From nobody Mon Sep 28 04:08:39 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37A4F394793 for ; Wed, 26 Aug 2026 21:18:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779129; cv=none; b=RCM+46G0C6J/14/AR+iK9DkuV+rkkNZ5ClRIr3JIbPEWA6ZrCTvIhkWjWHalD7JTC8CN6B9o5NCtFIOs9iRGMatb2HsDsidgNZKC7i0d10MyCcA2hHYwUSeWu1gpxAwUrZXRL5qw5yDboWKEKAqr+XvOY34YqYwzGXXD1b0WFDo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779129; c=relaxed/simple; bh=6sCSVbTksTpzUfz2Vygg/QdEYlpQa3FDKHZ/LkAuyec=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=NJ98OH/irGB2OOlJhkV7tROunbFcnOAJ3QSgkPc/IqtTE+vLZYB4rUUEUtalLyFybTG/rF6wG5Z2S2kwlAhOxsAziljGUksC490VRztMGF+VSQ/29/8+YAjzLEi/oJSX+3NE442mQRnFIm9JivDrbYVenMiajlqo9ab7VF0ODXk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=RWgn+1rS; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="RWgn+1rS" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-cc1b80835d5so1602524a12.2 for ; Wed, 26 Aug 2026 14:18:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787779127; x=1788383927; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=YdQOf/sgj3pcH0YMGOZwkO4ah2h30JX4XXRsNdNb4bg=; b=RWgn+1rSikEO9GnIR/AX1nK2tZrovo9tfMf6ZDoIs8qerRCqfo/EXy1RQEXGmU8PHb dTY1MFqE0sURmihsk1FAPTF/eCdD//OMYC9u0BS/XYoBxR/ikz6AKqcJ2glxIzw9DIPT +ftLJWwAQSwyyv9bX+d9SP4skgy01vYzyYFXdktPP6IFThBb6QqCv1uTO60F65XYKRpI +YTMkm8eGKmcaNpzA9aWdQDf1+lYArvitNS+9aFiTurdq0/KU0UybehZCXnJqt1y0nGO yC72aTe818PM3NpPRz24C0SmguduDYsV0cQsp10ya1D5YlfRg0IiqJO4ilsgIaUMnlJo /KvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787779127; x=1788383927; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=YdQOf/sgj3pcH0YMGOZwkO4ah2h30JX4XXRsNdNb4bg=; b=S0YO/KumYLFIImi9xyTkzs770cHpYEiaor2xPwTcQLH2/AXIlGxd4aqeRZYTBq9+xG Ey0HVgQrZtoL7L+JfrdmJPIbuSqHRTmW9bXox9O9UEql52VdyjxqSzREQvFiwV5MxZxW zmyIKtxPpk8WQACw88B3CuIbIlk4l6MONLYW2WFImOfM1Uvpug4Bfx1O+YtSdvhpmsr+ k03hhwzVKjb3cvmBRvf7mUMPMudE/kJfMv9bzJvvE3ivVIBcdfr4DCTXPtRHTP084jSo BblizM565/NddCkrn4oor1KMVxLVK5iYNaz6uzL7cZLKNHFSfapdQolvx84QFc8YEmEi 4SXw== X-Forwarded-Encrypted: i=1; AHgh+RpENc7FwVVKHDHLbJFGvvwsWXxAruTBKCsKNu/h8JHgZPirTgeQwzUcCiOiDeVs42dW9EbBT7Z4DDYOk7o=@vger.kernel.org X-Gm-Message-State: AFuF++mEiQoy39SkDNpM3Q27Ag+WGXMoGbdWwsy3Yc0hMnJ1++f9cQOY W2QoI3RY55RdVFHOIpzuo/UXN8Yx17suu1ZjNu166/DqDek6zfrSjAwesE8K0+kTf1i0glUXo4x b4aw6eg== X-Received: from pgab135.prod.google.com ([2002:a63:348d:0:b0:cc1:522f:464c]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:a95:b0:3c1:fbf:1e2e with SMTP id adf61e73a8af0-3cf83b22768mr20870291637.10.1787779127361; Wed, 26 Aug 2026 14:18:47 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 26 Aug 2026 14:18:41 -0700 In-Reply-To: <20260826211844.884951-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826211844.884951-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.887.g758fc8c411-goog Message-ID: <20260826211844.884951-2-seanjc@google.com> Subject: [PATCH 1/4] KVM: nSVM: Reject KVM_SET_NESTED_STATE if L1 has EFER.LMA=1 && EFER.LME=0 From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Reject KVM_SET_NESTED_STATE if the incoming L1 host state has what is effectively an impossible EFER combination of LMA=3D1 but LME=3D0, i.e. if = the state says long mode is active but not enabled. Unlike VMX, SVM doesn't have an explicit consistent check for the illegal combination; presumably hardware simply ignores EFER.LMA if EFER.LME=3D0. Unfortunately, KVM doesn't ignore EFER.LMA in this case and consumes the illegal state when constructing the shadow MMU for L2. E.g. if userspace also clears CR4.PAE, then kvm_calc_cpu_role() will compute a role with 4 or 5 levels of paging, but shadow_mmu_init_context() will wire up the MMU to use the paging32 template, which maxes out its levels at 2. Note, the "real badness" is effectively the same as what happened with the nVMX bug fixed by commit 112e66017bff ("KVM: nVMX: add missing consistency checks for CR0 and CR4"). Unfortunately, the sanity check added by commit 72e2fb24a0b0 ("KVM: x86/mmu: Bug the VM if a vCPU ends up in long mode without PAE enabled") doesn't work for this case, since L2 state is active at the time of the page fault, but it's L1 that has the bad state. Fixes: cc440cdad5b7 ("KVM: nSVM: implement KVM_GET_NESTED_STATE and KVM_SET= _NESTED_STATE") Cc: stable@vger.kernel.org Cc: Yosry Ahmed Reported-by: Stefan Teodorescu Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/nested.c | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c index 73f37b050d0a..49fb10ad1f9f 100644 --- a/arch/x86/kvm/svm/nested.c +++ b/arch/x86/kvm/svm/nested.c @@ -2028,6 +2028,7 @@ static int svm_set_nested_state(struct kvm_vcpu *vcpu, if (!(save->cr0 & X86_CR0_PG) || !(save->cr0 & X86_CR0_PE) || (save->rflags & X86_EFLAGS_VM) || + ((save->efer & EFER_LMA) && !(save->efer & EFER_LME)) || !nested_vmcb_check_save(vcpu, &save_cached, false)) goto out_free; =20 --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:08:39 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C15B44839A for ; Wed, 26 Aug 2026 21:18:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779130; cv=none; b=FzqgUG5PcH7e6WkRaLuJxUWfrOqZpillsecjgfI5gN1Ov6R2/6SKGNsXEchTTVgiWXmOL+GfVs1kOh3CcaCQamuMHcmPWVGJprxxbKwYOGxJx+OFWlGa4IIrRJ9NvwMwvYK6dppASsRQU5TJAAjTjS0LelQv90wdB/S/nGg7VNo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779130; c=relaxed/simple; bh=D2SeNS61d9dVgtDOWdeCnHOyaoz2w294vOhGlL5Cxr0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=d3P8RL4n2erk1PunOA8iV4GTVBnanXqu2DEwZsSHTXmdjUz5m51kdInyTLvkIG8fRlFpbgOBiI15WO8TPehVv0F7n7LOk59JhMwSQ0dX17I2EIjQWWj7LWL9RVXpLblt+20oidDgWZNeOxxByEsuXpV56zycqw37tln2vDY5TG8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=uSZCL3Bi; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="uSZCL3Bi" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-cbb467e56aaso19202a12.1 for ; Wed, 26 Aug 2026 14:18:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787779129; x=1788383929; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gm2xvEQmU0KWTaMXq3LZgCB6my4zIF400tJYxp9L68k=; b=uSZCL3BiHFNexQmRE6w4G3AdF2spVvBYXeZU0pKe2PKH+LuZUO57ZtUYNTy+j7i8qF ad1SbhwvxecMMDIqb0s30cZTdURxqDtlGRL1w0kky+ztGxGMAM20kKBdLpxG86+3AORD ogeeRtR5XI66EDfw0RWMsc1XS7DvSrsItokzQrwryh609F7nrIg7uVa3a2Jr7KN8REyg Shctr3lgPAGFxx28MauXit3jL9evPRnZ1aeslck+hIr9tbolXhdqqENxDnkzUj0XNMNC UEtq8YvyAxK/LmHgOvTP9FJuWGhiZHWSXfGWxgS/5ElveUp7ibmfRNenI4q89bTS1jQL la6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787779129; x=1788383929; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gm2xvEQmU0KWTaMXq3LZgCB6my4zIF400tJYxp9L68k=; b=gdEBxghMl6fBPitDPSPZdyMzAKQVjdVdRBJeKrCguDrbv0BGH1hJ4ErVtxUP8Ttts/ PiaAJx03dVcK87vAi8yNqpyiSlnA2/Mb7cMB5b0RSUJ8TuEFwhRWvfgrHl1bqs8qoURd x4Az8T8bxtmcLNd5lNaxoTa16Tz9TZQlGIyrAx710D/amoXjMr0BCHkYoApCsRLel8tA Dlo0iIte6+eu9ogHTEhNerOkSYuVLJIA3/zjCpf12hYQUo52FAsOFBRYXnbd5OmS/tK3 fMAkdIm2RZNR9/PU/bM/ofAGwqRZoq1TJ0hdqa4BThkbEnRNaaFvLuWKSvwjg7JmS3Zo qCHg== X-Forwarded-Encrypted: i=1; AHgh+RqBV42p0poNZXKaobfCkgm5Lh9D+aLAIp3x1W4aeqjxZ7L4YcXxnZjWJQ92EwQv/qBcSQA5r/28+1IiiWc=@vger.kernel.org X-Gm-Message-State: AFuF++lQm32B3hvdII+YqjSUondlsc6F5Orsyi9NL+7JZ+wzqGMK1XpR QyvQ9Pk+qMwGVqrccdJ+HG3pz02J6u55UjQhmHn6jJ4Q9nWZQhhNFFF0o4M0LpKKWWzGDsE6uZo ENRGj0w== X-Received: from pgbs186.prod.google.com ([2002:a63:5ec3:0:b0:cc1:c943:f652]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:3c85:b0:847:7f3c:b5f5 with SMTP id d2e1a72fcca58-85374ec9fe4mr16903779b3a.11.1787779128400; Wed, 26 Aug 2026 14:18:48 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 26 Aug 2026 14:18:42 -0700 In-Reply-To: <20260826211844.884951-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826211844.884951-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.887.g758fc8c411-goog Message-ID: <20260826211844.884951-3-seanjc@google.com> Subject: [PATCH 2/4] KVM: x86/mmu: Bug the VM if KVM attempts to walk more levels than the MMU has From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Extend the "EFER.LMA && !CR4.PAE" check, which exists largely to guard against KVM configuring a paging32 MMU with more than 2 levels of paging, with a very explicit check for exactly that: that KVM isn't trying to walk more levels of paging than the MMU template provides. I.e. harden KVM against all bugs that would cause KVM to generates accesses beyond the bounds of guest_walker's arrays, regardless of how KVM ended up with the misconfigured MMU. Cc: stable@vger.kernel.org Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/paging_tmpl.h | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h index 27427e7f22fa..46a0f7796e55 100644 --- a/arch/x86/kvm/mmu/paging_tmpl.h +++ b/arch/x86/kvm/mmu/paging_tmpl.h @@ -368,13 +368,14 @@ static int FNAME(walk_addr_generic)(struct guest_walk= er *walker, pte_access =3D ~0; =20 /* - * Queue a page fault for injection if this assertion fails, as callers - * assume that walker.fault contains sane info on a walk failure. I.e. - * avoid making the situation worse by inducing even worse badness - * between when the assertion fails and when KVM kicks the vCPU out to - * userspace (because the VM is bugged). + * Queue a page fault for injection if any of the below assertions fail, + * as callers assume that walker.fault contains sane info on a walk + * failure. I.e. avoid making the situation worse by inducing even + * worse badness between when the assertion fails and when KVM kicks + * the vCPU out to userspace (because the VM is bugged). */ - if (KVM_BUG_ON(is_long_mode(vcpu) && !is_pae(vcpu), vcpu->kvm)) + if (KVM_BUG_ON(is_long_mode(vcpu) && !is_pae(vcpu), vcpu->kvm) || + KVM_BUG_ON(w->cpu_role.base.level > PT_MAX_FULL_LEVELS, vcpu->kvm)) goto error; =20 ++walker->level; --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:08:39 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8225E48987C for ; Wed, 26 Aug 2026 21:18:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779132; cv=none; b=me8vBc6BSM9CN3iA7st+1n95f3ysTuf/fV2CHAwm6vtR4IUx1eZBu6u3uTcTCE4K7XtTJ4ISqw4JEu3gcReKy5vPgbZG9B5Gh40iuHtLGXQHK2MvB8TNavUxyYYFXLt4d4jHFyFtIZhu66wSQ22gCbo9FiYpxLBYcOzBYmw6eXs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779132; c=relaxed/simple; bh=8NeLykLRObnZo9WdI4jh2504OsgL7LQCSOwniXL4gss=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=ogzGATi90axtYnWX9leSvSiXDSPw/In3kW6t2DXzRtoJx4uJl1doUEnb8Uinc9WSdogCVrUoWfOMYQAS7gZDFhz9MVG3n3oeoTZ0VJlTuEoem00kXakvKfudi1Y7jxZpIRAENbGzdcTTDzVxHki9PKN16ZyUneEpS98zQFr8Vmk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=uzJQBPCC; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="uzJQBPCC" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2cc7e86e7c5so23964415ad.3 for ; Wed, 26 Aug 2026 14:18:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787779131; x=1788383931; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ki7qK8/nnEsokLeZZvHmHWCVS1qAQX7AXkZyfPN9a6c=; b=uzJQBPCCXAguEolxUAcpwLKgNHn1qgG7FczeI1e40vccMFgf/qVQFs+KH8atoQA0WV WU42jDLberlUGgczkhgJzkUFOWQcVhKaLXf0QivlTuJ9do9FBRaesNyFqGcPSh+yYcut 6xuVXyzy9FgvI1HCVdOLObUHSzspiIMBqZuqa/YveiRNdoH/LRl+G8XEU7z8g/srnS2E 5rAGOFXa2+x4hhfxlQn5PwC/s0xi6y/yJ/keWOcF9C2EoxLE18PAoDYAN4Q+Z4ZHUG+s xNL3W3HM6/6Y+xtFjMlPxK4k0wViqUOTEZOpgxglFCJ/I079ffUyM8EwOwq11UZ0BK4J o7og== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787779131; x=1788383931; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=ki7qK8/nnEsokLeZZvHmHWCVS1qAQX7AXkZyfPN9a6c=; b=Q71ipznO4GLEM81ovZQroT5tqDZqDwar9+xTHbqWzPo4h+WzwfSRfvATTBdsXl8uXZ UP88NR7DFQ/AnBplwsgEC5vumvK7bf7fA7HR4x7BHWaa8k+MTo4z1Bzm1pH88RI6TZwl QcTsB9UMSMjwuPsxzC6ZhmkiryJ4PhLBK4H+VSkcnTdnzI0zeu3tsDtO2g89rpgb+GXQ 79iChTqPEcHJPRCOuEH3RQKOSLIEMiwL0CFipsJ9b7i0iQ2EZDfXHsaL/sJTEHxZSd6j Ggxy4olSyFx9UXxTw9aRBmsPYz5GCouuTAXqBSbms/7olgAa4kjA9YHzcVGJ8VXs3cBM +FYA== X-Forwarded-Encrypted: i=1; AHgh+Rqmz80A6dFSZCb/gdzWq9aqdxpYzJI27M1vvmlA/3jozA70Km4ee1XN/yfs5hyv7bNORwfJ1ZE4QJui7ww=@vger.kernel.org X-Gm-Message-State: AFuF++kDyHaVAlcVt+/GhUq/cdQi30c8USKBP4vhWLbILcojUXh0Jug5 iw2uwMk0oN1ZDLMMA7OauW7J1b2QyP8OlaKJXzZ6xCiwKX8S5FlM7/GknnCwcAaDean8ij5N3HO VDgsV7Q== X-Received: from plcj13.prod.google.com ([2002:a17:902:f24d:b0:2cf:1f9d:da12]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:1aaf:b0:2d6:e074:9cad with SMTP id d9443c01a7336-2d707a5ff42mr191145915ad.6.1787779130696; Wed, 26 Aug 2026 14:18:50 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 26 Aug 2026 14:18:43 -0700 In-Reply-To: <20260826211844.884951-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826211844.884951-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.887.g758fc8c411-goog Message-ID: <20260826211844.884951-4-seanjc@google.com> Subject: [PATCH 3/4] KVM: x86/mmu: Bug the VM if KVM calcs a CPU role with EFER.LMA=1 && CR4.PAE=0 From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Bug the VM if KVM attempts to construct a CPU role with the should-be- impossible combination of long mode being active without PAE paging being enabled. KVM's MMU construction assumes that EFER.LMA can be set if and only CR4.PAE is set, and will create a completely invalid MMU if that assumption fails. FNAME(walk_addr_generic) already has sanity checks to try and mitigate the fallout, but attempt to catch such bugs earlier, as this is (at least) the second time KVM has had bugs that escaped into FNAME(walk_addr_generic), and it's entirely possible the bad state could cause problems elsewhere. Cc: stable@vger.kernel.org Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/mmu.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 064ecc33b926..81c30e2c74f3 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -5910,6 +5910,9 @@ static union kvm_cpu_role kvm_calc_cpu_role(struct kv= m_vcpu *vcpu, return role; } =20 + if (KVM_BUG_ON(____is_efer_lma(regs) && !____is_cr4_pae(regs), vcpu->kvm)) + *(u64 *)®s->efer &=3D ~EFER_LMA; + role.base.efer_nx =3D ____is_efer_nx(regs); role.base.cr0_wp =3D ____is_cr0_wp(regs); role.base.cr4_smep =3D ____is_cr4_smep(regs); --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:08:39 2026 Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C9F52483BC5 for ; Wed, 26 Aug 2026 21:18:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779136; cv=none; b=pIy9tdepcbjvP3IlnweKrH4nFb79KFqDRdh4LOcE4FiAifaDnlmbUDpvjfBQc7sjdTOOOq0cN4DBm6RKwka5oHbhEKGpazrMaz6e+bXP5I2xvitbMxTXGTHtrVJu2Z2gVUgulUegv5QaJi049nPK4Urt91EUig7gnNQ82+HDub4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787779136; c=relaxed/simple; bh=tFWrmimjbmFsTO6Cj56QVEBL9NL5uWQhjAmGwuhHZ24=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=h0nmWiM9D5AbFe9euRz/EQbDQ1QUOpJF+R2I2VxvIOn3WwKQw0RSp2EiFxbJySHmJfsXWMo8NwewrXy7Q+Mgo0EFPA4h0UOos2sZTPLSdMv88LDae+j+TUMJTTHOwPm79keHyAv7J4F8DPU3XFwnhig7lsRaEPTkBTbrLRvAqhs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=PP/t7p+n; arc=none smtp.client-ip=209.85.215.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="PP/t7p+n" Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cb835525b10so1732365a12.2 for ; Wed, 26 Aug 2026 14:18:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787779132; x=1788383932; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=qnzWXMToAhHNxcx5OICbp797PZiUEkyVlvzbtVLX0aI=; b=PP/t7p+nWZbq7iJjpLgPZAtOz/sgR1ceE6jxIjwLyiuYmKFkm3KJuZdZuoBlBo6Cg3 Y4kET3OZwNGNhKr73Ilo9x4qWXpo6P32G0CCzozFPSjGY/dJdMszwaA24C1o2EEiImBK Pk7av/jgizBXywwVTdnerR9K7ynC43SnJBKxiskQLz2VZ03mpeWArhJTA1ZD2Vp4IHhQ Fn3jfRp5owX1JMc7lDHGjC4/RK+lcNDTMvVYX838Z1hvvpEdx1Qk2SlKZltDYUUA/sTx pxSoPDgh8eG38XXhhPsb9vqAyFmLTLgFfB4/9gC2FW53bCsC0flqhofA/lB+LFIRp9Z8 poMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787779132; x=1788383932; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=qnzWXMToAhHNxcx5OICbp797PZiUEkyVlvzbtVLX0aI=; b=Ffdnw1I1bcr9ZTwlukNxUUUAgS3Et6nLZbt7ZaZvMvQ4foWrXmlFoTW4OzryNtOe8n gWhmT2mdr/Q0Hhinkxfe2DgbaBdElT1wt4tymNbSLVVPPNiPVJT+QYMhMNJHkCmzC9PV mPyuzm1CEXeqCgeJ/F7z/dGjrfIwXav+VeaGyOit85puI1kQjxdTq8u4DCT8Y8NjXljs pyKh/Bxw2k9Xrw7YSZj8LkxEuirk57XzmXk1qH/A9j8S9mt+l9epLc3IlPf8CKSf6DuV UY22LEJwLFeThrRrXUXJ0FebAEyHkE5W16k4Qiag1aa0WNMLWw7j8A5Or4hqEUepRViJ VmtQ== X-Forwarded-Encrypted: i=1; AHgh+RrHd6MStoYbgFlio9uAJ1Zj7JN7L/ixtCF+zEls6HCJDpSz4FC0qVYYS/e4nnonMLz3on+JFcVJX0v0AAE=@vger.kernel.org X-Gm-Message-State: AFuF++n8ZUhOHim4aZ/7wo32PY+UVDIEONN1GpdZdANMx28ndIw817Tq RYgD3MA7pq2J7rdDYi8QRB+5N8Tw1fg947KgmLBXR4Zqo5vpwdCTkptHl4YbQdQ0dmKOrtlYW2F vRrKWdg== X-Received: from pgbfl16.prod.google.com ([2002:a05:6a02:50d0:b0:cc1:c07e:b53c]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:998e:b0:3bf:49c8:f7b with SMTP id adf61e73a8af0-3cf8465a25bmr15916030637.13.1787779131760; Wed, 26 Aug 2026 14:18:51 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 26 Aug 2026 14:18:44 -0700 In-Reply-To: <20260826211844.884951-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826211844.884951-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.887.g758fc8c411-goog Message-ID: <20260826211844.884951-5-seanjc@google.com> Subject: [PATCH 4/4] KVM: x86/mmu: Convert MMU walker's bounds check from BUG_ON() to KVM_BUG_ON() From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Bug the VM, not the host, if KVM's sanity check that walking guest PTEs doesn't underflow the walker's level fires. Bugging the host while holding mmu_lock is all but guaranteed to panic the host, KVM hasn't _yet_ consumed the out-of-bounds level (i.e. hasn't corrupted memory), and KVM is already committed to bugging the VM and synthesizing a guest page fault if a fatal MMU error occurs while walking guest PTEs. I.e. there's no reason to keep the BUG_ON() at this point. Signed-off-by: Sean Christopherson Reviewed-by: Yosry Ahmed --- arch/x86/kvm/mmu/paging_tmpl.h | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h index 46a0f7796e55..2cf5e733aba4 100644 --- a/arch/x86/kvm/mmu/paging_tmpl.h +++ b/arch/x86/kvm/mmu/paging_tmpl.h @@ -392,7 +392,9 @@ static int FNAME(walk_addr_generic)(struct guest_walker= *walker, offset =3D index * sizeof(pt_element_t); pte_gpa =3D gfn_to_gpa(table_gfn) + offset; =20 - BUG_ON(walker->level < 1); + if (KVM_BUG_ON(walker->level < 1, vcpu->kvm)) + goto error; + walker->table_gfn[walker->level - 1] =3D table_gfn; walker->pte_gpa[walker->level - 1] =3D pte_gpa; =20 --=20 2.55.0.887.g758fc8c411-goog