From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130894; cv=none; d=zohomail.com; s=zohoarc; b=MSBf3+UyDz/BWcFAevEOm9sZAhv3hVwNDy+lUu9vTqwtFkJxG8xib9B+I9a/Z1M7zD4yGzkPdI0eVxjPdTv2j+dFv6ffvaByZ5cj7YX/ZevP+VeRgoHDEHJozIW1vdS6QQ1KQLcfE45bWLwNe/DclpJjcHVYpDDyZWG5T5a4KWA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130894; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=iG8S7D9YAqkRZpmiMfZnvdLr/zW0nBYYhrBnB0uaR+4=; b=WYC8fKwSSVBEFD1+XAZeIGhHzgWHO7KJjpC4TC7XcSCEQWNqzWvAO3rIRsmk60M4iUP4RAqWvcl12dyGFbZJdV3RLgO9/ks7zF9R78r6Vrz/hnoYyhNrMZ/Zrw9ruiWI4NBlXtqPfyneVs1BU0jWir395792OowHjRc/LBvBxQM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130894270379.6742726465776; Fri, 11 Sep 2026 05:48:14 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416559.1645521 (Exim 4.92) (envelope-from ) id 1x50fW-0004Fe-LB; Fri, 11 Sep 2026 12:47:50 +0000 Received: by outflank-mailman (output) from mailman id 1416559.1645521; Fri, 11 Sep 2026 12:47:50 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fW-0004FX-IR; Fri, 11 Sep 2026 12:47:50 +0000 Received: by outflank-mailman (input) for mailman id 1416559; Fri, 11 Sep 2026 12:47:49 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fV-0004FR-Mm for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:47:49 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fU-00DvVv-Oz for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:47:48 +0200 Received: from [10.42.69.3] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f86b-8faa-0a2a0a5109dd-0a2a4503b718-14 for ; Fri, 11 Sep 2026 14:47:48 +0200 Received: from [185.255.28.34] (helo=prod-mta-13-01.swg-srv.net) by tlsNG-33051d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f874-fae8-0a2a45030019-b9ff1c2298bb-3 for ; Fri, 11 Sep 2026 14:47:48 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-01.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a090826e80000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:42 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id 5128981E4A; Fri, 11 Sep 2026 14:47:41 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=iG8S7D9YAqkRZpmiMfZnvdLr/zW0nBYYhrBnB0uaR+4=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=pJ5wSN5lXSzr+sZTTI9rPmgijl7J8kOiBTnDViQ+IGugobNFfU7RY1Z5pTRxf3tmiYZVcnnsh ldOkaVDn3ob+krcWlJabnhSCHRiwmXTnlZhSzGnhBzDv8s9VWqwR9XC/YHzHMG2mHyvPSt3oeyB LWlFXC4KJk2LX31HstxMtceIlfX/fV89eH6v7mdfZrBpRls+QJVWu4oMIxBOwJiQeE2gfdYaKb6 a7Ijw1+6fz30SXZkcXzxIVkgcepaKSeJ4DGgVH0xY2pT4yQ7Qgk6J6ak1+20qZ+XWMz5ffgS0H0 2edsf/FKIi900ZQN4V/zlekBPXKf8a3coYse9aV5+ihQ== X-Zone-Loop: 66a1a4e8ef3c679b2054f71da0be143b8b1336fbbd3c x-campaign-type: default x-transaction-id: dc9be154-fbe2-4a43-ad82-2fdf3382dc45 x-swg-uid: 01-bc942bc5-26f1-4737-a1cf-c5b0b84c3775 X-Mailer: Sweego Message-ID: <1789130862.8631fc262581453bbf619ec5b2062170.1a090826e80000c4f3@vates.tech> x-swg-bid: 1789130862.8631fc262581453bbf619ec5b2062170.1a090826e80000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 1/6] xen/arm: report proper GIC version via XEN_DOMCTL_getdomaininfo Date: Fri, 11 Sep 2026 14:47:31 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b2.6aee1b0ecd97f04d.1a090826c72.643865296eedc423=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130861682 X-purgate-ID: tlsNG-33051d/1789130868-768FA4E9-B7D8BB50/0/0 X-purgate-type: clean X-purgate-size: 2036 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130895157158500 ---=Part.b2.6aee1b0ecd97f04d.1a090826c72.643865296eedc423=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" When creating a domain on ARM, and passing XEN_DOMCTL_CONFIG_GIC_NATIVE for the gic_version field in the struct xen_arch_domainconfig, arch_sanitise_domain_config() resolves this to the approrpiate GIC_V2 or GIC_V3 version the domain actually has, based on the host's gic_hw_version(). That value is stored in the domain as d->arch.vgic.version, but can't be queried through any other domctl later. Toolstacks that create and build a domain in the same call already have this info from the createdomain reply and never need to ask again. Toolstacks that create a domain and build it later from a separate process do need to ask again. But, the ARM implementation only fills in info->flags and info->gpaddr_bits. info->arch_config is left zeroed, so XEN_DOMCTL_getdomaininfo always reports gic_version as XEN_DOMCTL_CONFIG_GIC_NATIVE (0) regardless of what was actually configured earlier. Signed-off-by: Julian Vetter Reviewed-by: Andrew Cooper Reviewed-by: Michal Orzel --- Changes in v5: - No changes. --- xen/arch/arm/domctl.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/xen/arch/arm/domctl.c b/xen/arch/arm/domctl.c index 6c9a3f9920..b76af56fad 100644 --- a/xen/arch/arm/domctl.c +++ b/xen/arch/arm/domctl.c @@ -24,6 +24,8 @@ void arch_get_domain_info(const struct domain *d, info->flags |=3D XEN_DOMINF_hap; =20 info->gpaddr_bits =3D p2m_ipa_bits; + + info->arch_config.gic_version =3D d->arch.vgic.version; } =20 static int handle_vuart_init(struct domain *d,=20 --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b2.6aee1b0ecd97f04d.1a090826c72.643865296eedc423=--- From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130904; cv=none; d=zohomail.com; s=zohoarc; b=cUxdsKeo4pF8jETjMuTN2yHtSWVFD9qpX3QjdyDJeb28j3vq1swPdYecJ/alQVZCt2SxMAgbzyLuQEx//J3e9RShfUC6fT9LFvVQUMzYUHhKMOTR+fQflA69M3DH5KESMMiBN53r97s23Nc89K/LvzfeFrBx0xBCgrKFoeOMni4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130904; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=owWzbNGsyZu7biLRA5l6PyyQaMaYKEJeQpD3hgcKdLc=; b=cSfeWMY4Mtcwg4mylntMPxz63yg/q+SaA37+x8z9KpmHifbobPoGPPz0XjYMAW5IZPr/2yIushnqCR9yCGSbePwanTti0M3/IlPLr3S68btB0EYkDO5MgLg4ZHI2lXuXDUW1q6CtOiR3rYwQDbEakhIneTugDvpsEw8J9gfzbmE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130904103883.9827022470942; Fri, 11 Sep 2026 05:48:24 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416560.1645531 (Exim 4.92) (envelope-from ) id 1x50fa-0004Sf-Rc; Fri, 11 Sep 2026 12:47:54 +0000 Received: by outflank-mailman (output) from mailman id 1416560.1645531; Fri, 11 Sep 2026 12:47:54 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fa-0004SY-Oy; Fri, 11 Sep 2026 12:47:54 +0000 Received: by outflank-mailman (input) for mailman id 1416560; Fri, 11 Sep 2026 12:47:53 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fZ-0004S4-BJ for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:47:53 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fY-00DvZA-OM for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:47:52 +0200 Received: from [10.42.69.3] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f86b-8faa-0a2a0a5109dd-0a2a4503b718-28 for ; Fri, 11 Sep 2026 14:47:52 +0200 Received: from [185.255.28.35] (helo=prod-mta-13-02.swg-srv.net) by tlsNG-33051d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f878-fae8-0a2a45030019-b9ff1c23b39b-3 for ; Fri, 11 Sep 2026 14:47:52 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-02.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a090827031000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:42 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id DDBF981E58; Fri, 11 Sep 2026 14:47:41 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=owWzbNGsyZu7biLRA5l6PyyQaMaYKEJeQpD3hgcKdLc=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=lvBJ+pyEfGMK2g2wEkh96uE1QSMAEFubh6NIIeRFUkkWcvMXlTXmmUMs8UFexSU7nJo6WrXxC ryQDcXNGKH6kor9TKnVx8xrv66HXGYv8oqV3H9nrVE06XTMJlSSNHlEfXRvJ6/m0ihQq2E9Tzin kLqEZEBZPr9Lngqb2bvjPLbhSopbsh5pj1bCIlVJqjybLpS6Ofv36Ul79iU8+hnLUXKRPqXPwWO YhxilDsKhr3MyynsZosTrLfe+oErgrPTQi/LFO9JCCs2YXGxmQme9lBFL/K1LeLhvLapwZ+L1IE emlg5t55rbsk4uO4GNQbOzGL79P1W/B+RXl+z7/3cYrQ== X-Zone-Loop: 9cf6a9fa902ee05aca6b2846dc4d8a46f206bd129666 x-campaign-type: default x-transaction-id: dea90c76-0d89-4479-bfe3-5d1f753d466f x-swg-uid: 01-816b2962-cec2-4b9f-b0a1-e9689d89178c X-Mailer: Sweego Message-ID: <1789130862.8631fc262581453bbf619ec5b2062170.1a090827031000c4f3@vates.tech> x-swg-bid: 1789130862.8631fc262581453bbf619ec5b2062170.1a090827031000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 2/6] ARM/sysctl: Expose the supported guest GIC modes in physinfo Date: Fri, 11 Sep 2026 14:47:32 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b3.969fd93c1d23af99.1a090826e8d.a9cdd1a1b522cf15=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130862221 X-purgate-ID: tlsNG-33051d/1789130872-778F24E9-5366F047/0/0 X-purgate-type: clean X-purgate-size: 5235 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130904719158500 ---=Part.b3.969fd93c1d23af99.1a090826e8d.a9cdd1a1b522cf15=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" From: Andrew Cooper In preparation to simplify the domain creation logic surrounding GIC version. On a GICv3 host, also report support for GICv2-compatible guests when the hardware's vGICv2 compatibility mode is enabled, rather than just the native GIC version. Signed-off-by: Andrew Cooper Signed-off-by: Julian Vetter Reviewed-by: Michal Orzel --- Changes in v5: - Add vgic_v2_hw_enabled() to new vgic implementation. --- xen/arch/arm/include/asm/vgic.h | 6 ++++++ xen/arch/arm/sysctl.c | 34 +++++++++++++++++++++++++++++++++ xen/arch/arm/vgic-v2.c | 5 +++++ xen/arch/arm/vgic/vgic-v2.c | 5 +++++ xen/include/public/sysctl.h | 2 ++ 5 files changed, 52 insertions(+) diff --git a/xen/arch/arm/include/asm/vgic.h b/xen/arch/arm/include/asm/vgi= c.h index 6f9ab1c98c..26c53aaf3c 100644 --- a/xen/arch/arm/include/asm/vgic.h +++ b/xen/arch/arm/include/asm/vgic.h @@ -433,6 +433,12 @@ unsigned int vgic_max_vcpus(unsigned int domctl_vgic_v= ersion); void vgic_v2_setup_hw(paddr_t dbase, paddr_t cbase, paddr_t csize, paddr_t vbase, uint32_t aliased_offset); =20 +#ifdef CONFIG_VGICV2 +bool vgic_v2_hw_enabled(void); +#else +static inline bool vgic_v2_hw_enabled(void) { return false; } +#endif + #ifdef CONFIG_GICV3 struct rdist_region; void vgic_v3_setup_hw(paddr_t dbase, diff --git a/xen/arch/arm/sysctl.c b/xen/arch/arm/sysctl.c index 32cab4feff..8411deb7e2 100644 --- a/xen/arch/arm/sysctl.c +++ b/xen/arch/arm/sysctl.c @@ -12,7 +12,11 @@ #include #include #include + #include +#include +#include + #include =20 void arch_do_physinfo(struct xen_sysctl_physinfo *pi) @@ -21,6 +25,36 @@ void arch_do_physinfo(struct xen_sysctl_physinfo *pi) =20 pi->arch_capabilities |=3D MASK_INSR(sve_encode_vl(get_sys_vl_len()), XEN_SYSCTL_PHYSCAP_ARM_SVE_MASK); + + /* + * The GIC version(s) we're happy creating guests with. Right now for + * simplicity it is tied to the active hardware version, but this will + * cease to be the case if/when the compatibility modes are enabled. + */ + switch ( gic_hw_version() ) + { + case GIC_V2: + pi->arch_capabilities |=3D XEN_SYSCTL_PHYSCAP_ARM_GIC_V2; + break; + + case GIC_V3: + pi->arch_capabilities |=3D XEN_SYSCTL_PHYSCAP_ARM_GIC_V3; + + /* GICv3 may additionally support GICv2-compatible guests. */ + if ( vgic_v2_hw_enabled() ) + pi->arch_capabilities |=3D XEN_SYSCTL_PHYSCAP_ARM_GIC_V2; + break; + + case GIC_INVALID: + /* + * Running a control domain without having the GIC sorted yet? + * Something's broken, but there's nothing we can do about it here. + */ + ASSERT_UNREACHABLE(); + printk_once(XENLOG_ERR "Unrecognised GIC version %d\n", + gic_hw_version()); + break; + } } =20 long arch_do_sysctl(struct xen_sysctl *sysctl, diff --git a/xen/arch/arm/vgic-v2.c b/xen/arch/arm/vgic-v2.c index 6328ce6f7e..62666a84db 100644 --- a/xen/arch/arm/vgic-v2.c +++ b/xen/arch/arm/vgic-v2.c @@ -49,6 +49,11 @@ void __init vgic_v2_setup_hw(paddr_t dbase, paddr_t cbas= e, paddr_t csize, vgic_v2_hw.aliased_offset =3D aliased_offset; } =20 +bool vgic_v2_hw_enabled(void) +{ + return vgic_v2_hw.enabled; +} + #define NR_TARGETS_PER_ITARGETSR 4U #define NR_BITS_PER_TARGET (32U / NR_TARGETS_PER_ITARGETSR) =20 diff --git a/xen/arch/arm/vgic/vgic-v2.c b/xen/arch/arm/vgic/vgic-v2.c index 06fa365453..f6a58ed89e 100644 --- a/xen/arch/arm/vgic/vgic-v2.c +++ b/xen/arch/arm/vgic/vgic-v2.c @@ -47,6 +47,11 @@ void __init vgic_v2_setup_hw(paddr_t dbase, paddr_t cbas= e, paddr_t csize, printk("Using the new VGIC implementation.\n"); } =20 +bool vgic_v2_hw_enabled(void) +{ + return gic_v2_hw_data.enabled; +} + /* * transfer the content of the LRs back into the corresponding ap_list: * - active bit is transferred as is diff --git a/xen/include/public/sysctl.h b/xen/include/public/sysctl.h index c7cd9b4eb0..d20ebf3644 100644 --- a/xen/include/public/sysctl.h +++ b/xen/include/public/sysctl.h @@ -106,6 +106,8 @@ struct xen_sysctl_tbuf_op { =20 #if defined(__arm__) || defined(__aarch64__) #define XEN_SYSCTL_PHYSCAP_ARM_SVE_MASK (0x1FU) +#define XEN_SYSCTL_PHYSCAP_ARM_GIC_V2 (1U << 5) +#define XEN_SYSCTL_PHYSCAP_ARM_GIC_V3 (1U << 6) #endif =20 struct xen_sysctl_physinfo { --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b3.969fd93c1d23af99.1a090826e8d.a9cdd1a1b522cf15=--- From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130898; cv=none; d=zohomail.com; s=zohoarc; b=Ysu7xZatYrwNJZfrCVQQHEpgpCcX8jwJQYUCSCzi7v5U0c7wF4VkGop2aoLvkVu42EEIVtXfzuzd0V3odgpTwqIQBxB8szez23JcfQA7HwkPddAxzJ5vWv5g7GiMuHEhRcYNORPyKE2rjH7xrSswy8VItZlndiUMYXgTMAM9+w8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130898; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=vrC5MCXxLXkzGn7Ngh7f+8ojnwijQbLllCJ+rZnRPgc=; b=eKmtqvjoU3V+y+ZvCknLXLNeFSMc80o79/hSryjdsbA7Yr/WCHjurE3tfEk1NHOmCC1+JhE7tZvdpBE7tGIOQgsqr5JSO1SeMsvOn24b1sMTUAxhG2p4Hoof8J6QtAvAplLU3/s9AOkxCpx6t+4weP4MPvgR/vgJ/uhoH+iPgOU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130898029352.59119167466145; Fri, 11 Sep 2026 05:48:18 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416561.1645541 (Exim 4.92) (envelope-from ) id 1x50fh-0004j8-4u; Fri, 11 Sep 2026 12:48:01 +0000 Received: by outflank-mailman (output) from mailman id 1416561.1645541; Fri, 11 Sep 2026 12:48:01 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fh-0004iy-0Q; Fri, 11 Sep 2026 12:48:01 +0000 Received: by outflank-mailman (input) for mailman id 1416561; Fri, 11 Sep 2026 12:47:59 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50ff-0004go-Dc for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:47:59 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fe-008TeR-9z for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:47:58 +0200 Received: from [10.42.69.2] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f877-bab6-0a2a0a5309dd-0a2a4502e99c-14 for ; Fri, 11 Sep 2026 14:47:58 +0200 Received: from [185.255.28.35] (helo=prod-mta-13-02.swg-srv.net) by tlsNG-720697.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f87d-6ca4-0a2a45020019-b9ff1c239bc3-3 for ; Fri, 11 Sep 2026 14:47:58 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-02.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a090827272000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:43 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id 52F7081E4A; Fri, 11 Sep 2026 14:47:42 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=vrC5MCXxLXkzGn7Ngh7f+8ojnwijQbLllCJ+rZnRPgc=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=OPkpc6pvgZSQvxmsmOL6Tj+9fky4rSsYhrMNQUkfLTJ9kL07+O1YWA86FbvEpuT35s0QnVfwl n+KH9ypUSOv4akxYTBupy8fH5EfAZILJq9qZLwA0c/YDxKi7dOrgbQAy6znP67Onz0jQfX3MwAo EzW0nP91ANi12s+0rTt0WvuUDydduMvPZgE7wBE1xGrEX6ogQzDUJQmrqTN83K1k2V66fqXGRll cjZcxUqY1B8x+IRVbK6IlGVMvY9VMdpgqNhMj5YnmSWHS0s27tFIxL7wcgcTiE75sW0NobVdi/k QS3sB3UraFeR+ShVOxFX2AC1gGsV9PEz++ErYh4yeV8g== X-Zone-Loop: 4a3653298c3bf37ca16e2812419115f707825a9f6892 x-campaign-type: default x-transaction-id: 78459a14-e521-4521-990a-8b7311a5bc2a x-swg-uid: 01-92954f62-b3c4-493b-b03d-5b6ef9ae6f6d X-Mailer: Sweego Message-ID: <1789130863.8631fc262581453bbf619ec5b2062170.1a090827272000c4f3@vates.tech> x-swg-bid: 1789130863.8631fc262581453bbf619ec5b2062170.1a090827272000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 3/6] tools/arm: choose GIC version explicitly instead of relying on GIC_NATIVE Date: Fri, 11 Sep 2026 14:47:33 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b4.900c1da711343b33.1a09082703b.b4d96a58cee70c8d=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130862651 X-purgate-ID: tlsNG-720697/1789130878-F36BF2AC-B6BB2CCB/0/0 X-purgate-type: clean X-purgate-size: 9446 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130899054158500 ---=Part.b4.900c1da711343b33.1a09082703b.b4d96a58cee70c8d=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" XEN_DOMCTL_CONFIG_GIC_NATIVE lets the toolstack ask Xen to silently resolve the domain's GIC version to whatever the host hardware has. Xen then writes the resolved value back into the same in/out xen_arch_domainconfig the toolstack used as input, which is the kind of API abuse we're trying to get rid of. The struct passed to createdomain should only be an input parameter. Move the "pick the best available GIC version" decision to the toolstack, using the XEN_SYSCTL_PHYSCAP_ARM_GIC_V2/V3 capability bits already exposed via XEN_SYSCTL_physinfo: * libxl__arch_domain_build_info_setdefault() resolves the GIC version against those bits before the config is built. An unspecified version becomes v3 if available, else v2, else fails. An explicitly requested v2/v3 is validated against the same bits, so a version the host cannot provide is directly rejected in the toolstack. * The Python xc.domain_create() binding does the same via a call to xc_physinfo(). * libxl__arch_domain_prepare_config() therefore only ever sees a concrete v2/v3 request and just validates it. The GIC_NATIVE case is dropped since setdefault() always resolves it first. The LIBXL_GIC_VERSION enum value 0 is renamed from DEFAULT to NONE to reflect that it now only means "the user did not pick a version". setdefault() resolves it before anything else can observe it, so there is no longer a "default" left in the config. The xl.cfg(5) gic_version documentation is updated to match. This guarantees no toolstack path can still produce XEN_DOMCTL_CONFIG_GIC_NATIVE, in preparation for removing it from the Xen side and from the ABI entirely. Signed-off-by: Julian Vetter Acked-by: Michal Orzel --- Changes in v5: - Go back to the initial per-version arch_capabilities_arm_gic_{v2,v3}() helpers instead of a generic arch_capabilities_arm_has(caps, mask) - Validate an explicitly requested GIC version against the host capabilities, not just resolve an unspecified one - Rename LIBXL_GIC_VERSION_DEFAULT to LIBXL_GIC_VERSION_NONE - Document the change in xl.cfg(5) --- docs/man/xl.cfg.5.pod.in | 9 ++-- .../include/xen-tools/arm-arch-capabilities.h | 21 +++++++++ tools/libs/light/libxl_arm.c | 45 +++++++++++++++++-- tools/libs/light/libxl_types.idl | 4 +- tools/python/xen/lowlevel/xc/xc.c | 18 +++++++- 5 files changed, 87 insertions(+), 10 deletions(-) diff --git a/docs/man/xl.cfg.5.pod.in b/docs/man/xl.cfg.5.pod.in index d34951edb9..6a5e75eeab 100644 --- a/docs/man/xl.cfg.5.pod.in +++ b/docs/man/xl.cfg.5.pod.in @@ -3081,15 +3081,16 @@ Emulate a GICv2 Emulate a GICv3. Note that the emulated GIC does not support the GICv2 compatibility mode. =20 -=3Ditem B +=3Ditem B =20 -Emulate the same version as the native GIC hardware used by the host where -the domain was created. +Let the toolstack choose the GIC version: GICv3 if the host supports it, +otherwise GICv2. This is the default when C is not specified. =20 =3Dback =20 This requires hardware compatibility with the requested version, either -natively or via hardware backwards compatibility support. +natively or via hardware backwards compatibility support. The GIC versions +the host can emulate for a guest are reported via C. =20 =3Ditem B =20 diff --git a/tools/include/xen-tools/arm-arch-capabilities.h b/tools/includ= e/xen-tools/arm-arch-capabilities.h index 4aa4c6c34a..21e3c73bd1 100644 --- a/tools/include/xen-tools/arm-arch-capabilities.h +++ b/tools/include/xen-tools/arm-arch-capabilities.h @@ -6,6 +6,7 @@ #ifndef ARM_ARCH_CAPABILITIES_H #define ARM_ARCH_CAPABILITIES_H =20 +#include #include #include =20 @@ -25,4 +26,24 @@ unsigned int arch_capabilities_arm_sve(unsigned int arch= _capabilities) #endif } =20 +static inline +bool arch_capabilities_arm_gic_v2(unsigned int arch_capabilities) +{ +#if defined(__arm__) || defined(__aarch64__) + return MASK_EXTR(arch_capabilities, XEN_SYSCTL_PHYSCAP_ARM_GIC_V2); +#else + return false; +#endif +} + +static inline +bool arch_capabilities_arm_gic_v3(unsigned int arch_capabilities) +{ +#if defined(__arm__) || defined(__aarch64__) + return MASK_EXTR(arch_capabilities, XEN_SYSCTL_PHYSCAP_ARM_GIC_V3); +#else + return false; +#endif +} + #endif /* ARM_ARCH_CAPABILITIES_H */ diff --git a/tools/libs/light/libxl_arm.c b/tools/libs/light/libxl_arm.c index 7e9f8a1bc3..283cfb749b 100644 --- a/tools/libs/light/libxl_arm.c +++ b/tools/libs/light/libxl_arm.c @@ -196,9 +196,6 @@ int libxl__arch_domain_prepare_config(libxl__gc *gc, LOG(DEBUG, " - Allocate %u SPIs", config->arch.nr_spis); =20 switch (d_config->b_info.arch_arm.gic_version) { - case LIBXL_GIC_VERSION_DEFAULT: - config->arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_NATIVE; - break; case LIBXL_GIC_VERSION_V2: config->arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_V2; break; @@ -1800,6 +1797,48 @@ int libxl__arch_domain_build_info_setdefault(libxl__= gc *gc, /* Trapping of unmapped accesses enabled by default. */ libxl_defbool_setdefault(&b_info->trap_unmapped_accesses, true); =20 + /* + * Resolve the GIC version against the host capabilities reported by + * XEN_SYSCTL_physinfo. If the user didn't request a specific version,= pick + * the best one available. Otherwise validate the requested version he= re, + * so a bad request fails early instead of in the hypervisor. + */ + { + bool has_v3 =3D arch_capabilities_arm_gic_v3(physinfo->arch_capabi= lities); + bool has_v2 =3D arch_capabilities_arm_gic_v2(physinfo->arch_capabi= lities); + + switch (b_info->arch_arm.gic_version) { + case LIBXL_GIC_VERSION_NONE: + if (has_v3) + b_info->arch_arm.gic_version =3D LIBXL_GIC_VERSION_V3; + else if (has_v2) + b_info->arch_arm.gic_version =3D LIBXL_GIC_VERSION_V2; + else { + LOG(ERROR, "No supported GIC version found on this host"); + return ERROR_FAIL; + } + break; + + case LIBXL_GIC_VERSION_V3: + if (!has_v3) { + LOG(ERROR, "GICv3 requested but not supported on this host= "); + return ERROR_FAIL; + } + break; + + case LIBXL_GIC_VERSION_V2: + if (!has_v2) { + LOG(ERROR, "GICv2 requested but not supported on this host= "); + return ERROR_FAIL; + } + break; + + default: + LOG(ERROR, "Unknown GIC version %d", b_info->arch_arm.gic_vers= ion); + return ERROR_FAIL; + } + } + /* Sanitise SVE parameter */ if (b_info->arch_arm.sve_vl) { unsigned int max_sve_vl =3D diff --git a/tools/libs/light/libxl_types.idl b/tools/libs/light/libxl_type= s.idl index a7893460f0..8699ab3013 100644 --- a/tools/libs/light/libxl_types.idl +++ b/tools/libs/light/libxl_types.idl @@ -520,10 +520,10 @@ libxl_vnode_info =3D Struct("vnode_info", [ ]) =20 libxl_gic_version =3D Enumeration("gic_version", [ - (0, "DEFAULT"), + (0, "NONE"), (0x20, "v2"), (0x30, "v3") - ], init_val =3D "LIBXL_GIC_VERSION_DEFAULT") + ], init_val =3D "LIBXL_GIC_VERSION_NONE") =20 libxl_tee_type =3D Enumeration("tee_type", [ (0, "none"), diff --git a/tools/python/xen/lowlevel/xc/xc.c b/tools/python/xen/lowlevel/= xc/xc.c index 7a4bf54597..0127b4b1b7 100644 --- a/tools/python/xen/lowlevel/xc/xc.c +++ b/tools/python/xen/lowlevel/xc/xc.c @@ -163,7 +163,23 @@ static PyObject *pyxc_domain_create(XcObject *self, ~(XEN_X86_EMU_VPCI | XEN_X86_EMU_USE_PIRQ); #elif defined (__arm__) || defined(__aarch64__) - config.arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_NATIVE; + { + xc_physinfo_t pinfo; + + if ( xc_physinfo(self->xc_handle, &pinfo) !=3D 0 ) + return pyxc_error_to_exception(self->xc_handle); + + if ( arch_capabilities_arm_gic_v3(pinfo.arch_capabilities) ) + config.arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_V3; + else if ( arch_capabilities_arm_gic_v2(pinfo.arch_capabilities) ) + config.arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_V2; + else + { + errno =3D EINVAL; + PyErr_SetFromErrno(xc_error_obj); + return NULL; + } + } #else #error Architecture not supported #endif --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b4.900c1da711343b33.1a09082703b.b4d96a58cee70c8d=--- From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130910; cv=none; d=zohomail.com; s=zohoarc; b=Jc5AfPka3DYHhRCG8FS8oZfVaOxJczXy9aj11Dw/+f9kGIoSqmCKRbnsKsyvND6D+uQOIbxTapy9mDyZvq7YGLtPPZHWA4c3mVFhfHCq+Tj52NJJ/pSwyk5ET4IHRfpK5lmLFjLh50EiztEyRioylvv9MW4obpX93fQPryDzRvE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130910; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=zbpTZxCu0I/pB7xgrSlTLWOGkj1LZPQfs18Cj/FuclM=; b=Nc1nuC4X0ZoU7R6mWpEDmvXVdRHQY+UXRiRSuHCcWp9dLGKsmW8PZRsyLZOYA0S2R4bOXmYPuye/xb8ev39AC77uQm5pnCvhN2fn5omMYqlvazif+xe9O3zaDzALjANc8WkhLubSOO3CbORyzIKQ5JhQQbzsdc8qL/V73WiV1fY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130910556181.35645743669124; Fri, 11 Sep 2026 05:48:30 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416563.1645548 (Exim 4.92) (envelope-from ) id 1x50fm-00051G-FT; Fri, 11 Sep 2026 12:48:06 +0000 Received: by outflank-mailman (output) from mailman id 1416563.1645548; Fri, 11 Sep 2026 12:48:06 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fm-000519-CT; Fri, 11 Sep 2026 12:48:06 +0000 Received: by outflank-mailman (input) for mailman id 1416563; Fri, 11 Sep 2026 12:48:05 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fl-0004zb-5Y for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:48:05 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fk-003mH0-I9 for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:48:04 +0200 Received: from [10.42.69.8] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f878-e002-0a2a0a5209dd-0a2a4508ea68-34 for ; Fri, 11 Sep 2026 14:48:04 +0200 Received: from [185.255.28.35] (helo=prod-mta-13-02.swg-srv.net) by tlsNG-c1860d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f884-f659-0a2a45080019-b9ff1c23a55f-3 for ; Fri, 11 Sep 2026 14:48:04 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-02.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a09082744e000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:43 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id BCC3B81E58; Fri, 11 Sep 2026 14:47:42 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=zbpTZxCu0I/pB7xgrSlTLWOGkj1LZPQfs18Cj/FuclM=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=AeNM5EMT2vhtM4JjC8UeSEXPSCuZ4S15CwxoIycGSwShFZK+t2iig+CBTmkE7jfM5aVBiaEgG ZYFY19TLpYWvzNNyHeIroLgEpezksClxUXyYxYuhHacD1u16DCAyTz6pFtiXniwnvnqkUZJ3wrU ezDcRX4c2jaQ5DwTKfqOMrGy2kGdNFILQRqtOsxD1XHJSVJ3MH8RJhnmKrwDXpoYNZ4jj8f4d9T 9wJf2wuCF1I1qer9vyfYwNVC5AHPsTYu1gNTBty9V7vqGYTYHxkwovunLvzIUW/33ebAL673xi/ EayiYoAbq01ndrNihk0o6sn0HIPUiLtCvGwFPTEM2DvA== X-Zone-Loop: 18cebf876a10915a7bcfecb2c42a0f6bd638fe9d6436 x-campaign-type: default x-transaction-id: 5161c42c-a3d7-4903-addd-10705e8612ac x-swg-uid: 01-cc6aca94-5c1b-480e-9e57-b03ac945f3df X-Mailer: Sweego Message-ID: <1789130863.8631fc262581453bbf619ec5b2062170.1a09082744e000c4f3@vates.tech> x-swg-bid: 1789130863.8631fc262581453bbf619ec5b2062170.1a09082744e000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 4/6] xen/arm: remove XEN_DOMCTL_CONFIG_GIC_NATIVE from the ABI Date: Fri, 11 Sep 2026 14:47:34 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b5.3ccc6b8d5b09d419.1a0908271e9.ca25eca4288c8cfc=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130863081 X-purgate-ID: tlsNG-c1860d/1789130884-CC97287B-6445FDFD/0/0 X-purgate-type: clean X-purgate-size: 8032 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130912793158500 ---=Part.b5.3ccc6b8d5b09d419.1a0908271e9.ca25eca4288c8cfc=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Now that the toolstack always resolves a concrete GIC_V2 or GIC_V3 before calling createdomain, nothing on the Xen side needs to resolve GIC_NATIVE either: * A new gic_domctl_hw_version() helper returns the XEN_DOMCTL_CONFIG_GIC_* value matching the host's gic_hw_version(). * arch_sanitise_domain_config() uses it to validate the requested version against the hardware, rather than resolving GIC_NATIVE and writing the result back into config->arch.gic_version. A guest must use the host's GIC version, except that a GICv3 host with the GICv2 compatibility mode enabled may also run GICv2 guests. This is the same information that XEN_SYSCTL_physinfo reports to the toolstack. * create_dom0() and arch_parse_dom0less_node(), which both always want a vGIC that exactly matches the hardware, use the same helper instead of GIC_NATIVE. With nothing left resolving or relying on it, drop XEN_DOMCTL_CONFIG_GIC_NATIVE from the public ABI. Every caller must now request a concrete GIC_V2 or GIC_V3. This is an incompatible change for any toolstack still passing 0 (formerly GIC_NATIVE) expecting Xen to auto-select a version. Add a CHANGELOG.md entry, noting that available GIC versions can be queried via XEN_SYSCTL_physinfo. Signed-off-by: Julian Vetter --- Changes in v5: - Rename gic_domctl_version() to gic_domctl_hw_version() - Accept a GICv2 guest on a GICv3 host with GICv2 compatibility mode enabled, instead of requiring an exact match with the host GIC version --- CHANGELOG.md | 4 ++++ xen/arch/arm/dom0less-build.c | 3 ++- xen/arch/arm/domain.c | 27 +++++++++++---------------- xen/arch/arm/domain_build.c | 3 ++- xen/arch/arm/gic.c | 16 ++++++++++++++++ xen/arch/arm/include/asm/gic.h | 6 ++++++ xen/include/public/arch-arm.h | 2 +- 7 files changed, 42 insertions(+), 19 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index aa1a777dd4..78d1b13f3f 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -18,6 +18,10 @@ The format is based on [Keep a Changelog](https://keepac= hangelog.com/en/1.0.0/) ### Added =20 ### Removed + - On Arm: + - XEN_DOMCTL_CONFIG_GIC_NATIVE has been removed. Toolstacks must now + explicitly request GIC_V2 or GIC_V3 when creating a domain. + Available GIC versions can be queried via XEN_SYSCTL_physinfo. - On x86: - The kexec "v1" interface, which was declared obsolete in Xen 4.4 (201= 3). The only known user was the classic-xen fork of Linux. This does not diff --git a/xen/arch/arm/dom0less-build.c b/xen/arch/arm/dom0less-build.c index 3f48f74226..7bbb2eafb6 100644 --- a/xen/arch/arm/dom0less-build.c +++ b/xen/arch/arm/dom0less-build.c @@ -23,6 +23,7 @@ #include #include #include +#include #include #include =20 @@ -368,7 +369,7 @@ int __init arch_parse_dom0less_node(struct dt_device_no= de *node, unsigned int flags =3D bd->create_flags; uint32_t val; =20 - d_cfg->arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_NATIVE; + d_cfg->arch.gic_version =3D gic_domctl_hw_version(); d_cfg->flags |=3D XEN_DOMCTL_CDF_hvm | XEN_DOMCTL_CDF_hap; =20 if ( domu_dt_sci_parse(node, d_cfg) ) diff --git a/xen/arch/arm/domain.c b/xen/arch/arm/domain.c index a739dd157e..6f5f92876e 100644 --- a/xen/arch/arm/domain.c +++ b/xen/arch/arm/domain.c @@ -609,23 +609,18 @@ int arch_sanitise_domain_config(struct xen_domctl_cre= atedomain *config) return -EINVAL; } =20 - /* Fill in the native GIC version, passed back to the toolstack. */ - if ( config->arch.gic_version =3D=3D XEN_DOMCTL_CONFIG_GIC_NATIVE ) + /* + * A guest can only use the host's GIC version, except that a GICv3 ho= st + * with the GICv2 compatibility mode enabled can also run GICv2 guests. + * This mirrors what XEN_SYSCTL_physinfo reports to the toolstack. + */ + if ( config->arch.gic_version !=3D gic_domctl_hw_version() && + !(config->arch.gic_version =3D=3D XEN_DOMCTL_CONFIG_GIC_V2 && + vgic_v2_hw_enabled()) ) { - switch ( gic_hw_version() ) - { - case GIC_V2: - config->arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_V2; - break; - - case GIC_V3: - config->arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_V3; - break; - - default: - ASSERT_UNREACHABLE(); - return -EINVAL; - } + dprintk(XENLOG_INFO, "Unsupported GIC version %u\n", + config->arch.gic_version); + return -EINVAL; } =20 /* max_vcpus depends on the GIC version, and Xen's compiled limit. */ diff --git a/xen/arch/arm/domain_build.c b/xen/arch/arm/domain_build.c index 72d5316180..cf7e1100bd 100644 --- a/xen/arch/arm/domain_build.c +++ b/xen/arch/arm/domain_build.c @@ -26,6 +26,7 @@ #include #include #include +#include #include #include #include @@ -1960,7 +1961,7 @@ void __init create_dom0(void) int rc; =20 /* The vGIC for DOM0 is exactly emulating the hardware GIC */ - dom0_cfg.arch.gic_version =3D XEN_DOMCTL_CONFIG_GIC_NATIVE; + dom0_cfg.arch.gic_version =3D gic_domctl_hw_version(); dom0_cfg.arch.nr_spis =3D vgic_def_nr_spis(); dom0_cfg.arch.tee_type =3D tee_get_type(); dom0_cfg.max_vcpus =3D dom0_max_vcpus(); diff --git a/xen/arch/arm/gic.c b/xen/arch/arm/gic.c index 078049e741..997b6ee6ed 100644 --- a/xen/arch/arm/gic.c +++ b/xen/arch/arm/gic.c @@ -56,6 +56,22 @@ enum gic_version gic_hw_version(void) return gic_hw_ops->info->hw_version; } =20 +uint8_t gic_domctl_hw_version(void) +{ + switch ( gic_hw_version() ) + { + case GIC_V2: + return XEN_DOMCTL_CONFIG_GIC_V2; + + case GIC_V3: + return XEN_DOMCTL_CONFIG_GIC_V3; + + default: + ASSERT_UNREACHABLE(); + return 0; + } +} + unsigned int gic_number_lines(void) { return gic_hw_ops->info->nr_lines; diff --git a/xen/arch/arm/include/asm/gic.h b/xen/arch/arm/include/asm/gic.h index ee2c26adb4..434b888e69 100644 --- a/xen/arch/arm/include/asm/gic.h +++ b/xen/arch/arm/include/asm/gic.h @@ -262,6 +262,12 @@ DECLARE_PER_CPU(uint64_t, lr_mask); =20 extern enum gic_version gic_hw_version(void); =20 +/* + * The XEN_DOMCTL_CONFIG_GIC_* value matching the GIC version actually + * present on this host. + */ +extern uint8_t gic_domctl_hw_version(void); + /* Program the IRQ type into the GIC */ void gic_set_irq_type(struct irq_desc *desc, unsigned int type); =20 diff --git a/xen/include/public/arch-arm.h b/xen/include/public/arch-arm.h index 00de30b896..9d3bf11cbd 100644 --- a/xen/include/public/arch-arm.h +++ b/xen/include/public/arch-arm.h @@ -319,7 +319,7 @@ DEFINE_XEN_GUEST_HANDLE(vcpu_guest_context_t); * struct xen_arch_domainconfig's ABI is covered by * XEN_DOMCTL_INTERFACE_VERSION. */ -#define XEN_DOMCTL_CONFIG_GIC_NATIVE 0 +/* XEN_DOMCTL_CONFIG_GIC_NATIVE 0 - removed in Xen 4.23 */ #define XEN_DOMCTL_CONFIG_GIC_V2 1 #define XEN_DOMCTL_CONFIG_GIC_V3 2 =20 --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b5.3ccc6b8d5b09d419.1a0908271e9.ca25eca4288c8cfc=--- From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130907; cv=none; d=zohomail.com; s=zohoarc; b=TwIWCvfZoEGUW50s87BLX6xbe/IQEK30vSJydQxlB7QDk5fuqpk11GAgccW1IGowfOdPKmS5lmHkZZxXrbwQt1ql0qluPDLXNgCWiA6pq4IPRwzGLc6uX3QyMQNMxZ/Gk2AZoIC7ZCGHkwwGXYdKySJnavPDhhy8zDm+i0f1Lq8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130907; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=e63R22GnWuCkoRCDuBwl1UbdkbLnvthe1GGv5qc8yeY=; b=P4zGkCEY3/7XB7fcJ/P1gN8RHTUswu2SI72LCoUsIiAqpeWLg8DwRG6K7l2aYXq4NO8ddFwd3fG454+LOfMFKmPrcVNhLzkFVdfm/2r4lKqCnKIAi2d1ERu8zxi1dp4+u3qzTQphbsD5xqnyX8xx7qgsMiG8AadyX6ikIOPmITE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130907129446.4035868758609; Fri, 11 Sep 2026 05:48:27 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416566.1645558 (Exim 4.92) (envelope-from ) id 1x50fq-0005K3-NJ; Fri, 11 Sep 2026 12:48:10 +0000 Received: by outflank-mailman (output) from mailman id 1416566.1645558; Fri, 11 Sep 2026 12:48:10 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fq-0005Jw-K3; Fri, 11 Sep 2026 12:48:10 +0000 Received: by outflank-mailman (input) for mailman id 1416566; Fri, 11 Sep 2026 12:48:09 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fp-0005Ho-07 for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:48:09 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fo-003mHJ-Cz for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:48:08 +0200 Received: from [10.42.69.3] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f880-8faa-0a2a0a5109dd-0a2a4503a8fe-30 for ; Fri, 11 Sep 2026 14:48:08 +0200 Received: from [185.255.28.34] (helo=prod-mta-13-01.swg-srv.net) by tlsNG-33051d.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f887-fae8-0a2a45030019-b9ff1c228c1f-3 for ; Fri, 11 Sep 2026 14:48:08 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13-01.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a0908275e9000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:44 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id 5E9CA81E4A; Fri, 11 Sep 2026 14:47:43 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=e63R22GnWuCkoRCDuBwl1UbdkbLnvthe1GGv5qc8yeY=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=O8RPO7Y9bDH1z0REYTvpNlDaZ6ZIZpHN9X2le3qBzyUKjaq+iwuduSOBrv8oiPsANPVhYMAuR D0iyqA1hXYMNTgGgjvHajI/f2j8lnjOLEvtqEySRvjcLNLNgxlPGO2eeo0gGU4iXSrbUEB3HUk4 ywCoTjPXKWT+/KwT8lY8ZQV57A3vy7eL4i3L9dRLeO3EgXTxkydgt1rYhbJjPRQEoW/KJkY8oVn snXBEuwcTAyFaDncGrsdJ+cPUYkSPq+Nq2kf7R45WFY4UH8Uwwm1ZC0zqxfWV38FK9V1Bbb0Th8 I7qu+icrV9nHBOYaC65F4BnXm2g1J/s0HWzYjDkalQjA== X-Zone-Loop: dbabf15597bf0f1b03989ea4fb9095ef3b6a7138c8ce x-campaign-type: default x-transaction-id: 8f6e74c2-9dcb-4c11-9c27-f0f2c2c37ab9 x-swg-uid: 01-1b89235f-4f94-4f3c-b9fe-0516b47c83f8 X-Mailer: Sweego Message-ID: <1789130864.8631fc262581453bbf619ec5b2062170.1a0908275e9000c4f3@vates.tech> x-swg-bid: 1789130864.8631fc262581453bbf619ec5b2062170.1a0908275e9000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 5/6] xen/arm: report clock_frequency via sysctl physinfo, not createdomain Date: Fri, 11 Sep 2026 14:47:35 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b6.4d0d4fd336db1aff.1a09082744a.3ae593f4d687c111=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130863690 X-purgate-ID: tlsNG-33051d/1789130888-766FB4E9-C27AEC19/0/0 X-purgate-type: clean X-purgate-size: 16977 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130908994158500 ---=Part.b6.4d0d4fd336db1aff.1a09082744a.3ae593f4d687c111=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The xen_arch_domainconfig.clock_frequency value is populated in domain_vtimer_init() during XEN_DOMCTL_createdomain from the global timer_dt_clock_frequency, which comes from the host's DT timer node and has nothing to do with the domain being created. Like now removed GIC_NATIVE resolution, this is a host-wide system property being smuggled out through a domain-creation IN struct. Expose it instead as a new arch_clock_frequency_hz field in XEN_SYSCTL_physinfo, populated via arch_do_physinfo(), and mirroring how the GIC capability bits were already moved there. Rather than making the field dependant on DT boot, make Xen always report the timer frequency, either via the DT "clock-frequency" node, or directly via CNTFRQ_EL0. preinit_xen_time() already computes cpu_khz for every boot path. The renamed timer_clock_frequency_hz now captures whichever of the two produced that value, in full Hz precision, instead of only recording the DT case. So, ACPI guests get a real value too, allowing to drop the special case. The DT "clock-frequency" property exists because firmware might leave CNTFRQ_EL0 wrong, and since CNTFRQ_EL0 cannot be trapped the only fix is to replicate the correct value into the guest DT. To keep that signal, a new XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ capability bit records whether arch_clock_frequency_hz came from the DT property. Then libxl only emits a "clock-frequency" property into the guest timer node when that bit is set. A guest whose CNTFRQ_EL0 is already correct keeps an unmodified timer node, exactly as before. Although the CNTFRQ_EL0 register is 64 bits wide, and some current timer implementations run at 1GHz, a 32bit value is sufficient to store the timer value, because it only mirrors the DT 'clock-frequency' property, which the bindings define as a single 32-bit cell. In struct xen_sysctl_physinfo the new field just reuses the former pad word, so sysctl consumers are unaffected. struct xen_arch_domainconfig however loses clock_frequency from its middle, which shrinks the struct and shifts every field after it, so bump XEN_DOMCTL_INTERFACE_VERSION. The xen_arch_domainconfig parameter passed to domain_vtimer_init() is no longer needed, so drop that parameter entirely. libxl now fetches the frequency via libxl_get_physinfo() in libxl__arch_domain_save_config() instead of reading it back out of the createdomain reply. The OCaml xen_arch_domainconfig mirror drops the field too. Signed-off-by: Julian Vetter Reviewed-by: Michal Orzel --- Changes in v5: - Bump XEN_DOMCTL_INTERFACE_VERSION: removing clock_frequency shrinks and shifts struct xen_arch_domainconfig - Add XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ (with an arch_capabilities_arm_timer_dt_freq() helper) so libxl emits a guest DT "clock-frequency" only when the value came from the host DT - Reword the arch_clock_frequency_hz comment: 0 now only means non-ARM --- .../include/xen-tools/arm-arch-capabilities.h | 10 +++++++++ tools/libs/light/libxl.c | 1 + tools/libs/light/libxl_arm.c | 21 ++++++++++++++++++- tools/libs/light/libxl_types.idl | 1 + tools/ocaml/libs/xc/xenctrl.ml | 1 - tools/ocaml/libs/xc/xenctrl.mli | 1 - xen/arch/arm/domain.c | 2 +- xen/arch/arm/include/asm/time.h | 7 ++++--- xen/arch/arm/include/asm/vtimer.h | 3 +-- xen/arch/arm/sysctl.c | 5 +++++ xen/arch/arm/time.c | 9 +++++--- xen/arch/arm/vtimer.c | 4 +--- xen/include/public/arch-arm.h | 16 +------------- xen/include/public/domctl.h | 4 ++-- xen/include/public/sysctl.h | 20 +++++++++++++++++- 15 files changed, 72 insertions(+), 33 deletions(-) diff --git a/tools/include/xen-tools/arm-arch-capabilities.h b/tools/includ= e/xen-tools/arm-arch-capabilities.h index 21e3c73bd1..a927bc4703 100644 --- a/tools/include/xen-tools/arm-arch-capabilities.h +++ b/tools/include/xen-tools/arm-arch-capabilities.h @@ -46,4 +46,14 @@ bool arch_capabilities_arm_gic_v3(unsigned int arch_capa= bilities) #endif } =20 +static inline +bool arch_capabilities_arm_timer_dt_freq(unsigned int arch_capabilities) +{ +#if defined(__arm__) || defined(__aarch64__) + return MASK_EXTR(arch_capabilities, XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FR= EQ); +#else + return false; +#endif +} + #endif /* ARM_ARCH_CAPABILITIES_H */ diff --git a/tools/libs/light/libxl.c b/tools/libs/light/libxl.c index a1fe16274d..ec7e6d3f65 100644 --- a/tools/libs/light/libxl.c +++ b/tools/libs/light/libxl.c @@ -410,6 +410,7 @@ int libxl_get_physinfo(libxl_ctx *ctx, libxl_physinfo *= physinfo) physinfo->cap_gnttab_v2 =3D !!(xcphysinfo.capabilities & XEN_SYSCTL_PHYSCAP_gnttab_v2); physinfo->arch_capabilities =3D xcphysinfo.arch_capabilities; + physinfo->arch_clock_frequency_hz =3D xcphysinfo.arch_clock_frequency_= hz; =20 GC_FREE; return 0; diff --git a/tools/libs/light/libxl_arm.c b/tools/libs/light/libxl_arm.c index 283cfb749b..3d232040c9 100644 --- a/tools/libs/light/libxl_arm.c +++ b/tools/libs/light/libxl_arm.c @@ -252,6 +252,9 @@ int libxl__arch_domain_save_config(libxl__gc *gc, libxl__domain_build_state *state, const struct xen_domctl_createdomain *c= onfig) { + libxl_physinfo info; + int rc; + switch (config->arch.gic_version) { case XEN_DOMCTL_CONFIG_GIC_V2: d_config->b_info.arch_arm.gic_version =3D LIBXL_GIC_VERSION_V2; @@ -264,7 +267,23 @@ int libxl__arch_domain_save_config(libxl__gc *gc, return ERROR_FAIL; } =20 - state->clock_frequency =3D config->arch.clock_frequency; + libxl_physinfo_init(&info); + rc =3D libxl_get_physinfo(CTX, &info); + if (rc) { + LOG(ERROR, "failed to get physinfo"); + libxl_physinfo_dispose(&info); + return ERROR_FAIL; + } + /* + * Pass the timer frequency on to the guest DT only when Xen took it f= rom + * the host DT (XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ). Otherwise the g= uest + * gets the right value from CNTFRQ_EL0. + */ + if (arch_capabilities_arm_timer_dt_freq(info.arch_capabilities)) + state->clock_frequency =3D info.arch_clock_frequency_hz; + else + state->clock_frequency =3D 0; + libxl_physinfo_dispose(&info); =20 return 0; } diff --git a/tools/libs/light/libxl_types.idl b/tools/libs/light/libxl_type= s.idl index 8699ab3013..e2e4be7323 100644 --- a/tools/libs/light/libxl_types.idl +++ b/tools/libs/light/libxl_types.idl @@ -1201,6 +1201,7 @@ libxl_physinfo =3D Struct("physinfo", [ ("cap_gnttab_v1", bool), ("cap_gnttab_v2", bool), ("arch_capabilities", uint32), + ("arch_clock_frequency_hz", uint32), # ARM only ], dir=3DDIR_OUT) =20 libxl_connectorinfo =3D Struct("connectorinfo", [ diff --git a/tools/ocaml/libs/xc/xenctrl.ml b/tools/ocaml/libs/xc/xenctrl.ml index 147afa62c2..582897af6d 100644 --- a/tools/ocaml/libs/xc/xenctrl.ml +++ b/tools/ocaml/libs/xc/xenctrl.ml @@ -32,7 +32,6 @@ type xen_arm_arch_domainconfig =3D { gic_version: int; nr_spis: int; - clock_frequency: int32; } =20 type x86_arch_emulation_flags =3D diff --git a/tools/ocaml/libs/xc/xenctrl.mli b/tools/ocaml/libs/xc/xenctrl.= mli index 9fccb2c2c2..9414b87164 100644 --- a/tools/ocaml/libs/xc/xenctrl.mli +++ b/tools/ocaml/libs/xc/xenctrl.mli @@ -26,7 +26,6 @@ type vcpuinfo =3D { type xen_arm_arch_domainconfig =3D { gic_version: int; nr_spis: int; - clock_frequency: int32; } =20 type x86_arch_emulation_flags =3D diff --git a/xen/arch/arm/domain.c b/xen/arch/arm/domain.c index 6f5f92876e..d4037c402a 100644 --- a/xen/arch/arm/domain.c +++ b/xen/arch/arm/domain.c @@ -713,7 +713,7 @@ int arch_domain_create(struct domain *d, if ( (rc =3D domain_vgic_init(d, config->arch.nr_spis)) !=3D 0 ) goto fail; =20 - if ( (rc =3D domain_vtimer_init(d, &config->arch)) !=3D 0 ) + if ( (rc =3D domain_vtimer_init(d)) !=3D 0 ) goto fail; =20 if ( (rc =3D tee_domain_init(d, config->arch.tee_type)) !=3D 0 ) diff --git a/xen/arch/arm/include/asm/time.h b/xen/arch/arm/include/asm/tim= e.h index c194dbb9f5..fd79dd31eb 100644 --- a/xen/arch/arm/include/asm/time.h +++ b/xen/arch/arm/include/asm/time.h @@ -87,10 +87,11 @@ enum timer_ppi }; =20 /* - * Value of "clock-frequency" in the DT timer node if present. - * 0 means the property doesn't exist. + * The timer frequency, in Hz, that Xen ended up using, and whether it came + * from the DT "clock-frequency" property rather than CNTFRQ_EL0. */ -extern uint32_t timer_dt_clock_frequency; +extern uint32_t timer_clock_frequency_hz; +extern bool timer_clock_frequency_from_dt; =20 /* Get one of the timer IRQ number */ unsigned int timer_get_irq(enum timer_ppi ppi); diff --git a/xen/arch/arm/include/asm/vtimer.h b/xen/arch/arm/include/asm/v= timer.h index 9d4fb4c6e8..6bbfcf4e69 100644 --- a/xen/arch/arm/include/asm/vtimer.h +++ b/xen/arch/arm/include/asm/vtimer.h @@ -20,8 +20,7 @@ #ifndef __ARCH_ARM_VTIMER_H__ #define __ARCH_ARM_VTIMER_H__ =20 -extern int domain_vtimer_init(struct domain *d, - struct xen_arch_domainconfig *config); +extern int domain_vtimer_init(struct domain *d); extern int vcpu_vtimer_init(struct vcpu *v); extern bool vtimer_emulate(struct cpu_user_regs *regs, union hsr hsr); extern void virt_timer_save(struct vcpu *v); diff --git a/xen/arch/arm/sysctl.c b/xen/arch/arm/sysctl.c index 8411deb7e2..e22d2fb613 100644 --- a/xen/arch/arm/sysctl.c +++ b/xen/arch/arm/sysctl.c @@ -15,6 +15,7 @@ =20 #include #include +#include #include =20 #include @@ -26,6 +27,10 @@ void arch_do_physinfo(struct xen_sysctl_physinfo *pi) pi->arch_capabilities |=3D MASK_INSR(sve_encode_vl(get_sys_vl_len()), XEN_SYSCTL_PHYSCAP_ARM_SVE_MASK); =20 + pi->arch_clock_frequency_hz =3D timer_clock_frequency_hz; + if ( timer_clock_frequency_from_dt ) + pi->arch_capabilities |=3D XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ; + /* * The GIC version(s) we're happy creating guests with. Right now for * simplicity it is tied to the active hardware version, but this will diff --git a/xen/arch/arm/time.c b/xen/arch/arm/time.c index be54b87438..438a27825d 100644 --- a/xen/arch/arm/time.c +++ b/xen/arch/arm/time.c @@ -35,7 +35,8 @@ uint64_t __read_mostly boot_count; * register-mapped time source in the SoC. */ unsigned long __read_mostly cpu_khz; /* CPU clock frequency in kHz. */ =20 -uint32_t __read_mostly timer_dt_clock_frequency; +uint32_t __read_mostly timer_clock_frequency_hz; +bool __read_mostly timer_clock_frequency_from_dt; =20 static unsigned int timer_irq[MAX_TIMER_PPI]; =20 @@ -120,7 +121,8 @@ static void __init preinit_dt_xen_time(void) { cpu_khz =3D DIV_ROUND(rate, 1000); validate_timer_frequency(); - timer_dt_clock_frequency =3D rate; + timer_clock_frequency_hz =3D rate; + timer_clock_frequency_from_dt =3D true; } } =20 @@ -136,7 +138,8 @@ void __init preinit_xen_time(void) =20 if ( !cpu_khz ) { - cpu_khz =3D DIV_ROUND(READ_SYSREG(CNTFRQ_EL0) & CNTFRQ_MASK, 1000); + timer_clock_frequency_hz =3D READ_SYSREG(CNTFRQ_EL0) & CNTFRQ_MASK; + cpu_khz =3D DIV_ROUND(timer_clock_frequency_hz, 1000); validate_timer_frequency(); } =20 diff --git a/xen/arch/arm/vtimer.c b/xen/arch/arm/vtimer.c index 2e85ff2b6e..18f5676158 100644 --- a/xen/arch/arm/vtimer.c +++ b/xen/arch/arm/vtimer.c @@ -52,7 +52,7 @@ static void virt_timer_expired(void *data) perfc_incr(vtimer_virt_inject); } =20 -int domain_vtimer_init(struct domain *d, struct xen_arch_domainconfig *con= fig) +int domain_vtimer_init(struct domain *d) { d->arch.virt_timer_base.offset =3D get_cycles(); d->arch.virt_timer_base.nanoseconds =3D @@ -60,8 +60,6 @@ int domain_vtimer_init(struct domain *d, struct xen_arch_= domainconfig *config) d->time_offset.seconds =3D d->arch.virt_timer_base.nanoseconds; do_div(d->time_offset.seconds, 1000000000); =20 - config->clock_frequency =3D timer_dt_clock_frequency; - /* * Per the ACPI specification, providing a secure EL1 timer * interrupt is optional and will be ignored by non-secure OS. diff --git a/xen/include/public/arch-arm.h b/xen/include/public/arch-arm.h index 9d3bf11cbd..5d15f572c7 100644 --- a/xen/include/public/arch-arm.h +++ b/xen/include/public/arch-arm.h @@ -335,7 +335,7 @@ DEFINE_XEN_GUEST_HANDLE(vcpu_guest_context_t); #define XEN_DOMCTL_CONFIG_ARM_V8R_EL1_MSA_VMSA 2 =20 struct xen_arch_domainconfig { - /* IN/OUT */ + /* IN */ uint8_t gic_version; /* IN - Contains SVE vector length divided by 128 */ uint8_t sve_vl; @@ -343,20 +343,6 @@ struct xen_arch_domainconfig { uint16_t tee_type; /* IN */ uint32_t nr_spis; - /* - * OUT - * Based on the property clock-frequency in the DT timer node. - * The property may be present when the bootloader/firmware doesn't - * set correctly CNTFRQ which hold the timer frequency. - * - * As it's not possible to trap this register, we have to replicate - * the value in the guest DT. - * - * =3D 0 =3D> property not present - * > 0 =3D> Value of the property - * - */ - uint32_t clock_frequency; /* IN */ uint8_t arm_sci_type; /* IN */ diff --git a/xen/include/public/domctl.h b/xen/include/public/domctl.h index 510300bb67..4ca8a2d7ca 100644 --- a/xen/include/public/domctl.h +++ b/xen/include/public/domctl.h @@ -30,9 +30,9 @@ * fields) don't require a change of the version. * Stable ops are NOT covered by XEN_DOMCTL_INTERFACE_VERSION! * - * Last version bump: Xen 4.22 + * Last version bump: Xen 4.23 */ -#define XEN_DOMCTL_INTERFACE_VERSION 0x00000018 +#define XEN_DOMCTL_INTERFACE_VERSION 0x00000019 =20 /* * NB. xen_domctl.domain is an IN/OUT parameter for this operation. diff --git a/xen/include/public/sysctl.h b/xen/include/public/sysctl.h index d20ebf3644..8356032e13 100644 --- a/xen/include/public/sysctl.h +++ b/xen/include/public/sysctl.h @@ -108,6 +108,8 @@ struct xen_sysctl_tbuf_op { #define XEN_SYSCTL_PHYSCAP_ARM_SVE_MASK (0x1FU) #define XEN_SYSCTL_PHYSCAP_ARM_GIC_V2 (1U << 5) #define XEN_SYSCTL_PHYSCAP_ARM_GIC_V3 (1U << 6) +/* See arch_clock_frequency_hz in struct xen_sysctl_physinfo. */ +#define XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ (1U << 7) #endif =20 struct xen_sysctl_physinfo { @@ -120,7 +122,23 @@ struct xen_sysctl_physinfo { uint32_t cpu_khz; uint32_t capabilities;/* XEN_SYSCTL_PHYSCAP_??? */ uint32_t arch_capabilities;/* XEN_SYSCTL_PHYSCAP_{X86,ARM,...}_??? */ - uint32_t pad; + + /* + * ARM only. The timer frequency, in Hz, that Xen is using, taken eith= er + * from the host DT timer node's "clock-frequency" property or from a + * direct CNTFRQ_EL0 read. + * + * XEN_SYSCTL_PHYSCAP_ARM_TIMER_DT_FREQ is set in the former case. The= host + * DT overrides CNTFRQ_EL0 (the usual way a wrong bootloader/firmware = value + * is corrected), so the toolstack must carry the same override into t= he + * guest's timer node, since CNTFRQ_EL0 cannot be trapped and fixed up= per + * guest. + * + * =3D 0 =3D> Non-ARM. On ARM the frequency is validated at boot and is + * always non-zero. + * > 0 =3D> The frequency, in Hz. + */ + uint32_t arch_clock_frequency_hz; uint64_aligned_t total_pages; uint64_aligned_t free_pages; uint64_aligned_t scrub_pages; --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b6.4d0d4fd336db1aff.1a09082744a.3ae593f4d687c111=--- From nobody Thu Sep 24 20:24:22 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=none dis=none) header.from=vates.tech ARC-Seal: i=1; a=rsa-sha256; t=1789130916; cv=none; d=zohomail.com; s=zohoarc; b=azs5hz1RHY+0YP6dw29pKkdtafbUkw/fTQCjLIUfH+ThPJDp+77dFP9g47p0pBX+yRSBdb2m4WYs82y0mOv06v0tZ5J8Fjuv8V61KA8uSusbACr6w+07uJ3dW3rg6bXHHWStI93dpyYgmp5ZkBGH8L6zxCA8T0i3MXOzeYHwhQo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789130916; h=Content-Type:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=bwq3tKReeS3EIzOUNkZD7o9vflbF8tf5tTJBaX+CqXY=; b=h0dSOh+cF99zY3EWiQEFAhxJqpDgFNHH7QCatZL/0TLinsag1F0RC0MSvyaLirb3kxR1JYeHNTJxTdGjETHiMRRzk31rwyv7bZhUTyI9HXffcZQ+d0+NShlq/2eUSBc2hy9D2rY5/h7tJ+6V9mopk4ueUxk4EHKapo92nQQxPao= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1789130916761209.00873754142356; Fri, 11 Sep 2026 05:48:36 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1416573.1645576 (Exim 4.92) (envelope-from ) id 1x50fy-00066g-GL; Fri, 11 Sep 2026 12:48:18 +0000 Received: by outflank-mailman (output) from mailman id 1416573.1645576; Fri, 11 Sep 2026 12:48:18 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fy-00066V-D3; Fri, 11 Sep 2026 12:48:18 +0000 Received: by outflank-mailman (input) for mailman id 1416573; Fri, 11 Sep 2026 12:48:16 +0000 Received: from mx.expurgate.net ([195.190.135.10]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x50fw-0005yo-MI for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 12:48:16 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x50fw-009G6I-36 for xen-devel@lists.xenproject.org; Fri, 11 Sep 2026 14:48:16 +0200 Received: from [10.42.69.5] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6aa3f888-2eae-0a2a0a5409dd-0a2a4505d40a-36 for ; Fri, 11 Sep 2026 14:48:16 +0200 Received: from [185.255.28.18] (helo=prod-mta-13.swg-srv.net) by tlsNG-c201ff.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6aa3f88f-4cb1-0a2a45050019-b9ff1c128ed1-3 for ; Fri, 11 Sep 2026 14:48:15 +0200 Received: from mail2.vates.fr ([37.26.189.201] mail2.vates.fr) (Authenticated sender: 8631fc262581453bbf619ec5b2062170/smtp/7773de5a-2839-4720-82ee-e06722ae1d3e) by prod-mta-13.swg-srv.net (ZoneMTA - prod-mta-13) with ESMTPSA id 1a0908277f6000c4f3.00a for (version=TLSv1.3 cipher=TLS_AES_256_GCM_SHA384); Fri, 11 Sep 2026 12:47:44 +0000 Received: from julian.home (areims-651-1-80-194.w90-18.abo.wanadoo.fr [90.18.187.194]) (Authenticated sender: julian.vetter@vates.tech) by mail2.vates.fr (Postfix) with ESMTPSA id C669A81CED; Fri, 11 Sep 2026 14:47:43 +0200 (CEST) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:Cc:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vates.tech; q=dns/txt; s=selector1; bh=bwq3tKReeS3EIzOUNkZD7o9vflbF8tf5tTJBaX+CqXY=; h=from:subject:date:message-id:to:cc:mime-version:content-type:in-reply-to:references:feedback-id; b=DofaliK4R8+ApxDtPfcvuHykChD8FlPngblcUTorVBQd0XPjxllHqSy506QrCXcv3Psfuy7Wx UzmFK2M+L6iujE/BcaGJI/4xLmExuqzDdZlf8u3kMa25T2m973SIVTNyYMjY9YUUGi21+EVjrO6 RiGtH7gVPxHCmRYeXap2vJxr91Q2TkonpZkgQp5cEC32BvEDSqlFeA+JWjMQPsveGultVyenr8/ XX5YnI1IKpSjWvja+ddGnnj1RE8ELXe0lHwa7NUZwGxhSyu/izECHOjbHQ0DIWMgzmJWAZri4vD nPPfTaBuNFMPU8LWYHsxpdMN7IjwTFaDMCDbsfqiFtNA== X-Zone-Loop: 84019aec531728e8ea85ba7fa79d01b9f6bf84d68e54 x-campaign-type: default x-transaction-id: b35b5ddd-a065-43ec-80ad-b498bd300587 x-swg-uid: 01-00ba8ebd-f8fe-40ec-9058-7e1b054c491c X-Mailer: Sweego Message-ID: <1789130864.8631fc262581453bbf619ec5b2062170.1a0908277f6000c4f3@vates.tech> x-swg-bid: 1789130864.8631fc262581453bbf619ec5b2062170.1a0908277f6000c4f3 Feedback-ID: default:8631fc262581453bbf619ec5b2062170:Sweego x-campaign-id: default x-client-id: 8631fc262581453bbf619ec5b2062170 X-Originating-IP: [37.26.189.201] From: Julian Vetter To: xen-devel@lists.xenproject.org Cc: Oleksii Kurochko , Community Manager , Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Juergen Gross , Andrii Sultanov , Guillaume Thouvenin , =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Bertrand Marquis , Volodymyr Babchuk , Oleksii Moisieiev , Timothy Pearson , Alistair Francis , Connor Davis , Teddy Astie , Julian Vetter Subject: [PATCH v5 6/6] xen: make config argument const Date: Fri, 11 Sep 2026 14:47:36 +0200 In-Reply-To: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> References: <1789130592.8631fc262581453bbf619ec5b2062170.1a0907e5286000c4f3@vates.tech> MIME-Version: 1.0 X-BM-Disclaimer: Yes Content-Type: multipart/alternative; boundary="-=Part.b7.9cd30c3973d2ad73.1a0908275f8.bc0c5a2802185582=-" X-Bm-Milter-Handled: 4ffbd6c1-ee69-4e1b-aabd-f977039bd3e2 X-Bm-Transport-Timestamp: 1789130864120 X-purgate-ID: tlsNG-c201ff/1789130896-734BC2A1-F9E6E16B/0/0 X-purgate-type: clean X-purgate-size: 8311 X-ZohoMail-DKIM: pass (identity @vates.tech) X-ZM-MESSAGEID: 1789130919111158500 ---=Part.b7.9cd30c3973d2ad73.1a0908275f8.bc0c5a2802185582=- Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" arch_sanitise_domain_config() validates the configuration requested by the toolstack, and should not fill anything in. The config struct passed to createdomain is supposed to be pure input. ARM used to abuse this (GIC_NATIVE resolution, now removed) to smuggle output back to the toolstack. Making the parameter const stops that type of abuse from happening on any architecture. The x86 implementation turned out to have its own instance of the same issue. It set XEN_DOMCTL_CDF_oos_off into config->flags for non-HVM guests. Since The sanitisation runs before the function domain_create() copies config->flags into d->options, this relied on mutating the toolstack's config to take effect. Move the default onto d->options directly in arch_domain_create() (which runs after d->options is populated), where all the remaining domain options are resolved. This has the same effect and no mutation of the input config is required. ARM, PPC and RISC-V need no equivalent change, Their implementations were already read-only. Signed-off-by: Julian Vetter Reviewed-by: Jan Beulich # x86 Reviewed-by: Michal Orzel --- Changes in v5: - No changes. --- xen/arch/arm/domain.c | 2 +- xen/arch/arm/firmware/sci.c | 2 +- xen/arch/arm/firmware/scmi-smc.c | 2 +- xen/arch/arm/include/asm/firmware/sci.h | 6 +++--- xen/arch/ppc/stubs.c | 2 +- xen/arch/riscv/domain.c | 2 +- xen/arch/x86/domain.c | 16 ++++++++-------- xen/include/xen/sched.h | 5 ++--- 8 files changed, 18 insertions(+), 19 deletions(-) diff --git a/xen/arch/arm/domain.c b/xen/arch/arm/domain.c index d4037c402a..3299727d3a 100644 --- a/xen/arch/arm/domain.c +++ b/xen/arch/arm/domain.c @@ -557,7 +557,7 @@ static bool v8r_el1_msa_domain_sanitise_config( } } =20 -int arch_sanitise_domain_config(struct xen_domctl_createdomain *config) +int arch_sanitise_domain_config(const struct xen_domctl_createdomain *conf= ig) { unsigned int max_vcpus; unsigned int flags_required =3D (XEN_DOMCTL_CDF_hvm | XEN_DOMCTL_CDF_h= ap); diff --git a/xen/arch/arm/firmware/sci.c b/xen/arch/arm/firmware/sci.c index aa93cda7f0..f73ed06092 100644 --- a/xen/arch/arm/firmware/sci.c +++ b/xen/arch/arm/firmware/sci.c @@ -45,7 +45,7 @@ int sci_domain_init(struct domain *d, struct xen_domctl_c= reatedomain *config) return cur_mediator->domain_init(d, config); } =20 -int sci_domain_sanitise_config(struct xen_domctl_createdomain *config) +int sci_domain_sanitise_config(const struct xen_domctl_createdomain *confi= g) { if ( !cur_mediator ) return 0; diff --git a/xen/arch/arm/firmware/scmi-smc.c b/xen/arch/arm/firmware/scmi-= smc.c index a0cc6c6192..391df8b945 100644 --- a/xen/arch/arm/firmware/scmi-smc.c +++ b/xen/arch/arm/firmware/scmi-smc.c @@ -68,7 +68,7 @@ static bool scmi_handle_smc(struct cpu_user_regs *regs) } =20 static int -scmi_smc_domain_sanitise_config(struct xen_domctl_createdomain *config) +scmi_smc_domain_sanitise_config(const struct xen_domctl_createdomain *conf= ig) { if ( config->arch.arm_sci_type !=3D XEN_DOMCTL_CONFIG_ARM_SCI_NONE && config->arch.arm_sci_type !=3D XEN_DOMCTL_CONFIG_ARM_SCI_SCMI_SMC= ) diff --git a/xen/arch/arm/include/asm/firmware/sci.h b/xen/arch/arm/include= /asm/firmware/sci.h index 485ce211c9..1d566be8e2 100644 --- a/xen/arch/arm/include/asm/firmware/sci.h +++ b/xen/arch/arm/include/asm/firmware/sci.h @@ -32,7 +32,7 @@ struct sci_mediator_ops { * it to sanitize domain SCI configuration parameters. * Optional. */ - int (*domain_sanitise_config)(struct xen_domctl_createdomain *config); + int (*domain_sanitise_config)(const struct xen_domctl_createdomain *co= nfig); =20 /* * Called during domain destruction, releases all resources, that @@ -101,7 +101,7 @@ int sci_domain_init(struct domain *d, struct xen_domctl= _createdomain *config); * Sanitise domain configuration parameters. * */ -int sci_domain_sanitise_config(struct xen_domctl_createdomain *config); +int sci_domain_sanitise_config(const struct xen_domctl_createdomain *confi= g); =20 /* * Destroy SCI domain instance. @@ -162,7 +162,7 @@ static inline int sci_domain_init(struct domain *d, } =20 static inline int -sci_domain_sanitise_config(struct xen_domctl_createdomain *config) +sci_domain_sanitise_config(const struct xen_domctl_createdomain *config) { if ( config->arch.arm_sci_type !=3D XEN_DOMCTL_CONFIG_ARM_SCI_NONE ) return -EINVAL; diff --git a/xen/arch/ppc/stubs.c b/xen/arch/ppc/stubs.c index a333f06119..82a289af85 100644 --- a/xen/arch/ppc/stubs.c +++ b/xen/arch/ppc/stubs.c @@ -162,7 +162,7 @@ void arch_vcpu_destroy(struct vcpu *v) BUG_ON("unimplemented"); } =20 -int arch_sanitise_domain_config(struct xen_domctl_createdomain *config) +int arch_sanitise_domain_config(const struct xen_domctl_createdomain *conf= ig) { BUG_ON("unimplemented"); } diff --git a/xen/arch/riscv/domain.c b/xen/arch/riscv/domain.c index 2819ff4e7c..e096a53cb5 100644 --- a/xen/arch/riscv/domain.c +++ b/xen/arch/riscv/domain.c @@ -289,7 +289,7 @@ void sync_vcpu_execstate(struct vcpu *v) /* Nothing to do -- no lazy switching */ } =20 -int arch_sanitise_domain_config(struct xen_domctl_createdomain *config) +int arch_sanitise_domain_config(const struct xen_domctl_createdomain *conf= ig) { return 0; } diff --git a/xen/arch/x86/domain.c b/xen/arch/x86/domain.c index 996b50af7a..0ddddb1024 100644 --- a/xen/arch/x86/domain.c +++ b/xen/arch/x86/domain.c @@ -590,7 +590,7 @@ void arch_vcpu_destroy(struct vcpu *v) ASSERT_UNREACHABLE(); } =20 -int arch_sanitise_domain_config(struct xen_domctl_createdomain *config) +int arch_sanitise_domain_config(const struct xen_domctl_createdomain *conf= ig) { bool hvm =3D config->flags & XEN_DOMCTL_CDF_hvm; bool hap =3D config->flags & XEN_DOMCTL_CDF_hap; @@ -633,13 +633,6 @@ int arch_sanitise_domain_config(struct xen_domctl_crea= tedomain *config) return -EINVAL; } =20 - if ( !hvm ) - /* - * It is only meaningful for XEN_DOMCTL_CDF_oos_off to be clear - * for HVM guests. - */ - config->flags |=3D XEN_DOMCTL_CDF_oos_off; - if ( nested_virt && !hvm_nested_virt_supported() ) { dprintk(XENLOG_INFO, "Nested virt requested but not available\n"); @@ -833,6 +826,13 @@ int arch_domain_create(struct domain *d, =20 spin_lock_init(&d->arch.e820_lock); =20 + /* + * It is only meaningful for XEN_DOMCTL_CDF_oos_off to be clear for HVM + * guests. + */ + if ( !is_hvm_domain(d) ) + d->options |=3D XEN_DOMCTL_CDF_oos_off; + if ( d->domain_id && cpu_has_amd_erratum(&boot_cpu_data, AMD_ERRATUM_1= 21) ) { if ( !opt_allow_unsafe ) diff --git a/xen/include/xen/sched.h b/xen/include/xen/sched.h index e352e2b38e..da80aa63ff 100644 --- a/xen/include/xen/sched.h +++ b/xen/include/xen/sched.h @@ -770,10 +770,9 @@ static inline void domain_update_node_affinity(struct = domain *d) } =20 /* - * To be implemented by each architecture, sanity checking the configurati= on - * and filling in any appropriate defaults. + * To be implemented by each architecture, sanity checking the configurati= on. */ -int arch_sanitise_domain_config(struct xen_domctl_createdomain *config); +int arch_sanitise_domain_config(const struct xen_domctl_createdomain *conf= ig); =20 /* * Create a domain: the configuration is only necessary for real domain --=20 2.53.0 --=20 Julian Vetter | Vates Hypervisor & Kernel Developer XCP-ng & Xen Orchestra - Vates solutions web: https://vates.tech ---=Part.b7.9cd30c3973d2ad73.1a0908275f8.bc0c5a2802185582=---