From: Marc Zyngier <maz@kernel.org>
To: Mark Brown <broonie@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Shuah Khan <shuah@kernel.org>, Oliver Upton <oupton@kernel.org>,
Fuad Tabba <fuad.tabba@linux.dev>,
Peter Maydell <peter.maydell@linaro.org>,
Leonardo Bras <leo.bras@arm.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Yao Yuan <yaoyuan@linux.alibaba.com>,
linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org,
kvmarm@lists.linux.dev, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2
Date: Sat, 03 Oct 2026 13:30:05 +0100 [thread overview]
Message-ID: <86fqyn2che.wl-maz@kernel.org> (raw)
In-Reply-To: <20260930-arm64-gcs-v21-2-3556644cd927@kernel.org>
On Wed, 30 Sep 2026 22:48:12 +0100,
Mark Brown <broonie@kernel.org> wrote:
>
> Since there is an architectural dependency between the features as an
> optimisation we only context switch guest registers for FEAT_S1PIE and
> FEAT_S1POE if the guest also has FEAT_TCR2. We do not, however, enforce
> this as a requirement when starting a guest and only configure the traps
> for accessing the registers based on their individual features. This means
> that a VMM can configure a guest which can read and write the system
> registers for FEAT_S1PIE and FEAT_S1POE without the hypervisor updating the
> values of these registers for the guest.
>
> Avoid this by refusing to create a guest with an affected configuration.
>
> Rather than doing something data driven we open code the checks, I started
> doing something data driven but it was very clear that such code should be
> shared with the host kernel cpufeature code. Refactoring for that seemed
> like disproportionate effort and invasiveness for the context so is
> deferred for followup work.
This *absolutely* needs to be data driven, and we're not going back to
over two years ago. We already have most of what is needed in
config.c, and it is only a matter of making sure that S1PxE is only
enabled for the guest if TCR2 and ATS1A are also present. If that
means additional sanitisation of the idregs when finalised, so be it.
If userspace decides to expose crap in the ID registers, that's its
own problem, and we're not in the business of enforcing idiotic
configurations. The only thing that matters is that the state that KVM
deals with is consistent.
M.
--
Without deviation from the norm, progress is not possible.
next prev parent reply other threads:[~2026-10-03 12:30 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 21:48 [PATCH v21 00/15] KVM: arm64: Provide guest support for GCS Mark Brown
2026-09-30 21:48 ` [PATCH v21 01/15] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled Mark Brown
2026-09-30 21:48 ` [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2 Mark Brown
2026-10-01 10:50 ` Lorenzo Stoakes (ARM)
2026-10-03 12:30 ` Marc Zyngier [this message]
2026-09-30 21:48 ` [PATCH v21 03/15] KVM: arm64: Manage GCS access and registers for guests Mark Brown
2026-10-01 11:28 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 04/15] KVM: arm64: Ensure GCS memory effects are visible Mark Brown
2026-09-30 21:48 ` [PATCH v21 05/15] KVM: arm64: Set PSTATE.EXLOCK when entering an exception Mark Brown
2026-10-01 11:37 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 06/15] KVM: arm64: Validate GCS exception lock when emulating ERET Mark Brown
2026-10-01 13:10 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 07/15] KVM: arm64: Forward GCS exceptions to nested guests Mark Brown
2026-10-01 14:25 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 08/15] KVM: arm64: Enforce EXLOCK for SPSR and ELR Mark Brown
2026-10-01 16:26 ` Lorenzo Stoakes (ARM)
2026-10-01 21:11 ` Mark Brown
2026-10-02 11:50 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 09/15] KVM: arm64: Allow GCS to be enabled for guests Mark Brown
2026-10-01 16:29 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 10/15] KVM: selftests: arm64: Check that invalid feature combinations are rejected Mark Brown
2026-10-01 16:35 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 11/15] KVM: selftests: arm64: Add GCS registers to get-reg-list Mark Brown
2026-10-01 16:36 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 12/15] KVM: selftests: arm64: Add GCS to set_id_regs Mark Brown
2026-10-01 16:38 ` Lorenzo Stoakes (ARM)
2026-10-01 18:14 ` Mark Brown
2026-10-02 11:27 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 13/15] KVM: selftests: arm64: Only restore SPSR_EL1 and ELR_EL1 if they change Mark Brown
2026-10-01 16:41 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 14/15] tools: Synchronise the kernel esr.h Mark Brown
2026-10-01 16:47 ` Lorenzo Stoakes (ARM)
2026-10-01 17:27 ` Mark Brown
2026-10-02 11:31 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 15/15] KVM: selftests: arm64: Add GCS EXLOCK exception emulation test Mark Brown
2026-10-01 16:53 ` Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=86fqyn2che.wl-maz@kernel.org \
--to=maz@kernel.org \
--cc=broonie@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=fuad.tabba@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=leo.bras@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=oupton@kernel.org \
--cc=peter.maydell@linaro.org \
--cc=shuah@kernel.org \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=will@kernel.org \
--cc=yaoyuan@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®