From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E670A3B05AF for ; Sat, 8 Aug 2026 08:58:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.72 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179516; cv=none; b=jtQ6RuR4/Bs0q2Msh2/3Vov0xaf+AwGPBil5zID5+cnBHcmL98wevmTxoY2+Y41ngqSZG7/1sjrWylzzDX9ITgqqHIJ2pwsSEePsW12UYgvdxneJrJQd7dufF3KHA908YOkEs+2aDZQLTauFTPxWot6DQ4aeOlg9pYl4tdNhaEI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179516; c=relaxed/simple; bh=yZk+++kSee3JvNzACwuptz4ROqE71reOY1As/HQTYeY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=aRDfIsFoLkvR6mrorGN/WOp/SGWpd+r9QpKmVCQuGXc+jH4AVv+932lL8tESu2forvK87Sh/F6DatgXlmS1B7ovfINhr9kDc6HMl8OttuPR70puFK1LtvryxvLmJI5Opkzp4mTofxqKuEVA6z0LJKBfOfx/NVqBVhUpUvKM4RxA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=hJqFRdHC; arc=none smtp.client-ip=209.85.128.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="hJqFRdHC" Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-4955b84e25eso2516745e9.1 for ; Sat, 08 Aug 2026 01:58:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786179513; x=1786784313; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=56TnglbK1xrAvqmnbHBS7x8Hfawflf/2HSwwBboYSo0=; b=hJqFRdHCSjyl1g389TZ6TEmCI+rl3h01HrP7yaU0iLJw1pD7CMYp+ACgpgyol8FPdy TQtEgmV56ifpGqbc8sJUIgM3pGkxVf66dFykTSy049fVdtPNQ9yokz6fxOUzI2kjkbr2 lcOqGk3MhIH5unwoetY2/vh3s0wxqH/y39qmd3dnzxGSSsAar1Mdx6ren5prfdBc7zEO FMZ4uBMPoYJB+uHXl58/Q1Sll0Ms6S3JGc532RFL7+WPrvwKnCkmxAjWIl5v06HFfOyo EAISuuSE+1J3PZVqYCyxyzdPRm+XSow1alW1ayaGdKj+cYDnIxYNx1v2IDyyXdSEOsxY bD/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786179513; x=1786784313; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=56TnglbK1xrAvqmnbHBS7x8Hfawflf/2HSwwBboYSo0=; b=prrIW+7XxfuWeGkD422KmNM/raa5WcuV9hxweBcZ56eJqy6tWJi65Qz6m24S6HXveo 09iwmq0CE5xtuMZAzEbQQfxnsNYyLAX2OEs70Yx7ny28yOHYGoFknsaTJ/eGy4O9674+ /N7o5tGfdHsW6x4eELeSKm5pkJsb/y1tnwmt9f1fDfyiYaN6qF5kq2M0myoi2t0KVCm0 iahTM8PZMPz74JE4jDjduphWghpNmafy/Qr6myfqx6ylKSlncEClvFbTjjnt9XzwHWG/ q7fUS9j22dJHR82rPibzpBNICf9dNDDsIYt0+dhgLXgj8TUUrFFLfDP6dRtWu5FNNcIF aONg== X-Gm-Message-State: AOJu0Ywu2HW2uZwtV2CubHR5mrbh+bdWexiYM+f4xSv9u091bEC+zWsQ U+7H8l0hjwTpTeEJbx4GTS2MrxOAZD7kIddYesOwQMGE1Fm98iORpdIyyo7blI5w8Bu3aFzQQLB S8EKg576NlkKCd0T8spqfFjGn1UhiU0RH+XyXNnrscrCBZPIb3MaingK6QlsWcRI8DNMMb3ng9/ gqObWaqrJ5IpXhjlbBSxcuYvvin7tu6Kjj3oBKoaljpqp9NGlKij6MaYQ= X-Received: from wrqv10.prod.google.com ([2002:a5d:4b0a:0:b0:47f:586c:8371]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:46cc:b0:493:bd2a:93be with SMTP id 5b1f17b1804b1-4995e085347mr124527135e9.6.1786179512744; Sat, 08 Aug 2026 01:58:32 -0700 (PDT) Date: Sat, 8 Aug 2026 08:58:23 +0000 In-Reply-To: <20260808085824.732659-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260808085824.732659-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.654.g21b8a5bc05-goog Message-ID: <20260808085824.732659-3-smostafa@google.com> Subject: [PATCH v2 2/3] KVM: arm64: Fix timer offsets for non-protected VMs From: Mostafa Saleh To: linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: maz@kernel.org, oupton@kernel.org, seiden@linux.ibm.com, joey.gouly@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, catalin.marinas@arm.com, will@kernel.org, vdonnefort@google.com, tabba@google.com, sebastianene@google.com, keirf@google.com, yaoyuan@linux.alibaba.com, Mostafa Saleh , Sashiko Content-Type: text/plain; charset="UTF-8" With pKVM, protected VMs always have offset of zero. However, timer offsets for non-protected guests fail to take effect for two reasons: 1) In __timer_enable_traps(), enabling of traps check for is_protected_kvm_enabled() rather than vcpu_is_protected(vcpu) 2) The vcpu timer offsets were never initialised and kept as NULL. This is problematic for cases when the timer is trapped in the hypervisor as the with the case of broken CNTVOFF_EL2, which leads to the hypervisor and host using different offsets and causing VM hangs. This can be confirmed by running the arch_timer selftest which fails: ./arch_timer -o 100000000 Random seed: 0x6b8b4567 Guest assert failed, vcpu 0; stage; 3; iter: 0 ==== Test Assertion Failure ==== arm64/arch_timer.c:137: config_iter + 1 == irq_iter pid=310 tid=312 errno=4 - Interrupted system call Guest assert failed, vcpu 3; stage; 3; iter: 0 Guest assert failed, vcpu 1; stage; 3; iter: 0 ==== Test Assertion Failure ==== arm64/arch_timer.c:137: config_iter + 1 == irq_iter pid=310 tid=313 errno=4 - Interrupted system call Guest assert failed, vcpu 2; stage; 3; iter: 0 ==== Test Assertion Failure ==== arm64/arch_timer.c:137: config_iter + 1 == irq_iter pid=310 tid=314 errno=4 - Interrupted system call [...] After the fix: ./arch_timer -o 100000000 Random seed: 0x6b8b4567 PASS(vCPU-1). PASS(vCPU-3). PASS(vCPU-0). PASS(vCPU-2) Reported-by: Sashiko Fixes: cb0c272acebd ("KVM: arm64: Initialize the hypervisor's VM state at EL2") Signed-off-by: Mostafa Saleh --- arch/arm64/kvm/hyp/nvhe/pkvm.c | 14 ++++++++++++++ arch/arm64/kvm/hyp/nvhe/timer-sr.c | 6 +++--- 2 files changed, 17 insertions(+), 3 deletions(-) diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c index 24d6f164129a..89f3d5fb55ca 100644 --- a/arch/arm64/kvm/hyp/nvhe/pkvm.c +++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c @@ -529,6 +529,20 @@ static int init_pkvm_hyp_vcpu(struct pkvm_hyp_vcpu *hyp_vcpu, hyp_vcpu->vcpu.arch.cflags = READ_ONCE(host_vcpu->arch.cflags); hyp_vcpu->vcpu.arch.mp_state.mp_state = KVM_MP_STATE_STOPPED; + if (!pkvm_hyp_vcpu_is_protected(hyp_vcpu)) { + /* + * Timer offsets are pointing to the untrusted KVM copy, + * which is pinned in __pkvm_init_vm() for the VM life time. + * It is worth noting that hyp_vm->host_kvm points to an EL2 + * linear map address and timer_get_offset() will use + * kern_hyp_va() which is safe as it is idempotent. + */ + vcpu_vtimer(&hyp_vcpu->vcpu)->offset.vm_offset = + &hyp_vm->host_kvm->arch.timer_data.voffset; + vcpu_ptimer(&hyp_vcpu->vcpu)->offset.vm_offset = + &hyp_vm->host_kvm->arch.timer_data.poffset; + } + ret = pkvm_vcpu_init_sysregs(hyp_vcpu); if (ret) goto done; diff --git a/arch/arm64/kvm/hyp/nvhe/timer-sr.c b/arch/arm64/kvm/hyp/nvhe/timer-sr.c index ff176f4ce7de..51b4f5010b66 100644 --- a/arch/arm64/kvm/hyp/nvhe/timer-sr.c +++ b/arch/arm64/kvm/hyp/nvhe/timer-sr.c @@ -45,11 +45,11 @@ void __timer_enable_traps(struct kvm_vcpu *vcpu) /* * Disallow physical timer access for the guest * Physical counter access is allowed if no offset is enforced - * or running protected (we don't offset anything in this case). + * or running a protected VM (we don't offset anything in this case). */ clr = CNTHCTL_EL1PCEN; - if (is_protected_kvm_enabled() || - !kern_hyp_va(vcpu->kvm)->arch.timer_data.poffset) + if (vcpu_is_protected(vcpu) || + !timer_get_offset(vcpu_ptimer(vcpu))) set |= CNTHCTL_EL1PCTEN; else clr |= CNTHCTL_EL1PCTEN; -- 2.55.0.654.g21b8a5bc05-goog