Re: [PATCH 1/2] KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC

From: Jim Mattson

Date: Wed Feb 04 2026 - 23:21:24 EST


On Tue, Feb 3, 2026 at 11:07 AM Sean Christopherson <seanjc@xxxxxxxxxx> wrote:
>
> Initialize all per-vCPU AVIC control fields in the VMCB if AVIC is enabled
> in KVM and the VM has an in-kernel local APIC, i.e. if it's _possible_ the
> vCPU could activate AVIC at any point in its lifecycle. Configuring the
> VMCB if and only if AVIC is active "works" purely because of optimizations
> in kvm_create_lapic() to speculatively set apicv_active if AVIC is enabled
> *and* to defer updates until the first KVM_RUN. In quotes because KVM
> likely won't do the right thing if kvm_apicv_activated() is false, i.e. if
> a vCPU is created while APICv is inhibited at the VM level for whatever
> reason. E.g. if the inhibit is *removed* before KVM_REQ_APICV_UPDATE is
> handled in KVM_RUN, then __kvm_vcpu_update_apicv() will elide calls to
> vendor code due to seeing "apicv_active == activate".
>
> Cleaning up the initialization code will also allow fixing a bug where KVM
> incorrectly leaves CR8 interception enabled when AVIC is activated without
> creating a mess with respect to whether AVIC is activated or not.
>
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
Reviewed-by: Jim Mattson <jmattson@xxxxxxxxxx>