Re: [PATCH v3 0/4] KVM: arm64: Fix HCR_EL2 for non-protected VMs in pKVM
From: Oliver Upton
Date: Tue Sep 29 2026 - 15:33:17 EST
On Tue, 29 Sep 2026 10:00:27 +0100, Fuad Tabba wrote:
> Changes since v2 [1]:
> - Patch 1: apply the FGUs on a CPU without FEAT_FGT instead of moving
> the check in handle_tlbi_el1() (Oliver [2]). Wei-Lin's Reviewed-by
> dropped with the rewrite.
>
> In pKVM, EL2 sets a non-protected VM's HCR_EL2 in pkvm_vcpu_reset_hcr(),
> which misses the RW, TID5 and TTLBOS handling of vcpu_set_hcr(), and
> takes only TWI, TWE and VSE from the host. As a result, an AArch32 VM
> can't run, a VM can read GMID_EL1 or execute a TLBI OS its ID registers
> hide, and the host's TVM, VI and VF never reach it.
>
> [...]
Applied to fixes, thanks!
[1/4] KVM: arm64: Apply the fine-grained UNDEFs without FEAT_FGT
https://git.kernel.org/kvmarm/kvmarm/c/4bdd2b3a708c
[2/4] KVM: arm64: Clear HCR_EL2.RW for 32-bit non-protected vCPUs
https://git.kernel.org/kvmarm/kvmarm/c/80ae56184b57
[3/4] KVM: arm64: Use the host's HCR_EL2 for non-protected VMs in pKVM
https://git.kernel.org/kvmarm/kvmarm/c/04447b95c62b
[4/4] KVM: arm64: selftests: Check a feature hidden in an ID register is UNDEF
https://git.kernel.org/kvmarm/kvmarm/c/afb4334fb52c
--
Best,
Oliver