Re: [PATCH 1/4] KVM: nSVM: Reject KVM_SET_NESTED_STATE if L1 has EFER.LMA=1 && EFER.LME=0

From: Yosry Ahmed

Date: Thu Aug 27 2026 - 18:01:36 EST


On Thu, Aug 27, 2026 at 2:42 PM Paolo Bonzini <pbonzini@xxxxxxxxxx> wrote:
>
> On 8/27/26 19:33, Sean Christopherson wrote:
> >>> If anything is wrong, it's the CR0.PG check. Presumably that got carried forward
> >>> from commit c0725420cfdc ("KVM: SVM: Add helper functions for nested SVM"). I
> >>> don't see anything in the APM that requires paging to be enabled, and nothing in
> >>> that ancient series points at concrete documentation either.
> >>
> >> Oh yeah you're right, for some reason I thought it was paging not
> >> protected mode. Well then, it seems like
> >> nested_svm_check_permissions() is also incorrectly checking paging as
> >> well, seems like both checks are incorrect? Also, I don't see anything
> >> in the APM about checking RFLAGS.VM before VMRUN.
> >
> > Presumably it's covered by the !PROTECTED_MODE clause.
> >
> > IF ((MSR_EFER.SVME == 0) || (!PROTECTED_MODE)) // This instruction can only be executed in protected
> > EXCEPTION [#UD] // mode with SVM enabled
> >
> > Section "1.3.4 Legacy Modes" describes "Protected Mode" and "Virtual-8086 Mode"
> > as separate submodes. And the tables for most instructions differentiate between
> > Real, Virtual 8086, and Protected modes when enumerating exceptions.
>
> Right.
>
> As to CR0.PG it does seem incorrect to check it entirely, however note
> that there is this too (15.25.3 Enabling Nested Paging):
>
> If VMRUN is executed with hCR0.PG cleared to zero and
> NP_ENABLE set to 1, VMRUN terminates with
> #VMEXIT(VMEXIT_INVALID)
>
> which would have to be checked in nested_vmcb_check_controls().

Yeah.

>
> >> If the goal here is to keep the checks here consistent with
> >> nested_svm_check_permissions(), aside from the new EFER check, then
> >> maybe we should also check CPL here?
> Perhaps, but nested_svm_check_permissions() is not reached with CPL=0
> because the #GP overrides the interception (table 15-7, instruction
> intercepts). The same should be true about EFLAGS.VM=1.

It is reachable in the odd cases where KVM intercepts #GP.

But either way, I think having a CPL check in KVM_SET_NESTED_STATE is
probably the right thing to do.

>
> Paolo
>
>