All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Mark Brown" <broonie@kernel.org>
Cc: "Oliver Upton" <oupton@kernel.org>,
	"Marc Zyngier" <maz@kernel.org>,
	kvmarm@lists.linux.dev
Subject: Re: [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2
Date: Wed, 30 Sep 2026 22:05:50 +0000	[thread overview]
Message-ID: <20260930220551.014471F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260930-arm64-gcs-v21-2-3556644cd927@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] kvm: arm64: TOCTOU race bypasses S1PIE/TCR2 ID register validation
--

commit ecf3602b27fe0cb6f8ce76b1a8c6698e3dee08f4
Author: Mark Brown <broonie@kernel.org>

KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2

This commit adds validation to reject starting a guest with FEAT_S1PIE or
FEAT_S1POE enabled if FEAT_TCR2 is disabled, as the hypervisor requires
TCR2 to properly context-switch these registers.

> diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
> index 44aae52c473d7..3ae293798b270 100644
> --- a/arch/arm64/kvm/sys_regs.c
> +++ b/arch/arm64/kvm/sys_regs.c

[ ... ]

> @@ -5928,6 +5946,9 @@ int kvm_finalize_sys_regs(struct kvm_vcpu *vcpu)
>  		kvm_vgic_finalize_idregs(kvm);
>  	}
>  
> +	if (!kvm_validate_id_regs(vcpu->kvm))
> +		return -EINVAL;
> +

[Severity: Critical]
Does this introduce a Time-Of-Check to Time-Of-Use (TOCTOU) regression
that bypasses the S1PIE/TCR2 ID register check?

If Thread A executes the first KVM_RUN, it passes this kvm_validate_id_regs()
check because the invalid configuration hasn't been set yet. The config_lock
is then released.

Thread B could then execute KVM_SET_ONE_REG for the ID register, take
config_lock, and inject the invalid S1PIE=1/TCR2=0 configuration via
set_id_reg() in arch/arm64/kvm/sys_regs.c, bypassing the immutability check
because KVM_ARCH_FLAG_HAS_RAN_ONCE is not yet set.

When Thread A proceeds to execute kvm_calculate_traps(), it reads the
maliciously modified ID registers and disables the traps, before finally
setting KVM_ARCH_FLAG_HAS_RAN_ONCE in kvm_arch_vcpu_run_pid_change() in
arch/arm64/kvm/arm.c.

This regression allows KVM to configure traps based on S1PIE, disabling the
trap for PIRE0_EL1, but skipping context-switching the register because TCR2
is disabled. Could this allow the guest to directly overwrite the host's
physical PIRE0_EL1 register?

>  	return 0;
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930-arm64-gcs-v21-0-3556644cd927@kernel.org?part=2

  reply	other threads:[~2026-09-30 22:05 UTC|newest]

Thread overview: 41+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30 21:48 [PATCH v21 00/15] KVM: arm64: Provide guest support for GCS Mark Brown
2026-09-30 21:48 ` [PATCH v21 01/15] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled Mark Brown
2026-09-30 21:48 ` [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2 Mark Brown
2026-09-30 22:05   ` sashiko-bot [this message]
2026-10-01 11:25     ` Lorenzo Stoakes (ARM)
2026-10-01 12:07       ` Mark Brown
2026-10-01 10:50   ` Lorenzo Stoakes (ARM)
2026-10-03 12:30   ` Marc Zyngier
2026-09-30 21:48 ` [PATCH v21 03/15] KVM: arm64: Manage GCS access and registers for guests Mark Brown
2026-10-01 11:28   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 04/15] KVM: arm64: Ensure GCS memory effects are visible Mark Brown
2026-09-30 21:48 ` [PATCH v21 05/15] KVM: arm64: Set PSTATE.EXLOCK when entering an exception Mark Brown
2026-10-01 11:37   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 06/15] KVM: arm64: Validate GCS exception lock when emulating ERET Mark Brown
2026-10-01 13:10   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 07/15] KVM: arm64: Forward GCS exceptions to nested guests Mark Brown
2026-10-01 14:25   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 08/15] KVM: arm64: Enforce EXLOCK for SPSR and ELR Mark Brown
2026-10-01 16:26   ` Lorenzo Stoakes (ARM)
2026-10-01 21:11     ` Mark Brown
2026-10-02 11:50       ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 09/15] KVM: arm64: Allow GCS to be enabled for guests Mark Brown
2026-10-01 16:29   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 10/15] KVM: selftests: arm64: Check that invalid feature combinations are rejected Mark Brown
2026-10-01 16:35   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 11/15] KVM: selftests: arm64: Add GCS registers to get-reg-list Mark Brown
2026-10-01 16:36   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 12/15] KVM: selftests: arm64: Add GCS to set_id_regs Mark Brown
2026-10-01 16:38   ` Lorenzo Stoakes (ARM)
2026-10-01 18:14     ` Mark Brown
2026-10-02 11:27       ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 13/15] KVM: selftests: arm64: Only restore SPSR_EL1 and ELR_EL1 if they change Mark Brown
2026-10-01 16:41   ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 14/15] tools: Synchronise the kernel esr.h Mark Brown
2026-09-30 22:14   ` sashiko-bot
2026-10-01 16:47   ` Lorenzo Stoakes (ARM)
2026-10-01 17:27     ` Mark Brown
2026-10-02 11:31       ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 15/15] KVM: selftests: arm64: Add GCS EXLOCK exception emulation test Mark Brown
2026-09-30 22:24   ` sashiko-bot
2026-10-01 16:53   ` Lorenzo Stoakes (ARM)

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930220551.014471F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=broonie@kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.