From: sashiko-bot@kernel.org
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: linux-perf-users@vger.kernel.org,
linux-trace-kernel@vger.kernel.org, kvm@vger.kernel.org
Subject: Re: [PATCH v16 02/13] KVM: x86: Prevent host DR7 debug register leak into guest OS on NMI
Date: Mon, 14 Sep 2026 13:23:32 +0000 [thread overview]
Message-ID: <20260914132333.1D2A31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <178939019982.94750.4441254006258061798.stgit@devnote2>
> From: Masami Hiramatsu (Google) <mhiramat@kernel.org>
>
> When KVM enters a guest OS, host hardware breakpoints are disabled
> before running the guest. However, an NMI can occur during guest
> execution, where local_db_save() or arch_install_hw_breakpoint()
> can be invoked.
>
> In particular, if local_db_save() or arch_install_hw_breakpoint()
> is executed from NMI, hardware DR7 can be modified or restored with
> host breakpoint settings, leaking host breakpoints into the guest OS
> or clobbering the guest's debug registers.
>
> Introduce a per-CPU flag, cpu_dr_in_guest, to indicate that the CPU
> is executing in guest mode. Set this flag in vcpu_enter_guest()
> during entering the guest with disabling host breakpoints.
> If this flag is set, local_db_save() and local_db_restore() return
> immediately, and arch_install_hw_breakpoint() returns an error.
> In addition, protect cpu_dr_in_guest in within_cpu_entry() to
> prevent recursive #DB exceptions.
>
> Fixes: f85d40160691 ("KVM: X86: Disable hardware breakpoints unconditionally before kvm_x86->run()")
> Assisted-by: Antigravity:gemini-3.8-flash
> Signed-off-by: Masami Hiramatsu (Google) <mhiramat@kernel.org>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review · https://sashiko.dev/#/patchset/178939017565.94750.9431053336761330458.stgit@devnote2?part=2
next prev parent reply other threads:[~2026-09-14 13:23 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-14 12:49 [PATCH v16 00/13] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-09-14 12:49 ` [PATCH v16 01/13] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-09-14 13:04 ` sashiko-bot
2026-09-14 12:49 ` [PATCH v16 02/13] KVM: x86: Prevent host DR7 debug register leak into guest OS on NMI Masami Hiramatsu (Google)
2026-09-14 13:23 ` sashiko-bot [this message]
2026-09-14 14:35 ` Sean Christopherson
2026-09-16 23:45 ` Masami Hiramatsu
2026-09-14 12:50 ` [PATCH v16 03/13] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-09-14 13:31 ` sashiko-bot
2026-09-14 12:50 ` [PATCH v16 04/13] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-14 13:41 ` sashiko-bot
2026-09-14 12:50 ` [PATCH v16 05/13] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-14 13:52 ` sashiko-bot
2026-09-14 12:50 ` [PATCH v16 06/13] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-09-14 14:14 ` sashiko-bot
2026-09-14 12:50 ` [PATCH v16 07/13] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-09-14 14:19 ` sashiko-bot
2026-09-14 12:51 ` [PATCH v16 08/13] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-09-14 14:30 ` sashiko-bot
2026-09-21 9:21 ` Masami Hiramatsu
2026-09-14 12:51 ` [PATCH v16 09/13] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-09-14 14:35 ` sashiko-bot
2026-09-14 12:51 ` [PATCH v16 10/13] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-09-14 14:58 ` sashiko-bot
2026-09-22 2:39 ` Masami Hiramatsu
2026-09-14 12:51 ` [PATCH v16 11/13] selftests: tracing: Add wprobe trigger testcase Masami Hiramatsu (Google)
2026-09-14 15:05 ` sashiko-bot
2026-09-14 12:51 ` [PATCH v16 12/13] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-09-14 15:12 ` sashiko-bot
2026-09-14 12:52 ` [PATCH v16 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-09-14 15:19 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260914132333.1D2A31F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mhiramat@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.