From: Mushahid Hussain <hmushi@amazon.co.uk>
To: <kvm@vger.kernel.org>
Cc: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>,
Vitaly Kuznetsov <vkuznets@redhat.com>,
"K . Y . Srinivasan" <kys@microsoft.com>,
Haiyang Zhang <haiyangz@microsoft.com>,
"Wei Liu" <wei.liu@kernel.org>, Dexuan Cui <decui@microsoft.com>,
Long Li <longli@microsoft.com>, <linux-hyperv@vger.kernel.org>,
<linux-kernel@vger.kernel.org>, <nh-open-source@amazon.com>,
<mushi.shar@gmail.com>, <stable@vger.kernel.org>
Subject: [PATCH 1/3] KVM: nVMX: Clear stale vmcs02 sync flag in free_nested()
Date: Mon, 5 Oct 2026 19:24:29 +0000 [thread overview]
Message-ID: <20261005192431.87317-2-hmushi@amazon.co.uk> (raw)
In-Reply-To: <20261005192431.87317-1-hmushi@amazon.co.uk>
free_nested() frees vmcs02 but leaves need_sync_vmcs02_to_vmcs12_rare
set. The flag means that the rare guest fields of vmcs12 are valid
only in vmcs02. After vmcs02 is freed the flag is wrong.
L1 then executes VMXON and loads a vmcs12 with VMPTRLD. The flag is
still set, so the first sync copies the rare fields from the new,
never launched vmcs02 into vmcs12. This sets TR, LDTR, GDTR, IDTR,
the segment registers and the FS/GS bases to zero in guest memory.
set_current_vmptr() re-arms the other lazy flags at VMPTRLD. This
flag has no such point, so VMXOFF is the place to clear it.
A nested Hyper-V follows this sequence when it resumes from
hibernation. It executes VMXOFF before hibernation. On resume, it
reloads the VMCS images that winresume restored from the hiberfile.
VM-entry fails with exit reason 0x80000021 (invalid guest state) and
the guest hypervisor resets the machine. vmx_leave_nested() also goes
through free_nested(), so KVM_SET_NESTED_STATE takes the same path.
Clear the flag together with the other nested state.
Fixes: 7952d769c29c ("KVM: nVMX: Sync rarely accessed guest fields only when needed")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-fable-5.1
Signed-off-by: Mushahid Hussain <hmushi@amazon.co.uk>
---
arch/x86/kvm/vmx/nested.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
index 9b0bfa2f854cf..6c3723ddd40b8 100644
--- a/arch/x86/kvm/vmx/nested.c
+++ b/arch/x86/kvm/vmx/nested.c
@@ -350,6 +350,7 @@ static void free_nested(struct kvm_vcpu *vcpu)
vmx->nested.vmxon = false;
vmx->nested.smm.vmxon = false;
vmx->nested.vmxon_ptr = INVALID_GPA;
+ vmx->nested.need_sync_vmcs02_to_vmcs12_rare = false;
free_vpid(vmx->nested.vpid02);
vmx->nested.posted_intr_nv = -1;
vmx->nested.current_vmptr = INVALID_GPA;
--
2.47.3
next prev parent reply other threads:[~2026-10-05 19:25 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 19:24 [PATCH 0/3] KVM: x86: Support hibernation of a nested Hyper-V Mushahid Hussain
2026-10-05 19:24 ` Mushahid Hussain [this message]
2026-10-05 19:24 ` [PATCH 2/3] KVM: x86: Extract __kvm_set_clock() from kvm_vm_ioctl_set_clock() Mushahid Hussain
2026-10-05 19:24 ` [PATCH 3/3] KVM: x86: hyper-v: Implement HvCallRestorePartitionTime Mushahid Hussain
2026-10-05 19:38 ` sashiko-bot
2026-10-05 22:30 ` David Woodhouse
2026-10-06 5:08 ` [PATCH 0/3] KVM: x86: Support hibernation of a nested Hyper-V David Woodhouse
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005192431.87317-2-hmushi@amazon.co.uk \
--to=hmushi@amazon.co.uk \
--cc=decui@microsoft.com \
--cc=haiyangz@microsoft.com \
--cc=kvm@vger.kernel.org \
--cc=kys@microsoft.com \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=mushi.shar@gmail.com \
--cc=nh-open-source@amazon.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=stable@vger.kernel.org \
--cc=vkuznets@redhat.com \
--cc=wei.liu@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox