Re: [RFC PATCH v3 02/27] x86/apic: Drop savic_eoi() in favor of native_apic_msr_eoi() for Secure AVIC

From: Naveen N Rao

Date: Thu Oct 08 2026 - 04:06:08 EST


On Mon, Oct 05, 2026 at 08:20:24PM -0700, Borislav Petkov wrote:
> On Wed, Jul 08, 2026 at 12:02:00PM +0530, Naveen N Rao (AMD) wrote:
> > Drop savic_eoi() in favor of using the native helper that writes to the
> > APIC_EOI MSR. savic_eoi() was added mainly to be able to handle
> > level-triggered interrupts. However, it relies on APIC_TMR indicating a
> > vector to be level-triggered, but APIC_TMR can never have a bit set
> > since it is only updated when the LAPIC accepts a level-triggered
> > interrupt. In the case of a Secure AVIC SEV-SNP guest, all
> > level-triggered interrupt sources are in the VMM (emulated IOAPIC
> > primarily) and KVM accepts them on behalf of the guest resulting in the
> > APIC_TMR in KVM APIC backing page having a bit set. This is never seen
> > by the guest, which has its own private APIC backing page. As such, the
> > savic_eoi() handler is dead code. Remove it.
>
> So this sounds to me like we forgot some detail while spec-cing SAVIC. Or
> maybe for SAVIC, KVM should not accept them on behalf of the guest anymore.
> But what do I know...

There were some changes proposed for KVM previously around this:
https://lore.kernel.org/kvm/20250923050317.205482-14-Neeraj.Upadhyay@xxxxxxx/

The idea was to have KVM track the injected level-triggered interrupt in
its copy of APIC_ISR so that it can issue EOI to the I/O APIC properly.

However, this would require some guest changes at least. Either:
- issuing a VMGEXIT on each EOI (regardless of APIC_TMR in the guest
backing page), or
- tracking level-triggered vectors in the guest and issuing a VMGEXIT on
EOI only for those.

The former is problematic since guests can queue IPIs themselves, so it
isn't always possible to ensure EOI exits correspond to a previously
injected I/O APIC interrupt. For the latter, guest will need to do more
work to track and issue EOI accurately. Doable, I think, but it isn't
clear to me that this is worthwhile, especially for modern SEV-SNP
guests with Secure AVIC support.

>
> Btw, In the future, pls split such conglomerate commit messages into paragraphs for
> better/easier readability.

Sure.


Thanks,
Naveen