From: Leonardo Bras <leo.bras@arm.com>
To: Mark Brown <broonie@kernel.org>
Cc: Leonardo Bras <leo.bras@arm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Shuah Khan <shuah@kernel.org>, Oliver Upton <oupton@kernel.org>,
Fuad Tabba <fuad.tabba@linux.dev>,
Peter Maydell <peter.maydell@linaro.org>,
Wei-Lin Chang <weilin.chang@arm.com>,
Yao Yuan <yaoyuan@linux.alibaba.com>,
linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org,
kvmarm@lists.linux.dev, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v20 06/14] KVM: arm64: Validate GCS exception lock when emulating ERET
Date: Fri, 4 Sep 2026 14:16:34 +0100 [thread overview]
Message-ID: <aprEsh-xogu8zFnK@LeoBrasDK> (raw)
In-Reply-To: <2dfd8a6c-42c2-466c-b3d6-2313466fc3d5@sirena.org.uk>
On Thu, Sep 03, 2026 at 08:22:44PM +0100, Mark Brown wrote:
> On Thu, Sep 03, 2026 at 04:37:37PM +0100, Leonardo Bras wrote:
> > On Tue, Sep 01, 2026 at 10:47:04PM +0100, Mark Brown wrote:
>
> > > + return vcpu_read_sys_reg(vcpu, GCSCR_EL2) & GCSCR_ELx_EXLOCKEN;
> > > +}
>
> > The above perfectly translates the GCS part of IllegalExceptionReturn().
>
> > It's a nit, as I suppose there should be no compiler warning on that, but
> > the function should return a bool, and the last return line returns an u64.
>
> > Maybe adding a "return !!()" would be better?
>
> There's no need to manually do translations like that in C, the
> conversion of 0 to false and any non-zero value to true when an
> integer is used in a boolean context is in the standard.
>
Yeah, I am aware the conversion will happen anyway, but I remember someone
complaining about something like this in the past, that's why I sent as a
nit.
> > > * - trying to return to EL1 with HCR_EL2.TGE set
> > > + * - GCSCR_ELx.EXLOCKEN is 1 and PSTATE.EXLOCK is 0 when attempting
> > > + * to return from ELx the same EL.
> > > */
> > > if (mode == PSR_MODE_EL3t || mode == PSR_MODE_EL3h ||
> > > mode == 0b00001 || (mode & BIT(1)) ||
> > > (spsr & PSR_MODE32_BIT) ||
> > > + kvm_check_illegal_exlock_return(vcpu, spsr) ||
> > > (vcpu_el2_tge_is_set(vcpu) && (mode == PSR_MODE_EL1t ||
> > > mode == PSR_MODE_EL1h))) {
> > > u64 mask;
> >
> > In IllegalExceptionReturn(), the GCS-related clause happens at the end, and
> > here it happens before the TGE one. Could this cause any weird behavior in
> > the future?
> >
> > I get that by doing like this you don't change the last line of the "if",
> > but I wonder if that could change anything.
>
> Given that we take the same action regardless of which or clause
> triggers I can't see how it would matter.
I see... well, as long as neither test ever have any collateral effect, I
think it should not matter, then.
>
> > > --- a/arch/arm64/kvm/hyp/vhe/switch.c
> > > +++ b/arch/arm64/kvm/hyp/vhe/switch.c
> > > @@ -383,6 +383,10 @@ static bool kvm_hyp_handle_eret(struct kvm_vcpu *vcpu, u64 *exit_code)
> > > return false;
> > > }
>
> > > + /* Push GCS exception lock failures into the slow path */
> > > + if (kvm_check_illegal_exlock_return(vcpu, spsr))
> > > + return false;
>
> > > /* If ERETAx fails, take the slow path */
> > > if (esr_iss_is_eretax(esr)) {
> > > if (!(vcpu_has_ptrauth(vcpu) && kvm_auth_eretax(vcpu, &elr)))
>
> > IIUC, this function will be called on the __kvm_vcpu_run_vhe() inner loop,
> > in the cases where the guest exited due to a eret.
>
> > What you change here is that in case of an illegal exlock return, it goes
> > out of the loop and return to host kernel, probably to deal with it in the
> > mentioned slowpath, the same way the ERETAx entry does.
>
> > I don't question on this being needed.
> > I would just like to understand why this is needed here.
>
> > This does not seem to be related to nested, as this is called in
> > __fixup_guest_exit() and not in fixup_nv_guest_exit(). But would not
> > hardware be responsible for cheking this, then?
>
> The code is here because it's part of the ERET handling, this should
> only happen for NV as we're not trapping ERET instructions otherwise.
Oh, makes sense!
> We need this because ERETs from vEL2 are handled in software, modulo the
> NV3 fast path mentioned at the top of the function.
Oh, and this is done in __fixup_guest_exit() because vEL2 is not a
nested guest. It would be it's guests' exit that would be dealt in
fixup_nv_guest_exit().
Is this correct?
Thanks!
Leo
next prev parent reply other threads:[~2026-09-04 13:16 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 21:46 [PATCH v20 00/14] KVM: arm64: Provide guest support for GCS Mark Brown
2026-09-01 21:46 ` [PATCH v20 01/14] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled Mark Brown
2026-09-03 16:10 ` Lorenzo Stoakes (ARM)
2026-09-01 21:47 ` [PATCH v20 02/14] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Mark Brown
2026-09-03 16:23 ` Lorenzo Stoakes (ARM)
2026-09-03 19:29 ` Mark Brown
2026-09-01 21:47 ` [PATCH v20 03/14] KVM: arm64: Manage GCS access and registers for guests Mark Brown
2026-09-02 16:44 ` Leonardo Bras
2026-09-03 20:52 ` Mark Brown
2026-09-03 18:13 ` Lorenzo Stoakes (ARM)
2026-09-03 20:41 ` Mark Brown
2026-09-04 8:54 ` Lorenzo Stoakes (ARM)
2026-09-01 21:47 ` [PATCH v20 04/14] KVM: arm64: Ensure GCS memory effects are visible Mark Brown
2026-09-02 16:30 ` Leonardo Bras
2026-09-04 12:16 ` Lorenzo Stoakes (ARM)
2026-09-01 21:47 ` [PATCH v20 05/14] KVM: arm64: Set PSTATE.EXLOCK when entering an exception Mark Brown
2026-09-03 14:25 ` Leonardo Bras
2026-09-03 16:20 ` Mark Brown
2026-09-03 16:40 ` Leonardo Bras
2026-09-04 13:04 ` Lorenzo Stoakes (ARM)
2026-09-01 21:47 ` [PATCH v20 06/14] KVM: arm64: Validate GCS exception lock when emulating ERET Mark Brown
2026-09-03 15:37 ` Leonardo Bras
2026-09-03 19:22 ` Mark Brown
2026-09-04 13:16 ` Leonardo Bras [this message]
2026-09-01 21:47 ` [PATCH v20 07/14] KVM: arm64: Forward GCS exceptions to nested guests Mark Brown
2026-09-01 21:47 ` [PATCH v20 08/14] KVM: arm64: Enforce EXLOCK for SPSR and ELR Mark Brown
2026-09-01 21:47 ` [PATCH v20 09/14] KVM: arm64: Allow GCS to be enabled for guests Mark Brown
2026-09-01 21:47 ` [PATCH v20 10/14] KVM: selftests: arm64: Add GCS registers to get-reg-list Mark Brown
2026-09-01 21:47 ` [PATCH v20 11/14] KVM: selftests: arm64: Add GCS to set_id_regs Mark Brown
2026-09-01 21:47 ` [PATCH v20 12/14] KVM: selftests: arm64: Only restore SPSR_EL1 and ELR_EL1 if they change Mark Brown
2026-09-01 21:47 ` [PATCH v20 13/14] tools: Synchronise the kernel esr.h Mark Brown
2026-09-01 21:47 ` [PATCH v20 14/14] KVM: selftests: arm64: Add GCS EXLOCK exception emulation test Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aprEsh-xogu8zFnK@LeoBrasDK \
--to=leo.bras@arm.com \
--cc=broonie@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=fuad.tabba@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=peter.maydell@linaro.org \
--cc=shuah@kernel.org \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=will@kernel.org \
--cc=yaoyuan@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox