[PATCH v2 1/2] KVM: x86/mmu: Report a memory fault exit when the fault handler EFAULTs
From: mike . malyshev
Date: Sun Sep 20 2026 - 03:27:37 EST
From: Anish Moorthy <amoorthy@xxxxxxxxxx>
KVM_CAP_MEMORY_FAULT_INFO documents that KVM_RUN will fill
kvm_run.memory_fault when KVM cannot resolve a guest page fault VM-Exit,
"e.g. if there is a valid memslot but no backing VMA for the
corresponding host virtual address". kvm_handle_error_pfn() does not
honor that guarantee. It returns a bare -EFAULT, leaving userspace with
no indication of which guest physical address faulted, or even that the
exit was a memory fault at all. Userspace cannot distinguish a
transient, resolvable condition from a fatal one, so in practice the VMM
terminates the guest.
Fill kvm_run.memory_fault before returning -EFAULT.
A concrete user is an Intel integrated GPU assigned to a guest via
vfio-pci. The guest driver clears PCI_COMMAND.MEM on one vCPU while
another vCPU is mid-MMIO to a BAR of the same device. Clearing
PCI_COMMAND.MEM makes vfio-pci zap the BAR's mmap, so the second vCPU's
fault finds a valid memslot whose VMA can no longer supply a PFN, and
KVM_RUN fails with a bare -EFAULT. The VM dies, even though the guest
did nothing architecturally invalid and the condition clears as soon as
the driver re-enables memory decoding.
Reproduce by pairing a vCPU that spins on accesses to the assigned
device's BAR0 with a vCPU that toggles PCI_COMMAND.MEM; the race is hit
within minutes. The same crash has been observed in the field on
production edge hardware.
Reporting the fault does not by itself define the access semantics.
Userspace still has to decide what a read or write to a BAR with memory
decoding disabled returns. But it is the information userspace needs in
order to make that decision instead of killing the guest.
Suggested-by: Sean Christopherson <seanjc@xxxxxxxxxx>
Fixes: 16f95f3b95ca ("KVM: Add KVM_EXIT_MEMORY_FAULT exit to report faults to userspace")
Link: https://lore.kernel.org/all/20240809205158.1340255-1-amoorthy@xxxxxxxxxx/
Link: https://lore.kernel.org/all/Zr-8M9rYplgN6IS3@xxxxxxxxxx/
Signed-off-by: Anish Moorthy <amoorthy@xxxxxxxxxx>
Co-developed-by: Mikhail Malyshev <mike.malyshev@xxxxxxxxx>
Signed-off-by: Mikhail Malyshev <mike.malyshev@xxxxxxxxx>
---
arch/x86/kvm/mmu/mmu.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c
index 9788ff1803740..244575f576071 100644
--- a/arch/x86/kvm/mmu/mmu.c
+++ b/arch/x86/kvm/mmu/mmu.c
@@ -3616,6 +3616,7 @@ static int kvm_handle_error_pfn(struct kvm_vcpu *vcpu, struct kvm_page_fault *fa
return RET_PF_RETRY;
}
+ kvm_mmu_prepare_memory_fault_exit(vcpu, fault);
return -EFAULT;
}
--
2.43.0