From nobody Tue Sep 29 14:53:53 2026 Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 36E8D1A6814 for ; Thu, 6 Aug 2026 19:19:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786043990; cv=none; b=Btv6zVRN4i5BkCSC4HdVGO9Z2insFc+iOJj6b71Apir8SeS7/umBGsif2sw8yTp3hYvThCW6MUgMn3+PMIfzi47JYmOHgLdZL7OLuaABUEmC1zkyCrxtg+UXsYugzZ3BZgGOnRFk8rL7TSyqO5R41w8s/fliM1fqhfRn/tGlA4Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786043990; c=relaxed/simple; bh=cYtQg2vj/ZSHq3uIkkBxbWvJhN8tLiaKh7/diaKbv2c=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=YCKXa+CAdsa/tH1VKyGOUXR6Uady2EBtJ2L+ZvsNO7Q/im2YWGEt49/x15AWUORidIS/y5bblVwCSepGXJHfL2gCN+duvsX7O+C4o5qp5kGJuchAY7q+603p4QWW01mF9yU54EMpwvheoQICHYYV0/4kX2QRNCHbrMjJWd05yls= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Nu5DVgnr; arc=none smtp.client-ip=209.85.210.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Nu5DVgnr" Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-8486ffba174so5678370b3a.1 for ; Thu, 06 Aug 2026 12:19:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786043987; x=1786648787; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:from:to:cc:subject:date:message-id:reply-to:content-type; bh=r7w0Q8W/kNI7T8UNYVfIFE+WLMuLMMSdtgl2pAuiQ8s=; b=Nu5DVgnrOnyLw1p3r8P/99RlbIZL8kPUPKjpmwUeBzGD7VOsCAMLAO6MybgbuikIU4 nYHHw5CwppylnAwZwxBSUmFk5eibJmA8Ye/w7gqNz4NA8SCEgClnjYvJFKYSLGsiIA5h n2PvOmz1lW5iBs7QDDTsjm6zOabdHbEUQ8dJOOCqGHygb3aBMpBny3F4F1zLTf+6VB0X RmjAYi2IXzXhcIF2/b+edGrlh7i/oWJBNM/dgukn/n2y3/vpSEb5hSfs4arI6nE7pyZV MIxk3ETtktgqzc2DTXXSapoEA27Ljh3mG8VUpN0d2BaUhbT0J6cWrmEIE+N9YoJ67Q4N iavg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786043987; x=1786648787; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=r7w0Q8W/kNI7T8UNYVfIFE+WLMuLMMSdtgl2pAuiQ8s=; b=N4IKeH8TRwbv+vZO+KGjYtnd36yEENZ/Louij50MDpDMHlo53KCHMswuX98hUyS76I zBjC5tIb+5PHbRwfMMC50i5xvbigzxqs0CZeHnk8Kz/jlp0cQahfvw4K1v44DPYKXE6L onwNZW5XlkdXC2FY2ESuV6/TtuHua4D+QeKZFcUnYhlDd8ayTRc2r0EjKBwmvLBe2LUq zBQ860qAESYJfsy+RPNuQUVbNFuLbynE1fE96cFIVolBj8F4/vd53T6SO5PxrhI9AxLJ dW7ia4m6KoaYrQ4CC7OhD+lFKNDGe+Rqmz1LQAgbds51g1VFvMEgNUWzye92lhmySJE0 MWIA== X-Forwarded-Encrypted: i=1; AHgh+Ro+gdsa2HYxKIRHoov8n4NkOLJ0nMz4UqkJjOWEmc6jYE33q4P9WLDZtcjz3d9CBfay3HuILgF7khqx3/Q=@vger.kernel.org X-Gm-Message-State: AOJu0YzzNCEAn5ouAcLFOPTyIe2wTcQG/CcQvp3pyp5ypUJuxWdiS+m8 CKqP4S5CurRmmvP1u/HW06rxHfZG3USnfhnnamHEckE8T85TpTDeMO5QDa8jOyheOPUq4sk9hBp BE02niA== X-Received: from pfks7.prod.google.com ([2002:a05:6a00:1947:b0:84e:2400:dc7d]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:e8b:b0:845:363e:12d9 with SMTP id d2e1a72fcca58-84f2dfc8f0dmr20048498b3a.3.1786043986994; Thu, 06 Aug 2026 12:19:46 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 6 Aug 2026 12:19:45 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.679.g6767b8d81c-goog Message-ID: <20260806191945.4192732-1-seanjc@google.com> Subject: [PATCH] KVM: x86/mmu: Bug the VM if KVM attempts to unsync an upper-level shadow page From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jinu Kim Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Bug the VM and skip marking a shadow page unsync if KVM attempts to unsync an upper-level shadow page, as marking an upper-level SP unsync is all but guaranteed to be far worse than terminating the VM. E.g. sync_spte() (rightly) assumes SPTEs in the SP are leaf SPTEs and so calls drop_spte() instead of drop_parent_pte(), which can effectively crash the host via when running with CONFIG_BUG_ON_DATA_CORRUPTION=3Dy due to there not being = an rmap entry for the SPTE. Simply not marking the SP unsync, i.e. letting the VM continue on, is equally dangerous for the guest as it means KVM's shadow MMU is using stale information, e.g. could unintentionally corrupt the guest. Cc: Jinu Kim Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/mmu.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 6c13da942bfc..d9ad158ff7a2 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -2990,6 +2990,9 @@ int mmu_try_to_unsync_pages(struct kvm *kvm, const st= ruct kvm_memory_slot *slot, if (prefetch) return -EEXIST; =20 + if (KVM_BUG_ON(sp->role.level !=3D PG_LEVEL_4K, kvm)) + continue; + /* * TDP MMU page faults require an additional spinlock as they * run with mmu_lock held for read, not write, and the unsync @@ -3013,7 +3016,6 @@ int mmu_try_to_unsync_pages(struct kvm *kvm, const st= ruct kvm_memory_slot *slot, continue; } =20 - WARN_ON_ONCE(sp->role.level !=3D PG_LEVEL_4K); kvm_unsync_page(kvm, sp); } if (locked) base-commit: a204badd8432f93b7e862e7dac6db0fe3d65f370 --=20 2.55.0.679.g6767b8d81c-goog