mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Ben Hutchings <ben@decadent.org.uk>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: akpm@linux-foundation.org, Denis Kirjanov <kda@linux-powerpc.org>,
	"Joerg Roedel" <jroedel@suse.de>
Subject: [PATCH 3.16 07/10] KVM: VMX: Fix x2apic check in  vmx_msr_bitmap_mode()
Date: Thu, 09 May 2019 15:08:17 +0100	[thread overview]
Message-ID: <lsq.1557410897.741749439@decadent.org.uk> (raw)
In-Reply-To: <lsq.1557410896.171359878@decadent.org.uk>

3.16.67-rc1 review patch.  If anyone has any objections, please let me know.

------------------

From: Joerg Roedel <jroedel@suse.de>

The stable backport of upstream commit

	904e14fb7cb96 KVM: VMX: make MSR bitmaps per-VCPU

has a bug in vmx_msr_bitmap_mode(). It enables the x2apic
MSR-bitmap when the kernel emulates x2apic for the guest in
software. The upstream version of the commit checkes whether
the hardware has virtualization enabled for x2apic
emulation.

Since KVM emulates x2apic for guests even when the host does
not support x2apic in hardware, this causes the intercept of
at least the X2APIC_TASKPRI MSR to be disabled on machines
not supporting that MSR. The result is undefined behavior,
on some machines (Intel Westmere based) it causes a crash of
the guest kernel when it tries to access that MSR.

Change the check in vmx_msr_bitmap_mode() to match the upstream
code. This fixes the guest crashes observed with stable
kernels starting with v4.4.168 through v4.4.175.

Signed-off-by: Joerg Roedel <jroedel@suse.de>
Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
---
 arch/x86/kvm/vmx.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

--- a/arch/x86/kvm/vmx.c
+++ b/arch/x86/kvm/vmx.c
@@ -4224,7 +4224,9 @@ static u8 vmx_msr_bitmap_mode(struct kvm
 {
 	u8 mode = 0;
 
-	if (irqchip_in_kernel(vcpu->kvm) && apic_x2apic_mode(vcpu->arch.apic)) {
+	if (cpu_has_secondary_exec_ctrls() &&
+	    (vmcs_read32(SECONDARY_VM_EXEC_CONTROL) &
+	     SECONDARY_EXEC_VIRTUALIZE_X2APIC_MODE)) {
 		mode |= MSR_BITMAP_MODE_X2APIC;
 		if (enable_apicv)
 			mode |= MSR_BITMAP_MODE_X2APIC_APICV;


  parent reply	other threads:[~2019-05-09 14:13 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-05-09 14:08 [PATCH 3.16 00/10] 3.16.67-rc1 review Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 09/10] timer/debug: Change /proc/timer_stats from 0644 to 0600 Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 08/10] fork: record start_time late Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 10/10] percpu: stop printing kernel addresses Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 04/10] spi: omap-100k: Remove unused definitions Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 03/10] inet: update the IP ID generation algorithm to higher standards Ben Hutchings
2019-05-09 14:08 ` Ben Hutchings [this message]
2019-05-09 14:08 ` [PATCH 3.16 06/10] ipv4: fix a race in update_or_create_fnhe() Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 01/10] Revert "brcmfmac: assure SSID length from firmware is limited" Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 02/10] brcmfmac: add length checks in scheduled scan result handler Ben Hutchings
2019-05-09 14:08 ` [PATCH 3.16 05/10] vxlan: Fix big-endian declaration of VNI Ben Hutchings
2019-05-09 17:38 ` [PATCH 3.16 00/10] 3.16.67-rc1 review Guenter Roeck
2019-05-09 19:00   ` Ben Hutchings

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=lsq.1557410897.741749439@decadent.org.uk \
    --to=ben@decadent.org.uk \
    --cc=akpm@linux-foundation.org \
    --cc=jroedel@suse.de \
    --cc=kda@linux-powerpc.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®