From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 947B723EAAF for ; Tue, 28 Jul 2026 00:52:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199921; cv=none; b=ZwBDo7dsHpQ1hR+28qscoqUMb2+FnmpGgLvDsDoufInBHeKV6RGJ0DhilYxbzqw1OcH1WGwneCEBe9TD6js4R5YHjtxJ7DOC/ZdMgdy/r330m3t5pnfU7rxi2ZP953J6+Nt+SA9vjtR6IY/Zx7tjhDUoooHFrFzcaFqJ3sL/HQo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785199921; c=relaxed/simple; bh=f4H3IH81xz+uOCdrbsf7SRi0ExkOj3mz9Ecxb6nQTsQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=RMJ+qTGd6LcRwlcLhiwNpRfCGJgTzKxaM23CGNhkm2S+DMKFrdSdA/rQ27z2pTe2W8fOFDkW0nywFupP7dABvjxrn0hw7DeLeKFxNCDCL2aRFhEnoy/KoFCyTIDbs6zSWNEhg23tulhqTxPe0hU8KZF8wMZO91RVNogT8KRZkK4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=svmCO/hg; arc=none smtp.client-ip=209.85.214.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="svmCO/hg" Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2cceabd70f5so90729095ad.1 for ; Mon, 27 Jul 2026 17:52:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785199920; x=1785804720; darn=vger.kernel.org; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date:from:to:cc :subject:date:message-id:reply-to:content-type; bh=GQi7x436nDykBGBr3THdmSxZ/qUpCFOrJDr01TocQQI=; b=svmCO/hgcWGDPCkMI7bBY0J79vrJjcH51C393MSQImOG93bYozgXpz3EJuRdc+MFSb IoD99nn3UTdrJ0jEEx64f82yToPdT35TMbW31Lj3O7RnzCIlwy0CgjACYYtgO7HKzs8f qJrg/RcYP7T1eGxtAOPXe9Ay00ask67aUZXxwompFK/ofZh3UKF1UZ5nnvsIUum3ynW+ 9qrBWzi4lhAtBEGflUbGFGiDwkz1jx9yUpceylV/GtDA5BjwLYr8LzVrxhw3HzPufCqv Tver2Rzm07sNPQi1hW+DbpOVdGqLaA4tkd5nuVh8Tkldc7I5bVF/FDwOeb/2ziYsEe8J e4Ow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785199920; x=1785804720; h=content-transfer-encoding:content-type:cc:to:from:subject :message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=GQi7x436nDykBGBr3THdmSxZ/qUpCFOrJDr01TocQQI=; b=oDzjPHb5Z+FsPXRCgp8F2SFIFvPZQfGi6PpsDrdQzLkBmWz6CW8cSGqGdI1PSz6Zs3 y+aJgr36eSLq8JfiOO23adz1RLGEoBJMPp+EIE9jzHz6k2riXBy+gsFjEHJO2S12hfLB EagG/es9zujdDVNE++NLz5Fwxf02EOy3RZpW72q7qYwaFymjxIFE/z35ErxWU/CZG2/t han/CTjDoJ0NgyrUHC97e1MO+SZkAUIK9Y/umPjFya+JpR9eNT1wkvvs5MuAlEhOmsz5 bmhCcL4RmDfvjhlo2pbHtvhCkSmjkFvGG2x3C3/l7vGosAgs5AopiCa8dbcKQgPy0uQ8 bkQw== X-Forwarded-Encrypted: i=1; AHgh+RroldmaBEmN6ViBueBZV4OzrZ/0g+8s4pbBf0LaHUxsPLOEH2cDL+sT0Ne5qVKmHRRo/xS1KkFVZEZTrEw=@vger.kernel.org X-Gm-Message-State: AOJu0YyqOsTbDHvJ/vuqgxf4UtGdIC9AKLP6CGPM0hi9+hh/9Y8SjRZV UtiJ2fwK4N/efErjUmotpr4j2JSk7RFinGiOeeY6386GaF392aC7uuLe/TpWtNRFgOlfuk88QE5 JzJCphA== X-Received: from plig13.prod.google.com ([2002:a17:903:458d:b0:2cc:ed0e:f302]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:ce11:b0:2c9:e5ff:995d with SMTP id d9443c01a7336-2d015f01e44mr1928135ad.31.1785199919741; Mon, 27 Jul 2026 17:51:59 -0700 (PDT) Date: Mon, 27 Jul 2026 17:51:59 -0700 In-Reply-To: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260703212145.343527-1-dwmw2@infradead.org> <20260703212145.343527-16-dwmw2@infradead.org> Message-ID: Subject: Re: [PATCH v6 15/36] KVM: x86: Fix compute_guest_tsc() to handle negative time deltas From: Sean Christopherson To: David Woodhouse Cc: Paolo Bonzini , Jonathan Corbet , Shuah Khan , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Vitaly Kuznetsov , Juergen Gross , Boris Ostrovsky , Paul Durrant , Jonathan Cameron , Sascha Bischoff , Marc Zyngier , Joey Gouly , Jack Allister , Dongli Zhang , joe.jin@oracle.com, kvm@vger.kernel.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, xen-devel@lists.xenproject.org, linux-kselftest@vger.kernel.org Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable On Sat, Jul 25, 2026, David Woodhouse wrote: > On Fri, 2026-07-24 at 14:27 -0700, Sean Christopherson wrote: > > On Fri, Jul 03, 2026, David Woodhouse wrote: > > > From: David Woodhouse > > >=20 > > > The compute_guest_tsc() function computes the guest TSC at a given > > > kernel_ns timestamp. When the master clock reference point > > > (master_kernel_ns) is earlier than vcpu->arch.this_tsc_nsec, the delt= a > > > is negative. Since pvclock_scale_delta() takes a u64, the negative > > > value wraps to a huge positive number, producing a wildly wrong resul= t. > > >=20 > > > Handle negative deltas explicitly by negating the delta, scaling it, > > > and subtracting from this_tsc_write. > >=20 > > Does this need=20 > >=20 > > =C2=A0 Cc: stable@vger.kernel.org > >=20 > > or is this a "technically a bug fix, but can't happen in practice" sort= of thing? >=20 > Honestly, there's so much hosed in kvmclock that we could debate a > cc:stable for half of this series. I'm not doing *any* of this to > actually add new features. For this one I'm not sure it's reachable in > practice; I think I did it mostly to shut Sashiko up. Heh, in that case, throw a blurb in the changelog stating as much. Knowing= that a bug is likely unreachable in practice is helpful, e.g. in the super unlik= ely case that this change breaks someone. > I think even in the KVM_SET_CLOCK_GUEST it can't trigger, although I > have fantasies about changing the way KVM_SET_CLOCK_GUEST works to fix > that final =C2=B11ns imprecision (which requires separate work on the > timekeeping core), that *might* trigger the negative delta here...