[PATCH 0/2] KVM: x86: Fix lost nested APF VM-Exits

From: Loc Nguyen

Date: Fri Oct 02 2026 - 01:42:17 EST


A nested asynchronous page fault delivered to L1 as a synthetic #PF
VM-Exit can be lost after KVM queues the exception. Most callers of
kvm_queue_exception_vmexit() arrive through kvm_multiple_exception(),
which requests event processing, but the nested APF path calls the
helper directly.

Without KVM_REQ_EVENT, vcpu_enter_guest() can skip
kvm_check_and_inject_events() and re-enter L2. A later VM-Exit can then
clear the pending exception while reconstructing vectoring state. The
APF reason remains PAGE_NOT_PRESENT, allowing a later regular #PF to
consume the stale reason.

Patch 1 requests event processing in kvm_queue_exception_vmexit() so
that all queued exception VM-Exits are processed before re-entering the
guest.

Patch 2 adds a regression test that holds an L2 backing page missing
with userfaultfd. The test verifies that L1 receives the synthetic #PF
VM-Exit with the expected APF token and PAGE_NOT_PRESENT reason.

Testing was performed in a nested VMX environment:

- x86_64 kernel build with KVM_WERROR=y
- nested_apf_event_test fails on the base kernel with a lost nested
APF event and passes with the fix
- full KVM selftest suite passes
- kvm-unit-tests VMX suite passes with TIMEOUT=900

Loc Nguyen (2):
KVM: x86: Request event processing for exception VM-Exits
KVM: selftests: Add a test for lost nested APF VM-Exits

arch/x86/kvm/x86.c | 2 +
tools/testing/selftests/kvm/Makefile.kvm | 1 +
.../selftests/kvm/x86/nested_apf_event_test.c | 306 ++++++++++++++++++
3 files changed, 309 insertions(+)
create mode 100644 tools/testing/selftests/kvm/x86/nested_apf_event_test.c


base-commit: b378201ccd5280d0fff89bbe55e1eb00620ec0d5
--
2.43.0