From: Sean Christopherson <seanjc@google.com>
To: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Yosry Ahmed <yosry@kernel.org>,
Shivansh Dhiman <shivansh.dhiman@amd.com>,
Nikunj A Dadhania <nikunj@amd.com>,
Ravi Bangoria <ravi.bangoria@amd.com>,
Tom Lendacky <thomas.lendacky@amd.com>
Subject: [PATCH v5 01/12] KVM: x86: Preserve DR6.BLD (Bus Lock Detect) when delivering #DB payload
Date: Tue, 29 Sep 2026 18:13:02 -0700 [thread overview]
Message-ID: <20260930011313.3197688-2-seanjc@google.com> (raw)
In-Reply-To: <20260930011313.3197688-1-seanjc@google.com>
Preserve Bus Lock Detect if it isn't present in the payload. Unlike RTM,
which is explicitly modified on every #DB, DR6.BLD is modified if and only
if the #DB is due to a (coincident) Bus Lock Detect.
Per Intel's SDM:
Other debug exceptions do not modify this bit.
And AMD's APM
All other #DB exceptions leave DR6[BLD] unmodified,
Restore the explicit RTM handling that was clobbered by commit
9a3ecd5e2aa1 ("KVM: X86: Rename DR6_INIT to DR6_ACTIVE_LOW"), as the
semantics of any given bit are feature specific, i.e. are obviously not
consistent for active-high versus active-low. In other words, while the
bug was technically introduced when support for Bus Lock Detect was added,
it's really that attempt to genericize handling of active-low bits that set
KVM up to fail.
Fixes: e8ea85fb280e ("KVM: X86: Add support for the emulation of DR6_BUS_LOCK bit")
Cc: stable@vger.kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
---
arch/x86/kvm/x86.c | 52 ++++++++++++++++++++++++++--------------------
1 file changed, 30 insertions(+), 22 deletions(-)
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index cf3fcdfd8ad2..ea1406c3b260 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -401,30 +401,37 @@ void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
switch (ex->vector) {
case DB_VECTOR:
/*
- * "Certain debug exceptions may clear bit 0-3. The
- * remaining contents of the DR6 register are never
- * cleared by the processor".
+ * DR6 is a mess. Reserved/unused bits are fixed-to-1, and so
+ * to maintain backwards compatibility with existing software,
+ * features that use previously-reserved bits have active-low
+ * semantics, i.e. clear the bit when the feature is present in
+ * the payload.
+ *
+ * Further complicating matters, some DR6 bits are preserved by
+ * hardware, while others are explicitly modified on every #DB.
+ * The trap bits are always set based on the payload, as is the
+ * RTM flag (but it's active low). All other bits are modified
+ * if and only if a relevant debug exception occurs, e.g. BD,
+ * BS, and BT are never cleared by hardware, and BLD is never
+ * set by hardware (when supported, excepting RESET).
+ *
+ * Lastly, the payload does NOT have active-low semantics, e.g.
+ * so that it's compatible VMX's pending debug exceptions and
+ * qualification fields, and to avoid bleeding the DR6 madness
+ * into other KVM code.
+ *
+ * To compute DR6:
+ *
+ * 1. "Reset" the bits that are modified on all #DBs
+ * 2. Clear active-low bits that are present in the payload.
+ * 3. Set active-high bits that are present in the payload.
+ * 4. Clear fixed-0 bits.
+ * 5. Set fixed-1 bits.
*/
vcpu->arch.dr6 &= ~DR_TRAP_BITS;
- /*
- * In order to reflect the #DB exception payload in guest
- * dr6, three components need to be considered: active low
- * bit, FIXED_1 bits and active high bits (e.g. DR6_BD,
- * DR6_BS and DR6_BT)
- * DR6_ACTIVE_LOW contains the FIXED_1 and active low bits.
- * In the target guest dr6:
- * FIXED_1 bits should always be set.
- * Active low bits should be cleared if 1-setting in payload.
- * Active high bits should be set if 1-setting in payload.
- *
- * Note, the payload is compatible with the pending debug
- * exceptions/exit qualification under VMX, that active_low bits
- * are active high in payload.
- * So they need to be flipped for DR6.
- */
- vcpu->arch.dr6 |= DR6_ACTIVE_LOW;
- vcpu->arch.dr6 |= ex->payload;
- vcpu->arch.dr6 ^= ex->payload & DR6_ACTIVE_LOW;
+ vcpu->arch.dr6 |= DR6_RTM;
+ vcpu->arch.dr6 &= ~(ex->payload & DR6_ACTIVE_LOW);
+ vcpu->arch.dr6 |= (ex->payload & ~DR6_ACTIVE_LOW);
/*
* The #DB payload is defined as compatible with the 'pending
@@ -433,6 +440,7 @@ void kvm_deliver_exception_payload(struct kvm_vcpu *vcpu,
* breakpoint), it is reserved and must be zero in DR6.
*/
vcpu->arch.dr6 &= ~BIT(12);
+ vcpu->arch.dr6 |= DR6_FIXED_1;
break;
case PF_VECTOR:
vcpu->arch.cr2 = ex->payload;
--
2.56.0.rc1.315.gc6ed9934b7-goog
next prev parent reply other threads:[~2026-09-30 1:13 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 1:13 [PATCH v5 00/12] KVM: x86: Bus Lock Detect fixes and SVM support Sean Christopherson
2026-09-30 1:13 ` Sean Christopherson [this message]
2026-09-30 1:13 ` [PATCH v5 02/12] KVM: x86: Rename kvm_dr6_fixed() => kvm_get_dr6_fixed_1() Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 03/12] KVM: Return an "unsigned long", not "u64" for the fixed-1 DR6 bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 04/12] KVM: x86: Force fixed-1 bits in DR6 after synchronizing with hardware Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 05/12] KVM: x86: WARN if fixed-1 DR6 bits aren't already set when delivering payload Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 06/12] KVM: x86: Kill off DR6_FIXED_1 to prevent future misuse Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 07/12] KVM: SVM: Add helper to query if LBR virtualization needs to be enabled Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 08/12] KVM: nSVM: Disable LBRV in nested control cache when unsupported Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 09/12] KVM: nSVM: Open code check on LBR virtualization being enabled in vmcb12 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 10/12] KVM: nSVM: Don't assume all active-low bits DR6 are fixed-1 Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 11/12] KVM: SVM: Add a vCPU-aware helper to get supported DEBUGCTL bits Sean Christopherson
2026-09-30 1:13 ` [PATCH v5 12/12] KVM: SVM: Add support for virtualizating Bus Lock Detect Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930011313.3197688-2-seanjc@google.com \
--to=seanjc@google.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=nikunj@amd.com \
--cc=pbonzini@redhat.com \
--cc=ravi.bangoria@amd.com \
--cc=shivansh.dhiman@amd.com \
--cc=thomas.lendacky@amd.com \
--cc=yosry@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®