Skip to content

Commit b3744c5

Browse files
yang-weijiangsean-jc
authored andcommitted
KVM: x86: Allow setting CR4.CET if IBT or SHSTK is supported
Drop X86_CR4_CET from CR4_RESERVED_BITS and instead mark CET as reserved if and only if IBT *and* SHSTK are unsupported, i.e. allow CR4.CET to be set if IBT or SHSTK is supported. This creates a virtualization hole if the CPU supports both IBT and SHSTK, but the kernel or vCPU model only supports one of the features. However, it's entirely legal for a CPU to have only one of IBT or SHSTK, i.e. the hole is a flaw in the architecture, not in KVM. More importantly, so long as KVM is careful to initialize and context switch both IBT and SHSTK state (when supported in hardware) if either feature is exposed to the guest, a misbehaving guest can only harm itself. E.g. VMX initializes host CET VMCS fields based solely on hardware capabilities. Signed-off-by: Yang Weijiang <weijiang.yang@intel.com> Signed-off-by: Mathias Krause <minipli@grsecurity.net> Tested-by: Mathias Krause <minipli@grsecurity.net> Tested-by: John Allen <john.allen@amd.com> Tested-by: Rick Edgecombe <rick.p.edgecombe@intel.com> Signed-off-by: Chao Gao <chao.gao@intel.com> [sean: split to separate patch, write changelog] Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com> Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com> Link: https://lore.kernel.org/r/20250919223258.1604852-24-seanjc@google.com Signed-off-by: Sean Christopherson <seanjc@google.com>
1 parent 843af0f commit b3744c5

File tree

2 files changed

+4
-1
lines changed

2 files changed

+4
-1
lines changed

arch/x86/include/asm/kvm_host.h

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -142,7 +142,7 @@
142142
| X86_CR4_OSXSAVE | X86_CR4_SMEP | X86_CR4_FSGSBASE \
143143
| X86_CR4_OSXMMEXCPT | X86_CR4_LA57 | X86_CR4_VMXE \
144144
| X86_CR4_SMAP | X86_CR4_PKE | X86_CR4_UMIP \
145-
| X86_CR4_LAM_SUP))
145+
| X86_CR4_LAM_SUP | X86_CR4_CET))
146146

147147
#define CR8_RESERVED_BITS (~(unsigned long)X86_CR8_TPR)
148148

arch/x86/kvm/x86.h

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -680,6 +680,9 @@ static inline bool __kvm_is_valid_cr4(struct kvm_vcpu *vcpu, unsigned long cr4)
680680
__reserved_bits |= X86_CR4_PCIDE; \
681681
if (!__cpu_has(__c, X86_FEATURE_LAM)) \
682682
__reserved_bits |= X86_CR4_LAM_SUP; \
683+
if (!__cpu_has(__c, X86_FEATURE_SHSTK) && \
684+
!__cpu_has(__c, X86_FEATURE_IBT)) \
685+
__reserved_bits |= X86_CR4_CET; \
683686
__reserved_bits; \
684687
})
685688

0 commit comments

Comments
 (0)