From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9FB2B3D4132 for ; Wed, 5 Aug 2026 18:52:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785955923; cv=none; b=Ti2a1NY8vxNeo/rLAiOy0+yR1S8oIdycQExT1ql/cow1w6GLPtE6ceKePpAdj29gny5GN81Y0/WVPXO+jb184b3WGaqyVocoC+E572YCddMZHhrEhoLw9p3KIQDZrPiHn3VKwakNqgHOYU1Eq1SLyo+j7mLKhys/k+iMy/VOn44= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785955923; c=relaxed/simple; bh=AJISq/mX2kSr5kvSQbLRpVzSC8SDiz9SMVxObBq6r4A=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=LyEBSQDdmoLb9nY03rtkldzHYctzOrjnALoxpJU9rR2IOiNkV/Xo3BRCHBPCEroHEmsLs1RPfEcx7b+aI8j/lCfahLgHvgLSOVYY4DrCgMHao1ajerSxpq8F/jtMg0+qfUgyIOHZQiFEdGW/+fuJxUkbSHlJIT1JDqM/Mzv5MXY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Ye+q1YYN; arc=none smtp.client-ip=209.85.210.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Ye+q1YYN" Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-84e375d9736so1739433b3a.2 for ; Wed, 05 Aug 2026 11:52:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1785955922; x=1786560722; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=4ToGqmYCLIsCza1nv6x574MwhjIbpl6LQnMNJCZ7DMg=; b=Ye+q1YYNwI/hIRllhz0etQ8Go54c0pBf4iQTi97BDzxjJxpxsyZEi8/YLbqQDf0Vid 8fADBQDM4Mi098drKKCNAUp9aYYlPuk3UMPBNxFJlEUg4OksTtsAugHy3GRKmHxqwl1o oD6Xxf+DqnxelVRErNHJE7NzGOhwNX5ubfj/JxZp15fFxqro69tBJk6NJB2pD3GZ7NdW 5vQCtO+bOQj2KzC5z9q0yjU2AJE0sd+NLdpKGxYpZo258528SLYN9Pmr4ao64KbMOpc/ P1EhW+dsi9LRNq+7CmXyIWIGZGbP6SS9L5sNxxYAyQLlK6Alb9x/nd3PZmbuxzaMsUwE i9ww== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785955922; x=1786560722; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=4ToGqmYCLIsCza1nv6x574MwhjIbpl6LQnMNJCZ7DMg=; b=rE2fVcHW9ZJfHrO4eYmBFrGc3AsP7zU78TgSh8j+0VXkT4mjEL6uZoUNzgcJgpHXEp QaFQLNpwVgR5421JWb8YHHY+4zap0db+akhas3B7CljPCfSJvonhgil1twBP4lpbONxS t1QUwHN8cYg12uLfdZ4GM9KK0nrBvgRYLSiisWnKMpqlwNPM4mtZaokcNqTfrNTATO8z Xg3bV3ePEfr33Fb2N2J27IReBEAAz/YMSk6l6ElFspKn1lViCAU+mjM2Vzcr2uwAdLhD IsurFw/+wv7U+RuDfwCMa3GxQlj4Tk2O7UiuJnPsl49YI+8PucNyfTVRPLjoElvnmdhK A2Qw== X-Forwarded-Encrypted: i=1; AHgh+Roe/DGQlsQSpKt35c4b8UTzx9Ia46k9QE018u/VJJxpjGVVIBCsGBde0NmGCgJK968bh9VPTkHz62zV0e0=@vger.kernel.org X-Gm-Message-State: AOJu0Yx5kDBG149IQ3aTSWYYIA4Q/RhCkm7FndPQYfN1DNOKJRRugVZ3 I5ws9/ZmOET49EWzTHSVJGHxZMsiTQoE/FLT8J69+nzZUeXXG867+TbVDplyXQPVq0WjA7xqLHs bOxZDhg== X-Received: from pgjz15.prod.google.com ([2002:a63:e54f:0:b0:c85:9c9a:ab4a]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:4288:b0:847:83bc:d2a4 with SMTP id d2e1a72fcca58-84f2dfc8c42mr10676600b3a.2.1785955921695; Wed, 05 Aug 2026 11:52:01 -0700 (PDT) Date: Wed, 5 Aug 2026 11:52:01 -0700 In-Reply-To: <20260803180849.2323590-1-abdelkareem.abdelsaamad@citrix.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260803180849.2323590-1-abdelkareem.abdelsaamad@citrix.com> Message-ID: Subject: Re: [PATCH v7 17/26] KVM: nSVM: Add missing consistency check for EVENTINJ From: Sean Christopherson To: Abdelkareem Abdelsaamad Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, Yosry Ahmed , pbonzini@redhat.com, teddy.astie@vates.tech, jbeulich@suse.com, andrew.cooper3@citrix.com, roger.pau@citrix.com, jason.andryuk@amd.com Content-Type: text/plain; charset="us-ascii" On Mon, Aug 03, 2026, Abdelkareem Abdelsaamad wrote: > Hey, > I am currently working on hardening the Xen hypervisor's nested SVM > implementation to add the VMRUN consistency checks for injected events, > see the Xen patch discussion thread in [1]. > > While reviewing KVM's logic in nested_svm_event_inj_valid_exept(), I > can see that BR_VECTOR (5) and OF_VECTOR (4) are treated as > unconditionally valid. The referenced AMD APM Vol 2, Section 15.20 > explicitly state otherwise: > "If the VMM attempts to inject an event that is impossible for the > guest mode (e.g., a #BR exception when the guest is in 64-bit mode), > the event injection will fail... VMRUN will immediately exit with > VMEXIT_INVALID." > "Injecting an exception (TYPE = 3) with vectors 3 or 4 behaves like > a trap raised by INT3 and INTO instructions, respectively" > > Also, the APM volume 3 chapter 3 (INTO instruction), states that the > #OF triggering instruction, INTO, is Invalid in 64-bit mode. LOL, _that's_ what SVM decides is worthy of a consistency check? > I attempted testing the injection with Xen-Testing-Framework (XTF) > bare-minimum testing setup. I injected an exception (TYPE=3) with the > named vectors (BR_VECTOR (5) and OF_VECTOR (4)) on Genoa host. They > both caused VMEXIT_INVALID. > > I think the check in nested_svm_event_inj_valid_exept() needs to be > gated on a condition that only allows Type 3 exception injections for > OF_VECTOR (4) and BR_VECTOR (5) when the guest is not in 64-bit mode. It'd probably require a dedicated check in nested_svm_check_cached_vmcb12(), because the consistency check involves both control state and save state. Given that event injection validaton on SVM is inherently flawed due to hardware behavior being microarchitecture specific, addressing this is very low down on the priority list. If someone wants to tackle it, by all means, but realistically I doubt this will get fixed anytime soon. > Please, could you have a look and share your insights on the > implemented logic? > > [1] https://lists.xenproject.org/archives/html/xen-devel/2026-07/msg00808.html > > --Abdelkareem