161491cf4SDavid Woodhouse /* 261491cf4SDavid Woodhouse * Xen HVM emulation support in KVM 361491cf4SDavid Woodhouse * 461491cf4SDavid Woodhouse * Copyright © 2019 Oracle and/or its affiliates. All rights reserved. 561491cf4SDavid Woodhouse * Copyright © 2022 Amazon.com, Inc. or its affiliates. All Rights Reserved. 661491cf4SDavid Woodhouse * 761491cf4SDavid Woodhouse * This work is licensed under the terms of the GNU GPL, version 2 or later. 861491cf4SDavid Woodhouse * See the COPYING file in the top-level directory. 961491cf4SDavid Woodhouse * 1061491cf4SDavid Woodhouse */ 1161491cf4SDavid Woodhouse 1261491cf4SDavid Woodhouse #include "qemu/osdep.h" 1355a3f666SJoao Martins #include "qemu/log.h" 1479b7067dSJoao Martins #include "qemu/main-loop.h" 1561491cf4SDavid Woodhouse #include "sysemu/kvm_int.h" 1661491cf4SDavid Woodhouse #include "sysemu/kvm_xen.h" 1761491cf4SDavid Woodhouse #include "kvm/kvm_i386.h" 18bedcc139SJoao Martins #include "exec/address-spaces.h" 1961491cf4SDavid Woodhouse #include "xen-emu.h" 2055a3f666SJoao Martins #include "trace.h" 2179b7067dSJoao Martins #include "sysemu/runstate.h" 2261491cf4SDavid Woodhouse 23bedcc139SJoao Martins #include "hw/xen/interface/version.h" 2479b7067dSJoao Martins #include "hw/xen/interface/sched.h" 25bedcc139SJoao Martins 26bedcc139SJoao Martins static int kvm_gva_rw(CPUState *cs, uint64_t gva, void *_buf, size_t sz, 27bedcc139SJoao Martins bool is_write) 28bedcc139SJoao Martins { 29bedcc139SJoao Martins uint8_t *buf = (uint8_t *)_buf; 30bedcc139SJoao Martins int ret; 31bedcc139SJoao Martins 32bedcc139SJoao Martins while (sz) { 33bedcc139SJoao Martins struct kvm_translation tr = { 34bedcc139SJoao Martins .linear_address = gva, 35bedcc139SJoao Martins }; 36bedcc139SJoao Martins 37bedcc139SJoao Martins size_t len = TARGET_PAGE_SIZE - (tr.linear_address & ~TARGET_PAGE_MASK); 38bedcc139SJoao Martins if (len > sz) { 39bedcc139SJoao Martins len = sz; 40bedcc139SJoao Martins } 41bedcc139SJoao Martins 42bedcc139SJoao Martins ret = kvm_vcpu_ioctl(cs, KVM_TRANSLATE, &tr); 43bedcc139SJoao Martins if (ret || !tr.valid || (is_write && !tr.writeable)) { 44bedcc139SJoao Martins return -EFAULT; 45bedcc139SJoao Martins } 46bedcc139SJoao Martins 47bedcc139SJoao Martins cpu_physical_memory_rw(tr.physical_address, buf, len, is_write); 48bedcc139SJoao Martins 49bedcc139SJoao Martins buf += len; 50bedcc139SJoao Martins sz -= len; 51bedcc139SJoao Martins gva += len; 52bedcc139SJoao Martins } 53bedcc139SJoao Martins 54bedcc139SJoao Martins return 0; 55bedcc139SJoao Martins } 56bedcc139SJoao Martins 57bedcc139SJoao Martins static inline int kvm_copy_from_gva(CPUState *cs, uint64_t gva, void *buf, 58bedcc139SJoao Martins size_t sz) 59bedcc139SJoao Martins { 60bedcc139SJoao Martins return kvm_gva_rw(cs, gva, buf, sz, false); 61bedcc139SJoao Martins } 62bedcc139SJoao Martins 63bedcc139SJoao Martins static inline int kvm_copy_to_gva(CPUState *cs, uint64_t gva, void *buf, 64bedcc139SJoao Martins size_t sz) 65bedcc139SJoao Martins { 66bedcc139SJoao Martins return kvm_gva_rw(cs, gva, buf, sz, true); 67bedcc139SJoao Martins } 68bedcc139SJoao Martins 69f66b8a83SJoao Martins int kvm_xen_init(KVMState *s, uint32_t hypercall_msr) 7061491cf4SDavid Woodhouse { 7161491cf4SDavid Woodhouse const int required_caps = KVM_XEN_HVM_CONFIG_HYPERCALL_MSR | 7261491cf4SDavid Woodhouse KVM_XEN_HVM_CONFIG_INTERCEPT_HCALL | KVM_XEN_HVM_CONFIG_SHARED_INFO; 7361491cf4SDavid Woodhouse struct kvm_xen_hvm_config cfg = { 74f66b8a83SJoao Martins .msr = hypercall_msr, 7561491cf4SDavid Woodhouse .flags = KVM_XEN_HVM_CONFIG_INTERCEPT_HCALL, 7661491cf4SDavid Woodhouse }; 7761491cf4SDavid Woodhouse int xen_caps, ret; 7861491cf4SDavid Woodhouse 7961491cf4SDavid Woodhouse xen_caps = kvm_check_extension(s, KVM_CAP_XEN_HVM); 8061491cf4SDavid Woodhouse if (required_caps & ~xen_caps) { 8161491cf4SDavid Woodhouse error_report("kvm: Xen HVM guest support not present or insufficient"); 8261491cf4SDavid Woodhouse return -ENOSYS; 8361491cf4SDavid Woodhouse } 8461491cf4SDavid Woodhouse 8561491cf4SDavid Woodhouse if (xen_caps & KVM_XEN_HVM_CONFIG_EVTCHN_SEND) { 8661491cf4SDavid Woodhouse struct kvm_xen_hvm_attr ha = { 8761491cf4SDavid Woodhouse .type = KVM_XEN_ATTR_TYPE_XEN_VERSION, 8861491cf4SDavid Woodhouse .u.xen_version = s->xen_version, 8961491cf4SDavid Woodhouse }; 9061491cf4SDavid Woodhouse (void)kvm_vm_ioctl(s, KVM_XEN_HVM_SET_ATTR, &ha); 9161491cf4SDavid Woodhouse 9261491cf4SDavid Woodhouse cfg.flags |= KVM_XEN_HVM_CONFIG_EVTCHN_SEND; 9361491cf4SDavid Woodhouse } 9461491cf4SDavid Woodhouse 9561491cf4SDavid Woodhouse ret = kvm_vm_ioctl(s, KVM_XEN_HVM_CONFIG, &cfg); 9661491cf4SDavid Woodhouse if (ret < 0) { 9761491cf4SDavid Woodhouse error_report("kvm: Failed to enable Xen HVM support: %s", 9861491cf4SDavid Woodhouse strerror(-ret)); 9961491cf4SDavid Woodhouse return ret; 10061491cf4SDavid Woodhouse } 10161491cf4SDavid Woodhouse 10261491cf4SDavid Woodhouse s->xen_caps = xen_caps; 10361491cf4SDavid Woodhouse return 0; 10461491cf4SDavid Woodhouse } 10561491cf4SDavid Woodhouse 1065e691a95SDavid Woodhouse int kvm_xen_init_vcpu(CPUState *cs) 1075e691a95SDavid Woodhouse { 1085e691a95SDavid Woodhouse int err; 1095e691a95SDavid Woodhouse 1105e691a95SDavid Woodhouse /* 1115e691a95SDavid Woodhouse * The kernel needs to know the Xen/ACPI vCPU ID because that's 1125e691a95SDavid Woodhouse * what the guest uses in hypercalls such as timers. It doesn't 1135e691a95SDavid Woodhouse * match the APIC ID which is generally used for talking to the 1145e691a95SDavid Woodhouse * kernel about vCPUs. And if vCPU threads race with creating 1155e691a95SDavid Woodhouse * their KVM vCPUs out of order, it doesn't necessarily match 1165e691a95SDavid Woodhouse * with the kernel's internal vCPU indices either. 1175e691a95SDavid Woodhouse */ 1185e691a95SDavid Woodhouse if (kvm_xen_has_cap(EVTCHN_SEND)) { 1195e691a95SDavid Woodhouse struct kvm_xen_vcpu_attr va = { 1205e691a95SDavid Woodhouse .type = KVM_XEN_VCPU_ATTR_TYPE_VCPU_ID, 1215e691a95SDavid Woodhouse .u.vcpu_id = cs->cpu_index, 1225e691a95SDavid Woodhouse }; 1235e691a95SDavid Woodhouse err = kvm_vcpu_ioctl(cs, KVM_XEN_VCPU_SET_ATTR, &va); 1245e691a95SDavid Woodhouse if (err) { 1255e691a95SDavid Woodhouse error_report("kvm: Failed to set Xen vCPU ID attribute: %s", 1265e691a95SDavid Woodhouse strerror(-err)); 1275e691a95SDavid Woodhouse return err; 1285e691a95SDavid Woodhouse } 1295e691a95SDavid Woodhouse } 1305e691a95SDavid Woodhouse 1315e691a95SDavid Woodhouse return 0; 1325e691a95SDavid Woodhouse } 1335e691a95SDavid Woodhouse 13461491cf4SDavid Woodhouse uint32_t kvm_xen_get_caps(void) 13561491cf4SDavid Woodhouse { 13661491cf4SDavid Woodhouse return kvm_state->xen_caps; 13761491cf4SDavid Woodhouse } 13855a3f666SJoao Martins 139bedcc139SJoao Martins static bool kvm_xen_hcall_xen_version(struct kvm_xen_exit *exit, X86CPU *cpu, 140bedcc139SJoao Martins int cmd, uint64_t arg) 141bedcc139SJoao Martins { 142bedcc139SJoao Martins int err = 0; 143bedcc139SJoao Martins 144bedcc139SJoao Martins switch (cmd) { 145bedcc139SJoao Martins case XENVER_get_features: { 146bedcc139SJoao Martins struct xen_feature_info fi; 147bedcc139SJoao Martins 148bedcc139SJoao Martins /* No need for 32/64 compat handling */ 149bedcc139SJoao Martins qemu_build_assert(sizeof(fi) == 8); 150bedcc139SJoao Martins 151bedcc139SJoao Martins err = kvm_copy_from_gva(CPU(cpu), arg, &fi, sizeof(fi)); 152bedcc139SJoao Martins if (err) { 153bedcc139SJoao Martins break; 154bedcc139SJoao Martins } 155bedcc139SJoao Martins 156bedcc139SJoao Martins fi.submap = 0; 157bedcc139SJoao Martins if (fi.submap_idx == 0) { 158bedcc139SJoao Martins fi.submap |= 1 << XENFEAT_writable_page_tables | 159bedcc139SJoao Martins 1 << XENFEAT_writable_descriptor_tables | 160bedcc139SJoao Martins 1 << XENFEAT_auto_translated_physmap | 161bedcc139SJoao Martins 1 << XENFEAT_supervisor_mode_kernel; 162bedcc139SJoao Martins } 163bedcc139SJoao Martins 164bedcc139SJoao Martins err = kvm_copy_to_gva(CPU(cpu), arg, &fi, sizeof(fi)); 165bedcc139SJoao Martins break; 166bedcc139SJoao Martins } 167bedcc139SJoao Martins 168bedcc139SJoao Martins default: 169bedcc139SJoao Martins return false; 170bedcc139SJoao Martins } 171bedcc139SJoao Martins 172bedcc139SJoao Martins exit->u.hcall.result = err; 173bedcc139SJoao Martins return true; 174bedcc139SJoao Martins } 175bedcc139SJoao Martins 17679b7067dSJoao Martins int kvm_xen_soft_reset(void) 17779b7067dSJoao Martins { 17879b7067dSJoao Martins assert(qemu_mutex_iothread_locked()); 17979b7067dSJoao Martins 18079b7067dSJoao Martins trace_kvm_xen_soft_reset(); 18179b7067dSJoao Martins 18279b7067dSJoao Martins /* Nothing to reset... yet. */ 18379b7067dSJoao Martins return 0; 18479b7067dSJoao Martins } 18579b7067dSJoao Martins 18679b7067dSJoao Martins static int schedop_shutdown(CPUState *cs, uint64_t arg) 18779b7067dSJoao Martins { 18879b7067dSJoao Martins struct sched_shutdown shutdown; 18979b7067dSJoao Martins int ret = 0; 19079b7067dSJoao Martins 19179b7067dSJoao Martins /* No need for 32/64 compat handling */ 19279b7067dSJoao Martins qemu_build_assert(sizeof(shutdown) == 4); 19379b7067dSJoao Martins 19479b7067dSJoao Martins if (kvm_copy_from_gva(cs, arg, &shutdown, sizeof(shutdown))) { 19579b7067dSJoao Martins return -EFAULT; 19679b7067dSJoao Martins } 19779b7067dSJoao Martins 19879b7067dSJoao Martins switch (shutdown.reason) { 19979b7067dSJoao Martins case SHUTDOWN_crash: 20079b7067dSJoao Martins cpu_dump_state(cs, stderr, CPU_DUMP_CODE); 20179b7067dSJoao Martins qemu_system_guest_panicked(NULL); 20279b7067dSJoao Martins break; 20379b7067dSJoao Martins 20479b7067dSJoao Martins case SHUTDOWN_reboot: 20579b7067dSJoao Martins qemu_system_reset_request(SHUTDOWN_CAUSE_GUEST_RESET); 20679b7067dSJoao Martins break; 20779b7067dSJoao Martins 20879b7067dSJoao Martins case SHUTDOWN_poweroff: 20979b7067dSJoao Martins qemu_system_shutdown_request(SHUTDOWN_CAUSE_GUEST_SHUTDOWN); 21079b7067dSJoao Martins break; 21179b7067dSJoao Martins 21279b7067dSJoao Martins case SHUTDOWN_soft_reset: 21379b7067dSJoao Martins qemu_mutex_lock_iothread(); 21479b7067dSJoao Martins ret = kvm_xen_soft_reset(); 21579b7067dSJoao Martins qemu_mutex_unlock_iothread(); 21679b7067dSJoao Martins break; 21779b7067dSJoao Martins 21879b7067dSJoao Martins default: 21979b7067dSJoao Martins ret = -EINVAL; 22079b7067dSJoao Martins break; 22179b7067dSJoao Martins } 22279b7067dSJoao Martins 22379b7067dSJoao Martins return ret; 22479b7067dSJoao Martins } 22579b7067dSJoao Martins 22679b7067dSJoao Martins static bool kvm_xen_hcall_sched_op(struct kvm_xen_exit *exit, X86CPU *cpu, 22779b7067dSJoao Martins int cmd, uint64_t arg) 22879b7067dSJoao Martins { 22979b7067dSJoao Martins CPUState *cs = CPU(cpu); 23079b7067dSJoao Martins int err = -ENOSYS; 23179b7067dSJoao Martins 23279b7067dSJoao Martins switch (cmd) { 23379b7067dSJoao Martins case SCHEDOP_shutdown: 23479b7067dSJoao Martins err = schedop_shutdown(cs, arg); 23579b7067dSJoao Martins break; 23679b7067dSJoao Martins 237*c789b9efSDavid Woodhouse case SCHEDOP_poll: 238*c789b9efSDavid Woodhouse /* 239*c789b9efSDavid Woodhouse * Linux will panic if this doesn't work. Just yield; it's not 240*c789b9efSDavid Woodhouse * worth overthinking it because with event channel handling 241*c789b9efSDavid Woodhouse * in KVM, the kernel will intercept this and it will never 242*c789b9efSDavid Woodhouse * reach QEMU anyway. The semantics of the hypercall explicltly 243*c789b9efSDavid Woodhouse * permit spurious wakeups. 244*c789b9efSDavid Woodhouse */ 245*c789b9efSDavid Woodhouse case SCHEDOP_yield: 246*c789b9efSDavid Woodhouse sched_yield(); 247*c789b9efSDavid Woodhouse err = 0; 248*c789b9efSDavid Woodhouse break; 249*c789b9efSDavid Woodhouse 25079b7067dSJoao Martins default: 25179b7067dSJoao Martins return false; 25279b7067dSJoao Martins } 25379b7067dSJoao Martins 25479b7067dSJoao Martins exit->u.hcall.result = err; 25579b7067dSJoao Martins return true; 25679b7067dSJoao Martins } 25779b7067dSJoao Martins 25855a3f666SJoao Martins static bool do_kvm_xen_handle_exit(X86CPU *cpu, struct kvm_xen_exit *exit) 25955a3f666SJoao Martins { 26055a3f666SJoao Martins uint16_t code = exit->u.hcall.input; 26155a3f666SJoao Martins 26255a3f666SJoao Martins if (exit->u.hcall.cpl > 0) { 26355a3f666SJoao Martins exit->u.hcall.result = -EPERM; 26455a3f666SJoao Martins return true; 26555a3f666SJoao Martins } 26655a3f666SJoao Martins 26755a3f666SJoao Martins switch (code) { 26879b7067dSJoao Martins case __HYPERVISOR_sched_op: 26979b7067dSJoao Martins return kvm_xen_hcall_sched_op(exit, cpu, exit->u.hcall.params[0], 27079b7067dSJoao Martins exit->u.hcall.params[1]); 271bedcc139SJoao Martins case __HYPERVISOR_xen_version: 272bedcc139SJoao Martins return kvm_xen_hcall_xen_version(exit, cpu, exit->u.hcall.params[0], 273bedcc139SJoao Martins exit->u.hcall.params[1]); 27455a3f666SJoao Martins default: 27555a3f666SJoao Martins return false; 27655a3f666SJoao Martins } 27755a3f666SJoao Martins } 27855a3f666SJoao Martins 27955a3f666SJoao Martins int kvm_xen_handle_exit(X86CPU *cpu, struct kvm_xen_exit *exit) 28055a3f666SJoao Martins { 28155a3f666SJoao Martins if (exit->type != KVM_EXIT_XEN_HCALL) { 28255a3f666SJoao Martins return -1; 28355a3f666SJoao Martins } 28455a3f666SJoao Martins 28555a3f666SJoao Martins if (!do_kvm_xen_handle_exit(cpu, exit)) { 28655a3f666SJoao Martins /* 28755a3f666SJoao Martins * Some hypercalls will be deliberately "implemented" by returning 28855a3f666SJoao Martins * -ENOSYS. This case is for hypercalls which are unexpected. 28955a3f666SJoao Martins */ 29055a3f666SJoao Martins exit->u.hcall.result = -ENOSYS; 29155a3f666SJoao Martins qemu_log_mask(LOG_UNIMP, "Unimplemented Xen hypercall %" 29255a3f666SJoao Martins PRId64 " (0x%" PRIx64 " 0x%" PRIx64 " 0x%" PRIx64 ")\n", 29355a3f666SJoao Martins (uint64_t)exit->u.hcall.input, 29455a3f666SJoao Martins (uint64_t)exit->u.hcall.params[0], 29555a3f666SJoao Martins (uint64_t)exit->u.hcall.params[1], 29655a3f666SJoao Martins (uint64_t)exit->u.hcall.params[2]); 29755a3f666SJoao Martins } 29855a3f666SJoao Martins 29955a3f666SJoao Martins trace_kvm_xen_hypercall(CPU(cpu)->cpu_index, exit->u.hcall.cpl, 30055a3f666SJoao Martins exit->u.hcall.input, exit->u.hcall.params[0], 30155a3f666SJoao Martins exit->u.hcall.params[1], exit->u.hcall.params[2], 30255a3f666SJoao Martins exit->u.hcall.result); 30355a3f666SJoao Martins return 0; 30455a3f666SJoao Martins } 305