From: Steven Price <steven.price@arm.com>
To: Suzuki K Poulose <suzuki.poulose@arm.com>,
kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
James Morse <james.morse@arm.com>,
Oliver Upton <oliver.upton@linux.dev>,
Zenghui Yu <yuzenghui@huawei.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
Alexandru Elisei <alexandru.elisei@arm.com>,
Christoffer Dall <christoffer.dall@arm.com>,
Fuad Tabba <tabba@google.com>,
linux-coco@lists.linux.dev,
Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
Gavin Shan <gshan@redhat.com>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Alper Gun <alpergun@google.com>,
"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>
Subject: Re: [PATCH v8 15/43] arm64: RME: Allow VMM to set RIPAS
Date: Wed, 14 May 2025 11:24:10 +0100 [thread overview]
Message-ID: <36c46f16-85c2-43f8-b460-942f34631e0d@arm.com> (raw)
In-Reply-To: <d0cbb637-6ba1-4858-b326-31271e9949ea@arm.com>
On 13/05/2025 11:43, Suzuki K Poulose wrote:
> On 12/05/2025 15:45, Steven Price wrote:
>> On 06/05/2025 14:23, Suzuki K Poulose wrote:
>>> Hi Steven
>>>
>>> On 16/04/2025 14:41, Steven Price wrote:
[...]
>
>>
>>>> + }
>>>> +
>>>> + realm_fold_rtt_level(realm, get_start_level(realm) + 1,
>>>> + start, end);
>>>
>>> We don't seem to be reclaiing the RTTs from shared mapping case ?
>>
>> I'm not sure I follow: realm_fold_rtt_level() will free any RTTs that
>> are released.
>>
>> Or are you referring to the fact that we don't (yet) fold the shared
>> range? I have been purposefully leaving that for now as normally we'd
>
> sorry it was a bit vague. We don't seem to be reclaiming the RTTs in
> realm_unmap_shared_range(), like we do for the private range.
Ah, you mean we potentially leave empty RTTs which are only reclaimed
when destroying the realm. Whereas in the private range we
opportunistically fold which will (usually) cause these to be freed.
>> follow the page size in the VMM to choose the page size on the guest,
>> but that doesn't work when the RMM might have a different page size to
>> the host. So my reasons for leaving it for later are:
>>
>> * First huge pages is very much a TODO in general.
>>
>> * When we support >4K host pages then a huge page on the host may not
>> be available in the RMM, so we can't just follow the VMM.
>>
>> * We don't have support in realm_unmap_shared_range() to split a block
>> mapping up - it could be added, but it's not clear to me if it's best
>> to split a block mapping, or remove the whole and refault as
>> required.
>>
>> * guest_memfd might well be able to provide some good hints here, but
>> we'll have to wait for that series to settle.
>
> I am not sure I follow. None of this affects folding, once we have
> "unmapped". For that matter, we could easily DESTROY the RTTs in
> shared side without unmapping, but we can do that later as an
> optimisation.
Yeah, ignore the above - like you say it's not relevant to unmapping, I
hadn't understood your point ;)
I'll stick a call to realm_fold_rtt_level() at the end of
realm_unmap_shared_range() which should opportunistically free unused
RTTs. Like you say there's a optimisation to just straight to destroying
the RTTs in the shared region - but I think that's best left until later.
>>
>>>> +}
>>>> +
>>>> +void kvm_realm_unmap_range(struct kvm *kvm, unsigned long start,
>>>> + unsigned long size, bool unmap_private)
>>>> +{
>>>> + unsigned long end = start + size;
>>>> + struct realm *realm = &kvm->arch.realm;
>>>> +
>>>> + end = min(BIT(realm->ia_bits - 1), end);
>>>> +
>>>> + if (realm->state == REALM_STATE_NONE)
>>>> + return;
>>>> +
>>>> + realm_unmap_shared_range(kvm, find_map_level(realm, start, end),
>>>> + start, end);
>>>> + if (unmap_private)
>>>> + realm_unmap_private_range(kvm, start, end);
>>>> +}
>>>> +
>>>> +static int realm_init_ipa_state(struct realm *realm,
>>>> + unsigned long ipa,
>>>> + unsigned long end)
>>>> +{
>>>> + phys_addr_t rd_phys = virt_to_phys(realm->rd);
>>>> + int ret;
>>>> +
>>>> + while (ipa < end) {
>>>> + unsigned long next;
>>>> +
>>>> + ret = rmi_rtt_init_ripas(rd_phys, ipa, end, &next);
>>>> +
>>>> + if (RMI_RETURN_STATUS(ret) == RMI_ERROR_RTT) {
>>>> + int err_level = RMI_RETURN_INDEX(ret);
>>>> + int level = find_map_level(realm, ipa, end);
>>>> +
>>>> + if (WARN_ON(err_level >= level))
>>>
>>> I am wondering if WARN_ON() is required here. A buggy VMM could trigger
>>> the WARN_ON(). (e.g, INIT_IPA after POPULATE, where L3 table is
>>> created.). The only case where it may be worth WARNING is if the level
>>> == 3.
>>
>> I have to admit I've struggled to get my head round this ;)
>>
>> init_ripas will fail with ERROR_RTT in three cases:
>>
>> 1. (base_align) The base address isn't aligned for the level reached.
>>
>> 2. (rtt_state) The rtte state is !UNASSIGNED.
>>
>> 3. (no_progress) base==walk_top - the while condition should prevent
>> this.
>>
>> So I think case 1 is the case we're expecting, and creating RTTs should
>> resolve it.
>>
>> Case 2 is presumably the case you are concerned about, although it's not
>> because tables have been created, but because INIT_RIPAS is invalid on
>> areas that have been populated already.
>
> Correct, this is the case I was referring to.
>
>>
>> If my reading of the spec is correct, then level == 3 isn't a possible
>> result, so beyond potentially finding RMM bugs I don't think a WARN for
>
> It is almost certainly possible, with L3 page mapping created for
> POPULATE and a follow up INIT_RIPAS with 2M or even 1G alignment, could
> lead us to expect that only L1 or L2 is required (find_map_level) but
> the RTT walk reached L3 and failed. This is not a case of RMM bug, but
> a VMM not following the rules.
Sorry, I wasn't clear. I mean "level == 3" isn't something that we
should be WARNing on.
>> that is very interesting. So for now I'll just drop the WARN_ON here
>> altogether.
>
> Thanks, that is much safer
Ack.
Thanks,
Steve
> Suzuki
>
next prev parent reply other threads:[~2025-05-14 10:24 UTC|newest]
Thread overview: 124+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-16 13:41 [PATCH v8 00/43] arm64: Support for Arm CCA in KVM Steven Price
2025-04-16 13:41 ` [PATCH v8 01/43] kvm: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2025-04-16 13:41 ` [PATCH v8 02/43] arm64: RME: Handle Granule Protection Faults (GPFs) Steven Price
2025-04-16 13:41 ` [PATCH v8 03/43] arm64: RME: Add SMC definitions for calling the RMM Steven Price
2025-04-25 10:30 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 04/43] arm64: RME: Add wrappers for RMI calls Steven Price
2025-04-25 10:48 ` Suzuki K Poulose
2025-04-25 10:53 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 05/43] arm64: RME: Check for RME support at KVM init Steven Price
2025-04-25 11:08 ` Suzuki K Poulose
2025-05-01 13:31 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 06/43] arm64: RME: Define the user ABI Steven Price
2025-04-28 8:58 ` Suzuki K Poulose
2025-05-01 13:31 ` Steven Price
2025-05-01 13:47 ` Suzuki K Poulose
2025-04-30 4:25 ` Gavin Shan
2025-05-01 13:44 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 07/43] arm64: RME: ioctls to create and configure realms Steven Price
2025-04-29 9:45 ` Suzuki K Poulose
2025-05-01 15:09 ` Steven Price
2025-04-30 5:39 ` Gavin Shan
2025-05-01 15:11 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 08/43] kvm: arm64: Don't expose debug capabilities for realm guests Steven Price
2025-04-30 5:42 ` Gavin Shan
2025-04-16 13:41 ` [PATCH v8 09/43] KVM: arm64: Allow passing machine type in KVM creation Steven Price
2025-04-30 5:47 ` Gavin Shan
2025-04-16 13:41 ` [PATCH v8 10/43] arm64: RME: RTT tear down Steven Price
2025-04-16 13:41 ` [PATCH v8 11/43] arm64: RME: Allocate/free RECs to match vCPUs Steven Price
2025-05-01 16:50 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 12/43] KVM: arm64: vgic: Provide helper for number of list registers Steven Price
2025-04-30 5:54 ` Gavin Shan
2025-05-01 16:51 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 13/43] arm64: RME: Support for the VGIC in realms Steven Price
2025-05-02 11:04 ` Suzuki K Poulose
2025-05-12 14:44 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 14/43] KVM: arm64: Support timers in realm RECs Steven Price
2025-05-02 12:22 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 15/43] arm64: RME: Allow VMM to set RIPAS Steven Price
2025-04-30 11:38 ` Gavin Shan
2025-05-01 16:00 ` Steven Price
2025-05-01 23:59 ` Gavin Shan
2025-05-06 13:23 ` Suzuki K Poulose
2025-05-12 14:45 ` Steven Price
2025-05-13 10:43 ` Suzuki K Poulose
2025-05-14 10:24 ` Steven Price [this message]
2025-04-16 13:41 ` [PATCH v8 16/43] arm64: RME: Handle realm enter/exit Steven Price
2025-04-30 11:55 ` Gavin Shan
2025-05-12 14:45 ` Steven Price
2025-05-07 10:26 ` Suzuki K Poulose
2025-05-12 14:45 ` Steven Price
2025-05-29 4:52 ` Emi Kisanuki (Fujitsu)
2025-06-02 15:14 ` Steven Price
2025-06-02 15:16 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 17/43] arm64: RME: Handle RMI_EXIT_RIPAS_CHANGE Steven Price
2025-04-30 12:11 ` Gavin Shan
2025-05-16 13:50 ` Steven Price
2025-05-07 10:42 ` Suzuki K Poulose
2025-05-16 13:50 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 18/43] KVM: arm64: Handle realm MMIO emulation Steven Price
2025-05-19 18:11 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 19/43] arm64: RME: Allow populating initial contents Steven Price
2025-04-16 13:41 ` [PATCH v8 20/43] arm64: RME: Runtime faulting of memory Steven Price
2025-05-01 0:16 ` Gavin Shan
2025-05-16 15:33 ` Steven Price
2025-05-20 14:48 ` Suzuki K Poulose
2025-05-21 8:55 ` Steven Price
2025-05-19 17:35 ` Suzuki K Poulose
2025-05-20 14:58 ` Suzuki K Poulose
2025-05-21 9:10 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 21/43] KVM: arm64: Handle realm VCPU load Steven Price
2025-05-19 17:48 ` Suzuki K Poulose
2025-05-21 10:21 ` Steven Price
2025-04-16 13:41 ` [PATCH v8 22/43] KVM: arm64: Validate register access for a Realm VM Steven Price
2025-05-01 2:54 ` Gavin Shan
2025-05-19 17:56 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 23/43] KVM: arm64: Handle Realm PSCI requests Steven Price
2025-04-16 13:41 ` [PATCH v8 24/43] KVM: arm64: WARN on injected undef exceptions Steven Price
2025-04-16 13:41 ` [PATCH v8 25/43] arm64: Don't expose stolen time for realm guests Steven Price
2025-04-16 13:41 ` [PATCH v8 26/43] arm64: RME: allow userspace to inject aborts Steven Price
2025-04-16 13:41 ` [PATCH v8 27/43] arm64: RME: support RSI_HOST_CALL Steven Price
2025-05-01 2:57 ` Gavin Shan
2025-04-16 13:41 ` [PATCH v8 28/43] arm64: RME: Allow checking SVE on VM instance Steven Price
2025-04-16 13:41 ` [PATCH v8 29/43] arm64: RME: Always use 4k pages for realms Steven Price
2025-05-01 2:59 ` Gavin Shan
2025-05-20 14:59 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 30/43] arm64: RME: Prevent Device mappings for Realms Steven Price
2025-05-20 13:20 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 31/43] arm_pmu: Provide a mechanism for disabling the physical IRQ Steven Price
2025-04-16 13:41 ` [PATCH v8 32/43] arm64: RME: Enable PMU support with a realm guest Steven Price
2025-04-16 13:41 ` [PATCH v8 33/43] arm64: RME: Hide KVM_CAP_READONLY_MEM for realm guests Steven Price
2025-05-01 3:01 ` Gavin Shan
2025-05-20 12:45 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 34/43] arm64: RME: Propagate number of breakpoints and watchpoints to userspace Steven Price
2025-05-01 3:36 ` Gavin Shan
2025-05-01 3:40 ` Gavin Shan
2025-05-01 3:40 ` Gavin Shan
2025-05-20 12:47 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 35/43] arm64: RME: Set breakpoint parameters through SET_ONE_REG Steven Price
2025-05-20 12:48 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 36/43] arm64: RME: Initialize PMCR.N with number counter supported by RMM Steven Price
2025-05-01 3:42 ` Gavin Shan
2025-05-20 12:49 ` Suzuki K Poulose
2025-04-16 13:41 ` [PATCH v8 37/43] arm64: RME: Propagate max SVE vector length from RMM Steven Price
2025-05-01 3:50 ` Gavin Shan
2025-05-20 12:50 ` Suzuki K Poulose
2025-04-16 13:42 ` [PATCH v8 38/43] arm64: RME: Configure max SVE vector length for a Realm Steven Price
2025-05-01 3:50 ` Gavin Shan
2025-05-20 12:52 ` Suzuki K Poulose
2025-04-16 13:42 ` [PATCH v8 39/43] arm64: RME: Provide register list for unfinalized RME RECs Steven Price
2025-05-01 23:30 ` Gavin Shan
2025-04-16 13:42 ` [PATCH v8 40/43] arm64: RME: Provide accurate register list Steven Price
2025-05-01 23:41 ` Gavin Shan
2025-05-20 13:15 ` Suzuki K Poulose
2025-04-16 13:42 ` [PATCH v8 41/43] KVM: arm64: Expose support for private memory Steven Price
2025-05-01 3:04 ` Gavin Shan
2025-04-16 13:42 ` [PATCH v8 42/43] KVM: arm64: Expose KVM_ARM_VCPU_REC to user space Steven Price
2025-05-01 3:04 ` Gavin Shan
2025-04-16 13:42 ` [PATCH v8 43/43] KVM: arm64: Allow activating realms Steven Price
2025-05-01 3:06 ` Gavin Shan
2025-05-20 13:12 ` Suzuki K Poulose
2025-05-02 0:46 ` [PATCH v8 00/43] arm64: Support for Arm CCA in KVM Gavin Shan
2025-05-16 16:00 ` Steven Price
2025-05-15 3:01 ` Emi Kisanuki (Fujitsu)
2025-05-16 15:57 ` Steven Price
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=36c46f16-85c2-43f8-b460-942f34631e0d@arm.com \
--to=steven.price@arm.com \
--cc=alexandru.elisei@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christoffer.dall@arm.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=james.morse@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=sdonthineni@nvidia.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox