[PATCH v2 20/29] KVM: x86: Add KVM_REQ_MMU_SYNC_ALL_ROOTS
From: Yosry Ahmed
Date: Wed Oct 07 2026 - 20:19:19 EST
Add a new x86 request to sync all roots, current and previous. This will
be used when syncing the shadow NPTs on nested VMRUN when an ASID flush
(or new ASID) is requested by L1, as all physical translations in all
roots should be sync'd (since shadow mappings are not tagged with an
ASID).
Refactor syncing all roots (currently only done by
kvm_vcpu_flush_tlb_guest()) to a helper, and use it to handle the
request.
Clear KVM_REQ_MMU_SYNC when handling KVM_REQ_MMU_SYNC_ALL_ROOTS as the
latter is a superset. Do not do so inside kvm_mmu_sync_all_roots(), to
avoid any subtle behavioral changes from kvm_vcpu_flush_tlb_guest()
clearing KVM_REQ_MMU_SYNC. It makes sense to always clear it when
syncing the MMU, but there might be weird dependencies on the sync only
happening before the actual vCPU run, and kvm_vcpu_flush_tlb_guest() is
called in other code paths than handling KVM_REQ_TLB_FLUSH_GUEST before
vCPU run.
No functional change intended.
Signed-off-by: Yosry Ahmed <yosry@xxxxxxxxxx>
---
arch/x86/include/asm/kvm_host.h | 1 +
arch/x86/kvm/mmu.h | 7 +++++++
arch/x86/kvm/x86.c | 11 ++++++++---
3 files changed, 16 insertions(+), 3 deletions(-)
diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h
index e2eef7057bd35..1d28bb7e92c7f 100644
--- a/arch/x86/include/asm/kvm_host.h
+++ b/arch/x86/include/asm/kvm_host.h
@@ -127,6 +127,7 @@
KVM_ARCH_REQ_FLAGS(33, KVM_REQUEST_WAIT | KVM_REQUEST_NO_WAKEUP)
#define KVM_REQ_UPDATE_PROTECTED_GUEST_STATE \
KVM_ARCH_REQ_FLAGS(34, KVM_REQUEST_WAIT)
+#define KVM_REQ_MMU_SYNC_ALL_ROOTS KVM_ARCH_REQ(35)
#define INVALID_PAGE (~(hpa_t)0)
#define VALID_PAGE(x) ((x) != INVALID_PAGE)
diff --git a/arch/x86/kvm/mmu.h b/arch/x86/kvm/mmu.h
index b443a5083bfb0..b6ad0ff72393e 100644
--- a/arch/x86/kvm/mmu.h
+++ b/arch/x86/kvm/mmu.h
@@ -170,6 +170,13 @@ void kvm_mmu_unload(struct kvm_vcpu *vcpu);
void kvm_mmu_free_obsolete_roots(struct kvm_vcpu *vcpu);
void kvm_mmu_sync_roots(struct kvm_vcpu *vcpu);
void kvm_mmu_sync_prev_roots(struct kvm_vcpu *vcpu);
+
+static inline void kvm_mmu_sync_all_roots(struct kvm_vcpu *vcpu)
+{
+ kvm_mmu_sync_roots(vcpu);
+ kvm_mmu_sync_prev_roots(vcpu);
+}
+
void kvm_mmu_track_write(struct kvm_vcpu *vcpu, gpa_t gpa, const u8 *new,
int bytes);
diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index 12eaeaea51633..a54e9da2ed09e 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -2020,8 +2020,7 @@ static void kvm_vcpu_flush_tlb_guest(struct kvm_vcpu *vcpu)
* a forced sync of the shadow page tables. Ensure all the
* roots are synced and the guest TLB in hardware is clean.
*/
- kvm_mmu_sync_roots(vcpu);
- kvm_mmu_sync_prev_roots(vcpu);
+ kvm_mmu_sync_all_roots(vcpu);
}
kvm_x86_call(flush_tlb_guest)(vcpu);
@@ -8167,8 +8166,14 @@ static int vcpu_enter_guest(struct kvm_vcpu *vcpu)
if (unlikely(r))
goto out;
}
- if (kvm_check_request(KVM_REQ_MMU_SYNC, vcpu))
+
+ if (kvm_check_request(KVM_REQ_MMU_SYNC_ALL_ROOTS, vcpu)) {
+ kvm_mmu_sync_all_roots(vcpu);
+ kvm_clear_request(KVM_REQ_MMU_SYNC, vcpu);
+ } else if (kvm_check_request(KVM_REQ_MMU_SYNC, vcpu)) {
kvm_mmu_sync_roots(vcpu);
+ }
+
if (kvm_check_request(KVM_REQ_LOAD_MMU_PGD, vcpu))
kvm_mmu_load_pgd(vcpu);
--
2.56.0.360.g66cac248cb-goog