From: "Lorenzo Stoakes (ARM)" <ljs@kernel.org>
To: Mark Brown <broonie@kernel.org>
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Joey Gouly <joey.gouly@arm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Shuah Khan <shuah@kernel.org>, Oliver Upton <oupton@kernel.org>,
Fuad Tabba <fuad.tabba@linux.dev>,
Peter Maydell <peter.maydell@linaro.org>,
Leonardo Bras <leo.bras@arm.com>,
Wei-Lin Chang <weilin.chang@arm.com>,
Yao Yuan <yaoyuan@linux.alibaba.com>,
linux-arm-kernel@lists.infradead.org, linux-doc@vger.kernel.org,
kvmarm@lists.linux.dev, linux-kselftest@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH v20 01/14] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled
Date: Thu, 3 Sep 2026 17:10:39 +0100 [thread overview]
Message-ID: <apmXlJ3ScZ3-qlKV@gremlin> (raw)
In-Reply-To: <20260901-arm64-gcs-v20-1-f31750bdfadb@kernel.org>
On Tue, Sep 01, 2026 at 10:46:59PM +0100, Mark Brown wrote:
> The initial EL2 setup for GCS did not include disabling of EL1 usage of
> GCS instructions, also disable these traps.
>
> Fixes: ff5181d8a2a8 ("arm64/gcs: Provide basic EL2 setup to allow GCS usage at EL0 and EL1")
> Reviewed-by: Leonardo Bras <leo.bras@arm.com>
> Signed-off-by: Mark Brown <broonie@kernel.org>
> ---
> arch/arm64/include/asm/el2_setup.h | 5 +++++
> 1 file changed, 5 insertions(+)
>
> diff --git a/arch/arm64/include/asm/el2_setup.h b/arch/arm64/include/asm/el2_setup.h
> index aa8ec9df8024..d308c6e6757d 100644
> --- a/arch/arm64/include/asm/el2_setup.h
> +++ b/arch/arm64/include/asm/el2_setup.h
> @@ -393,6 +393,11 @@
> orr x0, x0, #HFGRTR_EL2_nGCS_EL1_MASK
> orr x0, x0, #HFGRTR_EL2_nGCS_EL0_MASK
>
> + /* Disable traps of GCS instructions at EL1 */
> + orr x2, x2, #HFGITR_EL2_nGCSEPP_MASK
> + orr x2, x2, #HFGITR_EL2_nGCSSTR_EL1_MASK
> + orr x2, x2, #HFGITR_EL2_nGCSPUSHM_EL1_MASK
(Forgive me being verbose here I'm thinking my way through things :)
So this is effectively:
Set bits from these masks:
HFGITR_EL2_nGCSEPP_MASK |
HFGITR_EL2_nGCSSTR_EL1_MASK |
HFGITR_EL2_nGCSPUSHM_EL1_MASK
Then (later instruction):
msr_s SYS_HFGITR_EL2, x2
I.e. set the hypervisor fine-grained instruction register ([0]).
And I can see from that document that for each bit:
0b1
Execution of the specified instructions is not trapped by this mechanism.
So this correctly disables these instructions:
GCSPUSHX
GCSPOPCX
GCSSTR
GCSSTTR when PSTATE.UAO is 1
GCSSTTR when the Effective value of HCR_EL2.{NV, NV1} is {1, 1}
GCSPUSHM
And these are the only listed GCS sets of instructions there.
On that basis LGTM :)
So:
Reviewed-by: Lorenzo Stoakes (ARM) <ljs@kernel.org>
[0]: https://support.arm.com/documentation/111107/2026-06/AArch64-Registers/HFGITR-EL2--Hypervisor-Fine-Grained-Instruction-Trap-Register
> +
> .Lskip_gce_fgt_\@:
>
> .Lset_fgt_\@:
>
> --
> 2.47.3
>
>
--
Cheers, Lorenzo
next prev parent reply other threads:[~2026-09-03 16:10 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-01 21:46 [PATCH v20 00/14] KVM: arm64: Provide guest support for GCS Mark Brown
2026-09-01 21:46 ` [PATCH v20 01/14] arm64/gcs: Ensure FGTs for EL1 GCS instructions are disabled Mark Brown
2026-09-03 16:10 ` Lorenzo Stoakes (ARM) [this message]
2026-09-01 21:47 ` [PATCH v20 02/14] KVM: arm64: Fix FGT mapping for HFGITR_EL2.nGCSEPP Mark Brown
2026-09-03 16:23 ` Lorenzo Stoakes (ARM)
2026-09-03 19:29 ` Mark Brown
2026-09-01 21:47 ` [PATCH v20 03/14] KVM: arm64: Manage GCS access and registers for guests Mark Brown
2026-09-02 16:44 ` Leonardo Bras
2026-09-03 20:52 ` Mark Brown
2026-09-03 18:13 ` Lorenzo Stoakes (ARM)
2026-09-03 20:41 ` Mark Brown
2026-09-01 21:47 ` [PATCH v20 04/14] KVM: arm64: Ensure GCS memory effects are visible Mark Brown
2026-09-02 16:30 ` Leonardo Bras
2026-09-01 21:47 ` [PATCH v20 05/14] KVM: arm64: Set PSTATE.EXLOCK when entering an exception Mark Brown
2026-09-03 14:25 ` Leonardo Bras
2026-09-03 16:20 ` Mark Brown
2026-09-03 16:40 ` Leonardo Bras
2026-09-01 21:47 ` [PATCH v20 06/14] KVM: arm64: Validate GCS exception lock when emulating ERET Mark Brown
2026-09-03 15:37 ` Leonardo Bras
2026-09-03 19:22 ` Mark Brown
2026-09-01 21:47 ` [PATCH v20 07/14] KVM: arm64: Forward GCS exceptions to nested guests Mark Brown
2026-09-01 21:47 ` [PATCH v20 08/14] KVM: arm64: Enforce EXLOCK for SPSR and ELR Mark Brown
2026-09-01 21:47 ` [PATCH v20 09/14] KVM: arm64: Allow GCS to be enabled for guests Mark Brown
2026-09-01 21:47 ` [PATCH v20 10/14] KVM: selftests: arm64: Add GCS registers to get-reg-list Mark Brown
2026-09-01 21:47 ` [PATCH v20 11/14] KVM: selftests: arm64: Add GCS to set_id_regs Mark Brown
2026-09-01 21:47 ` [PATCH v20 12/14] KVM: selftests: arm64: Only restore SPSR_EL1 and ELR_EL1 if they change Mark Brown
2026-09-01 21:47 ` [PATCH v20 13/14] tools: Synchronise the kernel esr.h Mark Brown
2026-09-01 21:47 ` [PATCH v20 14/14] KVM: selftests: arm64: Add GCS EXLOCK exception emulation test Mark Brown
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apmXlJ3ScZ3-qlKV@gremlin \
--to=ljs@kernel.org \
--cc=broonie@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=fuad.tabba@linux.dev \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=leo.bras@arm.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=peter.maydell@linaro.org \
--cc=shuah@kernel.org \
--cc=suzuki.poulose@arm.com \
--cc=weilin.chang@arm.com \
--cc=will@kernel.org \
--cc=yaoyuan@linux.alibaba.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox