Re: [PATCH] x86/apic/savic: Forward APIC_SPIV writes to the hypervisor

From: Borislav Petkov

Date: Wed Sep 30 2026 - 01:07:24 EST


+ some more AMD people and drop stable@

On Tue, Sep 29, 2026 at 05:52:55AM +0000, shrutiss@xxxxxxxxxx wrote:
> From: Shruti <shrutiss@xxxxxxxxxx>

You should use your legal name when you sign off on patches.

Leaving in the rest for the newly CCed.

> For Secure AVIC (SAVIC) guests, the hypervisor (KVM) emulates the LAPIC
> timer and LVT registers, while the guest's APIC backing page is kept in
> encrypted guest-private memory that the hypervisor cannot read.
>
> Currently, savic_write() updates APIC_SPIV (Spurious Interrupt Vector
> Register) only in the guest's private APIC backing page without
> notifying the hypervisor. Because the hypervisor never sees the guest
> set the APIC Software Enable bit (APIC_SPIV_APIC_ENABLED) in APIC_SPIV,
> it continues to treat the vCPU's Local APIC as software-disabled.
>
> When the hypervisor sees a vCPU's APIC as software-disabled, it forcibly
> masks all LVT writes (including APIC_LVTT for the local timer) and drops
> timer and fixed interrupts for that vCPU. On SMP guests, where secondary
> CPUs (APs) start with their emulated APIC reset to software-disabled,
> this prevents APs from receiving local timer interrupts and leaves them
> hung in idle (HLT) during boot.
>
> Forward APIC_SPIV writes to the hypervisor via savic_ghcb_msr_write() in
> addition to updating the guest's APIC backing page so the hypervisor's
> APIC state stays in sync with the guest.
>
> Fixes: c822f58a4fab ("x86/apic: Populate .read()/.write() callbacks of Secure AVIC driver")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Shruti <shrutiss@xxxxxxxxxx>
> ---
> arch/x86/kernel/apic/x2apic_savic.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/arch/x86/kernel/apic/x2apic_savic.c b/arch/x86/kernel/apic/x2apic_savic.c
> index dbc5678bc3b6..1ef4c5b6c494 100644
> --- a/arch/x86/kernel/apic/x2apic_savic.c
> +++ b/arch/x86/kernel/apic/x2apic_savic.c
> @@ -214,7 +214,6 @@ static void savic_write(u32 reg, u32 data)
> break;
> case APIC_TASKPRI:
> case APIC_EOI:
> - case APIC_SPIV:
> case SAVIC_NMI_REQ:
> case APIC_ESR:
> case APIC_ECTRL:
> @@ -223,6 +222,10 @@ static void savic_write(u32 reg, u32 data)
> case APIC_EILVTn(0) ... APIC_EILVTn(3):
> apic_set_reg(ap, reg, data);
> break;
> + case APIC_SPIV:
> + savic_ghcb_msr_write(reg, data);
> + apic_set_reg(ap, reg, data);
> + break;
> case APIC_ICR:
> savic_icr_write(data, 0);
> break;
> --
> 2.55.0.1082.g2b9226bbc0-goog
>

--
Regards/Gruss,
Boris.

https://people.kernel.org/tglx/notes-about-netiquette