From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F8303B5311 for ; Sat, 8 Aug 2026 08:58:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.69 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179529; cv=none; b=TzExgV5ZxH9LJPBUr5iTpcmnBMazTTYTbcGJ3CzCg1BsvjADbzPLFw+ptJg6c40m/gmXIiSV8FWjgSKgmpr89vXvgCiVim4CzKAyIY7DJEjYe5l+bZXv3nBT7JSO47wWuMEW5gyaZwyRSWlPc50MsbyybXtYZxtCtqUok+Q41qs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179529; c=relaxed/simple; bh=G4qF8Z3F8YznyvYaSnDICEuJAKLvMzJPHvz7WlvNabM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=i7nMPLbKkTivsPgs9wkiXck6J7ORvjg5XRx1QDjhXr7kiASYNzYcNgDVAOM98wQjrqdlpTXIUAxiTpzgQLpOn7X4EoxT9ATZ9NbCmHXhglwqpEWK4B4pV1fGvhntoWKKuudqJkkXjabuXVn8TSPDAAYXKTqsl5WHjfCtUG1LiJk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=VxbawsPE; arc=none smtp.client-ip=209.85.128.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="VxbawsPE" Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-4994aebe932so3855545e9.3 for ; Sat, 08 Aug 2026 01:58:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786179514; x=1786784314; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jwmzaJ2YawJZB/O6hrcBLYDYP6+Ln0uIsTfu/SId0gY=; b=VxbawsPE8cZAzcp/TTzYfqrn1esWOMMTsu4xVj8uloTR7emZqipf9544H5KAhPGWRs QxWMsuhAhx+90L851fGpHo/5kCPeps0unv/9Ixn0U18VfQQionI2hB5qmw0k5lve08rG 7HgVTtYbs0MSz6qbmCyrUp88oqQcb7kQznmxKLB5VAvvzcyXyNWYA/GGjQLKxYeJbcx5 dcRA6gcDelYmPs2PAYiAmd9q7TzldR5o3nDuyyuj35kOqo0XUBJnhfESr6H+e9VeH6pd GFbgS6EB/4hDT4BaXxnpOlRPmBtsOTBrPr/6l7PgHWkJNRNXbk3tO8poIggY9/ngMjkh wilQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786179514; x=1786784314; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jwmzaJ2YawJZB/O6hrcBLYDYP6+Ln0uIsTfu/SId0gY=; b=Av1b17o9ylMGpXYaeig7qbxVrLJnVD1pmbLTBnmhNfu/fift5mkrhjTxsGivoOJw0q RDw/PTdOpnMYPz9eK09Kf9OnwVEWxzh2UXCxBo1J4KuHBRyO/v0db/UbOD+HU73egOgF 58YF5CjdVnhD4hwkkWjm1EFEbe3Orw8ClC3gU5v938RCwF+gy75LJWV6QLDcjTcJ4vJ+ wiAGoDLjSgZ8YCTixXQnqBjPlrW/+bfIdM7N8p2BraRreeQfMvSaIuXrPciz6ZYxoT/C Hi6i6JDY3ziQPjpSR+2I+eD0ytfOFJ+E4TTgZr1cAA3Rrjftd3x8NVTL8v1/CX0nIZde 6n5Q== X-Gm-Message-State: AOJu0YznjFEie4GpjfT+IZhJU6qBaS7HvpK3T6pCaAZ0KdaflXxn8V/j mvlIxXRoYtqEqlZDlHdMBP83uwKdM8xp2wcz1d5WQN9WYCrdc/We163cjw0aT/6lhuAr3XzwxKc m+dNeT/HN8Z7i5JWg33MU1NqDOKRRgYvihfznn8x3KHTcrgkqaIIjrvrTCvsjBds8t+60yMExlX oULrh0Oigkhqae+j2UomTjE3kid4Pbew3xmg20RVUPyeX7GoeECFn4hbo= X-Received: from wmdd13.prod.google.com ([2002:a05:600c:a20d:b0:493:b301:e269]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:620e:b0:495:6274:56c2 with SMTP id 5b1f17b1804b1-4994e70a6f5mr464694635e9.2.1786179514030; Sat, 08 Aug 2026 01:58:34 -0700 (PDT) Date: Sat, 8 Aug 2026 08:58:24 +0000 In-Reply-To: <20260808085824.732659-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260808085824.732659-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.654.g21b8a5bc05-goog Message-ID: <20260808085824.732659-4-smostafa@google.com> Subject: [PATCH v2 3/3] KVM: arm64: Fix hvhe and broken CNTVOFF_EL2 From: Mostafa Saleh To: linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: maz@kernel.org, oupton@kernel.org, seiden@linux.ibm.com, joey.gouly@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, catalin.marinas@arm.com, will@kernel.org, vdonnefort@google.com, tabba@google.com, sebastianene@google.com, keirf@google.com, yaoyuan@linux.alibaba.com, Mostafa Saleh , Fuad Tabba Content-Type: text/plain; charset="UTF-8" When running on a setup affected with broken CNTVOFF_EL2 (has_broken_cntvoff()) Booting with VHE or protected mode(nvhe) (id_aa64mmfr1.vh=0 and arm64_sw.hvhe=0) works fine. However launching a protected VM with protected hvhe mode panics the guest kernel: [ 0.000000] Internal error: Oops - Undefined instruction: 0000000000000000 [#1] SMP [ 0.000000] Modules linked in: [ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc3-g05f75bd71e0e-dirty #29 PREEMPT [ 0.000000] Hardware name: linux,dummy-virt (DT) [ 0.000000] pstate: 000003c5 (nzcv DAIF -PAN -UAO -TCO -DIT -SSBS BTYPE=--) [ 0.000000] pc : arch_timer_shutdown_virt+0x4/0x1c [ 0.000000] lr : arch_timer_starting_cpu+0x1c4/0x2d4 [ 0.000000] sp : ffffa6bd9a193c00 [ 0.000000] x29: ffffa6bd9a193c20 x28: ffffa6bd9a1bcf88 x27: 0000000000000000 [ 0.000000] x26: ffff00001be70dd8 x25: ffffa6bd99d85000 x24: ffffa6bd99d85ee4 [ 0.000000] x23: ffffa6bd99d85000 x22: ffffa6bd9a1499c0 x21: ffffa6bd9a1ab900 [ 0.000000] x20: 00ffffffffffffff x19: ffff00001be8b600 x18: 000000000000028c [ 0.000000] x17: 00000000510f0010 x16: 00000000510f0010 x15: 00000000500f0000 [ 0.000000] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000018 [ 0.000000] x11: ffffa6bd9a8ac000 x10: 0000000000f0000f x9 : ffffffffffffffff [ 0.000000] x8 : ffffa6bd98822e18 x7 : 0070752d65746174 x6 : 00111ff76e007261 [ 0.000000] x5 : ffffa6bd9ad68078 x4 : 0000000000000000 x3 : ffffa6bd98822a0c [ 0.000000] x2 : 0000000000000073 x1 : 0000000000000001 x0 : ffff00001be8b600 [ 0.000000] Call trace: [ 0.000000] arch_timer_shutdown_virt+0x4/0x1c (P) [ 0.000000] cpuhp_invoke_callback+0x11c/0x280 [ 0.000000] cpuhp_issue_call+0x1e8/0x224 [ 0.000000] __cpuhp_setup_state_cpuslocked+0x1d8/0x2b8 [ 0.000000] __cpuhp_setup_state+0x50/0x74 [ 0.000000] arch_timer_register+0xc0/0x148 [ 0.000000] arch_timer_of_init+0x148/0x170 [ 0.000000] timer_probe+0x74/0x124 [ 0.000000] time_init+0x18/0x58 [ 0.000000] start_kernel+0x1c0/0x3ac [ 0.000000] __primary_switched+0x88/0x90 [ 0.000000] Code: c80b7d2a 35ffffab 17ffffeb d503245f (d53be328) The workaround avoids setting non-zero CNTVOFF_EL2 and trapping the virtual counter to emulate the offset. In the VHE path (timer_set_traps()), traps are only enabled when the guest actually has a non-zero virtual timer offset. However, __timer_enable_traps() in hyp/nvhe/timer-sr.c unconditionally set CNTHCTL_EL1TVT and CNTHCTL_EL1TVCT whenever has_broken_cntvoff() was true. Which causes 2 issues: 1) Protected VMs: kvm_handle_pvm_sysreg() does not find "cntv_ctl_el0" in pvm_sys_reg_descs and injects undefined instruction exceptions. 2) non-protected guests are trapped all the time even with offset of zero. Fix this by adding a check in __timer_enable_traps() similar to the one in timer_set_traps() Fixes: 0bc9a9e85fcf ("KVM: arm64: Work around x1e's CNTVOFF_EL2 bogosity") Signed-off-by: Marc Zyngier Reviewed-by: Yuan Yao Reviewed-by: Fuad Tabba Tested-by: Fuad Tabba Signed-off-by: Mostafa Saleh --- arch/arm64/kvm/hyp/nvhe/timer-sr.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/arm64/kvm/hyp/nvhe/timer-sr.c b/arch/arm64/kvm/hyp/nvhe/timer-sr.c index 51b4f5010b66..993065716913 100644 --- a/arch/arm64/kvm/hyp/nvhe/timer-sr.c +++ b/arch/arm64/kvm/hyp/nvhe/timer-sr.c @@ -61,9 +61,9 @@ void __timer_enable_traps(struct kvm_vcpu *vcpu) /* * Trap the virtual counter/timer if we have a broken cntvoff - * implementation. + * implementation and non zero offset as in timer_set_traps() */ - if (has_broken_cntvoff()) + if (has_broken_cntvoff() && timer_get_offset(vcpu_vtimer(vcpu))) set |= CNTHCTL_EL1TVT | CNTHCTL_EL1TVCT; sysreg_clear_set(cnthctl_el2, clr, set); -- 2.55.0.654.g21b8a5bc05-goog