b971b8
From 781e82d0330afe60ab1c366e43dfe8292fcf68eb Mon Sep 17 00:00:00 2001
b971b8
Message-Id: <781e82d0330afe60ab1c366e43dfe8292fcf68eb@dist-git>
b971b8
From: Jiri Denemark <jdenemar@redhat.com>
b971b8
Date: Tue, 26 May 2020 10:58:53 +0200
b971b8
Subject: [PATCH] cpu: Honor check='full' for host-passthrough CPUs
b971b8
MIME-Version: 1.0
b971b8
Content-Type: text/plain; charset=UTF-8
b971b8
Content-Transfer-Encoding: 8bit
b971b8
b971b8
The check attribute was completely ignored for host-passthrough CPUs
b971b8
even if they explicitly requested some features to be enabled. For
b971b8
example, a domain with the following CPU definition
b971b8
b971b8
  <cpu mode='host-passthrough' check='full'>
b971b8
    <feature policy='require' name='svm'/>
b971b8
  </cpu>
b971b8
b971b8
would happily start even when 'svm' cannot be enabled.
b971b8
b971b8
Let's call virCPUArchUpdateLive for host-passthrough CPUs with
b971b8
VIR_CPU_CHECK_FULL to make sure the architecture specific code can
b971b8
validate the provided virtual CPU against the desired definition.
b971b8
b971b8
https://bugzilla.redhat.com/show_bug.cgi?id=1515677
b971b8
b971b8
Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
b971b8
Reviewed-by: Ján Tomko <jtomko@redhat.com>
b971b8
(cherry picked from commit ac36a824641862dcac057c6403b27ab1e91874f5)
b971b8
b971b8
https://bugzilla.redhat.com/show_bug.cgi?id=1839999
b971b8
b971b8
Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
b971b8
Message-Id: <b8d30055a0df31c423d6c1832ca0bfbf3eafd222.1590483392.git.jdenemar@redhat.com>
b971b8
Reviewed-by: Ján Tomko <jtomko@redhat.com>
b971b8
---
b971b8
 src/cpu/cpu.c     |  3 ++-
b971b8
 src/cpu/cpu_x86.c | 10 +++++++++-
b971b8
 2 files changed, 11 insertions(+), 2 deletions(-)
b971b8
b971b8
diff --git a/src/cpu/cpu.c b/src/cpu/cpu.c
b971b8
index 1cb2dd04f4..f2a0f560f6 100644
b971b8
--- a/src/cpu/cpu.c
b971b8
+++ b/src/cpu/cpu.c
b971b8
@@ -647,7 +647,8 @@ virCPUUpdateLive(virArch arch,
b971b8
     if (!driver->updateLive)
b971b8
         return 1;
b971b8
 
b971b8
-    if (cpu->mode == VIR_CPU_MODE_CUSTOM) {
b971b8
+    if (cpu->mode == VIR_CPU_MODE_CUSTOM ||
b971b8
+        cpu->check == VIR_CPU_CHECK_FULL) {
b971b8
         if (driver->updateLive(cpu, dataEnabled, dataDisabled) < 0)
b971b8
             return -1;
b971b8
 
b971b8
diff --git a/src/cpu/cpu_x86.c b/src/cpu/cpu_x86.c
b971b8
index 9e686a86d2..8c865bdaa4 100644
b971b8
--- a/src/cpu/cpu_x86.c
b971b8
+++ b/src/cpu/cpu_x86.c
b971b8
@@ -3009,8 +3009,10 @@ virCPUx86UpdateLive(virCPUDefPtr cpu,
b971b8
                     virCPUDataPtr dataEnabled,
b971b8
                     virCPUDataPtr dataDisabled)
b971b8
 {
b971b8
+    bool hostPassthrough = cpu->mode == VIR_CPU_MODE_HOST_PASSTHROUGH;
b971b8
     virCPUx86MapPtr map;
b971b8
     virCPUx86ModelPtr model = NULL;
b971b8
+    virCPUx86ModelPtr modelDisabled = NULL;
b971b8
     virCPUx86Data enabled = VIR_CPU_X86_DATA_INIT;
b971b8
     virCPUx86Data disabled = VIR_CPU_X86_DATA_INIT;
b971b8
     virBuffer bufAdded = VIR_BUFFER_INITIALIZER;
b971b8
@@ -3026,6 +3028,10 @@ virCPUx86UpdateLive(virCPUDefPtr cpu,
b971b8
     if (!(model = x86ModelFromCPU(cpu, map, -1)))
b971b8
         goto cleanup;
b971b8
 
b971b8
+    if (hostPassthrough &&
b971b8
+        !(modelDisabled = x86ModelFromCPU(cpu, map, VIR_CPU_FEATURE_DISABLE)))
b971b8
+        goto cleanup;
b971b8
+
b971b8
     if (dataEnabled &&
b971b8
         x86DataCopy(&enabled, &dataEnabled->data.x86) < 0)
b971b8
         goto cleanup;
b971b8
@@ -3040,7 +3046,8 @@ virCPUx86UpdateLive(virCPUDefPtr cpu,
b971b8
 
b971b8
         if (x86DataIsSubset(&model->data, &feature->data))
b971b8
             expected = VIR_CPU_FEATURE_REQUIRE;
b971b8
-        else
b971b8
+        else if (!hostPassthrough ||
b971b8
+                 x86DataIsSubset(&modelDisabled->data, &feature->data))
b971b8
             expected = VIR_CPU_FEATURE_DISABLE;
b971b8
 
b971b8
         if (expected == VIR_CPU_FEATURE_DISABLE &&
b971b8
@@ -3101,6 +3108,7 @@ virCPUx86UpdateLive(virCPUDefPtr cpu,
b971b8
 
b971b8
  cleanup:
b971b8
     x86ModelFree(model);
b971b8
+    x86ModelFree(modelDisabled);
b971b8
     virCPUx86DataClear(&enabled);
b971b8
     virCPUx86DataClear(&disabled);
b971b8
     VIR_FREE(added);
b971b8
-- 
b971b8
2.26.2
b971b8