From nobody Sat Sep 26 12:28:31 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F34A248A8B1 for ; Tue, 1 Sep 2026 17:42:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788284524; cv=none; b=fChnPl9YWBVDXNa7xNjp+HP7K102xYQxDpspgC4ZlaYMiPPJ9arB/SzdE2WHONwB6qCOmNhOUFTK3+lxwEPtpJBfNB6UG/sKHgs9ZSMky1oZV2H/ZjaO7Mf+jca8y87kxgNKZm+xUTW1lqeDtVa6grUJa+cPjXc/pBZ2WYsb1no= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788284524; c=relaxed/simple; bh=Knciy0bo+UDETfe3BdK54qzwNZE0tRYeqpiCo6ccnoE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Zc7pVx2aPP5PpNRhFFwp/vrHwk+Mar7qpa+g1bo82/rQA+eONuGNr+9n/dv6+C0JaL+hPBJeRWEMO2TJYjy1PyI0A6fUl/KlaD4Vo4jHoxRUHvnew7EjZxuHkYSwtZWSgqLfegYQEQZoClSKT0DJQfLdVzhlMbi+WUSj5vuZlC4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UNBohxKx; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UNBohxKx" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4FA841F00A3A; Tue, 1 Sep 2026 17:42:01 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788284522; bh=ksh6yFu5bGeGsVFMN4yVIVHUeG1qltYeUrXjTEtnYDU=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=UNBohxKx031T6Gsy3Qow83SSr1CIrgtJM9eTn6QybCiY9JBHKqi4nVLBiilQWlxGM dDM5zpu3IsW/oY+fvOAMY7NkUutFV1c7TTwPRCGdmspQzH/r0/uhdiCGB9faCPPcOb vyY018HCY1o8v4REP7TTLE8BnTB62SD4ahDHwNLROfLVgX5Lg59ji/RuZ3TxbMFW8h n30DovXMLmi2Sv5CNcy8NGnmqbNtfgNbxM0AqeVsf9WO1l7r7kan1lNG1HBwXNB+0p ReU+x+Mi3xpPpen3PY18SmdC/k3GABeDZzY6aVnmJxHUPK6bSunuLd9b45KX66ZYkB 84HtZb4mXsn0w== From: Mark Brown Date: Tue, 01 Sep 2026 18:38:41 +0100 Subject: [PATCH v11 1/2] arm64/fpsimd: Suppress SVE access traps when loading FPSIMD state Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-arm64-sve-trap-mitigation-v11-1-be8095543a46@kernel.org> References: <20260901-arm64-sve-trap-mitigation-v11-0-be8095543a46@kernel.org> In-Reply-To: <20260901-arm64-sve-trap-mitigation-v11-0-be8095543a46@kernel.org> To: Catalin Marinas , Will Deacon Cc: Mark Rutland , Ryan Roberts , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Mark Brown X-Mailer: b4 0.17-dev X-Developer-Signature: v=1; a=openpgp-sha256; l=7374; i=broonie@kernel.org; h=from:subject:message-id; bh=Knciy0bo+UDETfe3BdK54qzwNZE0tRYeqpiCo6ccnoE=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBqlw5krBQhZFScWiUEOg0+EM5IWyW3WHdFiKhQo JocRL8RcuOJATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCapcOZAAKCRAk1otyXVSH 0JFYB/0R75XVtd0k+rhrWUr5crGapvqJiKYcOY2RkXEP8xhMApPNoFdsVkuQ86iFbhQ8bgIH5iM iZQ48MkUlQ/qyt1JVy6l2odx/SULgTNY3ZqzDGmFdHe/olRTkO5zlmabwesx3AmSYZH8jywlQhX /4oOBVqbMFrTuHy3bisNvV7lvW8IaV7EEqfQx56xFEw+xH2Fu4UpEa/kKzQrWFybLXkznqdj2ie lfpkce6dSdBWG/1z5a3gwkABrBtCfc50CKRBaoDFDTWWB9sOYKe3Em9Jk96v6UPzoleWZs1s426 iIca8uiBQbmifyH8lE7sYwk3PGfFfyWL3pqNJPjc0qE5/7iC X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB When we are in a syscall we take the opportunity to discard the SVE state, saving only the FPSIMD subset of the register state. If we have to reload the floating point state from memory then we reenable SVE access traps, stopping tracking SVE until the task uses SVE again at which point it will take another SVE access trap. This means that for a task which is actively using SVE and also doing many blocking system calls will have the additional overhead of SVE access traps. The use of SVE for applications like memcpy() means that frequent SVE usage is common with modern distributions, even with tasks that do not obviously use floating point. I did some instrumentation which counted the number of SVE access traps and the number of times we loaded FPSIMD only register state for each task. Testing with Debian Bookworm this showed that during boot the overwhelming majority of tasks triggered another SVE access trap more than 50% of the time after loading FPSIMD only state with a substantial number near 100%, though some programs had a very small number of SVE accesses most likely from startup. There were few tasks in the range 5-45%, most tasks either used SVE frequently or used it only a tiny proportion of times. As expected older distributions which do not have the SVE performance work available showed no SVE usage in general applications. This indicates that there should be some benefit from reducing the number of SVE access traps for blocking system calls like we did for non blocking system calls in commit 8c845e273104 ("arm64/sve: Leave SVE enabled on syscall if we don't context switch"). Let's do this with a timeout, when we take a SVE access trap record a jiffies after which we'll reeanble SVE traps and then check this whenever we load a FPSIMD only floating point state from memory. If the time has passed then we reenable traps, otherwise we leave traps disabled and flush the non-shared register state like we would on trap. The timeout is currently set to a second, I pulled this number out of thin air so there is doubtless some room for tuning. This means that for a task which is actively using SVE the number of SVE access traps will be equivalent or reduced but applications which use SVE only very infrequently will avoid the overheads associated with tracking SVE state after a second. The extra cost from additional tracking of SVE state only occurs when a task is preempted so short running tasks should be minimally affected. As would be expected fp-pidbench shows minimal change from this patch, it does not block and on a quiet system is unlikely to see it's state reloaded from memory. There should be no functional change resulting from this, it is purely a performance optimisation. Signed-off-by: Mark Brown --- arch/arm64/include/asm/fpsimd.h | 15 ++++++++---- arch/arm64/include/asm/processor.h | 1 + arch/arm64/kernel/fpsimd.c | 47 ++++++++++++++++++++++++++++++++--= ---- 3 files changed, 51 insertions(+), 12 deletions(-) diff --git a/arch/arm64/include/asm/fpsimd.h b/arch/arm64/include/asm/fpsim= d.h index a67d5774e672..bce70a2a6d1e 100644 --- a/arch/arm64/include/asm/fpsimd.h +++ b/arch/arm64/include/asm/fpsimd.h @@ -332,6 +332,15 @@ static inline void sve_load_state(const struct arm64_s= ve_state *state, bool ffr) __sve_load_p(state, vl, ffr); } =20 +static inline void sve_flush_p(void) +{ + asm volatile( + __SVE_PREAMBLE + FOR_EACH_P_REG("n", "pfalse p\\n\\().b") + " wrffr p0.b\n" + ); +} + /* * Zero all SVE registers except for the first 128 bits of each vector. * @@ -349,11 +358,7 @@ static inline void sve_flush_live(void) ); } =20 - asm volatile( - __SVE_PREAMBLE - FOR_EACH_P_REG("n", "pfalse p\\n\\().b") - " wrffr p0.b\n" - ); + sve_flush_p(); } =20 struct arm64_cpu_capabilities; diff --git a/arch/arm64/include/asm/processor.h b/arch/arm64/include/asm/pr= ocessor.h index 6dfbcacd9ba0..0ff743440336 100644 --- a/arch/arm64/include/asm/processor.h +++ b/arch/arm64/include/asm/processor.h @@ -169,6 +169,7 @@ struct thread_struct { unsigned int fpsimd_cpu; struct arm64_sve_state *sve_state; /* SVE registers, if any */ struct arm64_sme_state *sme_state; /* ZA and ZT state, if any */ + unsigned long sve_timeout; /* jiffies to drop TIF_SVE */ unsigned int vl[ARM64_VEC_MAX]; /* vector length */ unsigned int vl_onexec[ARM64_VEC_MAX]; /* vl after next exec */ unsigned long fault_address; /* fault info */ diff --git a/arch/arm64/kernel/fpsimd.c b/arch/arm64/kernel/fpsimd.c index e7f1682a3059..32e3d43c6e76 100644 --- a/arch/arm64/kernel/fpsimd.c +++ b/arch/arm64/kernel/fpsimd.c @@ -370,18 +370,11 @@ static void task_fpsimd_load(void) if (system_supports_sve() || system_supports_sme()) { switch (current->thread.fp_type) { case FP_STATE_FPSIMD: - /* Stop tracking SVE for this task until next use. */ - clear_thread_flag(TIF_SVE); break; case FP_STATE_SVE: if (!thread_sm_enabled(¤t->thread)) WARN_ON_ONCE(!test_and_set_thread_flag(TIF_SVE)); =20 - if (test_thread_flag(TIF_SVE)) { - unsigned long vq =3D sve_vq_from_vl(task_get_sve_vl(current)); - sysreg_clear_set_s(SYS_ZCR_EL1, ZCR_ELx_LEN, vq - 1); - } - restore_sve_regs =3D true; restore_ffr =3D true; break; @@ -400,6 +393,15 @@ static void task_fpsimd_load(void) } } =20 + /* + * If SVE has been enabled we may keep it enabled even if + * loading only FPSIMD state, so always set the VL. + */ + if (system_supports_sve() && test_thread_flag(TIF_SVE)) { + unsigned long vq =3D sve_vq_from_vl(task_get_sve_vl(current)); + sysreg_clear_set_s(SYS_ZCR_EL1, ZCR_ELx_LEN, vq - 1); + } + /* Restore SME, override SVE register configuration if needed */ if (system_supports_sme()) { unsigned long sme_vl =3D task_get_sme_vl(current); @@ -430,6 +432,30 @@ static void task_fpsimd_load(void) } else { WARN_ON_ONCE(current->thread.fp_type !=3D FP_STATE_FPSIMD); fpsimd_load_state(¤t->thread.uw.fpsimd_state); + + /* + * If the task had been using SVE we keep it enabled + * when loading FPSIMD only state for a period to + * minimise overhead for tasks actively using SVE, + * disabling it periodicaly to ensure that tasks that + * use SVE intermittently do eventually avoid the + * overhead of carrying SVE state. The timeout is + * initialised when we take a SVE trap in do_sve_acc(). + */ + if (system_supports_sve() && test_thread_flag(TIF_SVE)) { + if (time_after(jiffies, current->thread.sve_timeout)) { + clear_thread_flag(TIF_SVE); + sve_user_disable(); + } else { + /* + * Loading V will have flushed the + * rest of the Z register, SVE is + * enabled at EL1 and VL was set + * above. + */ + sve_flush_p(); + } + } } } =20 @@ -1324,6 +1350,13 @@ void do_sve_acc(unsigned long esr, struct pt_regs *r= egs) =20 get_cpu_fpsimd_context(); =20 + /* + * We will keep SVE enabled when loading FPSIMD only state for + * the next second to minimise traps when userspace is + * actively using SVE. + */ + current->thread.sve_timeout =3D jiffies + HZ; + if (test_and_set_thread_flag(TIF_SVE)) WARN_ON(1); /* SVE access shouldn't have trapped */ =20 --=20 2.47.3 From nobody Sat Sep 26 12:28:31 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CFEA648AE39 for ; Tue, 1 Sep 2026 17:42:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788284526; cv=none; b=rr9aGRoz9mTKZyhFc9M0LkiQz6ixY7OpaPkGBgCHDy3J9trFyCMrHQF9LtmFGq0q9jfpJidWzbTp52n/rsDPpS/TlFW5UjXuWmXSBo3afmvTNut71D7uiszTVCDFWq9QDtNsDT3vRhJKdF5Tc34BwqpXZ33Oi/WyPm3JGEBwTpY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1788284526; c=relaxed/simple; bh=28ej9lX6BTa8SavizmAaCMmgCQFPdsywzv1lKDVkBbQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=M8h6gs4yKE3T6zC+tNvK3wYhWGVUgV2ybqV5hWz8eLMbCdzw6NQufcrEVr+5BwKXegr+rtPDmftlcJgjAqYSC6m6kzYVSC7hXfoSqam/QtKaUyZX0ilERA1eKdVcMWIluGPw+QQ+yVe1vG7ey3Vtkn47vLgG9RAxhXfEieDhTSg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UO6SaejV; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UO6SaejV" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 1D4551F000E9; Tue, 1 Sep 2026 17:42:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1788284524; bh=QHCoVKDwev31CZRQgniIkI3MubB2o6wMEg0d+8Q2S+0=; h=From:Date:Subject:References:In-Reply-To:To:Cc; b=UO6SaejVNgcQzvC5/BZJaDHJ7aLmqg/7YjrsXM9qGV2ZGgLYQ2pzLgLIgOBSJM6zd oQSBdXyof/2Huf41qiaVlNmJMCWAR+5Kk2IVmf84ykntKNRW5MNOAoLh5H7oTWzPkR gVfZodXqMi0Ft1uoJkwXjpnPSE2bU8NQbPFI/i5K1xz2eMbY6zwsM79l4/Jz6PTMJK J14uTqM7BU5gKsWQz2/FgIiCFNM10njjQzKSTQpL4eoNspRao1vaknUhA/wwx+RBUt 5stkoSijDPV4Cekne5FBbauGUzwgcTEtjqmU82i6hpE1rWcD5TK4lZ20nm/YavYNLL HKZSF+iNuUqww== From: Mark Brown Date: Tue, 01 Sep 2026 18:38:42 +0100 Subject: [PATCH v11 2/2] arm64/sve: Disable TIF_SVE on syscall once per second Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260901-arm64-sve-trap-mitigation-v11-2-be8095543a46@kernel.org> References: <20260901-arm64-sve-trap-mitigation-v11-0-be8095543a46@kernel.org> In-Reply-To: <20260901-arm64-sve-trap-mitigation-v11-0-be8095543a46@kernel.org> To: Catalin Marinas , Will Deacon Cc: Mark Rutland , Ryan Roberts , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Mark Brown X-Mailer: b4 0.17-dev X-Developer-Signature: v=1; a=openpgp-sha256; l=2616; i=broonie@kernel.org; h=from:subject:message-id; bh=28ej9lX6BTa8SavizmAaCMmgCQFPdsywzv1lKDVkBbQ=; b=owEBbQGS/pANAwAKASTWi3JdVIfQAcsmYgBqlw5kwTcSK4+P1IfePYLoFIca4cm3IuwS2ecaw 2V2ztIVGBeJATMEAAEKAB0WIQSt5miqZ1cYtZ/in+ok1otyXVSH0AUCapcOZAAKCRAk1otyXVSH 0CJdB/9sv51gCXyxJkI/luXlMaw2mdmESC8ijFo7ANiG+trh1UAzYTdwBzy7wbnXsV9C0hn6trO kFQbXwXKtUJN0OkML0jbysWxI8SEvIhfIYC5JMwAqcbLO7eAGEDOld2p2vi77wG3oOf9qFfI0YI IsA6BFPFzg3fQhbnY48ohCEUF7xc0QiaaVMUGrxs240XvwFfw2vYWFtW6XWNCtJPN4Rcna/pJAx dCxGPhie3m3/hgpHo6x3dJKAMSAvW8Rt+Z50xAONC1qhAWjnSU/BbIScbmultToUXtyKktsJK9F 0mV8jRmUJfo5+CIU4UeKlIvK9KoVy/iofcXsxN/UXE/ewPbh X-Developer-Key: i=broonie@kernel.org; a=openpgp; fpr=3F2568AAC26998F9E813A1C5C3F436CA30F5D8EB Our syscall ABI requires that when performing a syscall the portions of the Z registers not shared with the V registers, the P and FFR registers are reset to 0. Since we have no way of monitoring EL0 SVE usage this is implemented by changing the in register values on every syscall for tasks which have SVE enabled, for systems with 128 bit SVE vector lengths this has been benchmarked as a 6% overhead. We currently support disabling SVE for userspace tasks when loading the floating point state from memory during a syscall, allowing tasks that use SVE infrequently to avoid this overhead, but this may not help CPU bound tasks if they are not fortunate enough to block or be scheduled during a syscall. This is done whenever the state is loaded from a second after the last time the task generate a SVE access trap. Extend this mechanism to also apply during syscall entry, disabling SVE instead of flushing the live registers when we perform a syscall a second after the last time a SVE access trap was taken. This adds an additional memory access and branch for tasks using SVE and means that CPU bound tasks actively using SVE will take extra SVE access traps (at most one per second) but will allows CPU bound tasks that infrequently use SVE to avoid the overhead of flushing the registers on syscall. On a system with 128 bit SVE vectors fp-pidbench shows a roughly 4.5% improvement compared to baseline after having used SVE, for a roughly 0.4% overhead when SVE is used between each syscall. Obviously this is very much a microbenchmark. This is purely a performance optimisation, there should be no functional change. Signed-off-by: Mark Brown --- arch/arm64/kernel/entry-common.c | 15 +++++++++++++-- 1 file changed, 13 insertions(+), 2 deletions(-) diff --git a/arch/arm64/kernel/entry-common.c b/arch/arm64/kernel/entry-com= mon.c index 72c03ccea59f..475c22e103fb 100644 --- a/arch/arm64/kernel/entry-common.c +++ b/arch/arm64/kernel/entry-common.c @@ -274,8 +274,19 @@ static inline void fpsimd_syscall_enter(void) if (!system_supports_sve()) return; =20 - if (test_thread_flag(TIF_SVE)) - sve_flush_live(); + if (test_thread_flag(TIF_SVE)) { + /* + * Ensure that tasks that don't block in a syscall + * also get a chance to drop TIF_SVE. + */ + if (unlikely(time_after(jiffies, + current->thread.sve_timeout))) { + clear_thread_flag(TIF_SVE); + sve_user_disable(); + } else { + sve_flush_live(); + } + } =20 /* * Any live non-FPSIMD SVE state has been zeroed. Allow --=20 2.47.3