[PATCH v2 1/4] KVM: arm64: Don't WARN on an unsupported TLBI OS from vEL1

From: Fuad Tabba

Date: Mon Sep 28 2026 - 02:48:13 EST


KVM hides TLBI OS from a guest whose ID registers don't advertise it by
trapping the instructions: through the fine-grained traps on a CPU with
FGT, and through HCR_EL2.TTLBOS on one with FEAT_EVT2. With FGT,
triage_sysreg_trap() makes a trapped TLBI OS UNDEFINED. Without it, the
instruction reaches handle_tlbi_el1(), which assumes an EL1 TLBI only
traps from a guest at vEL2 and WARNs before checking whether the guest
supports it. The guest still gets its UNDEF after the WARN. A VMM can
trigger the WARN by hiding TLBI OS and having the guest execute one.

Check support before the WARN.

Fixes: 0cb8aae226768 ("KVM: arm64: nv: Add handling of outer-shareable TLBI operations")
Cc: stable@xxxxxxxxxxxxxxx
Reviewed-by: Wei-Lin Chang <weilin.chang@xxxxxxx>
Signed-off-by: Fuad Tabba <fuad.tabba@xxxxxxxxx>
---
arch/arm64/kvm/sys_regs.c | 7 ++++---
1 file changed, 4 insertions(+), 3 deletions(-)

diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
index 44aae52c473d7..0ce29ce678b08 100644
--- a/arch/arm64/kvm/sys_regs.c
+++ b/arch/arm64/kvm/sys_regs.c
@@ -4257,6 +4257,10 @@ static bool handle_tlbi_el1(struct kvm_vcpu *vcpu, struct sys_reg_params *p,
{
u32 sys_encoding = sys_insn(p->Op0, p->Op1, p->CRn, p->CRm, p->Op2);

+ /* Without FGT, HCR_EL2.TTLBOS also traps a hidden TLBI OS from vEL1 */
+ if (!kvm_supported_tlbi_s1e1_op(vcpu, sys_encoding))
+ return undef_access(vcpu, p, r);
+
/*
* If we're here, this is because we've trapped on a EL1 TLBI
* instruction that affects the EL1 translation regime while
@@ -4279,9 +4283,6 @@ static bool handle_tlbi_el1(struct kvm_vcpu *vcpu, struct sys_reg_params *p,

WARN_ON(!vcpu_is_el2(vcpu));

- if (!kvm_supported_tlbi_s1e1_op(vcpu, sys_encoding))
- return undef_access(vcpu, p, r);
-
if (vcpu_el2_e2h_is_set(vcpu) && vcpu_el2_tge_is_set(vcpu)) {
kvm_handle_s1e2_tlbi(vcpu, sys_encoding, p->regval);
return true;
--
2.39.5