From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f201.google.com (mail-pl1-f201.google.com [209.85.214.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 491472749C1 for ; Sat, 28 Feb 2026 03:33:32 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772249613; cv=none; b=HH6TfaudvlLEk8XiFIhziHqh1SBtdTnYuEiSLxOex+k4bDo5HAuepf1MI9M2jn5tLS230nuKOM+N1o8CoUxY9jNo2ymp7fd+5JPXt0ygx9rKFUPOWvrIjDZaDE1hO+qKM9gU5nslHrzz7bQ5CA9co89f0djxud52pVapB9Fipq4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772249613; c=relaxed/simple; bh=+v3nri1DdjIgOGn4RXg7h370aWy1wlIJbf+reNqIh84=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=dh6YlsiMNekRxTRQzgRIBhfWQR9pjpBKVhJPwpuizYgXBbz8VWAL33/rdsCrKx5pNLfnf2rB3n+mtDtmfIn6yyd8M+97r1ZvPGsnYXC6i6DfZiGnuKMl0Dm+PAXLuZQ47E550dDJD1j4v09/dzvechMJg3LRR4cWdF2TDxbhPHA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=LGTzl81N; arc=none smtp.client-ip=209.85.214.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--chengkev.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="LGTzl81N" Received: by mail-pl1-f201.google.com with SMTP id d9443c01a7336-2adb1bdf778so27328705ad.3 for ; Fri, 27 Feb 2026 19:33:32 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1772249612; x=1772854412; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:from:to:cc:subject :date:message-id:reply-to; bh=yceO0f6YP14FV+FbBXD5MBGCTsrjqX1uNk/E2eJRM18=; b=LGTzl81NfTC5L5Wf+YHpRiQgQ76vxFzHO+C3rJK9dqseW5fLEYh5X/pqOe2vk58J6y QWVu886a4Rq41JiiW2ukyhNiqBfntoiJ40Z04BIbzEnlmfckITldHrhP9oRjIkBrH+Du KWtiRiMrSp0OjmeB0vIf932F0+MhelaaIgZR4vi/55fcG4U/qsmv1VngZKRWpbsmr7bB tvc8yXvso20dSnofdv6ZHCyhzRHvQ1M6a8ZZW+uNArZ4Y2PJTxHqGJuyHNAK93wzKfpw 0plC97PcceewhrSKRWX2sP/HJAfLnUGQ2Gi2xYxvciy3ycRcsNvmn3xuNxRynr42iY5M QTog== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772249612; x=1772854412; h=cc:to:from:subject:message-id:mime-version:date:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=yceO0f6YP14FV+FbBXD5MBGCTsrjqX1uNk/E2eJRM18=; b=U1Bl5SQWzb6CqoK5bwdXvS5ZJVmgx7E6pqeH3h7Hs8Ws+ncA/q3CzXZoEex1URPX1R xqkvxqCVumpzA5QfBVnLOvNWldFRMgqvAHR7suXeEIcXqxnrhoOZGZC3gAoqXbOiqXG8 51+8/aDDYpEic5+NCFOpx6XnFTX2WseWZrWRVzCxN0jUlVJwQLUYDAvpHBdVCsPsgqEB Hab+1+d5HZnAZL44qa8h4Jhl3mCyxPOgsCdeFNJwhQs/Bpeck9VCSzIw6e+UEb3fzall iQhPWdx5EaACSF5G2Xjmv4audGijhnqjoKWU5tKF2D69tsxzFgclC8SMo3Vz7wGHYJwu 25uQ== X-Forwarded-Encrypted: i=1; AJvYcCXQ5zJcWytLyfJ1GEzuccxLRwkaYVZfbBoLxol/m1PWhuqtPkbII8R1VQ594nuSIUeR1d6gsJBK+ETaSqM=@vger.kernel.org X-Gm-Message-State: AOJu0YzpTznVpIj8VGINwr9DI1Z5ux57Pa3wmODBH7xNzDIcMpCxjvzQ Xo76bitF3FqCpEKmT1qEVI4MsjyjxTCc36uad3wbGnHyib+v/t8fERZVWloEPi9w8bblKjZ3YZ9 EdPJEMw7QQftgfA== X-Received: from plim9.prod.google.com ([2002:a17:903:3b49:b0:2a0:e956:8aed]) (user=chengkev job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:1786:b0:2a4:8cd:c3cf with SMTP id d9443c01a7336-2ae2e4d348amr51524705ad.49.1772249611304; Fri, 27 Feb 2026 19:33:31 -0800 (PST) Date: Sat, 28 Feb 2026 03:33:24 +0000 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.53.0.473.g4a7958ca14-goog Message-ID: <20260228033328.2285047-1-chengkev@google.com> Subject: [PATCH V4 0/4] Align SVM with APM defined behaviors From: Kevin Cheng To: seanjc@google.com, pbonzini@redhat.com Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, yosry@kernel.org, Kevin Cheng Content-Type: text/plain; charset="UTF-8" The APM lists the following behaviors - The VMRUN, VMLOAD, VMSAVE, CLGI, VMMCALL, and INVLPGA instructions can be used when the EFER.SVME is set to 1; otherwise, these instructions generate a #UD exception. - If VMMCALL instruction is not intercepted, the instruction raises a #UD exception. The patches in this series fix current SVM bugs that do not adhere to the APM listed behaviors. v3 -> v4: - Dropped "KVM: SVM: Inject #UD for STGI if EFER.SVME=0 and SVM Lock and DEV are not available" as per Sean - Added back STGI and CLGI intercept clearing in init_vmcb to maintain previous behavior on intel guests. Previously intel guests always had STGI and CLGI intercepts cleared if vgif was enabled. In V3, because the clearing of the intercepts was moved from init_vmcb() to the !guest_cpuid_is_intel_compatible() case in svm_recalc_instruction_intercepts(), the CLGI intercept would be indefinitely set on intel guests. I added back the clearing to init_vmcb() to retain intel guest behavior before this patch. - In "Raise #UD if VMMCALL instruction is not intercepted" patch: - Exempt Hyper-V L2 TLB flush hypercalls from the #UD injection, as L0 intentionally intercepts these VMMCALLs on behalf of L1 via the direct hypercall enlightenment. - Added nested_svm_is_l2_tlb_flush_hcall() which just returns true if the hypercall was a Hyper-V L2 TLB flush hypercall. v3: https://lore.kernel.org/kvm/20260122045755.205203-1-chengkev@google.com/ v2 -> v3: - Elaborated on 'Move STGI and CLGI intercept handling' commit message as per Sean - Fixed bug due to interaction with svm_enable_nmi_window() and 'Move STGI and CLGI intercept handling' as pointed out by Yosry. Code changes suggested by Sean/Yosry. - Removed open-coded nested_svm_check_permissions() in STGI interception function as per Yosry v2: https://lore.kernel.org/all/20260112174535.3132800-1-chengkev@google.com/ v1 -> v2: - Split up the series into smaller more logical changes as suggested by Sean - Added patch for injecting #UD for STGI under APM defined conditions as suggested by Sean - Combined EFER.SVME=0 conditional with intel CPU logic in svm_recalc_instruction_intercepts Kevin Cheng (4): KVM: SVM: Move STGI and CLGI intercept handling KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 KVM: SVM: Recalc instructions intercepts when EFER.SVME is toggled KVM: SVM: Raise #UD if VMMCALL instruction is not intercepted arch/x86/kvm/svm/hyperv.h | 11 ++++++++ arch/x86/kvm/svm/nested.c | 4 +-- arch/x86/kvm/svm/svm.c | 59 +++++++++++++++++++++++++++++++++++---- 3 files changed, 65 insertions(+), 9 deletions(-) -- 2.53.0.473.g4a7958ca14-goog