From: Sean Christopherson <seanjc@google.com>
To: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
syzbot+dd769db18693736eee89@syzkaller.appspotmail.com,
Sashiko Bot <sashiko-bot@kernel.org>
Subject: [PATCH v3 1/2] KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC
Date: Fri, 24 Jul 2026 10:34:24 -0700 [thread overview]
Message-ID: <20260724173425.278753-2-seanjc@google.com> (raw)
In-Reply-To: <20260724173425.278753-1-seanjc@google.com>
When getting a to-be-injected IRQ, don't WARN if the IRQ disappeared and
the VM has an in-kernel PIC, as the ExtINT handling that's routed through
KVM's virtual PIC is tracked per-VM, not per-vCPU. If another vCPU grabs
the IRQ, or deasserts the interrupt (which is level-triggered), then it's
both expected and "fine" for a
Keep the assert for split IRQCHIP VMs to help detect KVM bugs, as userspace
is responsible for routing ExtINT to the intended vCPU, i.e. once an ExtINT
is pending, it can't be cleared without holding the vCPU's mutex, and thus
false positives are impossible.
Fixes: bf672720e83c ("KVM: x86: check the kvm_cpu_get_interrupt result before using it")
Debugged-by: Alexander Potapenko <glider@google.com>
Reported-by: syzbot+dd769db18693736eee89@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=dd769db18693736eee89
Closes: https://lore.kernel.org/all/6a360fdf.871e809a.2d6dda.0000.GAE@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
---
arch/x86/kvm/irq.h | 16 ++++++++++++++++
arch/x86/kvm/vmx/nested.c | 4 +++-
arch/x86/kvm/x86.c | 4 +++-
3 files changed, 22 insertions(+), 2 deletions(-)
diff --git a/arch/x86/kvm/irq.h b/arch/x86/kvm/irq.h
index 1a84ea31e7fd..eeaf527cecc4 100644
--- a/arch/x86/kvm/irq.h
+++ b/arch/x86/kvm/irq.h
@@ -118,6 +118,22 @@ int kvm_cpu_has_extint(struct kvm_vcpu *v);
int kvm_cpu_get_extint(struct kvm_vcpu *v);
int kvm_cpu_get_interrupt(struct kvm_vcpu *v);
+static inline void kvm_warn_on_lost_irq(struct kvm_vcpu *vcpu)
+{
+ /*
+ * WARN if an IRQ was lost between detecting the IRQ and grabbing the
+ * IRQ for injection, unless it's possible the lost IRQ was due to one
+ * of the exceptional cases below.
+ *
+ * If the VM has an in-kernel PIC, the ExtINT handling that's routed
+ * through KVM's virtual PIC is tracked per-VM, not per-vCPU. If
+ * another vCPU grabs the IRQ, or deasserts the interrupt (which is
+ * level-triggered), then it's both expected and "fine" for an IRQ
+ * seemingly be "lost" from this vCPU's perspective.
+ */
+ WARN_ON_ONCE(!pic_in_kernel(vcpu->kvm));
+}
+
void kvm_inject_pending_timer_irqs(struct kvm_vcpu *vcpu);
void kvm_inject_apic_timer_irqs(struct kvm_vcpu *vcpu);
void kvm_apic_nmi_wd_deliver(struct kvm_vcpu *vcpu);
diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
index 0635e92471c8..c28a3ec4e4b7 100644
--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -4464,8 +4464,10 @@ static int vmx_check_nested_events(struct kvm_vcpu *vcpu)
}
irq = kvm_apic_has_interrupt(vcpu);
- if (WARN_ON_ONCE(irq < 0))
+ if (unlikely(irq < 0)) {
+ kvm_warn_on_lost_irq(vcpu);
goto no_vmexit;
+ }
/*
* If the IRQ is L2's PI notification vector, process posted
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 0626e835e9eb..e97b76b7794f 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -7686,10 +7686,12 @@ static int kvm_check_and_inject_events(struct kvm_vcpu *vcpu,
if (r) {
int irq = kvm_cpu_get_interrupt(vcpu);
- if (!WARN_ON_ONCE(irq == -1)) {
+ if (likely(irq != -1)) {
kvm_queue_interrupt(vcpu, irq, false);
kvm_x86_call(inject_irq)(vcpu, false);
WARN_ON(kvm_x86_call(interrupt_allowed)(vcpu, true) < 0);
+ } else {
+ kvm_warn_on_lost_irq(vcpu);
}
}
if (kvm_cpu_has_injectable_intr(vcpu))
--
2.55.0.229.g6434b31f56-goog
next prev parent reply other threads:[~2026-07-24 17:34 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-24 17:34 [PATCH v3 0/2] KVM: x86: Suppress false positives on "lost" IRQs Sean Christopherson
2026-07-24 17:34 ` Sean Christopherson [this message]
2026-07-24 17:49 ` [PATCH v3 1/2] KVM: x86: Don't WARN if IRQ disappears because it was cleared from the PIC sashiko-bot
2026-07-24 17:34 ` [PATCH v3 2/2] KVM: x86: Don't WARN if IRQ disappears when Xen emulation is enabled Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260724173425.278753-2-seanjc@google.com \
--to=seanjc@google.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=sashiko-bot@kernel.org \
--cc=syzbot+dd769db18693736eee89@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox