[PATCH v21 06/23] KVM: arm64: Don't call vcpu_set_pauth_traps for pKVM host
From: Suzuki K Poulose
Date: Thu Oct 01 2026 - 17:09:53 EST
vcpu_set_pauth_traps() bails out and does nothing for pKVM hosts.
Clean this up by moving the is_protected_kvm_enabled() check to the
caller, in preparation for adding VM specific vcpu load/put callbacks.
While at it, do an early return if the vcpu doesn't have ptrauth.
No functional changes
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v19:
- New patch, since addition of this to the Refactoring patch makes it a bit
more bigger and harder to follow
---
arch/arm64/kvm/arm.c | 52 +++++++++++++++++++++++---------------------
1 file changed, 27 insertions(+), 25 deletions(-)
diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index 90547fbbc8ad7..849f5fcc26c15 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -631,33 +631,34 @@ void kvm_arch_vcpu_unblocking(struct kvm_vcpu *vcpu)
static void vcpu_set_pauth_traps(struct kvm_vcpu *vcpu)
{
- if (vcpu_has_ptrauth(vcpu) && !is_protected_kvm_enabled()) {
- /*
- * Either we're running an L2 guest, and the API/APK bits come
- * from L1's HCR_EL2, or API/APK are both set.
- */
- if (unlikely(is_nested_ctxt(vcpu))) {
- u64 val;
+ if (!vcpu_has_ptrauth(vcpu))
+ return;
- val = __vcpu_sys_reg(vcpu, HCR_EL2);
- val &= (HCR_API | HCR_APK);
- vcpu->arch.hcr_el2 &= ~(HCR_API | HCR_APK);
- vcpu->arch.hcr_el2 |= val;
- } else {
- vcpu->arch.hcr_el2 |= (HCR_API | HCR_APK);
- }
+ /*
+ * Either we're running an L2 guest, and the API/APK bits come
+ * from L1's HCR_EL2, or API/APK are both set.
+ */
+ if (unlikely(is_nested_ctxt(vcpu))) {
+ u64 val;
- /*
- * Save the host keys if there is any chance for the guest
- * to use pauth, as the entry code will reload the guest
- * keys in that case.
- */
- if (vcpu->arch.hcr_el2 & (HCR_API | HCR_APK)) {
- struct kvm_cpu_context *ctxt;
+ val = __vcpu_sys_reg(vcpu, HCR_EL2);
+ val &= (HCR_API | HCR_APK);
+ vcpu->arch.hcr_el2 &= ~(HCR_API | HCR_APK);
+ vcpu->arch.hcr_el2 |= val;
+ } else {
+ vcpu->arch.hcr_el2 |= (HCR_API | HCR_APK);
+ }
- ctxt = this_cpu_ptr_hyp_sym(kvm_hyp_ctxt);
- ptrauth_save_keys(ctxt);
- }
+ /*
+ * Save the host keys if there is any chance for the guest
+ * to use pauth, as the entry code will reload the guest
+ * keys in that case.
+ */
+ if (vcpu->arch.hcr_el2 & (HCR_API | HCR_APK)) {
+ struct kvm_cpu_context *ctxt;
+
+ ctxt = this_cpu_ptr_hyp_sym(kvm_hyp_ctxt);
+ ptrauth_save_keys(ctxt);
}
}
@@ -749,7 +750,8 @@ void kvm_arch_vcpu_load(struct kvm_vcpu *vcpu, int cpu)
else
vcpu->arch.hcr_el2 |= HCR_TWI;
- vcpu_set_pauth_traps(vcpu);
+ if (!is_protected_kvm_enabled())
+ vcpu_set_pauth_traps(vcpu);
if (is_protected_kvm_enabled()) {
kvm_call_hyp_nvhe(__pkvm_vcpu_load,
--
2.43.0