From nobody Thu Sep 24 19:51:08 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789050009; cv=none; d=zohomail.com; s=zohoarc; b=cdwxK3q0UCQQfI5w1ayRLnNw4SvZ4h9eJpPMWL1K3ba7vw2avb9i/Qcz99zTG2JVboXnEP/Szh/LcZMiggNkihmtcxNUDJNUMcZmWlKZLaGmQjXYFrq6FZAAkvO17OYXWIMm7R2J+RQwD0X9DQgEFYoM+mRb5rsMqr3SSK/FIYU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789050009; h=Content-Type:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=q5157ZIk+fhtfXlWXDnxrkU02QVm1vl4mMJWupMvsb4=; b=hA5Uor8LySFINYk0qcg25azIMVYBHW6lcfuLRyDWrqJCJLc9RdG2YR3mfGcC+te1jUTEpOI4a7a1TsL/LM/0Ibd3BnjNuOPSqs4GVaj6/0pfwzbKsbgbpHTYMGzb6HlbaDmJlX8Jdo8rfDC9M2WGGI5x9uQ0odj5lBfFBirSLpQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789050009525467.21945646592906; Thu, 10 Sep 2026 07:20:09 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1414795.1644514 (Exim 4.92) (envelope-from ) id 1x4fcc-000746-Nk; Thu, 10 Sep 2026 14:19:26 +0000 Received: by outflank-mailman (output) from mailman id 1414795.1644514; Thu, 10 Sep 2026 14:19:26 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x4fcc-00073z-JD; Thu, 10 Sep 2026 14:19:26 +0000 Received: by outflank-mailman (input) for mailman id 1414795; Thu, 10 Sep 2026 14:19:25 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x4fca-00073t-V7 for xen-devel@lists.xenproject.org; Thu, 10 Sep 2026 14:19:24 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x4fca-008gbB-0b for xen-devel@lists.xenproject.org; Thu, 10 Sep 2026 16:19:24 +0200 Received: from [10.42.69.9] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa2bc68-2eae-0a2a0a5409dd-0a2a4509c8f2-4 for ; Thu, 10 Sep 2026 16:19:24 +0200 Received: from [185.255.28.34] (helo=prod-mta-13-01.swg-srv.net) by tlsNG-bad1c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa2bc6b-be1a-0a2a45090019-b9ff1c22b48d-3 for ; Thu, 10 Sep 2026 16:19:23 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-01.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a08bb0014d000c4f3.002 for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Thu, 10 Sep 2026 14:19:22 +0000 Received: from localhost.localdomain (88-188-240-210.subs.proxad.net [88.188.240.210]) (Authenticated sender: teddy.astie@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id 0716F815B7; Thu, 10 Sep 2026 16:19:22 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=q5157ZIk+fhtfXlWXDnxrkU02QVm1vl4mMJWupMvsb4=; h=from:subject:date:message-id:to:cc:mime-version:content-type:feedback-id; b=OOgnb2SVQx4unlYvKmvfbdD37ZR0hveZAMwWhFaIdMj5/2UWt2hZl8fmoGZvjDZpD6X5240jV zaGXSAmr0rhzhSymfYjqClVy8H2ok6CkUVJ4fjvGg/mwfpbjoU0rersK+/pyxAgjlq35+dg7qWM 3Mt4AEZEFTgmDwHsMiD7RVMaSWcGxMxSI3XMCJ7nM3LVHF3IdHuQw8jtliFJBNOsLBx0Ij6gj8y VzDR1iBF8AFbZz9mMjExNupgsuFZpo0jwyQujYTYFBiEOG9qw1WIOueJ7NBAiCz+A3B0xmdaHuT wgXfR7vzlBxvt/FtA0pM3xnx/oh5zdB+WOZEqlgjQK/Q== X-Zone-Loop: ce52342aa4c6f8d9bd17ba046d39e84fdc35a683afa7 x-campaign-type: default x-transaction-id: de9d2505-5c97-4bfe-80d4-92ba24dfd4a0 x-swg-uid: 01-8073edbe-a982-4726-9016-40b938011ad1 X-Mailer: Sweego Message-ID: <1789049962.8631fc262581453bbf619ec5b2062170.1a08bb0014d000c4f3@vates.tech> x-swg-bid: 1789049962.8631fc262581453bbf619ec5b2062170.1a08bb0014d000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Teddy Astie To: xen-devel@lists.xenproject.org Cc: Teddy Astie , Jan Beulich , Andrew Cooper , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= Subject: [PATCH v2] vmx: Handle TDX instruction exit reasons Date: Thu, 10 Sep 2026 16:17:46 +0200 MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.86.98788a3c7f66c689.1a08baffebb.98e53e7353613c8a=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789049962172 X-purgate-ID: tlsNG-bad1c0/1789049963-3B4D3034-D326E88F/0/0 X-purgate-type: clean X-purgate-size: 3754 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789050011842158500 ---=Part.86.98788a3c7f66c689.1a08baffebb.98e53e7353613c8a=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" On hardware that supports TDX, guests can cause VMEXIT related to TDX instructions (SEAMCALL and TDCALL) regardless of VMCS configuration. Currently, that causes the domain to crash when a domain tries to use these instructions in kernel-mode, and emit #UD when used in user-mode. Adjust the behavior so that the guest always gets #UD when trying to use these instructions regardless of the privilege level that the vCPU is running. In the nested virtualization case, also reinject the exit reason to L1 rather than failing on "Unhandled nested vmexit" (leading to a L1 crash that can be caused by L2 by executing one of the TDX instructions). Signed-off-by: Teddy Astie Acked-by: Jan Beulich --- v2: - Merge both patches. - Always #UD on these VMEXIT in the non nested case xen/arch/x86/hvm/vmx/vmx.c | 2 ++ xen/arch/x86/hvm/vmx/vvmx.c | 2 ++ xen/arch/x86/include/asm/hvm/vmx/vmx.h | 2 ++ xen/arch/x86/include/asm/perfc_defn.h | 2 +- 4 files changed, 7 insertions(+), 1 deletion(-) diff --git a/xen/arch/x86/hvm/vmx/vmx.c b/xen/arch/x86/hvm/vmx/vmx.c index e55c90ce7f..98ec999cb8 100644 --- a/xen/arch/x86/hvm/vmx/vmx.c +++ b/xen/arch/x86/hvm/vmx/vmx.c @@ -4681,6 +4681,8 @@ void asmlinkage vmx_vmexit_handler(struct cpu_user_re= gs *regs) case EXIT_REASON_MWAIT_INSTRUCTION: case EXIT_REASON_MONITOR_INSTRUCTION: case EXIT_REASON_GETSEC: + case EXIT_REASON_SEAMCALL: + case EXIT_REASON_TDCALL: /* * We should never exit on GETSEC because CR4.SMXE is always 0 when * running in guest context, and the CPU checks that before getting diff --git a/xen/arch/x86/hvm/vmx/vvmx.c b/xen/arch/x86/hvm/vmx/vvmx.c index a5aa5eb163..8ef6529e26 100644 --- a/xen/arch/x86/hvm/vmx/vvmx.c +++ b/xen/arch/x86/hvm/vmx/vvmx.c @@ -2497,6 +2497,8 @@ int nvmx_n2_vmexit_handler(struct cpu_user_regs *regs, case EXIT_REASON_INVEPT: case EXIT_REASON_XSETBV: case EXIT_REASON_INVVPID: + case EXIT_REASON_SEAMCALL: + case EXIT_REASON_TDCALL: /* inject to L1 */ nvcpu->nv_vmexit_pending =3D 1; break; diff --git a/xen/arch/x86/include/asm/hvm/vmx/vmx.h b/xen/arch/x86/include/= asm/hvm/vmx/vmx.h index da04752e17..b8219e0408 100644 --- a/xen/arch/x86/include/asm/hvm/vmx/vmx.h +++ b/xen/arch/x86/include/asm/hvm/vmx/vmx.h @@ -201,6 +201,8 @@ static inline void pi_clear_sn(struct pi_desc *pi_desc) #define EXIT_REASON_XRSTORS 64 #define EXIT_REASON_BUS_LOCK 74 #define EXIT_REASON_NOTIFY 75 +#define EXIT_REASON_SEAMCALL 76 +#define EXIT_REASON_TDCALL 77 /* Remember to also update VMX_PERF_EXIT_REASON_SIZE! */ =20 /* diff --git a/xen/arch/x86/include/asm/perfc_defn.h b/xen/arch/x86/include/a= sm/perfc_defn.h index ac7439b992..102b9be6ef 100644 --- a/xen/arch/x86/include/asm/perfc_defn.h +++ b/xen/arch/x86/include/asm/perfc_defn.h @@ -6,7 +6,7 @@ PERFCOUNTER_ARRAY(exceptions, "exceptions", 32) =20 #ifdef CONFIG_HVM =20 -#define VMX_PERF_EXIT_REASON_SIZE 76 +#define VMX_PERF_EXIT_REASON_SIZE 78 #define VMEXIT_NPF_PERFC 166 #define SVM_PERF_EXIT_REASON_SIZE (VMEXIT_NPF_PERFC + 1) PERFCOUNTER_ARRAY(vmexits, "vmexits", --=20 2.55.0 --=20 Teddy Astie | Vates XCP-ng Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.86.98788a3c7f66c689.1a08baffebb.98e53e7353613c8a=---