From nobody Sat Jul 25 00:52:35 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BBD6148BD57 for ; Tue, 21 Jul 2026 10:28:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784629718; cv=none; b=LRSAeNcL84D63oTd7m72o972/1RC747z53PvC+MmHDFHHy3SkDJqMq2x1zsgVZCIbXZEf5RuIzHXZ/1MhuQpThbDkKtWuddBPqzSx7VM9tvsU1psUiYKzn2SKVW/ySRAQHuVAz/MqeE0Y4xUyYFJ/eV/bNcv+k+9xBOYq33FXnM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784629718; c=relaxed/simple; bh=flLnTzzvdktYAMXGKCG/ht6BWQVMu8ko2+dOzbhNc0o=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=e4sNQug09Fwo/D3aIluYOCKXWuybRPugL6Ih9F4ukdHSZ5eUom2m35e+bw7e/eN9rXiQltwUogqtHOz1vjbFlTiZShhSUrY9skZBeQfWQGKzM67HB+oeC7c8HpUujwIJ+Qqkt40hEDAJORazDkxDV0ZUC/voutI7fPt6RjlkbSU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=U4Pm9ix+; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=HFW2KGkm; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="U4Pm9ix+"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="HFW2KGkm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784629715; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=qX+yOp5vEEJO47GrrgFjd6hpRsB9whe/kZX5TD9uf8A=; b=U4Pm9ix+2hPMkrSv3V1WGo1CFGbhONS3Y97fVKqDDkAi4KtAE7geOBXsvfTCljsuYGtBgl 1RgvZWEbteyjgaE87ovqADs7Eq4nNlkDWunrO+h40GjSrdO0gCeM11gnLWFRZUHp4LbZEm lReePLb5XXiBSawTDxwjlFiYtTB4P1E= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-515-6lTMFcvMP62n29Tu63DSKw-1; Tue, 21 Jul 2026 06:28:34 -0400 X-MC-Unique: 6lTMFcvMP62n29Tu63DSKw-1 X-Mimecast-MFC-AGG-ID: 6lTMFcvMP62n29Tu63DSKw_1784629713 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-493fa6e28a7so100051185e9.1 for ; Tue, 21 Jul 2026 03:28:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1784629713; x=1785234513; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=qX+yOp5vEEJO47GrrgFjd6hpRsB9whe/kZX5TD9uf8A=; b=HFW2KGkmOX203n1dk6XQ/3ewss8l2aL3ZbRRVhIXtQcpUDXvGZdgX/kX1F91DM7KMf 4QaerTq31ay/RoZ4GqC6J6SX16AjqAZE73wFjKPCLwIgH0/xQKhyAcd92xIjegrBUcqH tgUSmidMLMsE4Kfx88Dt3ddFzAlodgUDjfUIvjzB1v1sgYiGkhleqLUnkJeZn29moGsp ZHe/BZ5hqJFDpuq1PJfpsyF6kM+5IRt6TOUny9+0DHS1CALDUVZGdR4RzOLMuqa4cOTQ ZyBY3ZqpXAmvdWH2Ts24OdzAOgea0nYbC56Qf7efPHh21LMMRHid44BsonKse7lsMUJ3 yL9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784629713; x=1785234513; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qX+yOp5vEEJO47GrrgFjd6hpRsB9whe/kZX5TD9uf8A=; b=r70t75G+dE3XdPRYW7xQYOY+Jqwzc7lrYXAVOWrX1ihAKx0pVAXvPzIkcK1c7pW0Mk gZmGQCAnmtgyMYLWgwlDO6z/T1jAaLeHMEXsC+VMVzdMIb9IfqK0Wbkz4REaQQ3Ada4X N/B0M5yMoDq/H23bbPo6DOVLpVqoMgYr7CAcNkzvdTXg+GMlAdEOi6PFpUYLNvPVpkgj i6FzAKoPaZCyJYXDMOjyEHS4hE7hPFDfS/kKGlFvyTcjCSeAiF+ZlspOKDNiBeIg0487 5ik7ncQP4L7wEfvd2fH37MP9cLF4gv0np+bCYbXxGn1LwuTdQkQAhtpCR5yvzcGRQb+f OINQ== X-Gm-Message-State: AOJu0YziC9AkiShGYpprzUMSY33ThE2yZg0O4X84GGPmhirdPXPjxpqm up9ag6278vMNEbj6LwH5zpngW7p7ixBm+F4D0mWDZGkjvKl/LIcOKCfhCvOFsMfqOakzvOCno12 p27c7TFOPdmJ+i+C5JvtAjloGhfWCiamVtALXA2nAW4ktfvfQ76lR41pEVI854mWbS606LMB3mR DBmeGXfZNYRbsqicicHB4iII6sTyRi1hNcvH3b6GR+yLL0twBEsg== X-Gm-Gg: AfdE7ckJtTX41NCQAnqmNifGu9u8duJo+PdcbqzJonhSnIASET5WDoq9E1MeJ/2XlTg FdxSKcxxkwuCCTZKnue0SkzJUSBzl8zX6wrCUZn7DWCCH4jEoVthKjERgws3m10mmKFJcF9xcSV PdL+1BTS+kuS7gH/gxgSc2R7KZaoSD1vBMIrleYjpzJSaY4CNCTHmIcjwbvd7ksTqH5mujXDIwR FJaFW5abupgrm/q4qbLQ/d9GmwFDUft721z05YVQOGjmBduFUDxn14a8uE9AWzV2exTrkfa1lGi 2xEbGTWgr1Tla4sfNNrXxh79ddDk4NBzSacbhysT0/oFAJpFkL1+6rwbwoL4lU8ka6G4bUP1K8d 7OnHCxviTMjG9uvIr0+6Rn4LKTTpVHIayIwL3I3ii3JCzXRrS/0N6R5z93e/WeDhujyR+JtXXoD bNi4f+ X-Received: by 2002:a05:600c:3510:b0:493:cc25:85cb with SMTP id 5b1f17b1804b1-4954a3e20b1mr207187255e9.8.1784629713332; Tue, 21 Jul 2026 03:28:33 -0700 (PDT) X-Received: by 2002:a05:600c:3510:b0:493:cc25:85cb with SMTP id 5b1f17b1804b1-4954a3e20b1mr207186825e9.8.1784629712755; Tue, 21 Jul 2026 03:28:32 -0700 (PDT) Received: from [192.168.10.48] ([151.49.94.110]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-495653687b2sm67947495e9.1.2026.07.21.03.28.31 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 21 Jul 2026 03:28:31 -0700 (PDT) From: Paolo Bonzini To: linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: Sean Christopherson , Hyunwoo Kim , stable@vger.kernel.org Subject: [PATCH] KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Date: Tue, 21 Jul 2026 12:28:29 +0200 Message-ID: <20260721102829.313226-1-pbonzini@redhat.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Sean Christopherson Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. If reclaiming shadow pages zaps an in-use root, i.e. marks it invalid, then KVM will attempt to map memory into an invalid root. On its own, populating an invalid root is "fine", but because child shadow pages inherit their parent's role, any children created during the map/fetch will be created as invalid pages, thus violating KVM's invariant that invalid pages are never on the list of active MMU pages. Note, the underlying flaw has existed since KVM first started tracking invalid roots in 2008 (commit 2e53d63acba7, "KVM: MMU: ignore zapped root pagetables"), but the true badness only came along in 2020 (Linux 5.9) with the invariant that invalid shadow pages can't be on the list of active pages. Note #2, inheriting role.invalid when creating child shadow pages is also far from ideal; that flaw will be addressed separately. Reported-by: Hyunwoo Kim Fixes: f95eec9bed76 ("KVM: x86/mmu: Don't put invalid SPs back on the list = of active pages") Cc: stable@vger.kernel.org Signed-off-by: Sean Christopherson Signed-off-by: Paolo Bonzini --- arch/x86/kvm/mmu/mmu.c | 9 +++++---- arch/x86/kvm/mmu/paging_tmpl.h | 10 ++++++---- 2 files changed, 11 insertions(+), 8 deletions(-) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 234d0a95abf5..41f92ed1ca37 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -4852,16 +4852,17 @@ static int direct_page_fault(struct kvm_vcpu *vcpu,= struct kvm_page_fault *fault if (r !=3D RET_PF_CONTINUE) return r; =20 - r =3D RET_PF_RETRY; write_lock(&vcpu->kvm->mmu_lock); =20 - if (is_page_fault_stale(vcpu, fault)) - goto out_unlock; - r =3D make_mmu_pages_available(vcpu); if (r) goto out_unlock; =20 + if (is_page_fault_stale(vcpu, fault)) { + r =3D RET_PF_RETRY; + goto out_unlock; + } + r =3D direct_map(vcpu, fault); =20 out_unlock: diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h index df3ae0c7ec2c..1ba840a73b7a 100644 --- a/arch/x86/kvm/mmu/paging_tmpl.h +++ b/arch/x86/kvm/mmu/paging_tmpl.h @@ -864,15 +864,17 @@ static int FNAME(page_fault)(struct kvm_vcpu *vcpu, s= truct kvm_page_fault *fault } #endif =20 - r =3D RET_PF_RETRY; write_lock(&vcpu->kvm->mmu_lock); =20 - if (is_page_fault_stale(vcpu, fault)) - goto out_unlock; - r =3D make_mmu_pages_available(vcpu); if (r) goto out_unlock; + + if (is_page_fault_stale(vcpu, fault)) { + r =3D RET_PF_RETRY; + goto out_unlock; + } + r =3D FNAME(fetch)(vcpu, fault, &walker); =20 out_unlock: --=20 2.55.0