[PATCH v7 01/24] KVM: arm64: Add a generic clock
From: Mostafa Saleh
Date: Wed Jul 15 2026 - 08:00:19 EST
IOMMU drivers need to track time, mainly for timeouts.
Add 2 new functions to nvhe/clock.c:
- hyp_clock_init(): Get the system timer frequency at boot
- hyp_clock_ns(): Get current time in nano seconds.
This is mainly used for timeouts, so a malicious host can DoS the
system or cause premature timeouts which likely end up in hyp panic,
that should be acceptable as neither of those would undermine the
security guarantees.
Signed-off-by: Mostafa Saleh <smostafa@xxxxxxxxxx>
---
arch/arm64/kvm/hyp/include/nvhe/clock.h | 3 +++
arch/arm64/kvm/hyp/nvhe/Makefile | 4 ++--
arch/arm64/kvm/hyp/nvhe/clock.c | 29 +++++++++++++++++++++++++
arch/arm64/kvm/hyp/nvhe/setup.c | 5 +++++
4 files changed, 39 insertions(+), 2 deletions(-)
diff --git a/arch/arm64/kvm/hyp/include/nvhe/clock.h b/arch/arm64/kvm/hyp/include/nvhe/clock.h
index ae03ec6965af..7ef982939bf9 100644
--- a/arch/arm64/kvm/hyp/include/nvhe/clock.h
+++ b/arch/arm64/kvm/hyp/include/nvhe/clock.h
@@ -13,4 +13,7 @@ static inline void
trace_hyp_clock_update(u32 mult, u32 shift, u64 epoch_ns, u64 epoch_cyc) { }
static inline u64 trace_hyp_clock(void) { return 0; }
#endif
+
+u64 hyp_clock_ns(void);
+int hyp_clock_init(void);
#endif
diff --git a/arch/arm64/kvm/hyp/nvhe/Makefile b/arch/arm64/kvm/hyp/nvhe/Makefile
index f57450ebcb49..7c879292974d 100644
--- a/arch/arm64/kvm/hyp/nvhe/Makefile
+++ b/arch/arm64/kvm/hyp/nvhe/Makefile
@@ -26,10 +26,10 @@ hyp-obj-y := timer-sr.o sysreg-sr.o debug-sr.o switch.o tlb.o hyp-init.o host.o
hyp-main.o hyp-smp.o psci-relay.o early_alloc.o page_alloc.o \
cache.o setup.o mm.o mem_protect.o sys_regs.o pkvm.o stacktrace.o ffa.o
hyp-obj-y += ../vgic-v3-sr.o ../aarch32.o ../vgic-v2-cpuif-proxy.o ../entry.o \
- ../hyp-entry.o ../exception.o ../pgtable.o ../vgic-v5-sr.o
+ ../hyp-entry.o ../exception.o ../pgtable.o ../vgic-v5-sr.o clock.o
hyp-obj-y += ../../../kernel/smccc-call.o
hyp-obj-$(CONFIG_LIST_HARDENED) += list_debug.o
-hyp-obj-$(CONFIG_NVHE_EL2_TRACING) += clock.o trace.o events.o
+hyp-obj-$(CONFIG_NVHE_EL2_TRACING) += trace.o events.o
hyp-obj-y += $(lib-objs)
# Path to simple_ring_buffer.c
diff --git a/arch/arm64/kvm/hyp/nvhe/clock.c b/arch/arm64/kvm/hyp/nvhe/clock.c
index f3e2619db4e4..43d2cba4f810 100644
--- a/arch/arm64/kvm/hyp/nvhe/clock.c
+++ b/arch/arm64/kvm/hyp/nvhe/clock.c
@@ -8,7 +8,12 @@
#include <asm/arch_timer.h>
#include <asm/div64.h>
+#include <linux/math64.h>
+#include <vdso/time64.h>
+static u32 timer_freq;
+
+#ifdef CONFIG_NVHE_EL2_TRACING
static struct clock_data {
struct {
u32 mult;
@@ -66,3 +71,27 @@ u64 trace_hyp_clock(void)
return (u64)ns + clock->data[bank].epoch_ns;
}
+#endif /* CONFIG_NVHE_EL2_TRACING */
+
+int hyp_clock_init(void)
+{
+ timer_freq = read_sysreg(cntfrq_el0);
+ /*
+ * KVM will not initialize if FW didn't set cntfrq_el0, that is already
+ * part of the boot protocol.
+ */
+ if (!timer_freq)
+ return -ENODEV;
+
+ /* Timer freq can't be larger than 1Ghz by spec. */
+ if (timer_freq > NSEC_PER_SEC)
+ return -EINVAL;
+
+ return 0;
+}
+
+/* Return time in ns. */
+u64 hyp_clock_ns(void)
+{
+ return mul_u64_u32_div(__arch_counter_get_cntvct(), NSEC_PER_SEC, timer_freq);
+}
diff --git a/arch/arm64/kvm/hyp/nvhe/setup.c b/arch/arm64/kvm/hyp/nvhe/setup.c
index 75b00c323310..970c5cf342f5 100644
--- a/arch/arm64/kvm/hyp/nvhe/setup.c
+++ b/arch/arm64/kvm/hyp/nvhe/setup.c
@@ -10,6 +10,7 @@
#include <asm/kvm_pgtable.h>
#include <asm/kvm_pkvm.h>
+#include <nvhe/clock.h>
#include <nvhe/early_alloc.h>
#include <nvhe/ffa.h>
#include <nvhe/gfp.h>
@@ -320,6 +321,10 @@ void __noreturn __pkvm_init_finalise(void)
if (ret)
goto out;
+ ret = hyp_clock_init();
+ if (ret)
+ goto out;
+
ret = fix_host_ownership();
if (ret)
goto out;
--
2.55.0.141.g00534a21ce-goog