[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v2] x86/svm: Sync nextrip during virtual VMRUN


  • To: andrew.cooper3@xxxxxxxxxx, xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: chunjie.zhu@xxxxxxxxxx
  • Date: Sat, 10 Oct 2026 12:05:02 +0800
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=eqy7CVCB5sQxyVXT2EVuVVOIkP3k3Vbdge2Vuw9ZONA=; b=QvZQVnEzAoQJhlghOlErI8wqcWcExlbGlv1L1GgSX3+DOZYR9H8vPRECcfGSrk1MaczNYsyx4ST2gerJ5Pl3utL77elYdMbfy+JfYfy9TKQXRe9WvQLsPiYVb8yJATOA7RVxsg8bT1/ApElUU/j5VjagjxuXGFFvbQuyVP3sCAnm65msLO4MoM77l32mqMQbwFv5z3KUpyHsrUxEPBzDZZkP5otS+uwVhBUeBFb6lqSPEbG/oV9xYwUvt194U65fl0HFGkhy45W7PJUerRm/cf5RQ7hLeBQOsxvUAciQc+oQT+g8pjaA2GOjOYJQAp/AaPNzi/DUBUcIr4vdcLnokw==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=m7qpeppD6tNuYH9cPFiEnK6NzRP00HEIdWaxZHuhmh14Q1oOxQQFcZYxBlAUyvu88rL3tTmmkFmWd/MqFQiiCM2fDgiyx3IQJpKiyUASlY0KyG0whvigmjJhE3NS9sXIE+n0PCw4C1VbLm95MH+MpLEj3OgP0Mgm2JR62irqN5oQ1zEhrPPiyhOTOUMhx5Apq33oUU5HBGbBplt8wbBH1jW8eHCeeHpDcDvpjtdY8Mg4JdsJdCLmHsMAD2oyW0TYaon/L/Yjv59RLfbWvo2JprFbuS3ixmpm8oD//Dka0D1cRMKCnllCQ5QAsh1xU3rOPilPIgbI9obJDEXxzfvIZw==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-Id:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: chunjie.zhu@xxxxxxxxxx, jason.andryuk@xxxxxxx, jbeulich@xxxxxxxx, roger@xxxxxxxxxxxxxx, ross.lagerwall@xxxxxxxxxx, teddy.astie@xxxxxxxxxx
  • Delivery-date: Sat, 10 Oct 2026 04:05:37 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

From: Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>

NextRIP is consumed on VMRUN as the return address pushed onto the
stack for injected soft exceptions/interrupts.  nsvm_vmcb_prepare4vmrun()
builds n2vmcb from the virtual VMCB on every entry to the L2 guest, but
never copied this field, leaving n2vmcb->nextrip stale.  Injecting an
event in this state can wedge the L2 vCPU, as the APM does not define
behaviour for a VMRUN with a garbage NextRIP.

Nested virt is only offered on NRIPS-capable hardware, and NRIPS is
required to be advertised to L1 (see start_nested_svm()), so the L1
hypervisor is required to keep NextRIP correct.  Therefore no
conditional logic is needed here; an unconditional sync suffices.

Suggested-by: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>
Signed-off-by: Chunjie Zhu <chunjie.zhu@xxxxxxxxxx>
---
Changes in v2:
- Retitle from "x86/svm: mandatory update VMCB nextrip for soft
  interrupts" to "x86/svm: Sync nextrip during virtual VMRUN" (Andrew
  Cooper).
- Move the rationale out of the in-code comment and into the commit
  message; keep the code comment short (Jan Beulich).
- Drop the stray non-ASCII whitespace characters from the comment
  (Jan Beulich).
- Drop the speculation about garbage/invalid NextRIP values: nested
  virt is only enabled on NRIPS-capable hardware and NRIPS is
  mandatorily advertised to L1, so the L1 hypervisor is required to
  keep NextRIP valid and no conditional sync is needed (Andrew
  Cooper).
- Cc AMD SVM maintainers/reviewers per submission guidelines (Jan
  Beulich).

 xen/arch/x86/hvm/svm/nestedsvm.c | 9 ++++++++-
 1 file changed, 8 insertions(+), 1 deletion(-)

diff --git a/xen/arch/x86/hvm/svm/nestedsvm.c b/xen/arch/x86/hvm/svm/nestedsvm.c
index faacfe007832..f2f3f9d14ec6 100644
--- a/xen/arch/x86/hvm/svm/nestedsvm.c
+++ b/xen/arch/x86/hvm/svm/nestedsvm.c
@@ -465,7 +465,14 @@ static int nsvm_vmcb_prepare4vmrun(struct vcpu *v, struct 
cpu_user_regs *regs)
     n2vmcb->virt_ext.bytes =
         n1vmcb->virt_ext.bytes | ns_vmcb->virt_ext.bytes;
 
-    /* NextRIP - only evaluated on #VMEXIT. */
+    /*
+     * NextRIP is consumed on VMRUN as the return address pushed on the
+     * stack for injected soft exceptions/interrupts. Nested virt is only
+     * available on NRIPS-capable hardware and NRIPS is required to be
+     * advertised to L1 (see start_nested_svm), so the L1 hypervisor is
+     * required to keep this field correct.
+     */
+    n2vmcb->nextrip = ns_vmcb->nextrip;
 
     /*
      * VMCB Save State Area
-- 
2.34.1




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.