From: Per Larsen <perlarsen@google.com>
To: Marc Zyngier <maz@kernel.org>,
Oliver Upton <oliver.upton@linux.dev>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>,
Sudeep Holla <sudeep.holla@arm.com>
Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
linux-kernel@vger.kernel.org, sebastianene@google.com,
qperret@google.com, qwandor@google.com, arve@android.com,
perl@immunant.com, lpieralisi@kernel.org,
kernel-team@android.com, tabba@google.com, james.morse@arm.com,
armellel@google.com, jean-philippe@linaro.org,
ahomescu@google.com, Per Larsen <perlarsen@google.com>
Subject: [PATCH v4 1/5] KVM: arm64: Restrict FF-A host version renegotiation
Date: Fri, 16 May 2025 12:14:00 +0000 [thread overview]
Message-ID: <20250516-virtio-msg-ffa-v4-1-580ee70e5081@google.com> (raw)
In-Reply-To: <20250516-virtio-msg-ffa-v4-0-580ee70e5081@google.com>
Prevent the host from re-negotiating a lesser minor version with the
hypervisor. Once the hypervisor negotiates a version, that should
remain locked in. Fix the current behaviour by returning NOT_SUPPORTED
to avoid the FF-A interoperability rules with lesser minor versions that
allow the host version to downgrade.
Signed-off-by: Per Larsen <perlarsen@google.com>
---
arch/arm64/kvm/hyp/nvhe/ffa.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/ffa.c b/arch/arm64/kvm/hyp/nvhe/ffa.c
index 3369dd0c4009f84ad3cf9481c747bdc57a162370..2c199d40811efb5bfae199c4a67d8ae3d9307357 100644
--- a/arch/arm64/kvm/hyp/nvhe/ffa.c
+++ b/arch/arm64/kvm/hyp/nvhe/ffa.c
@@ -712,7 +712,10 @@ static void do_ffa_version(struct arm_smccc_res *res,
hyp_spin_lock(&version_lock);
if (has_version_negotiated) {
- res->a0 = hyp_ffa_version;
+ if (FFA_MINOR_VERSION(ffa_req_version) < FFA_MINOR_VERSION(hyp_ffa_version))
+ res->a0 = FFA_RET_NOT_SUPPORTED;
+ else
+ res->a0 = hyp_ffa_version;
goto unlock;
}
--
2.49.0.1101.gccaa498523-goog
WARNING: multiple messages have this Message-ID (diff)
From: Per Larsen via B4 Relay <devnull+perlarsen.google.com@kernel.org>
To: Marc Zyngier <maz@kernel.org>,
Oliver Upton <oliver.upton@linux.dev>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>,
Sudeep Holla <sudeep.holla@arm.com>
Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev,
linux-kernel@vger.kernel.org, sebastianene@google.com,
qperret@google.com, qwandor@google.com, arve@android.com,
perl@immunant.com, lpieralisi@kernel.org,
kernel-team@android.com, tabba@google.com, james.morse@arm.com,
armellel@google.com, jean-philippe@linaro.org,
ahomescu@google.com, Per Larsen <perlarsen@google.com>
Subject: [PATCH v4 1/5] KVM: arm64: Restrict FF-A host version renegotiation
Date: Fri, 16 May 2025 12:14:00 +0000 [thread overview]
Message-ID: <20250516-virtio-msg-ffa-v4-1-580ee70e5081@google.com> (raw)
In-Reply-To: <20250516-virtio-msg-ffa-v4-0-580ee70e5081@google.com>
From: Per Larsen <perlarsen@google.com>
Prevent the host from re-negotiating a lesser minor version with the
hypervisor. Once the hypervisor negotiates a version, that should
remain locked in. Fix the current behaviour by returning NOT_SUPPORTED
to avoid the FF-A interoperability rules with lesser minor versions that
allow the host version to downgrade.
Signed-off-by: Per Larsen <perlarsen@google.com>
---
arch/arm64/kvm/hyp/nvhe/ffa.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/ffa.c b/arch/arm64/kvm/hyp/nvhe/ffa.c
index 3369dd0c4009f84ad3cf9481c747bdc57a162370..2c199d40811efb5bfae199c4a67d8ae3d9307357 100644
--- a/arch/arm64/kvm/hyp/nvhe/ffa.c
+++ b/arch/arm64/kvm/hyp/nvhe/ffa.c
@@ -712,7 +712,10 @@ static void do_ffa_version(struct arm_smccc_res *res,
hyp_spin_lock(&version_lock);
if (has_version_negotiated) {
- res->a0 = hyp_ffa_version;
+ if (FFA_MINOR_VERSION(ffa_req_version) < FFA_MINOR_VERSION(hyp_ffa_version))
+ res->a0 = FFA_RET_NOT_SUPPORTED;
+ else
+ res->a0 = hyp_ffa_version;
goto unlock;
}
--
2.49.0.1101.gccaa498523-goog
next prev parent reply other threads:[~2025-05-16 12:14 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-05-16 12:13 [PATCH v4 0/5] KVM: arm64: Support FF-A 1.2 and SEND_DIRECT2 ABI Per Larsen
2025-05-16 12:13 ` Per Larsen via B4 Relay
2025-05-16 12:14 ` Per Larsen [this message]
2025-05-16 12:14 ` [PATCH v4 1/5] KVM: arm64: Restrict FF-A host version renegotiation Per Larsen via B4 Relay
2025-05-29 9:54 ` Will Deacon
2025-05-16 12:14 ` [PATCH v4 2/5] KVM: arm64: Zero x4-x7 in ffa_set_retval Per Larsen
2025-05-16 12:14 ` Per Larsen via B4 Relay
2025-05-29 12:17 ` Will Deacon
2025-05-16 12:14 ` [PATCH v4 3/5] KVM: arm64: Mark FFA_NOTIFICATION_* calls as unsupported Per Larsen
2025-05-16 12:14 ` Per Larsen via B4 Relay
2025-05-29 12:05 ` Will Deacon
2025-05-16 12:14 ` [PATCH v4 4/5] KVM: arm64: Bump the supported version of FF-A to 1.2 Per Larsen
2025-05-16 12:14 ` Per Larsen via B4 Relay
2025-05-16 12:14 ` [PATCH v4 5/5] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ2 in host handler Per Larsen
2025-05-16 12:14 ` Per Larsen via B4 Relay
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250516-virtio-msg-ffa-v4-1-580ee70e5081@google.com \
--to=perlarsen@google.com \
--cc=ahomescu@google.com \
--cc=armellel@google.com \
--cc=arve@android.com \
--cc=catalin.marinas@arm.com \
--cc=james.morse@arm.com \
--cc=jean-philippe@linaro.org \
--cc=joey.gouly@arm.com \
--cc=kernel-team@android.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=perl@immunant.com \
--cc=qperret@google.com \
--cc=qwandor@google.com \
--cc=sebastianene@google.com \
--cc=sudeep.holla@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.