From nobody Thu Sep 24 18:40:34 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C80A3511E8A for ; Mon, 21 Sep 2026 21:16:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025374; cv=none; b=HaruKxMm2qR/c2/gwbfPXFBsqIOg7ak0gol04LXKqRUMaqSgXED3pqlSQKbAphAR0yLI7RLWZ5wxVtVSncgJtdUNXeBI87GuiDPiVA/VOLyA4k/ywocFdLLRV/PkjmNnJ2dAh2t0GaabBLsaO+Ztuuob72fdMKfrjBqZ1eubsxQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025374; c=relaxed/simple; bh=pRV+4Yz/MRvphetpcx2XfsYCtav+An9pfXk6M+2KL+E=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=cjGssFWUW0o5cE0wwTBOL17kaf6Zb5jKWAG04mmKps8ZiHpCuVl98V+8JoNqrtMTNtkUR7X0VhkNREOXESeyvjaK2lgjO+SStlazZBqt6jgY7u7UnJjd0IPblMRX4LodRleG0XYdoBc5+uCB2JPnpo1/mIyLQVG31AF5fail44I= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=nYHmB6PT; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="nYHmB6PT" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-39512608fb1so8225901a91.1 for ; Mon, 21 Sep 2026 14:16:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790025372; x=1790630172; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=cljxKoEkJHuB8e5gB97za3SJLDV8TCYQCWMWqDIf1FI=; b=nYHmB6PT8s6j2TfY+J6qs2bNq7T2p3V+fTw0BRpknmD28vIzwmOZnseQXu3L67iD/y Bl/dYv2SHg78sy4J6xcva9d93tg8NKfp1Kev52JGXFn7oxntcTgIur0pUG8SIyJIFEIW 6IYdN4UhQLww5KFA1cGtXiHfWSKZMVyQdqgwi8fR/4YoJrHAoHHAddIvij8SbELux5LH g2LeWyToXTkDP3Q9H6IjthX3pPYZQWwYMJLnlVapahFXEQ1p0G6lfI64CHV4eDh0Kph+ AzTfyYzOp7vJ/MkiT4eBpES0/w+EU43zk1ARxrvEZMOqTKevQmfeetdzOgwbUDdkPKtk j2qQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790025372; x=1790630172; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=cljxKoEkJHuB8e5gB97za3SJLDV8TCYQCWMWqDIf1FI=; b=wuxXDemuotYv+g/1VR19fnsxEcu0fHttJovVDeAAx1FTkb1JkVnRKZPaASzPeG3pdw wxy5OUCxJ+ohUrP6uORQWThZ3NyrCsthH5KCNVNPju6hNsfucJcPkVoyg9tGpoZWTCPX 2tTIxq5nr6vFc4+zXk4lSdTVr+Dw3H4+C/PLcd4GCBX0bB5FBTTH5v4pHM7jD3YK3gHQ 1d/6xY/isd2xLLGKGe/17E0Oy+wVQHnZVINYdKlXgB4E+LD45vZPnQVY2ycy+a1pVLpc l3oWoW0rsS13iJQLnM5pfEakFIaJJ1uGIGDVO05v5DRUe16+EyamZWyHjX9uvx+jl7nI 2LLw== X-Forwarded-Encrypted: i=1; AKwUvBygV+AFOhA227GyUl4Iuxt2oxNMMjIEEDrjuxUGp/kKwJBEBmQjIhvJz/GwvaLQ4i5aa6yQ1kmLbAHVixE=@vger.kernel.org X-Gm-Message-State: AFuF++mAGKBGtFuhTF7UrvDNqzEALWeIE8qFCLOF+zUSh1Fwg6usyUN+ +sAoF+Dt4LmY8SgmuSYWEgU5ZAJiFjsa8EZs0J58lwxLfXoPWduiQMtIB9M0mKq+W2nCyCXypGy XAhAmCw== X-Received: from pjqx12.prod.google.com ([2002:a17:90a:b00c:b0:3a0:525a:e19f]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:39ad:b0:39e:6c69:9b95 with SMTP id 98e67ed59e1d1-39e6c69b29dmr10920170a91.58.1790025371869; Mon, 21 Sep 2026 14:16:11 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 21 Sep 2026 14:16:07 -0700 In-Reply-To: <20260921211608.1030158-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921211608.1030158-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921211608.1030158-2-seanjc@google.com> Subject: [PATCH v2 1/2] KVM: x86: Re-pend GET_NESTED_STATE_PAGES if getting said pages fails From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jinwoo Lee , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Re-pend GET_NESTED_STATE_PAGES before exiting to userspace if getting the nested pages fails in the KVM_RUN path. If userspace re-runs the vCPU, and vmcs02 holds valid PFNs from the *previous* run of L2, then KVM could re-enter L2 with stale, unpinned PFNs mapped into e.g. the vAPIC page. Note, both SVM and VMX (as of commit 11722439fb20 ("KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit") ensure the request is cleared on VM-Exit (including the "forced" case), i.e. there is no risk of double-mapping due to emulated VMLAUNCH/VMRESUME/VMRUN *and* the request trying to map the nested pages. Fixes: 671ddc700fd0 ("KVM: nVMX: Don't leak L1 MMIO regions to L2") Cc: stable@vger.kernel.org Reported-by: Jinwoo Lee Closes: https://lore.kernel.org/all/20260813043932.3214460-1-rkskek9254@gma= il.com Reported-by: Stefan Teodorescu Signed-off-by: Sean Christopherson --- arch/x86/kvm/x86.c | 1 + 1 file changed, 1 insertion(+) diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index af3ceee714c9..3c5d3e19ec99 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -8024,6 +8024,7 @@ static int vcpu_enter_guest(struct kvm_vcpu *vcpu) =20 if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) { if (unlikely(!kvm_nested_call(get_nested_state_pages)(vcpu))) { + kvm_make_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu); r =3D 0; goto out; } --=20 2.55.0.1082.g2b9226bbc0-goog From nobody Thu Sep 24 18:40:34 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EFE4C4E9C11 for ; Mon, 21 Sep 2026 21:16:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025375; cv=none; b=Lrz4wvFWenBmXvlVsbhWyEcNHvRq8Cg0SYI1AoPRgE/nWDHcTfIZdXf+xT4ACxc8Pi7zWfnRBw/X3aSLR+3Zc8aVqS50fcFtodvo7rgUZiyoKoKb5uR8zRArU6rIXAGTWVuFGpx7pitfyzi0ACjtc4I+yJpZ5Iwm7bPsB/SE9Ac= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790025375; c=relaxed/simple; bh=8j/UVd3R9hPZYEQmpaTIM9YhX+5Gk60NqIXL2kiut2E=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=TRL4PRKJmMWGFzLq+8Ba5NtF5dYslqqrVZx0j35Ip1lLLD/E/9FhQkCsoGb+oy6btV+CFRpmAIdE54VdeKIbOuk26jAwr2Q6JP49G0nQzFg5iQx20Acle3B7O7ylgAa7xIkYAmejslJFeNLxmfzEhatkT1+w7egu6Nr5MO0scSY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=KH/pyQZN; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="KH/pyQZN" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-38ea32e57e2so6464381a91.1 for ; Mon, 21 Sep 2026 14:16:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790025373; x=1790630173; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=gUPmdTjIpuFQRYNvpR8eehCmbHOJvqsMfaeTcAMfPLk=; b=KH/pyQZNRSDTSTS2+6sDBdZZY3nf/MJIMCMxDe4Y1OmroDYHdXknoHGAJsZJESbr6n HPl5XfbAXI+Jk4SXvntXwytpLV+Z7aabGGXD67YvPvMLy6d43KztxF5XKzy9CejMekfv K/r529E+Xl3uFR53KFzQ8/wvrRFjvCJbNqf3rlL1QQmu6IWzcpj54rRAaTD3lUEby0Zx rDjksdsGaHuXIphAneirKwv2J/93zQNYiOUG2eG1P5gNV1Dy44VUGS+J8ZjLtGEql/8D Jfsri6EM/sAwiiuvsRHO6BrsqzSv7OqQ251cLxGRUAohcjzuKSZqGR6Ofp5F+s9Gr6hc jifQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790025373; x=1790630173; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=gUPmdTjIpuFQRYNvpR8eehCmbHOJvqsMfaeTcAMfPLk=; b=KVyOcl5lV3tcGRaGOsK2L3vPyyF7Ht1YLQ91RRLG5WSV1nvQ+xjVewIj8wwYUchsGO dviUqDqBkBkbOwDUUI2wYruWA8IBVR8BFOc4uS/Y+0O8TIobHHYET/y0MT3LX8BOZrW2 sGasmwemZZAtbqZGF5bszms5Gr8fWcJDkds6r1d4h8CAlbuAqTNXItc8dymkU78CoUSl 91ymu0k3XGxr2Zo024ZMruQtReAENUWdxUsLnEawC8HjB4jAMQalwhk/C0nEottRQfzX 4C7YK4HB7NrOkE/L21lsRUrvdX2hJ99dTs/9aDO03jy4r2XrCoW5LfknpB0fK7+sMDbu rh3g== X-Forwarded-Encrypted: i=1; AKwUvBx/2+EkjGUSN20yXxbHQLWBfILFeJSkEtTGZohNxXO4JE3tAxmxvwQtNZbi4T8t1mZJ5I7/PssjFXwIuGw=@vger.kernel.org X-Gm-Message-State: AFuF++md1j29NNkX171HsM3jh5SzQY4lbh+LS0P/xKtjUjhAIrzl+Nzm B/q2e9TIO24M2VjHwszFSYqwWqeg7brVagLsC5TVCeQEcTjjAkRyM2bpeOpH7nPRAB7AyOlss+l iiCAycw== X-Received: from pjbkz3.prod.google.com ([2002:a17:90b:2103:b0:39d:9b47:4551]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:574d:b0:39b:3109:10ce with SMTP id 98e67ed59e1d1-3a06ae1fd24mr248043a91.16.1790025373221; Mon, 21 Sep 2026 14:16:13 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 21 Sep 2026 14:16:08 -0700 In-Reply-To: <20260921211608.1030158-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921211608.1030158-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921211608.1030158-3-seanjc@google.com> Subject: [PATCH v2 2/2] KVM: x86: Fill kvm_run exit fields in common get_nested_state_pages() error paths From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jinwoo Lee , Stefan Teodorescu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Fill kvm_run with "internal error, emulation" in the common error handling paths for getting nested state pages, as requiring each check to manually fill kvm_run is error prone and requires a non-trivial amount of copy+paste. Specifically, both SVM and VMX fail to fill kvm_run if load_pdptrs() fails, and SVM fails to fill kvm_run if kvm_hv_verify_vp_assist() fails. If those flows fail, the *best* case scenario is that KVM will exit to userspace with KVM_EXIT_UNKNOWN. The worst case scenario is that KVM exits with a stale exit_reason and confuses userspace. Note, SVM never exits to userspace if something goes sideways when dealing with vmcb12 assets while emulating VMRUN, i.e. lack of SVM-specific code is not a bug. Fixes: 0f85722341b0 ("KVM: nVMX: delay loading of PDPTRs to KVM_REQ_GET_NES= TED_STATE_PAGES") Fixes: 232f75d3b4b5 ("KVM: nSVM: call nested_svm_load_cr3 on nested state l= oad") Fixes: 3f4a812edf5c ("KVM: nSVM: hyper-v: Enable L2 TLB flush") Cc: stable@vger.kernel.org Reported-by: Jinwoo Lee Closes: https://lore.kernel.org/all/20260813043932.3214460-1-rkskek9254@gma= il.com Reported-by: Stefan Teodorescu Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/nested.c | 7 +------ arch/x86/kvm/vmx/nested.c | 15 +++++---------- arch/x86/kvm/x86.c | 3 +++ 3 files changed, 9 insertions(+), 16 deletions(-) diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c index 23d29597d6bf..82c49a24dd75 100644 --- a/arch/x86/kvm/svm/nested.c +++ b/arch/x86/kvm/svm/nested.c @@ -2130,13 +2130,8 @@ static bool svm_get_nested_state_pages(struct kvm_vc= pu *vcpu) return false; } =20 - if (!nested_svm_merge_msrpm(vcpu)) { - vcpu->run->exit_reason =3D KVM_EXIT_INTERNAL_ERROR; - vcpu->run->internal.suberror =3D - KVM_INTERNAL_ERROR_EMULATION; - vcpu->run->internal.ndata =3D 0; + if (!nested_svm_merge_msrpm(vcpu)) return false; - } =20 if (kvm_hv_verify_vp_assist(vcpu)) return false; diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 0e5f4d7ce9eb..56fbe73a44dc 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -3465,10 +3465,6 @@ static bool nested_get_vmcs12_pages(struct kvm_vcpu = *vcpu) } else { pr_debug_ratelimited("%s: no backing for APIC-access address in vmcs12\= n", __func__); - vcpu->run->exit_reason =3D KVM_EXIT_INTERNAL_ERROR; - vcpu->run->internal.suberror =3D - KVM_INTERNAL_ERROR_EMULATION; - vcpu->run->internal.ndata =3D 0; return false; } } @@ -3539,11 +3535,6 @@ static bool vmx_get_nested_state_pages(struct kvm_vc= pu *vcpu) if (!nested_get_evmcs_page(vcpu)) { pr_debug_ratelimited("%s: enlightened vmptrld failed\n", __func__); - vcpu->run->exit_reason =3D KVM_EXIT_INTERNAL_ERROR; - vcpu->run->internal.suberror =3D - KVM_INTERNAL_ERROR_EMULATION; - vcpu->run->internal.ndata =3D 0; - return false; } #endif @@ -3915,8 +3906,12 @@ static int nested_vmx_run(struct kvm_vcpu *vcpu, boo= l launch) =20 vmentry_failed: vcpu->arch.nested_run_pending =3D 0; - if (status =3D=3D NVMX_VMENTRY_KVM_INTERNAL_ERROR) + if (status =3D=3D NVMX_VMENTRY_KVM_INTERNAL_ERROR) { + vcpu->run->exit_reason =3D KVM_EXIT_INTERNAL_ERROR; + vcpu->run->internal.suberror =3D KVM_INTERNAL_ERROR_EMULATION; + vcpu->run->internal.ndata =3D 0; return 0; + } if (status =3D=3D NVMX_VMENTRY_VMEXIT) return 1; WARN_ON_ONCE(status !=3D NVMX_VMENTRY_VMFAIL); diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c index 3c5d3e19ec99..e9684abae4d8 100644 --- a/arch/x86/kvm/x86.c +++ b/arch/x86/kvm/x86.c @@ -8024,6 +8024,9 @@ static int vcpu_enter_guest(struct kvm_vcpu *vcpu) =20 if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) { if (unlikely(!kvm_nested_call(get_nested_state_pages)(vcpu))) { + vcpu->run->exit_reason =3D KVM_EXIT_INTERNAL_ERROR; + vcpu->run->internal.suberror =3D KVM_INTERNAL_ERROR_EMULATION; + vcpu->run->internal.ndata =3D 0; kvm_make_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu); r =3D 0; goto out; --=20 2.55.0.1082.g2b9226bbc0-goog