On Mon, May 05, 2025 at 03:37:17PM -0700, Sean Christopherson wrote:
On Mon, May 05, 2025, Sasha Levin wrote:
From: Borislav Petkov bp@alien8.de
[ Upstream commit 8442df2b49ed9bcd67833ad4f091d15ac91efd00 ]
Add support for
CPUID Fn8000_0021_EAX[31] (SRSO_MSR_FIX). If this bit is 1, it indicates that software may use MSR BP_CFG[BpSpecReduce] to mitigate SRSO.
Enable BpSpecReduce to mitigate SRSO across guest/host boundaries.
Switch back to enabling the bit when virtualization is enabled and to clear the bit when virtualization is disabled because using a MSR slot would clear the bit when the guest is exited and any training the guest has done, would potentially influence the host kernel when execution enters the kernel and hasn't VMRUN the guest yet.
More detail on the public thread in Link below.
Co-developed-by: Sean Christopherson seanjc@google.com Signed-off-by: Sean Christopherson seanjc@google.com Signed-off-by: Borislav Petkov (AMD) bp@alien8.de Link: https://lore.kernel.org/r/20241202120416.6054-1-bp@kernel.org Signed-off-by: Sasha Levin sashal@kernel.org
Can we please hold off on this until the fix lands[1]? This version introduces a very measurable performance regression[2] for non-KVM use cases.
Sure, I'll drop it. Thanks!