Re: [PATCH 1/6] KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit

From: Yosry Ahmed

Date: Mon Jul 27 2026 - 13:11:38 EST


On Thu, Jul 23, 2026 at 5:48 PM Sean Christopherson <seanjc@xxxxxxxxxx> wrote:
>
> Always check and clear KVM_REQ_GET_NESTED_STATE_PAGES when emulating a
> nested VM-Exit to ensure the request is cleared, even when KVM was built
> with CONFIG_KVM_HYPERV=n, as KVM subtly relies on the "check" to clear
> the flag and thus avoid double-mapping the vmcs12 pages, e.g. if KVM
> manages to bail from VM-Enter without processing the request, and then
> emulates VMLAUNCH or VMRESUME.
>
> Fixes: b4f69df0f65e ("KVM: x86: Make Hyper-V emulation optional")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Yosry Ahmed <yosry@xxxxxxxxxx>
> Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
> ---
> arch/x86/kvm/vmx/nested.c | 5 +++--
> 1 file changed, 3 insertions(+), 2 deletions(-)
>
> diff --git a/arch/x86/kvm/vmx/nested.c b/arch/x86/kvm/vmx/nested.c
> index b5460de4b1a7..f2518d67e7de 100644
> --- a/arch/x86/kvm/vmx/nested.c
> +++ b/arch/x86/kvm/vmx/nested.c
> @@ -5066,8 +5066,9 @@ void __nested_vmx_vmexit(struct kvm_vcpu *vcpu, u32 vm_exit_reason,
> /* trying to cancel vmlaunch/vmresume is a bug */
> kvm_warn_on_nested_run_pending(vcpu);
>
> -#ifdef CONFIG_KVM_HYPERV
> + /* Note, "checking" the request also clears the request. */

kvm_check_request() is in dire need of a rename.
kvm_test_clear_request()? Then we wouldn't need such a comment.
Obviously not as part of the stable fix, maybe another patch or even
separate from this series? I can also send a patch if you prefer so.

For this patch:

Reviewed-by: Yosry Ahmed <yosry@xxxxxxxxxx>


> if (kvm_check_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu)) {
> +#ifdef CONFIG_KVM_HYPERV
> /*
> * KVM_REQ_GET_NESTED_STATE_PAGES is also used to map
> * Enlightened VMCS after migration and we still need to
> @@ -5075,8 +5076,8 @@ void __nested_vmx_vmexit(struct kvm_vcpu *vcpu, u32 vm_exit_reason,
> * the first L2 run.
> */
> (void)nested_get_evmcs_page(vcpu);
> - }
> #endif
> + }
>
> /* Service pending TLB flush requests for L2 before switching to L1. */
> kvm_service_local_tlb_flush_requests(vcpu);
> --
> 2.55.0.229.g6434b31f56-goog
>