Re: [PATCH v22 01/23] KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0
From: Gavin Shan
Date: Mon Oct 05 2026 - 20:02:57 EST
On 10/5/26 7:07 PM, Suzuki K Poulose wrote:
Protected VMs doesn't allow setting offsets for virtual and physicalReviewed-by: Gavin Shan <gshan@xxxxxxxxxx>
counters, as the offset is always fixed to 0. The VM ioctl is filtered
out based on the cap. However we don't prevent the userspace from trying
to write to the CNTVCT/CNTPCT registers. This would lead to KVM triggering
a WARN() in timer_set_offset() as the vm_offset pointer is set to NULL.
Fix this by always "fixing" the timer offsets to 0 and marking that the
timer offset is set in the kvm->arch.flags at KVM init time for protected
VMs. This prevents the access to the VM specific vm_offset at low cost.
A userspace writing to the CNT*CT_EL0 would observe success, without
any real effect. This is cleaner over spilling "*_is_protected()"
checks and "matches" what we really do in practise. i.e., always run
with "fixed counter offset of 0".
Reported by Sashiko
Link: https://lore.kernel.org/all/20260908164641.416911F00A3A@xxxxxxxxxxxxxxx
Fixes: f7d05ee84a6a ("KVM: arm64: Prevent host from managing timer offsets for protected VMs")
Suggested-by: Marc Zyngier <maz@xxxxxxxxxx>
Tested-by: Gavin Shan <gshan@xxxxxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v19:
- Fix typos in commit description and explain why we choose the approach.
- Improve comment in the code
Changes since v18:
- Retain NULL vm_offset for protected VMs to avoid host tampering with the
offset.
- Moved the flag setting into kvm_timer_init_vm(), where it should have been
in the first place
---
arch/arm64/kvm/arch_timer.c | 12 ++++++++++--
1 file changed, 10 insertions(+), 2 deletions(-)