From: Gavin Shan <gshan@redhat.com>
To: Suzuki K Poulose <suzuki.poulose@arm.com>,
kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com,
linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
aneesh.kumar@kernel.org, oupton@kernel.org, joey.gouly@arm.com,
tabba@google.com, yuzenghui@huawei.com,
linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
sdonthineni@nvidia.com, alpergun@google.com,
fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
lpieralisi@kernel.org, enju.kohei@fujitsu.com
Subject: Re: [PATCH v19 00/20] KVM: arm64: CCA: Add basic plumbing for Realms
Date: Thu, 24 Sep 2026 20:40:50 +1000 [thread overview]
Message-ID: <a5dbea3b-d175-42d2-a29d-9280c92236da@redhat.com> (raw)
In-Reply-To: <20260920212845.707-1-suzuki.poulose@arm.com>
On 9/21/26 7:28 AM, Suzuki K Poulose wrote:
> This series is a trimmed down version of the Arm CCA KVM support, previously
> posted here [0]. Like in the v17, we have tried to split the entire series
> into the following chunks.
>
> 1) Base RMM RMI support under drivers/firmware/arm_rmm -> [1]
> 2) Linux Host support for handling GPFs - [2]
> 3) NEW: Enlighten KVM arm64 about the different VM types and use call
> backs for the VM type, rather than spilling the is_this_type_of_vm()
> everywhere. Adds VCPU and Stage2 MMU related callbacks with support
> for the existing VM types. There are other places where we may be
> able to abstract, but those need careful performance evaluations
> to make sure they are fit (e.g., vcpu_run)
>
> With that in place we generalise the predicate "kvm_vm_is_protected()"
> to cover all "Confidential" VMs (which includes Protected VM and Realms),
> allowing us to handle common themes without having to do things like :
>
> if (kvm_vm_is_protected() || kvm_vm_is_realm())
>
> Also replaces the code with precise check for a given VM type to
> avoiding combination of if (). e.g,, kvm_vm_is_unprotected_pkvm(kvm).
> The checks under arch/arm64/kvm/{nvhe,pkvm} still retain the vm_is_protected()
> check as pVMs are the only possible protected VMs there.
>
> 4) Bare minimal Realm VM support without the actual functionality to
> run a Realm. This would help the maintainers to review the series in
> smaller chunks. This doesn't depend on [1] and can be independently
> merged, without being "functional".
> This series includes vcpu operations and the s2 vm operations, which
> do need the RMI driver backend to be meaningful. But the KVM handler
> is in the right shape. The remaining changes would be added once the
> RMI firmware library lands. Also covers the SET_ONE_REG/GET_ONE_REG
>
> 5) Core implementation of the RMI driver for KVM and actual enablement of the
> Realm support. This depends on (1), (2) and the guest-memfd-in-place
> conversion series v12 from Ackerley. This is available here at the integration
> branch [3]
>
> This series is comprised of (3) and (4) above.
>
> The integration branch has been tested with the following components:
>
> tf-RMM: main branch (commit 5e6e2acd) compliant to RMM-v2.0-beta3 [4]
> kvmtool: git@git.gitlab.arm.com:linux-arm/kvmtool-cca.git cca/kvm-v18
>
> [0] Arm CCA KVM Support v16 : https://lore.kernel.org/all/20260803134403.80630-1-steven.price@arm.com
> [1] Linux firmware RMI https://lore.kernel.org/all/20260912083611.2513845-1-suzuki.poulose@arm.com
> [2] Linux GPF Host https://lore.kernel.org/all/20260913070459.2547407-1-suzuki.poulose@arm.com
> [3] https://git.gitlab.arm.com/linux-arm/linux-cca/ cca/cca-host/kvm-v19/integration
> [4] https://support.arm.com/documentation/den0137/2-0bet3/
>
Apart from the issue found against PATCH[v19 05/20], I didn't see more issues with this
series in my tests where kselftest/kvm cases and kvm-unit-tests are done on various
combinations: 4KB host kernel, 64KB host kernel, kernel parameter "kvm-arm.mode=
{nvhe, protected}" or nil. So with the found issue caused by PATCH[v19 05/20] fixed:
Tested-by: Gavin Shan <gshan@redhat.com>
Thanks,
Gavin
> Changes since v18:
> https://lore.kernel.org/all/20260915160141.3543048-1-suzuki.poulose@arm.com
>
> - Patch count down by 3, after merging different patches together, see more below
> - Retain NULL vm_offset for pVMs and move the counter offset flag initialisation
> to kvm_timer_init_vm() - Marc
> - Merge widening the scope of kvm_vm_is_protected() to the patch where the
> flavors are introduced(Marc) and also dropped Fuad's reviewed-by, as the
> patch is now bigger.
> - Merge "Use kvm_vm_is_unprotected_pkvm" for !kvm_vm_is_protected to patch
> where flavor is introuced.
> - Merge "vgic-v3" mandate and preventing vgic-v2 mappings to a single patch,
> where kvm_vm_hyp_is_distrusting() introduced - Fuad
> - Drop kvm_vm_hyp_is_pkvm(), reverting to is_protected_kvm_enabled()
> - Use is_protected_kvm_enabeld() for pKVM guest flavor checks.
> - s/PKVM/pKVM for commit descriptions too
> - Make sure the vm_mem_abort callback is !NULL at init time.
> - Bail out early for !pKVM && !Realm VMs in kvm_vm_ioctl_allowed(). Use
> kvm_vm_hyp_is_distrusting()
> - WARN_ON_ONCE(!kvm) for kvm_vm_ioctl_allowed() as it must be only called with
> a valid kvm instance and only from kvm_arch_vm_ioctl()
> - Rename kvm_arch_vm_{ext,ioctl}_allowed => kvm_vm_{ext,ioctl}_allowed - Fuad
> - Move kvm_realm_ext_allowed() to asm/kvm_rmi.h - Fuad
> - Don't expose PMCR_EL0 to the userspace until we support PMU
>
>
> Changes since v17:
> https://lore.kernel.org/all/20260908162223.1683432-1-suzuki.poulose@arm.com
>
> - Add a patch to fix pKVM handling of SYS_CNTVCT/CNTPCT to override the counter
> offset (Patch1)
> - Restrict Realms to VGIC v3 only - New patch
> - Add kvm_vm_is_unprotected() to replace is_protected_kvm_enabled() &&
> !kvm_vm_is_protected() - New patch
> - Use macro to initialize the per-flavor vcpu, s2_vm ops
> - Add a wrapper to initialise vcpu and s2_vm ops with a BUILD_BUG_ON()
> for the array size checks against VM flavour types
> - Drop forward decalaration of the vcpu, s2_vm operations that spoiled the
> fun ;-)
> - Remove irrelevant comment about the order of timer loading for !VHE
> - Use the explicti kvm_call_hyp_nvhe for pKVM specific ops
> - Don't call nvhe_vcpu_put from pkvm_vcpu_put, open code them
> - Drop cpu argument for vcpu_load() callback. We set the cpu
> before the callbacks are invoked
> - Drop kvm_vm_is_confidential(), instead widen the scope of kvm_vm_is_protected()
> to cover pVMs and Realms. Add an explicit helper kvm_vm_is_protected_pkvm()
> for the cases where we need to check for a "pVM on pKVM"
> - Add kvm_vm_hyp_is_pkvm() for checking if the VM is running on pKVM.
> covers both unprotected and pvms. But really uses is_protected_kvm_enabled()
> under the hood
> - Add kvm_vm_hyp_is_distrusting() to cover pKVM guests (both protected and
> unprotected) and Realms. Use this for preventing the vgic v2 mapping into
> Stage2 for a guest
> - Drop superfluous !kvm check from kvm_vm_ioctl_enable_cap() - Sashiko
> - Drop KVM_CAP_CREATE_IRQCHIP, as we don't support VGIC_V2 for Realms
> - Filter out the vm_ioctls that are based on blocked cap.
> - Repurpose the pkvm plumbing for filtering the caps and ioctl to generic
> and plumb the Realm support in
> - s/PKVM/pKVM for the comments
> - Drop type argument for pkvm_init_host_vm and also drop protected variable,
> now that we have the vm_flavor to check.
> - Use kvm_vm_hyp_is_pkvm() to replace is_protected_kvm_enabled() with valid
> kvm instance
> - CCA: Merge the GET/SET REG handling patches into a single patch
> - CCA: Reword the commit description for SVE VL access handling
> - Reordered the patches to group the Realm realted to changes to the rear end
>
> Jean-Philippe Brucker (2):
> KVM: arm64: CCA: Expose SVE VL register before VCPU finalization
> KVM: arm64: CCA: Control user register access for Realms
>
> Steven Price (4):
> KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h
> KVM: arm64: CCA: Introduce Realms
> KVM: arm64: CCA: WARN on injected undef exceptions
> KVM: arm64: CCA: Support timers in realm RECs
>
> Suzuki K Poulose (14):
> KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0
> KVM: arm64: Disable Steal time accounting for protected guests
> KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h
> KVM: arm64: Track the type of VM in kvm_arch
> KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks
> KVM: arm64: Add vcpu load/put call backs for flavors
> KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range
> KVM: arm64: Add VM specific callback for S2 MMU operations
> KVM: arm64: Abstract out memory abort handling
> KVM: arm64: Mandate VGIC v3 for for VMs running on hyp that don't
> trust the host
> KVM: arm64: CCA: Add a new mode for supporting Realm guests
> KVM: arm64: CCA: Add VCPU load/put for Realms
> KVM: arm64: CCA: Add bare minimal S2 operations for Realm
> KVM: arm64: CCA: Don't expose unsupported capabilities for realm
> guests
>
> .../admin-guide/kernel-parameters.txt | 3 +
> arch/arm64/include/asm/kvm_emulate.h | 16 +
> arch/arm64/include/asm/kvm_host.h | 69 +++-
> arch/arm64/include/asm/kvm_pgtable.h | 6 +-
> arch/arm64/include/asm/kvm_pkvm.h | 25 +-
> arch/arm64/include/asm/kvm_rmi.h | 84 +++++
> arch/arm64/include/asm/virt.h | 1 +
> arch/arm64/kvm/Makefile | 2 +-
> arch/arm64/kvm/arch_timer.c | 34 +-
> arch/arm64/kvm/arm.c | 300 +++++++++++++++---
> arch/arm64/kvm/guest.c | 73 ++++-
> arch/arm64/kvm/handle_exit.c | 2 +-
> arch/arm64/kvm/hyp/nvhe/pkvm.c | 6 +-
> arch/arm64/kvm/hyp/pgtable.c | 1 +
> arch/arm64/kvm/hypercalls.c | 4 +-
> arch/arm64/kvm/inject_fault.c | 1 +
> arch/arm64/kvm/mmu.c | 210 +++++++++---
> arch/arm64/kvm/pkvm.c | 6 +-
> arch/arm64/kvm/pvtime.c | 14 +-
> arch/arm64/kvm/rmi.c | 18 ++
> arch/arm64/kvm/sys_regs.c | 28 +-
> arch/arm64/kvm/vgic/vgic-init.c | 2 +
> include/kvm/arm_psci.h | 2 +
> 23 files changed, 752 insertions(+), 155 deletions(-)
> create mode 100644 arch/arm64/include/asm/kvm_rmi.h
> create mode 100644 arch/arm64/kvm/rmi.c
>
next prev parent reply other threads:[~2026-09-24 10:41 UTC|newest]
Thread overview: 77+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-20 21:28 [PATCH v19 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 01/20] KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0 Suzuki K Poulose
2026-09-22 19:25 ` Jonathan Cameron
2026-09-22 21:53 ` Suzuki K Poulose
2026-09-23 16:48 ` Jonathan Cameron
2026-09-22 22:04 ` Suzuki K Poulose
2026-09-23 16:51 ` Jonathan Cameron
2026-09-20 21:28 ` [PATCH v19 02/20] KVM: arm64: Disable Steal time accounting for protected guests Suzuki K Poulose
2026-09-20 21:44 ` sashiko-bot
2026-09-20 22:24 ` Suzuki K Poulose
2026-09-21 23:07 ` Suzuki K Poulose
2026-09-28 0:14 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 03/20] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-22 19:32 ` Jonathan Cameron
2026-09-20 21:28 ` [PATCH v19 04/20] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-20 21:38 ` sashiko-bot
2026-09-21 8:25 ` Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 05/20] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-20 21:38 ` sashiko-bot
2026-09-21 8:18 ` Suzuki K Poulose
2026-09-22 19:40 ` Jonathan Cameron
2026-09-23 6:05 ` Gavin Shan
2026-09-23 6:19 ` Gavin Shan
2026-09-23 10:24 ` Suzuki K Poulose
2026-09-23 13:23 ` Gavin Shan
2026-09-23 13:29 ` Gavin Shan
2026-09-23 13:54 ` Suzuki K Poulose
2026-09-23 16:27 ` Suzuki K Poulose
2026-09-23 21:37 ` Suzuki K Poulose
2026-09-24 1:11 ` Gavin Shan
2026-09-24 8:48 ` Suzuki K Poulose
2026-09-24 10:37 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 06/20] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-22 19:57 ` Jonathan Cameron
2026-09-22 22:09 ` Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 07/20] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-22 22:12 ` Jonathan Cameron
2026-09-20 21:28 ` [PATCH v19 08/20] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-22 22:15 ` Jonathan Cameron
2026-09-28 0:17 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 09/20] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-22 22:29 ` Jonathan Cameron
2026-09-22 23:21 ` Suzuki K Poulose
2026-09-23 16:54 ` Jonathan Cameron
2026-09-24 15:11 ` Suzuki K Poulose
2026-09-28 1:09 ` Gavin Shan
2026-09-28 1:25 ` Gavin Shan
2026-09-28 8:13 ` Suzuki K Poulose
2026-09-28 8:10 ` Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 10/20] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-22 22:38 ` Jonathan Cameron
2026-09-22 23:55 ` Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 11/20] KVM: arm64: Mandate VGIC v3 for for VMs running on hyp that don't trust the host Suzuki K Poulose
2026-09-22 22:42 ` Jonathan Cameron
2026-09-22 23:38 ` Suzuki K Poulose
2026-09-28 1:10 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 12/20] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-22 22:43 ` Jonathan Cameron
2026-09-20 21:28 ` [PATCH v19 13/20] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-28 1:22 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 14/20] KVM: arm64: CCA: Add bare minimal S2 operations for Realm Suzuki K Poulose
2026-09-28 1:27 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 15/20] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-22 22:49 ` Jonathan Cameron
2026-09-28 1:27 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 16/20] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-22 22:53 ` Jonathan Cameron
2026-09-20 21:28 ` [PATCH v19 17/20] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-22 22:54 ` Jonathan Cameron
2026-09-28 1:28 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 18/20] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-20 21:28 ` [PATCH v19 19/20] KVM: arm64: CCA: Expose SVE VL register before VCPU finalization Suzuki K Poulose
2026-09-28 1:29 ` Gavin Shan
2026-09-20 21:28 ` [PATCH v19 20/20] KVM: arm64: CCA: Control user register access for Realms Suzuki K Poulose
2026-09-28 1:30 ` Gavin Shan
2026-09-24 10:40 ` Gavin Shan [this message]
2026-09-24 10:49 ` [PATCH v19 00/20] KVM: arm64: CCA: Add basic plumbing " Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a5dbea3b-d175-42d2-a29d-9280c92236da@redhat.com \
--to=gshan@redhat.com \
--cc=WeiLin.Chang@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=enju.kohei@fujitsu.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.