From: Fuad Tabba <fuad.tabba@linux.dev>
To: Marc Zyngier <maz@kernel.org>, Oliver Upton <oupton@kernel.org>,
kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Joey Gouly <joey.gouly@arm.com>,
Steffen Eiden <seiden@linux.ibm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Vincent Donnefort <vdonnefort@google.com>,
Quentin Perret <qperret@google.com>,
Fuad Tabba <tabba@google.com>
Subject: [PATCH 07/17] KVM: arm64: Add system register reset framework for protected VMs
Date: Mon, 31 Aug 2026 17:34:11 +0100 [thread overview]
Message-ID: <20260831163421.272420-8-fuad.tabba@linux.dev> (raw)
In-Reply-To: <20260831163421.272420-1-fuad.tabba@linux.dev>
Reset a protected VM's system registers at EL2 rather than taking the
host's values: add kvm_reset_pvm_sys_regs() and the
pvm_sys_reg_reset_vals[] table that drives it, and call it from
init_pkvm_hyp_vcpu() for protected vCPUs. The values follow the
host-side reset in sys_regs.c, with a poison value where it resets to
UNKNOWN, and for VBAR_EL1 and CONTEXTIDR_EL1 in place of the 0 it
resets them to. MPIDR_EL1 is derived from vcpu_id, as for any KVM
guest.
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---
arch/arm64/kvm/hyp/include/nvhe/pkvm.h | 1 +
arch/arm64/kvm/hyp/nvhe/pkvm.c | 5 ++
arch/arm64/kvm/hyp/nvhe/sys_regs.c | 91 ++++++++++++++++++++++++--
3 files changed, 93 insertions(+), 4 deletions(-)
diff --git a/arch/arm64/kvm/hyp/include/nvhe/pkvm.h b/arch/arm64/kvm/hyp/include/nvhe/pkvm.h
index 49a0a992047ba..a04b7c04d5135 100644
--- a/arch/arm64/kvm/hyp/include/nvhe/pkvm.h
+++ b/arch/arm64/kvm/hyp/include/nvhe/pkvm.h
@@ -95,6 +95,7 @@ bool kvm_handle_pvm_hvc64(struct kvm_vcpu *vcpu, u64 *exit_code);
bool kvm_handle_pvm_sysreg(struct kvm_vcpu *vcpu, u64 *exit_code);
bool kvm_handle_pvm_restricted(struct kvm_vcpu *vcpu, u64 *exit_code);
void kvm_init_pvm_id_regs(struct kvm_vcpu *vcpu);
+void kvm_reset_pvm_sys_regs(struct kvm_vcpu *vcpu);
int kvm_check_pvm_sysreg_table(void);
#endif /* __ARM64_KVM_NVHE_PKVM_H__ */
diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c
index e85f13233da08..af334318d0a03 100644
--- a/arch/arm64/kvm/hyp/nvhe/pkvm.c
+++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c
@@ -551,6 +551,11 @@ static int init_pkvm_hyp_vcpu(struct pkvm_hyp_vcpu *hyp_vcpu,
goto done;
ret = pkvm_vcpu_init_sve(hyp_vcpu, host_vcpu);
+ if (ret)
+ goto done;
+
+ if (pkvm_hyp_vcpu_is_protected(hyp_vcpu))
+ kvm_reset_pvm_sys_regs(&hyp_vcpu->vcpu);
done:
if (ret)
unpin_host_vcpu(host_vcpu);
diff --git a/arch/arm64/kvm/hyp/nvhe/sys_regs.c b/arch/arm64/kvm/hyp/nvhe/sys_regs.c
index 8758c68017765..ebfd48aa15b56 100644
--- a/arch/arm64/kvm/hyp/nvhe/sys_regs.c
+++ b/arch/arm64/kvm/hyp/nvhe/sys_regs.c
@@ -525,6 +525,84 @@ static const struct sys_reg_desc pvm_sys_reg_descs[] = {
/* Performance Monitoring Registers are restricted. */
};
+struct sys_reg_desc_reset {
+ int reg;
+ void (*reset)(struct kvm_vcpu *vcpu, const struct sys_reg_desc_reset *rd);
+ u64 value;
+};
+
+/* Hardware value, as sys_regs.c's reset_actlr()/reset_amair_el1(). */
+static void reset_actlr(struct kvm_vcpu *vcpu, const struct sys_reg_desc_reset *r)
+{
+ __vcpu_assign_sys_reg(vcpu, r->reg, read_sysreg(actlr_el1));
+}
+
+static void reset_amair_el1(struct kvm_vcpu *vcpu, const struct sys_reg_desc_reset *r)
+{
+ __vcpu_assign_sys_reg(vcpu, r->reg, read_sysreg(amair_el1));
+}
+
+static void reset_mpidr(struct kvm_vcpu *vcpu, const struct sys_reg_desc_reset *r)
+{
+ __vcpu_assign_sys_reg(vcpu, r->reg, kvm_calculate_mpidr(vcpu));
+}
+
+static void reset_value(struct kvm_vcpu *vcpu, const struct sys_reg_desc_reset *r)
+{
+ __vcpu_assign_sys_reg(vcpu, r->reg, r->value);
+}
+
+#define RESET_VAL(REG, RESET_VAL) { REG, reset_value, RESET_VAL }
+
+#define RESET_ZERO(REG) RESET_VAL(REG, 0)
+
+#define RESET_UNKNOWN(REG) RESET_VAL(REG, 0x1de7ec7edbadc0deULL)
+
+#define RESET_FUNC(REG, RESET_FUNC) { REG, RESET_FUNC, 0 }
+
+/* Sorted ascending by reg; kvm_check_pvm_sysreg_table() enforces it. */
+static const struct sys_reg_desc_reset pvm_sys_reg_reset_vals[] = {
+ RESET_FUNC(MPIDR_EL1, reset_mpidr),
+ RESET_UNKNOWN(TPIDR_EL0),
+ RESET_UNKNOWN(TPIDRRO_EL0),
+ RESET_UNKNOWN(TPIDR_EL1),
+ RESET_ZERO(CNTKCTL_EL1),
+ RESET_UNKNOWN(PAR_EL1),
+ RESET_ZERO(MDCCINT_EL1),
+ RESET_ZERO(DISR_EL1),
+ RESET_ZERO(PMCCFILTR_EL0),
+ RESET_ZERO(PMUSERENR_EL0),
+ RESET_ZERO(CPACR_EL1),
+ RESET_VAL(CONTEXTIDR_EL1, 0x00000000dbadc0deULL),
+ RESET_VAL(SCTLR_EL1, 0x00C50078ULL),
+ RESET_FUNC(ACTLR_EL1, reset_actlr),
+ RESET_ZERO(TCR_EL1),
+ RESET_UNKNOWN(AFSR0_EL1),
+ RESET_UNKNOWN(AFSR1_EL1),
+ RESET_UNKNOWN(ESR_EL1),
+ RESET_UNKNOWN(MAIR_EL1),
+ RESET_FUNC(AMAIR_EL1, reset_amair_el1),
+ RESET_ZERO(MDSCR_EL1),
+ RESET_ZERO(ZCR_EL1),
+ RESET_UNKNOWN(TTBR0_EL1),
+ RESET_UNKNOWN(TTBR1_EL1),
+ RESET_UNKNOWN(FAR_EL1),
+ RESET_VAL(VBAR_EL1, 0x1de7ec7edbadc000ULL),
+ RESET_UNKNOWN(PIRE0_EL1),
+ RESET_UNKNOWN(PIR_EL1),
+};
+
+void kvm_reset_pvm_sys_regs(struct kvm_vcpu *vcpu)
+{
+ unsigned long i;
+
+ for (i = 0; i < ARRAY_SIZE(pvm_sys_reg_reset_vals); i++) {
+ const struct sys_reg_desc_reset *r = &pvm_sys_reg_reset_vals[i];
+
+ r->reset(vcpu, r);
+ }
+}
+
/*
* Initializes feature registers for protected vms.
*/
@@ -550,16 +628,21 @@ void kvm_init_pvm_id_regs(struct kvm_vcpu *vcpu)
}
/*
- * Checks that the sysreg table is unique and in-order.
- *
- * Returns 0 if the table is consistent, or 1 otherwise.
+ * Both tables must be unique and sorted ascending. pvm_sys_reg_descs.reg is the
+ * sys_reg() encoding, pvm_sys_reg_reset_vals.reg the vcpu_sysreg index, so they
+ * compare differently. BUG_ON() at __pkvm_init: fatal at boot.
*/
int kvm_check_pvm_sysreg_table(void)
{
unsigned int i;
for (i = 1; i < ARRAY_SIZE(pvm_sys_reg_descs); i++) {
- if (cmp_sys_reg(&pvm_sys_reg_descs[i-1], &pvm_sys_reg_descs[i]) >= 0)
+ if (cmp_sys_reg(&pvm_sys_reg_descs[i - 1], &pvm_sys_reg_descs[i]) >= 0)
+ return 1;
+ }
+
+ for (i = 1; i < ARRAY_SIZE(pvm_sys_reg_reset_vals); i++) {
+ if (pvm_sys_reg_reset_vals[i - 1].reg >= pvm_sys_reg_reset_vals[i].reg)
return 1;
}
--
2.39.5
next prev parent reply other threads:[~2026-08-31 16:34 UTC|newest]
Thread overview: 42+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 16:34 [PATCH 00/17] KVM: arm64: Confine protected VM vCPU state to EL2 Fuad Tabba
2026-08-31 16:34 ` [PATCH 01/17] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM Fuad Tabba
2026-08-31 16:34 ` [PATCH 02/17] KVM: arm64: Advertise the capabilities that protected VMs support Fuad Tabba
2026-09-02 13:22 ` Vincent Donnefort
2026-09-03 16:20 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 03/17] KVM: arm64: Reject the PVTIME vCPU attribute for protected VMs Fuad Tabba
2026-09-02 13:30 ` Vincent Donnefort
2026-09-03 16:21 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 04/17] KVM: arm64: Introduce per-EC entry handlers for pKVM Fuad Tabba
2026-09-02 10:12 ` Joey Gouly
2026-09-02 11:35 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 05/17] KVM: arm64: Skip fixed-feature state flush for protected vCPUs Fuad Tabba
2026-08-31 19:58 ` sashiko-bot
2026-09-01 10:22 ` Fuad Tabba
2026-09-02 15:05 ` Vincent Donnefort
2026-09-02 15:26 ` Vincent Donnefort
2026-09-03 16:22 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 06/17] KVM: arm64: Add {flush,sync}_hyp_timer_state() primitives Fuad Tabba
2026-08-31 16:34 ` Fuad Tabba [this message]
2026-08-31 20:22 ` [PATCH 07/17] KVM: arm64: Add system register reset framework for protected VMs sashiko-bot
2026-09-01 10:17 ` Fuad Tabba
2026-09-02 15:14 ` Joey Gouly
2026-09-03 16:24 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 08/17] KVM: arm64: Implement HVC handling for protected guests at EL2 Fuad Tabba
2026-08-31 21:00 ` sashiko-bot
2026-09-01 10:19 ` Fuad Tabba
2026-09-03 15:12 ` Joey Gouly
2026-09-03 16:25 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 09/17] KVM: arm64: Handle PSCI calls for protected VMs " Fuad Tabba
2026-08-31 21:14 ` sashiko-bot
2026-09-01 10:23 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 10/17] KVM: arm64: Restrict KVM_ARM_VCPU_INIT and PSCI version for protected VMs Fuad Tabba
2026-08-31 16:34 ` [PATCH 11/17] KVM: arm64: Prevent host PC adjustments for protected vCPUs Fuad Tabba
2026-08-31 16:34 ` [PATCH 12/17] KVM: arm64: Inject an UNDEF at EL2 for unhandled protected guest exits Fuad Tabba
2026-08-31 16:34 ` [PATCH 13/17] KVM: arm64: Add per-EC entry/exit state marshalling for protected guests Fuad Tabba
2026-08-31 22:15 ` sashiko-bot
2026-09-01 10:24 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 14/17] KVM: arm64: Pend a protected guest's SError with HCR_EL2.VSE only Fuad Tabba
2026-08-31 16:34 ` [PATCH 15/17] KVM: arm64: Reject host access to protected VM private state Fuad Tabba
2026-08-31 16:34 ` [PATCH 16/17] KVM: arm64: Reject host power-on of a vCPU that EL2 holds powered off Fuad Tabba
2026-08-31 16:34 ` [PATCH 17/17] KVM: arm64: Document the protected VM userspace API Fuad Tabba
2026-08-31 19:27 ` [PATCH 00/17] KVM: arm64: Confine protected VM vCPU state to EL2 Fuad Tabba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831163421.272420-8-fuad.tabba@linux.dev \
--to=fuad.tabba@linux.dev \
--cc=catalin.marinas@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=qperret@google.com \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vdonnefort@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.