Re: [PATCH v4 00/18] KVM: arm64: Confine protected VM vCPU state to EL2

From: Marc Zyngier

Date: Sat Oct 03 2026 - 04:38:47 EST


On Sat, 03 Oct 2026 07:57:13 +0100,
Fuad Tabba <fuad.tabba@xxxxxxxxx> wrote:
>
> Hi Marc,
>
> On Fri, 02 Oct 2026 16:55:26 +0100, Marc Zyngier <maz@xxxxxxxxxx> wrote:
>
> [...]
>
> > Given how busy this merge window is, there were plenty of conflicts, most
> > of them with your own patches. Please have a look at the way I resolved
> > them and let me know if anything is on the bogus side of wrong...
>
> Thanks for taking these, and for sorting out the conflicts. Most of the
> resolution matches mine, but two things in the pkvm-state merge are off:
>
> - In __kvm_vcpu_run(), the !host_vcpu and SVCR bail-outs still return
> -EINVAL. Patch 10 changed them to ARM_EXCEPTION_IL, since the host
> reads bit 31 of -EINVAL as a pending SError.
>
> - In __kvm_adjust_pc(), the pin path uses kern_hyp_va() on the __kern
> pointer, which sparse flags. It needs kern_hyp_va_host().
>
> The diff below fixes both. It also drops the set_bit()s in
> pkvm_init_features_from_host() that kvm_pkvm_vcpu_allowed_features()
> already does, and realigns the esr_dabt_is_cm() line. Could you fold it
> into the merge resolution?
>
> With it applied on next, I booted protected and non-protected guests,
> ran CPU hotplug in both, and ran the pKVM selftest (from my tree), all
> passing.

Thanks for having a look at it. I've now applied the new resolution
and pushed out the updated branch,

Cheers,

M.

--
Without deviation from the norm, progress is not possible.