From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f73.google.com (mail-pj1-f73.google.com [209.85.216.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C295D372B4D for ; Thu, 26 Feb 2026 01:47:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772070466; cv=none; b=kbxqY6S5sCNVn710RlPZL/OvcwBAQFzExorcAzJ/sU0EJ0dhsi7xxmwXsLsgzFOX0nFCC7aYlcYqt620QIZCPkpHeWcjv2rCzCih/V8sYV48r/HdAfFkLg+pGz4OurmMnowVIgPzAb8Gl2gZ/42uU1Xm+YISRh//+Snt+HnKuRk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772070466; c=relaxed/simple; bh=f134Tod3jaISOuJ/2X6eUVCIIlmvQsjuVXA48eHIo3o=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=dQcdDPYAZsbDLqQbzai+XXRK48OJqne+VkJS3kls31T+omMAS0+dXdvfrLYbs3SiK1w4Jf8j+Vxk2FTZD5wStgBz5TxFaT0miJPDj3mdGluZJkwy0i1UMR/Qa73UztsX+M4sRYAZfP4UY8NnFrzHsr4lBNcPqd29WWoEsLfS80E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=CXuyqNeP; arc=none smtp.client-ip=209.85.216.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="CXuyqNeP" Received: by mail-pj1-f73.google.com with SMTP id 98e67ed59e1d1-358ffccebf1so203132a91.3 for ; Wed, 25 Feb 2026 17:47:44 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1772070464; x=1772675264; darn=vger.kernel.org; h=content-transfer-encoding:cc:to:from:subject:message-id:references :mime-version:in-reply-to:date:from:to:cc:subject:date:message-id :reply-to; bh=/KnV4oVfH16sVxdEzAUkTHJmU2+lcl4+7S0fmyw+FdU=; b=CXuyqNePFFpK1cxDXeV8kW4rBUXHSPmXmqJFhGvYrpeNgXn8OD6rOKo1p+Sev4vk6+ gxScI9fMaHwpKrGorgsw951lXmZTg6FYjHbpNti/2JGhhv3Z/4dcq5gnZbq6qPWgXEXi fnVND3mSJ+aVCCPyM9u0AFQGfeKz1jYxZU1tEtd2AruXQmDTEtMwPSKz0kYY9oXHuo49 sH+PB4svngmKTfg8B6px64fM6pgw2WwN2n5VWhm0BLTsSxKT8guxB/KoyiYZ3uwK1cGj NNHsNAaptBsCi0hFbPIdT1vMoiJOIUP505o99nt4M/PD6EzrkkiQNzILGSO+3/gtNCBx ORwg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772070464; x=1772675264; h=content-transfer-encoding:cc:to:from:subject:message-id:references :mime-version:in-reply-to:date:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to; bh=/KnV4oVfH16sVxdEzAUkTHJmU2+lcl4+7S0fmyw+FdU=; b=Xao4x1bFqDd7sZbEIRlOtO0Tf+hnanNMYdgVNxHUgDLTuNg5FueJT48Fui0cc+Tlq0 yOqSrZhMn5LEnWCX1Wyexs9B/ySbeW+Pd3Q3dMheGqlilCiTCAlKKyI2MJNgWEUtoVfK 31GruNrocKBJwDISeLROiwZ7R6LC8MsHTGz1UIT2JmX0EKJr19PiT2bKUDkELVcYy0Hu sQU44oPPWSS5D9HAxT3EDlaIKodWYvqemSutUkTs0rCrB5gyDvI22tMg8VPN29jy/jSL f63jS8QZ7qYdZ9Xoz7p7XyOizQn2ICtI0WwkGM75pYHpcWUxerMrLbKPoUa0zbI3aa0B 8OhA== X-Forwarded-Encrypted: i=1; AJvYcCWdH7OrmYL8ITcgIzND5bAmGH1jDOmpeuZK6BJbLe0mdRzGEQWwDSFzA3fU+gM5s/r8JkbI+oXh55jmvL0=@vger.kernel.org X-Gm-Message-State: AOJu0YykNTlTQ43wzVrVauq637cL4q42aPOQih/mmRpcDrL8pqiIQFG2 c5vJHaJQDSWmhwERxZ6v58cUroTChF4eAND4ArNMKuO23NuJPR1RNzgAcgtihKGMV90MxAsEhp3 OriTIJg== X-Received: from pjbbj20.prod.google.com ([2002:a17:90b:894:b0:34c:f8b8:349b]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:388c:b0:356:7b41:d355 with SMTP id 98e67ed59e1d1-3593dab83f5mr593484a91.1.1772070463862; Wed, 25 Feb 2026 17:47:43 -0800 (PST) Date: Wed, 25 Feb 2026 17:47:41 -0800 In-Reply-To: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <6877331d.a00a0220.3af5df.000c.GAE@google.com> Message-ID: Subject: Re: [syzbot] [kvm?] WARNING in kvm_read_guest_offset_cached From: Sean Christopherson To: Alexander Potapenko Cc: syzbot , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, pbonzini@redhat.com, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable On Tue, Feb 10, 2026, Alexander Potapenko wrote: > On Wed, Jul 16, 2025 at 5:23=E2=80=AFPM 'Sean Christopherson' via > syzkaller-bugs wrote: > > > > On Tue, Jul 15, 2025, syzbot wrote: > > > Hello, > > > > > > syzbot found the following issue on: > > > > > > HEAD commit: 155a3c003e55 Merge tag 'for-6.16/dm-fixes-2' of git:/= /git... > > > git tree: upstream > > > console output: https://syzkaller.appspot.com/x/log.txt?x=3D103e858c5= 80000 > > > kernel config: https://syzkaller.appspot.com/x/.config?x=3D8d5ef2da1= e1c848 > > > dashboard link: https://syzkaller.appspot.com/bug?extid=3Dbc0e18379a2= 90e5edfe4 > > > compiler: gcc (Debian 12.2.0-14) 12.2.0, GNU ld (GNU Binutils f= or Debian) 2.40 > > > syz repro: https://syzkaller.appspot.com/x/repro.syz?x=3D153188f= 0580000 > > > C reproducer: https://syzkaller.appspot.com/x/repro.c?x=3D16f6198c5= 80000 > > > > > > Downloadable assets: > > > disk image (non-bootable): https://storage.googleapis.com/syzbot-asse= ts/d900f083ada3/non_bootable_disk-155a3c00.raw.xz > > > vmlinux: https://storage.googleapis.com/syzbot-assets/725a320dfe66/vm= linux-155a3c00.xz > > > kernel image: https://storage.googleapis.com/syzbot-assets/9f06899bb6= f3/bzImage-155a3c00.xz > > > > > > IMPORTANT: if you fix the issue, please add the following tag to the = commit: > > > Reported-by: syzbot+bc0e18379a290e5edfe4@syzkaller.appspotmail.com > > > > > > ------------[ cut here ]------------ > > > WARNING: CPU: 0 PID: 6107 at arch/x86/kvm/../../../virt/kvm/kvm_main.= c:3459 kvm_read_guest_offset_cached+0x3f5/0x4b0 virt/kvm/kvm_main.c:3459 > > > Modules linked in: > > > CPU: 0 UID: 0 PID: 6107 Comm: syz.0.16 Not tainted 6.16.0-rc6-syzkall= er-00002-g155a3c003e55 #0 PREEMPT(full) > > > Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debia= n-1.16.3-2~bpo12+1 04/01/2014 > > > RIP: 0010:kvm_read_guest_offset_cached+0x3f5/0x4b0 virt/kvm/kvm_main.= c:3459 > > > Code: 0f 01 e8 3e 6c 61 00 e9 9b fc ff ff e8 14 25 85 00 48 8b 3c 24 = 31 d2 48 89 ee e8 16 bf fa 00 e9 2e fe ff ff e8 fc 24 85 00 90 <0f> 0b 90 b= b ea ff ff ff e9 4d fe ff ff e8 e9 24 85 00 48 8b 74 24 > > > RSP: 0018:ffffc9000349f960 EFLAGS: 00010293 > > > RAX: 0000000000000000 RBX: ffff888050329898 RCX: ffffffff8136ca66 > > > RDX: ffff88803cfa8000 RSI: ffffffff8136cd84 RDI: 0000000000000006 > > > RBP: 0000000000000004 R08: 0000000000000006 R09: 0000000000000008 > > > R10: 0000000000000000 R11: 0000000000000001 R12: 0000000000000004 > > > R13: ffffc90003921000 R14: 0000000000000000 R15: ffffc900039215a0 > > > FS: 000055558378f500(0000) GS:ffff8880d6713000(0000) knlGS:000000000= 0000000 > > > CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 > > > CR2: 0000000000000000 CR3: 0000000025de6000 CR4: 0000000000352ef0 > > > Call Trace: > > > > > > apf_pageready_slot_free arch/x86/kvm/x86.c:13452 [inline] > > > > kvm_pv_enable_async_pf() sets vcpu->arch.apf.msr_en_val even if the gpa= is bad, > > which leaves the cache in an empty state. Something like so over a few= patches > > fixes the problem: >=20 > This bug is still occasionally reproducible on an Intel host running 6.19= . Gah, I never actually posted a series to fix this. I'll try to get that do= ne this week.