From nobody Mon Sep 21 07:38:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1785868263; cv=none; d=zohomail.com; s=zohoarc; b=juQQ96s6d9o+w3qAdAVGxHPs1vN5/tZ63GerK1NDYBUEgpJ0lkjkzL9+V4eHnOmnmhSmEX14ckfGPp8HyyPy/7nFQGigW0yBgO0Aojl80GdiXqoXFd8LsjRtiqze9VpTGgCtrAptnY1pfTOg8h9R7nnGfYUDO18avc1UbGLv+BE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785868263; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JS/V8qwxlbUSRvItjd4irVPxLogeuTm4ybEkMD+IaB8=; b=dg6x7FSalSa6hRgMfqQ1f4ZRmxF10mGMZMdWXt0FfTHslMDPYK9cFscsfNk109MlzxIC8S3fct1wdxXnU8rTw76kaoZnvfoy8siEdiS+GcGcZsfTPQUi4dl6F6z+WYtUqXoZslhc9OWt+Ks4h1Pvr1MX6a2vaVzI8zOMB4kzMA8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785868263944915.441763029698; Tue, 4 Aug 2026 11:31:03 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wrJu7-0006M0-95; Tue, 04 Aug 2026 14:30:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrJti-0006Cq-DU; Tue, 04 Aug 2026 14:29:56 -0400 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wrJtg-0004gF-18; Tue, 04 Aug 2026 14:29:53 -0400 Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 674FlmNQ1193959; Tue, 4 Aug 2026 18:29:50 GMT Received: from ppma22.wdc07v.mail.ibm.com (5c.69.3da9.ip4.static.sl-reverse.com [169.61.105.92]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fs77g72h8-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 04 Aug 2026 18:29:49 +0000 (GMT) Received: from pps.filterd (ppma22.wdc07v.mail.ibm.com [127.0.0.1]) by ppma22.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 674IQOwH025207; Tue, 4 Aug 2026 18:29:49 GMT Received: from smtprelay03.fra02v.mail.ibm.com ([9.218.2.224]) by ppma22.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fsugw3b2s-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Tue, 04 Aug 2026 18:29:49 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (smtpav03.fra02v.mail.ibm.com [10.20.54.102]) by smtprelay03.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 674ITjsj34799882 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 4 Aug 2026 18:29:45 GMT Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 3A7712004B; Tue, 4 Aug 2026 18:29:45 +0000 (GMT) Received: from smtpav03.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 87C2820043; Tue, 4 Aug 2026 18:29:42 +0000 (GMT) Received: from localhost.localdomain (unknown [9.39.28.45]) by smtpav03.fra02v.mail.ibm.com (Postfix) with ESMTP; Tue, 4 Aug 2026 18:29:42 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=JS/V8qwxlbUSRvItj d4irVPxLogeuTm4ybEkMD+IaB8=; b=F3ig/J5bokHrYbO7mcM1mLSWBfoai0NBG CKUKc3/llpCn79r5svsN9ipauNcNuo617ILF+k7iP2Vsb76ttrco8S0U/6hotCZH Izz0F6axOviE0kLqepRM4Kgsh+YW22P1dnUXj7beZ02tnH/VPW90p+ETHVWoA8hO epJGXIxAURbEHVq3g5jlHb17T4Yb362NAFLk3or5dtfO3B1xoDz9XCDw9SPhJlhJ lWTVXKfk+skplT31xY6nyJMcUzZU83MijSL3t5bsp0aiImji9wjEm0PMuuzyFiW/ mr2k1iuWQ9I+sBQSWfBG4i4Hzgr86nQdpqEQYdg62vaMN5y3vLybg== From: Amit Machhiwal To: qemu-ppc@nongnu.org, Harsh Prateek Bora Cc: Amit Machhiwal , Vaibhav Jain , Nicholas Piggin , Chinmay Rath , Glenn Miles , Paolo Bonzini , kvm@vger.kernel.org, qemu-devel@nongnu.org, Gautam Menghani Subject: [PATCH v5 2/3] target/ppc/kvm: Add support for querying host compatibility mode Date: Tue, 4 Aug 2026 23:59:13 +0530 Message-ID: <20260804182914.83091-3-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260804182914.83091-1-amachhiw@linux.ibm.com> References: <20260804182914.83091-1-amachhiw@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA0MDE0OCBTYWx0ZWRfX9VanjKwkLMzh VbDEjNZNdSi6W+kQm6+zmDLUvyyo3NjJAXxhhYYYXCdQ9unUQ8WFv3DC34rfXkSZ0RLBr+w/OfO CCpSpsrU7N2KNkc7Y1iJ91qKi1NVIiE6aYx0MgsfOw/TtE8QUnNyLbNHyZMiGj195jjJq6KUSIH z0dPSlNMavh7uGy/4rFZbRq3BQA4JsLuupkK0jwzFarLDFgdRYt+jQhMsFsewvGphwFQellktjo HCL9Y4fAqPbxF0QkkzMmXlTrparxqYnhAeK6f850/SJOGqYyv5SDLdwtvqmCzxMQWAtOdbZa9+N lIGuNd2uKaIKEq/D796DkvptXRDRsfoxeBe60BF6Vlrz+WdwWH+9VNUm3iaL9WbwxemnlFHBfl+ 0ii55j3lLy4jm9IrTGbehvemxvpXOCgAKB+Z/vyyhlgsX8sqXiNTOdKhfRftbk2k75O6WAKqu1Z +NlmxzZkY2BBxx4lAHA== X-Authority-Analysis: v=2.4 cv=WIFPmHsR c=1 sm=1 tr=0 ts=6a722f9e cx=c_pps a=5BHTudwdYE3Te8bg5FgnPg==:117 a=5BHTudwdYE3Te8bg5FgnPg==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=R_9d5M2Ok3QZz6TfjUMA:9 X-Proofpoint-GUID: rCBTd9ju0TgfLTm1LVwxDxGyNbTC-hZa X-Proofpoint-ORIG-GUID: 4tW9FUBMfYR8_w0ow-XWwd5Ag115KPFy X-Proofpoint-Spam-Info: AW1haW4tMjYwODA0MDE0OCBTYWx0ZWRfX8QYv61FM0c6Z DXs3BDPmFxQyngQfwfy8+SID6zfJ7rPc6Kk1S/GIAycwX2o7NNj0Xcl32VVb57lgHiVPvWFAEYr dyILM0s6YqDzFOun9I65m7pM9eNFykU= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-04_03,2026-08-04_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 spamscore=0 lowpriorityscore=0 priorityscore=1501 phishscore=0 malwarescore=0 suspectscore=0 clxscore=1015 impostorscore=0 bulkscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608040148 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=amachhiw@linux.ibm.com; helo=mx0b-001b2d01.pphosted.com X-Spam_score_int: -26 X-Spam_score: -2.7 X-Spam_bar: -- X-Spam_report: (-2.7 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1785868265077158500 Content-Type: text/plain; charset="utf-8" Add infrastructure to query the host CPU compatibility mode via the KVM_PPC_GET_COMPAT_CAPS ioctl. This allows QEMU to determine if the host is running in a compatibility mode (e.g., a Power11 processor operating in Power10 compatibility mode). The kvmppc_get_compat_caps() function issues the ioctl and returns the compat_capabilities bitmap. The kvm_ppc_host_compat_pvr() function derives the effective PVR from the bitmap using ctz64() to find the lowest set bit (highest supported compat level in IBM MSB-0 numbering). The struct kvm_ppc_compat_caps places 'size' first and userspace sets it to sizeof(struct kvm_ppc_compat_caps) before calling the ioctl. The kernel uses copy_struct_from/to_user() to handle forward and backward ABI compatibility: an older userspace with a smaller struct gets trailing fields zero-padded. When newer userspace passes a larger struct to an older kernel (usize > ksize), the kernel unconditionally returns -E2BIG and writes its own ksize back into host_compat.size. QEMU detects this, validates the returned size against KVM_PPC_COMPAT_CAPS_SIZE_VER0, and retries with that size. Additionally, cas_check_pvr() in hw/ppc/spapr_hcall.c is updated to prevent fallback to raw mode when the host is running in compatibility mode. This ensures that nested guests cannot exceed the host's compatibility level. The call is guarded with kvm_enabled() since kvm_ppc_host_compat_pvr() invokes kvm_vm_ioctl() which dereferences kvm_state; without the guard, a TCG guest on a CONFIG_KVM=3Dy binary would segfault. If the capability is not supported or the query fails, the functions return 0, allowing fallback to existing behavior. Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Signed-off-by: Amit Machhiwal --- No changes in this version. hw/ppc/spapr_hcall.c | 14 +++++++++ target/ppc/kvm.c | 75 ++++++++++++++++++++++++++++++++++++++++++++ target/ppc/kvm_ppc.h | 7 +++++ 3 files changed, 96 insertions(+) diff --git a/hw/ppc/spapr_hcall.c b/hw/ppc/spapr_hcall.c index 23bcd788daf6..708902934cff 100644 --- a/hw/ppc/spapr_hcall.c +++ b/hw/ppc/spapr_hcall.c @@ -1136,6 +1136,7 @@ static uint32_t cas_check_pvr(PowerPCCPU *cpu, uint32= _t max_compat, { bool explicit_match =3D false; /* Matched the CPU's real PVR */ uint32_t best_compat =3D 0; + uint32_t compat_host_pvr =3D 0; int i; =20 /* @@ -1163,6 +1164,19 @@ static uint32_t cas_check_pvr(PowerPCCPU *cpu, uint3= 2_t max_compat, } } =20 + if (explicit_match && kvm_enabled()) { + compat_host_pvr =3D kvm_ppc_host_compat_pvr(); + /* + * If the host is booted in a compatibility mode, do not try booti= ng in + * the raw mode as it may allow KVM guests to boot with a higher C= PU + * version compared to what host was booted with; which should not= be + * allowed. + */ + if (compat_host_pvr) { + explicit_match =3D false; + } + } + *raw_mode_supported =3D explicit_match; =20 /* Parsing finished */ diff --git a/target/ppc/kvm.c b/target/ppc/kvm.c index 116b39a00f4e..d4c5601a00c4 100644 --- a/target/ppc/kvm.c +++ b/target/ppc/kvm.c @@ -2602,6 +2602,81 @@ bool kvmppc_supports_ail_3(void) return cap_ail_mode_3; } =20 +#if defined(TARGET_PPC64) +static target_ulong kvmppc_get_compat_caps(void) +{ + struct kvm_ppc_compat_caps host_compat; + int ret; + + if (!kvm_check_extension(kvm_state, KVM_CAP_PPC_COMPAT_CAPS)) { + return 0; + } + + /* + * Set size to sizeof(struct kvm_ppc_compat_caps) so the kernel applies + * copy_struct_from/to_user() versioning. size must be >=3D VER0. + */ + memset(&host_compat, 0, sizeof(host_compat)); + host_compat.size =3D sizeof(host_compat); + + ret =3D kvm_vm_ioctl(kvm_state, KVM_PPC_GET_COMPAT_CAPS, &host_compat); + if (ret =3D=3D -E2BIG && host_compat.size >=3D KVM_PPC_COMPAT_CAPS_SIZ= E_VER0) { + /* + * Kernel is older and knows only a smaller struct version. It + * wrote back its ksize into host_compat.size. Retry with that + * size so the kernel accepts the call. + * + * When a VER1 struct is introduced, add a check here: + * if (host_compat.size >=3D KVM_PPC_COMPAT_CAPS_SIZE_VER1) { ..= . } + */ + uint64_t ksize =3D host_compat.size; + memset(&host_compat, 0, sizeof(host_compat)); + host_compat.size =3D ksize; + ret =3D kvm_vm_ioctl(kvm_state, KVM_PPC_GET_COMPAT_CAPS, &host_com= pat); + } + + if (ret < 0) { + error_report("KVM: failed to get host CPU compat capabilities: %s", + strerror(-ret)); + return 0; + } + + return host_compat.compat_capabilities & KVM_PPC_COMPAT_BITMASK; +} + +/* + * Return the effective host PVR based on the CPU compatibility mode + * reported by KVM. Returns 0 if no compat mode is active or the + * capability is not supported, in which case the caller falls back + * to the raw hardware PVR. + */ +uint32_t kvm_ppc_host_compat_pvr(void) +{ + uint32_t compat_host_pvr =3D 0; + uint64_t cap_idx =3D 0; + target_ulong host_caps =3D kvmppc_get_compat_caps(); + + if (host_caps) { + cap_idx =3D 1ULL << ctz64(host_caps); + switch (cap_idx) { + case KVM_PPC_COMPAT_CAP_POWER9: + compat_host_pvr =3D CPU_POWERPC_POWER9_DD22; + break; + case KVM_PPC_COMPAT_CAP_POWER10: + compat_host_pvr =3D CPU_POWERPC_POWER10_DD20; + break; + case KVM_PPC_COMPAT_CAP_POWER11: + compat_host_pvr =3D CPU_POWERPC_POWER11_DD20; + break; + default: + break; + } + } + + return compat_host_pvr; +} +#endif /* TARGET_PPC64 */ + PowerPCCPUClass *kvm_ppc_get_host_cpu_class(void) { uint32_t host_pvr =3D mfpvr(); diff --git a/target/ppc/kvm_ppc.h b/target/ppc/kvm_ppc.h index 742881231e16..195dbaac5e17 100644 --- a/target/ppc/kvm_ppc.h +++ b/target/ppc/kvm_ppc.h @@ -81,6 +81,8 @@ bool kvmppc_supports_ail_3(void); int kvmppc_enable_hwrng(void); int kvmppc_put_books_sregs(PowerPCCPU *cpu); PowerPCCPUClass *kvm_ppc_get_host_cpu_class(void); + +uint32_t kvm_ppc_host_compat_pvr(void); void kvmppc_check_papr_resize_hpt(Error **errp); int kvmppc_resize_hpt_prepare(PowerPCCPU *cpu, target_ulong flags, int shi= ft); int kvmppc_resize_hpt_commit(PowerPCCPU *cpu, target_ulong flags, int shif= t); @@ -440,6 +442,11 @@ static inline PowerPCCPUClass *kvm_ppc_get_host_cpu_cl= ass(void) return NULL; } =20 +static inline uint32_t kvm_ppc_host_compat_pvr(void) +{ + return 0; +} + static inline void kvmppc_check_papr_resize_hpt(Error **errp) { } --=20 2.50.1 (Apple Git-155)