From nobody Mon Sep 28 19:22:58 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1EFE547F79C for ; Tue, 18 Aug 2026 16:53:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071990; cv=none; b=oXk3cV+YDpG43tVuDXxebScIghC9cNpJ/s3rS1rbpnULPlvX9rV9ibGFYm9zXcxfVQyXHl0QNLU14EcpAvbw/GqorTTeQ+JxY7qh8E4tDEEnagy+/S9UmE9Rypd8MMDv/nl9Fd2E8lPlkkOO0NALWB+kMvFZUjOCSZVWTo2JWfY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071990; c=relaxed/simple; bh=Bhb3zO8azk8H0t0RPc2Yk//hmGILiRqK/CXorU8yZhk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=iLlTu6o2lAx0zF0WtqWlcwLiJUcSZ/1BYmIrTJqBuSFv9xTqfoywIQSalTJJJ9N25jeQ9eyCl/IJHuYxWEcmQj7xsRWuQ0nPSJyF3ngyF8B2j0eL61RS9JUxsQZWvOW7WDLyd2XpitY1pp6zFH60HRjGqw7OqAr8vQ5pGCCHNIU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=dBvNSZMq; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="dBvNSZMq" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787071988; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=ypyTrqP+IqNPV89W2oCSz7Jyng5LOr7QKCQoG3JdNd4=; b=dBvNSZMqOECw+m39MKKIrWyPIwv8CNtxWGaVTMmBrZk49bvYK2A0V/Y9Av3nP+A4qEldpq nOacA41wycjKCRRBBlMBukz/5lgej9V90m7P9VAXXo915jwb6hkp2eyrPif4JMywzSukDW YK4AoQkMFzVvW26w2wy1H6t3TCv2xs4= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-590-0KZHRxkHPtGtYLRPgBOPAg-1; Tue, 18 Aug 2026 12:53:04 -0400 X-MC-Unique: 0KZHRxkHPtGtYLRPgBOPAg-1 X-Mimecast-MFC-AGG-ID: 0KZHRxkHPtGtYLRPgBOPAg_1787071983 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id A0B62180035C; Tue, 18 Aug 2026 16:53:03 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.151]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D06353000239; Tue, 18 Aug 2026 16:53:01 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH v2 1/4] KVM: nVMX: Make VMPTRLD result in #UD when eVMCS is used Date: Tue, 18 Aug 2026 18:52:55 +0200 Message-ID: <20260818165258.2613603-2-vkuznets@redhat.com> In-Reply-To: <20260818165258.2613603-1-vkuznets@redhat.com> References: <20260818165258.2613603-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" VMPTRLD with active eVMCS is already forbidden, however, returning 1 without skipping the instruction or queuing an exception will likely result in L1 getting stuck. Genuine Hyper-V seems to inject #UD under similar circumstances, mimic the behavior in KVM. Reported-by: f734222792@gmail.com Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D221841 Suggested-by: Sean Christopherson Signed-off-by: Vitaly Kuznetsov --- arch/x86/kvm/vmx/nested.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index ddf6df7bee93..216f54a0b8ae 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -5879,6 +5879,12 @@ static int handle_vmptrld(struct kvm_vcpu *vcpu) if (!nested_vmx_check_permission(vcpu)) return 1; =20 + /* Forbid normal VMPTRLD if Enlightened version was used */ + if (nested_vmx_is_evmptr12_valid(vmx)) { + kvm_queue_exception(vcpu, UD_VECTOR); + return 1; + } + if (nested_vmx_get_vmptr(vcpu, &vmptr, &r)) return r; =20 @@ -5888,10 +5894,6 @@ static int handle_vmptrld(struct kvm_vcpu *vcpu) if (vmptr =3D=3D vmx->nested.vmxon_ptr) return nested_vmx_fail(vcpu, VMXERR_VMPTRLD_VMXON_POINTER); =20 - /* Forbid normal VMPTRLD if Enlightened version was used */ - if (nested_vmx_is_evmptr12_valid(vmx)) - return 1; - if (vmx->nested.current_vmptr !=3D vmptr) { struct gfn_to_hva_cache *ghc =3D &vmx->nested.vmcs12_cache; struct vmcs_hdr hdr; --=20 2.55.0 From nobody Mon Sep 28 19:22:58 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D393D47F76E for ; Tue, 18 Aug 2026 16:53:09 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071991; cv=none; b=E77GH4tu5/Ash6pvBzzQtfEa6dDyw1ZtucmeC0dXlARQIXGxKv61O5Z+UpJ/eMOKieIbdt7ByzKIIXT2WzgAduiUDjZxGRqJ9zPqbY6QatuwGXoY2icifS3ZV3ImgTTH+bkvryIxqE+7VrjSKL4PYIo9LyS4zuFKhMsI3CM4vDI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071991; c=relaxed/simple; bh=7jVQRx/QUuEBZ2NRuBVvYhfdAtjKfhXsOqENgke1SQU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=pRWXbwzJuvyWSjIfXsNX9n4wWdXmzKQoZAI6J4lJ+Rz41nQxBf0ZcOijk8b7FV2M7SdREC76x0G4T8MKO/fSW9WyDwNvJY/IltbUOHapF1cQGBsQj/pDoo76WP7sEMLyQgyYXwel8iPNPKnPpzSULGE6Z/qzY7Buj1G3mkOGKSY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=QgC8CrBn; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="QgC8CrBn" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787071989; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tFtO2RxvYwwbNi/TJdZpyT1ucNq7pbvZhlbyUHeqMho=; b=QgC8CrBnUy9RdgGZueaiHRM6ufCmnBVuC72NNoNKjljO7hWDQETD1lgmH4oDxklj4jIezp 3U4E5tgBewceCJjuC0fdusGFxPTEBBhg2ZLRoA5yz3mNnftABG3Gtba5iWVLuKWk/nZamT +OmAYxcXse015Lo2sg0gm1he5eczMNo= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-190-HVMXvxf_Oti0hXuKgg376A-1; Tue, 18 Aug 2026 12:53:07 -0400 X-MC-Unique: HVMXvxf_Oti0hXuKgg376A-1 X-Mimecast-MFC-AGG-ID: HVMXvxf_Oti0hXuKgg376A_1787071986 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id DD5BF195608F; Tue, 18 Aug 2026 16:53:05 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.151]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 1144F3000239; Tue, 18 Aug 2026 16:53:03 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH v2 2/4] KVM: nVMX: Make VMPTRST return eVMCS GPA when it is used Date: Tue, 18 Aug 2026 18:52:56 +0200 Message-ID: <20260818165258.2613603-3-vkuznets@redhat.com> In-Reply-To: <20260818165258.2613603-1-vkuznets@redhat.com> References: <20260818165258.2613603-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" VMPTRST with active eVMCS is currently forbidden, however, returning 1 without skipping the instruction will likely result in L1 getting stuck. While TLFS does not specify the expected behavior, genuine Hyper-V seems to be returning eVMCS GPA. Implement the same behavior in KVM. Reported-by: f734222792@gmail.com Link: https://bugzilla.kernel.org/show_bug.cgi?id=3D221841 Signed-off-by: Vitaly Kuznetsov --- arch/x86/kvm/vmx/nested.c | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 216f54a0b8ae..4b56df4c57f1 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -5946,7 +5946,7 @@ static int handle_vmptrst(struct kvm_vcpu *vcpu) { unsigned long exit_qual =3D vmx_get_exit_qual(vcpu); u32 instr_info =3D vmcs_read32(VMX_INSTRUCTION_INFO); - gpa_t current_vmptr =3D to_vmx(vcpu)->nested.current_vmptr; + gpa_t current_vmptr; struct x86_exception e; gva_t gva; int r; @@ -5954,8 +5954,16 @@ static int handle_vmptrst(struct kvm_vcpu *vcpu) if (!nested_vmx_check_permission(vcpu)) return 1; =20 - if (unlikely(nested_vmx_is_evmptr12_valid(to_vmx(vcpu)))) - return 1; + /* + * Hyper-V TLFS does not specify the behavior of VMPTRST when eVMCS is us= ed + * but genuine Hyper-V seems to be returning eVMCS GPA. + */ +#ifdef CONFIG_KVM_HYPERV + if (nested_vmx_is_evmptr12_valid(to_vmx(vcpu))) + current_vmptr =3D to_vmx(vcpu)->nested.hv_evmcs_vmptr; + else +#endif + current_vmptr =3D to_vmx(vcpu)->nested.current_vmptr; =20 if (get_vmx_mem_address(vcpu, exit_qual, instr_info, true, sizeof(gpa_t), &gva)) --=20 2.55.0 From nobody Mon Sep 28 19:22:58 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4B1AB47F76E for ; Tue, 18 Aug 2026 16:53:17 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071998; cv=none; b=MXDsZfHeuh3FCwW/UPGDWFr69q4ir2hKgkLzdjaTQbcnM0QWVXsBxiJ/IcM+PET+ySkp21SK4F8UFYwVmHpDmIlWwanxg98xWnF+GCJBKA92RCfpUu67DCQAOw0c9c98CP5u2WmEdbz8BZavhlmf35P06cEDdhNsdqdC2uwzwE0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071998; c=relaxed/simple; bh=Vm9xUDcAS267yA06KGs7MhS8cKAPJEvEmCcnUx5RbRM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Ufm/vHza2N5LYyAYR6W22VpERuGHuwwmMNx5tGqEc9RBtP+fydOm3v0HX+cff8NLdPZLChfP1eFGH9p5ROLoK4R2wJYWwouFQ6zSOYNntXfAEfsB6gWAxKLeTsx9DYbPkXtaavpjk+HPhlRZXM9pf1yGknwkGE+npKMSfqP/7zU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=B7lW9OXc; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="B7lW9OXc" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787071996; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=gyc4YAR9TNpBO2M57zNok/MGHeJZrHvF82zUYZWDP9o=; b=B7lW9OXcZcNStzehRQs1x9QjrjlPm5uEvrGTHn14EDV2l3s1tzQ2ps9zUJrQhehryNBKBO f36EpyMgB7uSDVfTO5GJtD6joT8syMJ66ACvA+5SSDYolUGL4opm6IlXYoJwbpqR8lCm97 KImsLwoGRohhWeDHy7WVpxn+6cVTW4s= Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-390-dIZR2-1qMYCFi9CqqonKOQ-1; Tue, 18 Aug 2026 12:53:09 -0400 X-MC-Unique: dIZR2-1qMYCFi9CqqonKOQ-1 X-Mimecast-MFC-AGG-ID: dIZR2-1qMYCFi9CqqonKOQ_1787071988 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 30502195608F; Tue, 18 Aug 2026 16:53:08 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.151]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 4CDCF30002E9; Tue, 18 Aug 2026 16:53:06 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH v2 3/4] KVM: selftests: Adapt to the updated VMPTRST behavior when eVMCS is used Date: Tue, 18 Aug 2026 18:52:57 +0200 Message-ID: <20260818165258.2613603-4-vkuznets@redhat.com> In-Reply-To: <20260818165258.2613603-1-vkuznets@redhat.com> References: <20260818165258.2613603-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" Previously, VMPTRST was forbidden with eVMCS and selftests were mocking the correct behavior in vmptrst() by returning enlightened vmptr directly. Since KVM's behavior has changed to match genuine Hyper-V, adjust evmcs test accordingly. Signed-off-by: Vitaly Kuznetsov --- tools/testing/selftests/kvm/include/x86/evmcs.h | 8 -------- tools/testing/selftests/kvm/include/x86/vmx.h | 3 --- tools/testing/selftests/kvm/x86/hyperv_evmcs.c | 5 ++--- 3 files changed, 2 insertions(+), 14 deletions(-) diff --git a/tools/testing/selftests/kvm/include/x86/evmcs.h b/tools/testin= g/selftests/kvm/include/x86/evmcs.h index be79bda024bf..8b14a5dfa04b 100644 --- a/tools/testing/selftests/kvm/include/x86/evmcs.h +++ b/tools/testing/selftests/kvm/include/x86/evmcs.h @@ -265,14 +265,6 @@ static inline bool load_evmcs(struct hyperv_test_pages= *hv) return true; } =20 -static inline int evmcs_vmptrst(u64 *value) -{ - *value =3D current_vp_assist->current_nested_vmcs & - ~HV_X64_MSR_VP_ASSIST_PAGE_ENABLE; - - return 0; -} - static inline int evmcs_vmread(u64 encoding, u64 *value) { switch (encoding) { diff --git a/tools/testing/selftests/kvm/include/x86/vmx.h b/tools/testing/= selftests/kvm/include/x86/vmx.h index 90fffaf91595..047d02aa9688 100644 --- a/tools/testing/selftests/kvm/include/x86/vmx.h +++ b/tools/testing/selftests/kvm/include/x86/vmx.h @@ -341,9 +341,6 @@ static inline int vmptrst(u64 *value) u64 tmp; u8 ret; =20 - if (enable_evmcs) - return evmcs_vmptrst(value); - __asm__ __volatile__("vmptrst %[value]; setna %[ret]" : [value]"=3Dm"(tmp), [ret]"=3Drm"(ret) : : "cc", "memory"); diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing= /selftests/kvm/x86/hyperv_evmcs.c index c7fa114aee20..88262ddf7fcb 100644 --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c @@ -95,16 +95,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct hyp= erv_test_pages *hv_pages, GUEST_ASSERT(prepare_for_vmx_operation(vmx_pages)); GUEST_SYNC(3); GUEST_ASSERT(load_evmcs(hv_pages)); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); + /* VMPTRST returns -1 until VMLAUNCH with eVMCS ptr set */ + GUEST_ASSERT(vmptrstz() =3D=3D -1); =20 GUEST_SYNC(4); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); =20 prepare_vmcs(vmx_pages, l2_guest_code, &l2_guest_stack[L2_GUEST_STACK_SIZE]); =20 GUEST_SYNC(5); - GUEST_ASSERT(vmptrstz() =3D=3D hv_pages->enlightened_vmcs_gpa); current_evmcs->revision_id =3D -1u; GUEST_ASSERT(vmlaunch()); current_evmcs->revision_id =3D EVMCS_VERSION; --=20 2.55.0 From nobody Mon Sep 28 19:22:58 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CBD283E0C69 for ; Tue, 18 Aug 2026 16:53:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071997; cv=none; b=JQVBK6RV0TLffkYTpQ38cOKYkzIt1lBBlocyt6GdGlMZezUvX7oX2adFyXeguqKtrG4jp5GpmmRxBh13qOpaEtOn9BmwuZVD5PfX+omvcqh8A8EDP9bIlFRkL/pHxg3HR0b2tihDYCI0ZreJ/f0xq/LIEXaLdkZ9oSTp/t56IhU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787071997; c=relaxed/simple; bh=5KSvQ0lR3nSV3GQnaya6+8BX26FqdLEUSjUQw/DpadY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=YDx5A15kzg3uEei9LVnUzsLLX76w7F8U9+vkLEDsx7tIDOzA0k20sOo/2BquSnHeofr9OW4+69jSe/KmXSp166xRxH+I2+SQF2ldr1Y95t/ZFDx0Gas2iR8qpF3wCkmpgohRYxKQuk0zoPbiqObOE4wPnaUw3t2fodc9rAY3w38= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=XTs3Gp4j; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="XTs3Gp4j" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787071994; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XeAlhq82vYxgd3YLN8Csk0DSOJO0EC+fstAN50H0WxM=; b=XTs3Gp4jccJ1Wf7MjLvxPqj+6Bz/kmNTIlVbX2KOz5919FPO8d/pk5FPpcN6ZXi4TIJEu1 mhhUasILTrxTU2U7BFL+MUrVbG+nh6sacMDL5svhSmd7KwmzQgGrWzG9RXsHnVZTn5v4jn kEUfTZdGQ4O9tPzTA3kcqUdGGa0rB54= Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-301-wKwttiWpOgqbXcMYHsx5Ew-1; Tue, 18 Aug 2026 12:53:11 -0400 X-MC-Unique: wKwttiWpOgqbXcMYHsx5Ew-1 X-Mimecast-MFC-AGG-ID: wKwttiWpOgqbXcMYHsx5Ew_1787071990 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 4642419560B2; Tue, 18 Aug 2026 16:53:10 +0000 (UTC) Received: from fedora.redhat.com (unknown [10.44.48.151]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 7D4753000239; Tue, 18 Aug 2026 16:53:08 +0000 (UTC) From: Vitaly Kuznetsov To: kvm@vger.kernel.org, Sean Christopherson , Paolo Bonzini Cc: f734222792@gmail.com, linux-kernel@vger.kernel.org Subject: [PATCH v2 4/4] KVM: selftests: Check VMPTRLD with active eVMCS Date: Tue, 18 Aug 2026 18:52:58 +0200 Message-ID: <20260818165258.2613603-5-vkuznets@redhat.com> In-Reply-To: <20260818165258.2613603-1-vkuznets@redhat.com> References: <20260818165258.2613603-1-vkuznets@redhat.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Content-Type: text/plain; charset="utf-8" Check that VMPTRLD when eVMCS is active results in #UD. This matches genuine Hyper-V's behavior. Use KVM_ASM_SAFE framework to handle #UD from VMPTRLD. Unfortunately, the same trick cannot be applied to the existing #UD check on VMLAUNCH as VMLAUNCH clobbers all registers which KVM_ASM_SAFE depends on. Keep VMLAUNCH handling separately. Assisted-by: Claude:claude-sonnet-4-6 Signed-off-by: Vitaly Kuznetsov --- tools/testing/selftests/kvm/include/x86/vmx.h | 19 +++++++++++--- .../testing/selftests/kvm/x86/hyperv_evmcs.c | 26 +++++++++++++++---- 2 files changed, 37 insertions(+), 8 deletions(-) diff --git a/tools/testing/selftests/kvm/include/x86/vmx.h b/tools/testing/= selftests/kvm/include/x86/vmx.h index 047d02aa9688..e6adde3970d4 100644 --- a/tools/testing/selftests/kvm/include/x86/vmx.h +++ b/tools/testing/selftests/kvm/include/x86/vmx.h @@ -325,9 +325,6 @@ static inline int vmptrld(u64 vmcs_pa) { u8 ret; =20 - if (enable_evmcs) - return -1; - __asm__ __volatile__ ("vmptrld %[pa]; setna %[ret]" : [ret]"=3Drm"(ret) : [pa]"m"(vmcs_pa) @@ -336,6 +333,22 @@ static inline int vmptrld(u64 vmcs_pa) return ret; } =20 +static inline int vmptrld_safe(u64 vmcs_pa) +{ + u64 error_code; + u8 vector; + u8 failed; + + asm volatile(KVM_ASM_SAFE("vmptrld %[pa]") + "\n\tsetna %[failed]" + : KVM_ASM_SAFE_OUTPUTS(vector, error_code), + [failed]"=3Dqm"(failed) + : [pa]"m"(vmcs_pa) + : "cc", "memory", KVM_ASM_SAFE_CLOBBERS); + + return vector ? vector : failed ? -EINVAL : 0; +} + static inline int vmptrst(u64 *value) { u64 tmp; diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing= /selftests/kvm/x86/hyperv_evmcs.c index 88262ddf7fcb..cff27638834b 100644 --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c @@ -23,7 +23,11 @@ static int ud_count; static void guest_ud_handler(struct ex_regs *regs) { ud_count++; - regs->rip +=3D 3; /* VMLAUNCH */ + /* + * VMLAUNCH insn can't be easily covered by KVM_ASM_SAFE framework but + * luckily the instruction is always three bytes. + */ + regs->rip +=3D 3; } =20 static void guest_nmi_handler(struct ex_regs *regs) @@ -182,7 +186,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct hy= perv_test_pages *hv_pages, GUEST_ASSERT(vmreadz(VM_EXIT_REASON) =3D=3D EXIT_REASON_VMCALL); GUEST_SYNC(11); =20 - /* Try enlightened vmptrld with an incorrect GPA */ + /* VMPTRLD instruction causes #UD after enlightened VMLAUNCH */ + GUEST_ASSERT(vmptrld_safe(hv_pages->enlightened_vmcs_gpa) =3D=3D UD_VECTO= R); + + /* + * Try enlightened vmptrld with an incorrect GPA. GUEST_SYNC(12) signals + * the host to enable guest_ud_handler() which cannot be enabled beforeha= nd + * to not override the default fixup handler from KVM_ASM_SAFE(). + */ + GUEST_SYNC(12); evmcs_vmptrld(0xdeadbeef, hv_pages->enlightened_vmcs); GUEST_ASSERT(vmlaunch()); GUEST_ASSERT(ud_count =3D=3D 1); @@ -256,7 +268,6 @@ int main(int argc, char *argv[]) vcpu_args_set(vcpu, 3, vmx_pages_gva, hv_pages_gva, addr_gva2gpa(vm, hcal= l_page)); vcpu_set_msr(vcpu, HV_X64_MSR_VP_INDEX, vcpu->id); =20 - vm_install_exception_handler(vm, UD_VECTOR, guest_ud_handler); vm_install_exception_handler(vm, NMI_VECTOR, guest_nmi_handler); =20 pr_info("Running L1 which uses EVMCS to run L2\n"); @@ -286,7 +297,7 @@ int main(int argc, char *argv[]) =20 /* Force immediate L2->L1 exit before resuming */ if (stage =3D=3D 8) { - pr_info("Injecting NMI into L1 before L2 had a chance to run after rest= ore\n"); + pr_debug("Injecting NMI into L1 before L2 had a chance to run after res= tore\n"); inject_nmi(vcpu); } =20 @@ -296,9 +307,14 @@ int main(int argc, char *argv[]) * KVM_STATE_NESTED_EVMCS is not lost. */ if (stage =3D=3D 9) { - pr_info("Trying extra KVM_GET_NESTED_STATE/KVM_SET_NESTED_STATE cycle\n= "); + pr_debug("Trying extra KVM_GET_NESTED_STATE/KVM_SET_NESTED_STATE cycle\= n"); vcpu =3D save_restore_vm(vm, vcpu); } + + if (stage =3D=3D 12) { + pr_debug("Trying enlightened VMLAUNCH with an invalid PTR\n"); + vm_install_exception_handler(vm, UD_VECTOR, guest_ud_handler); + } } =20 done: --=20 2.55.0