From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvmarm@lists.linux.dev, kvm@vger.kernel.org,
Marc Zyngier <maz@kernel.org>, Oliver Upton <oupton@kernel.org>
Subject: Re: [PATCH v17 12/20] KVM: arm64: CCA: Support timers in realm RECs
Date: Tue, 8 Sep 2026 19:58:18 +0100 [thread overview]
Message-ID: <f523ceb8-faa7-412d-9227-aca139e2bc1e@arm.com> (raw)
In-Reply-To: <20260908165643.50C501F00A3A@smtp.kernel.org>
On 08/09/2026 17:56, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] Realm VM timers are blackholed on GICv5 hosts due to unconditional physical interrupt masking combined with disabled direct injection.
> --
>
> commit 759ada4556cf9518a1b30ec3610b7b7833129bd9
> Author: Steven Price <steven.price@arm.com>
>
> KVM: arm64: CCA: Support timers in realm RECs
>
> This commit adds support for handling timers when exiting a realm REC to the
> normal world. It implements realm_timer_irq_ops which relies on the existing
> software resampling mechanism for Realm timer interrupts.
>
>> diff --git a/arch/arm64/kvm/arch_timer.c b/arch/arm64/kvm/arch_timer.c
>> index eba84cab95d01..3eddf44f7b1dd 100644
>> --- a/arch/arm64/kvm/arch_timer.c
>> +++ b/arch/arm64/kvm/arch_timer.c
> [ ... ]
>> @@ -1609,8 +1623,12 @@ int kvm_timer_enable(struct kvm_vcpu *vcpu)
>>
>> get_timer_map(vcpu, &map);
>>
>> - ops = vgic_is_v5(vcpu->kvm) ? &arch_timer_irq_ops_vgic_v5 :
>> - &arch_timer_irq_ops;
>> + if (vcpu_is_rec(vcpu))
>> + ops = &realm_timer_irq_ops;
>> + else if (vgic_is_v5(vcpu->kvm))
>> + ops = &arch_timer_irq_ops_vgic_v5;
>> + else
>> + ops = &arch_timer_irq_ops;
>>
>> for (int i = 0; i < nr_timers(vcpu); i++)
>> kvm_vgic_set_irq_ops(vcpu, timer_irq(vcpu_get_timer(vcpu, i)), ops);
>
> [Severity: High]
> Will this cause Realm VM timers to be lost on a GICv5 host?
>
> When a Realm VM is created on a GICv5 host, vcpu_is_rec(vcpu) takes precedence,
> assigning realm_timer_irq_ops. However, this struct lacks the
> .set_direct_injection callback used for hardware direct injection.
>
> At the same time, because vgic_is_v5(vcpu->kvm) is still true for the host,
> other timer paths will unconditionally assume direct injection is active. For
> example, kvm_timer_update_irq() skips software injection:
>
> kvm_timer_update_irq() {
> ...
> /* Skip injecting on GICv5 for directly injected (DVI'd) timers */
> if (vgic_is_v5(vcpu->kvm)) {
> ...
> if (map.direct_ptimer == timer_ctx ||
> map.direct_vtimer == timer_ctx)
> return;
> }
> }
>
> Additionally, kvm_timer_vcpu_load_gic() unconditionally masks the physical
> timer interrupt for GICv5 setups:
>
> kvm_timer_vcpu_load_gic() {
> ...
> phys_active |= pending;
> phys_active |= vgic_is_v5(vcpu->kvm);
>
> set_timer_irq_phys_active(ctx, phys_active);
> }
>
> Since hardware injection is not configured by the Realm ops and software
> injection is bypassed due to the GICv5 checks, does this completely blackhole
> timer interrupts for Realm VMs on GICv5 hardware?
>
CCA doesn't support VGIC_V5. We only support VGIC_V3. I have added the
following patch to make sure this is mandated:
---8>---
KVM: arm64: CCA: Mandate VGIC_V3 for Realms
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
diff --git a/arch/arm64/kvm/vgic/vgic-init.c
b/arch/arm64/kvm/vgic/vgic-init.c
index 4012df6002ea6..452c085073f3e 100644
--- a/arch/arm64/kvm/vgic/vgic-init.c
+++ b/arch/arm64/kvm/vgic/vgic-init.c
@@ -84,6 +84,9 @@ int kvm_vgic_create(struct kvm *kvm, u32 type)
!kvm_vgic_global_state.can_emulate_gicv2)
return -ENODEV;
+ /* Realms only support VGIC_V3 */
+ if (kvm_vm_is_realm(kvm) && type != KVM_DEV_TYPE_ARM_VGIC_V3)
+ return -ENODEV;
/*
* Ensure mutual exclusion with vCPU creation and any vCPU
ioctls by:
Suzuki
next prev parent reply other threads:[~2026-09-08 18:58 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-08 16:22 [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 01/20] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-09 11:20 ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 02/20] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-09 11:22 ` Fuad Tabba
2026-09-09 11:24 ` Suzuki K Poulose
2026-09-10 3:40 ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 03/20] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-09 11:28 ` Fuad Tabba
2026-09-09 11:30 ` Suzuki K Poulose
2026-09-10 3:39 ` Gavin Shan
2026-09-10 6:35 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 04/20] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-10 4:00 ` Gavin Shan
2026-09-10 10:21 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 05/20] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-10 5:33 ` Gavin Shan
2026-09-10 8:40 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 06/20] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-09 3:26 ` Kohei Enju
2026-09-09 10:48 ` Marc Zyngier
2026-09-10 4:49 ` Kohei Enju
2026-09-10 5:53 ` Gavin Shan
2026-09-10 8:43 ` Suzuki K Poulose
2026-09-10 9:40 ` Gavin Shan
2026-09-08 16:22 ` [PATCH v17 07/20] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 08/20] KVM: arm64: coco: Add a helper to check if a VM is confidential compute guest Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 09/20] KVM: arm64: coco: arch_timer: Prevent timer offset configuration Suzuki K Poulose
2026-09-08 16:46 ` sashiko-bot
2026-09-10 12:19 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 10/20] KVM: arm64: coco: Disable Steal time accounting for coco guests Suzuki K Poulose
2026-09-09 11:45 ` Fuad Tabba
2026-09-09 11:52 ` Suzuki K Poulose
2026-09-09 12:23 ` Fuad Tabba
2026-09-10 10:27 ` Suzuki K Poulose
2026-09-10 12:42 ` Fuad Tabba
2026-09-10 12:44 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 11/20] KVM: arm64: coco: Don't handle MMIO with no ISV Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 12/20] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-08 16:56 ` sashiko-bot
2026-09-08 18:58 ` Suzuki K Poulose [this message]
2026-09-08 16:22 ` [PATCH v17 13/20] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 14/20] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-08 16:52 ` sashiko-bot
2026-09-10 12:18 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 15/20] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 16/20] KVM: arm64: CCA: Provide register list for unfinalized RECs Suzuki K Poulose
2026-09-08 16:57 ` sashiko-bot
2026-09-10 12:15 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 17/20] KVM: arm64: CCA: Provide an accurate register list Suzuki K Poulose
2026-09-08 17:00 ` sashiko-bot
2026-09-10 12:17 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 18/20] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-09 11:50 ` Fuad Tabba
2026-09-08 16:22 ` [PATCH v17 19/20] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-08 16:59 ` sashiko-bot
2026-09-08 18:59 ` Suzuki K Poulose
2026-09-08 16:22 ` [PATCH v17 20/20] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-09 13:18 ` [PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms Fuad Tabba
2026-09-09 13:52 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f523ceb8-faa7-412d-9227-aca139e2bc1e@arm.com \
--to=suzuki.poulose@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.