From: Eric Auger <eric.auger@redhat.com>
To: eric.auger.pro@gmail.com, eric.auger@redhat.com,
qemu-devel@nongnu.org, qemu-arm@nongnu.org,
kvmarm@lists.linux.dev, peter.maydell@linaro.org,
shaju.abraham@nutanix.com, khushit.shah@nutanix.com,
yangjinqian1@huawei.com, cohuck@redhat.com,
richard.henderson@linaro.org, sebott@redhat.com,
skolothumtho@nvidia.com, philmd@oss.qualcomm.com
Cc: maz@kernel.org, oliver.upton@linux.dev, pbonzini@redhat.com,
armbru@redhat.com, berrange@redhat.com, abologna@redhat.com,
jdenemar@redhat.com
Subject: [RFC PATCH v7 00/18] kvm/arm: Introduce a customizable aarch64 KVM host model
Date: Sun, 26 Jul 2026 17:29:38 +0200 [thread overview]
Message-ID: <20260726153221.24773-1-eric.auger@redhat.com> (raw)
This series enhances the current host KVM model with capability to
set writable ID reg fields.
Since v6.7 kernel, KVM/arm allows the userspace to overwrite the values
of a subset of ID regs. The list of writable fields continues to grow.
The feature ID range is defined as the AArch64 System register space
with op0==3, op1=={0, 1, 3}, CRn==0, CRm=={0-7}, op2=={0-7}.
The end goal is to get more flexibility when migrating guests
between different host hardware.
QEMU retrieves the writable ID fields from KVM UAPI [1] and
match them against a generated description of ID regs and their
named fields that stem from AARCHMRS Registers.json file.
Current description is based on latest 2026-03 edition.
The content of the generated files was compared against kernel
linux/arch/arm64/tools/sysreg file. It is not straightforward
to have unit tests for python scripts as there are many cases for
field extraction.
For each writable named field a uint64 property is created
following the "SYSREG_<REG>_<FIELD>" naming convention. REG and
FIELD names are those described in ARM ARM Reference manual.
The list of SYSREG_ID properties can be retrieved through the qmp
monitor using query-cpu-model-expansion [2].
For the record, Jinqian was able to migrate between Hisilicon KunPeng
HIP09 and HIP12 chips with this series using this kind of command:
-cpu host,pauth=off,pmu=off,sve=off,\
SYSREG_ID_AA64PFR1_EL1_NMI=0x0,\
SYSREG_ID_AA64ISAR1_EL1_LS64=0x0,\
SYSREG_ID_AA64ISAR1_EL1_XS=0x0,\
SYSREG_ID_AA64ISAR1_EL1_LRCPC=0x2,\
SYSREG_ID_AA64ISAR2_EL1_RPRFM=0x0,\
SYSREG_ID_AA64ISAR2_EL1_CLRBHB=0x0,\
SYSREG_ID_AA64ISAR2_EL1_PAC_frac=0x0,\
SYSREG_ID_AA64ISAR2_EL1_BC=0x0,\
SYSREG_ID_AA64ISAR2_EL1_RPRES=0x0,\
SYSREG_ID_AA64ISAR2_EL1_WFxT=0x0,\
SYSREG_ID_AA64MMFR0_EL1_FGT=0x0,\
SYSREG_ID_AA64MMFR0_EL1_BigEnd=0x0,\
SYSREG_ID_AA64MMFR1_EL1_ECBHB=0x0,\
SYSREG_ID_AA64MMFR1_EL1_CMOW=0x0,\
SYSREG_ID_AA64MMFR1_EL1_TIDCP1=0x0,\
SYSREG_ID_AA64MMFR1_EL1_nTLBPA=0x0,\
SYSREG_ID_AA64MMFR1_EL1_AFP=0x0,\
SYSREG_ID_AA64MMFR1_EL1_HCX=0x0,\
SYSREG_ID_AA64MMFR1_EL1_ETS=0x0,\
SYSREG_ID_AA64MMFR1_EL1_PAN=0x2,\
SYSREG_ID_AA64MMFR1_EL1_HAFDBS=0x2,\
SYSREG_ID_AA64MMFR2_EL1_CnP=0x0,\
SYSREG_ID_AA64MMFR3_EL1_TCRX=0x0,\
SYSREG_ID_AA64DFR0_EL1_PMUVer=0x6,\
SYSREG_ID_AA64DFR0_EL1_DebugVer=0x9,\
SYSREG_ID_AA64DFR0_EL1_DoubleLock=0xf,\
SYSREG_ID_AA64ZFR0_EL1_F64MM=0x0,\
SYSREG_ID_AA64ZFR0_EL1_F32MM=0x0,\
SYSREG_ID_AA64ZFR0_EL1_SM4=0x0,\
SYSREG_ID_AA64ZFR0_EL1_SHA3=0x0,\
SYSREG_ID_AA64ZFR0_EL1_BitPerm=0x0,\
SYSREG_ID_AA64ZFR0_EL1_AES=0x0,\
SYSREG_ID_AA64ZFR0_EL1_SVEver=0x0,\
SYSREG_CTR_EL0_L1Ip=0x2 \
Connie & Eric
This series can be found at:
https://github.com/eauger/qemu/tree/arm-cpu-model-v7
History:
--------
v6 -> v7:
- query-cpu-model-expansion now applies the sysreg props
onto a scratch vcpu (POC) allowing a finer validation of settings
(not perfect though as init may be revisited depending on
settings)
- Properly handle ValueRange (Khushit)
- Remove cpu parameter in get_host_cpu_idregs call chain
(Khushit)
v5 -> v6:
v6 is mostly for Khushit to see how he may work on top
of this series. It fulfills some of his requirements:
- Upon Khushit request I added description for enum values
and reserved fields
- set_sysreg_prop checks the input value against enum values
if any
- writable_bitmap is now dispatched into the sysreg descripton
and not stored in vcpu state anymore (besides it is VM wide)
- implemented write for qmp inspection. However this is not
yet checked against KVM. That's the next step I think, ie.
instantiate a scratch vcpu to test if the field value can be
applied?
- if some inconsistencies between writable mask and idreg
field, reserved fields only produce traces
- this version does not yet fix some reported issues about host
supporting nested virt. I will further sync with Khushit.
so this is definitively not candidate to be applied, hence the
RFC tag.
Cornelia Huck (3):
target/arm/kvm: Retrieve writable ID reg map
arm/cpu-features: document ID reg properties
arm-qmp-cmds: introspection for ID register props
Eric Auger (14):
scripts: introduce scripts/update-aarch64-cpu-sysregs-header.py
target/arm/cpu-sysregs.h.inc: Sort by name alphabetical order
target/arm/cpu-sysregs.h.inc: Update with automatic generation
arm/cpu: Add infra to handle generated ID register definitions
scripts: Introduce scripts/aarch64_sysreg_helpers module
scripts: Introduce scripts/update-aarch64-cpu-sysreg-properties.py
target/arm/cpu-idregs.h.inc: generate with script
target/arm/cpu-idregs.h.inc: Generate enum values
arm/kvm: Initialize all writable ID registers from host
target/arm/kvm: Introduce kvm_arm_expose_idreg_properties
target/arm/cpu: Expose writable ID reg field properties on the kvm
host vcpu model
target/arm/cpu-idregs.h.inc: Generate reserved fields
target/arm/kvm: Ignore and trace unexpected writable reserved fields
target/arm/kvm: add utility to write idregs in scratch vcpu
Shaju Abraham (1):
target/arm/cpu_idregs: generate tables for Arm64 ID registers and
fields
docs/system/arm/cpu-features.rst | 106 +-
target/arm/cpu-idregs.h | 41 +
target/arm/kvm_arm.h | 13 +
target/arm/cpu-idregs.h.inc | 2164 +++++++++++++++++
target/arm/cpu-sysregs.h.inc | 57 +-
target/arm/arm-qmp-cmds.c | 98 +
target/arm/cpu-idregs.c | 96 +
target/arm/cpu64.c | 5 +
target/arm/kvm-stub.c | 6 +
target/arm/kvm.c | 360 ++-
scripts/aarch64_sysreg_helpers.py | 109 +
.../update-aarch64-cpu-sysreg-properties.py | 290 +++
scripts/update-aarch64-cpu-sysregs-header.py | 51 +
target/arm/meson.build | 1 +
target/arm/trace-events | 8 +
15 files changed, 3373 insertions(+), 32 deletions(-)
create mode 100644 target/arm/cpu-idregs.h
create mode 100644 target/arm/cpu-idregs.h.inc
create mode 100644 target/arm/cpu-idregs.c
create mode 100644 scripts/aarch64_sysreg_helpers.py
create mode 100644 scripts/update-aarch64-cpu-sysreg-properties.py
create mode 100755 scripts/update-aarch64-cpu-sysregs-header.py
--
2.53.0
next reply other threads:[~2026-07-26 15:32 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-26 15:29 Eric Auger [this message]
2026-07-26 15:29 ` [RFC PATCH v7 01/18] scripts: introduce scripts/update-aarch64-cpu-sysregs-header.py Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 02/18] target/arm/cpu-sysregs.h.inc: Sort by name alphabetical order Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 03/18] target/arm/cpu-sysregs.h.inc: Update with automatic generation Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 04/18] arm/cpu: Add infra to handle generated ID register definitions Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 05/18] scripts: Introduce scripts/aarch64_sysreg_helpers module Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 06/18] scripts: Introduce scripts/update-aarch64-cpu-sysreg-properties.py Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 07/18] target/arm/cpu-idregs.h.inc: generate with script Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 08/18] target/arm/cpu-idregs.h.inc: Generate enum values Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 09/18] target/arm/cpu_idregs: generate tables for Arm64 ID registers and fields Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 10/18] target/arm/kvm: Retrieve writable ID reg map Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 11/18] arm/kvm: Initialize all writable ID registers from host Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 12/18] target/arm/kvm: Introduce kvm_arm_expose_idreg_properties Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 13/18] target/arm/cpu: Expose writable ID reg field properties on the kvm host vcpu model Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 14/18] target/arm/cpu-idregs.h.inc: Generate reserved fields Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 15/18] target/arm/kvm: Ignore and trace unexpected writable " Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 16/18] arm/cpu-features: document ID reg properties Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 17/18] target/arm/kvm: add utility to write idregs in scratch vcpu Eric Auger
2026-07-26 15:29 ` [RFC PATCH v7 18/18] arm-qmp-cmds: introspection for ID register props Eric Auger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260726153221.24773-1-eric.auger@redhat.com \
--to=eric.auger@redhat.com \
--cc=abologna@redhat.com \
--cc=armbru@redhat.com \
--cc=berrange@redhat.com \
--cc=cohuck@redhat.com \
--cc=eric.auger.pro@gmail.com \
--cc=jdenemar@redhat.com \
--cc=khushit.shah@nutanix.com \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=philmd@oss.qualcomm.com \
--cc=qemu-arm@nongnu.org \
--cc=qemu-devel@nongnu.org \
--cc=richard.henderson@linaro.org \
--cc=sebott@redhat.com \
--cc=shaju.abraham@nutanix.com \
--cc=skolothumtho@nvidia.com \
--cc=yangjinqian1@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox