Re: [PATCH v1 3/4] KVM: arm64: Use the host's HCR_EL2 for non-protected VMs in pKVM

From: Fuad Tabba

Date: Mon Sep 28 2026 - 02:37:39 EST


Hi Marc,

On Sun, 27 Sep 2026 10:15:07 +0100, Marc Zyngier <maz@xxxxxxxxxx> wrote:
[...]
> > ATA, an owned bit, stays clear, as pKVM doesn't support MTE for any
> > guest. TID2 and TID4 move to pvm_init_traps_hcr(), since EL2 now sets
> > them only for a protected VM. A protected VM's HCR_EL2 is unchanged.
>
> But the host does set these bits for non-protected VMs. What is going
> to honor these traps?

The host, as it does today: the traps of a non-protected VM that the
hypervisor doesn't handle itself are forwarded to the host. What
changes is where the bits come from: for a non-protected VM they come
from the host's HCR_EL2 with the rest, and the hypervisor only sets
them itself for a protected VM. I'll rewrite the message to make that
clear.

>
> No mention of why you are adding HCR_EL2_GPF here?

It was only there to name the bit in the mask below. It's gone in v2.

[...]
> > +#define PKVM_HCR_EL2_OWNED ((HCR_GUEST_FLAGS & ~(HCR_TWI | HCR_TWE)) | HCR_BSU | \
> > + HCR_E2H | HCR_TGE | HCR_TEA | HCR_GPF | HCR_TERR | \
> > + HCR_FWB | HCR_DC | HCR_ID | HCR_CD | HCR_NV | \
> > + HCR_NV1 | HCR_NV2 | HCR_API | HCR_APK | HCR_ATA | \
> > + HCR_DCT | HCR_FIEN | HCR_AMVOFFEN | HCR_ENSCXT | \
> > + HCR_EL2_RES0)
> > +
>
> The name of the macro doesn't indicate that this only applies to
> protected VM.
>
> Also, please don't add new uses of the compat HCR macros. I really
> want to remove them (probably post -rc1).

Will do: the masks in v2 are named per VM type and use the HCR_EL2_* names.

[...]
> This feels fragile. You start with a restrictive set (TWI, TWE, VSE),
> and then drop it all. At this point, I have no idea what you are
> letting in.
>
> It would be better to express things in a consistent way:
>
> - either the bits that are controlled by the host for either protected
> and non-protected guests,
>
> - or the bits that are controlled by the hypervisor for either cases.
>
> Here, you're mixing both, and that's confusing.

Ack. I'll go with the bits the host controls, one set per VM type:
TWI, TWE and VSE for a protected VM, and those plus the per-VM traps
and virtual interrupts for a non-protected one. The flush then applies
the same mask logic to both.

Cheers,
/fuad