Re: [PATCH v21 05/23] KVM: arm64: Track the type of VM in kvm_arch

From: Suzuki K Poulose

Date: Sat Oct 03 2026 - 03:08:03 EST


On 03/10/2026 06:53, Suzuki K Poulose wrote:
On 02/10/2026 16:29, Marc Zyngier wrote:
On Fri, 02 Oct 2026 15:37:00 +0100,
Fuad Tabba <tabba@xxxxxxxxxx> wrote:

Hi Marc,

On Fri, 02 Oct 2026 15:15:06 +0100, Marc Zyngier <maz@xxxxxxxxxx> wrote:
[...]
Honestly, we introduce the flavor stuff to make it easy to match
things on a particular VM type in a readable way. So why isn't this
reading:

         if (vcpu->kvm->arch.vm_flavor != VM_PROTECTED_PKVM)
                 return;

I know this is a sketch, but just in case: that's inverted. The sync
only applies to non-protected pKVM VMs (EL2 ignores it for protected
ones), so it would be != VM_PKVM.

See what I meant about this stuff being completely intractable? I
still have no idea what it means! ;-)


Just to be clear: unprotected_pkvm() != (vm_flavor != VM_PROTECED_PKVM).
Rather, unprotected_pkvm => (vm_flavor == VM_PKVM).

And the code wanted to bail out early for !unprotected_pkvm(). We can
stick in "is_protected_kvm_enabled()" for unprotected_pkvm predicate

But, I can drop the helper and use the vm_flavor check.

FWIW: Here is the diff for the above change. If you are happy
with the following, I could fold this in.


diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index 90547fbbc8ad7..bcec14c587119 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -772,7 +772,7 @@ void kvm_arch_vcpu_put(struct kvm_vcpu *vcpu)
kvm_call_hyp_nvhe(__pkvm_vcpu_put);

/* __pkvm_vcpu_put implies a sync of the state */
- if (kvm_vm_is_unprotected_pkvm(vcpu->kvm))
+ if (vcpu->kvm->arch.vm_flavor == VM_PKVM)
vcpu_set_flag(vcpu, PKVM_HOST_STATE_DIRTY);
}

@@ -1006,7 +1006,7 @@ int kvm_arch_vcpu_run_pid_change(struct kvm_vcpu *vcpu)

if (is_protected_kvm_enabled()) {
/* Start with the vcpu in a dirty state */
- if (kvm_vm_is_unprotected_pkvm(vcpu->kvm))
+ if (vcpu->kvm->arch.vm_flavor == VM_PKVM)
vcpu_set_flag(vcpu, PKVM_HOST_STATE_DIRTY);
ret = pkvm_create_hyp_vm(kvm);
if (ret)
diff --git a/arch/arm64/kvm/handle_exit.c b/arch/arm64/kvm/handle_exit.c
index 384c5d258c7f8..4e16e7d165515 100644
--- a/arch/arm64/kvm/handle_exit.c
+++ b/arch/arm64/kvm/handle_exit.c
@@ -490,7 +490,7 @@ static void handle_exit_pkvm_state(struct kvm_vcpu *vcpu, int exception_index)
{
int exception_code = ARM_EXCEPTION_CODE(exception_index);

- if (!kvm_vm_is_unprotected_pkvm(vcpu->kvm))
+ if (!is_protected_kvm_enabled() || vcpu->kvm->arch.vm_flavor != VM_PKVM)
return;

/*



Cheers
Suzuki>
Cheers
Suzuki

    M.