From: Sean Christopherson <seanjc@google.com>
To: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
Xiaoyao Li <xiaoyao.li@intel.com>,
Binbin Wu <binbin.wu@linux.intel.com>,
Kai Huang <kai.huang@intel.com>, Yan Zhao <yan.y.zhao@intel.com>
Subject: [PATCH v2 0/8] KVM: VMX: Harden against interpreting TDX vCPU as vcpu_vmx
Date: Wed, 26 Aug 2026 10:12:38 -0700 [thread overview]
Message-ID: <20260826171246.777729-1-seanjc@google.com> (raw)
Move and rename "all" (read: everything I could find) common helpers out of
vmx.c and/or replace their vmx_ prefix with vt_, and then poison to_vmx() for
all common .c files to harden KVM against misinterpreting a TDX vCPU as a VMX
vCPU, i.e. consuming to_vmx() on a TDX vCPU. Spotted when working through
the bus lock series.
As with v1, the TDX changes are compile-tested only.
v2:
- Complete my train of though in patch 1's changelog. [Binbin]
- Rename vmx_handle_exit_irqoff() => vt_handle_exit_irqoff. [Binbin, Sashiko]
- Collect a review. [Binbin]
- Move and rename everything I could find, using a dummy "struct vcpu_vmx_tdx"
to allow relocating common inline helpers from vmx.h to common.h.
v1: https://lore.kernel.org/all/20260814161129.2177118-1-seanjc@google.com
Sean Christopherson (8):
KVM: VMX: Move the shared "IRQs off" exit handler(s) to common code
KVM: VMX: Move the shared NMI handler/trampoline to common code
KVM: VMX: Disallowing using to_vmx() in common VT code
KVM: VMX: Rename posted interrupt prefixes from "vmx" to "vt"
KVM: VMX: Rename EPT violation handler prefix from "vmx" to "vt"
KVM: VMX: Use dummy pseudo-overlay struct for to_vt() and vt_to_vcpu()
KVM: VMX: Move common VT getters/converters to common.h
KVM: VMX: Rename common exit info getters prefixes from "vmx" to "vt"
arch/x86/kvm/vmx/common.h | 60 +++++++++++--
arch/x86/kvm/vmx/main.c | 92 ++++++++++++++++++-
arch/x86/kvm/vmx/nested.c | 36 ++++----
arch/x86/kvm/vmx/posted_intr.c | 20 +++--
arch/x86/kvm/vmx/posted_intr.h | 8 +-
arch/x86/kvm/vmx/tdx.c | 32 +++----
arch/x86/kvm/vmx/vmx.c | 155 ++++++++-------------------------
arch/x86/kvm/vmx/vmx.h | 37 --------
arch/x86/kvm/vmx/x86_ops.h | 1 -
9 files changed, 227 insertions(+), 214 deletions(-)
base-commit: 76671054f9a1ff6abb976583cd8da37650acdc97
--
2.55.0.887.g758fc8c411-goog
next reply other threads:[~2026-08-26 17:12 UTC|newest]
Thread overview: 25+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 17:12 Sean Christopherson [this message]
2026-08-26 17:12 ` [PATCH v2 1/8] KVM: VMX: Move the shared "IRQs off" exit handler(s) to common code Sean Christopherson
2026-08-27 10:48 ` Xiaoyao Li
2026-08-27 19:34 ` Sean Christopherson
2026-08-26 17:12 ` [PATCH v2 2/8] KVM: VMX: Move the shared NMI handler/trampoline " Sean Christopherson
2026-08-27 11:20 ` Xiaoyao Li
2026-08-26 17:12 ` [PATCH v2 3/8] KVM: VMX: Disallowing using to_vmx() in common VT code Sean Christopherson
2026-08-27 2:32 ` Huang, Kai
2026-08-27 11:21 ` Xiaoyao Li
2026-08-26 17:12 ` [PATCH v2 4/8] KVM: VMX: Rename posted interrupt prefixes from "vmx" to "vt" Sean Christopherson
2026-08-26 17:22 ` sashiko-bot
2026-08-26 18:38 ` Sean Christopherson
2026-08-27 2:35 ` Huang, Kai
2026-08-27 11:38 ` Xiaoyao Li
2026-08-27 14:17 ` Sean Christopherson
2026-08-26 17:12 ` [PATCH v2 5/8] KVM: VMX: Rename EPT violation handler prefix " Sean Christopherson
2026-08-27 2:36 ` Huang, Kai
2026-08-27 11:48 ` Xiaoyao Li
2026-08-26 17:12 ` [PATCH v2 6/8] KVM: VMX: Use dummy pseudo-overlay struct for to_vt() and vt_to_vcpu() Sean Christopherson
2026-08-27 11:58 ` Xiaoyao Li
2026-08-26 17:12 ` [PATCH v2 7/8] KVM: VMX: Move common VT getters/converters to common.h Sean Christopherson
2026-08-27 12:02 ` Xiaoyao Li
2026-08-26 17:12 ` [PATCH v2 8/8] KVM: VMX: Rename common exit info getters prefixes from "vmx" to "vt" Sean Christopherson
2026-08-27 12:09 ` Xiaoyao Li
2026-08-27 2:53 ` [PATCH v2 0/8] KVM: VMX: Harden against interpreting TDX vCPU as vcpu_vmx Huang, Kai
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260826171246.777729-1-seanjc@google.com \
--to=seanjc@google.com \
--cc=binbin.wu@linux.intel.com \
--cc=kai.huang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=xiaoyao.li@intel.com \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.