diff --git a/drivers/misc/pkvm-smc/pkvm-smc.c b/drivers/misc/pkvm-smc/pkvm-smc.c index 2101462be303..e91e291265fd 100644 --- a/drivers/misc/pkvm-smc/pkvm-smc.c +++ b/drivers/misc/pkvm-smc/pkvm-smc.c @@ -14,17 +14,24 @@ static unsigned long pkvm_module_token; int kvm_nvhe_sym(pkvm_smc_filter_hyp_init)(const struct pkvm_module_ops *ops); +extern int kvm_nvhe_sym(permissive); + +static bool permissive; +module_param(permissive, bool, 0444); +MODULE_PARM_DESC(permissive, "Only log SMC filter violations."); static int __init smc_filter_init(void) { int ret; + kvm_nvhe_sym(permissive) = permissive; ret = pkvm_load_el2_module(kvm_nvhe_sym(pkvm_smc_filter_hyp_init), &pkvm_module_token); if (ret) pr_err("Failed to register pKVM SMC filter: %d\n", ret); else - pr_info("pKVM SMC filter registered successfully\n"); + pr_info("pKVM SMC filter registered successfully with permissive = %s\n", + permissive ? "true" : "false"); return ret; } diff --git a/drivers/misc/pkvm-smc/pkvm/pkvm-smc.c b/drivers/misc/pkvm-smc/pkvm/pkvm-smc.c index 96850e783385..d2cc51808690 100644 --- a/drivers/misc/pkvm-smc/pkvm/pkvm-smc.c +++ b/drivers/misc/pkvm-smc/pkvm/pkvm-smc.c @@ -14,6 +14,7 @@ #include const struct pkvm_module_ops *pkvm_ops; +bool permissive; #ifdef CONFIG_TRACING extern char __hyp_event_ids_start[]; @@ -38,6 +39,10 @@ struct pkvm_smc_filter { static bool deny_smc(struct user_pt_regs *regs) { trace_filtered_smc(regs->regs[0]); + + if (permissive) + return false; + regs->regs[0] = SMCCC_RET_NOT_SUPPORTED; return true; }