From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Mark Brown <broonie@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Shuah Khan <shuah@kernel.org>, Oliver Upton <oupton@kernel.org>,
Fuad Tabba <fuad.tabba@linux.dev>,
Peter Maydell <peter.maydell@linaro.org>,
Leonardo Bras <leo.bras@arm.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Yao Yuan <yaoyuan@linux.alibaba.com>,
linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org,
kvmarm@lists.linux.dev, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2
Date: Thu, 1 Oct 2026 11:50:51 +0100 [thread overview]
Message-ID: <ar4yT297fh45gwM6@gremlin> (raw)
In-Reply-To: <20260930-arm64-gcs-v21-2-3556644cd927@kernel.org>
On Wed, Sep 30, 2026 at 10:48:12PM +0100, Mark Brown wrote:
> Fixes: 663abf04ee4d ("KVM: arm64: Make PIR{,E0}_EL1 save/restore conditional on FEAT_TCRX")
> Signed-off-by: Mark Brown <broonie@kernel.org>
Great, this looks like the most sensible way of resolving the issue with
userland being able to trigger a kernel oops due to the save/restore
registers optimisations.
It's also entirely sensible to disallow completely broken configurations
like this.
LGTM so:
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
> diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
> index 44aae52c473d..3ae293798b27 100644
> --- a/arch/arm64/kvm/sys_regs.c
> +++ b/arch/arm64/kvm/sys_regs.c
> @@ -5928,6 +5946,9 @@ int kvm_finalize_sys_regs(struct kvm_vcpu *vcpu)
> kvm_vgic_finalize_idregs(kvm);
> }
>
> + if (!kvm_validate_id_regs(vcpu->kvm))
> + return -EINVAL;
> +
Seems like the right place to put it as part of the finalisation process,
run once per VM and guaranteeing the invariant so it's guaranteed that
ctx_has_s1pie() -> ctxt_has_tcrx() and ctx_has_s1poe() -> ctxt_has_tcrx().
(Just working it through for my own understanding), tracing through it ends
up at struct kvm_arch->id_regs[]:
kvm_has_tcr2()
-> kvm_has_feat()
-> __kvm_has_feat()
-> kvm_cmp_feat()
-> kvm_cmp_feat_unsigned()
-> get_idreg_field_unsigned()
-> kvm_read_vm_id_reg()
-> __vm_id_reg()
-> ka->id_regs[]
Which will all have been populated by here. however failing at this point
will stop KVM_ARCH_FLAG_HAS_RUN_ONCE from being set (also obviously your
other series separately fixes the issue with KVM_ARCH_FLAG_FGU_INITIALIZED
being set with !KVM_ARCH_FLAG_HAS_RUN_ONCE).
--
Cheers, Lorenzo
next prev parent reply other threads:[~2026-10-01 10:50 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 21:48 [PATCH v21 00/15] KVM: arm64: Provide guest support for GCS Mark Brown
2026-09-30 21:48 ` [PATCH v21 01/15] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled Mark Brown
2026-09-30 21:48 ` [PATCH v21 02/15] KVM: arm64: Refuse to start a guest with S1PIE or S1POE but not TCR2 Mark Brown
2026-09-30 22:05 ` sashiko-bot
2026-10-01 11:25 ` Lorenzo Stoakes (ARM)
2026-10-01 12:07 ` Mark Brown
2026-10-01 10:50 ` Lorenzo Stoakes (ARM) [this message]
2026-10-03 12:30 ` Marc Zyngier
2026-09-30 21:48 ` [PATCH v21 03/15] KVM: arm64: Manage GCS access and registers for guests Mark Brown
2026-10-01 11:28 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 04/15] KVM: arm64: Ensure GCS memory effects are visible Mark Brown
2026-09-30 21:48 ` [PATCH v21 05/15] KVM: arm64: Set PSTATE.EXLOCK when entering an exception Mark Brown
2026-10-01 11:37 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 06/15] KVM: arm64: Validate GCS exception lock when emulating ERET Mark Brown
2026-10-01 13:10 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 07/15] KVM: arm64: Forward GCS exceptions to nested guests Mark Brown
2026-10-01 14:25 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 08/15] KVM: arm64: Enforce EXLOCK for SPSR and ELR Mark Brown
2026-10-01 16:26 ` Lorenzo Stoakes (ARM)
2026-10-01 21:11 ` Mark Brown
2026-10-02 11:50 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 09/15] KVM: arm64: Allow GCS to be enabled for guests Mark Brown
2026-10-01 16:29 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 10/15] KVM: selftests: arm64: Check that invalid feature combinations are rejected Mark Brown
2026-10-01 16:35 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 11/15] KVM: selftests: arm64: Add GCS registers to get-reg-list Mark Brown
2026-10-01 16:36 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 12/15] KVM: selftests: arm64: Add GCS to set_id_regs Mark Brown
2026-10-01 16:38 ` Lorenzo Stoakes (ARM)
2026-10-01 18:14 ` Mark Brown
2026-10-02 11:27 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 13/15] KVM: selftests: arm64: Only restore SPSR_EL1 and ELR_EL1 if they change Mark Brown
2026-10-01 16:41 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 14/15] tools: Synchronise the kernel esr.h Mark Brown
2026-09-30 22:14 ` sashiko-bot
2026-10-01 16:47 ` Lorenzo Stoakes (ARM)
2026-10-01 17:27 ` Mark Brown
2026-10-02 11:31 ` Lorenzo Stoakes (ARM)
2026-09-30 21:48 ` [PATCH v21 15/15] KVM: selftests: arm64: Add GCS EXLOCK exception emulation test Mark Brown
2026-09-30 22:24 ` sashiko-bot
2026-10-01 16:53 ` Lorenzo Stoakes (ARM)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ar4yT297fh45gwM6@gremlin \
--to=ljs@kernel.org \
--cc=broonie@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=fuad.tabba@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=leo.bras@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=peter.maydell@linaro.org \
--cc=shuah@kernel.org \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=will@kernel.org \
--cc=yaoyuan@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.