mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
@ 2026-10-05  5:03 Fuad Tabba
  2026-10-05  8:30 ` Marc Zyngier
  2026-10-05  8:30 ` Oliver Upton
  0 siblings, 2 replies; 4+ messages in thread
From: Fuad Tabba @ 2026-10-05  5:03 UTC (permalink / raw)
  To: maz, oupton, kvmarm, linux-arm-kernel, linux-kernel
  Cc: catalin.marinas, will, joey.gouly, seiden, suzuki.poulose,
	yuzenghui, vdonnefort, qperret, tabba, mark.rutland

kvm_inject_serror_esr() reads PSTATE.A and SCTLR2_EL1.NMEA to decide
whether to emulate the SError's exception entry or pend it through
HCR_EL2.VSE. For a protected vCPU, the host's copy of those is stale,
and when it reads as unmasked KVM emulates the entry on that copy. EL2
never delivers it as an SError: its entry handler turns the pending
exception into an external abort on the trapped access, and an MMIO
completion still pending trips WARN_ON(INCREMENT_PC).

Always pend through HCR_EL2.VSE for a protected vCPU. EL2 forwards it,
and the guest's own masking decides when the SError is taken.

Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---
Applies on kvmarm/next. A follow-up to "KVM: arm64: Confine protected VM
vCPU state to EL2" [1], from Sashiko's review of its v4 patch 12.

[1] https://lore.kernel.org/all/20261001135711.1640520-1-fuad.tabba@linux.dev/

 arch/arm64/kvm/inject_fault.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
index d6c4fc16f8795..49a342b078365 100644
--- a/arch/arm64/kvm/inject_fault.c
+++ b/arch/arm64/kvm/inject_fault.c
@@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
 	 *
 	 * As we're emulating the SError injection we need to explicitly populate
 	 * ESR_ELx.EC because hardware will not do it on our behalf.
+	 *
+	 * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
+	 * HCR_EL2.VSE and let the guest's own masking apply.
 	 */
-	if (!serror_is_masked(vcpu)) {
+	if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
 		pend_serror_exception(vcpu);
 		esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
 		vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));

base-commit: fa22cd9947fc245d71bc40482f7f78eb0d5a4af0
-- 
2.39.5


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
  2026-10-05  5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
@ 2026-10-05  8:30 ` Marc Zyngier
  2026-10-05  8:30 ` Oliver Upton
  1 sibling, 0 replies; 4+ messages in thread
From: Marc Zyngier @ 2026-10-05  8:30 UTC (permalink / raw)
  To: Fuad Tabba
  Cc: oupton, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
	will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
	qperret, tabba, mark.rutland

On Mon, 05 Oct 2026 06:03:52 +0100,
Fuad Tabba <fuad.tabba@linux.dev> wrote:
> 
> kvm_inject_serror_esr() reads PSTATE.A and SCTLR2_EL1.NMEA to decide
> whether to emulate the SError's exception entry or pend it through
> HCR_EL2.VSE. For a protected vCPU, the host's copy of those is stale,
> and when it reads as unmasked KVM emulates the entry on that copy. EL2
> never delivers it as an SError: its entry handler turns the pending
> exception into an external abort on the trapped access, and an MMIO
> completion still pending trips WARN_ON(INCREMENT_PC).
> 
> Always pend through HCR_EL2.VSE for a protected vCPU. EL2 forwards it,
> and the guest's own masking decides when the SError is taken.
> 
> Fixes: 872383bd12e11 ("KVM: arm64: Add per-EC entry/exit state marshalling for protected guests")
> Reported-by: Sashiko <sashiko-bot@kernel.org>
> Closes: https://lore.kernel.org/all/20261001142109.794CA1F000FF@smtp.kernel.org/
> Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
> ---
> Applies on kvmarm/next. A follow-up to "KVM: arm64: Confine protected VM
> vCPU state to EL2" [1], from Sashiko's review of its v4 patch 12.
> 
> [1] https://lore.kernel.org/all/20261001135711.1640520-1-fuad.tabba@linux.dev/
> 
>  arch/arm64/kvm/inject_fault.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> index d6c4fc16f8795..49a342b078365 100644
> --- a/arch/arm64/kvm/inject_fault.c
> +++ b/arch/arm64/kvm/inject_fault.c
> @@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
>  	 *
>  	 * As we're emulating the SError injection we need to explicitly populate
>  	 * ESR_ELx.EC because hardware will not do it on our behalf.
> +	 *
> +	 * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
> +	 * HCR_EL2.VSE and let the guest's own masking apply.
>  	 */
> -	if (!serror_is_masked(vcpu)) {
> +	if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
>  		pend_serror_exception(vcpu);
>  		esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
>  		vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));
> 

I thought we had discussed that one before (or am I making things
up?). Why can't the host always evaluate serror_is_masked() as true?
Given that PSTATE is never synced back to the host, it would only be a
matter of set PSTATE.A==1 at vcpu creation time.

It'd be more palatable than this sprinkling of vcpu_is_protected(),
which really do not scale.

Thanks,

	M.

-- 
Jazz isn't dead. It just smells funny.

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
  2026-10-05  5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
  2026-10-05  8:30 ` Marc Zyngier
@ 2026-10-05  8:30 ` Oliver Upton
  2026-10-05 10:34   ` Fuad Tabba
  1 sibling, 1 reply; 4+ messages in thread
From: Oliver Upton @ 2026-10-05  8:30 UTC (permalink / raw)
  To: Fuad Tabba
  Cc: maz, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
	will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
	qperret, tabba, mark.rutland

Hi Fuad,

On Mon, Oct 05, 2026 at 06:03:52AM +0100, Fuad Tabba wrote:
> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> index d6c4fc16f8795..49a342b078365 100644
> --- a/arch/arm64/kvm/inject_fault.c
> +++ b/arch/arm64/kvm/inject_fault.c
> @@ -378,8 +378,11 @@ int kvm_inject_serror_esr(struct kvm_vcpu *vcpu, u64 esr)
>  	 *
>  	 * As we're emulating the SError injection we need to explicitly populate
>  	 * ESR_ELx.EC because hardware will not do it on our behalf.
> +	 *
> +	 * A protected vCPU's PSTATE and SCTLR2_EL1 live at EL2, so pend through
> +	 * HCR_EL2.VSE and let the guest's own masking apply.
>  	 */
> -	if (!serror_is_masked(vcpu)) {
> +	if (!vcpu_is_protected(vcpu) && !serror_is_masked(vcpu)) {
>  		pend_serror_exception(vcpu);
>  		esr |= FIELD_PREP(ESR_ELx_EC_MASK, ESR_ELx_EC_SERROR) | ESR_ELx_IL;
>  		vcpu_write_sys_reg(vcpu, esr, exception_esr_elx(vcpu));

The emulated injection is only necessary when vcpu_has_nv(), it was just
convenient for the sake of testing that everything short circuits to
emulation instead of VSE.

I see Marc suggests letting the stale PSTATE.A value force the desired
behavior which seems fine to me. If that doesn't work, I'd rather
emulated injection be predicated on vcpu_has_nv() than
vcpu_is_protected() with the appropriate rephrasing of the preceding
comment.

Thanks,
Oliver

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE
  2026-10-05  8:30 ` Oliver Upton
@ 2026-10-05 10:34   ` Fuad Tabba
  0 siblings, 0 replies; 4+ messages in thread
From: Fuad Tabba @ 2026-10-05 10:34 UTC (permalink / raw)
  To: Oliver Upton
  Cc: maz, kvmarm, linux-arm-kernel, linux-kernel, catalin.marinas,
	will, joey.gouly, seiden, suzuki.poulose, yuzenghui, vdonnefort,
	qperret, mark.rutland

Hi Marc, Oliver,

On Mon, 05 Oct 2026 09:30:39 +0100, Marc Zyngier <maz@kernel.org> wrote:
[...]
> I thought we had discussed that one before (or am I making things
> up?). Why can't the host always evaluate serror_is_masked() as true?
> Given that PSTATE is never synced back to the host, it would only be a
> matter of set PSTATE.A==1 at vcpu creation time.
>
> It'd be more palatable than this sprinkling of vcpu_is_protected(),
> which really do not scale.

Yes, it's better for the host to always see SErrors as masked. v2 will
do that when the hyp vCPU is created, and leave
kvm_inject_serror_esr() alone.

Cheers,
/fuad

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-05 10:35 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05  5:03 [PATCH] KVM: arm64: Pend host SErrors for protected vCPUs through HCR_EL2.VSE Fuad Tabba
2026-10-05  8:30 ` Marc Zyngier
2026-10-05  8:30 ` Oliver Upton
2026-10-05 10:34   ` Fuad Tabba

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®