From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id CE03CC55162 for ; Sun, 2 Aug 2026 11:53:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Type:MIME-Version: References:In-Reply-To:Subject:Cc:To:From:Message-ID:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=qG8el77ac5B/pcNIohLMU22cDEqP6jWhheMGhqwN4Fo=; b=pnBfoAB6aYjD+krklJcXOu3TKb w9uXus7WUoHCK745JEPNnfFswFAp8PMTDc1x45/F1TQ5G3KpTZAlYAMZBSgJ4vDTPFouLnnwrfJZi EiDOQyk3rYqt5erJoNiXcT2ns28/H/AmLTMt6SZrFhYgrhI7Xd/dQKTIgLhPD+BWOT1zKRNDqYXAQ UM9xWaNgiIG51b7uvOXc3TW0btV8SrB9imA+r00sDGA/yy9lmEM4Z30N242rZhVeHnXlDD8XMCs5G 0uT0rjzVbesQT6hXH/9zk7ux0TqRw1fmftgh1igX6/PFoPZi0gJ7N70DYwa8Na1qwNk/KCaTjCFmM 3coPiRYg==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1wqUkv-0000000Fb2A-32zk; Sun, 02 Aug 2026 11:53:25 +0000 Received: from sea.source.kernel.org ([2600:3c0a:e001:78e:0:1991:8:25]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1wqUku-0000000Fb22-2Dw8 for linux-arm-kernel@lists.infradead.org; Sun, 02 Aug 2026 11:53:24 +0000 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by sea.source.kernel.org (Postfix) with ESMTP id 00D9B4020C; Sun, 2 Aug 2026 11:53:24 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id CBC271F000E9; Sun, 2 Aug 2026 11:53:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785671603; bh=qG8el77ac5B/pcNIohLMU22cDEqP6jWhheMGhqwN4Fo=; h=Date:From:To:Cc:Subject:In-Reply-To:References; b=QsY+YTELaoPvjJFP2u0KZw7KP6sjEf2w5+gW00Iw6Pqa0KNtIShRdrdxLkWFLBpE+ f1tjdIGCAfoM3OkQtds7QM7g+oYs/h9IuD0IT8rvhvgKERY2tRAadwPt4IEKQnf4Zt bVjReKadb/9TZTtaguEyuAlb+OtszlTRt7q3oOhsgT3LLyfFWM6UhzvJSqaezrv9ed T73yw8Ulqm1Xzls0qoG3JnM5AGuFaOzZTr3Mxt+ETvdq5ERn4voDbHv2A9U5tFVRlh 9CpsSlN86gRtytwCBocizVKUk5Gszr34WdLpE5KFAnNL08UrEAsS70Z4ED8YM7YHsG OsxuigYZEugXA== Received: from sofa.misterjones.org ([185.219.108.64] helo=lobster-girl.misterjones.org) by disco-boy.misterjones.org with esmtpsa (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.98.2) (envelope-from ) id 1wqUkr-0000000BRRN-1DNS; Sun, 02 Aug 2026 11:53:21 +0000 Date: Sun, 02 Aug 2026 12:53:22 +0100 Message-ID: <87ldaopwlp.wl-maz@kernel.org> From: Marc Zyngier To: Karl Mehltretter Cc: Oliver Upton , Suzuki K Poulose , Catalin Marinas , Will Deacon , Andre Przywara , linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [PATCH] KVM: arm64: Preserve AArch32 CP64 registers on rejected reads In-Reply-To: <20260801153616.71960-1-kmehltretter@gmail.com> References: <20260801153616.71960-1-kmehltretter@gmail.com> User-Agent: Wanderlust/2.15.9 (Almost Unreal) SEMI-EPG/1.14.7 (Harue) FLIM-LB/1.14.9 (=?UTF-8?B?R29qxY0=?=) APEL-LB/10.8 EasyPG/1.0.0 Emacs/30.1 (aarch64-unknown-linux-gnu) MULE/6.0 (HANACHIRUSATO) MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue") Content-Type: text/plain; charset=US-ASCII X-SA-Exim-Connect-IP: 185.219.108.64 X-SA-Exim-Rcpt-To: kmehltretter@gmail.com, oupton@kernel.org, suzuki.poulose@arm.com, catalin.marinas@arm.com, will@kernel.org, andre.przywara@arm.com, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org X-SA-Exim-Mail-From: maz@kernel.org X-SA-Exim-Scanned: No (on disco-boy.misterjones.org); SAEximRunCond expanded to false X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Sat, 01 Aug 2026 16:36:16 +0100, Karl Mehltretter wrote: > > kvm_handle_cp_64() only seeds params.regval for writes. If a CP64 read is > decoded but rejected, emulate_cp() still returns handled and the caller s/rejected/UNDEFs/ > writes params.regval back to Rt/Rt2. > > This can happen for write-only GIC SGI registers Can it? I know we have some code handling this case, but this was for a (long gone) userspace harness driving this code. On any HW, reading from WO registers directly results in an UNDEF, without SW involvement. Same thing for RO vs writes. If you know of any case contradicting this statement, please let me know. > and for rejected PMU counter reads. In both cases KVM injects an s/rejected PMU counter reads/read accesses generating an UNDEF/ > UNDEF into the guest, so the MRRC destination registers must remain > unchanged. s/destination registers/GPRs/ > > Instead, the uninitialised regval is copied into the guest registers. With > stack auto-initialisation this is a deterministic zero or pattern value. > With CONFIG_INIT_STACK_NONE it may be stale host stack data. > > Match kvm_handle_cp_32() and kvm_handle_sys_reg() by seeding regval from > the destination registers before emulation. > > Fixes: 6d52f35af10c ("arm64: KVM: add SGI generation register emulation") This has nothing to do with the handling of a particular register, and it has *always* been wrong. The correct tag appears to be: Fixes: 62a89c44954f0 ("arm64: KVM: 32bit handling of coprocessor traps") > Assisted-by: Claude:claude-opus-5 > Signed-off-by: Karl Mehltretter > --- > Runtime tested on a Raspberry Pi 400 with a minimal KVM harness running > an AArch32 guest. On the unpatched 6.1.21-v8+ vendor kernel, the PMCCNTR > MRRC test took UNDEF with r0=0x00000001/r1=0x00000000 instead of the > guest's sentinel values. With this patch on v7.2-rc3-278-g38436106b2f5, > the same test preserved r0=0x12345678/r1=0x9abcdef0. > > --- a/arch/arm64/kvm/sys_regs.c > +++ b/arch/arm64/kvm/sys_regs.c > @@ -4860,11 +4860,11 @@ > /* > * Make a 64-bit value out of Rt and Rt2. As we use the same trap > * backends between AArch32 and AArch64, we get away with it. > + * > + * This also makes rejected reads preserve Rt/Rt2. There is no such thing as "rejected reads" in the architecture (we only use this word for userspace accesses, not guests). Also, I don't think this deserves a comment as it aligns the logic with the rest of the sysreg handling code. > */ > - if (params.is_write) { > - params.regval = vcpu_get_reg(vcpu, Rt) & 0xffffffff; > - params.regval |= vcpu_get_reg(vcpu, Rt2) << 32; > - } > + params.regval = vcpu_get_reg(vcpu, Rt) & 0xffffffff; > + params.regval |= vcpu_get_reg(vcpu, Rt2) << 32; > > /* > * If the table contains a handler, handle the Other than the nitpicks above, this looks OK to me. Thanks, M. -- Jazz isn't dead. It just smells funny.