From: Fuad Tabba <fuad.tabba@linux.dev>
To: Marc Zyngier <maz@kernel.org>, Oliver Upton <oupton@kernel.org>,
kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org
Cc: Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Steffen Eiden <seiden@linux.ibm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>,
Mark Rutland <mark.rutland@arm.com>,
Quentin Perret <qperret@google.com>,
Vincent Donnefort <vdonnefort@google.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Venkata Rao Kakani <venkata.kakani@oss.qualcomm.com>,
Fuad Tabba <tabba@google.com>,
linux-kernel@vger.kernel.org
Subject: [PATCH v3 0/4] KVM: arm64: Fix HCR_EL2 for non-protected VMs in pKVM
Date: Tue, 29 Sep 2026 10:00:27 +0100 [thread overview]
Message-ID: <20260929090031.3829185-1-fuad.tabba@linux.dev> (raw)
Hi folks,
Changes since v2 [1]:
- Patch 1: apply the FGUs on a CPU without FEAT_FGT instead of moving
the check in handle_tlbi_el1() (Oliver [2]). Wei-Lin's Reviewed-by
dropped with the rewrite.
In pKVM, EL2 sets a non-protected VM's HCR_EL2 in pkvm_vcpu_reset_hcr(),
which misses the RW, TID5 and TTLBOS handling of vcpu_set_hcr(), and
takes only TWI, TWE and VSE from the host. As a result, an AArch32 VM
can't run, a VM can read GMID_EL1 or execute a TLBI OS its ID registers
hide, and the host's TVM, VI and VF never reach it.
The second patch clears RW for an AArch32 vCPU. The third also takes
from the host, for a non-protected VM, the bits the host varies with the
VM's configuration or at runtime: VI, VF, TVM, TID2, TID4, TID5 and
TTLBOS. The rest stay EL2's, and a protected VM still takes only TWI,
TWE and VSE.
The third patch depends on the first: once TTLBOS reaches the VM, a
trapped TLBI OS from a non-nested guest on a CPU without FEAT_FGT hits
a WARN in handle_tlbi_el1(), as it does without pKVM. The first makes
the FGUs apply on such a CPU too, so the access is UNDEFINED before it
reaches handle_tlbi_el1().
The last patch adds a selftest that checks a feature hidden in an ID
register is UNDEFINED in the guest. Its TLBI OS case fails in pKVM
before the third patch.
VSE still comes from the host as before. Syncing it back after delivery
is a separate fix [3].
Based on Linux 7.3-rc4 (93f51579e7df2).
Cheers,
/fuad
[1] https://lore.kernel.org/all/20260928064643.3265087-1-fuad.tabba@linux.dev/
[2] https://lore.kernel.org/all/arqeRSIoEwurSrya@kernel.org/
[3] https://lore.kernel.org/all/20260921101030.1231605-1-fuad.tabba@linux.dev/
Fuad Tabba (4):
KVM: arm64: Apply the fine-grained UNDEFs without FEAT_FGT
KVM: arm64: Clear HCR_EL2.RW for 32-bit non-protected vCPUs
KVM: arm64: Use the host's HCR_EL2 for non-protected VMs in pKVM
KVM: arm64: selftests: Check a feature hidden in an ID register is
UNDEF
arch/arm64/kvm/emulate-nested.c | 3 -
arch/arm64/kvm/hyp/include/nvhe/pkvm.h | 9 +
arch/arm64/kvm/hyp/nvhe/hyp-main.c | 7 +-
arch/arm64/kvm/hyp/nvhe/pkvm.c | 25 ++-
tools/testing/selftests/kvm/Makefile.kvm | 1 +
.../selftests/kvm/arm64/hidden_features.c | 184 ++++++++++++++++++
6 files changed, 214 insertions(+), 15 deletions(-)
create mode 100644 tools/testing/selftests/kvm/arm64/hidden_features.c
base-commit: 93f51579e7df248780214094418f205253383cc5
--
2.39.5
next reply other threads:[~2026-09-29 9:00 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 9:00 Fuad Tabba [this message]
2026-09-29 9:00 ` [PATCH v3 1/4] KVM: arm64: Apply the fine-grained UNDEFs without FEAT_FGT Fuad Tabba
2026-09-29 14:54 ` Wei-Lin Chang
2026-09-29 15:10 ` Fuad Tabba
2026-09-29 9:00 ` [PATCH v3 2/4] KVM: arm64: Clear HCR_EL2.RW for 32-bit non-protected vCPUs Fuad Tabba
2026-09-29 9:00 ` [PATCH v3 3/4] KVM: arm64: Use the host's HCR_EL2 for non-protected VMs in pKVM Fuad Tabba
2026-09-29 9:00 ` [PATCH v3 4/4] KVM: arm64: selftests: Check a feature hidden in an ID register is UNDEF Fuad Tabba
2026-09-29 19:32 ` [PATCH v3 0/4] KVM: arm64: Fix HCR_EL2 for non-protected VMs in pKVM Oliver Upton
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929090031.3829185-1-fuad.tabba@linux.dev \
--to=fuad.tabba@linux.dev \
--cc=catalin.marinas@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=qperret@google.com \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vdonnefort@google.com \
--cc=venkata.kakani@oss.qualcomm.com \
--cc=weilin.chang@arm.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®