From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id A1ED4CA5FFC for ; Mon, 5 Oct 2026 09:09:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From: Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=DLKeyb4FQiikUiaKihoWT3nIS5PH4xtsJy8WMP36dpI=; b=VuoQkMCHBn9EdKn0WzPsAYUcT8 mZSzYuaZGj2xjRaqfEkkP9bNlyxWqZ0Av06pom0lxwzN7Qb3KNSXzWp9cp/bkZcprtTWocYcmiWPa SuoIq1hyYpnuosw50uCgOGp985YaCoR4w32oTn47ZL7tp3VtKzpBicELARLTa4q/+MIIrcx1syMEp unsyZuy1iW9SLyGL4ImapIpWQWY/9RRLtt6FqTmKYDbaXhaD0xR15hUgVqkyuuPqLEFbnCs+G+5bu BcoFq7LTi1uXQYuxivYsE5YdLJgemAlqFZDlPAThkipOrYeCjYFDpAcW1WegCYpk9SuR6A9nYJsWa cS2dro8A==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1xDehL-0000000FxmY-3Gwo; Mon, 05 Oct 2026 09:09:27 +0000 Received: from desiato.infradead.org ([2001:8b0:10b:1:d65d:64ff:fe57:4e05]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1xDehK-0000000FxkI-3xfs for linux-arm-kernel@bombadil.infradead.org; Mon, 05 Oct 2026 09:09:26 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=infradead.org; s=desiato.20200630; h=Content-Transfer-Encoding:MIME-Version :References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From:Sender:Reply-To: Content-Type:Content-ID:Content-Description; bh=DLKeyb4FQiikUiaKihoWT3nIS5PH4xtsJy8WMP36dpI=; b=j0phi70EMlFhIkvZu273N38Y6I qpzND5t7yPC9TBqYYTk6nUPiPvcoeGm3yQjN2m7jsZsgivmQSrKxnGLRIcsiKHXt7DQvdFK9XflhD VwK1731x2k0Rakl/G0VLpvnOzOG1ZcmMoacL4ZMAVpPDzzCbJHIF8crCluM7gYuaSzsLzB2kMIIA1 +ZpcX2UZTLCuHBcVE2sVxRtfQ8QCl6OQuMWnAHLz35Uz1bb4kCMVp9sbHLDpU7uOsbvWJQBlNZ/Vw svWc/si9i2fWQ0VpZt1aidnS1qKLqaiU9GZHG/pIhoMq5X1UIKR+xSXi7xURG4kOj+518O5e3Jah7 DhWessNA==; Received: from foss.arm.com ([217.140.110.172]) by desiato.infradead.org with esmtp (Exim 4.99.2 #2 (Red Hat Linux)) id 1xDehG-00000007ktP-2n3w for linux-arm-kernel@lists.infradead.org; Mon, 05 Oct 2026 09:09:25 +0000 Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 263081576; Mon, 5 Oct 2026 02:09:16 -0700 (PDT) Received: from ewhatever.cambridge.arm.com (ewhatever.cambridge.arm.com [10.2.197.99]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 6B9DD3F66F; Mon, 5 Oct 2026 02:09:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1791191359; bh=3j/0cI8X8V5LDuJwuszsQwkWGMoyMgSVPrs4wf72zBE=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=EO6La4XELE1Ia/YTG6nTqM3uVjvDgrwPC36jJMZdZDJEY9s1+REqywi5BuJf21TiH 4TUtxIT/34cJIlvpTr17sVL+iu27cNgjHi+2MmWQGbzH3w4FQDhaau/79tG+f2+WDU X19LsvQpuJFrzHOepvv0rJlQaFbQT5oZPCylseMw= From: Suzuki K Poulose To: kvm@vger.kernel.org, kvmarm@lists.linux.dev Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, steven.price@arm.com, aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com, joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com, linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com, sdonthineni@nvidia.com, alpergun@google.com, fj0570is@fujitsu.com, WeiLin.Chang@arm.com, lpieralisi@kernel.org, enju.kohei@fujitsu.com, sudeep.holla@arm.com, jonathan.cameron@oss.qualcomm.com, Jean-Philippe Brucker , Suzuki K Poulose Subject: [PATCH v22 22/23] KVM: arm64: CCA: Expose SVE VL register before VCPU finalization Date: Mon, 5 Oct 2026 10:07:53 +0100 Message-ID: <20261005090754.2140522-23-suzuki.poulose@arm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20261005090754.2140522-1-suzuki.poulose@arm.com> References: <20261005090754.2140522-1-suzuki.poulose@arm.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20261005_100923_056422_17B04046 X-CRM114-Status: GOOD ( 19.22 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org From: Jean-Philippe Brucker Userspace must configure the SVE vector length before the Realm is created (as it is part of the parameter for Realm creation), but the Realm VCPUs cannot be finalized until after the Realm Descriptor has been created. KVM_GET_REG_LIST currently rejects the unfinalized VCPUs, which prevents the userspace from discovering and configuring the VLs for the Realm. Allow KVM_GET_REG_LIST for unfinalized RECs and make the SVE register enumeration handle the unfinalized case explicitly. i.e., only expose KVM_REG_ARM64_SVE_VLS before SVE is finalized. One adverse side effect of this change is that a KVM_GET_REG_LIST call that only probes for the array size will now succeed even if SVE is not finalized, but that seems harmless since the following KVM_GET_REG_LIST with the full array will fail. Signed-off-by: Jean-Philippe Brucker Signed-off-by: Steven Price Signed-off-by: Suzuki K Poulose --- arch/arm64/kvm/arm.c | 15 ++++++++++++++- arch/arm64/kvm/guest.c | 10 +++++----- 2 files changed, 19 insertions(+), 6 deletions(-) diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c index fe707a0c47308..d99e7818f5894 100644 --- a/arch/arm64/kvm/arm.c +++ b/arch/arm64/kvm/arm.c @@ -2004,6 +2004,19 @@ static int kvm_arm_vcpu_set_events(struct kvm_vcpu *vcpu, return __kvm_arm_vcpu_set_events(vcpu, events); } +/* + * Realm VCPUs can be finalized only after the Realm descriptor is created. + * But in order to seal the SVE VL, we need to allow the userspace to read/write + * to the SVE_VL, before everything is finalized. + * Allow the register list for RECs before the VCPUs are finalized. + */ +static bool kvm_arm_vcpu_reg_list_allowed(struct kvm_vcpu *vcpu) +{ + if (kvm_arm_vcpu_is_finalized(vcpu)) + return true; + return vcpu_is_rec(vcpu); +} + long kvm_arch_vcpu_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg) { @@ -2059,7 +2072,7 @@ long kvm_arch_vcpu_ioctl(struct file *filp, break; r = -EPERM; - if (!kvm_arm_vcpu_is_finalized(vcpu)) + if (!kvm_arm_vcpu_reg_list_allowed(vcpu)) break; r = -EFAULT; diff --git a/arch/arm64/kvm/guest.c b/arch/arm64/kvm/guest.c index b01d6622b8720..c3ca369882273 100644 --- a/arch/arm64/kvm/guest.c +++ b/arch/arm64/kvm/guest.c @@ -598,8 +598,8 @@ static unsigned long num_sve_regs(const struct kvm_vcpu *vcpu) if (!vcpu_has_sve(vcpu)) return 0; - /* Policed by KVM_GET_REG_LIST: */ - WARN_ON(!kvm_arm_vcpu_sve_finalized(vcpu)); + if (!kvm_arm_vcpu_sve_finalized(vcpu)) + return 1; /* KVM_REG_ARM64_SVE_VLS */ return slices * (SVE_NUM_PREGS + SVE_NUM_ZREGS + 1 /* FFR */) + 1; /* KVM_REG_ARM64_SVE_VLS */ @@ -616,9 +616,6 @@ static int copy_sve_reg_indices(const struct kvm_vcpu *vcpu, if (!vcpu_has_sve(vcpu)) return 0; - /* Policed by KVM_GET_REG_LIST: */ - WARN_ON(!kvm_arm_vcpu_sve_finalized(vcpu)); - /* * Enumerate this first, so that userspace can save/restore in * the order reported by KVM_GET_REG_LIST: @@ -628,6 +625,9 @@ static int copy_sve_reg_indices(const struct kvm_vcpu *vcpu, return -EFAULT; ++num_regs; + if (!kvm_arm_vcpu_sve_finalized(vcpu)) + return num_regs; + for (i = 0; i < slices; i++) { for (n = 0; n < SVE_NUM_ZREGS; n++) { reg = KVM_REG_ARM64_SVE_ZREG(n, i); -- 2.43.0