From: Yosry Ahmed <yosry@kernel.org>
To: Sean Christopherson <seanjc@google.com>
Cc: Paolo Bonzini <pbonzini@redhat.com>,
kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Yosry Ahmed <yosry@kernel.org>
Subject: [PATCH v5 00/13] KVM: selftests: Stress save+restore and #PF (ft. nested)
Date: Tue, 28 Jul 2026 17:42:19 +0000 [thread overview]
Message-ID: <20260728174232.2423257-1-yosry@kernel.org> (raw)
Add a stress test for save+restore while the guest is triggering and
handling #PFs, in both L1 and L2. The goal was to create a generic
selftest that would catch bugs like the one fixed by commit 5c247d08bc81
("KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested
#VMEXIT"), instead of relying on high-level testing (e.g. building GCC
in L2) to catch it.
The test tries to be as generic as possible by triggering #PFs in a
guest and installing a proper #PF handler, while the host is
continuously doing save+restore cycles. Exiting to userspace is randomly
triggered by a second thread that constantly signals the vCPU thread.
Patches (1-6) are prep patches, fixing GPR and RFLAGS switching for nSVM
and generalizing GPR switching to cover nVMX, which is needed for the
test to run properly with nVMX. Patch 6 removes
HORRIFIC_L2_UCALL_CLOBBER_HACK, as it is no longer needed. While this
series does not have the "complete" fix added by commit 6783ca4105a7
("KVM: selftests: Add a shameful hack to preserve/clobber GPRs across
ucall"), it's a good step in the right direction.
Patches (7-9) add minor infrastructure improvements (assertion failure
formatting and exposing MMU masks to the guest).
Patches (10-13) add the actual test. The test is first introduced as a
simple (read: dummy) stress test that just explicitly syncs to userspace
after each #PF handling to do save+restore, then gradually evolves to
add the random signaling, nested support, and triggering L2->L1 exits.
After the last patch, the test reliably reproduces the CR2 bug.
v4 -> v5:
- Only set KVM_CAP_EXCEPTION_PAYLOAD when running nested [Sashiko].
- Do not intercept #PF by default for nVMX tests [Sean].
- Nits and cleanups [Sean].
v3 -> v4:
- Switch guest_regs back to a struct and provide struct offsets as
ASM constraints similar to kvm-unit-tests [Sean].
- Expose PTE masks to guests as part of a guest MMU [Sean].
- Use __stringify() from <linux/stringify.h> instead of custom STR() and
XSTR() macros [Sean].
- Handle guest RFLAGS save/restore as part of guest_regs.
- Run both L0 and L2 tests sequentially by default if nested is supported,
instead of requiring a '-n' command line argument [Sean].
- Minor fixups and cleanups [Sean].
v2 -> v3:
- Rebased on top of L2 stack rework in selftests.
- Fix GPR array size (i.e. NR_GUEST_REGS) [Sashiko].
- Handle evmcs_vmlaunch() and evmcs_vmresume() [Sashiko].
- Fix off-by-one assertion error in intermediate patches.
- Increase inter-signal delay from 100us to 1msec.
v1 -> v2:
- Switch guest_regs to an array, which simplifies the offsets
calculation and forgoes the dependency on using OFFSET() or defining
the struct offsets for assembly otherwise.
- Move page table mapping to the test (instead of a generic helper), as
the helper mistakenly tried to map the entire memslot, not just page
tables.
- Do not use identity mappings for page tables as it collisions with
GVAs used for ELF in some cases.
- Simplify page table walking by using loops.
- Make sure the signals are ignored before creating the signaling
thread [Sashiko]
- Assert that the guest actually ran and had page faults [Sashiko]
- Add a patch to fix RAX and RFLAGS offsets in run_guest() [Sashiko]
- Initialize exception_has_payload when injecting a #UD [Sashiko]
- Only check KVM_STATE_NESTED_GUEST_MODE when running in nested mode
[Sashiko]
v1: https://lore.kernel.org/all/20260518202514.2037078-1-yosry@kernel.org/
v2: https://lore.kernel.org/kvm/20260604203546.365658-1-yosry@kernel.org/
v3: https://lore.kernel.org/kvm/20260629183746.699840-1-yosry@kernel.org/
v4: https://lore.kernel.org/kvm/20260727235228.1007324-1-yosry@kernel.org/
Yosry Ahmed (13):
KVM: selftests: Use __stringify() instead of custom XSTR() macros
KVM: selftests: Fix RAX and RFLAGS VMCB offsets when running L2
KVM: selftests: Rework GPR registers switching for SVM (and fix
offsets)
KVM: selftests: Handle rflags save/restore for SVM in guest_regs
KVM: selftests: Reuse GPR switching logic for nVMX
KVM: selftests: Drop HORRIFIC_L2_UCALL_CLOBBER_HACK
KVM: selftests: Add a blank line before logging assertion failures
KVM: selftests: Expose PTE masks to guests as part of an MMU
KVM: selftests: Do not intercept #PF by default in nVMX tests
KVM: selftests: Add basic stress test for save+restore and #PF
handling
KVM: selftests: Trigger save+restore randomly in the #PF stress test
KVM: selftests: Support running stress save+restore and #PF test in L2
KVM: selftests: Trigger L2->L1 exits stress save+restore and #PF test
tools/testing/selftests/kvm/Makefile.kvm | 1 +
.../testing/selftests/kvm/include/test_util.h | 1 +
.../testing/selftests/kvm/include/x86/evmcs.h | 46 +--
.../selftests/kvm/include/x86/processor.h | 52 +++-
tools/testing/selftests/kvm/include/x86/vmx.h | 69 ++---
tools/testing/selftests/kvm/lib/assert.c | 2 +-
.../testing/selftests/kvm/lib/x86/processor.c | 14 +
tools/testing/selftests/kvm/lib/x86/svm.c | 62 ++--
tools/testing/selftests/kvm/lib/x86/ucall.c | 32 +-
tools/testing/selftests/kvm/lib/x86/vmx.c | 2 +-
.../kvm/x86/evmcs_smm_controls_test.c | 5 +-
.../selftests/kvm/x86/fix_hypercall_test.c | 1 -
.../kvm/x86/save_restore_pf_stress_test.c | 288 ++++++++++++++++++
tools/testing/selftests/kvm/x86/smm_test.c | 5 +-
14 files changed, 439 insertions(+), 141 deletions(-)
create mode 100644 tools/testing/selftests/kvm/x86/save_restore_pf_stress_test.c
base-commit: 271255273d5ff348fe29d89fe4712b2f7f7907c3
--
2.55.0.487.gaf234c4eb3-goog
next reply other threads:[~2026-07-28 17:42 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 17:42 Yosry Ahmed [this message]
2026-07-28 17:42 ` [PATCH v5 01/13] KVM: selftests: Use __stringify() instead of custom XSTR() macros Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 02/13] KVM: selftests: Fix RAX and RFLAGS VMCB offsets when running L2 Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 03/13] KVM: selftests: Rework GPR registers switching for SVM (and fix offsets) Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 04/13] KVM: selftests: Handle rflags save/restore for SVM in guest_regs Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 05/13] KVM: selftests: Reuse GPR switching logic for nVMX Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 06/13] KVM: selftests: Drop HORRIFIC_L2_UCALL_CLOBBER_HACK Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 07/13] KVM: selftests: Add a blank line before logging assertion failures Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 08/13] KVM: selftests: Expose PTE masks to guests as part of an MMU Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 09/13] KVM: selftests: Do not intercept #PF by default in nVMX tests Yosry Ahmed
2026-07-28 17:45 ` Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 10/13] KVM: selftests: Add basic stress test for save+restore and #PF handling Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 11/13] KVM: selftests: Trigger save+restore randomly in the #PF stress test Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 12/13] KVM: selftests: Support running stress save+restore and #PF test in L2 Yosry Ahmed
2026-07-28 17:42 ` [PATCH v5 13/13] KVM: selftests: Trigger L2->L1 exits stress save+restore and #PF test Yosry Ahmed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260728174232.2423257-1-yosry@kernel.org \
--to=yosry@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox