From: Wei Liu <wei.liu@kernel.org>
To: mhklinux@outlook.com
Cc: kys@microsoft.com, haiyangz@microsoft.com, wei.liu@kernel.org,
decui@microsoft.com, longli@microsoft.com, tglx@kernel.org,
mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com,
x86@kernel.org, hpa@zytor.com, linux-hyperv@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH 1/1] x86/hyperv: Avoid using per-cpu output page in hv_apicid_to_vp_index()
Date: Tue, 1 Sep 2026 17:52:36 -0700 [thread overview]
Message-ID: <20260902005236.GB2583463@liuwe-devbox-debian-v2.local> (raw)
In-Reply-To: <20260901193236.540188-1-mhklinux@outlook.com>
On Tue, Sep 01, 2026 at 12:32:36PM -0700, Michael Kelley wrote:
> hv_apicid_to_vp_index() currently uses the per-cpu hypercall input
> and output pages. This function is called when running in VTL2 and
> when running in an SEV-SNP CoCo VM with no paravisor. In the former
> case, the output page is allocated, but in the latter case it is
> not, so the hypervisor stores the output VP index in memory that has
> not been allocated by the guest.
>
> Fix this by using the input page for both input and output. The
> hypercall has very small input and output, so sharing the same
> page for both is straightforward. An alternative fix is to
> allocate the per-cpu output page when running in an SEV-SNP CoCo
> guest, but this uses significantly more memory, particularly
> with larger vCPU counts.
>
> Fixes: 86c48271e0d6 ("x86/hyperv: Fix APIC ID and VP index confusion in hv_snp_boot_ap()")
> Signed-off-by: Michael Kelley <mhklinux@outlook.com>
> ---
>
> I'm not aware that this bug is causing any real problems because
> SEV-SNP CoCo VMs on Hyper-V are rarely, if ever, used without a
> paravisor. But it was on my list of little clean-ups to do, and
> a recent Sashiko analysis [1] flagged the issue. So the best thing
> to do is just fix it.
>
> [1] https://lore.kernel.org/linux-hyperv/20260901171238.834601F00A3A@smtp.kernel.org/
Thanks Michael. You beat me to it.
Wei
>
> arch/x86/hyperv/hv_init.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/arch/x86/hyperv/hv_init.c b/arch/x86/hyperv/hv_init.c
> index d5edc8530964..d0302bf2641e 100644
> --- a/arch/x86/hyperv/hv_init.c
> +++ b/arch/x86/hyperv/hv_init.c
> @@ -731,7 +731,8 @@ int hv_apicid_to_vp_index(u32 apic_id)
> input->partition_id = HV_PARTITION_ID_SELF;
> input->apic_ids[0] = apic_id;
>
> - output = *this_cpu_ptr(hyperv_pcpu_output_arg);
> + /* Treat input as having 2 APIC IDs so output is 64-bit aligned */
> + output = (u32 *)((void *)input + struct_size(input, apic_ids, 2));
>
> control = HV_HYPERCALL_REP_COMP_1 | HVCALL_GET_VP_INDEX_FROM_APIC_ID;
> status = hv_do_hypercall(control, input, output);
> --
> 2.25.1
>
prev parent reply other threads:[~2026-09-02 0:52 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 19:32 [PATCH 1/1] x86/hyperv: Avoid using per-cpu output page in hv_apicid_to_vp_index() Michael Kelley
2026-09-02 0:52 ` Wei Liu [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902005236.GB2583463@liuwe-devbox-debian-v2.local \
--to=wei.liu@kernel.org \
--cc=bp@alien8.de \
--cc=dave.hansen@linux.intel.com \
--cc=decui@microsoft.com \
--cc=haiyangz@microsoft.com \
--cc=hpa@zytor.com \
--cc=kys@microsoft.com \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=mhklinux@outlook.com \
--cc=mingo@redhat.com \
--cc=tglx@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox