From nobody Fri Jul 24 20:51:24 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 98C7F2F7EE7 for ; Fri, 24 Jul 2026 17:34:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784914470; cv=none; b=bktCi5AwpO5fy4U7IvZLQRAkvn+VNs+0rMFYiLYz7xDRZrGmTmFYev4dYk7UDRnhYvpBcdzQtNUrbkw4jNbpLvjj89Owm91yN19ifiGIATgH4Lsv21Oc+J2nmBhcM2q2MvACkr8YGBjNbItIoM1D1pdurii4AKF5tzxQY+hnBgE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784914470; c=relaxed/simple; bh=P/vz4YlFPpQWKS/Iy2gHb9O7M5CQuGY/6CWVmMfyjQs=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=SptzYXHXqGzUeLNwgRnvvYDRGTXLz7qBT6euRka6ktuGEQVICHZADAewRV8Bz+LP1cO4oRwJTCMFZi4OTpF2iTKCtP8BA4YcJV4UZID12TF/Zfr1X2m+2kzWp/CX7X34pXBcz1JcFPAdpSu1B/ei9LtC8/q4Y5N32gOChBeT+8k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Pzbu6oEH; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Pzbu6oEH" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-c89704da8c7so983341a12.0 for ; Fri, 24 Jul 2026 10:34:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784914468; x=1785519268; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=wLT7gNHgdr1B3mxcznzuNraCWdUDx8twv8dXwpur9iw=; b=Pzbu6oEHP5xIGrx+MIXSmcpciV8eylKCRJLfTFxYqiPa6UvGcouWYuKrYiET55Uuc7 UetiRycqtmZRGsG6PvqIc9OHgz6utR06lu+yyd7uR++YY2dnOyxW839cdZlYdDPo8qir oD31Ps+QA1cUMTSrPUS1o9K5MlFdoJz46xvhmJzoVuBPvNpLjVu8L8S5ktFwrQALADn5 PtGDNRwonP/6NSocdwj69nxay5h3liBmCbky4DiijCOdN1iJEocAJWdUKIBxQy6n9tly AOkLgWyFbubN972tNVhbMgWkIEKq3obN8RnXaW+gd8Ecoha/pagzUxtLkUCkXMSa0F6a bm+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784914468; x=1785519268; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=wLT7gNHgdr1B3mxcznzuNraCWdUDx8twv8dXwpur9iw=; b=Ud3TsQLelgSUfRhiYr5fxUPigfK3XPjNE8ddAnNBtV3dF1hJKEHhtrFA8PH5bXwp80 Vk2j9jMd8/hZbKsWnxHN0CAWot1m2GmoM3wCKKa2YOuhsW3UTd8SidXKKdxBkYq1H9tp Rlhzmmf4se68opquWRC8ciwOn0G1t7kn5eeCug0QptZgcxVMJHK7aWrgF7W66bSzobfd QF8Q3bVCB9D9VQ770Z+0/2Po2XPpDOc+mlYXQibPmf9+YHRdFJC0zvmAZo7CZqwm5R/G ilYjcwy3RcexHHU0jqRxf7QloSB/YEqP4X56JmzmmDGLv6YgIBYel1tywva7ZBxj9+nO LE3Q== X-Forwarded-Encrypted: i=1; AHgh+RoCvb6IwRcQOruP8xnILYxaF5wOr05VP13v6+/EtZuwb3vRoksE8ozdRvJJ/ZbgMMxHv7+HaM1FvF5r71Y=@vger.kernel.org X-Gm-Message-State: AOJu0YzwNiVWrzig/QyaFkiHT6NipJTDv1Aw9JxQ8nIzfYvSnu3mu+b/ lNHPCJXdH6Ztqdm1K2BXGvY/YWMRIkxL0YFaQvV53PX6sPv3H8NNHKhWd4Z7SwowYyucrUS0eAp w/5k4YQ== X-Received: from pgbcr2.prod.google.com ([2002:a05:6a02:4102:b0:c8a:8cda:bd59]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:610f:b0:3c3:ac9c:9a6e with SMTP id adf61e73a8af0-3c44b2ae3bemr9304061637.68.1784914467661; Fri, 24 Jul 2026 10:34:27 -0700 (PDT) Reply-To: Sean Christopherson Date: Fri, 24 Jul 2026 10:34:24 -0700 In-Reply-To: <20260724173425.278753-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260724173425.278753-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260724173425.278753-2-seanjc@google.com> Subject: [PATCH v3 1/2] KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+dd769db18693736eee89@syzkaller.appspotmail.com, Sashiko Bot Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When getting a to-be-injected IRQ, don't WARN if the IRQ disappeared and the VM has an in-kernel PIC, as the ExtINT handling that's routed through KVM's virtual PIC is tracked per-VM, not per-vCPU. If another vCPU grabs the IRQ, or deasserts the interrupt (which is level-triggered), then it's both expected and "fine" for a Keep the assert for split IRQCHIP VMs to help detect KVM bugs, as userspace is responsible for routing ExtINT to the intended vCPU, i.e. once an ExtINT is pending, it can't be cleared without holding the vCPU's mutex, and thus false positives are impossible. Fixes: bf672720e83c ("KVM: x86: check the kvm_cpu_get_interrupt result befo= re using it") Debugged-by: Alexander Potapenko Reported-by: syzbot+dd769db18693736eee89@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3Ddd769db18693736eee89 Closes: https://lore.kernel.org/all/6a360fdf.871e809a.2d6dda.0000.GAE@googl= e.com Signed-off-by: Sean Christopherson --- arch/x86/kvm/irq.h | 16 ++++++++++++++++ arch/x86/kvm/vmx/nested.c | 4 +++- arch/x86/kvm/x86.c | 4 +++- 3 files changed, 22 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/irq.h b/arch/x86/kvm/irq.h index 1a84ea31e7fd..eeaf527cecc4 100644 --- a/arch/x86/kvm/irq.h +++ b/arch/x86/kvm/irq.h @@ -118,6 +118,22 @@ int kvm_cpu_has_extint(struct kvm_vcpu *v); int kvm_cpu_get_extint(struct kvm_vcpu *v); int kvm_cpu_get_interrupt(struct kvm_vcpu *v); =20 +static inline void kvm_warn_on_lost_irq(struct kvm_vcpu *vcpu) +{ + /* + * WARN if an IRQ was lost between detecting the IRQ and grabbing the + * IRQ for injection, unless it's possible the lost IRQ was due to one + * of the exceptional cases below. + * + * If the VM has an in-kernel PIC, the ExtINT handling that's routed + * through KVM's virtual PIC is tracked per-VM, not per-vCPU. If + * another vCPU grabs the IRQ, or deasserts the interrupt (which is + * level-triggered), then it's both expected and "fine" for an IRQ + * seemingly be "lost" from this vCPU's perspective. + */ + WARN_ON_ONCE(!pic_in_kernel(vcpu->kvm)); +} + void kvm_inject_pending_timer_irqs(struct kvm_vcpu *vcpu); void kvm_inject_apic_timer_irqs(struct kvm_vcpu *vcpu); void kvm_apic_nmi_wd_deliver(struct kvm_vcpu *vcpu); diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 0635e92471c8..c28a3ec4e4b7 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -4464,8 +4464,10 @@ static int vmx_check_nested_events(struct kvm_vcpu *= vcpu) } =20 irq =3D kvm_apic_has_interrupt(vcpu); - if (WARN_ON_ONCE(irq < 0)) + if (unlikely(irq < 0)) { + kvm_warn_on_lost_irq(vcpu); goto no_vmexit; + } =20 /* * If the IRQ is L2's PI notification vector, process posted diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index 0626e835e9eb..e97b76b7794f 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -7686,10 +7686,12 @@ static int kvm_check_and_inject_events(struct kvm_v= cpu *vcpu, if (r) { int irq =3D kvm_cpu_get_interrupt(vcpu); =20 - if (!WARN_ON_ONCE(irq =3D=3D -1)) { + if (likely(irq !=3D -1)) { kvm_queue_interrupt(vcpu, irq, false); kvm_x86_call(inject_irq)(vcpu, false); WARN_ON(kvm_x86_call(interrupt_allowed)(vcpu, true) < 0); + } else { + kvm_warn_on_lost_irq(vcpu); } } if (kvm_cpu_has_injectable_intr(vcpu)) --=20 2.55.0.229.g6434b31f56-goog From nobody Fri Jul 24 20:51:24 2026 Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D361032B108 for ; Fri, 24 Jul 2026 17:34:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784914471; cv=none; b=nIdjzz11xbF3ZrYGC+RGTO7ratab0ZduPS2HFudNEEi+zFFE/umYKdIsqk68Shd74LH5hOlRLDetXGiI29Z/lA9mNTEtarWVA3Ama1oxY1guaZFNfCACtOFQC4K1VV5LhbAS6zqSIO4hQzUPWmt5EayaqSdoffq1zUUcq0bRvJQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784914471; c=relaxed/simple; bh=rLkMc5AOpVKMTLuxHjDhFbknUJV0WEQRy7oPL6tNQKE=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=eLLT+Z8DGIzrtoJsMxZ/016qCsay/G+m09UCIXqt6XB+IZE344XwWj/5gprtiDcFlnHlddxqZJD6AlW2c3tMFIOOdgabH1eTZPOnGcncfOI9e8HggZPgORN8KWd/V/sFLILh0dH4aMs5zt0HP91WfXK77dE7yH0zQeckT77YPJU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Crk8PD5a; arc=none smtp.client-ip=209.85.214.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Crk8PD5a" Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2cce870a060so11424275ad.2 for ; Fri, 24 Jul 2026 10:34:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1784914469; x=1785519269; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=o72EGRo2pvQ3WbX6SzXXg6Q1ixoc9GAPCSAe802AzLg=; b=Crk8PD5auDoxf/+KWPpYZUIrMltPh9A5H+eeFhbaRG79SympiQC2ho13OsX9xLNZ6i /hCtmfEyMjZcO/bWRqjHAhSJU2XXdt9dD4pg3V0CAnPnqQ6hIW8FMO+gL7UvLz+7pqnl QjsGzWgWktYljz2wup/tC7os0K9Pqf5Hnd59lJwrnT4Kl17WWiwD8b3Wp8rrnj/8ylGz S4T7KSLlC88zG7vZlgLdbYRJSj0yTIHTdodL9Nlgv3+AmWNfKPBmKJw2G2YXej2LKAEX diRT0p85RPKfTWWkfKE/f2RtNqmwSQzUcgOCu9dW6AxLTQS+RaIj1vfZWpb+7uw5bgMd rh3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784914469; x=1785519269; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=o72EGRo2pvQ3WbX6SzXXg6Q1ixoc9GAPCSAe802AzLg=; b=cJaKc8yZ1gk3K/u47D/sAatxoIrpgv8Q72ZiT6GMyxP5R/xIQmX/Xmw890FwPfWhs5 CQRkCrYhUEI/fMMtBmjHyxbLKCGMzj9hCOz5y64QZtUR3uhEukk3PgkPkfHsF+7hkKPx +oEmRZdYG6HJ3/IeCFm9FoCVvIqYH4VpIWfhDI3poFQfiJvHFBx3JK0lxmT0mTyD+7s9 TmsegeFAzGppcDoD+Z3u6mrRBJSCkkc3iCSZgotIynXHSRddwG3PWMq9TmQ1eL5IdqmL D9eMCubeFJgNQEmbUSzE3pJn/Stc8rO7feQQf1yTILfI3RnE+WrVv0fthvWfuXBT3d38 wg8g== X-Forwarded-Encrypted: i=1; AHgh+RqXLNb3zoxNRcX5WiG2OKHa4OvDZ8U7WiUiXiO0BDhe13UxDe/NlzqoK/j7rNpqS/ULnyRVCG6qOKsCE+c=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9YrZ7paz/EY0n/I8ylj0edHW011njspkuxt0AJN4f1HfW5Zju 9y5DC5AW1dSVtFK95RPyVUvyNQO6fyV+MHtaBn/BtClLBtiY3pHkj8NK5YgpcmOAVF+6bLJOuye 8qLK+tQ== X-Received: from plv5.prod.google.com ([2002:a17:903:bc5:b0:2ce:fc90:1592]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:2f43:b0:2ce:8551:318c with SMTP id d9443c01a7336-2cfa6d879b6mr98306685ad.40.1784914468877; Fri, 24 Jul 2026 10:34:28 -0700 (PDT) Reply-To: Sean Christopherson Date: Fri, 24 Jul 2026 10:34:25 -0700 In-Reply-To: <20260724173425.278753-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260724173425.278753-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260724173425.278753-3-seanjc@google.com> Subject: [PATCH v3 2/2] KVM: x86: Don't WARN if IRQ disappears when Xen emulation is enabled. From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+dd769db18693736eee89@syzkaller.appspotmail.com, Sashiko Bot Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When getting a to-be-injected IRQ, don't WARN if the IRQ disappeared and Xen emulation is supported, as a guest could concurrently toggle its evtchn_upcall_pending flag in shared memory and deassert the IRQ. Even more annoyingly, userspace could disable Xen emulation for the entire VM KVM_XEN_HVM_CONFIG. So, suppress WARNs on lost IRQs if Xen emulation is supported to prevent false positives. Alternatively, KVM could track if the VM has ever used Xen emulation, but the added complexity isn't worth carrying given that the vast majority of deployments can and should disable Xen emulation. Fixes: bf672720e83c ("KVM: x86: check the kvm_cpu_get_interrupt result befo= re using it") Reported-by: Sashiko Bot Closes: https://lore.kernel.org/all/20260625212001.3B6561F000E9@smtp.kernel= .org Signed-off-by: Sean Christopherson --- arch/x86/kvm/irq.h | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/irq.h b/arch/x86/kvm/irq.h index eeaf527cecc4..a74f03858004 100644 --- a/arch/x86/kvm/irq.h +++ b/arch/x86/kvm/irq.h @@ -130,8 +130,12 @@ static inline void kvm_warn_on_lost_irq(struct kvm_vcp= u *vcpu) * another vCPU grabs the IRQ, or deasserts the interrupt (which is * level-triggered), then it's both expected and "fine" for an IRQ * seemingly be "lost" from this vCPU's perspective. + * + * Similarly, Xen's event channel isn't entirely within KVM's control, + * e.g. Xen emulation can be disabled entirely per-VM, or the guest + * can desassert an IRQ by writing to shared memory. */ - WARN_ON_ONCE(!pic_in_kernel(vcpu->kvm)); + WARN_ON_ONCE(!pic_in_kernel(vcpu->kvm) && !IS_ENABLED(CONFIG_KVM_XEN)); } =20 void kvm_inject_pending_timer_irqs(struct kvm_vcpu *vcpu); --=20 2.55.0.229.g6434b31f56-goog