From: sashiko-bot@kernel.org
To: "David Woodhouse" <dwmw2@infradead.org>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v7 11/36] KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling
Date: Tue, 28 Jul 2026 15:11:09 +0000 [thread overview]
Message-ID: <20260728151110.33DD21F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260728144954.355376-12-dwmw2@infradead.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [Critical] Uninitialized kernel_ns and host_tsc variables are used on 32-bit builds if use_master_clock is true.
- [High] The fallback clock path reads rdtsc() after preemption is re-enabled, causing mismatched TSC frequency calculations and guest clock corruption.
--
--- Patch [11]: [PATCH v7 11/36] KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling ---
commit a9ced800a4cffa309e689174fd612acf127799a3
Author: David Woodhouse <dwmw@amazon.co.uk>
KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling
This commit restructures kvm_guest_time_update to simplify the TSC catchup
adjustment by ensuring kernel_ns and host_tsc are always now during catchup,
then swapping in the master clock reference values afterward.
> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index 27f2f02bd5f40..faeb2d7b19a48 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c
> @@ -1776,45 +1776,60 @@ static void kvm_setup_guest_pvclock(struct pvclock_vcpu_time_info *ref_hv_clock,
> int kvm_guest_time_update(struct kvm_vcpu *v)
> {
[ ... ]
> - kernel_ns = 0;
> - host_tsc = 0;
> -
> /*
> * If the host uses TSC clock, then passthrough TSC as stable
> * to the guest.
> */
> do {
> seq = read_seqcount_begin(&ka->pvclock_sc);
> +
> use_master_clock = ka->use_master_clock;
> +
> + /*
> + * The TSC read and the call to get_cpu_tsc_khz() must happen
> + * on the same CPU.
> + */
> + get_cpu();
> +
> + tgt_tsc_hz = (u64)get_cpu_tsc_khz() * HZ_PER_KHZ;
> +
> +#ifdef CONFIG_X86_64
> + if (use_master_clock &&
> + !kvm_get_time_and_clockread(&kernel_ns, &host_tsc) &&
> + !read_seqcount_retry(&ka->pvclock_sc, seq))
> + use_master_clock = false;
> +#endif
> +
> + put_cpu();
> +
> + if (use_master_clock) {
> - host_tsc = ka->master_cycle_now;
> - kernel_ns = ka->master_kernel_ns;
> + master_host_tsc = ka->master_cycle_now;
> + master_kernel_ns = ka->master_kernel_ns;
> + } else {
> + local_irq_disable();
> + host_tsc = rdtsc();
[Severity: High]
Because put_cpu() re-enables preemption, could the vCPU thread be preempted
and migrated to another physical CPU before local_irq_disable() and rdtsc()
are called in this fallback path?
If migration occurs here, host_tsc might be read on a different CPU than
where tgt_tsc_hz was calculated.
> + kernel_ns = get_kvmclock_base_ns();
> + local_irq_enable();
> }
[ ... ]
> @@ -1824,17 +1839,32 @@ int kvm_guest_time_update(struct kvm_vcpu *v)
> * entry to avoid unknown leaps of TSC even when running
> * again on the same CPU. This may cause apparent elapsed
> * time to disappear, and the guest to stand still or run
> - * very slowly.
> + * very slowly.
> */
> if (vcpu->tsc_catchup) {
> - u64 tsc = compute_guest_tsc(v, kernel_ns);
> - if (tsc > tsc_timestamp) {
> - adjust_tsc_offset_guest(v, tsc - tsc_timestamp);
> - tsc_timestamp = tsc;
> - }
> + s64 adjustment;
> +
> + /*
> + * Calculate the delta between what the guest TSC *should* be
> + * and what it actually is according to kvm_read_l1_tsc().
> + */
> + adjustment = compute_guest_tsc(v, kernel_ns) -
> + kvm_read_l1_tsc(v, host_tsc);
[Severity: Critical]
On 32-bit builds, will kernel_ns and host_tsc remain uninitialized when
use_master_clock is true?
The original 0-initializations for kernel_ns and host_tsc were removed by
this patch. Their new initialization via kvm_get_time_and_clockread() is
guarded by CONFIG_X86_64.
When vcpu->tsc_catchup is set on 32-bit builds, it seems this would pass
uninitialized stack variables to compute_guest_tsc() and kvm_read_l1_tsc()
for the adjustment calculation.
> + if (adjustment > 0)
> + adjust_tsc_offset_guest(v, adjustment);
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260728144954.355376-1-dwmw2@infradead.org?part=11
next prev parent reply other threads:[~2026-07-28 15:11 UTC|newest]
Thread overview: 53+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 14:39 [PATCH v7 00/36] Cleaning up the KVM clock mess David Woodhouse
2026-07-28 14:39 ` [PATCH v7 01/36] KVM: x86: Improve accuracy of KVM clock when TSC scaling is in force David Woodhouse
2026-07-28 14:39 ` [PATCH v7 02/36] KVM: x86: Explicitly disable TSC scaling without CONSTANT_TSC David Woodhouse
2026-07-28 14:39 ` [PATCH v7 03/36] KVM: x86: Activate master clock immediately on vCPU creation David Woodhouse
2026-07-28 15:17 ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 04/36] KVM: x86: Avoid NTP frequency skew for KVM clock on 32-bit host David Woodhouse
2026-07-28 14:39 ` [PATCH v7 05/36] KVM: x86: Fold __get_kvmclock() into get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 06/36] KVM: x86: Drop CPU pinning in get_kvmclock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 07/36] KVM: x86: Restructure get_kvmclock() David Woodhouse
2026-07-28 15:11 ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 08/36] KVM: x86: Fix KVM clock precision in get_kvmclock() with TSC scaling David Woodhouse
2026-07-28 14:39 ` [PATCH v7 09/36] KVM: x86: Use get_kvmclock() in kvm_get_wall_clock_epoch() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 10/36] KVM: x86: Fix compute_guest_tsc() to handle negative time deltas David Woodhouse
2026-07-28 14:39 ` [PATCH v7 11/36] KVM: x86: Restructure kvm_guest_time_update() for TSC upscaling David Woodhouse
2026-07-28 15:11 ` sashiko-bot [this message]
2026-07-28 14:39 ` [PATCH v7 12/36] KVM: x86: Simplify and comment kvm_get_time_scale() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 13/36] KVM: x86: Remove implicit rdtsc() from kvm_compute_l1_tsc_offset() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 14/36] KVM: x86: Improve synchronization in kvm_synchronize_tsc() David Woodhouse
2026-07-28 15:08 ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 15/36] KVM: x86: Kill last_tsc_{nsec,write,offset} fields David Woodhouse
2026-07-28 15:09 ` sashiko-bot
2026-07-28 14:39 ` [PATCH v7 16/36] KVM: x86: Replace nr_vcpus_matched_tsc count with all_vcpus_matched_tsc bool David Woodhouse
2026-07-28 14:39 ` [PATCH v7 17/36] KVM: x86: Allow KVM master clock mode when TSCs are offset from each other David Woodhouse
2026-07-28 14:39 ` [PATCH v7 18/36] KVM: x86: Factor out kvm_use_master_clock() David Woodhouse
2026-07-28 14:39 ` [PATCH v7 19/36] KVM: x86: Avoid gratuitous global clock updates David Woodhouse
2026-07-28 14:40 ` [PATCH v7 20/36] KVM: x86/xen: Prevent runstate times from becoming negative David Woodhouse
2026-07-28 15:15 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 21/36] KVM: x86: Avoid redundant masterclock updates from multiple vCPUs David Woodhouse
2026-07-28 15:23 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 22/36] KVM: x86: Remove runtime Xen TSC frequency CPUID update David Woodhouse
2026-07-28 15:18 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 23/36] KVM: x86: Re-synchronize TSC after KVM_SET_TSC_KHZ David Woodhouse
2026-07-28 15:19 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 24/36] KVM: x86: Use ktime_get_snapshot_id() for master clock David Woodhouse
2026-07-28 15:21 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 25/36] KVM: x86: Compute kvmclock base without pvclock_gtod_data David Woodhouse
2026-07-28 14:40 ` [PATCH v7 26/36] KVM: x86: Cache host vclock_mode for masterclock eligibility checks David Woodhouse
2026-07-28 15:26 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 27/36] KVM: x86: Remove pvclock_gtod_data and private timekeeping code David Woodhouse
2026-07-28 15:25 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 28/36] KVM: x86: Activate master clock from kvm_arch_init_vm() David Woodhouse
2026-07-28 15:31 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 29/36] UAPI: x86: Move pvclock-abi to UAPI for x86 platforms David Woodhouse
2026-07-28 14:40 ` [PATCH v7 30/36] KVM: selftests: Use UAPI pvclock-abi.h in xen_shinfo_test David Woodhouse
2026-07-28 14:40 ` [PATCH v7 31/36] KVM: x86: Add KVM_[GS]ET_CLOCK_GUEST for accurate KVM clock migration David Woodhouse
2026-07-28 14:40 ` [PATCH v7 32/36] KVM: x86: Add KVM_VCPU_TSC_SCALE and fix the documentation on TSC migration David Woodhouse
2026-07-28 15:26 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 33/36] KVM: selftests: Add KVM/PV clock selftest to prove timer correction David Woodhouse
2026-07-28 14:40 ` [PATCH v7 34/36] KVM: selftests: Add master clock offset test David Woodhouse
2026-07-28 15:22 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 35/36] KVM: selftests: Add Xen/generic CPUID timing leaf test David Woodhouse
2026-07-28 15:23 ` sashiko-bot
2026-07-28 14:40 ` [PATCH v7 36/36] KVM: selftests: Add Xen runstate migration test David Woodhouse
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728151110.33DD21F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dwmw2@infradead.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox