From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f73.google.com (mail-pj1-f73.google.com [209.85.216.73]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EDDF30E82B for ; Mon, 12 Jan 2026 17:45:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.73 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768239941; cv=none; b=jnDgiT6NxCNlZFpVK2aiH7DuoeN5DPzLHFng2uJ0HW+v6A0Um5FEnU68C2zxajZqdhWyKrzYeKNoYd2lw1ETIygmWUW8ESCaHulaWbs7b1mpfQcegVfNayubSYlfkkF8RxjXkFsunON3RhThMsMGjXfImHic3pD8o0sL+3kOT/0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768239941; c=relaxed/simple; bh=tRUBNtvsGTyz9uO2LZ/ZrWHUO/SAepqw+Xmr/joWlQM=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=jf6sR+CvXiOu8y4+PykqO7ssOHoAEiyV/wzJEbDaCiCwxxwhmMci4LrEJCtzsSL7U6C7CQwbalff/0NCOe88NExb2wPB12d7mVOGOSTwrEUTlL37nM/UehG7TG5SjHGJ3EaTFdfknhqP4VY+kyYPeooFMfPlqUpQyyMBKZx91EU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=KiCrBAzJ; arc=none smtp.client-ip=209.85.216.73 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="KiCrBAzJ" Received: by mail-pj1-f73.google.com with SMTP id 98e67ed59e1d1-34c64cd48a8so7623778a91.0 for ; Mon, 12 Jan 2026 09:45:39 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1768239939; x=1768844739; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=QFvZ/pSKJV6B/QHBj1Be7Gjgij0dz+ZlxZdi6kp9tRU=; b=KiCrBAzJtHYHN1fIpV63YTW2gamLtw7lAgFwBHPm5y4xe8Cdzilzuunuxa9darFkFd zxKv5VzzcOEh0brZBvagf00N0w114bjPl2IF6uTkBn0fAmN4RbtMjUKX2JevKeL8xwDt Om1f/8wH+8Vj4ejYU3/Sb6zJ8R+dRcCtqaLmxR0DD8cv0SaPsWkMrSClsBbspbUXsXtg QZK3EOT9Y62YTAx7n02CWreJ8V/HTMBHWqb4DDDTKGIkiEGNZDueimlveFCw8C7Ab1cQ gR+Q95pnXHifBhfP+DrZJFegdRQFQjo5DC1aENy1a254a4zF82lpZtZaHd30hCECnwSt 21Cg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1768239939; x=1768844739; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=QFvZ/pSKJV6B/QHBj1Be7Gjgij0dz+ZlxZdi6kp9tRU=; b=OlT3TKtXOCtGNuT7e3vOdnZv91vfGQQs/rkI7h+Xd4CNHzAPhazORWW+vRl8UnROE5 T3bnyHHmbyHPYGh0uc+vqWCSdVJDuyMTJOjvUehhvI6Vbarlcf5W1/VqOkiD2QfWJmii SZ6bebk8AUUPT+1qOntNNNgLbvQ93Zqq1iiJ45IMYaYn+v5g8yEKCpGeVl1ggjVOow5L yq1IQyknzt9+yfQ4MJt96hvDZRDNei18VpTU+2K2TG29P6LZsxcuTyrPSFc1WzBpA/91 5GAl7lQn74WvQKkee0X7eBoMmiICEMyK0gHEXs3geQL6tXBkWEH9Hn5CygUUdTfD3AGD 4tCA== X-Forwarded-Encrypted: i=1; AJvYcCXwq0RhbYwuo/wfPhHMT1vs6GLmi8GnPCLddL+sSbxJrw8tXs9mNlaiVyeaWhS0nSwyKF00qeSY3YYxV2M=@vger.kernel.org X-Gm-Message-State: AOJu0Yx0d30R+svAZgIRJNm1leoO3grOnWgdFXpMthw+Wno5fp0+2ucj GVQ/6W3RxUIUNvsCJ56Ae7fJU4q9UHZckqYRHS7VRmt+poI1oLSnT+XGdn6QJwxL/WxE7TWRbxf lPBQx38Kuc6EXgg== X-Google-Smtp-Source: AGHT+IH+5Ti2CyCkFUj7kZjziTJj2MyxNeskCbGX9fhVYJduvDiOjLzxqfbfPh3Z93MKpWd4k05+583dHXFLfw== X-Received: from pjzd8.prod.google.com ([2002:a17:90a:e288:b0:34c:811d:e3ca]) (user=chengkev job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:5287:b0:340:bde5:c9e3 with SMTP id 98e67ed59e1d1-34f68c91773mr17708252a91.23.1768239938830; Mon, 12 Jan 2026 09:45:38 -0800 (PST) Date: Mon, 12 Jan 2026 17:45:30 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.52.0.457.g6b5491de43-goog Message-ID: <20260112174535.3132800-1-chengkev@google.com> Subject: [PATCH V2 0/5] Align SVM with APM defined behaviors From: Kevin Cheng To: seanjc@google.com, pbonzini@redhat.com Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, yosry.ahmed@linux.dev, Kevin Cheng Content-Type: text/plain; charset="UTF-8" The APM lists the following behaviors - The VMRUN, VMLOAD, VMSAVE, CLGI, VMMCALL, and INVLPGA instructions can be used when the EFER.SVME is set to 1; otherwise, these instructions generate a #UD exception. - If VMMCALL instruction is not intercepted, the instruction raises a #UD exception. - STGI instruction causes a #UD exception if SVM is not enabled and neither SVM Lock nor the device exclusion vector (DEV) are supported. The patches in this series fix current SVM bugs that do not adhere to the APM listed behaviors. v1 -> v2: - Split up the series into smaller more logical changes as suggested by Sean - Added patch for injecting #UD for STGI under APM defined conditions as suggested by Sean - Combined EFER.SVME=0 conditional with intel CPU logic in svm_recalc_instruction_intercepts v1: https://lore.kernel.org/all/20260106041250.2125920-1-chengkev@google.com/ Kevin Cheng (5): KVM: SVM: Move STGI and CLGI intercept handling KVM: SVM: Inject #UD for STGI if EFER.SVME=0 and SVM Lock and DEV are not available KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 KVM: SVM: Recalc instructions intercepts when EFER.SVME is toggled KVM: SVM: Raise #UD if VMMCALL instruction is not intercepted arch/x86/kvm/svm/svm.c | 52 ++++++++++++++++++++++++++++++++++++------ 1 file changed, 45 insertions(+), 7 deletions(-) -- 2.52.0.457.g6b5491de43-goog