From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f169.google.com (mail-pg1-f169.google.com [209.85.215.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EEDF0266581 for ; Fri, 14 Aug 2026 01:12:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786669968; cv=none; b=LMYlUdmVHnl17CebfsY/zMGIf1UEIfrOJnrgpyxhGfomOnrO8mOi+pO9dUfzSvx3cqHU3YawaZbdSWwBJlZt2GKMOJ3Z9j4sNyXHLEI5v3e6jSf9KYG5fVJoFwATXheuR1lFbIBKbKfQPMFGr9lTqEGxlQUCaposKySQsSfaYDM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786669968; c=relaxed/simple; bh=GlnDYwFGGLDYutOM6HPj1F35OIEL3ElIdqJQ6KJRVTc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=EepCcx6KJZTMObB2+lt1D74jAzGLaRPYjbZnvRJjsjgenMDZLFh3PGoauT53PHBOCShe7dq30rJ5ma/M2FaHSdF+hdReNjVCQrytLBiezAO2qcgqJMYhztOUnsVBZMFMCHLIKIIWfmhlg3dEyyCdmIt33uth9PQtFFRVlrP3V1o= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=U077U9Ga; arc=none smtp.client-ip=209.85.215.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="U077U9Ga" Received: by mail-pg1-f169.google.com with SMTP id 41be03b00d2f7-cbedd5aece4so1201304a12.0 for ; Thu, 13 Aug 2026 18:12:46 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1786669966; x=1787274766; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GlnDYwFGGLDYutOM6HPj1F35OIEL3ElIdqJQ6KJRVTc=; b=U077U9GaT1dCukOcEwadD8LjwuA4U1xeiKcnu0fixGTVD++EcqU09caXQTtHYy20GD LQgR06juufTVk0O1M9FEu0ompVoZz28jNuOgj4cKFEDokNXETZHKeNZtk9tTgwnZzKbW IE8RI9j837JUZhQXr41K68vHQBFLT2X07dPP3jOX0aFFhZwRUe4tSRE6vyoG2qDh3ew1 eF3QGq3gfTHp435B4fSJGxtwEEIgR3dY128qhQp+GBlOdDT8sv1xBYmW+2rJs9fEYKvm c2zY85RS2FpEvz2scBbc6fJhqOvFXYl5p4QggtdgYwLaGH3mNbMF0uALdf9K64pzfhCB ha+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786669966; x=1787274766; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=GlnDYwFGGLDYutOM6HPj1F35OIEL3ElIdqJQ6KJRVTc=; b=f3/X2XbVWtK6eenu7s7EqqIRDuZHQ6eyS1huCbj3CqV9E92CnphG2RadzjZOR4W/e5 lrjKmWJoL5FIoaehCcgFw//ZO65t16Wche5UeGBySmeVSiCUYCd7cOlWKMzkucMY7FJa VKO6iZW1wlGvBtYd/LeXDW28EWSbPFsh5zmLBnw1rZ04FTMU4JPSUv0I8VcAyiPtN06Y H+yBi3MJxYaCRqtjB0WqevEH/5K8gihXQ3eKR1cHbckBBtAJXNK9ybSrDxdiAA5v6ccR glhnRP2bnzAUdunwinTNl/Ol8STDKVjZwhfH4GbOh2g19hCZuqEvoKQ/NipQ2wil47cn NQaw== X-Forwarded-Encrypted: i=1; AHgh+Rq9SnTZbCb+Ndr7JC6LwpuMyNmilyFSTCu4rZWceXkgv4cILRx8g6/GjbxFd7qQPSXLayF09H1ZjytFHfw=@vger.kernel.org X-Gm-Message-State: AOJu0YwWJYTVgtdQtRJwS5kk4DzrWFIyRD/a6b56HRA6fL0OdFHO4on4 EnPR17U66J1KG+0BE/g6jYlpgxMHlD89Mmo1OCFotWHgp2/PeLXGszmCpEMHTpAoz2g= X-Gm-Gg: AR+sD11ynjCqQV+G/9ttH9FJBtRZFsCuHKUDIEbZp+oFtePvI6RKfIV2jT8ZhDYBmMm iKzVPungIjbyfHu9MtNNFbable9AtB4quyJzfTE4lsktCmfGPvBEzHZG+l3ZcXLbUaOTgEqyFWG 50aCFGrMsW3Zx7p5VRC7L8R/njjNnuazH8fiCJ6ghOKUsGz8fKLd6VoiO8goaYGiajt+Zj01KtT KE0k29nRb+9z8Ekh6g3xwcTKuRTVgtEYbrUI5+75eHuRg3Ae9+0qD2JV2bfxNBirJxKN0jGvokk xjpU0mUQ7MkpxQ5PfMRXqLRGO6FcQye/XPlexcnBvcW26ah0CJkVDS/a7c2B+TEljQcTTINMrBP O0TK4rKTFz3x85+USKWR9c1eYR191T78l4tVn/f/O0lXuMBTDozaUfs5PqLAjuZSv0E2H+7kMI2 SM3XqEipJ64XdmJud/MYSN23zeRONrYblivdIvV91YuvkQuhH/x+G01gnH1J9ceP2fqk4rpoUVY uhGxbhC8ZFrhV/1Q5efLSGfHhBFumOjXKxmhVJcFuPgDgkY3FPEHQCfiiAuVg== X-Received: by 2002:a17:90b:264c:b0:369:7491:7b24 with SMTP id 98e67ed59e1d1-3931f47d73bmr6214537a91.6.1786669966275; Thu, 13 Aug 2026 18:12:46 -0700 (PDT) Received: from localhost.localdomain ([2603:8001:5f01:8bab:591a:2e75:81f3:25ff]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31f15063cd8sm9015120eec.9.2026.08.13.18.12.45 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Thu, 13 Aug 2026 18:12:45 -0700 (PDT) From: Artem Dinaburg To: Sean Christopherson Cc: Artem Dinaburg , Jinu Kim , Paolo Bonzini , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, x86@kernel.org Subject: Re: [PATCH v2] KVM: x86/mmu: Write-protect tracked GFNs in all address spaces Date: Thu, 13 Aug 2026 21:12:27 -0400 Message-ID: <20260814011229.72845-1-artem@trailofbits.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: <20260804105755.276646-1-kimjw04271234@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On Wed, Aug 05, 2026 at 12:14:04PM -0700, Sean Christopherson wrote: > Actually, irrespective of what we do with SMM, we should harden KVM to > skip marking upper-level SPs as unsync, because while corrupting guest > memory is bad, corrupting guest memory *and* crashing/compromising the > host is worse. This is correct. There is a working guest-to-host escape via an upper-level unsync shadow page. It works on Debian oldstable and likely other shipping distributions. I'd like to see that patch applied even if the SMM question stays open. > it wasn't clear to me how marking an upper-level SP as unsync leads to a > corrupted rmap, and I hadn't thought too hard about it. There is a bug, unrelated to rmap and still unfixed in the longterm trees, that turns an unsync upper-level shadow page into a writable mapping the guest shouldn't have. It can be readily found via AI assistance. Either of the two suggested fixes would be fine, but the unsync behavior is dangerous and should be prevented.