From: Sean Christopherson <seanjc@google.com>
To: Sasha Levin <sashal@kernel.org>
Cc: stable@vger.kernel.org
Subject: Re: [PATCH 6.6.y] KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid
Date: Fri, 17 Oct 2025 15:04:40 -0700 [thread overview]
Message-ID: <aPK9eFfTBgM7Qxwm@google.com> (raw)
In-Reply-To: <20251014144851.94249-1-sashal@kernel.org>
On Tue, Oct 14, 2025, Sasha Levin wrote:
> From: Sean Christopherson <seanjc@google.com>
>
> [ Upstream commit 0910dd7c9ad45a2605c45fd2bf3d1bcac087687c ]
>
> Skip the WRMSR and HLT fastpaths in SVM's VM-Exit handler if the next RIP
> isn't valid, e.g. because KVM is running with nrips=false. SVM must
> decode and emulate to skip the instruction if the CPU doesn't provide the
> next RIP, and getting the instruction bytes to decode requires reading
> guest memory. Reading guest memory through the emulator can fault, i.e.
> can sleep, which is disallowed since the fastpath handlers run with IRQs
> disabled.
>
> BUG: sleeping function called from invalid context at ./include/linux/uaccess.h:106
> in_atomic(): 1, irqs_disabled(): 1, non_block: 0, pid: 32611, name: qemu
> preempt_count: 1, expected: 0
> INFO: lockdep is turned off.
> irq event stamp: 30580
> hardirqs last enabled at (30579): [<ffffffffc08b2527>] vcpu_run+0x1787/0x1db0 [kvm]
> hardirqs last disabled at (30580): [<ffffffffb4f62e32>] __schedule+0x1e2/0xed0
> softirqs last enabled at (30570): [<ffffffffb4247a64>] fpu_swap_kvm_fpstate+0x44/0x210
> softirqs last disabled at (30568): [<ffffffffb4247a64>] fpu_swap_kvm_fpstate+0x44/0x210
> CPU: 298 UID: 0 PID: 32611 Comm: qemu Tainted: G U 6.16.0-smp--e6c618b51cfe-sleep #782 NONE
> Tainted: [U]=USER
> Hardware name: Google Astoria-Turin/astoria, BIOS 0.20241223.2-0 01/17/2025
> Call Trace:
> <TASK>
> dump_stack_lvl+0x7d/0xb0
> __might_resched+0x271/0x290
> __might_fault+0x28/0x80
> kvm_vcpu_read_guest_page+0x8d/0xc0 [kvm]
> kvm_fetch_guest_virt+0x92/0xc0 [kvm]
> __do_insn_fetch_bytes+0xf3/0x1e0 [kvm]
> x86_decode_insn+0xd1/0x1010 [kvm]
> x86_emulate_instruction+0x105/0x810 [kvm]
> __svm_skip_emulated_instruction+0xc4/0x140 [kvm_amd]
> handle_fastpath_invd+0xc4/0x1a0 [kvm]
> vcpu_run+0x11a1/0x1db0 [kvm]
> kvm_arch_vcpu_ioctl_run+0x5cc/0x730 [kvm]
> kvm_vcpu_ioctl+0x578/0x6a0 [kvm]
> __se_sys_ioctl+0x6d/0xb0
> do_syscall_64+0x8a/0x2c0
> entry_SYSCALL_64_after_hwframe+0x4b/0x53
> RIP: 0033:0x7f479d57a94b
> </TASK>
>
> Note, this is essentially a reapply of commit 5c30e8101e8d ("KVM: SVM:
> Skip WRMSR fastpath on VM-Exit if next RIP isn't valid"), but with
> different justification (KVM now grabs SRCU when skipping the instruction
> for other reasons).
>
> Fixes: b439eb8ab578 ("Revert "KVM: SVM: Skip WRMSR fastpath on VM-Exit if next RIP isn't valid"")
> Cc: stable@vger.kernel.org
> Link: https://lore.kernel.org/r/20250805190526.1453366-2-seanjc@google.com
> Signed-off-by: Sean Christopherson <seanjc@google.com>
> [ adapted switch-based MSR/HLT fastpath to if-based MSR-only check ]
> Signed-off-by: Sasha Levin <sashal@kernel.org>
> ---
Acked-by: Sean Christopherson <seanjc@google.com>
prev parent reply other threads:[~2025-10-17 22:04 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-10-13 11:42 FAILED: patch "[PATCH] KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP" failed to apply to 6.6-stable tree gregkh
2025-10-14 14:48 ` [PATCH 6.6.y] KVM: SVM: Skip fastpath emulation on VM-Exit if next RIP isn't valid Sasha Levin
2025-10-17 22:04 ` Sean Christopherson [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aPK9eFfTBgM7Qxwm@google.com \
--to=seanjc@google.com \
--cc=sashal@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox