x86 fixes:

- Fix preemption bugs in the SVSM vTPM guest implementation
    (Melody Wang)
 
  - Fix MCE-triggered hardware debug register corruption on
    task migration (Masami Hiramatsu)
 
 Signed-off-by: Ingo Molnar <mingo@kernel.org>
 -----BEGIN PGP SIGNATURE-----
 
 iQJFBAABCgAvFiEEBpT5eoXrXCwVQwEKEnMQ0APhK1gFAmq4zuYRHG1pbmdvQGtl
 cm5lbC5vcmcACgkQEnMQ0APhK1iXThAAsqCXcDx+RNrPihj8j4G7qLBx5P7q+8I0
 HQ+LWhdIp/wEOSYVUk4GOX4r13bPg1S6BZl9YZlcV8A5uspQdK9hBvVjH+5g21ZH
 0GTepgxQs+OawPHWRPrRAmV8HvKKFvnqdDqCor7/HZgiW5aLozfA5+9EmzHcjUHZ
 emAWP6gnbliqJLyOHwbMCHSXnPywYaIBwGFAzWiXdkQzCu/SHvkeoQ0xyvCM+aoE
 cWGJD6S3MgvUOEtEQGpPNISpyXHRrorfNd3Km2ypzpoNbkYoompVW64+RkGUlHJH
 CmRyP/dK5h4Y0NhE8dZH3gn1FjvjPXT399vwkShYpc4LRLcGnLwk6cpVb4DHKwDG
 PUQSkV3akXuL/CndoMMcC7HYsYLriC02wiAYKLQGBM+q9O61iLhJin4f/5tvY219
 olyU40sPienXzFS+stenFoN46NuVq5tx7+1qURcO1kE8c2dohAixnJ/PVvl/zJCx
 +RSKQcW8rONn0aptg9RkKqlKxERpf0hIUCuNfOUmlcTG9q8zpCOkkfwGZ8LHoOFE
 P/FQ5uRAy9IF3egl+BUGOPLVlekJ3VxY6Vh6GPP1DwbUQqFoiEMYsfsW5jSgJcfN
 zP72bSSx9dKoPfI6dpDN1tUHFDFEsYU0hFWhfn5+Bo1LJdp1s6LZqRzDc4PSXtla
 RNrDnMS31sc=
 =1sLJ
 -----END PGP SIGNATURE-----

Merge tag 'x86-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip

Pull x86 fixes from Ingo Molnar:

 - Fix preemption bugs in the SVSM vTPM guest implementation
   (Melody Wang)

 - Fix MCE-triggered hardware debug register corruption on
   task migration (Masami Hiramatsu)

* tag 'x86-urgent-2026-09-27' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
  x86/mce: Fix hardware debug register corruption on task migration
  x86/sev: Make vTPM SVSM calls preemption-safe
This commit is contained in:
Linus Torvalds 2026-09-27 08:44:12 -07:00
commit efb44d93a6
2 changed files with 18 additions and 19 deletions

View File

@ -74,6 +74,14 @@ int svsm_perform_call_protocol(struct svsm_call *call)
flags = native_local_irq_save();
/*
* 'caa' is a per-CPU variable. To avoid using a stale or incorrect
* 'caa' if the task is preempted or migrated to another CPU after it
* is fetched, always fetch 'caa' and then issue the SVSM call with
* interrupts disabled. This ensures the correct 'caa' is used.
*/
call->caa = svsm_get_caa();
ghcb = __sev_get_ghcb(&state);
do {
@ -321,7 +329,6 @@ int snp_svsm_vtpm_send_command(u8 *buffer)
{
struct svsm_call call = {};
call.caa = svsm_get_caa();
call.rax = SVSM_VTPM_CALL(SVSM_VTPM_CMD);
call.rcx = __pa(buffer);
@ -345,7 +352,6 @@ bool snp_svsm_vtpm_probe(void)
if (!snp_vmpl)
return false;
call.caa = svsm_get_caa();
call.rax = SVSM_VTPM_CALL(SVSM_VTPM_QUERY);
if (svsm_perform_call_protocol(&call))

View File

@ -2108,6 +2108,9 @@ bool filter_mce(struct mce *m)
static __always_inline void exc_machine_check_kernel(struct pt_regs *regs)
{
irqentry_state_t irq_state;
unsigned long dr7;
dr7 = local_db_save();
WARN_ON_ONCE(user_mode(regs));
@ -2116,20 +2119,26 @@ static __always_inline void exc_machine_check_kernel(struct pt_regs *regs)
* mce_check_crashing_cpu() for details.
*/
if (mca_cfg.initialized && mce_check_crashing_cpu())
return;
goto out;
irq_state = irqentry_nmi_enter(regs);
do_machine_check(regs);
irqentry_nmi_exit(regs, irq_state);
out:
local_db_restore(dr7);
}
static __always_inline void exc_machine_check_user(struct pt_regs *regs)
{
unsigned long dr7;
irqentry_enter_from_user_mode(regs);
dr7 = local_db_save();
do_machine_check(regs);
local_db_restore(dr7);
irqentry_exit_to_user_mode(regs);
}
@ -2138,21 +2147,13 @@ static __always_inline void exc_machine_check_user(struct pt_regs *regs)
/* MCE hit kernel mode */
DEFINE_IDTENTRY_MCE(exc_machine_check)
{
unsigned long dr7;
dr7 = local_db_save();
exc_machine_check_kernel(regs);
local_db_restore(dr7);
}
/* The user mode variant. */
DEFINE_IDTENTRY_MCE_USER(exc_machine_check)
{
unsigned long dr7;
dr7 = local_db_save();
exc_machine_check_user(regs);
local_db_restore(dr7);
}
#ifdef CONFIG_X86_FRED
@ -2169,28 +2170,20 @@ DEFINE_IDTENTRY_MCE_USER(exc_machine_check)
*/
DEFINE_FREDENTRY_MCE(exc_machine_check)
{
unsigned long dr7;
dr7 = local_db_save();
if (user_mode(regs))
exc_machine_check_user(regs);
else
exc_machine_check_kernel(regs);
local_db_restore(dr7);
}
#endif
#else
/* 32bit unified entry point */
DEFINE_IDTENTRY_RAW(exc_machine_check)
{
unsigned long dr7;
dr7 = local_db_save();
if (user_mode(regs))
exc_machine_check_user(regs);
else
exc_machine_check_kernel(regs);
local_db_restore(dr7);
}
#endif