mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] x86/apic/savic: Forward APIC_SPIV writes to the hypervisor
@ 2026-09-29  5:52 shrutiss
  0 siblings, 0 replies; only message in thread
From: shrutiss @ 2026-09-29  5:52 UTC (permalink / raw)
  To: Thomas Gleixner, Ingo Molnar, Borislav Petkov, Dave Hansen, x86,
	Neeraj Upadhyay
  Cc: H . Peter Anvin, Kishon Vijay Abraham I, Tianyu Lan,
	linux-kernel, linux-coco, kvm, stable, jxgao

From: Shruti <shrutiss@google.com>

For Secure AVIC (SAVIC) guests, the hypervisor (KVM) emulates the LAPIC
timer and LVT registers, while the guest's APIC backing page is kept in
encrypted guest-private memory that the hypervisor cannot read.

Currently, savic_write() updates APIC_SPIV (Spurious Interrupt Vector
Register) only in the guest's private APIC backing page without
notifying the hypervisor. Because the hypervisor never sees the guest
set the APIC Software Enable bit (APIC_SPIV_APIC_ENABLED) in APIC_SPIV,
it continues to treat the vCPU's Local APIC as software-disabled.

When the hypervisor sees a vCPU's APIC as software-disabled, it forcibly
masks all LVT writes (including APIC_LVTT for the local timer) and drops
timer and fixed interrupts for that vCPU. On SMP guests, where secondary
CPUs (APs) start with their emulated APIC reset to software-disabled,
this prevents APs from receiving local timer interrupts and leaves them
hung in idle (HLT) during boot.

Forward APIC_SPIV writes to the hypervisor via savic_ghcb_msr_write() in
addition to updating the guest's APIC backing page so the hypervisor's
APIC state stays in sync with the guest.

Fixes: c822f58a4fab ("x86/apic: Populate .read()/.write() callbacks of Secure AVIC driver")
Cc: stable@vger.kernel.org
Signed-off-by: Shruti <shrutiss@google.com>
---
 arch/x86/kernel/apic/x2apic_savic.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/arch/x86/kernel/apic/x2apic_savic.c b/arch/x86/kernel/apic/x2apic_savic.c
index dbc5678bc3b6..1ef4c5b6c494 100644
--- a/arch/x86/kernel/apic/x2apic_savic.c
+++ b/arch/x86/kernel/apic/x2apic_savic.c
@@ -214,7 +214,6 @@ static void savic_write(u32 reg, u32 data)
 		break;
 	case APIC_TASKPRI:
 	case APIC_EOI:
-	case APIC_SPIV:
 	case SAVIC_NMI_REQ:
 	case APIC_ESR:
 	case APIC_ECTRL:
@@ -223,6 +222,10 @@ static void savic_write(u32 reg, u32 data)
 	case APIC_EILVTn(0) ... APIC_EILVTn(3):
 		apic_set_reg(ap, reg, data);
 		break;
+	case APIC_SPIV:
+		savic_ghcb_msr_write(reg, data);
+		apic_set_reg(ap, reg, data);
+		break;
 	case APIC_ICR:
 		savic_icr_write(data, 0);
 		break;
-- 
2.55.0.1082.g2b9226bbc0-goog


^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-09-29  5:52 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29  5:52 [PATCH] x86/apic/savic: Forward APIC_SPIV writes to the hypervisor shrutiss

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®