[PATCH v3 15/18] KVM: arm64: Reject host access to protected VM private state

From: Fuad Tabba

Date: Mon Sep 14 2026 - 07:45:06 EST


A protected vCPU's register and debug state is no longer exposed to
the host. Host ioctls that would reach that state now fail rather
than operate on a copy that isn't the guest's:

- KVM_GET_ONE_REG and KVM_SET_ONE_REG return -EPERM once the vCPU has
run: the copy then holds reset values plus what the exit handlers
marshal out. Pre-run access still builds the guest's boot state.
- KVM_ARM_VCPU_INIT returns -EPERM once the vCPU has run: it would
reset the host copy alone and rewrite mp_state, which EL2 reads
only at hyp vCPU creation, so a vCPU the guest powered off would
come back RUNNABLE.
- KVM_SET_VCPU_EVENTS rejects external-abort injection with -EPERM;
SError injection is forwarded and stays permitted.
- KVM_SET_GUEST_DEBUG returns -EPERM: a protected guest's debug state
is hypervisor-owned.

The KVM_{GET,SET}_ONE_REG and KVM_ARM_VCPU_INIT checks are one filter
on the ioctl number in kvm_arch_vcpu_ioctl(), the only caller of the
three functions they were in. Its -EPERM now precedes the cases'
-EFAULT and the ONE_REG case's pending-reset handling, which the next
KVM_RUN performs. The external-abort check reads the payload, and
KVM_SET_GUEST_DEBUG has its own case in kvm_vcpu_ioctl(), so it never
reaches kvm_arch_vcpu_ioctl(): those two stay in their handlers.

KVM_CHECK_EXTENSION returns 0 for KVM_CAP_ARM_INJECT_EXT_DABT and
KVM_CAP_SET_GUEST_DEBUG on a protected VM: kvm_pkvm_ext_allowed()
returns false on every capability it doesn't list, and the patch that
advertises the capabilities protected VMs support leaves these two
out. The two ioctl checks stay for a VMM that doesn't query
KVM_CHECK_EXTENSION.

Signed-off-by: Fuad Tabba <fuad.tabba@xxxxxxxxx>
---
arch/arm64/kvm/arm.c | 21 +++++++++++++++++++++
arch/arm64/kvm/guest.c | 11 +++++++++++
2 files changed, 32 insertions(+)

diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index ca6e109b3e5d6..0362f5f235e02 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -1865,6 +1865,23 @@ static int kvm_arm_vcpu_set_events(struct kvm_vcpu *vcpu,
return __kvm_arm_vcpu_set_events(vcpu, events);
}

+/*
+ * Once a protected vCPU has run, the host copy is not the guest's state,
+ * and EL2 has read mp_state, which it does only at hyp vCPU creation.
+ */
+static long pkvm_filter_vcpu_ioctl(struct kvm_vcpu *vcpu, unsigned int ioctl)
+{
+ switch (ioctl) {
+ case KVM_ARM_VCPU_INIT:
+ case KVM_SET_ONE_REG:
+ case KVM_GET_ONE_REG:
+ if (vcpu_is_protected(vcpu) && vcpu_has_run_once(vcpu))
+ return -EPERM;
+ }
+
+ return 0;
+}
+
long kvm_arch_vcpu_ioctl(struct file *filp,
unsigned int ioctl, unsigned long arg)
{
@@ -1873,6 +1890,10 @@ long kvm_arch_vcpu_ioctl(struct file *filp,
struct kvm_device_attr attr;
long r;

+ r = pkvm_filter_vcpu_ioctl(vcpu, ioctl);
+ if (r)
+ return r;
+
switch (ioctl) {
case KVM_ARM_VCPU_INIT: {
struct kvm_vcpu_init init;
diff --git a/arch/arm64/kvm/guest.c b/arch/arm64/kvm/guest.c
index b01d6622b8720..d5e2e08f05461 100644
--- a/arch/arm64/kvm/guest.c
+++ b/arch/arm64/kvm/guest.c
@@ -786,6 +786,13 @@ int __kvm_arm_vcpu_set_events(struct kvm_vcpu *vcpu,
u64 esr = events->exception.serror_esr;
int ret = 0;

+ /*
+ * EL2 injects an external abort only to complete a forwarded abort.
+ * SError injection is forwarded.
+ */
+ if (vcpu_is_protected(vcpu) && ext_dabt_pending)
+ return -EPERM;
+
/*
* Immediately commit the pending SEA to the vCPU's architectural
* state which is necessary since we do not return a pending SEA
@@ -883,6 +890,10 @@ int kvm_arch_vcpu_ioctl_set_guest_debug(struct kvm_vcpu *vcpu,
{
trace_kvm_set_guest_debug(vcpu, dbg->control);

+ /* A protected guest's debug state is not exposed to the host. */
+ if (vcpu_is_protected(vcpu))
+ return -EPERM;
+
if (dbg->control & ~KVM_GUESTDBG_VALID_MASK)
return -EINVAL;

--
2.39.5