Re: [PATCH v15 26/37] KVM: arm64: WARN on injected undef exceptions

Steven Price <[email protected]>
Newsgroups dev.linux.lists.linux-coco,dev.linux.lists.kvmarm,org.infradead.lists.linux-arm-kernel,org.kernel.vger.kvm,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On 15/07/2026 17:25, Marc Zyngier wrote:
> On Wed, 15 Jul 2026 17:15:31 +0100,
> Steven Price <[email protected]> wrote:
>>
>> On 15/07/2026 16:46, Marc Zyngier wrote:
>>> On Wed, 15 Jul 2026 15:28:28 +0100,
>>> Steven Price <[email protected]> wrote:
>>>>
>>>> The RMM doesn't allow injection of a undefined exception into a realm
>>>> guest. Add a WARN to catch if this ever happens.
>>>>
>>>> Signed-off-by: Steven Price <[email protected]>
>>>> Reviewed-by: Gavin Shan <[email protected]>
>>>> Reviewed-by: Suzuki K Poulose <[email protected]>
>>>> ---
>>>> Changes since v6:
>>>>  * if (x) WARN(1, ...) makes no sense, just WARN(x, ...)!
>>>> ---
>>>>  arch/arm64/kvm/inject_fault.c | 1 +
>>>>  1 file changed, 1 insertion(+)
>>>>
>>>> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
>>>> index 6492397b73d7..613f223bc7a3 100644
>>>> --- a/arch/arm64/kvm/inject_fault.c
>>>> +++ b/arch/arm64/kvm/inject_fault.c
>>>> @@ -327,6 +327,7 @@ void kvm_inject_size_fault(struct kvm_vcpu *vcpu)
>>>>   */
>>>>  void kvm_inject_undefined(struct kvm_vcpu *vcpu)
>>>>  {
>>>> +	WARN(vcpu_is_rec(vcpu), "Unexpected undefined exception injection to REC");
>>>>  	if (vcpu_el1_is_32bit(vcpu))
>>>>  		inject_undef32(vcpu);
>>>>  	else
>>>
>>> No. WARN_ONCE at a push, but even then, this looks dodgy.
>>
>> Yep WARN_ONCE() would be better. This function should never be called
>> for a realm guest.
>>
>>> Exceptions must be injectable. Otherwise, how do you respond to, for
>>> example, a sysreg access for a feature that is hidden from the guest?
>>
>> The RMM doesn't allow the host to inject exceptions - with the exception
>> of SEA after a host-emulated MMIO.
>>
>>> Will the RMM perform this in KVM's stead?
>>
>> Yes the RMM would have to handle this for the likes of sysreg accesses.
>> The host doesn't control the trapping of sysreg accesses. There are a
>> few GIC-related registers which are forwarded to the host ("REC exit due
>> to system register access") but generally the handling of sysregs is
>> entirely internal to the RMM.
> 
> Then the only option is not to just warn, but to mark all realms as
> dead and refuse to run them any further. If we can't inject an
> exception and that the RMM isn't doing its job, I can't see how we can
> continue at all.

You've got a point - I'm not sure whether it's entirely reasonable to
refuse to run any realm, but it certainly would be sensible to mark the
guest which triggers this as dead. Would a KVM_BUG() be more appropriate
here?

Thanks,
Steve
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.