]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
KVM: arm64: vgic: Avoid double-deactivate of IRQs in the nested context
authorD Scott Phillips <scott@os.amperecomputing.com>
Tue, 14 Jul 2026 23:11:58 +0000 (16:11 -0700)
committerMarc Zyngier <maz@kernel.org>
Tue, 21 Jul 2026 10:19:00 +0000 (11:19 +0100)
In the nested state, the physical interrupt has already been
deactivated through the HW bit in the LR. The extra deactivation
would be harmless but can hit an errata case on AmpereOne, so
avoid it here.

On AmpereOne, deactivating a physical interrupt through
ICC_DIR_EL1 or ICC_EOIR1_EL1 (depending on EOImode) which is not
active, but is the highest priority pending interrupt causes the
cpu to lose the interrupt pending state and also prevents the
delivery of future interrupts.

Fixes: 6dd333c8942b2 ("KVM: arm64: GICv3: nv: Plug L1 LR sync into deactivation primitive")
Signed-off-by: D Scott Phillips <scott@os.amperecomputing.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/linux-arm-kernel/20260710222128.416581-1-scott@os.amperecomputing.com/
Link: https://patch.msgid.link/20260714231158.496808-1-scott@os.amperecomputing.com
Signed-off-by: Marc Zyngier <maz@kernel.org>
Documentation/arch/arm64/silicon-errata.rst
arch/arm64/kvm/vgic/vgic-v3.c

index 014aa1c215a16aa490655f48789244d29b16d789..88b4aa45a20667cbfc5826c74253af927f767a58 100644 (file)
@@ -55,10 +55,14 @@ stable kernels.
 +----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne       | AC03_CPU_38     | AMPERE_ERRATUM_AC03_CPU_38  |
 +----------------+-----------------+-----------------+-----------------------------+
+| Ampere         | AmpereOne       | AC03_CPU_57     | N/A                         |
++----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne AC04  | AC04_CPU_10     | AMPERE_ERRATUM_AC03_CPU_38  |
 +----------------+-----------------+-----------------+-----------------------------+
 | Ampere         | AmpereOne AC04  | AC04_CPU_23     | AMPERE_ERRATUM_AC04_CPU_23  |
 +----------------+-----------------+-----------------+-----------------------------+
+| Ampere         | AmpereOne AC04  | AC04_CPU_29     | N/A                         |
++----------------+-----------------+-----------------+-----------------------------+
 +----------------+-----------------+-----------------+-----------------------------+
 | ARM            | Cortex-A510     | #2457168        | ARM64_ERRATUM_2457168       |
 +----------------+-----------------+-----------------+-----------------------------+
index 9e841e7afd4a76f54e8efe1bf5722cf3fa04108f..7aa417440f6a2fd435bb6857e85fa5018db071cb 100644 (file)
@@ -275,7 +275,13 @@ void vgic_v3_deactivate(struct kvm_vcpu *vcpu, u64 val)
                lr = vgic_v3_compute_lr(vcpu, irq) & ~ICH_LR_ACTIVE_BIT;
        }
 
-       if (lr & ICH_LR_HW)
+       /*
+        * In the nested state, the irq has already been deactivated via the HW
+        * bit in the LR. Deactivating again would be harmless except AmpereOne
+        * errata AC03_CPU_57, AC04_CPU_29 could cause irq delivery to break if
+        * the deactivation hits the highest priority pending irq.
+        */
+       if ((lr & ICH_LR_HW) && !vgic_state_is_nested(vcpu))
                vgic_v3_deactivate_phys(FIELD_GET(ICH_LR_PHYS_ID_MASK, lr));
 
        vgic_v3_fold_lr(vcpu, lr);