From: sashiko-bot@kernel.org
To: "Vitaly Kuznetsov" <vkuznets@redhat.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS
Date: Fri, 14 Aug 2026 16:31:05 +0000 [thread overview]
Message-ID: <20260814163105.BDEC31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260814162221.2144473-5-vkuznets@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The hardcoded `VMPTRLD_INSN_SIZE` of 5 bytes is brittle because `vmptrld` is executed using an inline assembly memory operand constraint (`"m"`), which results in a variable-sized instruction depending on compiler optimizations and register allocation.
--
--- Patch [4]: [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS ---
commit 80c84d1f71bebfd26712329b4fe8a487216ec3fb
Author: Vitaly Kuznetsov <vkuznets@redhat.com>
KVM: selftests: Check VMPTRLD with active eVMCS
Check that VMPTRLD when eVMCS is active results in #UD. This matches
genuine Hyper-V's behavior.
> diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> index 88262ddf7fcb2..6a6d940a78918 100644
> --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> @@ -18,12 +18,16 @@
> #include "hyperv.h"
> #include "vmx.h"
>
> +#define VMLAUNCH_INSN_SIZE 3
> +#define VMPTRLD_INSN_SIZE 5
> +
> static int ud_count;
> +static int ud_insn_skip_size;
>
> static void guest_ud_handler(struct ex_regs *regs)
> {
> ud_count++;
> - regs->rip += 3; /* VMLAUNCH */
> + regs->rip += ud_insn_skip_size;
> }
[ ... ]
> @@ -182,10 +186,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct hyperv_test_pages *hv_pages,
> GUEST_ASSERT(vmreadz(VM_EXIT_REASON) == EXIT_REASON_VMCALL);
> GUEST_SYNC(11);
>
> + ud_insn_skip_size = VMPTRLD_INSN_SIZE;
> + vmptrld(hv_pages->enlightened_vmcs_gpa);
[Severity: Medium]
Could this hardcoded instruction size lead to guest instruction stream
corruption?
The vmptrld() inline assembly in include/x86/vmx.h uses a memory operand
constraint ("m") for the physical address:
static inline int vmptrld(u64 vmcs_pa)
{
u8 ret;
__asm__ __volatile__ ("vmptrld %[pa]; setna %[ret]"
: [ret]"=rm"(ret)
: [pa]"m"(vmcs_pa)
: "cc", "memory");
...
}
Depending on compiler optimizations and register allocation, the resulting
instruction might not be exactly 5 bytes in size (for example, it could be 4
or 7 bytes depending on the chosen addressing mode).
Since guest_ud_handler() unconditionally advances regs->rip by
ud_insn_skip_size, if the generated instruction length does not match
VMPTRLD_INSN_SIZE, resuming the guest could land in the middle of an
instruction and cause #GP faults or infinite #UD loops.
> + GUEST_ASSERT(ud_count == 1);
> +
> /* Try enlightened vmptrld with an incorrect GPA */
> + ud_insn_skip_size = VMLAUNCH_INSN_SIZE;
> evmcs_vmptrld(0xdeadbeef, hv_pages->enlightened_vmcs);
> GUEST_ASSERT(vmlaunch());
> - GUEST_ASSERT(ud_count == 1);
> + GUEST_ASSERT(ud_count == 2);
> GUEST_DONE();
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260814162221.2144473-1-vkuznets@redhat.com?part=4
prev parent reply other threads:[~2026-08-14 16:31 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 16:22 [PATCH 0/4] KVM: nVMX: Adjust VMPTRLD/VMPTRST behavior with active eVMCS Vitaly Kuznetsov
2026-08-14 16:22 ` [PATCH 1/4] KVM: nVMX: Make VMPTRLD result in #UD when eVMCS is used Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot
2026-08-14 16:43 ` Sean Christopherson
2026-08-14 16:22 ` [PATCH 2/4] KVM: nVMX: Make VMPTRST return eVMCS GPA when it " Vitaly Kuznetsov
2026-08-14 16:32 ` sashiko-bot
2026-08-14 16:44 ` Sean Christopherson
2026-08-14 16:22 ` [PATCH 3/4] KVM: selftests: Adapt to the updated VMPTRST behavior when eVMCS " Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot
2026-08-14 16:22 ` [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814163105.BDEC31F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkuznets@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.