Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Chang S. Bae" <chang.seok.bae@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v8 03/20] KVM: x86: Support APX state for XSAVE ABI
Date: Wed, 30 Sep 2026 21:57:31 +0000	[thread overview]
Message-ID: <20260930215732.4F6A51F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260930210750.1487547-4-chang.seok.bae@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] x86/kvm: stale APX registers (R16-R31) on KVM_SET_XSAVE
--

commit 589bfa90166bba201eeea61923abb798785e7f3a
Author: Chang S. Bae <chang.seok.bae@intel.com>

KVM: x86: Support APX state for XSAVE ABI

This commit introduces a facility to copy APX state between the VCPU cache
and the userspace buffer. It establishes copy functions to ensure APX state
is properly handled during user ABI interactions.

> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index 79468ddfe4736..0df74422759f8 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c

[ ... ]

> +static int kvm_copy_uabi_to_vcpu_regs(struct kvm_vcpu *vcpu, void *buf, u64 supported_xcr0)
> +{
> +	union fpregs_state *xstate = (union fpregs_state *)buf;
> +
> +	if (!(xstate->xsave.header.xfeatures & XFEATURE_MASK_APX))
> +		return 0;

[Severity: High]
Does this early return leave stale values in the APX registers instead of
initializing them to zero?

When a guest is restored via KVM_SET_XSAVE and the XSAVE payload indicates
the APX state is in its INIT state (the APX bit in the header is 0),
returning early here bypasses zeroing the extended general purpose
registers in vcpu->arch.regs. This can lead to guest state corruption
across snapshot restores or live migration, as the guest might observe
stale non-zero values in R16-R31 when it expects them to be zero.

> +
> +	if (!(supported_xcr0 & XFEATURE_MASK_APX))
> +		return -EINVAL;
> +
> +	BUILD_BUG_ON(NR_VCPU_GENERAL_PURPOSE_REGS <= VCPU_REGS_R31);
> +
> +	memcpy(&vcpu->arch.regs[VCPU_REGS_R16],
> +	       buf + xstate_offset(XFEATURE_APX),
> +	       xstate_size(XFEATURE_APX));
> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930210750.1487547-1-chang.seok.bae@intel.com?part=3

  reply	other threads:[~2026-09-30 21:57 UTC|newest]

Thread overview: 38+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 21:07 [PATCH v8 00/20] KVM: x86: Enable APX for guests Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 01/20] KVM: x86: Extend VCPU registers for EGPRs Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 02/20] KVM: VMX: Save guest EGPRs in VCPU cache Chang S. Bae
2026-09-30 21:56   ` sashiko-bot
2026-10-01 19:57     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 03/20] KVM: x86: Support APX state for XSAVE ABI Chang S. Bae
2026-09-30 21:57   ` sashiko-bot [this message]
2026-10-01 19:58     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 04/20] KVM: VMX: Refactor VMX instruction information access Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 05/20] KVM: VMX: Refactor instruction information decoding Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 06/20] KVM: VMX: Remove unused control-register access defines Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 07/20] KVM: VMX: Refactor register index retrieval from exit qualification Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 08/20] KVM: VMX: Support instruction information extension Chang S. Bae
2026-09-30 21:52   ` sashiko-bot
2026-10-01 19:58     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 09/20] KVM: nVMX: Propagate extended instruction information Chang S. Bae
2026-09-30 21:52   ` sashiko-bot
2026-10-01 19:58     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 10/20] KVM: x86: Support EGPR accessing and tracking for emulator Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 11/20] KVM: x86: Handle EGPR index and REX2-incompatible opcodes Chang S. Bae
2026-09-30 21:47   ` sashiko-bot
2026-10-01 19:59     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 12/20] KVM: x86: Support REX2-prefixed opcode decode Chang S. Bae
2026-09-30 21:54   ` sashiko-bot
2026-10-01 19:59     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 13/20] KVM: x86: Reject EVEX-prefixed instructions Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 14/20] KVM: x86: Move KVM_SUPPORTED_{XCR0,XSS} into kvm_x86_vendor_init() Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 15/20] KVM: x86: Guard valid XCR0.APX settings Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 16/20] KVM: x86: Add APX to supported XCR0 Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 17/20] KVM: x86: Expose APX foundation feature to userspace Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 18/20] KVM: x86: Expose APX sub-features " Chang S. Bae
2026-09-30 21:43   ` sashiko-bot
2026-10-01 20:00     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 19/20] KVM: x86: selftests: Add APX state and ABI test Chang S. Bae
2026-09-30 21:48   ` sashiko-bot
2026-10-01 19:59     ` Chang S. Bae
2026-09-30 21:07 ` [PATCH v8 20/20] KVM: x86: selftests: Add APX state handling and XCR0 sanity checks Chang S. Bae
2026-10-01 20:29 ` [PATCH v8 00/20] KVM: x86: Enable APX for guests Chang S. Bae

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930215732.4F6A51F00898@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=chang.seok.bae@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox