All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "David Woodhouse" <dwmw2@infradead.org>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v7 24/36] KVM: x86: Use ktime_get_snapshot_id() for master clock
Date: Tue, 28 Jul 2026 15:21:56 +0000	[thread overview]
Message-ID: <20260728152156.A48831F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728144954.355376-25-dwmw2@infradead.org>

Thank you for your contribution! Sashiko AI review found 6 potential issue(s) to consider:
- [High] Mathematically incorrect usage of `ktime_mono_to_any()` with a RAW timestamp.
- [High] Cannot retrieve CLOCK_MONOTONIC using only the standard system_time_snapshot.
- [High] The patch silently breaks KVM masterclock support on Hyper-V hosts.
- [High] Missing validation for zero cycles in kvm_snapshot_has_tsc leads to a massive guest time jump and potential DoS.
- [Low] The patch introduces a build failure by calling a non-existent kernel API and accessing non-existent struct fields.
- [Low] Static helper functions were abandoned but not removed, breaking the build.
--

--- Patch [24]: [PATCH v7 24/36] KVM: x86: Use ktime_get_snapshot_id() for master clock ---
commit 08cee26ad4312fb3cda5c262811876db0f33c933
Author: David Woodhouse <dwmw@amazon.co.uk>

KVM: x86: Use ktime_get_snapshot_id() for master clock

This commit replaces the KVM-private timekeeping reimplementation with calls 
to a generic ktime_get_snapshot_id interface. It is intended as a step towards 
eliminating the pvclock_gtod_data private copy of timekeeping state.

> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index 57494812cc839..45a768fd7cb35 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c

[ ... ]

> @@ -1580,14 +1581,39 @@ static int do_realtime(struct timespec64 *ts, u64 *tsc_timestamp)

[Severity: Low]
The commit message mentions replacing do_kvmclock_base, do_monotonic, 
do_realtime, and vgettsc. Were these functions meant to be removed in this 
patch? Leaving them defined as static helper functions without any callers 
will break builds compiled with -Werror=unused-function.

>   * reports the TSC value from which it do so. Returns true if host is
>   * using TSC based clocksource.
>   */
> +static bool kvm_snapshot_has_tsc(struct system_time_snapshot *snap,
> +				u64 *tsc_timestamp)
> +{
> +	/*
> +	 * ktime_get_snapshot_id() cannot fail for standard clock IDs
> +	 * (only for invalid/aux clocks or during suspend, with a WARN).
> +	 */
> +	if (!snap->valid)

[Severity: Low]
Does the system_time_snapshot structure have a valid field? It appears this 
field, along with hw_csid and hw_cycles used below, might not exist in the 
mainline struct system_time_snapshot, which would cause a build failure.

> +		return false;
> +
> +	if (snap->cs_id == CSID_X86_TSC) {

[Severity: High]
Does this explicit check for CSID_X86_TSC exclude the previously supported 
Hyper-V clocksource? Since VDSO_CLOCKMODE_HVCLOCK defaults to CSID_GENERIC, 
it seems this might silently break KVM masterclock support for nested VMs 
running on Hyper-V hosts.

[Severity: High]
If the hardware read transiently fails (such as during host migration) and 
snap->cycles is 0, this block unconditionally returns true and passes 0 as the 
host TSC reference. Could this result in a massive leap in guest time and 
cause a timer storm that soft-locks or crashes the guest VM? The commit 
message mentions raw_cycles being zero means the clocksource could not provide 
a raw counter value, but it does not appear to be handled here.

> +		*tsc_timestamp = snap->cycles;
> +		return true;
> +	}
> +
> +	if (snap->hw_csid == CSID_X86_TSC && snap->hw_cycles) {
> +		*tsc_timestamp = snap->hw_cycles;
> +		return true;
> +	}
> +
> +	return false;
> +}
> +
>  static bool kvm_get_time_and_clockread(s64 *kernel_ns, u64 *tsc_timestamp)
>  {
> -	/* checked again under seqlock below */
> -	if (!gtod_is_based_on_tsc(pvclock_gtod_data.clock.vclock_mode))
> +	struct system_time_snapshot snap = {};
> +
> +	ktime_get_snapshot_id(CLOCK_MONOTONIC_RAW, &snap);

[Severity: Low]
Is ktime_get_snapshot_id available in the generic timekeeping code? Calling a 
non-existent API will result in a build failure.

> +	if (!kvm_snapshot_has_tsc(&snap, tsc_timestamp))
>  		return false;
>  
> -	return gtod_is_based_on_tsc(do_kvmclock_base(kernel_ns,
> -						     tsc_timestamp));
> +	*kernel_ns = ktime_to_ns(ktime_mono_to_any(snap.systime, TK_OFFS_BOOT));

[Severity: High]
Does passing a RAW timestamp (from CLOCK_MONOTONIC_RAW) to ktime_mono_to_any 
mathematically mix two different time domains? It looks like this adds the 
monotonic-to-boot offset to a raw monotonic timestamp, which could corrupt 
the guest masterclock base time.

Additionally, does snap.systime exist in struct system_time_snapshot, or is 
this another missing field that will break the build?

> +	return true;
>  }
>  
>  /*
> @@ -1596,12 +1622,14 @@ static bool kvm_get_time_and_clockread(s64 *kernel_ns, u64 *tsc_timestamp)
>   */
>  bool kvm_get_monotonic_and_clockread(s64 *kernel_ns, u64 *tsc_timestamp)
>  {
> -	/* checked again under seqlock below */
> -	if (!gtod_is_based_on_tsc(pvclock_gtod_data.clock.vclock_mode))
> +	struct system_time_snapshot snap = {};
> +
> +	ktime_get_snapshot_id(CLOCK_MONOTONIC, &snap);
> +	if (!kvm_snapshot_has_tsc(&snap, tsc_timestamp))
>  		return false;
>  
> -	return gtod_is_based_on_tsc(do_monotonic(kernel_ns,
> -						 tsc_timestamp));
> +	*kernel_ns = ktime_to_ns(snap.systime);

[Severity: High]
Can CLOCK_MONOTONIC time actually be retrieved using only the standard 
system_time_snapshot? The standard struct captures real, boot, and raw times, 
but lacks the timekeeper offsets needed to properly compute monotonic time. 
KVM guest timekeeping requests might return corrupt data if relying solely on 
this structure without proper offsets.

> +	return true;
>  }

[ ... ]

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260728144954.355376-1-dwmw2@infradead.org?part=24

  reply	other threads:[~2026-07-28 15:21 UTC|newest]

Thread overview: 53+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-28 14:39 [PATCH v7 00/36] Cleaning up the KVM clock mess David Woodhouse
2026-07-28 14:39 ` [PATCH v7 01/36] KVM: x86: Improve accuracy of KVM clock when TSC scaling is in force David Woodhouse
2026-07-28 14:39 ` [PATCH v7 02/36] KVM: x86: Explicitly disable TSC scaling without CONSTANT_TSC David Woodhouse
2026-07-28 14:39 ` [PATCH v7 03/36] KVM: x86: Activate master clock immediately on vCPU creation David Woodhouse
2026-07-28 15:17   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 04/36] KVM: x86: Avoid NTP frequency skew for KVM clock on 32-bit host David Woodhouse
2026-07-28 14:39 ` [PATCH v7 05/36] KVM: x86: Fold __get_kvmclock() into get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 06/36] KVM: x86: Drop CPU pinning in get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 07/36] KVM: x86: Restructure get_kvmclock() David Woodhouse
2026-07-28 15:11   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 08/36] KVM: x86: Fix KVM clock precision in get_kvmclock() with TSC scaling David Woodhouse
2026-07-28 14:39 ` [PATCH v7 09/36] KVM: x86: Use get_kvmclock() in kvm_get_wall_clock_epoch() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 10/36] KVM: x86: Fix compute_guest_tsc() to handle negative time deltas David Woodhouse
2026-07-28 14:39 ` [PATCH v7 11/36] KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling David Woodhouse
2026-07-28 15:11   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 12/36] KVM: x86: Simplify and comment kvm_get_time_scale() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 13/36] KVM: x86: Remove implicit rdtsc() from kvm_compute_l1_tsc_offset() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 14/36] KVM: x86: Improve synchronization in kvm_synchronize_tsc() David Woodhouse
2026-07-28 15:08   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 15/36] KVM: x86: Kill last_tsc_{nsec,write,offset} fields David Woodhouse
2026-07-28 15:09   ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 16/36] KVM: x86: Replace nr_vcpus_matched_tsc count with all_vcpus_matched_tsc bool David Woodhouse
2026-07-28 14:39 ` [PATCH v7 17/36] KVM: x86: Allow KVM master clock mode when TSCs are offset from each other David Woodhouse
2026-07-28 14:39 ` [PATCH v7 18/36] KVM: x86: Factor out kvm_use_master_clock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 19/36] KVM: x86: Avoid gratuitous global clock updates David Woodhouse
2026-07-28 14:40 ` [PATCH v7 20/36] KVM: x86/xen: Prevent runstate times from becoming negative David Woodhouse
2026-07-28 15:15   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 21/36] KVM: x86: Avoid redundant masterclock updates from multiple vCPUs David Woodhouse
2026-07-28 15:23   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 22/36] KVM: x86: Remove runtime Xen TSC frequency CPUID update David Woodhouse
2026-07-28 15:18   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 23/36] KVM: x86: Re-synchronize TSC after KVM_SET_TSC_KHZ David Woodhouse
2026-07-28 15:19   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 24/36] KVM: x86: Use ktime_get_snapshot_id() for master clock David Woodhouse
2026-07-28 15:21   ` sashiko-bot [this message]
2026-07-28 14:40 ` [PATCH v7 25/36] KVM: x86: Compute kvmclock base without pvclock_gtod_data David Woodhouse
2026-07-28 14:40 ` [PATCH v7 26/36] KVM: x86: Cache host vclock_mode for masterclock eligibility checks David Woodhouse
2026-07-28 15:26   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 27/36] KVM: x86: Remove pvclock_gtod_data and private timekeeping code David Woodhouse
2026-07-28 15:25   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 28/36] KVM: x86: Activate master clock from kvm_arch_init_vm() David Woodhouse
2026-07-28 15:31   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 29/36] UAPI: x86: Move pvclock-abi to UAPI for x86 platforms David Woodhouse
2026-07-28 14:40 ` [PATCH v7 30/36] KVM: selftests: Use UAPI pvclock-abi.h in xen_shinfo_test David Woodhouse
2026-07-28 14:40 ` [PATCH v7 31/36] KVM: x86: Add KVM_[GS]ET_CLOCK_GUEST for accurate KVM clock migration David Woodhouse
2026-07-28 14:40 ` [PATCH v7 32/36] KVM: x86: Add KVM_VCPU_TSC_SCALE and fix the documentation on TSC migration David Woodhouse
2026-07-28 15:26   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 33/36] KVM: selftests: Add KVM/PV clock selftest to prove timer correction David Woodhouse
2026-07-28 14:40 ` [PATCH v7 34/36] KVM: selftests: Add master clock offset test David Woodhouse
2026-07-28 15:22   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 35/36] KVM: selftests: Add Xen/generic CPUID timing leaf test David Woodhouse
2026-07-28 15:23   ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 36/36] KVM: selftests: Add Xen runstate migration test David Woodhouse

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260728152156.A48831F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dwmw2@infradead.org \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.