]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode
authorYosry Ahmed <yosry@kernel.org>
Tue, 24 Feb 2026 22:50:17 +0000 (22:50 +0000)
committerSean Christopherson <seanjc@google.com>
Mon, 2 Mar 2026 23:58:19 +0000 (15:58 -0800)
On nested VMRUN, KVM ensures AVIC is inhibited by requesting
KVM_REQ_APICV_UPDATE, triggering a check of inhibit reasons, finding
APICV_INHIBIT_REASON_NESTED, and disabling AVIC.

However, when KVM_SET_NESTED_STATE is performed on a vCPU not in guest
mode with AVIC enabled, KVM_REQ_APICV_UPDATE is not requested, and AVIC
is not inhibited.

Request KVM_REQ_APICV_UPDATE in the KVM_SET_NESTED_STATE path if AVIC is
active, similar to the nested VMRUN path.

Fixes: f44509f849fe ("KVM: x86: SVM: allow AVIC to co-exist with a nested guest running")
Cc: stable@vger.kernel.org
Signed-off-by: Yosry Ahmed <yosry@kernel.org>
Link: https://patch.msgid.link/20260224225017.3303870-1-yosry@kernel.org
Signed-off-by: Sean Christopherson <seanjc@google.com>
arch/x86/kvm/svm/nested.c

index d5a8f5608f2d3ae7396b6254f840c3a33bb1b8e4..3667f8ba52682114da6720b6220ab8a2e82aa564 100644 (file)
@@ -1928,6 +1928,9 @@ static int svm_set_nested_state(struct kvm_vcpu *vcpu,
 
        svm->nested.force_msr_bitmap_recalc = true;
 
+       if (kvm_vcpu_apicv_active(vcpu))
+               kvm_make_request(KVM_REQ_APICV_UPDATE, vcpu);
+
        kvm_make_request(KVM_REQ_GET_NESTED_STATE_PAGES, vcpu);
        ret = 0;
 out_free: