From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 789F454706D for ; Tue, 6 Oct 2026 00:02:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791244961; cv=none; b=JViI3k/s4IolG6TNbfx4aAgqDU/dh1VUOxm41AAPUQq+0GYskfHGpGYkqYc2qKG27ijuyloW5ygbFg0wUfW4aY9Bt1h+wI3IrwZ4LUwylkvu9DeJ//lHGY1szPI5Ab/r57Ri/FhlBXoQ0UboPCVznW2dGxswd4lJDcKCIz7diWo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791244961; c=relaxed/simple; bh=bbI1GlrUdF/ahNCG52V/oWZizEAOPQOpaRP4fBVF3RY=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=YYHxTQ4eg7MmzN4lx4WyFVB6xnVwkIzohnReFfVzb7gcx1QJAN7nziXPWQ6FuzfO70QB2t36EKmEVIjWp+eZhR2G3yihBg2E8L3bBRvdyktOkkVO++I9BNnFb5XIFoV1uyC6Hl/ROqZnfleuq9UuvRr6TcrV+6Z0iq5UjCUGwYs= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=HZrDvHx7; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="HZrDvHx7" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1791244958; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=PDFj6k/aDmm3juPYr/fQM/Yto+7HWelNY9uNTEiKbGU=; b=HZrDvHx7o2DVQPytjsKqQnQRzDRDzQwlHln09y7C24935MV83DYjNdPtZPjAofwcj+uZYd td3cHUyVVDeROmmR4BZJJAnZbD858plOR+RnRJw4X/PeCuHFIEfhRMKFNyQBWtNKSc+iTa T/JVm10KrUbjpxNGBwjWdRebUsPWjmg= Received: from mail-pj1-f70.google.com (mail-pj1-f70.google.com [209.85.216.70]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-614--HxD692xNFaiCDkllfpC9g-1; Mon, 05 Oct 2026 20:02:37 -0400 X-MC-Unique: -HxD692xNFaiCDkllfpC9g-1 X-Mimecast-MFC-AGG-ID: -HxD692xNFaiCDkllfpC9g_1791244956 Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-39deb05ef51so2187476a91.3 for ; Mon, 05 Oct 2026 17:02:36 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791244956; x=1791849756; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=PDFj6k/aDmm3juPYr/fQM/Yto+7HWelNY9uNTEiKbGU=; b=ojwm062Q64qaApx20+1QtMQ+oOT7XdsejA1I9bawXFFZjGgVkFtBL2CHMyIReq0zPM uba7ddnbYAOJ7Nc3PKvzs1TO+Aj/AEfpC+yu0Cdy03dxpFJw/kcOUBdwwYdK9n1lKRaP Ywy41+WQiBlnOt9qLld/k55rCZorlYtYt0scndtthy+yYjsxUVX+f2RiDJgCl2kijwI/ DgNy5U8F1m29PavJfeWY0jLG9jbBlfc/mHavRhSezkeXBi2xElyVbW5rif2AUAVC01gS gXJO2pYplgCZfEmLOkqOr1jtn6oQwC3I4IWBNMC+B5h3v4agW1I5GXok06wJ1o72mUOm O/aw== X-Forwarded-Encrypted: i=1; AKwUvBwS9riCzlTGeZxqlZLAewvjXaXJGUUKnLqtHyt2caV9x5trVd4gxNO6XXKLC9ZSOToLihEWWZtu2iVu@lists.linux.dev X-Gm-Message-State: AFq9FYKZ5IwAa1cEXQMMuGTj9U196Q/5ZajU1P1bn7L++fTDv58yEW3i cxjYSpFV1h/ghf0BOupTE2PIT0dpMPstcTKto4eeBj/tUin9W++UyIKZHGVPI9SNrhDh/NhREbH qpg+0AFIdKedZjuTMIqhYvJXzhS3jhfr/Rl3CzAMuNgsx7jB3hcYWqEqkSwAo9Fw= X-Gm-Gg: AYBFou0GBclpAFYS9MvGJ805VvJM9oronA0zVLuT6sUzqLLAc9bMX7DKQc3dS5sOLJL ZAdPui4lPWm+RfNn5//ycIvFH4GIV74AAHtR7/0SZzBRwJYK44vWH4kvBQgPX3ZZDUVIHMT8WSv EY6qJiSYJavqimiqKoT9K7IP+3la6fMnnwx0Koy9NyatCDsiVXU+fSp24qlGEgb6VpH+0w5zGGA +U9ZJKV0Z8jHpSpCehd5udopv+exc+QsIno65+Ku/bk5uhU7hMsQgn/lefj5cQlgxXQ3dvQtOZL WZlx+jPgY7yrj8PSLwojnh+SSr2K/vsa5pQLs8SDR5aq7MU1L+NQYkpNdsDPHUaShowo7ZMmXPg nMq/vHpA93fL2V0AloDBhgf2JvC2+CnftpvvsA/EBWA== X-Received: by 2002:a17:90b:4c05:b0:3a4:ba6e:65c9 with SMTP id 98e67ed59e1d1-3a6ce963ad0mr5001511a91.59.1791244955774; Mon, 05 Oct 2026 17:02:35 -0700 (PDT) X-Received: by 2002:a17:90b:4c05:b0:3a4:ba6e:65c9 with SMTP id 98e67ed59e1d1-3a6ce963ad0mr5001495a91.59.1791244955239; Mon, 05 Oct 2026 17:02:35 -0700 (PDT) Received: from [192.168.68.52] (n175-34-8-244.mrk21.qld.optusnet.com.au. [175.34.8.244]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-3a85436fb54sm1801682a91.10.2026.10.05.17.02.26 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 05 Oct 2026 17:02:34 -0700 (PDT) Message-ID: <0fa5d03c-9e6c-4d81-a0de-e7aafc34918f@redhat.com> Date: Tue, 6 Oct 2026 10:02:25 +1000 Precedence: bulk X-Mailing-List: linux-coco@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v22 01/23] KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0 To: Suzuki K Poulose , kvm@vger.kernel.org, kvmarm@lists.linux.dev Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, steven.price@arm.com, aneesh.kumar@kernel.org, oupton@kernel.org, joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com, linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com, sdonthineni@nvidia.com, alpergun@google.com, fj0570is@fujitsu.com, WeiLin.Chang@arm.com, lpieralisi@kernel.org, enju.kohei@fujitsu.com, sudeep.holla@arm.com, jonathan.cameron@oss.qualcomm.com References: <20261005090754.2140522-1-suzuki.poulose@arm.com> <20261005090754.2140522-2-suzuki.poulose@arm.com> From: Gavin Shan In-Reply-To: <20261005090754.2140522-2-suzuki.poulose@arm.com> X-Mimecast-Spam-Score: 0 X-Mimecast-MFC-PROC-ID: vqipwkfNGZu0qM7GJf6GRG4lox8ItXy6Ba9buyve6I4_1791244956 X-Mimecast-Originator: redhat.com Content-Language: en-US Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit On 10/5/26 7:07 PM, Suzuki K Poulose wrote: > Protected VMs doesn't allow setting offsets for virtual and physical > counters, as the offset is always fixed to 0. The VM ioctl is filtered > out based on the cap. However we don't prevent the userspace from trying > to write to the CNTVCT/CNTPCT registers. This would lead to KVM triggering > a WARN() in timer_set_offset() as the vm_offset pointer is set to NULL. > > Fix this by always "fixing" the timer offsets to 0 and marking that the > timer offset is set in the kvm->arch.flags at KVM init time for protected > VMs. This prevents the access to the VM specific vm_offset at low cost. > A userspace writing to the CNT*CT_EL0 would observe success, without > any real effect. This is cleaner over spilling "*_is_protected()" > checks and "matches" what we really do in practise. i.e., always run > with "fixed counter offset of 0". > > Reported by Sashiko > > Link: https://lore.kernel.org/all/20260908164641.416911F00A3A@smtp.kernel.org > Fixes: f7d05ee84a6a ("KVM: arm64: Prevent host from managing timer offsets for protected VMs") > Suggested-by: Marc Zyngier > Tested-by: Gavin Shan > Signed-off-by: Suzuki K Poulose > --- > Changes since v19: > - Fix typos in commit description and explain why we choose the approach. > - Improve comment in the code > Changes since v18: > - Retain NULL vm_offset for protected VMs to avoid host tampering with the > offset. > - Moved the flag setting into kvm_timer_init_vm(), where it should have been > in the first place > --- > arch/arm64/kvm/arch_timer.c | 12 ++++++++++-- > 1 file changed, 10 insertions(+), 2 deletions(-) > Reviewed-by: Gavin Shan