[PATCH v4 0/9] KVM: nSVM: Enable DecodeAssists for nested guests

From: Tina Zhang

Date: Wed Aug 19 2026 - 01:54:53 EST


The SVM DecodeAssists feature provides decode state for selected
VM-Exits. KVM currently does not expose this feature to L1. Some L1
hypervisors may therefore treat the platform's SVM support as
incomplete.

In practice, this was observed with Hyper-V running on top of KVM.
Hyper-V appears to require DecodeAssists before enabling nested SVM for
its guests. Virtualizing the feature lets users enable Hyper-V
virtualization features inside a Windows VM when needed, e.g. to run
QEMU/KVM in WSL. Without DecodeAssists, Hyper-V does not enable nested
SVM because DecodeAssists is missing from KVM's virtual SVM model.

Virtualize DecodeAssists for nested SVM. Propagate instruction bytes
from VMCB02 for hardware-originated data #NPF and intercepted data #PF
VM-Exits. For KVM-generated exits, synthesize the architectural
EXITINFO state and use matching bytes from the emulator when available,
fetching missing bytes through L2's address translation only as a
fallback. Do not use the fallback for SEV guests, whose encrypted
memory cannot provide plaintext instruction bytes to KVM.

The selftest coverage in this version is intentionally broad and may be
more extensive than necessary. Some redundant cases can be removed in
a later revision, but for now the series provides a comprehensive test
set for users to exercise hardware-reflected, KVM-synthesized,
userspace-injected, and boundary cases.

The selftest has been run with kvm.force_emulation_prefix both disabled
and enabled.

Changes since v3:
- Rebase onto kvm-x86/next.
- Register DecodeAssists in the CPUID 0x8000000A SVM capability
initializer so that common code validates its CPUID word before the
SVM code enables it for nested guests.
- Make the VMCB02 instruction-byte source const and simplify the
synthesized-byte copy and fallback-fetch flow.

v3:
https://lore.kernel.org/r/cover.1785411877.git.zhang_wei@xxxxxxxxxxxxxx

Changes since v2:
- Rebase onto kvm-x86/next.
- Track hardware-provided instruction bytes independently of the VMCB02
exit code, and preserve the bytes when L0 handles an intercepted #PF
before reflecting it to L1.
- Select the instruction-byte source using host-owned VMCB02 state
instead of control fields in guest-owned VMCB12.
- Record whether a queued #PF VM-Exit has a matching emulator context,
so userspace-injected #PF exits do not consume stale emulator bytes.
- Stop fallback instruction fetches at noncanonical addresses and at the
32-bit linear-address boundary.
- Extend the selftest with regression coverage for replacing a hardware
#NPF with a synthesized #NPF and for userspace-injected #PF during
emulation, and harden its page layout and ucall handling.

v2:
https://lore.kernel.org/r/cover.1783999988.git.zhang_wei@xxxxxxxxxxxxxx

Changes since v1:
- Split the implementation into seven patches to make the individual
pieces easier to review.
- Add EXITINFO virtualization for emulator-generated MOV CR/DR, INTn,
INVLPG, and INVLPGA intercepts.
- Limit GuestInstrBytes propagation to data #NPF and intercepted #PF
exits, and clear the fields for instruction-fetch and unrelated exits.
- Provide GuestInstrBytes for KVM-synthesized data #PF/#NPF exits. Use
matching emulator bytes first and fetch missing bytes from L2 RIP as a
fallback, while avoiding fallback reads for SEV guests.
- Expand the selftest beyond hardware #NPF and stale-state coverage to
exercise hardware, synthesized, userspace-injected, instruction-fetch,
page-boundary, and CS-limit cases.

v1:
https://lore.kernel.org/r/20260629125205.52394-1-zhang_wei@xxxxxxxxxxxxxx

Tina Zhang (9):
KVM: x86: Add helper to provide intercept linear addresses
KVM: nSVM: Synthesize DecodeAssists EXITINFO for emulated intercepts
KVM: nSVM: Track hardware-provided instruction bytes
KVM: nSVM: Propagate hardware DecodeAssist bytes to VMCB12
KVM: x86: Track emulator-originated nested #PF VM-Exits
KVM: nSVM: Use emulator bytes for synthesized nested #NPF/#PF
KVM: nSVM: Fetch missing DecodeAssist bytes for synthesized #NPF/#PF
KVM: nSVM: Advertise DecodeAssists to L1
KVM: selftests: Add nested SVM DecodeAssists test

arch/x86/include/asm/kvm_host.h | 1 +
arch/x86/kvm/cpuid.c | 1 +
arch/x86/kvm/emulate.c | 29 +-
arch/x86/kvm/kvm_emulate.h | 1 +
arch/x86/kvm/svm/nested.c | 174 +++-
arch/x86/kvm/svm/svm.c | 72 +-
arch/x86/kvm/svm/svm.h | 20 +-
arch/x86/kvm/x86.c | 33 +-
tools/testing/selftests/kvm/Makefile.kvm | 1 +
.../selftests/kvm/include/x86/processor.h | 1 +
.../kvm/x86/svm_nested_decode_assists_test.c | 791 ++++++++++++++++++
11 files changed, 1094 insertions(+), 30 deletions(-)
create mode 100644 tools/testing/selftests/kvm/x86/svm_nested_decode_assists_test.c


base-commit: 1b731e5ded480bd1e5546aed35584238661ce72e
--
2.43.7