From: Steven Price <steven.price@arm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: Steven Price <steven.price@arm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
James Morse <james.morse@arm.com>,
Oliver Upton <oliver.upton@linux.dev>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
Alexandru Elisei <alexandru.elisei@arm.com>,
Christoffer Dall <christoffer.dall@arm.com>,
Fuad Tabba <tabba@google.com>,
linux-coco@lists.linux.dev,
Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
Gavin Shan <gshan@redhat.com>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Alper Gun <alpergun@google.com>,
"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>,
Emi Kisanuki <fj0570is@fujitsu.com>,
Vishal Annapurve <vannapurve@google.com>,
WeiLin.Chang@arm.com, Lorenzo Pieralisi <lpieralisi@kernel.org>
Subject: [PATCH v16 27/45] KVM: arm64: CCA: Allow populating initial contents
Date: Mon, 3 Aug 2026 14:43:43 +0100 [thread overview]
Message-ID: <20260803134403.80630-28-steven.price@arm.com> (raw)
In-Reply-To: <20260803134403.80630-1-steven.price@arm.com>
The VMM needs to populate the realm with some data before starting (e.g.
a kernel and initrd). This is measured by the RMM and used as part of
the attestation later on.
Signed-off-by: Steven Price <steven.price@arm.com>
---
Changes since v15:
* Handle negative error codes
Changes since v14:
* Holding of locks slots_lock and config_lock have been moved up the
callstack with lockdesp assertions placed in the lower functions.
* Add overflow check into kvm_arm_rmi_populate().
Changes since v13:
* Rename realm_create_protected_data_page() to realm_data_map_init().
Changes since v12:
* The ioctl now updates the structure with the amount populated rather
than returning this through the ioctl return code.
* Use the new RMM v2.0 range based RMI calls.
* Adapt to upstream changes in kvm_gmem_populate().
Changes since v11:
* The multiplex CAP is gone and there's a new ioctl which makes use of
the generic kvm_gmem_populate() functionality.
Changes since v7:
* Improve the error codes.
* Other minor changes from review.
Changes since v6:
* Handle host potentially having a larger page size than the RMM
granule.
* Drop historic "par" (protected address range) from
populate_par_region() - it doesn't exist within the current
architecture.
* Add a cond_resched() call in kvm_populate_realm().
Changes since v5:
* Refactor to use PFNs rather than tracking struct page in
realm_create_protected_data_page().
* Pull changes from a later patch (in the v5 series) for accessing
pages from a guest memfd.
* Do the populate in chunks to avoid holding locks for too long and
triggering RCU stall warnings.
---
arch/arm64/include/asm/kvm_rmi.h | 4 ++
arch/arm64/kvm/Kconfig | 1 +
arch/arm64/kvm/arm.c | 13 ++++
arch/arm64/kvm/rmi.c | 119 +++++++++++++++++++++++++++++++
4 files changed, 137 insertions(+)
diff --git a/arch/arm64/include/asm/kvm_rmi.h b/arch/arm64/include/asm/kvm_rmi.h
index 90563183a717..03f8bd2d13a2 100644
--- a/arch/arm64/include/asm/kvm_rmi.h
+++ b/arch/arm64/include/asm/kvm_rmi.h
@@ -108,6 +108,10 @@ int kvm_rec_exit(struct kvm_vcpu *vcpu, int rec_run_status);
int kvm_rec_handle_request(struct kvm_vcpu *vcpu);
bool kvm_rec_handle_hvc(struct kvm_vcpu *vcpu, int *ret);
+struct kvm_arm_rmi_populate;
+
+int kvm_arm_rmi_populate(struct kvm *kvm,
+ struct kvm_arm_rmi_populate *arg);
void kvm_realm_unmap_range(struct kvm *kvm,
unsigned long ipa,
unsigned long size,
diff --git a/arch/arm64/kvm/Kconfig b/arch/arm64/kvm/Kconfig
index 189e8ad78b22..83b95e836b4d 100644
--- a/arch/arm64/kvm/Kconfig
+++ b/arch/arm64/kvm/Kconfig
@@ -37,6 +37,7 @@ menuconfig KVM
select SCHED_INFO
select GUEST_PERF_EVENTS if PERF_EVENTS
select KVM_GUEST_MEMFD
+ select HAVE_KVM_ARCH_GMEM_POPULATE
select ARM_RMM
help
Support hosting virtualized guest machines.
diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index b7c308817d45..f1b26b263bf0 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -2154,6 +2154,19 @@ int kvm_arch_vm_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg)
return -EFAULT;
return kvm_vm_ioctl_get_reg_writable_masks(kvm, &range);
}
+ case KVM_ARM_RMI_POPULATE: {
+ struct kvm_arm_rmi_populate req;
+ int ret;
+
+ if (!kvm_is_realm(kvm))
+ return -ENXIO;
+ if (copy_from_user(&req, argp, sizeof(req)))
+ return -EFAULT;
+ ret = kvm_arm_rmi_populate(kvm, &req);
+ if (copy_to_user(argp, &req, sizeof(req)))
+ return -EFAULT;
+ return ret;
+ }
default:
return -EINVAL;
}
diff --git a/arch/arm64/kvm/rmi.c b/arch/arm64/kvm/rmi.c
index c8ec766d3dc0..d18c241f7eb2 100644
--- a/arch/arm64/kvm/rmi.c
+++ b/arch/arm64/kvm/rmi.c
@@ -609,6 +609,76 @@ void kvm_realm_unmap_range(struct kvm *kvm, unsigned long start,
realm_unmap_private_range(kvm, start, end, may_block);
}
+static int realm_data_map_init(struct kvm *kvm, unsigned long ipa,
+ kvm_pfn_t dst_pfn, kvm_pfn_t src_pfn,
+ unsigned long flags)
+{
+ struct realm *realm = &kvm->arch.realm;
+ phys_addr_t rd = virt_to_phys(realm->rd);
+ phys_addr_t dst_phys, src_phys;
+ long ret;
+
+ lockdep_assert_held(&kvm->slots_lock);
+ lockdep_assert_held(&kvm->arch.config_lock);
+
+ dst_phys = __pfn_to_phys(dst_pfn);
+ src_phys = __pfn_to_phys(src_pfn);
+
+ if (rmi_delegate_page(dst_phys))
+ return -ENXIO;
+
+retry:
+ ret = rmi_rtt_data_map_init(rd, dst_phys, ipa, src_phys, flags);
+ if (ret >= 0 && RMI_RETURN_STATUS(ret) == RMI_ERROR_RTT) {
+ /* Create missing RTTs and retry */
+ int level = RMI_RETURN_INDEX(ret);
+
+ KVM_BUG_ON(level >= KVM_PGTABLE_LAST_LEVEL, kvm);
+
+ ret = realm_create_rtt_levels(realm, ipa, level,
+ level + 1, NULL);
+ if (!ret)
+ goto retry;
+ }
+
+ if (ret && WARN_ON(rmi_undelegate_page(dst_phys))) {
+ /* Leak the page if the undelegate fails */
+ get_page(pfn_to_page(dst_pfn));
+ }
+
+ return ret <= 0 ? ret : -ENXIO;
+}
+
+static int populate_region_cb(struct kvm *kvm, gfn_t gfn, kvm_pfn_t pfn,
+ struct page *src_page, void *opaque)
+{
+ unsigned long data_flags = *(unsigned long *)opaque;
+ phys_addr_t ipa = gfn_to_gpa(gfn);
+
+ return realm_data_map_init(kvm, ipa, pfn, page_to_pfn(src_page),
+ data_flags);
+}
+
+static long populate_region(struct kvm *kvm,
+ gfn_t base_gfn,
+ unsigned long pages,
+ u64 uaddr,
+ unsigned long data_flags)
+{
+ long ret = 0;
+
+ lockdep_assert_held(&kvm->slots_lock);
+ lockdep_assert_held(&kvm->arch.config_lock);
+
+ if (!uaddr)
+ return -EINVAL;
+
+ ret = kvm_gmem_populate(kvm, base_gfn, u64_to_user_ptr(uaddr), pages,
+ false, populate_region_cb, &data_flags);
+
+ return ret;
+}
+
enum ripas_action {
RIPAS_INIT,
RIPAS_SET,
@@ -727,6 +797,55 @@ static int realm_ensure_created(struct kvm *kvm)
return realm_create_rd(kvm);
}
+int kvm_arm_rmi_populate(struct kvm *kvm,
+ struct kvm_arm_rmi_populate *args)
+{
+ unsigned long data_flags = 0;
+ unsigned long ipa_start = args->base;
+ unsigned long ipa_end = ipa_start + args->size;
+ long pages_populated;
+ int ret;
+
+ if (args->reserved ||
+ (args->flags & ~KVM_ARM_RMI_POPULATE_FLAGS_MEASURE) ||
+ args->base + args->size < args->base ||
+ !IS_ALIGNED(ipa_start, PAGE_SIZE) ||
+ !IS_ALIGNED(ipa_end, PAGE_SIZE) ||
+ !IS_ALIGNED(args->source_uaddr, PAGE_SIZE))
+ return -EINVAL;
+
+ if (args->flags & KVM_ARM_RMI_POPULATE_FLAGS_MEASURE)
+ data_flags |= RMI_MEASURE_CONTENT;
+
+ mutex_lock(&kvm->slots_lock);
+ mutex_lock(&kvm->arch.config_lock);
+
+ ret = realm_ensure_created(kvm);
+ if (ret)
+ goto out_unlock;
+
+ if (args->size == 0)
+ goto out_unlock;
+
+ pages_populated = populate_region(kvm, gpa_to_gfn(ipa_start),
+ args->size >> PAGE_SHIFT,
+ args->source_uaddr, data_flags);
+
+ if (pages_populated < 0) {
+ ret = pages_populated;
+ goto out_unlock;
+ }
+
+ args->size -= pages_populated << PAGE_SHIFT;
+ args->source_uaddr += pages_populated << PAGE_SHIFT;
+ args->base += pages_populated << PAGE_SHIFT;
+
+out_unlock:
+ mutex_unlock(&kvm->arch.config_lock);
+ mutex_unlock(&kvm->slots_lock);
+ return ret;
+}
+
static int kvm_complete_ripas_change(struct kvm_vcpu *vcpu)
{
struct kvm *kvm = vcpu->kvm;
--
2.43.0
next prev parent reply other threads:[~2026-08-03 13:46 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 13:43 [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Steven Price
2026-08-03 13:43 ` [PATCH v16 01/45] firmware: arm_rmm: Add SMC definitions for calling the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 02/45] firmware: arm_rmm: Add wrappers for direct RMI calls Steven Price
2026-08-03 13:43 ` [PATCH v16 03/45] firmware: arm_rmm: Check for RMI support at init Steven Price
2026-08-03 13:43 ` [PATCH v16 04/45] firmware: arm_rmm: Configure the RMM with the host's page size Steven Price
2026-08-03 13:43 ` [PATCH v16 05/45] firmware: arm_rmm: Add support for SRO Steven Price
2026-08-03 13:43 ` [PATCH v16 06/45] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Steven Price
2026-08-09 6:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 07/45] arm64: mm: Handle Granule Protection Faults (GPFs) Steven Price
2026-08-11 14:44 ` Catalin Marinas
2026-08-11 15:11 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 08/45] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2026-08-03 13:43 ` [PATCH v16 09/45] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Steven Price
2026-08-03 13:43 ` [PATCH v16 10/45] KVM: arm64: CCA: Add wrappers for realm related RMIs Steven Price
2026-08-03 13:43 ` [PATCH v16 11/45] KVM: arm64: CCA: Check for RMI support at KVM init Steven Price
2026-08-04 14:55 ` Fuad Tabba
2026-08-04 14:59 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 12/45] KVM: arm64: CCA: Check for LPA2 support Steven Price
2026-08-03 13:43 ` [PATCH v16 13/45] KVM: arm64: CCA: Define the user ABI Steven Price
2026-08-03 13:43 ` [PATCH v16 14/45] KVM: arm64: CCA: Add basic infrastructure for creating a realm Steven Price
2026-08-03 13:43 ` [PATCH v16 15/45] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Steven Price
2026-08-03 13:43 ` [PATCH v16 16/45] KVM: arm64: CCA: Allow passing the machine type in KVM creation Steven Price
2026-08-03 13:43 ` [PATCH v16 17/45] KVM: arm64: CCA: Tear down RTTs Steven Price
2026-08-03 22:29 ` Alper Gun
2026-08-04 12:16 ` Suzuki K Poulose
2026-08-11 14:51 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 18/45] KVM: arm64: CCA: Allocate and free RECs to match vCPUs Steven Price
2026-08-03 13:43 ` [PATCH v16 19/45] KVM: arm64: CCA: Support the VGIC in realms Steven Price
2026-08-03 13:43 ` [PATCH v16 20/45] KVM: arm64: CCA: Support timers in realm RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 21/45] KVM: arm64: CCA: Handle realm enter/exit Steven Price
2026-08-04 8:57 ` Aneesh Kumar K.V
2026-08-04 13:36 ` Aneesh Kumar K.V
2026-08-10 8:03 ` Kohei Enju
2026-08-03 13:43 ` [PATCH v16 22/45] KVM: arm64: CCA: Handle RMI_EXIT_RIPAS_CHANGE Steven Price
2026-08-05 15:59 ` Ackerley Tng
2026-08-06 8:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 23/45] KVM: arm64: CCA: Handle realm MMIO emulation Steven Price
2026-08-03 13:43 ` [PATCH v16 24/45] KVM: arm64: Expose support for private memory Steven Price
2026-08-05 16:02 ` Ackerley Tng
2026-08-07 10:12 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 25/45] KVM: arm64: CCA: Create the realm descriptor Steven Price
2026-08-03 13:43 ` [PATCH v16 26/45] KVM: arm64: CCA: Activate realms on first vCPU run Steven Price
2026-08-03 13:43 ` Steven Price [this message]
2026-08-06 22:43 ` [PATCH v16 27/45] KVM: arm64: CCA: Allow populating initial contents Ackerley Tng
2026-08-07 10:58 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 28/45] KVM: arm64: CCA: Set RIPAS of initial memslots Steven Price
2026-08-03 13:43 ` [PATCH v16 29/45] KVM: arm64: CCA: Support runtime faulting of memory Steven Price
2026-08-06 23:11 ` Ackerley Tng
2026-08-11 15:42 ` Catalin Marinas
2026-08-03 13:43 ` [PATCH v16 30/45] KVM: arm64: CCA: Handle realm vCPU load Steven Price
2026-08-10 14:46 ` Kohei Enju
2026-08-03 13:43 ` [PATCH v16 31/45] KVM: arm64: CCA: Validate register access for Realm VMs Steven Price
2026-08-03 13:43 ` [PATCH v16 32/45] KVM: arm64: CCA: Handle Realm PSCI requests Steven Price
2026-08-03 13:43 ` [PATCH v16 33/45] KVM: arm64: WARN on injected undef exceptions Steven Price
2026-08-03 13:43 ` [PATCH v16 34/45] KVM: arm64: CCA: Allow userspace to inject aborts Steven Price
2026-08-03 13:43 ` [PATCH v16 35/45] KVM: arm64: CCA: Support RSI_HOST_CALL Steven Price
2026-08-03 13:43 ` [PATCH v16 36/45] KVM: arm64: CCA: Allow checking SVE on VM instance Steven Price
2026-08-03 13:43 ` [PATCH v16 37/45] KVM: arm64: CCA: Prevent Device mappings for realms Steven Price
2026-08-03 13:43 ` [PATCH v16 38/45] KVM: arm64: CCA: Propagate breakpoint and watchpoint counts to userspace Steven Price
2026-08-03 13:43 ` [PATCH v16 39/45] KVM: arm64: CCA: Set breakpoint parameters through SET_ONE_REG Steven Price
2026-08-03 13:43 ` [PATCH v16 40/45] KVM: arm64: CCA: Propagate max SVE vector length from the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 41/45] KVM: arm64: CCA: Configure max SVE vector length for a Realm Steven Price
2026-08-03 13:43 ` [PATCH v16 42/45] KVM: arm64: CCA: Provide register list for unfinalized RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 43/45] KVM: arm64: CCA: Provide an accurate register list Steven Price
2026-08-03 13:44 ` [PATCH v16 44/45] KVM: arm64: CCA: Require ICH_HCR_EL2.TDIR for realms Steven Price
2026-08-10 4:58 ` Kohei Enju
2026-08-10 9:41 ` Marc Zyngier
2026-08-03 13:44 ` [PATCH v16 45/45] KVM: arm64: CCA: Enable realms to be created Steven Price
2026-08-03 15:01 ` [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Marc Zyngier
2026-08-03 15:06 ` Steven Price
2026-08-03 15:20 ` Marc Zyngier
2026-08-03 15:45 ` Steven Price
2026-08-04 14:24 ` Fuad Tabba
2026-08-06 22:05 ` Suzuki K Poulose
2026-08-11 4:44 ` Gavin Shan
2026-08-11 11:12 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260803134403.80630-28-steven.price@arm.com \
--to=steven.price@arm.com \
--cc=WeiLin.Chang@arm.com \
--cc=alexandru.elisei@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christoffer.dall@arm.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=james.morse@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=sdonthineni@nvidia.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vannapurve@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.