[PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops

Sean Christopherson posted 4 patches 1 month ago
arch/x86/kvm/mmu/mmu.c | 48 ++++++++++++++++++++++++++++--------------
1 file changed, 32 insertions(+), 16 deletions(-)
[PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops
Posted by Sean Christopherson 1 month ago
Fix a bug in the pre-fault path where KVM fails to reload an invalidated
MMU root, which puts the KVM_PRE_FAULT_MEMORY task into an infinite loop
(although it's breakable, so not fatal to the host).  My best guess is that
the test started failing once PREEMPT_LAZY was enabled by default.  Note,
the bug is *really* easy to repro with a to-be-proposed patch to have KVM
do auto-pre-faulting[*], i.e. prefetch surrounding pages on fault.

Then harden the similar "map private PFN" to also guard against unexpected
root invalidations, because Sashiko keeps pointing out that it's theoretically
possible for that code to end up in the same type of infinite loop.

[*] https://lore.kernel.org/all/ao4CufEI_pRCjbMF@google.com

v2:
 - Collect reviews. [Rick, Kai]
 - Tweak the slots_comment in kvm_tdp_mmu_map_private_pfn() to better capture
   the nuances of KVM_REQ_MMU_FREE_OBSOLETE_ROOTS. [Rick]
 - Call out in the changelog for patch 2 that simply warning on
   KVM_REQ_MMU_FREE_OBSOLETE_ROOTS is flawed, but handled in a subsequent
   patch. [Sashiko]
 - Make it more clear that encountering retry in kvm_tdp_mmu_map_private_pfn()
   can only happen if there are KVM bugs. [Rick]
 - Set r to RET_PF_RETRY when a stale page fault is detected. [Sashiko]

v1: https://lore.kernel.org/all/20260806214050.78058-1-seanjc@google.com

Sean Christopherson (4):
  KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration
  KVM: x86/mmu: Harden "map private PFN" against unexpected root
    invalidation
  KVM: x86/mmu: Top-up memory caches when retrying "map private PFN"
  KVM: x86/mmu: Add sanity check to detect stale page faults in "map
    private PFN"

 arch/x86/kvm/mmu/mmu.c | 48 ++++++++++++++++++++++++++++--------------
 1 file changed, 32 insertions(+), 16 deletions(-)


base-commit: 76671054f9a1ff6abb976583cd8da37650acdc97
-- 
2.55.0.860.g4b6b3295ed-goog
Re: [PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops
Posted by Sean Christopherson 6 days, 14 hours ago
On Wed, 26 Aug 2026 09:42:10 -0700, Sean Christopherson wrote:
> Fix a bug in the pre-fault path where KVM fails to reload an invalidated
> MMU root, which puts the KVM_PRE_FAULT_MEMORY task into an infinite loop
> (although it's breakable, so not fatal to the host).  My best guess is that
> the test started failing once PREEMPT_LAZY was enabled by default.  Note,
> the bug is *really* easy to repro with a to-be-proposed patch to have KVM
> do auto-pre-faulting[*], i.e. prefetch surrounding pages on fault.
> 
> [...]

Applied to kvm-x86 mmu, thanks!

[1/4] KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration
      https://github.com/kvm-x86/linux/commit/355323a4dc94
[2/4] KVM: x86/mmu: Harden "map private PFN" against unexpected root invalidation
      https://github.com/kvm-x86/linux/commit/698b8c88e159
[3/4] KVM: x86/mmu: Top-up memory caches when retrying "map private PFN"
      https://github.com/kvm-x86/linux/commit/6415d9c4ee19
[4/4] KVM: x86/mmu: Add sanity check to detect stale page faults in "map private PFN"
      https://github.com/kvm-x86/linux/commit/f7a3be227619

--
https://github.com/kvm-x86/linux/tree/next
Re: [PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops
Posted by Paolo Bonzini 6 days, 12 hours ago
On Mon, Sep 21, 2026 at 4:07 PM Sean Christopherson <seanjc@google.com> wrote:
>
> On Wed, 26 Aug 2026 09:42:10 -0700, Sean Christopherson wrote:
> > Fix a bug in the pre-fault path where KVM fails to reload an invalidated
> > MMU root, which puts the KVM_PRE_FAULT_MEMORY task into an infinite loop
> > (although it's breakable, so not fatal to the host).  My best guess is that
> > the test started failing once PREEMPT_LAZY was enabled by default.  Note,
> > the bug is *really* easy to repro with a to-be-proposed patch to have KVM
> > do auto-pre-faulting[*], i.e. prefetch surrounding pages on fault.
> >
> > [...]
>
> Applied to kvm-x86 mmu, thanks!
>
> [1/4] KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration
>       https://github.com/kvm-x86/linux/commit/355323a4dc94
> [2/4] KVM: x86/mmu: Harden "map private PFN" against unexpected root invalidation
>       https://github.com/kvm-x86/linux/commit/698b8c88e159
> [3/4] KVM: x86/mmu: Top-up memory caches when retrying "map private PFN"
>       https://github.com/kvm-x86/linux/commit/6415d9c4ee19
> [4/4] KVM: x86/mmu: Add sanity check to detect stale page faults in "map private PFN"
>       https://github.com/kvm-x86/linux/commit/f7a3be227619

Should I apply this to kvm/master?

Paolo
Re: [PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops
Posted by Sean Christopherson 6 days, 12 hours ago
On Mon, Sep 21, 2026, Paolo Bonzini wrote:
> On Mon, Sep 21, 2026 at 4:07 PM Sean Christopherson <seanjc@google.com> wrote:
> >
> > On Wed, 26 Aug 2026 09:42:10 -0700, Sean Christopherson wrote:
> > > Fix a bug in the pre-fault path where KVM fails to reload an invalidated
> > > MMU root, which puts the KVM_PRE_FAULT_MEMORY task into an infinite loop
> > > (although it's breakable, so not fatal to the host).  My best guess is that
> > > the test started failing once PREEMPT_LAZY was enabled by default.  Note,
> > > the bug is *really* easy to repro with a to-be-proposed patch to have KVM
> > > do auto-pre-faulting[*], i.e. prefetch surrounding pages on fault.
> > >
> > > [...]
> >
> > Applied to kvm-x86 mmu, thanks!
> >
> > [1/4] KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration
> >       https://github.com/kvm-x86/linux/commit/355323a4dc94
> > [2/4] KVM: x86/mmu: Harden "map private PFN" against unexpected root invalidation
> >       https://github.com/kvm-x86/linux/commit/698b8c88e159
> > [3/4] KVM: x86/mmu: Top-up memory caches when retrying "map private PFN"
> >       https://github.com/kvm-x86/linux/commit/6415d9c4ee19
> > [4/4] KVM: x86/mmu: Add sanity check to detect stale page faults in "map private PFN"
> >       https://github.com/kvm-x86/linux/commit/f7a3be227619
> 
> Should I apply this to kvm/master?

I'm not opposed to pulling this into 7.3, but I also don't think it's necessary.
There's no danger to the host, and without the auto-pre-faulting functionality,
it effectively requires a deliberately misbehaving VMM.  I doubt this will impact
anything other than the pre-fault selftest for 7.3.