From: Yosry Ahmed <yosry@kernel.org>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v2 29/29] KVM: selftests: Add a test for nested TLB flushes
Date: Fri, 9 Oct 2026 18:06:18 +0000 [thread overview]
Message-ID: <asktCBk0LcdYGdDW@google.com> (raw)
In-Reply-To: <sashiko-outbox-163475@kernel.org>
On Thu, Oct 08, 2026 at 12:35:35AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] kvm: selftests: missing memory clobber in invlpga() allows reordering
> --
>
> commit c21865242d0952d01a007708f2fbf08ce2550486
> Author: Yosry Ahmed <yosry@kernel.org>
>
> KVM: selftests: Add a test for nested TLB flushes
>
> Add a test that exercises most common scenarios for TLB flushes. The
> test is split into guest-triggered and KVM-triggered TLB flushes.
>
> > diff --git a/tools/testing/selftests/kvm/include/x86/svm.h b/tools/testing/selftests/kvm/include/x86/svm.h
> > index c8539166270ea..7644e37c7042c 100644
> > --- a/tools/testing/selftests/kvm/include/x86/svm.h
> > +++ b/tools/testing/selftests/kvm/include/x86/svm.h
> [ ... ]
> > @@ -316,4 +316,9 @@ struct __attribute__ ((__packed__)) vmcb {
> >
> > #define SVM_CR0_SELECTIVE_MASK (X86_CR0_TS | X86_CR0_MP)
> >
> > +static inline void invlpga(unsigned long addr, u32 asid)
> > +{
> > + asm volatile("invlpga %0, %1" : : "a"(addr), "c"(asid));
> > +}
> > +
> > #endif /* SELFTEST_KVM_SVM_H */
>
> [Severity: Medium]
> Does this inline assembly need a "memory" clobber?
>
> Unlike the VMX counterparts invvpid and invept introduced in this patch, this
> inline assembly lacks a "memory" clobber. This might allow the compiler to
> reorder prior memory stores past the TLB flush instruction.
>
> > diff --git a/tools/testing/selftests/kvm/x86/nested_tlb_flush_test.c b/tools/testing/selftests/kvm/x86/nested_tlb_flush_test.c
> > new file mode 100644
> > index 0000000000000..fb32b7bf6b19f
> > --- /dev/null
> > +++ b/tools/testing/selftests/kvm/x86/nested_tlb_flush_test.c
> [ ... ]
> > +static void l1_guest_code(void *data)
> > +{
> > + gpa_t gpa;
> > + int i;
> > +
> > + prepare_l2(data, l2_guest_code);
> > +
> > + /*
> > + * Alternately switch the PTE (or TDP PTE) mapping TEST_VADDR between
> > + * two pages containing VAL1 and VAL2, flush TLBs, and verify that L2
> > + * reads the expected value.
> > + */
> > + for (i = 0; i < NR_ITERATIONS; i++) {
> > + gpa = test_gpa[i % 2];
> > +
> > + *pte_gva &= ~PHYSICAL_PAGE_MASK;
> > + *pte_gva |= gpa & PHYSICAL_PAGE_MASK;
> > +
> > + WRITE_ONCE(l2_expected_val, (i % 2 == 0) ? VAL1 : VAL2);
> > + run_l2(data, i == 0);
>
> [Severity: Medium]
> Can the compiler execute the *pte_gva assignments after the TLB flush inside
> run_l2()?
>
> Because the invlpga() inline assembly lacks a "memory" clobber, and there is no
> other compiler barrier between the assignment and invlpga(), the compiler is
> legally permitted to reorder the memory store to execute after the invlpga()
> instruction.
>
> If this reordering occurs, the hardware will flush the TLB while the old PTE is
> still in memory, which could allow a speculative hardware page walk to re-cache
> the old PTE before the store completes. When L2 resumes, it may use the stale
> TLB entry, causing the test to spuriously fail. The "memory" clobber in the
> run_guest() wrapper only ensures both operations complete prior to VM-entry; it
> does not enforce their relative execution order.
Will add the "memory" clobber.
>
> --
> Sashiko AI review · https://sashiko.dev/#/patchset/20261008001425.2458927-1-yosry@kernel.org?part=29
prev parent reply other threads:[~2026-10-09 18:06 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 0:13 [PATCH v2 00/29] KVM: nSVM: Optimize nSVM TLB flushes Yosry Ahmed
2026-10-08 0:13 ` [PATCH v2 01/29] KVM: nSVM: Flush the TLB after forcefully leaving nested Yosry Ahmed
2026-10-08 0:13 ` [PATCH v2 02/29] KVM: SVM: Document number of ASIDs CPUID setting Yosry Ahmed
2026-10-08 0:13 ` [PATCH v2 03/29] KVM: VMX: Generalize VPID allocation to be vendor-neutral Yosry Ahmed
2026-10-08 0:30 ` sashiko-bot
2026-10-08 21:53 ` Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 04/29] KVM: x86/mmu: Support specifying reserved TLB tags Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 05/29] KVM: SVM: Add helpers to set/clear ASID flush in VMCB Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 06/29] KVM: SVM: Fallback to flush everything if FLUSHBYASID is not available Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 07/29] KVM: SEV: Do ASID initialization at VMCB initialization Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 08/29] KVM: SEV: Expose sev_get_asid() outside of sev.c Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 09/29] KVM: SEV: Explicitly initialize the per vCPU ASID on SEV VM migration Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 10/29] KVM: SVM: Use a static ASID per vCPU Yosry Ahmed
2026-10-08 0:30 ` sashiko-bot
2026-10-08 22:01 ` Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 11/29] KVM: SVM: Only flush the fallback ASID when used by a different vCPU Yosry Ahmed
2026-10-08 0:33 ` sashiko-bot
2026-10-09 15:37 ` Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 12/29] KVM: nSVM: Drop svm->nested.initialized Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 13/29] KVM: nSVM: Add a placeholder ASID for L2 Yosry Ahmed
2026-10-08 0:42 ` sashiko-bot
2026-10-09 15:43 ` Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 14/29] KVM: x86: hyper-v: Rename kvm_hv_vcpu_purge_flush_tlb() Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 15/29] KVM: x86: hyper-v: Allow purging all TLB flush FIFOs Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 16/29] KVM: nSVM: Flush both L1 and L2 ASIDs on KVM_REQ_TLB_FLUSH Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 17/29] KVM: nSVM: Always switch VMCB before leaving guest mode Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 18/29] KVM: nSVM: Split nested_svm_transition_tlb_flush() into entry/exit fns Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 19/29] KVM: nSVM: Service local TLB flushes before nested transitions Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 20/29] KVM: x86: Add KVM_REQ_MMU_SYNC_ALL_ROOTS Yosry Ahmed
2026-10-08 3:29 ` Lai Jiangshan
2026-10-08 0:14 ` [PATCH v2 21/29] KVM: nSVM: Handle nested TLB flush requests through TLB_CONTROL Yosry Ahmed
2026-10-08 0:36 ` sashiko-bot
2026-10-09 15:46 ` Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 22/29] KVM: nSVM: Flush the TLB if L1 changes L2's ASID in vmcb12 Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 23/29] KVM: nSVM: Do not reset TLB_CONTROL in vmcb02 on nested VM-Enter Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 24/29] KVM: x86/mmu: Rename __kvm_mmu_invalidate_addr() to kvm_mmu_sync_addr() Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 25/29] KVM: x86/mmu: Refactor kvm_mmu_invlpg() to allow skipping the GVA flush Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 26/29] KVM: nSVM: Flush L2's ASID when emulating INVLPGA Yosry Ahmed
2026-10-08 0:45 ` sashiko-bot
2026-10-08 0:14 ` [PATCH v2 27/29] KVM: nSVM: Flush the ASID on nested transitions if shared by L1 and L2 Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 28/29] KVM: nSVM: Use different ASIDs for " Yosry Ahmed
2026-10-08 0:14 ` [PATCH v2 29/29] KVM: selftests: Add a test for nested TLB flushes Yosry Ahmed
2026-10-08 0:35 ` sashiko-bot
2026-10-09 18:06 ` Yosry Ahmed [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=asktCBk0LcdYGdDW@google.com \
--to=yosry@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox