From: Fuad Tabba <fuad.tabba@linux.dev>
To: Marc Zyngier <maz@kernel.org>, Oliver Upton <oupton@kernel.org>,
kvmarm@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org
Cc: Catalin Marinas <catalin.marinas@arm.com>,
Will Deacon <will@kernel.org>, Joey Gouly <joey.gouly@arm.com>,
Steffen Eiden <seiden@linux.ibm.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
Vincent Donnefort <vdonnefort@google.com>,
Quentin Perret <qperret@google.com>,
Fuad Tabba <tabba@google.com>
Subject: [PATCH 00/17] KVM: arm64: Confine protected VM vCPU state to EL2
Date: Mon, 31 Aug 2026 17:34:04 +0100 [thread overview]
Message-ID: <20260831163421.272420-1-fuad.tabba@linux.dev> (raw)
Hi folks,
Following the vCPU state-sync series [1], this series completes the
job for protected VMs: a protected guest's register state stays at
EL2, and the host sees only what handling each exit needs.
EL2 marshals a protected vCPU's state per exception class instead of
copying the whole context both ways. It owns the vCPU's trap
configuration, system register reset and HVC handling, and implements
PSCI itself: AFFINITY_INFO never reaches the host, and CPU_ON and
CPU_OFF are decided at EL2 with the host only scheduling or parking
the target. Host ioctls that would reach the state EL2 owns fail with
a clean errno, so a protected VM's state is not save/restorable. All
of this is scoped to KVM_VM_TYPE_ARM_PROTECTED, and pkvm.rst describes
the resulting API.
The kvmtool changes that go with this will be posted separately, and I
will reply here with a link.
Patch 1 is the HCR_EL2.VSE fix posted separately [2]. It is not part
of this series; it is carried so the series applies as is and Sashiko
can run on it.
The KVM_ARM_PREFERRED_TARGET documentation fix [3] went out just ahead
of this series. Nothing here needs it to apply, but patch 17 documents
vCPU feature availability as something the capabilities report, while
api.rst 4.83 still points userspace at a bitmap that has always been
empty.
The series is structured as follows:
01: The HCR_EL2.VSE fix, posted separately.
02-03: Capability allowlist and the PVTIME rejection.
04-05: Per-exception-class entry handlers; EL2 owns a protected
vCPU's trap configuration.
06-08: Timer state, system register reset and HVC handling at EL2.
09-10: PSCI at EL2, and the KVM_ARM_VCPU_INIT and PSCI version
restrictions.
11-14: Host PC adjustments blocked; an UNDEF at EL2 for exit
classes the host does not emulate; per-class state
marshalling; a protected guest's SError pended with
HCR_EL2.VSE.
15-16: Host access to private state, and host power-on of a vCPU
EL2 holds powered off, rejected.
17: Documentation.
Still to come: selftests, self-hosted debug, SVE for protected guests,
and much more, as separate series.
Based on v7.3-rc1 (cee9395acd804).
Cheers,
/fuad
P.S. Sashiko, bring it on!
[1] https://lore.kernel.org/all/20260729131823.2021516-1-fuad.tabba@linux.dev/
[2] https://lore.kernel.org/all/20260829071120.2522788-1-fuad.tabba@linux.dev/
[3] https://lore.kernel.org/all/20260831162815.269851-1-fuad.tabba@linux.dev/
Fuad Tabba (15):
KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM
KVM: arm64: Advertise the capabilities that protected VMs support
KVM: arm64: Reject the PVTIME vCPU attribute for protected VMs
KVM: arm64: Skip fixed-feature state flush for protected vCPUs
KVM: arm64: Add system register reset framework for protected VMs
KVM: arm64: Implement HVC handling for protected guests at EL2
KVM: arm64: Handle PSCI calls for protected VMs at EL2
KVM: arm64: Restrict KVM_ARM_VCPU_INIT and PSCI version for protected
VMs
KVM: arm64: Prevent host PC adjustments for protected vCPUs
KVM: arm64: Inject an UNDEF at EL2 for unhandled protected guest exits
KVM: arm64: Add per-EC entry/exit state marshalling for protected
guests
KVM: arm64: Pend a protected guest's SError with HCR_EL2.VSE only
KVM: arm64: Reject host access to protected VM private state
KVM: arm64: Reject host power-on of a vCPU that EL2 holds powered off
KVM: arm64: Document the protected VM userspace API
Marc Zyngier (2):
KVM: arm64: Introduce per-EC entry handlers for pKVM
KVM: arm64: Add {flush,sync}_hyp_timer_state() primitives
Documentation/virt/kvm/api.rst | 22 +-
.../virt/kvm/arm/fw-pseudo-registers.rst | 2 +
Documentation/virt/kvm/arm/pkvm.rst | 141 ++++-
Documentation/virt/kvm/devices/vcpu.rst | 4 +-
arch/arm64/include/asm/kvm_asm.h | 1 +
arch/arm64/include/asm/kvm_host.h | 21 +
arch/arm64/include/asm/kvm_pkvm.h | 34 +-
arch/arm64/kvm/arm.c | 40 ++
arch/arm64/kvm/guest.c | 29 +
arch/arm64/kvm/hyp/exception.c | 27 +-
arch/arm64/kvm/hyp/include/nvhe/pkvm.h | 18 +
arch/arm64/kvm/hyp/nvhe/hyp-main.c | 564 +++++++++++++++++-
arch/arm64/kvm/hyp/nvhe/pkvm.c | 401 ++++++++++++-
arch/arm64/kvm/hyp/nvhe/switch.c | 29 +-
arch/arm64/kvm/hyp/nvhe/sys_regs.c | 91 ++-
arch/arm64/kvm/hypercalls.c | 7 +
arch/arm64/kvm/inject_fault.c | 5 +-
arch/arm64/kvm/pkvm.c | 21 +-
arch/arm64/kvm/psci.c | 3 +
19 files changed, 1378 insertions(+), 82 deletions(-)
base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
--
2.39.5
next reply other threads:[~2026-08-31 16:34 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 16:34 Fuad Tabba [this message]
2026-08-31 16:34 ` [PATCH 01/17] KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM Fuad Tabba
2026-08-31 16:34 ` [PATCH 02/17] KVM: arm64: Advertise the capabilities that protected VMs support Fuad Tabba
2026-09-02 13:22 ` Vincent Donnefort
2026-09-03 16:20 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 03/17] KVM: arm64: Reject the PVTIME vCPU attribute for protected VMs Fuad Tabba
2026-09-02 13:30 ` Vincent Donnefort
2026-09-03 16:21 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 04/17] KVM: arm64: Introduce per-EC entry handlers for pKVM Fuad Tabba
2026-09-02 10:12 ` Joey Gouly
2026-09-02 11:35 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 05/17] KVM: arm64: Skip fixed-feature state flush for protected vCPUs Fuad Tabba
2026-09-02 15:05 ` Vincent Donnefort
2026-09-02 15:26 ` Vincent Donnefort
2026-09-03 16:22 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 06/17] KVM: arm64: Add {flush,sync}_hyp_timer_state() primitives Fuad Tabba
2026-08-31 16:34 ` [PATCH 07/17] KVM: arm64: Add system register reset framework for protected VMs Fuad Tabba
2026-09-02 15:14 ` Joey Gouly
2026-09-03 16:24 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 08/17] KVM: arm64: Implement HVC handling for protected guests at EL2 Fuad Tabba
2026-09-03 15:12 ` Joey Gouly
2026-09-03 16:25 ` Fuad Tabba
2026-08-31 16:34 ` [PATCH 09/17] KVM: arm64: Handle PSCI calls for protected VMs " Fuad Tabba
2026-08-31 16:34 ` [PATCH 10/17] KVM: arm64: Restrict KVM_ARM_VCPU_INIT and PSCI version for protected VMs Fuad Tabba
2026-08-31 16:34 ` [PATCH 11/17] KVM: arm64: Prevent host PC adjustments for protected vCPUs Fuad Tabba
2026-08-31 16:34 ` [PATCH 12/17] KVM: arm64: Inject an UNDEF at EL2 for unhandled protected guest exits Fuad Tabba
2026-08-31 16:34 ` [PATCH 13/17] KVM: arm64: Add per-EC entry/exit state marshalling for protected guests Fuad Tabba
2026-08-31 16:34 ` [PATCH 14/17] KVM: arm64: Pend a protected guest's SError with HCR_EL2.VSE only Fuad Tabba
2026-08-31 16:34 ` [PATCH 15/17] KVM: arm64: Reject host access to protected VM private state Fuad Tabba
2026-08-31 16:34 ` [PATCH 16/17] KVM: arm64: Reject host power-on of a vCPU that EL2 holds powered off Fuad Tabba
2026-08-31 16:34 ` [PATCH 17/17] KVM: arm64: Document the protected VM userspace API Fuad Tabba
2026-08-31 19:27 ` [PATCH 00/17] KVM: arm64: Confine protected VM vCPU state to EL2 Fuad Tabba
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260831163421.272420-1-fuad.tabba@linux.dev \
--to=fuad.tabba@linux.dev \
--cc=catalin.marinas@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=qperret@google.com \
--cc=seiden@linux.ibm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vdonnefort@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox