From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D4B423F9F28 for ; Tue, 4 Aug 2026 18:29:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785868197; cv=none; b=fOsYtdTMojxQzUeceqdDvhMVrV+z87+zqVuLMgUb+hiTkOX1jg7+waO9GkUXwtoFzwZvdy9CTcDdzRRWOUr3kTZmW/J/jxn0JuFZiCP4wr8XXc5QnNTFQI0uxYEbodzxFvE+YgNUq0Pn5QyW+jmmkz7QpUzony2FX0hPLmyDiyI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785868197; c=relaxed/simple; bh=+qovK+kGrz2U91sq3fuilxXdHPdS/Z6mhTbeMgY+QJU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=dgpMl+CKI6vKUioYB7tIMK3DzhS8QhepAKNs+7TeuMIcCufAgXNmpg/wORMkc21WDAFBDCGpX6aK+Y+n6v+jopOzdLE7m6LOofk8MRcpVhpa/wgyJAlOyjki2gloptMD8Y3mcB3f/ZxgQLdBeu0VTAxU4Yn2R0eQbg6Gmg6+JVo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=F3ig/J5b; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="F3ig/J5b" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 674FlmNQ1193959; Tue, 4 Aug 2026 18:29:50 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=JS/V8qwxlbUSRvItj d4irVPxLogeuTm4ybEkMD+IaB8=; b=F3ig/J5bokHrYbO7mcM1mLSWBfoai0NBG CKUKc3/llpCn79r5svsN9ipauNcNuo617ILF+k7iP2Vsb76ttrco8S0U/6hotCZH Izz0F6axOviE0kLqepRM4Kgsh+YW22P1dnUXj7beZ02tnH/VPW90p+ETHVWoA8hO epJGXIxAURbEHVq3g5jlHb17T4Yb362NAFLk3or5dtfO3B1xoDz9XCDw9SPhJlhJ lWTVXKfk+skplT31xY6nyJMcUzZU83MijSL3t5bsp0aiImji9wjEm0PMuuzyFiW/ mr2k1iuWQ9I+sBQSWfBG4i4Hzgr86nQdpqEQYdg62vaMN5y3vLybg== Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fs77g72h8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 04 Aug 2026 18:29:49 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 674IQOwH025207; Tue, 4 Aug 2026 18:29:49 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fsugw3b2s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 04 Aug 2026 18:29:49 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (smtpav03.fra02v.mail.ibm.com [10.20.54.102]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 674ITjsj34799882 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 4 Aug 2026 18:29:45 GMT Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3A7712004B; Tue, 4 Aug 2026 18:29:45 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 87C2820043; Tue, 4 Aug 2026 18:29:42 +0000 (GMT) Received: from localhost.localdomain (unknown [9.39.28.45]) by smtpav03.fra02v.mail.ibm.com (Postfix) with ESMTP; Tue, 4 Aug 2026 18:29:42 +0000 (GMT) From: Amit Machhiwal To: qemu-ppc@nongnu.org, Harsh Prateek Bora Cc: Amit Machhiwal , Vaibhav Jain , Nicholas Piggin , Chinmay Rath , Glenn Miles , Paolo Bonzini , kvm@vger.kernel.org, qemu-devel@nongnu.org, Gautam Menghani Subject: [PATCH v5 2/3] target/ppc/kvm: Add support for querying host compatibility mode Date: Tue, 4 Aug 2026 23:59:13 +0530 Message-ID: <20260804182914.83091-3-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260804182914.83091-1-amachhiw@linux.ibm.com> References: <20260804182914.83091-1-amachhiw@linux.ibm.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA0MDE0OCBTYWx0ZWRfX9VanjKwkLMzh VbDEjNZNdSi6W+kQm6+zmDLUvyyo3NjJAXxhhYYYXCdQ9unUQ8WFv3DC34rfXkSZ0RLBr+w/OfO CCpSpsrU7N2KNkc7Y1iJ91qKi1NVIiE6aYx0MgsfOw/TtE8QUnNyLbNHyZMiGj195jjJq6KUSIH z0dPSlNMavh7uGy/4rFZbRq3BQA4JsLuupkK0jwzFarLDFgdRYt+jQhMsFsewvGphwFQellktjo HCL9Y4fAqPbxF0QkkzMmXlTrparxqYnhAeK6f850/SJOGqYyv5SDLdwtvqmCzxMQWAtOdbZa9+N lIGuNd2uKaIKEq/D796DkvptXRDRsfoxeBe60BF6Vlrz+WdwWH+9VNUm3iaL9WbwxemnlFHBfl+ 0ii55j3lLy4jm9IrTGbehvemxvpXOCgAKB+Z/vyyhlgsX8sqXiNTOdKhfRftbk2k75O6WAKqu1Z +NlmxzZkY2BBxx4lAHA== X-Authority-Analysis: v=2.4 cv=WIFPmHsR c=1 sm=1 tr=0 ts=6a722f9e cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=R_9d5M2Ok3QZz6TfjUMA:9 X-Proofpoint-GUID: rCBTd9ju0TgfLTm1LVwxDxGyNbTC-hZa X-Proofpoint-ORIG-GUID: 4tW9FUBMfYR8_w0ow-XWwd5Ag115KPFy X-Proofpoint-Spam-Info: AW1haW4tMjYwODA0MDE0OCBTYWx0ZWRfX8QYv61FM0c6Z DXs3BDPmFxQyngQfwfy8+SID6zfJ7rPc6Kk1S/GIAycwX2o7NNj0Xcl32VVb57lgHiVPvWFAEYr dyILM0s6YqDzFOun9I65m7pM9eNFykU= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-04_03,2026-08-04_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 lowpriorityscore=0 priorityscore=1501 phishscore=0 malwarescore=0 suspectscore=0 clxscore=1015 impostorscore=0 bulkscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608040148 Add infrastructure to query the host CPU compatibility mode via the KVM_PPC_GET_COMPAT_CAPS ioctl. This allows QEMU to determine if the host is running in a compatibility mode (e.g., a Power11 processor operating in Power10 compatibility mode). The kvmppc_get_compat_caps() function issues the ioctl and returns the compat_capabilities bitmap. The kvm_ppc_host_compat_pvr() function derives the effective PVR from the bitmap using ctz64() to find the lowest set bit (highest supported compat level in IBM MSB-0 numbering). The struct kvm_ppc_compat_caps places 'size' first and userspace sets it to sizeof(struct kvm_ppc_compat_caps) before calling the ioctl. The kernel uses copy_struct_from/to_user() to handle forward and backward ABI compatibility: an older userspace with a smaller struct gets trailing fields zero-padded. When newer userspace passes a larger struct to an older kernel (usize > ksize), the kernel unconditionally returns -E2BIG and writes its own ksize back into host_compat.size. QEMU detects this, validates the returned size against KVM_PPC_COMPAT_CAPS_SIZE_VER0, and retries with that size. Additionally, cas_check_pvr() in hw/ppc/spapr_hcall.c is updated to prevent fallback to raw mode when the host is running in compatibility mode. This ensures that nested guests cannot exceed the host's compatibility level. The call is guarded with kvm_enabled() since kvm_ppc_host_compat_pvr() invokes kvm_vm_ioctl() which dereferences kvm_state; without the guard, a TCG guest on a CONFIG_KVM=y binary would segfault. If the capability is not supported or the query fails, the functions return 0, allowing fallback to existing behavior. Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Signed-off-by: Amit Machhiwal --- No changes in this version. hw/ppc/spapr_hcall.c | 14 +++++++++ target/ppc/kvm.c | 75 ++++++++++++++++++++++++++++++++++++++++++++ target/ppc/kvm_ppc.h | 7 +++++ 3 files changed, 96 insertions(+) diff --git a/hw/ppc/spapr_hcall.c b/hw/ppc/spapr_hcall.c index 23bcd788daf6..708902934cff 100644 --- a/hw/ppc/spapr_hcall.c +++ b/hw/ppc/spapr_hcall.c @@ -1136,6 +1136,7 @@ static uint32_t cas_check_pvr(PowerPCCPU *cpu, uint32_t max_compat, { bool explicit_match = false; /* Matched the CPU's real PVR */ uint32_t best_compat = 0; + uint32_t compat_host_pvr = 0; int i; /* @@ -1163,6 +1164,19 @@ static uint32_t cas_check_pvr(PowerPCCPU *cpu, uint32_t max_compat, } } + if (explicit_match && kvm_enabled()) { + compat_host_pvr = kvm_ppc_host_compat_pvr(); + /* + * If the host is booted in a compatibility mode, do not try booting in + * the raw mode as it may allow KVM guests to boot with a higher CPU + * version compared to what host was booted with; which should not be + * allowed. + */ + if (compat_host_pvr) { + explicit_match = false; + } + } + *raw_mode_supported = explicit_match; /* Parsing finished */ diff --git a/target/ppc/kvm.c b/target/ppc/kvm.c index 116b39a00f4e..d4c5601a00c4 100644 --- a/target/ppc/kvm.c +++ b/target/ppc/kvm.c @@ -2602,6 +2602,81 @@ bool kvmppc_supports_ail_3(void) return cap_ail_mode_3; } +#if defined(TARGET_PPC64) +static target_ulong kvmppc_get_compat_caps(void) +{ + struct kvm_ppc_compat_caps host_compat; + int ret; + + if (!kvm_check_extension(kvm_state, KVM_CAP_PPC_COMPAT_CAPS)) { + return 0; + } + + /* + * Set size to sizeof(struct kvm_ppc_compat_caps) so the kernel applies + * copy_struct_from/to_user() versioning. size must be >= VER0. + */ + memset(&host_compat, 0, sizeof(host_compat)); + host_compat.size = sizeof(host_compat); + + ret = kvm_vm_ioctl(kvm_state, KVM_PPC_GET_COMPAT_CAPS, &host_compat); + if (ret == -E2BIG && host_compat.size >= KVM_PPC_COMPAT_CAPS_SIZE_VER0) { + /* + * Kernel is older and knows only a smaller struct version. It + * wrote back its ksize into host_compat.size. Retry with that + * size so the kernel accepts the call. + * + * When a VER1 struct is introduced, add a check here: + * if (host_compat.size >= KVM_PPC_COMPAT_CAPS_SIZE_VER1) { ... } + */ + uint64_t ksize = host_compat.size; + memset(&host_compat, 0, sizeof(host_compat)); + host_compat.size = ksize; + ret = kvm_vm_ioctl(kvm_state, KVM_PPC_GET_COMPAT_CAPS, &host_compat); + } + + if (ret < 0) { + error_report("KVM: failed to get host CPU compat capabilities: %s", + strerror(-ret)); + return 0; + } + + return host_compat.compat_capabilities & KVM_PPC_COMPAT_BITMASK; +} + +/* + * Return the effective host PVR based on the CPU compatibility mode + * reported by KVM. Returns 0 if no compat mode is active or the + * capability is not supported, in which case the caller falls back + * to the raw hardware PVR. + */ +uint32_t kvm_ppc_host_compat_pvr(void) +{ + uint32_t compat_host_pvr = 0; + uint64_t cap_idx = 0; + target_ulong host_caps = kvmppc_get_compat_caps(); + + if (host_caps) { + cap_idx = 1ULL << ctz64(host_caps); + switch (cap_idx) { + case KVM_PPC_COMPAT_CAP_POWER9: + compat_host_pvr = CPU_POWERPC_POWER9_DD22; + break; + case KVM_PPC_COMPAT_CAP_POWER10: + compat_host_pvr = CPU_POWERPC_POWER10_DD20; + break; + case KVM_PPC_COMPAT_CAP_POWER11: + compat_host_pvr = CPU_POWERPC_POWER11_DD20; + break; + default: + break; + } + } + + return compat_host_pvr; +} +#endif /* TARGET_PPC64 */ + PowerPCCPUClass *kvm_ppc_get_host_cpu_class(void) { uint32_t host_pvr = mfpvr(); diff --git a/target/ppc/kvm_ppc.h b/target/ppc/kvm_ppc.h index 742881231e16..195dbaac5e17 100644 --- a/target/ppc/kvm_ppc.h +++ b/target/ppc/kvm_ppc.h @@ -81,6 +81,8 @@ bool kvmppc_supports_ail_3(void); int kvmppc_enable_hwrng(void); int kvmppc_put_books_sregs(PowerPCCPU *cpu); PowerPCCPUClass *kvm_ppc_get_host_cpu_class(void); + +uint32_t kvm_ppc_host_compat_pvr(void); void kvmppc_check_papr_resize_hpt(Error **errp); int kvmppc_resize_hpt_prepare(PowerPCCPU *cpu, target_ulong flags, int shift); int kvmppc_resize_hpt_commit(PowerPCCPU *cpu, target_ulong flags, int shift); @@ -440,6 +442,11 @@ static inline PowerPCCPUClass *kvm_ppc_get_host_cpu_class(void) return NULL; } +static inline uint32_t kvm_ppc_host_compat_pvr(void) +{ + return 0; +} + static inline void kvmppc_check_papr_resize_hpt(Error **errp) { } -- 2.50.1 (Apple Git-155)