From: Oliver Upton <oupton@kernel.org>
To: Leonardo Bras <leo.bras@arm.com>
Cc: kvmarm@lists.linux.dev, Marc Zyngier <maz@kernel.org>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Steffen Eiden <seiden@linux.ibm.com>
Subject: Re: [PATCH 04/22] KVM: arm64: nv: Only shadow writable-dirty guest descs as writable
Date: Mon, 21 Sep 2026 14:39:23 -0700 [thread overview]
Message-ID: <arGkC3uv6z7z5d8K@kernel.org> (raw)
In-Reply-To: <arFgiKnNTds9p1a7@LeoBrasDK>
On Mon, Sep 21, 2026 at 05:51:20PM +0100, Leonardo Bras wrote:
> > diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c
> > index 07bd1e3ae9fb..f35c4ce95473 100644
> > --- a/arch/arm64/kvm/mmu.c
> > +++ b/arch/arm64/kvm/mmu.c
> > @@ -1572,7 +1572,7 @@ static int topup_mmu_memcache(struct kvm_vcpu *vcpu, void *memcache)
> > static enum kvm_pgtable_prot adjust_nested_fault_perms(struct kvm_s2_trans *nested,
> > enum kvm_pgtable_prot prot)
> > {
> > - if (!nested->writable)
> > + if (!(nested->writable && nested->dirty))
> > prot &= ~KVM_PGTABLE_PROT_W;
>
> So if the page gets prot_w if it's either writable or dirty, or both.
> Humm, since we should _not_ have a dirty page that is not writable, that
> could be fine. But then, why test the dirty?
>
> Maybe we should have a KVM_PGTABLE_PROT_D (dirty) as well?
The reasoning here requires zooming out and looking at the full flow of
a nested stage-2 abort.
Suppose an L2 takes a translation fault for an address that is missing
from the shadow stage-2. L0 KVM walks the L1 page tables and arrives at
a writable-clean descriptor for the fault address. That descriptor gets
shadowed into L0 KVM's shadow stage-2 MMU. Since L0 KVM relies on taking
a permission fault to set the dirty state in the L1 page tables, we can
only install a read-only translation in the shadow stage-2.
Prematurely granting write access would be architecturally incorrect
since the L1 descriptor would remain in a writable-clean state. In the
same vein, setting the page with DBM=1 in the shadow stage-2 would be
incorrect since hardware will relax it to writable-dirty without an
intervening fault that can be used to fix the L1 descriptor.
> > if (!nested->readable)
> > prot &= ~KVM_PGTABLE_PROT_R;
> > diff --git a/arch/arm64/kvm/nested.c b/arch/arm64/kvm/nested.c
> > index b247bc1d83fa..dcc7d0cc7c95 100644
> > --- a/arch/arm64/kvm/nested.c
> > +++ b/arch/arm64/kvm/nested.c
> > @@ -269,6 +269,8 @@ static void compute_s2_permissions(struct kvm_vcpu *vcpu, struct s2_walk_info *w
> >
> > trans->readable = s2ap & BIT(0);
> > trans->writable = s2ap & BIT(1);
> > +
> > + trans->dirty = ws->desc & BIT(7);
> > }
>
> IIUC, both writable and dirty here will always have the same value, as they
> both are set based in the same bit in ws->desc.
>
> Maybe this is intended, but then it's a bit confusing they are not
> both using the s2ap variable.
This is intentional, although this series gives an incomplete picture.
I am separately tracking the dirty state of the descriptor in
anticipation of FEAT_S2PIE support for nested. It just so happens that
in the direct permission model the 'write' and 'dirty' bits are aliased
to the same single bit.
> Another point here is that the actual writable bit should be DBM, at least
> in some scenarios, but this discussion can be contended in the New PTE
> patchset.
>
> Also, nits:
> - any reason for the newline between writable and dirty?
> - should not KVM_PTE_LEAF_ATTR_LO_S2_S2AP_W be used instead of BIT[7] in
> this patch, as it makes more clear what we are checking?
Same thing here: these are both intentional changes in preparation for
supporting direct and indirect permission models at stage-2.
Thanks,
Oliver
next prev parent reply other threads:[~2026-09-21 21:39 UTC|newest]
Thread overview: 90+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-23 18:41 [PATCH 00/22] KVM: arm64: nv: Implement FEAT_HAFDBS, FEAT_HAFT Oliver Upton
2026-06-23 18:41 ` [PATCH 01/22] KVM: arm64: nv: Introduce struct for stage-2 walk step Oliver Upton
2026-09-21 11:30 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 02/22] KVM: arm64: nv: Consolidate computation of stage-2 permissions Oliver Upton
2026-06-23 18:57 ` sashiko-bot
2026-09-21 13:46 ` Leonardo Bras
2026-09-21 21:28 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 03/22] KVM: arm64: nv: Get rid of kvm_s2_trans*() accessors Oliver Upton
2026-09-21 16:18 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 04/22] KVM: arm64: nv: Only shadow writable-dirty guest descs as writable Oliver Upton
2026-06-23 18:58 ` sashiko-bot
2026-06-23 20:05 ` Oliver Upton
2026-09-21 16:51 ` Leonardo Bras
2026-09-21 21:39 ` Oliver Upton [this message]
2026-06-23 18:41 ` [PATCH 05/22] KVM: arm64: nv: Pass an access descriptor for stage-2 walks Oliver Upton
2026-06-23 19:06 ` sashiko-bot
2026-09-21 17:28 ` Leonardo Bras
2026-09-21 21:45 ` Oliver Upton
2026-09-22 14:24 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 06/22] KVM: arm64: nv: Use a helper for stage-2 descriptor updates Oliver Upton
2026-09-22 16:14 ` Leonardo Bras
2026-09-22 16:31 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 07/22] KVM: arm64: nv: Set dirty state at stage-2 Oliver Upton
2026-06-23 19:03 ` sashiko-bot
2026-07-06 16:50 ` Wei-Lin Chang
2026-07-08 7:35 ` Oliver Upton
2026-09-23 14:09 ` Leonardo Bras
2026-09-23 16:46 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 08/22] KVM: arm64: nv: Treat DBM as writable " Oliver Upton
2026-06-23 18:55 ` sashiko-bot
2026-06-23 20:08 ` Oliver Upton
2026-09-23 14:38 ` Leonardo Bras
2026-09-23 17:16 ` Oliver Upton
2026-09-24 17:22 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 09/22] KVM: arm64: Compute S1 permissions as part of s1_walk() Oliver Upton
2026-09-23 15:47 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 10/22] KVM: arm64: Plumb through access descriptor for stage-1 Oliver Upton
2026-09-23 16:21 ` Leonardo Bras
2026-09-23 20:37 ` Oliver Upton
2026-09-25 11:10 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 11/22] KVM: arm64: Use a struct for stage-1 walk context Oliver Upton
2026-09-23 17:03 ` Leonardo Bras
2026-09-23 20:23 ` Oliver Upton
2026-09-25 11:20 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 12/22] KVM: arm64: Create helper for stage-1 descriptor updates Oliver Upton
2026-06-23 18:55 ` sashiko-bot
2026-09-25 14:35 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 13/22] KVM: arm64: Set dirty state at stage-1 Oliver Upton
2026-06-23 18:54 ` sashiko-bot
2026-06-26 15:49 ` Leonardo Bras
2026-06-26 16:03 ` Marc Zyngier
2026-06-29 10:38 ` Leonardo Bras
2026-06-26 17:35 ` Oliver Upton
2026-06-29 10:39 ` Leonardo Bras
2026-09-25 15:07 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 14/22] KVM: arm64: Grant write permission when DBM is set at S1 Oliver Upton
2026-06-23 18:57 ` sashiko-bot
2026-09-25 15:18 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 15/22] KVM: arm64: Don't update descriptors for "non-arch" access Oliver Upton
2026-09-25 15:51 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 16/22] KVM: arm64: nv: Expose FEAT_HAFDBS Oliver Upton
2026-06-23 19:01 ` sashiko-bot
2026-09-25 15:53 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 17/22] KVM: arm64: Set Access flag on table descriptors at stage-1 Oliver Upton
2026-06-23 20:56 ` sashiko-bot
2026-09-28 14:33 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 18/22] KVM: arm64: nv: Set access flag on table descriptors at stage-2 Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-06-23 20:14 ` Oliver Upton
2026-09-28 14:40 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 19/22] KVM: arm64: nv: Expose FEAT_HAFT Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-09-28 14:42 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 20/22] KVM: arm64: selftests: Only test AF behavior for emulated AT insns Oliver Upton
2026-09-28 16:01 ` Leonardo Bras
2026-06-23 18:42 ` [PATCH 21/22] KVM: arm64: selftests: Test AT emulation for FEAT_HAFT Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-06-23 20:17 ` Oliver Upton
2026-09-28 17:06 ` Leonardo Bras
2026-06-23 18:42 ` [PATCH 22/22] HACK: KVM: arm64: nv: Set the dirty state for CMOs that fetch for write Oliver Upton
2026-07-01 10:16 ` Wei-Lin Chang
2026-07-01 17:33 ` Oliver Upton
2026-07-02 6:50 ` Wei-Lin Chang
2026-09-28 17:21 ` Leonardo Bras
2026-06-26 15:31 ` [PATCH 00/22] KVM: arm64: nv: Implement FEAT_HAFDBS, FEAT_HAFT Leonardo Bras
2026-06-26 17:12 ` Marc Zyngier
2026-06-26 17:45 ` Oliver Upton
2026-06-29 10:37 ` Leonardo Bras
2026-06-29 10:29 ` Leonardo Bras
2026-09-18 14:55 ` Leonardo Bras
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arGkC3uv6z7z5d8K@kernel.org \
--to=oupton@kernel.org \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=leo.bras@arm.com \
--cc=maz@kernel.org \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.