Re: [PATCH v4 5/6] KVM: arm64: Add HDBSS fault handling and buffer flush
From: Tian Zheng
Date: Tue Jul 14 2026 - 09:28:50 EST
On 7/14/2026 6:50 PM, Leonardo Bras wrote:
On Tue, Jul 14, 2026 at 03:38:39PM +0800, Tian Zheng wrote:
On 7/13/2026 10:06 PM, Leonardo Bras wrote:Got it :)
On Thu, Jul 09, 2026 at 06:40:25PM +0800, Tian Zheng wrote:
From: eillon <yezhenyu2@xxxxxxxxxx>This will return a long, which will be casted as bool.
Add HDBSS fault handling for buffer full, external abort, and general
protection fault (GPF) events. When the HDBSS buffer becomes full,
the hardware traps to EL2 with an HDBSSF event, which is handled by
setting a flush request.
Add kvm_flush_hdbss_buffer() to consume HDBSS buffer entries and
propagate dirty information into the userspace-visible dirty bitmap.
Flush is triggered on vcpu_put, check_vcpu_requests, and
sync_dirty_log.
Add esr_iss2_is_hdbssf() helper for HDBSS fault detection in guest
abort handling.
Signed-off-by: Eillon <yezhenyu2@xxxxxxxxxx>
Signed-off-by: Tian Zheng <zhengtian10@xxxxxxxxxx>
---
arch/arm64/include/asm/esr.h | 5 +++
arch/arm64/include/asm/kvm_dirty_bit.h | 11 +++++
arch/arm64/include/asm/kvm_host.h | 1 +
arch/arm64/kvm/arm.c | 14 ++++++
arch/arm64/kvm/dirty_bit.c | 62 ++++++++++++++++++++++++++
arch/arm64/kvm/mmu.c | 4 ++
6 files changed, 97 insertions(+)
diff --git a/arch/arm64/include/asm/esr.h b/arch/arm64/include/asm/esr.h
index 81c17320a588..2e6b679b5908 100644
--- a/arch/arm64/include/asm/esr.h
+++ b/arch/arm64/include/asm/esr.h
@@ -437,6 +437,11 @@
#ifndef __ASSEMBLER__
#include <asm/types.h>
+static inline bool esr_iss2_is_hdbssf(unsigned long esr)
+{
+ return ESR_ELx_ISS2(esr) & ESR_ELx_HDBSSF;
In general, what I see in the kernel is something like:
return !!(ESR_ELx_ISS2(esr) & ESR_ELx_HDBSSF)
ok!
In kvm_arm_enable_hdbss_global(), we explicitly check and reject HDBSS+}You mention that it does not support dirty-ring, but above function will
+
static inline unsigned long esr_brk_comment(unsigned long esr)
{
return esr & ESR_ELx_BRK64_ISS_COMMENT_MASK;
diff --git a/arch/arm64/include/asm/kvm_dirty_bit.h b/arch/arm64/include/asm/kvm_dirty_bit.h
index 84b12f0a10af..4b28000e972f 100644
--- a/arch/arm64/include/asm/kvm_dirty_bit.h
+++ b/arch/arm64/include/asm/kvm_dirty_bit.h
@@ -10,7 +10,18 @@
#include <asm/kvm_pgtable.h>
#include <asm/sysreg.h>
+/* HDBSS entry field definitions */
+#define HDBSS_ENTRY_VALID BIT(0)
+#define HDBSS_ENTRY_TTWL_SHIFT (1)
+#define HDBSS_ENTRY_TTWL_MASK (GENMASK(3, 1))
+#define HDBSS_ENTRY_TTWL(x) \
+ (((x) << HDBSS_ENTRY_TTWL_SHIFT) & HDBSS_ENTRY_TTWL_MASK)
+#define HDBSS_ENTRY_TTWL_RESV HDBSS_ENTRY_TTWL(-4)
+#define HDBSS_ENTRY_IPA GENMASK_ULL(55, 12)
+
int kvm_arm_vcpu_alloc_hdbss(struct kvm_vcpu *vcpu, unsigned int order);
void kvm_arm_vcpu_free_hdbss(struct kvm_vcpu *vcpu);
+void kvm_flush_hdbss_buffer(struct kvm_vcpu *vcpu);
+int kvm_handle_hdbss_fault(struct kvm_vcpu *vcpu);
#endif /* __ARM64_KVM_DIRTY_BIT_H__ */
diff --git a/arch/arm64/include/asm/kvm_host.h b/arch/arm64/include/asm/kvm_host.h
index c41ec6d9c45a..cecfb884a64f 100644
--- a/arch/arm64/include/asm/kvm_host.h
+++ b/arch/arm64/include/asm/kvm_host.h
@@ -55,6 +55,7 @@
#define KVM_REQ_GUEST_HYP_IRQ_PENDING KVM_ARCH_REQ(9)
#define KVM_REQ_MAP_L1_VNCR_EL2 KVM_ARCH_REQ(10)
#define KVM_REQ_VGIC_PROCESS_UPDATE KVM_ARCH_REQ(11)
+#define KVM_REQ_FLUSH_HDBSS KVM_ARCH_REQ(12)
#define KVM_DIRTY_LOG_MANUAL_CAPS (KVM_DIRTY_LOG_MANUAL_PROTECT_ENABLE | \
KVM_DIRTY_LOG_INITIALLY_SET)
diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index bf6688245d83..566953a4e23a 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -755,6 +755,9 @@ void kvm_arch_vcpu_put(struct kvm_vcpu *vcpu)
kvm_vcpu_put_hw_mmu(vcpu);
kvm_arm_vmid_clear_active();
+ if (vcpu->kvm->arch.enable_hdbss)
+ kvm_flush_hdbss_buffer(vcpu);
+
vcpu_clear_on_unsupported_cpu(vcpu);
vcpu->cpu = -1;
}
@@ -1157,6 +1160,9 @@ static int check_vcpu_requests(struct kvm_vcpu *vcpu)
if (kvm_dirty_ring_check_request(vcpu))
return 0;
+ if (kvm_check_request(KVM_REQ_FLUSH_HDBSS, vcpu))
+ kvm_flush_hdbss_buffer(vcpu);
+
check_nested_vcpu_requests(vcpu);
}
@@ -1971,7 +1977,15 @@ long kvm_arch_vcpu_unlocked_ioctl(struct file *filp, unsigned int ioctl,
void kvm_arch_sync_dirty_log(struct kvm *kvm, struct kvm_memory_slot *memslot)
{
+ /*
+ * Flush all CPUs' dirty log buffers to the dirty_bitmap. Called
+ * before reporting dirty_bitmap to userspace. Send a request with
+ * KVM_REQUEST_WAIT to flush buffer synchronously.
+ */
+ if (!kvm->arch.enable_hdbss)
+ return;
+ kvm_make_all_cpus_request(kvm, KVM_REQ_FLUSH_HDBSS | KVM_REQUEST_WAIT);
}
static int kvm_vm_ioctl_set_device_addr(struct kvm *kvm,
diff --git a/arch/arm64/kvm/dirty_bit.c b/arch/arm64/kvm/dirty_bit.c
index 6c7a6ef66b5a..002366337637 100644
--- a/arch/arm64/kvm/dirty_bit.c
+++ b/arch/arm64/kvm/dirty_bit.c
@@ -50,3 +50,65 @@ void kvm_arm_vcpu_free_hdbss(struct kvm_vcpu *vcpu)
vcpu->arch.hdbss.hdbssbr_el2 = 0;
}
+
+void kvm_flush_hdbss_buffer(struct kvm_vcpu *vcpu)
+{
+ int idx, curr_idx;
+ u64 *hdbss_buf;
+ struct kvm *kvm = vcpu->kvm;
+
+ if (!kvm->arch.enable_hdbss)
+ return;
+
+ curr_idx = HDBSSPROD_IDX(read_sysreg_s(SYS_HDBSSPROD_EL2));
+
+ /* Do nothing if HDBSS buffer is empty or br_el2 is NULL */
+ if (curr_idx == 0 || vcpu->arch.hdbss.hdbssbr_el2 == 0)
+ return;
+
+ hdbss_buf = page_address(phys_to_page(vcpu->arch.hdbss.base_phys));
+ if (!hdbss_buf)
+ return;
+
+ guard(write_lock_irqsave)(&vcpu->kvm->mmu_lock);
+ for (idx = 0; idx < curr_idx; idx++) {
+ u64 gpa;
+
+ gpa = hdbss_buf[idx];
+ if (!(gpa & HDBSS_ENTRY_VALID))
+ continue;
+
+ gpa &= HDBSS_ENTRY_IPA;
+ kvm_vcpu_mark_page_dirty(vcpu, gpa >> PAGE_SHIFT);
mark the page as dirty in the dirty-ring :/
enablement if dirty-ring is active:
```
if (kvm->dirty_ring_size)
return 0;
```
So when kvm_flush_hdbss_buffer() runs (which requires enable_hdbss = true),
we know for certain that
kvm->dirty_ring_size == 0. Therefore, kvm_vcpu_mark_page_dirty() will always
take the dirty_bitmap path,
never the dirty-ring path.
That said, I'll add a comment in kvm_flush_hdbss_buffer() before dirty ring
mode is supported, to make this explicit:
```
/*
* HDBSS is mutually exclusive with dirty-ring mode (see
* kvm_arm_enable_hdbss_global()), so kvm_vcpu_mark_page_dirty()
* will update the dirty_bitmap, not the dirty-ring.
*/
```
Out of curiosity: which issues have you found on supporting dirty-ring at
this point?
Thanks!
Leo
I haven't looked deeply into dirty-ring yet — my main concern is that if both the dirty
ring and HDBSS buffer fill up, the flush path might get blocked or complicated.
For now, I'm planning to match the HDBSS buffer size to the dirty ring size in v5 and test it.
Ideally, the two buffers would be the same size, and the entire dirty tracking path would use
HDBSS exclusively — no fallback to the legacy dirty bitmap path. If that works, I think this approach should be fine.
Let me know if you have any insights on dirty ring's full-buffer behavior — that would be helpful.