[PATCH v2 3/3] KVM: TDX: Ratelimit the "EPT Violation on pending acceptance page" warning

From: Sean Christopherson

Date: Tue Sep 29 2026 - 20:11:43 EST


Ratelimit TDX's kernel logging when a guest accesses an unaccepted page and
has opted to disable EPT Violation #VEs for unaccepted accesses, as the
pr_warn() is trivial for a misbehaving userspace to trigger.

Fixes: e6a85781f783 ("KVM: TDX: Detect unexpected SEPT violations due to pending SPTEs")
Cc: stable@xxxxxxxxxxxxxxx
Reported-by: Sashiko Bot <sashiko-bot@xxxxxxxxxx>
Closes: https://lore.kernel.org/all/20260923164348.2DB2D1F000FF@xxxxxxxxxxxxxxx
Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
arch/x86/kvm/vmx/tdx.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
index e3723f1222fc..4cac43299851 100644
--- a/arch/x86/kvm/vmx/tdx.c
+++ b/arch/x86/kvm/vmx/tdx.c
@@ -1937,8 +1937,8 @@ static int tdx_handle_ept_violation(struct kvm_vcpu *vcpu)

if (vt_is_tdx_private_gpa(vcpu->kvm, gpa)) {
if (tdx_is_sept_violation_unexpected_pending(vcpu)) {
- pr_warn("Guest access before accepting 0x%llx on vCPU %d\n",
- gpa, vcpu->vcpu_id);
+ pr_warn_ratelimited("Guest access before accepting 0x%llx on vCPU %d\n",
+ gpa, vcpu->vcpu_id);
kvm_prepare_shutdown_exit(vcpu);
return 0;
}
--
2.56.0.rc1.315.gc6ed9934b7-goog