Re: [PATCH v5 3/6] KVM: x86: ioapic: Preserve irr_delivered for duplicate edge interrupts

Hao Zhang <[email protected]>
Newsgroups dev.linux.lists.sashiko-reviews,org.kernel.vger.kvm
Message-ID <[email protected]>
On Wed, Aug 12, 2026, [email protected] wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] KVM's IOAPIC fails to latch edge-triggered interrupts if they pulse while the pin is masked, and fails to deliver latched edge-triggered interrupts upon unmasking.
> --
> 
> --- Patch [3]: [PATCH v5 3/6] KVM: x86: ioapic: Preserve irr_delivered for duplicate edge interrupts ---
> commit 691f4f74cce4e2c3436bc9f3cdf594c985c284e3
> Author: Hao Zhang <[email protected]>
> 
> KVM: x86: ioapic: Preserve irr_delivered for duplicate edge interrupts
> 
> For edge-triggered interrupts, ioapic_set_irq() clears irr_delivered before
> checking whether the new edge is a duplicate. This patch moves the state
> update after the duplicate-edge check to prevent duplicate edges from making
> a delivered interrupt appear pending during VM migration.
> 
> > diff --git a/arch/x86/kvm/ioapic.c b/arch/x86/kvm/ioapic.c
> > index 24a7cc3b8b7ef..676effd674f9e 100644
> > --- a/arch/x86/kvm/ioapic.c
> > +++ b/arch/x86/kvm/ioapic.c
> > @@ -230,11 +230,11 @@ static int ioapic_set_irq(struct kvm_ioapic *ioapic, unsigned int irq,
> 
> [Severity: High]
> This isn't a bug introduced by this patch, but while reviewing
> ioapic_set_irq(), does KVM fail to latch edge-triggered interrupts if they
> pulse while the pin is masked?
>
> Earlier in ioapic_set_irq(), the IRR bit is cleared unconditionally when the
> pin goes low:
> 
> 	if (!irq_level) {
> 		ioapic->irr &= ~mask;
> 		ret = 1;
> 		goto out;
> 	}
> 
> This appears to destroy the latch state for edge-triggered interrupts that
> were not yet delivered.
> 
> Furthermore, looking at ioapic_write_indirect(), when unmasking, pending
> interrupt injection is restricted only to level-triggered interrupts:
> 
> 		if (e->fields.trig_mode == IOAPIC_LEVEL_TRIG &&
> 		    ioapic->irr & (1 << index) && !e->fields.mask && !e->fields.remote_irr) {
> 
> Could this sequence cause latched edge-triggered interrupts to be silently
> ignored and lost if a guest temporarily masks IOAPIC pins during interrupt
> handling?
>

Sashiko seems to assume that an edge-triggered interrupt which is signaled
while the IOAPIC RTE is masked must remain latched and then be delivered when
the RTE is unmasked.

However, the Intel 82093AA I/O Advanced Programmable Interrupt Controller datasheet
(https://pdos.csail.mit.edu/6.828/2018/readings/ia32/ioapic.pdf) states that 
edge-sensitive interrupts signaled on a masked interrupt pin are ignored, 
i.e. they are not delivered or held pending.

KVM's userspace ABI (https://www.kernel.org/doc/html/v6.12/virt/kvm/api.html#kvm-irq-line) 
also represents an edge interrupt as a pulse, by asserting the line and then deasserting 
it. If that complete pulse occurs while the RTE is masked, there is no pending edge that 
needs to be delivered on unmask.

This is also separate from this patch. The patch only preserves irr_delivered
for a duplicate edge interrupt that is coalesced after a previous edge has
already been delivered, so that KVM_GET_IRQCHIP does not expose the delivered
edge interrupt as pending.

> >  	old_irr = ioapic->irr;
> >  	ioapic->irr |= mask;
> >  	if (edge) {
> > -		ioapic->irr_delivered &= ~mask;
> >  		if (old_irr == ioapic->irr) {
> >  			ret = 0;
> >  			goto out;
> >  		}
> > +		ioapic->irr_delivered &= ~mask;
> >  	}
> >  
> >  	ret = ioapic_service(ioapic, irq, line_status);
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/[email protected]?part=3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.