From nobody Sat Sep 26 09:16:55 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D3B824570C6 for ; Wed, 2 Sep 2026 23:20:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391233; cv=none; b=d4NnnC4ByXVFRDjqQNeGFvbBpVELFQK/daWjNvx8l5tALNPRyvc3mh6xnZ3L5z+IvIIATMZYiO1hP7O3Rhh821tSrhoToX+3cOwsJUnjM2oLncmCk6dyHSeDreluMk9PcjOaH6af3aX77tLojGfcoDBJDElKHts3kXxZ+EV5eas= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391233; c=relaxed/simple; bh=rO1VhpjY+sD0s6cY1RGW2FsZ7eLK+0PYMsJ+6bCCG6Q=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=t50k8DrYSQOpOiLRBL/QnOQ1ZXbDICubzdakATRfh565MCsO3VfEc+PebpBcwa3V8D9Hfd2u8OOO7CrI7oL/h9LB8BTQ6fYGcI6foXjxH8eENlHyad+rwu5bqm+i27xH1ynC7lz4sHHbi1tRAcV6jBr2Qv6cKdvK72U5vMFvZ3o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=lFBUfnWD; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="lFBUfnWD" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-84e024d2129so2714422b3a.2 for ; Wed, 02 Sep 2026 16:20:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788391231; x=1788996031; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=CXxJWNy5cOYGfFxugmTGZyVHmkAbs3asDYkKP0d8VCs=; b=lFBUfnWDw+jYkq8wz+LBGbW19unRcjA/lxUWlnZ9GLi8U4+oQYuq/Ukb0oPz4gVQSK ORrX4dj/zOvLHwRUblNtAg38qCCMEs47xlb6CnrrgtTeRFfXLUu2AY4xmzd5Bd8Jb2sr ugTwPEFZe5n5N1jMj8LAgdygYB04ldqIZ8Ll48moSgOJdywExyfrl/5h8qdiv1kAta9l OxNrLo+pYFN7CN0gK/Km1b/8vEOgDXgaoP9WMbIam162nyR2UtLwPI0QY/WnEnbOBbRV Z7Qy6szzfK+xh4K92hohZMejvyBz1ZFySTkx4ORvUkVhRKxLV+JyKUFkFvAd8Yiu7tRV D87Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788391231; x=1788996031; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=CXxJWNy5cOYGfFxugmTGZyVHmkAbs3asDYkKP0d8VCs=; b=Zf43aE5hkbXy/15zORQcQVFfUEmkwOQGx/XddIRSAiuunhKklvC3odMDIDKI3wI0wI k7kqQz3PtvF2viKimAtfWFMvyutpi2EB5Kh08AqtFZSE2p96UtJ+asw1KoaT4MfJeQp1 P7CDqf3OvQAA1gr5dY4xQcSZiUevX5pYACU+Nc18SMVY55nWQYA9toHD7jpu0b/3WCpr CBeZynINDww+D1ag/wwQiuEcbJvIBVt4+mr4QYjFFI9T3MSYMpeXUGDoewlaPamdi9fs xUOhG23jG5IQnkPb9RRRqGEITZK3DD4V32fwaUgG6SGKEUORYnX26EbdHYZqRCOUbZgm PMpw== X-Forwarded-Encrypted: i=1; AKwUvBzbNHGnjs11X5AAlF4g27F5zlfnbJh05C8fcFEOXEjoUAM8qSi2Q10LuQeyU+Q7aAm9+unu07f75aWzj/4=@vger.kernel.org X-Gm-Message-State: AFuF++nujvy4Jn9u4fi9q2iN71audlMy0JcK7hmg3RpnCEs3uQtZFvOA 9MGL24epdkV18+p1/uKICWNTiDgXceh8atGNvjZiWyoTbtHI7T6wGrzyl5HQbujI8K7ouzEOtaQ RUJY6Lw== X-Received: from pfblc11.prod.google.com ([2002:a05:6a00:4f4b:b0:84e:2062:2edb]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:148e:b0:847:893f:2d0c with SMTP id d2e1a72fcca58-85ed1d0414dmr11974433b3a.5.1788391230832; Wed, 02 Sep 2026 16:20:30 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 16:20:24 -0700 In-Reply-To: <20260902232028.2767071-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260902232028.2767071-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902232028.2767071-2-seanjc@google.com> Subject: [PATCH v2 1/5] KVM: nSVM: Reject KVM_SET_NESTED_STATE if L1 has EFER.LMA=1 && EFER.LME=0 From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Reject KVM_SET_NESTED_STATE if the incoming L1 host state has what is effectively an impossible EFER combination of LMA=3D1 but LME=3D0, i.e. if = the state says long mode is active but not enabled. Unlike VMX, SVM doesn't have an explicit consistent check for the illegal combination; presumably hardware simply ignores EFER.LMA if EFER.LME=3D0. Unfortunately, KVM doesn't ignore EFER.LMA in this case and consumes the illegal state when constructing the shadow MMU for L2. E.g. if userspace also clears CR4.PAE, then kvm_calc_cpu_role() will compute a role with 4 or 5 levels of paging, but shadow_mmu_init_context() will wire up the MMU to use the paging32 template, which maxes out its levels at 2. Note, the "real badness" is effectively the same as what happened with the nVMX bug fixed by commit 112e66017bff ("KVM: nVMX: add missing consistency checks for CR0 and CR4"). Unfortunately, the sanity check added by commit 72e2fb24a0b0 ("KVM: x86/mmu: Bug the VM if a vCPU ends up in long mode without PAE enabled") doesn't work for this case, since L2 state is active at the time of the page fault, but it's L1 that has the bad state. Fixes: cc440cdad5b7 ("KVM: nSVM: implement KVM_GET_NESTED_STATE and KVM_SET= _NESTED_STATE") Cc: stable@vger.kernel.org Cc: Yosry Ahmed Reported-by: Stefan Teodorescu Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/nested.c | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c index 73f37b050d0a..49fb10ad1f9f 100644 --- a/arch/x86/kvm/svm/nested.c +++ b/arch/x86/kvm/svm/nested.c @@ -2028,6 +2028,7 @@ static int svm_set_nested_state(struct kvm_vcpu *vcpu, if (!(save->cr0 & X86_CR0_PG) || !(save->cr0 & X86_CR0_PE) || (save->rflags & X86_EFLAGS_VM) || + ((save->efer & EFER_LMA) && !(save->efer & EFER_LME)) || !nested_vmcb_check_save(vcpu, &save_cached, false)) goto out_free; =20 --=20 2.55.0.970.g62bdec98f9-goog From nobody Sat Sep 26 09:16:55 2026 Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1340845A2B8 for ; Wed, 2 Sep 2026 23:20:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391235; cv=none; b=G6XHDpmXNAa1OsbOtImRpjSqY4PdbC7fy9QogsAScJJVFJbIj4tqWNIGaISv2/ssPfdBFHfE5fmDlGzo3eoKeNFqES4sFEioNLRmM5s2sANKwcHe66RtsjOCZdKhOFqYwTvLkursT5KPDBAqMn16BbFqPrL1lp7Z0f5YeLQqkPM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391235; c=relaxed/simple; bh=LSeczqcNX4oLR8BivFZ4NLYEJWVMgvGLhQtLV1bS2JU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RjB6jDA8NQrJrg37BxaWhDuI09YU7PbBDTIaIT9JyfINui77Tv5vvjpGsPF4soLs96xIPc8ef4mblmPUWxhHdZGh7UKrf2q8Q9+DfiPNldcgICyy2G2Ga6zvvIFjuw19TeyyaN207GydCMvFrrNX9+EQ2tqOQ+EefP6yGR0GVNI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=OGg7ecs/; arc=none smtp.client-ip=209.85.214.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="OGg7ecs/" Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2d6f75c1219so33061695ad.3 for ; Wed, 02 Sep 2026 16:20:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788391232; x=1788996032; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=OiiE2/S2XBAKWq1rmxArOvIbLAdbtFy6rIi0vLxRxWw=; b=OGg7ecs/11orytrUuzoc6pMG1/CzYuZylW58JUCXzbO8u+kRSutUgypJnEdSsreiDO pan85lMZZmHTGP9Wqwr2E08tSxJNjIrc9+yTQQyDEXQz1MzMsBpGyH2wbRRENzbRtZdg dTcNA9mpDGR3+JXE40BquJgwR1DamhIaRGBGTJ73B0nf9lWzzi56ixY6rlVAjPieBykM syG0GAC9rPIijy36+eQcF//z4+HkGo4n+qDSXTan/VYNEHxBaqdiLFHO9I0lL0Zs4Zlz /l9c0d5fkj89unqCPnbjZtQr0Te556ZT01D8uJ2ZNCmkOACuCkiWT72M2xVQhv6rQxP8 P7Lg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788391232; x=1788996032; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=OiiE2/S2XBAKWq1rmxArOvIbLAdbtFy6rIi0vLxRxWw=; b=Ws37WJ0E3/D6ZRwpsJyX2WdiI8H2rvzTqM/vYagay8ZLVzC8WcRTHaqT8PoauvvSM6 wjg8bbTSQ2A/MkOg4eEa3T62YUOrIyWmGSs8E/aho/ArGW6VeTjS6UD0Zb6nWP7Ka/8f C1fU91Olwp28iLBTnZUzTOfI9s8xQ5fcM0b6KRnA8B57qXmg4AB6PHHs5V7KmYsQQQeX xCO3XSHH2qKSc1Q4Gr1/FTvwyllqCAxf6yl4i2TMyq/1t+RXknhNjUpzK1G/gW8cbiVQ iwnwHoW9wp0NIPchPjjpLL2CL5C8bW57iLB0euYzFlsiq4LuGie4DWwdW4xOHOjSynDS JeTg== X-Forwarded-Encrypted: i=1; AKwUvBx3KmvoaEDwdoJIONT0L4owBnCijoMW//QM4FKZML4NUDqLgxgoXW5eB9Z1eiEb+qZOQYo/ZKbVl1PrYwI=@vger.kernel.org X-Gm-Message-State: AFuF++nacKRnyHHxj96Hcn/8VhtofVPZ/MeaDJ4K37b8PyGDf+vc2A+N CHELW0sCZoxToaJscEOwLPOX4Mia6m+u0GYUbn18inbBo8PfcwRz+Uhk/QVgefMShkj+2Ckbe+W 6wZ9KnQ== X-Received: from plblb11.prod.google.com ([2002:a17:902:fa4b:b0:2d5:3395:63b9]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:ebc4:b0:2d9:3365:7f48 with SMTP id d9443c01a7336-2daec703f04mr123545765ad.14.1788391232071; Wed, 02 Sep 2026 16:20:32 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 16:20:25 -0700 In-Reply-To: <20260902232028.2767071-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260902232028.2767071-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902232028.2767071-3-seanjc@google.com> Subject: [PATCH v2 2/5] KVM: nSVM: Ignore EFER.LMA if EFER.LME=0 when preparing L2 state From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Force EFER.LMA=3D0 if EFER.LME=3D0 when preparing L2 state for VMRUN, i.e. mimic real hardware's behavior of ignoring EFER.LMA if EFER.LME=3D0. VMRUN unfortunately allows the nonsensical combination, i.e. doesn't fail, but KVM itself has an invariant EFER.LMA can be set et if and only if EFER.LME is set. Breaking that invariant can lead to a variety of issue, particularly in MMU code that keys off EFER.LMA when determining whether to emulate/virtualization 4/5-level paging versus PAE paging. Cc: stable@vger.kernel.org Cc: Yosry Ahmed Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/nested.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c index 49fb10ad1f9f..23d29597d6bf 100644 --- a/arch/x86/kvm/svm/nested.c +++ b/arch/x86/kvm/svm/nested.c @@ -789,6 +789,10 @@ static void nested_vmcb02_prepare_save(struct vcpu_svm= *svm) =20 kvm_set_rflags(vcpu, save->rflags | X86_EFLAGS_FIXED); =20 + /* SVM ignores EFER.LMA if EFER.LME=3D0 (instead of failing VMRUN). */ + if (!(svm->nested.save.efer & EFER_LME)) + svm->nested.save.efer &=3D ~EFER_LMA; + svm_set_efer(vcpu, svm->nested.save.efer); =20 svm_set_cr0(vcpu, svm->nested.save.cr0); --=20 2.55.0.970.g62bdec98f9-goog From nobody Sat Sep 26 09:16:55 2026 Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 32BF445D1B9 for ; Wed, 2 Sep 2026 23:20:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391235; cv=none; b=ahia+FiOtHilgVQ3X1lOkpqoNBZXg+cfBmyp+J2coiajwtE3ny84w808RBloM0ONXa0Dq2teNUkhoS0/pdO61txqPw66XuqMoVds1IjFquFdXE3zk4TVdoCLFtWhIciMxRw4O2ywuLgGs/3qkcJ2QqdvC4oKuPdxvWCkVAE7450= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391235; c=relaxed/simple; bh=Cjjfciu6Yrbk8TQm+bLXiRt8OKbDv1+8Ce4prQ3HDfo=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=C6mq2eTyOPNPggiQ4fbO4lG3g9mH5j0vTLe9rUngguUYDwqbzeMQJTc34m3zUdh0KZ4YlU8fPphGB6jJ2x8DZSdOOEW6DUec4LmDt+WaPgXx4XWAauO6Ga8XsC/XPOLcpSDBwMLpSvcUwJ2c+mhTxIqGP92jTNX/Jr/f7h1Ap+o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=GIFxvuJk; arc=none smtp.client-ip=209.85.215.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="GIFxvuJk" Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cbedb8673ceso1494820a12.0 for ; Wed, 02 Sep 2026 16:20:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788391233; x=1788996033; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=mkiR9odrgpXoU7TeaqfCDaUE1/ZRycIEI7gHGOfzeQs=; b=GIFxvuJkX3qdMvCnIdXz5V/Hle39T7Cmpkf0uHV3OT7VdbTlqlv35jzog+k/tNzFzY vykEwfTVuA/9Et/t4Tm6nYdSHa0ydSmAbAhDeEatfHnpQZVhomEzzY0B/8tKtBeCp2KT VvVP2HJGkdmIkLfAMctZMU9clQG/Rb8VklBx1vVQlYLYdji3vY220yA5HKHIh2sQaIqb ZSCLCE3sH4BFM+rMAqtDrFwZPxjS9FG0Fu4y9Gxc5rmFseF4twsq5ME4+knnMAtbgfVh EdDfOWWZv2DfFWoxGES48+4G6TU7s/mD/K0Z79TvC6c0/oim5Kq9rnRoMHxiU6w3ZNDc FVUA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788391233; x=1788996033; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=mkiR9odrgpXoU7TeaqfCDaUE1/ZRycIEI7gHGOfzeQs=; b=PJ7aJR5KNEO55a7CjcBbIAeVorAtZUXdm/YCyUormuMNUq7/QLAXGTnfOD7arkp56n X3By+ftENkzhd071qFSYBnjKoB/xbfvGWsUYPFegZ2FIZGW6U1nYOHEDS8tJbttqYKlX Vr/B98nmuAMFN4WMgvhLep48/7SyRHOHonC156xH8gEVliGAUYYQ0CE2Lg6n5fzzKQY6 XPKDTIqmQiG4C90nt/DYiiPpD3I/gQZuDcufzax3pd57j8S1ZkGu0fzS4+8uWTmSosax 8QpqF9iCWvHoKoENf8CbQB3O1mOYbkaSzqD4HJW7R2n2TGIjEpsnb165Igl/XcQAtzZR 2vGA== X-Forwarded-Encrypted: i=1; AKwUvBxjW+vtjUe8JlUJLZSstr6mRLD7UxTKMoRfcKryHInBdBUYNIHXUKiG1CZ2l+INFh9UAIH64ZuO0mq5f7o=@vger.kernel.org X-Gm-Message-State: AFuF++nh8gUnuVGCuUv5Hr81PBISA9oyk2dmexPNUIH0FVGFG3n9tFBc WV5RQXGep/kytgmswezYzhFtHBh0aWF9Olww3DwGSWvFVZiFpErskcfBAiQiXuGAB95haKKIOsp hXBpfrA== X-Received: from pfff13.prod.google.com ([2002:a05:6a00:bd0d:b0:848:8b93:1295]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:806:b0:845:c694:5c3d with SMTP id d2e1a72fcca58-85ed20eeab2mr10809152b3a.1.1788391233139; Wed, 02 Sep 2026 16:20:33 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 16:20:26 -0700 In-Reply-To: <20260902232028.2767071-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260902232028.2767071-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902232028.2767071-4-seanjc@google.com> Subject: [PATCH v2 3/5] KVM: x86/mmu: Bug the VM if KVM attempts to walk more levels than the MMU has From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Extend the "EFER.LMA && !CR4.PAE" check, which exists largely to guard against KVM configuring a paging32 MMU with more than 2 levels of paging, with a very explicit check for exactly that: that KVM isn't trying to walk more levels of paging than the MMU template provides. I.e. harden KVM against all bugs that would cause KVM to generates accesses beyond the bounds of guest_walker's arrays, regardless of how KVM ended up with the misconfigured MMU. Note, don't use w->cpu_role.base.level directly as the paging64 template only provides two levels of page tables for PAE paging on 32-bit hosts, and handles the third level by manually emulating the PDPTR access. Cc: stable@vger.kernel.org Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/paging_tmpl.h | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h index 27427e7f22fa..f925b11d76dd 100644 --- a/arch/x86/kvm/mmu/paging_tmpl.h +++ b/arch/x86/kvm/mmu/paging_tmpl.h @@ -368,13 +368,14 @@ static int FNAME(walk_addr_generic)(struct guest_walk= er *walker, pte_access =3D ~0; =20 /* - * Queue a page fault for injection if this assertion fails, as callers - * assume that walker.fault contains sane info on a walk failure. I.e. - * avoid making the situation worse by inducing even worse badness - * between when the assertion fails and when KVM kicks the vCPU out to - * userspace (because the VM is bugged). + * Queue a page fault for injection if any of the below assertions fail, + * as callers assume that walker.fault contains sane info on a walk + * failure. I.e. avoid making the situation worse by inducing even + * worse badness between when the assertion fails and when KVM kicks + * the vCPU out to userspace (because the VM is bugged). */ - if (KVM_BUG_ON(is_long_mode(vcpu) && !is_pae(vcpu), vcpu->kvm)) + if (KVM_BUG_ON(is_long_mode(vcpu) && !is_pae(vcpu), vcpu->kvm) || + KVM_BUG_ON(walker->max_level > PT_MAX_FULL_LEVELS, vcpu->kvm)) goto error; =20 ++walker->level; --=20 2.55.0.970.g62bdec98f9-goog From nobody Sat Sep 26 09:16:55 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F49945A2AA for ; Wed, 2 Sep 2026 23:20:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391237; cv=none; b=uOvz/7txwuazk4VM5zHGegAcp1g8w5w0dHIbaRCZQVQFzk6EIrZzCUf+nin074oilqkfirCG1AcpUCCLf+eMF2xtZJkQYsYh2wEtYD7e4gYlYFRZxHsTIu8VE9+qVv6Haxu4/Ce+2zJi6p2yqrTdjY/H/mqugAMMgLK0ju/vkTE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391237; c=relaxed/simple; bh=Yn7iZwfRL+iBGbAsuRhs7RQpTQvIvY4V0qX2H0NjNCk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=e39l0PRXa98yV1o9ujjAuJ/yeWXcGCjicG2K0zNJrttPZR6UJycjgaD8eDBquy4+NlvOb7KFRySxh++8/ZhDqm/bhDoni47FI2pvNR88/A0muOLOUIkFODBqkxKBc9w7G4yBGeACr5F9TTPWPxW1rByGdcaLDyw1bubNX1O0HSY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=U3k+AhfZ; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="U3k+AhfZ" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d55d8cd938so28698265ad.1 for ; Wed, 02 Sep 2026 16:20:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788391234; x=1788996034; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=o8QpYFg7hPmqiVoT4t2j3x9pF7hOUnJyzFfssLlOpVU=; b=U3k+AhfZ9OUsxBw0/VmiToPIoCWwwkyNZgX7/4NISk0OpCjfYLXby7cZcd5txFyuue OhZTiLPTnS6zaJX0AER4BLzOS5/c2qBKIYULjb5Vtozs0ncBJUJwwvsRfKObSPxewpKN kgQF+5IfqPx5/Dh6M0nNw51qcCPUgVcPiTLzg3Tc3dXfiqCNoUEvxatz26faO890Y8zO SJdB9QHY3+NNTqHTHEvuOJ5Uvuh8B5GQiqbiNlJDz5LZ0Oyft172CDerHTDDTaXdIWOB UA8cXVOP9lUNqlST9YodGteV+9XfHoquRX/MCCD4FNZhGNeagglRqB99XjFHvN5Vf3Zw tD8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788391234; x=1788996034; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=o8QpYFg7hPmqiVoT4t2j3x9pF7hOUnJyzFfssLlOpVU=; b=f4mqdJ8RWC+m/MAB8cvCnuxiRC98TKiew70c5uDghHS3TLHd12taUopTeWSEKdqjBN nqbng7jtjkheEb6FP/DajH2L9g4JxxpIicqEaVBsTu8Kj1nCpLffHxiMjv7MB8vKBE55 LrxDlbEwXsb3W61NFqpwWXQ8kYq1ukbsmOHs7u0yvvyBPhXlSMLQyKxDNJ1F/dJ25qin XIel0DSTFxAi1JB8Q7HrT0yXs36nlJqqXPhsDSBYY4D2T7O2am8ZcaF5Mxpe+7hjE7pr J1DlwHNICqKk+x+fLrnSf320GYaavkYf3Njw6hCGQAu2WTnHE0439RbX7uUxKljapY3m wHzA== X-Forwarded-Encrypted: i=1; AKwUvBxj8i/O866B+JtN1f4GV9GuNo+FKSJbsexQDYRsnuqcGFEPzWo2m9rMRZRgo2kGegjEZlu5bl3OSW2NwGc=@vger.kernel.org X-Gm-Message-State: AFuF++mgpnf5HQSWAaHACccSwNyPG/fJqAfMby7Kph0u3hePO/FKwCQx kd3kmkLAn3KTgvOtnXI5Ti03ztFLsYpitq8ZXHySxdORnX+xmRyWFVpd9txkPCU5TEbXm4l7n1u 2Rum7tA== X-Received: from plje8.prod.google.com ([2002:a17:902:ed88:b0:2d9:a2:2c28]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:e804:b0:2d1:134:b86e with SMTP id d9443c01a7336-2daec5ad579mr105653085ad.2.1788391234310; Wed, 02 Sep 2026 16:20:34 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 16:20:27 -0700 In-Reply-To: <20260902232028.2767071-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260902232028.2767071-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902232028.2767071-5-seanjc@google.com> Subject: [PATCH v2 4/5] KVM: x86/mmu: Bug the VM if KVM calcs a CPU role with EFER.LMA=1 && CR4.PAE=0 From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Bug the VM if KVM attempts to construct a CPU role with the should-be- impossible combination of long mode being active without PAE paging being enabled. KVM's MMU construction assumes that EFER.LMA can be set if and only CR4.PAE is set, and will create a completely invalid MMU if that assumption fails. FNAME(walk_addr_generic) already has sanity checks to try and mitigate the fallout, but attempt to catch such bugs earlier, as this is (at least) the second time KVM has had bugs that escaped into FNAME(walk_addr_generic), and it's entirely possible the bad state could cause problems elsewhere. Cc: stable@vger.kernel.org Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/mmu.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 064ecc33b926..81c30e2c74f3 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -5910,6 +5910,9 @@ static union kvm_cpu_role kvm_calc_cpu_role(struct kv= m_vcpu *vcpu, return role; } =20 + if (KVM_BUG_ON(____is_efer_lma(regs) && !____is_cr4_pae(regs), vcpu->kvm)) + *(u64 *)®s->efer &=3D ~EFER_LMA; + role.base.efer_nx =3D ____is_efer_nx(regs); role.base.cr0_wp =3D ____is_cr0_wp(regs); role.base.cr4_smep =3D ____is_cr4_smep(regs); --=20 2.55.0.970.g62bdec98f9-goog From nobody Sat Sep 26 09:16:55 2026 Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 48612468C0C for ; Wed, 2 Sep 2026 23:20:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391237; cv=none; b=UpGtMhmkrRTbUD9l40PXWkMv/xbbqt559Ltpc1+4Tn7FakhsP6HAZsdDJW/BWItVJzmGGT5Q73ClHnRBtKPVL+9Zp2HCnAT016uuAFGWpVq7pN32j/5NuZxr8n3leWmz/DLbUJQiw4LL2Z96XK/S2pVmy0KnGwFWRntS1RzUfwo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788391237; c=relaxed/simple; bh=FSGBRuEwSzDJ3Vm1ryh1BmDfkHN4mR10cVRnM1E5HAA=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=t2V/VrkPsSEWYq2BqLKj3lZnuSGlsPUbqBK+wDwE/2WCO6KgIcTBlQEw0G+/A7NiYnF0S1CQGVgrPAdjN6pEqMJR7W1KVzkaM7rwG/9V7a+VJMgDGM4kgBSW+RLDQ/fLNB9byd2DxozLjIt7uPE4Yj2t4/3AUAiJ7rnKP3Cffgo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=hyJwR4ig; arc=none smtp.client-ip=209.85.216.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="hyJwR4ig" Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-38f283baf1fso2339104a91.3 for ; Wed, 02 Sep 2026 16:20:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1788391236; x=1788996036; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=0Np7Ag6FWXRYQphBkLQrwzv96GttQT1QLppJ7Rhn8bg=; b=hyJwR4igCP4n6dYUEf3Ar4mb7hdQinNbHG1dZIMfaUmuJ+F5RN514QTV1jQn6Xw97L L4FYkLDqMVXYcIGe4zBqeIY3m5O9F4EfuKe5bNeHBRLlSYfFAqNsITScToPjIyM7+NgV Cu3vSr0E2BsM3FeM3WEFVRFrJT0hmlSYOKSGd+2Z5xS5pXeQNCuIOh9Nu0hHNmcuhXg7 zArJfclzAXVltR8x7O23+EEkmhhhmYgVwMcQ7HUCaKp20154PWS+LOh72STp42qhAIjU ODNuD+3YT7Sn0t4sJc9UKVB+B/DpXDfMc4CFihHI7YugtU/ayaJadV1XldCqsf3/ZYJi GPzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1788391236; x=1788996036; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=0Np7Ag6FWXRYQphBkLQrwzv96GttQT1QLppJ7Rhn8bg=; b=OrvrqWmUs8ViA9UJyKpOgJgmp8oG/Ax2WhRl4EcKDX+z4mLPdhteid9JUighyv75zr vHdB6sPyff/0QokdyQ1Wdmu4gGek8ccQW6nl0ZpWdPgqtgY4dEv+3ikQ7QYHOq7nfDXO wI/Ege1446UC9PLda0a7UjFfiG3ZPaJX7I/AAGBul1F86yqWT5OgYIYBvUCj/mNWooJy mu2DGv0Bg/+NBR3szSbD9+vKnZ/D4+kTMAMBk/wiZDe5q4dMrwv/cyAkEJmbDUGK6HJN 8P3PtU+Z5RICtuuWsPwRMF+2RaZqogb8mfeysQATNc0RHKJeVRIX5tJue3DNzHejovLd pULg== X-Forwarded-Encrypted: i=1; AKwUvBwF0I/k1/TncnM26/GUh7wKCz0QrIT5Xt9NFL6A9EARyexlYiQcLjtyIjbchn1CYnorQViFL52zrB3sGPI=@vger.kernel.org X-Gm-Message-State: AFuF++nAlIda9wXyXV+L8cxIqs69dYoUhhjfudCbw8nSkF8fzoQg1JEC kQyi+CP67gcEbqEWbo+hkoemgHYcgivldbsYtKAd+c4H9GYEi9gQLdrfKXVUUoykEyXYI7MYuUo H7HMqug== X-Received: from pjbli10.prod.google.com ([2002:a17:90b:48ca:b0:398:b684:5c15]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:1a8a:b0:398:9be9:ab8c with SMTP id 98e67ed59e1d1-39aee0e7272mr10212107a91.17.1788391235459; Wed, 02 Sep 2026 16:20:35 -0700 (PDT) Reply-To: Sean Christopherson Date: Wed, 2 Sep 2026 16:20:28 -0700 In-Reply-To: <20260902232028.2767071-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260902232028.2767071-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.970.g62bdec98f9-goog Message-ID: <20260902232028.2767071-6-seanjc@google.com> Subject: [PATCH v2 5/5] KVM: x86/mmu: Convert MMU walker's bounds check from BUG_ON() to KVM_BUG_ON() From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Bug the VM, not the host, if KVM's sanity check that walking guest PTEs doesn't underflow the walker's level fires. Bugging the host while holding mmu_lock is all but guaranteed to panic the host, KVM hasn't _yet_ consumed the out-of-bounds level (i.e. hasn't corrupted memory), and KVM is already committed to bugging the VM and synthesizing a guest page fault if a fatal MMU error occurs while walking guest PTEs. I.e. there's no reason to keep the BUG_ON() at this point. Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/paging_tmpl.h | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmpl.h index f925b11d76dd..c8ec47b09264 100644 --- a/arch/x86/kvm/mmu/paging_tmpl.h +++ b/arch/x86/kvm/mmu/paging_tmpl.h @@ -392,7 +392,9 @@ static int FNAME(walk_addr_generic)(struct guest_walker= *walker, offset =3D index * sizeof(pt_element_t); pte_gpa =3D gfn_to_gpa(table_gfn) + offset; =20 - BUG_ON(walker->level < 1); + if (KVM_BUG_ON(walker->level < 1, vcpu->kvm)) + goto error; + walker->table_gfn[walker->level - 1] =3D table_gfn; walker->pte_gpa[walker->level - 1] =3D pte_gpa; =20 --=20 2.55.0.970.g62bdec98f9-goog