From: sashiko-bot@kernel.org
To: "Tina Zhang" <zhang_wei@open-hieco.net>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v4 5/9] KVM: x86: Track emulator-originated nested #PF VM-Exits
Date: Wed, 19 Aug 2026 06:11:26 +0000 [thread overview]
Message-ID: <20260819061127.0E84C1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <e1860aaffc3a07d289dd083d2f3dd37b4d4bcc9c.1787116250.git.zhang_wei@open-hieco.net>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Medium] The newly added `has_emulator_context` field is left uninitialized or improperly cleared when queueing non-nested exceptions and restoring state from userspace.
- [Low] The `has_emulator_context` field is populated but never read anywhere in the codebase.
--
--- Patch [5]: [PATCH v4 5/9] KVM: x86: Track emulator-originated nested #PF VM-Exits ---
commit 224b6e38736ada4f6f56c322ba1950bffe0ab244
Author: Tina Zhang <zhang_wei@open-hieco.net>
KVM: x86: Track emulator-originated nested #PF VM-Exits
Add has_emulator_context to kvm_queued_exception to record whether a
queued exception VM-Exit originated from the current emulator exception.
> diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h
> index 283847619ff88..eb9f1b9afeb7d 100644
> --- a/arch/x86/include/asm/kvm_host.h
> +++ b/arch/x86/include/asm/kvm_host.h
> @@ -688,6 +688,7 @@ struct kvm_queued_exception {
> bool pending;
> bool injected;
> bool has_error_code;
> + bool has_emulator_context;
[Severity: Low]
Does this code ever read the newly added has_emulator_context field? It
looks like it is populated here and throughout the exception queueing paths,
but is never actually consumed.
> u8 vector;
> u32 error_code;
> unsigned long payload;
> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index d94b59140c452..75d00340c71fa 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c
[ ... ]
> @@ -473,7 +476,8 @@ static void kvm_multiple_exception(struct kvm_vcpu *vcpu, unsigned int nr,
> if (is_guest_mode(vcpu) &&
> kvm_nested_call(is_exception_vmexit)(vcpu, nr, error_code)) {
> kvm_queue_exception_vmexit(vcpu, nr, has_error, error_code,
> - has_payload, payload);
> + has_payload, payload,
> + has_emulator_context);
> return;
> }
[Severity: Medium]
Is it possible to leave the has_emulator_context field uninitialized here?
Looking at the rest of kvm_multiple_exception(), the new has_emulator_context
parameter is passed in, but it isn't assigned to the vcpu exception state in
the normal queue path:
if (!vcpu->arch.exception.pending && !vcpu->arch.exception.injected) {
queue:
vcpu->arch.exception.pending = true;
...
vcpu->arch.exception.has_payload = has_payload;
vcpu->arch.exception.payload = payload;
return;
}
Could this result in leaking stale state for has_emulator_context?
Furthermore, does this flag also need to be explicitly cleared in
kvm_vcpu_ioctl_x86_set_vcpu_events() when restoring exception state from
userspace?
--
Sashiko AI review · https://sashiko.dev/#/patchset/cover.1787116250.git.zhang_wei@open-hieco.net?part=5
next prev parent reply other threads:[~2026-08-19 6:11 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 5:51 [PATCH v4 0/9] KVM: nSVM: Enable DecodeAssists for nested guests Tina Zhang
2026-08-19 5:51 ` [PATCH v4 1/9] KVM: x86: Add helper to provide intercept linear addresses Tina Zhang
2026-08-19 6:10 ` sashiko-bot
2026-08-19 5:51 ` [PATCH v4 2/9] KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts Tina Zhang
2026-08-19 6:05 ` sashiko-bot
2026-08-19 5:51 ` [PATCH v4 3/9] KVM: nSVM: Track hardware-provided instruction bytes Tina Zhang
2026-08-19 6:05 ` sashiko-bot
2026-08-19 5:51 ` [PATCH v4 4/9] KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12 Tina Zhang
2026-08-19 6:11 ` sashiko-bot
2026-08-19 5:51 ` [PATCH v4 5/9] KVM: x86: Track emulator-originated nested #PF VM-Exits Tina Zhang
2026-08-19 6:11 ` sashiko-bot [this message]
2026-08-19 5:51 ` [PATCH v4 6/9] KVM: nSVM: Use emulator bytes for synthesized nested #NPF/#PF Tina Zhang
2026-08-19 5:51 ` [PATCH v4 7/9] KVM: nSVM: Fetch missing DecodeAssist bytes for synthesized #NPF/#PF Tina Zhang
2026-08-19 5:51 ` [PATCH v4 8/9] KVM: nSVM: Advertise DecodeAssists to L1 Tina Zhang
2026-08-19 5:51 ` [PATCH v4 9/9] KVM: selftests: Add nested SVM DecodeAssists test Tina Zhang
2026-08-19 6:10 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260819061127.0E84C1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=zhang_wei@open-hieco.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.