From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lj1-f174.google.com (mail-lj1-f174.google.com [209.85.208.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A636114B065 for ; Fri, 12 Apr 2024 16:52:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.208.174 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712940737; cv=none; b=PQKCwQcbAlV4r3X+ynCPdWlcfW7I9AhVr57PDa/yM5Vs9H25CzpEB5Sb4Yhk7/oeUgLDDr1QprTfDZg1qzshId2xZV5iNHI0mTVJYYesLpDKSjRXV9dzg9Ptr3xfOJiPQ8bN42KbgBgNW8jWsyY9HPnFvd5SyZIwKZ47WTkuHUk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1712940737; c=relaxed/simple; bh=JEVa4ex2ZDcngKNJsXDeM2lwaJ7PKNt/9rGEMEiRKOI=; h=Date:From:To:Cc:Subject:Message-ID:MIME-Version:Content-Type: Content-Disposition:In-Reply-To; b=F1JoBJlawjMxsnXt2ly/wOfnb/qjPxBaVBuOu1abx44wXT8WVzlICl2lo+tt/9FkVEeo/70WQT99AGMztKnR+HOlDKMAv1xBQUMTvESJbc3GGV3cVjC4gMko9HVjo4CtQWBnFXcOeNmXjw7jwLxTGHhXucAO9tdNUpdAoPDTWCE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linaro.org; spf=pass smtp.mailfrom=linaro.org; dkim=pass (2048-bit key) header.d=linaro.org header.i=@linaro.org header.b=fcL6zmI2; arc=none smtp.client-ip=209.85.208.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linaro.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linaro.org header.i=@linaro.org header.b="fcL6zmI2" Received: by mail-lj1-f174.google.com with SMTP id 38308e7fff4ca-2d895138ce6so12275631fa.0 for ; Fri, 12 Apr 2024 09:52:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1712940733; x=1713545533; darn=lists.linux.dev; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=F129E/qMOIsRNJvcD537N8BPcYpqI13fs6vRxipyLXs=; b=fcL6zmI2FlLP48ZuT1RKtR874hfdseaTHYqSd6KoqXMWxdALvgV31CaNLwVsdu+Vsm 3FN+UueMhQniPDWR8qDeY/vWXPP49jQ3jn+rHaZsnha7leqzXv6sxp1sIFadKRD9IE73 YfHvl3EEMjQASS+UC4YScQrvwhi5u5nZDuS/66W/cf4+cdu3YevjqY22bpVpHdTfS7RI FCjVcqSzVl4RypbQnpDDGjX9T/etuit64A2DNJ1OxSoYWe4I7B3OEVQRjyUTCI8RTW7a 5dHZdKKE2mHiWWpe8GSpSLi5W2q2d2FxDPeNBrGNwZkuw+PTJCOCf0kkNlwqmc0eAcHG RI7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1712940733; x=1713545533; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=F129E/qMOIsRNJvcD537N8BPcYpqI13fs6vRxipyLXs=; b=SSAiiDdY8VAEyve1/Y9EQ5yyf2ytuXh2wSxTSwpNHfcaDJZ77IIuvh6ub4RPZX/aDw Pb3bWrLqiDg4Sb8mCusKc0V0jbvX1XaEpAcviafyBj+AWBdA1A0hg9tXcj82QvjZ73jF XSJ1+VgyHSUXkxtJFHI+MkGYFdo5UnivPXmcKF/ip5KBXZlmOAl768S+gpEvdV7QnWuK qVu33tVaKsKuRqBY5wF90crrNHGyzw6xf814Sh8NI0xvPreIEKPRa5R0bCJSFmQNvTbn bp1zpEPjw81RaczobJppAkp3kAQhsA/1r12aug72mb0/EbMMDsWKQUpm3a0SH9vlFyAR ZzMw== X-Forwarded-Encrypted: i=1; AJvYcCW35lzmWMYyBP2kfMnUkCTZywu5RQqH44yvJwFom+8rvB1koTfSka0Z6c6cVnPXMy3Ibzec+/KZKwCDyClbKVOZncbKdc5w X-Gm-Message-State: AOJu0YwTtlUXfH7l7Ng9Y+8fzZsgYeAZUjMAz5rJ4+BbLzUjQ74cF7Mv agKyCmzbrZ9L1Llzbdxop21tSk7L3lp8nPbfUf0g9ik+bpTF0i8jRbu9FdReb2Y= X-Google-Smtp-Source: AGHT+IFM2/dXuGXELLLfc+flbBb9xsmkA1SIJGRaZWidPMq1PtFsBq8OiGD0hOU+ZU8oOVk804e3sg== X-Received: by 2002:a05:651c:93:b0:2d8:3e60:b9c9 with SMTP id 19-20020a05651c009300b002d83e60b9c9mr1767624ljq.33.1712940732768; Fri, 12 Apr 2024 09:52:12 -0700 (PDT) Received: from myrica ([2.221.137.100]) by smtp.gmail.com with ESMTPSA id fc18-20020a05600c525200b0041563096e15sm9497631wmb.5.2024.04.12.09.52.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 12 Apr 2024 09:52:12 -0700 (PDT) Date: Fri, 12 Apr 2024 17:52:24 +0100 From: Jean-Philippe Brucker To: Steven Price Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev, Catalin Marinas , Marc Zyngier , Will Deacon , James Morse , Oliver Upton , Suzuki K Poulose , Zenghui Yu , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Joey Gouly , Alexandru Elisei , Christoffer Dall , Fuad Tabba , linux-coco@lists.linux.dev, Ganapatrao Kulkarni , Mathieu Poirier , Thomas Fossati , Kevin Zhao , Leonardo Augusto =?utf-8?Q?Guimar=C3=A3es?= Garcia Subject: Re: [v2] Support for Arm CCA VMs on Linux Message-ID: <20240412165224.GA357251@myrica> Precedence: bulk X-Mailing-List: kvmarm@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20240412084056.1733704-1-steven.price@arm.com> On Fri, Apr 12, 2024 at 09:40:56AM +0100, Steven Price wrote: > We are happy to announce the second version of the Arm Confidential > Compute Architecture (CCA) support for the Linux stack. The intention is > to seek early feedback in the following areas: > * KVM integration of the Arm CCA; > * KVM UABI for managing the Realms, seeking to generalise the > operations where possible with other Confidential Compute solutions; > * Linux Guest support for Realms. > > See the previous RFC[1] for a more detailed overview of Arm's CCA > solution, or visible the Arm CCA Landing page[2]. > > This series is based on the final RMM v1.0 (EAC5) specification[3]. Instructions for building and running the CCA stack on QEMU, both as system emulation and VMM, are available here: https://linaro.atlassian.net/wiki/spaces/QEMU/pages/29051027459/Building+an+RME+stack+for+QEMU I'll send out the QEMU VMM patches shortly: https://git.codelinaro.org/linaro/dcap/qemu.git branch cca/v2 Thanks, Jean > [1] Previous RFC > https://lore.kernel.org/r/20230127112248.136810-1-suzuki.poulose%40arm.com > [2] Arm CCA Landing page (See Key Resources section for various documentation) > https://www.arm.com/architecture/security-features/arm-confidential-compute-architecture > [3] RMM v1.0-EAC5 specification > https://developer.arm.com/documentation/den0137/1-0eac5/ > [4] Shrinkwrap > https://git.gitlab.arm.com/tooling/shrinkwrap > [5] Linux support for Arm CCA RMM v1.0-EAC5 > https://lore.kernel.org/r/fb259449-026e-4083-a02b-f8a4ebea1f87%40arm.com > From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id ABECAC4345F for ; Fri, 12 Apr 2024 16:52:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:In-Reply-To:MIME-Version:Message-ID: Subject:Cc:To:From:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:References: List-Owner; bh=m9S26R3FwRDP4SWbeeQR1ol2RSPXy/0IjjXdUbu2wQI=; b=Rq6z2dSGF4HOLe RVGOsPIC14ooXd8yBJCxWfb3IHGGPSabBDBXexOsQI2O3PDMajqZqTDotEv5pBobMbiOUZ9wMvH7Q cnFzWbKxmcOD6pfn94jW/zx8QVjV+oJameu/kTz8l72R/S3aPrhNxmOXMyvkNrYjoG9O3jE/eaHX+ i/zPc9eigxdiQVpElKU/DnfcCANzsBojy6cjJ3l4rA/2NA/ssorb/2caVWZCU7wPST+Dt0If9D8Q+ RvvwlZ9ZxUlRfug7DYBSV9H3zX/7Dvk3co3tF6Rgu/lHhONlIraJM3jjJznT7QflYcYyot15ck/uJ 1Sl3fDa5pv51bVIDoEDQ==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.97.1 #2 (Red Hat Linux)) id 1rvK8T-00000000YKP-0w85; Fri, 12 Apr 2024 16:52:21 +0000 Received: from mail-lj1-x236.google.com ([2a00:1450:4864:20::236]) by bombadil.infradead.org with esmtps (Exim 4.97.1 #2 (Red Hat Linux)) id 1rvK8O-00000000YJa-2b60 for linux-arm-kernel@lists.infradead.org; Fri, 12 Apr 2024 16:52:20 +0000 Received: by mail-lj1-x236.google.com with SMTP id 38308e7fff4ca-2d895138ce6so12275651fa.0 for ; Fri, 12 Apr 2024 09:52:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1712940733; x=1713545533; darn=lists.infradead.org; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=F129E/qMOIsRNJvcD537N8BPcYpqI13fs6vRxipyLXs=; b=ecC/4LW5UO2q5RZL3SHaNFKIqbVD0pS7FoIElOMkYfmjXo8kzZHMd0RwYFOvAsAvSK 7tzVGau7DtpqC8Y3fq/EVF4kVADxVnjVRncOdplyW43pyDSy5GOsELm8WVRjTPGTu8nd aCtxCft7vJxH6WoEO8uov/AsD7vP26KwO7hVy5emBiqyf2pVMq4WMKwn6ZAvyWX+46eO 6XVIgvcytiTb3Q8u/53kx/IP1hx27jcw+G2+I/RxXNr6mXRT+TV2sRWc9uvYIwOTuKkt PD5xDIwSiXBI+mo0Hx2k1PUwGPoEYfnY9BZWMujdR7vF/pw1SwZJAlBK+M2z1NyhRW/h YabQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1712940733; x=1713545533; h=in-reply-to:content-disposition:mime-version:message-id:subject:cc :to:from:date:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=F129E/qMOIsRNJvcD537N8BPcYpqI13fs6vRxipyLXs=; b=ICKf81cpmVVesIBm1O+dlN6GwvenQj/rZ0RgXvCc6wxQcZAYdRcVPthIZZPGGtIj7D 3b3+G46fRtvWzx4sUK/Ou9ydJUQ+vyv6gihFzq4MmUC6vXdW0s7fAjXZa1jmJA8rizGP NVI40LtlopJh2Qt132BAGa+BskBx3vDbiiBdKXhIwhMQqpSgV5O5c9osUp3fnGFe81Ic KCtWsVYTx+6/hRh4cgOmGcwbRAr6QBAXjSf+chCEti/WnMAzar4vjAq0CCuytF+fc7WG pISN3AcBeJHmND/+5CIBCjSbOtsV97OjP6dMn9CMH0AsCbCKQEHppKmw4JtlRD+RkOE4 oKMA== X-Forwarded-Encrypted: i=1; AJvYcCUz+mSOBqwA0swzbUnQmK7I3ZYauiWRNPsOWfzNYCnNvjRszMl4P2koyCkrOx6mRhm5sHaBhL1WDdW5CddtbWFBCRUOxD834Fxb71YnBQ8F0BAyjVc= X-Gm-Message-State: AOJu0YyAPydeRMp3q2BNuEQJbWpApQCkynwi94TFBJeRogyrqoVQ2zIe 88P8W7M/bOsUc/l63XciDhLNX5qaCyNs0ORkUsUY5TL3KrFkK8ZgRcaOiluOWl0= X-Google-Smtp-Source: AGHT+IFM2/dXuGXELLLfc+flbBb9xsmkA1SIJGRaZWidPMq1PtFsBq8OiGD0hOU+ZU8oOVk804e3sg== X-Received: by 2002:a05:651c:93:b0:2d8:3e60:b9c9 with SMTP id 19-20020a05651c009300b002d83e60b9c9mr1767624ljq.33.1712940732768; Fri, 12 Apr 2024 09:52:12 -0700 (PDT) Received: from myrica ([2.221.137.100]) by smtp.gmail.com with ESMTPSA id fc18-20020a05600c525200b0041563096e15sm9497631wmb.5.2024.04.12.09.52.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 12 Apr 2024 09:52:12 -0700 (PDT) Date: Fri, 12 Apr 2024 17:52:24 +0100 From: Jean-Philippe Brucker To: Steven Price Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev, Catalin Marinas , Marc Zyngier , Will Deacon , James Morse , Oliver Upton , Suzuki K Poulose , Zenghui Yu , linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org, Joey Gouly , Alexandru Elisei , Christoffer Dall , Fuad Tabba , linux-coco@lists.linux.dev, Ganapatrao Kulkarni , Mathieu Poirier , Thomas Fossati , Kevin Zhao , Leonardo Augusto =?utf-8?Q?Guimar=C3=A3es?= Garcia Subject: Re: [v2] Support for Arm CCA VMs on Linux Message-ID: <20240412165224.GA357251@myrica> MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: <20240412084056.1733704-1-steven.price@arm.com> X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20240412_095216_900903_375481E4 X-CRM114-Status: GOOD ( 13.80 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org On Fri, Apr 12, 2024 at 09:40:56AM +0100, Steven Price wrote: > We are happy to announce the second version of the Arm Confidential > Compute Architecture (CCA) support for the Linux stack. The intention is > to seek early feedback in the following areas: > * KVM integration of the Arm CCA; > * KVM UABI for managing the Realms, seeking to generalise the > operations where possible with other Confidential Compute solutions; > * Linux Guest support for Realms. > > See the previous RFC[1] for a more detailed overview of Arm's CCA > solution, or visible the Arm CCA Landing page[2]. > > This series is based on the final RMM v1.0 (EAC5) specification[3]. Instructions for building and running the CCA stack on QEMU, both as system emulation and VMM, are available here: https://linaro.atlassian.net/wiki/spaces/QEMU/pages/29051027459/Building+an+RME+stack+for+QEMU I'll send out the QEMU VMM patches shortly: https://git.codelinaro.org/linaro/dcap/qemu.git branch cca/v2 Thanks, Jean > [1] Previous RFC > https://lore.kernel.org/r/20230127112248.136810-1-suzuki.poulose%40arm.com > [2] Arm CCA Landing page (See Key Resources section for various documentation) > https://www.arm.com/architecture/security-features/arm-confidential-compute-architecture > [3] RMM v1.0-EAC5 specification > https://developer.arm.com/documentation/den0137/1-0eac5/ > [4] Shrinkwrap > https://git.gitlab.arm.com/tooling/shrinkwrap > [5] Linux support for Arm CCA RMM v1.0-EAC5 > https://lore.kernel.org/r/fb259449-026e-4083-a02b-f8a4ebea1f87%40arm.com > _______________________________________________ linux-arm-kernel mailing list linux-arm-kernel@lists.infradead.org http://lists.infradead.org/mailman/listinfo/linux-arm-kernel