From: sashiko-bot@kernel.org
To: "Fuad Tabba" <fuad.tabba@linux.dev>
Cc: kvmarm@lists.linux.dev, "Marc Zyngier" <maz@kernel.org>,
"Oliver Upton" <oupton@kernel.org>
Subject: Re: [PATCH v2 12/17] KVM: arm64: Add per-EC entry/exit state marshalling for protected guests
Date: Mon, 07 Sep 2026 07:26:07 +0000 [thread overview]
Message-ID: <20260907072608.31AFB1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260907070002.3333525-13-fuad.tabba@linux.dev>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] Dead fallback code due to EL2 WARN_ON panic semantics
--
commit e6a23fd729ce9b1a6ab9652bdfcd06dd180d6ce8
Author: Fuad Tabba <fuad.tabba@linux.dev>
KVM: arm64: Add per-EC entry/exit state marshalling for protected guests
This commit introduces per-EC entry and exit state marshalling for protected
guests. It routes protected guests through specific entry and exit handlers
to copy only the necessary context rather than the entire context between the
host and the hyp vCPU.
> diff --git a/arch/arm64/kvm/hyp/nvhe/hyp-main.c b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
> index 1a3f23e90e563..2015bf5ce6287 100644
> --- a/arch/arm64/kvm/hyp/nvhe/hyp-main.c
> +++ b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
[ ... ]
> @@ -34,13 +38,342 @@ void __kvm_hyp_host_forward_smc(struct kvm_cpu_context *host_ctxt);
[ ... ]
> +static void handle_pvm_entry_hvc64(struct pkvm_hyp_vcpu *hyp_vcpu)
> +{
> + u64 ret = READ_ONCE(hyp_vcpu->host_vcpu->arch.ctxt.regs.regs[0]);
> + u32 psci_fn = smccc_get_function(&hyp_vcpu->vcpu);
> +
> + switch (psci_fn) {
> + case PSCI_0_2_FN_CPU_ON:
> + case PSCI_0_2_FN64_CPU_ON:
> + /*
> + * Roll back a CPU_ON the host failed, unless the target
> + * already reached ON: it is running, and the guest sees
> + * SUCCESS.
> + */
> + if (ret != PSCI_RET_SUCCESS) {
> + unsigned long cpu_id = smccc_get_arg1(&hyp_vcpu->vcpu);
> + struct pkvm_hyp_vcpu *target_vcpu;
> + struct pkvm_hyp_vm *hyp_vm;
> + int prev;
> +
> + hyp_vm = pkvm_hyp_vcpu_to_hyp_vm(hyp_vcpu);
> + target_vcpu = pkvm_mpidr_to_hyp_vcpu(hyp_vm, cpu_id);
> +
> + /*
> + * pvm_psci_vcpu_on() resolved this MPIDR and vcpus[]
> + * entries are never removed, so the lookup cannot miss.
> + */
> + if (WARN_ON(!target_vcpu)) {
> + ret = PSCI_RET_INTERNAL_FAILURE;
> + break;
> + }
[Severity: Low]
Is the fallback error handling unreachable here?
At EL2 in nVHE/pKVM, WARN_ON evaluates to a BRK instruction which panics the
hypervisor. There is no warn-and-continue behavior in this context. If
target_vcpu evaluates to NULL, the hypervisor will panic immediately, leaving
the fallback assignment to PSCI_RET_INTERNAL_FAILURE and the break statement
entirely dead code.
> +
> + prev = cmpxchg_relaxed(&target_vcpu->power_state,
> + PSCI_0_2_AFFINITY_LEVEL_ON_PENDING,
> + PSCI_0_2_AFFINITY_LEVEL_OFF);
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260907070002.3333525-1-fuad.tabba@linux.dev?part=12
next prev parent reply other threads:[~2026-09-07 7:26 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 6:59 [PATCH v2 00/16] KVM: arm64: Confine protected VM vCPU state to EL2 Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 01/17] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 02/17] KVM: arm64: Reject the PVTIME vCPU attribute for protected VMs Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 03/17] KVM: arm64: Introduce per-EC entry handlers for pKVM Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 04/17] KVM: arm64: Skip fixed-feature state flush for protected vCPUs Fuad Tabba
2026-09-07 7:23 ` sashiko-bot
2026-09-07 9:11 ` Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 05/17] KVM: arm64: Add {flush,sync}_hyp_timer_state() primitives Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 06/17] KVM: arm64: Add system register reset framework for protected VMs Fuad Tabba
2026-09-07 7:16 ` sashiko-bot
2026-09-07 9:12 ` Fuad Tabba
2026-09-09 13:50 ` Joey Gouly
2026-09-10 10:05 ` Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 07/17] KVM: arm64: Implement HVC handling for protected guests at EL2 Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 08/17] KVM: arm64: Handle PSCI calls for protected VMs " Fuad Tabba
2026-09-07 7:16 ` sashiko-bot
2026-09-07 9:14 ` Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 09/17] KVM: arm64: Restrict KVM_ARM_VCPU_INIT and PSCI version for protected VMs Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 10/17] KVM: arm64: Prevent host PC adjustments for protected vCPUs Fuad Tabba
2026-09-11 13:23 ` Joey Gouly
2026-09-11 13:58 ` Marc Zyngier
2026-09-07 6:59 ` [PATCH v2 11/17] KVM: arm64: Inject an UNDEF at EL2 for unhandled protected guest exits Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 12/17] KVM: arm64: Add per-EC entry/exit state marshalling for protected guests Fuad Tabba
2026-09-07 7:26 ` sashiko-bot [this message]
2026-09-07 9:15 ` Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 13/17] KVM: arm64: Pend a protected guest's SError with HCR_EL2.VSE only Fuad Tabba
2026-09-11 10:29 ` Marc Zyngier
2026-09-11 10:58 ` Fuad Tabba
2026-09-07 6:59 ` [PATCH v2 14/17] KVM: arm64: Reject host access to protected VM private state Fuad Tabba
2026-09-11 12:58 ` Marc Zyngier
2026-09-07 7:00 ` [PATCH v2 15/17] KVM: arm64: Reject host power-on of a vCPU that EL2 holds powered off Fuad Tabba
2026-09-07 7:29 ` sashiko-bot
2026-09-07 9:17 ` Fuad Tabba
2026-09-07 7:00 ` [PATCH v2 16/17] KVM: arm64: Advertise the capabilities that protected VMs support Fuad Tabba
2026-09-07 7:00 ` [PATCH v2 17/17] KVM: arm64: Document the protected VM userspace API Fuad Tabba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907072608.31AFB1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=fuad.tabba@linux.dev \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.