All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Marc Zyngier" <maz@kernel.org>
Cc: kvm@vger.kernel.org, "Marc Zyngier" <maz@kernel.org>,
	kvmarm@lists.linux.dev, "Oliver Upton" <oupton@kernel.org>
Subject: Re: [PATCH v4 23/29] KVM: arm64: Add NVHCR_EL2 context switching
Date: Thu, 30 Jul 2026 08:05:28 +0000	[thread overview]
Message-ID: <20260730080529.29E051F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260730071022.296811-24-maz@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] TOCTOU vulnerability in NV3 context switching leading to cross-VM information leak
--

--- Patch [23]: [PATCH v4 23/29] KVM: arm64: Add NVHCR_EL2 context switching ---
commit f6089755f833008f36c0718e0727dbb85a4f24ae
Author: Marc Zyngier <maz@kernel.org>

KVM: arm64: Add NVHCR_EL2 context switching

This commit introduces NVHCR_EL2 context switching. For a guest in hyp
context, NVHCR_EL2 reflects HCR_EL2 and is eagerly synced. For an L2 guest,
it is context switched like any EL1 register, conditioned on the guest using
NV3.

> diff --git a/arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h b/arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h
> index a17cbe7582de9..c382848d31947 100644
> --- a/arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h
> +++ b/arch/arm64/kvm/hyp/include/hyp/sysreg-sr.h
> @@ -172,6 +172,10 @@ static inline void __sysreg_save_el1_state(struct kvm_cpu_context *ctxt)
>  
>  	if (ctxt_has_sctlr2(ctxt))
>  		ctxt_sys_reg(ctxt, SCTLR2_EL1) = read_sysreg_el1(SYS_SCTLR2);
> +
> +	/* Retrieve L2's HCR_EL2, and save it for future use */
> +	if (is_nested_nv3_ctxt(ctxt_to_vcpu(ctxt)))
> +		ctxt_sys_reg(ctxt, NVHCR_EL2) = read_sysreg_s(SYS_NVHCR_EL2);

[Severity: High]
Does this introduce a TOCTOU regression leading to a cross-VM information
leak?

KVM uses the guest-modifiable VNCR state to decide whether to read the
hardware register, allowing a TOCTOU that reads uninitialized or stale
hardware state.

Looking at is_nested_nv3_ctxt(), it evaluates HCRX_EL2.NVTGE directly from
the guest-modifiable VNCR page:

arch/arm64/include/asm/kvm_emulate.h:is_nested_nv3_ctxt() {
    ...
    return (... && (__vcpu_sys_reg(vcpu, HCRX_EL2) & HCRX_EL2_NVTGE));
}

If an L1 guest concurrently modifies its VNCR page from another vCPU to
change NVTGE from 0 to 1 during an L2 guest's execution, KVM might read from
SYS_NVHCR_EL2 here on vcpu_put() or during sysreg trap handling. This could
copy the leaked hardware state into the L2 guest's context, where it can be
read.

[ ... ]

> @@ -285,6 +289,13 @@ static inline void __sysreg_restore_el1_state(struct kvm_cpu_context *ctxt,
>  
>  	if (ctxt_has_sctlr2(ctxt))
>  		write_sysreg_el1(ctxt_sys_reg(ctxt, SCTLR2_EL1), SYS_SCTLR2);
> +
> +	/*
> +	 * Publish the L2 view of HCR_EL2 to the HW if L1 is using NV3.
> +	 * Otherwise, the data is already in place in the L1's own VNCR.
> +	 */
> +	if (is_nested_nv3_ctxt(ctxt_to_vcpu(ctxt)))
> +		write_sysreg_s(ctxt_sys_reg(ctxt, NVHCR_EL2), SYS_NVHCR_EL2);

[Severity: High]
Can the same concurrent VNCR page modification cause KVM to skip initializing
the hardware register?

If NVTGE is 0 during vcpu_load(), KVM skips initializing the hardware
register, leaving the previous VM's state in hardware. A malicious L1 guest
can trigger this by configuring an L2 guest, spawning a concurrent vCPU to
modify the VNCR page, and executing a trapped instruction in L2.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260730071022.296811-1-maz@kernel.org?part=23

  reply	other threads:[~2026-07-30  8:05 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30  7:09 [PATCH v4 00/29] KVM: arm64: Add support for FEAT_NV2p1 and FEAT_NV3 Marc Zyngier
2026-07-30  7:09 ` [PATCH v4 01/29] arm64: sysreg: Emit RESx/UNKN values for Mapping/Fields definitions Marc Zyngier
2026-07-30 10:23   ` Mark Rutland
2026-07-30  7:09 ` [PATCH v4 02/29] arm64: Update ID_AA64MMFR4_EL1 description to 2026-03 JSON release Marc Zyngier
2026-07-30  9:48   ` Joey Gouly
2026-07-30  7:09 ` [PATCH v4 03/29] KVM: arm64: Merge guest's HCRX_EL2 using NV_HCRX_GUEST_EXCLUDE Marc Zyngier
2026-07-30  7:29   ` sashiko-bot
2026-07-30  8:01     ` Marc Zyngier
2026-07-30 13:39       ` Marc Zyngier
2026-07-30  9:42   ` Joey Gouly
2026-07-30  7:09 ` [PATCH v4 04/29] KVM: arm64: Drop __HCRX_EL2_* masks Marc Zyngier
2026-07-30  7:09 ` [PATCH v4 05/29] KVM: arm64: Plumb HCRX_EL2.SRMASKEn in HCRX_EL2 sanitisation Marc Zyngier
2026-07-30  7:09 ` [PATCH v4 06/29] KVM: arm64: Classify CPTR_EL2 as a SR_LOC_SPECIAL register Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 07/29] KVM: arm64: Don't evaluate HCR_EL2.NV nor HFGITR_EL2.ERET on ERET fast path Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 08/29] arm64: Add ARM64_HAS_NV2P1 capability Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 09/29] KVM: arm64: Relax CPTR_EL2 handling when FEAT_NV2p1 is present Marc Zyngier
2026-07-30  7:56   ` sashiko-bot
2026-07-30  7:10 ` [PATCH v4 10/29] KVM: arm64: Relax CNTHCTL_EL2 " Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 11/29] KVM: arm64: Expose FEAT_NV2p1 to NV guests Marc Zyngier
2026-07-30  8:09   ` sashiko-bot
2026-07-30  7:10 ` [PATCH v4 12/29] arm64: Add FEAT_NV2p1 detection Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 13/29] arm64: sysreg: Add NVHCR_EL2 description as a mirror of HCR_EL2 Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 14/29] arm64: sysreg: Add HCRX_EL2 bits related to FEAT_NV3 Marc Zyngier
2026-07-30  7:40   ` sashiko-bot
2026-07-30  7:48     ` Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 15/29] arm64: Add ARM64_HAS_NV3 capability Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 16/29] KVM: arm64: Split NV-specific exit fixups from the non-NV handling Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 17/29] KVM: arm64: Add NV3 control bits to HCRX_EL2 sanitisation Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 18/29] KVM: arm64: Add kvm_has_nv{2,3}() predicates Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 19/29] KVM: arm64: Make HCR_EL2 a non-VNCR register Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 20/29] KVM: arm64: Add sanitisation for NVHCR_EL2 Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 21/29] KVM: arm64: Add NVHCR_EL2 handling to the sysreg array Marc Zyngier
2026-07-30  7:58   ` sashiko-bot
2026-07-30  7:10 ` [PATCH v4 22/29] KVM: arm64: Add routing for NVHCR_EL2 trap Marc Zyngier
2026-07-30  8:12   ` sashiko-bot
2026-07-30  7:10 ` [PATCH v4 23/29] KVM: arm64: Add NVHCR_EL2 context switching Marc Zyngier
2026-07-30  8:05   ` sashiko-bot [this message]
2026-07-30  7:10 ` [PATCH v4 24/29] KVM: arm64: Engage NV3 ERET trap elision Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 25/29] KVM: arm64: Engage NV3 TLBI " Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 26/29] KVM: arm64: Add FEAT_NV3 detection Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 27/29] KVM: arm64: Expose FEAT_NV3 to guests Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 28/29] KVM: arm64: selftest: Add NVHCR_EL2 to get-reg-list Marc Zyngier
2026-07-30  7:10 ` [PATCH v4 29/29] arm64: Add override for ID_AA64MMFR4_EL1.NV_frac Marc Zyngier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260730080529.29E051F00A3D@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.