From nobody Mon Feb 9 14:37:51 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=unpredictable.fr ARC-Seal: i=1; a=rsa-sha256; t=1770297231; cv=none; d=zohomail.com; s=zohoarc; b=OufJOdF69fvY8e7Nl5c2SsPPfhoTnKJu0lVIv1LLMdH+fcYTe1+9Hnm6Rjtx/86aUpiGum5XYOpfNaH0+Swyj46gokhs2QV4ri5pywWtHxtIKc9/hVpOFKDCA7S45y5OswYkhZH1XqXCWp2aNjnoxtFAWEAjCMU1pB9U8YChzR4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1770297231; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UUJb39yVv7QixYIjzYIfzno5hqH3z9zRrMYraeKJgEA=; b=fK0/io4FGS9jBU54pUD+HciIYVhTnonqp4MmD+g1yi8V2qwk42b+hd5KHpkd9BNxYNDn9ntC1vruVUyv1FjH8CmJ6ZfmN5dhnuFDNwo3+acpvi3jSkOB2SUUUrUK3g+RybIkm36FiQKhM90bZy/jtgdP+BdSI5qZ8d+ypRykp+4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1770297231583289.6601522803347; Thu, 5 Feb 2026 05:13:51 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vnzAo-0000CC-18; Thu, 05 Feb 2026 08:13:30 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vnzAm-0000BQ-BS for qemu-devel@nongnu.org; Thu, 05 Feb 2026 08:13:28 -0500 Received: from p-west2-cluster3-host1-snip4-10.eps.apple.com ([57.103.69.113] helo=outbound.mr.icloud.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vnzAi-0001hA-PI for qemu-devel@nongnu.org; Thu, 05 Feb 2026 08:13:27 -0500 Received: from outbound.mr.icloud.com (unknown [127.0.0.2]) by p00-icloudmta-asmtp-us-west-2a-100-percent-8 (Postfix) with ESMTPS id 02C1E18013A4; Thu, 5 Feb 2026 13:13:20 +0000 (UTC) Received: from localhost.localdomain (unknown [17.57.152.38]) by p00-icloudmta-asmtp-us-west-2a-100-percent-8 (Postfix) with ESMTPSA id 28C2218000BF; Thu, 5 Feb 2026 13:13:16 +0000 (UTC) Dkim-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=unpredictable.fr; s=sig1; t=1770297203; x=1772889203; bh=UUJb39yVv7QixYIjzYIfzno5hqH3z9zRrMYraeKJgEA=; h=From:To:Subject:Date:Message-ID:MIME-Version:x-icloud-hme; b=fzptjhenPI1QbbTt4/1H9dQlULZxeq9t99BBY2hadPThtNlfX5vVJHrFUu3ve9ci9yilZ7n4TwT+jzcs6fY3RXvaax9YVLmiRi2mnFRIyUOjjAseigQOp1xd2xNHtHI9mC1RrUaTxBVdP7BE9lVlwZXNBbeuOjvwA+e0es+PWeDgrx9rdQaMsf9lMjAutOthD5oTiZ7+is1NMvr0S6IkNmnnMnGLf7/cm1K76zS4m6HPiCdfk5/xJKptBgwEfxwhksX0cQ6suAZVboNhJII/62qu3olG6WyogSXxh3BTBK2sIZor2Gl1Lh74Zc39sF85CzcMxXe+XDFYcV318k0dKg== mail-alias-created-date: 1752046281608 From: Mohamed Mediouni To: qemu-devel@nongnu.org, mohamed@unpredictable.fr Cc: Akihiko Odaki , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Marcel Apfelbaum , Richard Henderson , Peter Maydell , qemu-arm@nongnu.org, Zhao Liu , Roman Bolshakov , Igor Mammedov , "Michael S. Tsirkin" , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Cameron Esfahani , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Ani Sinha , Yanan Wang , Eduardo Habkost , Paolo Bonzini , Pierrick Bouvier , Shannon Zhao , Alexander Graf , Phil Dennis-Jordan , Pedro Barbuda Subject: [PATCH v20 17/22] whpx: arm64: clamp down IPA size Date: Thu, 5 Feb 2026 14:11:46 +0100 Message-ID: <20260205131155.22780-18-mohamed@unpredictable.fr> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260205131155.22780-1-mohamed@unpredictable.fr> References: <20260205131155.22780-1-mohamed@unpredictable.fr> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-ORIG-GUID: Ba-9R_-dNjcApIi9bNmIw0WUqxLGkI7- X-Authority-Info-Out: v=2.4 cv=NKbYOk6g c=1 sm=1 tr=0 ts=69849773 cx=c_apl:c_apl_out:c_pps a=9OgfyREA4BUYbbCgc0Y0oA==:117 a=9OgfyREA4BUYbbCgc0Y0oA==:17 a=HzLeVaNsDn8A:10 a=VkNPw1HP01LnGYTKEx00:22 a=KKAkSRfTAAAA:8 a=wAo57kR77d7e8uaIccUA:9 a=cvBusfyB2V15izCimMoJ:22 X-Proofpoint-GUID: Ba-9R_-dNjcApIi9bNmIw0WUqxLGkI7- X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMjA1MDA5OCBTYWx0ZWRfXz1FT54cwYVaK KTbVHMtjMwyGwzd34DQqzpu3zIi80FXej8VYSkk4n09vpsRqbziTYQ1l/NLInjeDPMDKwaZ/2W1 ONATZn+J2Vo12LKDbwW4FoAlfi8mCGZI6mip76XYouYkjKcc4ROYZCp9xL+u/PTd9Fnqewv1l6/ dUYan2u9O5jufoG3EHwBLayYzH0jobeUCVfeKfSCODsSXwGV6akckHmswdYer6pT6IZROQPppMs jAMr4o4IXHQKgsv83qyw6SF/f2b/D1v3po2SzJgur+1ydLaSOcPboGbFvjYgzRbX83IjO0C5kzM yOWGYOtlmKJrxozAZBqyPxTR5YSx5GXyybLdwz7sychzNm5iJlv+Lno8E6IeJQ= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-02-05_02,2026-02-05_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 malwarescore=0 clxscore=1030 suspectscore=0 mlxlogscore=999 lowpriorityscore=0 phishscore=0 adultscore=0 mlxscore=0 spamscore=0 bulkscore=0 classifier=spam authscore=0 adjust=0 reason=mlx scancount=1 engine=8.22.0-2601150000 definitions=main-2602050098 X-JNJ: AAAAAAABmzAIM39j4TIZwMI9LtnzlWaaya81cGeCKPeqVKgvvIeiwTYuzkQbmlMLHqQ9ph+bGTZZEa2+JTF+BXDJMW5uuKk2Zx/O/wRZ4HyGCUfbaOrp1hq94V3yWJb7h4NeRuu0+vwXDxexZJ4SUID6wozsBDn5S3iWnFzgbNONDsHlxMALo99nDeP0bwPyIEQZ+R4ZlBOuOw2/lAdMA5CGPAECK8qKd9msGrbYjXOVUcDY3m5z0UEI/tBDPg2xlCGooKloqn6JNZo38vh16okwmrfSO6fIRqfBMuO3PZb4wjMsGa38bc0Gk28EZgbA4/Jrpfqjnq9j/rERyWeYSmOGRuVjj1fNoD73/o9K4+BCklgarIuw8/biZA7SxXMqfwvFVj53z3PdOCuzDBUeBuMKwnjoa2hZB8/cv2SFqfvXzcmECpK6i6w/P0GXXKxiXBsCFGBgIEBmtVkjz5AAyb04BsP7xubGwouiKqHZzjbtiZYGOYhwg+w91CFFk7gD3/4Gt9zxMiQLeBwA83wLW2Isc0UXwItpNtiy277qT9W/kUmS/PqNgQ4ZaqXKOKg/digydnmNCFLLLOsLy8HhuxH1Dk3h391NxHNpcmENb36Nr4Wl0A58LY798KL3UgOECYw/v5gExRIkODu1CEaZJMxXT/YaSR2ikFti/wCUO8XCq1E+KIANS+7blT+P1bSQA8vDRKpjbEEjmRrI2Zi1LD/k9FFS/Iqm45zwPoNMox7zorz9k36g7YUAvEShp1NfC1WrL3Hcizww+2inzZu1e54AjKwotLn+jakBSXI7+j5mv66FcCJbh5wEjZyRlqXQFYW11HZMAYX8pF9pkYKFfya2yJfzpiFWIgKmHVesQVLhWsq+GYGiGe+VjRQRfXjQOIYGRg9seSX+sTkb4Do9aJwQ5Wr2QcarhXzYlnjSgRV52ldgTmCW6CLZlqBRQw== Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=57.103.69.113; envelope-from=mohamed@unpredictable.fr; helo=outbound.mr.icloud.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @unpredictable.fr) X-ZM-MESSAGEID: 1770297235298154100 Content-Type: text/plain; charset="utf-8" Code taken from HVF and adapted for WHPX use. Note that WHPX doesn't have a default vs maximum IPA distinction. Signed-off-by: Mohamed Mediouni Reviewed-by: Pierrick Bouvier --- hw/arm/virt.c | 32 ++++++++++++++++++++++++++ include/hw/core/boards.h | 1 + target/arm/whpx/meson.build | 2 ++ target/arm/whpx/whpx-all.c | 45 +++++++++++++++++++++++++++++++++++++ target/arm/whpx/whpx-stub.c | 15 +++++++++++++ target/arm/whpx_arm.h | 16 +++++++++++++ 6 files changed, 111 insertions(+) create mode 100644 target/arm/whpx/whpx-stub.c create mode 100644 target/arm/whpx_arm.h diff --git a/hw/arm/virt.c b/hw/arm/virt.c index a4dc6201bf..ed1692d8be 100644 --- a/hw/arm/virt.c +++ b/hw/arm/virt.c @@ -72,6 +72,7 @@ #include "hw/core/irq.h" #include "kvm_arm.h" #include "hvf_arm.h" +#include "whpx_arm.h" #include "hw/firmware/smbios.h" #include "qapi/visitor.h" #include "qapi/qapi-visit-common.h" @@ -3363,6 +3364,36 @@ static int virt_kvm_type(MachineState *ms, const cha= r *type_str) return fixed_ipa ? 0 : requested_pa_size; } =20 +static int virt_whpx_get_physical_address_range(MachineState *ms) +{ + VirtMachineState *vms =3D VIRT_MACHINE(ms); + + int max_ipa_size =3D whpx_arm_get_ipa_bit_size(); + + /* We freeze the memory map to compute the highest gpa */ + virt_set_memmap(vms, max_ipa_size); + + int requested_ipa_size =3D 64 - clz64(vms->highest_gpa); + + /* + * If we're <=3D the default IPA size just use the default. + * If we're above the default but below the maximum, round up to + * the maximum. whpx_arm_get_max_ipa_bit_size() conveniently only + * returns values that are valid ARM PARange values. + */ + if (requested_ipa_size <=3D max_ipa_size) { + requested_ipa_size =3D max_ipa_size; + } else { + error_report("-m and ,maxmem option values " + "require an IPA range (%d bits) larger than " + "the one supported by the host (%d bits)", + requested_ipa_size, max_ipa_size); + return -1; + } + + return requested_ipa_size; +} + static int virt_hvf_get_physical_address_range(MachineState *ms) { VirtMachineState *vms =3D VIRT_MACHINE(ms); @@ -3462,6 +3493,7 @@ static void virt_machine_class_init(ObjectClass *oc, = const void *data) mc->get_default_cpu_node_id =3D virt_get_default_cpu_node_id; mc->kvm_type =3D virt_kvm_type; mc->hvf_get_physical_address_range =3D virt_hvf_get_physical_address_r= ange; + mc->whpx_get_physical_address_range =3D virt_whpx_get_physical_address= _range; assert(!mc->get_hotplug_handler); mc->get_hotplug_handler =3D virt_machine_get_hotplug_handler; hc->pre_plug =3D virt_machine_device_pre_plug_cb; diff --git a/include/hw/core/boards.h b/include/hw/core/boards.h index 07f8938752..0b2aefb126 100644 --- a/include/hw/core/boards.h +++ b/include/hw/core/boards.h @@ -278,6 +278,7 @@ struct MachineClass { void (*wakeup)(MachineState *state); int (*kvm_type)(MachineState *machine, const char *arg); int (*hvf_get_physical_address_range)(MachineState *machine); + int (*whpx_get_physical_address_range)(MachineState *machine); =20 BlockInterfaceType block_default_type; int units_per_default_bus; diff --git a/target/arm/whpx/meson.build b/target/arm/whpx/meson.build index 1de2ef0283..3df632c9d3 100644 --- a/target/arm/whpx/meson.build +++ b/target/arm/whpx/meson.build @@ -1,3 +1,5 @@ arm_system_ss.add(when: 'CONFIG_WHPX', if_true: files( 'whpx-all.c', )) + +arm_common_system_ss.add(when: 'CONFIG_WHPX', if_false: files('whpx-stub.c= ')) diff --git a/target/arm/whpx/whpx-all.c b/target/arm/whpx/whpx-all.c index 192d7ec7a8..850f6ec81f 100644 --- a/target/arm/whpx/whpx-all.c +++ b/target/arm/whpx/whpx-all.c @@ -35,6 +35,7 @@ #include "system/whpx-accel-ops.h" #include "system/whpx-all.h" #include "system/whpx-common.h" +#include "whpx_arm.h" #include "hw/arm/bsa.h" #include "arm-powerctl.h" =20 @@ -633,6 +634,40 @@ static void whpx_cpu_update_state(void *opaque, bool r= unning, RunState state) { } =20 +uint32_t whpx_arm_get_ipa_bit_size(void) +{ + WHV_CAPABILITY whpx_cap; + UINT32 whpx_cap_size; + HRESULT hr; + hr =3D whp_dispatch.WHvGetCapability( + WHvCapabilityCodePhysicalAddressWidth, &whpx_cap, + sizeof(whpx_cap), &whpx_cap_size); + if (FAILED(hr)) { + error_report("WHPX: failed to get supported " + "physical address width, hr=3D%08lx", hr); + } + + /* + * We clamp any IPA size we want to back the VM with to a valid PARange + * value so the guest doesn't try and map memory outside of the valid = range. + * This logic just clamps the passed in IPA bit size to the first valid + * PARange value <=3D to it. + */ + return round_down_to_parange_bit_size(whpx_cap.PhysicalAddressWidth); +} + +static void clamp_id_aa64mmfr0_parange_to_ipa_size(ARMISARegisters *isar) +{ + uint32_t ipa_size =3D whpx_arm_get_ipa_bit_size(); + uint64_t id_aa64mmfr0; + + /* Clamp down the PARange to the IPA size the kernel supports. */ + uint8_t index =3D round_down_to_parange_index(ipa_size); + id_aa64mmfr0 =3D GET_IDREG(isar, ID_AA64MMFR0); + id_aa64mmfr0 =3D (id_aa64mmfr0 & ~R_ID_AA64MMFR0_PARANGE_MASK) | index; + SET_IDREG(isar, ID_AA64MMFR0, id_aa64mmfr0); +} + int whpx_init_vcpu(CPUState *cpu) { HRESULT hr; @@ -706,6 +741,7 @@ int whpx_init_vcpu(CPUState *cpu) val.Reg64 =3D deposit64(arm_cpu->mp_affinity, 31, 1, 1 /* RES1 */); whpx_set_reg(cpu, WHvArm64RegisterMpidrEl1, val); =20 + clamp_id_aa64mmfr0_parange_to_ipa_size(&arm_cpu->isar); return 0; } =20 @@ -722,6 +758,8 @@ int whpx_accel_init(AccelState *as, MachineState *ms) UINT32 whpx_cap_size; WHV_PARTITION_PROPERTY prop; WHV_CAPABILITY_FEATURES features; + MachineClass *mc =3D MACHINE_GET_CLASS(ms); + int pa_range =3D 0; =20 whpx =3D &whpx_global; /* on arm64 Windows Hypervisor Platform, vGICv3 always used */ @@ -732,6 +770,13 @@ int whpx_accel_init(AccelState *as, MachineState *ms) goto error; } =20 + if (mc->whpx_get_physical_address_range) { + pa_range =3D mc->whpx_get_physical_address_range(ms); + if (pa_range < 0) { + return -EINVAL; + } + } + whpx->mem_quota =3D ms->ram_size; =20 hr =3D whp_dispatch.WHvGetCapability( diff --git a/target/arm/whpx/whpx-stub.c b/target/arm/whpx/whpx-stub.c new file mode 100644 index 0000000000..32e434a5f6 --- /dev/null +++ b/target/arm/whpx/whpx-stub.c @@ -0,0 +1,15 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * WHPX stubs for ARM + * + * Copyright (c) 2025 Mohamed Mediouni + * + */ + +#include "qemu/osdep.h" +#include "whpx_arm.h" + +uint32_t whpx_arm_get_ipa_bit_size(void) +{ + g_assert_not_reached(); +} diff --git a/target/arm/whpx_arm.h b/target/arm/whpx_arm.h new file mode 100644 index 0000000000..de7406b66f --- /dev/null +++ b/target/arm/whpx_arm.h @@ -0,0 +1,16 @@ +/* SPDX-License-Identifier: GPL-2.0-or-later */ +/* + * WHPX support -- ARM specifics + * + * Copyright (c) 2025 Mohamed Mediouni + * + */ + +#ifndef QEMU_WHPX_ARM_H +#define QEMU_WHPX_ARM_H + +#include "target/arm/cpu-qom.h" + +uint32_t whpx_arm_get_ipa_bit_size(void); + +#endif --=20 2.50.1 (Apple Git-155)