From nobody Fri Sep 25 09:19:53 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1F669493D24 for ; Mon, 14 Sep 2026 18:12:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409552; cv=none; b=soYNkfvoXSQgIvKY4mC/4QxnZFcTAVXfEG+c1lIieGCfLO99xYZBdouOgLLH2lEr5bK6OUKtpvs3y1q5FZljpZPZFnT8ZBOzPgTctPMMPeakWQfRPS//s7gWBTDbcJOgGNTihyjetD0je8LgG0nyLOohFo+3DxtQEyvDD7AuY/M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409552; c=relaxed/simple; bh=H4sD9NLhYyNcdEysJoW8KxDlT7mpxdzkkXtdPUFPlqM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=hFLkbksnXhE/edpgqX1FBCNhs7ImjyPJzaSJ3mE782QggS8YF57IWNdmubudmnW/Avkv6M6U5rYeDAfNnIf2UJ4L2gDe772OdUEy+4kSIOEdBKD7EPYr6ek04HEAKfFqfGCMIRyZ5CQdLq0dV85EXOIEYtQpSaMk4/zvAIPQXY0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=fcmS4yQk; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="fcmS4yQk" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cc4e0dd08f4so2420010a12.0 for ; Mon, 14 Sep 2026 11:12:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789409546; x=1790014346; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=rGmw5H8u8SeMzlWekJA+yxf9/caHSlRymD+gvDgsKlA=; b=fcmS4yQknnbr4ayLfd2G0p9/fSw1Lb9tk4COVJz0L7sGngUKHgtM7I07jqpY4pP7sJ DkAbVeNVSJQuEuSKLiE3Z/jDgUcc9A8BYzqvvsr/lNTZsnADDyRMu8u34h/u6INd30LR gM4we7lPn7XpYoVNMfEwvyRLKEXjv7jC+s4s9b7kmvJgtO3FCsFYvJPwoQdX+jZ2BWka psUB4tYT+M8sdJ0lyAnY3eu84ADL++WZJMshV3MQtNgGRC53+v3XvjqYaiQ5IGFgbUo9 ud+ZIhY24HbeEuAJ65Nmz07f55FSPwyRA1RyAPw/fOXJT9tPm6rD2pP5VwW5MpzpjsHs Z+Cw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789409546; x=1790014346; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=rGmw5H8u8SeMzlWekJA+yxf9/caHSlRymD+gvDgsKlA=; b=n3drkDSkVLlJek5NEjLBDQB5gJD+EgwGfDAIeWE4aV42fyQ2U06azb3Xn/oSEB0h4V F8AHxqttyC7MwxvmA6+J8Bvdu1rskoxmzGXuAZ00d5CksogW7KfcpFM/tcZapsY4Vb3h 5BD0KascIVcQHhC0+sH2gbJWhJg/ZHSemh6ki1vYngrjCvXu7sksrCFMSDku7fMnYu7E 26bVzxRBXIs+u+kuronbVfhNg8OeWgD6eakxRDCs8hE78UFCky70/Oa3L4+t5BgZQi7Z aGxD0tL+Q2jYJRAaRl/rnDY+dpF/J7GmkimbgjzL/CX5XEE+7IIQENzd+McW0YMfxcY5 tCIQ== X-Forwarded-Encrypted: i=1; AKwUvBz7jTu2FdwqCwKbWq3RcIU2WFufwWCqD8ciIorwxNUgCVwozVki7+O+an/cV4KcVUfH0C3tQ9tNLuIZNCs=@vger.kernel.org X-Gm-Message-State: AFuF++kz5XnuHEBsV8jFl8KP3lh7io/NQjiTsgA23+vwk45TwWondqfp 3np+pUfNw50KlNkRBTzRNV4jV5bU1ykwI5pQPfvIZ7MscB9Mn7e8CV2Y0CBHii7eFzX4GDmO8pH Xt71YxA== X-Received: from plbkn11.prod.google.com ([2002:a17:903:78b:b0:2dd:54fd:8640]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4b10:b0:39d:e54c:a28a with SMTP id 98e67ed59e1d1-39debf9b35dmr6973791a91.8.1789409545861; Mon, 14 Sep 2026 11:12:25 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 14 Sep 2026 11:12:19 -0700 In-Reply-To: <20260914181223.289061-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260914181223.289061-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260914181223.289061-2-seanjc@google.com> Subject: [PATCH 1/5] KVM: Reject attempts to lock all vCPUs if vCPU creation is in-progress From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Reject locking of all vCPUs if vCPU creation is in-progress, i.e. if the number of "created" vCPUs doesn't match the number of "onlined" vCPUs. It's simply not possible to guarantee that KVM has truly locked all vCPUs if one or more vCPUs are actively being created. Holding kvm->lock does prevent in-flight vCPUs from being fully onlined, but it's infeasible for common KVM to know whether or not that provides sufficient protection. In practice, this is likely a minor bug fix for the ARM and RISC-V usage of kvm_trylock_all_vcpus(), and a glorified nop for everything else. E.g. ARM's kvm_timer_vcpu_init() can race kvm_vm_ioctl_set_counter_offset() with respect to observing KVM_ARCH_FLAG_VM_COUNTER_OFFSET. Opportunistically drop all existing manual checks on vCPU creation being in-progress as all such checks immediately precede or follow locking of all vCPUs. Signed-off-by: Sean Christopherson Tested-by: Jean-Christophe Guillain --- arch/x86/kvm/svm/sev.c | 10 ---------- arch/x86/kvm/vmx/tdx.c | 5 ----- virt/kvm/kvm_main.c | 6 ++++++ 3 files changed, 6 insertions(+), 15 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 5705723f1f41..068f8a236a35 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -1125,9 +1125,6 @@ static int sev_launch_update_vmsa(struct kvm *kvm, st= ruct kvm_sev_cmd *argp) if (!sev_es_guest(kvm)) return -ENOTTY; =20 - if (kvm_is_vcpu_creation_in_progress(kvm)) - return -EBUSY; - ret =3D kvm_lock_all_vcpus(kvm); if (ret) return ret; @@ -2115,10 +2112,6 @@ static int sev_check_source_vcpus(struct kvm *dst, s= truct kvm *src) struct kvm_vcpu *src_vcpu; unsigned long i; =20 - if (kvm_is_vcpu_creation_in_progress(src) || - kvm_is_vcpu_creation_in_progress(dst)) - return -EBUSY; - if (!sev_es_guest(src)) return 0; =20 @@ -2510,9 +2503,6 @@ static int snp_launch_update_vmsa(struct kvm *kvm, st= ruct kvm_sev_cmd *argp) unsigned long i; int ret; =20 - if (kvm_is_vcpu_creation_in_progress(kvm)) - return -EBUSY; - ret =3D kvm_lock_all_vcpus(kvm); if (ret) return ret; diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index b272c20586a7..58c255256e4c 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -2728,11 +2728,6 @@ static tdx_vm_state_guard_t tdx_acquire_vm_state_loc= ks(struct kvm *kvm) =20 mutex_lock(&kvm->lock); =20 - if (kvm->created_vcpus !=3D atomic_read(&kvm->online_vcpus)) { - r =3D -EBUSY; - goto out_err; - } - r =3D kvm_lock_all_vcpus(kvm); if (r) goto out_err; diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 65eb26a0520d..78cc090435be 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -1363,6 +1363,9 @@ int kvm_trylock_all_vcpus(struct kvm *kvm) =20 lockdep_assert_held(&kvm->lock); =20 + if (kvm_is_vcpu_creation_in_progress(kvm)) + return -EBUSY; + kvm_for_each_vcpu(i, vcpu, kvm) if (!mutex_trylock_nest_lock(&vcpu->mutex, &kvm->lock)) goto out_unlock; @@ -1386,6 +1389,9 @@ int kvm_lock_all_vcpus(struct kvm *kvm) =20 lockdep_assert_held(&kvm->lock); =20 + if (kvm_is_vcpu_creation_in_progress(kvm)) + return -EBUSY; + kvm_for_each_vcpu(i, vcpu, kvm) { r =3D mutex_lock_killable_nest_lock(&vcpu->mutex, &kvm->lock); if (r) --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 09:19:53 2026 Received: from mail-pg1-f199.google.com (mail-pg1-f199.google.com [209.85.215.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4146D3749F7 for ; Mon, 14 Sep 2026 18:12:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409552; cv=none; b=UlxfPDOv7v7ScAOqtCliEUx7/o+ye54r1RQtaa9vS2J7mAlM/lCc6tVah/4zjcXh6kwxYyL2WgYoFmcpOFbrbITdBSC53Iy5Uu/3FLpCVE2dtM8BTSqml27HXr3y1q1J3SFbMI77M2AfN9RGgFOva45jSkXCk+dsQvtE/A9oI7w= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409552; c=relaxed/simple; bh=Z7Y8dGSOUAE2MQXoMonDfShLm6KfkAJm+Mr8AwQANRk=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=arALx98DFpVtBwef7b5DgS/Cz8EMDzS9qai2i6AIxxzo0us8bRrf3s+GIRjuuFqVklLLDHwaRfSl4A1vRoTWUkuPcAeCjh2W2HQM8mXK1qllySXhXjLeCBpM+38ezcZ8Mpjak6ir5tqN352tP2/7TXG32ahkTTgSHTFWS1PsmBE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nbUlZ8Lz; arc=none smtp.client-ip=209.85.215.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nbUlZ8Lz" Received: by mail-pg1-f199.google.com with SMTP id 41be03b00d2f7-c89704da8c7so4868016a12.0 for ; Mon, 14 Sep 2026 11:12:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789409547; x=1790014347; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=vZN0JxymvylxGmruHUZ/7Vl0ag7CYvowzU5bHzceTLw=; b=nbUlZ8Lz8npVGmwamv0VeCS7gaKt9nyUXV7kns1JffTbE6JNXTYEwddl/jLOc0otEk nSb93KKzGptFeWZFjl0CsjiTmSRmmfYRu0cma7PA1J9CCxjviHzjKOiAgkU8kSGyVaaW pbMIDpb8snDC7EX30N35PxQBf4Ef4B5omiFkXixVXfpAE+J6vFQaMAF7zuBmn8q0naWy 867nIwgWU2/ziH3EFocYZ91fGAmJyw0qk1zvPnGbh0LLQgkoR98HZz3R7Uw9qidHet+P l9Fbsr2LB7i2hIuaS/pEH039+ZBHPUS5bYaTENwwunps+VyyH+NjkzF4ye4m04SQ4chO eSOA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789409547; x=1790014347; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=vZN0JxymvylxGmruHUZ/7Vl0ag7CYvowzU5bHzceTLw=; b=QtFxs6R3Q/9ovBxVzeK+RVrjogg0YOLTchBk4iAMKgHZr2Hisbw1O2GD8PmX24GmxI Dy8N2AKIzdj7iUboLzE3SP2FsPFl8fjGFGWJ6O8goM12FKOCKAg5tJzBplNeWJt5y6+v e0nLGO7HnubRPmNVeb/HFINSgN45j0B2Xz2Zos4JW8KQwIe2kTm0YvzEWGi7q96bK9fm qHas9dggY+JGk6JRZqqUtS1tfUxzNmKGGLLoowfIc87Ywb1UuTvO3JZrPHBFfJUUvaj6 gYiWVydkYRiHx2+VC7MRyL6CDpTsPxjWX986WlgewxZ6q285ipK8St13W3DF7l9Vk8cW Mp8Q== X-Forwarded-Encrypted: i=1; AKwUvBzOIR+FGQMKa5u/yybYDX9zgxqt/wu7UTb/jA1b9EAwmbli16NmhQX7doKFEivtphkL7Pi0Z2oRTgJHvwM=@vger.kernel.org X-Gm-Message-State: AFuF++k7g4QMl854rfSQWAT+YPZ1XC+vgmwEyHNBOD2RAin/91pSVn5y MAEfFYiljGvXO1a9CMj0FZnOiafxXDYJIF2A1yFxSKYR+DlNiB9I2UoVVP4UYkgd6QlYqocQ+2a R2QRoWg== X-Received: from pfbfe8.prod.google.com ([2002:a05:6a00:2f08:b0:86b:44d9:6a02]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:3022:b0:852:38ff:b4b6 with SMTP id d2e1a72fcca58-86f85207cf0mr6989884b3a.17.1789409547160; Mon, 14 Sep 2026 11:12:27 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 14 Sep 2026 11:12:20 -0700 In-Reply-To: <20260914181223.289061-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260914181223.289061-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260914181223.289061-3-seanjc@google.com> Subject: [PATCH 2/5] KVM: Protect all of kvm_vm_ioctl_create_vcpu() with kvm->lock From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When creating a vCPU, don't drop kvm->lock to when doing the bulk of actual vCPU creation, as allowing multiple vCPUs to be created in parallel adds significant complexity in KVM (as evidenced by the many related bugs), and all known VMMs fully serialize vCPU creation. For many years, "everyone" has assumed that dropping kvm->lock was done for performance reasons optimization, e.g. to allow userspace to create all vCPUs concurrently for latency purposes. But as above, no known VMM does that. Looking at the history of this code, before commit 11ec28047118 ("KVM: Convert vm lock to a mutex"), kvm->lock was a spinlock. I.e. KVM *had* to drop kvm->lock when doing the bulk of vCPU creation, otherwise KVM couldn't do normal memory allocations. When kvm->lock got turned into a mutex for unrelated reasons, no one took advantage updated of the change to simplify vCPU creation. And 19 years later, everyone just assumed that KVM continued to deal with the complexity for performance reasons. Furthermore, naively parallelizing vCPU creation in userspace is likely a net negative due to the overheads of task creation. Unless a VMM carefully avoids the extra overhead related to parallelization, e.g. spawns each vCPU's thread before creating the vCPU, creating vCPUs concurrently is a net *negative* up until about ~64 vCPUs, after which the times are a wash. The absolute speed of light _is_ faster if KVM doesn't hold kvm-lock, but at vCPU counts of ~16 or less, it's probably in the noise when considering total VM creation time, as the added latency is less than 1ms up until 16 or so vCPUs. On top of all that, KVM has had a *lot* of fatal bugs (most often found by syzkaller) related to vCPUs being created while trying to do per-VM operations (basically, see every flow that locks all vCPUs). I.e. the parallel vCPU creation "support" is actively harmful as the only "use case" is for misbehaving userspace to exploit KVM bugs. Serializing vCPU creation will allow reverting commit 97d65b544f48 ("KVM: Check for duplicate vcpu_id as early as possible"), which had "minor" math error: the worst case scenario isn't "256 bytes per VM", it's "256 unsigned longs per VM", i.e. 2048 bytes per VM, which doubles the size of each VM and pushes several architectures into order-1 allocations. Signed-off-by: Sean Christopherson Tested-by: Jean-Christophe Guillain --- virt/kvm/kvm_main.c | 22 +++++----------------- 1 file changed, 5 insertions(+), 17 deletions(-) diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 78cc090435be..c17cc8dd371b 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -4165,6 +4165,8 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, = unsigned long id) struct kvm_vcpu *vcpu; struct page *page; =20 + guard(mutex)(&kvm->lock); + /* * KVM tracks vCPU IDs as 'int', be kind to userspace and reject * too-large values instead of silently truncating. @@ -4177,26 +4179,18 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm= , unsigned long id) if (id >=3D KVM_MAX_VCPU_IDS) return -EINVAL; =20 - mutex_lock(&kvm->lock); - if (kvm->created_vcpus >=3D kvm->max_vcpus) { - mutex_unlock(&kvm->lock); + if (kvm->created_vcpus >=3D kvm->max_vcpus) return -EINVAL; - } =20 - if (test_bit(id, kvm->vcpu_ids)) { - mutex_unlock(&kvm->lock); + if (test_bit(id, kvm->vcpu_ids)) return -EEXIST; - } =20 r =3D kvm_arch_vcpu_precreate(kvm, id); - if (r) { - mutex_unlock(&kvm->lock); + if (r) return r; - } =20 kvm->created_vcpus++; __set_bit(id, kvm->vcpu_ids); - mutex_unlock(&kvm->lock); =20 vcpu =3D kmem_cache_zalloc(kvm_vcpu_cache, GFP_KERNEL_ACCOUNT); if (!vcpu) { @@ -4227,8 +4221,6 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, = unsigned long id) goto arch_vcpu_destroy; } =20 - mutex_lock(&kvm->lock); - if (WARN_ON_ONCE(kvm_get_vcpu_by_id(kvm, id))) { r =3D -EEXIST; goto unlock_vcpu_destroy; @@ -4267,7 +4259,6 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, = unsigned long id) atomic_inc(&kvm->online_vcpus); mutex_unlock(&vcpu->mutex); =20 - mutex_unlock(&kvm->lock); kvm_arch_vcpu_postcreate(vcpu); kvm_create_vcpu_debugfs(vcpu); return r; @@ -4278,7 +4269,6 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, = unsigned long id) xa_erase(&kvm->vcpu_array, vcpu->vcpu_idx); unlock_vcpu_destroy: vcpu->vcpu_idx =3D -1; - mutex_unlock(&kvm->lock); kvm_dirty_ring_free(&vcpu->dirty_ring); arch_vcpu_destroy: kvm_arch_vcpu_destroy(vcpu); @@ -4287,10 +4277,8 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm,= unsigned long id) vcpu_free: kmem_cache_free(kvm_vcpu_cache, vcpu); vcpu_decrement: - mutex_lock(&kvm->lock); kvm->created_vcpus--; __clear_bit(id, kvm->vcpu_ids); - mutex_unlock(&kvm->lock); return r; } =20 --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 09:19:53 2026 Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 74BFA49B200 for ; Mon, 14 Sep 2026 18:12:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409554; cv=none; b=GIcMcmx5kyeoo41oo6774nDag7WN1J8lvitW0ElY+r7K/mLkObG3YXpAa2Extlg8q/93B5iQSHk9OfrXEe6esGmfl+kUnaswpsQFRnZkDHajo+0Tu8A10sNtC1RO/WJavKcvnh7coMOHWSWHQ8pXfRHzV3q5W0R4iqfYps8pt24= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409554; c=relaxed/simple; bh=/IdUyLNiMdGu0jrgGR9Q1GZN+1EphXX7mT7YjuCIqIw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=Kaw1hE1fBmX3dGw5TmwHl+fp+PyAFEJ1Nathdqw2nS/5scLFwrOmgLEaQCF8cEGo9LOFkFSJ5yN4mta+TQ13B9o/VHd5qZQR2gMaFKdA6Mrb4S7eD/FGARx1ETe+Q1pwmYvxAop33xw6NHPy81KVFO6BbdR5j9wCZx1sgpQLYSw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=mOugi3ZT; arc=none smtp.client-ip=209.85.215.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="mOugi3ZT" Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-cc1b6f65dacso3167102a12.1 for ; Mon, 14 Sep 2026 11:12:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789409548; x=1790014348; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZO1urm4Fark0kk4FfGgKDyyN0dzql0DO01I8NkWQ2as=; b=mOugi3ZTM5REKyYD+tE/9Q04x+mflskhf479f69cTl7Yr6Nyv+PWK3CMeK9UGmx2bP 1n8no7kk9inVZcah97wDhRyQbeSoYa4Q/pcARGYpbFCBPRbXLB7ggxHuIbd/BPicP6EK 0GKRIQp5Ij4RIXgy0kxTj82aklzOj7Ttjq+lryAPBzZkk3RNX66Ucdbf9LuO8V3UIsdo 2WAi8bcWnPb8VSlIct6/A73YvLU6Hg6ENRC78biexQFPceRKistP5zCtwpzqGFX44TnF KdJ0Mwi2mR+OvpHKuV93EwBUEOfJQN84kxg5C7Bompyp5qkcN+e4fTaj/TTUoiWKcb8b KxAA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789409548; x=1790014348; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=ZO1urm4Fark0kk4FfGgKDyyN0dzql0DO01I8NkWQ2as=; b=fUYb95RFlkNnqczaKa9CsVAFLDZZ7IW/vHewMq8Lr7SSFNaj6Tx7B3BRaHaW55d1g4 E9CDUZQZ/5qntHKz057wCRH9OnMvLOBqHCmNcEQuZmeEKXz1X9sIowZEM3qyPD7g+Kw6 bzyu6B04wMHgAWkQWVnICEDu7OvTu/G58yuKnCLL5Zmh8o+czd2rnO3c6pxkNcFEqpk8 FPTRWnejnlTAf9aTexLu6izU7M0MpqDmkJZdfhtuktGZI2knGEJ4PqR7AkQeXMWAp+YJ st1Npe0yi55GGRnauwFmDbH0ZL1l9ON68d6+4i34kzYbDjID1EyQlxw4vg5bbJ/WDfMm RQSQ== X-Forwarded-Encrypted: i=1; AKwUvBwOs2kYFaoEvAmcj/KCZe3CZj1UAB/MiwQ1mMbD669aQLVDylkUX906WwLYPd2erugeDr12xbNQRLhcHwg=@vger.kernel.org X-Gm-Message-State: AFuF++kolkfdA0fBoSH3dA7S9JPIgpnrEdsZqJUi0xAgftmwpGSq0JV4 8PJNjU6BiSEOHGN/Vml+f4nuRWY/yT+qycayXw6jJep1Cji/ZgWiMqviyldqTWzce43k0uW8AxI vUXyfFQ== X-Received: from pjbkx24.prod.google.com ([2002:a17:90b:2298:b0:39d:c134:415]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4fc1:b0:39d:fce7:f63a with SMTP id 98e67ed59e1d1-39dfce7f7fbmr1445324a91.6.1789409548252; Mon, 14 Sep 2026 11:12:28 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 14 Sep 2026 11:12:21 -0700 In-Reply-To: <20260914181223.289061-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260914181223.289061-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260914181223.289061-4-seanjc@google.com> Subject: [PATCH 3/5] KVM: Move check for existing vCPU ID to the top of vCPU creation From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Now that kvm->lock is held for the entirety of vCPU creation, check for a conflicting vCPU ID at the begnning of vCPU creation, before the arch precreate() hook is invoked. This will allow reverting commit 97d65b544f48 ("KVM: Check for duplicate vcpu_id as early as possible"). For now, keep the redundant vcpu_ids tracking as a sanity check. No functional change intended (absent KVM bugs, checking vcpu_ids and walking kvm_get_vcpu_by_id() should yield the same result). Signed-off-by: Sean Christopherson Tested-by: Jean-Christophe Guillain --- virt/kvm/kvm_main.c | 10 ++++------ 1 file changed, 4 insertions(+), 6 deletions(-) diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index c17cc8dd371b..d5524ac8c5cf 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -4182,7 +4182,10 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm,= unsigned long id) if (kvm->created_vcpus >=3D kvm->max_vcpus) return -EINVAL; =20 - if (test_bit(id, kvm->vcpu_ids)) + if (kvm_get_vcpu_by_id(kvm, id)) + return -EEXIST; + + if (WARN_ON_ONCE(test_bit(id, kvm->vcpu_ids))) return -EEXIST; =20 r =3D kvm_arch_vcpu_precreate(kvm, id); @@ -4221,11 +4224,6 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm,= unsigned long id) goto arch_vcpu_destroy; } =20 - if (WARN_ON_ONCE(kvm_get_vcpu_by_id(kvm, id))) { - r =3D -EEXIST; - goto unlock_vcpu_destroy; - } - /* * Set the vCPU's index *before* the vCPU is reachable by other tasks. * Unwind the index back to -1 on failure so that KVM can use the index --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 09:19:53 2026 Received: from mail-pg1-f197.google.com (mail-pg1-f197.google.com [209.85.215.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2294349CF27 for ; Mon, 14 Sep 2026 18:12:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409555; cv=none; b=r0iSAqWmUf8b+VmRIQ5Am4oQhRdutgtDNJnywQEbs/+fBkOrD6z7IFidFhIWHdkSArtsUS9scC/YVyTYBuvHsmufBJ0aoCop0nTv86XaDMJNEJue3mzm8E1iCu+2euQ3CxHbIF47IN8XyfaI2yKReD9rxtRWLhptYKqKHEfITBE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409555; c=relaxed/simple; bh=x0QuQ7B46vZSLWuhvb7Pej5iUeD3ReCFBUcJ7PEUjmM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RPM8A8O1G4rJNrdZe9msZ3fuWZNG/gwaC5LK12M8xcLJgO76iigVzYsPbxKD5qPqcT07W0dlxsB7ddLD/uFd0429ix9DEUw4+MM8DBd7sPqvIwdxdQbLoRP8FqaossprVOrzropF0RSji3Ru1s6kFcmGQrGRuwKzaFsIp7ifmEE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=n6TzLXHb; arc=none smtp.client-ip=209.85.215.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="n6TzLXHb" Received: by mail-pg1-f197.google.com with SMTP id 41be03b00d2f7-cc4922b7c31so3577518a12.1 for ; Mon, 14 Sep 2026 11:12:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789409549; x=1790014349; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:reply-to:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Vrq15StmiM1CTIka90pdQUrQi6qd2fHaKI/Mz3n+CgQ=; b=n6TzLXHbYJ1jVtp596d/POf/6h2dWOS8arTo+unEBbLgR8KTq3gA3PtIQ4zeTZiat6 b6DXUWkKiL/IhjOylG2yz384swPPztJHNcDMdYjp7gnLRzx5DwjqeJfg+2NF95Ok8FL4 RL/+SwEI6l06HAMUCSx1rVeH3WjgF3/lMEW9ApREwLISzY2kqQQWkA2DbVqwE6WYLQ+V BXeULoVOfYgFoD6n3nORnDgpYlJ/Ge8IffzqY6cIZ2WLbTCimfHe+6jTpXCCK3y5px4V xVxm6/RAI2+iKtu3gpribISYGp68y2MSQUBedc9GC6CIOYd+9jf/TsIxaoogDfPjqVx6 +Bmw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789409549; x=1790014349; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Vrq15StmiM1CTIka90pdQUrQi6qd2fHaKI/Mz3n+CgQ=; b=pUgO7y+vTHiSmt6mN+vk/A+Kyua5fOgf6YcFP8myIPfpQW8y+s8enYy616MErU6Wb9 Hz3SrDOVOQLjMlPizKWUoAZIYv0GMvDTlkAoZ1ttF31Z48xVdx9eiHwLI56i8q4giX2o 3fMuET8dMKu/5BrXQbqNrsZQiHYMpeh/USpdo6pDJLVqqqUT0T/QLTnsRLDUkQ13/tTa NpnwvkmedR6ZMsWm8ZY7J0ciL6T/JdQO19YvZyHXMPkDf39c64Zv5pwhXwqsmMLkwk5M 6kpnfPkAgff8MEcnVrKOoChAqTfm1r5IEylrGSfSWOvT3O/89IOWZm8g7v7QJRcZjKS4 XkLA== X-Forwarded-Encrypted: i=1; AKwUvBwLloq/Khme/fVyhY1cEmBPYwYuHF7rB1Lomn9vUyczl0vK+X8FWIOMdCI12XXZL3/KSO8VRnJ5msnpbCA=@vger.kernel.org X-Gm-Message-State: AFuF++lLcpv9WxVvEv8Ppa7Uvbuj4dNadxwFlJQr0dM3kZ69PTyE9LAS d3jVPSfeCwmFNv0MLuDY3pZGdmWmIfeB2FB3rOLcTk1L9HUHt0cQ2IQ4VG8anuTpeIyQ+50Q0LB lrl1BpQ== X-Received: from pfbcp14.prod.google.com ([2002:a05:6a00:348e:b0:848:4e44:7f19]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4195:b0:86c:a9a8:844f with SMTP id d2e1a72fcca58-86f831591d9mr8229457b3a.1.1789409549392; Mon, 14 Sep 2026 11:12:29 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 14 Sep 2026 11:12:22 -0700 In-Reply-To: <20260914181223.289061-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260914181223.289061-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260914181223.289061-5-seanjc@google.com> Subject: [PATCH 4/5] Revert "KVM: Check for duplicate vcpu_id as early as possible" From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Now that KVM uses kvm_get_vcpu_by_id() to check for an existing vCPU ID before doing any meaningful work, which was made possible by holding kvm->lock for the entirety of vCPU creation, revert the now-redundant "early" vCPU ID tracking. The claims about the impact of kvm->vcpu_ids on the memory footprint were a wee bit wrong: the worst case scenario isn't 256 bytes per VM, it's 256 "unsigned longs" per VM, i.e. 2048 bytes per VM. Increasing the size of "struct kvm" by 2048 nearly doubled the total size on many architectures, and tripped x86's KVM_SANITY_CHECK_VM_STRUCT_SIZE, which was added to detect this *exact* scenario, where a single change significantly increased the size of "struct kvm". I.e. attempting to build KVM with CONFIG_DEBUG_KERNEL=3Dn fails on x86 (the build failures got missed because all build bots apparently test only CONFIG_DEBUG_KERNEL=3Dy kernels, and maintainers' test flows were similarly lacking). This reverts commit 97d65b544f48b2ee49f6aea32145e3e7969955dc. Fixes: 97d65b544f48 ("KVM: Check for duplicate vcpu_id as early as possible= ") Reported-by: Jean-Christophe Guillain Closes: https://lore.kernel.org/all/56a4bc35ee605588b7cc36c8e45c12b5f3b506c= b.camel@guillain.net Reported-by: Pawe=C5=82 S Closes: https://lore.kernel.org/all/CABD%3DWFOS4j4hDv%2BpW-eEM9HAM2q2GY_iYd= AG%2BqvYcUEinUrcQQ@mail.gmail.com Signed-off-by: Sean Christopherson Tested-by: Jean-Christophe Guillain --- include/linux/kvm_host.h | 1 - virt/kvm/kvm_main.c | 5 ----- 2 files changed, 6 deletions(-) diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h index 03bfc92864b6..6aab167bf482 100644 --- a/include/linux/kvm_host.h +++ b/include/linux/kvm_host.h @@ -791,7 +791,6 @@ struct kvm { /* The current active memslot set for each address space */ struct kvm_memslots __rcu *memslots[KVM_MAX_NR_ADDRESS_SPACES]; struct xarray vcpu_array; - DECLARE_BITMAP(vcpu_ids, KVM_MAX_VCPU_IDS); /* * Protected by slots_lock, but can be read outside if an * incorrect answer is acceptable. diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index d5524ac8c5cf..985af39b980a 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -4185,15 +4185,11 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm= , unsigned long id) if (kvm_get_vcpu_by_id(kvm, id)) return -EEXIST; =20 - if (WARN_ON_ONCE(test_bit(id, kvm->vcpu_ids))) - return -EEXIST; - r =3D kvm_arch_vcpu_precreate(kvm, id); if (r) return r; =20 kvm->created_vcpus++; - __set_bit(id, kvm->vcpu_ids); =20 vcpu =3D kmem_cache_zalloc(kvm_vcpu_cache, GFP_KERNEL_ACCOUNT); if (!vcpu) { @@ -4276,7 +4272,6 @@ static int kvm_vm_ioctl_create_vcpu(struct kvm *kvm, = unsigned long id) kmem_cache_free(kvm_vcpu_cache, vcpu); vcpu_decrement: kvm->created_vcpus--; - __clear_bit(id, kvm->vcpu_ids); return r; } =20 --=20 2.55.0.1032.g73a4cd73de-goog From nobody Fri Sep 25 09:19:53 2026 Received: from mail-pj1-f71.google.com (mail-pj1-f71.google.com [209.85.216.71]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A36B449B5CC for ; Mon, 14 Sep 2026 18:12:35 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.71 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409558; cv=none; b=q/M8bs6R8pG9KzvkXjyTQUETzUNsqNsM5F8ZAAnYZljHE8Tk6qmzB8Bv4SVXZCgBwl/JiGVpuSMWBNusYul9OK+qNMlxAED23BZiFPXQg2saN9aN2lFMGP95aUlRHXmEW1vsabo6igAgs/HrlDrupOyqj23fqV3BznQIBPRGpCA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789409558; c=relaxed/simple; bh=dJrvpB5i1rMlVAI+qV3aDnzI33qsio45lawj5JfEjHs=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=lRVRavCBtGrKZnL1RpSiX8x4P2O0q+Ea1E2/B7ECJ1U4dOP7EZ0AGpzquu8/mjmK/BwRo6C1O2OcBgSuCWdv6gAeuUxm7JTaYPiqO+YSJrJqgi2sdBBJEqZ7eOvvnpvFZ8tYL9TE3Yu160523v2gMj9cGKCo4e3Fzxh0ZUYDNAg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ll3QclfO; arc=none smtp.client-ip=209.85.216.71 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ll3QclfO" Received: by mail-pj1-f71.google.com with SMTP id 98e67ed59e1d1-38ecc48b3c2so5761868a91.1 for ; Mon, 14 Sep 2026 11:12:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789409552; x=1790014352; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=eILuU/ujF/gCxOipJ6aAt7TsmD8PW8XQkQA4cx27AIY=; b=ll3QclfObzQf89D5n0MifPRcHjYAPY8zYA1imWEzyXbIBgBF73qzGNuQny0cTx/z9V gJtZLdKJCLQYt9JykqMC7qt/3HYW0YBl2DYyYSB5JmdukUz026bZpY95atFn75EsV2KF CbUO8svIDspuK4reDoj0cNUd6EncsHvvBFKxKa+eJhyNS5aQ8Zs8wxE0+Uo+w5xiQPDe 0s/KJKd1Ht+XUeR8xo0IZGesiy3P9gRw5G+YnG6p8B5y9JRsap2+XLKJ+jhJ+XoXr9dj q0in9xGGsDXmqEhjP97w9vlPXv0VQJ07dMXk0ai0/pUncWstt1n59I8tYZYyd55WJuXU hUwQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1789409552; x=1790014352; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=eILuU/ujF/gCxOipJ6aAt7TsmD8PW8XQkQA4cx27AIY=; b=J148Tzdyvn9YVSoZyBDeC+5EoIraU74LExGN2KsnfdcEKyZpUV2xbA89fVdK2Mz6Bg h3FLRgb1t/xKf2vJCoKdxI2G05Yi1PuLjd6kQu47t708jqpTVblH58JScLTOYEzyKRu8 lhL6JbaxqbBU4onKSFoi52v52ci0Iite68Y9fBZHxZYJ2KlVH0CqrmI8dH7EXF4roltF 15njVn627E9RDv59togFCYY6iNqxwx2nK63roqRpOlM3hVpJfmI+j4dIkEovAJzpwGzo VNQRK5sXhXe15/zax15+IpsZB7PN3GCNblHI1hHwpYckhxFHYJvxeoxZDLx3PJ3VJ8L0 I6jA== X-Forwarded-Encrypted: i=1; AKwUvBzCWuco+3/FDd8n6Z1J6UUfZrvYHgGQ4VaSo/kHHH5KhaDS5RRYF9cS6F3vxjvE5pcPpA4Qf3HG3R1bOak=@vger.kernel.org X-Gm-Message-State: AFuF++liV9BEsSHp/6To69mVToo3O4EBDwsnBmp+665xrZkZFzqpZpIs +Ugn8bDwUL9mB7E6nFPTH7hIFZkG3DLmpYJniDUZvpz4lMRMCXwNvcSYbhHC9TbpkvG0Z6LBCm7 cSmH85g== X-Received: from pjso8.prod.google.com ([2002:a17:90a:c088:b0:398:ba84:67d7]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:17c8:b0:396:65dd:4093 with SMTP id 98e67ed59e1d1-39dec04f9d9mr6872853a91.14.1789409550513; Mon, 14 Sep 2026 11:12:30 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 14 Sep 2026 11:12:23 -0700 In-Reply-To: <20260914181223.289061-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260914181223.289061-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1032.g73a4cd73de-goog Message-ID: <20260914181223.289061-6-seanjc@google.com> Subject: [PATCH 5/5] KVM: WARN if vCPU creation is in-progress when locking all vCPUs From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Now that KVM holds kvm->lock for the entirety of vCPU creation, from when created_vcpus is incremented until the new vCPU is fully onlined, WARN if the impossible happens and KVM somehow sees a discrepancy between the number of vCPUs "created" and "onlined". Signed-off-by: Sean Christopherson Tested-by: Jean-Christophe Guillain --- virt/kvm/kvm_main.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 985af39b980a..e66d9761ee49 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -1363,7 +1363,7 @@ int kvm_trylock_all_vcpus(struct kvm *kvm) =20 lockdep_assert_held(&kvm->lock); =20 - if (kvm_is_vcpu_creation_in_progress(kvm)) + if (WARN_ON_ONCE(kvm_is_vcpu_creation_in_progress(kvm))) return -EBUSY; =20 kvm_for_each_vcpu(i, vcpu, kvm) @@ -1389,7 +1389,7 @@ int kvm_lock_all_vcpus(struct kvm *kvm) =20 lockdep_assert_held(&kvm->lock); =20 - if (kvm_is_vcpu_creation_in_progress(kvm)) + if (WARN_ON_ONCE(kvm_is_vcpu_creation_in_progress(kvm))) return -EBUSY; =20 kvm_for_each_vcpu(i, vcpu, kvm) { --=20 2.55.0.1032.g73a4cd73de-goog