From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Sean Christopherson <seanjc@google.com>
Cc: sashiko-reviews@lists.linux.dev, kvm@vger.kernel.org,
Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [PATCH v2 2/3] KVM: TDX: Fix the exit reason handling
Date: Tue, 11 Aug 2026 08:19:34 +0800 [thread overview]
Message-ID: <07df932f-ca83-463d-b830-aa10a8fa11f2@intel.com> (raw)
In-Reply-To: <anplcWfYReCMeu1A@google.com>
On 8/11/2026 7:57 AM, Sean Christopherson wrote:
> On Mon, Aug 10, 2026, Xiaoyao Li wrote:
>> On 8/10/2026 7:39 PM, sashiko-bot@kernel.org wrote:
>>>> @@ -2147,7 +2156,7 @@ void tdx_get_exit_info(struct kvm_vcpu *vcpu, u32 *reason,
>>>> struct vcpu_tdx *tdx = to_tdx(vcpu);
>>>> *reason = tdx->vt.exit_reason.full;
>>>> - if (*reason != -1u) {
>>>> + if (tdx->vt.exit_reason.basic != -1) {
>>> [Severity: Medium]
>>> Will this check always evaluate to true due to C integer promotion rules?
>>>
>>> The basic field in union vmx_exit_reason is a 16-bit unsigned bitfield. When
>>> comparing it to -1, the unsigned 16-bit value is promoted to a signed 32-bit
>>> integer. If the value was set to -1 (65535), the comparison evaluates as
>>> 65535 != -1, which is always true.
>>>
>>
>> Well, how about something below on top of this patch?
>
> No, we need to not rely on magic exit_reason.basic values. Can't this be?
>
> if ((tdx->vp_enter_ret & TDX_SW_ERROR) != TDX_SW_ERROR) {
I think the reason of checking if (*reason != -1u) in the original
commit 095b71a03f49 ("KVM: TDX: Add a place holder to handle TDX VM
exit") was that, -1u means there is no valid Exit Reason in the lower 32
bits in vp_enter_ret.
Change it to check TDX_SW_ERROR, doesn't look correct to me. Set the
EPT_MISCONFIG magic handling aside, TDX_SW_ERROR only means the SEAMCALL
instruction faults, e.g., hitting #UD, #GP, or VMFAILINVALID. Just a
small subset of the cases where there is no valid Exit Reason.
> <read values>
> } else {
> <zero values>
> }
>
> We'd need to use the unsafe version if we go with my suggestion[*], but other
> than that wrinkle, the above seems like the obviously correct fix (maybe too
> obvious)?
>
> [*] https://lore.kernel.org/all/anXxBzO41_5eaaOI@google.com
next prev parent reply other threads:[~2026-08-11 0:19 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 11:21 [PATCH v2 0/3] KVM: TDX: Enable VM-DoS Prevention Features for TDX Xiaoyao Li
2026-08-10 11:21 ` [PATCH v2 1/3] KVM: TDX: Enable Notify VM exit Xiaoyao Li
2026-08-11 0:37 ` Edgecombe, Rick P
2026-08-10 11:21 ` [PATCH v2 2/3] KVM: TDX: Fix the exit reason handling Xiaoyao Li
2026-08-10 11:39 ` sashiko-bot
2026-08-10 12:02 ` Xiaoyao Li
2026-08-10 23:57 ` Sean Christopherson
2026-08-11 0:04 ` Sean Christopherson
2026-08-11 0:19 ` Xiaoyao Li [this message]
2026-08-11 0:03 ` Sean Christopherson
2026-08-11 3:17 ` Xiaoyao Li
2026-08-11 0:38 ` Edgecombe, Rick P
2026-08-11 1:32 ` Xiaoyao Li
2026-08-10 11:22 ` [PATCH v2 3/3] KVM: TDX: Enable Bus Lock VM exit Xiaoyao Li
2026-08-10 11:46 ` sashiko-bot
2026-08-10 12:03 ` Xiaoyao Li
2026-08-11 1:18 ` Edgecombe, Rick P
2026-08-11 1:44 ` Xiaoyao Li
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=07df932f-ca83-463d-b830-aa10a8fa11f2@intel.com \
--to=xiaoyao.li@intel.com \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
--cc=seanjc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.