From: sashiko-bot@kernel.org
To: "Yosry Ahmed" <yosry@kernel.org>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v2 06/10] KVM: selftests: Drop HORRIFIC_L2_UCALL_CLOBBER_HACK
Date: Thu, 04 Jun 2026 20:50:07 +0000 [thread overview]
Message-ID: <20260604205007.D004E1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260604203546.365658-7-yosry@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] Removal of the ucall GPR hack causes L2 register corruption in EVMCS nested virtualization tests.
--
commit 15ef07c71219fb9256d8d4da6427386aaf993fbd
Author: Yosry Ahmed <yosry@kernel.org>
KVM: selftests: Drop HORRIFIC_L2_UCALL_CLOBBER_HACK
This commit drops the HORRIFIC_L2_UCALL_CLOBBER_HACK from ucall_arch_do_ucall(),
relying on the nVMX test code to preserve L2 GPRs across nested VM-exits.
> diff --git a/tools/testing/selftests/kvm/lib/x86/ucall.c b/tools/testing/selftests/kvm/lib/x86/ucall.c
> index e7dd5791959ba..38050c60a0670 100644
> --- a/tools/testing/selftests/kvm/lib/x86/ucall.c
> +++ b/tools/testing/selftests/kvm/lib/x86/ucall.c
> @@ -10,36 +10,8 @@
>
> void ucall_arch_do_ucall(gva_t uc)
> {
[ ... ]
> - HORRIFIC_L2_UCALL_CLOBBER_HACK);
> + asm volatile("in %[port], %%al"
> + : : [port] "d" (UCALL_PIO_PORT), "D" (uc) : "rax", "memory");
[Severity: Medium]
Does the removal of this hack cause L2 register corruption in Enlightened
VMX (EVMCS) tests?
While standard nVMX tests preserve GPRs using VMX_SWITCH_GPRS_ASM, it appears
the EVMCS helpers evmcs_vmlaunch() and evmcs_vmresume() in
tools/testing/selftests/kvm/include/x86/evmcs.h were not updated.
These functions still use a hardcoded inline assembly sequence that explicitly
clobbers %rbx and %r8-%r15.
If L2 triggers a ucall and an asynchronous event forces a nested VM-Exit
to L1, wouldn't the L1 compiler clobber L2's GPRs, causing L2 to resume
with corrupted registers and leading to a test failure?
> }
>
> void *ucall_arch_get_ucall(struct kvm_vcpu *vcpu)
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260604203546.365658-1-yosry@kernel.org?part=6
next prev parent reply other threads:[~2026-06-04 20:50 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-04 20:35 [PATCH v2 00/10] KVM: selftests: Stress save+restore and #PF (ft. nested) Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 01/10] KVM: selftests: Move STR() and XSTR() definitions to test_util.h Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 02/10] KVM: selftests: Fix RAX and RFLAGS VMCB offsets when running L2 Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 03/10] KVM: selftests: Use an array for guest_regs (and fix offsets) Yosry Ahmed
2026-06-04 20:44 ` sashiko-bot
2026-06-04 20:49 ` Yosry Ahmed
2026-06-04 21:37 ` Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 04/10] KVM: selftests: Move GPR load/save definitions outside of nSVM code Yosry Ahmed
2026-06-04 20:47 ` sashiko-bot
2026-06-04 20:35 ` [PATCH v2 05/10] KVM: selftests: Reuse GPR switching logic for nVMX Yosry Ahmed
2026-06-04 20:52 ` sashiko-bot
2026-06-04 20:35 ` [PATCH v2 06/10] KVM: selftests: Drop HORRIFIC_L2_UCALL_CLOBBER_HACK Yosry Ahmed
2026-06-04 20:50 ` sashiko-bot [this message]
2026-06-04 21:11 ` Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 07/10] KVM: selftests: Add basic stress test for save+restore and #PF handling Yosry Ahmed
2026-06-05 16:31 ` Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 08/10] KVM: selftests: Trigger save+restore randomly in the #PF stress test Yosry Ahmed
2026-06-04 20:49 ` sashiko-bot
2026-06-04 20:55 ` Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 09/10] KVM: selftests: Support running stress save+restore and #PF test in L2 Yosry Ahmed
2026-06-04 20:35 ` [PATCH v2 10/10] KVM: selftests: Trigger L2->L1 exits stress save+restore and #PF test Yosry Ahmed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260604205007.D004E1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=yosry@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.