From nobody Mon Sep 28 23:53:42 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 75D6536B909 for ; Fri, 14 Aug 2026 16:22:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724560; cv=none; b=f4Lh19upA3A5IAJgZyZoN98ojf4clyLrHNVd5tEKH5Q0ZxhwgVI/i3+JiVB3rHxtUKaKIYg0nmnJdpDLjROnXd0nxZbzO92sFC4cDDQOiHcgbkeVezWb6yYuH1FZYmaJwva6sdgBOSHLv//ChueMRpMALgWq++bQGYsp6SH3fm4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724560; c=relaxed/simple; bh=Bhb3zO8azk8H0t0RPc2Yk//hmGILiRqK/CXorU8yZhk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=DAOJEJryFXSbmAxRNQByV69bDP5VcoU0VJOLwukPHMOGErruBPjBOH34YWcZ0w6IW07jNsmrxhocDN8L1HqnJp4rJTwX9derFitav/n51JLTV+C9m28ErLXd+3bW/PR/zJo7nRamAfwBR0yUEk7Cu6rxNOyA3Pi23/kIsPNVUTE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=fP7QzQ50; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="fP7QzQ50" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786724556; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ypyTrqP+IqNPV89W2oCSz7Jyng5LOr7QKCQoG3JdNd4=; b=fP7QzQ50XENXN/1lRRs9HiTngPIBHZll/Azk1JELhkUShSgBdcSL5N5NAB56UdJNadD6b3 Ea/AhVm5ULafj0D2G4pPsNopBnEKZpRFkZUaSthK2QGERsJLvfZJJI00v1wUlaTUoEFQ3C JImorfdrE67nJg0GIt8i35SDBF8tTBg= Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-672-OPiMIwhPOQGkGq6JMgyrNA-1; Fri, 14 Aug 2026 12:22:28 -0400 X-MC-Unique: OPiMIwhPOQGkGq6JMgyrNA-1 X-Mimecast-MFC-AGG-ID: OPiMIwhPOQGkGq6JMgyrNA_1786724547 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 261541956046; Fri, 14 Aug 2026 16:22:27 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.234]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 5A527426; Fri, 14 Aug 2026 16:22:25 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH 1/4] KVM: nVMX: Make VMPTRLD result in #UD when eVMCS is used Date: Fri, 14 Aug 2026 18:22:18 +0200 Message-ID: <20260814162221.2144473-2-vkuznets@redhat.com> In-Reply-To: <20260814162221.2144473-1-vkuznets@redhat.com> References: <20260814162221.2144473-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" VMPTRLD with active eVMCS is already forbidden, however, returning 1 without skipping the instruction or queuing an exception will likely result in L1 getting stuck. Genuine Hyper-V seems to inject #UD under similar circumstances, mimic the behavior in KVM. Reported-by: f734222792@gmail.com Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D221841 Suggested-by: Sean Christopherson Signed-off-by: Vitaly Kuznetsov --- arch/x86/kvm/vmx/nested.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index ddf6df7bee93..216f54a0b8ae 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -5879,6 +5879,12 @@ static int handle_vmptrld(struct kvm_vcpu *vcpu) if (!nested_vmx_check_permission(vcpu)) return 1; =20 + /* Forbid normal VMPTRLD if Enlightened version was used */ + if (nested_vmx_is_evmptr12_valid(vmx)) { + kvm_queue_exception(vcpu, UD_VECTOR); + return 1; + } + if (nested_vmx_get_vmptr(vcpu, &vmptr, &r)) return r; =20 @@ -5888,10 +5894,6 @@ static int handle_vmptrld(struct kvm_vcpu *vcpu) if (vmptr =3D=3D vmx->nested.vmxon_ptr) return nested_vmx_fail(vcpu, VMXERR_VMPTRLD_VMXON_POINTER); =20 - /* Forbid normal VMPTRLD if Enlightened version was used */ - if (nested_vmx_is_evmptr12_valid(vmx)) - return 1; - if (vmx->nested.current_vmptr !=3D vmptr) { struct gfn_to_hva_cache *ghc =3D &vmx->nested.vmcs12_cache; struct vmcs_hdr hdr; --=20 2.55.0 From nobody Mon Sep 28 23:53:42 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E34A33BED27 for ; Fri, 14 Aug 2026 16:22:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724556; cv=none; b=s85L0BSCR2fBZ7/c2LncKJeOIhNNUNdZAkA35I9/c+rS8yWa8LNGa3TBxX6LAAmfr7HXFd5ZI8SY/o4lz2FZw8yx8ov0nxppJCEz71ADtcTyQLFkyOn9bJNqhEHBXLsbsQPHCUFoI8qflLnFllKz71dYE+IjEsTKJznaJJIs21I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724556; c=relaxed/simple; bh=40pQPNfaf546yG/yNFv0wnGFuPKLwd5/zubhhplX+YM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=YcCkeW+x5LLEyPzW1n1Qs+vIhFR8/rx/pv14eveKwqTIs/Y0vR/m/ebVJB5eTCQGHN1Uy9AI5p2CoUg83upbbN13hjLvEtmtqsucGyYmn59B0mxqSQUI47cowyZ8CECYL0AJc4N3s1kNgEVcVCwvDdkcNHwKmDyhJ1Oy2fD86jc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=FRRVx4Qs; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="FRRVx4Qs" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786724553; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=PkvCI5v2xTBFYBwpYSNpPfRznyVSNzaRiOF1l/gIpY0=; b=FRRVx4Qsv9LV5Gded0vtOiHVQBzofMwLUbK3UD7vC/M7N/x201BhuHc23iM0bK5ar7m/WP JzITCj0lme/UEVg+ZjXfmLOLZj2o329T1WRYLXTO2fyOkLO9AQ1U+rOviPbhwBIuGIGB68 XQpLBx6cung9ywm7k7t82xtgacUoM8Y= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-573-I_5rLwHhN5qvUNM_u-YyYA-1; Fri, 14 Aug 2026 12:22:30 -0400 X-MC-Unique: I_5rLwHhN5qvUNM_u-YyYA-1 X-Mimecast-MFC-AGG-ID: I_5rLwHhN5qvUNM_u-YyYA_1786724549 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 525D81800365; Fri, 14 Aug 2026 16:22:29 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.234]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 89261423; Fri, 14 Aug 2026 16:22:27 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH 2/4] KVM: nVMX: Make VMPTRST return eVMCS GPA when it is used Date: Fri, 14 Aug 2026 18:22:19 +0200 Message-ID: <20260814162221.2144473-3-vkuznets@redhat.com> In-Reply-To: <20260814162221.2144473-1-vkuznets@redhat.com> References: <20260814162221.2144473-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" VMPTRST with active eVMCS is currently forbidden, however, returning 1 without skipping the instruction will likely result in L1 getting stuck. While TLFS does not specify the expected behavior, genuine Hyper-V seems to be returning eVMCS GPA. Implement the same behavior in KVM. Reported-by: f734222792@gmail.com Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D221841 Signed-off-by: Vitaly Kuznetsov --- arch/x86/kvm/vmx/nested.c | 12 +++++++++--- 1 file changed, 9 insertions(+), 3 deletions(-) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 216f54a0b8ae..0f5e4b47ecb1 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -5946,7 +5946,7 @@ static int handle_vmptrst(struct kvm_vcpu *vcpu) { unsigned long exit_qual =3D vmx_get_exit_qual(vcpu); u32 instr_info =3D vmcs_read32(VMX_INSTRUCTION_INFO); - gpa_t current_vmptr =3D to_vmx(vcpu)->nested.current_vmptr; + gpa_t current_vmptr; struct x86_exception e; gva_t gva; int r; @@ -5954,8 +5954,14 @@ static int handle_vmptrst(struct kvm_vcpu *vcpu) if (!nested_vmx_check_permission(vcpu)) return 1; =20 - if (unlikely(nested_vmx_is_evmptr12_valid(to_vmx(vcpu)))) - return 1; + /* + * Hyper-V TLFS does not specify the behavior of VMPTRST when eVMCS is us= ed + * but genuine Hyper-V seems to be returning eVMCS GPA. + */ + if (nested_vmx_is_evmptr12_valid(to_vmx(vcpu))) + current_vmptr =3D to_vmx(vcpu)->nested.hv_evmcs_vmptr; + else + current_vmptr =3D to_vmx(vcpu)->nested.current_vmptr; =20 if (get_vmx_mem_address(vcpu, exit_qual, instr_info, true, sizeof(gpa_t), &gva)) --=20 2.55.0 From nobody Mon Sep 28 23:53:42 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D4150488DA6 for ; Fri, 14 Aug 2026 16:22:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724558; cv=none; b=LB2Z/jafNP1O/tUFsvDD1+AKO4qoavXBrjDF3u6RjKu0c27mRdFMvQ28myPaDwnuVNq4UAwLN79AAXlsdGDCoGkrTfcKo8gaEwAGZEHQ9O2LaTtSmfgdzPzisTcBId9EmB8Bb49Ia0wSuzWWw+xMD+fi8OQ5DFYlfCvSpqUN+mY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724558; c=relaxed/simple; bh=Bu0jWuOdVSWXqO8E3D+c2oT9tCFIc6TCk2kM+B9wfh4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=BHCHY/XhAO+YgnpIv7QFCyS6ehD7ElcEDMEfefEd49nvib+eAr4w/tsNarzIYK1nqfTuqZ6Q3m91lvqSftjnyFUQvOp4CFxtTYk0shPpPivLJVFamuLGoSOgU+bD5/l4hW872/nJEcMQN+/26M5BEdjn0y6Gj9nY5302ARvOzJo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=Valb90Lt; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="Valb90Lt" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786724555; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=NlrUYML2KUzX5oZG9HuRkuYPajINJivUH33duwgHhK8=; b=Valb90LtS2ZG+ARheHJGTnh/e5ldqiJvG0z4w4+IGmn5QJOy/dCeQJCfvXR6u+oISZD5i+ zNPlWaJYKnLrGaNXj2v2Lb+5+xKrySJYWrzI5EdItV1gG7pLfijsnWPL/e+y3TqdQ1DXye WZSizuFY/W8hTwRdsjJj93tfPFpE0fQ= Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-711-CAAZdqx7OOa7x77kiV86Lg-1; Fri, 14 Aug 2026 12:22:32 -0400 X-MC-Unique: CAAZdqx7OOa7x77kiV86Lg-1 X-Mimecast-MFC-AGG-ID: CAAZdqx7OOa7x77kiV86Lg_1786724551 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8BED7180064B; Fri, 14 Aug 2026 16:22:31 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.234]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id C116E422; Fri, 14 Aug 2026 16:22:29 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH 3/4] KVM: selftests: Adapt to the updated VMPTRST behavior when eVMCS is used Date: Fri, 14 Aug 2026 18:22:20 +0200 Message-ID: <20260814162221.2144473-4-vkuznets@redhat.com> In-Reply-To: <20260814162221.2144473-1-vkuznets@redhat.com> References: <20260814162221.2144473-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" Previously, VMPTRST was forbidden with eVMCS and selftests were mocking the correct behavior in vmptrst() by returning enlightened vmptr directly. Since KVM's behavior has changed to match genuine Hyper-V, adjust evmcs test accordingly. Signed-off-by: Vitaly Kuznetsov --- tools/testing/selftests/kvm/include/x86/vmx.h | 3 --- tools/testing/selftests/kvm/x86/hyperv_evmcs.c | 5 ++--- 2 files changed, 2 insertions(+), 6 deletions(-) diff --git a/tools/testing/selftests/kvm/include/x86/vmx.h b/tools/testing/= selftests/kvm/include/x86/vmx.h index 90fffaf91595..047d02aa9688 100644 --- a/tools/testing/selftests/kvm/include/x86/vmx.h +++ b/tools/testing/selftests/kvm/include/x86/vmx.h @@ -341,9 +341,6 @@ static inline int vmptrst(u64 *value) u64 tmp; u8 ret; =20 - if (enable_evmcs) - return evmcs_vmptrst(value); - __asm__ __volatile__("vmptrst %[value]; setna %[ret]" : [value]"=3Dm"(tmp), [ret]"=3Drm"(ret) : : "cc", "memory"); diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing= /selftests/kvm/x86/hyperv_evmcs.c index c7fa114aee20..88262ddf7fcb 100644 --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c @@ -95,16 +95,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct hyp= erv_test_pages *hv_pages, GUEST_ASSERT(prepare_for_vmx_operation(vmx_pages)); GUEST_SYNC(3); GUEST_ASSERT(load_evmcs(hv_pages)); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); + /* VMPTRST returns -1 until VMLAUNCH with eVMCS ptr set */ + GUEST_ASSERT(vmptrstz() =3D=3D -1); =20 GUEST_SYNC(4); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); =20 prepare_vmcs(vmx_pages, l2_guest_code, &l2_guest_stack[L2_GUEST_STACK_SIZE]); =20 GUEST_SYNC(5); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); current_evmcs->revision_id =3D -1u; GUEST_ASSERT(vmlaunch()); current_evmcs->revision_id =3D EVMCS_VERSION; --=20 2.55.0 From nobody Mon Sep 28 23:53:42 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5524648CD56 for ; Fri, 14 Aug 2026 16:22:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724560; cv=none; b=SKWt9o27BY27LP98b6nZ8wo9zCKLGuDB6NTqZnCN1von59bj1n1X9FoIiCCnFQMik399la+PGNj1WnVzLGgPgwYb7SYP4gm8QBRkIhXIa1F5R53bQZcRa4xpa/qcPEUYd6r4fTqpVCKZlR45o6tBGVXwQQyHd7JTFiP/byIF0iA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786724560; c=relaxed/simple; bh=vjsvimg+UZg7jmSYzW9/QZeVGKNQK1R8FqFtL5IDmBo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=UKlemLzK2QhrTovvCy5/ajOUYbAXxrTwZc/TO6AX8Ep5ojRxJjOL9tNXma6/AgCeuo0c67VPYCc9qkyciooK7pXqI+BnUEKylB2AFe6vMj0RorA5xGeoTc8Fb82De2cVSHcYKay6uUF0OtYqbKw0AvS8hhXa/NV7QhQd7GD7tdA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=K22rpnEo; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="K22rpnEo" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786724558; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=PpeDr30TrQyKrAUaIAR21FEKOI9dU4xsJ2hFkXOUhfE=; b=K22rpnEolM2sYCNItPohG7l5aCE4xNPU0HS8TaAPzVEx0O0Nio04ZMeaRgSPctC9tiGHq3 K3na8/sfUWlMIX3BraM0T/kCxccbknJsPj4TeOTsbZAt2y9FC6Ub0nJ8VVermJViQ/Kr5a NX/kBfu2irbm7Xp4Cn95ubqGITciQs8= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-356-D4gEATPPP5qwcZodsnnUbA-1; Fri, 14 Aug 2026 12:22:35 -0400 X-MC-Unique: D4gEATPPP5qwcZodsnnUbA-1 X-Mimecast-MFC-AGG-ID: D4gEATPPP5qwcZodsnnUbA_1786724553 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id D0B3819560AD; Fri, 14 Aug 2026 16:22:33 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.234]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id F0BB7422; Fri, 14 Aug 2026 16:22:31 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS Date: Fri, 14 Aug 2026 18:22:21 +0200 Message-ID: <20260814162221.2144473-5-vkuznets@redhat.com> In-Reply-To: <20260814162221.2144473-1-vkuznets@redhat.com> References: <20260814162221.2144473-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Content-Type: text/plain; charset="utf-8" Check that VMPTRLD when eVMCS is active results in #UD. This matches genuine Hyper-V's behavior. Signed-off-by: Vitaly Kuznetsov --- tools/testing/selftests/kvm/include/x86/vmx.h | 3 --- tools/testing/selftests/kvm/x86/hyperv_evmcs.c | 13 +++++++++++-- 2 files changed, 11 insertions(+), 5 deletions(-) diff --git a/tools/testing/selftests/kvm/include/x86/vmx.h b/tools/testing/= selftests/kvm/include/x86/vmx.h index 047d02aa9688..e2178a6683ca 100644 --- a/tools/testing/selftests/kvm/include/x86/vmx.h +++ b/tools/testing/selftests/kvm/include/x86/vmx.h @@ -325,9 +325,6 @@ static inline int vmptrld(u64 vmcs_pa) { u8 ret; =20 - if (enable_evmcs) - return -1; - __asm__ __volatile__ ("vmptrld %[pa]; setna %[ret]" : [ret]"=3Drm"(ret) : [pa]"m"(vmcs_pa) diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing= /selftests/kvm/x86/hyperv_evmcs.c index 88262ddf7fcb..6a6d940a7891 100644 --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c @@ -18,12 +18,16 @@ #include "hyperv.h" #include "vmx.h" =20 +#define VMLAUNCH_INSN_SIZE 3 +#define VMPTRLD_INSN_SIZE 5 + static int ud_count; +static int ud_insn_skip_size; =20 static void guest_ud_handler(struct ex_regs *regs) { ud_count++; - regs->rip +=3D 3; /* VMLAUNCH */ + regs->rip +=3D ud_insn_skip_size; } =20 static void guest_nmi_handler(struct ex_regs *regs) @@ -182,10 +186,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct h= yperv_test_pages *hv_pages, GUEST_ASSERT(vmreadz(VM_EXIT_REASON) =3D=3D EXIT_REASON_VMCALL); GUEST_SYNC(11); =20 + ud_insn_skip_size =3D VMPTRLD_INSN_SIZE; + vmptrld(hv_pages->enlightened_vmcs_gpa); + GUEST_ASSERT(ud_count =3D=3D 1); + /* Try enlightened vmptrld with an incorrect GPA */ + ud_insn_skip_size =3D VMLAUNCH_INSN_SIZE; evmcs_vmptrld(0xdeadbeef, hv_pages->enlightened_vmcs); GUEST_ASSERT(vmlaunch()); - GUEST_ASSERT(ud_count =3D=3D 1); + GUEST_ASSERT(ud_count =3D=3D 2); GUEST_DONE(); } =20 --=20 2.55.0