Commit 90f5ecd3 authored by Kai Huang's avatar Kai Huang Committed by Dave Hansen
Browse files

x86/tdx: Reimplement __tdx_hypercall() using TDX_MODULE_CALL asm



Now the TDX_HYPERCALL asm is basically identical to the TDX_MODULE_CALL
with both '\saved' and '\ret' enabled, with two minor things though:

1) The way to restore the structure pointer is different

The TDX_HYPERCALL uses RCX as spare to restore the structure pointer,
but the TDX_MODULE_CALL assumes no spare register can be used.  In other
words, TDX_MODULE_CALL already covers what TDX_HYPERCALL does.

2) TDX_MODULE_CALL only clears shared registers for TDH.VP.ENTER

For this just need to make that code available for the non-host case.

Thus, remove the TDX_HYPERCALL and reimplement the __tdx_hypercall()
using the TDX_MODULE_CALL.

Extend the TDX_MODULE_CALL to cover "clear shared registers" for
TDG.VP.VMCALL.  Introduce a new __tdcall_saved_ret() to replace the
temporary __tdcall_hypercall().

The __tdcall_saved_ret() can also be used for those new TDCALLs which
require more input/output registers than the basic TDCALLs do.

Suggested-by: default avatarPeter Zijlstra <peterz@infradead.org>
Signed-off-by: default avatarKai Huang <kai.huang@intel.com>
Signed-off-by: default avatarDave Hansen <dave.hansen@linux.intel.com>
Reviewed-by: default avatarKirill A. Shutemov <kirill.shutemov@linux.intel.com>
Acked-by: default avatarPeter Zijlstra (Intel) <peterz@infradead.org>
Link: https://lore.kernel.org/all/e68a2473fb6f5bcd78b078cae7510e9d0753b3df.1692096753.git.kai.huang%40intel.com
parent c641cfb5
Loading
Loading
Loading
Loading
+8 −125
Original line number Diff line number Diff line
/* SPDX-License-Identifier: GPL-2.0 */
#include <asm/asm-offsets.h>
#include <asm/asm.h>
#include <asm/frame.h>

#include <linux/linkage.h>
#include <linux/errno.h>
@@ -46,135 +45,19 @@ SYM_FUNC_START(__tdcall_ret)
SYM_FUNC_END(__tdcall_ret)

/*
 * TDX_HYPERCALL - Make hypercalls to a TDX VMM using TDVMCALL leaf of TDCALL
 * instruction
 *
 * Transforms values in  function call argument struct tdx_module_args @args
 * into the TDCALL register ABI. After TDCALL operation, VMM output is saved
 * back in @args, if \ret is 1.
 *
 * Depends on the caller to pass TDG.VP.VMCALL as the TDCALL leaf, and set
 * @args::rcx to TDVMCALL_EXPOSE_REGS_MASK.
 *
 *-------------------------------------------------------------------------
 * TD VMCALL ABI:
 *-------------------------------------------------------------------------
 *
 * Input Registers:
 *
 * RAX                 - TDCALL instruction leaf number (0 - TDG.VP.VMCALL)
 * RCX                 - BITMAP which controls which part of TD Guest GPR
 *                       is passed as-is to the VMM and back.
 * R10                 - Set 0 to indicate TDCALL follows standard TDX ABI
 *                       specification. Non zero value indicates vendor
 *                       specific ABI.
 * R11                 - VMCALL sub function number
 * RBX, RDX, RDI, RSI  - Used to pass VMCALL sub function specific arguments.
 * R8-R9, R12-R15      - Same as above.
 *
 * Output Registers:
 *
 * RAX                 - TDCALL instruction status (Not related to hypercall
 *                        output).
 * RBX, RDX, RDI, RSI  - Hypercall sub function specific output values.
 * R8-R15              - Same as above.
 *
 */
.macro TDX_HYPERCALL
	FRAME_BEGIN

	/* Save callee-saved GPRs as mandated by the x86_64 ABI */
	push %r15
	push %r14
	push %r13
	push %r12
	push %rbx

	/* Move Leaf ID to RAX */
	movq %rdi, %rax

	/* Move bitmap of shared registers to RCX */
	movq TDX_MODULE_rcx(%rsi), %rcx

	/* Copy hypercall registers from arg struct: */
	movq TDX_MODULE_r8(%rsi),  %r8
	movq TDX_MODULE_r9(%rsi),  %r9
	movq TDX_MODULE_r10(%rsi), %r10
	movq TDX_MODULE_r11(%rsi), %r11
	movq TDX_MODULE_r12(%rsi), %r12
	movq TDX_MODULE_r13(%rsi), %r13
	movq TDX_MODULE_r14(%rsi), %r14
	movq TDX_MODULE_r15(%rsi), %r15
	movq TDX_MODULE_rdi(%rsi), %rdi
	movq TDX_MODULE_rbx(%rsi), %rbx
	movq TDX_MODULE_rdx(%rsi), %rdx

	pushq %rsi
	movq TDX_MODULE_rsi(%rsi), %rsi

	tdcall

	/*
	 * Restore the pointer of the structure to save output registers.
	 *
	 * RCX is used as bitmap of shared registers and doesn't hold any
	 * value provided by the VMM, thus it can be used as spare to
	 * restore the structure pointer.
	 */
	popq %rcx
	movq %rsi, TDX_MODULE_rsi(%rcx)
	movq %rcx, %rsi

	movq %r8,  TDX_MODULE_r8(%rsi)
	movq %r9,  TDX_MODULE_r9(%rsi)
	movq %r10, TDX_MODULE_r10(%rsi)
	movq %r11, TDX_MODULE_r11(%rsi)
	movq %r12, TDX_MODULE_r12(%rsi)
	movq %r13, TDX_MODULE_r13(%rsi)
	movq %r14, TDX_MODULE_r14(%rsi)
	movq %r15, TDX_MODULE_r15(%rsi)
	movq %rdi, TDX_MODULE_rdi(%rsi)
	movq %rbx, TDX_MODULE_rbx(%rsi)
	movq %rdx, TDX_MODULE_rdx(%rsi)

	/*
	 * Zero out registers exposed to the VMM to avoid speculative execution
	 * with VMM-controlled values. This needs to include all registers
	 * present in TDVMCALL_EXPOSE_REGS_MASK, except RBX, and R12-R15 which
	 * will be restored.
	 */
	xor %r8d,  %r8d
	xor %r9d,  %r9d
	xor %r10d, %r10d
	xor %r11d, %r11d
	xor %rdi,  %rdi
	xor %rsi,  %rsi
	xor %rdx,  %rdx

	/* Restore callee-saved GPRs as mandated by the x86_64 ABI */
	pop %rbx
	pop %r12
	pop %r13
	pop %r14
	pop %r15

	FRAME_END

	RET
.endm

/*
 * __tdcall_saved_ret() - Used by TDX guests to request services from the
 * TDX module (including VMM services) using TDCALL instruction, with
 * saving output registers to the 'struct tdx_module_args' used as input.
 *
 * __tdcall_hypercall() function ABI:
 * __tdcall_saved_ret() function ABI:
 *
 * @fn   (RDI)	- TDCALL leaf ID, moved to RAX
 * @args (RSI)	- struct tdx_module_args for input/output
 *
 * @fn and @args::rcx from the caller must be TDG_VP_VMCALL and
 * TDVMCALL_EXPOSE_REGS_MASK respectively.
 * All registers in @args are used as input/output registers.
 *
 * On successful completion, return the hypercall error code.
 */
SYM_FUNC_START(__tdcall_hypercall)
	TDX_HYPERCALL
SYM_FUNC_END(__tdcall_hypercall)
SYM_FUNC_START(__tdcall_saved_ret)
	TDX_MODULE_CALL host=0 ret=1 saved=1
SYM_FUNC_END(__tdcall_saved_ret)
+2 −2
Original line number Diff line number Diff line
@@ -89,11 +89,11 @@ noinstr u64 __tdx_hypercall(struct tdx_hypercall_args *args)
	};

	/*
	 * Failure of __tdcall_hypercall() indicates a failure of the TDVMCALL
	 * Failure of __tdcall_saved_ret() indicates a failure of the TDVMCALL
	 * mechanism itself and that something has gone horribly wrong with
	 * the TDX module.  __tdx_hypercall_failed() never returns.
	 */
	if (__tdcall_hypercall(TDG_VP_VMCALL, &margs))
	if (__tdcall_saved_ret(TDG_VP_VMCALL, &margs))
		__tdx_hypercall_failed();

	args->r8  = margs.r8;
+1 −1
Original line number Diff line number Diff line
@@ -83,6 +83,7 @@ struct tdx_module_args {
/* Used to communicate with the TDX module */
u64 __tdcall(u64 fn, struct tdx_module_args *args);
u64 __tdcall_ret(u64 fn, struct tdx_module_args *args);
u64 __tdcall_saved_ret(u64 fn, struct tdx_module_args *args);

/*
 * Used in __tdx_hypercall() to pass down and get back registers' values of
@@ -106,7 +107,6 @@ struct tdx_hypercall_args {
};

/* Used to request services from the VMM */
u64 __tdcall_hypercall(u64 fn, struct tdx_module_args *args);
u64 __tdx_hypercall(struct tdx_hypercall_args *args);

/*
+4 −4
Original line number Diff line number Diff line
@@ -142,10 +142,10 @@
	movq %r11, TDX_MODULE_r11(%rsi)
.endif	/* \ret */

.if \host && \saved && \ret
.if \saved && \ret
	/*
	 * Clear registers shared by guest for VP.ENTER to prevent
	 * speculative use of guest's values, including those are
	 * Clear registers shared by guest for VP.VMCALL/VP.ENTER to prevent
	 * speculative use of guest's/VMM's values, including those are
	 * restored from the stack.
	 *
	 * See arch/x86/kvm/vmx/vmenter.S:
@@ -170,7 +170,7 @@
	xorl %r15d, %r15d
	xorl %ebx,  %ebx
	xorl %edi,  %edi
.endif	/* \host && \ret && \host */
.endif	/* \ret && \host */

.if \host
.Lout\@: