Re: [PATCH 1/2] LoongArch: KVM: Fix PC double advance in kernel MMIO read fast path

From: Bibo Mao

Date: Thu Jul 23 2026 - 21:24:25 EST




On 2026/7/23 下午7:15, Zeng Chi wrote:
From: Zeng Chi <zengchi@xxxxxxxxxx>

In the in-kernel MMIO read fast path of kvm_emu_mmio_read(),
kvm_complete_mmio_read() already advances the guest PC via update_pc().
The explicit update_pc() call right after it advances the PC a second
time, so PC moves forward by 8 instead of 4 and the instruction
following the MMIO read is silently skipped.

The user space MMIO read completion path in kvm_arch_vcpu_ioctl_run()
calls kvm_complete_mmio_read() only once, and the MMIO write fast path
advances the PC exactly once as well.

Remove the redundant update_pc() so the kernel MMIO read fast path
advances the PC by a single instruction.

Fixes: 80edf90831a2 ("LoongArch: KVM: Add sign extension with kernel MMIO read emulation")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Zeng Chi <zengchi@xxxxxxxxxx>
---
arch/loongarch/kvm/exit.c | 1 -
1 file changed, 1 deletion(-)

diff --git a/arch/loongarch/kvm/exit.c b/arch/loongarch/kvm/exit.c
index 8572b63478bb..482ba17bcd3d 100644
--- a/arch/loongarch/kvm/exit.c
+++ b/arch/loongarch/kvm/exit.c
@@ -481,7 +481,6 @@ int kvm_emu_mmio_read(struct kvm_vcpu *vcpu, larch_inst inst)
srcu_read_unlock(&vcpu->kvm->srcu, idx);
if (!ret) {
kvm_complete_mmio_read(vcpu, run);
- update_pc(&vcpu->arch);
vcpu->mmio_needed = 0;
return EMULATE_DONE;
}

Hi Zeng,

Thanks for finding this problem, it is a big critical potential issue :(

Reviewed-by: Bibo Mao <maobibo@xxxxxxxxxxx>