Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Suzuki K Poulose" <suzuki.poulose@arm.com>
Cc: "Marc Zyngier" <maz@kernel.org>,
	kvm@vger.kernel.org, "Oliver Upton" <oupton@kernel.org>,
	kvmarm@lists.linux.dev
Subject: Re: [PATCH v22 23/23] KVM: arm64: CCA: Control user register access for Realms
Date: Mon, 05 Oct 2026 09:30:06 +0000	[thread overview]
Message-ID: <20261005093006.928C41F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261005090754.2140522-24-suzuki.poulose@arm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Medium] kvm: arm64: missing lifecycle checks for Realm configuration registers
--

commit c1323429b568607fedbbcbc78dbc0df5d8c3cfd9
Author: Jean-Philippe Brucker <jpb@kernel.org>
Subject: KVM: arm64: CCA: Control user register access for Realms

This commit restricts the host access to register states for a given Realm,
aligning with RMM restrictions. It exposes certain registers for initial
Realm parameter configuration, as well as specific core registers at creation
or during specific exits.

[Severity: Medium]
In arch/arm64/kvm/guest.c within validate_realm_set_reg at line 769, the code
returns true unconditionally for KVM_REG_ARM_ID_AA64DFR0_EL1 and
KVM_REG_ARM64_SVE_VLS. Does this allow an unprivileged VMM userspace process
to write to these Realm configuration registers even after the Realm
Descriptor has already been created? If the VMM calls KVM_SET_ONE_REG after
finalization, it appears KVM might silently accept the write and update its
software state, while the RMM ignores it. Could this lead to a silent state
desynchronization between KVM and the RMM?

[Severity: Medium]
Similarly, in arch/arm64/kvm/guest.c within kvm_realm_validate_core_reg at
line 86, the function returns true unconditionally for the PC register. The
comment above states that the PC can only be set before the realm is
activated. Without an explicit lifecycle check in this path, can the VMM
modify the PC via KVM_SET_ONE_REG even after the Realm Execution Context
has been activated?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261005090754.2140522-1-suzuki.poulose@arm.com?part=23

  reply	other threads:[~2026-10-05  9:30 UTC|newest]

Thread overview: 64+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05  9:07 [PATCH v22 00/23] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 01/23] KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0 Suzuki K Poulose
2026-10-06  0:02   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 02/23] KVM: arm64: Disable Steal time accounting for protected guests Suzuki K Poulose
2026-10-06  0:03   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 03/23] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 04/23] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 05/23] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-10-06  3:55   ` Gavin Shan
2026-10-06  8:33   ` Marc Zyngier
2026-10-06  8:49     ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 06/23] KVM: arm64: Don't call vcpu_set_pauth_traps for pKVM host Suzuki K Poulose
2026-10-06  0:29   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 07/23] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 08/23] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-10-06  2:15   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 09/23] KVM: arm64: Prevent unsupported vcpu features for VM types Suzuki K Poulose
2026-10-06  2:24   ` Gavin Shan
2026-10-06  2:25   ` Gavin Shan
2026-10-06  5:16     ` Suzuki K Poulose
2026-10-06  8:50   ` Marc Zyngier
2026-10-05  9:07 ` [PATCH v22 10/23] KVM: arm64: Consolidate stage2 unmap range into kvm_stage2_unmap_range Suzuki K Poulose
2026-10-06  2:37   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 11/23] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-10-06  3:00   ` Gavin Shan
2026-10-06  5:22     ` Suzuki K Poulose
2026-10-06  9:24   ` Marc Zyngier
2026-10-06 10:36     ` Suzuki K Poulose
2026-10-06 15:14       ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 12/23] KVM: arm64: Use a local kvm pointer in kvm_handle_guest_abort() Suzuki K Poulose
2026-10-06  3:02   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 13/23] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-10-06  3:07   ` Gavin Shan
2026-10-06  5:25     ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 14/23] KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms Suzuki K Poulose
2026-10-06  3:10   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 15/23] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-10-06  3:11   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 16/23] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-10-06  3:16   ` Gavin Shan
2026-10-06  5:09     ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 17/23] KVM: arm64: CCA: Add bare minimal S2 operations for Realm Suzuki K Poulose
2026-10-06  3:18   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 18/23] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-10-06  3:42   ` Gavin Shan
2026-10-06  5:10     ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 19/23] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-10-06  4:58   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 20/23] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-10-06  3:49   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 21/23] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-10-06  5:44   ` Gavin Shan
2026-10-05  9:07 ` [PATCH v22 22/23] KVM: arm64: CCA: Expose SVE VL register before VCPU finalization Suzuki K Poulose
2026-10-06  5:35   ` Gavin Shan
2026-10-06  5:57     ` Suzuki K Poulose
2026-10-05  9:07 ` [PATCH v22 23/23] KVM: arm64: CCA: Control user register access for Realms Suzuki K Poulose
2026-10-05  9:30   ` sashiko-bot [this message]
2026-10-05 13:08     ` Suzuki K Poulose
2026-10-06  5:47   ` Gavin Shan
2026-10-06  6:01     ` Suzuki K Poulose
2026-10-06  6:16       ` Gavin Shan
2026-10-06 12:36         ` Suzuki K Poulose
2026-10-06 22:00           ` Gavin Shan
2026-10-06  6:23       ` Gavin Shan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005093006.928C41F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=suzuki.poulose@arm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox