Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Sean Christopherson <seanjc@google.com>
Cc: sashiko-reviews@lists.linux.dev, kvm@vger.kernel.org,
	Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [PATCH v2 2/3] KVM: TDX: Fix the exit reason handling
Date: Wed, 12 Aug 2026 20:28:46 +0800	[thread overview]
Message-ID: <646f9595-459f-4224-b4e5-4ec2eecc0bc6@intel.com> (raw)
In-Reply-To: <95d81370-3244-43c8-a6fb-6c2146d24dda@intel.com>

On 8/12/2026 11:20 AM, Xiaoyao Li wrote:
> On 8/11/2026 8:04 AM, Sean Christopherson wrote:
>> On Mon, Aug 10, 2026, Sean Christopherson wrote:
>>> On Mon, Aug 10, 2026, Xiaoyao Li wrote:
>>>> On 8/10/2026 7:39 PM, sashiko-bot@kernel.org wrote:
>>>>>> @@ -2147,7 +2156,7 @@ void tdx_get_exit_info(struct kvm_vcpu 
>>>>>> *vcpu, u32 *reason,
>>>>>>        struct vcpu_tdx *tdx = to_tdx(vcpu);
>>>>>>        *reason = tdx->vt.exit_reason.full;
>>>>>> -    if (*reason != -1u) {
>>>>>> +    if (tdx->vt.exit_reason.basic != -1) {
>>>>> [Severity: Medium]
>>>>> Will this check always evaluate to true due to C integer promotion 
>>>>> rules?
>>>>>
>>>>> The basic field in union vmx_exit_reason is a 16-bit unsigned 
>>>>> bitfield. When
>>>>> comparing it to -1, the unsigned 16-bit value is promoted to a 
>>>>> signed 32-bit
>>>>> integer. If the value was set to -1 (65535), the comparison 
>>>>> evaluates as
>>>>> 65535 != -1, which is always true.
>>>>>
>>>>
>>>> Well, how about something below on top of this patch?
>>>
>>> No, we need to not rely on magic exit_reason.basic values.  Can't 
>>> this be?
>>>
>>>     if ((tdx->vp_enter_ret & TDX_SW_ERROR) != TDX_SW_ERROR) {
>>
>> This would arguably be a bug fix as well, because the "real" 
>> EXIT_REASON_EPT_MISCONFIG
>> path gets a false negative.  E.g. when getting information for an EPT 
>> Misconfig
>> for the tracepoint, KVM really should print all information, not zeros.
>>
>> At a glance, this exact change can probably be a separate patch too.
> 
> Yeah, this issue can be fixed by the patch which turns real 
> EPT_MISCONFIG to TDX_SW_ERROR.
> 
> Side topic, tdx_to_vmx_exit_reason() can change EXIT_REASON_TDCALL to 
> other Exit Reason. Do we want to print TDCALL instead of the transformed 
> reason here?

Well, the more I think about this all, the more I dislike the fancy 
trick to turn TDCALL into other Exit Reason, in 
tdx_to_vmx_exit_reason().  Without it, it's straightforward to handle 
the EPT_MISCONFIG. And without it, the exit trace can also get the 
correct Exit Reason. How about something below? which is on top of 
kvm-x86/next


diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
index b272c20586a7..2474a298e2cd 100644
--- a/arch/x86/kvm/vmx/tdx.c
+++ b/arch/x86/kvm/vmx/tdx.c
@@ -924,7 +924,6 @@ static __always_inline u32 
tdcall_to_vmx_exit_reason(struct kvm_vcpu *vcpu)
  static __always_inline u32 tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu)
  {
         struct vcpu_tdx *tdx = to_tdx(vcpu);
-       u32 exit_reason;

         switch (tdx->vp_enter_ret & TDX_SEAMCALL_STATUS_MASK) {
         case TDX_SUCCESS:
@@ -932,30 +931,11 @@ static __always_inline u32 
tdx_to_vmx_exit_reason(struct kvm_vcpu *vcpu)
         case TDX_NON_RECOVERABLE_TD:
         case TDX_NON_RECOVERABLE_TD_NON_ACCESSIBLE:
         case TDX_NON_RECOVERABLE_TD_WRONG_APIC_MODE:
-               break;
+               return (u32)tdx->vp_enter_ret;
         default:
                 return -1u;
         }

-       exit_reason = tdx->vp_enter_ret;
-
-       switch (exit_reason) {
-       case EXIT_REASON_TDCALL:
-               if (tdvmcall_exit_type(vcpu))
-                       return EXIT_REASON_VMCALL;
-
-               return tdcall_to_vmx_exit_reason(vcpu);
-       case EXIT_REASON_EPT_MISCONFIG:
-               /*
-                * Defer KVM_BUG_ON() until tdx_handle_exit() because 
this is in
-                * non-instrumentable code with interrupts disabled.
-                */
-               return -1u;
-       default:
-               break;
-       }
-
-       return exit_reason;
  }

  static noinstr void tdx_vcpu_enter_exit(struct kvm_vcpu *vcpu)
@@ -1093,9 +1073,6 @@ fastpath_t tdx_vcpu_run(struct kvm_vcpu *vcpu, u64 
run_flags)

         kvm_clear_available_registers(vcpu, ~TDX_REGS_AVAIL_SET);

-       if (unlikely(tdx->vp_enter_ret == EXIT_REASON_EPT_MISCONFIG))
-               return EXIT_FASTPATH_NONE;
-
         if (unlikely((tdx->vp_enter_ret & TDX_SW_ERROR) == TDX_SW_ERROR))
                 return EXIT_FASTPATH_NONE;

@@ -2027,6 +2004,41 @@ int tdx_complete_emulated_msr(struct kvm_vcpu 
*vcpu, int err)
         return 1;
  }

+#define TDVMCALL_CPUID         EXIT_REASON_CPUID
+#define TDVMCALL_HLT           EXIT_REASON_HLT
+#define TDVMCALL_IO_INSTRUCTION        EXIT_REASON_IO_INSTRUCTION
+#define TDVMCALL_MSR_READ      EXIT_REASON_MSR_READ
+#define TDVMCALL_MSR_WRITE     EXIT_REASON_MSR_WRITE
+#define TDVMCALL_MMIO          EXIT_REASON_EPT_VIOLATION
+
+static int handle_tdcall(struct kvm_vcpu *vcpu)
+{
+       struct vcpu_tdx *tdx = to_tdx(vcpu);
+
+       if (tdvmcall_exit_type(vcpu))
+               return tdx_emulate_vmcall(vcpu);
+
+       switch (tdvmcall_leaf(vcpu)) {
+       case TDVMCALL_CPUID:
+               return tdx_emulate_cpuid(vcpu);
+       case TDVMCALL_HLT:
+               return kvm_emulate_halt_noskip(vcpu);
+       case TDVMCALL_IO_INSTRUCTION:
+               return tdx_emulate_io(vcpu);
+       case TDVMCALL_MSR_READ:
+               kvm_ecx_write(vcpu, tdx->vp_enter_args.r12);
+               return kvm_emulate_rdmsr(vcpu);
+       case TDVMCALL_MSR_WRITE:
+               kvm_ecx_write(vcpu, tdx->vp_enter_args.r12);
+               kvm_eax_write(vcpu, tdx->vp_enter_args.r13);
+               kvm_edx_write(vcpu, tdx->vp_enter_args.r13 >> 32);
+               return kvm_emulate_wrmsr(vcpu);
+       case TDVMCALL_MMIO:
+               return tdx_emulate_mmio(vcpu);
+       default:
+               return handle_tdvmcall(vcpu);
+       }
+}

  int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath)
  {
@@ -2037,11 +2049,6 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, 
fastpath_t fastpath)
         if (fastpath != EXIT_FASTPATH_NONE)
                 return 1;

-       if (unlikely(vp_enter_ret == EXIT_REASON_EPT_MISCONFIG)) {
-               KVM_BUG_ON(1, vcpu->kvm);
-               return -EIO;
-       }
-
         /*
          * Handle TDX SW errors, including TDX_SEAMCALL_UD, 
TDX_SEAMCALL_GP and
          * TDX_SEAMCALL_VMFAILINVALID.
@@ -2083,26 +2090,12 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, 
fastpath_t fastpath)
         case EXIT_REASON_EXTERNAL_INTERRUPT:
                 ++vcpu->stat.irq_exits;
                 return 1;
-       case EXIT_REASON_CPUID:
-               return tdx_emulate_cpuid(vcpu);
-       case EXIT_REASON_HLT:
-               return kvm_emulate_halt_noskip(vcpu);
         case EXIT_REASON_TDCALL:
-               return handle_tdvmcall(vcpu);
-       case EXIT_REASON_VMCALL:
-               return tdx_emulate_vmcall(vcpu);
-       case EXIT_REASON_IO_INSTRUCTION:
-               return tdx_emulate_io(vcpu);
-       case EXIT_REASON_MSR_READ:
-               kvm_ecx_write(vcpu, tdx->vp_enter_args.r12);
-               return kvm_emulate_rdmsr(vcpu);
-       case EXIT_REASON_MSR_WRITE:
-               kvm_ecx_write(vcpu, tdx->vp_enter_args.r12);
-               kvm_eax_write(vcpu, tdx->vp_enter_args.r13);
-               kvm_edx_write(vcpu, tdx->vp_enter_args.r13 >> 32);
-               return kvm_emulate_wrmsr(vcpu);
+               return handle_tdcall(vcpu);
         case EXIT_REASON_EPT_MISCONFIG:
-               return tdx_emulate_mmio(vcpu);
+               /* EPT MISCONFIGs are *always* KVM/kernel bugs. */
+               KVM_BUG_ON(1, vcpu->kvm);
+               return -EIO;
         case EXIT_REASON_EPT_VIOLATION:
                 return tdx_handle_ept_violation(vcpu);
         case EXIT_REASON_OTHER_SMI:

  reply	other threads:[~2026-08-12 12:28 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-10 11:21 [PATCH v2 0/3] KVM: TDX: Enable VM-DoS Prevention Features for TDX Xiaoyao Li
2026-08-10 11:21 ` [PATCH v2 1/3] KVM: TDX: Enable Notify VM exit Xiaoyao Li
2026-08-11  0:37   ` Edgecombe, Rick P
2026-08-10 11:21 ` [PATCH v2 2/3] KVM: TDX: Fix the exit reason handling Xiaoyao Li
2026-08-10 11:39   ` sashiko-bot
2026-08-10 12:02     ` Xiaoyao Li
2026-08-10 23:57       ` Sean Christopherson
2026-08-11  0:04         ` Sean Christopherson
2026-08-12  3:20           ` Xiaoyao Li
2026-08-12 12:28             ` Xiaoyao Li [this message]
2026-08-11  0:19         ` Xiaoyao Li
2026-08-13  0:20           ` Sean Christopherson
2026-08-11  0:03   ` Sean Christopherson
2026-08-11  3:17     ` Xiaoyao Li
2026-08-11 17:36       ` Sean Christopherson
2026-08-11  0:38   ` Edgecombe, Rick P
     [not found]     ` <6bb1328d-e995-4ad7-9744-3ab01d2ae591@intel.com>
2026-08-11 15:20       ` Edgecombe, Rick P
2026-08-12  7:29         ` Xiaoyao Li
2026-08-12 20:21           ` Edgecombe, Rick P
2026-08-13  0:16       ` Sean Christopherson
2026-08-10 11:22 ` [PATCH v2 3/3] KVM: TDX: Enable Bus Lock VM exit Xiaoyao Li
2026-08-10 11:46   ` sashiko-bot
2026-08-10 12:03     ` Xiaoyao Li
2026-08-11  1:18   ` Edgecombe, Rick P
2026-08-11  1:44     ` Xiaoyao Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=646f9595-459f-4224-b4e5-4ec2eecc0bc6@intel.com \
    --to=xiaoyao.li@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=seanjc@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox