From: Itaru Kitayama <itaru.kitayama@linux.dev>
To: Steven Price <steven.price@arm.com>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
Catalin Marinas <catalin.marinas@arm.com>,
Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
James Morse <james.morse@arm.com>,
Oliver Upton <oliver.upton@linux.dev>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
Alexandru Elisei <alexandru.elisei@arm.com>,
Christoffer Dall <christoffer.dall@arm.com>,
Fuad Tabba <tabba@google.com>,
linux-coco@lists.linux.dev,
Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
Gavin Shan <gshan@redhat.com>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Alper Gun <alpergun@google.com>,
"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>
Subject: Re: [PATCH v5 00/43] arm64: Support for Arm CCA in KVM
Date: Mon, 2 Dec 2024 14:10:56 +0900 [thread overview]
Message-ID: <Z01BYOgsLXV5yULk@vm3> (raw)
In-Reply-To: <20241004152804.72508-1-steven.price@arm.com>
On Fri, Oct 04, 2024 at 04:27:21PM +0100, Steven Price wrote:
> This series adds support for running protected VMs using KVM under the
> Arm Confidential Compute Architecture (CCA).
>
> The related guest support was posted[1] earlier. As with the guest this
> series moves to the "v1.0-rel0" version of the specification[2].
>
> Almost all changes since v4[3] are either due to rebasing or minor
> changes to improve the code following review comments. There are two bug
> fixes:
>
> * Setting the GPRS on entry after an exit where the host is allowed to
> change registers is now done in kvm_rec_enter(). This fixes a bug
> where register updates done by user space were being ignored.
>
> * Drop the PTE_SHARED bit for unprotected page table entries - this bit
> isn't controlled by the host and the RMM now enforces the bit is
> zero.
>
> Major limitations:
>
> * Only supports 4k host PAGE_SIZE (if PAGE_SIZE != 4k then the realm
> extensions are disabled).
>
> * No support for huge pages when mapping the guest's pages. There is
> some 'dead' code left over from before guest_mem was supported. This
> is partly a current limitation of guest_memfd.
>
> The ABI to the RMM (the RMI) is based on RMM v1.0-rel0 specification[2].
>
> This series is based on v6.12-rc1. It is also available as a git
> repository:
>
> https://gitlab.arm.com/linux-arm/linux-cca cca-host/v5
>
> Work in progress changes for kvmtool are available from the git
> repository below:
>
> https://gitlab.arm.com/linux-arm/kvmtool-cca cca/v3
>
> [1] https://lore.kernel.org/r/20241004144307.66199-1-steven.price%40arm.com
> [2] https://developer.arm.com/documentation/den0137/1-0rel0/
> [3] https://lore.kernel.org/r/20240821153844.60084-1-steven.price%40arm.com
>
> Jean-Philippe Brucker (7):
> arm64: RME: Propagate number of breakpoints and watchpoints to
> userspace
> arm64: RME: Set breakpoint parameters through SET_ONE_REG
> arm64: RME: Initialize PMCR.N with number counter supported by RMM
> arm64: RME: Propagate max SVE vector length from RMM
> arm64: RME: Configure max SVE vector length for a Realm
> arm64: RME: Provide register list for unfinalized RME RECs
> arm64: RME: Provide accurate register list
>
> Joey Gouly (2):
> arm64: rme: allow userspace to inject aborts
> arm64: rme: support RSI_HOST_CALL
>
> Sean Christopherson (1):
> KVM: Prepare for handling only shared mappings in mmu_notifier events
>
> Steven Price (29):
> arm64: RME: Handle Granule Protection Faults (GPFs)
> arm64: RME: Add SMC definitions for calling the RMM
> arm64: RME: Add wrappers for RMI calls
> arm64: RME: Check for RME support at KVM init
> arm64: RME: Define the user ABI
> arm64: RME: ioctls to create and configure realms
> arm64: kvm: Allow passing machine type in KVM creation
> arm64: RME: Keep a spare page delegated to the RMM
> arm64: RME: RTT tear down
> arm64: RME: Allocate/free RECs to match vCPUs
> arm64: RME: Support for the VGIC in realms
> KVM: arm64: Support timers in realm RECs
> arm64: RME: Allow VMM to set RIPAS
> arm64: RME: Handle realm enter/exit
> KVM: arm64: Handle realm MMIO emulation
> arm64: RME: Allow populating initial contents
> arm64: RME: Runtime faulting of memory
> KVM: arm64: Handle realm VCPU load
> KVM: arm64: Validate register access for a Realm VM
> KVM: arm64: Handle Realm PSCI requests
> KVM: arm64: WARN on injected undef exceptions
> arm64: Don't expose stolen time for realm guests
> arm64: RME: Always use 4k pages for realms
> arm64: rme: Prevent Device mappings for Realms
> arm_pmu: Provide a mechanism for disabling the physical IRQ
> arm64: rme: Enable PMU support with a realm guest
> kvm: rme: Hide KVM_CAP_READONLY_MEM for realm guests
> arm64: kvm: Expose support for private memory
> KVM: arm64: Allow activating realms
>
> Suzuki K Poulose (4):
> kvm: arm64: pgtable: Track the number of pages in the entry level
> kvm: arm64: Include kvm_emulate.h in kvm/arm_psci.h
> kvm: arm64: Expose debug HW register numbers for Realm
> arm64: rme: Allow checking SVE on VM instance
On FVP, the v5+v7 kernel is unable to execute virt-manager:
Starting install...
Allocating 'test9.qcow2' | 0 B 00:00 ...
Removing disk 'test9.qcow2' | 0 B 00:00
ERROR internal error: process exited while connecting to monitor: 2024-12-04T18:56:11.646168Z qemu-system-aarch64: -accel kvm: ioctl(KVM_CREATE_VM) failed: Invalid argument
2024-12-04T18:56:11.646520Z qemu-system-aarch64: -accel kvm: failed to initialize kvm: Invalid argument
Domain installation does not appear to have been successful.
Below is my virt-manager options:
virt-install --machine=virt --arch=aarch64 --name=test9 --memory=2048 --vcpu=1 --nographic --check all=off --features acpi=off --virt-type kvm --boot kernel=Image-cca,initrd=rootfs.cpio,kernel_args='earlycon console=ttyAMA0 rdinit=/sbin/init rw root=/dev/vda acpi=off' --qemu-commandline='-M virt,confidential-guest-support=rme0,gic-version=3 -cpu host -object rme-guest,id=rme0 -nodefaults' --disk size=4 --import --osinfo detect=on,require=off
Userland is Ubuntu 24.10, the VMM is Linaro's cca/2024-11-20:
https://git.codelinaro.org/linaro/dcap/qemu/-/tree/cca/2024-11-20?ref_type=heads
virt-install doesn't complain if I try to bring up a normal VM.
Thanks,
Itaru.
>
> Documentation/virt/kvm/api.rst | 3 +
> arch/arm64/include/asm/kvm_emulate.h | 34 +
> arch/arm64/include/asm/kvm_host.h | 16 +-
> arch/arm64/include/asm/kvm_pgtable.h | 2 +
> arch/arm64/include/asm/kvm_rme.h | 155 +++
> arch/arm64/include/asm/rmi_cmds.h | 510 ++++++++
> arch/arm64/include/asm/rmi_smc.h | 255 ++++
> arch/arm64/include/asm/virt.h | 1 +
> arch/arm64/include/uapi/asm/kvm.h | 49 +
> arch/arm64/kvm/Kconfig | 1 +
> arch/arm64/kvm/Makefile | 3 +-
> arch/arm64/kvm/arch_timer.c | 45 +-
> arch/arm64/kvm/arm.c | 166 ++-
> arch/arm64/kvm/guest.c | 99 +-
> arch/arm64/kvm/hyp/pgtable.c | 5 +-
> arch/arm64/kvm/hypercalls.c | 4 +-
> arch/arm64/kvm/inject_fault.c | 2 +
> arch/arm64/kvm/mmio.c | 10 +-
> arch/arm64/kvm/mmu.c | 185 ++-
> arch/arm64/kvm/pmu-emul.c | 7 +-
> arch/arm64/kvm/psci.c | 29 +
> arch/arm64/kvm/reset.c | 23 +-
> arch/arm64/kvm/rme-exit.c | 207 ++++
> arch/arm64/kvm/rme.c | 1628 ++++++++++++++++++++++++++
> arch/arm64/kvm/sys_regs.c | 83 +-
> arch/arm64/kvm/vgic/vgic-v3.c | 8 +-
> arch/arm64/kvm/vgic/vgic.c | 41 +-
> arch/arm64/mm/fault.c | 31 +-
> drivers/perf/arm_pmu.c | 15 +
> include/kvm/arm_arch_timer.h | 2 +
> include/kvm/arm_pmu.h | 4 +
> include/kvm/arm_psci.h | 2 +
> include/linux/kvm_host.h | 2 +
> include/linux/perf/arm_pmu.h | 5 +
> include/uapi/linux/kvm.h | 31 +-
> virt/kvm/kvm_main.c | 7 +
> 36 files changed, 3569 insertions(+), 101 deletions(-)
> create mode 100644 arch/arm64/include/asm/kvm_rme.h
> create mode 100644 arch/arm64/include/asm/rmi_cmds.h
> create mode 100644 arch/arm64/include/asm/rmi_smc.h
> create mode 100644 arch/arm64/kvm/rme-exit.c
> create mode 100644 arch/arm64/kvm/rme.c
>
> --
> 2.34.1
>
next prev parent reply other threads:[~2024-12-02 5:11 UTC|newest]
Thread overview: 82+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-10-04 15:27 [PATCH v5 00/43] arm64: Support for Arm CCA in KVM Steven Price
2024-10-04 15:27 ` [PATCH v5 01/43] KVM: Prepare for handling only shared mappings in mmu_notifier events Steven Price
2024-10-04 15:27 ` [PATCH v5 02/43] kvm: arm64: pgtable: Track the number of pages in the entry level Steven Price
2024-10-23 4:03 ` Gavin Shan
2024-10-23 14:35 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 03/43] kvm: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2024-10-04 15:27 ` [PATCH v5 04/43] arm64: RME: Handle Granule Protection Faults (GPFs) Steven Price
2024-10-24 14:17 ` Aneesh Kumar K.V
2024-10-25 13:24 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 05/43] arm64: RME: Add SMC definitions for calling the RMM Steven Price
2024-10-07 8:54 ` Suzuki K Poulose
2024-10-25 6:37 ` Gavin Shan
2024-10-25 13:24 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 06/43] arm64: RME: Add wrappers for RMI calls Steven Price
2024-10-25 7:03 ` Gavin Shan
2024-10-25 13:24 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 07/43] arm64: RME: Check for RME support at KVM init Steven Price
2024-10-07 10:34 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 08/43] arm64: RME: Define the user ABI Steven Price
2024-10-04 15:27 ` [PATCH v5 09/43] arm64: RME: ioctls to create and configure realms Steven Price
2024-10-08 16:31 ` Suzuki K Poulose
2024-10-30 7:55 ` Aneesh Kumar K.V
2024-11-01 16:22 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 10/43] kvm: arm64: Expose debug HW register numbers for Realm Steven Price
2024-10-04 15:27 ` [PATCH v5 11/43] arm64: kvm: Allow passing machine type in KVM creation Steven Price
2024-10-04 15:27 ` [PATCH v5 12/43] arm64: RME: Keep a spare page delegated to the RMM Steven Price
2024-10-04 15:27 ` [PATCH v5 13/43] arm64: RME: RTT tear down Steven Price
2024-10-15 11:25 ` Suzuki K Poulose
2024-11-01 16:35 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 14/43] arm64: RME: Allocate/free RECs to match vCPUs Steven Price
2024-10-15 12:48 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 15/43] arm64: RME: Support for the VGIC in realms Steven Price
2024-10-15 13:02 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 16/43] KVM: arm64: Support timers in realm RECs Steven Price
2024-10-04 15:27 ` [PATCH v5 17/43] arm64: RME: Allow VMM to set RIPAS Steven Price
2024-10-16 8:46 ` Suzuki K Poulose
2024-10-30 7:52 ` Aneesh Kumar K.V
2024-10-04 15:27 ` [PATCH v5 18/43] arm64: RME: Handle realm enter/exit Steven Price
2024-10-17 13:00 ` Suzuki K Poulose
2024-11-29 12:18 ` Steven Price
2024-11-29 13:45 ` Suzuki K Poulose
2024-11-29 14:55 ` Steven Price
2024-10-04 15:27 ` [PATCH v5 19/43] KVM: arm64: Handle realm MMIO emulation Steven Price
2024-10-07 4:31 ` Aneesh Kumar K.V
2024-10-07 10:22 ` Steven Price
2024-10-17 11:59 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 20/43] arm64: RME: Allow populating initial contents Steven Price
2024-10-04 15:27 ` [PATCH v5 21/43] arm64: RME: Runtime faulting of memory Steven Price
2024-10-22 5:36 ` Aneesh Kumar K.V
2024-10-23 5:50 ` Aneesh Kumar K.V
2024-10-24 13:51 ` Suzuki K Poulose
2024-10-24 14:30 ` Aneesh Kumar K.V
2024-10-04 15:27 ` [PATCH v5 22/43] KVM: arm64: Handle realm VCPU load Steven Price
2024-10-04 15:27 ` [PATCH v5 23/43] KVM: arm64: Validate register access for a Realm VM Steven Price
2024-10-17 15:32 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 24/43] KVM: arm64: Handle Realm PSCI requests Steven Price
2024-10-04 15:27 ` [PATCH v5 25/43] KVM: arm64: WARN on injected undef exceptions Steven Price
2024-10-04 15:27 ` [PATCH v5 26/43] arm64: Don't expose stolen time for realm guests Steven Price
2024-10-18 13:17 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 27/43] arm64: rme: allow userspace to inject aborts Steven Price
2024-10-04 15:27 ` [PATCH v5 28/43] arm64: rme: support RSI_HOST_CALL Steven Price
2024-10-04 15:27 ` [PATCH v5 29/43] arm64: rme: Allow checking SVE on VM instance Steven Price
2024-10-04 15:27 ` [PATCH v5 30/43] arm64: RME: Always use 4k pages for realms Steven Price
2024-10-04 15:27 ` [PATCH v5 31/43] arm64: rme: Prevent Device mappings for Realms Steven Price
2024-10-18 13:30 ` Suzuki K Poulose
2024-10-04 15:27 ` [PATCH v5 32/43] arm_pmu: Provide a mechanism for disabling the physical IRQ Steven Price
2024-10-04 15:27 ` [PATCH v5 33/43] arm64: rme: Enable PMU support with a realm guest Steven Price
2024-10-04 15:27 ` [PATCH v5 34/43] kvm: rme: Hide KVM_CAP_READONLY_MEM for realm guests Steven Price
2024-10-04 15:27 ` [PATCH v5 35/43] arm64: RME: Propagate number of breakpoints and watchpoints to userspace Steven Price
2024-10-04 15:27 ` [PATCH v5 36/43] arm64: RME: Set breakpoint parameters through SET_ONE_REG Steven Price
2024-10-04 15:27 ` [PATCH v5 37/43] arm64: RME: Initialize PMCR.N with number counter supported by RMM Steven Price
2024-10-04 15:27 ` [PATCH v5 38/43] arm64: RME: Propagate max SVE vector length from RMM Steven Price
2024-10-04 15:28 ` [PATCH v5 39/43] arm64: RME: Configure max SVE vector length for a Realm Steven Price
2024-10-04 15:28 ` [PATCH v5 40/43] arm64: RME: Provide register list for unfinalized RME RECs Steven Price
2024-10-04 15:28 ` [PATCH v5 41/43] arm64: RME: Provide accurate register list Steven Price
2024-10-04 15:28 ` [PATCH v5 42/43] arm64: kvm: Expose support for private memory Steven Price
2024-10-09 7:03 ` kernel test robot
2024-10-04 15:28 ` [PATCH v5 43/43] KVM: arm64: Allow activating realms Steven Price
2024-12-02 5:10 ` Itaru Kitayama [this message]
2024-12-02 8:54 ` [PATCH v5 00/43] arm64: Support for Arm CCA in KVM Steven Price
2024-12-02 10:26 ` Jean-Philippe Brucker
2024-12-02 10:42 ` Itaru Kitayama
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Z01BYOgsLXV5yULk@vm3 \
--to=itaru.kitayama@linux.dev \
--cc=alexandru.elisei@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christoffer.dall@arm.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=james.morse@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.