mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode
@ 2026-09-28  7:05 Qiliang Yuan
  2026-09-28  7:25 ` Qiliang Yuan
  0 siblings, 1 reply; 4+ messages in thread
From: Qiliang Yuan @ 2026-09-28  7:05 UTC (permalink / raw)
  To: Sean Christopherson, Paolo Bonzini, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, Dave Hansen, x86, H. Peter Anvin
  Cc: kvm, linux-kernel, Qiliang Yuan

enter_smm() clears CR0.PG and EFER.LMA/LME but leaves CR3 as-is, so a
64-bit guest whose page tables live above 4GiB enters SMM with
CR3[63:32] != 0 while outside of long mode.  Bare-metal SVM accepts that
state, but Hyper-V's emulation of VMRUN for a nested hypervisor rejects
it as an invalid VMCB, and the vCPU dies on the very first instruction
of the SMI handler:

  KVM: entry failed, hardware error 0xffffffff
  EIP=00008000 EFL=00000002 [-------] CPL=0 II=0 A20=1 SMM=1 HLT=0
  CS =f900 7bff9000 ffffffff 00809300
  CR0=00050032 CR2=2a91044a CR3=77681000 CR4=00000000
  EFER=0000000000000000

QEMU prints only CR3[31:0] here; the CR3 saved in SMRAM for this vCPU
was 0x277681000.  All vCPUs that failed had a CR3 above 4GiB, while the
one vCPU whose CR3 was below 4GiB entered SMM without issue.

This reproduces reliably when booting a Windows 11 guest (8GiB of RAM)
with Secure Boot OVMF, i.e. with SMM enabled, in KVM on WSL2 on an AMD
host.

With paging disabled outside of long mode, only CR3[31:0] is
reachable: a MOV to CR3 can only write 32 bits, and the SMI handler
must load its own CR3 before enabling paging.  RSM restores the full
CR3 from the SMRAM state-save area, which was written before this point.
Clear the upper 32 bits so that the resulting SMM entry state passes
Hyper-V's VMRUN consistency checks.

Signed-off-by: Qiliang Yuan <odys.yuan@gmail.com>
---
 arch/x86/kvm/smm.c | 11 +++++++++++
 1 file changed, 11 insertions(+)

diff --git a/arch/x86/kvm/smm.c b/arch/x86/kvm/smm.c
index f623c5986119..3955fa4e9ad9 100644
--- a/arch/x86/kvm/smm.c
+++ b/arch/x86/kvm/smm.c
@@ -361,6 +361,17 @@ void enter_smm(struct kvm_vcpu *vcpu)
 	if (guest_cpu_cap_has(vcpu, X86_FEATURE_LM))
 		if (kvm_x86_call(set_efer)(vcpu, 0))
 			goto error;
+
+	/*
+	 * CR3 is unmodified on SMM entry, but with paging disabled and outside
+	 * of long mode, bits 63:32 are unreachable and RSM restores the full
+	 * value from SMRAM.  Clear them, as a CR3 above 4GiB with EFER.LMA=0
+	 * fails VMRUN consistency checks when KVM runs nested under Hyper-V.
+	 */
+	if (kvm_read_cr3(vcpu) >> 32) {
+		vcpu->arch.cr3 = (u32)vcpu->arch.cr3;
+		kvm_register_mark_dirty(vcpu, VCPU_EXREG_CR3);
+	}
 #endif
 
 	vcpu->arch.cpuid_dynamic_bits_dirty = true;

---
base-commit: eb3f4b7426cfd2b79d65b7d37155480b32259a11
change-id: 20260928-kvm-smm-cr3-upper-bits-9819a1a2f337

Best regards,
-- 
Qiliang Yuan <odys.yuan@gmail.com>


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode
  2026-09-28  7:05 [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode Qiliang Yuan
@ 2026-09-28  7:25 ` Qiliang Yuan
  2026-09-28 17:42   ` Wei Liu
  0 siblings, 1 reply; 4+ messages in thread
From: Qiliang Yuan @ 2026-09-28  7:25 UTC (permalink / raw)
  To: Sean Christopherson, Paolo Bonzini
  Cc: Qiliang Yuan, Thomas Gleixner, Ingo Molnar, Borislav Petkov,
	Dave Hansen, x86, H. Peter Anvin, kvm, linux-kernel,
	Vitaly Kuznetsov, K. Y. Srinivasan, Haiyang Zhang, Wei Liu,
	Dexuan Cui, Long Li, linux-hyperv

+Cc Hyper-V folks and linux-hyperv, since the failure is triggered by
Hyper-V's handling of VMRUN for a nested (L1) hypervisor, i.e. KVM
running on WSL2.

For the Hyper-V side: the VMRUN is rejected when the guest state has
CR0.PG=0, EFER.LMA=0 and CR3[63:32] != 0, a combination that bare-metal
SVM does not reject.  Is that check intentional?  If it is not, a
Hyper-V fix would help older KVM versions as well; either way the patch
avoids creating that state in the first place.

The full patch is here:
https://lore.kernel.org/r/20260928-kvm-smm-cr3-upper-bits-v1-1-138f52dd531e@gmail.com

Thanks,
Qiliang

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode
  2026-09-28  7:25 ` Qiliang Yuan
@ 2026-09-28 17:42   ` Wei Liu
  2026-09-28 18:19     ` Sean Christopherson
  0 siblings, 1 reply; 4+ messages in thread
From: Wei Liu @ 2026-09-28 17:42 UTC (permalink / raw)
  To: Qiliang Yuan
  Cc: Sean Christopherson, Paolo Bonzini, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, kvm,
	linux-kernel, Vitaly Kuznetsov, K. Y. Srinivasan, Haiyang Zhang,
	Wei Liu, Dexuan Cui, Long Li, linux-hyperv

Hi Qiliang

On Mon, Sep 28, 2026 at 03:25:34PM +0800, Qiliang Yuan wrote:
> +Cc Hyper-V folks and linux-hyperv, since the failure is triggered by
> Hyper-V's handling of VMRUN for a nested (L1) hypervisor, i.e. KVM
> running on WSL2.
> 
> For the Hyper-V side: the VMRUN is rejected when the guest state has
> CR0.PG=0, EFER.LMA=0 and CR3[63:32] != 0, a combination that bare-metal
> SVM does not reject.  Is that check intentional?  If it is not, a
> Hyper-V fix would help older KVM versions as well; either way the patch
> avoids creating that state in the first place.
> 
> The full patch is here:
> https://lore.kernel.org/r/20260928-kvm-smm-cr3-upper-bits-v1-1-138f52dd531e@gmail.com

Please share the Windows version from `winver`.

My colleague said that it had been fixed. Maybe the change needs to be ported.

Thanks,
Wei

> 
> Thanks,
> Qiliang

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode
  2026-09-28 17:42   ` Wei Liu
@ 2026-09-28 18:19     ` Sean Christopherson
  0 siblings, 0 replies; 4+ messages in thread
From: Sean Christopherson @ 2026-09-28 18:19 UTC (permalink / raw)
  To: Wei Liu
  Cc: Qiliang Yuan, Paolo Bonzini, Thomas Gleixner, Ingo Molnar,
	Borislav Petkov, Dave Hansen, x86, H. Peter Anvin, kvm,
	linux-kernel, Vitaly Kuznetsov, K. Y. Srinivasan, Haiyang Zhang,
	Dexuan Cui, Long Li, linux-hyperv

On Mon, Sep 28, 2026, Wei Liu wrote:
> Hi Qiliang
> 
> On Mon, Sep 28, 2026 at 03:25:34PM +0800, Qiliang Yuan wrote:
> > +Cc Hyper-V folks and linux-hyperv, since the failure is triggered by
> > Hyper-V's handling of VMRUN for a nested (L1) hypervisor, i.e. KVM
> > running on WSL2.
> > 
> > For the Hyper-V side: the VMRUN is rejected when the guest state has
> > CR0.PG=0, EFER.LMA=0 and CR3[63:32] != 0, a combination that bare-metal
> > SVM does not reject.  Is that check intentional?  If it is not, a
> > Hyper-V fix would help older KVM versions as well; either way the patch
> > avoids creating that state in the first place.
> > 
> > The full patch is here:
> > https://lore.kernel.org/r/20260928-kvm-smm-cr3-upper-bits-v1-1-138f52dd531e@gmail.com
> 
> Please share the Windows version from `winver`.
> 
> My colleague said that it had been fixed. Maybe the change needs to be ported.

Ya, I'd much prefer to get this fixed in Hyper-V.  If we need to carry a KVM hack,
then at the very least it should be limited to when KVM detects that it's running
on Hyper-V. 

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-28 18:19 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28  7:05 [PATCH] KVM: x86: Clear CR3[63:32] on SMM entry from long mode Qiliang Yuan
2026-09-28  7:25 ` Qiliang Yuan
2026-09-28 17:42   ` Wei Liu
2026-09-28 18:19     ` Sean Christopherson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®