diff mbox

Bug#707257: linux-image-3.8-1-686-pae: KVM crashes with "entry failed, hardware error 0x80000021"

Message ID 20130624123049.GH18508@redhat.com (mailing list archive)
State New, archived
Headers show

Commit Message

Gleb Natapov June 24, 2013, 12:30 p.m. UTC
On Mon, Jun 24, 2013 at 01:59:34PM +0200, Stefan Pietsch wrote:
> On 24.06.2013 13:47, Gleb Natapov wrote:
> > On Mon, Jun 24, 2013 at 01:43:26PM +0200, Stefan Pietsch wrote:
> >> On 23.06.2013 19:36, Gleb Natapov wrote:
> >>> On Sun, Jun 23, 2013 at 06:51:30PM +0200, Stefan Pietsch wrote:
> >>>> On 23.06.2013 09:51, Gleb Natapov wrote:
> >>>>> On Thu, Jun 20, 2013 at 07:01:49PM +0200, Stefan Pietsch wrote:
> >>>>>>> Can you provide the output of 25391454e73e3156202264eb3c473825afe4bc94
> >>>>>>> and emulate_invalid_guest_state=0. Also run "x/20i $pc-20" in qemu
> >>>>>>> monitor after the hang.
> >>>>>>
> >>>>>>
> >>>>>> 25391454e73e3156202264eb3c473825afe4bc94
> >>>>>>  emulate_invalid_guest_state=0
> >>>>>>
> >>>>> Very interesting. Looks like somewhere during TPR access FS
> >>>>> register gets corrupted. Can you remove /usr/share/kvm/kvmvapic.bin
> >>>>> and try again? This will disable some code paths during TPR access and
> >>>>> will narrow down the issue.
> >>>>
> >>>>
> >>>> Doing this, qemu complains
> >>>> "Could not open option rom 'kvmvapic.bin': No such file or directory",
> >>>> but the virtual machine boots successful with
> >>>> emulate_invalid_guest_state=0 and emulate_invalid_guest_state=1.
> >>>>
> >>> Hmm, I think we ate close. Can you try with upstream qemu?
> >>>
> >>>> kvmvapic.bin comes with Debian package "seabios 1.7.2-3".
> >>
> >> I already tried this with the Debian package qemu-kvm 1.5.0+dfsg-4.
> > And it didn't work? Mind trying some debug kernel patches? I suspect
> > your CPU does something no CPU I have do, so I want to verify it.
> 
> 
> As soon as I remove "kvmvapic.bin" the virtual machine boots with
> qemu-kvm 1.5.0. I just verified this with Linux kernel 3.10.0-rc5.
> "emulate_invalid_guest_state=0" or "emulate_invalid_guest_state=1" make
> no difference.
> 
> Please send your patches.
Here it is, run with it and kvmvapic.bin present. See what is printed in
dmesg after the failure.


--
			Gleb.
--
To unsubscribe from this list: send the line "unsubscribe kvm" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Comments

Stefan Pietsch June 24, 2013, 8:42 p.m. UTC | #1
On 24.06.2013 14:30, Gleb Natapov wrote:
> On Mon, Jun 24, 2013 at 01:59:34PM +0200, Stefan Pietsch wrote:
>> As soon as I remove "kvmvapic.bin" the virtual machine boots with
>> qemu-kvm 1.5.0. I just verified this with Linux kernel 3.10.0-rc5.
>> "emulate_invalid_guest_state=0" or "emulate_invalid_guest_state=1" make
>> no difference.
>>
>> Please send your patches.
> Here it is, run with it and kvmvapic.bin present. See what is printed in
> dmesg after the failure.
> 
> 
> diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c
> index f4a5b3f..65488a4 100644
> --- a/arch/x86/kvm/vmx.c
> +++ b/arch/x86/kvm/vmx.c
> @@ -3385,6 +3385,7 @@ static void vmx_get_segment(struct kvm_vcpu *vcpu,
>  {
>  	struct vcpu_vmx *vmx = to_vmx(vcpu);
>  	u32 ar;
> +	unsigned long rip;
>  
>  	if (vmx->rmode.vm86_active && seg != VCPU_SREG_LDTR) {
>  		*var = vmx->rmode.segs[seg];
> @@ -3408,6 +3409,9 @@ static void vmx_get_segment(struct kvm_vcpu *vcpu,
>  	var->db = (ar >> 14) & 1;
>  	var->g = (ar >> 15) & 1;
>  	var->unusable = (ar >> 16) & 1;
> +	rip = kvm_rip_read(vcpu);
> +	if ((rip == 0xc101611c || rip == 0xc101611a) && seg == VCPU_SREG_FS)
> +		printk("base=%p limit=%p selector=%x ar=%x\n", var->base, var->limit, var->selector, ar);
>  }
>  
>  static u64 vmx_get_segment_base(struct kvm_vcpu *vcpu, int seg)


Booting kernel Linux 3.10-rc5 with your patch applied produces these
messages in dmesg when starting a virtual machine:

emulate_invalid_guest_state=0
[  118.732151] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  118.732341] base=ffff0000 limit=  (null) selector=f0000fff ar=0

emulate_invalid_guest_state=1
[  196.481653] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481700] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481706] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481711] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481716] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481720] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481725] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481730] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481735] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481739] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.481777] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482068] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482073] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482079] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482084] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482131] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482136] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482142] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482146] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482193] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482198] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482203] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482208] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482255] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482259] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482265] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482269] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482316] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482321] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482326] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482331] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482378] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482382] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482388] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482392] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482439] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482444] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482449] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482454] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482501] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482505] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482511] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482516] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482562] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482567] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482573] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.482577] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483137] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483142] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483147] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483152] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483712] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483716] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483722] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.483727] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484321] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484326] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484333] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484337] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484897] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484901] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484907] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.484911] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.487824] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.487830] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.487836] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.487841] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.488842] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.488847] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.488853] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.488858] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.489416] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.489420] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.489426] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.489431] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490052] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490057] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490062] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490067] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490148] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490152] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490158] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490162] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490262] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490266] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490272] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.490277] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529018] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529025] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529032] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529036] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529099] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529103] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529109] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529114] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529219] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529223] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529229] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529234] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529353] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529357] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529363] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529367] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529407] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529412] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529417] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529422] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529621] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529625] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529631] base=ffff0000 limit=  (null) selector=f0000fff ar=0
[  196.529636] base=ffff0000 limit=  (null) selector=f0000fff ar=0

--
To unsubscribe from this list: send the line "unsubscribe kvm" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
diff mbox

Patch

diff --git a/arch/x86/kvm/vmx.c b/arch/x86/kvm/vmx.c
index f4a5b3f..65488a4 100644
--- a/arch/x86/kvm/vmx.c
+++ b/arch/x86/kvm/vmx.c
@@ -3385,6 +3385,7 @@  static void vmx_get_segment(struct kvm_vcpu *vcpu,
 {
 	struct vcpu_vmx *vmx = to_vmx(vcpu);
 	u32 ar;
+	unsigned long rip;
 
 	if (vmx->rmode.vm86_active && seg != VCPU_SREG_LDTR) {
 		*var = vmx->rmode.segs[seg];
@@ -3408,6 +3409,9 @@  static void vmx_get_segment(struct kvm_vcpu *vcpu,
 	var->db = (ar >> 14) & 1;
 	var->g = (ar >> 15) & 1;
 	var->unusable = (ar >> 16) & 1;
+	rip = kvm_rip_read(vcpu);
+	if ((rip == 0xc101611c || rip == 0xc101611a) && seg == VCPU_SREG_FS)
+		printk("base=%p limit=%p selector=%x ar=%x\n", var->base, var->limit, var->selector, ar);
 }
 
 static u64 vmx_get_segment_base(struct kvm_vcpu *vcpu, int seg)