Re: [PATCH 1/2] KVM: arm64: pvtime: Don't lose stolen time on failed updates

From: Marc Zyngier

Date: Thu Sep 24 2026 - 14:36:38 EST


On Mon, 21 Sep 2026 10:20:34 +0100,
Hao Zhang <hao_zhang_kdev@xxxxxxx> wrote:
>
> From: Hao Zhang <zhanghao1@xxxxxxxxxx>
>
> kvm_update_stolen_time() advances last_steal before checking whether
> kvm_put_guest() successfully writes the updated value to guest memory.
>
> If the write fails, the updated stolen time is not visible to the guest,
> but the corresponding run delay has already been consumed from KVM's
> accounting state. A later successful update therefore starts from the
> advanced last_steal value and permanently loses that interval.

I'm sceptical.

A "transient" write failure means that userspace has unmapped the page
this should have been stored to. Userspace is in charge of the VM --
it literally is the owner.

Why should we prevent it from shooting itself in the foot? Userspace
can equally stop the vcpu from running, and this is "stolen time"
that is not accounted for.

M.

--
Without deviation from the norm, progress is not possible.