Linux KVM/arm64 development list
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Fuad Tabba" <fuad.tabba@linux.dev>
Cc: "Marc Zyngier" <maz@kernel.org>,
	"Oliver Upton" <oupton@kernel.org>,
	kvmarm@lists.linux.dev
Subject: Re: [PATCH 1/2] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM
Date: Sat, 29 Aug 2026 07:21:03 +0000	[thread overview]
Message-ID: <20260829072103.D20271F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260829071120.2522788-1-fuad.tabba@linux.dev>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] pKVM unconditionally leaks and overwrites protected guest context (including general purpose registers, system registers, and trap configuration) to and from the untrusted host on every guest entry/exit.
--

commit 4f524814ed8b14fca5b29ea5c6eacae85dfdeb56
Author: Fuad Tabba <fuad.tabba@linux.dev>

KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM

This commit ensures that the HCR_EL2.VSE bit is synchronized from the hyp
vCPU back to the host vCPU on guest exit under pKVM. It prevents the same
virtual SError from being pended repeatedly.

> diff --git a/arch/arm64/kvm/hyp/nvhe/hyp-main.c b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
> index 65a7c735aa398..be35ff5958c82 100644
> --- a/arch/arm64/kvm/hyp/nvhe/hyp-main.c
> +++ b/arch/arm64/kvm/hyp/nvhe/hyp-main.c
> @@ -276,6 +276,10 @@ static void sync_hyp_vcpu(struct pkvm_hyp_vcpu *hyp_vcpu)
>  
>  	host_vcpu->arch.iflags		= hyp_vcpu->vcpu.arch.iflags;
>  
> +	/* Cleared by hardware once the guest takes the vSError. */
> +	host_vcpu->arch.hcr_el2 &= ~HCR_VSE;
> +	host_vcpu->arch.hcr_el2 |= hyp_vcpu->vcpu.arch.hcr_el2 & HCR_VSE;
> +

[Severity: Critical]
This is a pre-existing issue, but does this code unconditionally leak and
overwrite protected guest context to and from the untrusted host on every
guest entry and exit?

In sync_hyp_vcpu(), just above the lines added here, the code copies the
confidential guest context back into host memory:

    if (pkvm_hyp_vcpu_is_protected(hyp_vcpu)) {
        host_vcpu->arch.ctxt = hyp_vcpu->vcpu.arch.ctxt;

This appears to leak protected guest register state to the host on each exit.

Additionally, on the entry path in flush_hyp_vcpu(), the untrusted host
context completely overwrites the protected guest's context:

    hyp_vcpu->vcpu.arch.ctxt = host_vcpu->arch.ctxt;

It also seems to allow the host to inject its own debug trap configuration:

    hyp_vcpu->vcpu.arch.mdcr_el2 = host_vcpu->arch.mdcr_el2;

Could this allow the untrusted host EL1 to read and write all protected
guest registers and inject debug traps, breaking the pKVM threat model
guarantee that host EL1 cannot read or modify protected-VM memory or
register state?

>  	sync_hyp_vgic_state(hyp_vcpu);
>  }

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260829071120.2522788-1-fuad.tabba@linux.dev?part=1

  parent reply	other threads:[~2026-08-29  7:21 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-29  7:11 [PATCH 1/2] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM Fuad Tabba
2026-08-29  7:11 ` [PATCH 2/2] KVM: arm64: selftests: Check SError is not pending after delivery Fuad Tabba
2026-08-29  7:21 ` sashiko-bot [this message]
2026-08-29 10:37   ` [PATCH 1/2] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260829072103.D20271F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=fuad.tabba@linux.dev \
    --cc=kvmarm@lists.linux.dev \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox