xref: /linux/arch/x86/kvm/vmx/nested.h (revision 3a2c4d55e32ad65efebdb6de44eef3bfa08bb49d)
1 /* SPDX-License-Identifier: GPL-2.0 */
2 #ifndef __KVM_X86_VMX_NESTED_H
3 #define __KVM_X86_VMX_NESTED_H
4 
5 #include "regs.h"
6 #include "hyperv.h"
7 #include "vmcs12.h"
8 #include "vmx.h"
9 
10 /*
11  * Status returned by nested_vmx_enter_non_root_mode():
12  */
13 enum nvmx_vmentry_status {
14 	NVMX_VMENTRY_SUCCESS,		/* Entered VMX non-root mode */
15 	NVMX_VMENTRY_VMFAIL,		/* Consistency check VMFail */
16 	NVMX_VMENTRY_VMEXIT,		/* Consistency check VMExit */
17 	NVMX_VMENTRY_KVM_INTERNAL_ERROR,/* KVM internal error */
18 };
19 
20 void vmx_leave_nested(struct kvm_vcpu *vcpu);
21 void nested_vmx_setup_ctls_msrs(struct vmcs_config *vmcs_conf, u32 ept_caps);
22 void nested_vmx_hardware_unsetup(void);
23 __init int nested_vmx_hardware_setup(int (*exit_handlers[])(struct kvm_vcpu *));
24 void nested_vmx_set_vmcs_shadowing_bitmap(void);
25 int nested_vmx_check_restored_vmcs12(struct kvm_vcpu *vcpu);
26 void nested_vmx_free_vcpu(struct kvm_vcpu *vcpu);
27 enum nvmx_vmentry_status nested_vmx_enter_non_root_mode(struct kvm_vcpu *vcpu,
28 						     bool from_vmentry);
29 bool nested_vmx_reflect_vmexit(struct kvm_vcpu *vcpu);
30 void __nested_vmx_vmexit(struct kvm_vcpu *vcpu, u32 vm_exit_reason,
31 			 u32 exit_intr_info, unsigned long exit_qualification,
32 			 u32 exit_insn_len);
33 
34 static inline void nested_vmx_vmexit(struct kvm_vcpu *vcpu, u32 vm_exit_reason,
35 				     u32 exit_intr_info,
36 				     unsigned long exit_qualification)
37 {
38 	u32 exit_insn_len;
39 
40 	if (to_vmx(vcpu)->fail || vm_exit_reason == -1 ||
41 	    (vm_exit_reason & VMX_EXIT_REASONS_FAILED_VMENTRY))
42 		exit_insn_len = 0;
43 	else
44 		exit_insn_len = vmcs_read32(VM_EXIT_INSTRUCTION_LEN);
45 
46 	__nested_vmx_vmexit(vcpu, vm_exit_reason, exit_intr_info,
47 			    exit_qualification, exit_insn_len);
48 }
49 
50 void nested_sync_vmcs12_to_shadow(struct kvm_vcpu *vcpu);
51 int vmx_set_vmx_msr(struct kvm_vcpu *vcpu, u32 msr_index, u64 data);
52 int vmx_get_vmx_msr(struct nested_vmx_msrs *msrs, u32 msr_index, u64 *pdata);
53 int get_vmx_mem_address(struct kvm_vcpu *vcpu, unsigned long exit_qualification,
54 			u32 vmx_instruction_info, bool wr, int len, gva_t *ret);
55 bool nested_vmx_check_io_bitmaps(struct kvm_vcpu *vcpu, unsigned int port,
56 				 int size);
57 
58 static inline struct vmcs12 *get_vmcs12(struct kvm_vcpu *vcpu)
59 {
60 	kvm_lockdep_assert_vcpu_is_locked_or_unreachable(vcpu);
61 
62 	return to_vmx(vcpu)->nested.cached_vmcs12;
63 }
64 
65 static inline struct vmcs12 *get_shadow_vmcs12(struct kvm_vcpu *vcpu)
66 {
67 	kvm_lockdep_assert_vcpu_is_locked_or_unreachable(vcpu);
68 
69 	return to_vmx(vcpu)->nested.cached_shadow_vmcs12;
70 }
71 
72 /*
73  * Note: the same condition is checked against the state provided by userspace
74  * in vmx_set_nested_state; if it is satisfied, the nested state must include
75  * the VMCS12.
76  */
77 static inline int vmx_has_valid_vmcs12(struct kvm_vcpu *vcpu)
78 {
79 	struct vcpu_vmx *vmx = to_vmx(vcpu);
80 
81 	/* 'hv_evmcs_vmptr' can also be EVMPTR_MAP_PENDING here */
82 	return vmx->nested.current_vmptr != -1ull ||
83 		nested_vmx_is_evmptr12_set(vmx);
84 }
85 
86 static inline u16 nested_get_vpid02(struct kvm_vcpu *vcpu)
87 {
88 	struct vcpu_vmx *vmx = to_vmx(vcpu);
89 
90 	return vmx->nested.vpid02 ? vmx->nested.vpid02 : vmx->vpid;
91 }
92 
93 static inline unsigned long nested_ept_get_eptp(struct kvm_vcpu *vcpu)
94 {
95 	/* return the page table to be shadowed - in our case, EPT12 */
96 	return get_vmcs12(vcpu)->ept_pointer;
97 }
98 
99 static inline bool nested_ept_ad_enabled(struct kvm_vcpu *vcpu)
100 {
101 	return nested_ept_get_eptp(vcpu) & VMX_EPTP_AD_ENABLE_BIT;
102 }
103 
104 /*
105  * Return the cr0/4 value that a nested guest would read. This is a combination
106  * of L1's "real" cr0 used to run the guest (guest_cr0), and the bits shadowed
107  * by the L1 hypervisor (cr0_read_shadow).  KVM must emulate CPU behavior as
108  * the value+mask loaded into vmcs02 may not match the vmcs12 fields.
109  */
110 static inline unsigned long nested_read_cr0(struct vmcs12 *fields)
111 {
112 	return (fields->guest_cr0 & ~fields->cr0_guest_host_mask) |
113 		(fields->cr0_read_shadow & fields->cr0_guest_host_mask);
114 }
115 static inline unsigned long nested_read_cr4(struct vmcs12 *fields)
116 {
117 	return (fields->guest_cr4 & ~fields->cr4_guest_host_mask) |
118 		(fields->cr4_read_shadow & fields->cr4_guest_host_mask);
119 }
120 
121 static inline unsigned nested_cpu_vmx_misc_cr3_count(struct kvm_vcpu *vcpu)
122 {
123 	return vmx_misc_cr3_count(to_vmx(vcpu)->nested.msrs.misc_low);
124 }
125 
126 /*
127  * Do the virtual VMX capability MSRs specify that L1 can use VMWRITE
128  * to modify any valid field of the VMCS, or are the VM-exit
129  * information fields read-only?
130  */
131 static inline bool nested_cpu_has_vmwrite_any_field(struct kvm_vcpu *vcpu)
132 {
133 	return to_vmx(vcpu)->nested.msrs.misc_low &
134 		VMX_MISC_VMWRITE_SHADOW_RO_FIELDS;
135 }
136 
137 static inline bool nested_cpu_has_zero_length_injection(struct kvm_vcpu *vcpu)
138 {
139 	return to_vmx(vcpu)->nested.msrs.misc_low & VMX_MISC_ZERO_LEN_INS;
140 }
141 
142 static inline bool nested_cpu_supports_monitor_trap_flag(struct kvm_vcpu *vcpu)
143 {
144 	return to_vmx(vcpu)->nested.msrs.procbased_ctls_high &
145 			CPU_BASED_MONITOR_TRAP_FLAG;
146 }
147 
148 static inline bool nested_cpu_has_vmx_shadow_vmcs(struct kvm_vcpu *vcpu)
149 {
150 	return to_vmx(vcpu)->nested.msrs.secondary_ctls_high &
151 		SECONDARY_EXEC_SHADOW_VMCS;
152 }
153 
154 static inline bool nested_cpu_has(struct vmcs12 *vmcs12, u32 bit)
155 {
156 	return vmcs12->cpu_based_vm_exec_control & bit;
157 }
158 
159 static inline bool nested_cpu_has2(struct vmcs12 *vmcs12, u32 bit)
160 {
161 	return (vmcs12->cpu_based_vm_exec_control &
162 			CPU_BASED_ACTIVATE_SECONDARY_CONTROLS) &&
163 		(vmcs12->secondary_vm_exec_control & bit);
164 }
165 
166 static inline bool nested_cpu_has_preemption_timer(struct vmcs12 *vmcs12)
167 {
168 	return vmcs12->pin_based_vm_exec_control &
169 		PIN_BASED_VMX_PREEMPTION_TIMER;
170 }
171 
172 static inline bool nested_cpu_has_nmi_exiting(struct vmcs12 *vmcs12)
173 {
174 	return vmcs12->pin_based_vm_exec_control & PIN_BASED_NMI_EXITING;
175 }
176 
177 static inline bool nested_cpu_has_virtual_nmis(struct vmcs12 *vmcs12)
178 {
179 	return vmcs12->pin_based_vm_exec_control & PIN_BASED_VIRTUAL_NMIS;
180 }
181 
182 static inline int nested_cpu_has_mtf(struct vmcs12 *vmcs12)
183 {
184 	return nested_cpu_has(vmcs12, CPU_BASED_MONITOR_TRAP_FLAG);
185 }
186 
187 static inline int nested_cpu_has_ept(struct vmcs12 *vmcs12)
188 {
189 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENABLE_EPT);
190 }
191 
192 static inline bool nested_cpu_has_xsaves(struct vmcs12 *vmcs12)
193 {
194 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENABLE_XSAVES);
195 }
196 
197 static inline bool nested_cpu_has_pml(struct vmcs12 *vmcs12)
198 {
199 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENABLE_PML);
200 }
201 
202 static inline bool nested_cpu_has_virt_x2apic_mode(struct vmcs12 *vmcs12)
203 {
204 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_VIRTUALIZE_X2APIC_MODE);
205 }
206 
207 static inline bool nested_cpu_has_vpid(struct vmcs12 *vmcs12)
208 {
209 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENABLE_VPID);
210 }
211 
212 static inline bool nested_cpu_has_apic_reg_virt(struct vmcs12 *vmcs12)
213 {
214 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_APIC_REGISTER_VIRT);
215 }
216 
217 static inline bool nested_cpu_has_vid(struct vmcs12 *vmcs12)
218 {
219 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_VIRTUAL_INTR_DELIVERY);
220 }
221 
222 static inline bool nested_cpu_has_posted_intr(struct vmcs12 *vmcs12)
223 {
224 	return vmcs12->pin_based_vm_exec_control & PIN_BASED_POSTED_INTR;
225 }
226 
227 static inline bool nested_cpu_has_vmfunc(struct vmcs12 *vmcs12)
228 {
229 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENABLE_VMFUNC);
230 }
231 
232 static inline bool nested_cpu_has_eptp_switching(struct vmcs12 *vmcs12)
233 {
234 	return nested_cpu_has_vmfunc(vmcs12) &&
235 		(vmcs12->vm_function_control &
236 		 VMX_VMFUNC_EPTP_SWITCHING);
237 }
238 
239 static inline bool nested_cpu_has_shadow_vmcs(struct vmcs12 *vmcs12)
240 {
241 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_SHADOW_VMCS);
242 }
243 
244 static inline bool nested_cpu_has_save_preemption_timer(struct vmcs12 *vmcs12)
245 {
246 	return vmcs12->vm_exit_controls &
247 	    VM_EXIT_SAVE_VMX_PREEMPTION_TIMER;
248 }
249 
250 static inline bool nested_exit_on_nmi(struct kvm_vcpu *vcpu)
251 {
252 	return nested_cpu_has_nmi_exiting(get_vmcs12(vcpu));
253 }
254 
255 /*
256  * In nested virtualization, check if L1 asked to exit on external interrupts.
257  * For most existing hypervisors, this will always return true.
258  */
259 static inline bool nested_exit_on_intr(struct kvm_vcpu *vcpu)
260 {
261 	return get_vmcs12(vcpu)->pin_based_vm_exec_control &
262 		PIN_BASED_EXT_INTR_MASK;
263 }
264 
265 static inline bool nested_cpu_has_encls_exit(struct vmcs12 *vmcs12)
266 {
267 	return nested_cpu_has2(vmcs12, SECONDARY_EXEC_ENCLS_EXITING);
268 }
269 
270 /*
271  * if fixed0[i] == 1: val[i] must be 1
272  * if fixed1[i] == 0: val[i] must be 0
273  */
274 static inline bool fixed_bits_valid(u64 val, u64 fixed0, u64 fixed1)
275 {
276 	return ((val & fixed1) | fixed0) == val;
277 }
278 
279 static inline bool nested_guest_cr0_valid(struct kvm_vcpu *vcpu, unsigned long val)
280 {
281 	u64 fixed0 = to_vmx(vcpu)->nested.msrs.cr0_fixed0;
282 	u64 fixed1 = to_vmx(vcpu)->nested.msrs.cr0_fixed1;
283 	struct vmcs12 *vmcs12 = get_vmcs12(vcpu);
284 
285 	if (to_vmx(vcpu)->nested.msrs.secondary_ctls_high &
286 		SECONDARY_EXEC_UNRESTRICTED_GUEST &&
287 	    nested_cpu_has2(vmcs12, SECONDARY_EXEC_UNRESTRICTED_GUEST))
288 		fixed0 &= ~(X86_CR0_PE | X86_CR0_PG);
289 
290 	return fixed_bits_valid(val, fixed0, fixed1);
291 }
292 
293 static inline bool nested_host_cr0_valid(struct kvm_vcpu *vcpu, unsigned long val)
294 {
295 	u64 fixed0 = to_vmx(vcpu)->nested.msrs.cr0_fixed0;
296 	u64 fixed1 = to_vmx(vcpu)->nested.msrs.cr0_fixed1;
297 
298 	return fixed_bits_valid(val, fixed0, fixed1);
299 }
300 
301 static inline bool nested_cr4_valid(struct kvm_vcpu *vcpu, unsigned long val)
302 {
303 	u64 fixed0 = to_vmx(vcpu)->nested.msrs.cr4_fixed0;
304 	u64 fixed1 = to_vmx(vcpu)->nested.msrs.cr4_fixed1;
305 
306 	return fixed_bits_valid(val, fixed0, fixed1) &&
307 	       __kvm_is_valid_cr4(vcpu, val);
308 }
309 
310 static inline bool nested_cpu_has_no_hw_errcode_cc(struct kvm_vcpu *vcpu)
311 {
312 	return to_vmx(vcpu)->nested.msrs.basic & VMX_BASIC_NO_HW_ERROR_CODE_CC;
313 }
314 
315 /* No difference in the restrictions on guest and host CR4 in VMX operation. */
316 #define nested_guest_cr4_valid	nested_cr4_valid
317 #define nested_host_cr4_valid	nested_cr4_valid
318 
319 extern struct kvm_x86_nested_ops vmx_nested_ops;
320 
321 #endif /* __KVM_X86_VMX_NESTED_H */
322