Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Sascha Bischoff <Sascha.Bischoff@arm.com>
To: "sashiko-reviews@lists.linux.dev" <sashiko-reviews@lists.linux.dev>
Cc: "maz@kernel.org" <maz@kernel.org>,
	"kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	"kvmarm@lists.linux.dev" <kvmarm@lists.linux.dev>,
	"oupton@kernel.org" <oupton@kernel.org>, nd <nd@arm.com>
Subject: Re: [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region
Date: Fri, 4 Sep 2026 09:59:09 +0000	[thread overview]
Message-ID: <15f92744b6da7cd67196895789088e8b04986502.camel@arm.com> (raw)
In-Reply-To: <20260807162053.3AEC71F000E9@smtp.kernel.org>

On Fri, 2026-08-07 at 16:20 +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [High] Userspace can inject an inconsistent state by setting
> IRS_IST_BASER.valid=1 without allocating a host IST, leading to a
> CONSTRAINED UNPREDICTABLE hardware state if the guest subsequently
> clears the valid bit.
> --
> 
> --- Patch [32]: [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace
> accesses to IRS MMIO region ---
> commit 24ee880222eb3e4ff06c9b27b1d655da134efd7a
> Author: Sascha Bischoff <Sascha.Bischoff@arm.com>
> Date:   Fri Aug 7 11:28:54 2026 +0000
> 
> KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region
>     
> As part of saving and restoring the state of a GICv5-based system,
> userspace must save and restore the IRS MMIO registers. These include
> important information such as the guest IST configuration, and KVM
> must present consistent state to the guest after migration.
> 
> > diff --git a/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > b/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > index 095046c7959fa..212066b8d7ed5 100644
> > --- a/arch/arm64/kvm/vgic/vgic-irs-v5.c
> > +++ b/arch/arm64/kvm/vgic/vgic-irs-v5.c
> [ ... ]
> > +static int vgic_v5_mmio_uaccess_write_irs(struct kvm_vcpu *vcpu,
> > gpa_t addr,
> > +					  unsigned int len,
> > unsigned long val)
> > +{
> > +	struct vgic_dist *vgic = &vcpu->kvm->arch.vgic;
> > +	struct vgic_v5_irs *irs_data = vgic->vgic_v5_irs_data;
> > +	size_t offset = addr & (SZ_64K - 1);
> >  
> > -		/* The address cannot be changed while the IST is
> > valid. */
> > -		if (irs->ist_baser.valid && valid)
> > -			return;
> > +	/*
> > +	 * The following registers are ONLY settable via
> > uaccesses. The guest
> > +	 * cannot write them!
> > +	 */
> >  
> > -		/* Valid -> Invalid */
> > -		if (irs->ist_baser.valid && !valid) {
> > -			/* Make the LPI IST invalid and then ...
> > */
> > -			if
> > (irq_set_vcpu_affinity(vgic_v5_vpe_db(vcpu), &cmd))
> > -				break;
> > +	switch (offset) {
> [ ... ]
> > +	case GICV5_IRS_IST_BASER:
> > +		if (irs_data->ist_baser.valid &&
> > +		    !vgic_v5_ist_baser_matches(irs_data, val))
> > +			return -EINVAL;
> > +
> > +		vgic_v5_update_irs_ist_baser(irs_data, val);
> > +		break;
> 
> [Severity: High]
> Does this allow userspace to inject an inconsistent state?
> 
> If userspace sets the valid bit of GICV5_IRS_IST_BASER to 1 via
> vgic_v5_mmio_uaccess_write_irs() but does not actually allocate a
> host LPI IST
> (by omitting the KVM_DEV_ARM_VGIC_GRP_IST ioctl), the VM can still be
> started.
> 
> When the guest subsequently clears the valid bit, KVM's MMIO handler:
> 
> vgic_v5_write_irs_ist_baser() {
>     ...
>     if (irs->ist_baser.valid && !valid) {
>         /* Make the LPI IST invalid and then ... */
>         rc = irq_set_vcpu_affinity(vgic_v5_vpe_db(vcpu), &cmd);
> 
> detects a Valid -> Invalid transition and issues the
> LPI_VIST_MAKE_INVALID
> command. This sends an unmap command to the hardware for a VIST that
> was never
> mapped.
> 
> Since this results in CONSTRAINED UNPREDICTABLE hardware behavior,
> should KVM
> reject uaccess writes that set the valid bit without a backing IST,
> or perhaps
> verify IST presence before issuing the unmap command?
> 

Right, this is an issue. I've added some tracking in such that when
userspace sets the IRS_IST_BASER.Valid bit it must also restore an LPI
IST. Without that, we now fail KVM_RUN. This means that the userspace-
set state must be consistent with the state being provided to the
hardware (via the VMTE) for the guest to be runnable.

This change spans this commit and "KVM: arm64: gic-v5: Implement
save/restore mechanisms for ISTs".

Thanks,
Sascha

  reply	other threads:[~2026-09-04  9:59 UTC|newest]

Thread overview: 118+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-07 11:12 [PATCH v5 00/49] KVM: arm64: Add GICv5 IRS support Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 01/49] irqchip/gic-v5: Allow KVM setup without a maintenance IRQ Sascha Bischoff
2026-08-07 11:13 ` [PATCH v5 02/49] irqchip/gic-v5: Provide OF IRS config frame attrs to KVM Sascha Bischoff
2026-08-07 11:53   ` sashiko-bot
2026-09-03 14:20     ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 03/49] irqchip/gic-v5: Set up gic_kvm_info on ACPI hosts Sascha Bischoff
2026-08-07 12:01   ` sashiko-bot
2026-09-03 14:22     ` Sascha Bischoff
2026-08-07 13:44   ` Lorenzo Pieralisi
2026-09-03 14:25     ` Sascha Bischoff
2026-08-07 11:14 ` [PATCH v5 04/49] KVM: arm64: gic-v5: Define remaining IRS MMIO registers Sascha Bischoff
2026-08-07 12:05   ` sashiko-bot
2026-09-03 14:34     ` Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 05/49] arm64/sysreg: Add GICv5 GIC VDPEND encoding Sascha Bischoff
2026-08-07 11:15 ` [PATCH v5 06/49] arm64/sysreg: Update ICC_CR0_EL1 with LINK and LINK_IDLE fields Sascha Bischoff
2026-08-07 12:17   ` sashiko-bot
2026-09-03 16:33     ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 07/49] KVM: arm64: gic-v5: Cache host IRS ID registers Sascha Bischoff
2026-08-07 12:27   ` sashiko-bot
2026-09-04  6:36     ` Sascha Bischoff
2026-08-07 11:16 ` [PATCH v5 08/49] KVM: arm64: gic-v5: Add VPE doorbell domain Sascha Bischoff
2026-08-07 12:45   ` sashiko-bot
2026-09-04  7:27     ` Sascha Bischoff
2026-08-07 11:17 ` [PATCH v5 09/49] KVM: arm64: gic-v5: Create and manage VM and VPE tables Sascha Bischoff
2026-08-07 12:50   ` sashiko-bot
2026-09-04  8:00     ` Sascha Bischoff
2026-08-07 11:17 ` [PATCH v5 10/49] KVM: arm64: gic-v5: Introduce guest IST alloc and management Sascha Bischoff
2026-08-07 13:07   ` sashiko-bot
2026-09-04  8:08     ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 11/49] KVM: arm64: gic-v5: Implement VMT/vIST IRS MMIO Ops Sascha Bischoff
2026-08-07 13:13   ` sashiko-bot
2026-09-04  8:15     ` Sascha Bischoff
2026-08-07 11:18 ` [PATCH v5 12/49] KVM: arm64: gic-v5: Keep GICv5 vCPU limit model-specific Sascha Bischoff
2026-08-07 13:30   ` sashiko-bot
2026-09-04 10:03     ` Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 13/49] KVM: arm64: gic-v5: Implement VPE IRS MMIO Ops Sascha Bischoff
2026-08-07 11:19 ` [PATCH v5 14/49] KVM: arm64: gic-v5: Set up VMTEs and VPE doorbells Sascha Bischoff
2026-08-07 13:42   ` sashiko-bot
2026-09-04  8:22     ` Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 15/49] KVM: arm64: gic-v5: Add resident/non-resident hyp calls Sascha Bischoff
2026-08-07 11:20 ` [PATCH v5 16/49] KVM: arm64: gic-v5: Request doorbells when VPEs enter WFI Sascha Bischoff
2026-08-07 14:17   ` sashiko-bot
2026-09-04  8:31     ` Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 17/49] KVM: arm64: gic-v5: Introduce struct vgic_v5_irs and IRS base address Sascha Bischoff
2026-08-07 11:21 ` [PATCH v5 18/49] KVM: arm64: gic-v5: Add IRS IODEV support to MMIO handlers Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 19/49] KVM: arm64: gic-v5: Add KVM_VGIC_V5_ADDR_TYPE_IRS to UAPI Sascha Bischoff
2026-08-07 14:27   ` sashiko-bot
2026-09-04  8:42     ` Sascha Bischoff
2026-08-07 11:22 ` [PATCH v5 20/49] KVM: arm64: gic-v5: Add GICv5 IRS IODEV and MMIO emulation Sascha Bischoff
2026-08-07 14:34   ` sashiko-bot
2026-09-04  8:47     ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 21/49] KVM: arm64: gic-v5: Initialise per-VM IRS state Sascha Bischoff
2026-08-07 14:49   ` sashiko-bot
2026-09-04  8:51     ` Sascha Bischoff
2026-08-07 11:23 ` [PATCH v5 22/49] KVM: arm64: gic-v5: Register the IRS IODEV Sascha Bischoff
2026-08-07 14:52   ` sashiko-bot
2026-09-04  8:57     ` Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 23/49] KVM: arm64: gic-v5: Set IRICHPPIDIS based on IRS enable state Sascha Bischoff
2026-08-07 11:24 ` [PATCH v5 24/49] KVM: arm64: selftests: Update vGICv5 selftest to set IRS address Sascha Bischoff
2026-08-07 15:04   ` sashiko-bot
2026-09-04  9:03     ` Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 25/49] KVM: arm64: gic-v5: Add GIC VDPEND hyp call Sascha Bischoff
2026-08-07 11:25 ` [PATCH v5 26/49] KVM: arm64: gic: Introduce set_pending_state() to irq_ops Sascha Bischoff
2026-08-07 15:14   ` sashiko-bot
2026-09-04  9:28     ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 27/49] KVM: arm64: gic-v5: Support SPI injection Sascha Bischoff
2026-08-07 15:23   ` sashiko-bot
2026-09-04  9:22     ` Sascha Bischoff
2026-08-07 11:26 ` [PATCH v5 28/49] Documentation: KVM: Extend VGICv5 device attribute docs Sascha Bischoff
2026-08-07 15:29   ` sashiko-bot
2026-09-04  9:30     ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 29/49] KVM: arm64: gic-v5: Add GICv5 SPI injection to irqfd Sascha Bischoff
2026-08-07 15:40   ` sashiko-bot
2026-09-04  9:47     ` Sascha Bischoff
2026-08-07 11:27 ` [PATCH v5 30/49] KVM: arm64: gic-v5: Mask per-vCPU PPI state in vgic_v5_finalize_ppi_state() Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 31/49] KVM: arm64: gic-v5: Add GICv5 EL1 sysreg userspace accessors Sascha Bischoff
2026-08-07 16:27   ` sashiko-bot
2026-09-04 10:01     ` Sascha Bischoff
2026-08-07 11:28 ` [PATCH v5 32/49] KVM: arm64: gic-v5: Handle userspace accesses to IRS MMIO region Sascha Bischoff
2026-08-07 16:20   ` sashiko-bot
2026-09-04  9:59     ` Sascha Bischoff [this message]
2026-08-07 11:29 ` [PATCH v5 33/49] KVM: arm64: gic-v5: Add CoreSight MMIO regs to IRS Sascha Bischoff
2026-08-07 11:29 ` [PATCH v5 34/49] KVM: arm64: gic-v5: Add VGICv5 IST save/restore UAPI Sascha Bischoff
2026-08-07 16:30   ` sashiko-bot
2026-09-04 10:06     ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 35/49] KVM: arm64: gic-v5: Implement save/restore mechanisms for ISTs Sascha Bischoff
2026-08-07 16:48   ` sashiko-bot
2026-09-04 10:23     ` Sascha Bischoff
2026-08-07 11:30 ` [PATCH v5 36/49] Documentation: KVM: Document KVM_DEV_ARM_VGIC_GRP_CPU_SYSREGS for VGICv5 Sascha Bischoff
2026-08-07 16:55   ` sashiko-bot
2026-09-04 11:04     ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 37/49] Documentation: KVM: Add KVM_DEV_ARM_VGIC_GRP_IRS_REGS to VGICv5 docs Sascha Bischoff
2026-08-07 16:52   ` sashiko-bot
2026-09-04 10:09     ` Sascha Bischoff
2026-08-07 11:31 ` [PATCH v5 38/49] Documentation: KVM: Add docs for KVM_DEV_ARM_VGIC_GRP_IST Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 39/49] Documentation: KVM: Add the VGICv5 IRS save/restore sequences Sascha Bischoff
2026-08-07 11:32 ` [PATCH v5 40/49] KVM: selftests: Add VGICv5 IRS address attribute tests Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 41/49] KVM: selftests: Add VGICv5 NR_IRQS " Sascha Bischoff
2026-08-07 17:12   ` sashiko-bot
2026-09-04 10:15     ` Sascha Bischoff
2026-08-07 11:33 ` [PATCH v5 42/49] KVM: selftests: Add VGICv5 IRS_REGS " Sascha Bischoff
2026-08-07 17:17   ` sashiko-bot
2026-09-04 10:38     ` Sascha Bischoff
2026-08-07 11:34 ` [PATCH v5 43/49] KVM: selftests: Add VGICv5 IST " Sascha Bischoff
2026-08-07 17:21   ` sashiko-bot
2026-09-04 10:45     ` Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 44/49] KVM: selftests: Add VGICv5 USERSPACE_PPIS tests Sascha Bischoff
2026-08-07 11:35 ` [PATCH v5 45/49] KVM: selftests: Add VGICv5 CPU sysreg attribute tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 46/49] KVM: selftests: Add VGICv5 SPI injection tests Sascha Bischoff
2026-08-07 11:36 ` [PATCH v5 47/49] KVM: selftests: Add VGICv5 LPI delivery tests Sascha Bischoff
2026-08-07 17:39   ` sashiko-bot
2026-09-04 10:48     ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 48/49] KVM: selftests: Add VGICv5 IST save/restore coverage Sascha Bischoff
2026-08-07 17:50   ` sashiko-bot
2026-09-04 10:54     ` Sascha Bischoff
2026-08-07 11:37 ` [PATCH v5 49/49] KVM: selftests: Add VGICv5 sparse vCPU IDs test Sascha Bischoff
2026-08-07 17:56   ` sashiko-bot
2026-09-04 10:57     ` Sascha Bischoff

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=15f92744b6da7cd67196895789088e8b04986502.camel@arm.com \
    --to=sascha.bischoff@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=nd@arm.com \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox