From nobody Tue Sep 29 13:19:19 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 60DD2274641; Fri, 7 Aug 2026 17:25:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123518; cv=none; b=lA2qFDFSe9xBcYnoNsjp0BMVceWt26iAX2CpjI9NKYGp2ntYUzGziOYhQC/TuwsqnY9SZQDBlwka18LdJ3N8vyw+Vh/3WYF4ePSDvoao2I4Ajq6dRtqjF71280zLKWAuULJXPxrIHE0rMAurROXRvz2GhUS0yaFl6+uBPXsnDPw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123518; c=relaxed/simple; bh=hVPjohWCWcjBwKb9wuXF3Mm1CkRm974eDc4eHr9djKo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Pe//kxvyWvHLFt/g2x2SOAqqbvUC03pb07Rjr96bkGRSCQiADyV7G8o24s00OenP/fJFotAFQuT2L5I6z0THQwrR7E9f6RkM9imt6NIKu+20UZKEINXMBdbwhsVD7/SCIKw5XjrKPgqoTo72OjE9iTFuDzF8cu0a60BOBrcUQ9E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=DZW1L+n6; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="DZW1L+n6" Received: from pps.filterd (m0356516.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677GlsjJ1937437; Fri, 7 Aug 2026 17:24:53 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=POGGW7D4HqvqqWOHZ qJMmbMxinU2dGjKXW6RNdKVNs0=; b=DZW1L+n6W0Pkd/cgAK9ILfFFkyOdNwT/D YbuuTqCn8Vq+ifEAOUUMvKlz5QH87vGhdkGYq5AOk2NgeiCklJiEAkO8/Vv4bQgR yGN/XH/UZby+caljAxg+X3GuqS+rAREl7p/awAae6o/GqNKue1ILUG7zCsTuG755 Q7IyUBxcD8b0tkJ4hkQfsG7qDmsB3s1XZvI+nPcuvjyxeTErTQ2gCQY3obUTTJIX VySApNsHr6cN6xwN47+JJ7TYFFOF6WlJ3Pl+xMm3ojz75dF9RmWCJQmrR3ojZ+Ri BlStSu/Ntw799vVgAonT7xNmQXQwwKLbDcvQ88wc/5qM7IjS+neEg== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fvy024wg1-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:24:53 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 677HBGHO009346; Fri, 7 Aug 2026 17:24:52 GMT Received: from smtprelay04.fra02v.mail.ibm.com ([9.218.2.228]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fswbgrfa2-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:24:52 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay04.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 677HOmS430278222 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 7 Aug 2026 17:24:48 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 5460E2004D; Fri, 7 Aug 2026 17:24:48 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 974C720043; Fri, 7 Aug 2026 17:24:44 +0000 (GMT) Received: from localhost.localdomain (unknown [9.124.216.72]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Fri, 7 Aug 2026 17:24:44 +0000 (GMT) From: Amit Machhiwal To: linuxppc-dev@lists.ozlabs.org, Madhavan Srinivasan Cc: Vaibhav Jain , Amit Machhiwal , Anushree Mathur , Paolo Bonzini , Nicholas Piggin , Michael Ellerman , "Christophe Leroy (CS GROUP)" , Jonathan Corbet , Shuah Khan , Ritesh Harjani , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, Gautam Menghani Subject: [PATCH v8 1/4] KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl Date: Fri, 7 Aug 2026 22:54:30 +0530 Message-ID: <20260807172433.82045-2-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260807172433.82045-1-amachhiw@linux.ibm.com> References: <20260807172433.82045-1-amachhiw@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-ORIG-GUID: mPSN9XVJfx015M7NbOndJ8BeRBw-Fr06 X-Authority-Analysis: v=2.4 cv=e5k2j6p/ c=1 sm=1 tr=0 ts=6a7614e5 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=Y2IxJ9c9Rs8Kov3niI8_:22 a=VnNF1IyMAAAA:8 a=ETYFO_97Qo2pusGNp_0A:9 X-Proofpoint-GUID: kurpvY7eqfTKg5IFse8TXSsPxJ94pzWm X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfXzxapaznAKGiw DPux05OMCDc8NplWRbsqthEbrp3uwexV2KL5LngcDzPooo74XcLyEZ4YrtvQOZadeGFmf1diS0m LWIVC4PgUyicTWH+2qA8g/sQd4Ba/IVPk8yZhCD2dtKkILFelE3lP6aF54FHzvuswFRamyhiGer SbNtKN5FCq9PlucxKr3o9Q/dUTs+7F0Apa8oGZTPRKxp5xM7QHeRhQR3jEvw/WvCHH7jx5z9JIW amK58RgnTdHG72zyDGJgWhljKMMHAvQ/8Y93piWwUPLVCFQwu4fS088ulSP1EEoUHoM4YlTSq66 8TmDxRKgnae/efD4/0v0E16FisRoemE6ChKWFFJ7C7RfdO9gKMSCkq4GLfNVv4J14Svvctl3vVe 2XFyXkRd8xA9QVhZmQ0du/BRH0KxBLJg/7tr8RRLtRJDu7HcPnPK14Kso7uteZeHgjhURPw9BoX TxfUQkpGlcDyjiqy3rQ== X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfXxlfrTI0jTcQV FtANJ220pZF65eownEh0yQhwAe8cL7U6RL0jj1ddcBf4UO+9+xmlSiBm+/+PzwPGdWIHTel9wYk 5zgte/tL7ojh7Ml46t+pInouASVpQi4= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_03,2026-08-07_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 impostorscore=0 priorityscore=1501 adultscore=0 phishscore=0 clxscore=1015 malwarescore=0 spamscore=0 lowpriorityscore=0 bulkscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070135 Content-Type: text/plain; charset="utf-8" Introduce a new capability and ioctl to expose CPU compatibility modes supported by the host processor for nested guests. On IBM POWER systems, newer processor generations (N) can operate in compatibility modes corresponding to earlier generations, like (N-1) and (N-2). This is particularly relevant for nested virtualization, where nested KVM guests may need to run with a specific processor compatibility level. Introduce KVM_CAP_PPC_COMPAT_CAPS capability and the corresponding KVM_PPC_GET_COMPAT_CAPS vm ioctl. The ioctl returns a bitmap describing the compatibility modes supported by the host in respective bit numbers, allowing userspace (e.g., QEMU) to select an appropriate compatibility level when configuring nested KVM guests. The ioctl handling is added in kvm_arch_vm_ioctl() and retrieves host CPU compatibility capabilities via a PowerPC-specific backend implementation when available. The struct kvm_ppc_compat_caps places the 'size' field first so it can be read alone via get_user() before copy_struct_from_user() is called, avoiding pointer arithmetic to locate the size field. The ioctl is defined using _IO so the ioctl number remains stable even if the struct grows in future versions. It uses copy_struct_from_user() and copy_struct_to_user() to provide forward- and backward-compatible extensibility: older userspace passing a smaller struct to a newer kernel gets zero-padded trailing fields. Newer userspace passing a larger struct to an older kernel (usize > ksize) succeeds if trailing bytes are zero (the kernel reports back min(usize, ksize) as the filled size); if trailing bytes are non-zero, the kernel writes back ksize into host_caps.size and returns -E2BIG so userspace can retry with the correct size. KVM_PPC_COMPAT_CAPS_SIZE_VER0 is defined as a frozen integer constant (24) marking the size of the initial struct version, used as the minimum floor for size field validation, similar to other versioned struct interfaces in the kernel. The 'flags' field is reserved for future use. The kernel rejects any call where flags is non-zero with -EINVAL, preventing garbage values from being baked into ABI permanently. The ioctl returns appropriate error codes: E2BIG if usize exceeds PAGE_SIZE, or if new userspace provides a larger struct with non-zero trailing bytes (with ksize written back into host_caps.size for the retry); EINVAL for an invalid size or non-zero reserved fields; EFAULT for failed copy operations; and ENOTTY if the backend doesn't implement get_compat_caps. Suggested-by: Vaibhav Jain Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Tested-by: Anushree Mathur Signed-off-by: Amit Machhiwal Reviewed-by: Ritesh Harjani (IBM) --- Changes in this version: - Add PAGE_SIZE guard after get_user() to bound the check_zeroed_user() scan in the usize > ksize path [Ritesh] - Drop manual usize > sizeof(host_caps) pre-check; delegate entirely to copy_struct_from_user() which succeeds on zero trailing bytes and returns -E2BIG only on non-zero trailing bytes; handle -E2BIG with ksize writeback and -EFAULT escalation if put_user() fails [Ritesh] - Fix host_caps.size on success path: use min_t(u64, usize, sizeof(host_caps)) so new userspace with zero trailing bytes gets back the number of bytes the kernel actually populated, not usize [Ritesh] arch/powerpc/include/asm/kvm_ppc.h | 1 + arch/powerpc/include/uapi/asm/kvm.h | 8 +++ arch/powerpc/kvm/powerpc.c | 78 +++++++++++++++++++++++++++++ include/uapi/linux/kvm.h | 3 ++ 4 files changed, 90 insertions(+) diff --git a/arch/powerpc/include/asm/kvm_ppc.h b/arch/powerpc/include/asm/= kvm_ppc.h index 0953f2daa466..169ea6a7fbad 100644 --- a/arch/powerpc/include/asm/kvm_ppc.h +++ b/arch/powerpc/include/asm/kvm_ppc.h @@ -319,6 +319,7 @@ struct kvmppc_ops { bool (*hash_v3_possible)(void); int (*create_vm_debugfs)(struct kvm *kvm); int (*create_vcpu_debugfs)(struct kvm_vcpu *vcpu, struct dentry *debugfs_= dentry); + int (*get_compat_caps)(struct kvm_ppc_compat_caps *host_caps); }; =20 extern struct kvmppc_ops *kvmppc_hv_ops; diff --git a/arch/powerpc/include/uapi/asm/kvm.h b/arch/powerpc/include/uap= i/asm/kvm.h index 077c5437f521..19e53d5ae540 100644 --- a/arch/powerpc/include/uapi/asm/kvm.h +++ b/arch/powerpc/include/uapi/asm/kvm.h @@ -437,6 +437,14 @@ struct kvm_ppc_cpu_char { __u64 behaviour_mask; /* valid bits in behaviour */ }; =20 +/* For KVM_PPC_GET_COMPAT_CAPS */ +struct kvm_ppc_compat_caps { + __u64 size; /* Size of this structure */ + __u64 flags; /* Reserved for future use */ + __u64 compat_capabilities; /* Capabilities supported by the host */ +}; +#define KVM_PPC_COMPAT_CAPS_SIZE_VER0 24 /* sizeof first published struct = */ + /* * Values for character and character_mask. * These are identical to the values used by H_GET_CPU_CHARACTERISTICS. diff --git a/arch/powerpc/kvm/powerpc.c b/arch/powerpc/kvm/powerpc.c index b6b83fe3233f..14a661a88d4e 100644 --- a/arch/powerpc/kvm/powerpc.c +++ b/arch/powerpc/kvm/powerpc.c @@ -703,6 +703,13 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long= ext) } } break; +#if defined(CONFIG_KVM_BOOK3S_HV_POSSIBLE) + case KVM_CAP_PPC_COMPAT_CAPS: + r =3D 0; + if (hv_enabled && kvmhv_on_pseries()) + r =3D 1; + break; +#endif /* CONFIG_KVM_BOOK3S_HV_POSSIBLE */ default: r =3D 0; break; @@ -2469,6 +2476,77 @@ int kvm_arch_vm_ioctl(struct file *filp, unsigned in= t ioctl, unsigned long arg) r =3D kvm->arch.kvm_ops->svm_off(kvm); break; } + case KVM_PPC_GET_COMPAT_CAPS: { + struct kvm_ppc_compat_caps host_caps =3D {}; + u64 usize; + + /* + * Read the size field first to drive copy_struct_from_user. + * size must be the first field of the struct. + */ + r =3D -EFAULT; + if (get_user(usize, (__u64 __user *)argp)) + goto out; + + r =3D -E2BIG; + if (unlikely(usize > PAGE_SIZE)) + goto out; + + /* + * Enforce a minimum: reject buffers smaller than the initial + * struct version (VER0). This allows old userspace compiled + * against the original struct to still work on a newer kernel + * that has grown the struct with appended fields. + */ + r =3D -EINVAL; + if (usize < KVM_PPC_COMPAT_CAPS_SIZE_VER0) + goto out; + + /* + * copy_struct_from_user() handles forward/backward compat: + * usize =3D=3D ksize: verbatim copy + * usize < ksize: zero-pad trailing (old userspace, new kernel) + * usize > ksize: succeed iff trailing bytes are zero, else -E2BIG + */ + r =3D copy_struct_from_user(&host_caps, sizeof(host_caps), + argp, usize); + if (r) { + /* + * New userspace with a larger struct called an older + * kernel. Write back ksize in host_caps.size so + * userspace knows which older struct to retry with, + * then fail with -E2BIG. + */ + if (r =3D=3D -E2BIG) + if (put_user((__u64)sizeof(host_caps), + (__u64 __user *)argp)) + r =3D -EFAULT; + goto out; + } + + /* Reserved fields must be zero */ + r =3D -EINVAL; + if (host_caps.flags) + goto out; + + r =3D -ENOTTY; + if (!kvm->arch.kvm_ops->get_compat_caps) + goto out; + + r =3D kvm->arch.kvm_ops->get_compat_caps(&host_caps); + if (r) + goto out; + + /* + * Report the number of bytes actually populated by the kernel, + * not usize: if new userspace passed a larger struct with zero + * trailing bytes, we only filled sizeof(host_caps) bytes. + */ + host_caps.size =3D min_t(u64, usize, sizeof(host_caps)); + r =3D copy_struct_to_user(argp, usize, &host_caps, + sizeof(host_caps), NULL); + break; + } default: { struct kvm *kvm =3D filp->private_data; r =3D kvm->arch.kvm_ops->arch_vm_ioctl(filp, ioctl, arg); diff --git a/include/uapi/linux/kvm.h b/include/uapi/linux/kvm.h index 419011097fa8..70e36e6a0ad4 100644 --- a/include/uapi/linux/kvm.h +++ b/include/uapi/linux/kvm.h @@ -997,6 +997,7 @@ struct kvm_enable_cap { #define KVM_CAP_S390_KEYOP 247 #define KVM_CAP_S390_VSIE_ESAMODE 248 #define KVM_CAP_S390_HPAGE_2G 249 +#define KVM_CAP_PPC_COMPAT_CAPS 250 =20 struct kvm_irq_routing_irqchip { __u32 irqchip; @@ -1341,6 +1342,8 @@ struct kvm_s390_keyop { /* Available with KVM_CAP_COUNTER_OFFSET */ #define KVM_ARM_SET_COUNTER_OFFSET _IOW(KVMIO, 0xb5, struct kvm_arm_count= er_offset) #define KVM_ARM_GET_REG_WRITABLE_MASKS _IOR(KVMIO, 0xb6, struct reg_mask_= range) +/* Available with KVM_CAP_PPC_COMPAT_CAPS */ +#define KVM_PPC_GET_COMPAT_CAPS _IO(KVMIO, 0xb8) =20 /* ioctl for vm fd */ #define KVM_CREATE_DEVICE _IOWR(KVMIO, 0xe0, struct kvm_create_device) --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 13:19:19 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 533A23CB2D7; Fri, 7 Aug 2026 17:25:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123524; cv=none; b=cKVXm4IKEb5xnEi1yA/B0ihw5CB7eoOEybn+0F1pUWOL6nzZWmhBt0aXJN/rKmkCPTdckLfKYd/ZhoAH7rxD+GftCIp5kxQxI186ZQjKC7DDo2XgS/kbuHxesd2WM302jVO3F0fScal4NvLqJ1AKkxt6h8rBAJIOJNSWf/Q2uVU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123524; c=relaxed/simple; bh=8SJaesSmEMz50q645V+iXmIoBbDesixH+uHDXS6TbAc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=uRMnCydCImxb2EZkH9YLWqfhPk8PIyykkZbpySlavPp0er/DIM2o3VsGKiFDLS3KH8ZiJqmaCK4nNCrcBTgO9XjMK2V387V5HkQcZHMecMWhd1kPHzMP/Ma9J1+K6K9l0DGc/3JSKiOwMCB0fK9njmV7Cb7OHW+LlA5DiCXF/1Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=Oo5/c2sx; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="Oo5/c2sx" Received: from pps.filterd (m0360072.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677Gm16d2078702; Fri, 7 Aug 2026 17:24:58 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=6ZsR7bxa41ZnjXxzT z2yS40d1f72fEwF8oWdyBI1bAo=; b=Oo5/c2sx5qIM0lm+AYjRdD7bWu2HFfWvC c0u9HGqc1t4so3ZPdaeIBTBwH2cHV88hmGt9ZUAll3a6XWhq5v6u5brMfYekf/Zr 6PxdYVF6Xo0TCJ1TKCFrGejXTeSZUy7UXZAhEdpP51BvSOCnbhSGOxNUfE2EbZ1x dlz6Aphw5FQsut9R92GmYhbur/KjGVnjcgVUrUYZoxqyOZiY5kgancPWxFpcigcs lqzN5nIpwFAjrvH5qD1VY1jbapd7hV+LDkitZ7Xxn/LdGnY04sWiql0c79xrErRP CBjeS4Ry35kntLrBPVBCtdKpvRYA1RHNmwCnk13x2IlEabJrYQaaA== Received: from ppma23.wdc07v.mail.ibm.com (5d.69.3da9.ip4.static.sl-reverse.com [169.61.105.93]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fvy00cwjh-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:24:58 +0000 (GMT) Received: from pps.filterd (ppma23.wdc07v.mail.ibm.com [127.0.0.1]) by ppma23.wdc07v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 677GuNx3010399; Fri, 7 Aug 2026 17:24:57 GMT Received: from smtprelay02.fra02v.mail.ibm.com ([9.218.2.226]) by ppma23.wdc07v.mail.ibm.com (PPS) with ESMTPS id 4fsvmhrk1e-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:24:57 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay02.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 677HOrmT48628166 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 7 Aug 2026 17:24:53 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 4AE0D20043; Fri, 7 Aug 2026 17:24:53 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 864B320040; Fri, 7 Aug 2026 17:24:49 +0000 (GMT) Received: from localhost.localdomain (unknown [9.124.216.72]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Fri, 7 Aug 2026 17:24:49 +0000 (GMT) From: Amit Machhiwal To: linuxppc-dev@lists.ozlabs.org, Madhavan Srinivasan Cc: Vaibhav Jain , Amit Machhiwal , Anushree Mathur , Paolo Bonzini , Nicholas Piggin , Michael Ellerman , "Christophe Leroy (CS GROUP)" , Jonathan Corbet , Shuah Khan , Ritesh Harjani , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, Gautam Menghani Subject: [PATCH v8 2/4] KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM Date: Fri, 7 Aug 2026 22:54:31 +0530 Message-ID: <20260807172433.82045-3-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260807172433.82045-1-amachhiw@linux.ibm.com> References: <20260807172433.82045-1-amachhiw@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfX24IehhchE8HV D3NX4bSlbA039NPj7ZTtjBCyw8Nutya8L2ZogMwvCnnEPmboJrIPXp5ZkCpjlh1HDwE3C5S/AyJ XQceclZBfQH3G7RfJzi+dCDa+op9WcI= X-Authority-Analysis: v=2.4 cv=VPTtWdPX c=1 sm=1 tr=0 ts=6a7614ea cx=c_pps a=3Bg1Hr4SwmMryq2xdFQyZA==:117 a=3Bg1Hr4SwmMryq2xdFQyZA==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=RzCfie-kr_QcCd8fBx8p:22 a=VnNF1IyMAAAA:8 a=pGLkceISAAAA:8 a=igDgF-0WGXUSGxExIdQA:9 X-Proofpoint-ORIG-GUID: 7odzluqe5z2V-guF_F8BWQZJN--6fgRI X-Proofpoint-GUID: R6dKHr4Il_rg6qblzO-AaOZDgoQ4H3Nq X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfX3wjYt9VeR/Gl xx72fgEQekb32RMvQOzKyemJ+YYyT0Jw6hqy81tPQT6AtJgwzXyQMKNmtXiGUJImr8SNTOAfneq +Y5b1Racap9YsX05hfThVNN+/goAa2FL4JuWISbHrS8qejdnAGqRetkKXYM4kz7+y0nzkK3EHWT Shu1WaQQ0sXXAD8C0FHA2IHahhyr8xDsps+xXbUcvul2wwtN6nt/QlvgC0n2goeW2rGXvXFBg11 o8uHm03dp9AgGdMiwHb+bf/IXlTX6e6a/1jeVVFUaLti60a+E1YQWii4gLza2vmQlRSPnBW01na 2sU1fY3qeSaO7oHzVeyZvhAykvHKHB6HbdopTN9WzYz+F5ATQwiv8dbm1XC3v75s56+1qSOnein jgReLgtLutsnSjdwaJthCkFRKhY8LFYdduqJnIXwnPsPHN8UNstQY0lNv0SlsBP6uVhefbtD2yp NLPhsVSd0iwzbE+3Iug== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_03,2026-08-07_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 lowpriorityscore=0 malwarescore=0 bulkscore=0 spamscore=0 clxscore=1015 priorityscore=1501 phishscore=0 impostorscore=0 adultscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070135 Content-Type: text/plain; charset="utf-8" On POWER systems, the host CPU may run in a compatibility mode (e.g., a Power11 processor operating in Power10 compatibility mode). In such cases, the effective CPU level exposed to guests differs from the physical processor generation. When running nested KVM guests, QEMU derives the host CPU type using mfpvr(), which reflects the physical processor version. This can result in a mismatch between the CPU model selected by QEMU and the compatibility mode enforced by the host, leading to guest boot failures. For example, booting a nested guest on a Power11 LPAR configured in Power10 compatibility mode fails with: KVM-NESTEDv2: couldn't set guest wide elements [..KVM reg dump..] This occurs because QEMU selects a CPU model corresponding to the physical processor (via mfpvr()), while the host operates in a lower compatibility mode. As a result, KVM rejects the requested compatibility level during guest initialization. On pseries nestedv2 systems, add support for retrieving host CPU compatibility capabilities for nested guests on PowerVM. The capability bitmap reflects the processor modes negotiated between the Power hypervisor (L0) and the host partition (L1) via the H_GUEST_GET_CAPABILITIES hcall, but is retrieved from the cached nested_capabilities value populated during module initialization, avoiding repeated hypervisor calls. A WARN_ON_ONCE() flags the unexpected case where nested_capabilities is zero on a nestedv2 system. The implementation defines KVM-specific capability constants (KVM_PPC_COMPAT_CAP_POWER9/10/11), masks unsupported bits, and exposes the result through the KVM_PPC_GET_COMPAT_CAPS ioctl. Hook the implementation into the Book3S HV kvmppc_ops so that it can be invoked by the generic KVM ioctl handling code. Suggested-by: Vaibhav Jain Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Tested-by: Anushree Mathur Reviewed-by: Ritesh Harjani (IBM) Signed-off-by: Amit Machhiwal --- arch/powerpc/include/uapi/asm/kvm.h | 10 ++++++++++ arch/powerpc/kvm/book3s_hv.c | 20 ++++++++++++++++++++ 2 files changed, 30 insertions(+) diff --git a/arch/powerpc/include/uapi/asm/kvm.h b/arch/powerpc/include/uap= i/asm/kvm.h index 19e53d5ae540..913a64b901a3 100644 --- a/arch/powerpc/include/uapi/asm/kvm.h +++ b/arch/powerpc/include/uapi/asm/kvm.h @@ -445,6 +445,16 @@ struct kvm_ppc_compat_caps { }; #define KVM_PPC_COMPAT_CAPS_SIZE_VER0 24 /* sizeof first published struct = */ =20 +/* + * Capability bits for compat_capabilities field in kvm_ppc_compat_caps. + * These bits indicate which processor compatibility modes are supported. + */ +#define KVM_PPC_COMPAT_CAP_POWER9 (1ULL << 62) +#define KVM_PPC_COMPAT_CAP_POWER10 (1ULL << 61) +#define KVM_PPC_COMPAT_CAP_POWER11 (1ULL << 60) +#define KVM_PPC_COMPAT_BITMASK (KVM_PPC_COMPAT_CAP_POWER9 | \ + KVM_PPC_COMPAT_CAP_POWER10 | \ + KVM_PPC_COMPAT_CAP_POWER11) /* * Values for character and character_mask. * These are identical to the values used by H_GET_CPU_CHARACTERISTICS. diff --git a/arch/powerpc/kvm/book3s_hv.c b/arch/powerpc/kvm/book3s_hv.c index f9380ef65750..152cd08a5b38 100644 --- a/arch/powerpc/kvm/book3s_hv.c +++ b/arch/powerpc/kvm/book3s_hv.c @@ -6523,6 +6523,25 @@ static bool kvmppc_hash_v3_possible(void) return true; } =20 + +static int kvmppc_get_compat_caps(struct kvm_ppc_compat_caps *host_caps) +{ + unsigned long capabilities =3D 0; + long rc =3D -EINVAL; + + if (kvmhv_on_pseries()) { + if (kvmhv_is_nestedv2()) { + WARN_ON_ONCE(!nested_capabilities); + capabilities =3D nested_capabilities; + rc =3D 0; + } + } + + host_caps->compat_capabilities =3D capabilities & KVM_PPC_COMPAT_BITMASK; + + return rc; +} + static struct kvmppc_ops kvm_ops_hv =3D { .get_sregs =3D kvm_arch_vcpu_ioctl_get_sregs_hv, .set_sregs =3D kvm_arch_vcpu_ioctl_set_sregs_hv, @@ -6565,6 +6584,7 @@ static struct kvmppc_ops kvm_ops_hv =3D { .hash_v3_possible =3D kvmppc_hash_v3_possible, .create_vcpu_debugfs =3D kvmppc_arch_create_vcpu_debugfs_hv, .create_vm_debugfs =3D kvmppc_arch_create_vm_debugfs_hv, + .get_compat_caps =3D kvmppc_get_compat_caps, }; =20 static int kvm_init_subcore_bitmap(void) --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 13:19:19 2026 Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4FD0C1DDC38; Fri, 7 Aug 2026 17:25:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.156.1 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123517; cv=none; b=LZ5DHaCFndC7U9XcJK7cQHg2qAoJrh5hvdgKUq2zienG0ZXSYbsDbmQrMVjbU5ghwxyT1TY5iCDSDhzGkhpEk3KX8Qsh4vFZ+B4y9luLW8xUxb6fnYe7udWWT8KNMipSNBDscWC7IkDYjVPpy2Th/zYuKrrIvnWDEc4cAIEWujE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123517; c=relaxed/simple; bh=5h/s+AAYgQlPhirHpaBQESgx7qCL8kqNs1uxioqPv9o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Hu2+0cIK6i22gZ3BqUlfTlorbOjbRdUPivlMGwi0ignmyCZpFOlCckm9KcmJV9HOr56Vjb5QR4NOwHNkOITkEYdncioTusSH/kEhF3K48M0dVcXAAuSAjHv5qD5k+wnK54bj9jnuzZg+sw+n4q2wukoTVW7RIL0Tx5wHdgft6o0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=SsSTgmcI; arc=none smtp.client-ip=148.163.156.1 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="SsSTgmcI" Received: from pps.filterd (m0356517.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677GlWrq2029326; Fri, 7 Aug 2026 17:25:04 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=JK/HgCIRS7bWKsUL0 /9kFYeCHCkOOqKTR3vxOapEigE=; b=SsSTgmcIk7+v9Ugn7B9nI+8uS7UJk5NyS JoWgQhrf8xS+GbK7X/tzTd2TVlXI3/XTWWRnreUjI2rYsPaYQV/D/0Y9OK93ZT40 vPHnssu7vUY+c8k/60a6hHvx/MrTmnzPADBfbQNGXJWepJszf3qvvtyeYZYYyAuf p98oFU2KbOwWl01QYzQ6FH7YdfFG0sIAaXcWplWgiZbFDux0ZcCE02vBf+PXbGJW Jhv4hKm0BRRSUt5qIVlxKD/jsOdmuLVSIPPIMzFgDIni3HiaLaOnT9yStRf5UUrw IECx/aI3dk01TtxxmhBFQytLx9D5rOtW9IUbLeMe9hjR+DNQRkkhw== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fvxyyw39t-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:25:03 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 677HBGHS009346; Fri, 7 Aug 2026 17:25:02 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fswbgrfas-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:25:02 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 677HOwCS26477032 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 7 Aug 2026 17:24:58 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8026F20043; Fri, 7 Aug 2026 17:24:58 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 8B78F20040; Fri, 7 Aug 2026 17:24:54 +0000 (GMT) Received: from localhost.localdomain (unknown [9.124.216.72]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Fri, 7 Aug 2026 17:24:54 +0000 (GMT) From: Amit Machhiwal To: linuxppc-dev@lists.ozlabs.org, Madhavan Srinivasan Cc: Vaibhav Jain , Amit Machhiwal , Anushree Mathur , Paolo Bonzini , Nicholas Piggin , Michael Ellerman , "Christophe Leroy (CS GROUP)" , Jonathan Corbet , Shuah Khan , Ritesh Harjani , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, Gautam Menghani Subject: [PATCH v8 3/4] KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV Date: Fri, 7 Aug 2026 22:54:32 +0530 Message-ID: <20260807172433.82045-4-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260807172433.82045-1-amachhiw@linux.ibm.com> References: <20260807172433.82045-1-amachhiw@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Authority-Analysis: v=2.4 cv=SYrHsPRu c=1 sm=1 tr=0 ts=6a7614ef cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=U7nrCbtTmkRpXpFmAIza:22 a=VnNF1IyMAAAA:8 a=pGLkceISAAAA:8 a=jUdWb-NNBahwQYUnPB4A:9 X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfX1Snl4TzWlYkC tVBQsvSNndo3+tHseXWQaD/tqmQBjW1RlgRLsftCSqQGe8gz4wvmf41L5yPUr4+VZpu9G4/17oj cfOAwoFTS4Uh8OEBgJjhkPVnfF88h9Q= X-Proofpoint-ORIG-GUID: 7_2383a5b3hge9jzIonl5iWQY4wg5EK5 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfX6QBKb/qqbDwf AsKzQsU6FyJY4GNkJDKOdIu0QZX+qIzOFxw9aTy0POBd7TAiOellvjpYExlkB1eEj5uLc/bIax7 qYLoiW61mWf0cNZzfmmpzg1eM6hb+IcGlk0zMKXuk+W3Scd5p0oSQwLaEs1TnMm4jkCMLWq9Lkk 6uKvgrxSFg6vBl5ckPXNGTzqQM27iMGNdaTN9mHr17JP9rJa5Y68XlKpzsgMtzfIod/eWpr9Sgv 1y3T/BTT33N5sciWkgp+Xy35Ed/1AYgn9gapZOql5Pdo+2Ips0eKymZjamGaz8PBo+rSMc+nfSj HRhXHKKLJ7FMjMRdiAk0Pjio2ufrE7IBWJjV+d+//mz78rTWf7RPH/SZbd/pdVziflHMeJ197Jp Gkmerj49StQxAuBPl9t4uNGBiz4QnMuxX5D+KsVegeaSsNakd45GgqwX56LvtjoDQA5FfCbyGLL nya1lR8cSqHWtNKD+Ew== X-Proofpoint-GUID: LcnEmZl0_0ZwACMQBcSHp6B8WfNRBpf7 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_03,2026-08-07_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 clxscore=1015 malwarescore=0 priorityscore=1501 lowpriorityscore=0 suspectscore=0 bulkscore=0 impostorscore=0 phishscore=0 spamscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070135 Content-Type: text/plain; charset="utf-8" Currently, when booting a compatibility-mode KVM guest (L1) on a PowerNV hypervisor (L0), the guest runs with the expected processor compatibility level. However, when booting a nested KVM guest (L2) inside the L1, QEMU derives the CPU model from the raw host PVR and attempts to run the nested guest at that level, instead of honoring the compatibility mode of the L1. Extend host CPU compatibility capability reporting to support nested virtualization on PowerNV systems (PAPR nested API v1). For nested API v2 (PowerVM), compatibility capabilities are served from the cached nested_capabilities value (populated at module init via kvmhv_nested_init() using the H_GUEST_GET_CAPABILITIES hcall). This information is not available on PowerNV systems. For nested API v1, derive the compatibility capabilities from the L1 guest by reading the "cpu-version" property from the device tree, which reflects the effective (logical) processor compatibility level. Map this value to the corresponding compatibility capability bitmap using KVM-specific constants. The mapping is cumulative: a system running at a given compatibility level is assumed to also support older generations down the supported chain. Note that unlike KVM on PowerVM (nested API v2), KVM on PowerNV currently does not strictly enforce older generation compatibility modes for nested guests - the reported capabilities reflect what the host CPU can present, not what the hypervisor independently validates. Introduce a helper kvmppc_map_compat_capabilities() to translate CPU version values into KVM_PPC_COMPAT_CAP bits using a fallthrough switch, and integrate it into kvmppc_get_compat_caps(). The implementation applies masking to ensure only supported processor modes are exposed. This allows userspace to query host CPU compatibility modes on both KVM on PowerVM and on PowerNV platforms via the KVM_PPC_GET_COMPAT_CAPS ioctl. Suggested-by: Vaibhav Jain Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Tested-by: Anushree Mathur Reviewed-by: Ritesh Harjani (IBM) Signed-off-by: Amit Machhiwal --- arch/powerpc/kvm/book3s_hv.c | 36 ++++++++++++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) diff --git a/arch/powerpc/kvm/book3s_hv.c b/arch/powerpc/kvm/book3s_hv.c index 152cd08a5b38..4d0307f55e06 100644 --- a/arch/powerpc/kvm/book3s_hv.c +++ b/arch/powerpc/kvm/book3s_hv.c @@ -6523,20 +6523,56 @@ static bool kvmppc_hash_v3_possible(void) return true; } =20 +static int kvmppc_map_compat_capabilities(u32 cpu_version, + unsigned long *capabilities) +{ + switch (cpu_version) { + case PVR_ARCH_31_P11: + *capabilities |=3D KVM_PPC_COMPAT_CAP_POWER11; + fallthrough; + case PVR_ARCH_31: + *capabilities |=3D KVM_PPC_COMPAT_CAP_POWER10; + fallthrough; + case PVR_ARCH_300: + *capabilities |=3D KVM_PPC_COMPAT_CAP_POWER9; + break; + default: + return -EINVAL; + } + + return 0; +} =20 static int kvmppc_get_compat_caps(struct kvm_ppc_compat_caps *host_caps) { + struct device_node *np; unsigned long capabilities =3D 0; long rc =3D -EINVAL; + u32 cpu_version =3D 0; =20 if (kvmhv_on_pseries()) { if (kvmhv_is_nestedv2()) { WARN_ON_ONCE(!nested_capabilities); capabilities =3D nested_capabilities; rc =3D 0; + } else { + for_each_node_by_type(np, "cpu") { + if (!of_property_read_u32(np, "cpu-version", + &cpu_version)) { + of_node_put(np); + break; + } + } + if (!cpu_version) + return -EINVAL; + rc =3D kvmppc_map_compat_capabilities(cpu_version, + &capabilities); } } =20 + if (rc < 0) + return rc; + host_caps->compat_capabilities =3D capabilities & KVM_PPC_COMPAT_BITMASK; =20 return rc; --=20 2.50.1 (Apple Git-155) From nobody Tue Sep 29 13:19:19 2026 Received: from mx0b-001b2d01.pphosted.com (mx0b-001b2d01.pphosted.com [148.163.158.5]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 43A4A274641; Fri, 7 Aug 2026 17:25:41 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.163.158.5 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123542; cv=none; b=scySXGUbjBO63RfyG08/q5rYAHup/l9DYtifudSU/PZ3gTc1KUp7LSyYwlJie4ECuRsN+2YybbTG1P1SYrgtwAIbk//CBLFsTID/f9Ieba6JtDwHymbaoLFdjyNkvRHXMqv42OwlG2pX7Ga7sq+UWlzrJkl5SIap4dTppamIPSY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786123542; c=relaxed/simple; bh=xqCTlNOq8YeVsr8UtyFwODR/zMinajep/MnE8MBsAZY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=YVEMd5W8ux8v/0ILMRyMfhKBMn9WFnmDZd5fpptHJtJvaYC8v/J3zEx6BPHbOrwpih23asePYdKakM8a53uP9Kzti2OsuVLhaaWdj9Cq48YlDVF1plzpKzt/VmyP9/KGDOGEDborVTT/FHeJ1MvuKvv1BFDgZ8vcw1LfNH3agNg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com; spf=pass smtp.mailfrom=linux.ibm.com; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b=KoQRI13W; arc=none smtp.client-ip=148.163.158.5 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.ibm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ibm.com header.i=@ibm.com header.b="KoQRI13W" Received: from pps.filterd (m0353725.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 677Glwqv1928128; Fri, 7 Aug 2026 17:25:27 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=pp1; bh=ri/s8/IRsCo9q7qhj pmRMpMFjLqk+LSvHjimzadH/4E=; b=KoQRI13WvBzQBsL+ZudeixKf+V0iIJMFt NFAoznlKiuqSKJuZTtSFa2dDjxvuOo0Uq8yY6mRo27y/naZZfE0uywNnVpsTBnhM XuWEaGqm6xXNcjsXPNTsR/z/1WOiR3VmAN5vBLDOOC11Kioor1vfdDY/WYyeaiaV tePHRzyG7GSAuJwdOxPswkD+koAOULLNw1XwTQd5yEopgVo++nKPTJ+B/sF7NPEx qSSNh8cPnsPtwueHXlrVu3GSE8MScN1j+REboPATS8yK8LoxkymLgXPPxBc74Jsj /x/wiDngVwSrFVZ74S8qdjeuUBXylCU9EgY277licNNPzJbPIv8xA== Received: from ppma13.dal12v.mail.ibm.com (dd.9e.1632.ip4.static.sl-reverse.com [50.22.158.221]) by mx0a-001b2d01.pphosted.com (PPS) with ESMTPS id 4fvy02cx24-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:25:26 +0000 (GMT) Received: from pps.filterd (ppma13.dal12v.mail.ibm.com [127.0.0.1]) by ppma13.dal12v.mail.ibm.com (8.18.1.7/8.18.1.7) with ESMTP id 677HBPYd009569; Fri, 7 Aug 2026 17:25:25 GMT Received: from smtprelay02.fra02v.mail.ibm.com ([9.218.2.226]) by ppma13.dal12v.mail.ibm.com (PPS) with ESMTPS id 4fswbgrfd6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 07 Aug 2026 17:25:25 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (smtpav07.fra02v.mail.ibm.com [10.20.54.106]) by smtprelay02.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 677HPLdd50135318 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Fri, 7 Aug 2026 17:25:21 GMT Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7FE0720043; Fri, 7 Aug 2026 17:25:21 +0000 (GMT) Received: from smtpav07.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id C0E9C20040; Fri, 7 Aug 2026 17:25:17 +0000 (GMT) Received: from localhost.localdomain (unknown [9.124.216.72]) by smtpav07.fra02v.mail.ibm.com (Postfix) with ESMTP; Fri, 7 Aug 2026 17:25:17 +0000 (GMT) From: Amit Machhiwal To: linuxppc-dev@lists.ozlabs.org, Madhavan Srinivasan Cc: Vaibhav Jain , Amit Machhiwal , Anushree Mathur , Paolo Bonzini , Nicholas Piggin , Michael Ellerman , "Christophe Leroy (CS GROUP)" , Jonathan Corbet , Shuah Khan , Ritesh Harjani , kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-doc@vger.kernel.org, Gautam Menghani Subject: [PATCH v8 4/4] KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl Date: Fri, 7 Aug 2026 22:54:33 +0530 Message-ID: <20260807172433.82045-5-amachhiw@linux.ibm.com> X-Mailer: git-send-email 2.50.1 In-Reply-To: <20260807172433.82045-1-amachhiw@linux.ibm.com> References: <20260807172433.82045-1-amachhiw@linux.ibm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-Reinject: loops=2 maxloops=12 X-Authority-Analysis: v=2.4 cv=G6ws1dk5 c=1 sm=1 tr=0 ts=6a761506 cx=c_pps a=AfN7/Ok6k8XGzOShvHwTGQ==:117 a=AfN7/Ok6k8XGzOShvHwTGQ==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=RnoormkPH1_aCDwRdu11:22 a=V8glGbnc2Ofi9Qvn3v5h:22 a=VnNF1IyMAAAA:8 a=hQeoMbdVOOR6M4iuoH8A:9 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfX/x6h+07+hx6U Bf/klCiC3CC+/GSSKwiGJlvOXIZ3I+hOBG48ZXLkBuDDtIlFKRmb721U/PaENhA83V5OE+a4btO qVc+deCX2ZKDUz7HBZMWK0Pb5aQjXe/Uywn3yX8rXsqEgUpXcnOhDjHOIUOE/M4cl34LrC9twHR 8pxgtsltyO5HUFo1NFY4JtLeRUGdjEbqNy1h1qVtX9dfL9JDD/0vdoAb2eE/3T3/uFDaxJ8wF5k OqS5Lp8qyxtCtvlSds2G97yaAzzB5sO+I3woKl/0YCVsT9DyBB0UQrzWH86UU9LvZ30LPkP90tW 0vbQf47d2vAy5aF1kHZZa2OO47yVEV/Aln5+VedPlfclcMHqwL7hJG6LiGg2eCvwLZDftw5Mbf4 jclnmEyqpxOqwueD8HeOe6OfbTQJGaM5+6cxWYJlD836zet12h58FGFZunI0Mvs1Z5DyGuHD3Pb 4gJXhh4xE08uXN7ZAsw== X-Proofpoint-ORIG-GUID: 3Wm6WCw3j61AcVtrdKDiKqzDhx_tFALz X-Proofpoint-Spam-Info: AW1haW4tMjYwODA3MDEzNSBTYWx0ZWRfXzrVfHVSZeArH 4LiqDTNWKFo9DJPrJOqVLc2P6Dok0avAF+xhcKd/KqTtiQ/w4S/qHFbZ5YYEMYxFHbaLe6WoXK6 spPD44PZm6C/UpW62tSNyAyXT7q374Y= X-Proofpoint-GUID: vbxh3gC8tQCtsoH6IvGUyCky_0BfrTww X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-07_03,2026-08-07_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 spamscore=0 lowpriorityscore=0 suspectscore=0 malwarescore=0 phishscore=0 priorityscore=1501 adultscore=0 bulkscore=0 clxscore=1015 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608070135 Content-Type: text/plain; charset="utf-8" Add documentation for the KVM_PPC_GET_COMPAT_CAPS ioctl to the KVM API documentation. The ioctl exposes host processor compatibility modes supported for nested KVM guests on PowerPC systems. The documentation covers error code descriptions including E2BIG for forward compatibility, the extensible size-based versioning contract using KVM_PPC_COMPAT_CAPS_SIZE_VER0, the rationale for rejecting non-zero reserved fields to prevent ABI ambiguity, bit numbering clarification for IBM MSB-0 convention, and KVM-specific capability bit constants. Tested-by: Gautam Menghani Reviewed-by: Gautam Menghani Tested-by: Anushree Mathur Signed-off-by: Amit Machhiwal Reviewed-by: Ritesh Harjani (IBM) --- Changes in this version: - Update E2BIG description: document PAGE_SIZE guard as first case; -E2BIG for usize > ksize is only returned when trailing bytes are non-zero; zero trailing bytes now succeed [Ritesh] - Rewrite versioning paragraph as three explicit cases to match the corrected copy_struct_from_user() / copy_struct_to_user() contract, including the usize > ksize zero-trailing-bytes success path [Ritesh] Documentation/virt/kvm/api.rst | 89 ++++++++++++++++++++++++++++++++++ 1 file changed, 89 insertions(+) diff --git a/Documentation/virt/kvm/api.rst b/Documentation/virt/kvm/api.rst index e3003a241d5b..e656d117cd0b 100644 --- a/Documentation/virt/kvm/api.rst +++ b/Documentation/virt/kvm/api.rst @@ -6566,6 +6566,95 @@ KVM_S390_KEYOP_SSKE Sets the storage key for the guest address ``guest_addr`` to the key specified in ``key``, returning the previous value in ``key``. =20 +4.145 KVM_PPC_GET_COMPAT_CAPS +----------------------------- +:Capability: KVM_CAP_PPC_COMPAT_CAPS +:Architectures: powerpc +:Type: vm ioctl +:Parameters: struct kvm_ppc_compat_caps (in/out) +:Returns: 0 on success, negative value on failure + +Errors include: + + =3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + EFAULT if ``struct kvm_ppc_compat_caps`` cannot be read from or + written to userspace + EINVAL if the ``size`` field is smaller than + ``KVM_PPC_COMPAT_CAPS_SIZE_VER0``, if the ``flags`` field + is non-zero, or if the backend fails to retrieve or map + CPU compatibility capabilities + E2BIG if ``size`` exceeds ``PAGE_SIZE`` (pathological input guard), + or if ``size`` is larger than the kernel's struct size and + the unknown trailing bytes are non-zero (new userspace on + old kernel with non-default fields set); in the latter case + the kernel writes back its own struct size into the ``size`` + field so userspace can retry with the correct size + ENOTTY if the backend does not implement the ``get_compat_caps`` + operation (e.g., on non-HV KVM implementations where the + required KVM operations are not available) + =3D=3D=3D=3D=3D=3D=3D=3D =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +IBM POWER system server-based processors provide a compatibility mode feat= ure +where an Nth generation processor can operate in modes consistent with ear= lier +generations such as (N-1) and (N-2). + +This ioctl provides userspace with information about the CPU compatibility= modes +supported by the current host processor for booting the nested KVM guests = on +KVM on PowerNV (nested API v1) and KVM on PowerVM (nested API v2) platform= s. + +:: + + struct kvm_ppc_compat_caps { + __u64 size; /* Size of this structure */ + __u64 flags; /* Reserved for future use, must be 0 */ + __u64 compat_capabilities; /* Capabilities supported by the host */ + }; + +Before calling this ioctl, userspace must set the ``size`` field to +``sizeof(struct kvm_ppc_compat_caps)`` and zero the ``flags`` field. +The kernel rejects non-zero ``flags`` with ``-EINVAL`` to prevent +uninitialized stack values from being silently accepted, keeping the +field available for future use without ABI ambiguity. + +The ioctl uses ``copy_struct_from_user()`` and ``copy_struct_to_user()`` +to support extensible versioning across three cases: + +- If ``size`` is smaller than the kernel's struct size (old userspace, + new kernel), the kernel zero-pads the unknown trailing fields before + returning, and writes back ``size`` unchanged so userspace knows how + many bytes were filled. +- If ``size`` equals the kernel's struct size, the struct is copied + verbatim. +- If ``size`` is larger than the kernel's struct size (new userspace, + old kernel) and the unknown trailing bytes are all zero, the call + succeeds as if the sizes matched. If any trailing bytes are non-zero, + the kernel returns ``-E2BIG`` and writes back its own struct size into + the ``size`` field so userspace can retry with the correct size. + +``KVM_PPC_COMPAT_CAPS_SIZE_VER0`` (24) is a frozen constant marking the +size of the initial struct version. + +The ``compat_capabilities`` bit field describes the processor compatibility +modes supported by the host. The following bits indicate support for speci= fic +processor modes (using IBM's MSB-0 convention where bit 0 is the most +significant bit): + +- ``KVM_PPC_COMPAT_CAP_POWER9`` (bit 1) -- KVM guests can run in Power9 p= rocessor mode +- ``KVM_PPC_COMPAT_CAP_POWER10`` (bit 2) -- KVM guests can run in Power10 = processor mode +- ``KVM_PPC_COMPAT_CAP_POWER11`` (bit 3) -- KVM guests can run in Power11 = processor mode + +.. note:: + + The bit numbering above uses IBM's MSB-0 convention (bit 0 is the most + significant bit). In the actual implementation, these are defined as: + + - ``KVM_PPC_COMPAT_CAP_POWER9`` =3D ``(1ULL << 62)`` + - ``KVM_PPC_COMPAT_CAP_POWER10`` =3D ``(1ULL << 61)`` + - ``KVM_PPC_COMPAT_CAP_POWER11`` =3D ``(1ULL << 60)`` + + Userspace should use the defined constants from ```` rather + than hardcoding bit positions. + .. _kvm_run: =20 5. The kvm_run structure --=20 2.50.1 (Apple Git-155)