From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A6A8D28B4FE for ; Thu, 1 Jan 2026 09:05:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767258325; cv=none; b=HbHSysqnnZAawWlFXZcBLn2Zp3UQUWUzdDZnfw6+a+i8xwi9M8mbQseNzIFXZ0feRK/XZSjMmMu02qdH+UcFjiHbdNOogLv2cIXJmA/ue2rfaMTSzKTuReSXheftTwjmpMJ6N2TitIvxaR5LMTWyEHyIXnp49zc+j2V/+u0Uoso= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1767258325; c=relaxed/simple; bh=QecIbI8ayv5frn1nCSUZ1SrVTu0TcbdLc3zmHPbFHJk=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=E29unQU09oz6wlOGjglyD8dh4jkNQL+BTDmFa0SGATeC0sJLOTiXU5xAWC23EjsXvKV5rwmypWj66A+lb/MTNyUvtmST09BSYVsuAyEftLgp37V1rPwYEI49AlY8yX6AGmyOUPDLjl6mVWzffi9LNj4zeWc0GQWmPnCemBekIz8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=itPhK1UM; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=rxA+j7IE; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="itPhK1UM"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="rxA+j7IE" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1767258321; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding; bh=UlAEzcPXR845UamWej3hkdwwZvPd+P/8Ht0alhVeA1k=; b=itPhK1UMG7Pfmog2GCKoZ2RW/ecL0ze0f3AqdLIMvMqEhIvoKALnO7ebFdPBZBQ13IzCma OaVqiLo0BKmWaRo3UlV7BQLGb8ogcIu723DTJrb5xH7sVX1Rb1+KDxoGfiXi/gsiNYQWBo 32+lF/hVfCJfWLENIDaj7dBWAVEhuYQ= Received: from mail-wm1-f70.google.com (mail-wm1-f70.google.com [209.85.128.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-421-fNGVPWK3OSmcU3BnDJ3anA-1; Thu, 01 Jan 2026 04:05:20 -0500 X-MC-Unique: fNGVPWK3OSmcU3BnDJ3anA-1 X-Mimecast-MFC-AGG-ID: fNGVPWK3OSmcU3BnDJ3anA_1767258319 Received: by mail-wm1-f70.google.com with SMTP id 5b1f17b1804b1-47d28e7960fso60610475e9.0 for ; Thu, 01 Jan 2026 01:05:20 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1767258318; x=1767863118; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=UlAEzcPXR845UamWej3hkdwwZvPd+P/8Ht0alhVeA1k=; b=rxA+j7IEW/82sHOtLfrjpGwbuE78voI36ix4GlAyCqaNRPg5zN4W0fiHXuAdMmESeU HPTJ/nl4c97P4HeN0QbSH7S3yAowyIkKeYaCz42wY9Fp+fNFpacr3ERKECszRmKnsZxw 9J9T4eFAnQVWlhDqiFnXHqnBT+XXKm0OUM5Qrm2wb9sfQs3+XcyF4B7cFuqxXDydBYpW rzFxa3U2pox7A4JGM4EFKpf6Zw+UEqLYIMSCye4lgVoQKDsSSy5Bc9MocD+uCkuRbQpf vHQn63usM67jbQeaX+Jl/to4RelpqRgOZ385pxXlBX+EbAUBCoww34u4FayTc1JdP+Oh 6xlg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1767258318; x=1767863118; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=UlAEzcPXR845UamWej3hkdwwZvPd+P/8Ht0alhVeA1k=; b=FshxYcQdcKjcxb1tQZUGZ8SHkr1sRCA/8uAxaDLopLQQswxuECN5DhnUnKjlzu7WQt 7eFKM74dHDqEfKqU62o/Z18W40x0Xk564JT2Ik0/S8ZV8W44WvZ7+hHTlQWM+REnjZPv IuMsLhZr+Fy3kfxDQcb8WV3C8RBuv2k4xQr0fuXRX2OuEOOSibgxs9q5xioiaIbGr1il GeGu/87INihco1b99bPVKok4ku1CLsUTetrDjjXZkVl8sdMyVOcpFjEI1XEBi+isl1to 0EIqwynLpxZjELW2dma30YmGfRDT61V09mvXVQazX4+sugK8RGixdkx8kIJ8gpz7+qyK WZzQ== X-Gm-Message-State: AOJu0Yw5CRXC09VGaZMEfI4Fgylb1TgJEWvvPaCQtTIT2CUN5junH2y0 7ChWaFFf1PUy4D+netlECbrCfuk79arxWwxkkzsRcLPXVdxbdHTQiLkaEv/2+3A8KbuwRAruSVR IgEo+XY2XmkqlLZdmU3J3OtDL7wNKtN9EuC/oF7y1jc8M7qVs+4dGsKj+iF9kobhcWCe18dXHVo 19fvlGUCQNVobsxsXYo8UBBzIlY51cix0ZUX8Ju/PAAhAGRebAYg== X-Gm-Gg: AY/fxX5EYWrNCzThxihnU9Z5AXdzsG556KHXUTIrAuPV1H605Sh+GwCc3s376GNl4U9 9TSJt7UiWGVJPOeC0f6aouH5x6yPeguMOfce7FUL7Mo4d5Z7nnBAu1S/IHj4HsxXzS2wY5To4s4 htPChuP7L10lzDle7uKZpOkFjFDYJAqR3W2/qWCnIkTds+3RLaF4sm1RD8TzcFlD8+k7N/70YBw gh+RoR6BZdWALcxKoXHQq42ARek1P4llbZFhUp19yDuvSikG1i1o6fNwlPbgnYop41kRmhjMi84 qQB1HzlEH2bpsfTRImu66ap1nLRauSleK7ymHdUQ23GD2pa6R8Rf8gyhDT+vbOVAMZMpcZTDHci 9YPp0usCIPSKx4x5Dl8Y+YUJSqh0j7czwwSsczeCk9af0M4oPGtuD0uicZ65B5CGxoefd1ksXBe 0Yd6rc2ktx8hgYWw== X-Received: by 2002:a05:600c:1d1d:b0:471:d2f:7987 with SMTP id 5b1f17b1804b1-47d1958f9c5mr445504515e9.26.1767258318550; Thu, 01 Jan 2026 01:05:18 -0800 (PST) X-Google-Smtp-Source: AGHT+IFnRKxVGahaGqq0YTZ2CUKQ2TtfV42YjByKztYMXCFLLp/SOg/1JjoMPjiKkrkVYXp6l52M0w== X-Received: by 2002:a05:600c:1d1d:b0:471:d2f:7987 with SMTP id 5b1f17b1804b1-47d1958f9c5mr445504105e9.26.1767258318083; Thu, 01 Jan 2026 01:05:18 -0800 (PST) Received: from [192.168.10.48] ([151.61.26.160]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-47be3aac6d9sm306477025e9.4.2026.01.01.01.05.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 01 Jan 2026 01:05:17 -0800 (PST) From: Paolo Bonzini To: linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: seanjc@google.com, x86@kernel.org Subject: [PATCH v2 0/4] x86, fpu/kvm: fix crash with AMX Date: Thu, 1 Jan 2026 10:05:12 +0100 Message-ID: <20260101090516.316883-1-pbonzini@redhat.com> X-Mailer: git-send-email 2.52.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Fix a possible host panic, due to an unexpected #NM, when a KVM guest is using AMX features. The guest's XFD value, which is stored in fpstate->xfd, is used for both guest execution and host XSAVE operations. However, the guest-configured XFD setting can disable features that were enabled when the guest executed XSAVE, and this causes a #NM when executing XRSTOR on the guest FPU state. This can happen in two cases: due to a KVM_SET_XSAVE that includes a disabled component, or if an interrupt causes XSAVE to be executed before the call to fpu_update_guest_xfd(). The first patch fixes both cases, the rest is improvements to selftests in order to cover this test and also verify that #NM faults are injected corectly. v1 had extra patches to export higher-level functions for KVM in place of switch_fpu_return() and fpregs_assert_state_consistent(). Those were part of refactoring how KVM loaded guest state when KVM_RUN is issued, but are not needed anymore with this v2 fix and I will submit them separately. Tested on a Sapphire Rapids machine, reviews and acks are welcome so that I can submit it to Linus via the KVM tree. Paolo Paolo Bonzini (2): selftests: kvm: replace numbered sync points with actions selftests: kvm: try getting XFD and XSAVE state out of sync Sean Christopherson (2): x86/fpu: Clear XSTATE_BV[i] in save state whenever XFD[i]=1 selftests: kvm: Verify TILELOADD actually #NM faults when XFD[18]=1 arch/x86/kernel/fpu/core.c | 32 ++++- arch/x86/kvm/x86.c | 9 ++ tools/testing/selftests/kvm/x86/amx_test.c | 144 ++++++++++++--------- 3 files changed, 123 insertions(+), 62 deletions(-) -- 2.52.0