From nobody Thu Sep 24 19:05:15 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1790251017; cv=none; d=zohomail.com; s=zohoarc; b=nwfCFIgBndVXaHBooCtEphN/x8Ib7LU1ttzzGKCc7CQV2pCnDJE4ylfCanZ1M0A81wCbxKOp7iypEgbPbCPTVm2M33Jdl9XoucdQ0uwPQ/CKzxdVpW8sBfUWYJbKTRibxYAABatF52BOPz4t8hLdWB2Ho3OWVdiKQWiw6oyjVhA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790251017; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=eTWX2WdGLYZXeD1eAt/KWVZ7FoLWWCD3HQ4uh8l7BPI=; b=nOqN9fuAXy+n0Dugx7UsW5HsqxX0VWfSxwmzjWTobn6aNXXRwoUllv3xzPSFVcZSfUSj3mlnLCnqbuwu1goznAhA/QL3YVSWvh2qhu1frdyBTEh8Ubt0oJWkzy+tHXYybB74LUtEYH1o9sJCXBUw1+vodepEZG7XJ2pnC7RcOXU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1790251017410581.0330684303376; Thu, 24 Sep 2026 04:56:57 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1432147.1653657 (Exim 4.92) (envelope-from ) id 1x9i42-0002WF-FB; Thu, 24 Sep 2026 11:56:34 +0000 Received: by outflank-mailman (output) from mailman id 1432147.1653657; Thu, 24 Sep 2026 11:56:34 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i42-0002W8-BM; Thu, 24 Sep 2026 11:56:34 +0000 Received: by outflank-mailman (input) for mailman id 1432147; Thu, 24 Sep 2026 11:56:33 +0000 Received: from mx.expurgate.net ([194.145.224.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i41-0002W0-RZ for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 11:56:33 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x9i40-00ESgq-Lf for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 13:56:32 +0200 Received: from [10.42.69.1] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6ab50fe7-bab6-0a2a0a5309dd-0a2a4501a264-18 for ; Thu, 24 Sep 2026 13:56:32 +0200 Received: from [185.255.28.18] (helo=prod-mta-13.swg-srv.net) by tlsNG-d62444.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6ab50ff0-5984-0a2a45010019-b9ff1c128407-3 for ; Thu, 24 Sep 2026 13:56:32 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a0d3463da200072c4.003 for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Thu, 24 Sep 2026 11:56:31 +0000 Received: from localhost.localdomain (88-188-240-210.subs.proxad.net [88.188.240.210]) (Authenticated sender: teddy.astie@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id 33B0181C7E; Thu, 24 Sep 2026 13:56:30 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=eTWX2WdGLYZXeD1eAt/KWVZ7FoLWWCD3HQ4uh8l7BPI=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=oSTt+Gv1Jd6mQo4POXduteqWgiYTVw6R3vIIf1aNCGPlrGn0prdCfi3zr/dPJrmgXqnDgZFH+ qJWvevvTVy9T7PYDA/tXRSRcu1Ap+5FZjFhU2xYwdKcn4zJvKufhMIFYbArbbiMJTRIWzvfnSK0 2k5ePji6vT8u3PubePAMlTJNd26RKLStkMFo9V0mozzbNor9Skj6UO863rG5PBtkBMWE2ZI72hv XaLvnIzGFp+g2XswtghY/DPabeq/uMco3dO+As7nXv0OkdoeOMjiyW+YW8vRQGa4mmj6nl4K+Fo gA5/mnrpiXEATVfEhI+urH/59pg2keQ2k+4g8BDCNZTQ== X-Zone-Loop: 84793b4c4493e596a76e7d3e1c882968d7b48f441399 x-campaign-type: default x-transaction-id: 7dfe51b2-bf94-4bf8-92b5-f687f16a9af1 x-swg-uid: 01-6621afb4-7c13-42f1-964d-3681abcbc246 X-Mailer: Sweego Message-ID: <1790250991.8631fc262581453bbf619ec5b2062170.1a0d3463da200072c4@vates.tech> x-swg-bid: 1790250991.8631fc262581453bbf619ec5b2062170.1a0d3463da200072c4 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Teddy Astie To: xen-devel@lists.xenproject.org Cc: Teddy Astie , Jan Beulich , Andrew Cooper , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Jason Andryuk Subject: [PATCH 1/3] vm_event: svm: Don't BUG() when enabling intercept on hypervisor MSR Date: Thu, 24 Sep 2026 13:56:02 +0200 In-Reply-To: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> References: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.3d5.7b6538e51e68e334.1a0d3463b1b.4a3c00cbe7847fd8=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1790250990364 X-purgate-ID: tlsNG-d62444/1790250992-BE27A757-864A250C/0/0 X-purgate-type: clean X-purgate-size: 1686 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1790251021027158500 ---=Part.3d5.7b6538e51e68e334.1a0d3463b1b.4a3c00cbe7847fd8=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" svm_msrbits() only cover MSRs in the ranges specified in APM and returns NULL for all the other ones (i.e hypervisor range), which triggers the BUG_ON() that follows. APM specifies that MSR outside the architectural and AMD specific ranges are unconditionally intercepted, hence don't require any specific handling by SVM logic, fix this by ignoring cases when msr_bit is NULL. This is only reachable with CONFIG_VM_EVENT using XEN_DOMCTL_MONITOR_EVENT_= MOV_TO_MSR to configure a MSR intercept in the hypervisor range (0x40000000=E2=80=930x= 40001fff). Fixes: 6e9fc4d628b6 ("hvm/svm: Enable MSR events") Signed-off-by: Teddy Astie --- xen/arch/x86/hvm/svm/svm.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/xen/arch/x86/hvm/svm/svm.c b/xen/arch/x86/hvm/svm/svm.c index b5fc459e62..7a16289f85 100644 --- a/xen/arch/x86/hvm/svm/svm.c +++ b/xen/arch/x86/hvm/svm/svm.c @@ -237,7 +237,9 @@ void svm_intercept_msr(struct vcpu *v, uint32_t msr, in= t flags) const struct domain *d =3D v->domain; =20 msr_bit =3D svm_msrbit(v->arch.hvm.svm.msrpm, msr); - BUG_ON(msr_bit =3D=3D NULL); + if ( msr_bit =3D=3D NULL ) + return; + msr &=3D 0x1fff; =20 if ( flags & MSR_INTERCEPT_READ ) --=20 2.55.0 --=20 Teddy Astie | Vates XCP-ng Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.3d5.7b6538e51e68e334.1a0d3463b1b.4a3c00cbe7847fd8=--- From nobody Thu Sep 24 19:05:15 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1790251041; cv=none; d=zohomail.com; s=zohoarc; b=KyeoFgqetrqaoloFn1Ytkny9a7M0/YG7hBV53ndmHBZP9TeV0ssD07OY3g3eh+swI7asrIQ2LlXiwVY7ktJdU3j//g7HNSQtuU+DEXOkSBSpWv1S+zanfumYaLBtYqSJKfnmrToRU2CUmzu5BLMYNr3AQHSdozhdgPvVfmIqWBA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790251041; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vfl7bGD+ze0wdzwbimwGjn278qJxmVdn7i/sXvYd5YU=; b=h510TLOoxnm9ZwtFFKO9xqeQJ9XPLnv17xP0CyIaJzs0tHm1NDWf5byN8nWPu98L5iJjqerqbUptbdPtZhVlxThuruC739hm/5fRCbu+u4Oqe7tR2R7B92jzohXS0b5vGbrgfAOxdEyzMEWqNNV/vSWTy74t7BEWTokjqBSrRj4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1790251041069293.9954840761677; Thu, 24 Sep 2026 04:57:21 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1432153.1653664 (Exim 4.92) (envelope-from ) id 1x9i4c-00030U-Od; Thu, 24 Sep 2026 11:57:10 +0000 Received: by outflank-mailman (output) from mailman id 1432153.1653664; Thu, 24 Sep 2026 11:57:10 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i4c-00030N-LW; Thu, 24 Sep 2026 11:57:10 +0000 Received: by outflank-mailman (input) for mailman id 1432153; Thu, 24 Sep 2026 11:57:09 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i4b-00030A-I3 for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 11:57:09 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x9i4a-00GHwW-Uv for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 13:57:08 +0200 Received: from [10.42.69.9] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6ab51009-bab6-0a2a0a5309dd-0a2a45099cb8-38 for ; Thu, 24 Sep 2026 13:57:08 +0200 Received: from [185.255.28.35] (helo=prod-mta-13-02.swg-srv.net) by tlsNG-bad1c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6ab51014-be1a-0a2a45090019-b9ff1c239d61-3 for ; Thu, 24 Sep 2026 13:57:08 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-02.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a0d346bb7600072c4.003 for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Thu, 24 Sep 2026 11:57:03 +0000 Received: from localhost.localdomain (88-188-240-210.subs.proxad.net [88.188.240.210]) (Authenticated sender: teddy.astie@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id A0AD081BC9; Thu, 24 Sep 2026 13:57:02 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=vfl7bGD+ze0wdzwbimwGjn278qJxmVdn7i/sXvYd5YU=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=D9JGfLSbCVAuwEO1Oj3DK8JcoYiGThpPRrn5J+3bbraEw8XI3ijj+YVANc8GJ/Ts+UcKrZPQb 1k7nNs75+GB6ptYLBWb9qjPdJRi71yj1GIfHJbqUGvAR1igZthNKtFaAd5jyxqM4fXICn5Pef4b acHsKuuFfmbGJjs7mg/RZW0M92iXvL/CdKeDC/S3Jjs4UAvqSU0SXiFfV4WWkqzOilwdeqnmzaK BQHIEM9EH6jveL15OgcBoV1LmzwKG0XX7KSszD0XxGubNSDGKNBk8lJnlKQPcVpwBwI1lC0BYrL Snu3aib8l/X1EgEc8gXuwr2yPBmLOfeBAISIQ3OOI55Q== X-Zone-Loop: 13123eb627616702cda6ae9aeb66064768f2e2126120 x-campaign-type: default x-transaction-id: eb13b39e-63ea-4c42-9183-302a6576ce27 x-swg-uid: 01-158bd62e-43bf-41b1-84c9-e1ad41e7e18b X-Mailer: Sweego Message-ID: <1790251023.8631fc262581453bbf619ec5b2062170.1a0d346bb7600072c4@vates.tech> x-swg-bid: 1790251023.8631fc262581453bbf619ec5b2062170.1a0d346bb7600072c4 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Teddy Astie To: xen-devel@lists.xenproject.org Cc: Teddy Astie , Jan Beulich , Andrew Cooper , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Jason Andryuk Subject: [PATCH 2/3] vm_event: svm: Fix incorrect monitored_msr() check Date: Thu, 24 Sep 2026 13:56:35 +0200 In-Reply-To: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> References: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.3d6.9b770b8b9dcd803a.1a0d346b9d6.9cd4415412d644c6=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1790251022806 X-purgate-ID: tlsNG-bad1c0/1790251028-BF6D2034-0AA31886/0/0 X-purgate-type: clean X-purgate-size: 2120 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1790251043159158500 ---=Part.3d6.9b770b8b9dcd803a.1a0d346b9d6.9cd4415412d644c6=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" monitored_msr() is called with truncated MSR values (&=3D 0x1fff) which doesn't match the original one, making the check incorrect. Fix that by keeping the msr value intact and computing the bitmap offset separately (in msr_offset). Fixes: 2746088d9cb4 ("svm: don't clear interception for MSRs required for i= ntrospection") Signed-off-by: Teddy Astie --- Should we multiply by 2 msr_offset instead of doing that in {set,clear}_bit= () ? xen/arch/x86/hvm/svm/svm.c | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/xen/arch/x86/hvm/svm/svm.c b/xen/arch/x86/hvm/svm/svm.c index 7a16289f85..d986f3aa8f 100644 --- a/xen/arch/x86/hvm/svm/svm.c +++ b/xen/arch/x86/hvm/svm/svm.c @@ -234,23 +234,22 @@ svm_msrbit(unsigned long *msr_bitmap, uint32_t msr) void svm_intercept_msr(struct vcpu *v, uint32_t msr, int flags) { unsigned long *msr_bit; + unsigned int msr_offset =3D msr & 0x1fff; const struct domain *d =3D v->domain; =20 msr_bit =3D svm_msrbit(v->arch.hvm.svm.msrpm, msr); if ( msr_bit =3D=3D NULL ) return; =20 - msr &=3D 0x1fff; - if ( flags & MSR_INTERCEPT_READ ) - __set_bit(msr * 2, msr_bit); + __set_bit(msr_offset * 2, msr_bit); else if ( !monitored_msr(d, msr) ) - __clear_bit(msr * 2, msr_bit); + __clear_bit(msr_offset * 2, msr_bit); =20 if ( flags & MSR_INTERCEPT_WRITE ) - __set_bit(msr * 2 + 1, msr_bit); + __set_bit(msr_offset * 2 + 1, msr_bit); else if ( !monitored_msr(d, msr) ) - __clear_bit(msr * 2 + 1, msr_bit); + __clear_bit(msr_offset * 2 + 1, msr_bit); } =20 #ifdef CONFIG_VM_EVENT --=20 2.55.0 --=20 Teddy Astie | Vates XCP-ng Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.3d6.9b770b8b9dcd803a.1a0d346b9d6.9cd4415412d644c6=--- From nobody Thu Sep 24 19:05:15 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1790251073; cv=none; d=zohomail.com; s=zohoarc; b=KabuZZX9na4ZZRXl7puRxpMycg6oXVd6oKGE0Mv9pmzeAcBzbP4UBrm78ONVQVW1cTvHeiy/y3UCfz45wIhB5LqJ6gJTLBzIx3t+BEpIFDd7rMNPjACHTx+H7R+s3cqX7V6GGJfkQstK/DaAzFRymRIzSfSbGEdbp0+JgNtpg9U= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1790251073; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YSK+oBEhJCxxZzsM9y3NERCslvzp5sV47ASUQ0IT6sQ=; b=UWcxLA2TRvF+v+thppDjFflnpp88AdTmDjstzBOI5uLeMf8SMPDNuQB2TWhZZKUx0tNIfkCNtl2OPqnb9JMl3cSEBOZGnopjzyIrV+ULVjMpWV96iqEQuvfRESTUuNFyiRjKXuUV4g2+wDsASgFJOAsWKI+4ypdNW6bIckgsxFQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1790251073546431.73379021488154; Thu, 24 Sep 2026 04:57:53 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1432158.1653673 (Exim 4.92) (envelope-from ) id 1x9i52-0003gB-W8; Thu, 24 Sep 2026 11:57:36 +0000 Received: by outflank-mailman (output) from mailman id 1432158.1653673; Thu, 24 Sep 2026 11:57:36 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i52-0003g4-TT; Thu, 24 Sep 2026 11:57:36 +0000 Received: by outflank-mailman (input) for mailman id 1432158; Thu, 24 Sep 2026 11:57:35 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x9i51-0003Zl-AA for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 11:57:35 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x9i50-009XC0-NK for xen-devel@lists.xenproject.org; Thu, 24 Sep 2026 13:57:34 +0200 Received: from [10.42.69.4] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6ab5102d-2eae-0a2a0a5409dd-0a2a4504e240-4 for ; Thu, 24 Sep 2026 13:57:34 +0200 Received: from [185.255.28.35] (helo=prod-mta-13-02.swg-srv.net) by tlsNG-ebf023.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6ab5102e-b57f-0a2a45040019-b9ff1c238647-3 for ; Thu, 24 Sep 2026 13:57:34 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-02.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a0d347225a00072c4.002 for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Thu, 24 Sep 2026 11:57:29 +0000 Received: from localhost.localdomain (88-188-240-210.subs.proxad.net [88.188.240.210]) (Authenticated sender: teddy.astie@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id CD01C81C7E; Thu, 24 Sep 2026 13:57:28 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=YSK+oBEhJCxxZzsM9y3NERCslvzp5sV47ASUQ0IT6sQ=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=opwvSSeaIJAYQFGwOrE+4Z9hfuOxsUVQHroj+0c3lInNotR48+FoVZIQFZGqTJOkp38IfXV95 QOGnA7JoasjQlz2yDv9RzH612+AU7vYeDdnc9W3pEQdJjf8zyq9Lv+DzgukDP74ipB4MN7zw7mt q42pyDg+NpCmtbeH2Q08OTejFqo2kGFw/khaqapw6CzD7MW1Fpn+3ZoGs3Q3+jW82YGvYKxyAoF vpHJ1opFe/2BKNwRp8RprOY325qOb8ijsRfz6UtTkRezxNBkPmXzY11uhNtkzsdEsRNnAzBi2vQ RrRkF5Ar5osO6jDMlZ0OgB4Ds778YatiEGkKuPzSzjsw== X-Zone-Loop: 20541bc9a38802228b6bffc229bb790710352b308f84 x-campaign-type: default x-transaction-id: 6c62f9b7-f9f4-40a4-b512-ea2630e8d76d x-swg-uid: 01-16fd0064-d4a8-427c-b52a-feec3ef13f2b X-Mailer: Sweego Message-ID: <1790251049.8631fc262581453bbf619ec5b2062170.1a0d347225a00072c4@vates.tech> x-swg-bid: 1790251049.8631fc262581453bbf619ec5b2062170.1a0d347225a00072c4 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Teddy Astie To: xen-devel@lists.xenproject.org Cc: Teddy Astie , Jan Beulich , Andrew Cooper , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= Subject: [PATCH 3/3] vm_event: vmx: Allow intercepting hypervisor MSRs in debug builds Date: Thu, 24 Sep 2026 13:57:07 +0200 In-Reply-To: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> References: <1790250881.8631fc262581453bbf619ec5b2062170.1a0d344933500072c4@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.3d7.f43ed18a8ff1f602.1a0d3472009.a677eb19d0ec6198=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1790251048970 X-purgate-ID: tlsNG-ebf023/1790251054-C28C9B50-A43345E1/0/0 X-purgate-type: clean X-purgate-size: 1594 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1790251075072158500 ---=Part.3d7.f43ed18a8ff1f602.1a0d3472009.a677eb19d0ec6198=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" MSRs that are not covered by MSR bitmap (e.g hypervisor range) are unconditionally intercepted by hardware and don't need any specific handlin= g. However, vmx_set_msr_intercept() wrongly ASSERT() if the MSR is a part of t= he hypervisor range. Fix it by skipping the ASSERT() in this case. This is only reachable with CONFIG_VM_EVENT using XEN_DOMCTL_MONITOR_EVENT_= MOV_TO_MSR to configure a MSR intercept in the hypervisor range (0x40000000=E2=80=930x= 40001fff). Fixes: 62999081ca27 ("x86/vmx: Introduce and use struct vmx_msr_bitmap") Signed-off-by: Teddy Astie --- xen/arch/x86/hvm/vmx/vmcs.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xen/arch/x86/hvm/vmx/vmcs.c b/xen/arch/x86/hvm/vmx/vmcs.c index 8e52ef4d49..050168bbce 100644 --- a/xen/arch/x86/hvm/vmx/vmcs.c +++ b/xen/arch/x86/hvm/vmx/vmcs.c @@ -986,7 +986,7 @@ void vmx_set_msr_intercept(struct vcpu *v, unsigned int= msr, if ( type & VMX_MSR_W ) set_bit(msr, msr_bitmap->write_high); } - else + else if ( !((msr >=3D 0x40000000U) && (msr <=3D 0x40001fffU)) ) ASSERT(!"MSR out of range for interception\n"); } =20 --=20 2.55.0 --=20 Teddy Astie | Vates XCP-ng Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.3d7.f43ed18a8ff1f602.1a0d3472009.a677eb19d0ec6198=---