From: sashiko-bot@kernel.org
To: "Paolo Bonzini" <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH 09/11] KVM: selftests: Verify that L0's TPR doesn't get clobbered
Date: Sat, 26 Sep 2026 05:42:50 +0000 [thread overview]
Message-ID: <20260926054250.B0AA31F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260926053253.195597-10-pbonzini@redhat.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] kvm: selftests: host lockup in nested_x2apic_test on buggy kernels
--
commit 4b6251f570c0e52b8b50c2db54a19f22c22f7cf3
Author: Sean Christopherson <seanjc@google.com>
KVM: selftests: Verify that L0's TPR doesn't get clobbered
This commit updates the nested_x2apic_test to verify that KVM properly
intercepts L2's writes to the APIC_TASKPRI register. It adds checks in
both L2 and L1 guest code to assert that the TPR value written in L2 is
correctly handled and observable.
> diff --git a/tools/testing/selftests/kvm/x86/nested_x2apic_test.c b/tools/testing/selftests/kvm/x86/nested_x2apic_test.c
> index a1072bf499ee2..3b59ba3e33420 100644
> --- a/tools/testing/selftests/kvm/x86/nested_x2apic_test.c
> +++ b/tools/testing/selftests/kvm/x86/nested_x2apic_test.c
> @@ -28,6 +28,10 @@ static void l2_guest_code(void)
> {
> if (inhibit_apicv)
> wrmsr(MSR_IA32_APICBASE, rdmsr(MSR_IA32_APICBASE) & GENMASK_ULL(11, 0));
> +
> + x2apic_write_reg(APIC_TASKPRI, 0xf0);
[Severity: Medium]
Does writing 0xf0 here risk permanently freezing the host CPU when testing on
buggy kernels?
When running this test on an unpatched kernel where KVM fails to intercept
this x2APIC MSR (the AVIC bug this test targets), this writes directly to the
host CPU's physical TPR. A TPR value of 0xf0 sets the task priority class to
15, which blocks all maskable interrupts (including local timers and device
interrupts).
Could a harmless value like 0x10 be used instead, which would still fail the
L1 assertion without masking critical host interrupts?
> + GUEST_ASSERT_EQ(x2apic_read_reg(APIC_TASKPRI), 0xf0);
> +
> asm volatile("cpuid" ::: "eax", "ebx", "ecx", "edx");
> }
>
> @@ -73,10 +77,22 @@ static void l1_guest_code(void *test_data)
>
> sti_nop();
>
> + GUEST_ASSERT_EQ(x2apic_read_reg(APIC_TASKPRI), 0xf0);
[Severity: Medium]
If the test runs on a kernel with the AVIC bug, won't this assertion fail and
abort the test immediately?
If the test aborts here due to the assertion failure, the host's physical TPR
is never restored. Because L2 previously wrote 0xf0 to the host TPR, this
leaves the host CPU completely unresponsive to maskable interrupts.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260926053253.195597-1-pbonzini@redhat.com?part=9
next prev parent reply other threads:[~2026-09-26 5:42 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 5:32 [PATCH 00/11] KVM: fix issues with stale control fields Paolo Bonzini
2026-09-26 5:32 ` [PATCH 01/11] KVM: SVM: Preserve TLB control (i.e. pending TLB flush) on failed VMRUN Paolo Bonzini
2026-09-26 5:32 ` [PATCH 02/11] KVM: SVM: Update control fields on #VMEXIT if and only if VMRUN succeeded Paolo Bonzini
2026-09-26 5:32 ` [PATCH 03/11] KVM: SVM: Don't mark ASID fields as dirty when setting control.tlb_ctl Paolo Bonzini
2026-09-26 5:32 ` [PATCH 04/11] KVM: SVM: Sync guest's PERF_CNTR_GLOBAL_CTL from h/w only on successful VMRUN Paolo Bonzini
2026-09-26 5:32 ` [PATCH 05/11] KVM: SVM: Use the active VMCB's MSR bitmap when checking if MSR is intercepted Paolo Bonzini
2026-09-26 5:42 ` sashiko-bot
2026-09-26 5:32 ` [PATCH 06/11] KVM: nVMX: Force MSR bitmap refresh if runtime eVMCS controls are modified Paolo Bonzini
2026-09-26 5:32 ` [PATCH 07/11] KVM: selftests: Add x2APIC MSR test for inhibiting APICv while nested Paolo Bonzini
2026-09-26 5:32 ` [PATCH 08/11] KVM: selftests: Run the nested x2APIC with and without APICv being inhibited in L2 Paolo Bonzini
2026-09-26 5:32 ` [PATCH 09/11] KVM: selftests: Verify that L0's TPR doesn't get clobbered Paolo Bonzini
2026-09-26 5:42 ` sashiko-bot [this message]
2026-09-26 5:32 ` [PATCH 10/11] KVM: selftests: Extend nested x2APIC test to validate disabling x2APIC virt Paolo Bonzini
2026-09-26 5:46 ` sashiko-bot
2026-09-26 5:32 ` [PATCH 11/11] KVM: selftests: Extend nested x2APIC test to validate using eVMCS for vmcs12 Paolo Bonzini
2026-09-26 6:11 ` [PATCH 00/11] KVM: fix issues with stale control fields Paolo Bonzini
2026-09-28 17:01 ` Sean Christopherson
2026-09-26 6:12 ` Paolo Bonzini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260926054250.B0AA31F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox