From nobody Fri Oct 2 10:08:01 2026 Received: from mail-wm1-f50.google.com (mail-wm1-f50.google.com [209.85.128.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A2BE22F8EB7 for ; Sun, 2 Aug 2026 18:22:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.50 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785694951; cv=none; b=Phq8UqogXj+bOyCtfj6OOlZH69Lsz0XfmX887pwNNiU5LhBg8NsMedkLZH3zqy6braMYfK342kkvCIcDJw5jZKcCAd2Pc45hhgBgIQwIkDY0Ez0L3L3ZrevzDxRMvBH7aLdC3ROP6PMVD/cldnJCoJUXS9CsohnMIEfjo1MYbsE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785694951; c=relaxed/simple; bh=L/4yfN0r7nIB8kAjf781EJfIlqPTgPdAq2Eibjb6hDg=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=rUiAATC1zyL47yXmrSvquHgr7R6HpdcdkQ1fqPzheCdP59aguJZki9nb9JCLNl99638SzfcU47xPuVSYOAbMnIlEKYz4WgYrflqm3BbwsON5UBn3frVLXW0AhdlK0JCfMm/s39NBh82r5zSJgKI21s0gAiwHVPyY4Ke2E5UM8aw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=d+8yBPJl; arc=none smtp.client-ip=209.85.128.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="d+8yBPJl" Received: by mail-wm1-f50.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso11189555e9.3 for ; Sun, 02 Aug 2026 11:22:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785694948; x=1786299748; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=pLz8CqUuxfuhpUaYrzuwzfN7xMtH1IZWfv3SLyQlY8s=; b=d+8yBPJlKQQCIPvd5DS/OCV3o8Kc4nQSRLQQG2h9gX86uyj+BzxqS9cNug2Hsl3wKN xgP21VIA7QNk8oVsRq+veKfHBoROoLkQbwdv6ZD7dyTW3GbBdwr1rYaOmQXankmQu3CF FiKNG3khXRS1D69YLJyAZSnfjoSEgneOVAaJUSkXQk4Ue4ZOfGoiQa9usJjDtghEH/ZZ Ce4bgrHUcXDJ9gRvw9KIU8k9KSv89ueAPDNoXs+poZDGjQAbS/9hkJ4bSOYk47/MOWgn PngLgIHTdzh85zYw1lu3C7pqVIH+wC/cY3Jt4R7PS9zrwRcfhlAqNcC8F/Ok7Z6+YAgm Co4A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785694948; x=1786299748; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pLz8CqUuxfuhpUaYrzuwzfN7xMtH1IZWfv3SLyQlY8s=; b=tTu/MyWcUUbpjvbcI6+CnSyhJ2WZp49zMXv6jQy64PvdmPl6OEpi77FeC/gTKszqGj GcLRhZLVRvEw0e7mxVcEMUxzfxY7Wti3AV0UysURdO2LynKz5tnDvYBLAPJ3Hc6T28rG LZAL7dq6AYaCazc9i7NHs39/JO19RTQ7vGRF2/ySsxZN5HcPOKWsiX+9CmHBxZWxwnk9 +gRZozdaLxjcRCYNsTKq7gOWXFfXYenCFoQhwvZwKj+w2dHua3tfe8Z0L30lr0AbjeK5 d0j95C6t7Rj2Rn8VX41OlB5NqxxTp+OzmOjOXszbRTjqrB30cVTzyKcMqlSS9yX/wiAN HXEw== X-Forwarded-Encrypted: i=1; AHgh+RpPCmN8dBz1+VDvFuEmwAZN/NcRHv1/bOj3WrjFa92ibacznXVZ7FKA8M2n/yXAS/vHczOH9HX56W0/Fl8=@vger.kernel.org X-Gm-Message-State: AOJu0YyNBSzpqWKiD1Dhdpk8XYYV/4UMwQBAJGPKFBmE82PxuhYi+lAg 8r2eGBl+i3K2yMcIiJYynrkV1dxapabXjwkd5sFBRvRUh+E2QAkuQsD3FnyDQ5f/ X-Gm-Gg: AR+sD12g3/065iUU6NqWeGJV/DhcnGVZzpt4a5mfM0TZIdG4i8UpfoooOJUcZAjikib 1h6akEC+B2hYkLivE37167/IxGPPY0kX6qspx0YxTBRtG3TTTuvjtArEPrRuo74MfNQ5U9ljdKu crnRg/k4M9T2U3bZXcYLQBflNnxkTpfaQvQiekcuQkfmsaPNI9k//RUASbWjXdududp45mbVC+g cyApjJ2C2xpoEQE8qoFTH+DnxsdTmjxeo/8BUQzZUYOApCoKfqSqk1QrNuN+Pooecr2P8c68vc5 10gy8HO69X46Ksi1hm4lNql6GqwpfEOBqSFk8xe73giiSi5P0g7BcqoNdA+oNXEFPpmlMLaSzpD jz56Zub9nPeJ7fumL9Fm1mj8U59P0leir5xWJgbIDurQTQYQU6t7IZAyP3eSe7XA6j7gbOZBr6K jZQ3R+6zf8R/wea00lTJCZpHLDbXZ5BSrbq28ETgvag7yAIRyeClukw2+nzskQLbmy7IFe9BiSd vo40bXEmEoxZxjBtX5nx9v8vhTDS+1GBhU9lsy5V3OPXi3o6W7JhneC+VVYr7JP5uA3CLLz2el/ dVYYeR00/4ucOh8gGdyRuUtvGdKDcEa/HuxBJ0rVB9VcLpu2KNCX7lQxZM/BBVdU3ZCWgpdB3hu Thw== X-Received: by 2002:a05:600c:354a:b0:495:4e89:3f30 with SMTP id 5b1f17b1804b1-4980c673874mr155891915e9.15.1785694947549; Sun, 02 Aug 2026 11:22:27 -0700 (PDT) Received: from MBP-von-Karl.localdomain (dynamic-2a02-3100-ac60-3101-f9d3-c495-76bf-b296.310.pool.telefonica.de. [2a02:3100:ac60:3101:f9d3:c495:76bf:b296]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807ba13e9sm234230405e9.13.2026.08.02.11.22.25 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 02 Aug 2026 11:22:26 -0700 (PDT) From: Karl Mehltretter To: Marc Zyngier , Oliver Upton Cc: Karl Mehltretter , Suzuki K Poulose , Catalin Marinas , Will Deacon , Andre Przywara , linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH v2] KVM: arm64: Preserve GPRs for AArch32 CP64 reads generating an UNDEF Date: Sun, 2 Aug 2026 20:22:22 +0200 Message-Id: <20260802182222.2239-1-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" kvm_handle_cp_64() only seeds params.regval for writes. If a CP64 read is decoded but UNDEFs, emulate_cp() still returns handled and the caller writes params.regval back to Rt/Rt2. This can happen for PMU counter read accesses generating an UNDEF. KVM injects the exception into the guest, so the MRRC GPRs must remain unchanged. Instead, the uninitialised regval is copied into the guest GPRs. With stack auto-initialisation this is a deterministic zero or pattern value. With CONFIG_INIT_STACK_NONE it may be stale host stack data. Match kvm_handle_cp_32() and kvm_handle_sys_reg() by seeding regval from the GPRs before emulation. Fixes: 62a89c44954f0 ("arm64: KVM: 32bit handling of coprocessor traps") Assisted-by: Claude:claude-opus-5 Signed-off-by: Karl Mehltretter Reviewed-by: Marc Zyngier --- Runtime tested on a Raspberry Pi 400 with a minimal KVM harness running an AArch32 guest. On the unpatched 6.1.21-v8+ vendor kernel, the PMCCNTR MRRC test took UNDEF with r0=3D0x00000001/r1=3D0x00000000 instead of the guest's sentinel values. With this patch on v7.2-rc3-278-g38436106b2f5, the same test preserved r0=3D0x12345678/r1=3D0x9abcdef0. Changes in v2: - Rework the commit message to use correct terminology, omit the unreachable GIC example, fix the Fixes tag and drop the added comment in the source code (Marc Zyngier). Link to v1: https://lore.kernel.org/r/20260801153616.71960-1-kmehltretter@g= mail.com --- a/arch/arm64/kvm/sys_regs.c +++ b/arch/arm64/kvm/sys_regs.c @@ -4860,11 +4860,9 @@ /* * Make a 64-bit value out of Rt and Rt2. As we use the same trap * backends between AArch32 and AArch64, we get away with it. */ - if (params.is_write) { - params.regval =3D vcpu_get_reg(vcpu, Rt) & 0xffffffff; - params.regval |=3D vcpu_get_reg(vcpu, Rt2) << 32; - } + params.regval =3D vcpu_get_reg(vcpu, Rt) & 0xffffffff; + params.regval |=3D vcpu_get_reg(vcpu, Rt2) << 32; =20 /* * If the table contains a handler, handle the --=20 2.51.0