On 8/5/26 6:15 PM, Sohil Mehta wrote:
> Linear Address Space Separation (LASS) is a security feature that blocks
> accesses across the user/kernel boundary based on bit 63 of the linear
> address alone, before any page walk is performed. Host support for LASS
> has been merged [1][2]. This series adds the KVM virtualization support.
>
I tested this series on Sierra Forest, using the QEMU support linked
below to expose LASS to the guest.

Covered:

- Guest enumeration of LASS and enabling of CR4.LASS.
- User accesses to supervisor addresses on hardware and under
  the forced emulation prefix.
- Supervisor accesses to user addresses from a guest kernel module under
  the forced emulation prefix: reads and writes, RFLAGS.AC suppression,
  SMAP=0 behavior, implicit descriptor-table accesses, and violations at
  a branch target.
- Nested VMX: VMCLEAR with a low operand address, taking a #GP at
  RFLAGS.AC=0 and completing at AC=1, via get_vmx_mem_address() ->
  vmx_is_lass_violation().

Not covered: the TSS I/O bitmap paths in patch 2, and ENCLS.

QEMU changes to expose LASS to guests:
https://lore.kernel.org/all/[email protected]/

Tested-by: Kishen Maloor <[email protected]>


Reply via email to