From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f74.google.com (mail-pj1-f74.google.com [209.85.216.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B452826ED3D for ; Tue, 3 Feb 2026 19:07:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770145634; cv=none; b=WegRXRMkpz6Rp6q+7egy/4R7yo7iXcCSoVcFbcjQ9WlK5hOU/8QU/bVZIWNA5TzOnBZ8dIodvpu352n0xTIc9Yw3xjVrq3s4fDvfyAGNhUXtwM2HHh6Cx6CxkiohYkMMz/lirPO4Wl72T5v1NNn/s3qadRD6vZ+YR0PfnRKWo0o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770145634; c=relaxed/simple; bh=rSmJCm/c/mKOveunYcaZmGnbytpuXAWyHrTksnP3oZI=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=tHRKJOfbINx0sQgn0fcjiCBN+4SMXag+ULvaDa6m40Lnnddt2vaFYFmiigM2hMs9V+RZXTdTVaXUkd1j4gQTHqtnINVQnAtKJNnrzVTMr3fZ7ylRdpSVYo8cD02u9N95VJ/OkctpzaoD6TNsgVNgra+zFSr328DOVsTkFEbg9lU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=jiy0Aqn7; arc=none smtp.client-ip=209.85.216.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="jiy0Aqn7" Received: by mail-pj1-f74.google.com with SMTP id 98e67ed59e1d1-352e195f662so5070040a91.2 for ; Tue, 03 Feb 2026 11:07:13 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1770145633; x=1770750433; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=V0PgStJD0hlGtCGajd6vbNEL6gWOOLYA62RNilMSbNc=; b=jiy0Aqn7vcoWgVB6RtzbVbw91z1r9HN3EFc5TSZB3P0iCX+6S9hR9WUfTOscGinDFn X9DCemanQkHsB+7GFS7adPA9cVUCiyIOK0HIEct1fnA/sN1yPo8qWpfoEPQCwPHRmmvq GTYHLn1nTKcAZXAMaCpzCeKm9OsefDRJvGk+4Y8jn3Xp8tWYFkcL3XdI1+LLJWMnRVYz NasaKS1wHmInCR+ykpHGj4j8tNeKAlyt+fGCJ3a0Rqx8P1z9N3jXW8xNLaA5EGzW2Rs+ EeHQcX4PtlSwpk3BuhOl87idkqB8DiMt9hlFoQFuvQECcceMdk2jg8uiXpaZCIVm/4vl HqdQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770145633; x=1770750433; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=V0PgStJD0hlGtCGajd6vbNEL6gWOOLYA62RNilMSbNc=; b=pTafTyhtBvl8AEmORKdnJ4LRZpQC4HCfQuLPMIQYFeX3bz1pBrmmn4/W/csHbef7NG soL9yiznjLTLrSuC9pvrDs9KwW1UYG/MWk21GXbMC+aPlCX3H1B7QcMbpVqOsssemwB9 Me03HMUg1yzwAh+rxFpTcxNSqnnvrkyme+lCK5mMpDw2yXMrkwR0M+56HrbPUn2/Rqkq oGFTIv/lfsGQ4yNWWdhN5duqxeFmdiMJCRkiAoAKDy1lagAQ+RIXi5gjD/AYQIdBL8xi feT/+TlwJchPpGv09mjshyvQdBfw7e8JjNEAAWzOVvuLzzllPjbN8frB4VvfbjXG4QVj Vmlg== X-Forwarded-Encrypted: i=1; AJvYcCWgqn+h6UzplHyFEWZYX9DV++uFOvZGfBOQETmD9ph8awcs4+hjs+NsIIvr5SpnR7YgaxeMj2qW5/2hK3E=@vger.kernel.org X-Gm-Message-State: AOJu0YzqNXAvt3t1z+gfIphY2nFWnRyM2/mx1SMRfHutJN58jvyJp2R6 Z34+GykgWdcmmX4JfLfX6SJHgMiTChXPds9XmXtx2GrHJE89bvGkMEHeKKtyanLF/CK82vQNGiQ Ge6hLMA== X-Received: from pjnu10.prod.google.com ([2002:a17:90a:890a:b0:34c:4074:d7ec]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:5346:b0:340:c179:365a with SMTP id 98e67ed59e1d1-35486f549ffmr303479a91.0.1770145633024; Tue, 03 Feb 2026 11:07:13 -0800 (PST) Reply-To: Sean Christopherson Date: Tue, 3 Feb 2026 11:07:08 -0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.53.0.rc2.204.g2597b5adb4-goog Message-ID: <20260203190711.458413-1-seanjc@google.com> Subject: [PATCH 0/2] KVM: SVM: Fix CR8 intercpetion woes with AVIC From: Sean Christopherson To: Sean Christopherson , Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Jim Mattson , Naveen N Rao , "Maciej S . Szmigiero" Content-Type: text/plain; charset="UTF-8" Fix a bug (or rather, a class of bugs) where SVM leaves the CR8 write intercept enabled after AVIC is enabled. On its own, the dangling CR8 intercept is "just" a performance issue. But combined with the TPR sync bug fixed by commit d02e48830e3f ("KVM: SVM: Sync TPR from LAPIC into VMCB::V_TPR even if AVIC is active"), the danging intercept is fatal to Windows guests as the TPR seen by hardware gets wildly out of sync with reality. Tagged for stable even though there shouldn't be functional issues so long as the TPR sync bug is fixed, because (a) write_cr8 exits can represent the overwhelming majority of exits (hence the quotes around "just" a performance issue), and (b) running with a bad/wrong configuration increases the chances of encountering other lurking TPR bugs (if there are any), i.e. of hitting bugs that would otherwise be rare edge (which is good for testing, but bad for production). Sean Christopherson (2): KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated arch/x86/kvm/svm/avic.c | 8 +++++--- arch/x86/kvm/svm/svm.c | 11 ++++++----- 2 files changed, 11 insertions(+), 8 deletions(-) base-commit: e944fe2c09f405a2e2d147145c9b470084bc4c9a -- 2.53.0.rc2.204.g2597b5adb4-goog