Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Gavin Shan <gshan@redhat.com>
To: Mathieu Poirier <mathieu.poirier@linaro.org>,
	berrange@redhat.com, kchamart@redhat.com,
	pierrick.bouvier@oss.qualcomm.com, peter.maydell@linaro.org,
	mst@redhat.com, cohuck@redhat.com, pbonzini@redhat.com,
	eblake@redhat.com, armbru@redhat.com,
	lorenzo.pieralisi@linaro.org, enju.kohei@fujitsu.com
Cc: qemu-devel@nongnu.org, qemu-arm@nongnu.org, kvm@vger.kernel.org
Subject: Re: [RFC v4 01/24] linux-headers: Add RME related definitions
Date: Fri, 4 Sep 2026 16:07:49 +1000	[thread overview]
Message-ID: <b06c933e-b8fd-4e03-8f50-9a9086542ccf@redhat.com> (raw)
In-Reply-To: <20260903193611.1058589-2-mathieu.poirier@linaro.org>

Hi Mathieu,

On 9/4/26 5:35 AM, Mathieu Poirier wrote:
> From: Jean-Philippe Brucker <jean-philippe@linaro.org>
> 
> This is a temporary patch intended for testing purposes only. It provides
> definitions related to supporting Realms by the QEMU-VMM.
> 
> Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
> Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
> ---
>   linux-headers/asm-arm64/kvm.h |  9 +++++++++
>   linux-headers/linux/kvm.h     | 10 +++++++++-
>   2 files changed, 18 insertions(+), 1 deletion(-)
> 
> diff --git a/linux-headers/asm-arm64/kvm.h b/linux-headers/asm-arm64/kvm.h
> index 6aefe7973814..4c08631ec7d2 100644
> --- a/linux-headers/asm-arm64/kvm.h
> +++ b/linux-headers/asm-arm64/kvm.h
> @@ -208,6 +208,15 @@ struct kvm_arm_counter_offset {
>   	__u64 reserved;
>   };
>   
> +#define KVM_ARM_RMI_POPULATE_FLAGS_MEASURE     (1 << 0)
> +struct kvm_arm_rmi_populate {
> +	__u64 base;
> +	__u64 size;
> +	__u64 source_uaddr;
> +	__u32 flags;
> +	__u32 reserved;
> +};
> +
>   #define KVM_ARM_TAGS_TO_GUEST		0
>   #define KVM_ARM_TAGS_FROM_GUEST		1
>   
> diff --git a/linux-headers/linux/kvm.h b/linux-headers/linux/kvm.h
> index 29f81c05aca2..8b7627f11447 100644
> --- a/linux-headers/linux/kvm.h
> +++ b/linux-headers/linux/kvm.h
> @@ -689,14 +689,19 @@ struct kvm_enable_cap {
>    * address size for the VM. Bits[7-0] are reserved for the guest
>    * PA size shift (i.e, log2(PA_Size)). For backward compatibility,
>    * value 0 implies the default IPA size, 40bits.
> + *
> + * Bits[30-31] are reserved for the VM type
>    */
>   #define KVM_VM_TYPE_ARM_IPA_SIZE_MASK	0xffULL
>   #define KVM_VM_TYPE_ARM_IPA_SIZE(x)		\
>   	((x) & KVM_VM_TYPE_ARM_IPA_SIZE_MASK)
>   
> +#define KVM_VM_TYPE_ARM_NORMAL		0
> +#define KVM_VM_TYPE_ARM_REALM		(1UL << 30)
>   #define KVM_VM_TYPE_ARM_PROTECTED	(1UL << 31)
>   #define KVM_VM_TYPE_ARM_MASK		(KVM_VM_TYPE_ARM_IPA_SIZE_MASK | \
> -					 KVM_VM_TYPE_ARM_PROTECTED)
> +					 KVM_VM_TYPE_ARM_PROTECTED | \
> +					 KVM_VM_TYPE_ARM_REALM)
>   
>   /*
>    * ioctls for /dev/kvm fds:
> @@ -719,6 +724,8 @@ struct kvm_enable_cap {
>   #define KVM_GET_EMULATED_CPUID	  _IOWR(KVMIO, 0x09, struct kvm_cpuid2)
>   #define KVM_GET_MSR_FEATURE_INDEX_LIST    _IOWR(KVMIO, 0x0a, struct kvm_msr_list)
>   
> +#define KVM_ARM_RMI_POPULATE	  _IOWR(KVMIO, 0xd7, struct kvm_arm_rmi_populate)
> +
>   /*
>    * Extension capability list.
>    */
> @@ -988,6 +995,7 @@ struct kvm_enable_cap {
>   #define KVM_CAP_S390_HPAGE_2G 249
>   #define KVM_CAP_PPC_COMPAT_CAPS 250
>   #define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 251
> +#define KVM_CAP_ARM_RMI 252
>   

Both KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES and KVM_CAP_ARM_RMI aren't consistent to
the definitions in Steven Price's (v16) host series [1]. They need corrections as
below. Otherwise, realm VM can't be started and the following errors are raised by
qemu.

[1] https://lore.kernel.org/kvm/20260803134403.80630-14-steven.price@arm.com/

root@host:~# qemu-system-aarch64 -enable-kvm                  \
-object rme-guest,id=rme0,convert-in-place=on                 \
-machine virt,gic-version=3,confidential-guest-support=rme0   \
-m 2G -cpu host                                               \
-smp maxcpus=4,cpus=4,sockets=1,clusters=1,cores=2,threads=2  \
-object memory-backend-guest-memfd,id=mem0,size=2G,share=on   \
-numa node,nodeid=0,cpus=0-3,memdev=mem0                      \
-serial mon:stdio -monitor none -nographic -nodefaults        \
-kernel /mnt/linux/arch/arm64/boot/Image                      \
-initrd /mnt/buildroot/output/images/rootfs.cpio.xz           \
-append earlycon=pl011,mmio,0x10009000000
     :
qemu-system-aarch64: VM doesn't support Realms
qemu-system-aarch64: failed to initialize kvm: No such device


-#define KVM_CAP_PPC_COMPAT_CAPS 250
-#define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 251
-#define KVM_CAP_ARM_RMI 252
+#define KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES 250
+#define KVM_CAP_ARM_RMI 251

>   struct kvm_irq_routing_irqchip {
>   	__u32 irqchip;

Thanks,
Gavin


  reply	other threads:[~2026-09-04  6:13 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 19:35 [RFC v4 00/24] Add Realm support to QEMU-VMM Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 01/24] linux-headers: Add RME related definitions Mathieu Poirier
2026-09-04  6:07   ` Gavin Shan [this message]
2026-09-04 16:24     ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 02/24] target/arm/kvm: Return immediately on error in kvm_arch_init() Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 03/24] target/arm: Add confidential guest support Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 04/24] target/arm/kvm-rme: Add mechanic to initialize realms Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 05/24] target/arm/kvm: Split kvm_arch_get/put_registers Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 06/24] target/arm/kvm-rme: Initialize vCPU Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 07/24] target/arm/kvm: Create scratch Realm VM when requested Mathieu Poirier
2026-09-04  3:09   ` Kohei Enju
2026-09-04 16:25     ` Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 08/24] target/arm/kvm: Use kvm_vm_check_extension() where necessary Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 09/24] hw/core/loader: Add a ROM loader notifier Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 10/24] target/arm/kvm-rme: Keep track of images loaded in Realm memory Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 11/24] target/arm/kvm-rme: Populate Realm with runtime images Mathieu Poirier
2026-09-03 19:35 ` [RFC v4 12/24] target/arm/cpu: Set number of breakpoints and watchpoints in KVM Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 13/24] target/arm/cpu: Set number of PMU counters " Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 14/24] target/arm/cpu: Don't read Realm registers Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 15/24] hw/arm/virt: Set proper conduit method for Realms Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 16/24] hw/arm/virt: Embed Realm VM type with IPA address space Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 17/24] hw/arm/virt: Reserve one bit of guest physical address for RME Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 18/24] hw/arm/virt: Disable DTB randomness for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 19/24] hw/arm/virt: Move virt_flash_create() to machvirt_init() Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 20/24] hw/arm/virt: Use RAM instead of flash for confidential guest firmware Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 21/24] target/arm/kvm-rme: Add DMA remapping for the shared memory region Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 22/24] docs/interop/firmware.json: Add arm-rme firmware feature Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 23/24] hw/arm/boot: Load DTB as is for confidential VMs Mathieu Poirier
2026-09-03 19:36 ` [RFC v4 24/24] hw/arm/boot: Skip bootloader for confidential guests Mathieu Poirier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b06c933e-b8fd-4e03-8f50-9a9086542ccf@redhat.com \
    --to=gshan@redhat.com \
    --cc=armbru@redhat.com \
    --cc=berrange@redhat.com \
    --cc=cohuck@redhat.com \
    --cc=eblake@redhat.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=kchamart@redhat.com \
    --cc=kvm@vger.kernel.org \
    --cc=lorenzo.pieralisi@linaro.org \
    --cc=mathieu.poirier@linaro.org \
    --cc=mst@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=pierrick.bouvier@oss.qualcomm.com \
    --cc=qemu-arm@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox