From: Gavin Shan <gshan@redhat.com>
To: Mathieu Poirier <mathieu.poirier@linaro.org>,
berrange@redhat.com, kchamart@redhat.com,
pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
eblake@redhat.com, armbru@redhat.com,
lorenzo.pieralisi@linaro.org, enju.kohei@fujitsu.com
Cc: qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org
Subject: Re: [RFC v4 01/24] linux-headers: Add RME related definitions
Date: Fri, 4 Sep 2026 16:07:49 +1000 [thread overview]
Message-ID: <b06c933e-b8fd-4e03-8f50-9a9086542ccf@redhat.com> (raw)
In-Reply-To: <20260903193611.1058589-2-mathieu.poirier@linaro.org>
Hi Mathieu,
On 9/4/26 5:35 AM, Mathieu Poirier wrote:
> From: Jean-Philippe Brucker <jean-philippe@linaro.org>
>
> This is a temporary patch intended for testing purposes only. It provides
> definitions related to supporting Realms by the QEMU-VMM.
>
> Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
> Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
> ---
> linux-headers/asm-arm64/kvm.h | 9 +++++++++
> linux-headers/linux/kvm.h | 10 +++++++++-
> 2 files changed, 18 insertions(+), 1 deletion(-)
>
> diff --git a/linux-headers/asm-arm64/kvm.h b/linux-headers/asm-arm64/kvm.h
> index 6aefe7973814..4c08631ec7d2 100644
> --- a/linux-headers/asm-arm64/kvm.h
> +++ b/linux-headers/asm-arm64/kvm.h
> @@ -208,6 +208,15 @@ struct kvm_arm_counter_offset {
> __u64 reserved;
> };
>
> +#define KVM_ARM_RMI_POPULATE_FLAGS_MEASURE (1 << 0)
> +struct kvm_arm_rmi_populate {
> + __u64 base;
> + __u64 size;
> + __u64 source_uaddr;
> + __u32 flags;
> + __u32 reserved;
> +};
> +
> #define KVM_ARM_TAGS_TO_GUEST 0
> #define KVM_ARM_TAGS_FROM_GUEST 1
>
> diff --git a/linux-headers/linux/kvm.h b/linux-headers/linux/kvm.h
> index 29f81c05aca2..8b7627f11447 100644
> --- a/linux-headers/linux/kvm.h
> +++ b/linux-headers/linux/kvm.h
> @@ -689,14 +689,19 @@ struct kvm_enable_cap {
> * address size for the VM. Bits[7-0] are reserved for the guest
> * PA size shift (i.e, log2(PA_Size)). For backward compatibility,
> * value 0 implies the default IPA size, 40bits.
> + *
> + * Bits[30-31] are reserved for the VM type
> */
> #define KVM_VM_TYPE_ARM_IPA_SIZE_MASK 0xffULL
> #define KVM_VM_TYPE_ARM_IPA_SIZE(x) \
> ((x) & KVM_VM_TYPE_ARM_IPA_SIZE_MASK)
>
> +#define KVM_VM_TYPE_ARM_NORMAL 0
> +#define KVM_VM_TYPE_ARM_REALM (1UL << 30)
> #define KVM_VM_TYPE_ARM_PROTECTED (1UL << 31)
> #define KVM_VM_TYPE_ARM_MASK (KVM_VM_TYPE_ARM_IPA_SIZE_MASK | \
> - KVM_VM_TYPE_ARM_PROTECTED)
> + KVM_VM_TYPE_ARM_PROTECTED | \
> + KVM_VM_TYPE_ARM_REALM)
>
> /*
> * ioctls for /dev/kvm fds:
> @@ -719,6 +724,8 @@ struct kvm_enable_cap {
> #define KVM_GET_EMULATED_CPUID _IOWR(KVMIO, 0x09, struct kvm_cpuid2)
> #define KVM_GET_MSR_FEATURE_INDEX_LIST _IOWR(KVMIO, 0x0a, struct kvm_msr_list)
>
> +#define KVM_ARM_RMI_POPULATE _IOWR(KVMIO, 0xd7, struct kvm_arm_rmi_populate)
> +
> /*
> * Extension capability list.
> */
> @@ -988,6 +995,7 @@ struct kvm_enable_cap {
> #define KVM_CAP_S390_HPAGE_2G 249
> #define KVM_CAP_PPC_COMPAT_CAPS 250
> #define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 251
> +#define KVM_CAP_ARM_RMI 252
>
Both KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES and KVM_CAP_ARM_RMI aren't consistent to
the definitions in Steven Price's (v16) host series [1]. They need corrections as
below. Otherwise, realm VM can't be started and the following errors are raised by
qemu.
[1] https://lore.kernel.org/kvm/20260803134403.80630-14-steven.price@arm.com/
root@host:~# qemu-system-aarch64 -enable-kvm \
-object rme-guest,id=rme0,convert-in-place=on \
-machine virt,gic-version=3,confidential-guest-support=rme0 \
-m 2G -cpu host \
-smp maxcpus=4,cpus=4,sockets=1,clusters=1,cores=2,threads=2 \
-object memory-backend-guest-memfd,id=mem0,size=2G,share=on \
-numa node,nodeid=0,cpus=0-3,memdev=mem0 \
-serial mon:stdio -monitor none -nographic -nodefaults \
-kernel /mnt/linux/arch/arm64/boot/Image \
-initrd /mnt/buildroot/output/images/rootfs.cpio.xz \
-append earlycon=pl011,mmio,0x10009000000
:
qemu-system-aarch64: VM doesn't support Realms
qemu-system-aarch64: failed to initialize kvm: No such device
-#define KVM_CAP_PPC_COMPAT_CAPS 250
-#define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 251
-#define KVM_CAP_ARM_RMI 252
+#define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 250
+#define KVM_CAP_ARM_RMI 251
> struct kvm_irq_routing_irqchip {
> __u32 irqchip;
Thanks,
Gavin
next prev parent reply other threads:[~2026-09-04 6:13 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 19:35 [RFC v4 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-09-04 6:07 ` Gavin Shan [this message]
2026-09-04 16:24 ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 03/24] target/arm: Add confidential guest support Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-09-04 3:09 ` Kohei Enju
2026-09-04 16:25 ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=b06c933e-b8fd-4e03-8f50-9a9086542ccf@redhat.com \
--to=gshan@redhat.com \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=cohuck@redhat.com \
--cc=eblake@redhat.com \
--cc=enju.kohei@fujitsu.com \
--cc=kchamart@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=lorenzo.pieralisi@linaro.org \
--cc=mathieu.poirier@linaro.org \
--cc=mst@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox