From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4C34723A99F for ; Tue, 28 Jul 2026 00:43:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199436; cv=none; b=ALW8nIR0qRK1T8FpFU1cX+eTwISdN4a8TaMET6o6yY7L4ZpndDhtZuFFFpVwwfqWxhQJjNt/qervPf2Y7Rd2v8PpIO01HPOGT5dPHgYKi44qYkPjQjYG40JUym9wVhwTPaJm+EM6cdjri3BLrK5bLhHxaDWxmQ5nMr03ef6PKH4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199436; c=relaxed/simple; bh=Do24KOSgHy/zD2Q1f6gGWrXDl3Dz3aVRlC2BD25fSE4=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=TEyvTTAit08+yIMK8DMsPxsZeVbvXYh6cKdju6AmFUwA7r6PGwSCX5hpneQQB1SLcFfooCPrUMgC6UvhHqhjcCXjMsyUJ1DpfhuvruKlY5u/h4CwOAEy1i7FAOt09YsjaUpx+5fuWZ1HC1Yyc5DpmDw9yVziL6uSDOLkKwWmVSk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=iSyndCUQ; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="iSyndCUQ" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2cacf17c7e0so45786385ad.0 for ; Mon, 27 Jul 2026 17:43:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785199433; x=1785804233; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:from:to:cc:subject:date:message-id:reply-to:content-type; bh=8NSeQojaPK9D5VUZ36qpU3WFDgkSN/KL2Zh1SU3UqOE=; b=iSyndCUQ+DyqhWQbABVZ2Ccgnn3NIgRELrn3AJ1bK/QvrB6Bf0Z78l1iNqxTLnnxjn DLGWzgDvTQdG9Hm/x7vFftYSS+acz39VKV+X8qqjjuHkKccWBf0Tl9Hg4v2bbobEo1Vs ZkkjAodjxQmYUjGTVAY/57TSYygNd6vVhLmHB0li2VnpKWOEhhKjdg94gmHILrhyHcS4 LoUwLyzmf5ap8yEt60M9H3FdezMgVfSw+3aMpigosQPwXqYSsVf+9mCjXfsRU9PyRzZ6 Ra2PpUaj2BX7AF3HyvUrlcOjNtke8lc8VjWLc05FuYuGOL+xtQwtN63+PDyM9PcSn7HD zJlA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785199433; x=1785804233; h=content-type:cc:to:from:subject:message-id:mime-version:date :reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=8NSeQojaPK9D5VUZ36qpU3WFDgkSN/KL2Zh1SU3UqOE=; b=WuTNJ8+mJfa5igTIExNIDVli6xnXdAmVw98elNGo1IXYy0Q3qFP1WaYtJDTNPvsZi6 0FLc4yWe75fZyuSKdEJWgVYXtwz10jpgByGXU+gSXPY5ZHpkkyhyBApfydGne2ur+nK+ xU2gSt4sGvz8vD9Dk2GcjBaZG0FUAb+7rOa5q3MNf0H8RVMFnfTAb4S5yd/fEqFOwRf2 Ta5Xt6XoPOwzu2xZK9dYVNsFLNiZCAHUVQfgWthfCrL50BGJd3PXgfHLAfY07EhYY3tp z4b/i40fB/BUk2qkoeoWxCManKLzTF5lg/0JCZVS3xxTElvGXFr5hEMElvic6Z8c2qJ4 sr+w== X-Forwarded-Encrypted: i=1; AHgh+RpU/v78mOTIaxDAwDf0nyTenDZQRnB95uNtdh56Iv+d1K8EKV7VRKdPqf19jNijulnf9tpVn4hH6rPX+JM=@vger.kernel.org X-Gm-Message-State: AOJu0YxD8nRTTIl5TDLFyEWcrqmsrVsgHkhEywPlrkaMjBP/EJfS3Ks5 vgZ2zvqvSXinguERCKE918z/LMAZhIrRwlxIPYMaU+n9KqcnYF6B+ZwnKqMescE1QahSZ5gwtNQ 1T0p/vQ== X-Received: from plha15.prod.google.com ([2002:a17:902:eccf:b0:2bc:c295:bdd2]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:f709:b0:2b2:67ca:5ff9 with SMTP id d9443c01a7336-2d015902adfmr2734955ad.0.1785199433058; Mon, 27 Jul 2026 17:43:53 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 27 Jul 2026 17:43:45 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260728004351.887076-1-seanjc@google.com> Subject: [PATCH v4 0/6] KVM: nVMX: Synthesize SHUTDOWN on RSM with bad state From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Hao Zhang Content-Type: text/plain; charset="UTF-8" Synthesize SHUTDOWN if invalid guest state is detected a RSM, i.e. if SMRAM is clobbered by L1 (or host userspace) while handling an SMI that occurred while L2 was active. This fixes yet another case of syzkaller tripping KVM's sanity check that KVM doesn't cancel a pending nested VM-Enter. Hao, can you provide your Signed-off-by for the selftest, assuming it looks good to you? Thanks! v4: - Synthesize SHUTDOWN instead of trying to suppress the KVM_BUG_ON(). - Add a selftest. v3: - https://lore.kernel.org/all/al8M4gCwsWXS_jMs@192.168.1.215 - Retain KVM_NESTED_RUN_PENDING_UNTRUSTED until after sync_vmcs02_to_vmcs12(), to avoid saving VMCS12 fields that are valid only after L2 has actually run. - Clear the untrusted pending state before restoring L1 state to avoid leaking nested_run_pending into L1 and blocking event injection. - Clarify the VMX pending-run BUG comment and update the changelog. - Tested with the syzkaller repro on the fixed kernel, no WARNING/KVM_BUG in the repro log v2: - https://lore.kernel.org/all/al8M4gCwsWXS_jMs@192.168.1.215 - Mark nested state restored by RSM from SMRAM as KVM_NESTED_RUN_PENDING_UNTRUSTED. - Keep the BUG check in __vmx_handle_exit(), but make it apply only to KVM_NESTED_RUN_PENDING. v1: https://lore.kernel.org/all/al3Qbq-jUYE-_72N@192.168.1.215 Hao Zhang (1): KVM: selftests: Extend the invalid nVMX guest state test to cover RSM Sean Christopherson (5): KVM: x86: Extract VMX's unhandleable emulation check to common x86 KVM: nVMX: Synthesize SHUTDOWN on RSM if L2 requires emulation KVM: x86: Rework kvm_x86_ops.vcpu_pre_run() into .vcpu_needs_initialization() KVM: selftests: Use port 0x80 in invalid nVMX guest state test KVM: selftests: Refactor invalid nVMX state test to prepare for RSM testcase arch/x86/include/asm/kvm-x86-ops.h | 3 +- arch/x86/include/asm/kvm_host.h | 4 +- arch/x86/kvm/smm.c | 4 + arch/x86/kvm/svm/sev.c | 5 + arch/x86/kvm/svm/svm.c | 12 +- arch/x86/kvm/svm/svm.h | 1 + arch/x86/kvm/vmx/main.c | 21 +++- arch/x86/kvm/vmx/tdx.c | 9 +- arch/x86/kvm/vmx/vmx.c | 12 +- arch/x86/kvm/vmx/x86_ops.h | 4 +- arch/x86/kvm/x86.c | 10 +- .../kvm/x86/vmx_invalid_nested_guest_state.c | 118 ++++++++++++++---- 12 files changed, 143 insertions(+), 60 deletions(-) base-commit: 271255273d5ff348fe29d89fe4712b2f7f7907c3 -- 2.55.0.229.g6434b31f56-goog