From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f74.google.com (mail-pj1-f74.google.com [209.85.216.74]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A86E92D6E4B for ; Sat, 7 Feb 2026 04:10:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.74 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770437421; cv=none; b=Siu6rkap64ElVVNNWpRvQs3HN0rHYAIErrWJ5X9Wv75H65iiqG2y+W6Cdw5qjWR0PnJ6yPXNeuwPSZRpVmlyuPZP5dWaX5oO71cSB7RR8V458EEQL4aaRC9ZN6eOMIdIPlbcQ4agZevyAx147OIynEjevmFQqc2LwPvOj3eaiKw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770437421; c=relaxed/simple; bh=rOROJGvPCEPzOWAqMf5MRNjNGJydhI+lyttEtylFZI0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=oDvKojZbTSoJLAYL2X6rRtIHBMXs0V3o5kkecBqXGx/R34oeeZ1GvpYA4jInALRi2+LROJmzCX/lPN4S1nQGuakPbUdkWnkuPMrkjFWo5deAGYQYOUTD6WMRbOdoBS6KXQKo4aW4veoSShouDy7UN5RVsK5a3TJ5aZAZDNUzuhk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=yV395FpA; arc=none smtp.client-ip=209.85.216.74 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="yV395FpA" Received: by mail-pj1-f74.google.com with SMTP id 98e67ed59e1d1-3545dbb7f14so2721972a91.0 for ; Fri, 06 Feb 2026 20:10:21 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1770437421; x=1771042221; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=1AowVblkqagzbzM8Tx2Y14o60T6tXfbxiInvAlXBy8E=; b=yV395FpAMBD/aNjASi55LAZDUwyrEKkHoRp4/1eugWoQLx/b4iYRr9TV87a1p8InPX FNGBl+FsNEfSAVZlaH5e6Q61f37RDTRQgkZ3CJ9vOW1+lbCmC+r84OCSa7gCaHEK27+K jjAH5K+rCFCIfP3icQCWLs+SOWqPuJfD0DSE3jVnn/6DmRmGnMCymfffdP9lGeyL6ywY NuawsZso9kL3yR27phVBipUE8CH9PDG35fMqkcEmolT4JWGHQjKNb4JytEC8XD+P3Hhv v272Lkww0WC2AWQovXPz3gc4M/bCl+TQdUop8IkvtL6zK76U4tA+jpheb86kqcdMf0WG 0fjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770437421; x=1771042221; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=1AowVblkqagzbzM8Tx2Y14o60T6tXfbxiInvAlXBy8E=; b=SDYvfAig27tevYFmRLjmSnOH0EGciFF/aX1BsCQGyK2a8YwpyYUa/JnVzW/drZ66IX 3qZFKQHV+4+YjHnUDNYdUUH1MvZ2XDJlxVTAcG7CULZGsqHB1DL21QTZWHe53v8D0Pg3 22Rf2Pyy1+GVgDqBqZFJTFT4h2f/CHxObfQpSZhZc6uFjAC6Dq6ytDqWZGKSIeZ33VaG 3dLTL7ao5xtTH5XB2/4V+GT7ojIWF2H9wq4+I67dBukyiCY7jVE6FgW63O+Yv8uAThfw R3fN+M9q8xUjHtvBfF1uWWYev6EFPbBC8scybApkpGcMxNwKfv/eRA7HunbC7Ou2RY1A +TFQ== X-Forwarded-Encrypted: i=1; AJvYcCWkMjvRBJAQV8dyOvzFpVn6tUYRGryiG9MRUicuiN4PWx4h8emP26DDwacpX09aXa/690uCDtMYizsnmio=@vger.kernel.org X-Gm-Message-State: AOJu0Yyxt7pDPwQ5OgPMPbE0coDINLmSCOoBKza5f+lg9Citz/NnYObv ADTbjHNbWJl1TBs1wxJUTOnINjXUZcPwgANuARX8p3v4VulAOEvO2XkqrQ7ifjG7BDHiAX86i3q fy4I1tQ== X-Received: from pjtl24.prod.google.com ([2002:a17:90a:c598:b0:354:c16d:17b]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:4a04:b0:34a:4a8d:2e2e with SMTP id 98e67ed59e1d1-354b3cae0b8mr4379330a91.17.1770437421200; Fri, 06 Feb 2026 20:10:21 -0800 (PST) Reply-To: Sean Christopherson Date: Fri, 6 Feb 2026 20:10:06 -0800 In-Reply-To: <20260207041011.913471-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260207041011.913471-1-seanjc@google.com> X-Mailer: git-send-email 2.53.0.rc2.204.g2597b5adb4-goog Message-ID: <20260207041011.913471-5-seanjc@google.com> Subject: [GIT PULL] KVM: x86: Misc changes for 6.20 From: Sean Christopherson To: Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Sean Christopherson Content-Type: text/plain; charset="UTF-8" No real theme here, truly a misc set of changes. The most notable change is the Suppress EOI Broadcast quirk (not actually implemented as a quirk), which generated a _lot_ of discussion (David W. still isn't thrilled that in-kernel I/O APIC support isn't included[*]), but overall I think we ended up with a solid implementation. [*] https://lore.kernel.org/all/83f9b0a5dd0bc1de9d1e61954f6dd5211df45163.camel@infradead.org The following changes since commit 9ace4753a5202b02191d54e9fdf7f9e3d02b85eb: Linux 6.19-rc4 (2026-01-04 14:41:55 -0800) are available in the Git repository at: https://github.com/kvm-x86/linux.git tags/kvm-x86-misc-6.20 for you to fetch changes up to 6517dfbcc918f970a928d9dc17586904bac06893: KVM: x86: Add x2APIC "features" to control EOI broadcast suppression (2026-01-30 13:28:35 -0800) ---------------------------------------------------------------- KVM x86 misc changes for 6.20 - Disallow changing the virtual CPU model if L2 is active, for all the same reasons KVM disallows change the model after the first KVM_RUN. - Fix a bug where KVM would incorrectly reject host accesses to PV MSRs that were advertised as supported to userspace when running with KVM_CAP_ENFORCE_PV_FEATURE_CPUID enabled. - Fix a bug where KVM would attempt to read protect guest state (CR3) when configuring an async #PF entry. - Fail the build if EXPORT_SYMBOL_GPL or EXPORT_SYMBOL is used in KVM (for x86 only) to enforce usage of EXPORT_SYMBOL_FOR_KVM_INTERNAL. Explicitly allow the few exports that are intended for external usage. - Ignore -EBUSY when checking nested events after a vCPU exits blocking as the WARN is user-triggerable, and because exiting to userspace on -EBUSY does more harm than good in pretty much every situation. - Throw in the towel and drop the WARN on INIT/SIPI being blocked when vCPU is in Wait-For-SIPI, as playing whack-a-mole with syzkaller turned out to be an unwinnable game. - Add support for new Intel instructions that don't require anything beyond enumerating feature flags to userspace. - Grab SRCU when reading PDPTRs in KVM_GET_SREGS2. - Add WARNs to guard against modifying KVM's CPU caps outside of the intended setup flow, as nested VMX in particular is sensitive to unexpected changes in KVM's golden configuration. - Add a quirk to allow userspace to opt-in to actually suppress EOI broadcasts when the suppression feature is enabled by the guest (currently limited to split IRQCHIP, i.e. userspace I/O APIC). Sadly, simply fixing KVM to honor Suppress EOI Broadcasts isn't an option as some userspaces have come to rely on KVM's buggy behavior (KVM advertises Supress EOI Broadcast irrespective of whether or not userspace I/O APIC supports Directed EOIs). - Minor cleanups. ---------------------------------------------------------------- Jun Miao (1): KVM: x86: align the code with kvm_x86_call() Khushit Shah (1): KVM: x86: Add x2APIC "features" to control EOI broadcast suppression Sean Christopherson (6): KVM: x86: Disallow setting CPUID and/or feature MSRs if L2 is active KVM: x86: Return "unsupported" instead of "invalid" on access to unsupported PV MSR KVM: x86: Enforce use of EXPORT_SYMBOL_FOR_KVM_INTERNAL KVM: x86: Ignore -EBUSY when checking nested events from vcpu_block() KVM: x86: Drop WARN on INIT/SIPI being blocked when vCPU is in Wait-For-SIPI KVM: x86: Harden against unexpected adjustments to kvm_cpu_caps Vasiliy Kovalev (1): KVM: x86: Add SRCU protection for reading PDPTRs in __get_sregs2() Xiaoyao Li (1): KVM: x86: Don't read guest CR3 when doing async pf while the MMU is direct Zhao Liu (4): KVM: x86: Advertise MOVRS CPUID to userspace KVM: x86: Advertise AMX CPUIDs in subleaf 0x1E.0x1 to userspace KVM: x86: Advertise AVX10.2 CPUID to userspace KVM: x86: Advertise AVX10_VNNI_INT CPUID to userspace Documentation/virt/kvm/api.rst | 28 ++++++++++++- arch/x86/include/asm/cpufeatures.h | 1 + arch/x86/include/asm/kvm_host.h | 9 +++++ arch/x86/include/uapi/asm/kvm.h | 6 ++- arch/x86/kvm/Makefile | 49 +++++++++++++++++++++++ arch/x86/kvm/cpuid.c | 75 +++++++++++++++++++++++++++++------ arch/x86/kvm/cpuid.h | 12 +++++- arch/x86/kvm/ioapic.c | 2 +- arch/x86/kvm/lapic.c | 77 +++++++++++++++++++++++++++++++----- arch/x86/kvm/lapic.h | 2 + arch/x86/kvm/mmu/mmu.c | 11 +++--- arch/x86/kvm/pmu.c | 2 +- arch/x86/kvm/reverse_cpuid.h | 19 +++++++++ arch/x86/kvm/svm/svm.c | 4 +- arch/x86/kvm/vmx/vmx.c | 4 +- arch/x86/kvm/x86.c | 81 +++++++++++++++++++++++--------------- arch/x86/kvm/x86.h | 15 ++++++- 17 files changed, 328 insertions(+), 69 deletions(-)