All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Tomohiro Misono" <misono.tomohiro@fujitsu.com>
Cc: linux-perf-users@vger.kernel.org
Subject: Re: [PATCH 2/4] arm64: tlb: Add tlbi workaround for FUJITSU-MONAKA Erratum E#030001
Date: Fri, 02 Oct 2026 10:41:54 +0000	[thread overview]
Message-ID: <20261002104154.722471F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261002-monaka-fix-for-upstream-v1-2-4aec0b0cbe34@fujitsu.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] kvm: arm64: Nested virtualization bypasses FUJITSU-MONAKA E#030001 erratum workaround
--

commit a8becb6b6a9a519a1569cd1fb836fdfcaee436c2
Author: Tomohiro Misono <misono.tomohiro@fujitsu.com>

arm64: tlb: Add tlbi workaround for FUJITSU-MONAKA Erratum E#030001

This commit adds a workaround for FUJITSU-MONAKA erratum E#030001 where
range-based TLBI operations may fail to invalidate 512MB mappings. It
issues additional non-range TLBI instructions for the affected VA or IPA
ranges.

> diff --git a/arch/arm64/include/asm/tlbflush.h b/arch/arm64/include/asm/tlbflush.h
> index 14a78ac0f8009..0487daec16528 100644
> --- a/arch/arm64/include/asm/tlbflush.h
> +++ b/arch/arm64/include/asm/tlbflush.h
[ ... ]
> @@ -518,6 +549,8 @@ static __always_inline void __flush_tlb_range_op(tlbi_op lop, tlbi_op rop,
>  		__tlbi_level_asid(lop, addr, level, asid);
>  		addr += stride;
>  	}
> +
> +	fujitsu_erratum_wa(lop, start, end, asid);
>  }

[Severity: High]
Does KVM's nested virtualization bypass this erratum workaround?

Looking at arch/arm64/kvm/hyp/vhe/tlb.c, __kvm_tlbi_s1e2() directly invokes
native range-based TLBI instructions on behalf of a nested guest:

arch/arm64/kvm/hyp/vhe/tlb.c:__kvm_tlbi_s1e2() {
	...
	case OP_TLBI_RVAE2:
	case OP_TLBI_RVAE2IS:
	case OP_TLBI_RVAE2OS:
	case OP_TLBI_RVAE1:
	case OP_TLBI_RVAE1IS:
	case OP_TLBI_RVAE1OS:
	...
		__tlbi(rvae1is, va);
		break;
	...
}

Because the nested guest hypervisor traps into this KVM emulation which
executes raw instructions without decoding the range or applying
fujitsu_erratum_wa(), it appears the workaround is skipped here. Could this
leave stale TLB entries in the guest hypervisor's translation regime if an
untrusted nested guest targets an affected 512MB mapping?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261002-monaka-fix-for-upstream-v1-0-4aec0b0cbe34@fujitsu.com?part=2

  reply	other threads:[~2026-10-02 10:41 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-02 10:26 [PATCH 0/4] arm64: Add workarounds for FUJITSU-MONAKA CPU Tomohiro Misono
2026-10-02 10:26 ` [PATCH 1/4] arm64: cputype: Add FUJITSU MONAKA definition Tomohiro Misono
2026-10-02 10:31   ` sashiko-bot
2026-10-02 10:26 ` [PATCH 2/4] arm64: tlb: Add tlbi workaround for FUJITSU-MONAKA Erratum E#030001 Tomohiro Misono
2026-10-02 10:41   ` sashiko-bot [this message]
2026-10-02 12:43   ` Will Deacon
2026-10-06  9:48     ` Tomohiro Misono (Fujitsu)
2026-10-02 13:01   ` Mark Rutland
2026-10-06  9:45     ` Tomohiro Misono (Fujitsu)
2026-10-02 10:26 ` [PATCH 3/4] perf: arm_pmu: Add workaround for FUJITSU-MONAKA Erratum E#030002 Tomohiro Misono
2026-10-02 10:35   ` sashiko-bot
2026-10-02 12:44   ` Will Deacon
2026-10-06  9:52     ` Tomohiro Misono (Fujitsu)
2026-10-02 10:26 ` [PATCH 4/4] irqchip/gicv3: Add workaround for FUJITSU-MONAKA erratum E#030003 Tomohiro Misono
2026-10-02 10:41   ` sashiko-bot
2026-10-07 11:37     ` Kohei Enju
2026-10-02 12:26   ` Marc Zyngier
2026-10-06  9:08     ` Kohei Enju
2026-10-06  9:42       ` Marc Zyngier
2026-10-07  8:17         ` Kohei Enju

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002104154.722471F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=misono.tomohiro@fujitsu.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.