[PATCH v2 1/3] KVM: x86: Add a helper to prepare vcpu->run for a SHUTDOWN exit to userspace

From: Sean Christopherson

Date: Tue Sep 29 2026 - 20:13:36 EST


Add kvm_prepare_shutdown_exit() to dedup the paths that exit to userspace
with KVM_EXIT_SHUTDOWN, all of which happen to be x86 (presumably other
architectures use KVM_EXIT_SYSTEM_EVENT?).

Note, this adds a clearing of mmio_needed for SVM's shutdown_interception().
Not clearing mmio_needed in that case is all but guaranteed to be benign;
KVM should never enter the guest with outstanding emulated MMIO operations
(the equivalent VMX and TDX paths likely copy+pasted the code from
KVM_REQ_TRIPLE_FAULT, which does need to clear mmio_needed as KVM can
synthesize a triple fault shutdown in the middle of instruction emulation).

Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
---
arch/x86/kvm/svm/svm.c | 3 +--
arch/x86/kvm/vmx/tdx.c | 3 +--
arch/x86/kvm/vmx/vmx.c | 3 +--
arch/x86/kvm/x86.c | 3 +--
include/linux/kvm_host.h | 8 ++++++++
5 files changed, 12 insertions(+), 8 deletions(-)

diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c
index 0eb1623052c1..d2feb57d774f 100644
--- a/arch/x86/kvm/svm/svm.c
+++ b/arch/x86/kvm/svm/svm.c
@@ -2190,7 +2190,6 @@ static int mc_interception(struct kvm_vcpu *vcpu)

static int shutdown_interception(struct kvm_vcpu *vcpu)
{
- struct kvm_run *kvm_run = vcpu->run;
struct vcpu_svm *svm = to_svm(vcpu);


@@ -2214,7 +2213,7 @@ static int shutdown_interception(struct kvm_vcpu *vcpu)
kvm_vcpu_reset(vcpu, true);
}

- kvm_run->exit_reason = KVM_EXIT_SHUTDOWN;
+ kvm_prepare_shutdown_exit(vcpu);
return 0;
}

diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
index ee1d412b0ee6..29d4751f37fb 100644
--- a/arch/x86/kvm/vmx/tdx.c
+++ b/arch/x86/kvm/vmx/tdx.c
@@ -2092,8 +2092,7 @@ int tdx_handle_exit(struct kvm_vcpu *vcpu, fastpath_t fastpath)

switch (exit_reason.basic) {
case EXIT_REASON_TRIPLE_FAULT:
- vcpu->run->exit_reason = KVM_EXIT_SHUTDOWN;
- vcpu->mmio_needed = 0;
+ kvm_prepare_shutdown_exit(vcpu);
return 0;
case EXIT_REASON_EXCEPTION_NMI:
return tdx_handle_exception_nmi(vcpu);
diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
index dc635145eeaf..35db7197c586 100644
--- a/arch/x86/kvm/vmx/vmx.c
+++ b/arch/x86/kvm/vmx/vmx.c
@@ -5588,8 +5588,7 @@ static __always_inline int handle_external_interrupt(struct kvm_vcpu *vcpu)

static int handle_triple_fault(struct kvm_vcpu *vcpu)
{
- vcpu->run->exit_reason = KVM_EXIT_SHUTDOWN;
- vcpu->mmio_needed = 0;
+ kvm_prepare_shutdown_exit(vcpu);
return 0;
}

diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
index cf3fcdfd8ad2..cffd1b6ef789 100644
--- a/arch/x86/kvm/x86.c
+++ b/arch/x86/kvm/x86.c
@@ -8139,8 +8139,7 @@ static int vcpu_enter_guest(struct kvm_vcpu *vcpu)
kvm_nested_call(triple_fault)(vcpu);

if (kvm_check_request(KVM_REQ_TRIPLE_FAULT, vcpu)) {
- vcpu->run->exit_reason = KVM_EXIT_SHUTDOWN;
- vcpu->mmio_needed = 0;
+ kvm_prepare_shutdown_exit(vcpu);
r = 0;
goto out;
}
diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h
index a836756baebb..02ca5d5d83b5 100644
--- a/include/linux/kvm_host.h
+++ b/include/linux/kvm_host.h
@@ -2522,6 +2522,14 @@ static inline void kvm_account_pgtable_pages(void *virt, int nr)
/* Max number of entries allowed for each kvm dirty ring */
#define KVM_DIRTY_RING_MAX_ENTRIES 65536

+static inline void kvm_prepare_shutdown_exit(struct kvm_vcpu *vcpu)
+{
+ vcpu->run->exit_reason = KVM_EXIT_SHUTDOWN;
+#ifdef CONFIG_HAS_IOMEM
+ vcpu->mmio_needed = 0;
+#endif
+}
+
static inline void kvm_prepare_memory_fault_exit(struct kvm_vcpu *vcpu,
gpa_t gpa, gpa_t size,
bool is_write, bool is_exec,
--
2.56.0.rc1.315.gc6ed9934b7-goog