From: mlevitsk@redhat.com
To: Paolo Bonzini <pbonzini@redhat.com>,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org
Cc: d.riley@proxmox.com, jon@nutanix.com
Subject: Re: [PATCH 17/28] KVM: nVMX: pass PFERR_USER_MASK to MMU on EPT violations
Date: Tue, 02 Jun 2026 10:27:27 -0400 [thread overview]
Message-ID: <6cdfabf53b2faeb1a22b802feb66a0e3b882ebfc.camel@redhat.com> (raw)
In-Reply-To: <20260505195226.563317-18-pbonzini@redhat.com>
On Tue, 2026-05-05 at 21:52 +0200, Paolo Bonzini wrote:
> For EPT, PFERR_USER_MASK refers not to the CPL of the guest,
> but to the AND of the U bits encountered while walking guest
> page tables; this is consistent with how MBEC differentiates
> between XS and XU. This is available through the
> "advanced vmexit information for EPT violations" feature.
>
> Tested-by: David Riley <d.riley@proxmox.com>
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
> ---
> arch/x86/kvm/vmx/common.h | 12 +++++++++---
> arch/x86/kvm/vmx/vmx.c | 10 ++++++++++
> 2 files changed, 19 insertions(+), 3 deletions(-)
>
> diff --git a/arch/x86/kvm/vmx/common.h b/arch/x86/kvm/vmx/common.h
> index 40fa72f31fc7..08005676702c 100644
> --- a/arch/x86/kvm/vmx/common.h
> +++ b/arch/x86/kvm/vmx/common.h
> @@ -100,9 +100,15 @@ static inline int __vmx_handle_ept_violation(struct kvm_vcpu *vcpu, gpa_t gpa,
> error_code |= (exit_qualification & EPT_VIOLATION_PROT_USER_EXEC)
> ? PFERR_PRESENT_MASK : 0;
>
> - if (exit_qualification & EPT_VIOLATION_GVA_IS_VALID)
> - error_code |= (exit_qualification & EPT_VIOLATION_GVA_TRANSLATED) ?
> - PFERR_GUEST_FINAL_MASK : PFERR_GUEST_PAGE_MASK;
> + if (exit_qualification & EPT_VIOLATION_GVA_IS_VALID) {
> + if (exit_qualification & EPT_VIOLATION_GVA_TRANSLATED) {
> + error_code |= PFERR_GUEST_FINAL_MASK;
> + if (exit_qualification & EPT_VIOLATION_GVA_USER)
> + error_code |= PFERR_USER_MASK;
> + } else {
> + error_code |= PFERR_GUEST_PAGE_MASK;
> + }
> + }
Minor nitpick:
Technically this code should check for VMX_EPT_ADVANCED_VMEXIT_INFO_BIT.
Otherwise we might pass (in theory) the PFERR_USER_MASK when it's not there.
Yes, in practice, undefined bits are zero, and on top of that, as long as MBEC is not supported, MMU core
should just ignore the PFERR_USER_MASK, but still even if this is for documentation purposes,
it might be worth it to check it here.
What do you think?
>
> if (vt_is_tdx_private_gpa(vcpu->kvm, gpa))
> error_code |= PFERR_PRIVATE_ACCESS;
> diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
> index f1d616f928a1..9d5cd358ccc5 100644
> --- a/arch/x86/kvm/vmx/vmx.c
> +++ b/arch/x86/kvm/vmx/vmx.c
> @@ -2790,6 +2790,16 @@ static int setup_vmcs_config(struct vmcs_config *vmcs_conf,
> vmx_cap->vpid = 0;
> }
>
> + /*
> + * Virtualizing MBEC requires advanced vmexit information in order to
> + * distinguish supervisor and user accesses. For simplicity and clarity
> + * disable MBEC entirely if advanced vmexit information is not available,
This makes sense, however it feels to me a bit out of place in this patch,
it seems better to belong to one of the former patches.
When thinking about this, and last two patches, I started to think that maybe
it is worth merging:
'KVM: VMX: enable use of MBEC',
'KVM: nVMX: pass advanced EPT violation vmexit info to guest'
'KVM: nVMX: pass PFERR_USER_MASK to MMU on EPT violations'
into one patch 'KVM: VMX: enable use of MBEC', except the code that passes advanced
EPT violation to the nested guest (the 4nd hunk of the second patch).
And then turn this hunk to a separate patch which can still be named
as the second patch.
This way it will be IMHO clearer when we honour the 'enable_mbec', and in theory
there will not be a two patch window in which mbec could be enabled with unsupported
configuration.
Finally (assuming that what I am thinking is correct, I haven't verified it),
assuming that 'EPT advanced qualification' was specially added for MBEC,
we can add a comment stating that it is unlikely that there are CPUs
(outside of some weird nested configurations), which support either but not both features.
> + * this way mbec=1 in the kvm_intel module parameters implies availability
> + * to nested guests as well.
Best regards,
Maxim Levitsky
> + */
> + if (!(vmx_cap->ept & VMX_EPT_ADVANCED_VMEXIT_INFO_BIT))
> + _cpu_based_2nd_exec_control &= ~SECONDARY_EXEC_MODE_BASED_EPT_EXEC;
> +
> if (!cpu_has_sgx())
> _cpu_based_2nd_exec_control &= ~SECONDARY_EXEC_ENCLS_EXITING;
>
next prev parent reply other threads:[~2026-06-02 14:27 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-05 19:51 [PATCH v6 00/28] KVM: combined patchset for MBEC/GMET support Paolo Bonzini
2026-05-05 19:51 ` [PATCH 01/28] KVM: TDX/VMX: rework EPT_VIOLATION_EXEC_FOR_RING3_LIN into PROT_MASK Paolo Bonzini
2026-06-02 14:19 ` mlevitsk
2026-05-05 19:52 ` [PATCH 02/28] KVM: x86/mmu: remove SPTE_PERM_MASK Paolo Bonzini
2026-06-02 14:20 ` mlevitsk
2026-05-05 19:52 ` [PATCH 03/28] KVM: x86/mmu: free up bit 10 of PTEs in preparation for MBEC Paolo Bonzini
2026-06-02 14:20 ` mlevitsk
2026-05-05 19:52 ` [PATCH 04/28] KVM: x86/mmu: shuffle high bits of SPTEs " Paolo Bonzini
2026-06-02 14:20 ` mlevitsk
2026-05-05 19:52 ` [PATCH 05/28] KVM: x86/mmu: remove SPTE_EPT_* Paolo Bonzini
2026-06-02 14:21 ` mlevitsk
2026-05-05 19:52 ` [PATCH 06/28] KVM: x86/mmu: merge make_spte_{non,}executable Paolo Bonzini
2026-06-02 14:22 ` mlevitsk
2026-05-05 19:52 ` [PATCH 07/28] KVM: x86/mmu: rename and clarify BYTE_MASK Paolo Bonzini
2026-06-02 14:22 ` mlevitsk
2026-05-05 19:52 ` [PATCH 08/28] KVM: x86/mmu: separate more EPT/non-EPT permission_fault() Paolo Bonzini
2026-05-07 14:35 ` Sean Christopherson
2026-06-02 14:22 ` mlevitsk
2026-05-05 19:52 ` [PATCH 09/28] KVM: x86/mmu: introduce ACC_READ_MASK Paolo Bonzini
2026-06-02 14:23 ` mlevitsk
2026-05-05 19:52 ` [PATCH 10/28] KVM: x86/mmu: pass PFERR_GUEST_PAGE/FINAL_MASK to kvm_translate_gpa Paolo Bonzini
2026-06-02 14:23 ` mlevitsk
2026-05-05 19:52 ` [PATCH 11/28] KVM: x86/mmu: pass pte_access for final nGPA->GPA walk Paolo Bonzini
2026-06-02 14:24 ` mlevitsk
2026-05-05 19:52 ` [PATCH 12/28] KVM: x86: make translate_nested_gpa vendor-specific Paolo Bonzini
2026-06-02 14:24 ` mlevitsk
2026-05-05 19:52 ` [PATCH 13/28] KVM: x86/mmu: split XS/XU bits for EPT Paolo Bonzini
2026-06-02 14:24 ` mlevitsk
2026-05-05 19:52 ` [PATCH 14/28] KVM: x86/mmu: move cr4_smep to base role Paolo Bonzini
2026-06-02 14:25 ` mlevitsk
2026-05-05 19:52 ` [PATCH 15/28] KVM: VMX: enable use of MBEC Paolo Bonzini
2026-05-07 14:40 ` Sean Christopherson
2026-06-02 14:26 ` mlevitsk
2026-05-05 19:52 ` [PATCH 16/28] KVM: nVMX: pass advanced EPT violation vmexit info to guest Paolo Bonzini
2026-06-02 14:26 ` mlevitsk
2026-05-05 19:52 ` [PATCH 17/28] KVM: nVMX: pass PFERR_USER_MASK to MMU on EPT violations Paolo Bonzini
2026-06-02 14:27 ` mlevitsk [this message]
2026-05-05 19:52 ` [PATCH 18/28] KVM: x86/mmu: add support for MBEC to EPT page table walks Paolo Bonzini
2026-06-02 14:28 ` mlevitsk
2026-05-05 19:52 ` [PATCH 19/28] KVM: nVMX: advertise MBEC to nested guests Paolo Bonzini
2026-06-02 14:28 ` mlevitsk
2026-05-05 19:52 ` [PATCH 20/28] KVM: nVMX: allow MBEC with EVMCS Paolo Bonzini
2026-06-02 14:28 ` mlevitsk
2026-06-02 15:29 ` Vitaly Kuznetsov
2026-05-05 19:52 ` [PATCH 21/28] KVM: x86/mmu: propagate access mask from root pages down Paolo Bonzini
2026-06-02 14:29 ` mlevitsk
2026-05-05 19:52 ` [PATCH 22/28] KVM: x86/mmu: introduce cpu_role bit for availability of PFEC.I/D Paolo Bonzini
2026-06-02 14:29 ` mlevitsk
2026-05-05 19:52 ` [PATCH 23/28] KVM: SVM: add GMET bit definitions Paolo Bonzini
2026-06-02 14:30 ` mlevitsk
2026-05-05 19:52 ` [PATCH 24/28] KVM: x86/mmu: hard code more bits in kvm_init_shadow_npt_mmu Paolo Bonzini
2026-06-02 14:30 ` mlevitsk
2026-05-05 19:52 ` [PATCH 25/28] KVM: x86/mmu: add support for GMET to NPT page table walks Paolo Bonzini
2026-06-02 14:31 ` mlevitsk
2026-05-05 19:52 ` [PATCH 26/28] KVM: SVM: enable GMET and set it in MMU role Paolo Bonzini
2026-06-02 14:31 ` mlevitsk
2026-05-05 19:52 ` [PATCH 27/28] KVM: SVM: work around errata 1218 Paolo Bonzini
2026-06-02 14:31 ` mlevitsk
2026-05-05 19:52 ` [PATCH 28/28] KVM: nSVM: enable GMET for guests Paolo Bonzini
2026-06-02 14:32 ` mlevitsk
2026-05-07 14:44 ` [PATCH v6 00/28] KVM: combined patchset for MBEC/GMET support Sean Christopherson
2026-05-07 17:49 ` Paolo Bonzini
2026-05-11 10:53 ` David Riley
2026-05-11 10:55 ` Paolo Bonzini
2026-05-11 11:07 ` David Riley
2026-05-14 2:11 ` Chao Gao
2026-05-14 19:13 ` Sean Christopherson
2026-05-12 14:32 ` Paolo Bonzini
2026-05-12 16:34 ` Paolo Bonzini
2026-05-15 14:53 ` David Riley
2026-05-15 18:31 ` Sean Christopherson
2026-05-19 8:02 ` David Riley
-- strict thread matches above, loose matches on Subject: below --
2026-04-30 15:07 [PATCH v5 " Paolo Bonzini
2026-04-30 15:07 ` [PATCH 17/28] KVM: nVMX: pass PFERR_USER_MASK to MMU on EPT violations Paolo Bonzini
2026-04-30 19:03 ` Sean Christopherson
2026-04-28 11:09 [PATCH v4 00/28] KVM: combined patchset for MBEC/GMET support Paolo Bonzini
2026-04-28 11:09 ` [PATCH 17/28] KVM: nVMX: pass PFERR_USER_MASK to MMU on EPT violations Paolo Bonzini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6cdfabf53b2faeb1a22b802feb66a0e3b882ebfc.camel@redhat.com \
--to=mlevitsk@redhat.com \
--cc=d.riley@proxmox.com \
--cc=jon@nutanix.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome