From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 42D9F31B812 for ; Wed, 7 Jan 2026 20:26:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767817598; cv=none; b=lydToixi5d6zbT+Ay35Cs6LyHbsvgDJ3jRHPiW74j4227LFlYT4TPwnm6g4+yayZgQImgqC4lQReuPe7Vle9b2JVwskcfpNZ/nEiDUlFbcOGOSF0sqje2lqIVQsUpkTjIkL7CTGZlow51+Dk3Gv4B/gIzrxfSx6TlABkW+O/F1I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767817598; c=relaxed/simple; bh=YWyxU/k0Mp4ZkLGCfAsfY27rBV1JmN5lmhmwnKWE8mI=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=hkHMzZlfKHyEhAUEga39Czfxg1vINojdruFB5Dh90U0cRpeIrkTdho5bj1C56/vdeaLPe7eGcd53i3dPw0Dhov71HNvR/IY9Wm74DwtDeZCJ3MQ+ZD7oir4vOOoCaTIiR247EdwnySE46Y0KDqtXkWWCE8L3u7MY2RCnMepyfF8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=NkGzPQ7l; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="NkGzPQ7l" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2a0bae9acd4so20290305ad.3 for ; Wed, 07 Jan 2026 12:26:37 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1767817597; x=1768422397; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=CsoItjovREIZYxetg6rcpfyKc8gupMs4pUCId31XNsM=; b=NkGzPQ7lvyih1LO8fVbTlKiZ75L4lcIA2/ploBjB7Sgk9mkcw1B7xFFpFtT5OqbFgj 6qZLIyL7HbvJXSpF0qzEhE0oEC7sPwEAMh4mvt23KIVsCB7mY7z4TKHJb0u18s6s2Vwe CeGnNqaVSOna3OUY/8lKzaeWv86rR32it8bE+7PtwdzpWeOPQLKlqH4apNsTlk7KkhGT dqDMcSr1i1YHf4XeiPI7Z2LB9QzRm45OMivwQKM0bQONVo++JqjRkyOFqdNB3eFpHTfu 9E+hr2f22sTnPn6mp1geN/or0vsVRjONBIWHrdsUokvoxjENUCczc/7Tx71KzQ/xc1fk aUYw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767817597; x=1768422397; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=CsoItjovREIZYxetg6rcpfyKc8gupMs4pUCId31XNsM=; b=rdfqQflob3UKm/+vxX/T2qY2c+aVXlaZNlLhaJNVGmhVnoSeOcrM4QCIftjwdNYAVc DtzIASA21SDSZwEHCa6YbhimHWCQ1I7FCH/zSDJqfJG4K+EB7Jhh3Om1w+WAGXuWX3Gl zdPGln/pWYRxlLj0Wgf0mwNFZdlzdb4APd+V+rNJ4jRvjK3YDXv43mDjf2wOPd73YJrh CIMxGFTtx6qYfO96Af9CYtEpGLRm7zH7n1SshOBHJwNHmksKhxC+xF7ZwtJjzK9V/PWJ Yb8VIf4FPxHrgYWqjmZSY44nn0+MP4EhYlwNZ+8azxJAIQw0kVPTsZU2f9QCSRIYvpOa 8TVg== X-Forwarded-Encrypted: i=1; AJvYcCVsddkSfZH4mKJtBnofS2DLg2fapK27s1+fqziqywpbnUC8FtW6yGoxVLwlZoOA5JEPHUWb6tHIJxo/s8M=@vger.kernel.org X-Gm-Message-State: AOJu0Yzfnx9XTj5O2sjNbw9B3FIRu23eJmGgX+B0at+W6ew0P9fqWEji mn+mdcu2aKf3kP4pHE0kKi23JLtZFrsW3J/C8Bs8USwHr4Rovo3m0KFoAIOgv4fEO1O6lReuHBR CDRFGhw== X-Google-Smtp-Source: AGHT+IGTQp8h1kLtlKev9LhcYdbZPkpIr4HJH3gtESE8OQAlg41p7sVR2D1YicwFAm7r4ks6pGsYokdc19I= X-Received: from plbbh11.prod.google.com ([2002:a17:902:a98b:b0:2a0:dab8:9117]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:2a85:b0:2a0:8f6f:1a0d with SMTP id d9443c01a7336-2a3ee4c0fefmr34205855ad.61.1767817596631; Wed, 07 Jan 2026 12:26:36 -0800 (PST) Date: Wed, 7 Jan 2026 12:26:35 -0800 In-Reply-To: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20251230205641.4092235-1-seanjc@google.com> Message-ID: Subject: Re: [PATCH] KVM: x86: Disallow setting CPUID and/or feature MSRs if L2 is active From: Sean Christopherson To: Yosry Ahmed Cc: Paolo Bonzini , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Kevin Cheng Content-Type: text/plain; charset="us-ascii" On Fri, Jan 02, 2026, Yosry Ahmed wrote: > On Tue, Dec 30, 2025 at 12:56:41PM -0800, Sean Christopherson wrote: > > diff --git a/arch/x86/kvm/x86.h b/arch/x86/kvm/x86.h > > index fdab0ad49098..9084e0dfa15c 100644 > > --- a/arch/x86/kvm/x86.h > > +++ b/arch/x86/kvm/x86.h > > @@ -172,9 +172,9 @@ static inline void kvm_nested_vmexit_handle_ibrs(struct kvm_vcpu *vcpu) > > indirect_branch_prediction_barrier(); > > } > > > > -static inline bool kvm_vcpu_has_run(struct kvm_vcpu *vcpu) > > +static inline bool kvm_can_set_cpuid_and_feature_msrs(struct kvm_vcpu *vcpu) > > { > > - return vcpu->arch.last_vmentry_cpu != -1; > > + return vcpu->arch.last_vmentry_cpu == -1 && !is_guest_mode(vcpu); > > } > > To make this self-contained (e.g. for readers not coming from > kvm_set_cpuid()), should we add a comment here about is_guest_mode() > only possibly being true with last_vmentry_cpu == -1 if userspace does > the set CPUID, set nested state, set CPUID again dance? Ya. If this looks good, I'll add it when applying. /* * Disallow modifying CPUID and feature MSRs, which affect the core virtual CPU * model exposed to the guest and virtualized by KVM, if the vCPU has already * run or is in guest mode (L2). In both cases, KVM has already consumed the * current virtual CPU model, and doesn't support "unwinding" to react to the * new model. * * Note, the only way is_guest_mode() can be true with 'last_vmentry_cpu == -1' * is if userspace sets CPUID and feature MSRs (to enable VMX/SVM), then sets * nested state, and then attempts to set CPUID and/or feature MSRs *again*. */ static inline bool kvm_can_set_cpuid_and_feature_msrs(struct kvm_vcpu *vcpu) { return vcpu->arch.last_vmentry_cpu == -1 && !is_guest_mode(vcpu); }