From nobody Tue Sep 29 11:54:19 2026 Received: from mail-ej1-f70.google.com (mail-ej1-f70.google.com [209.85.218.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AD873367B89 for ; Sat, 8 Aug 2026 08:58:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179515; cv=none; b=FWxiornEgHPU2Jzk92lbpnwWJEear7msKXmzymhLbW2+rAI3fWlzS3DDAHdEmnCZp3BRaJI6FSw3TUVWsWyQDvRYqAhn+4JRrp9f8hAvbe3l+iDyLhcbIt+m2+6Gfumy7ETXSwm427eaEQ0fcLcHg9e2Po5I3MCo3mTtlcn4CBU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179515; c=relaxed/simple; bh=sOMxXRo2tf/41bNIqVZVhHEfAJNv3PSGO+R2IPHZu9s=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=I4PbErC3/db6VPCSihuuozqfeca1spCvb3jIPwVbL8IZME51oJ5whPZaO5bGIFQbmPkYNZxr/WIEv9oqHZBt05aWd7G3Ylm3xnSv+qX9U/zCPx9feBxYOs6UqDfRNGRjve8e1F64vwfs7d3t6DMUdgoTicY5psfM+2ny/yqmO5E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=XBws4zW+; arc=none smtp.client-ip=209.85.218.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="XBws4zW+" Received: by mail-ej1-f70.google.com with SMTP id a640c23a62f3a-c15c6a68406so20561166b.3 for ; Sat, 08 Aug 2026 01:58:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786179512; x=1786784312; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=w+A/GWMMn/zlz2wejiFB/oEcYi+94/jbgzvZk1RNCE8=; b=XBws4zW+A7zPsC0+5ZsH5VyMRlfhosGCPlBZWH+4QyB3TMpf14nzOJ9CAhlYpgwypy z4CTEnVtxcBUsNgBE03OXm7IDujh1YEtiDpDRht2gG+/Y8u7hcyiHCm15QSxzgBnrD1Z YCy/PEPpiSdhV53GnGiGPaeCS41hc42rjqOMNPLgXmkKIQ/0MOS9AZ5792Pn2qHUcpr+ 2LSqIv2BgOfikAag1AfJxZuqjirXBGaQjKQ/3XM5HJKivobWhH9vfd+zmsQGhuWRC6ze UTURmza5Dx4BlZENfzlyPw5cajCxl/+AeeoeRnRLTR+faZrT8FNWXy/IajCs/I0Sd7Ku AM9g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786179512; x=1786784312; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=w+A/GWMMn/zlz2wejiFB/oEcYi+94/jbgzvZk1RNCE8=; b=Lit4rJjap+lEec8NtJgwfRUTrbh+xFQT3SrTlgiTgNp+FAEz/0O43tpBlfDsPV6lPP Iu7UjP/02qgX1BYSCi8+uCCIYIz3wW14ZX2WkHO4JUy44c6bWE7zLM4a7jerHhWBy7jp x2AEkkv/VyNVzB1YUWzBCSSXSNGNXC83ewjwu9uxWl2dbAsz9DXD9B5xn6DjHUZa7MFB KUJjmOsuGNTTst3ot45e1+vDvl0VtY5XVHMb7uh5ODQatcnV5hzreIZHowN6POTT1Bfz j08TRKJz90qkKXfJzgIoWVpRk5IiOk1J4HfZqBBFwcu60vqmuWq2IMr2CroRecctHmAo zJ0w== X-Gm-Message-State: AOJu0YxT2y9h37Gwi+bXrEyyRXWqoniiCoQfH7wwds1gwYma4Yt8DqRt Eg7NwezghhLJ+A0Lk53hcc7kM82Vj3n7V8TSW1KQNTp5o0MHutQVYaOSZZiAlz5gkJ0KRfXZaLL EJcTlbne9ow/hVdi5j5MDi8rTc8UwNPtdHnSADFEvBtz4ozuW2FPo7k9hx8Vx5JIdUvMW+FYUXn Hdrws4gwIzRIXgRniFtKkD29J0mZRRso3qu51+Z8Id2DU/ye1UEI8nNlU= X-Received: from ejdao2.prod.google.com ([2002:a17:907:f482:b0:c15:cd6e:51d6]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a17:907:9729:b0:c15:db5c:7127 with SMTP id a640c23a62f3a-c2073364a2bmr714358466b.20.1786179511440; Sat, 08 Aug 2026 01:58:31 -0700 (PDT) Date: Sat, 8 Aug 2026 08:58:22 +0000 In-Reply-To: <20260808085824.732659-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260808085824.732659-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.654.g21b8a5bc05-goog Message-ID: <20260808085824.732659-2-smostafa@google.com> Subject: [PATCH v2 1/3] KVM: arm64: Make timer_get_offset() work in all contexts From: Mostafa Saleh To: linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: maz@kernel.org, oupton@kernel.org, seiden@linux.ibm.com, joey.gouly@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, catalin.marinas@arm.com, will@kernel.org, vdonnefort@google.com, tabba@google.com, sebastianene@google.com, keirf@google.com, yaoyuan@linux.alibaba.com, Mostafa Saleh Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Marc Zyngier We currently have two implementations of get_timer offset(), one in arm_arch_timer.h, and another one in switch.h. These two only differ by a pair of kern_hyp_va(), which seems a pretty weak reason to open-code it. Turn this function into a macro to avoid the include dependency hell on kern_hyp_va(), and make it work correctly in all contexts. Signed-off-by: Marc Zyngier Signed-off-by: Mostafa Saleh --- arch/arm64/kvm/hyp/include/hyp/switch.h | 15 +---------- include/kvm/arm_arch_timer.h | 34 +++++++++++++++---------- 2 files changed, 22 insertions(+), 27 deletions(-) diff --git a/arch/arm64/kvm/hyp/include/hyp/switch.h b/arch/arm64/kvm/hyp/i= nclude/hyp/switch.h index 4bf624a49591..2aceda749641 100644 --- a/arch/arm64/kvm/hyp/include/hyp/switch.h +++ b/arch/arm64/kvm/hyp/include/hyp/switch.h @@ -706,22 +706,9 @@ static inline bool handle_tx2_tvm(struct kvm_vcpu *vcp= u) return true; } =20 -/* Open-coded version of timer_get_offset() to allow for kern_hyp_va() */ -static inline u64 hyp_timer_get_offset(struct arch_timer_context *ctxt) -{ - u64 offset =3D 0; - - if (ctxt->offset.vm_offset) - offset +=3D *kern_hyp_va(ctxt->offset.vm_offset); - if (ctxt->offset.vcpu_offset) - offset +=3D *kern_hyp_va(ctxt->offset.vcpu_offset); - - return offset; -} - static inline u64 compute_counter_value(struct arch_timer_context *ctxt) { - return arch_timer_read_cntpct_el0() - hyp_timer_get_offset(ctxt); + return arch_timer_read_cntpct_el0() - timer_get_offset(ctxt); } =20 static bool kvm_handle_cntxct(struct kvm_vcpu *vcpu) diff --git a/include/kvm/arm_arch_timer.h b/include/kvm/arm_arch_timer.h index 725023ddc792..f3f0a79647cd 100644 --- a/include/kvm/arm_arch_timer.h +++ b/include/kvm/arm_arch_timer.h @@ -163,20 +163,28 @@ static inline bool has_cntpoff(void) return (has_vhe() && cpus_have_final_cap(ARM64_HAS_ECV_CNTPOFF)); } =20 -static inline u64 timer_get_offset(struct arch_timer_context *ctxt) -{ - u64 offset =3D 0; +#ifdef __KVM_NVHE_HYPERVISOR__ +#define KERN_HYP_VA(x) kern_hyp_va(x) +#else +#define KERN_HYP_VA(x) x +#endif =20 - if (!ctxt) - return 0; - - if (ctxt->offset.vm_offset) - offset +=3D *ctxt->offset.vm_offset; - if (ctxt->offset.vcpu_offset) - offset +=3D *ctxt->offset.vcpu_offset; - - return offset; -} +#define timer_get_offset(ctxt) \ + ({ \ + struct arch_timer_context *__ctxt =3D (ctxt); \ + u64 off =3D 0; \ + \ + if (__ctxt) { \ + struct arch_timer_offset *ato =3D &__ctxt->offset;\ + \ + if (ato->vm_offset) \ + off +=3D *KERN_HYP_VA(ato->vm_offset); \ + if (ato->vcpu_offset) \ + off +=3D *KERN_HYP_VA(ato->vcpu_offset); \ + } \ + \ + off; \ + }) =20 static inline void timer_set_offset(struct arch_timer_context *ctxt, u64 o= ffset) { --=20 2.55.0.654.g21b8a5bc05-goog From nobody Tue Sep 29 11:54:19 2026 Received: from mail-wm1-f72.google.com (mail-wm1-f72.google.com [209.85.128.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E670A3B05AF for ; Sat, 8 Aug 2026 08:58:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.72 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179516; cv=none; b=jtQ6RuR4/Bs0q2Msh2/3Vov0xaf+AwGPBil5zID5+cnBHcmL98wevmTxoY2+Y41ngqSZG7/1sjrWylzzDX9ITgqqHIJ2pwsSEePsW12UYgvdxneJrJQd7dufF3KHA908YOkEs+2aDZQLTauFTPxWot6DQ4aeOlg9pYl4tdNhaEI= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179516; c=relaxed/simple; bh=yZk+++kSee3JvNzACwuptz4ROqE71reOY1As/HQTYeY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=aRDfIsFoLkvR6mrorGN/WOp/SGWpd+r9QpKmVCQuGXc+jH4AVv+932lL8tESu2forvK87Sh/F6DatgXlmS1B7ovfINhr9kDc6HMl8OttuPR70puFK1LtvryxvLmJI5Opkzp4mTofxqKuEVA6z0LJKBfOfx/NVqBVhUpUvKM4RxA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=hJqFRdHC; arc=none smtp.client-ip=209.85.128.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="hJqFRdHC" Received: by mail-wm1-f72.google.com with SMTP id 5b1f17b1804b1-4955b84e25eso2516745e9.1 for ; Sat, 08 Aug 2026 01:58:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786179513; x=1786784313; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=56TnglbK1xrAvqmnbHBS7x8Hfawflf/2HSwwBboYSo0=; b=hJqFRdHCSjyl1g389TZ6TEmCI+rl3h01HrP7yaU0iLJw1pD7CMYp+ACgpgyol8FPdy TQtEgmV56ifpGqbc8sJUIgM3pGkxVf66dFykTSy049fVdtPNQ9yokz6fxOUzI2kjkbr2 lcOqGk3MhIH5unwoetY2/vh3s0wxqH/y39qmd3dnzxGSSsAar1Mdx6ren5prfdBc7zEO FMZ4uBMPoYJB+uHXl58/Q1Sll0Ms6S3JGc532RFL7+WPrvwKnCkmxAjWIl5v06HFfOyo EAISuuSE+1J3PZVqYCyxyzdPRm+XSow1alW1ayaGdKj+cYDnIxYNx1v2IDyyXdSEOsxY bD/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786179513; x=1786784313; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=56TnglbK1xrAvqmnbHBS7x8Hfawflf/2HSwwBboYSo0=; b=prrIW+7XxfuWeGkD422KmNM/raa5WcuV9hxweBcZ56eJqy6tWJi65Qz6m24S6HXveo 09iwmq0CE5xtuMZAzEbQQfxnsNYyLAX2OEs70Yx7ny28yOHYGoFknsaTJ/eGy4O9674+ /N7o5tGfdHsW6x4eELeSKm5pkJsb/y1tnwmt9f1fDfyiYaN6qF5kq2M0myoi2t0KVCm0 iahTM8PZMPz74JE4jDjduphWghpNmafy/Qr6myfqx6ylKSlncEClvFbTjjnt9XzwHWG/ q7fUS9j22dJHR82rPibzpBNICf9dNDDsIYt0+dhgLXgj8TUUrFFLfDP6dRtWu5FNNcIF aONg== X-Gm-Message-State: AOJu0Ywu2HW2uZwtV2CubHR5mrbh+bdWexiYM+f4xSv9u091bEC+zWsQ U+7H8l0hjwTpTeEJbx4GTS2MrxOAZD7kIddYesOwQMGE1Fm98iORpdIyyo7blI5w8Bu3aFzQQLB S8EKg576NlkKCd0T8spqfFjGn1UhiU0RH+XyXNnrscrCBZPIb3MaingK6QlsWcRI8DNMMb3ng9/ gqObWaqrJ5IpXhjlbBSxcuYvvin7tu6Kjj3oBKoaljpqp9NGlKij6MaYQ= X-Received: from wrqv10.prod.google.com ([2002:a5d:4b0a:0:b0:47f:586c:8371]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:46cc:b0:493:bd2a:93be with SMTP id 5b1f17b1804b1-4995e085347mr124527135e9.6.1786179512744; Sat, 08 Aug 2026 01:58:32 -0700 (PDT) Date: Sat, 8 Aug 2026 08:58:23 +0000 In-Reply-To: <20260808085824.732659-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260808085824.732659-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.654.g21b8a5bc05-goog Message-ID: <20260808085824.732659-3-smostafa@google.com> Subject: [PATCH v2 2/3] KVM: arm64: Fix timer offsets for non-protected VMs From: Mostafa Saleh To: linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: maz@kernel.org, oupton@kernel.org, seiden@linux.ibm.com, joey.gouly@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, catalin.marinas@arm.com, will@kernel.org, vdonnefort@google.com, tabba@google.com, sebastianene@google.com, keirf@google.com, yaoyuan@linux.alibaba.com, Mostafa Saleh , Sashiko Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" With pKVM, protected VMs always have offset of zero. However, timer offsets for non-protected guests fail to take effect for two reasons: 1) In __timer_enable_traps(), enabling of traps check for is_protected_kvm_enabled() rather than vcpu_is_protected(vcpu) 2) The vcpu timer offsets were never initialised and kept as NULL. This is problematic for cases when the timer is trapped in the hypervisor as the with the case of broken CNTVOFF_EL2, which leads to the hypervisor and host using different offsets and causing VM hangs. This can be confirmed by running the arch_timer selftest which fails: ./arch_timer -o 100000000 Random seed: 0x6b8b4567 Guest assert failed, vcpu 0; stage; 3; iter: 0 =3D=3D=3D=3D Test Assertion Failure =3D=3D=3D=3D arm64/arch_timer.c:137: config_iter + 1 =3D=3D irq_iter pid=3D310 tid=3D312 errno=3D4 - Interrupted system call Guest assert failed, vcpu 3; stage; 3; iter: 0 Guest assert failed, vcpu 1; stage; 3; iter: 0 =3D=3D=3D=3D Test Assertion Failure =3D=3D=3D=3D arm64/arch_timer.c:137: config_iter + 1 =3D=3D irq_iter pid=3D310 tid=3D313 errno=3D4 - Interrupted system call Guest assert failed, vcpu 2; stage; 3; iter: 0 =3D=3D=3D=3D Test Assertion Failure =3D=3D=3D=3D arm64/arch_timer.c:137: config_iter + 1 =3D=3D irq_iter pid=3D310 tid=3D314 errno=3D4 - Interrupted system call [...] After the fix: ./arch_timer -o 100000000 Random seed: 0x6b8b4567 PASS(vCPU-1). PASS(vCPU-3). PASS(vCPU-0). PASS(vCPU-2) Reported-by: Sashiko Fixes: cb0c272acebd ("KVM: arm64: Initialize the hypervisor's VM state at E= L2") Signed-off-by: Mostafa Saleh --- arch/arm64/kvm/hyp/nvhe/pkvm.c | 14 ++++++++++++++ arch/arm64/kvm/hyp/nvhe/timer-sr.c | 6 +++--- 2 files changed, 17 insertions(+), 3 deletions(-) diff --git a/arch/arm64/kvm/hyp/nvhe/pkvm.c b/arch/arm64/kvm/hyp/nvhe/pkvm.c index 24d6f164129a..89f3d5fb55ca 100644 --- a/arch/arm64/kvm/hyp/nvhe/pkvm.c +++ b/arch/arm64/kvm/hyp/nvhe/pkvm.c @@ -529,6 +529,20 @@ static int init_pkvm_hyp_vcpu(struct pkvm_hyp_vcpu *hy= p_vcpu, hyp_vcpu->vcpu.arch.cflags =3D READ_ONCE(host_vcpu->arch.cflags); hyp_vcpu->vcpu.arch.mp_state.mp_state =3D KVM_MP_STATE_STOPPED; =20 + if (!pkvm_hyp_vcpu_is_protected(hyp_vcpu)) { + /* + * Timer offsets are pointing to the untrusted KVM copy, + * which is pinned in __pkvm_init_vm() for the VM life time. + * It is worth noting that hyp_vm->host_kvm points to an EL2 + * linear map address and timer_get_offset() will use + * kern_hyp_va() which is safe as it is idempotent. + */ + vcpu_vtimer(&hyp_vcpu->vcpu)->offset.vm_offset =3D + &hyp_vm->host_kvm->arch.timer_data.voffset; + vcpu_ptimer(&hyp_vcpu->vcpu)->offset.vm_offset =3D + &hyp_vm->host_kvm->arch.timer_data.poffset; + } + ret =3D pkvm_vcpu_init_sysregs(hyp_vcpu); if (ret) goto done; diff --git a/arch/arm64/kvm/hyp/nvhe/timer-sr.c b/arch/arm64/kvm/hyp/nvhe/t= imer-sr.c index ff176f4ce7de..51b4f5010b66 100644 --- a/arch/arm64/kvm/hyp/nvhe/timer-sr.c +++ b/arch/arm64/kvm/hyp/nvhe/timer-sr.c @@ -45,11 +45,11 @@ void __timer_enable_traps(struct kvm_vcpu *vcpu) /* * Disallow physical timer access for the guest * Physical counter access is allowed if no offset is enforced - * or running protected (we don't offset anything in this case). + * or running a protected VM (we don't offset anything in this case). */ clr =3D CNTHCTL_EL1PCEN; - if (is_protected_kvm_enabled() || - !kern_hyp_va(vcpu->kvm)->arch.timer_data.poffset) + if (vcpu_is_protected(vcpu) || + !timer_get_offset(vcpu_ptimer(vcpu))) set |=3D CNTHCTL_EL1PCTEN; else clr |=3D CNTHCTL_EL1PCTEN; --=20 2.55.0.654.g21b8a5bc05-goog From nobody Tue Sep 29 11:54:19 2026 Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3F8303B5311 for ; Sat, 8 Aug 2026 08:58:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179529; cv=none; b=TzExgV5ZxH9LJPBUr5iTpcmnBMazTTYTbcGJ3CzCg1BsvjADbzPLFw+ptJg6c40m/gmXIiSV8FWjgSKgmpr89vXvgCiVim4CzKAyIY7DJEjYe5l+bZXv3nBT7JSO47wWuMEW5gyaZwyRSWlPc50MsbyybXtYZxtCtqUok+Q41qs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786179529; c=relaxed/simple; bh=G4qF8Z3F8YznyvYaSnDICEuJAKLvMzJPHvz7WlvNabM=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=i7nMPLbKkTivsPgs9wkiXck6J7ORvjg5XRx1QDjhXr7kiASYNzYcNgDVAOM98wQjrqdlpTXIUAxiTpzgQLpOn7X4EoxT9ATZ9NbCmHXhglwqpEWK4B4pV1fGvhntoWKKuudqJkkXjabuXVn8TSPDAAYXKTqsl5WHjfCtUG1LiJk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=VxbawsPE; arc=none smtp.client-ip=209.85.128.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--smostafa.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="VxbawsPE" Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-4994aebe932so3855545e9.3 for ; Sat, 08 Aug 2026 01:58:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1786179514; x=1786784314; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jwmzaJ2YawJZB/O6hrcBLYDYP6+Ln0uIsTfu/SId0gY=; b=VxbawsPE8cZAzcp/TTzYfqrn1esWOMMTsu4xVj8uloTR7emZqipf9544H5KAhPGWRs QxWMsuhAhx+90L851fGpHo/5kCPeps0unv/9Ixn0U18VfQQionI2hB5qmw0k5lve08rG 7HgVTtYbs0MSz6qbmCyrUp88oqQcb7kQznmxKLB5VAvvzcyXyNWYA/GGjQLKxYeJbcx5 dcRA6gcDelYmPs2PAYiAmd9q7TzldR5o3nDuyyuj35kOqo0XUBJnhfESr6H+e9VeH6pd GFbgS6EB/4hDT4BaXxnpOlRPmBtsOTBrPr/6l7PgHWkJNRNXbk3tO8poIggY9/ngMjkh wilQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786179514; x=1786784314; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jwmzaJ2YawJZB/O6hrcBLYDYP6+Ln0uIsTfu/SId0gY=; b=Av1b17o9ylMGpXYaeig7qbxVrLJnVD1pmbLTBnmhNfu/fift5mkrhjTxsGivoOJw0q RDw/PTdOpnMYPz9eK09Kf9OnwVEWxzh2UXCxBo1J4KuHBRyO/v0db/UbOD+HU73egOgF 58YF5CjdVnhD4hwkkWjm1EFEbe3Orw8ClC3gU5v938RCwF+gy75LJWV6QLDcjTcJ4vJ+ wiAGoDLjSgZ8YCTixXQnqBjPlrW/+bfIdM7N8p2BraRreeQfMvSaIuXrPciz6ZYxoT/C Hi6i6JDY3ziQPjpSR+2I+eD0ytfOFJ+E4TTgZr1cAA3Rrjftd3x8NVTL8v1/CX0nIZde 6n5Q== X-Gm-Message-State: AOJu0YznjFEie4GpjfT+IZhJU6qBaS7HvpK3T6pCaAZ0KdaflXxn8V/j mvlIxXRoYtqEqlZDlHdMBP83uwKdM8xp2wcz1d5WQN9WYCrdc/We163cjw0aT/6lhuAr3XzwxKc m+dNeT/HN8Z7i5JWg33MU1NqDOKRRgYvihfznn8x3KHTcrgkqaIIjrvrTCvsjBds8t+60yMExlX oULrh0Oigkhqae+j2UomTjE3kid4Pbew3xmg20RVUPyeX7GoeECFn4hbo= X-Received: from wmdd13.prod.google.com ([2002:a05:600c:a20d:b0:493:b301:e269]) (user=smostafa job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:620e:b0:495:6274:56c2 with SMTP id 5b1f17b1804b1-4994e70a6f5mr464694635e9.2.1786179514030; Sat, 08 Aug 2026 01:58:34 -0700 (PDT) Date: Sat, 8 Aug 2026 08:58:24 +0000 In-Reply-To: <20260808085824.732659-1-smostafa@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260808085824.732659-1-smostafa@google.com> X-Mailer: git-send-email 2.55.0.654.g21b8a5bc05-goog Message-ID: <20260808085824.732659-4-smostafa@google.com> Subject: [PATCH v2 3/3] KVM: arm64: Fix hvhe and broken CNTVOFF_EL2 From: Mostafa Saleh To: linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org Cc: maz@kernel.org, oupton@kernel.org, seiden@linux.ibm.com, joey.gouly@arm.com, suzuki.poulose@arm.com, yuzenghui@huawei.com, catalin.marinas@arm.com, will@kernel.org, vdonnefort@google.com, tabba@google.com, sebastianene@google.com, keirf@google.com, yaoyuan@linux.alibaba.com, Mostafa Saleh , Fuad Tabba Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When running on a setup affected with broken CNTVOFF_EL2 (has_broken_cntvoff()) Booting with VHE or protected mode(nvhe) (id_aa64mmfr1.vh=3D0 and arm64_sw.hvhe=3D0) works fine. However launching a protected VM with protected hvhe mode panics the guest kernel: [ 0.000000] Internal error: Oops - Undefined instruction: 00000000000000= 00 [#1] SMP [ 0.000000] Modules linked in: [ 0.000000] CPU: 0 UID: 0 PID: 0 Comm: swapper/0 Not tainted 7.2.0-rc3-g= 05f75bd71e0e-dirty #29 PREEMPT [ 0.000000] Hardware name: linux,dummy-virt (DT) [ 0.000000] pstate: 000003c5 (nzcv DAIF -PAN -UAO -TCO -DIT -SSBS BTYPE= =3D--) [ 0.000000] pc : arch_timer_shutdown_virt+0x4/0x1c [ 0.000000] lr : arch_timer_starting_cpu+0x1c4/0x2d4 [ 0.000000] sp : ffffa6bd9a193c00 [ 0.000000] x29: ffffa6bd9a193c20 x28: ffffa6bd9a1bcf88 x27: 00000000000= 00000 [ 0.000000] x26: ffff00001be70dd8 x25: ffffa6bd99d85000 x24: ffffa6bd99d= 85ee4 [ 0.000000] x23: ffffa6bd99d85000 x22: ffffa6bd9a1499c0 x21: ffffa6bd9a1= ab900 [ 0.000000] x20: 00ffffffffffffff x19: ffff00001be8b600 x18: 00000000000= 0028c [ 0.000000] x17: 00000000510f0010 x16: 00000000510f0010 x15: 00000000500= f0000 [ 0.000000] x14: 0000000000000000 x13: 0000000000000000 x12: 00000000000= 00018 [ 0.000000] x11: ffffa6bd9a8ac000 x10: 0000000000f0000f x9 : fffffffffff= fffff [ 0.000000] x8 : ffffa6bd98822e18 x7 : 0070752d65746174 x6 : 00111ff76e0= 07261 [ 0.000000] x5 : ffffa6bd9ad68078 x4 : 0000000000000000 x3 : ffffa6bd988= 22a0c [ 0.000000] x2 : 0000000000000073 x1 : 0000000000000001 x0 : ffff00001be= 8b600 [ 0.000000] Call trace: [ 0.000000] arch_timer_shutdown_virt+0x4/0x1c (P) [ 0.000000] cpuhp_invoke_callback+0x11c/0x280 [ 0.000000] cpuhp_issue_call+0x1e8/0x224 [ 0.000000] __cpuhp_setup_state_cpuslocked+0x1d8/0x2b8 [ 0.000000] __cpuhp_setup_state+0x50/0x74 [ 0.000000] arch_timer_register+0xc0/0x148 [ 0.000000] arch_timer_of_init+0x148/0x170 [ 0.000000] timer_probe+0x74/0x124 [ 0.000000] time_init+0x18/0x58 [ 0.000000] start_kernel+0x1c0/0x3ac [ 0.000000] __primary_switched+0x88/0x90 [ 0.000000] Code: c80b7d2a 35ffffab 17ffffeb d503245f (d53be328) The workaround avoids setting non-zero CNTVOFF_EL2 and trapping the virtual counter to emulate the offset. In the VHE path (timer_set_traps()), traps are only enabled when the guest actually has a non-zero virtual timer offset. However, __timer_enable_traps() in hyp/nvhe/timer-sr.c unconditionally set CNTHCTL_EL1TVT and CNTHCTL_EL1TVCT whenever has_broken_cntvoff() was true. Which causes 2 issues: 1) Protected VMs: kvm_handle_pvm_sysreg() does not find "cntv_ctl_el0" in pvm_sys_reg_descs and injects undefined instruction exceptions. 2) non-protected guests are trapped all the time even with offset of zero. Fix this by adding a check in __timer_enable_traps() similar to the one in timer_set_traps() Fixes: 0bc9a9e85fcf ("KVM: arm64: Work around x1e's CNTVOFF_EL2 bogosity") Signed-off-by: Marc Zyngier Reviewed-by: Yuan Yao Reviewed-by: Fuad Tabba Tested-by: Fuad Tabba Signed-off-by: Mostafa Saleh --- arch/arm64/kvm/hyp/nvhe/timer-sr.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/arch/arm64/kvm/hyp/nvhe/timer-sr.c b/arch/arm64/kvm/hyp/nvhe/t= imer-sr.c index 51b4f5010b66..993065716913 100644 --- a/arch/arm64/kvm/hyp/nvhe/timer-sr.c +++ b/arch/arm64/kvm/hyp/nvhe/timer-sr.c @@ -61,9 +61,9 @@ void __timer_enable_traps(struct kvm_vcpu *vcpu) =20 /* * Trap the virtual counter/timer if we have a broken cntvoff - * implementation. + * implementation and non zero offset as in timer_set_traps() */ - if (has_broken_cntvoff()) + if (has_broken_cntvoff() && timer_get_offset(vcpu_vtimer(vcpu))) set |=3D CNTHCTL_EL1TVT | CNTHCTL_EL1TVCT; =20 sysreg_clear_set(cnthctl_el2, clr, set); --=20 2.55.0.654.g21b8a5bc05-goog