Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com,
	linux-kernel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
	aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com,
	joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com,
	linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
	sdonthineni@nvidia.com, alpergun@google.com,
	fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
	lpieralisi@kernel.org, enju.kohei@fujitsu.com,
	sudeep.holla@arm.com, jonathan.cameron@oss.qualcomm.com,
	Suzuki K Poulose <suzuki.poulose@arm.com>
Subject: [PATCH v23 00/14] KVM: arm64: CCA: Add basic plumbing for Realms
Date: Wed,  7 Oct 2026 08:35:23 +0100	[thread overview]
Message-ID: <20261007073537.2454351-1-suzuki.poulose@arm.com> (raw)

This is a trimmed down and updated version of the v22 of Arm CCA basic
plumbing series [0]. I have dropped the CCA specific bits for the sake keeping
them separate. This series now only contains the framework for handling
different VM types and lay down the path for adding Realm as one of the
protected VMs. The full support for running Realms under KVM is available as
an integration branch at [1].

The integration branch has been tested with the following components:

  tf-RMM:   main branch (commit 5e6e2acd) compliant to RMM-v2.0-beta3
  kvmtool: git@git.gitlab.arm.com:linux-arm/kvmtool-cca.git tag:cca-kvm-v20

[0] Arm CCA KVM basic plumbing v22
    https://lore.kernel.org/all/20261005090754.2140522-1-suzuki.poulose@arm.com
[1] https://git.gitlab.arm.com/linux-arm/linux-cca/ cca/cca-host/kvm-v23/integration

Changes since v22:
 https://lore.kernel.org/all/20261005090754.2140522-1-suzuki.poulose@arm.com
  - Drop the CCA specific patches for now, they are on the integration branch
  - system_supported_vcpu_features() - Start off with a base set of features for
    the type of VM
  - Add () around 'flavor' in KVM_VM_S2_OPS() macro
  - Drop BUILD_BUG_ON and redefine {kvm_vm,vcpu}_is_protected() for nVHE
  - Drop {kvm_vm,vcpu}_is_protected_pkvm() macros

Changes since v21:
 https://lore.kernel.org/all/20261001210703.1597150-1-suzuki.poulose@arm.com
 - Keep the kvm_arch struct packed, by moving psci_version, closer to vm_flavor and also moving the vm_s2_ops, closer to vm_flavor.
 - Drop the kern_hyp_va() for vcpu_is_protected() in nVHE, instead ban nVHE
   code from using vcpu_is_protected() (by using BUILD_BUG_ON()) and convert
   all users to vcpu_is_protected_pkvm()
 - Drop kvm_vm_is_unprotected_pkvm() in favor of open coded check against VM_PKVM
 - Drop WARN_ON_ONCE() in the kvm_vm_ioctl_allowed() to match Fuad's fix merged in v7.3-rc5
 - Move '&' to the KVM_*_OPS macros
 - Nuke __unmap_stage2_range() and define per-VM callback for stage2_unmap_range, removing the KVM_PGT_FN() hack for the call, and also for the others
 - Drop NULL check for vm_s2_ops callbacks and always define everything.
 - Add no_age_gfn() which plugs in for pVMs and Realms for the vm_age_*gfn callbacks

Steven Price (1):
  KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h

Suzuki K Poulose (13):
  KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0
  KVM: arm64: Disable Steal time accounting for protected guests
  KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h
  KVM: arm64: Track the type of VM in kvm_arch
  KVM: arm64: Don't call vcpu_set_pauth_traps for pKVM host
  KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks
  KVM: arm64: Add vcpu load/put call backs for flavors
  KVM: arm64: Consolidate stage2 unmap range into kvm_stage2_unmap_range
  KVM: arm64: Add VM specific callback for S2 MMU operations
  KVM: arm64: Use a local kvm pointer in kvm_handle_guest_abort()
  KVM: arm64: Abstract out memory abort handling
  KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms
  KVM: arm64: Prevent unsupported vcpu features for VM types

 arch/arm64/include/asm/kvm_host.h    |  73 ++++++-
 arch/arm64/include/asm/kvm_pgtable.h |  10 +-
 arch/arm64/include/asm/kvm_pkvm.h    |   6 +-
 arch/arm64/kvm/arch_timer.c          |  12 +-
 arch/arm64/kvm/arm.c                 | 275 ++++++++++++++++++++-------
 arch/arm64/kvm/hyp/nvhe/pkvm.c       |   6 +-
 arch/arm64/kvm/hyp/pgtable.c         |   1 +
 arch/arm64/kvm/mmio.c                |   1 +
 arch/arm64/kvm/mmu.c                 | 247 +++++++++++++++++-------
 arch/arm64/kvm/pkvm.c                |   6 +-
 arch/arm64/kvm/pvtime.c              |  14 +-
 arch/arm64/kvm/vgic/vgic-init.c      |   2 +
 include/kvm/arm_psci.h               |   2 +
 13 files changed, 493 insertions(+), 162 deletions(-)

-- 
2.43.0



             reply	other threads:[~2026-10-07  7:36 UTC|newest]

Thread overview: 34+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07  7:35 Suzuki K Poulose [this message]
2026-10-07  7:35 ` [PATCH v23 01/14] KVM: arm64: protected VM: Handle user writes to CNTVCT_EL0/CNTPCT_EL0 Suzuki K Poulose
2026-10-07 10:43   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 02/14] KVM: arm64: Disable Steal time accounting for protected guests Suzuki K Poulose
2026-10-07 10:51   ` Fuad Tabba
2026-10-07 13:10     ` Suzuki K Poulose
2026-10-07  7:35 ` [PATCH v23 03/14] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-10-07 11:00   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 04/14] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-10-07  7:35 ` [PATCH v23 05/14] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-10-07  7:35 ` [PATCH v23 06/14] KVM: arm64: Don't call vcpu_set_pauth_traps for pKVM host Suzuki K Poulose
2026-10-07 11:07   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 07/14] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-10-07 11:12   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 08/14] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-10-07 11:18   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 09/14] KVM: arm64: Consolidate stage2 unmap range into kvm_stage2_unmap_range Suzuki K Poulose
2026-10-07 11:23   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 10/14] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-10-07 11:38   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 11/14] KVM: arm64: Use a local kvm pointer in kvm_handle_guest_abort() Suzuki K Poulose
2026-10-07  7:35 ` [PATCH v23 12/14] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-10-07 13:45   ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 13/14] KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms Suzuki K Poulose
2026-10-07 13:45   ` Fuad Tabba
2026-10-08  8:51     ` Suzuki K Poulose
2026-10-08 11:17       ` Fuad Tabba
2026-10-07  7:35 ` [PATCH v23 14/14] KVM: arm64: Prevent unsupported vcpu features for VM types Suzuki K Poulose
2026-10-07 14:19   ` Fuad Tabba
2026-10-09  8:55     ` Marc Zyngier
2026-10-09 10:10       ` Fuad Tabba
2026-10-09 12:16         ` Marc Zyngier
2026-10-09 13:28 ` [PATCH v23 00/14] KVM: arm64: CCA: Add basic plumbing for Realms Marc Zyngier
2026-10-09 14:20   ` Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007073537.2454351-1-suzuki.poulose@arm.com \
    --to=suzuki.poulose@arm.com \
    --cc=WeiLin.Chang@arm.com \
    --cc=alpergun@google.com \
    --cc=aneesh.kumar@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=fj0570is@fujitsu.com \
    --cc=gankulkarni@os.amperecomputing.com \
    --cc=gshan@redhat.com \
    --cc=joey.gouly@arm.com \
    --cc=jonathan.cameron@oss.qualcomm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lpieralisi@kernel.org \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sdonthineni@nvidia.com \
    --cc=steven.price@arm.com \
    --cc=sudeep.holla@arm.com \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox