All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tina Zhang <zhang_wei@open-hieco.net>
To: Sean Christopherson <seanjc@google.com>,
	Paolo Bonzini <pbonzini@redhat.com>,
	kvm@vger.kernel.org
Cc: Shuah Khan <shuah@kernel.org>,
	zhouyanjing@hygon.cn, linux-kselftest@vger.kernel.org,
	linux-kernel@vger.kernel.org, Jim Mattson <jmattson@google.com>,
	Tina Zhang <zhang_wei@open-hieco.net>
Subject: [PATCH v3 0/9] KVM: nSVM: Enable DecodeAssists for nested guests
Date: Thu, 30 Jul 2026 20:08:03 +0800	[thread overview]
Message-ID: <cover.1785411877.git.zhang_wei@open-hieco.net> (raw)

The SVM DecodeAssists feature provides decode state for selected
VM-Exits.  KVM currently does not expose this feature to L1.  Some L1
hypervisors may therefore treat the platform's SVM support as
incomplete.

In practice, this was observed with Hyper-V running on top of KVM.
Hyper-V appears to require DecodeAssists before enabling nested SVM for
its guests.  Virtualizing the feature lets users enable Hyper-V
virtualization features inside a Windows VM when needed, e.g. to run
QEMU/KVM in WSL.  Without DecodeAssists, Hyper-V does not enable nested
SVM because DecodeAssists is missing from KVM's virtual SVM model.

Virtualize DecodeAssists for nested SVM.  Propagate instruction bytes
from VMCB02 for hardware-originated data #NPF and intercepted data #PF
VM-Exits.  For KVM-generated exits, synthesize the architectural
EXITINFO state and use matching bytes from the emulator when available,
fetching missing bytes through L2's address translation only as a
fallback.  Do not use the fallback for SEV guests, whose encrypted
memory cannot provide plaintext instruction bytes to KVM.

The selftest coverage in this version is intentionally broad and may be
more extensive than necessary.  Some redundant cases can be removed in
a later revision, but for now the series provides a comprehensive test
set for users to exercise hardware-reflected, KVM-synthesized,
userspace-injected, and boundary cases.

The selftest has been run with kvm.force_emulation_prefix both disabled
and enabled.

Changes since v2:
- Rebase onto kvm-x86/next.
- Track hardware-provided instruction bytes independently of the VMCB02
  exit code, and preserve the bytes when L0 handles an intercepted #PF
  before reflecting it to L1.
- Select the instruction-byte source using host-owned VMCB02 state
  instead of control fields in guest-owned VMCB12.
- Record whether a queued #PF VM-Exit has a matching emulator context,
  so userspace-injected #PF exits do not consume stale emulator bytes.
- Stop fallback instruction fetches at noncanonical addresses and at the
  32-bit linear-address boundary.
- Extend the selftest with regression coverage for replacing a hardware
  #NPF with a synthesized #NPF and for userspace-injected #PF during
  emulation, and harden its page layout and ucall handling.

v2:
https://lore.kernel.org/r/cover.1783999988.git.zhang_wei@open-hieco.net

Tina Zhang (9):
  KVM: x86: Add helper to provide intercept linear addresses
  KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts
  KVM: nSVM: Track hardware-provided instruction bytes
  KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12
  KVM: x86: Track emulator-originated nested #PF VM-Exits
  KVM: nSVM: Use emulator bytes for synthesized nested #NPF/#PF
  KVM: nSVM: Fetch missing DecodeAssist bytes for synthesized #NPF/#PF
  KVM: nSVM: Advertise DecodeAssists to L1
  KVM: selftests: Add nested SVM DecodeAssists test

 arch/x86/include/asm/kvm_host.h               |   1 +
 arch/x86/kvm/emulate.c                        |  29 +-
 arch/x86/kvm/kvm_emulate.h                    |   1 +
 arch/x86/kvm/svm/nested.c                     | 181 +++-
 arch/x86/kvm/svm/svm.c                        |  72 +-
 arch/x86/kvm/svm/svm.h                        |  20 +-
 arch/x86/kvm/x86.c                            |  33 +-
 tools/testing/selftests/kvm/Makefile.kvm      |   1 +
 .../selftests/kvm/include/x86/processor.h     |   1 +
 .../kvm/x86/svm_nested_decode_assists_test.c  | 791 ++++++++++++++++++
 10 files changed, 1100 insertions(+), 30 deletions(-)
 create mode 100644 tools/testing/selftests/kvm/x86/svm_nested_decode_assists_test.c


base-commit: 567329869b9c75c9d3df74b35fe10af9b51c479d
-- 
2.43.7

             reply	other threads:[~2026-07-30 12:08 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30 12:08 Tina Zhang [this message]
2026-07-30 12:08 ` [PATCH v3 1/9] KVM: x86: Add helper to provide intercept linear addresses Tina Zhang
2026-07-30 12:38   ` sashiko-bot
2026-07-30 12:08 ` [PATCH v3 2/9] KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts Tina Zhang
2026-07-30 12:30   ` sashiko-bot
2026-07-30 12:08 ` [PATCH v3 3/9] KVM: nSVM: Track hardware-provided instruction bytes Tina Zhang
2026-07-30 12:34   ` sashiko-bot
2026-07-30 12:08 ` [PATCH v3 4/9] KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12 Tina Zhang
2026-07-30 12:08 ` [PATCH v3 5/9] KVM: x86: Track emulator-originated nested #PF VM-Exits Tina Zhang
2026-07-30 12:08 ` [PATCH v3 6/9] KVM: nSVM: Use emulator bytes for synthesized nested #NPF/#PF Tina Zhang
2026-07-30 12:08 ` [PATCH v3 7/9] KVM: nSVM: Fetch missing DecodeAssist bytes for synthesized #NPF/#PF Tina Zhang
2026-07-30 12:31   ` sashiko-bot
2026-07-30 12:08 ` [PATCH v3 8/9] KVM: nSVM: Advertise DecodeAssists to L1 Tina Zhang
2026-07-30 12:33   ` sashiko-bot
2026-07-30 12:08 ` [PATCH v3 9/9] KVM: selftests: Add nested SVM DecodeAssists test Tina Zhang
2026-07-30 12:34   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1785411877.git.zhang_wei@open-hieco.net \
    --to=zhang_wei@open-hieco.net \
    --cc=jmattson@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    --cc=shuah@kernel.org \
    --cc=zhouyanjing@hygon.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.