From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f201.google.com (mail-pg1-f201.google.com [209.85.215.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4F0CA372056 for ; Thu, 25 Jun 2026 22:36:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782426987; cv=none; b=SVikmlRySgx1cC14UQmwbEyWpI45I+WQY1rdlP5phZbql7rrJ7YAYp3gg/Mm5ettA69/M5m1aycisAfGrDgn5bH5TcXhA3piYbkx5owuW8Du0xBtMtGTH8ghA9vREdy+iduKzp5jCGBTZmYDG+L1Qjg4CFuwWO07ZIw7pQU2SLA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782426987; c=relaxed/simple; bh=5nG2XUOYuDpiBR+eICqANAtfrT4atv3CJGP4IiwWT38=; h=Date:Mime-Version:Message-ID:Subject:From:To:Cc:Content-Type; b=Bd7NkFsft45eJXnbJ9RSp8/cEiLyNfkQ7Uoziu6LVJTwWbKDrI6GVFog++CYxrzjDCzF67J3YUp7NslaA2UeEoMgSlyAfNWpNiIpoy9f/Ny0Uu9CopR/DXRj+AroihMly69LNCPCBlCZJ0A83fojRRdUHaf+oGiyj7saXXTvY+A= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=jo+MzTGt; arc=none smtp.client-ip=209.85.215.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="jo+MzTGt" Received: by mail-pg1-f201.google.com with SMTP id 41be03b00d2f7-c889d1eedcdso173354a12.1 for ; Thu, 25 Jun 2026 15:36:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1782426984; x=1783031784; darn=vger.kernel.org; h=cc:to:from:subject:message-id:mime-version:date:reply-to:from:to:cc :subject:date:message-id:reply-to; bh=iUHnM3WkSpmD1Lwz4Juph4tt5gMwM0tIpsydVwTDLmk=; b=jo+MzTGtl3BtENuCYXfsq/VJzXTH8SKu7/cYpGPZu+L51NJQd+rJYC8eEa5j/PfLUd fXlTcSGWt9x1W+DmHaYpjTNcBtw3MczyVGOV2b37cFM1Nf2TytgbY+tEBurVr3a4U4d/ 5q+GDmLKn8tAwgReiKAqfsFUZKJGNEv04mvoMjPFlroSpRndplyXGzOP3S89Zs4qE5p5 4HaVZb02vXelWjVJZ3ph8DaM5P1uYwK264TYYBxz4yRslN267/4xEw9eVYpfmUrVtUWL VqmFSPhECmck+BIFKG7b0tUYjraWbWQb0LjViCwAk/wSGOS+AlKSRFO7qF65ieUs4xE0 NHUQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782426984; x=1783031784; h=cc:to:from:subject:message-id:mime-version:date:reply-to :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=iUHnM3WkSpmD1Lwz4Juph4tt5gMwM0tIpsydVwTDLmk=; b=jiovLmCNcKLSHEnxNx+mJrpOKYVk5plwe51LSVRjfXsLSbgNTkzRo1fEdgIqFdcXo8 suTwT03u7LYglRL6VwfZuDmPi49NAvTyqkIWZ7QBtFPMUWSx+LSfPshioAL8oYo4SdeP jPIzJzHUD5rEK0ysSsiKDXeBtpmPVUlEYfGDlav3tkTp7zaVQpYp9rW9P4ixERAVJmbR hbVgEuS+55FfG+/VSbUE4hvoGw0z9bSqN2lte+QTXl0EL0ySpjQecuUA8zjQVA6yuWA1 pvXbnue4YiNZvYdLZU0JGNn64SLLV5X34664E2h+3xGydHZ0nOx7+IbbbXzknLm9OGS6 LrXA== X-Forwarded-Encrypted: i=1; AHgh+RqvTuTg62H82l0tApS1K0n7N9ZAcrvF19718yyhHM/knqhMu56Y2jd+y/ipTZmbjJEcTzE8SrIcMa9/3F0=@vger.kernel.org X-Gm-Message-State: AOJu0YxmHNNP4gHAlIhyR5nYOsb2QcKg2Od8EmaKAPf1zfKtZH3q2yXa XzWPA+Rf5qE/hsQLk9PiVH6bYJ0CLFPMUpOqe7oFevKQ1GVW7ZevBcRkgK7WgliFZU+y6rEFaEb 06Z69rQ== X-Received: from pfcf1.prod.google.com ([2002:a05:6a00:2381:b0:845:4210:eae4]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:14c1:b0:842:3841:fdba with SMTP id d2e1a72fcca58-845b39b09a6mr4993851b3a.6.1782426984256; Thu, 25 Jun 2026 15:36:24 -0700 (PDT) Reply-To: Sean Christopherson Date: Thu, 25 Jun 2026 15:36:13 -0700 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Mailer: git-send-email 2.55.0.rc0.799.gd6f94ed593-goog Message-ID: <20260625223623.3376478-1-seanjc@google.com> Subject: [PATCH v3 00/10] KVM: x86/hyperv: Fix racy usage of vcpu->arch.hyperv From: Sean Christopherson To: Vitaly Kuznetsov , Sean Christopherson , Paolo Bonzini , David Woodhouse , Paul Durrant Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+5b32c49cd8f005e65654@syzkaller.appspotmail.com, syzbot+5d2b94b77112148d1744@syzkaller.appspotmail.com Content-Type: text/plain; charset="UTF-8" Fix a bug found by syzkaller (originally on a Google-internal kernel, but now on upstream as well) where KVM consumes a vCPU's HyperV structure before it's fully initialized, by concurrently triggering PV TLB flushes (queues flushes into a vCPU's FIFO without holding the vCPU's mutex) on a vCPU that is in the process of activating HyperV. Harden against similar bugs by asserting the vcpu->mutex is held when using the "normal" to_hv_vcpu(), same as we did for get_vmcs12() and get_shadow_vmcs12() (also in response to cross-task races). To avoid false positives when creating a vCPU, initialize vcpu_idx to -1, and treat the vCPU as unreachable (other than the caller, obviously) if its index is -1. v3: - Reset vcpu_idx back to -1 if adding the vCPU to the xarray fails. [syzbot] - Use the safe accessor in kvm_hv_has_stimer_pending(). [sashiko] - Explicitly initialize vcpu->arch.xen.vcpu_id to XEN_VCPU_ID_INVALID, and punt singleshot timer hypercalls to userspace if the vCPU ID hasn't been set. [sashiko, David] v2: - https://lore.kernel.org/all/20260612230622.687665-1-seanjc@google.com - Init vcpu->vcpu_idx to -1, use that as a canary to detect the vCPU is unreachable, and allow accessing Hyper-V state if the vCPU is otherwise unreachable. [syzbot] v1: https://lore.kernel.org/all/20260423140833.439512-1-seanjc@google.com Sean Christopherson (10): KVM: x86/hyperv: Get target FIFO in hv_tlb_flush_enqueue(), not caller KVM: x86/hyperv: Check for NULL vCPU Hyper-V object in kvm_hv_get_tlb_flush_fifo() KVM: x86/hyperv: Ensure vCPU's Hyper-V object is initialized on cross-vCPU accesses KVM: x86/xen: Punt singleshot timer hcalls to userspace if Xen vCPU ID isn't set KVM: x86/xen: Consolidate checks on Xen vCPU ID for singleshot timer hypercalls KVM: Initialize a vCPU's index to '-1' while it's being created KVM: Move nVMX's lockdep logic for vcpu->mutex to a common helper KVM: x86: Treat a vCPU as unreachable if its index is invalid KVM: x86/hyperv: Assert vCPU's mutex is held in to_hv_vcpu() KVM: x86/hyperv: Use {READ,WRITE}_ONCE for cross-task synic->active accesses arch/x86/kvm/hyperv.c | 64 +++++++++++++++++++++------------------ arch/x86/kvm/hyperv.h | 27 ++++++++++++++--- arch/x86/kvm/vmx/nested.h | 6 ++-- arch/x86/kvm/xen.c | 20 ++++++------ include/linux/kvm_host.h | 7 +++++ virt/kvm/kvm_main.c | 11 ++++++- 6 files changed, 86 insertions(+), 49 deletions(-) base-commit: a204badd8432f93b7e862e7dac6db0fe3d65f370 -- 2.55.0.rc0.799.gd6f94ed593-goog