On Wed, 2020-07-22 at 12:06 +1000, Michael Ellerman wrote: > Ram Pai <linuxram@xxxxxxxxxx> writes: > > An instruction accessing a mmio address, generates a HDSI fault. This fault is > > appropriately handled by the Hypervisor. However in the case of secureVMs, the > > fault is delivered to the ultravisor. > > > > Unfortunately the Ultravisor has no correct-way to fetch the faulting > > instruction. The PEF architecture does not allow Ultravisor to enable MMU > > translation. Walking the two level page table to read the instruction can race > > with other vcpus modifying the SVM's process scoped page table. > > You're trying to read the guest's kernel text IIUC, that mapping should > be stable. Possibly permissions on it could change over time, but the > virtual -> real mapping should not. This will of course no longer work if userspace tries to access MMIO but as long as you are ok limiting MMIO usage to the kernel, that's one way. iirc MMIO emulation in KVM on powerpc already has that race because of HW TLB inval broadcast and it hasn't hurt anybody ... so far. > > This problem can be correctly solved with some help from the kernel. > > > > Capture the faulting instruction in SPRG0 register, before executing the > > faulting instruction. This enables the ultravisor to easily procure the > > faulting instruction and emulate it. > > This is not something I'm going to merge. Sorry. Another approach is to have the guest explicitly switch to using UV calls for MMIO. Cheers, Ben.