From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: Fuad Tabba <fuad.tabba@linux.dev>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev, maz@kernel.org,
will@kernel.org, catalin.marinas@arm.com,
linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com,
joey.gouly@arm.com, yuzenghui@huawei.com,
linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
sdonthineni@nvidia.com, alpergun@google.com,
fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
lpieralisi@kernel.org, enju.kohei@fujitsu.com
Subject: Re: [PATCH v17 10/20] KVM: arm64: coco: Disable Steal time accounting for coco guests
Date: Wed, 9 Sep 2026 12:52:03 +0100 [thread overview]
Message-ID: <6152fc41-65f0-460f-90b4-1454c11bcba6@arm.com> (raw)
In-Reply-To: <CA+EHjTw9ReyvsNT=y+-P6ng7VQ6Pvz9PFK9bO71qvTR1pOxx5Q@mail.gmail.com>
On 09/09/2026 12:45, Fuad Tabba wrote:
> Hi Suzuki,
>
> On Tue, 8 Sept 2026 at 17:23, Suzuki K Poulose <suzuki.poulose@arm.com> wrote:
>>
>> PVTIME support is advertised by KVM_CAP_STEAL_TIME, which doesn't take into
>> account the kvm instance. Even with that, a VMM could skip the CAP check and
>> proceed to configure the PVTIME as we don't do further check on the DEVICE_CTRL.
>> Tighten this up by passing the KVM instance around wherever possible and
>> catch things early
>>
>> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
>
> ...
>
>> -bool kvm_arm_pvtime_supported(void)
>> +bool kvm_arm_pvtime_supported(struct kvm *kvm)
>> {
>> - return !!sched_info_on();
>> + return !!sched_info_on() && (!kvm || !kvm_vm_is_confidential(kvm));
>> }
>
> I think it would be better to leave KVM_CAP_STEAL_TIME reported and
> instead reject the configuration for these VMs, returning -EPERM from
> the KVM_ARM_VCPU_PVTIME_CTRL attr. A capability query should report
> what the kernel supports, not whether a given VM may use it; gating it
> per-VM here is also inconsistent, since the !kvm clause leaves the
> system-fd cap at 1 while the VM-fd cap reads 0. And -EPERM says that
But isn't that we want from a VMM perspective ? i.e., enable PVTIME if
it is supported for the given VM (type). Rather than PVTIME is supported
by the KVM, so I can go enable it by default. But, we endup getting a
failure while we enable it. I encountered this with kvmtool, where
CAP_STEAL_TIME is reported true and even the HAS_DEVICE_ATTR goes
through fine, but SET_DEVICE_ATTR seemed to fail.
Isn't it better to allow the VM to decide if the capability is supported
for the given VM type, like we are doing for other capabilities ?
> steal-time exists but isn't permitted for a confidential VM, whereas
> -ENXIO reads as "no such feature".
Cheers
Suzuki
>
> Cheers,
> /fuad
>
>>
>> int kvm_arm_pvtime_set_attr(struct kvm_vcpu *vcpu,
>> @@ -81,7 +81,7 @@ int kvm_arm_pvtime_set_attr(struct kvm_vcpu *vcpu,
>> int ret = 0;
>> int idx;
>>
>> - if (!kvm_arm_pvtime_supported() ||
>> + if (!kvm_arm_pvtime_supported(kvm) ||
>> attr->attr != KVM_ARM_VCPU_PVTIME_IPA)
>> return -ENXIO;
>>
>> @@ -110,7 +110,7 @@ int kvm_arm_pvtime_get_attr(struct kvm_vcpu *vcpu,
>> u64 __user *user = (u64 __user *)attr->addr;
>> u64 ipa;
>>
>> - if (!kvm_arm_pvtime_supported() ||
>> + if (!kvm_arm_pvtime_supported(vcpu->kvm) ||
>> attr->attr != KVM_ARM_VCPU_PVTIME_IPA)
>> return -ENXIO;
>>
>> @@ -126,7 +126,7 @@ int kvm_arm_pvtime_has_attr(struct kvm_vcpu *vcpu,
>> {
>> switch (attr->attr) {
>> case KVM_ARM_VCPU_PVTIME_IPA:
>> - if (kvm_arm_pvtime_supported())
>> + if (kvm_arm_pvtime_supported(vcpu->kvm))
>> return 0;
>> }
>> return -ENXIO;
>> --
>> 2.43.0
>>
next prev parent reply other threads:[~2026-09-09 11:52 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 16:22 [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 01/20] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-09 11:20 ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 02/20] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-09 11:22 ` Fuad Tabba
2026-09-09 11:24 ` Suzuki K Poulose
2026-09-10 3:40 ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 03/20] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-09 11:28 ` Fuad Tabba
2026-09-09 11:30 ` Suzuki K Poulose
2026-09-10 3:39 ` Gavin Shan
2026-09-10 6:35 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 04/20] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-10 4:00 ` Gavin Shan
2026-09-10 10:21 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 05/20] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-10 5:33 ` Gavin Shan
2026-09-10 8:40 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 06/20] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-09 3:26 ` Kohei Enju
2026-09-09 10:48 ` Marc Zyngier
2026-09-10 4:49 ` Kohei Enju
2026-09-10 5:53 ` Gavin Shan
2026-09-10 8:43 ` Suzuki K Poulose
2026-09-10 9:40 ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 07/20] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 08/20] KVM: arm64: coco: Add a helper to check if a VM is confidential compute guest Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 09/20] KVM: arm64: coco: arch_timer: Prevent timer offset configuration Suzuki K Poulose
2026-09-08 16:46 ` sashiko-bot
2026-09-10 12:19 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 10/20] KVM: arm64: coco: Disable Steal time accounting for coco guests Suzuki K Poulose
2026-09-09 11:45 ` Fuad Tabba
2026-09-09 11:52 ` Suzuki K Poulose [this message]
2026-09-09 12:23 ` Fuad Tabba
2026-09-10 10:27 ` Suzuki K Poulose
2026-09-10 12:42 ` Fuad Tabba
2026-09-10 12:44 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 11/20] KVM: arm64: coco: Don't handle MMIO with no ISV Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 12/20] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-08 16:56 ` sashiko-bot
2026-09-08 18:58 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 13/20] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 14/20] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-08 16:52 ` sashiko-bot
2026-09-10 12:18 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 15/20] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 16/20] KVM: arm64: CCA: Provide register list for unfinalized RECs Suzuki K Poulose
2026-09-08 16:57 ` sashiko-bot
2026-09-10 12:15 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 17/20] KVM: arm64: CCA: Provide an accurate register list Suzuki K Poulose
2026-09-08 17:00 ` sashiko-bot
2026-09-10 12:17 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 18/20] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-09 11:50 ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 19/20] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-08 16:59 ` sashiko-bot
2026-09-08 18:59 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 20/20] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-09 13:18 ` [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Fuad Tabba
2026-09-09 13:52 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6152fc41-65f0-460f-90b4-1454c11bcba6@arm.com \
--to=suzuki.poulose@arm.com \
--cc=WeiLin.Chang@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=enju.kohei@fujitsu.com \
--cc=fj0570is@fujitsu.com \
--cc=fuad.tabba@linux.dev \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.