From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 544BB46A5FE for ; Mon, 21 Sep 2026 17:44:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790012691; cv=none; b=BGMTAYPBmTppId23hMNvOxlGaQP8hv/Ud1kXq+8IfAe1zeAiLu11CShsvCVsQw+V0/by6GuY5amuAaIiAym7WrlgEdpCI7332rIWft9ZynqbDnhab5lzmeB/dq8EaqFUIrtqDgsedzM6sk5cLAwqu5F2IP3GoYsIkSoD02Jy31k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790012691; c=relaxed/simple; bh=Pm2NqTs6oRcRC4pVvxFdi78nyABlZFM4rmakGlSjCpY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=W8HYn6izBMgNY2qC+/vr5bZSuh/ViabPDy+3fJwSFl+f1qxZrFNASd2b3phMKp67mKwHbYgCc7YA1ha+SHZLHEpROXC5boe6eQ/pyB9vT2PKt9Jnk9Ou8hIdT2FDoDm158CMBIOaSpNzAibCsba6PFxxeD5IIAIf556rZhfZDxY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=vtBJcBV6; arc=none smtp.client-ip=209.85.210.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="vtBJcBV6" Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-8679cfe5019so4671941b3a.0 for ; Mon, 21 Sep 2026 10:44:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1790012689; x=1790617489; darn=lists.linux.dev; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:from:to:cc:subject:date:message-id :reply-to:content-type; bh=ZLfRYJewP8aR3Y4V2zbyCdDW63inecBdjfc5u4aaKpU=; b=vtBJcBV6i2yLP5ajG87HP2OTWMXGHcL3pnYVNnr2U9FAV/geCty5BENwZvCi+yWheL 2Mn2Ot6xi2pIoI3rufzY1G54vHghR5/r6/S1pKri2YEG2t1GDpj191MwykdcQosj8pX3 TJYvSenc0qydWjO9vwa8gJdQWs0zFWrkizdqvUowywBb8nkg6+LILrGLljXEOj+gd3sP 3MQsdfPLRO4Fp18F0rGXfatyMaZ7KHCT+fKAYrnRfgTIRh5VuIUIxKqc8onNc3Z/ZqnN rEvGg5emixffZVBFlurfIq+AXnk953jIoiwxshXVycag9HWP90MSGAVLfe8qRbr8WnQg kIwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1790012689; x=1790617489; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:reply-to:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=ZLfRYJewP8aR3Y4V2zbyCdDW63inecBdjfc5u4aaKpU=; b=KyuRhU5+xvpzhN/EKA7MJzxHngrqiwHdBH1EA8X3kjAvcy2leWhiR+glMgijOGg7Ib CfgJO0Moh4IxsgKJJaJsOs0LWpNxdSPnSXs8oFQV9NW2P1z5QZ8rm5GpBZn0uIDUkyh6 pB+H6TApmMBLLyZ+JeGqVzHJ1qUZkGUHY/9jduPLa+Npnw5o5yPokbzr+vPR2vOUCA/4 h5Oh6sJEureTux1DcGoVnPFHRv3XaDryxYJKLZ6wUpVZ9ZZLW9QIfODsrzrwNy64q5ht cKxVanisXr6GTKoKbWi8iG5sjRhPT+2mb6C99zPqJ+6Yu1RJ7PbUdSWRrOl5V9YPVHEU Yw7w== X-Forwarded-Encrypted: i=1; AKwUvBzRlGzVLds4R/kdQrFEyASTvIs92Or83x7hrw5VKhh1M4Mz8RvsOiKUzoSXw9aMe5/WP/RcbNT0rhWh@lists.linux.dev X-Gm-Message-State: AFuF++nj2hOPG7IChyy5vTqEJabkpbj2htIcY9GMvaLwlB1b2EvPSBQL 3kJbwkBVwK6aOgTHuhFA6JsTqzN2N4hxP3ZDHjnUGjhx9kH/SaQ9w79jEg/spD8iAxYBVqaFTnW XcmTuZQ== X-Received: from pfbgk3.prod.google.com ([2002:a05:6a00:8483:b0:873:d536:aebe]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:12dd:b0:86b:73b4:30fa with SMTP id d2e1a72fcca58-874dc0ff42cmr17041050b3a.11.1790012688332; Mon, 21 Sep 2026 10:44:48 -0700 (PDT) Reply-To: Sean Christopherson Date: Mon, 21 Sep 2026 10:44:39 -0700 In-Reply-To: <20260921174445.911676-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-coco@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921174445.911676-1-seanjc@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921174445.911676-2-seanjc@google.com> Subject: [PATCH v2 1/7] KVM: Reject attempts to lock all vCPUs if vCPU creation is in-progress From: Sean Christopherson To: Madhavan Srinivasan , Anup Patel , Paul Walmsley , Palmer Dabbelt , Albert Ou , Sean Christopherson , Paolo Bonzini , Kiryl Shutsemau , Rick Edgecombe Cc: Nicholas Piggin , Atish Patra , Alexandre Ghiti , Dave Hansen , linuxppc-dev@lists.ozlabs.org, kvm@vger.kernel.org, kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org, x86@kernel.org, linux-coco@lists.linux.dev, linux-kernel@vger.kernel.org, Jean-Christophe Guillain , "=?UTF-8?q?Pawe=C5=82=20S?=" Content-Type: text/plain; charset="UTF-8" Reject locking of all vCPUs if vCPU creation is in-progress, i.e. if the number of "created" vCPUs doesn't match the number of "onlined" vCPUs. It's simply not possible to guarantee that KVM has truly locked all vCPUs if one or more vCPUs are actively being created. Holding kvm->lock does prevent in-flight vCPUs from being fully onlined, but it's infeasible for common KVM to know whether or not that provides sufficient protection. In practice, this is likely a minor bug fix for the ARM and RISC-V usage of kvm_trylock_all_vcpus(), and a glorified nop for everything else. E.g. ARM's kvm_timer_vcpu_init() can race kvm_vm_ioctl_set_counter_offset() with respect to observing KVM_ARCH_FLAG_VM_COUNTER_OFFSET. Opportunistically drop x86's existing manual checks on vCPU creation being in-progress as all of x86's checks immediately precede or follow locking of all vCPUs. Leave arm64 and RISC-V alone for the moment, as their checks aren't as obviously redundant/equivalent. Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/sev.c | 10 ---------- arch/x86/kvm/vmx/tdx.c | 5 ----- virt/kvm/kvm_main.c | 6 ++++++ 3 files changed, 6 insertions(+), 15 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 5705723f1f41..068f8a236a35 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -1125,9 +1125,6 @@ static int sev_launch_update_vmsa(struct kvm *kvm, struct kvm_sev_cmd *argp) if (!sev_es_guest(kvm)) return -ENOTTY; - if (kvm_is_vcpu_creation_in_progress(kvm)) - return -EBUSY; - ret = kvm_lock_all_vcpus(kvm); if (ret) return ret; @@ -2115,10 +2112,6 @@ static int sev_check_source_vcpus(struct kvm *dst, struct kvm *src) struct kvm_vcpu *src_vcpu; unsigned long i; - if (kvm_is_vcpu_creation_in_progress(src) || - kvm_is_vcpu_creation_in_progress(dst)) - return -EBUSY; - if (!sev_es_guest(src)) return 0; @@ -2510,9 +2503,6 @@ static int snp_launch_update_vmsa(struct kvm *kvm, struct kvm_sev_cmd *argp) unsigned long i; int ret; - if (kvm_is_vcpu_creation_in_progress(kvm)) - return -EBUSY; - ret = kvm_lock_all_vcpus(kvm); if (ret) return ret; diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c index b272c20586a7..58c255256e4c 100644 --- a/arch/x86/kvm/vmx/tdx.c +++ b/arch/x86/kvm/vmx/tdx.c @@ -2728,11 +2728,6 @@ static tdx_vm_state_guard_t tdx_acquire_vm_state_locks(struct kvm *kvm) mutex_lock(&kvm->lock); - if (kvm->created_vcpus != atomic_read(&kvm->online_vcpus)) { - r = -EBUSY; - goto out_err; - } - r = kvm_lock_all_vcpus(kvm); if (r) goto out_err; diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c index 65eb26a0520d..78cc090435be 100644 --- a/virt/kvm/kvm_main.c +++ b/virt/kvm/kvm_main.c @@ -1363,6 +1363,9 @@ int kvm_trylock_all_vcpus(struct kvm *kvm) lockdep_assert_held(&kvm->lock); + if (kvm_is_vcpu_creation_in_progress(kvm)) + return -EBUSY; + kvm_for_each_vcpu(i, vcpu, kvm) if (!mutex_trylock_nest_lock(&vcpu->mutex, &kvm->lock)) goto out_unlock; @@ -1386,6 +1389,9 @@ int kvm_lock_all_vcpus(struct kvm *kvm) lockdep_assert_held(&kvm->lock); + if (kvm_is_vcpu_creation_in_progress(kvm)) + return -EBUSY; + kvm_for_each_vcpu(i, vcpu, kvm) { r = mutex_lock_killable_nest_lock(&vcpu->mutex, &kvm->lock); if (r) -- 2.55.0.1082.g2b9226bbc0-goog