[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH] x86/hvm: Clamp Viridian features to known set
- To: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, xen-devel@xxxxxxxxxxxxxxxxxxxx
- From: Ross Lagerwall <ross.lagerwall@xxxxxxxxxx>
- Date: Thu, 24 Sep 2026 13:56:02 +0100
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=3qnXD8olE1RhVt4hyXvZJ14EiAuMC0A2U0g57NmoSrE=; b=Z946lt3g1PJyUmRgfDFGMERwHGBWGHchLpqo3L7Uwxpd0n3yGiQGvPNUw4zFVF1ZToOXvFiWd8fgm71cOd96wcYCIklTi+gHr6SmBZPto8q9Oho0RmKYlDqMLIhhnUOTTDgF6i7BXJT1Vyrp9jmXq7SPSnxRsDEI0Co8Vh55DcybJ+NWwye8S5+2jVobxH40M9AmkgIj6pdsARnNRNNmfTo4yfQd69+mhGp4pWaEn2CKCAXZsBp+Rf5Y8XcYhn68qeYYuiKh5evJf8ECTtiWtYS1EmKVMddC/eNDyXmdlDJXwNSxGLrwaHAQ4K5A7riu0hWhz/LlsRs8gBUul6KGJw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=QzFHmTSXrhlLb2x5jaoCLOKDqG09UfBu39Dm6JpMXa0PxIzsTOKa2n79rzLUECPTwFBDecwNZTwzbF5eSkKigiN2rJKbBcL0/tNxiOVFrvxhqK7IkRCcsgQNMl14vVRbfNmqstgLWe/VTVjtapnlTpuTbWNaXgoUy4n+1ZUsvlfwxhmKZC2RZAK86BdWsgLFynovN2Ap3VjCeumDJzaTMEZfoE4N3I6zR5olu3GLSQAMrPnQmO+kc3HNg4mKSotJT9UHe3iWXI/AA/9yLVZhh924SBqHAdxCxKtwzWXHIswfsSV1wny2wPk2+lzCRwdlhz7lsvckZWCqkxTeEuuumQ==
- Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
- Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
- Cc: Jan Beulich <jbeulich@xxxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Teddy Astie <teddy.astie@xxxxxxxxxx>
- Delivery-date: Thu, 24 Sep 2026 12:56:18 +0000
- List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
On 9/24/26 12:20 PM, Andrew Cooper wrote:
On 24/09/2026 12:03 pm, Ross Lagerwall wrote:
Instead of returning EINVAL on an unknown feature bit, clamp to the
known feature set.
Sorry, but no.
This is equivalent to saying "I've got a VM using AVX512" and Xen saying
"ok, I'll ignore that safety check and let you run on non-AVX512 capable
hardware".
Requesting a feature that Xen doesn't know about is a hard error.
Truncating features out like this will cause a guest using those
features to malfunction.
It is a bug that this was expressed as an HVM Param in the first place.
It should be part of CPU Policy, and it's on a TODO list.
But isn't this the same thing the CPU Policy code does? In
recalculate_cpuid_policy(), it silently clamps the toolstack's choices to the
max featureset.
Ross
|