300-xen-list-add-LIST_HEAD_RO_AFTER_INIT.patch Patch0301: 0301-x86-mm-add-API-for-marking-only-part-of-a-MMIO-page-.patch Patch0302: 0302-drivers-char-Use-sub-page-ro-API-to-make-just-xhci-d.patch -Patch0303: 0303-automation-eclair-Remove-bespoke-service-B.UNEVALEFF.patch -Patch0304: 0304-tools-libxl-do-not-use-c-E-compiler-options-together.patch -Patch0305: 0305-xen-lib-Introduce-SHA2-256.patch -Patch0306: 0306-x86-ucode-Perform-extra-SHA2-checks-on-AMD-Fam17h-19.patch -Patch0307: 0307-x86-ucode-Extend-AMD-digest-checks-to-cover-Zen5-CPU.patch -Patch0309: 0309-x86-MTRR-hook-mtrr_bp_restore-back-up.patch -Patch0310: 0310-sched-null-avoid-another-crash-after-failed-domU-cre.patch -Patch0311: 0311-xen-vm_event-do-not-do-vm_event_op-for-an-invalid-do.patch -Patch0312: 0312-x86-cpu-Validate-CPUID-leaf-0x2-EDX-output.patch -Patch0313: 0313-xen-x86-irq-initialize-irq-desc-in-create_irq.patch -Patch0314: 0314-include-sort-wildcard-.-results.patch -Patch0315: 0315-xen-rangeset-fix-incorrect-subtraction.patch -Patch0316: 0316-x86-HVM-update-repeat-count-upon-nested-lin-phys-fai.patch -Patch0317: 0317-x86emul-also-clip-repetition-count-for-STOS.patch -Patch0318: 0318-compat-memory-avoid-UB-shifts-in-XENMEM_exchange-han.patch -Patch0319: 0319-x86-intel-workaround-several-MONITOR-MWAIT-errata.patch -Patch0320: 0320-xen-remove-N-from-the-linker-command-line.patch -Patch0321: 0321-x86-alternative-Support-replacements-when-a-feature-.patch -Patch0322: 0322-x86-guest-Remove-use-of-the-Xen-hypercall_page.patch -Patch0323: 0323-x86-thunk-Mis-align-__x86_indirect_thunk_-to-mitigat.patch -Patch0324: 0324-x86-thunk-Mis-align-the-RETs-in-clear_bhb_loops-to-m.patch -Patch0325: 0325-x86-stubs-Introduce-place_ret-to-abstract-away-raw-0.patch -Patch0326: 0326-x86-thunk-Build-Xen-with-Return-Thunks.patch -Patch0327: 0327-x86-spec-ctrl-Synthesise-ITS_NO-to-guests-on-unaffec.patch -Patch0328: 0328-xen-link-Include-.debug_str_offsets-in-DWARF2_DEBUG_.patch -Patch0329: 0329-x86emul-avoid-UB-shifts-in-FLDENV-FRSTOR-handling.patch -Patch0330: 0330-cpufreq-don-t-leave-stale-statistics-pointer.patch -Patch0331: 0331-x86-spec-ctrl-Support-Intel-s-new-PB-OPT.patch -Patch0332: 0332-x86-pv-fix-MMUEXT_FLUSH_CACHE-to-flush-all-pCPU-cach.patch -Patch0333: 0333-x86-IRQ-constrain-creator-domain-ID-assertion.patch -Patch0334: 0334-x86-emul-Fix-emulation-of-RDSEED-with-older-toolchai.patch -Patch0335: 0335-x86-pv-fix-emulation-of-wb-no-invd-to-flush-all-pCPU.patch -Patch0336: 0336-x86-vpci-fix-handling-of-BAR-overlaps-with-non-hole-.patch -Patch0337: 0337-x86-vmx-Fix-VMEntry-failure-on-ADL-SPR-with-shadow-g.patch -Patch0338: 0338-x86-pv-Fix-breakpoint-reporting.patch -Patch0339: 0339-tools-libxl-Only-access-legacy-altp2m-on-HVM.patch -Patch0340: 0340-x86-pmstat-Check-size-of-PMSTAT_get_pxstat-buffers.patch -Patch0341: 0341-cpufreq-Avoid-potential-buffer-overrun-and-leak.patch -Patch0342: 0342-xenalyze-Add-2-missed-VCPUOPs-in-vcpu_op_str.patch -Patch0343: 0343-x86-emul-Fix-extable-registration-in-invoke_stub.patch -Patch0344: 0344-libxc-PM-Ensure-pxstat-buffers-are-correctly-sized.patch -Patch0345: 0345-libxc-PM-Retry-get_pxstat-if-data-is-incomplete.patch -Patch0346: 0346-xen-build-pass-fzero-init-padding-bits-all-to-gcc15.patch -Patch0347: 0347-x86-cpu-policy-Fix-handling-of-leaf-0x80000021.patch # Security fixes (500+) -Patch0500: 0500-x86-cpufeature-Reposition-cpu_has_-lfence_dispatch-n.patch -Patch0501: 0501-x86-idle-Move-monitor-mwait-wrappers-into-cpu-idle.c.patch -Patch0502: 0502-x86-idle-Remove-MFENCEs-for-CLFLUSH_MONITOR.patch -Patch0503: 0503-Revert-part-of-x86-mwait-idle-disable-IBRS-during-lo.patch -Patch0504: 0504-x86-cpu-policy-Simplify-logic-in-guest_common_defaul.patch -Patch0505: 0505-x86-idle-Remove-broken-MWAIT-implementation.patch -Patch0506: 0506-x86-idle-Drop-incorrect-smp_mb-in-mwait_idle_with_hi.patch -Patch0507: 0507-x86-idle-Convert-force_mwait_ipi_wakeup-to-X86_BUG_M.patch -Patch0508: 0508-xen-softirq-Rework-arch_skip_send_event_check-into-a.patch -Patch0509: 0509-x86-idle-Implement-a-new-MWAIT-IPI-elision-algorithm.patch -Patch0510: 0510-x86-idle-Fix-buggy-x86-mwait-idle-enable-interrupts-.patch -Patch0511: 0511-x86-cpu-policy-Rearrange-guest_common_-_feature_adju.patch -Patch0512: 0512-x86-cpu-policy-Infrastructure-for-CPUID-leaf-0x80000.patch -Patch0513: 0513-x86-ucode-Digests-for-TSA-microcode.patch -Patch0514: 0514-x86-idle-Rearrange-VERW-and-MONITOR-in-mwait_idle_wi.patch -Patch0515: 0515-x86-spec-ctrl-Mitigate-Transitive-Scheduler-Attacks.patch # Upstreamable patches (600+) Patch0600: 0600-libxl-create-writable-error-xenstore-dir.patch