* [PATCH v7 1/3] KVM: arm64: Block host-initiated FF-A direct responses
2026-08-30 23:08 [PATCH v7 0/3] KVM: arm64: Support FF-A direct messaging interfaces Per Larsen via B4 Relay
@ 2026-08-30 23:08 ` Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 2/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ in host handler Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 3/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ2 " Per Larsen via B4 Relay
2 siblings, 0 replies; 4+ messages in thread
From: Per Larsen via B4 Relay @ 2026-08-30 23:08 UTC (permalink / raw)
To: Marc Zyngier, Joey Gouly, Suzuki K Poulose, Zenghui Yu,
Catalin Marinas, Will Deacon, Yeoreum Yun, Ben Horgan,
Oliver Upton
Cc: Sebastien Ene, linux-arm-kernel, kvmarm, linux-kernel, Per Larsen,
Fuad Tabba
From: Per Larsen <perlarsen@google.com>
ffa_call_supported() rejects FFA_MSG_SEND_DIRECT_RESP, but allows
FFA_FN64_MSG_SEND_DIRECT_RESP to be forwarded to firmware.
The host is never the target of an FF-A direct request and therefore
cannot initiate a direct response. Reject both calling conventions.
Suggested-by: Fuad Tabba <tabba@google.com>
Signed-off-by: Per Larsen <perlarsen@google.com>
---
arch/arm64/kvm/hyp/nvhe/ffa.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/ffa.c b/arch/arm64/kvm/hyp/nvhe/ffa.c
index a327c2bbb6b6..9e8bb95e8845 100644
--- a/arch/arm64/kvm/hyp/nvhe/ffa.c
+++ b/arch/arm64/kvm/hyp/nvhe/ffa.c
@@ -686,8 +686,10 @@ static bool ffa_call_supported(u64 func_id)
case FFA_MSG_SEND:
case FFA_MSG_POLL:
case FFA_MSG_WAIT:
- /* 32-bit variants of 64-bit calls */
+ /* The host is never the target of a direct request */
case FFA_MSG_SEND_DIRECT_RESP:
+ case FFA_FN64_MSG_SEND_DIRECT_RESP:
+ /* 32-bit variants of 64-bit calls */
case FFA_RXTX_MAP:
case FFA_MEM_DONATE:
case FFA_MEM_RETRIEVE_REQ:
--
2.55.0.897.gb25b4bd76c-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH v7 2/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ in host handler
2026-08-30 23:08 [PATCH v7 0/3] KVM: arm64: Support FF-A direct messaging interfaces Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 1/3] KVM: arm64: Block host-initiated FF-A direct responses Per Larsen via B4 Relay
@ 2026-08-30 23:08 ` Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 3/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ2 " Per Larsen via B4 Relay
2 siblings, 0 replies; 4+ messages in thread
From: Per Larsen via B4 Relay @ 2026-08-30 23:08 UTC (permalink / raw)
To: Marc Zyngier, Joey Gouly, Suzuki K Poulose, Zenghui Yu,
Catalin Marinas, Will Deacon, Yeoreum Yun, Ben Horgan,
Oliver Upton
Cc: Sebastien Ene, linux-arm-kernel, kvmarm, linux-kernel, Per Larsen,
Fuad Tabba
From: Sebastian Ene <sebastianene@google.com>
Allow direct messages to be forwarded from the host. The host should
not be sending framework messages so they are filtered out.
Signed-off-by: Sebastian Ene <sebastianene@google.com>
Reviewed-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Per Larsen <perlarsen@google.com>
---
arch/arm64/kvm/hyp/nvhe/ffa.c | 27 +++++++++++++++++++++++++++
include/linux/arm_ffa.h | 2 ++
2 files changed, 29 insertions(+)
diff --git a/arch/arm64/kvm/hyp/nvhe/ffa.c b/arch/arm64/kvm/hyp/nvhe/ffa.c
index 9e8bb95e8845..96cf6be969de 100644
--- a/arch/arm64/kvm/hyp/nvhe/ffa.c
+++ b/arch/arm64/kvm/hyp/nvhe/ffa.c
@@ -880,6 +880,29 @@ static void do_ffa_part_get(struct arm_smccc_1_2_regs *res,
hyp_spin_unlock(&host_buffers.lock);
}
+static void do_ffa_direct_msg(struct arm_smccc_1_2_regs *res,
+ struct kvm_cpu_context *ctxt)
+{
+ DECLARE_REG(u64, endp, ctxt, 1);
+ DECLARE_REG(u64, flags, ctxt, 2);
+
+ struct arm_smccc_1_2_regs *args = (void *)&ctxt->regs.regs[0];
+
+ if (upper_32_bits(endp) ||
+ FIELD_GET(FFA_SRC_ENDPOINT_MASK, endp) != HOST_FFA_ID) {
+ ffa_to_smccc_error(res, FFA_RET_INVALID_PARAMETERS);
+ return;
+ }
+
+ /* filter out framework messages and validate SBZ/MBZ bits */
+ if (flags) {
+ ffa_to_smccc_error(res, FFA_RET_INVALID_PARAMETERS);
+ return;
+ }
+
+ hyp_smccc_1_2_smc(args, res);
+}
+
bool kvm_host_ffa_handler(struct kvm_cpu_context *host_ctxt, u32 func_id)
{
struct arm_smccc_1_2_regs res = {0};
@@ -938,6 +961,10 @@ bool kvm_host_ffa_handler(struct kvm_cpu_context *host_ctxt, u32 func_id)
case FFA_PARTITION_INFO_GET:
do_ffa_part_get(&res, host_ctxt);
goto out_handled;
+ case FFA_MSG_SEND_DIRECT_REQ:
+ case FFA_FN64_MSG_SEND_DIRECT_REQ:
+ do_ffa_direct_msg(&res, host_ctxt);
+ goto out_handled;
}
if (ffa_call_supported(func_id))
diff --git a/include/linux/arm_ffa.h b/include/linux/arm_ffa.h
index e71d83ee0aef..a3f44e7c08de 100644
--- a/include/linux/arm_ffa.h
+++ b/include/linux/arm_ffa.h
@@ -269,6 +269,8 @@ bool ffa_partition_check_property(struct ffa_device *dev, u32 property)
(ffa_partition_check_property(dev, FFA_PARTITION_DIRECT_REQ2_RECV) && \
!dev->mode_32bit)
+#define FFA_SRC_ENDPOINT_MASK GENMASK(31, 16)
+
/* For use with FFA_MSG_SEND_DIRECT_{REQ,RESP} which pass data via registers */
struct ffa_send_direct_data {
unsigned long data0; /* w3/x3 */
--
2.55.0.897.gb25b4bd76c-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread* [PATCH v7 3/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ2 in host handler
2026-08-30 23:08 [PATCH v7 0/3] KVM: arm64: Support FF-A direct messaging interfaces Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 1/3] KVM: arm64: Block host-initiated FF-A direct responses Per Larsen via B4 Relay
2026-08-30 23:08 ` [PATCH v7 2/3] KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ in host handler Per Larsen via B4 Relay
@ 2026-08-30 23:08 ` Per Larsen via B4 Relay
2 siblings, 0 replies; 4+ messages in thread
From: Per Larsen via B4 Relay @ 2026-08-30 23:08 UTC (permalink / raw)
To: Marc Zyngier, Joey Gouly, Suzuki K Poulose, Zenghui Yu,
Catalin Marinas, Will Deacon, Yeoreum Yun, Ben Horgan,
Oliver Upton
Cc: Sebastien Ene, linux-arm-kernel, kvmarm, linux-kernel, Per Larsen,
Fuad Tabba
From: Per Larsen <perlarsen@google.com>
FF-A 1.2 adds the DIRECT_REQ2 messaging interface which is similar to
the existing FFA_MSG_SEND_DIRECT_{REQ,RESP} functions and can use the
existing handler function. Add support for FFA_MSG_SEND_DIRECT_REQ2 in
the host ffa handler.
Reviewed-by: Yeoreum Yun <yeoreum.yun@arm.com>
Signed-off-by: Per Larsen <perlarsen@google.com>
---
arch/arm64/kvm/hyp/nvhe/ffa.c | 21 ++++++++++++++++-----
1 file changed, 16 insertions(+), 5 deletions(-)
diff --git a/arch/arm64/kvm/hyp/nvhe/ffa.c b/arch/arm64/kvm/hyp/nvhe/ffa.c
index 96cf6be969de..eeb8d5b6f3e0 100644
--- a/arch/arm64/kvm/hyp/nvhe/ffa.c
+++ b/arch/arm64/kvm/hyp/nvhe/ffa.c
@@ -702,11 +702,12 @@ static bool ffa_call_supported(u64 func_id)
case FFA_NOTIFICATION_GET:
case FFA_NOTIFICATION_INFO_GET:
/* Optional interfaces added in FF-A 1.2 */
- case FFA_MSG_SEND_DIRECT_REQ2: /* Optional per 7.5.1 */
case FFA_MSG_SEND_DIRECT_RESP2: /* Optional per 7.5.1 */
case FFA_CONSOLE_LOG: /* Optional per 13.1: not in Table 13.1 */
case FFA_PARTITION_INFO_GET_REGS: /* Optional for virtual instances per 13.1 */
return false;
+ case FFA_MSG_SEND_DIRECT_REQ2: /* Optional per 7.5.1 */
+ return hyp_ffa_version >= FFA_VERSION_1_2;
}
return true;
@@ -880,7 +881,8 @@ static void do_ffa_part_get(struct arm_smccc_1_2_regs *res,
hyp_spin_unlock(&host_buffers.lock);
}
-static void do_ffa_direct_msg(struct arm_smccc_1_2_regs *res,
+static void do_ffa_direct_msg(const u64 func_id,
+ struct arm_smccc_1_2_regs *res,
struct kvm_cpu_context *ctxt)
{
DECLARE_REG(u64, endp, ctxt, 1);
@@ -894,8 +896,12 @@ static void do_ffa_direct_msg(struct arm_smccc_1_2_regs *res,
return;
}
- /* filter out framework messages and validate SBZ/MBZ bits */
- if (flags) {
+ /*
+ * filter out framework messages and validate SBZ/MBZ flag bits.
+ * FFA_MSG_SEND_DIRECT_REQ2 implies flag-less partition message.
+ */
+ if ((func_id == FFA_MSG_SEND_DIRECT_REQ ||
+ func_id == FFA_FN64_MSG_SEND_DIRECT_REQ) && flags) {
ffa_to_smccc_error(res, FFA_RET_INVALID_PARAMETERS);
return;
}
@@ -961,15 +967,20 @@ bool kvm_host_ffa_handler(struct kvm_cpu_context *host_ctxt, u32 func_id)
case FFA_PARTITION_INFO_GET:
do_ffa_part_get(&res, host_ctxt);
goto out_handled;
+ case FFA_MSG_SEND_DIRECT_REQ2:
+ if (!ffa_call_supported(func_id))
+ goto out_not_supported;
+ fallthrough;
case FFA_MSG_SEND_DIRECT_REQ:
case FFA_FN64_MSG_SEND_DIRECT_REQ:
- do_ffa_direct_msg(&res, host_ctxt);
+ do_ffa_direct_msg(func_id, &res, host_ctxt);
goto out_handled;
}
if (ffa_call_supported(func_id))
return false; /* Pass through */
+out_not_supported:
ffa_to_smccc_error(&res, FFA_RET_NOT_SUPPORTED);
out_handled:
ffa_set_retval(host_ctxt, &res);
--
2.55.0.897.gb25b4bd76c-goog
^ permalink raw reply related [flat|nested] 4+ messages in thread