From: sashiko-bot@kernel.org
To: "Chang S. Bae" <chang.seok.bae@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v8 09/20] KVM: nVMX: Propagate extended instruction information
Date: Wed, 30 Sep 2026 21:52:54 +0000 [thread overview]
Message-ID: <20260930215254.DC6D61F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930210750.1487547-10-chang.seok.bae@intel.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kvm: nvmx: missing eVMCS mapping for EXTENDED_INSTRUCTION_INFO causes host DoS
--
commit 50ba47ea51df9d3191678e833e5b9efb01e769c0
Author: Chang S. Bae <chang.seok.bae@intel.com>
KVM: nVMX: Propagate extended instruction information
This commit defines the new extended_instruction_info field in struct vmcs12
and propagates it to nested VMX. The propagation is gated on the guest APX
enumeration.
Link: https://lore.kernel.org/aRvOSnaUt1E+%2FpkC@intel.com
> diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
> index 7229934c38bb1..69302b806a98e 100644
> --- a/arch/x86/kvm/vmx/nested.c
> +++ b/arch/x86/kvm/vmx/nested.c
> @@ -4773,6 +4773,12 @@ static void prepare_vmcs12(struct kvm_vcpu *vcpu, struct vmcs12 *vmcs12,
> vmcs12->vm_exit_intr_info = exit_intr_info;
> vmcs12->vm_exit_instruction_len = exit_insn_len;
> vmcs12->vmx_instruction_info = vmcs_read32(VMX_INSTRUCTION_INFO);
> + /*
> + * The APX enumeration guarantees the presence of the extended
> + * fields. This CPUID bit alone is sufficient to rely on it.
> + */
> + if (guest_cpu_cap_has(vcpu, X86_FEATURE_APX))
> + vmcs12->extended_instruction_info = vmcs_read64(EXTENDED_INSTRUCTION_INFO);
[Severity: High]
Does this unconditional read cause an issue when KVM is running as an L1
hypervisor on top of Hyper-V?
When eVMCS is in use, vmcs_read64() transparently redirects to the eVMCS read
handler. If EXTENDED_INSTRUCTION_INFO is not mapped in vmcs_field_to_evmcs_1
for eVMCS v1, evmcs_field_offset() will return -ENOENT.
This missing mapping leads to a host-side warning in get_evmcs_offset()
firing on nested exits:
WARN_ONCE(offset < 0, "accessing unsupported EVMCS field %lx\n", field);
Because an unprivileged L2 guest could easily trigger these exits, could this
be used as a host-side denial of service in environments where panic_on_warn=1
is enabled?
>
> /*
> * According to spec, there's no need to store the guest's
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930210750.1487547-1-chang.seok.bae@intel.com?part=9
next prev parent reply other threads:[~2026-09-30 21:52 UTC|newest]
Thread overview: 38+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 21:07 [PATCH v8 00/20] KVM: x86: Enable APX for guests Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 01/20] KVM: x86: Extend VCPU registers for EGPRs Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 02/20] KVM: VMX: Save guest EGPRs in VCPU cache Chang S. Bae
2026-09-30 21:56 ` sashiko-bot
2026-10-01 19:57 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 03/20] KVM: x86: Support APX state for XSAVE ABI Chang S. Bae
2026-09-30 21:57 ` sashiko-bot
2026-10-01 19:58 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 04/20] KVM: VMX: Refactor VMX instruction information access Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 05/20] KVM: VMX: Refactor instruction information decoding Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 06/20] KVM: VMX: Remove unused control-register access defines Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 07/20] KVM: VMX: Refactor register index retrieval from exit qualification Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 08/20] KVM: VMX: Support instruction information extension Chang S. Bae
2026-09-30 21:52 ` sashiko-bot
2026-10-01 19:58 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 09/20] KVM: nVMX: Propagate extended instruction information Chang S. Bae
2026-09-30 21:52 ` sashiko-bot [this message]
2026-10-01 19:58 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 10/20] KVM: x86: Support EGPR accessing and tracking for emulator Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 11/20] KVM: x86: Handle EGPR index and REX2-incompatible opcodes Chang S. Bae
2026-09-30 21:47 ` sashiko-bot
2026-10-01 19:59 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 12/20] KVM: x86: Support REX2-prefixed opcode decode Chang S. Bae
2026-09-30 21:54 ` sashiko-bot
2026-10-01 19:59 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 13/20] KVM: x86: Reject EVEX-prefixed instructions Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 14/20] KVM: x86: Move KVM_SUPPORTED_{XCR0,XSS} into kvm_x86_vendor_init() Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 15/20] KVM: x86: Guard valid XCR0.APX settings Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 16/20] KVM: x86: Add APX to supported XCR0 Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 17/20] KVM: x86: Expose APX foundation feature to userspace Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 18/20] KVM: x86: Expose APX sub-features " Chang S. Bae
2026-09-30 21:43 ` sashiko-bot
2026-10-01 20:00 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 19/20] KVM: x86: selftests: Add APX state and ABI test Chang S. Bae
2026-09-30 21:48 ` sashiko-bot
2026-10-01 19:59 ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 20/20] KVM: x86: selftests: Add APX state handling and XCR0 sanity checks Chang S. Bae
2026-10-01 20:29 ` [PATCH v8 00/20] KVM: x86: Enable APX for guests Chang S. Bae
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930215254.DC6D61F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=chang.seok.bae@intel.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.