All of lore.kernel.org
 help / color / mirror / Atom feed
From: Tina Zhang <zhang_wei@open-hieco.net>
To: Sean Christopherson <seanjc@google.com>,
	Jim Mattson <jmattson@google.com>,
	kvm@vger.kernel.org
Cc: Paolo Bonzini <pbonzini@redhat.com>,
	Shuah Khan <shuah@kernel.org>,
	zhouyanjing@hygon.cn, linux-kselftest@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: [PATCH v6 0/8] KVM: nSVM: Enable DecodeAssists for nested guests
Date: Sun, 13 Sep 2026 14:43:40 +0800	[thread overview]
Message-ID: <cover.1789281096.git.zhang_wei@open-hieco.net> (raw)

The SVM DecodeAssists feature provides decode state for selected
VM-Exits.  KVM currently does not expose this feature to L1.  Some L1
hypervisors may therefore treat the platform's SVM support as
incomplete.

In practice, this was observed with Hyper-V running on top of KVM.
Hyper-V appears to require DecodeAssists before enabling nested SVM for
its guests.  Virtualizing the feature lets users enable Hyper-V
virtualization features inside a Windows VM when needed, e.g. to run
QEMU/KVM in WSL.

Virtualize both parts of DecodeAssists for nested SVM.  For emulated
MOV CR/DR, INTn, INVLPG, and related intercepts, populate EXITINFO1 as
specified by the architecture.  INVLPGA's address remains in saved guest
rAX.  Leave EXITINFO1 unchanged when DecodeAssists is not exposed.

For data #NPF and intercepted data #PF exits, propagate current hardware
instruction bytes when available.  For an emulator-generated #NPF, keep
the bytes used to decode the instruction and fetch any missing tail.
Queued #PF exits, including userspace-injected exceptions, use an
on-demand fetch from the current L2 CS:RIP.  Instruction-fetch faults
report zero bytes, and SEV guests do not use the memory-fetch fallback.

The selftest covers synthesized EXITINFO1, hardware and synthesized
instruction bytes, and truncated fetches.  Two MMIO cases check that
emulator-generated #NPF exits retain cached bytes after instruction
memory changes, while userspace-injected #PF exits do not reuse an old
emulator cache after MMIO completion.

The updated selftest passed with kvm.force_emulation_prefix both disabled
and enabled in an isolated VM using the v6 implementation.  SEV paths
have not been tested.

Changes since v5:
- Rebase onto kvm-x86/next at the base commit listed below.
- Reuse __linearize() for INVLPG and name the instruction-info field
  invlpg_linear_addr.
- Integrate EXITINFO1 generation into svm_check_intercept() instead of
  using a separate switch.  Leave undefined EXITINFO2 fields unchanged.
- Invalidate instruction bytes by clearing only insn_len.  Leave the
  VMCB12 fields untouched when DecodeAssists is not exposed, and stop
  clearing unused instruction-byte buffer tails.
- Remove the extra argument to nested_svm_exit_handled(); opcode exits
  are excluded by the instruction-byte applicability check.
- Replace the synthesized-byte staging buffer with direct VMCB02
  updates, and add an emulator accessor instead of inspecting the fetch
  cache in nSVM.  Reuse the cache only for the current emulator exception.
- Add the complete fallback before cache reuse so that no intermediate
  patch depends on a later patch to fetch missing bytes.  Reuse the
  generic guest-memory read helper with instruction-fetch permissions,
  checking address boundaries between page-sized chunks.
- Extend the MOVSB regression test to modify the opcode while MMIO is
  pending, restore userspace-injected #PF coverage, and give the MMIO
  source its own page.  Both MMIO cases run without forced emulation.

Previous versions:
v5:
https://lore.kernel.org/r/20260824123954.315112-1-zhang_wei@open-hieco.net
v4:
https://lore.kernel.org/r/cover.1787116250.git.zhang_wei@open-hieco.net
v3:
https://lore.kernel.org/r/cover.1785411877.git.zhang_wei@open-hieco.net
v2:
https://lore.kernel.org/r/cover.1783999988.git.zhang_wei@open-hieco.net
v1:
https://lore.kernel.org/r/20260629125205.52394-1-zhang_wei@open-hieco.net

Tina Zhang (8):
  KVM: x86: Provide INVLPG linear address to intercept handlers
  KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts
  KVM: nSVM: Track valid hardware DecodeAssist bytes
  KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12
  KVM: nSVM: Fetch DecodeAssist bytes for synthesized faults
  KVM: nSVM: Use emulator bytes for synthesized nested #NPF
  KVM: nSVM: Advertise DecodeAssists to L1
  KVM: selftests: Add nested SVM DecodeAssists test

 arch/x86/kvm/cpuid.c                          |   1 +
 arch/x86/kvm/emulate.c                        |  40 ++
 arch/x86/kvm/kvm_emulate.h                    |   4 +
 arch/x86/kvm/svm/nested.c                     | 163 +++++-
 arch/x86/kvm/svm/svm.c                        |  34 +-
 arch/x86/kvm/svm/svm.h                        |   3 +
 arch/x86/kvm/x86.c                            |  23 +-
 arch/x86/kvm/x86.h                            |   3 +
 tools/testing/selftests/kvm/Makefile.kvm      |   1 +
 .../selftests/kvm/include/x86/processor.h     |   1 +
 .../kvm/x86/svm_nested_decode_assists_test.c  | 547 ++++++++++++++++++
 11 files changed, 814 insertions(+), 6 deletions(-)
 create mode 100644 tools/testing/selftests/kvm/x86/svm_nested_decode_assists_test.c


base-commit: 76671054f9a1ff6abb976583cd8da37650acdc97
-- 
2.43.7

             reply	other threads:[~2026-09-13  6:44 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13  6:43 Tina Zhang [this message]
2026-09-13  6:43 ` [PATCH v6 1/8] KVM: x86: Provide INVLPG linear address to intercept handlers Tina Zhang
2026-09-14 18:23   ` Jim Mattson
2026-09-16  0:25     ` Tina Zhang
2026-09-16 19:06       ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 2/8] KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts Tina Zhang
2026-09-14 18:59   ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 3/8] KVM: nSVM: Track valid hardware DecodeAssist bytes Tina Zhang
2026-09-14 19:17   ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 4/8] KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12 Tina Zhang
2026-09-14 19:40   ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 5/8] KVM: nSVM: Fetch DecodeAssist bytes for synthesized faults Tina Zhang
2026-09-14 21:16   ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 6/8] KVM: nSVM: Use emulator bytes for synthesized nested #NPF Tina Zhang
2026-09-14 21:34   ` Jim Mattson
2026-09-13  6:43 ` [PATCH v6 7/8] KVM: nSVM: Advertise DecodeAssists to L1 Tina Zhang
2026-09-13  6:43 ` [PATCH v6 8/8] KVM: selftests: Add nested SVM DecodeAssists test Tina Zhang
2026-09-14 22:33   ` Jim Mattson
2026-09-17  8:22     ` Tina Zhang
2026-09-17 14:30       ` Jim Mattson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1789281096.git.zhang_wei@open-hieco.net \
    --to=zhang_wei@open-hieco.net \
    --cc=jmattson@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    --cc=shuah@kernel.org \
    --cc=zhouyanjing@hygon.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.