Since there is an architectural dependency between the features as an
optimisation we only context switch guest registers for FEAT_S1PIE and
FEAT_S1POE if the guest also has FEAT_TCR2. We do not, however, enforce
this as a requirement when starting a guest and only configure the traps
for accessing the registers based on their individual features. This means
that a VMM can configure a guest which can read and write the system
registers for FEAT_S1PIE and FEAT_S1POE without the hypervisor updating the
values of these registers for the guest.

Avoid this by refusing to create a guest with an affected configuration.

Rather than doing something data driven we open code the checks, I started
doing something data driven but it was very clear that such code should be
shared with the host kernel cpufeature code. Refactoring for that seemed
like disproportionate effort and invasiveness for the context so is
deferred for followup work.

Fixes: 663abf04ee4d ("KVM: arm64: Make PIR{,E0}_EL1 save/restore conditional on 
FEAT_TCRX")
Signed-off-by: Mark Brown <[email protected]>
---
 arch/arm64/kvm/sys_regs.c | 21 +++++++++++++++++++++
 1 file changed, 21 insertions(+)

diff --git a/arch/arm64/kvm/sys_regs.c b/arch/arm64/kvm/sys_regs.c
index 44aae52c473d..3ae293798b27 100644
--- a/arch/arm64/kvm/sys_regs.c
+++ b/arch/arm64/kvm/sys_regs.c
@@ -5860,6 +5860,24 @@ void kvm_calculate_traps(struct kvm_vcpu *vcpu)
        mutex_unlock(&kvm->arch.config_lock);
 }
 
+/*
+ * Some optimisations in fast paths would be broken by architecturally
+ * invalid feature combinations, reject those.
+ *
+ * This should share code with the host kernel cpufeature code, and
+ * make use of the MRS to generate dependencies.
+ */
+static bool kvm_validate_id_regs(struct kvm *kvm)
+{
+       if (kvm_has_s1pie(kvm) && !kvm_has_tcr2(kvm))
+               return false;
+
+       if (kvm_has_s1poe(kvm) && !kvm_has_tcr2(kvm))
+               return false;
+
+       return true;
+}
+
 /*
  * Perform last adjustments to the ID registers that are implied by the
  * configuration outside of the ID regs themselves, as well as any
@@ -5928,6 +5946,9 @@ int kvm_finalize_sys_regs(struct kvm_vcpu *vcpu)
                kvm_vgic_finalize_idregs(kvm);
        }
 
+       if (!kvm_validate_id_regs(vcpu->kvm))
+               return -EINVAL;
+
        return 0;
 }
 

-- 
2.47.3


Reply via email to