From: sashiko-bot@kernel.org
To: "Masami Hiramatsu (Google)" <mhiramat@kernel.org>
Cc: linux-perf-users@vger.kernel.org, kvm@vger.kernel.org,
linux-trace-kernel@vger.kernel.org
Subject: Re: [PATCH v17 02/13] perf/x86, KVM: Prevent host debug register leak into guest OS on NMI
Date: Tue, 22 Sep 2026 04:40:27 +0000 [thread overview]
Message-ID: <20260922044028.3AF7B1F00893@smtp.kernel.org> (raw)
In-Reply-To: <179005110742.388919.1509641807739909065.stgit@devnote2>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] perf/x86: -EBUSY in arch_install_hw_breakpoint breaks KGDB and misses NMI clobbers
--
commit f10b90aff527e68c852cc3297fd95e985f01fa91
Author: Masami Hiramatsu (Google) <mhiramat@kernel.org>
perf/x86, KVM: Prevent host debug register leak into guest OS on NMI
When KVM enters a guest OS, host hardware breakpoints are disabled
before running the guest. However, an NMI can occur while executing
in guest mode or during guest transition, where
arch_install_hw_breakpoint() can be invoked from NMI context.
If arch_install_hw_breakpoint() is executed while the CPU is in guest
mode or during the VM entry transition window, hardware debug registers
can be modified with host breakpoint settings, leaking host breakpoints
into the guest OS or clobbering the guest's debug registers.
> diff --git a/arch/x86/kernel/hw_breakpoint.c b/arch/x86/kernel/hw_breakpoint.c
> index f846c15f21ca1..0473a5c958566 100644
> --- a/arch/x86/kernel/hw_breakpoint.c
> +++ b/arch/x86/kernel/hw_breakpoint.c
> @@ -102,6 +102,9 @@ int arch_install_hw_breakpoint(struct perf_event *bp)
>
> lockdep_assert_irqs_disabled();
>
> + if (perf_guest_in_guest())
> + return -EBUSY;
> +
[Severity: High]
Does returning -EBUSY here break KGDB?
If an NMI (e.g., KGDB entry) occurs while the CPU is in guest mode, this
will return -EBUSY. In arch/x86/kernel/kgdb.c:kgdb_correct_hw_break(), it
receives this and leaves the breakpoint permanently disabled, since it does
not retry:
val = arch_install_hw_breakpoint(bp);
if (!val)
bp->attr.disabled = 0;
Also, since arch_uninstall_hw_breakpoint() and hw_breakpoint_restore() in
arch/x86/kernel/hw_breakpoint.c do not have this perf_guest_in_guest()
check, will they still unconditionally write host state to the physical DR7
register?
For example, if KGDB removes breakpoints or resumes the CPU during guest
mode, they might still clobber the guest's active DR7:
arch/x86/kernel/hw_breakpoint.c:arch_uninstall_hw_breakpoint() {
...
dr7 &= ~__encode_dr7(i, info->len, info->type);
set_debugreg(dr7, 7);
...
}
arch/x86/kernel/hw_breakpoint.c:hw_breakpoint_restore() {
...
set_debugreg(__this_cpu_read(cpu_dr7), 7);
...
}
> for (i = 0; i < HBP_NUM; i++) {
> struct perf_event **slot = this_cpu_ptr(&bp_per_reg[i]);
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/179005108298.388919.4535333252892590932.stgit@devnote2?part=2
next prev parent reply other threads:[~2026-09-22 4:40 UTC|newest]
Thread overview: 44+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 4:24 [PATCH v17 00/13] tracing: wprobe: x86: Add wprobe for watchpoint Masami Hiramatsu (Google)
2026-09-22 4:24 ` [PATCH v17 01/13] x86/mce: Fix hardware debug register corruption on task migration Masami Hiramatsu (Google)
2026-09-22 4:40 ` sashiko-bot
2026-09-23 0:27 ` Borislav Petkov
2026-09-23 8:46 ` Peter Zijlstra
2026-09-23 8:56 ` Masami Hiramatsu
2026-09-22 4:25 ` [PATCH v17 02/13] perf/x86, KVM: Prevent host debug register leak into guest OS on NMI Masami Hiramatsu (Google)
2026-09-22 4:40 ` sashiko-bot [this message]
2026-09-23 8:51 ` Peter Zijlstra
2026-09-23 14:33 ` Sean Christopherson
2026-09-24 1:31 ` Masami Hiramatsu
2026-09-24 9:18 ` Peter Zijlstra
2026-09-23 9:15 ` Peter Zijlstra
2026-09-23 15:32 ` Sean Christopherson
2026-09-24 0:56 ` Masami Hiramatsu
2026-09-24 9:23 ` Peter Zijlstra
2026-09-22 4:25 ` [PATCH v17 03/13] x86/hw_breakpoints: Make DR7 updates NMI safe Masami Hiramatsu (Google)
2026-09-22 4:40 ` sashiko-bot
2026-09-23 9:13 ` Peter Zijlstra
2026-09-24 12:56 ` Masami Hiramatsu
2026-09-22 4:25 ` [PATCH v17 04/13] x86/hw_breakpoints: Add arch_modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22 4:39 ` sashiko-bot
2026-09-22 4:25 ` [PATCH v17 05/13] HWBP: Add modify_local_hw_breakpoint_addr() API Masami Hiramatsu (Google)
2026-09-22 4:35 ` sashiko-bot
2026-09-22 4:25 ` [PATCH v17 06/13] tracing/wprobe: Add wprobe (watchpoint probe) trace event support Masami Hiramatsu (Google)
2026-09-22 4:41 ` sashiko-bot
2026-09-22 4:26 ` [PATCH v17 07/13] x86: hw_breakpoint: Add a kconfig to clarify when a breakpoint fires Masami Hiramatsu (Google)
2026-09-22 4:32 ` sashiko-bot
2026-09-22 4:26 ` [PATCH v17 08/13] selftests: tracing: Add a basic testcase for wprobe Masami Hiramatsu (Google)
2026-09-22 4:32 ` sashiko-bot
2026-09-22 4:26 ` [PATCH v17 09/13] selftests: tracing: Add syntax " Masami Hiramatsu (Google)
2026-09-22 4:34 ` sashiko-bot
2026-09-22 4:26 ` [PATCH v17 10/13] tracing/wprobe: Add set_wprobe and clear_wprobe event triggers Masami Hiramatsu (Google)
2026-09-22 4:43 ` sashiko-bot
2026-09-25 2:26 ` Masami Hiramatsu
2026-09-22 4:26 ` [PATCH v17 11/13] selftests: tracing: Add wprobe trigger testcases Masami Hiramatsu (Google)
2026-09-22 4:41 ` sashiko-bot
2026-09-25 3:28 ` Masami Hiramatsu
2026-09-22 4:27 ` [PATCH v17 12/13] tracing/wprobe: Support BTF typecast in fetchargs Masami Hiramatsu (Google)
2026-09-22 4:42 ` sashiko-bot
2026-09-22 4:27 ` [PATCH v17 13/13] tracing/wprobe: Support BTF struct offset resolution in set_wprobe trigger Masami Hiramatsu (Google)
2026-09-22 4:43 ` sashiko-bot
2026-09-25 3:00 ` Masami Hiramatsu
2026-09-25 3:42 ` Masami Hiramatsu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922044028.3AF7B1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-perf-users@vger.kernel.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mhiramat@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox