[PATCH v15 26/37] KVM: arm64: WARN on injected undef exceptions
Marc Zyngier
maz at kernel.org
Wed Jul 15 09:25:30 PDT 2026
On Wed, 15 Jul 2026 17:15:31 +0100,
Steven Price <steven.price at arm.com> wrote:
>
> On 15/07/2026 16:46, Marc Zyngier wrote:
> > On Wed, 15 Jul 2026 15:28:28 +0100,
> > Steven Price <steven.price at arm.com> wrote:
> >>
> >> The RMM doesn't allow injection of a undefined exception into a realm
> >> guest. Add a WARN to catch if this ever happens.
> >>
> >> Signed-off-by: Steven Price <steven.price at arm.com>
> >> Reviewed-by: Gavin Shan <gshan at redhat.com>
> >> Reviewed-by: Suzuki K Poulose <suzuki.poulose at arm.com>
> >> ---
> >> Changes since v6:
> >> * if (x) WARN(1, ...) makes no sense, just WARN(x, ...)!
> >> ---
> >> arch/arm64/kvm/inject_fault.c | 1 +
> >> 1 file changed, 1 insertion(+)
> >>
> >> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> >> index 6492397b73d7..613f223bc7a3 100644
> >> --- a/arch/arm64/kvm/inject_fault.c
> >> +++ b/arch/arm64/kvm/inject_fault.c
> >> @@ -327,6 +327,7 @@ void kvm_inject_size_fault(struct kvm_vcpu *vcpu)
> >> */
> >> void kvm_inject_undefined(struct kvm_vcpu *vcpu)
> >> {
> >> + WARN(vcpu_is_rec(vcpu), "Unexpected undefined exception injection to REC");
> >> if (vcpu_el1_is_32bit(vcpu))
> >> inject_undef32(vcpu);
> >> else
> >
> > No. WARN_ONCE at a push, but even then, this looks dodgy.
>
> Yep WARN_ONCE() would be better. This function should never be called
> for a realm guest.
>
> > Exceptions must be injectable. Otherwise, how do you respond to, for
> > example, a sysreg access for a feature that is hidden from the guest?
>
> The RMM doesn't allow the host to inject exceptions - with the exception
> of SEA after a host-emulated MMIO.
>
> > Will the RMM perform this in KVM's stead?
>
> Yes the RMM would have to handle this for the likes of sysreg accesses.
> The host doesn't control the trapping of sysreg accesses. There are a
> few GIC-related registers which are forwarded to the host ("REC exit due
> to system register access") but generally the handling of sysregs is
> entirely internal to the RMM.
Then the only option is not to just warn, but to mark all realms as
dead and refuse to run them any further. If we can't inject an
exception and that the RMM isn't doing its job, I can't see how we can
continue at all.
M.
--
Jazz isn't dead. It just smells funny.
More information about the linux-arm-kernel
mailing list