From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 628EB338939 for ; Thu, 22 Jan 2026 04:57:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769057879; cv=none; b=f5asnPUJQS1sq5wGjWw1DIXx2oqRMSNqb3EBnlLpvGa3amGdzgtZXuE+uh0JEApmrYQfyBRBidD6hVOakSQ+k5aSQ0oVzsSXeBN0WGl6U41XPYsD0NKcfhee7YvrlCFHjervaHosUaHsIVkoEB1HnT6W4J22Z/LysCdkMEVYJ+Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769057879; c=relaxed/simple; bh=2zKFfMTMqKvrVgdvqOdg0DtzxLD+I53GcCJU/6t6hqM=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=Y9X6vqGRbE9sk04A3F6+0SJtY8P5L4PgoPPLq7kZJ8dmrtzWsO5bdds1WYZCWwUfT8Af/Af3EAnKoR2/sHSZCjmqeINw7iWRO4GB5cNLYcJT1Wt+ge1zKN4kOtwDPZs3d7H9wOBmBQPxe7sru4zJXvZOKl/eVX7Mhosfk6ap+ZQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=m6k4mmxB; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="m6k4mmxB" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2a7701b6353so5675895ad.3 for ; Wed, 21 Jan 2026 20:57:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1769057878; x=1769662678; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=UGrDICrJR5zjmJ8xi9tG6zRY1ROX7Sa4yCNtwk3moDw=; b=m6k4mmxByDbAVxTZTqi6yZyQpkAvELMBgooXwDfvU79oMg1TW2kBXpFun9/6uciaX+ W+gqbygDT2sm2uPVvvO6cxo5amisSgBHy3fYo3vH3cwdF9WCdxyi8GoZ0w15AijuT/3A X86KRdg8LzpmmT6j7ycBBX5B8sjVCN7+6vRWRiNCb8eubRDlDiFEX31brbYaJlBRJF6f AbFrerv/Pq6blwdocreAidqIaFMDkvfDwATl9SeT6fHekbjCT7/nmY1o8GTg47fcXsWP qohEbLTZBahfUVtSXCQbGlyteajH3v19Anp/VgfRMp/1sE2jVAlNa8xqB/N4PDkjSJBK cQnQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769057878; x=1769662678; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=UGrDICrJR5zjmJ8xi9tG6zRY1ROX7Sa4yCNtwk3moDw=; b=QZqfVLFF3uSwa8nFsiD49frW8R8pNHlSxAJGpDlAi3BHG5kC7Z2iziMRWBCMibIrKf nZo687T5pRVxCMw5FrJI6EjPa44DoHx+Bp0YmtmVCJNKtWEdsskW+FW9bU1vew17mJTw RXYEfPcsk6QO+6NZhJ+jNvQO68zprYtgL8TkRf07VAwEq9taTYRDvwS1WFrHU0dJay91 EhoYC5MQDf6ipKrIj15CsTtLtRdpor4XhwqKGKQ7b+HVIxKwKt7FVv66v3+oc5hjA/rd vIxcMw8Fy1dtEamzyJmXJmUHGSz2+nBbAAlVXclHoS2zj4CW2DdcsvQ9KEpzFHT8HQzU E7ZQ== X-Forwarded-Encrypted: i=1; AJvYcCVuq6FtZcLUAecLcNc6g161hst4yMCnmQFK0lCMsiQGyX4gLSLFnxvn5jYAkzZzLso8Lvw3Mi7xiT8EH4A=@vger.kernel.org X-Gm-Message-State: AOJu0YzHlJH5Vufx/Pk8G2WI3BR19etRiamnsRhk0kyquueCyHxTTIfS IGx0bZtJtDfyQc6CgVrkkDH87U9ynRBl+VB5uHYwQPnhSYhyF/WSFgbKXGS9Bsse8/IF0CAOW9L duqUIFrqr6kVNKA== X-Received: from pjvh4.prod.google.com ([2002:a17:90a:db84:b0:352:de3b:3a0f]) (user=chengkev job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:3f4c:b0:349:3fe8:e7de with SMTP id 98e67ed59e1d1-3527325d6ecmr14606772a91.28.1769057877602; Wed, 21 Jan 2026 20:57:57 -0800 (PST) Date: Thu, 22 Jan 2026 04:57:49 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.52.0.457.g6b5491de43-goog Message-ID: <20260122045755.205203-1-chengkev@google.com> Subject: [PATCH V3 0/5] Align SVM with APM defined behaviors From: Kevin Cheng To: seanjc@google.com, pbonzini@redhat.com Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, yosry.ahmed@linux.dev, Kevin Cheng Content-Type: text/plain; charset="UTF-8" The APM lists the following behaviors - The VMRUN, VMLOAD, VMSAVE, CLGI, VMMCALL, and INVLPGA instructions can be used when the EFER.SVME is set to 1; otherwise, these instructions generate a #UD exception. - If VMMCALL instruction is not intercepted, the instruction raises a #UD exception. - STGI instruction causes a #UD exception if SVM is not enabled and neither SVM Lock nor the device exclusion vector (DEV) are supported. The patches in this series fix current SVM bugs that do not adhere to the APM listed behaviors. v2 -> v3: - Elaborated on 'Move STGI and CLGI intercept handling' commit message as per Sean - Fixed bug due to interaction with svm_enable_nmi_window() and 'Move STGI and CLGI intercept handling' as pointed out by Yosry. Code changes suggested by Sean/Yosry. - Removed open-coded nested_svm_check_permissions() in STGI interception function as per Yosry v2: https://lore.kernel.org/all/20260112174535.3132800-1-chengkev@google.com/ v1 -> v2: - Split up the series into smaller more logical changes as suggested by Sean - Added patch for injecting #UD for STGI under APM defined conditions as suggested by Sean - Combined EFER.SVME=0 conditional with intel CPU logic in svm_recalc_instruction_intercepts Kevin Cheng (5): KVM: SVM: Move STGI and CLGI intercept handling KVM: SVM: Inject #UD for STGI if EFER.SVME=0 and SVM Lock and DEV are not available KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 KVM: SVM: Recalc instructions intercepts when EFER.SVME is toggled KVM: SVM: Raise #UD if VMMCALL instruction is not intercepted arch/x86/kvm/svm/nested.c | 9 +++-- arch/x86/kvm/svm/svm.c | 74 +++++++++++++++++++++++++++++++++------ arch/x86/kvm/svm/svm.h | 1 + 3 files changed, 71 insertions(+), 13 deletions(-) -- 2.52.0.457.g6b5491de43-goog