Re: [PATCH v2 2/9] KVM: x86: Set guest DR6 by kvm_queue_exception_p() in instruction emulation
From: Sean Christopherson
Date: Mon May 11 2026 - 11:30:33 EST
On Thu, Dec 18, 2025, Hou Wenlong wrote:
> Record DR6 in emulate_db() and use kvm_queue_exception_p() to set DR6
> instead of directly using kvm_set_dr6() in emulation, which keeps the
> handling of DR6 during #DB injection consistent with other code paths.
>
> No functional change intended.
>
> Signed-off-by: Hou Wenlong <houwenlong.hwl@xxxxxxxxxxxx>
> ---
> arch/x86/kvm/emulate.c | 14 ++++----------
> arch/x86/kvm/kvm_emulate.h | 6 +++++-
> arch/x86/kvm/x86.c | 5 ++++-
> 3 files changed, 13 insertions(+), 12 deletions(-)
>
> diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
> index c8e292e9a24d..997cd6e46d90 100644
> --- a/arch/x86/kvm/emulate.c
> +++ b/arch/x86/kvm/emulate.c
> @@ -540,8 +540,9 @@ static int emulate_exception(struct x86_emulate_ctxt *ctxt, int vec,
> return X86EMUL_PROPAGATE_FAULT;
> }
>
> -static int emulate_db(struct x86_emulate_ctxt *ctxt)
> +static int emulate_db(struct x86_emulate_ctxt *ctxt, unsigned long dr6)
> {
> + ctxt->exception.dr6 = dr6;
> return emulate_exception(ctxt, DB_VECTOR, 0, false);
> }
>
> @@ -3834,15 +3835,8 @@ static int check_dr_read(struct x86_emulate_ctxt *ctxt)
> if ((cr4 & X86_CR4_DE) && (dr == 4 || dr == 5))
> return emulate_ud(ctxt);
>
> - if (ctxt->ops->get_dr(ctxt, 7) & DR7_GD) {
> - ulong dr6;
> -
> - dr6 = ctxt->ops->get_dr(ctxt, 6);
> - dr6 &= ~DR_TRAP_BITS;
> - dr6 |= DR6_BD | DR6_ACTIVE_LOW;
> - ctxt->ops->set_dr(ctxt, 6, dr6);
> - return emulate_db(ctxt);
> - }
> + if (ctxt->ops->get_dr(ctxt, 7) & DR7_GD)
> + return emulate_db(ctxt, DR6_BD);
>
> return X86EMUL_CONTINUE;
> }
> diff --git a/arch/x86/kvm/kvm_emulate.h b/arch/x86/kvm/kvm_emulate.h
> index fb3dab4b5a53..7fe38b174e18 100644
> --- a/arch/x86/kvm/kvm_emulate.h
> +++ b/arch/x86/kvm/kvm_emulate.h
> @@ -24,7 +24,11 @@ struct x86_exception {
> bool error_code_valid;
> u16 error_code;
> bool nested_page_fault;
> - u64 address; /* cr2 or nested page fault gpa */
> + union {
> + u64 address; /* cr2 or nested page fault gpa */
> + unsigned long dr6;
> + u64 payload;
Please split the introduction of the union to a separate patch, mainly so that
the effectively zeroing of ctxt.exception.address in init_emulate_ctxt() is
isolated, e.g. in case it somehow causes problems. But that will also allow
introducing the inject_emulated_exception() change separately from the
check_dr_read() change.
> + };
> u8 async_page_fault;
> unsigned long exit_qualification;
> };
> diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c
> index ab298bfa7d9f..f33ce947633e 100644
> --- a/arch/x86/kvm/x86.c
> +++ b/arch/x86/kvm/x86.c
> @@ -8925,7 +8925,9 @@ static void inject_emulated_exception(struct kvm_vcpu *vcpu)
> {
> struct x86_exception *ex = &vcpu->arch.emulate_ctxt->exception;
>
> - if (ex->vector == PF_VECTOR)
> + if (ex->vector == DB_VECTOR)
> + kvm_queue_exception_e(vcpu, DB_VECTOR, ex->dr6);
This should be kvm_queue_exception_p(). I also think pivoting on DB_VECTOR is
the wrong approach. Rather than key off the vector, add payload_valid (to match
error_code_valid), and then do:
struct x86_exception *ex = &vcpu->arch.emulate_ctxt->exception;
WARN_ON_ONCE(ex->vector != PF_VECTOR && ex->payload_valid &&
ex->error_code_valid);
if (ex->vector == PF_VECTOR)
kvm_inject_emulated_page_fault(vcpu, ex);
else if (ex->payload_valid)
kvm_queue_exception_p(vcpu, DB_VECTOR, ex->payload);
else if (ex->error_code_valid)
kvm_queue_exception_e(vcpu, ex->vector, ex->error_code);
else
kvm_queue_exception(vcpu, ex->vector);
PF_VECTOR is special because it has both an error code and a payload, and because
it needs additional handling on multiple fronts.
> + else if (ex->vector == PF_VECTOR)
> kvm_inject_emulated_page_fault(vcpu, ex);
> else if (ex->error_code_valid)
> kvm_queue_exception_e(vcpu, ex->vector, ex->error_code);
> @@ -8970,6 +8972,7 @@ static void init_emulate_ctxt(struct kvm_vcpu *vcpu)
> ctxt->interruptibility = 0;
> ctxt->have_exception = false;
> ctxt->exception.vector = -1;
> + ctxt->exception.payload = 0;
> ctxt->perm_ok = false;
>
> init_decode_cache(ctxt);
> --
> 2.31.1
>