From: Leonardo Bras <leo.bras@arm.com>
To: Oliver Upton <oupton@kernel.org>
Cc: Leonardo Bras <leo.bras@arm.com>,
kvmarm@lists.linux.dev, Marc Zyngier <maz@kernel.org>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Steffen Eiden <seiden@linux.ibm.com>
Subject: Re: [PATCH 21/22] KVM: arm64: selftests: Test AT emulation for FEAT_HAFT
Date: Mon, 28 Sep 2026 18:06:46 +0100 [thread overview]
Message-ID: <arqeptfuCm4W5T-3@LeoBrasDK> (raw)
In-Reply-To: <20260623184201.1518871-22-oupton@kernel.org>
On Tue, Jun 23, 2026 at 11:42:00AM -0700, Oliver Upton wrote:
> Test that KVM's AT emulation sets the access flag on table descriptors
> when FEAT_HAFT is enabled at stage-1. Additionally, add test coverage
> that asserts the access flag is clear on table/page descriptors when the
> AT instruction generates an access flag fault.
>
> Signed-off-by: Oliver Upton <oupton@kernel.org>
> ---
> tools/testing/selftests/kvm/arm64/at.c | 74 +++++++++++++++++++++++---
> 1 file changed, 66 insertions(+), 8 deletions(-)
>
> diff --git a/tools/testing/selftests/kvm/arm64/at.c b/tools/testing/selftests/kvm/arm64/at.c
> index d7289f3df04f..fb7399736f44 100644
> --- a/tools/testing/selftests/kvm/arm64/at.c
> +++ b/tools/testing/selftests/kvm/arm64/at.c
> @@ -13,10 +13,11 @@
>
> enum {
> CLEAR_ACCESS_FLAG,
> - TEST_ACCESS_FLAG,
> + ASSERT_ACCESS_FLAG_SET,
> + ASSERT_ACCESS_FLAG_CLEAR,
Rename Test_AF to ASSERT_ACCESS_FLAG_SET, and add a new test to
check if the AF is clear.
> };
>
> -static u64 *ptep_hva;
> +static u64 *page_ptep, *table_ptep;
>
So tables' AF can be checked.
> #define copy_el2_to_el1(reg) \
> write_sysreg_s(read_sysreg_s(SYS_##reg##_EL1), SYS_##reg##_EL12)
> @@ -45,11 +46,12 @@ do { \
> __GUEST_ASSERT(fsc == ESR_ELx_FSC_ACCESS_L(3), \
> "AT "#op": expected access flag fault (par: %lx)", \
> par); \
> + GUEST_SYNC(ASSERT_ACCESS_FLAG_CLEAR); \
> } else { \
> GUEST_ASSERT_EQ(FIELD_GET(SYS_PAR_EL1_ATTR, par), MAIR_ATTR_NORMAL); \
> GUEST_ASSERT_EQ(FIELD_GET(SYS_PAR_EL1_SH, par), PTE_SHARED >> 8); \
> GUEST_ASSERT_EQ(par & SYS_PAR_EL1_PA, TEST_ADDR); \
> - GUEST_SYNC(TEST_ACCESS_FLAG); \
> + GUEST_SYNC(ASSERT_ACCESS_FLAG_SET); \
If fault is expected, check if the AF is clear,
if fault is not expected, check if the AF is set.
> } \
> } while (0)
>
> @@ -68,6 +70,14 @@ static void test_at(bool expect_fault)
> isb();
> }
>
> +static bool guest_has_haft(void)
> +{
> + u64 mmfr1 = read_sysreg(id_aa64mmfr1_el1);
> +
> + return SYS_FIELD_GET(ID_AA64MMFR1_EL1, HAFDBS, mmfr1) >=
> + ID_AA64MMFR1_EL1_HAFDBS_HAFT;
> +}
> +
> static void guest_code(void)
> {
> /* Reuse the stage-1 MMU context from EL2 at EL1 */
> @@ -93,9 +103,43 @@ static void guest_code(void)
> isb();
> test_at(false);
>
> + if (!guest_has_haft())
> + GUEST_DONE();
Previous HAF test ends here, all below is about HAFT.
> +
> + sysrec_clear_set_s(SYS_HCRX_EL2, 0, HCRX_EL2_TCR2En);
> + sysreg_clear_set_s(SYS_TCR2_EL12, 0, TCR2_EL1_HAFT);
> + isb();
> + test_at(false);
No trapping when writing to TCR2_EL1, then write to TCR2_EL12 (can redirect
to TCR_EL1) to enable HAFT. When tested, AF should be set, and a fault is
not expected. Seems right.
> +
> + /* The effective value of HAFT is 0 if HA is 0 */
> + sysreg_clear_set_s(SYS_TCR_EL12, TCR_HA, 0);
> + isb();
> + test_at(true);
Now clears TCR_EL21.HA, which means HAFT should not work as well, not
setting a AF for neither, and causing a fault. Assert will test if both
pte and ptet AF will be zeroed.
Seems right for testing HAFT -> HA dependency.
> +
> + /* The effective value of HAFT is 0 if HCRX_EL2.TCR2En is 0 */
> + sysreg_clear_set_s(SYS_HCRX_EL2, HCRX_EL2_TCR2En, 0);
> + sysreg_clear_set_s(SYS_TCR_EL12, 0, TCR_HA);
> + isb();
> + test_at(false);
Cleans HCRX_EL2_TCR2En then re-enables HA, which means HA should be
enabled, but HAFT should not.
Since it expect not to fault, it means it's expecting the flags to be set,
running ASSERT_ACCESS_FLAG_SET. That will check if the pte.AF==1, then
since HCRX_EL2_TCR2En=0, vcpu_haft_enabled() returns 0, and
ASSERT_ACCESS_FLAG_SET checks if ptet.AF==0.
Seems correct so far.
It's kind of hard to follow all the flag status by the test routine alone,
though. The previous test was just a single flag, which was always set when
a fault did not happen. Now we have two flags, and the second one which
don't directly relate to the faulting.
Thanks to that, the testing logic of the second flag has to happen in the
handle_sync code, which seems decoupled from the guest test.
Maybe it could be more clear if test_at() received parameters related to
ptet_af_set as well, and we could have a second GUEST_SYNC to check if the
ptet.AF is either set or reset, based on that parameter?
Or maybe I am overthinking this.
In any case, seems to test the feature correctly.
With the fix of sashiko's typo, FWIW:
Reviewed-by: Leonardo Bras <leo.bras@arm.com>
Thanks!
Leo
> +
> GUEST_DONE();
> }
>
> +static bool vcpu_haft_enabled(struct kvm_vcpu *vcpu)
> +{
> + u64 mmfr1 = vcpu_get_reg(vcpu, KVM_ARM64_SYS_REG(SYS_ID_AA64MMFR1_EL1));
> + u8 hafdbs = SYS_FIELD_GET(ID_AA64MMFR1_EL1, HAFDBS, mmfr1);
> + u64 tcr2, hcrx;
> +
> + /* FEAT_HAFT implies FEAT_TCRX, FEAT_HCX */
> + if (hafdbs < ID_AA64MMFR1_EL1_HAFDBS_HAFT)
> + return false;
> +
> + hcrx = vcpu_get_reg(vcpu, KVM_ARM64_SYS_REG(SYS_HCRX_EL2));
> + tcr2 = vcpu_get_reg(vcpu, KVM_ARM64_SYS_REG(SYS_TCR2_EL1));
> + return hcrx & HCRX_EL2_TCR2En && tcr2 & TCR2_EL1_HAFT;
> +}
> +
> static void handle_sync(struct kvm_vcpu *vcpu, struct ucall *uc)
> {
> switch (uc->args[1]) {
> @@ -109,12 +153,25 @@ static void handle_sync(struct kvm_vcpu *vcpu, struct ucall *uc)
> * ensures that the access flag cannot be set speculatively
> * and is reliably cleared at the time of the AT instruction.
> */
> - clear_bit(__ffs(PTE_AF), ptep_hva);
> + clear_bit(__ffs(PTE_AF), page_ptep);
> + clear_bit(__ffs(PTE_AF), table_ptep);
> vm_mem_region_reload(vcpu->vm, vcpu->vm->memslots[MEM_REGION_PT]);
> break;
> - case TEST_ACCESS_FLAG:
> - TEST_ASSERT(test_bit(__ffs(PTE_AF), ptep_hva),
> - "Expected access flag to be set (desc: %lu)", *ptep_hva);
> + case ASSERT_ACCESS_FLAG_SET:
> + TEST_ASSERT(test_bit(__ffs(PTE_AF), page_ptep),
> + "Expected access flag to be set (desc: %lu)", *page_ptep);
> + if (!vcpu_haft_enabled(vcpu))
> + TEST_ASSERT(!test_bit(__ffs(PTE_AF), table_ptep),
> + "Expected access flag to be clear (desc: %lu)", *table_ptep);
> + else
> + TEST_ASSERT(test_bit(__ffs(PTE_AF), table_ptep),
> + "Expected access flag to be set (desc: %lu)", *table_ptep);
> + break;
> + case ASSERT_ACCESS_FLAG_CLEAR:
> + TEST_ASSERT(!test_bit(__ffs(PTE_AF), page_ptep),
> + "Expected access flag to be clear (desc: %lu)", *page_ptep);
> + TEST_ASSERT(!test_bit(__ffs(PTE_AF), table_ptep),
> + "Expected access flag to be clear (desc: %lu)", *table_ptep);
> break;
> default:
> TEST_FAIL("Unexpected SYNC arg: %lu", uc->args[1]);
> @@ -158,7 +215,8 @@ int main(void)
> kvm_arch_vm_finalize_vcpus(vm);
>
> virt_map(vm, TEST_ADDR, TEST_ADDR, 1);
> - ptep_hva = virt_get_pte_hva_at_level(vm, TEST_ADDR, 3);
> + page_ptep = virt_get_pte_hva_at_level(vm, TEST_ADDR, 3);
> + table_ptep = virt_get_pte_hva_at_level(vm, TEST_ADDR, 2);
> run_test(vcpu);
>
> kvm_vm_free(vm);
> --
> 2.47.3
>
next prev parent reply other threads:[~2026-09-28 17:06 UTC|newest]
Thread overview: 90+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-23 18:41 [PATCH 00/22] KVM: arm64: nv: Implement FEAT_HAFDBS, FEAT_HAFT Oliver Upton
2026-06-23 18:41 ` [PATCH 01/22] KVM: arm64: nv: Introduce struct for stage-2 walk step Oliver Upton
2026-09-21 11:30 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 02/22] KVM: arm64: nv: Consolidate computation of stage-2 permissions Oliver Upton
2026-06-23 18:57 ` sashiko-bot
2026-09-21 13:46 ` Leonardo Bras
2026-09-21 21:28 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 03/22] KVM: arm64: nv: Get rid of kvm_s2_trans*() accessors Oliver Upton
2026-09-21 16:18 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 04/22] KVM: arm64: nv: Only shadow writable-dirty guest descs as writable Oliver Upton
2026-06-23 18:58 ` sashiko-bot
2026-06-23 20:05 ` Oliver Upton
2026-09-21 16:51 ` Leonardo Bras
2026-09-21 21:39 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 05/22] KVM: arm64: nv: Pass an access descriptor for stage-2 walks Oliver Upton
2026-06-23 19:06 ` sashiko-bot
2026-09-21 17:28 ` Leonardo Bras
2026-09-21 21:45 ` Oliver Upton
2026-09-22 14:24 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 06/22] KVM: arm64: nv: Use a helper for stage-2 descriptor updates Oliver Upton
2026-09-22 16:14 ` Leonardo Bras
2026-09-22 16:31 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 07/22] KVM: arm64: nv: Set dirty state at stage-2 Oliver Upton
2026-06-23 19:03 ` sashiko-bot
2026-07-06 16:50 ` Wei-Lin Chang
2026-07-08 7:35 ` Oliver Upton
2026-09-23 14:09 ` Leonardo Bras
2026-09-23 16:46 ` Oliver Upton
2026-06-23 18:41 ` [PATCH 08/22] KVM: arm64: nv: Treat DBM as writable " Oliver Upton
2026-06-23 18:55 ` sashiko-bot
2026-06-23 20:08 ` Oliver Upton
2026-09-23 14:38 ` Leonardo Bras
2026-09-23 17:16 ` Oliver Upton
2026-09-24 17:22 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 09/22] KVM: arm64: Compute S1 permissions as part of s1_walk() Oliver Upton
2026-09-23 15:47 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 10/22] KVM: arm64: Plumb through access descriptor for stage-1 Oliver Upton
2026-09-23 16:21 ` Leonardo Bras
2026-09-23 20:37 ` Oliver Upton
2026-09-25 11:10 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 11/22] KVM: arm64: Use a struct for stage-1 walk context Oliver Upton
2026-09-23 17:03 ` Leonardo Bras
2026-09-23 20:23 ` Oliver Upton
2026-09-25 11:20 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 12/22] KVM: arm64: Create helper for stage-1 descriptor updates Oliver Upton
2026-06-23 18:55 ` sashiko-bot
2026-09-25 14:35 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 13/22] KVM: arm64: Set dirty state at stage-1 Oliver Upton
2026-06-23 18:54 ` sashiko-bot
2026-06-26 15:49 ` Leonardo Bras
2026-06-26 16:03 ` Marc Zyngier
2026-06-29 10:38 ` Leonardo Bras
2026-06-26 17:35 ` Oliver Upton
2026-06-29 10:39 ` Leonardo Bras
2026-09-25 15:07 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 14/22] KVM: arm64: Grant write permission when DBM is set at S1 Oliver Upton
2026-06-23 18:57 ` sashiko-bot
2026-09-25 15:18 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 15/22] KVM: arm64: Don't update descriptors for "non-arch" access Oliver Upton
2026-09-25 15:51 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 16/22] KVM: arm64: nv: Expose FEAT_HAFDBS Oliver Upton
2026-06-23 19:01 ` sashiko-bot
2026-09-25 15:53 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 17/22] KVM: arm64: Set Access flag on table descriptors at stage-1 Oliver Upton
2026-06-23 20:56 ` sashiko-bot
2026-09-28 14:33 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 18/22] KVM: arm64: nv: Set access flag on table descriptors at stage-2 Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-06-23 20:14 ` Oliver Upton
2026-09-28 14:40 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 19/22] KVM: arm64: nv: Expose FEAT_HAFT Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-09-28 14:42 ` Leonardo Bras
2026-06-23 18:41 ` [PATCH 20/22] KVM: arm64: selftests: Only test AF behavior for emulated AT insns Oliver Upton
2026-09-28 16:01 ` Leonardo Bras
2026-06-23 18:42 ` [PATCH 21/22] KVM: arm64: selftests: Test AT emulation for FEAT_HAFT Oliver Upton
2026-06-23 19:05 ` sashiko-bot
2026-06-23 20:17 ` Oliver Upton
2026-09-28 17:06 ` Leonardo Bras [this message]
2026-06-23 18:42 ` [PATCH 22/22] HACK: KVM: arm64: nv: Set the dirty state for CMOs that fetch for write Oliver Upton
2026-07-01 10:16 ` Wei-Lin Chang
2026-07-01 17:33 ` Oliver Upton
2026-07-02 6:50 ` Wei-Lin Chang
2026-09-28 17:21 ` Leonardo Bras
2026-06-26 15:31 ` [PATCH 00/22] KVM: arm64: nv: Implement FEAT_HAFDBS, FEAT_HAFT Leonardo Bras
2026-06-26 17:12 ` Marc Zyngier
2026-06-26 17:45 ` Oliver Upton
2026-06-29 10:37 ` Leonardo Bras
2026-06-29 10:29 ` Leonardo Bras
2026-09-18 14:55 ` Leonardo Bras
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=arqeptfuCm4W5T-3@LeoBrasDK \
--to=leo.bras@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.