* [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
@ 2026-07-23 11:15 Zeng Chi
2026-07-24 1:23 ` Bibo Mao
2026-07-25 3:38 ` Tao Cui
0 siblings, 2 replies; 3+ messages in thread
From: Zeng Chi @ 2026-07-23 11:15 UTC (permalink / raw)
To: zhaotianrui, maobibo, chenhuacai, kernel
Cc: kvm, loongarch, linux-kernel, zengchi, stable
From: Zeng Chi <zengchi@kylinos.cn>
In the in-kernel MMIO read fast path of kvm_emu_mmio_read(),
kvm_complete_mmio_read() already advances the guest PC via update_pc().
The explicit update_pc() call right after it advances the PC a second
time, so PC moves forward by 8 instead of 4 and the instruction
following the MMIO read is silently skipped.
The user space MMIO read completion path in kvm_arch_vcpu_ioctl_run()
calls kvm_complete_mmio_read() only once, and the MMIO write fast path
advances the PC exactly once as well.
Remove the redundant update_pc() so the kernel MMIO read fast path
advances the PC by a single instruction.
Fixes: 80edf90831a2 ("LoongArch: KVM: Add sign extension with kernel MMIO read emulation")
Cc: stable@vger.kernel.org
Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
---
arch/loongarch/kvm/exit.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/arch/loongarch/kvm/exit.c b/arch/loongarch/kvm/exit.c
index 8572b63478bb..482ba17bcd3d 100644
--- a/arch/loongarch/kvm/exit.c
+++ b/arch/loongarch/kvm/exit.c
@@ -481,7 +481,6 @@ int kvm_emu_mmio_read(struct kvm_vcpu *vcpu, larch_inst inst)
srcu_read_unlock(&vcpu->kvm->srcu, idx);
if (!ret) {
kvm_complete_mmio_read(vcpu, run);
- update_pc(&vcpu->arch);
vcpu->mmio_needed = 0;
return EMULATE_DONE;
}
--
2.25.1
No virus found
Checked by Hillstone Network AntiVirus
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
2026-07-23 11:15 [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Zeng Chi
@ 2026-07-24 1:23 ` Bibo Mao
2026-07-25 3:38 ` Tao Cui
1 sibling, 0 replies; 3+ messages in thread
From: Bibo Mao @ 2026-07-24 1:23 UTC (permalink / raw)
To: Zeng Chi, zhaotianrui, chenhuacai, kernel
Cc: kvm, loongarch, linux-kernel, zengchi, stable
On 2026/7/23 下午7:15, Zeng Chi wrote:
> From: Zeng Chi <zengchi@kylinos.cn>
>
> In the in-kernel MMIO read fast path of kvm_emu_mmio_read(),
> kvm_complete_mmio_read() already advances the guest PC via update_pc().
> The explicit update_pc() call right after it advances the PC a second
> time, so PC moves forward by 8 instead of 4 and the instruction
> following the MMIO read is silently skipped.
>
> The user space MMIO read completion path in kvm_arch_vcpu_ioctl_run()
> calls kvm_complete_mmio_read() only once, and the MMIO write fast path
> advances the PC exactly once as well.
>
> Remove the redundant update_pc() so the kernel MMIO read fast path
> advances the PC by a single instruction.
>
> Fixes: 80edf90831a2 ("LoongArch: KVM: Add sign extension with kernel MMIO read emulation")
> Cc: stable@vger.kernel.org
> Signed-off-by: Zeng Chi <zengchi@kylinos.cn>
> ---
> arch/loongarch/kvm/exit.c | 1 -
> 1 file changed, 1 deletion(-)
>
> diff --git a/arch/loongarch/kvm/exit.c b/arch/loongarch/kvm/exit.c
> index 8572b63478bb..482ba17bcd3d 100644
> --- a/arch/loongarch/kvm/exit.c
> +++ b/arch/loongarch/kvm/exit.c
> @@ -481,7 +481,6 @@ int kvm_emu_mmio_read(struct kvm_vcpu *vcpu, larch_inst inst)
> srcu_read_unlock(&vcpu->kvm->srcu, idx);
> if (!ret) {
> kvm_complete_mmio_read(vcpu, run);
> - update_pc(&vcpu->arch);
> vcpu->mmio_needed = 0;
> return EMULATE_DONE;
> }
>
Hi Zeng,
Thanks for finding this problem, it is a big critical potential issue :(
Reviewed-by: Bibo Mao <maobibo@loongson.cn>
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path
2026-07-23 11:15 [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Zeng Chi
2026-07-24 1:23 ` Bibo Mao
@ 2026-07-25 3:38 ` Tao Cui
1 sibling, 0 replies; 3+ messages in thread
From: Tao Cui @ 2026-07-25 3:38 UTC (permalink / raw)
To: zeng_chi911
Cc: chenhuacai, kernel, kvm, linux-kernel, loongarch, maobibo, stable,
zengchi, zhaotianrui, cui.tao, cuitao
From: Tao Cui <cuitao@kylinos.cn>
> In the in-kernel MMIO read fast path of kvm_emu_mmio_read(),
> kvm_complete_mmio_read() already advances the guest PC via update_pc().
> The explicit update_pc() call right after it advances the PC a second
> time, so PC moves forward by 8 instead of 4 and the instruction
> following the MMIO read is silently skipped.
Good catch!
Reviewed-by: Tao Cui <cuitao@kylinos.cn>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-07-25 3:38 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-23 11:15 [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path Zeng Chi
2026-07-24 1:23 ` Bibo Mao
2026-07-25 3:38 ` Tao Cui
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.