mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: shrutiss@google.com
To: Thomas Gleixner <tglx@linutronix.de>,
	Ingo Molnar <mingo@redhat.com>, Borislav Petkov <bp@alien8.de>,
	 Dave Hansen <dave.hansen@linux.intel.com>,
	x86@kernel.org,  Neeraj Upadhyay <Neeraj.Upadhyay@amd.com>
Cc: "H . Peter Anvin" <hpa@zytor.com>,
	Kishon Vijay Abraham I <kvijayab@amd.com>,
	Tianyu Lan <tiala@microsoft.com>,
	 linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
	kvm@vger.kernel.org,  stable@vger.kernel.org, jxgao@google.com
Subject: [PATCH] x86/apic/savic: Forward APIC_SPIV writes to the hypervisor
Date: Tue, 29 Sep 2026 05:52:55 +0000	[thread overview]
Message-ID: <20260929055255.1380202-1-shrutiss@google.com> (raw)

From: Shruti <shrutiss@google.com>

For Secure AVIC (SAVIC) guests, the hypervisor (KVM) emulates the LAPIC
timer and LVT registers, while the guest's APIC backing page is kept in
encrypted guest-private memory that the hypervisor cannot read.

Currently, savic_write() updates APIC_SPIV (Spurious Interrupt Vector
Register) only in the guest's private APIC backing page without
notifying the hypervisor. Because the hypervisor never sees the guest
set the APIC Software Enable bit (APIC_SPIV_APIC_ENABLED) in APIC_SPIV,
it continues to treat the vCPU's Local APIC as software-disabled.

When the hypervisor sees a vCPU's APIC as software-disabled, it forcibly
masks all LVT writes (including APIC_LVTT for the local timer) and drops
timer and fixed interrupts for that vCPU. On SMP guests, where secondary
CPUs (APs) start with their emulated APIC reset to software-disabled,
this prevents APs from receiving local timer interrupts and leaves them
hung in idle (HLT) during boot.

Forward APIC_SPIV writes to the hypervisor via savic_ghcb_msr_write() in
addition to updating the guest's APIC backing page so the hypervisor's
APIC state stays in sync with the guest.

Fixes: c822f58a4fab ("x86/apic: Populate .read()/.write() callbacks of Secure AVIC driver")
Cc: stable@vger.kernel.org
Signed-off-by: Shruti <shrutiss@google.com>
---
 arch/x86/kernel/apic/x2apic_savic.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kernel/apic/x2apic_savic.c b/arch/x86/kernel/apic/x2apic_savic.c
index dbc5678bc3b6..1ef4c5b6c494 100644
--- a/arch/x86/kernel/apic/x2apic_savic.c
+++ b/arch/x86/kernel/apic/x2apic_savic.c
@@ -214,7 +214,6 @@ static void savic_write(u32 reg, u32 data)
 		break;
 	case APIC_TASKPRI:
 	case APIC_EOI:
-	case APIC_SPIV:
 	case SAVIC_NMI_REQ:
 	case APIC_ESR:
 	case APIC_ECTRL:
@@ -223,6 +222,10 @@ static void savic_write(u32 reg, u32 data)
 	case APIC_EILVTn(0) ... APIC_EILVTn(3):
 		apic_set_reg(ap, reg, data);
 		break;
+	case APIC_SPIV:
+		savic_ghcb_msr_write(reg, data);
+		apic_set_reg(ap, reg, data);
+		break;
 	case APIC_ICR:
 		savic_icr_write(data, 0);
 		break;
-- 
2.55.0.1082.g2b9226bbc0-goog


                 reply	other threads:[~2026-09-29  5:52 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929055255.1380202-1-shrutiss@google.com \
    --to=shrutiss@google.com \
    --cc=Neeraj.Upadhyay@amd.com \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=hpa@zytor.com \
    --cc=jxgao@google.com \
    --cc=kvijayab@amd.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mingo@redhat.com \
    --cc=stable@vger.kernel.org \
    --cc=tglx@linutronix.de \
    --cc=tiala@microsoft.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®