* [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
@ 2026-10-05 5:03 Fuad Tabba
2026-10-05 8:30 ` Marc Zyngier
2026-10-05 8:30 ` Oliver Upton
0 siblings, 2 replies; 4+ messages in thread
From: Fuad Tabba @ 2026-10-05 5:03 UTC (permalink / raw)
To: maz, oupton, kvmarm, linux-arm-kernel, linux-kernel
Cc: catalin.marinas, will, joey.gouly, seiden, suzuki.poulose,
yuzenghui, vdonnefort, qperret, tabba, mark.rutland
kvm_inject_serror_esr() reads PSTATE.A and SCTLR2_EL1.NMEA to decide
whether to emulate the SError's exception entry or pend it through
HCR_EL2.VSE. For a protected vCPU, the host's copy of those is stale,
and when it reads as unmasked KVM emulates the entry on that copy. EL2
never delivers it as an SError: its entry handler turns the pending
exception into an external abort on the trapped access, and an MMIO
completion still pending trips WARN_ON(INCREMENT_PC).
Always pend through HCR_EL2.VSE for a protected vCPU. EL2 forwards it,
and the guest's own masking decides when the SError is taken.
Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---
Applies on kvmarm/next. A follow-up to "KVM: arm64: Confine protected VM
vCPU state to EL2" [1], from Sashiko's review of its v4 patch 12.
[1] https://lore.kernel.org/all/20261001135711.1640520-1-fuad.tabba@linux.dev/
arch/arm64/kvm/inject_fault.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
index d6c4fc16f8795..49a342b078365 100644
--- a/arch/arm64/kvm/inject_fault.c
+++ b/arch/arm64/kvm/inject_fault.c
@@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
*
* As we're emulating the SError injection we need to explicitly populate
* ESR_ELx.EC because hardware will not do it on our behalf.
+ *
+ * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
+ * HCR_EL2.VSE and let the guest's own masking apply.
*/
- if (!serror_is_masked(vcpu)) {
+ if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
pend_serror_exception(vcpu);
esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));
base-commit: fa22cd9947fc245d71bc40482f7f78eb0d5a4af0
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
2026-10-05 5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
@ 2026-10-05 8:30 ` Marc Zyngier
2026-10-05 8:30 ` Oliver Upton
1 sibling, 0 replies; 4+ messages in thread
From: Marc Zyngier @ 2026-10-05 8:30 UTC (permalink / raw)
To: Fuad Tabba
Cc: oupton, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
qperret, tabba, mark.rutland
On Mon, 05 Oct 2026 06:03:52 +0100,
Fuad Tabba <fuad.tabba@linux.dev> wrote:
>
> kvm_inject_serror_esr() reads PSTATE.A and SCTLR2_EL1.NMEA to decide
> whether to emulate the SError's exception entry or pend it through
> HCR_EL2.VSE. For a protected vCPU, the host's copy of those is stale,
> and when it reads as unmasked KVM emulates the entry on that copy. EL2
> never delivers it as an SError: its entry handler turns the pending
> exception into an external abort on the trapped access, and an MMIO
> completion still pending trips WARN_ON(INCREMENT_PC).
>
> Always pend through HCR_EL2.VSE for a protected vCPU. EL2 forwards it,
> and the guest's own masking decides when the SError is taken.
>
> Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
> ---
> Applies on kvmarm/next. A follow-up to "KVM: arm64: Confine protected VM
> vCPU state to EL2" [1], from Sashiko's review of its v4 patch 12.
>
> [1] https://lore.kernel.org/all/20261001135711.1640520-1-fuad.tabba@linux.dev/
>
> arch/arm64/kvm/inject_fault.c | 5 ++++-
> 1 file changed, 4 insertions(+), 1 deletion(-)
>
> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> index d6c4fc16f8795..49a342b078365 100644
> --- a/arch/arm64/kvm/inject_fault.c
> +++ b/arch/arm64/kvm/inject_fault.c
> @@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
> *
> * As we're emulating the SError injection we need to explicitly populate
> * ESR_ELx.EC because hardware will not do it on our behalf.
> + *
> + * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
> + * HCR_EL2.VSE and let the guest's own masking apply.
> */
> - if (!serror_is_masked(vcpu)) {
> + if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
> pend_serror_exception(vcpu);
> esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
> vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));
>
I thought we had discussed that one before (or am I making things
up?). Why can't the host always evaluate serror_is_masked() as true?
Given that PSTATE is never synced back to the host, it would only be a
matter of set PSTATE.A==1 at vcpu creation time.
It'd be more palatable than this sprinkling of vcpu_is_protected(),
which really do not scale.
Thanks,
M.
--
Jazz isn't dead. It just smells funny.
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
2026-10-05 5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
2026-10-05 8:30 ` Marc Zyngier
@ 2026-10-05 8:30 ` Oliver Upton
2026-10-05 10:34 ` Fuad Tabba
1 sibling, 1 reply; 4+ messages in thread
From: Oliver Upton @ 2026-10-05 8:30 UTC (permalink / raw)
To: Fuad Tabba
Cc: maz, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
qperret, tabba, mark.rutland
Hi Fuad,
On Mon, Oct 05, 2026 at 06:03:52AM +0100, Fuad Tabba wrote:
> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> index d6c4fc16f8795..49a342b078365 100644
> --- a/arch/arm64/kvm/inject_fault.c
> +++ b/arch/arm64/kvm/inject_fault.c
> @@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
> *
> * As we're emulating the SError injection we need to explicitly populate
> * ESR_ELx.EC because hardware will not do it on our behalf.
> + *
> + * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
> + * HCR_EL2.VSE and let the guest's own masking apply.
> */
> - if (!serror_is_masked(vcpu)) {
> + if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
> pend_serror_exception(vcpu);
> esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
> vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));
The emulated injection is only necessary when vcpu_has_nv(), it was just
convenient for the sake of testing that everything short circuits to
emulation instead of VSE.
I see Marc suggests letting the stale PSTATE.A value force the desired
behavior which seems fine to me. If that doesn't work, I'd rather
emulated injection be predicated on vcpu_has_nv() than
vcpu_is_protected() with the appropriate rephrasing of the preceding
comment.
Thanks,
Oliver
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
2026-10-05 8:30 ` Oliver Upton
@ 2026-10-05 10:34 ` Fuad Tabba
0 siblings, 0 replies; 4+ messages in thread
From: Fuad Tabba @ 2026-10-05 10:34 UTC (permalink / raw)
To: Oliver Upton
Cc: maz, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
qperret, mark.rutland
Hi Marc, Oliver,
On Mon, 05 Oct 2026 09:30:39 +0100, Marc Zyngier <maz@kernel.org> wrote:
[...]
> I thought we had discussed that one before (or am I making things
> up?). Why can't the host always evaluate serror_is_masked() as true?
> Given that PSTATE is never synced back to the host, it would only be a
> matter of set PSTATE.A==1 at vcpu creation time.
>
> It'd be more palatable than this sprinkling of vcpu_is_protected(),
> which really do not scale.
Yes, it's better for the host to always see SErrors as masked. v2 will
do that when the hyp vCPU is created, and leave
kvm_inject_serror_esr() alone.
Cheers,
/fuad
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-05 10:35 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05 5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
2026-10-05 8:30 ` Marc Zyngier
2026-10-05 8:30 ` Oliver Upton
2026-10-05 10:34 ` Fuad Tabba
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®