android_kernel_motorola_sm6375/arch/x86
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Sean Christopherson a908eca437 KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O
[ Upstream commit e750f85391286a4c8100275516973324b621a269 ]

When completing emulation of instruction that generated a userspace exit
for I/O, don't recheck L1 intercepts as KVM has already finished that
phase of instruction execution, i.e. has already committed to allowing L2
to perform I/O.  If L1 (or host userspace) modifies the I/O permission
bitmaps during the exit to userspace,  KVM will treat the access as being
intercepted despite already having emulated the I/O access.

Pivot on EMULTYPE_NO_DECODE to detect that KVM is completing emulation.
Of the three users of EMULTYPE_NO_DECODE, only complete_emulated_io() (the
intended "recipient") can reach the code in question.  gp_interception()'s
use is mutually exclusive with is_guest_mode(), and
complete_emulated_insn_gp() unconditionally pairs EMULTYPE_NO_DECODE with
EMULTYPE_SKIP.

The bad behavior was detected by a syzkaller program that toggles port I/O
interception during the userspace I/O exit, ultimately resulting in a WARN
on vcpu->arch.pio.count being non-zero due to KVM no completing emulation
of the I/O instruction.

  WARNING: CPU: 23 PID: 1083 at arch/x86/kvm/x86.c:8039 emulator_pio_in_out+0x154/0x170 [kvm]
  Modules linked in: kvm_intel kvm irqbypass
  CPU: 23 UID: 1000 PID: 1083 Comm: repro Not tainted 6.16.0-rc5-c1610d2d66b1-next-vm #74 NONE
  Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
  RIP: 0010:emulator_pio_in_out+0x154/0x170 [kvm]
  PKRU: 55555554
  Call Trace:
   <TASK>
   kvm_fast_pio+0xd6/0x1d0 [kvm]
   vmx_handle_exit+0x149/0x610 [kvm_intel]
   kvm_arch_vcpu_ioctl_run+0xda8/0x1ac0 [kvm]
   kvm_vcpu_ioctl+0x244/0x8c0 [kvm]
   __x64_sys_ioctl+0x8a/0xd0
   do_syscall_64+0x5d/0xc60
   entry_SYSCALL_64_after_hwframe+0x4b/0x53
   </TASK>

Reported-by: syzbot+cc2032ba16cc2018ca25@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/68790db4.a00a0220.3af5df.0020.GAE@google.com
Fixes: 8a76d7f25f ("KVM: x86: Add x86 callback for intercept check")
Cc: stable@vger.kernel.org
Cc: Jim Mattson <jmattson@google.com>
Link: https://lore.kernel.org/r/20250715190638.1899116-1-seanjc@google.com
Signed-off-by: Sean Christopherson <seanjc@google.com>
[ is_guest_mode() was open coded ]
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
2025-10-29 13:59:54 +01:00
..
boot x86/boot/compressed: prefer cc-option for CFLAGS additions 2025-06-27 11:02:50 +01:00
configs
crypto crypto: x86/aegis128 - access 32-bit arguments as 32-bit 2024-12-14 19:44:47 +01:00
entry x86/entry: Fix ORC unwinder for PUSH_REGS with save_ret=1 2025-04-10 14:29:41 +02:00
events perf/x86/intel/uncore: Fix the scale of IIO free running counters on SNR 2025-05-02 07:39:21 +02:00
hyperv
ia32
include KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O 2025-10-29 13:59:54 +01:00
kernel x86/umip: Fix decoding of register forms of 0F 01 (SGDT and SIDT aliases) 2025-10-29 13:59:54 +01:00
kvm KVM: x86: Don't (re)check L1 intercepts when completing userspace I/O 2025-10-29 13:59:54 +01:00
lib x86/insn: Fix PUSH instruction in x86 instruction decoder opcode map 2024-06-16 13:28:39 +02:00
math-emu
mm x86/fpu: Delay instruction pointer fixup until after warning 2025-08-28 16:21:34 +02:00
net
oprofile
pci x86/pci/xen: Fix PCIBIOS_* return code handling 2024-08-19 05:33:25 +02:00
platform x86/xen/pvh: Annotate indirect branch as safe 2024-12-14 19:44:21 +01:00
power
purgatory x86/purgatory: Switch to the position-independent small code model 2024-06-16 13:28:35 +02:00
ras
realmode x86/asm: Make more symbols local 2023-09-23 10:59:40 +02:00
tools x86/boot: Ignore relocations in .notes sections in walk_relocs() too 2024-06-16 13:28:33 +02:00
um um: Store full CSGSFS and SS register from mcontext 2025-06-04 14:32:30 +02:00
video
xen Grab mm lock before grabbing pt lock 2025-03-13 12:43:13 +01:00
.gitignore
Kbuild
Kconfig x86/mm: Disable hugetlb page table sharing on 32-bit 2025-07-17 18:25:06 +02:00
Kconfig.cpu x86/Kconfig: Transmeta Crusoe is CPU family 5, not 6 2024-02-23 08:25:12 +01:00
Kconfig.debug x86/kconfig: Select ARCH_WANT_FRAME_POINTERS again when UNWINDER_FRAME_POINTER=y 2024-06-16 13:28:45 +02:00
Makefile
Makefile.um um: allow not setting extra rpaths in the linux binary 2024-03-15 10:48:16 -04:00
Makefile_32.cpu