From nobody Fri Oct 2 11:42:33 2026 Received: from mail-wm1-f52.google.com (mail-wm1-f52.google.com [209.85.128.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0B32630CD89 for ; Sat, 1 Aug 2026 15:37:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785598663; cv=none; b=MKRRIxNrxRPLV26HHIxwWgcKuEsvPvuR8h9B8grZgD1+hX8qJ0OFRWQpIJzCJ6fHbTjZDYHzxtRVe0bKO+hb2bjW7c95rGMWSO1dvllpDDjCQnFgCp2SpvxPiOOLqC1dm1likyz+t1rPlJG3KAWQIAqmFEQAF/6oVcINSHTFsWM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785598663; c=relaxed/simple; bh=HJIn6ArNToUyryFG1+tm+1I7IC6zVMv0l1gSzPCFxrg=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=d/aZ7sBYy4H9cnM+tumJAjOYT5N8pnvRuelv+2SUsKPtvq4YsSNlP4FYBNTWnE/SGV+Kgd1r4t/0lSDqfONqc6wOTdbnfYxAlH1POkqH85Lzgr1V1CmpX+bJ+62dLv2nNqPj+hiqtiV9ktZ26b0qnW16zSO7ogYSOiZtsMRiTEg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=W1iOVsfI; arc=none smtp.client-ip=209.85.128.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="W1iOVsfI" Received: by mail-wm1-f52.google.com with SMTP id 5b1f17b1804b1-4954aff6088so5597415e9.3 for ; Sat, 01 Aug 2026 08:37:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785598659; x=1786203459; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=u7Hwn0xlTzxIN2uBpUzcPzgILfRygUZswZJisr8yQeU=; b=W1iOVsfIHGr8Fmf6fwi6f2Xz4MmCG0/3jUqF9F4sbcYYWraUh2uY4PiQtWuECHWzn8 zisapsT3Si60IAjSsOk2n4o4Rz8kW7wUChUAhOMjnhyvMzQPwPXCSTUXyWlfs4mYsHrk BWYd8q7odCzYI+TOvp1Liy+jSk7UfW5Cb3bck56uUjg9WQecg9Yx6cGkqgUomuDiz2BR XUULPyxWtXMLDunkuPFvDCBXtXwCUY30GuYWSe6pMaXKIjRcpZY1AmlSvktQgCSXnK8W XWfK2p7TKggA5ebU43Y/GHW9j9UN1yrxNS5TInKtIeDF1KF/ma89fwhJ1qQbRZuX6rzY T2lA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785598659; x=1786203459; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=u7Hwn0xlTzxIN2uBpUzcPzgILfRygUZswZJisr8yQeU=; b=TdLtB+VaE9sIXLRd3XEaWUBB2jE3u3k5sJbvo6OgWRlcbnPdIZ7cfcq5zWu4C5GX7R Yp9g912VE2jJHLwqLV3nTie9CDSUTG8+5wFuSL3yyIlcBY/viZFVWFqz2eKHcUAWubG3 GkiopoAVbM7dzHJErdrXo6kt8StuF9USqvdgRX5DGmdZofp69z2XIsJAwp7I4uLF2WE8 Sr59qplYPd2fzTYn+uTckkyTB/F+/2LDEg1zQP9/vYIQMK/aZDRHCTkbNlFjNjGxbH1M khNqrysj6Cz4bzM1AJTXumvIgVE4nuJESKLOpSoVJkRZ29UdYTkNQu80zijQD2zlVI0Y /FlQ== X-Forwarded-Encrypted: i=1; AHgh+Roy1RxzFWiA0OBYax9+Gzl7XiNexVlqG8KF3UL6zbKd7l6IHxQ2tqdrj2s/C2RboCo3vkEBotRPMKKmTIw=@vger.kernel.org X-Gm-Message-State: AOJu0YzbkxPIdi8EyTSGkKZxHvk8V7jM+VgfXIkimD8fl7IN+Nii0p5a VqnHve+8drtiGdsnlfn2GAwdPxtLqZvNfMAZ4NfHTIwRSZADGf4w6uos X-Gm-Gg: AR+sD13kLnnHL92Qmjdh9+Q1wlEKRvJQxyth+uSS0TRw9WG0tmFbtzMhf+hyHvfhSKC wQvBp/qmAWtV0dHP32+f1inbn3GZhiOm8NCs0Gm9o51XXToCCnchjuiFbdwn5sec/LBK7Ah7jGl sDE3L6jTekp+okWf8mVFznoOowoUI6H7rt1eLVKA6Jm/48GEPSVMaJv75ifSSbZ/xj57phx58Ys ygKbEgZu9mAqcOoEoA6lA3lBEBhI/MwUiBqj6hD0FCPTkFoPQtLwv4hXujeFxPj3x3NcJBEcwdT uv1BZaug1shG2buJ8+LsBGGOj+ri5f+rcCUFeBmJSv+I2wFGcP54EdIACb8trsKvcdlXY+xZcbd xw+sB+qX1YI3ZaXVvPos59XizyRzuIyOmo2EpxBvuvoJ45H1wCizYh04ehT7Zn38xeFh6/VzXuC PhHTa0UvHrSioXmznJoo91NWepSOkm0HQ/UUuIUunu4AKVfGUibfUn+lmk4PurFaKW54xei1oQj XDKi57ZE+YcGhnUzumudOTvq6XqlWJjFQ6csZwpPMLS/uYWEJLfCqCsL4o6z71GHTk3nCoUu1Fi +tty3j5Hmk1mwYwIzqH27CT85A== X-Received: by 2002:a05:600c:871a:b0:498:952:e276 with SMTP id 5b1f17b1804b1-4980c66c991mr73253905e9.8.1785598658895; Sat, 01 Aug 2026 08:37:38 -0700 (PDT) Received: from localhost.localdomain (dynamic-095-114-005-130.95.114.pool.telefonica.de. [95.114.5.130]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b67529sm65115055e9.8.2026.08.01.08.37.37 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 01 Aug 2026 08:37:38 -0700 (PDT) From: Karl Mehltretter To: Marc Zyngier , Oliver Upton Cc: Karl Mehltretter , Suzuki K Poulose , Catalin Marinas , Will Deacon , Andre Przywara , linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH] KVM: arm64: Preserve AArch32 CP64 registers on rejected reads Date: Sat, 1 Aug 2026 17:36:16 +0200 Message-Id: <20260801153616.71960-1-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" kvm_handle_cp_64() only seeds params.regval for writes. If a CP64 read is decoded but rejected, emulate_cp() still returns handled and the caller writes params.regval back to Rt/Rt2. This can happen for write-only GIC SGI registers and for rejected PMU counter reads. In both cases KVM injects an UNDEF into the guest, so the MRRC destination registers must remain unchanged. Instead, the uninitialised regval is copied into the guest registers. With stack auto-initialisation this is a deterministic zero or pattern value. With CONFIG_INIT_STACK_NONE it may be stale host stack data. Match kvm_handle_cp_32() and kvm_handle_sys_reg() by seeding regval from the destination registers before emulation. Fixes: 6d52f35af10c ("arm64: KVM: add SGI generation register emulation") Assisted-by: Claude:claude-opus-5 Signed-off-by: Karl Mehltretter --- Runtime tested on a Raspberry Pi 400 with a minimal KVM harness running an AArch32 guest. On the unpatched 6.1.21-v8+ vendor kernel, the PMCCNTR MRRC test took UNDEF with r0=3D0x00000001/r1=3D0x00000000 instead of the guest's sentinel values. With this patch on v7.2-rc3-278-g38436106b2f5, the same test preserved r0=3D0x12345678/r1=3D0x9abcdef0. --- a/arch/arm64/kvm/sys_regs.c +++ b/arch/arm64/kvm/sys_regs.c @@ -4860,11 +4860,11 @@ /* * Make a 64-bit value out of Rt and Rt2. As we use the same trap * backends between AArch32 and AArch64, we get away with it. + * + * This also makes rejected reads preserve Rt/Rt2. */ - if (params.is_write) { - params.regval =3D vcpu_get_reg(vcpu, Rt) & 0xffffffff; - params.regval |=3D vcpu_get_reg(vcpu, Rt2) << 32; - } + params.regval =3D vcpu_get_reg(vcpu, Rt) & 0xffffffff; + params.regval |=3D vcpu_get_reg(vcpu, Rt2) << 32; =20 /* * If the table contains a handler, handle the --=20 2.51.0