All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Marc Zyngier" <maz@kernel.org>
Cc: "Marc Zyngier" <maz@kernel.org>,
	kvmarm@lists.linux.dev, "Oliver Upton" <oupton@kernel.org>,
	kvm@vger.kernel.org
Subject: Re: [PATCH v3 26/28] KVM: arm64: Add FEAT_NV3 detection
Date: Wed, 22 Jul 2026 08:53:31 +0000	[thread overview]
Message-ID: <20260722085331.E34C61F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260722074234.3330999-27-maz@kernel.org>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] KVM's FEAT_NV3 fast-path evaluates to false for all guests, causing stale SYS_NVHCR_EL2 state during L2 nested entry.
- [High] Writes to SYS_NVHCR_EL2 lack required immediate Context Synchronization Event (ISB).
--

--- Patch [26]: [PATCH v3 26/28] KVM: arm64: Add FEAT_NV3 detection ---
commit e5daceb215a787136ab61f9dafcd9ffe40f4346c
Author: Marc Zyngier <maz@kernel.org>
    
    KVM: arm64: Add FEAT_NV3 detection

This commit adds the FEAT_NV3 detection code to cpufeature.c by introducing
the ARM64_HAS_NV3 capability. It engages the FEAT_NV3 fast-path in KVM now
that the infrastructure is in place.

> diff --git a/arch/arm64/kernel/cpufeature.c b/arch/arm64/kernel/cpufeature.c
> index c9c124b0ccc8e..6ae1c816e2010 100644
> --- a/arch/arm64/kernel/cpufeature.c
> +++ b/arch/arm64/kernel/cpufeature.c
> @@ -2627,6 +2627,13 @@ static const struct arm64_cpu_capabilities arm64_features[] = {
>  		.matches = has_cpuid_feature,
>  		ARM64_CPUID_FIELDS(ID_AA64MMFR4_EL1, NV_frac, NV2P1)
>  	},
> +	{
> +		.desc = "FEAT_NV3",
> +		.capability = ARM64_HAS_NV3,

[Severity: High]
Could engaging this capability break nested virtualization on NV3 hardware?

By enabling ARM64_HAS_NV3, the fast-path checks now depend on kvm_has_nv3(),
which appears to require the guest to advertise NV3:

arch/arm64/include/asm/kvm_emulate.h:kvm_has_nv3() {
    return (cpus_have_final_cap(ARM64_HAS_NESTED_VIRT) &&
            cpus_have_final_cap(ARM64_HAS_NV3) &&
            kvm_has_feat(kvm, ID_AA64MMFR4_EL1, NV_frac, NV3));
}

Since NV3 is explicitly hidden from guests (ID_AA64MMFR4_EL1.NV_frac is capped
at NV2P1), won't kvm_has_feat() always evaluate to false?

This would cause is_nested_nv3_ctxt() to always return false, skipping the
SYS_NVHCR_EL2 restore in L2 nested entry:

arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h:__sysreg_restore_el1_state() {
    ...
    if (is_nested_nv3_ctxt(ctxt_to_vcpu(ctxt)))
        write_sysreg_s(ctxt_sys_reg(ctxt, NVHCR_EL2), SYS_NVHCR_EL2);
    ...
}

Will the physical CPU execute the L2 guest using an uninitialized or stale
SYS_NVHCR_EL2 value?

[Severity: High]
Are there missing context synchronization events in this new fast-path?

When ARM64_HAS_NV3 is enabled, the code writes to the control-plane system
register SYS_NVHCR_EL2 without an immediate isb():

arch/arm64/kvm/hyp/vhe/switch.c:__compute_hcr() {
    if (cpus_have_final_cap(ARM64_HAS_NV3) && vcpu_el2_e2h_is_set(vcpu))
        write_sysreg_s(__vcpu_sys_reg(vcpu, HCR_EL2), SYS_NVHCR_EL2);
    else
        __vcpu_assign_sys_reg(vcpu, NVHCR_EL2, __vcpu_sys_reg(vcpu, HCR_EL2));

    /* No ISB here */
    guest_hcr = kvm_vcpu_apply_reg_masks(vcpu, HCR_EL2, 0);
    ...
}

It also happens during state restore before returning:

arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h:__sysreg_restore_el1_state() {
    ...
    if (is_nested_nv3_ctxt(ctxt_to_vcpu(ctxt)))
        write_sysreg_s(ctxt_sys_reg(ctxt, NVHCR_EL2), SYS_NVHCR_EL2);
}
/* No ISB before return */

Since SYS_NVHCR_EL2 is a control-plane register, doesn't it require an isb()
as the very next instruction to prevent the CPU from executing subsequent
instructions with undefined pipeline state?

> +		.type = ARM64_CPUCAP_SYSTEM_FEATURE,
> +		.matches = has_cpuid_feature,
> +		ARM64_CPUID_FIELDS(ID_AA64MMFR4_EL1, NV_frac, NV3)
> +	},
>  	{
>  		.capability = ARM64_HAS_32BIT_EL0_DO_NOT_USE,
>  		.type = ARM64_CPUCAP_SYSTEM_FEATURE,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260722074234.3330999-1-maz@kernel.org?part=26

  reply	other threads:[~2026-07-22  8:53 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22  7:42 [PATCH v3 00/28] KVM: arm64: Add support for FEAT_NV2p1 and FEAT_NV3 Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 01/28] arm64: sysreg: Emit RESx/UNKN values for Mapping/Fields definitions Marc Zyngier
2026-07-22  7:55   ` sashiko-bot
2026-07-22  9:05     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 02/28] arm64: Update ID_AA64MMFR4_EL1 description to 2026-03 JSON release Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 03/28] KVM: arm64: Merge guest's HCRX_EL2 using NV_HCRX_GUEST_EXCLUDE Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 04/28] KVM: arm64: Drop __HCRX_EL2_* masks Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 05/28] KVM: arm64: Plumb HCRX_EL2.SRMASKEn in HCRX_EL2 sanitisation Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 06/28] KVM: arm64: Classify CPTR_EL2 as a SR_LOC_SPECIAL register Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 07/28] KVM: arm64: Don't evaluate HCR_EL2.NV nor HFGITR_EL2.ERET on ERET fast path Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 08/28] arm64: Add ARM64_HAS_NV2P1 capability Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 09/28] KVM: arm64: Relax CPTR_EL2 handling when FEAT_NV2p1 is present Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 10/28] KVM: arm64: Relax CNTHCTL_EL2 " Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 11/28] KVM: arm64: Expose FEAT_NV2p1 to NV guests Marc Zyngier
2026-07-22  8:32   ` sashiko-bot
2026-07-22  9:01     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 12/28] arm64: Add FEAT_NV2p1 detection Marc Zyngier
2026-07-22  8:13   ` sashiko-bot
2026-07-22  8:57     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 13/28] arm64: sysreg: Add NVHCR_EL2 description as a mirror of HCR_EL2 Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 14/28] arm64: sysreg: Add HCRX_EL2 bits related to FEAT_NV3 Marc Zyngier
2026-07-22  8:11   ` sashiko-bot
2026-07-22  8:56     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 15/28] arm64: Add ARM64_HAS_NV3 capability Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 16/28] KVM: arm64: Split NV-specific exit fixups from the non-NV handling Marc Zyngier
2026-07-22  8:23   ` sashiko-bot
2026-07-22  9:08     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 17/28] KVM: arm64: Add NV3 control bits to HCRX_EL2 sanitisation Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 18/28] KVM: arm64: Add kvm_has_nv{2,3}() predicates Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 19/28] KVM: arm64: Make HCR_EL2 a non-VNCR register Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 20/28] KVM: arm64: Add sanitisation for NVHCR_EL2 Marc Zyngier
2026-07-22  8:38   ` sashiko-bot
2026-07-22  9:11     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 21/28] KVM: arm64: Add NVHCR_EL2 handling to the sysreg array Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 22/28] KVM: arm64: Add routing for NVHCR_EL2 trap Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 23/28] KVM: arm64: Add NVHCR_EL2 context switching Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 24/28] KVM: arm64: Engage NV3 ERET trap elision Marc Zyngier
2026-07-22  8:50   ` sashiko-bot
2026-07-22  9:16     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 25/28] KVM: arm64: Engage NV3 TLBI " Marc Zyngier
2026-07-22  8:57   ` sashiko-bot
2026-07-22  9:04     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 26/28] KVM: arm64: Add FEAT_NV3 detection Marc Zyngier
2026-07-22  8:53   ` sashiko-bot [this message]
2026-07-22  9:04     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 27/28] KVM: arm64: Expose FEAT_NV3 to guests Marc Zyngier
2026-07-22  9:06   ` sashiko-bot
2026-07-22  9:18     ` Marc Zyngier
2026-07-22  7:42 ` [PATCH v3 28/28] arm64: Add override for ID_AA64MMFR4_EL1.NV_frac Marc Zyngier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260722085331.E34C61F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.