From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 503E78C1F for ; Sat, 31 Jan 2026 02:31:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769826698; cv=none; b=Wvty4nDzRcDrg5Q9/9uJ7bHjXxgZleCtKrOxjFgQblNUrpetjE9+15Z1P2d7dUftVdycZHntevENWLDrlgbAz5Un2bJk9UrXHzOiysp6hPq2urPQNuQ8/skDfFVgUv7Sv0l8OKD7PrMLgc4gBQdwI/fYd9EXd2M0XRBYDRVymcE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769826698; c=relaxed/simple; bh=EKPQLWbsWyT9BUr2s5Ctqy4Jc4chfE3nJq0OgEVxysQ=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=dG0MKNgm7KOSNhnPrGv03JkR7/1qUDxBGDMKZlDjk0VszZxRhwFsbOekKUGf9Nlv08Cc+DPzSsCOfE5fzHdE9+CsN1hT6q2yRkcANxDHPDwllP9SxPKn9GqQgrXwfy31WmuvS7TDXiYMyL8LwKqsLDkr2dRKoku34QrLRWV0W9I= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=DWvVdY9S; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="DWvVdY9S" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2a351686c17so23056325ad.0 for ; Fri, 30 Jan 2026 18:31:36 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1769826696; x=1770431496; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=ctO94QNI1k+SuuLJULnF65RAXsyYJ0G/MWNFTi5M4v8=; b=DWvVdY9StnwMEIxAtMuD5nVYgOsPMQRFQ+U0+nuhOewbCst9Jv73Ru3GTpAwr3vd9y Hjxaj8zjixYnd19Xpl+FQPOyRRTDdyTDVqDqZSbSOTlCmqBcZHkG8KBuNl6mhNCOQXkz e16Bq/u8+EES6k2++Q53d44hH7hVtZc5PJqAriG6poeLXfPvRhibsIuUrq7FPQP60NSZ wQm1TQ9txr0ETEc2Mnd5ite1pUjA1xk5AWQLw4B7b3HhJA9Nlc8FSkAwWC/cypeHAW8v vXkj0jsk0zVQApVIGgf56yBpmhqXNNcmaIbugStuq1DwrwskWBa8ofMBkVSixQFz00F9 wkQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769826696; x=1770431496; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=ctO94QNI1k+SuuLJULnF65RAXsyYJ0G/MWNFTi5M4v8=; b=DYj0XYCtcoHPEU+OC4bUPm7uJT0tMlFmrVBdPEEpkIOiBkDou6DvHt6SBN0hBQljFd A7LJzw1Z0H6EjVyJQv+klvZoeCyac3PMn0m8rradQ3gfw3RJ3Tcxqv3IikWN1PWgOrOQ IadLg/SZPJsWX/Vu4jv8ICC4kqFHeGH3ZBh7xZY+OZ9AoYiDNBdls0vHlCZFwQE57YHC 4zAhGOh/6hKPwfTFoFrNRZnqOosUWH0fwpCSBFD4nNBZWnNH1G+okQCgDKFi5XN3/AqE BV5NMqxH5aDo7kCwAqm7RQniYEIxyIWUpDvsyTIn73O4AXTmMGfyLgvMJ6FK+dQAmMYf lfaw== X-Forwarded-Encrypted: i=1; AJvYcCVuO74WPwYSQltCTi/FW8UrukIYUvVJCwKOXMwlQFgZ1A0JNq2UVU0DWgSBeeGfjYqLQcUzleGmRyrEOqQ=@vger.kernel.org X-Gm-Message-State: AOJu0YyTnybGPLLC73qrTfvIUrZUsiqeANudMJg3zf/Nw6Vljwd2jeuS GiPiWii714HoTzuQzCPFbZloRbZJBhxVxdrNeOgPik0lfKjYEe3aMg5NY+g95pzTwMUd10IBHs+ O82Y1bw== X-Received: from plgz13.prod.google.com ([2002:a17:903:18d:b0:29f:bf99:8c9f]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:aa82:b0:29e:e642:95d6 with SMTP id d9443c01a7336-2a8d9a7a005mr34084265ad.59.1769826695713; Fri, 30 Jan 2026 18:31:35 -0800 (PST) Reply-To: Sean Christopherson Date: Fri, 30 Jan 2026 18:31:33 -0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.53.0.rc1.225.gd81095ad13-goog Message-ID: <20260131023133.2661-1-seanjc@google.com> Subject: [GIT PULL] KVM: Fix for 6.19-rc8 (or final) From: Sean Christopherson To: Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Sean Christopherson Content-Type: text/plain; charset="UTF-8" Sorry for the late pull request, I was waiting on reviews for the CET fix to settle down. I _just_ amended that commit to add a Reviewed-by, but it's been in linux-next with identical code since Tuesday. The most pressing issue is the IRQ routing bug (and also probably the scariest, but it's had several weeks in -next), as it leads to all kinds of badness on AMD platforms. The following changes since commit 3611ca7c12b740e250d83f8bbe3554b740c503b0: selftests: kvm: Verify TILELOADD actually #NM faults when XFD[18]=1 (2026-01-10 07:17:30 +0100) are available in the Git repository at: https://github.com/kvm-x86/linux.git tags/kvm-x86-fixes-6.19-rc8 for you to fetch changes up to f8ade833b733ae0b72e87ac6d2202a1afbe3eb4a: KVM: x86: Explicitly configure supported XSS from {svm,vmx}_set_cpu_caps() (2026-01-30 13:27:33 -0800) ---------------------------------------------------------------- KVM fixes for 6.19 - Fix a bug where AVIC is incorrectly inhibited when running with x2AVIC disabled via module param (or on a system without x2AVIC). - Fix a dangling device posted IRQs bug by explicitly checking if the irqfd is still active (on the list) when handling an eventfd signal, instead of zeroing the irqfd's routing information when the irqfd is deassigned. Zeroing the irqfd's routing info causes arm64 and x86's to not disable posting for the IRQ (kvm_arch_irq_bypass_del_producer() looks for an MSI), incorrectly leaving the IRQ in posted mode (and leading to use-after-free and memory leaks on AMD in particular). - Disable FORTIFY_SOURCE for KVM selftests to prevent the compiler from generating calls to the checked versions of memset() and friends, which leads to unexpected page faults in guest code due e.g. __memset_chk@plt not being resolved. - Explicitly configure the support XSS from within {svm,vmx}_set_cpu_caps() to fix a bug where VMX will compute the reference VMCS configuration with SHSTK and IBT enabled, but then compute each CPUs local config with SHSTK and IBT disabled if not all CET xfeatures are enabled, e.g. if the kernel is built with X86_KERNEL_IBT=n. The mismatch in features results in differing nVMX setting, and ultimately causes kvm-intel.ko to refuse to load with nested=1. ---------------------------------------------------------------- Sean Christopherson (4): KVM: SVM: Check vCPU ID against max x2AVIC ID if and only if x2AVIC is enabled KVM: Don't clobber irqfd routing type when deassigning irqfd KVM: x86: Assert that non-MSI doesn't have bypass vCPU when deleting producer KVM: x86: Explicitly configure supported XSS from {svm,vmx}_set_cpu_caps() Zhiquan Li (1): KVM: selftests: Add -U_FORTIFY_SOURCE to avoid some unpredictable test failures arch/x86/kvm/irq.c | 3 ++- arch/x86/kvm/svm/avic.c | 4 +-- arch/x86/kvm/svm/svm.c | 2 ++ arch/x86/kvm/vmx/vmx.c | 2 ++ arch/x86/kvm/x86.c | 30 ++++++++++++---------- arch/x86/kvm/x86.h | 2 ++ tools/testing/selftests/kvm/Makefile.kvm | 1 + virt/kvm/eventfd.c | 44 +++++++++++++++++--------------- 8 files changed, 52 insertions(+), 36 deletions(-)