qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Xiaoyao Li <xiaoyao.li@intel.com>,
	Kirill Martynov <stdcalllevi@yandex-team.ru>,
	Zhao Liu <zhao1.liu@intel.com>
Subject: [PULL 54/61] i386/cpu: Enable SMM cpu address space under KVM
Date: Sat, 13 Sep 2025 10:09:35 +0200	[thread overview]
Message-ID: <20250913080943.11710-55-pbonzini@redhat.com> (raw)
In-Reply-To: <20250913080943.11710-1-pbonzini@redhat.com>

From: Xiaoyao Li <xiaoyao.li@intel.com>

Kirill Martynov reported assertation in cpu_asidx_from_attrs() being hit
when x86_cpu_dump_state() is called to dump the CPU state[*]. It happens
when the CPU is in SMM and KVM emulation failure due to misbehaving
guest.

The root cause is that QEMU i386 never enables the SMM address space for
cpu since KVM SMM support has been added.

Enable the SMM cpu address space under KVM when the SMM is enabled for
the x86machine.

[*] https://lore.kernel.org/qemu-devel/20250523154431.506993-1-stdcalllevi@yandex-team.ru/

Reported-by: Kirill Martynov <stdcalllevi@yandex-team.ru>
Reviewed-by: Zhao Liu <zhao1.liu@intel.com>
Tested-by: Kirill Martynov <stdcalllevi@yandex-team.ru>
Signed-off-by: Xiaoyao Li <xiaoyao.li@intel.com>
Link: https://lore.kernel.org/r/20250730095253.1833411-2-xiaoyao.li@intel.com
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 system/physmem.c          |  5 -----
 target/i386/kvm/kvm-cpu.c | 10 ++++++++++
 target/i386/kvm/kvm.c     |  5 +++++
 3 files changed, 15 insertions(+), 5 deletions(-)

diff --git a/system/physmem.c b/system/physmem.c
index 311011156c7..a12c7ea1956 100644
--- a/system/physmem.c
+++ b/system/physmem.c
@@ -793,9 +793,6 @@ void cpu_address_space_init(CPUState *cpu, int asidx,
         cpu->as = as;
     }
 
-    /* KVM cannot currently support multiple address spaces. */
-    assert(asidx == 0 || !kvm_enabled());
-
     if (!cpu->cpu_ases) {
         cpu->cpu_ases = g_new0(CPUAddressSpace, cpu->num_ases);
         cpu->cpu_ases_count = cpu->num_ases;
@@ -818,8 +815,6 @@ void cpu_address_space_destroy(CPUState *cpu, int asidx)
 
     assert(cpu->cpu_ases);
     assert(asidx >= 0 && asidx < cpu->num_ases);
-    /* KVM cannot currently support multiple address spaces. */
-    assert(asidx == 0 || !kvm_enabled());
 
     cpuas = &cpu->cpu_ases[asidx];
     if (tcg_enabled()) {
diff --git a/target/i386/kvm/kvm-cpu.c b/target/i386/kvm/kvm-cpu.c
index 89a79536594..1dc1ba9b486 100644
--- a/target/i386/kvm/kvm-cpu.c
+++ b/target/i386/kvm/kvm-cpu.c
@@ -13,6 +13,7 @@
 #include "qapi/error.h"
 #include "system/system.h"
 #include "hw/boards.h"
+#include "hw/i386/x86.h"
 
 #include "kvm_i386.h"
 #include "accel/accel-cpu-target.h"
@@ -91,6 +92,15 @@ static bool kvm_cpu_realizefn(CPUState *cs, Error **errp)
         kvm_set_guest_phys_bits(cs);
     }
 
+    /*
+     * When SMM is enabled, there is 2 address spaces. Otherwise only 1.
+     *
+     * Only initialize address space 0 here, the second one for SMM is
+     * initialized at register_smram_listener() after machine init done.
+     */
+    cs->num_ases = x86_machine_is_smm_enabled(X86_MACHINE(current_machine)) ? 2 : 1;
+    cpu_address_space_init(cs, 0, "cpu-memory", cs->memory);
+
     return true;
 }
 
diff --git a/target/i386/kvm/kvm.c b/target/i386/kvm/kvm.c
index 34e74f24470..d191d7177f1 100644
--- a/target/i386/kvm/kvm.c
+++ b/target/i386/kvm/kvm.c
@@ -2704,6 +2704,7 @@ static MemoryRegion smram_as_mem;
 
 static void register_smram_listener(Notifier *n, void *unused)
 {
+    CPUState *cpu;
     MemoryRegion *smram =
         (MemoryRegion *) object_resolve_path("/machine/smram", NULL);
 
@@ -2728,6 +2729,10 @@ static void register_smram_listener(Notifier *n, void *unused)
     address_space_init(&smram_address_space, &smram_as_root, "KVM-SMRAM");
     kvm_memory_listener_register(kvm_state, &smram_listener,
                                  &smram_address_space, 1, "kvm-smram");
+
+    CPU_FOREACH(cpu) {
+        cpu_address_space_init(cpu, 1, "cpu-smm", &smram_as_root);
+    }
 }
 
 static void *kvm_msr_energy_thread(void *data)
-- 
2.51.0



  parent reply	other threads:[~2025-09-13  8:25 UTC|newest]

Thread overview: 73+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-09-13  8:08 [PULL 00/61] CPU, Rust, x86 changes for 2025-09-13 Paolo Bonzini
2025-09-13  8:08 ` [PULL 01/61] target/ppc: limit cpu_interrupt_exittb to system emulation Paolo Bonzini
2025-09-13  8:08 ` [PULL 02/61] target/sparc: limit cpu_check_irqs " Paolo Bonzini
2025-09-13  8:08 ` [PULL 03/61] target/i386: limit a20 " Paolo Bonzini
2025-09-13  8:08 ` [PULL 04/61] target-arm: remove uses of cpu_interrupt() for user-mode emulation Paolo Bonzini
2025-09-13  8:08 ` [PULL 05/61] user-exec: remove cpu_interrupt() stub Paolo Bonzini
2025-09-13  8:08 ` [PULL 06/61] treewide: clear bits of cs->interrupt_request with cpu_reset_interrupt() Paolo Bonzini
2025-09-13  8:08 ` [PULL 07/61] cpu-common: use atomic access for interrupt_request Paolo Bonzini
2025-09-13  8:08 ` [PULL 08/61] cpus: document that qemu_cpu_kick() can be used for BQL-less operation Paolo Bonzini
2025-09-13  8:08 ` [PULL 09/61] accel: use store_release/load_acquire for cross-thread exit_request Paolo Bonzini
2025-09-13  8:08 ` [PULL 10/61] accel: use atomic accesses for exit_request Paolo Bonzini
2025-09-13  8:08 ` [PULL 11/61] accel/tcg: create a thread-kick function for TCG Paolo Bonzini
2025-09-13  8:08 ` [PULL 12/61] accel/tcg: inline cpu_exit() Paolo Bonzini
2025-09-13  8:08 ` [PULL 13/61] cpus: remove TCG-ism from cpu_exit() Paolo Bonzini
2025-09-13  8:08 ` [PULL 14/61] cpus: properly kick CPUs out of inner execution loop Paolo Bonzini
2025-09-13  8:08 ` [PULL 15/61] treewide: rename qemu_wait_io_event/qemu_wait_io_event_common Paolo Bonzini
2025-09-13  8:08 ` [PULL 16/61] bsd-user, linux-user: introduce qemu_process_cpu_events Paolo Bonzini
2025-09-13  8:08 ` [PULL 17/61] cpus: clear exit_request in qemu_process_cpu_events Paolo Bonzini
2025-09-13  8:08 ` [PULL 18/61] accel: make all calls to qemu_process_cpu_events look the same Paolo Bonzini
2025-09-13  8:09 ` [PULL 19/61] tcg/user: do not set exit_request gratuitously Paolo Bonzini
2025-09-13  8:09 ` [PULL 20/61] ci: temporarily remove rust from Ubuntu Paolo Bonzini
2025-09-13  8:09 ` [PULL 21/61] configure: bump Meson to 1.9.0 for use with Rust Paolo Bonzini
2025-09-22 14:07   ` Peter Maydell
2025-09-22 15:14     ` Paolo Bonzini
2025-09-13  8:09 ` [PULL 22/61] meson, cargo: require Rust 1.83.0 Paolo Bonzini
2025-09-13  8:09 ` [PULL 23/61] rust: add missing const markers for MSRV==1.83.0 Paolo Bonzini
2025-09-13  8:09 ` [PULL 24/61] rust: use inline const expressions Paolo Bonzini
2025-09-13  8:09 ` [PULL 25/61] rust: add qdev Device derive macro Paolo Bonzini
2025-09-13  8:09 ` [PULL 26/61] rust: vmstate: convert to use builder pattern Paolo Bonzini
2025-09-13  8:09 ` [PULL 27/61] rust: vmstate: use const_refs_to_static Paolo Bonzini
2025-09-13  8:09 ` [PULL 28/61] rust: qdev: const_refs_to_static Paolo Bonzini
2025-09-13  8:09 ` [PULL 29/61] docs/rust: update msrv Paolo Bonzini
2025-09-13  8:09 ` [PULL 30/61] rust: remove unused global qemu "allocator" Paolo Bonzini
2025-09-13  8:09 ` [PULL 31/61] rust: add workspace authors Paolo Bonzini
2025-09-13  8:09 ` [PULL 32/61] rust: move vmstate_clock!() to qdev module Paolo Bonzini
2025-09-13  8:09 ` [PULL 33/61] rust: move VMState handling to QOM module Paolo Bonzini
2025-09-13  8:09 ` [PULL 34/61] rust: move Cell vmstate impl Paolo Bonzini
2025-09-13  8:09 ` [PULL 35/61] rust: split Rust-only "common" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 36/61] rust: make build.rs generic over various ./rust/projects Paolo Bonzini
2025-09-13  8:09 ` [PULL 37/61] rust: split "util" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 38/61] rust: split "migration" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 39/61] rust: split "bql" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 40/61] rust: split "qom" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 41/61] rust: split "chardev" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 42/61] rust: split "system" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 43/61] rust: split "hwcore" crate Paolo Bonzini
2025-09-13  8:09 ` [PULL 44/61] rust: rename qemu_api_macros -> qemu_macros Paolo Bonzini
2025-09-13  8:09 ` [PULL 45/61] rust/hpet: drop now unneeded qemu_api dep Paolo Bonzini
2025-09-13  8:09 ` [PULL 46/61] rust/pl011: drop dependency on qemu_api Paolo Bonzini
2025-09-13  8:09 ` [PULL 47/61] rust: repurpose qemu_api -> tests Paolo Bonzini
2025-09-13  8:09 ` [PULL 48/61] rust: re-export qemu_macros internal helper in "bits" Paolo Bonzini
2025-09-13  8:09 ` [PULL 49/61] rust: re-export qemu macros from common/qom/hwcore Paolo Bonzini
2025-09-13  8:09 ` [PULL 50/61] docs: update rust.rst Paolo Bonzini
2025-09-13  8:09 ` [PULL 51/61] rust: meson: remove unnecessary complication in device crates Paolo Bonzini
2025-09-13  8:09 ` [PULL 52/61] rust: do not inline do_init_io Paolo Bonzini
2025-09-13  8:09 ` [PULL 53/61] hpet: guard IRQ handling with BQL Paolo Bonzini
2025-09-13  8:09 ` Paolo Bonzini [this message]
2025-09-18 16:24   ` [PULL 54/61] i386/cpu: Enable SMM cpu address space under KVM Michael Tokarev
2025-09-22 15:16     ` Paolo Bonzini
2025-09-26 17:48   ` Peter Maydell
2025-09-28  6:51     ` Xiaoyao Li
2025-09-13  8:09 ` [PULL 55/61] target/i386: Define enum X86ASIdx for x86's address spaces Paolo Bonzini
2025-09-13  8:09 ` [PULL 56/61] multiboot: Fix the split lock Paolo Bonzini
2025-09-13  8:09 ` [PULL 57/61] i386/kvm: Get X86MachineState in kvm_arch_init() without the cast check Paolo Bonzini
2025-09-13  8:09 ` [PULL 58/61] i386/kvm: Drop KVM_CAP_X86_SMM check in kvm_arch_init() Paolo Bonzini
2025-09-13  8:09 ` [PULL 59/61] accel/kvm: Switch to check KVM_CAP_GUEST_MEMFD and KVM_CAP_USER_MEMORY2 on VM Paolo Bonzini
2025-09-13  8:09 ` [PULL 60/61] accel/kvm: Zero out mem explicitly in kvm_set_user_memory_region() Paolo Bonzini
2025-09-13  8:09 ` [PULL 61/61] accel/kvm: Set guest_memfd_offset to non-zero value only when guest_memfd is valid Paolo Bonzini
2025-09-13  9:37 ` [PULL 00/61] CPU, Rust, x86 changes for 2025-09-13 Peter Maydell
2025-09-16 14:37   ` Peter Maydell
2025-09-16 14:53     ` Paolo Bonzini
2025-09-17 16:33 ` Richard Henderson
2025-09-18 12:38   ` Xiaoyao Li

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20250913080943.11710-55-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=stdcalllevi@yandex-team.ru \
    --cc=xiaoyao.li@intel.com \
    --cc=zhao1.liu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).