Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v5] arm64: Don't read GMID_EL1 when MTE is disabled
@ 2026-08-27 18:59 Fuad Tabba
  2026-08-28 11:25 ` Catalin Marinas
  0 siblings, 1 reply; 2+ messages in thread
From: Fuad Tabba @ 2026-08-27 18:59 UTC (permalink / raw)
  To: Catalin Marinas, Will Deacon, linux-arm-kernel
  Cc: Marc Zyngier, Oliver Upton, Mark Rutland, Suzuki K Poulose,
	Mark Brown, kvmarm, linux-kernel, Fuad Tabba

__cpuinfo_store_cpu() gates the GMID_EL1 read on the raw
ID_AA64PFR1_EL1, so it reads the register even when the kernel has
disabled MTE (CONFIG_ARM64_MTE=n or arm64.nomte). KVM sets HCR_EL2.TID5
in that case, and pKVM injects an UNDEF the host cannot handle:

  Internal error: Oops - Undefined instruction: 0000000002000000 [#1]  SMP
  pc : __cpuinfo_store_cpu+0xf4/0x264
  Kernel panic - not syncing: Attempted to kill the idle task!

Only pKVM reaches it, and only after a CPU is offlined and brought back
online: its CPU_ON relay sets the host HCR before the CPU enters EL1,
while plain nVHE sets it at CPUHP_AP_KVM_ONLINE.

Gate the read on the CPU's own ID_AA64PFR1_EL1 with the command-line
override applied, and on CONFIG_ARM64_MTE, which no register reflects.
The boot CPU stores its registers before init_cpu_features() strips an
unsafe override, so clamp against the hardware value here too.

Fixes: f35abcbb8a084 ("KVM: arm64: Trap MTE access and discovery when MTE is disabled")
Cc: stable@vger.kernel.org
Signed-off-by: Fuad Tabba <fuad.tabba@linux.dev>
---

Notes:
    Changes since v4:
    - Gate on the ID_AA64PFR1_EL1 that __cpuinfo_store_cpu() has already
      read, clamping the override against it in cpufeature.c, rather than
      adding a __read_sysreg_by_encoding() caller in the header (Will). The
      register is not read a second time.
    - Dropped Suzuki's override clamp, which this no longer needs. It is
      worth having on its own, so I'll post it separately with the Fixes:
      tag and without the update_cpu_ftr_reg() hunk (Catalin).
    
    Tested on QEMU under pKVM, with -machine virt,mte=on.
    
    Offline/online CPU1 with arm64.nomte: unpatched panics in
    __cpuinfo_store_cpu(), patched does not. Same with CONFIG_ARM64_MTE=n
    and no override on the command line. And with id_aa64pfr1.mte=2 on a
    CPU without FEAT_MTE2, where the clamp keeps the gate false and
    init_cpu_ftr_reg() drops the override afterwards.

 arch/arm64/include/asm/cpu.h        |  1 +
 arch/arm64/include/asm/cpufeature.h |  7 ------
 arch/arm64/kernel/cpufeature.c      | 33 +++++++++++++++++++++++++----
 arch/arm64/kernel/cpuinfo.c         |  2 +-
 4 files changed, 31 insertions(+), 12 deletions(-)

diff --git a/arch/arm64/include/asm/cpu.h b/arch/arm64/include/asm/cpu.h
index 71493b760b839..3c008821219c2 100644
--- a/arch/arm64/include/asm/cpu.h
+++ b/arch/arm64/include/asm/cpu.h
@@ -78,5 +78,6 @@ void __init cpuinfo_store_boot_cpu(void);
 void __init init_cpu_features(struct cpuinfo_arm64 *info);
 void update_cpu_features(int cpu, struct cpuinfo_arm64 *info,
 				 struct cpuinfo_arm64 *boot);
+bool gmid_el1_accessible(const struct cpuinfo_arm64 *info);
 
 #endif /* __ASM_CPU_H */
diff --git a/arch/arm64/include/asm/cpufeature.h b/arch/arm64/include/asm/cpufeature.h
index a57870fa96db5..f6a7200700ccf 100644
--- a/arch/arm64/include/asm/cpufeature.h
+++ b/arch/arm64/include/asm/cpufeature.h
@@ -627,13 +627,6 @@ static inline bool id_aa64pfr1_mpamfrac(u64 pfr1)
 	return val > 0;
 }
 
-static inline bool id_aa64pfr1_mte(u64 pfr1)
-{
-	u32 val = cpuid_feature_extract_unsigned_field(pfr1, ID_AA64PFR1_EL1_MTE_SHIFT);
-
-	return val >= ID_AA64PFR1_EL1_MTE_MTE2;
-}
-
 void __init setup_boot_cpu_features(void);
 void __init setup_system_features(void);
 void __init setup_user_features(void);
diff --git a/arch/arm64/kernel/cpufeature.c b/arch/arm64/kernel/cpufeature.c
index 9a22df0c5120f..103e70d683ca2 100644
--- a/arch/arm64/kernel/cpufeature.c
+++ b/arch/arm64/kernel/cpufeature.c
@@ -1176,6 +1176,33 @@ static bool detect_ftr_has_mpam(void)
 	return id_aa64pfr0_mpam(pfr0) || id_aa64pfr1_mpamfrac(pfr1);
 }
 
+bool gmid_el1_accessible(const struct cpuinfo_arm64 *info)
+{
+	const struct arm64_ftr_bits *ftrp;
+	s64 mte, ovr;
+	u64 ftr_mask;
+
+	/* No ID register reflects CONFIG_ARM64_MTE. */
+	if (!IS_ENABLED(CONFIG_ARM64_MTE))
+		return false;
+
+	for (ftrp = ftr_id_aa64pfr1; ftrp->width; ftrp++) {
+		if (ftrp->shift == ID_AA64PFR1_EL1_MTE_SHIFT)
+			break;
+	}
+
+	ftr_mask = arm64_ftr_mask(ftrp);
+	mte = arm64_ftr_value(ftrp, info->reg_id_aa64pfr1);
+
+	/* The boot CPU runs before init_cpu_ftr_reg() strips unsafe overrides. */
+	if ((id_aa64pfr1_override.mask & ftr_mask) == ftr_mask) {
+		ovr = arm64_ftr_value(ftrp, id_aa64pfr1_override.val);
+		mte = arm64_ftr_safe_value(ftrp, ovr, mte);
+	}
+
+	return mte >= ID_AA64PFR1_EL1_MTE_MTE2;
+}
+
 void __init init_cpu_features(struct cpuinfo_arm64 *info)
 {
 	/* Before we start using the tables, make sure it is sorted */
@@ -1228,7 +1255,7 @@ void __init init_cpu_features(struct cpuinfo_arm64 *info)
 		init_cpu_ftr_reg(SYS_MPAMIDR_EL1, info->reg_mpamidr);
 	}
 
-	if (id_aa64pfr1_mte(info->reg_id_aa64pfr1))
+	if (gmid_el1_accessible(info))
 		init_cpu_ftr_reg(SYS_GMID_EL1, info->reg_gmid);
 }
 
@@ -1490,11 +1517,9 @@ void update_cpu_features(int cpu,
 	 * they read/write depends on the GMID_EL1.BS field. Check that the
 	 * value is the same on all CPUs.
 	 */
-	if (IS_ENABLED(CONFIG_ARM64_MTE) &&
-	    id_aa64pfr1_mte(info->reg_id_aa64pfr1)) {
+	if (gmid_el1_accessible(info))
 		taint |= check_update_ftr_reg(SYS_GMID_EL1, cpu,
 					      info->reg_gmid, boot->reg_gmid);
-	}
 
 	/*
 	 * If we don't have AArch32 at all then skip the checks entirely
diff --git a/arch/arm64/kernel/cpuinfo.c b/arch/arm64/kernel/cpuinfo.c
index d50e2a9b066b3..45c63f3d75c53 100644
--- a/arch/arm64/kernel/cpuinfo.c
+++ b/arch/arm64/kernel/cpuinfo.c
@@ -502,7 +502,7 @@ static void __cpuinfo_store_cpu(struct cpuinfo_arm64 *info)
 	info->reg_id_aa64smfr0 = read_cpuid(ID_AA64SMFR0_EL1);
 	info->reg_id_aa64fpfr0 = read_cpuid(ID_AA64FPFR0_EL1);
 
-	if (id_aa64pfr1_mte(info->reg_id_aa64pfr1))
+	if (gmid_el1_accessible(info))
 		info->reg_gmid = read_cpuid(GMID_EL1);
 
 	if (id_aa64pfr0_32bit_el0(info->reg_id_aa64pfr0))
-- 
2.39.5



^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v5] arm64: Don't read GMID_EL1 when MTE is disabled
  2026-08-27 18:59 [PATCH v5] arm64: Don't read GMID_EL1 when MTE is disabled Fuad Tabba
@ 2026-08-28 11:25 ` Catalin Marinas
  0 siblings, 0 replies; 2+ messages in thread
From: Catalin Marinas @ 2026-08-28 11:25 UTC (permalink / raw)
  To: Fuad Tabba
  Cc: Will Deacon, linux-arm-kernel, Marc Zyngier, Oliver Upton,
	Mark Rutland, Suzuki K Poulose, Mark Brown, kvmarm, linux-kernel,
	Fuad Tabba

On Thu, Aug 27, 2026 at 07:59:37PM +0100, Fuad Tabba wrote:
> +bool gmid_el1_accessible(const struct cpuinfo_arm64 *info)
> +{
> +	const struct arm64_ftr_bits *ftrp;
> +	s64 mte, ovr;
> +	u64 ftr_mask;
> +
> +	/* No ID register reflects CONFIG_ARM64_MTE. */
> +	if (!IS_ENABLED(CONFIG_ARM64_MTE))
> +		return false;
> +
> +	for (ftrp = ftr_id_aa64pfr1; ftrp->width; ftrp++) {
> +		if (ftrp->shift == ID_AA64PFR1_EL1_MTE_SHIFT)
> +			break;
> +	}
> +
> +	ftr_mask = arm64_ftr_mask(ftrp);
> +	mte = arm64_ftr_value(ftrp, info->reg_id_aa64pfr1);
> +
> +	/* The boot CPU runs before init_cpu_ftr_reg() strips unsafe overrides. */
> +	if ((id_aa64pfr1_override.mask & ftr_mask) == ftr_mask) {
> +		ovr = arm64_ftr_value(ftrp, id_aa64pfr1_override.val);
> +		mte = arm64_ftr_safe_value(ftrp, ovr, mte);
> +	}

This works. Or we could cut a few lines and just do
cpuid_feature_extract_unsigned_field() for mte and ovr and do a
hard-coded min(mte, ovr) as we now it's lower-safe. I don't have a
strong opinion either way, so for this patch:

Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-28 11:25 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-27 18:59 [PATCH v5] arm64: Don't read GMID_EL1 when MTE is disabled Fuad Tabba
2026-08-28 11:25 ` Catalin Marinas

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox