From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 069AC2FF669 for ; Fri, 5 Dec 2025 23:19:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764976761; cv=none; b=GAvT0GBw6odeDi8LdB5lWEGAiSkT+Y31iFjpesEKTknIy6YaOMS6VGjic/6lMmG5s9zDhPG8NUch+gToQj8PPgSeO6+l3PvqUQ458+rrr9Tvy7fE+XSj8ffFIoUWjqxsQnqVIG6/YxIc2gxtBWY5XtzShsdoTxJklD2JFgZuhTU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1764976761; c=relaxed/simple; bh=F4qmd0OW6egoY7GqSuYsPLXHpTzAKIfKTvqeLP44kPw=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=g3+5FLMdyCNMOuuirhVZnCkYrdQGGFzaBzDo+RMuwPerxjzmEjAR0VePGvV8e9DlwYiot3GksEEOJ2CzKHRKBgOuR3b3yHHdsdXHsUnfqZS7A+Po1uhHnIOaeR2IoKicvTPxtTnqln3tS72NukELx5y/vMyovXHZST7BP2iDpps= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=UxMZLPD7; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="UxMZLPD7" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-298535ef0ccso33741015ad.3 for ; Fri, 05 Dec 2025 15:19:18 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1764976757; x=1765581557; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=k2XQCiijHW2n4dUEHTnUIINf5DMpBs1wfkBUUXyMiLU=; b=UxMZLPD7KbcZ1LLSRuOC1BEARher8Tisoy10Gi4jMJo0xMd4DIjgDZ34btckags1pm MWjEnMN9iG821q2YzSmZHX+2cmLU8wibZ5AmueRHkna2s49KNGa60l8G/tAu1uuHPp9j 1ZG3pIj5CdmOtSYJdJzREvTzdDzf6fNpav2uMlSjsWpWU6fl4dcKayjUq8m2357v0hgp InMBiRZJJ5KTHOa5k+J3/ojKnFJLwW0Cp75HEJMaJSE1jF9Git+85EP0SFEGDTFES7OZ x2svaGYRsqI7D1LoFKorwpALWYPVIcEewn/oWRXdGNyORr19dKWWAVaUbZS2Lqla8GXg 43wQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1764976757; x=1765581557; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=k2XQCiijHW2n4dUEHTnUIINf5DMpBs1wfkBUUXyMiLU=; b=p+hk2D/qp0j2lDDzgjC+5qEjaLFOoSZaN6M3bo+3pfy3/3+ivP909HnfyzrR2lfGcF E8CbGCV7EBjTw6+GNnXaxnaUXBTqzdppcZd9yiDWfDMEoo3C6WJkCp6ax9kZAu8WdFU5 u0J2p99nocSVahtjJG/4SkjG8G4A16xKTsIrX/KgL6hAbcBFjCYHhmC2I4rt6wPH1XO3 0uiyd0+OFBVupVVyqDqrecJJnq76gEZ0cpm57c7Kuf0jk/dEc/v6Y37CM86H+MalRfX3 n6WjAYCsABhYnOeUDzvG7i0K3XAPk/q3JaEiLS79+nc3ZW7uzzrpS5RYZ2VEhS2BxL1r ewAw== X-Forwarded-Encrypted: i=1; AJvYcCUTldsxGotidcfJxOe9cD/fjUJrcvkr77oyVV3GSmfMg++bl/7vQ903djKw9vFUmr4h6X9VGBwwzMixphI=@vger.kernel.org X-Gm-Message-State: AOJu0YxWNOC5KQOnlbzd/6f2vMAv6SmZGrG/U3s9d8YXy3wkWuxpoY0+ cFC8ia3jJs6iJiHEMEKDnqjWc9i+OiFgkhBFUnFT6UXCrh6rqVZInIK6HNrEcI1mmzkJjbSVH8w cZMkHKg== X-Google-Smtp-Source: AGHT+IFSsAEr2/cYfi1CtvUqufOortDcW1lHxVDrPqOoZdu9sVDjZBHwAyXJEniJEwoAwyYIUCV901X27hs= X-Received: from pgac21.prod.google.com ([2002:a05:6a02:2955:b0:bc0:ea34:538]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a20:3d0b:b0:345:e30f:d6e6 with SMTP id adf61e73a8af0-36617ea92famr778354637.15.1764976757538; Fri, 05 Dec 2025 15:19:17 -0800 (PST) Reply-To: Sean Christopherson Date: Fri, 5 Dec 2025 15:19:03 -0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.52.0.223.gf5cc29aaa4-goog Message-ID: <20251205231913.441872-1-seanjc@google.com> Subject: [PATCH v3 00/10] KVM: VMX: Fix APICv activation bugs From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Dongli Zhang , Chao Gao Content-Type: text/plain; charset="UTF-8" Fix two bugs related to updating APICv state, add a regression test, and then rip out the "defer updates until nested VM-Exit" that contributed to bug #2, and eliminated a number ideas for fixing bug #1 (ignoring that my ideas weren't all that great). The only thing that gives me pause is the TLB flushing logic in vmx_set_virtual_apic_mode(), mainly because I don't love open coding things like that. But for me, it's a much lesser evil than the mounting pile of booleans related to tracking deferred updates, and the mental gymnastics needed to understanding the interactions and ordering. The fixes are tagged for stable@, and I'll probably land the selftest in 6.19 as well. Everything else is most definitely 6.20+ material. v3: - Add a selftest. - Rip out the deferred updates stuff. - Collect Chao's review. - Add Dongli's fix for bug #2. [Chao] v2: - https://lore.kernel.org/all/20251110063212.34902-1-dongli.zhang@oracle.com - Add support for guest mode (suggested by Chao Gao). - Add comments in the code (suggested by Chao Gao). - Remove WARN_ON_ONCE from vmx_hwapic_isr_update(). - Edit commit message "AMD SVM APICv" to "AMD SVM AVIC" (suggested by Alejandro Jimenez). Dongli Zhang (2): KVM: VMX: Update SVI during runtime APICv activation KVM: nVMX: Immediately refresh APICv controls as needed on nested VM-Exit Sean Christopherson (8): KVM: selftests: Add a test to verify APICv updates (while L2 is active) KVM: nVMX: Switch to vmcs01 to update PML controls on-demand if L2 is active KVM: nVMX: Switch to vmcs01 to update TPR threshold on-demand if L2 is active KVM: nVMX: Switch to vmcs01 to update SVI on-demand if L2 is active KVM: nVMX: Switch to vmcs01 to refresh APICv controls on-demand if L2 is active KVM: nVMX: Switch to vmcs01 to update APIC page on-demand if L2 is active KVM: nVMX: Switch to vmcs01 to set virtual APICv mode on-demand if L2 is active KVM: x86: Update APICv ISR (a.k.a. SVI) as part of kvm_apic_update_apicv() arch/x86/kvm/lapic.c | 21 +- arch/x86/kvm/lapic.h | 1 - arch/x86/kvm/vmx/nested.c | 30 +-- arch/x86/kvm/vmx/vmx.c | 104 +++++----- arch/x86/kvm/vmx/vmx.h | 9 - arch/x86/kvm/x86.c | 5 + tools/testing/selftests/kvm/Makefile.kvm | 1 + .../testing/selftests/kvm/include/x86/apic.h | 4 + .../kvm/x86/vmx_apicv_updates_test.c | 181 ++++++++++++++++++ 9 files changed, 257 insertions(+), 99 deletions(-) create mode 100644 tools/testing/selftests/kvm/x86/vmx_apicv_updates_test.c base-commit: 5d3e2d9ba9ed68576c70c127e4f7446d896f2af2 -- 2.52.0.223.gf5cc29aaa4-goog