From: Vitaly Kuznetsov <vkuznets@redhat.com>
To: Nicolas Saenz Julienne <nsaenz@amazon.com>, kvm@vger.kernel.org
Cc: seanjc@google.com, pbonzini@redhat.com, tglx@linutronix.de,
mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com,
x86@kernel.org, hpa@zytor.com, graf@amazon.de, rkagan@amazon.de,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] KVM: x86: hyper-v: Don't auto-enable stimer during deserialization
Date: Mon, 16 Oct 2023 14:14:22 +0200 [thread overview]
Message-ID: <87sf6a9335.fsf@redhat.com> (raw)
In-Reply-To: <20231016095217.37574-1-nsaenz@amazon.com>
Nicolas Saenz Julienne <nsaenz@amazon.com> writes:
> By not honoring the 'stimer->config.enable' state during stimer
> deserialization we might introduce spurious timer interrupts. For
> example through the following events:
> - The stimer is configured in auto-enable mode.
> - The stimer's count is set and the timer enabled.
> - The stimer expires, an interrupt is injected.
> - We live migrate the VM.
> - The stimer config and count are deserialized, auto-enable is ON, the
> stimer is re-enabled.
> - The stimer expires right away, and injects an unwarranted interrupt.
>
> So let's not change the stimer's enable state if the MSR write comes
> from user-space.
>
> Fixes: 1f4b34f825e8 ("kvm/x86: Hyper-V SynIC timers")
> Signed-off-by: Nicolas Saenz Julienne <nsaenz@amazon.com>
> ---
> arch/x86/kvm/hyperv.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/arch/x86/kvm/hyperv.c b/arch/x86/kvm/hyperv.c
> index 7c2dac6824e2..9f1deb6aa131 100644
> --- a/arch/x86/kvm/hyperv.c
> +++ b/arch/x86/kvm/hyperv.c
> @@ -729,7 +729,7 @@ static int stimer_set_count(struct kvm_vcpu_hv_stimer *stimer, u64 count,
> stimer->count = count;
> if (stimer->count == 0)
> stimer->config.enable = 0;
Can this branch be problematic too? E.g. if STIMER[X]_CONFIG is
deserialized after STIMER[X]_COUNT we may erroneously reset 'enable' to
0, right? In fact, when MSRs are ordered like this:
#define HV_X64_MSR_STIMER0_CONFIG 0x400000B0
#define HV_X64_MSR_STIMER0_COUNT 0x400000B1
I would guess that we always de-serialize 'config' first. With
auto-enable, the timer will get enabled when writing 'count' but what
happens in other cases?
Maybe the whole block needs to go under 'if (!host)' instead?
> - else if (stimer->config.auto_enable)
> + else if (stimer->config.auto_enable && !host)
> stimer->config.enable = 1;
>
> if (stimer->config.enable)
--
Vitaly
next prev parent reply other threads:[~2023-10-16 12:15 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-10-16 9:52 [PATCH] KVM: x86: hyper-v: Don't auto-enable stimer during deserialization Nicolas Saenz Julienne
2023-10-16 12:14 ` Vitaly Kuznetsov [this message]
2023-10-16 12:42 ` Nicolas Saenz Julienne
2023-10-16 16:27 ` Sean Christopherson
2023-10-16 17:04 ` Nicolas Saenz Julienne
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87sf6a9335.fsf@redhat.com \
--to=vkuznets@redhat.com \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=graf@amazon.de \
--cc=hpa@zytor.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=nsaenz@amazon.com \
--cc=pbonzini@redhat.com \
--cc=rkagan@amazon.de \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.