From: Sascha Bischoff <Sascha.Bischoff@arm.com>
To: "sashiko-reviews@lists.linux.dev" <sashiko-reviews@lists.linux.dev>
Cc: "maz@kernel.org" <maz@kernel.org>,
"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
"kvmarm@lists.linux.dev" <kvmarm@lists.linux.dev>,
"oupton@kernel.org" <oupton@kernel.org>, nd <nd@arm.com>
Subject: Re: [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region
Date: Fri, 4 Sep 2026 09:59:09 +0000 [thread overview]
Message-ID: <15f92744b6da7cd67196895789088e8b04986502.camel@arm.com> (raw)
In-Reply-To: <20260807162053.3AEC71F000E9@smtp.kernel.org>
On Fri, 2026-08-07 at 16:20 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [High] Userspace can inject an inconsistent state by setting
> IRS_IST_BASER.valid=1 without allocating a host IST, leading to a
> CONSTRAINED UNPREDICTABLE hardware state if the guest subsequently
> clears the valid bit.
> --
>
> --- Patch [32]: [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace
> accesses to IRS MMIO region ---
> commit 24ee880222eb3e4ff06c9b27b1d655da134efd7a
> Author: Sascha Bischoff <Sascha.Bischoff@arm.com>
> Date: Fri Aug 7 11:28:54 2026 +0000
>
> KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region
>
> As part of saving and restoring the state of a GICv5-based system,
> userspace must save and restore the IRS MMIO registers. These include
> important information such as the guest IST configuration, and KVM
> must present consistent state to the guest after migration.
>
> > diff --git a/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > b/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > index 095046c7959fa..212066b8d7ed5 100644
> > --- a/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > +++ b/arch/arm64/kvm/vgic/vgic-irs-v5.c
> [ ... ]
> > +static int vgic_v5_mmio_uaccess_write_irs(struct kvm_vcpu *vcpu,
> > gpa_t addr,
> > + unsigned int len,
> > unsigned long val)
> > +{
> > + struct vgic_dist *vgic = &vcpu->kvm->arch.vgic;
> > + struct vgic_v5_irs *irs_data = vgic->vgic_v5_irs_data;
> > + size_t offset = addr & (SZ_64K - 1);
> >
> > - /* The address cannot be changed while the IST is
> > valid. */
> > - if (irs->ist_baser.valid && valid)
> > - return;
> > + /*
> > + * The following registers are ONLY settable via
> > uaccesses. The guest
> > + * cannot write them!
> > + */
> >
> > - /* Valid -> Invalid */
> > - if (irs->ist_baser.valid && !valid) {
> > - /* Make the LPI IST invalid and then ...
> > */
> > - if
> > (irq_set_vcpu_affinity(vgic_v5_vpe_db(vcpu), &cmd))
> > - break;
> > + switch (offset) {
> [ ... ]
> > + case GICV5_IRS_IST_BASER:
> > + if (irs_data->ist_baser.valid &&
> > + !vgic_v5_ist_baser_matches(irs_data, val))
> > + return -EINVAL;
> > +
> > + vgic_v5_update_irs_ist_baser(irs_data, val);
> > + break;
>
> [Severity: High]
> Does this allow userspace to inject an inconsistent state?
>
> If userspace sets the valid bit of GICV5_IRS_IST_BASER to 1 via
> vgic_v5_mmio_uaccess_write_irs() but does not actually allocate a
> host LPI IST
> (by omitting the KVM_DEV_ARM_VGIC_GRP_IST ioctl), the VM can still be
> started.
>
> When the guest subsequently clears the valid bit, KVM's MMIO handler:
>
> vgic_v5_write_irs_ist_baser() {
> ...
> if (irs->ist_baser.valid && !valid) {
> /* Make the LPI IST invalid and then ... */
> rc = irq_set_vcpu_affinity(vgic_v5_vpe_db(vcpu), &cmd);
>
> detects a Valid -> Invalid transition and issues the
> LPI_VIST_MAKE_INVALID
> command. This sends an unmap command to the hardware for a VIST that
> was never
> mapped.
>
> Since this results in CONSTRAINED UNPREDICTABLE hardware behavior,
> should KVM
> reject uaccess writes that set the valid bit without a backing IST,
> or perhaps
> verify IST presence before issuing the unmap command?
>
Right, this is an issue. I've added some tracking in such that when
userspace sets the IRS_IST_BASER.Valid bit it must also restore an LPI
IST. Without that, we now fail KVM_RUN. This means that the userspace-
set state must be consistent with the state being provided to the
hardware (via the VMTE) for the guest to be runnable.
This change spans this commit and "KVM: arm64: gic-v5: Implement
save/restore mechanisms for ISTs".
Thanks,
Sascha
next prev parent reply other threads:[~2026-09-04 9:59 UTC|newest]
Thread overview: 118+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 11:12 [PATCH v5 00/49] KVM: arm64: Add GICv5 IRS support Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 01/49] irqchip/gic-v5: Allow KVM setup without a maintenance IRQ Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 02/49] irqchip/gic-v5: Provide OF IRS config frame attrs to KVM Sascha Bischoff
2026-08-07 11:53 ` sashiko-bot
2026-09-03 14:20 ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 03/49] irqchip/gic-v5: Set up gic_kvm_info on ACPI hosts Sascha Bischoff
2026-08-07 12:01 ` sashiko-bot
2026-09-03 14:22 ` Sascha Bischoff
2026-08-07 13:44 ` Lorenzo Pieralisi
2026-09-03 14:25 ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 04/49] KVM: arm64: gic-v5: Define remaining IRS MMIO registers Sascha Bischoff
2026-08-07 12:05 ` sashiko-bot
2026-09-03 14:34 ` Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 05/49] arm64/sysreg: Add GICv5 GIC VDPEND encoding Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 06/49] arm64/sysreg: Update ICC_CR0_EL1 with LINK and LINK_IDLE fields Sascha Bischoff
2026-08-07 12:17 ` sashiko-bot
2026-09-03 16:33 ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 07/49] KVM: arm64: gic-v5: Cache host IRS ID registers Sascha Bischoff
2026-08-07 12:27 ` sashiko-bot
2026-09-04 6:36 ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 08/49] KVM: arm64: gic-v5: Add VPE doorbell domain Sascha Bischoff
2026-08-07 12:45 ` sashiko-bot
2026-09-04 7:27 ` Sascha Bischoff
2026-08-07 11:17 ` [PATCH v5 09/49] KVM: arm64: gic-v5: Create and manage VM and VPE tables Sascha Bischoff
2026-08-07 12:50 ` sashiko-bot
2026-09-04 8:00 ` Sascha Bischoff
2026-08-07 11:17 ` [PATCH v5 10/49] KVM: arm64: gic-v5: Introduce guest IST alloc and management Sascha Bischoff
2026-08-07 13:07 ` sashiko-bot
2026-09-04 8:08 ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 11/49] KVM: arm64: gic-v5: Implement VMT/vIST IRS MMIO Ops Sascha Bischoff
2026-08-07 13:13 ` sashiko-bot
2026-09-04 8:15 ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 12/49] KVM: arm64: gic-v5: Keep GICv5 vCPU limit model-specific Sascha Bischoff
2026-08-07 13:30 ` sashiko-bot
2026-09-04 10:03 ` Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 13/49] KVM: arm64: gic-v5: Implement VPE IRS MMIO Ops Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 14/49] KVM: arm64: gic-v5: Set up VMTEs and VPE doorbells Sascha Bischoff
2026-08-07 13:42 ` sashiko-bot
2026-09-04 8:22 ` Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 15/49] KVM: arm64: gic-v5: Add resident/non-resident hyp calls Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 16/49] KVM: arm64: gic-v5: Request doorbells when VPEs enter WFI Sascha Bischoff
2026-08-07 14:17 ` sashiko-bot
2026-09-04 8:31 ` Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 17/49] KVM: arm64: gic-v5: Introduce struct vgic_v5_irs and IRS base address Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 18/49] KVM: arm64: gic-v5: Add IRS IODEV support to MMIO handlers Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 19/49] KVM: arm64: gic-v5: Add KVM_VGIC_V5_ADDR_TYPE_IRS to UAPI Sascha Bischoff
2026-08-07 14:27 ` sashiko-bot
2026-09-04 8:42 ` Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 20/49] KVM: arm64: gic-v5: Add GICv5 IRS IODEV and MMIO emulation Sascha Bischoff
2026-08-07 14:34 ` sashiko-bot
2026-09-04 8:47 ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 21/49] KVM: arm64: gic-v5: Initialise per-VM IRS state Sascha Bischoff
2026-08-07 14:49 ` sashiko-bot
2026-09-04 8:51 ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 22/49] KVM: arm64: gic-v5: Register the IRS IODEV Sascha Bischoff
2026-08-07 14:52 ` sashiko-bot
2026-09-04 8:57 ` Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 23/49] KVM: arm64: gic-v5: Set IRICHPPIDIS based on IRS enable state Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 24/49] KVM: arm64: selftests: Update vGICv5 selftest to set IRS address Sascha Bischoff
2026-08-07 15:04 ` sashiko-bot
2026-09-04 9:03 ` Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 25/49] KVM: arm64: gic-v5: Add GIC VDPEND hyp call Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 26/49] KVM: arm64: gic: Introduce set_pending_state() to irq_ops Sascha Bischoff
2026-08-07 15:14 ` sashiko-bot
2026-09-04 9:28 ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 27/49] KVM: arm64: gic-v5: Support SPI injection Sascha Bischoff
2026-08-07 15:23 ` sashiko-bot
2026-09-04 9:22 ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 28/49] Documentation: KVM: Extend VGICv5 device attribute docs Sascha Bischoff
2026-08-07 15:29 ` sashiko-bot
2026-09-04 9:30 ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 29/49] KVM: arm64: gic-v5: Add GICv5 SPI injection to irqfd Sascha Bischoff
2026-08-07 15:40 ` sashiko-bot
2026-09-04 9:47 ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 30/49] KVM: arm64: gic-v5: Mask per-vCPU PPI state in vgic_v5_finalize_ppi_state() Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 31/49] KVM: arm64: gic-v5: Add GICv5 EL1 sysreg userspace accessors Sascha Bischoff
2026-08-07 16:27 ` sashiko-bot
2026-09-04 10:01 ` Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region Sascha Bischoff
2026-08-07 16:20 ` sashiko-bot
2026-09-04 9:59 ` Sascha Bischoff [this message]
2026-08-07 11:29 ` [PATCH v5 33/49] KVM: arm64: gic-v5: Add CoreSight MMIO regs to IRS Sascha Bischoff
2026-08-07 11:29 ` [PATCH v5 34/49] KVM: arm64: gic-v5: Add VGICv5 IST save/restore UAPI Sascha Bischoff
2026-08-07 16:30 ` sashiko-bot
2026-09-04 10:06 ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 35/49] KVM: arm64: gic-v5: Implement save/restore mechanisms for ISTs Sascha Bischoff
2026-08-07 16:48 ` sashiko-bot
2026-09-04 10:23 ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 36/49] Documentation: KVM: Document KVM_DEV_ARM_VGIC_GRP_CPU_SYSREGS for VGICv5 Sascha Bischoff
2026-08-07 16:55 ` sashiko-bot
2026-09-04 11:04 ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 37/49] Documentation: KVM: Add KVM_DEV_ARM_VGIC_GRP_IRS_REGS to VGICv5 docs Sascha Bischoff
2026-08-07 16:52 ` sashiko-bot
2026-09-04 10:09 ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 38/49] Documentation: KVM: Add docs for KVM_DEV_ARM_VGIC_GRP_IST Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 39/49] Documentation: KVM: Add the VGICv5 IRS save/restore sequences Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 40/49] KVM: selftests: Add VGICv5 IRS address attribute tests Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 41/49] KVM: selftests: Add VGICv5 NR_IRQS " Sascha Bischoff
2026-08-07 17:12 ` sashiko-bot
2026-09-04 10:15 ` Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 42/49] KVM: selftests: Add VGICv5 IRS_REGS " Sascha Bischoff
2026-08-07 17:17 ` sashiko-bot
2026-09-04 10:38 ` Sascha Bischoff
2026-08-07 11:34 ` [PATCH v5 43/49] KVM: selftests: Add VGICv5 IST " Sascha Bischoff
2026-08-07 17:21 ` sashiko-bot
2026-09-04 10:45 ` Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 44/49] KVM: selftests: Add VGICv5 USERSPACE_PPIS tests Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 45/49] KVM: selftests: Add VGICv5 CPU sysreg attribute tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 46/49] KVM: selftests: Add VGICv5 SPI injection tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 47/49] KVM: selftests: Add VGICv5 LPI delivery tests Sascha Bischoff
2026-08-07 17:39 ` sashiko-bot
2026-09-04 10:48 ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 48/49] KVM: selftests: Add VGICv5 IST save/restore coverage Sascha Bischoff
2026-08-07 17:50 ` sashiko-bot
2026-09-04 10:54 ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 49/49] KVM: selftests: Add VGICv5 sparse vCPU IDs test Sascha Bischoff
2026-08-07 17:56 ` sashiko-bot
2026-09-04 10:57 ` Sascha Bischoff
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=15f92744b6da7cd67196895789088e8b04986502.camel@arm.com \
--to=sascha.bischoff@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=nd@arm.com \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox