Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Colton Lewis" <coltonlewis@google.com>
Cc: linux-perf-users@vger.kernel.org, "Marc Zyngier" <maz@kernel.org>,
	"Oliver Upton" <oupton@kernel.org>,
	kvm@vger.kernel.org, kvmarm@lists.linux.dev
Subject: Re: [PATCH v9 11/22] KVM: arm64: Set up MDCR_EL2 to handle a Partitioned PMU
Date: Thu, 24 Sep 2026 17:53:02 +0000	[thread overview]
Message-ID: <20260924175302.CB6CF1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260924172928.2110956-12-coltonlewis@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] KVM: arm64: Missing validation allows 0 PMU counters on CPUs lacking FEAT_HPMN0, breaking host PMU profiling
- [High] KVM: arm64: local_irq_save() fails to mask pseudo-NMIs, causing TOCTOU race on mdcr_el2
--

commit c7c5ea4b657ecda0bf87202cf7ee0d846216d5cf
Author: Colton Lewis <coltonlewis@google.com>

KVM: arm64: Set up MDCR_EL2 to handle a Partitioned PMU

This commit sets up MDCR_EL2 to handle partitioned PMUs, configuring the
HPME, HPMD, and HCCD bits when a partitioned PMU is used. It also unsets
coarse grain PMU traps if fine grain traps are available and protects
mdcr_el2 updates using local_irq_save() to prevent races with the PMU NMI
handler.

> diff --git a/arch/arm64/kvm/debug.c b/arch/arm64/kvm/debug.c
> index f4d7b12045e8f..a722fd4594e09 100644
> --- a/arch/arm64/kvm/debug.c
> +++ b/arch/arm64/kvm/debug.c
> @@ -37,14 +37,16 @@ static int cpu_has_spe(u64 dfr0)
>   */
>  static void kvm_arm_setup_mdcr_el2(struct kvm_vcpu *vcpu)
>  {
> -	preempt_disable();
> +	unsigned long flags;
> +
> +	local_irq_save(flags);
        ^^^^^^^^^^^^^^^^^^^^^^
[Severity: High]
Does this lock adequately protect against PMU interrupts?

On ARM64 systems with GICv3, the perf subsystem can use pseudo-NMIs for PMU
interrupts, and local_irq_save() does not mask NMIs. This leaves a structurally
open race window where a PMU NMI could fire during the read-modify-write phase
of vcpu->arch.mdcr_el2 inside kvm_arm_setup_mdcr_el2().

[ ... ]

> +		/*
> +		 * Take out the coarse grain traps if we are using
> +		 * fine grain traps and enforce counter access with
> +		 * HPMN.
> +		 */
> +		if (!vcpu_on_unsupported_cpu(vcpu) &&
> +		    (cpus_have_final_cap(ARM64_HAS_HPMN0) || nr_guest_cntr > 0)) {
                    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: High]
Can host userspace break host PMU profiling by configuring 0 guest counters?

If host userspace configures a partitioned PMU with 0 guest counters via
KVM_ARM_VCPU_PMU_V3_SET_NR_COUNTERS on a CPU where FEAT_HPMN0 is unsupported,
this condition evaluates to false and skips configuring HPMN.

Because KVM skips HPMN configuration when nr_guest_cntr == 0 on these older CPUs,
HPMN defaults to N. This transfers all host counters to PMCR_EL0.E control and
renders MDCR_EL2.HPME entirely ineffective for the host, which loses the ability
to stop host counters. This continuous hardware counting could lead to NMI storms.

Should KVM reject such invalid configurations on CPUs lacking FEAT_HPMN0 instead?

> +			vcpu->arch.mdcr_el2 &= ~MDCR_EL2_HPMN;
> +			vcpu->arch.mdcr_el2 |= FIELD_PREP(MDCR_EL2_HPMN, nr_guest_cntr);
> +
> +			if (cpus_have_final_cap(ARM64_HAS_FGT))
> +				vcpu->arch.mdcr_el2 &= ~(MDCR_EL2_TPM | MDCR_EL2_TPMCR);
> +		}
> +	}
> +

[ ... ]

>  	/* Write MDCR_EL2 directly if we're already at EL2 */
>  	if (has_vhe())
>  		write_sysreg(vcpu->arch.mdcr_el2, mdcr_el2);
                ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[Severity: High]
If a PMU pseudo-NMI fires during the critical section and calls
kvm_pmu_host_stop() to clear HPME, will this write clobber that update?

Because local_irq_save() fails to mask NMIs, this line writes the potentially
stale, cached vcpu->arch.mdcr_el2 state back to hardware, discarding any
intermediate HPME updates from the NMI handler and leaving PMU counters in the
wrong hardware state.

>  
> -	preempt_enable();
> +	local_irq_restore(flags);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260924172928.2110956-1-coltonlewis@google.com?part=11

  reply	other threads:[~2026-09-24 17:53 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-24 17:29 [PATCH v9 00/22] ARM64 PMU Partitioning Colton Lewis
2026-09-24 17:29 ` [PATCH v9 01/22] arm64: cpufeature: Add cpucap for HPMN0 Colton Lewis
2026-09-24 17:45   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 02/22] KVM: arm64: Reorganize PMU includes Colton Lewis
2026-09-24 17:38   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 03/22] KVM: arm64: Reorganize PMU functions Colton Lewis
2026-09-24 17:49   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 04/22] perf: arm_pmuv3: Generalize counter bitmasks Colton Lewis
2026-09-24 17:37   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 05/22] perf: arm_pmuv3: Move counter allocation mask to per-CPU struct pmu_hw_events Colton Lewis
2026-09-24 17:44   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 06/22] perf: arm_pmuv3: Check cntr_mask before using pmccntr Colton Lewis
2026-09-24 17:38   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 07/22] perf: arm_pmuv3: Allocate counter indices from high to low Colton Lewis
2026-09-24 17:37   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 08/22] KVM: arm64: Add initial scaffolding for Partitioned PMU Colton Lewis
2026-09-24 17:44   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 09/22] KVM: arm64: Set up FGT " Colton Lewis
2026-09-24 17:52   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 10/22] KVM: arm64: Add Partitioned PMU register trap handlers Colton Lewis
2026-09-24 17:50   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 11/22] KVM: arm64: Set up MDCR_EL2 to handle a Partitioned PMU Colton Lewis
2026-09-24 17:53   ` sashiko-bot [this message]
2026-09-24 17:29 ` [PATCH v9 12/22] KVM: arm64: Context swap Partitioned PMU guest registers Colton Lewis
2026-09-24 17:55   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 13/22] KVM: arm64: Enforce PMU event filter at vcpu_load() Colton Lewis
2026-09-24 17:47   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 14/22] perf: Add perf_pmu_resched_update() Colton Lewis
2026-09-24 17:46   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 15/22] KVM: arm64: Allow kvm_vcpu_pmu_resync_el0() to resync filters in process context Colton Lewis
2026-09-24 17:51   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 16/22] KVM: arm64: Apply dynamic guest counter reservations Colton Lewis
2026-09-24 17:57   ` sashiko-bot
2026-09-30 15:28   ` James Clark
2026-10-01 21:33     ` Colton Lewis
2026-09-24 17:29 ` [PATCH v9 17/22] KVM: arm64: Implement lazy PMU context swaps Colton Lewis
2026-09-24 17:55   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 18/22] perf: arm_pmuv3: Handle IRQs for Partitioned PMU guest counters Colton Lewis
2026-09-24 18:03   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 19/22] KVM: arm64: Detect overflows for the Partitioned PMU Colton Lewis
2026-09-24 18:07   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 20/22] KVM: arm64: Add vCPU device attr to partition the PMU Colton Lewis
2026-09-24 17:56   ` sashiko-bot
2026-09-30 15:27   ` James Clark
2026-10-01 21:21     ` Colton Lewis
2026-09-24 17:29 ` [PATCH v9 21/22] KVM: selftests: Add find_bit to KVM library Colton Lewis
2026-09-24 17:52   ` sashiko-bot
2026-09-24 17:29 ` [PATCH v9 22/22] KVM: arm64: selftests: Add test case for Partitioned PMU Colton Lewis
2026-09-24 17:55   ` sashiko-bot
2026-09-24 17:30 ` [PATCH] target/arm: Enable KVM PMU partitioning and counter limit Colton Lewis
2026-09-28 14:01   ` Peter Maydell
2026-09-29 21:21     ` Colton Lewis
2026-09-30 11:35       ` Peter Maydell
2026-10-01 21:34         ` Colton Lewis
2026-09-30 15:25 ` [PATCH v9 00/22] ARM64 PMU Partitioning James Clark
2026-10-01 21:33   ` Colton Lewis
2026-09-30 15:26 ` James Clark
2026-10-01 21:33   ` Colton Lewis

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260924175302.CB6CF1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=coltonlewis@google.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-perf-users@vger.kernel.org \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox