From: sashiko-bot@kernel.org
To: "Vitaly Kuznetsov" <vkuznets@redhat.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS
Date: Fri, 14 Aug 2026 16:31:05 +0000 [thread overview]
Message-ID: <20260814163105.BDEC31F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260814162221.2144473-5-vkuznets@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] The hardcoded `VMPTRLD_INSN_SIZE` of 5 bytes is brittle because `vmptrld` is executed using an inline assembly memory operand constraint (`"m"`), which results in a variable-sized instruction depending on compiler optimizations and register allocation.
--
--- Patch [4]: [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS ---
commit 80c84d1f71bebfd26712329b4fe8a487216ec3fb
Author: Vitaly Kuznetsov <vkuznets@redhat.com>
KVM: selftests: Check VMPTRLD with active eVMCS
Check that VMPTRLD when eVMCS is active results in #UD. This matches
genuine Hyper-V's behavior.
> diff --git a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> index 88262ddf7fcb2..6a6d940a78918 100644
> --- a/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> +++ b/tools/testing/selftests/kvm/x86/hyperv_evmcs.c
> @@ -18,12 +18,16 @@
> #include "hyperv.h"
> #include "vmx.h"
>
> +#define VMLAUNCH_INSN_SIZE 3
> +#define VMPTRLD_INSN_SIZE 5
> +
> static int ud_count;
> +static int ud_insn_skip_size;
>
> static void guest_ud_handler(struct ex_regs *regs)
> {
> ud_count++;
> - regs->rip += 3; /* VMLAUNCH */
> + regs->rip += ud_insn_skip_size;
> }
[ ... ]
> @@ -182,10 +186,15 @@ void guest_code(struct vmx_pages *vmx_pages, struct hyperv_test_pages *hv_pages,
> GUEST_ASSERT(vmreadz(VM_EXIT_REASON) == EXIT_REASON_VMCALL);
> GUEST_SYNC(11);
>
> + ud_insn_skip_size = VMPTRLD_INSN_SIZE;
> + vmptrld(hv_pages->enlightened_vmcs_gpa);
[Severity: Medium]
Could this hardcoded instruction size lead to guest instruction stream
corruption?
The vmptrld() inline assembly in include/x86/vmx.h uses a memory operand
constraint ("m") for the physical address:
static inline int vmptrld(u64 vmcs_pa)
{
u8 ret;
__asm__ __volatile__ ("vmptrld %[pa]; setna %[ret]"
: [ret]"=rm"(ret)
: [pa]"m"(vmcs_pa)
: "cc", "memory");
...
}
Depending on compiler optimizations and register allocation, the resulting
instruction might not be exactly 5 bytes in size (for example, it could be 4
or 7 bytes depending on the chosen addressing mode).
Since guest_ud_handler() unconditionally advances regs->rip by
ud_insn_skip_size, if the generated instruction length does not match
VMPTRLD_INSN_SIZE, resuming the guest could land in the middle of an
instruction and cause #GP faults or infinite #UD loops.
> + GUEST_ASSERT(ud_count == 1);
> +
> /* Try enlightened vmptrld with an incorrect GPA */
> + ud_insn_skip_size = VMLAUNCH_INSN_SIZE;
> evmcs_vmptrld(0xdeadbeef, hv_pages->enlightened_vmcs);
> GUEST_ASSERT(vmlaunch());
> - GUEST_ASSERT(ud_count == 1);
> + GUEST_ASSERT(ud_count == 2);
> GUEST_DONE();
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260814162221.2144473-1-vkuznets@redhat.com?part=4
prev parent reply other threads:[~2026-08-14 16:31 UTC|newest]
Thread overview: 11+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-14 16:22 [PATCH 0/4] KVM: nVMX: Adjust VMPTRLD/VMPTRST behavior with active eVMCS Vitaly Kuznetsov
2026-08-14 16:22 ` [PATCH 1/4] KVM: nVMX: Make VMPTRLD result in #UD when eVMCS is used Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot
2026-08-14 16:43 ` Sean Christopherson
2026-08-14 16:22 ` [PATCH 2/4] KVM: nVMX: Make VMPTRST return eVMCS GPA when it " Vitaly Kuznetsov
2026-08-14 16:32 ` sashiko-bot
2026-08-14 16:44 ` Sean Christopherson
2026-08-14 16:22 ` [PATCH 3/4] KVM: selftests: Adapt to the updated VMPTRST behavior when eVMCS " Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot
2026-08-14 16:22 ` [PATCH 4/4] KVM: selftests: Check VMPTRLD with active eVMCS Vitaly Kuznetsov
2026-08-14 16:31 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260814163105.BDEC31F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=vkuznets@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox