[PATCH v2] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context.

D Scott Phillips posted 1 patch 1 week, 3 days ago
Documentation/arch/arm64/silicon-errata.rst | 4 ++++
arch/arm64/kvm/vgic/vgic-v3.c               | 8 +++++++-
2 files changed, 11 insertions(+), 1 deletion(-)
[PATCH v2] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context.
Posted by D Scott Phillips 1 week, 3 days ago
In the nested state, the physical interrupt has already been
deactivated through the HW bit in the LR. The extra deactivation
would be harmless but can hit an errata case on AmpereOne, so
avoid it here.

On AmpereOne, deactivating a physical interrupt through
ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
active, but is the highest priority pending interrupt causes the
cpu to lose the interrupt pending state and also prevents the
delivery of future interrupts.

Fixes: 6dd333c8942b2 ("KVM: arm64: GICv3: nv: Plug L1 LR sync into deactivation primitive")
Signed-off-by: D Scott Phillips <scott@os.amperecomputing.com>
Cc: stable@vger.kernel.org
---
Link to v1: https://lore.kernel.org/linux-arm-kernel/20260710222128.416581-1-scott@os.amperecomputing.com/
Changes since v1:
 - Drop erratum cpucap
 - Add comment about errata at change
 - Update commit message with description from Marc, add Fixes:

 Documentation/arch/arm64/silicon-errata.rst | 4 ++++
 arch/arm64/kvm/vgic/vgic-v3.c               | 8 +++++++-
 2 files changed, 11 insertions(+), 1 deletion(-)

diff --git a/Documentation/arch/arm64/silicon-errata.rst b/Documentation/arch/arm64/silicon-errata.rst
index 014aa1c215a16..88b4aa45a2066 100644
--- a/Documentation/arch/arm64/silicon-errata.rst
+++ b/Documentation/arch/arm64/silicon-errata.rst
@@ -55,10 +55,14 @@ stable kernels.
 +----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne       | AC03_CPU_38     | AMPERE_ERRATUM_AC03_CPU_38  |
 +----------------+-----------------+-----------------+-----------------------------+
+| Ampere         | AmpereOne       | AC03_CPU_57     | N/A                         |
++----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne AC04  | AC04_CPU_10     | AMPERE_ERRATUM_AC03_CPU_38  |
 +----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne AC04  | AC04_CPU_23     | AMPERE_ERRATUM_AC04_CPU_23  |
 +----------------+-----------------+-----------------+-----------------------------+
+| Ampere         | AmpereOne AC04  | AC04_CPU_29     | N/A                         |
++----------------+-----------------+-----------------+-----------------------------+
 +----------------+-----------------+-----------------+-----------------------------+
 | ARM            | Cortex-A510     | #2457168        | ARM64_ERRATUM_2457168       |
 +----------------+-----------------+-----------------+-----------------------------+
diff --git a/arch/arm64/kvm/vgic/vgic-v3.c b/arch/arm64/kvm/vgic/vgic-v3.c
index 9e841e7afd4a7..7aa417440f6a2 100644
--- a/arch/arm64/kvm/vgic/vgic-v3.c
+++ b/arch/arm64/kvm/vgic/vgic-v3.c
@@ -275,7 +275,13 @@ void vgic_v3_deactivate(struct kvm_vcpu *vcpu, u64 val)
 		lr = vgic_v3_compute_lr(vcpu, irq) & ~ICH_LR_ACTIVE_BIT;
 	}
 
-	if (lr & ICH_LR_HW)
+	/*
+	 * In the nested state, the irq has already been deactivated via the HW
+	 * bit in the LR. Deactivating again would be harmless except AmpereOne
+	 * errata AC03_CPU_57, AC04_CPU_29 could cause irq delivery to break if
+	 * the deactivation hits the highest priority pending irq.
+	 */
+	if ((lr & ICH_LR_HW) && !vgic_state_is_nested(vcpu))
 		vgic_v3_deactivate_phys(FIELD_GET(ICH_LR_PHYS_ID_MASK, lr));
 
 	vgic_v3_fold_lr(vcpu, lr);
-- 
2.55.0
Re: [PATCH v2] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context.
Posted by Marc Zyngier 2 days, 2 hours ago
On Tue, 14 Jul 2026 16:11:58 -0700, D Scott Phillips wrote:
> In the nested state, the physical interrupt has already been
> deactivated through the HW bit in the LR. The extra deactivation
> would be harmless but can hit an errata case on AmpereOne, so
> avoid it here.
> 
> On AmpereOne, deactivating a physical interrupt through
> ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
> active, but is the highest priority pending interrupt causes the
> cpu to lose the interrupt pending state and also prevents the
> delivery of future interrupts.
> 
> [...]

Applied to fixes, thanks!

[1/1] KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context.
      commit: 8a570b19b4b16a8a3b5ffa2b332bd5613110b2d8

Cheers,

	M.
-- 
Without deviation from the norm, progress is not possible.