[PATCH v2 0/3] KVM: TDX: Syntehsize SHUTDOWN on unhandled EPT Violation

From: Sean Christopherson

Date: Tue Sep 29 2026 - 20:12:02 EST


Signal SHUTDOWN instead of -EIO if the guest accesses an unaccepted page and
has disabled EPT Violation #VEs on such accesses. Returning -EIO is all but
guaranteed to mislead the VMM into thinking KVM (or the VMM) messed up, and
will likely result in the VM being terminated instead of rebooted.

v2:
- Return SHUTDOWN directly, via a new helper. [Rick]
- Ratelimit the error message. [Sashiko, (and past me, amusingly)]

v1: https://lore.kernel.org/all/20260923163315.1580860-1-seanjc@xxxxxxxxxx

Sean Christopherson (3):
KVM: x86: Add a helper to prepare vcpu->run for a SHUTDOWN exit to
userspace
KVM: TDX: Synthesize SHUTDOWN instead of returning -EIO on unhandled
EPT violation
KVM: TDX: Ratelimit the "EPT Violation on pending acceptance page"
warning

arch/x86/kvm/svm/svm.c | 3 +--
arch/x86/kvm/vmx/tdx.c | 11 +++++------
arch/x86/kvm/vmx/vmx.c | 3 +--
arch/x86/kvm/x86.c | 3 +--
include/linux/kvm_host.h | 8 ++++++++
5 files changed, 16 insertions(+), 12 deletions(-)


base-commit: a0bc8e1d7a82bb143b8f8f44ae3a01938f37c2ea
--
2.56.0.rc1.315.gc6ed9934b7-goog