diff options
| author | Sean Christopherson <seanjc@google.com> | 2026-09-23 09:37:21 -0700 |
|---|---|---|
| committer | Paolo Bonzini <pbonzini@redhat.com> | 2026-09-26 00:39:55 -0400 |
| commit | 93de2a6a4b91b72607136dd656edf03fb399d27f (patch) | |
| tree | 9220c76eb23cb39a146fac9692ee69afa4aa3135 /include/net/gre.h | |
| download | linux-stable-93de2a6a4b91b72607136dd656edf03fb399d27f.tar.gz linux-stable-93de2a6a4b91b72607136dd656edf03fb399d27f.zip | |
KVM: SEV: Do cache maintenance on the source VM during intra-host migrationgrafted
Manually perform cache maintenance on the source VM during intra-host
migration to ensure no stale data is left in CPU caches after the VM is
destroyed. Because the source VM is "converted" to a non-SEV VM, KVM's
memory reclaim flows won't trigger cache maintenance, e.g. when all guest
memory is reclaimed in response to detaching from the mmu_notifier.
Note, relying on the destination VM to do cache maintenance isn't an option
as KVM doesn't require identical guest memory configurations, i.e. the
source VM may have access to memory that the destination VM does not.
Enforcing equivalent memory configurations is infeasible, as it would
require a *deep* comparison of memslots, e.g. to verify that not only are
the memslot identical, but what the memslots point at is also identical.
Fixes: b56639318bb2 ("KVM: SEV: Add support for SEV intra host migration")
Cc: stable@vger.kernel.org
Reported-by: Stefan Teodorescu <fane@google.com>
Signed-off-by: Sean Christopherson <seanjc@google.com>
Message-ID: <20260923163721.1584779-3-seanjc@google.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
Diffstat (limited to 'include/net/gre.h')
| -rw-r--r-- | include/net/gre.h | 145 |
1 files changed, 145 insertions, 0 deletions
diff --git a/include/net/gre.h b/include/net/gre.h new file mode 100644 index 000000000..b55f67ecd --- /dev/null +++ b/include/net/gre.h @@ -0,0 +1,145 @@ +/* SPDX-License-Identifier: GPL-2.0 */ +#ifndef __LINUX_GRE_H +#define __LINUX_GRE_H + +#include <linux/skbuff.h> +#include <net/ip_tunnels.h> + +struct gre_base_hdr { + __be16 flags; + __be16 protocol; +} __packed; + +struct gre_full_hdr { + struct gre_base_hdr fixed_header; + __be16 csum; + __be16 reserved1; + __be32 key; + __be32 seq; +} __packed; +#define GRE_HEADER_SECTION 4 + +#define GREPROTO_CISCO 0 +#define GREPROTO_PPTP 1 +#define GREPROTO_MAX 2 +#define GRE_IP_PROTO_MAX 2 + +struct gre_protocol { + int (*handler)(struct sk_buff *skb); + void (*err_handler)(struct sk_buff *skb, u32 info); +}; + +int gre_add_protocol(const struct gre_protocol *proto, u8 version); +int gre_del_protocol(const struct gre_protocol *proto, u8 version); + +int gre_parse_header(struct sk_buff *skb, struct tnl_ptk_info *tpi, + bool *csum_err, __be16 proto, int nhs); + +static inline bool netif_is_gretap(const struct net_device *dev) +{ + return dev->rtnl_link_ops && + !strcmp(dev->rtnl_link_ops->kind, "gretap"); +} + +static inline bool netif_is_ip6gretap(const struct net_device *dev) +{ + return dev->rtnl_link_ops && + !strcmp(dev->rtnl_link_ops->kind, "ip6gretap"); +} + +static inline int gre_calc_hlen(const unsigned long *o_flags) +{ + int addend = 4; + + if (test_bit(IP_TUNNEL_CSUM_BIT, o_flags)) + addend += 4; + if (test_bit(IP_TUNNEL_KEY_BIT, o_flags)) + addend += 4; + if (test_bit(IP_TUNNEL_SEQ_BIT, o_flags)) + addend += 4; + return addend; +} + +static inline void gre_flags_to_tnl_flags(unsigned long *dst, __be16 flags) +{ + IP_TUNNEL_DECLARE_FLAGS(res) = { }; + + __assign_bit(IP_TUNNEL_CSUM_BIT, res, flags & GRE_CSUM); + __assign_bit(IP_TUNNEL_ROUTING_BIT, res, flags & GRE_ROUTING); + __assign_bit(IP_TUNNEL_KEY_BIT, res, flags & GRE_KEY); + __assign_bit(IP_TUNNEL_SEQ_BIT, res, flags & GRE_SEQ); + __assign_bit(IP_TUNNEL_STRICT_BIT, res, flags & GRE_STRICT); + __assign_bit(IP_TUNNEL_REC_BIT, res, flags & GRE_REC); + __assign_bit(IP_TUNNEL_VERSION_BIT, res, flags & GRE_VERSION); + + ip_tunnel_flags_copy(dst, res); +} + +static inline __be16 gre_tnl_flags_to_gre_flags(const unsigned long *tflags) +{ + __be16 flags = 0; + + if (test_bit(IP_TUNNEL_CSUM_BIT, tflags)) + flags |= GRE_CSUM; + if (test_bit(IP_TUNNEL_ROUTING_BIT, tflags)) + flags |= GRE_ROUTING; + if (test_bit(IP_TUNNEL_KEY_BIT, tflags)) + flags |= GRE_KEY; + if (test_bit(IP_TUNNEL_SEQ_BIT, tflags)) + flags |= GRE_SEQ; + if (test_bit(IP_TUNNEL_STRICT_BIT, tflags)) + flags |= GRE_STRICT; + if (test_bit(IP_TUNNEL_REC_BIT, tflags)) + flags |= GRE_REC; + if (test_bit(IP_TUNNEL_VERSION_BIT, tflags)) + flags |= GRE_VERSION; + + return flags; +} + +static inline void gre_build_header(struct sk_buff *skb, int hdr_len, + const unsigned long *flags, __be16 proto, + __be32 key, __be32 seq) +{ + IP_TUNNEL_DECLARE_FLAGS(cond) = { }; + struct gre_base_hdr *greh; + + skb_push(skb, hdr_len); + + skb_set_inner_protocol(skb, proto); + skb_reset_transport_header(skb); + greh = (struct gre_base_hdr *)skb->data; + greh->flags = gre_tnl_flags_to_gre_flags(flags); + greh->protocol = proto; + + __set_bit(IP_TUNNEL_KEY_BIT, cond); + __set_bit(IP_TUNNEL_CSUM_BIT, cond); + __set_bit(IP_TUNNEL_SEQ_BIT, cond); + + if (ip_tunnel_flags_intersect(flags, cond)) { + __be32 *ptr = (__be32 *)(((u8 *)greh) + hdr_len - 4); + + if (test_bit(IP_TUNNEL_SEQ_BIT, flags)) { + *ptr = seq; + ptr--; + } + if (test_bit(IP_TUNNEL_KEY_BIT, flags)) { + *ptr = key; + ptr--; + } + if (test_bit(IP_TUNNEL_CSUM_BIT, flags) && + !(skb_shinfo(skb)->gso_type & + (SKB_GSO_GRE | SKB_GSO_GRE_CSUM))) { + *ptr = 0; + if (skb->ip_summed == CHECKSUM_PARTIAL) { + *(__sum16 *)ptr = csum_fold(lco_csum(skb)); + } else { + skb->ip_summed = CHECKSUM_PARTIAL; + skb->csum_start = skb_transport_header(skb) - skb->head; + skb->csum_offset = sizeof(*greh); + } + } + } +} + +#endif |
