From: Kohei Enju <enju.kohei@fujitsu.com>
To: Steven Price <steven.price@arm.com>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
Catalin Marinas <catalin.marinas@arm.com>,
Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
James Morse <james.morse@arm.com>,
Oliver Upton <oliver.upton@linux.dev>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
Alexandru Elisei <alexandru.elisei@arm.com>,
Christoffer Dall <christoffer.dall@arm.com>,
Fuad Tabba <tabba@google.com>,
linux-coco@lists.linux.dev,
Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
Gavin Shan <gshan@redhat.com>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Alper Gun <alpergun@google.com>,
"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>,
Emi Kisanuki <fj0570is@fujitsu.com>,
Vishal Annapurve <vannapurve@google.com>,
WeiLin.Chang@arm.com, Lorenzo Pieralisi <lpieralisi@kernel.org>
Subject: Re: [PATCH v16 21/45] KVM: arm64: CCA: Handle realm enter/exit
Date: Mon, 10 Aug 2026 17:03:02 +0900 [thread overview]
Message-ID: <anl7EwU9jSig-uQs@FCCLS0092175.localdomain> (raw)
In-Reply-To: <20260803134403.80630-22-steven.price@arm.com>
On 08/03 14:43, Steven Price wrote:
> Entering a realm is done using a SMC call to the RMM. On exit the
> exit-codes need to be handled slightly differently to the normal KVM
> path so define our own functions for realm enter/exit and hook them
> in if the guest is a realm guest.
Hi Steven,
I found that when the host kernel is booting with pseudo-NMI enabled
(irqchip.gicv3_pseudo_nmi=1), Realm VMs fail boot successfully and the
watchdog reports RCU stalls and soft lockups.
After some investigations, I confirmed that arch_timer interrupts
are not being delivered to some CPUs. This appears to be because PMR is
000000c0 (GICV3_PRIO_IRQ), as shown below:
[ 248.769692] pmr: 000000c0
For normal VMs, KVM opens PMR before entering the guest, because having
IRQs masked via PMR when entering the guest means the GIC will not
signal the CPU of interrupts of lower priority, and in the worst case
a guest exit may never occur.
(See __kvm_vcpu_run in arch/arm64/kvm/hyp/vhe/switch.c)
[ 248.756980] rcu: INFO: rcu_preempt detected stalls on CPUs/tasks:
[ 248.758649] rcu: 3-...0: (113 ticks this GP) idle=d2ec/1/0x4000000000000000 softirq=1631/1633 fqs=297
[ 248.759413] rcu: 4-...0: (7 ticks this GP) idle=b77c/1/0x4000000000000000 softirq=1589/1589 fqs=297
[ 248.760101] rcu: (detected by 7, t=6003 jiffies, g=4553, q=86 ncpus=8)
[ 248.760731] Sending NMI from CPU 7 to CPUs 3:
[ 248.766814] NMI backtrace for cpu 3
[ 248.768285] CPU: 3 UID: 0 PID: 387 Comm: kvm-vcpu-0 Not tainted 7.2.0-rc2-00267-g7326f0114689 #238 PREEMPT(lazy)
[ 248.768681] Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 02/02/2022
[ 248.768936] pstate: 61402009 (nZCv daif +PAN -UAO -TCO +DIT -SSBS BTYPE=--)
[ 248.769021] pc : kvm_rec_enter+0xa0/0xb8
[ 248.769585] lr : kvm_rec_enter+0x24/0xb8
[ 248.769655] sp : ffff800084943830
[ 248.769692] pmr: 000000c0
[ 248.769757] x29: ffff800084943830 x28: ffff0000079c6c00 x27: 0000000000000000
[ 248.770441] x26: 0000000000000000 x25: 0000000000000000 x24: 0000000000000000
[ 248.770536] x23: 0000000080000000 x22: 0000000000000001 x21: 0000000049d99000
[ 248.770590] x20: 0000000049d9a000 x19: ffff00000e018000 x18: 0000000000000000
[ 248.770647] x17: 0000000000000000 x16: 0000000000000000 x15: 0000000000000000
[ 248.770756] x14: 0000000000000000 x13: 0000000000000000 x12: 0000000000000000
[ 248.770863] x11: 0000000000000000 x10: 0000000000000000 x9 : ffff8000812ab1bc
[ 248.771018] x8 : 0000000000000000 x7 : 0000000000000020 x6 : 0000000000000080
[ 248.771123] x5 : 0000000000000004 x4 : 0000000000000040 x3 : 0000000000000000
[ 248.771172] x2 : 0000000000000000 x1 : 0000000000000000 x0 : 0000000000000000
[ 248.771385] Call trace:
[ 248.771612] kvm_rec_enter+0xa0/0xb8 (P)
[ 248.771757] kvm_arm_vcpu_enter_exit+0x8c/0x218
[ 248.771796] kvm_arch_vcpu_ioctl_run+0x274/0x890
[ 248.771843] kvm_vcpu_ioctl+0x180/0xb50
[ 248.771883] __arm64_sys_ioctl+0xb4/0x118
[ 248.771920] invoke_syscall.constprop.0+0xb8/0x120
[ 248.771954] do_el0_svc+0x48/0xc8
[ 248.771982] el0_svc+0x48/0x280
[ 248.772012] el0t_64_sync_handler+0xa0/0xe8
[ 248.772041] el0t_64_sync+0x1ac/0x1b0
[...]
> [...]
> +int noinstr kvm_rec_enter(struct kvm_vcpu *vcpu)
> +{
> + struct realm_rec *rec = &vcpu->arch.rec;
> + int ret;
> +
> + ret = rmi_rec_enter(rec->rec_phys, rec->run_phys);
> + if (!ret)
> + load_realm_timer_state(vcpu);
> +
> + return ret;
> +}
In my testing environment, adding local_daif_mask/restore() in line with
__kvm_vcpu_run() fixes the issue, and Realm VMs successfully boot
without RCU stalls or soft lockups.
However, I'm not sure if we can safely call local_daif_mask/restore()
here, bacause they call trace_hardirqs_off/on(), which presumably cannot
be called from noinstr context.
For reference, the VHE hyp path seems to call local_daif_mask/restore()
from noinstr context, but I'm not sure why this is considered safe:
noinstr kvm_arm_vcpu_enter_exit()
kvm_call_hyp_ret(__kvm_vcpu_run, vcpu) <- normal function call for VHE
local_daif_mask()
trace_hardirqs_off()
local_daif_restore()
trace_hardirqs_off/on()
The following change works in my test environment.
Any thoughts on the issue and the proposed fix?
diff --git a/arch/arm64/kvm/rmi.c b/arch/arm64/kvm/rmi.c
index c242dfc2c7a6..dd7cb2d7db88 100644
--- a/arch/arm64/kvm/rmi.c
+++ b/arch/arm64/kvm/rmi.c
@@ -1307,7 +1307,13 @@ int noinstr kvm_rec_enter(struct kvm_vcpu *vcpu)
struct realm_rec *rec = &vcpu->arch.rec;
int ret;
+ local_daif_mask();
+ pmr_sync();
+
ret = rmi_rec_enter(rec->rec_phys, rec->run_phys);
+
+ local_daif_restore(DAIF_PROCCTX_NOIRQ);
+
if (!ret)
load_realm_timer_state(vcpu);
Thanks,
Kohei
next prev parent reply other threads:[~2026-08-10 8:03 UTC|newest]
Thread overview: 70+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 13:43 [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Steven Price
2026-08-03 13:43 ` [PATCH v16 01/45] firmware: arm_rmm: Add SMC definitions for calling the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 02/45] firmware: arm_rmm: Add wrappers for direct RMI calls Steven Price
2026-08-03 13:43 ` [PATCH v16 03/45] firmware: arm_rmm: Check for RMI support at init Steven Price
2026-08-03 13:43 ` [PATCH v16 04/45] firmware: arm_rmm: Configure the RMM with the host's page size Steven Price
2026-08-03 13:43 ` [PATCH v16 05/45] firmware: arm_rmm: Add support for SRO Steven Price
2026-08-03 13:43 ` [PATCH v16 06/45] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Steven Price
2026-08-09 6:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 07/45] arm64: mm: Handle Granule Protection Faults (GPFs) Steven Price
2026-08-03 13:43 ` [PATCH v16 08/45] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2026-08-03 13:43 ` [PATCH v16 09/45] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Steven Price
2026-08-03 13:43 ` [PATCH v16 10/45] KVM: arm64: CCA: Add wrappers for realm related RMIs Steven Price
2026-08-03 13:43 ` [PATCH v16 11/45] KVM: arm64: CCA: Check for RMI support at KVM init Steven Price
2026-08-04 14:55 ` Fuad Tabba
2026-08-04 14:59 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 12/45] KVM: arm64: CCA: Check for LPA2 support Steven Price
2026-08-03 13:43 ` [PATCH v16 13/45] KVM: arm64: CCA: Define the user ABI Steven Price
2026-08-03 13:43 ` [PATCH v16 14/45] KVM: arm64: CCA: Add basic infrastructure for creating a realm Steven Price
2026-08-03 13:43 ` [PATCH v16 15/45] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Steven Price
2026-08-03 13:43 ` [PATCH v16 16/45] KVM: arm64: CCA: Allow passing the machine type in KVM creation Steven Price
2026-08-03 13:43 ` [PATCH v16 17/45] KVM: arm64: CCA: Tear down RTTs Steven Price
2026-08-03 22:29 ` Alper Gun
2026-08-04 12:16 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 18/45] KVM: arm64: CCA: Allocate and free RECs to match vCPUs Steven Price
2026-08-03 13:43 ` [PATCH v16 19/45] KVM: arm64: CCA: Support the VGIC in realms Steven Price
2026-08-03 13:43 ` [PATCH v16 20/45] KVM: arm64: CCA: Support timers in realm RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 21/45] KVM: arm64: CCA: Handle realm enter/exit Steven Price
2026-08-04 8:57 ` Aneesh Kumar K.V
2026-08-04 13:36 ` Aneesh Kumar K.V
2026-08-10 8:03 ` Kohei Enju [this message]
2026-08-03 13:43 ` [PATCH v16 22/45] KVM: arm64: CCA: Handle RMI_EXIT_RIPAS_CHANGE Steven Price
2026-08-05 15:59 ` Ackerley Tng
2026-08-06 8:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 23/45] KVM: arm64: CCA: Handle realm MMIO emulation Steven Price
2026-08-03 13:43 ` [PATCH v16 24/45] KVM: arm64: Expose support for private memory Steven Price
2026-08-05 16:02 ` Ackerley Tng
2026-08-07 10:12 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 25/45] KVM: arm64: CCA: Create the realm descriptor Steven Price
2026-08-03 13:43 ` [PATCH v16 26/45] KVM: arm64: CCA: Activate realms on first vCPU run Steven Price
2026-08-03 13:43 ` [PATCH v16 27/45] KVM: arm64: CCA: Allow populating initial contents Steven Price
2026-08-06 22:43 ` Ackerley Tng
2026-08-07 10:58 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 28/45] KVM: arm64: CCA: Set RIPAS of initial memslots Steven Price
2026-08-03 13:43 ` [PATCH v16 29/45] KVM: arm64: CCA: Support runtime faulting of memory Steven Price
2026-08-06 23:11 ` Ackerley Tng
2026-08-03 13:43 ` [PATCH v16 30/45] KVM: arm64: CCA: Handle realm vCPU load Steven Price
2026-08-10 14:46 ` Kohei Enju
2026-08-03 13:43 ` [PATCH v16 31/45] KVM: arm64: CCA: Validate register access for Realm VMs Steven Price
2026-08-03 13:43 ` [PATCH v16 32/45] KVM: arm64: CCA: Handle Realm PSCI requests Steven Price
2026-08-03 13:43 ` [PATCH v16 33/45] KVM: arm64: WARN on injected undef exceptions Steven Price
2026-08-03 13:43 ` [PATCH v16 34/45] KVM: arm64: CCA: Allow userspace to inject aborts Steven Price
2026-08-03 13:43 ` [PATCH v16 35/45] KVM: arm64: CCA: Support RSI_HOST_CALL Steven Price
2026-08-03 13:43 ` [PATCH v16 36/45] KVM: arm64: CCA: Allow checking SVE on VM instance Steven Price
2026-08-03 13:43 ` [PATCH v16 37/45] KVM: arm64: CCA: Prevent Device mappings for realms Steven Price
2026-08-03 13:43 ` [PATCH v16 38/45] KVM: arm64: CCA: Propagate breakpoint and watchpoint counts to userspace Steven Price
2026-08-03 13:43 ` [PATCH v16 39/45] KVM: arm64: CCA: Set breakpoint parameters through SET_ONE_REG Steven Price
2026-08-03 13:43 ` [PATCH v16 40/45] KVM: arm64: CCA: Propagate max SVE vector length from the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 41/45] KVM: arm64: CCA: Configure max SVE vector length for a Realm Steven Price
2026-08-03 13:43 ` [PATCH v16 42/45] KVM: arm64: CCA: Provide register list for unfinalized RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 43/45] KVM: arm64: CCA: Provide an accurate register list Steven Price
2026-08-03 13:44 ` [PATCH v16 44/45] KVM: arm64: CCA: Require ICH_HCR_EL2.TDIR for realms Steven Price
2026-08-10 4:58 ` Kohei Enju
2026-08-10 9:41 ` Marc Zyngier
2026-08-03 13:44 ` [PATCH v16 45/45] KVM: arm64: CCA: Enable realms to be created Steven Price
2026-08-03 15:01 ` [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Marc Zyngier
2026-08-03 15:06 ` Steven Price
2026-08-03 15:20 ` Marc Zyngier
2026-08-03 15:45 ` Steven Price
2026-08-04 14:24 ` Fuad Tabba
2026-08-06 22:05 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=anl7EwU9jSig-uQs@FCCLS0092175.localdomain \
--to=enju.kohei@fujitsu.com \
--cc=WeiLin.Chang@arm.com \
--cc=alexandru.elisei@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christoffer.dall@arm.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=james.morse@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vannapurve@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox