From: sashiko-bot@kernel.org
To: "Marc Zyngier" <maz@kernel.org>
Cc: "Oliver Upton" <oupton@kernel.org>,
"Marc Zyngier" <maz@kernel.org>,
kvm@vger.kernel.org, kvmarm@lists.linux.dev
Subject: Re: [PATCH v4 21/29] KVM: arm64: Add NVHCR_EL2 handling to the sysreg array
Date: Thu, 30 Jul 2026 07:58:47 +0000 [thread overview]
Message-ID: <20260730075848.0EF311F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260730071022.296811-22-maz@kernel.org>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] Inverted context logic for NVHCR_EL2 in locate_register() incorrectly maps the register to an unmanaged hardware CPU register.
- [High] Missing explicit Context Synchronization Event (ISB) after writing to the architectural control-plane system register NVHCR_EL2.
--
--- Patch [21]: [PATCH v4 21/29] KVM: arm64: Add NVHCR_EL2 handling to the sysreg array ---
commit aea2461c165a3a2d9e5915b4946e1ec44773006d
Author: Marc Zyngier <maz@kernel.org>
Subject: KVM: arm64: Add NVHCR_EL2 handling to the sysreg array
This commit exposes NVHCR_EL2 to userspace and treats direct access as UNDEF
to catch exception routing bugs. It also updates generic accessors to handle
the register's location.
> diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
> index 9439c5b2b1fe8..0aeb2e736fde3 100644
> --- a/arch/arm64/kvm/sys_regs.c
> +++ b/arch/arm64/kvm/sys_regs.c
> @@ -221,6 +221,20 @@ static void locate_register(const struct kvm_vcpu *vcpu, enum vcpu_sysreg reg,
> if (is_hyp_ctxt(vcpu) && vcpu_el2_e2h_is_set(vcpu))
> loc->loc = SR_LOC_SPECIAL;
> break;
> + case NVHCR_EL2:
> + /*
> + * Yes, NVHCR_EL2 maps to itself when loaded in nested
> + * context. If you feel like the architecture is double
> + * backing on itself upside down, you're not alone.
> + */
> + WARN_ON_ONCE(!kvm_has_nv3(vcpu->kvm));
> + if (is_hyp_ctxt(vcpu)) {
> + loc->loc = SR_LOC_MEMORY;
> + } else {
> + loc->loc = SR_LOC_LOADED | SR_LOC_MAPPED;
> + loc->map_reg = NVHCR_EL2;
> + }
> + break;
[Severity: High]
Does this invert the context logic for NVHCR_EL2?
If !is_hyp_ctxt(vcpu) (meaning the vCPU is running a nested guest), this maps
the register to an unmanaged hardware CPU register rather than the guest's
VNCR memory array.
Since KVM doesn't save or restore the physical SYS_NVHCR_EL2 register on
context switches, could this cause KVM_SET_ONE_REG to lose the guest's
NVHCR_EL2 state, and KVM_GET_ONE_REG to leak uninitialized host physical
register state?
[ ... ]
> @@ -298,6 +313,7 @@ static void write_sr_to_cpu(enum vcpu_sysreg reg, u64 val)
> case DACR32_EL2: write_sysreg_s(val, SYS_DACR32_EL2); break;
> case IFSR32_EL2: write_sysreg_s(val, SYS_IFSR32_EL2); break;
> case DBGVCR32_EL2: write_sysreg_s(val, SYS_DBGVCR32_EL2); break;
> + case NVHCR_EL2: write_sysreg_s(val, SYS_NVHCR_EL2); break;
[Severity: High]
Is an explicit context synchronization event (isb) required here after writing
to NVHCR_EL2?
The write_sysreg_s macro modifies a control-plane system register but is
followed immediately by a branch (break), skipping the architectural
requirement of having an isb as the very next instruction.
Could this leave the CPU pipeline operating in an architecturally undefined
state when userspace calls KVM_SET_ONE_REG?
> default: WARN_ON_ONCE(1);
> }
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260730071022.296811-1-maz@kernel.org?part=21
next prev parent reply other threads:[~2026-07-30 7:58 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-30 7:09 [PATCH v4 00/29] KVM: arm64: Add support for FEAT_NV2p1 and FEAT_NV3 Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 01/29] arm64: sysreg: Emit RESx/UNKN values for Mapping/Fields definitions Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 02/29] arm64: Update ID_AA64MMFR4_EL1 description to 2026-03 JSON release Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 03/29] KVM: arm64: Merge guest's HCRX_EL2 using NV_HCRX_GUEST_EXCLUDE Marc Zyngier
2026-07-30 7:29 ` sashiko-bot
2026-07-30 8:01 ` Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 04/29] KVM: arm64: Drop __HCRX_EL2_* masks Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 05/29] KVM: arm64: Plumb HCRX_EL2.SRMASKEn in HCRX_EL2 sanitisation Marc Zyngier
2026-07-30 7:09 ` [PATCH v4 06/29] KVM: arm64: Classify CPTR_EL2 as a SR_LOC_SPECIAL register Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 07/29] KVM: arm64: Don't evaluate HCR_EL2.NV nor HFGITR_EL2.ERET on ERET fast path Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 08/29] arm64: Add ARM64_HAS_NV2P1 capability Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 09/29] KVM: arm64: Relax CPTR_EL2 handling when FEAT_NV2p1 is present Marc Zyngier
2026-07-30 7:56 ` sashiko-bot
2026-07-30 7:10 ` [PATCH v4 10/29] KVM: arm64: Relax CNTHCTL_EL2 " Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 11/29] KVM: arm64: Expose FEAT_NV2p1 to NV guests Marc Zyngier
2026-07-30 8:09 ` sashiko-bot
2026-07-30 7:10 ` [PATCH v4 12/29] arm64: Add FEAT_NV2p1 detection Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 13/29] arm64: sysreg: Add NVHCR_EL2 description as a mirror of HCR_EL2 Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 14/29] arm64: sysreg: Add HCRX_EL2 bits related to FEAT_NV3 Marc Zyngier
2026-07-30 7:40 ` sashiko-bot
2026-07-30 7:48 ` Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 15/29] arm64: Add ARM64_HAS_NV3 capability Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 16/29] KVM: arm64: Split NV-specific exit fixups from the non-NV handling Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 17/29] KVM: arm64: Add NV3 control bits to HCRX_EL2 sanitisation Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 18/29] KVM: arm64: Add kvm_has_nv{2,3}() predicates Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 19/29] KVM: arm64: Make HCR_EL2 a non-VNCR register Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 20/29] KVM: arm64: Add sanitisation for NVHCR_EL2 Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 21/29] KVM: arm64: Add NVHCR_EL2 handling to the sysreg array Marc Zyngier
2026-07-30 7:58 ` sashiko-bot [this message]
2026-07-30 7:10 ` [PATCH v4 22/29] KVM: arm64: Add routing for NVHCR_EL2 trap Marc Zyngier
2026-07-30 8:12 ` sashiko-bot
2026-07-30 7:10 ` [PATCH v4 23/29] KVM: arm64: Add NVHCR_EL2 context switching Marc Zyngier
2026-07-30 8:05 ` sashiko-bot
2026-07-30 7:10 ` [PATCH v4 24/29] KVM: arm64: Engage NV3 ERET trap elision Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 25/29] KVM: arm64: Engage NV3 TLBI " Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 26/29] KVM: arm64: Add FEAT_NV3 detection Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 27/29] KVM: arm64: Expose FEAT_NV3 to guests Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 28/29] KVM: arm64: selftest: Add NVHCR_EL2 to get-reg-list Marc Zyngier
2026-07-30 7:10 ` [PATCH v4 29/29] arm64: Add override for ID_AA64MMFR4_EL1.NV_frac Marc Zyngier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260730075848.0EF311F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).