From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F115945041B; Wed, 19 Aug 2026 09:54:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133265; cv=none; b=bB1yTs4pK3CPsp+l89BAs21YNGlAfa666HDVg7SA+KYuhhKh7PEsQCBlHvH9xFw/Rm8Z9vJTRIM73wucnoYCUCz6HccSeBNvfljTLpCE76g4ODP5JL6BRn5nCkltvFYO2bOFZF16clYLVVs8qCK7rZ0SywvmyO3x3v6XbAsQVtY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133265; c=relaxed/simple; bh=8dXk8T96SEGXh0tSYxF32Ot0xtSPFjRMIOB8kBupyuY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=VMjZn0I0TGljkPcQG9TlCPjEX78467q0/PlRqI2c1VobrX79eeZ1+1JHXyq7u8syzIHTJMGhI6dkzA2pHzG0wPkbvms3kF9L8HmHATvNrJkVS8788OU9E5GIFtwy3K+Q9Cx00NHl6YwYZ43F78qCgScMGpIjgyRMTH93t9voRbM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=nfTzEoUZ; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="nfTzEoUZ" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133261; x=1818669261; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=8dXk8T96SEGXh0tSYxF32Ot0xtSPFjRMIOB8kBupyuY=; b=nfTzEoUZK1+xXfMfVQilkFzkPCfvtGniBhW1/3UmabrF6ZvUkgnncoVt JZjunhqgaceifZAiYY9WGZFBRYzlz1mKNNG9WMWTmLk3Lx2ZOIbrOIcvG pAzJfjdBnbMENgxCLctHTRsSBP6DYnsgOm7/NazP73AqZRHeSQ90xrzo5 oKaRkO8hSQBCMn/HXdo5BcL1f/ARc/78zJbFfeD43FJTrNRGpwKs0qFuT 50MjeR/ABcHS7tdsj8gdAe/Ncade/yFcjrFoDJKRe9T0oTKXn/lSGZM0N sDvnRuns6Csg1bDk31Ldcl5/wcckWy3QQSbPGLz5kfB0EsI5OxxFNuOUZ w==; X-CSE-ConnectionGUID: 1yBnZNvGR2K8DFyaMCCoHQ== X-CSE-MsgGUID: jYh77S7VRN6Gxk/0toYHXQ== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514806" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514806" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:15 -0700 X-CSE-ConnectionGUID: R/bnebrLQD6gWBxXp2/zhQ== X-CSE-MsgGUID: VmK28p59QfiLHmiyGPVL2Q== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708831" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:13 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 1/9] KVM: TDX: Enable Notify VM exit Date: Wed, 19 Aug 2026 17:48:55 +0800 Message-ID: <20260819094903.3060020-2-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Enable Notify VM exit functionality for TDX guests. Notify VM exit is an existing feature supported by KVM. Userspace can enable Notify VM exit through KVM_CAP_X86_NOTIFY_VMEXIT when it's reported as supported. However, KVM reports the support of this CAP just based on the hardware capability but doesn't differentiate between VMX and TDX. This leads to the issue that userspace can enable this cap for TDX guests without getting an error, but the feature is not actually enabled because KVM doesn't call the TDX module API to program the relevant TD VMCS fields. Enable Notify VM exit for TDX guests by: - Invoking TDX module API calls to set NOTIFY_VM_EXITING and Notify Window in TD VMCS. It's done in tdx_vcpu_init() where other TD VMCS bits are set. Since TDX vCPU cannot be reset, it only needs to be configured once when initializing the TDX vCPU. - Adding corresponding exit handler for TDX Notify VM Exit. Notify VM exit can happen when executing the IRET instruction. If the IRET unblocks the NMI blocking state, bit 12 of the exit qualification is set. In this case, the VMM needs to restore the "blocked by NMI" state when it decides to re-enter the guest. For TDX, KVM cannot manage the GUEST_INTERRUPTIBILITY_INFO and it's TDX module's responsibility to handle it. Extract the common part without NMI blocking handling into a helper in common.h so that it can be shared between VMX and TDX. Note, KVM uses "pre-production" terminology for the feature formally called Notify VM-Exit. All public versions of the SDM refer to the feature as Instruction Timeout. This will be remedied in the near future, for now, use KVM's terminology for consistency. Note, #2, there is no enumeration bit for Notify VM exit by TDX module because all TDX modules support it, and allow to set the corresponding TD VMCS fields as long as the hardware supports the feature. Fixes: 161d34609f9b ("KVM: TDX: Make TDX VM type supported") Cc: stable@vger.kernel.org Signed-off-by: Xiaoyao Li Reviewed-by: Rick Edgecombe Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Binbin Wu --- Changes in v4: - rename __vmx_handle_notify() to __vt_handle_notify(), to better reflect it is a shared helper for both VMX and TDX. Changes in v3: - Collect R-b tag from Rick. Changes in v2: - Mention the feature name mismatch between KVM and SDM in changelog and leave the renaming to future, since this patch is targeted for stable - Extract the common handling into a helper, and put the helper in common.h instead of refactorin the existing handle_notify() in vmx.h - Add a note to clarify the feature is always supported by TDX module, to make Sashiko happy. --- arch/x86/kvm/vmx/common.h | 19 +++++++++++++++++++ arch/x86/kvm/vmx/tdx.c | 10 ++++++++++ arch/x86/kvm/vmx/vmx.c | 13 +------------ 3 files changed, 30 insertions(+), 12 deletions(-) diff --git a/arch/x86/kvm/vmx/common.h b/arch/x86/kvm/vmx/common.h index 08005676702c..7fce1bbabc78 100644 --- a/arch/x86/kvm/vmx/common.h +++ b/arch/x86/kvm/vmx/common.h @@ -4,6 +4,7 @@ =20 #include #include +#include =20 #include "mmu.h" =20 @@ -183,6 +184,24 @@ static inline void __vmx_deliver_posted_interrupt(stru= ct kvm_vcpu *vcpu, kvm_vcpu_trigger_posted_interrupt(vcpu, POSTED_INTR_VECTOR); } =20 +static inline int __vt_handle_notify(struct kvm_vcpu *vcpu, + unsigned long exit_qual) +{ + bool context_invalid =3D exit_qual & NOTIFY_VM_CONTEXT_INVALID; + + ++vcpu->stat.notify_window_exits; + + if (vcpu->kvm->arch.notify_vmexit_flags & KVM_X86_NOTIFY_VMEXIT_USER || + context_invalid) { + vcpu->run->exit_reason =3D KVM_EXIT_NOTIFY; + vcpu->run->notify.flags =3D context_invalid ? + KVM_NOTIFY_CONTEXT_INVALID : 0; + return 0; + } + + return 1; +} + noinstr void vmx_handle_nmi(struct kvm_vcpu *vcpu); =20 #endif /* __KVM_X86_VMX_COMMON_H */ diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index b272c20586a7..d557840687d2 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -2126,6 +2126,9 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t= fastpath) * - If it's not an MSMI, no need to do anything here. */ return 1; + case EXIT_REASON_NOTIFY: + /* NMI blocking state is handled by TDX module */ + return __vt_handle_notify(vcpu, vmx_get_exit_qual(vcpu)); default: break; } @@ -3154,6 +3157,13 @@ static int tdx_vcpu_init(struct kvm_vcpu *vcpu, stru= ct kvm_tdx_cmd *cmd) td_vmcs_write64(tdx, POSTED_INTR_DESC_ADDR, __pa(&tdx->vt.pi_desc)); td_vmcs_setbit32(tdx, PIN_BASED_VM_EXEC_CONTROL, PIN_BASED_POSTED_INTR); =20 + if (kvm_notify_vmexit_enabled(vcpu->kvm)) { + td_vmcs_setbit32(tdx, SECONDARY_VM_EXEC_CONTROL, + SECONDARY_EXEC_NOTIFY_VM_EXITING); + td_vmcs_write32(tdx, NOTIFY_WINDOW, + vcpu->kvm->arch.notify_window); + } + tdx->state =3D VCPU_TD_STATE_INITIALIZED; =20 return 0; diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c index e3bfe6aca1a0..35ac9ddffaf4 100644 --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -6279,9 +6279,6 @@ static int handle_bus_lock_vmexit(struct kvm_vcpu *vc= pu) static int handle_notify(struct kvm_vcpu *vcpu) { unsigned long exit_qual =3D vmx_get_exit_qual(vcpu); - bool context_invalid =3D exit_qual & NOTIFY_VM_CONTEXT_INVALID; - - ++vcpu->stat.notify_window_exits; =20 /* * Notify VM exit happened while executing iret from NMI, @@ -6291,15 +6288,7 @@ static int handle_notify(struct kvm_vcpu *vcpu) vmcs_set_bits(GUEST_INTERRUPTIBILITY_INFO, GUEST_INTR_STATE_NMI); =20 - if (vcpu->kvm->arch.notify_vmexit_flags & KVM_X86_NOTIFY_VMEXIT_USER || - context_invalid) { - vcpu->run->exit_reason =3D KVM_EXIT_NOTIFY; - vcpu->run->notify.flags =3D context_invalid ? - KVM_NOTIFY_CONTEXT_INVALID : 0; - return 0; - } - - return 1; + return __vt_handle_notify(vcpu, exit_qual); } =20 static int vmx_get_msr_imm_reg(struct kvm_vcpu *vcpu) --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 68C5444A3E1; Wed, 19 Aug 2026 09:54:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133266; cv=none; b=b2sVKiPXkiL1EyRhY8+CCCdbF0F8abSTU6R2Xumbh1JzqYo1pNn1jyW/ti4WHYRF6MBcyk+uf2zDGiKiltzqIDFFetNV6dBSARMPhYRvw1OzWjaeXrNev6IrB5pogf9v7/FzYARUCvP/xKOSzr+98B9ZmAHAG/eMSlA3Ckz53Gg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133266; c=relaxed/simple; bh=qxUBLF2aXio14BNU3z4PahoymutUqnCKnIYScYetdQs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=tVkxIEbVzkpos4MR19jsK25PEd2uKwfF+Hvh2pEMyn9m31cj8c+m26vWyPGYItIYtV8pzy1xTCGQgChgOeB4FcPZahpeu7zPnNokN9rwFNITyEAVa45z3Xa/AGIgSxdw2Hva5/HyDJZ06rZ+OGI3Tjbed4uINAcF19SKWMP2EwE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=J5SArvk5; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="J5SArvk5" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133261; x=1818669261; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=qxUBLF2aXio14BNU3z4PahoymutUqnCKnIYScYetdQs=; b=J5SArvk5Qeg+RaCPICvvPWtr3VbMPrDDKADRyOtNiKwxrLp0XFLm4iXB iiTWHHTMkJw/YB484TCIQE5Jhk8w2oZoGNv9PLLPJdL6UeNoya19h2HNX XB7MEh62G2Dmlw9h68F8ItRHMg1cA8AOMI0pfbw1tIS/Ice5nNktDC8kN iIb5+PFDafdlODSL/EobP0M3bkisovBXRPtj/NNCcU5tPQceNuIQT77Y5 1KDVwRmwA6Hiuuqh/M5I8ngFRJunSQgRaPMIho1x8VJ5i0J4cxwESodep NDn5CEBTV/+uO8gjcNZ06+7wYzgFhypAu0qrmf7+E9DIBRxvJNCug0dec w==; X-CSE-ConnectionGUID: 3/f9Rt2NRlWkzsb81u+7ZQ== X-CSE-MsgGUID: 90jMdCpQRUyw8SPZKNadKg== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514825" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514825" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:17 -0700 X-CSE-ConnectionGUID: PdOQyOaZSwGBNrhuzbzhJg== X-CSE-MsgGUID: S2AAHbpuRrqJPmN/OhS0ng== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708840" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:15 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 2/9] KVM: TDX: Check if there is valid exit infos based on vp_enter_ret Date: Wed, 19 Aug 2026 17:48:56 +0800 Message-ID: <20260819094903.3060020-3-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Check if there is valid exit info based on vp_enter_ret instead of relying on the clobbered Exit Reason, in tdx_get_exit_info(). Current KVM uses "Exit Reason is not equal to the synthesized invalid Exit Reason, -1u," as the condition to identify there is a real TD Exit and valid exit infos. However, there is one issue with this approach: KVM updates the Exit Reason to the synthesized invalid Exit Reason for real EPT MISCONFIG as well. This is a false positive for real EPT MISCONFIG, which has valid exit infos. Though the issue can be addressed by changing the handling for real EPT MISCONFIG to not update the Exit Reason to the synthesized one, relying on the clobbered Exit Reason itself is brittle. Instead, check vp_enter_ret directly to identify if it is a valid Exit Reason. Fixes: da407fe45908 ("KVM: TDX: Handle EPT violation/misconfig exit") Cc: stable@vger.kernel.org Suggested-by: Sean Christopherson Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Binbin Wu --- Changes in v4: - new patch. --- arch/x86/kvm/vmx/tdx.c | 22 ++++++++++++++-------- 1 file changed, 14 insertions(+), 8 deletions(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index d557840687d2..1dead84e6077 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -921,21 +921,27 @@ static __always_inline u32 tdcall_to_vmx_exit_reason(= struct kvm_vcpu *vcpu) return EXIT_REASON_TDCALL; } =20 -static __always_inline u32 tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu) +static __always_inline bool tdx_is_exit_reason_valid(u64 vp_enter_ret) { - struct vcpu_tdx *tdx =3D to_tdx(vcpu); - u32 exit_reason; - - switch (tdx->vp_enter_ret & TDX_SEAMCALL_STATUS_MASK) { + switch (vp_enter_ret & TDX_SEAMCALL_STATUS_MASK) { case TDX_SUCCESS: case TDX_NON_RECOVERABLE_VCPU: case TDX_NON_RECOVERABLE_TD: case TDX_NON_RECOVERABLE_TD_NON_ACCESSIBLE: case TDX_NON_RECOVERABLE_TD_WRONG_APIC_MODE: - break; + return true; default: - return -1u; + return false; } +} + +static __always_inline u32 tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu) +{ + struct vcpu_tdx *tdx =3D to_tdx(vcpu); + u32 exit_reason; + + if (!tdx_is_exit_reason_valid(tdx->vp_enter_ret)) + return -1u; =20 exit_reason =3D tdx->vp_enter_ret; =20 @@ -2144,7 +2150,7 @@ void tdx_get_exit_info(struct kvm_vcpu *vcpu, u32 *re= ason, struct vcpu_tdx *tdx =3D to_tdx(vcpu); =20 *reason =3D tdx->vt.exit_reason.full; - if (*reason !=3D -1u) { + if (tdx_is_exit_reason_valid(tdx->vp_enter_ret)) { *info1 =3D vmx_get_exit_qual(vcpu); *info2 =3D tdx->ext_exit_qualification; *intr_info =3D vmx_get_intr_info(vcpu); --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B2A4444E05B; Wed, 19 Aug 2026 09:54:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133268; cv=none; b=ri708iJ2ZjcaEd4gsUVisUPEJpfTDhT0Oyo98zFBaw/rw3LxCOax2w+8pbECR2Hlhpv47iUYuV/Xp46G6e0MjFkgQLtGTE/BC48BBoJ9R3RIK52oxdBTSPYIwVqrVnLTfD9EWqSjXgWrvf/FMTzURpJj47gmmBg3bby/p90ZXvw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133268; c=relaxed/simple; bh=sqS+snPYKVZCRCXS2ZM/sjjsZEp9XzJ8UJLAmcIVFBU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Sk4z8jnaNCOgJ44V5a/5wTCUtTpt0HGRGh2oU7YodetTqvrDKklydOymJfhg7y6xj2Sxb1a4BwBqc16uBVxk1UN+IQNvdqAb0dkgfl6pFcs8VUBibkSoQSYB3SLOO/B5+9J+AofPNn0RQ/PnToi9EZYbxrA3whROTwY5ht5lcHM= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=J0V08n9o; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="J0V08n9o" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133265; x=1818669265; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=sqS+snPYKVZCRCXS2ZM/sjjsZEp9XzJ8UJLAmcIVFBU=; b=J0V08n9oeccDEp+J/hQ27WUNBdy6j/QYRc8yoXEv33/kNEL+Io/fi/JA BZt8c0T3P96tpTNuQUKY9eOnACMdk+q282YXaPRuJOX0y/WxwT0q04W3q zM7PHmgHodeQum0cDtrL4zMKz0a3jDF17hWBT4/Kk9hM2xmkuXYhgZlNF usjxfYWFfdx/ne7C5IWntcboiq3LOxXHuv6aKYmE2LLqZP6Ef2Ll1U/5z /oflpaoaYT3XmyZ+i7g+M3yF/6XNUI1c4VYFBHGDc4r5gL6QAQTtIian6 DLTep8D/eQDD7EfgdCn03RmRKLlyM7gHO/uwFeStO71qPhSaLvpBOLlN4 Q==; X-CSE-ConnectionGUID: 9vQUPra8T+WaFDOYPM62Tg== X-CSE-MsgGUID: uTJUbEslR8mPTquCcENIJQ== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514854" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514854" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:20 -0700 X-CSE-ConnectionGUID: DH1I/gUnQgWMN9V6Vw9gBA== X-CSE-MsgGUID: Ftx4oFy5TUuDfovSbbISwQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708853" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:18 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 3/9] KVM: TDX: Set bits 31:16 to 0 for the synthesized Exit Reason Date: Wed, 19 Aug 2026 17:48:57 +0800 Message-ID: <20260819094903.3060020-4-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Set bits 31:16 to 0 instead of all-1s for KVM's synthesized Exit Reason. KVM is going to support Bus Lock VM exit for TDX, after which bit 26 of the Exit Reason becomes meaningful and indicates that a bus lock happened. The existing synthesized Exit Reason, -1u, will cause a false positive in that case. Change the synthesized Exit Reason from -1u to U16_MAX, so that bits 31:16 are set to 0. This also avoids the potential issues when other bits in 31:16 become valid in the future. As a bonus, the check for synthesized Exit Reason in tdx_failed_vmentry() becomes unnecessary. Just drop it. Cc: stable@vger.kernel.org Signed-off-by: Xiaoyao Li Reviewed-by: Rick Edgecombe Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Binbin Wu --- Note, the checking of tdx_failed_vmentry() looks to miss the case where a real EPT_MISCONFIG happens with failed_vmentry being set. First, in practice, EPT_MISCONFIG cannot happen with failed_vmentry being set. Second, even if it can, this is a pre-existing issue and the next patch can address it. Changes in v4: - Collect R-b from Rick. Changes in v3: - split from the patch 2 in v2. - define a MARCO for the synthesized invalid Exit Reason. --- arch/x86/kvm/vmx/tdx.c | 15 +++++++++++---- 1 file changed, 11 insertions(+), 4 deletions(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index 1dead84e6077..4e275cb6927a 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -935,13 +935,21 @@ static __always_inline bool tdx_is_exit_reason_valid(= u64 vp_enter_ret) } } =20 +/* Synthesized invalid Exit Reason */ +#define TDX_INVALID_EXIT_REASON U16_MAX + static __always_inline u32 tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu) { struct vcpu_tdx *tdx =3D to_tdx(vcpu); u32 exit_reason; =20 + /* + * Return the synthesized invalid Exit Reason, as the TDX module + * never attempted to run the vCPU, i.e. the Exit Reason is undefined, + * but this is NOT a failed VM-Enter. + */ if (!tdx_is_exit_reason_valid(tdx->vp_enter_ret)) - return -1u; + return TDX_INVALID_EXIT_REASON; =20 exit_reason =3D tdx->vp_enter_ret; =20 @@ -956,7 +964,7 @@ static __always_inline u32 tdx_to_vmx_exit_reason(struc= t kvm_vcpu *vcpu) * Defer KVM_BUG_ON() until tdx_handle_exit() because this is in * non-instrumentable code with interrupts disabled. */ - return -1u; + return TDX_INVALID_EXIT_REASON; default: break; } @@ -987,8 +995,7 @@ static noinstr void tdx_vcpu_enter_exit(struct kvm_vcpu= *vcpu) =20 static bool tdx_failed_vmentry(struct kvm_vcpu *vcpu) { - return vmx_get_exit_reason(vcpu).failed_vmentry && - vmx_get_exit_reason(vcpu).full !=3D -1u; + return vmx_get_exit_reason(vcpu).failed_vmentry; } =20 static fastpath_t tdx_exit_handlers_fastpath(struct kvm_vcpu *vcpu) --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 21337449B39; Wed, 19 Aug 2026 09:54:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133276; cv=none; b=rmrTZCbD+yiwUzoTT62om6PuZCIx/7UiNTJ/vTY3Cpz8d+OWwu9paQoU3QWlKVzCyKxVHsf756u7xv0V7IRnnqaa1+2HxNGAZWL9QTjqIXsAqZ1doP07HkgUsy697ATcY2g75eempi4/unO1HHYYhQPz3FONvAE7CskPazNvXGc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133276; c=relaxed/simple; bh=IFIMZt6tYK7hDTH+pkH++eIOLwXZmAnKBFd3ZaAKOPc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=u8fW9FWD3ZQGNa0N2wGEeyQLgNVK8tKaEzhJaTiIQr85TS0TtV81vBFGYFxFYc78MJAqg/IpDoIv03ApCQdTQ5BsoRLAHkTQq+EzbOXl07d1TMkjMHlPzNoevty59z5Ut+8C5LOP7/hnu7jqOQkdMdq24r/5HUsvEM91J35uXGU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=Zwk1K+Np; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="Zwk1K+Np" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133267; x=1818669267; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=IFIMZt6tYK7hDTH+pkH++eIOLwXZmAnKBFd3ZaAKOPc=; b=Zwk1K+Np44Qc0zPDRQ8TSTEq9P/lMn5AYLmva679n1h0ngZK+pbH8xjB 70WXyou5+yyDWLHeq7FLso8oXWqkv43IWKQH/+LAvrlzs938eNwFwqnJM UxJ6nhSSA1shBvWs2ws3dZ/IKV1PhviReH4lDEo9hDzndMB+9/Ed/7Cui D2LVCfT8eRsjeZ58YzqMl1TKYBINbYgnGwWnVq5tucJbqy9GHEgeDsAhM 7rY+2CyZL2FDONuj11rhcLunsouiVw0WUXaPvsDuJqCLMYZ9ASoeVALUc GiceAiA0zOFY6w3lhgw0SXZiJPXKMBQ6NOz1+iyhXGoAuufYHsohSNL/U g==; X-CSE-ConnectionGUID: ugUXu+dKTVOCcxa492i4+w== X-CSE-MsgGUID: DkToUJhDTiGterKryB7Biw== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514884" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514884" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:23 -0700 X-CSE-ConnectionGUID: WcQt4xfgQ+i1ftWktXVR6g== X-CSE-MsgGUID: cUz0Ey+DS1yi6OLAMIaUcg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708870" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:21 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 4/9] KVM: TDX: Don't assume exit_reason[31:16] is all-0 in tdx_to_vmx_exit_reason() Date: Wed, 19 Aug 2026 17:48:58 +0800 Message-ID: <20260819094903.3060020-5-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When handling the real Exit Reason, don't assume the upper 16 bits as all-0 in tdx_to_vmx_exit_reason(), in preparation for enabling Bus Lock VM exit. When Bus Lock VM exit is enabled, the bit 26 of Exit Reason becomes valid and it can be 1 with various exit reasons. Change the logic in tdx_to_vmx_exit_reason() to check the 'basic' Exit Reason for correctness. Also preserve bit[31:16] when changing the (basic) Exit Reason, to not lose the information in bit[31:16]. Change the return type of tdx_to_vmx_exit_reason() to "union vmx_exit_reason" for the convenience of manipulating the basic field. Fixes: c42856af8f70 ("KVM: TDX: Add a place holder for handler of TDX hyper= calls (TDG.VP.VMCALL)") Cc: stable@vger.kernel.org Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. --- Changes in v3: - new patch split from patch 2 of v2. --- arch/x86/kvm/vmx/tdx.c | 24 ++++++++++++++---------- 1 file changed, 14 insertions(+), 10 deletions(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index 4e275cb6927a..987092283955 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -938,10 +938,10 @@ static __always_inline bool tdx_is_exit_reason_valid(= u64 vp_enter_ret) /* Synthesized invalid Exit Reason */ #define TDX_INVALID_EXIT_REASON U16_MAX =20 -static __always_inline u32 tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu) +static __always_inline union vmx_exit_reason tdx_to_vmx_exit_reason(struct= kvm_vcpu *vcpu) { struct vcpu_tdx *tdx =3D to_tdx(vcpu); - u32 exit_reason; + union vmx_exit_reason exit_reason; =20 /* * Return the synthesized invalid Exit Reason, as the TDX module @@ -949,22 +949,26 @@ static __always_inline u32 tdx_to_vmx_exit_reason(str= uct kvm_vcpu *vcpu) * but this is NOT a failed VM-Enter. */ if (!tdx_is_exit_reason_valid(tdx->vp_enter_ret)) - return TDX_INVALID_EXIT_REASON; + return (union vmx_exit_reason) { + .basic =3D TDX_INVALID_EXIT_REASON, + }; =20 - exit_reason =3D tdx->vp_enter_ret; + exit_reason.full =3D (u32)tdx->vp_enter_ret; =20 - switch (exit_reason) { + switch (exit_reason.basic) { case EXIT_REASON_TDCALL: if (tdvmcall_exit_type(vcpu)) - return EXIT_REASON_VMCALL; - - return tdcall_to_vmx_exit_reason(vcpu); + exit_reason.basic =3D EXIT_REASON_VMCALL; + else + exit_reason.basic =3D tdcall_to_vmx_exit_reason(vcpu); + break; case EXIT_REASON_EPT_MISCONFIG: /* * Defer KVM_BUG_ON() until tdx_handle_exit() because this is in * non-instrumentable code with interrupts disabled. */ - return TDX_INVALID_EXIT_REASON; + exit_reason.basic =3D TDX_INVALID_EXIT_REASON; + break; default: break; } @@ -981,7 +985,7 @@ static noinstr void tdx_vcpu_enter_exit(struct kvm_vcpu= *vcpu) =20 tdx->vp_enter_ret =3D tdh_vp_enter(&tdx->vp, &tdx->vp_enter_args); =20 - vt->exit_reason.full =3D tdx_to_vmx_exit_reason(vcpu); + vt->exit_reason =3D tdx_to_vmx_exit_reason(vcpu); =20 vt->exit_qualification =3D tdx->vp_enter_args.rcx; tdx->ext_exit_qualification =3D tdx->vp_enter_args.rdx; --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B618B44A402; Wed, 19 Aug 2026 09:54:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133280; cv=none; b=AgAjrbIOGYkfoAsJJ6+gcVtLoeyG5OrajLG6L8MEoXPf5dhAw9/kSHR7ohSoEGaVaaYX5YZ5mmFBG/P3wy9y+91qQhZ0MprWzzxVn+7llIFFfBW4hdS/HWNDvhDXRkyFiC8+s6aGKPWXmuryW7aLWG0wn2L+KOk6o5mk7MTjKi0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133280; c=relaxed/simple; bh=pNkqq2dwqlcQDn1HUnduSrLVReavua1ZNSuOBY8FdLM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=NNrxVv/T0Pyq4I3+t3aaXC2k7kE/YFjD/iDz6tpPNJGXvVbBB46gGf3RWNzrOAmGbOTD4fyQHtnSndp/z7qt42ZZMPtYRyjhntZDrXTM/XgH0q9UU8DAv9pEJSf6cJoNB8PQuu0uSi5DY5fW+UaxyBAsx/iocgUlrk3MRJfkw/8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=VEXleniP; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="VEXleniP" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133275; x=1818669275; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=pNkqq2dwqlcQDn1HUnduSrLVReavua1ZNSuOBY8FdLM=; b=VEXleniPNcqkXpRGFg4QLQVqtAcNYDstAHCHT1irr3PXZwtynEgefOE1 AvcEzOn0ggwDlvWZie25P/cK6OPNHHrFnyfJWPAGPd3AWJP+S5Xd9SI7F jxSzhpZgk8WCpXiClnI5lKVMUwS5e8YsQ335IYcV8QdrmBJVhhfVG/5Ct Kx2voBaFdAGMrDYaG5OnopLiEcD/uMD/OnDoLXuMa5PqN/zoDZO4kUTwJ pPBJrDr9hK2+JdzPxDparIrIGBOdtxvjYoRqbAzQN+A6t64fN3au2gvCN R7R14JIotGdDt4orEaZU6IMBLXNT6whf9W8iz1iVRe/Gh3GauIxyaodGD w==; X-CSE-ConnectionGUID: cl5n7Xt9TfyHWPng0du4zQ== X-CSE-MsgGUID: NVaOEHzSR6iTY/3QA/I1oA== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514946" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514946" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:28 -0700 X-CSE-ConnectionGUID: oe0TwS+QQ2+rLWoWKduaBw== X-CSE-MsgGUID: vjNQwiIKQ3u9GcJt6a6Emw== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708878" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:23 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 5/9] KVM: TDX: Update exit_reason on wait_for_sept_zap return Date: Wed, 19 Aug 2026 17:48:59 +0800 Message-ID: <20260819094903.3060020-6-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Update exit_reason to a value with bit[31:16] cleared and bit[15:0] set to TDX_INVALID_EXIT_REASON when it needs to return early due to wait_for_sept_zap in tdx_vcpu_run(). This avoids the stale exit_reason of the previous Exit being consumed twice. Fixes: 4b2abc49712b ("KVM: TDX: Kick off vCPUs when SEAMCALL is busy during= TD page removal") Cc: stable@vger.kernel.org Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. --- Changes in v4: - new patch; --- arch/x86/kvm/vmx/tdx.c | 15 ++++++++++++++- 1 file changed, 14 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index 987092283955..014710945e8a 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -1088,8 +1088,21 @@ fastpath_t tdx_vcpu_run(struct kvm_vcpu *vcpu, u64 r= un_flags) * allowing vCPU entry to avoid contention with tdh_vp_enter() and * TDCALLs. */ - if (unlikely(READ_ONCE(to_kvm_tdx(vcpu->kvm)->wait_for_sept_zap))) + if (unlikely(READ_ONCE(to_kvm_tdx(vcpu->kvm)->wait_for_sept_zap))) { + /* + * The vCPU never entered the guest, but this looks like a + * handled exit to the caller. Synthesize an invalid exit + * reason so the previous exit's stale value isn't consumed + * a second time. + * + * Make it super clear that bit[31:16] is cleared to 0 and only + * basic exit reason (bit[15:0]) is set to the synthesized + * invalid exit reason. + */ + vt->exit_reason.full =3D 0; + vt->exit_reason.basic =3D TDX_INVALID_EXIT_REASON; return EXIT_FASTPATH_EXIT_HANDLED; + } =20 trace_kvm_entry(vcpu, run_flags & KVM_RUN_FORCE_IMMEDIATE_EXIT); =20 --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 144D144E654; Wed, 19 Aug 2026 09:54:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133285; cv=none; b=eJE+fIQKs9BooRkNvE8ldYG4DhFroAMYoDdmmvYzNbIw80dgAnvizLmGvmewHIJro1yFImQnHR/p2INSlAQC5XUq3mTEduOv+T251eY9+seKTCDvoNqeof2G1o59kBb6auU5W2zO/pM/4ZUdKagCn/OynI8PrCBIO5pdhBMuNHY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133285; c=relaxed/simple; bh=lrotawLdDfCNHz98+9pbLuuZyH1ENmRJGuWwnKfbDhU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=SaSOpp3LLapVFGz6jKOoJJSI1jkdjVRyEFMbhT0D99w0EFZApMuS43y4F64gqGpfZgyKFsfhfgoUjMazyL90DvDmLgpYubPB37Bf5KjuxWOO8N8Gy9yb1KIIlD71NYBP2Tzrxrf/UwSnFBYDYlOiu5qBhihJ2NSFuNkH1aHiv4A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=dpOi68D1; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="dpOi68D1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133278; x=1818669278; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=lrotawLdDfCNHz98+9pbLuuZyH1ENmRJGuWwnKfbDhU=; b=dpOi68D1Kfd2IPzShbuZ0Mtpqc24LDoGyYRdg/D8ybLHKuQlzFw6DNET VaV5yRHhrQsAVqUIuCo+EvbmX9wb0a+umkx4xB2BerfEzx+IWxshxhMZs 6jyXk4o34guLCVWYN6NJlk5jlwNU7m6MpvzuknSU+zdeRq07eEKFDEMYb HmkIR60178ZGPw9/9pYTMjHTbXWC9wHBFCZaQxVE9W2I1f5+fFsrIbzCL 6Bk4+1aqwNUpZ1j06rkaqvCnynwlduekUeSxAHZrhN5qyC7MerUn5tVnT /cyqga/A2Lb2Tvm5qKpu/r/FzKj13xvRPCuP7n8+dAisRzb94Iq+AGTbi Q==; X-CSE-ConnectionGUID: Y2jgnelxTIWds9zi8iZ7Iw== X-CSE-MsgGUID: IXtbE6MWQIKe+R9kMIfjjA== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514950" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514950" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:28 -0700 X-CSE-ConnectionGUID: OGsF/snlS6GXIlVQ41GSXQ== X-CSE-MsgGUID: ardc860MRKGEeEfldxev3g== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708883" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:26 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 6/9] KVM: VMX: Preserve negative return value in vmx_handle_exit() with bus lock detected Date: Wed, 19 Aug 2026 17:49:00 +0800 Message-ID: <20260819094903.3060020-7-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Preserve the negative return value from __vmx_handle_exit() when a bus lock is detected, instead of always overwriting it with 0. The purpose of bus_lock_detected handling is to force a userspace exit to inform userspace that a bus lock happened. The negative return value can achieve this purpose, and changing the negative value to 0 fails to return an error to userspace. So, preserve the negative return value. Fixes: fe6b6bc802b4 ("KVM: VMX: Enable bus lock VM exit") Cc: stable@vger.kernel.org Reported-by: sashiko-bot@kernel.org Closes: https://lore.kernel.org/all/20260805034602.5B2BB1F000E9@smtp.kernel= .org/ Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. --- I'm not sure on the Closes: link, since Sashiko didn't find the VMX issue directly. Changes in v4 - grabbed from https://lore.kernel.org/all/20260806111923.1990562-2-xiaoyao= .li@intel.com/ --- arch/x86/kvm/vmx/vmx.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c index 35ac9ddffaf4..d302d0ce47f1 100644 --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -6860,11 +6860,12 @@ int vmx_handle_exit(struct kvm_vcpu *vcpu, fastpath= _t exit_fastpath) * a bus lock in guest. */ if (vmx_get_exit_reason(vcpu).bus_lock_detected) { - if (ret > 0) + if (ret > 0) { vcpu->run->exit_reason =3D KVM_EXIT_X86_BUS_LOCK; + ret =3D 0; + } =20 vcpu->run->flags |=3D KVM_RUN_X86_BUS_LOCK; - return 0; } return ret; } --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A709D448D16; Wed, 19 Aug 2026 09:54:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133286; cv=none; b=Bi5jE4frgSWR4plxsCnMaWQc3PqDqBw/Fyh3HmDmsPAkGcAw/+qj5nyuW3E/xw/4EAR4qzOxMK+TywUSB0nA9tC5tf0T90vNPgkrHnf4bA1Pi0z7dIzgLOhV+DPu2MrwK15Oa7Mkj1AthDcukmkKXifvk+Odwdci9s7F9m1PvRg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133286; c=relaxed/simple; bh=RdHnZjcIYeuyO7xWSUVuxu6vGL/Os6voQfl/ZJFuThw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Li2d40R+wdCY9qNNZIJ5PY2S5CVBZa8FtPIIzF7jDxpODRol10iYxhPzurNMlG6TqO+KuvAtWfOOvB9+zW6W567PHcpLHx7D9wA1Oai6Gs4JzlAOs2eKSowMIYQOBDGFYn+0U+Ee06Hf6TxS61Fjkv5u54nZI2lZDkpGGaLe3v8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=UJRZKwy8; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="UJRZKwy8" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133279; x=1818669279; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=RdHnZjcIYeuyO7xWSUVuxu6vGL/Os6voQfl/ZJFuThw=; b=UJRZKwy8HI10/p/AcAvod8leufAS8wD9pcEha7fui0lExceHtzUp30bS HXSuL3WR/l1c5B6+MLtXE5N3iSlzVtHY4gi3VX2hdJhQz2JPCS9aHhdk0 1kVZSsQOwyWDtQLQRV3AY8yYUooO4bRVuRSL+NQQI/OvmIRc/8IL9UoP6 mNBFAm4OjtVCkJYiqlfE27u+hboevmSQNYHtwb2/N7ad81L86DKB+13pY 5js9Nd7qMn1AtaW85Y5TY1G/nHgLCQEi/+f8GB96nG6CltOui7i+8S4+y M4GIRukz/TIUmNN44gtAe2WrykhPu3F6xHYF7RkFFu+8b9BbJO4na0pIK Q==; X-CSE-ConnectionGUID: CqE47eb2STe0ZePviwKoNg== X-CSE-MsgGUID: 8NLculOQSgG9ecUjex21ow== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514972" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514972" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:30 -0700 X-CSE-ConnectionGUID: JMAk3LbRQf+dNkC9mIqgqg== X-CSE-MsgGUID: MeS9+3tfRimZjzLajaonYQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708886" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:28 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 7/9] KVM: VMX: Make handle_bus_lock_vmexit() a shared helper Date: Wed, 19 Aug 2026 17:49:01 +0800 Message-ID: <20260819094903.3060020-8-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Move handle_bus_lock_vmexit() from vmx.c to main.c to make it a shared helper so that TDX can use it for Bus Lock VM exit handling as well. Rename it to add vt_ prefix to reflect that it is a helper for both VMX and TDX. Cc: stable@vger.kernel.org Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Nikolay Borisov --- Changes in v4: - split from next patch --- arch/x86/kvm/vmx/common.h | 1 + arch/x86/kvm/vmx/main.c | 11 +++++++++++ arch/x86/kvm/vmx/vmx.c | 13 +------------ 3 files changed, 13 insertions(+), 12 deletions(-) diff --git a/arch/x86/kvm/vmx/common.h b/arch/x86/kvm/vmx/common.h index 7fce1bbabc78..bbeec197a507 100644 --- a/arch/x86/kvm/vmx/common.h +++ b/arch/x86/kvm/vmx/common.h @@ -203,5 +203,6 @@ static inline int __vt_handle_notify(struct kvm_vcpu *v= cpu, } =20 noinstr void vmx_handle_nmi(struct kvm_vcpu *vcpu); +int vt_handle_bus_lock_vmexit(struct kvm_vcpu *vcpu); =20 #endif /* __KVM_X86_VMX_COMMON_H */ diff --git a/arch/x86/kvm/vmx/main.c b/arch/x86/kvm/vmx/main.c index 0ff3230fd95e..6a813c49ca8a 100644 --- a/arch/x86/kvm/vmx/main.c +++ b/arch/x86/kvm/vmx/main.c @@ -876,6 +876,17 @@ static int vt_gmem_max_mapping_level(struct kvm *kvm, = kvm_pfn_t pfn, #define vt_op_tdx_only(name) NULL #endif /* CONFIG_KVM_INTEL_TDX */ =20 +int vt_handle_bus_lock_vmexit(struct kvm_vcpu *vcpu) +{ + /* + * Hardware may or may not set the BUS_LOCK_DETECTED flag on BUS_LOCK + * VM-Exits. Unconditionally set the flag here and leave the handling + * to .handle_exit() callback. + */ + to_vt(vcpu)->exit_reason.bus_lock_detected =3D true; + return 1; +} + #define VMX_REQUIRED_APICV_INHIBITS \ (BIT(APICV_INHIBIT_REASON_DISABLED) | \ BIT(APICV_INHIBIT_REASON_ABSENT) | \ diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c index d302d0ce47f1..58c001b6cbc5 100644 --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -6265,17 +6265,6 @@ static int handle_encls(struct kvm_vcpu *vcpu) } #endif /* CONFIG_X86_SGX_KVM */ =20 -static int handle_bus_lock_vmexit(struct kvm_vcpu *vcpu) -{ - /* - * Hardware may or may not set the BUS_LOCK_DETECTED flag on BUS_LOCK - * VM-Exits. Unconditionally set the flag here and leave the handling to - * vmx_handle_exit(). - */ - to_vt(vcpu)->exit_reason.bus_lock_detected =3D true; - return 1; -} - static int handle_notify(struct kvm_vcpu *vcpu) { unsigned long exit_qual =3D vmx_get_exit_qual(vcpu); @@ -6364,7 +6353,7 @@ static int (*kvm_vmx_exit_handlers[])(struct kvm_vcpu= *vcpu) =3D { [EXIT_REASON_VMFUNC] =3D handle_vmx_instruction, [EXIT_REASON_PREEMPTION_TIMER] =3D handle_preemption_timer, [EXIT_REASON_ENCLS] =3D handle_encls, - [EXIT_REASON_BUS_LOCK] =3D handle_bus_lock_vmexit, + [EXIT_REASON_BUS_LOCK] =3D vt_handle_bus_lock_vmexit, [EXIT_REASON_NOTIFY] =3D handle_notify, [EXIT_REASON_SEAMCALL] =3D handle_tdx_instruction, [EXIT_REASON_TDCALL] =3D handle_tdx_instruction, --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 82BAB469859; Wed, 19 Aug 2026 09:54:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133290; cv=none; b=YTcHeF7tfJKWsLP923azlEsmamk+8Vf4Q8Fn4kfEEX6+lh5KA94AS9Ns5+5ynbyFt+xJEiDaLjb9HfVBoIBGka3hq77s//uVE7+r4GdHxycGUMyZ7znB2p7AD+wjHNV0QfAPeZRm0adJcO+Pihhl8hToM90DZUl8C6VRJRyc/fE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133290; c=relaxed/simple; bh=Xt9weOB2lj5KYEsyJLVJDLtGjvntwyLSMZgoSJIRW28=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jYxG3SqT+9bAXTpcVY6/QXSuJR9maxX93Ig6xBCXlSM+/yW+pzRZ/gJh6wtGy20ZWg97MloyHeIk4rvXBRIyPYeaVV2Ybd0sBcDo7Qm+MlGFb96+HtMfpo7pl3APkyPktRqqVAuLZxFuOVYCBlJfcAAMfS2vY8cG/LRhDn6uDhw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=Tdu0eXQT; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="Tdu0eXQT" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133281; x=1818669281; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=Xt9weOB2lj5KYEsyJLVJDLtGjvntwyLSMZgoSJIRW28=; b=Tdu0eXQTIh4OO8tfLQfFWTqMXNnCDeMwiX7pxEX/K7hyY9BrM6PQdm25 NGIIExn9xhmD5nJZ7RFwGI6yjC9VSQt6D73i5uGu7Deqp/S6xDTaUbFzv HAQ+M4c/yfHURL0VXhIPWF7dErIG9+yhSZeXteYZshhFSIi82EyGei++l zoF8tyzZwR6NSeyXsYXm+VaouoHaiHBEsi5XazY8FlOwS9XhoVD4d/AFg JJWsv5S5r9hQ19A/EvG8D7HK3xiOaOJ21e41IXvuDnKa0PAuPtTpFmiUd PzlbRXLloO8Kwnv6oR+6qZTWnDsUp13hRFEtfwaps7ElTVxoItesB4axN Q==; X-CSE-ConnectionGUID: 6iRpAtnnS4CudenNZ8N6Cw== X-CSE-MsgGUID: 6sH40P/4R8CzkdFfVvtjCQ== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87514996" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87514996" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:32 -0700 X-CSE-ConnectionGUID: HM1S2T6vTyeMdj2+i6+LJQ== X-CSE-MsgGUID: xwEVNGg8SBu2wkcOD/+ISg== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708892" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:30 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 8/9] KVM: TDX: Enable Bus Lock VM exit Date: Wed, 19 Aug 2026 17:49:02 +0800 Message-ID: <20260819094903.3060020-9-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Enable Bus Lock VM exit functionality for TDX guests. Bus Lock VM exit is an existing feature supported by KVM. Userspace can enable Bus Lock VM exit through KVM_BUS_LOCK_DETECTION_EXIT when it's reported as supported. However, KVM reports the support of this CAP just based on the hardware capability but doesn't differentiate between VMX and TDX. This leads to the issue that userspace can enable this cap for TDX guests without getting an error, but the feature is not actually enabled because KVM doesn't call the TDX module API to program the relevant TD VMCS fields. Enable Bus Lock VM exit for TDX guests by programming the BUS_LOCK_DETECTION control in the TD VMCS and by adding the exit handler. Note, there is no enumeration bit for this feature by TDX module because all TDX modules support it and allow to set the TD VMCS as long as the hardware supports the feature. Fixes: 161d34609f9b ("KVM: TDX: Make TDX VM type supported") Cc: stable@vger.kernel.org Originally-by: Chenyi Qiang Signed-off-by: Xiaoyao Li Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Nikolay Borisov --- Changes in 4: - The code to make handle_bus_lock_vmexit() a shared helper is split as a separate patch. - The handling for wait_for_sept_zap is no longer needed since a general handling for it is added as a separate patch. Changes in v3: - Refine the changelog. (Rick) Changes in v2: - Don't overwrite the negative return value to 0. (Sashiko) - Clear the bus_lock_detected bit when it returns early for wait_for_sept_zap case. - Add a note to clarify the feature is always supported by the TDX module, to make Sashiko happy. --- arch/x86/kvm/vmx/tdx.c | 24 +++++++++++++++++++++++- 1 file changed, 23 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index 014710945e8a..8db0c67aaadc 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -2058,7 +2058,7 @@ int tdx_complete_emulated_msr(struct kvm_vcpu *vcpu, = int err) } =20 =20 -int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) +static int __tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) { struct vcpu_tdx *tdx =3D to_tdx(vcpu); u64 vp_enter_ret =3D tdx->vp_enter_ret; @@ -2159,6 +2159,8 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t= fastpath) case EXIT_REASON_NOTIFY: /* NMI blocking state is handled by TDX module */ return __vt_handle_notify(vcpu, vmx_get_exit_qual(vcpu)); + case EXIT_REASON_BUS_LOCK: + return vt_handle_bus_lock_vmexit(vcpu); default: break; } @@ -2168,6 +2170,22 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_= t fastpath) return 0; } =20 +int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) +{ + int ret =3D __tdx_handle_exit(vcpu, fastpath); + + /* Exit to user space when bus lock was detected */ + if (vmx_get_exit_reason(vcpu).bus_lock_detected) { + if (ret > 0) { + vcpu->run->exit_reason =3D KVM_EXIT_X86_BUS_LOCK; + ret =3D 0; + } + + vcpu->run->flags |=3D KVM_RUN_X86_BUS_LOCK; + } + return ret; +} + void tdx_get_exit_info(struct kvm_vcpu *vcpu, u32 *reason, u64 *info1, u64 *info2, u32 *intr_info, u32 *error_code) { @@ -3194,6 +3212,10 @@ static int tdx_vcpu_init(struct kvm_vcpu *vcpu, stru= ct kvm_tdx_cmd *cmd) vcpu->kvm->arch.notify_window); } =20 + if (vcpu->kvm->arch.bus_lock_detection_enabled) + td_vmcs_setbit32(tdx, SECONDARY_VM_EXEC_CONTROL, + SECONDARY_EXEC_BUS_LOCK_DETECTION); + tdx->state =3D VCPU_TD_STATE_INITIALIZED; =20 return 0; --=20 2.43.0 From nobody Mon Sep 28 17:48:45 2026 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CE09A44C653; Wed, 19 Aug 2026 09:54:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.17 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133298; cv=none; b=OlSoIFdQk833oyGX3Do39iDXSoiVsg915VRVlTRmMaNyEK2OlGtsRToMei120Qk9xmf5rFMwQ731jNWMMBB5wQyte7til8MTeMAPLfGOff4VB2WIXKL0ITKdqXHBgpmYClejsybpMndY/KvIT5+CZhRhedPu22JX2NsjgWK+35s= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787133298; c=relaxed/simple; bh=H7NeiJ2egnfoOMilwZTkUIIYLGO/1E8OeCkopKoPm3s=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=K4QGUPnMvt23GBCIGAV/suf+JIVA+5/NKAcnFYwz3qS4EjMLGd/OYk2hwVLcP6l8X38h2Rnre0A8klR6BfOpUKdQ3kKaUIFHmHhlHRwU5PkVu9phS9aKz3VBMh2qOf/ttAe4O2fGa2z3g8vp3WEtEX5uyjCSz+4zVMCRCjfSxEk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com; spf=pass smtp.mailfrom=intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=ey9umI0f; arc=none smtp.client-ip=192.198.163.17 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="ey9umI0f" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1787133288; x=1818669288; h=from:to:cc:subject:date:message-id:in-reply-to: references:mime-version:content-transfer-encoding; bh=H7NeiJ2egnfoOMilwZTkUIIYLGO/1E8OeCkopKoPm3s=; b=ey9umI0fizXlD4wIzjlZddmaMYwOhSsOavGaqXSmqtgdSBtMhEx7fZog Hh8CIoj9gxf2F5D71kqZL0hlysTIRxThS0GDmlfENHJVievXihg6C3Cni bLPNx5udC2lTINKNeFr69qg/FPGHlZ5Lb9k6JIvW0j0kT4WeBJhW9AdQA R1fFx7oEUaj1o7z2aPv5ZqweGBb0r42wpHn5+eTMECrU124z8+7v+e6cj /3XAY5EbKnNhv7eBw6wYCq7yYkgO6heM0oARwk0y8l1Xovm46Z9RQLnbZ +hxPG3tkUBp1bhX0d9k+NuQEjgTfXJUhKKjiRUXwjLHLlSj3DD6Kr5MOl A==; X-CSE-ConnectionGUID: nV6C2rd1Q3y8s7NPPI75ow== X-CSE-MsgGUID: nCoqJgJVR7uDRij0TZ79RA== X-IronPort-AV: E=McAfee;i="6800,10657,11879"; a="87515019" X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="87515019" Received: from orviesa001.jf.intel.com ([10.64.159.141]) by fmvoesa111.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 19 Aug 2026 02:54:35 -0700 X-CSE-ConnectionGUID: Ogc31NEIR1OzIwBDdQCNGg== X-CSE-MsgGUID: DEobpRBoTJWyQITWWb8gzA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.25,231,1779174000"; d="scan'208";a="303708903" Received: from lxy-clx-4s.sh.intel.com ([10.239.48.33]) by orviesa001.jf.intel.com with ESMTP; 19 Aug 2026 02:54:33 -0700 From: Xiaoyao Li To: Sean Christopherson , Paolo Bonzini Cc: Kiryl Shutsemau , Rick Edgecombe , Xiaoyao Li , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, nik.borisov@suse.com Subject: [PATCH v4 9/9] KVM: VMX: Consolidate the exit handler for VMX and TDX Date: Wed, 19 Aug 2026 17:49:03 +0800 Message-ID: <20260819094903.3060020-10-xiaoyao.li@intel.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260819094903.3060020-1-xiaoyao.li@intel.com> References: <20260819094903.3060020-1-xiaoyao.li@intel.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The exit handlers for VMX and TDX have the similar pattern. Consolidate them into a single vt_handle_exit() helper. Signed-off-by: Xiaoyao Li Changes in v4: - new patch. Reviewed-By: Vishal Annapurve for the complete seri= es. Reviewed-by: Nikolay Borisov --- arch/x86/kvm/vmx/main.c | 38 ++++++++++++++++++++++++++++---------- arch/x86/kvm/vmx/tdx.c | 18 +----------------- arch/x86/kvm/vmx/vmx.c | 21 +-------------------- 3 files changed, 30 insertions(+), 47 deletions(-) diff --git a/arch/x86/kvm/vmx/main.c b/arch/x86/kvm/vmx/main.c index 6a813c49ca8a..10df9667d0c0 100644 --- a/arch/x86/kvm/vmx/main.c +++ b/arch/x86/kvm/vmx/main.c @@ -154,15 +154,6 @@ static fastpath_t vt_vcpu_run(struct kvm_vcpu *vcpu, u= 64 run_flags) return vmx_vcpu_run(vcpu, run_flags); } =20 -static int vt_handle_exit(struct kvm_vcpu *vcpu, - enum exit_fastpath_completion fastpath) -{ - if (is_td_vcpu(vcpu)) - return tdx_handle_exit(vcpu, fastpath); - - return vmx_handle_exit(vcpu, fastpath); -} - static bool vt_unhandleable_emulation_required(struct kvm_vcpu *vcpu) { if (is_td_vcpu(vcpu)) { @@ -887,6 +878,33 @@ int vt_handle_bus_lock_vmexit(struct kvm_vcpu *vcpu) return 1; } =20 +static int vt_handle_exit(struct kvm_vcpu *vcpu, + enum exit_fastpath_completion fastpath) +{ + int ret; + +#ifdef CONFIG_KVM_INTEL_TDX + if (is_td_vcpu(vcpu)) + ret =3D tdx_handle_exit(vcpu, fastpath); + else +#endif + ret =3D vmx_handle_exit(vcpu, fastpath); + + /* + * Exit to user space when bus lock detected to inform that there is + * a bus lock in guest. + */ + if (vmx_get_exit_reason(vcpu).bus_lock_detected) { + if (ret > 0) { + vcpu->run->exit_reason =3D KVM_EXIT_X86_BUS_LOCK; + ret =3D 0; + } + + vcpu->run->flags |=3D KVM_RUN_X86_BUS_LOCK; + } + return ret; +} + #define VMX_REQUIRED_APICV_INHIBITS \ (BIT(APICV_INHIBIT_REASON_DISABLED) | \ BIT(APICV_INHIBIT_REASON_ABSENT) | \ @@ -960,7 +978,7 @@ struct kvm_x86_ops vt_x86_ops __initdata =3D { =20 .vcpu_needs_initialization =3D vt_op_tdx_only(vcpu_needs_initialization), .vcpu_run =3D vt_op(vcpu_run), - .handle_exit =3D vt_op(handle_exit), + .handle_exit =3D vt_handle_exit, .skip_emulated_instruction =3D vmx_skip_emulated_instruction, .update_emulated_instruction =3D vmx_update_emulated_instruction, .unhandleable_emulation_required =3D vt_op(unhandleable_emulation_require= d), diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index 8db0c67aaadc..364a2322a9f5 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -2058,7 +2058,7 @@ int tdx_complete_emulated_msr(struct kvm_vcpu *vcpu, = int err) } =20 =20 -static int __tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) +int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) { struct vcpu_tdx *tdx =3D to_tdx(vcpu); u64 vp_enter_ret =3D tdx->vp_enter_ret; @@ -2170,22 +2170,6 @@ static int __tdx_handle_exit(struct kvm_vcpu *vcpu, = fastpath_t fastpath) return 0; } =20 -int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath) -{ - int ret =3D __tdx_handle_exit(vcpu, fastpath); - - /* Exit to user space when bus lock was detected */ - if (vmx_get_exit_reason(vcpu).bus_lock_detected) { - if (ret > 0) { - vcpu->run->exit_reason =3D KVM_EXIT_X86_BUS_LOCK; - ret =3D 0; - } - - vcpu->run->flags |=3D KVM_RUN_X86_BUS_LOCK; - } - return ret; -} - void tdx_get_exit_info(struct kvm_vcpu *vcpu, u32 *reason, u64 *info1, u64 *info2, u32 *intr_info, u32 *error_code) { diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c index 58c001b6cbc5..490baae56cf1 100644 --- a/arch/x86/kvm/vmx/vmx.c +++ b/arch/x86/kvm/vmx/vmx.c @@ -6681,7 +6681,7 @@ void dump_vmcs(struct kvm_vcpu *vcpu) * The guest has exited. See if we can fix it or if we need userspace * assistance. */ -static int __vmx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t exit_fastpa= th) +int vmx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t exit_fastpath) { struct vcpu_vmx *vmx =3D to_vmx(vcpu); union vmx_exit_reason exit_reason =3D vmx_get_exit_reason(vcpu); @@ -6840,25 +6840,6 @@ static int __vmx_handle_exit(struct kvm_vcpu *vcpu, = fastpath_t exit_fastpath) return 0; } =20 -int vmx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t exit_fastpath) -{ - int ret =3D __vmx_handle_exit(vcpu, exit_fastpath); - - /* - * Exit to user space when bus lock detected to inform that there is - * a bus lock in guest. - */ - if (vmx_get_exit_reason(vcpu).bus_lock_detected) { - if (ret > 0) { - vcpu->run->exit_reason =3D KVM_EXIT_X86_BUS_LOCK; - ret =3D 0; - } - - vcpu->run->flags |=3D KVM_RUN_X86_BUS_LOCK; - } - return ret; -} - void vmx_update_cr8_intercept(struct kvm_vcpu *vcpu, int tpr, int irr) { int tpr_threshold; --=20 2.43.0