From: Sean Christopherson <seanjc@google.com>
To: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Paul Durrant <paul@xen.org>, David Woodhouse <dwmw@amazon.co.uk>,
Dongli Zhang <dongli.zhang@oracle.com>
Subject: [PATCH v9 13/21] KVM: x86: Fix compute_guest_tsc() to handle negative time deltas
Date: Mon, 10 Aug 2026 15:54:51 -0700 [thread overview]
Message-ID: <20260810225500.869288-14-seanjc@google.com> (raw)
In-Reply-To: <20260810225500.869288-1-seanjc@google.com>
From: David Woodhouse <dwmw@amazon.co.uk>
The compute_guest_tsc() function computes the guest TSC at a given
kernel_ns timestamp. When the master clock reference point
(master_kernel_ns) is earlier than vcpu->arch.this_tsc_nsec, the delta
is negative. Since pvclock_scale_delta() takes a u64, the negative
value wraps to a huge positive number, producing a wildly wrong result.
Handle negative deltas explicitly by scaling the absolute value of the
delta and applying it to this_tsc_write with the appropriate sign.
This is believed to be unreachable in practice; no path has been
identified which invokes compute_guest_tsc() with a timestamp from
before the vCPU's TSC generation was established. Fix it for
robustness, in the spirit of defence in depth.
Signed-off-by: David Woodhouse <dwmw@amazon.co.uk>
Signed-off-by: Sean Christopherson <seanjc@google.com>
---
arch/x86/kvm/x86.c | 14 +++++++++-----
1 file changed, 9 insertions(+), 5 deletions(-)
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 50e92090ba65..76c16a15f059 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -1054,11 +1054,15 @@ static int kvm_set_tsc_khz(struct kvm_vcpu *vcpu, u32 user_tsc_khz)
static u64 compute_guest_tsc(struct kvm_vcpu *vcpu, s64 kernel_ns)
{
- u64 tsc = pvclock_scale_delta(kernel_ns-vcpu->arch.this_tsc_nsec,
- vcpu->arch.virtual_tsc_mult,
- vcpu->arch.virtual_tsc_shift);
- tsc += vcpu->arch.this_tsc_write;
- return tsc;
+ s64 delta_ns = kernel_ns - vcpu->arch.this_tsc_nsec;
+ u64 tsc;
+
+ /* Handle negative deltas gracefully (master clock ref may be earlier) */
+ tsc = pvclock_scale_delta(abs(delta_ns),
+ vcpu->arch.virtual_tsc_mult,
+ vcpu->arch.virtual_tsc_shift);
+
+ return vcpu->arch.this_tsc_write + (delta_ns >= 0 ? tsc : -tsc);
}
#ifdef CONFIG_X86_64
--
2.55.0.679.g6767b8d81c-goog
next prev parent reply other threads:[~2026-08-10 22:55 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-10 22:54 [PATCH v9 00/21] KVM: x86: Cleaning up the KVM clock mess, part 1 Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 01/21] KVM: x86: Update "last guest TSC" snapshot prior to enabling IRQs/preemption Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 02/21] KVM: x86: Improve accuracy of KVM clock when TSC scaling is in force Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 03/21] KVM: x86: Explicitly disable TSC scaling without CONSTANT_TSC Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 04/21] KVM: x86: Activate master clock immediately on vCPU creation Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 05/21] KVM: x86: Compute kvmclock base without pvclock_gtod_data Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 06/21] KVM: x86: Avoid NTP frequency skew for KVM clock on 32-bit host Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 07/21] KVM: x86: Drop unnecessary CPU pinning when computing/getting kvmclock Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 08/21] KVM: x86: Move "no master clock" fallback from __get_kvmclock() to get_kvmclock() Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 09/21] KVM: x86: Wrap all of __get_kvmclock_master_clock() with CONFIG_X86_64=y Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 10/21] KVM: x86: Fall back to non-master-clock if clockread fails in get_kvmclock() Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 11/21] KVM: x86: Fix KVM clock precision in get_kvmclock() with TSC scaling Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 12/21] KVM: x86: Use get_kvmclock() in kvm_get_wall_clock_epoch() Sean Christopherson
2026-08-10 22:54 ` Sean Christopherson [this message]
2026-08-10 22:54 ` [PATCH v9 14/21] KVM: x86: Disable preemption, not IRQs, when getting TSC+freq pair Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 15/21] KVM: x86: Make master clock logic in guest PV clock updates 64-bit only Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 16/21] KVM: x86: Upscale TSC to "now", not master clock when updating PV clocks Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 17/21] KVM: x86: Simplify and comment kvm_get_time_scale() Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 18/21] KVM: x86: Remove implicit rdtsc() from kvm_compute_l1_tsc_offset() Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 19/21] KVM: x86: Use kernel timekeeping snapshots for getting kvmclock time since boot Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 20/21] KVM: x86: Use kernel timekeeping snapshot for monotonic clock Sean Christopherson
2026-08-10 22:54 ` [PATCH v9 21/21] KVM: x86: Use kernel timekeeping snapshot to get walltime+TSC Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810225500.869288-14-seanjc@google.com \
--to=seanjc@google.com \
--cc=dongli.zhang@oracle.com \
--cc=dwmw@amazon.co.uk \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=paul@xen.org \
--cc=pbonzini@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox