From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f202.google.com (mail-pl1-f202.google.com [209.85.214.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B977E3D75D7 for ; Thu, 18 Jun 2026 18:57:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781809068; cv=none; b=n4X/MAd7cm8FS+IIHIk2tNQjtRHlH2JSbKW7fD7R2obWGE3ULY8V8kZZXuw3Qt5ASorSfAWDwacZZNQTcr5Ezpaba+nCQ5R7TPErnoOb7vgKMLTdvKrXdVZPsKbTGxd2tgNyjf6wsR0hG2u9/ZsOpkj1kRFfp6oq/2KeIzFI27o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781809068; c=relaxed/simple; bh=py7MQuy0S7siRplUy2+/e8TsqyKHJJRmnIvIe4TCPII=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=Mk+5IlUQlZr2OPamTIdLnlfdZRkQmPUMhdoJMZ9Nszv9HoivUvgz0YtYstVHxrs2vuhWmlkE/74SWhHsFP2LbdVq7HH5LQNrZNukidFUNTV5rsJuOmFtV+ozRTBlWw/KcJ73vIF3hmGvqyvcUygwVaxC5PGRoWDfzWlnXHi1y5M= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ByNdXZ4Z; arc=none smtp.client-ip=209.85.214.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ByNdXZ4Z" Received: by mail-pl1-f202.google.com with SMTP id d9443c01a7336-2c2b64850easo26539105ad.1 for ; Thu, 18 Jun 2026 11:57:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1781809067; x=1782413867; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=mZ1GTFxb1Ow96qVZrCxGwuuaR1ChhefSmDJIgPYjMY4=; b=ByNdXZ4ZOIpE9xK7tiP2XUZRpBAtVGMz/WcKXmZMlg3W+tbJgKEschUQXLCizBW3Sr LbVOS2Xv+DLJG3zRSnsnDBF38HjB3tQcku5gw4VET6ts+79zYmOq9OD/MpPPK+AT9FcP sJVVUiSRl+/vO1Zz/9XmaYgfYPZqifqOXgqdCSiSGuoyZLPAhwmj6lnvLIHkwOf/waEZ ODehUUIRdkaPObnunzTDXLV5RpG8DCYAzQ0RbkuIih394b4n7bPDicKlFk4IOJBU789K xRuPjN03umUYl9U8AUZKahaCka2X6+ENGECWtDkvA691E56zaaWf98OKr9nvbTv6VDTx WBTg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781809067; x=1782413867; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=mZ1GTFxb1Ow96qVZrCxGwuuaR1ChhefSmDJIgPYjMY4=; b=q7mLu1eGGsFMHL/eXK+7d+LESE7Km279eVeqKJVK3g7fldJg7tKP1jIpnV4mZKnlQv izq3+kjn/y1FGte8ADGmBrQZuSGYC1yynH6kA71QOx5LWyyYsOLdCV8YWXdqhTfBZFvz ggbNa7gVcahZe3o9HQtiqJw/V9FSWsZq7bC45u5QiqbuV8awWmn/7J3igmuHChZfJ2qG LO/KkSjY2diqw5f9cPG8N4lL3m/gz4j9kldiq+GVzf4GRo7X7F7X2XV1QASL4rxfLFhX bFBQPO9ZrGTOPpSF7H7jixzkxhXW4sHWfS8fQp/2ifytgKbU0FHRwY/4QZL2tgmTowUh qbrA== X-Forwarded-Encrypted: i=1; AFNElJ/nVX5JhClR1rj3EBbj01MjRTYvbnBH06dFsuIGskgUh8Hssx1ot7zRf/8QHpi2NrWVI7qUJfgCnl+6M94=@vger.kernel.org X-Gm-Message-State: AOJu0YzxY3bPYLg77rGrLYsVaRFaIoUs2NyObjyRZACfXFOLt6ArCSmn S3TWDa7IFV6d5Wiz2xYNjrvaviZGd57VKE+YZnUiOwH5K8SY3gXQ67pg0CqezP0Uju3NGGPz1Ne xTHtjYQ== X-Received: from plbla14.prod.google.com ([2002:a17:902:fa0e:b0:2c6:a033:d607]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:fc43:b0:2bd:907:2cf0 with SMTP id d9443c01a7336-2c718f417f0mr5985345ad.32.1781809067054; Thu, 18 Jun 2026 11:57:47 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 18 Jun 2026 11:57:45 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.rc0.738.g0c8ab3ebcc-goog Message-ID: <20260618185746.2023283-1-seanjc@google.com> Subject: [PATCH] KVM: x86: Replace BUG_ON() with WARN_ON_ONCE() on "bad" nested GPA translation From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org Content-Type: text/plain; charset="UTF-8" If KVM attempts to translate what it thinks is an L2 GPA with a non-nested MMU, simply WARN and return the GPA, i.e. trust the MMU more than the caller, as there is zero reason to potentially panic the host kernel just because KVM misused an API. Signed-off-by: Sean Christopherson --- arch/x86/kvm/svm/nested.c | 3 ++- arch/x86/kvm/vmx/nested.c | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c index 9aedb88c832d..3e6c671a8dc2 100644 --- a/arch/x86/kvm/svm/nested.c +++ b/arch/x86/kvm/svm/nested.c @@ -2152,7 +2152,8 @@ static gpa_t svm_translate_nested_gpa(struct kvm_vcpu *vcpu, gpa_t gpa, struct vcpu_svm *svm = to_svm(vcpu); struct kvm_mmu *mmu = vcpu->arch.mmu; - BUG_ON(!mmu_is_nested(vcpu)); + if (WARN_ON_ONCE(!mmu_is_nested(vcpu))) + return gpa; /* Non-GMET walks are always user-walks */ if (!(svm->nested.ctl.misc_ctl & SVM_MISC_ENABLE_GMET)) diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c index 3a293640d58c..6957bb6f5cf7 100644 --- a/arch/x86/kvm/vmx/nested.c +++ b/arch/x86/kvm/vmx/nested.c @@ -7470,7 +7470,8 @@ static gpa_t vmx_translate_nested_gpa(struct kvm_vcpu *vcpu, gpa_t gpa, { struct kvm_mmu *mmu = vcpu->arch.mmu; - BUG_ON(!mmu_is_nested(vcpu)); + if (WARN_ON_ONCE(!mmu_is_nested(vcpu))) + return gpa; /* * MBEC differentiates based on the effective U/S bit of base-commit: 9d4853b044beefa21c4ee3e18c40653601a64ced -- 2.55.0.rc0.738.g0c8ab3ebcc-goog