From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f202.google.com (mail-pf1-f202.google.com [209.85.210.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E79F133F386 for ; Sat, 7 Feb 2026 04:10:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.202 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770437429; cv=none; b=grPKKVZaSLqSF0P4Aj1o7a7HVB4O94/0BDNaFM+x+scopEgcwmYqw+VXXWRG1Bz0/EWbpr5X6TPTunEgU9pqCMeC30Qw/19J729UvjujtWlsrzjOiresk5ZyViBJxh6F0jZ6935j0n+58q2e1Uu6VhZOOWOxyEAO77tEF0JvKlg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770437429; c=relaxed/simple; bh=P4Sa7dZb1Nfom/LISSVzZfbMBXyCEFM6fHdjKFn3t+w=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=MR/+h8TdlCQBirorFBvO6fUw1xBVsfywCJeuHk7ELJi2ExAUIPdI5oSL47BLQOIxJfDbFrp0JaRoYJpy0WgcXO2qelTSC+5okWIZLce5F2QtgMUZlS3We5Aihxys63UDEL8nqA9nMxoxk3dywLJCYJQO2EVQUCdx7fZI4Z9BLs4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=M5uvnI1g; arc=none smtp.client-ip=209.85.210.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="M5uvnI1g" Received: by mail-pf1-f202.google.com with SMTP id d2e1a72fcca58-824377115daso1352245b3a.0 for ; Fri, 06 Feb 2026 20:10:28 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1770437428; x=1771042228; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=VlNioCvIfIQZRS3oCEYLN5B7K+bIa2/hrm7ZFysFPQo=; b=M5uvnI1gU2nSN8rKc9QQLLT9FC3jZRAjnyDOealuZ9Mr2q2sm838bpau4rNeDoz5NJ rf0nIyrFBpbFVT43v/L8zwHQ1xW9K6OppxOqO92xyCz5pSo1t52B0s1Tl6xrWbw66jSy P8AAQMZ13IdYwLNy5Pai5EpbbDS5NV9itoq5Mo7P1nvruzYGwX7mxNVFevFy7mEMtMcM xLMK9bfe3fvRSroaPhbDhbtYT7Sxf6+eqNIwzJFNV+4tZd8zVzOKTJEe+/QugVDPGAVs wWbiXy69qCHjPZr7p8GJvBVk3FqNbUaT89zh2tMZHJzt7PwGvWxToLbwSY2OwKyHyvYM la0A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770437428; x=1771042228; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=VlNioCvIfIQZRS3oCEYLN5B7K+bIa2/hrm7ZFysFPQo=; b=wF07SK5ErgCr/EyzhNA1lltXYP8YSJ4WGbjOOXyFgRtMZ/NpG/1qx5kVEPN8tq7eyX /3d5Aj3P5hi45Fj6kMgd4DzDxKq+0dnd/Ofwu0ivp8gLwrzWjtPC29gDNuqxPQZ2f9xV 6B6eyIr5O8nhAFajtr9l4ESAoQh13JCBUPDKFc4ET648uNNs6h2HItt6BF6Y2PdnulmR MjS+4jJ3rl8yj4IOPqLG/4otpVYkaSqLwFU0wl6Ai0c4UZe4KcZmGlzvFP8gNAf887aa /ymOguMfxpFm8/7k37pokf3fYe13IgPGEhcOIUo/FZ2DnoQfdidqrMJ+2Y3OWzlfWLZe CIcA== X-Forwarded-Encrypted: i=1; AJvYcCV90zvca6mpMcrT6rIQElWlBrhiCySh3hv7wCFP4aoYKnGV3NOCO5PCXG+iRZr4/lX4MjxLyi9enPR/rTI=@vger.kernel.org X-Gm-Message-State: AOJu0YwwFQmnwY5h2hOg3jG0jJGcaN8BgekEtV+cU1M6B1TZDQ3a68yW l1Ql7FoTQPFpv/UCl6RpnXRjG2SqGRMoMfJ+pn8QAs9cO2lWuIrx6MmqbIhC9FJMy5m8bqJ3HNV twIpidQ== X-Received: from pfbhj3.prod.google.com ([2002:a05:6a00:8703:b0:823:5939:cc60]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:71c2:b0:824:40d8:9d68 with SMTP id d2e1a72fcca58-824416efca2mr4000686b3a.32.1770437428265; Fri, 06 Feb 2026 20:10:28 -0800 (PST) Reply-To: Sean Christopherson Date: Fri, 6 Feb 2026 20:10:10 -0800 In-Reply-To: <20260207041011.913471-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260207041011.913471-1-seanjc@google.com> X-Mailer: git-send-email 2.53.0.rc2.204.g2597b5adb4-goog Message-ID: <20260207041011.913471-9-seanjc@google.com> Subject: [GIT PULL] KVM: x86: VMX changes for 6.20 From: Sean Christopherson To: Paolo Bonzini Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Sean Christopherson Content-Type: text/plain; charset="UTF-8" The bulk of the changes are to disallow access to vmcs12 fields that aren't fully supported, so that we don't have to carry a bunch of isolated checks for shadowed fields. But for me, the highlight is to finally print out the offending offsets+values on VMCS config mismatches. The following changes since commit 9ace4753a5202b02191d54e9fdf7f9e3d02b85eb: Linux 6.19-rc4 (2026-01-04 14:41:55 -0800) are available in the Git repository at: https://github.com/kvm-x86/linux.git tags/kvm-x86-vmx-6.20 for you to fetch changes up to c0d6b8bbbced660e9c2efe079e2b2cb34b27d97f: KVM: VMX: Print out "bad" offsets+value on VMCS config mismatch (2026-01-30 13:27:46 -0800) ---------------------------------------------------------------- KVM VMX changes for 6.20 - Fix an SGX bug where KVM would incorrectly try to handle EPCM #PFs by always relecting EPCM #PFs back into the guest. KVM doesn't shadow EPCM entries, and so EPCM violations cannot be due to KVM interference, and can't be resolved by KVM. - Fix a bug where KVM would register its posted interrupt wakeup handler even if loading kvm-intel.ko ultimately failed. - Disallow access to vmcb12 fields that aren't fully supported, mostly to avoid weirdness and complexity for FRED and other features, where KVM wants enable VMCS shadowing for fields that conditionally exist. - Print out the "bad" offsets and values if kvm-intel.ko refuses to load (or refuses to online a CPU) due to a VMCS config mismatch. ---------------------------------------------------------------- Hou Wenlong (1): KVM: VMX: Don't register posted interrupt wakeup handler if alloc_kvm_area() fails Sean Christopherson (6): KVM: VMX: Always reflect SGX EPCM #PFs back into the guest KVM: nVMX: Setup VMX MSRs on loading CPU during nested_vmx_hardware_setup() KVM: VMX: Add a wrapper around ROL16() to get a vmcs12 from a field encoding KVM: nVMX: Disallow access to vmcs12 fields that aren't supported by "hardware" KVM: nVMX: Remove explicit filtering of GUEST_INTR_STATUS from shadow VMCS fields KVM: VMX: Print out "bad" offsets+value on VMCS config mismatch arch/x86/kvm/vmx/hyperv_evmcs.c | 2 +- arch/x86/kvm/vmx/hyperv_evmcs.h | 2 +- arch/x86/kvm/vmx/nested.c | 31 ++++++++------- arch/x86/kvm/vmx/vmcs.h | 9 +++++ arch/x86/kvm/vmx/vmcs12.c | 74 +++++++++++++++++++++++++++++++++-- arch/x86/kvm/vmx/vmcs12.h | 8 ++-- arch/x86/kvm/vmx/vmx.c | 86 ++++++++++++++++++++++++++++++++--------- 7 files changed, 171 insertions(+), 41 deletions(-)