From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 083AA22A4EE for ; Tue, 28 Jul 2026 00:43:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199439; cv=none; b=qmALd/s2XJ+pjbezv4UNj0/Weuc0aSCsnKkFntXL1Sqcl1j/ce2UPKxDeqyoaNI8AFB7+39/Fz1vgV4UfR52+GNJbgN1satCVtVYsE2U8rxlRFL6BDTOnz5xxpaBw6R1iuF0hUvNB8ihTa76cKAZjc+YSEo8svAEecNWT7OWxsk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199439; c=relaxed/simple; bh=LufD9LC1kKKPCpQl1k0wWWbduu+gLp/3xbjKEMdRutw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=piAaca7cDx+4IWE4Zzc6U+ShE4mN7R8D0zjrkoQHV6q8EUK0YI+YC/DCZY2VlDJnZa+RKXDepM3c3hw2J+8JKENs0MtEfODnq0l4A7TMfnWEHTVwqzK12gQWxBhr+Nkx3QwTv8sshlg52NdyuBSb6NFf2Omp6N0QkSpULd3u9Bw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=L51Gn4hr; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="L51Gn4hr" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2cca3673560so11358135ad.1 for ; Mon, 27 Jul 2026 17:43:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785199435; x=1785804235; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=t7bULcfoxNSRzWp6C1NwQeJ8xPeisIVrS9F2F9UXXtE=; b=L51Gn4hrl5z8OgatmLNZixeEb43MZqq1t6Sj6ppmRsUeqc5iUW6vwo3CVtBFXaezY3 MVOcPhOX6bys2fkuj1+G0jvSpugFd0+swn6+bkYNyNd+blqy1HQIVSgRuKY2PM1P45v3 oRUDUevqBRPu0Jg4p2cZiqFA8+IiWm9YbBRZXCgYClGDPuCqxRDrQxOuhlGuNn7TgIX0 Jbjy5XGI18FklmS8i+T+Tjgux9yC6oatuLVEJCeQRwZspiiY7Hvm+CjsjxAxe0y6yMUN 8tglKDkvCr2x0P587xR/TCWyvT4xgBFsPd+E4UmFwNeq0N5X66FnZHZNwqGZs+51sTPt Q+FQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785199435; x=1785804235; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=t7bULcfoxNSRzWp6C1NwQeJ8xPeisIVrS9F2F9UXXtE=; b=DvaMDC/I0P1Y9gyunZcQsh9JxN118h/EYGg3BvqFe+id+SDY05PggI8fnwQ9WH3Pjv mp51jxd0f3qDbHvyaQBiQWLNweJoDquToa7DOfgpgTx9ND+K4S/ND8Oyo5aMQifP4Fb1 mNz8k/6/Zk6s0ZBSMVjReL2NMnBSvDiR7QN5M8xvgisFu/fC1kQcc5oH1OXqArNyRG4Y KsGuutWFzxiglbA4WcTkUO3Gd9+WH0YhpAl9nLiI+rDjCyJZ4+DOYTfaN2jzYqBw51h0 c1zD9jFeaL14ZtCv9B4E64E44G2iyMqGEJ9L+JliiYkDkSrwn4c8xuwvkM2pvlGnX9cz m+Pg== X-Forwarded-Encrypted: i=1; AHgh+RpNm/fZF0PSkD8I06TO6NyrNLN6YspR2sk4XCZdaOenEOlEApfpHOSZF0Rhv0VvlOB+zlpe6FJ32wL5q4A=@vger.kernel.org X-Gm-Message-State: AOJu0YwhTicPz80SxMR5wxpvEgY9JKqtrPBYXx/FZc+1ixOAl0M9jLEW /rHB0IACEhiIxofr40RzxX2x0PepI4WgPhf5AFsw2cxz6vxWqghZdI1r+QXIR6nrEnl9wEsWBpy TDTmAjA== X-Received: from plai17.prod.google.com ([2002:a17:902:c951:b0:2cc:97d3:e244]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:1a85:b0:2ca:ea56:7a58 with SMTP id d9443c01a7336-2d015d95234mr1604685ad.37.1785199435180; Mon, 27 Jul 2026 17:43:55 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 27 Jul 2026 17:43:47 -0700 In-Reply-To: <20260728004351.887076-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260728004351.887076-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.229.g6434b31f56-goog Message-ID: <20260728004351.887076-3-seanjc@google.com> Subject: [PATCH v4 2/6] KVM: nVMX: Synthesize SHUTDOWN on RSM if L2 requires emulation From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Hao Zhang Content-Type: text/plain; charset="UTF-8" Synthesize SHUTDOWN (for L1) if L2 requires unhandleable emulation after loading guest state from SMRAM during RSM to prevent a misbehaving L1 (or userspace via L1) from tripping the sanity check that KVM doesn't try to cancel a pending nested VM-Enter. If SMRAM is modified such that RSM will load what should be impossible state for L2, then KVM will detect that it needs to emulate the current code stream and will abort VM-Entry to L2. And because KVM (rightly) expects such a scenario to be impossible, KVM WARNs and bugs the VM. __ret && !(vcpu->kvm)->vm_bugged WARNING: arch/x86/kvm/vmx/vmx.c:6741 at vmx_handle_exit+0x65/0x790 [kvm_intel], CPU#13: vmx_invalid_nes/2902 Modules linked in: kvm_intel kvm irqbypass [last unloaded: kvm] CPU: 13 UID: 1000 PID: 2902 Comm: vmx_invalid_nes Tainted: G W 7.2.0-rc2 #124 PREEMPT Tainted: [W]=WARN Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:vmx_handle_exit+0x65/0x790 [kvm_intel] Call Trace: kvm_arch_vcpu_ioctl_run+0xdf8/0x1d00 [kvm] kvm_vcpu_ioctl+0x2d5/0x960 [kvm] __x64_sys_ioctl+0x8a/0xd0 do_syscall_64+0xb7/0x570 entry_SYSCALL_64_after_hwframe+0x4b/0x53 Alternatively, KVM could suppress the WARN for the RSM case, but that would still leave the vCPU in a "bad" state that KVM doesn't know how to handle (which is also why KVM rejects attempts to do KVM_RUN when the vCPU is loaded with invalid state). And architecturally, the Intel SDM explicitly states that RSM leads to shutdown if the CPU detects invalid state. Fixes: 2bb8cafea80b ("KVM: vVMX: signal failure for nested VMEntry if emulation_required") Reported-by: Hao Zhang Signed-off-by: Sean Christopherson --- arch/x86/kvm/smm.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/arch/x86/kvm/smm.c b/arch/x86/kvm/smm.c index a446487bdd5c..656a38dad7e7 100644 --- a/arch/x86/kvm/smm.c +++ b/arch/x86/kvm/smm.c @@ -649,6 +649,10 @@ int emulator_leave_smm(struct x86_emulate_ctxt *ctxt) #endif ret = rsm_load_state_32(ctxt, &smram.smram32); + if (ret == X86EMUL_CONTINUE && + kvm_x86_call(unhandleable_emulation_required)(vcpu)) + ret = X86EMUL_UNHANDLEABLE; + /* * If RSM fails and triggers shutdown, architecturally the shutdown * occurs *before* the transition to guest mode. But due to KVM's -- 2.55.0.229.g6434b31f56-goog