From: Vitaly Kuznetsov <vkuznets@redhat.com>
To: Khushit Shah <khushit.shah@nutanix.com>
Cc: "seanjc@google.com" <seanjc@google.com>,
"pbonzini@redhat.com" <pbonzini@redhat.com>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>,
Shaju Abraham <shaju.abraham@nutanix.com>
Subject: Re: [BUG] [KVM/VMX] Level triggered interrupts mishandled on Windows w/ nested virt(Credential Guard) when using split irqchip
Date: Wed, 10 Sep 2025 10:34:07 +0200 [thread overview]
Message-ID: <87ms72g0zk.fsf@redhat.com> (raw)
In-Reply-To: <376ABCC7-CF9A-4E29-9CC7-0E3BEE082119@nutanix.com>
Khushit Shah <khushit.shah@nutanix.com> writes:
>> On 8 Sep 2025, at 5:12 PM, Vitaly Kuznetsov <vkuznets@redhat.com> wrote:
>>
...
>> Also, I've just recalled I fixed (well, 'workarounded') an issue similar
>> to yours a while ago in QEMU:
>>
>> commit 958a01dab8e02fc49f4fd619fad8c82a1108afdb
>> Author: Vitaly Kuznetsov <vkuznets@redhat.com>
>> Date: Tue Apr 2 10:02:15 2019 +0200
>>
>> ioapic: allow buggy guests mishandling level-triggered interrupts to make progress
>>
>> maybe something has changed and it doesn't work anymore?
>
> This is really interesting, we are facing a very similar issue, but the interrupt storm only occurs when using split-irqchip.
> Using kernel-irqchip, we do not even see consecutive level triggered interrupts of the same vector. From the logs it is
> clear that somehow with kernel-irqchip, L1 passes the interrupt to L2 to service, but with split-irqchip, L1 EOI’s without
> servicing the interrupt. As it is working properly on kernel-irqchip, we can’t really point it as an Hyper-V issue. AFAIK,
> kernel-irqchip setting should be transparent to the guest, can you think of anything that can change this?
The problem I've fixed back then was also only visible with split
irqchip. The reason was:
"""
in-kernel IOAPIC implementation has commit 184564efae4d ("kvm: ioapic: conditionally delay
irq delivery duringeoi broadcast")
"""
so even though the guest cannot really distinguish between in-kernel and
split irqchips, the small differences in implementation can make a big
difference in the observed behavior. In case we re-assert improperly
handled level-triggered interrupt too fast, the guest is not able to
make much progress but if we let it execute for even the tiniest
fraction of time, then the forward progress happens.
I don't exactly know what happens in this particular case but I'd
suggest you try to atrificially delay re-asserting level triggered
interrupts and see what happens.
--
Vitaly
next prev parent reply other threads:[~2025-09-10 8:34 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-05 15:26 [BUG] [KVM/VMX] Level triggered interrupts mishandled on Windows w/ nested virt(Credential Guard) when using split irqchip Khushit Shah
2025-09-08 9:05 ` Vitaly Kuznetsov
2025-09-08 11:19 ` Khushit Shah
2025-09-08 11:42 ` Vitaly Kuznetsov
2025-09-09 10:34 ` Khushit Shah
2025-09-10 8:34 ` Vitaly Kuznetsov [this message]
2025-09-10 9:39 ` David Woodhouse
2025-09-18 16:05 ` Khushit Shah
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=87ms72g0zk.fsf@redhat.com \
--to=vkuznets@redhat.com \
--cc=khushit.shah@nutanix.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=shaju.abraham@nutanix.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox