From: sashiko-bot@kernel.org
To: "Sohil Mehta" <sohil.mehta@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v10 17/28] KVM: x86: Handle CR4.FRED when emulating RSM
Date: Fri, 11 Sep 2026 22:15:54 +0000 [thread overview]
Message-ID: <20260911221554.743ED1F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260911213659.2025974-18-sohil.mehta@intel.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [High] kvm_set_cr0() does not reject clearing CR0.PG when CR4.FRED is set, leading to an architecturally invalid vCPU state and guest-triggered VM-Entry failures.
Pre-existing issues:
- [High] RSM emulation fails for guests with CR4.CET enabled if the SMM handler temporarily clears CR0.WP.
--
commit 14cda06623e4685b7e725f05b0e66de0ac8e2fb9
Author: Sohil Mehta <sohil.mehta@intel.com>
KVM: x86: Handle CR4.FRED when emulating RSM
Clear CR4.FRED before CR0.PG when leaving long mode on RSM, and restore
it only after CR0.PG has been set, the same way CR4.PCIDE is already
handled in both directions.
> diff --git a/arch/x86/kvm/smm.c b/arch/x86/kvm/smm.c
> index 656a38dad7e7a..a504e93fc5f5f 100644
> --- a/arch/x86/kvm/smm.c
> +++ b/arch/x86/kvm/smm.c
> @@ -435,10 +435,10 @@ static int rsm_enter_protected_mode(struct kvm_vcpu *vcpu,
>
> /*
> * First enable PAE, long mode needs it before CR0.PG = 1 is set.
> - * Then enable protected mode. However, PCID cannot be enabled
> - * if EFER.LMA=0, so set it separately.
> + * Then enable protected mode. However, PCID and FRED cannot be
> + * enabled if EFER.LMA=0, so set them separately.
> */
> - bad = kvm_set_cr4(vcpu, cr4 & ~X86_CR4_PCIDE);
> + bad = kvm_set_cr4(vcpu, cr4 & ~(X86_CR4_PCIDE | X86_CR4_FRED));
> if (bad)
> return X86EMUL_UNHANDLEABLE;
[Severity: High]
This isn't a bug introduced by this patch, but does RSM emulation fail for
guests with CR4.CET enabled if the SMM handler temporarily clears CR0.WP?
If a guest enables CR4.CET and CR0.WP, and an SMI occurs where the SMM handler
clears CR0.WP (e.g., to modify read-only firmware data) and executes RSM
without restoring CR0.WP, rsm_enter_protected_mode() attempts to restore the
pre-SMM CR4 (which has CET=1) before restoring the pre-SMM CR0.
The kvm_set_cr4() call fails because the current vCPU CR0 still has WP=0. This
forces the VM to shut down due to an unhandleable emulation failure
(X86EMUL_UNHANDLEABLE).
Does X86_CR4_CET also need to be masked out here and deferred until after
kvm_set_cr0(), exactly like PCIDE and FRED?
[ ... ]
[Severity: High]
Does this missing update to kvm_set_cr0() cause a regression where a guest can
clear CR0.PG when CR4.FRED is set?
Looking at kvm_set_cr0() in arch/x86/kvm/regs.c:
if (!(cr0 & X86_CR0_PG) &&
(is_64_bit_mode(vcpu) || kvm_is_cr4_bit_set(vcpu, X86_CR4_PCIDE)))
return 1;
If a guest in 32-bit compatibility mode (CS.L=0, EFER.LMA=1) with CR4.FRED=1
executes a MOV to CR0 to clear CR0.PG, kvm_set_cr0() incorrectly allows the
operation because it only checks for is_64_bit_mode() or CR4.PCIDE=1.
KVM then clears EFER.LMA, leaving the vCPU with CR4.FRED=1 and EFER.LMA=0,
which is an architecturally invalid state.
Can this allow a guest kernel (CPL=0) to force a host-level VM-entry abort and
cause a Denial of Service by terminating its own VM?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260911213659.2025974-1-sohil.mehta@intel.com?part=17
next prev parent reply other threads:[~2026-09-11 22:15 UTC|newest]
Thread overview: 43+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 21:36 [PATCH v10 00/28] KVM: Enable FRED support with KVM VMX Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 01/28] KVM: VMX: Enable support for secondary VM exit controls Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 02/28] KVM: VMX: Initialize VM entry/exit FRED controls in vmcs_config Sohil Mehta
2026-09-11 22:00 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 03/28] KVM: VMX: Disable FRED if FRED consistency checks fail Sohil Mehta
2026-09-11 22:08 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 04/28] x86/cea: Prefix event stack names with ESTACK_ Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 05/28] x86/cea: Use array indexing to simplify exception stack access Sohil Mehta
2026-09-11 21:57 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 06/28] x86/fred: Export this_cpu_fred_rsp() for KVM usage Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 07/28] KVM: VMX: Initialize VMCS FRED fields Sohil Mehta
2026-09-11 22:10 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 08/28] KVM: VMX: Set FRED MSR intercepts Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 09/28] KVM: VMX: Save/restore guest FRED RSP0 Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 10/28] KVM: VMX: Add support for saving and restoring FRED MSRs Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 11/28] KVM: x86: Add a helper to detect if FRED is enabled for a vCPU Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 12/28] KVM: x86: Add a new save/restore flag for FRED metadata Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 13/28] KVM: VMX: Virtualize FRED nested exception tracking Sohil Mehta
2026-09-11 22:09 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 14/28] KVM: VMX: Virtualize FRED event_data Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 15/28] KVM: x86: Include CR4.FRED in the emulator CR4 write mask Sohil Mehta
2026-09-11 22:14 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 16/28] KVM: x86: Mark CR4.FRED as not reserved Sohil Mehta
2026-09-11 22:14 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 17/28] KVM: x86: Handle CR4.FRED when emulating RSM Sohil Mehta
2026-09-11 22:15 ` sashiko-bot [this message]
2026-09-11 21:36 ` [PATCH v10 18/28] KVM: VMX: Dump FRED context in dump_vmcs() Sohil Mehta
2026-09-11 22:11 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 19/28] KVM: x86: Advertise support for FRED Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 20/28] KVM: nVMX: Enable support for secondary VM exit controls Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 21/28] KVM: nVMX: Handle FRED VMCS fields in nested VMX context Sohil Mehta
2026-09-11 22:34 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 22/28] KVM: nVMX: Restrict event data VMCS fields to FRED-supported hosts Sohil Mehta
2026-09-11 22:20 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 23/28] KVM: nVMX: Shadow ORIGINAL_EVENT_DATA and INJECTED_EVENT_DATA fields Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 24/28] KVM: nVMX: Validate FRED-related VMCS fields Sohil Mehta
2026-09-11 22:29 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 25/28] KVM: nVMX: Enable VMX FRED controls Sohil Mehta
2026-09-11 22:37 ` sashiko-bot
2026-09-11 21:36 ` [PATCH v10 26/28] KVM: selftests: Add FRED MSRs to msrs_test Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 27/28] KVM: selftests: Add a new VM guest mode to run user level code Sohil Mehta
2026-09-11 21:36 ` [PATCH v10 28/28] KVM: selftests: Add fred exception tests Sohil Mehta
2026-09-11 22:32 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911221554.743ED1F00898@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=sohil.mehta@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox