All of lore.kernel.org
 help / color / mirror / Atom feed
From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Oliver Upton <oupton@kernel.org>, Marc Zyngier <maz@kernel.org>,
	kvm@vger.kernel.org, kvmarm@lists.linux.dev
Subject: Re: [PATCH v17 17/20] KVM: arm64: CCA: Provide an accurate register list
Date: Thu, 10 Sep 2026 13:17:42 +0100	[thread overview]
Message-ID: <0a75dfc9-17c7-4917-94b4-0b0b38db847a@arm.com> (raw)
In-Reply-To: <20260908170026.B47BF1F00A3A@smtp.kernel.org>

On 08/09/2026 18:00, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
> - [Medium] KVM_GET_REG_LIST fails to restrict core registers to the 9 GP registers for Realm VMs, exposing all core registers instead.
> - [Medium] Realm VM system register restrictions are only applied to KVM_GET_REG_LIST, allowing userspace to bypass them via KVM_SET_ONE_REG and KVM_GET_ONE_REG.
> --
> 
> commit 1a82d37b0064cc3f1fa34c6757432fa355d160a3
> Author: Jean-Philippe Brucker <jpb@kernel.org>
> 
> KVM: arm64: CCA: Provide an accurate register list
>      
> Userspace can set a few registers with KVM_SET_ONE_REG (9 GP registers
> at runtime, and 3 system registers during initialization). Update the
> register list returned by KVM_GET_REG_LIST.
> 
>> Userspace can set a few registers with KVM_SET_ONE_REG (9 GP registers
>> at runtime, and 3 system registers during initialization). Update the
>> register list returned by KVM_GET_REG_LIST.
> 
> [Severity: Medium]
> Does KVM_GET_REG_LIST successfully restrict core registers to just the 9 GP
> registers for Realm VMs?
> 
> Looking at copy_core_reg_indices(), it loops over the entire kvm_regs array
> without checking vcpu_is_rec(vcpu):
> 
> arch/arm64/kvm/guest.c:copy_core_reg_indices() {
> 	for (i = 0; i < sizeof(struct kvm_regs) / sizeof(__u32); i++) {
> 		u64 reg = KVM_REG_ARM64 | KVM_REG_ARM_CORE | i;
> 		int size = core_reg_size_from_offset(vcpu, i);
> 
> 		if (size < 0)
> 			continue;
>          ...
> }
> 
> This appears to expose all core registers to the userspace array rather than
> limiting it to the 9 GP registers mentioned in the commit message.

That is correct, but a later patch actually restricts this for set_reg()
calls. I will pull that into this series and will also fixup the commit
description, potentially folding that one here.

> 
> [ ... ]
> 
>> diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
>> index 44aae52c473d7..a58c1fc13ea17 100644
>> --- a/arch/arm64/kvm/sys_regs.c
>> +++ b/arch/arm64/kvm/sys_regs.c
> 
> [ ... ]
> 
>> @@ -5693,11 +5693,26 @@ static bool copy_reg_to_user(const struct sys_reg_desc *reg, u64 __user **uind)
>>   	return true;
>>   }
>>   
>> +static inline bool kvm_realm_sys_reg_hidden_user(const struct kvm_vcpu *vcpu,
>> +						 u64 reg)
>> +{
>> +	switch (reg) {
>> +	case SYS_ID_AA64DFR0_EL1:
>> +	case SYS_PMCR_EL0:
>> +		return false;
>> +	}
>> +	return true;
>> +}
>> +
>>   static int walk_one_sys_reg(const struct kvm_vcpu *vcpu,
>>   			    const struct sys_reg_desc *rd,
>>   			    u64 __user **uind,
>>   			    unsigned int *total)
>>   {
>> +	if (vcpu_is_rec(vcpu) &&
>> +	    kvm_realm_sys_reg_hidden_user(vcpu, reg_to_encoding(rd)))
>> +		return 0;
>> +
> 
> [Severity: Medium]
> Are the Realm system register restrictions bypassed by KVM_SET_ONE_REG and
> KVM_GET_ONE_REG?
> 
> While this patch correctly hides the registers from KVM_GET_REG_LIST by
> checking kvm_realm_sys_reg_hidden_user() in walk_one_sys_reg(), it doesn't
> appear to add a similar check to the ioctl handlers for setting or getting
> individual registers.
> 
> For example, in kvm_sys_reg_set_user(), the code only checks sysreg_hidden():

As above, this is in a separate patch, I will fix this in next version.


Suzuki


  reply	other threads:[~2026-09-10 12:17 UTC|newest]

Thread overview: 60+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 16:22 [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 01/20] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-09 11:20   ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 02/20] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-09 11:22   ` Fuad Tabba
2026-09-09 11:24     ` Suzuki K Poulose
2026-09-10  3:40   ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 03/20] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-09 11:28   ` Fuad Tabba
2026-09-09 11:30     ` Suzuki K Poulose
2026-09-10  3:39   ` Gavin Shan
2026-09-10  6:35     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 04/20] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-10  4:00   ` Gavin Shan
2026-09-10 10:21     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 05/20] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-10  5:33   ` Gavin Shan
2026-09-10  8:40     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 06/20] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-09  3:26   ` Kohei Enju
2026-09-09 10:48     ` Marc Zyngier
2026-09-10  4:49       ` Kohei Enju
2026-09-10  5:53   ` Gavin Shan
2026-09-10  8:43     ` Suzuki K Poulose
2026-09-10  9:40       ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 07/20] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 08/20] KVM: arm64: coco: Add a helper to check if a VM is confidential compute guest Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 09/20] KVM: arm64: coco: arch_timer: Prevent timer offset configuration Suzuki K Poulose
2026-09-08 16:46   ` sashiko-bot
2026-09-10 12:19     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 10/20] KVM: arm64: coco: Disable Steal time accounting for coco guests Suzuki K Poulose
2026-09-09 11:45   ` Fuad Tabba
2026-09-09 11:52     ` Suzuki K Poulose
2026-09-09 12:23       ` Fuad Tabba
2026-09-10 10:27         ` Suzuki K Poulose
2026-09-10 12:42           ` Fuad Tabba
2026-09-10 12:44             ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 11/20] KVM: arm64: coco: Don't handle MMIO with no ISV Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 12/20] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-08 16:56   ` sashiko-bot
2026-09-08 18:58     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 13/20] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 14/20] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-08 16:52   ` sashiko-bot
2026-09-10 12:18     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 15/20] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 16/20] KVM: arm64: CCA: Provide register list for unfinalized RECs Suzuki K Poulose
2026-09-08 16:57   ` sashiko-bot
2026-09-10 12:15     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 17/20] KVM: arm64: CCA: Provide an accurate register list Suzuki K Poulose
2026-09-08 17:00   ` sashiko-bot
2026-09-10 12:17     ` Suzuki K Poulose [this message]
2026-09-08 16:22 ` [PATCH v17 18/20] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-09 11:50   ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 19/20] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-08 16:59   ` sashiko-bot
2026-09-08 18:59     ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 20/20] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-09 13:18 ` [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Fuad Tabba
2026-09-09 13:52   ` Suzuki K Poulose

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0a75dfc9-17c7-4917-94b4-0b0b38db847a@arm.com \
    --to=suzuki.poulose@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.