From: Oliver Upton <[email protected]>

Running KVM with (as of writing, out-of-tree) support for FEAT_S2PIE
on -cpu max gets stuck in an infinite loop of stage-2 permission faults
due to the PTW incorrectly using an effective value of 0 for S2PIR_EL2.

Similar to how S1PIE is handled, only use the IMPLEMENTATION SPECIFIC
value of 0 for S2PIR_EL2 if EL3 is implemented and PIEN=0.

Cc: [email protected]
Fixes: a811c5dafb ("target/arm: Implement get_S2prot_indirect")
Reviewed-by: Richard Henderson <[email protected]>
Signed-off-by: Oliver Upton <[email protected]>
Message-id: [email protected]
[PMM: removed hardcoded tab]
Signed-off-by: Peter Maydell <[email protected]>
(cherry picked from commit d77a93ca4b53da18ce01c5b7678e0eb435851919)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/target/arm/ptw.c b/target/arm/ptw.c
index 7b993bb5b39..df98cf87aaf 100644
--- a/target/arm/ptw.c
+++ b/target/arm/ptw.c
@@ -1392,9 +1392,14 @@ static int get_S2prot_indirect(CPUARMState *env, 
GetPhysAddrResult *result,
                   PAGE_READ | PAGE_WRITE },
     };
 
-    uint64_t pir = (env->cp15.scr_el3 & SCR_PIEN ? env->cp15.s2pir_el2 : 0);
-    int s2pi = extract64(pir, pi_index * 4, 4);
+    uint64_t pir = env->cp15.s2pir_el2;
+    int s2pi;
 
+    if (arm_feature(env, ARM_FEATURE_EL3) && !(env->cp15.scr_el3 & SCR_PIEN)) {
+        pir = 0;
+    }
+
+    s2pi = extract64(pir, pi_index * 4, 4);
     result->f.prot = perm_table[s2pi][2];
     return perm_table[s2pi][s1_is_el0];
 }
-- 
2.47.3


Reply via email to