* [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV
@ 2026-10-07 8:08 Fuad Tabba
2026-10-07 8:41 ` Oliver Upton
2026-10-07 12:08 ` Marc Zyngier
0 siblings, 2 replies; 3+ messages in thread
From: Fuad Tabba @ 2026-10-07 8:08 UTC (permalink / raw)
To: Marc Zyngier, Oliver Upton, kvmarm, linux-arm-kernel, linux-kernel
Cc: Catalin Marinas, Will Deacon, Joey Gouly, Steffen Eiden,
Suzuki K Poulose, Zenghui Yu, Vincent Donnefort, Quentin Perret,
Mark Rutland, Fuad Tabba
kvm_inject_serror_esr() emulates an SError's exception entry when the
host's copy of PSTATE says SErrors are unmasked, although only NV needs
this, for a nested context whose guest hypervisor owns the vSError. A
protected vCPU's PSTATE lives at EL2, and the VMM can unmask SErrors in
the host's copy before the first run, so KVM emulates the entry on that
copy and the guest never takes the SError.
Emulate the entry only for a vCPU with NV, which protected VMs don't
support, and otherwise pend the SError through HCR_EL2.VSE, as KVM did
before commit ce66109cec867 ("KVM: arm64: nv: Take "masked" aborts to
EL2 when HCRX_EL2.TMEA is set").
Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
Suggested-by: Oliver Upton <oupton@kernel.org>
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---
v3:
- Gate the emulated entry in kvm_inject_serror_esr() on vcpu_has_nv(),
instead of masking SErrors in the host copy at first run (Oliver).
v2:
- Set PSTATE.A and clear SCTLR2_EL1.NMEA in the host copy when the hyp
vCPU is created, instead of testing vcpu_is_protected() in
kvm_inject_serror_esr() (Marc).
Applies on kvmarm/next. A follow-up to "KVM: arm64: Confine protected VM
vCPU state to EL2" [1], from Sashiko's review of its v4 patch 12.
v2: https://lore.kernel.org/r/20261006092826.2201763-1-fuad.tabba@linux.dev/
v1: https://lore.kernel.org/r/20261005050352.836980-1-fuad.tabba@linux.dev/
[1] https://lore.kernel.org/all/20261001135711.1640520-1-fuad.tabba@linux.dev/
arch/arm64/kvm/inject_fault.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
index d6c4fc16f8795..96bf926ca520e 100644
--- a/arch/arm64/kvm/inject_fault.c
+++ b/arch/arm64/kvm/inject_fault.c
@@ -371,15 +371,15 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
}
/*
- * Emulate the exception entry if SErrors are unmasked. This is useful if
- * the vCPU is in a nested context w/ vSErrors enabled then we've already
- * delegated he hardware vSError context (i.e. HCR_EL2.VSE, VSESR_EL2,
- * VDISR_EL2) to the guest hypervisor.
+ * With NV, emulate the exception entry if SErrors are unmasked: in a
+ * nested context with vSErrors enabled, the hardware vSError context
+ * (i.e. HCR_EL2.VSE, VSESR_EL2, VDISR_EL2) is delegated to the guest
+ * hypervisor. Otherwise, HCR_EL2.VSE delivers it once it is unmasked.
*
* As we're emulating the SError injection we need to explicitly populate
* ESR_ELx.EC because hardware will not do it on our behalf.
*/
- if (!serror_is_masked(vcpu)) {
+ if (vcpu_has_nv(vcpu) && !serror_is_masked(vcpu)) {
pend_serror_exception(vcpu);
esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));
--
2.39.5
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV
2026-10-07 8:08 [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV Fuad Tabba
@ 2026-10-07 8:41 ` Oliver Upton
2026-10-07 12:08 ` Marc Zyngier
1 sibling, 0 replies; 3+ messages in thread
From: Oliver Upton @ 2026-10-07 8:41 UTC (permalink / raw)
To: Fuad Tabba
Cc: Marc Zyngier, kvmarm, linux-arm-kernel, linux-kernel,
Catalin Marinas, Will Deacon, Joey Gouly, Steffen Eiden,
Suzuki K Poulose, Zenghui Yu, Vincent Donnefort, Quentin Perret,
Mark Rutland, Fuad Tabba
On Wed, Oct 07, 2026 at 09:08:33AM +0100, Fuad Tabba wrote:
> kvm_inject_serror_esr() emulates an SError's exception entry when the
> host's copy of PSTATE says SErrors are unmasked, although only NV needs
> this, for a nested context whose guest hypervisor owns the vSError. A
> protected vCPU's PSTATE lives at EL2, and the VMM can unmask SErrors in
> the host's copy before the first run, so KVM emulates the entry on that
> copy and the guest never takes the SError.
>
> Emulate the entry only for a vCPU with NV, which protected VMs don't
> support, and otherwise pend the SError through HCR_EL2.VSE, as KVM did
> before commit ce66109cec867 ("KVM: arm64: nv: Take "masked" aborts to
> EL2 when HCRX_EL2.TMEA is set").
>
> Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
> Suggested-by: Oliver Upton <oupton@kernel.org>
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
Reviewed-by: Oliver Upton <oupton@kernel.org>
Thanks,
Oliver
^ permalink raw reply [flat|nested] 3+ messages in thread* Re: [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV
2026-10-07 8:08 [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV Fuad Tabba
2026-10-07 8:41 ` Oliver Upton
@ 2026-10-07 12:08 ` Marc Zyngier
1 sibling, 0 replies; 3+ messages in thread
From: Marc Zyngier @ 2026-10-07 12:08 UTC (permalink / raw)
To: Oliver Upton, kvmarm, linux-arm-kernel, linux-kernel, Fuad Tabba
Cc: Catalin Marinas, Will Deacon, Joey Gouly, Steffen Eiden,
Suzuki K Poulose, Zenghui Yu, Vincent Donnefort, Quentin Perret,
Mark Rutland
On Wed, 07 Oct 2026 09:08:33 +0100, Fuad Tabba wrote:
> kvm_inject_serror_esr() emulates an SError's exception entry when the
> host's copy of PSTATE says SErrors are unmasked, although only NV needs
> this, for a nested context whose guest hypervisor owns the vSError. A
> protected vCPU's PSTATE lives at EL2, and the VMM can unmask SErrors in
> the host's copy before the first run, so KVM emulates the entry on that
> copy and the guest never takes the SError.
>
> [...]
Applied to next, thanks!
[1/1] KVM: arm64: Only emulate an SError's entry for vCPUs with NV
commit: 3bd107ed6b23de45b861e7f0c151d7fba59d721a
Cheers,
M.
--
Without deviation from the norm, progress is not possible.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-07 12:08 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 8:08 [PATCH v3] KVM: arm64: Only emulate an SError's entry for vCPUs with NV Fuad Tabba
2026-10-07 8:41 ` Oliver Upton
2026-10-07 12:08 ` Marc Zyngier
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®