Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Suzuki K Poulose" <suzuki.poulose@arm.com>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
	"Marc Zyngier" <maz@kernel.org>,
	"Oliver Upton" <oupton@kernel.org>
Subject: Re: [PATCH v18 23/23] KVM: arm64: CCA: Control user register access for Realms
Date: Tue, 15 Sep 2026 16:49:07 +0000	[thread overview]
Message-ID: <20260915164907.9729B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260915160141.3543048-24-suzuki.poulose@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] arm64: kvm: KVM_SET_ONE_REG rejects PMCR_EL0 for Realm VMs breaking PMU config
--

commit 2d966a4231d9ac9707a0d74a6ba5b743ae7b69b3
Author: Jean-Philippe Brucker <jpb@kernel.org>

KVM: arm64: CCA: Control user register access for Realms

This commit restricts user register access for Realm VMs by limiting which
registers the VMM can read or modify. KVM explicitly allows access to
ID_AA64DFR0_EL1 and SVE_VLS for Realm parameter configuration before the Realm
Descriptor is created.

> diff --git a/arch/arm64/kvm/guest.c b/arch/arm64/kvm/guest.c
> --- a/arch/arm64/kvm/guest.c
> +++ b/arch/arm64/kvm/guest.c
[ ... ]
> +static bool validate_realm_set_reg(struct kvm_vcpu *vcpu,
> +				   const struct kvm_one_reg *reg)
> +{
> +	if ((reg->id & KVM_REG_ARM_COPROC_MASK) == KVM_REG_ARM_CORE) {
> +		u64 off = core_reg_offset_from_id(reg->id);
> +
> +		return kvm_realm_validate_core_reg(off);
> +	} else {
> +		switch (reg->id) {
> +		case KVM_REG_ARM_ID_AA64DFR0_EL1:
> +		case KVM_REG_ARM64_SVE_VLS:
> +			return true;
> +		}
> +	}
> +
> +	return false;
> +}

[Severity: High]
Does this logic unconditionally reject KVM_SET_ONE_REG calls for PMCR_EL0?

When the VMM attempts to restore or configure the PMU, kvm_arm_set_reg()
calls validate_realm_set_reg(). Because the UAPI equivalent of SYS_PMCR_EL0
is missing from this whitelist, the VMM is prevented from configuring the
number of PMU counters for Realm VMs, breaking VM initialization.

> diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
> --- a/arch/arm64/kvm/sys_regs.c
> +++ b/arch/arm64/kvm/sys_regs.c
[ ... ]
> +static inline bool kvm_realm_sys_reg_hidden_user(const struct kvm_vcpu *vcpu,
> +						 u64 reg)
> +{
> +	if (!vcpu_is_rec(vcpu))
> +		return false;
> +
> +	switch (reg) {
> +	case SYS_ID_AA64DFR0_EL1:
> +	case SYS_PMCR_EL0:
> +		return false;
> +	}
> +	return true;
> +}

[Severity: High]
This explicitly unhides SYS_PMCR_EL0 in kvm_realm_sys_reg_hidden_user(),
meaning it is returned to the VMM via KVM_GET_REG_LIST.

Since validate_realm_set_reg() in arch/arm64/kvm/guest.c rejects writes to
the PMU register, does this create an ABI inconsistency where the register
is listed but cannot be set?

Could this mismatch in configuration flow be corrected to allow PMU support
for Realm VMs?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260915160141.3543048-1-suzuki.poulose@arm.com?part=23

  reply	other threads:[~2026-09-15 16:49 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 16:01 [PATCH v18 00/23] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 01/23] KVM: arm64: protected VM: Handle set_one_reg CNTVCT_EL0/CNTPCT_EL0 Suzuki K Poulose
2026-09-15 16:18   ` sashiko-bot
2026-09-15 16:46   ` Marc Zyngier
2026-09-15 17:48     ` Suzuki K Poulose
2026-09-15 21:20       ` Suzuki K Poulose
2026-09-16  8:16         ` Marc Zyngier
2026-09-16  8:27           ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 02/23] KVM: arm64: Disable Steal time accounting for protected guests Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 03/23] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 04/23] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 05/23] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-17 11:24   ` Fuad Tabba
2026-09-18  8:59     ` Suzuki K Poulose
2026-09-18  9:14       ` Fuad Tabba
2026-09-18  9:47         ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 06/23] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 07/23] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 08/23] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 09/23] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 10/23] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 11/23] KVM: arm64: Use kvm_vm_is_unprotected() for !kvm_vm_is_protected() Suzuki K Poulose
2026-09-17 11:47   ` Fuad Tabba
2026-09-17 16:47     ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 12/23] KVM: arm64: Widen the scope of "protected" VMs Suzuki K Poulose
2026-09-17 11:44   ` Marc Zyngier
2026-09-17 17:06     ` Suzuki K Poulose
2026-09-17 11:51   ` Fuad Tabba
2026-09-17 16:48     ` Suzuki K Poulose
2026-09-17 14:16   ` Joey Gouly
2026-09-15 16:01 ` [PATCH v18 13/23] KVM: arm64: Add a helper for VMs running on hyp that don't trust the host Suzuki K Poulose
2026-09-17 11:55   ` Fuad Tabba
2026-09-15 16:01 ` [PATCH v18 14/23] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 15/23] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 16/23] KVM: arm64: CCA: Add bare minimal S2 operations for Realm Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 17/23] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 18/23] KVM: arm64: CCA: Mandate VGIC_V3 for Realms Suzuki K Poulose
2026-09-17 12:57   ` Fuad Tabba
2026-09-15 16:01 ` [PATCH v18 19/23] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 20/23] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-15 16:43   ` sashiko-bot
2026-09-15 17:55     ` Suzuki K Poulose
2026-09-16  8:29       ` Suzuki K Poulose
2026-09-17 13:16   ` Fuad Tabba
2026-09-17 14:56     ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 21/23] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 22/23] KVM: arm64: CCA: Expose SVE VL register before VCPU finalization Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 23/23] KVM: arm64: CCA: Control user register access for Realms Suzuki K Poulose
2026-09-15 16:49   ` sashiko-bot [this message]
2026-09-15 17:51     ` Suzuki K Poulose
2026-09-16 19:23 ` [PATCH v18 00/23] KVM: arm64: CCA: Add basic plumbing " Mathieu Poirier
2026-09-22  9:22   ` Aneesh Kumar K.V
2026-09-23 14:32     ` Mathieu Poirier
2026-09-17 14:32 ` Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915164907.9729B1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=suzuki.poulose@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox