[PATCH 02/11] KVM: SVM: Update control fields on #VMEXIT if and only if VMRUN succeeded

From: Paolo Bonzini

Date: Sat Sep 26 2026 - 01:39:10 EST


From: Sean Christopherson <seanjc@xxxxxxxxxx>

Leave control.erap_ctl and control.clean as-is in the VMCS if VMRUN fails,
because as per AMD:

there's no explicit architectural guarantee about the behavior in the
presence of VMRUN failures. So the best thing to do would be to assume
that if VMRUN fails, the actions requested in the control fields may not
have been performed.

Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
Message-ID: <20260904170642.3291466-3-seanjc@xxxxxxxxxx>
Signed-off-by: Paolo Bonzini <pbonzini@xxxxxxxxxx>
---
arch/x86/kvm/svm/svm.c | 18 +++++++++---------
1 file changed, 9 insertions(+), 9 deletions(-)

diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index afbaaaab84ed..b63e7c69aa1c 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -4625,17 +4625,17 @@ static __no_kcsan fastpath_t svm_vcpu_run(struct kvm_vcpu *vcpu, u64 run_flags)
if (!svm_is_vmrun_failure(svm->vmcb->control.exit_code)) {
this_cpu_ptr(&svm_data)->flush_all_asids = false;
svm->vmcb->control.tlb_ctl = TLB_CONTROL_DO_NOTHING;
+
+ /*
+ * Unconditionally mask off the CLEAR_RAP bit, the AND is just
+ * as cheap as the TEST+Jcc to avoid it.
+ */
+ if (cpu_feature_enabled(X86_FEATURE_ERAPS))
+ svm->vmcb->control.erap_ctl &= ~ERAP_CONTROL_CLEAR_RAP;
+
+ vmcb_mark_all_clean(svm->vmcb);
}

- /*
- * Unconditionally mask off the CLEAR_RAP bit, the AND is just as cheap
- * as the TEST+Jcc to avoid it.
- */
- if (cpu_feature_enabled(X86_FEATURE_ERAPS))
- svm->vmcb->control.erap_ctl &= ~ERAP_CONTROL_CLEAR_RAP;
-
- vmcb_mark_all_clean(svm->vmcb);
-
/* if exit due to PF check for async PF */
if (svm->vmcb->control.exit_code == SVM_EXIT_EXCP_BASE + PF_VECTOR)
vcpu->arch.apf.host_apf_flags =
--
2.52.0