[PATCH v3 04/18] KVM: arm64: Disable steal time for protected VMs

Vincent Donnefort vdonnefort at google.com
Tue Sep 22 07:34:22 PDT 2026


On Mon, Sep 14, 2026 at 12:33:24PM +0100, Fuad Tabba wrote:
> pKVM doesn't support steal time for protected guests, and
> KVM_CAP_STEAL_TIME already reads 0 for them on the VM file descriptor,
> but kvm_arm_pvtime_supported() doesn't know the VM, so the host still
> accepts the KVM_ARM_VCPU_PVTIME_CTRL attribute, whose IPA would point
> kvm_update_stolen_time() at the guest's private memory on every vCPU
> load. Pass the VM in and return false for a protected one, so the
> attribute returns -ENXIO as it does where steal time isn't implemented.
> 
> Signed-off-by: Fuad Tabba <fuad.tabba at linux.dev>

Reviewed-by: Vincent Donnefort <vdonnefort at google.com>

> ---
>  arch/arm64/include/asm/kvm_host.h |  2 +-
>  arch/arm64/kvm/arm.c              |  2 +-
>  arch/arm64/kvm/pvtime.c           | 10 +++++-----
>  3 files changed, 7 insertions(+), 7 deletions(-)
> 
> diff --git a/arch/arm64/include/asm/kvm_host.h b/arch/arm64/include/asm/kvm_host.h
> index 27fe0cd5b2d7a..286489a69dff5 100644
> --- a/arch/arm64/include/asm/kvm_host.h
> +++ b/arch/arm64/include/asm/kvm_host.h
> @@ -1346,7 +1346,7 @@ long kvm_hypercall_pv_features(struct kvm_vcpu *vcpu);
>  gpa_t kvm_init_stolen_time(struct kvm_vcpu *vcpu);
>  void kvm_update_stolen_time(struct kvm_vcpu *vcpu);
>  
> -bool kvm_arm_pvtime_supported(void);
> +bool kvm_arm_pvtime_supported(struct kvm *kvm);
>  int kvm_arm_pvtime_set_attr(struct kvm_vcpu *vcpu,
>  			    struct kvm_device_attr *attr);
>  int kvm_arm_pvtime_get_attr(struct kvm_vcpu *vcpu,
> diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
> index 8b080804bc90b..db36815630790 100644
> --- a/arch/arm64/kvm/arm.c
> +++ b/arch/arm64/kvm/arm.c
> @@ -447,7 +447,7 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)
>  		r = system_supports_mte();
>  		break;
>  	case KVM_CAP_STEAL_TIME:
> -		r = kvm_arm_pvtime_supported();
> +		r = kvm_arm_pvtime_supported(kvm);
>  		break;
>  	case KVM_CAP_ARM_EL1_32BIT:
>  		r = cpus_have_final_cap(ARM64_HAS_32BIT_EL1);
> diff --git a/arch/arm64/kvm/pvtime.c b/arch/arm64/kvm/pvtime.c
> index 4ceabaa4c30bd..053fe831fa541 100644
> --- a/arch/arm64/kvm/pvtime.c
> +++ b/arch/arm64/kvm/pvtime.c
> @@ -67,9 +67,9 @@ gpa_t kvm_init_stolen_time(struct kvm_vcpu *vcpu)
>  	return base;
>  }
>  
> -bool kvm_arm_pvtime_supported(void)
> +bool kvm_arm_pvtime_supported(struct kvm *kvm)
>  {
> -	return !!sched_info_on();
> +	return !!sched_info_on() && (!kvm || !kvm_vm_is_protected(kvm));
>  }
>  
>  int kvm_arm_pvtime_set_attr(struct kvm_vcpu *vcpu,
> @@ -81,7 +81,7 @@ int kvm_arm_pvtime_set_attr(struct kvm_vcpu *vcpu,
>  	int ret = 0;
>  	int idx;
>  
> -	if (!kvm_arm_pvtime_supported() ||
> +	if (!kvm_arm_pvtime_supported(kvm) ||
>  	    attr->attr != KVM_ARM_VCPU_PVTIME_IPA)
>  		return -ENXIO;
>  
> @@ -110,7 +110,7 @@ int kvm_arm_pvtime_get_attr(struct kvm_vcpu *vcpu,
>  	u64 __user *user = (u64 __user *)attr->addr;
>  	u64 ipa;
>  
> -	if (!kvm_arm_pvtime_supported() ||
> +	if (!kvm_arm_pvtime_supported(vcpu->kvm) ||
>  	    attr->attr != KVM_ARM_VCPU_PVTIME_IPA)
>  		return -ENXIO;
>  
> @@ -126,7 +126,7 @@ int kvm_arm_pvtime_has_attr(struct kvm_vcpu *vcpu,
>  {
>  	switch (attr->attr) {
>  	case KVM_ARM_VCPU_PVTIME_IPA:
> -		if (kvm_arm_pvtime_supported())
> +		if (kvm_arm_pvtime_supported(vcpu->kvm))
>  			return 0;
>  	}
>  	return -ENXIO;
> -- 
> 2.39.5
> 

-- 
Vincent



More information about the linux-arm-kernel mailing list