[PATCH v2 0/4] KVM: arm64: Fix HCR_EL2 for non-protected VMs in pKVM
From: Fuad Tabba
Date: Mon Sep 28 2026 - 02:46:53 EST
Hi folks,
Changes since v1 [1]:
- Patch 3: take a list of host bits per VM type instead of the host's
value minus the bits EL2 owns; drop the HCR_GPF definition (Marc).
- Patches 2 and 3: use the HCR_EL2_* names in added lines (Marc).
- Patches 1-3: reworded the messages, and the comment in patch 2
(Marc).
- Patch 1: collected Wei-Lin's Reviewed-by.
In pKVM, EL2 sets a non-protected VM's HCR_EL2 in pkvm_vcpu_reset_hcr(),
which misses the RW, TID5 and TTLBOS handling of vcpu_set_hcr(), and
takes only TWI, TWE and VSE from the host. As a result, an AArch32 VM
can't run, a VM can read GMID_EL1 or execute a TLBI OS its ID registers
hide, and the host's TVM, VI and VF never reach it.
The second patch clears RW for an AArch32 vCPU. The third also takes
from the host, for a non-protected VM, the bits the host varies with the
VM's configuration or at runtime: VI, VF, TVM, TID2, TID4, TID5 and
TTLBOS. The rest stay EL2's, and a protected VM still takes only TWI,
TWE and VSE.
The third patch depends on the first: once TTLBOS reaches the VM, a
trapped TLBI OS from a non-nested guest hits a WARN in
handle_tlbi_el1(), as it does without pKVM.
The last patch adds a selftest that checks a feature hidden in an ID
register is UNDEFINED in the guest. Its TLBI OS case fails in pKVM
before the third patch.
VSE still comes from the host as before. Syncing it back after delivery
is a separate fix [2].
Based on Linux 7.3-rc4 (93f51579e7df2).
Cheers,
/fuad
[1] https://lore.kernel.org/all/20260925090619.852995-1-fuad.tabba@xxxxxxxxx/
[2] https://lore.kernel.org/all/20260921101030.1231605-1-fuad.tabba@xxxxxxxxx/
Fuad Tabba (4):
KVM: arm64: Don't WARN on an unsupported TLBI OS from vEL1
KVM: arm64: Clear HCR_EL2.RW for 32-bit non-protected vCPUs
KVM: arm64: Use the host's HCR_EL2 for non-protected VMs in pKVM
KVM: arm64: selftests: Check a feature hidden in an ID register is
UNDEF
arch/arm64/kvm/hyp/include/nvhe/pkvm.h | 9 +
arch/arm64/kvm/hyp/nvhe/hyp-main.c | 7 +-
arch/arm64/kvm/hyp/nvhe/pkvm.c | 25 ++-
arch/arm64/kvm/sys_regs.c | 7 +-
tools/testing/selftests/kvm/Makefile.kvm | 1 +
.../selftests/kvm/arm64/hidden_features.c | 184 ++++++++++++++++++
6 files changed, 218 insertions(+), 15 deletions(-)
create mode 100644 tools/testing/selftests/kvm/arm64/hidden_features.c
base-commit: 93f51579e7df248780214094418f205253383cc5
--
2.39.5