From: Kohei Enju <enju.kohei@fujitsu.com>
To: Steven Price <steven.price@arm.com>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
Catalin Marinas <catalin.marinas@arm.com>,
Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
James Morse <james.morse@arm.com>,
Oliver Upton <oliver.upton@linux.dev>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
Zenghui Yu <yuzenghui@huawei.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
Alexandru Elisei <alexandru.elisei@arm.com>,
Christoffer Dall <christoffer.dall@arm.com>,
Fuad Tabba <tabba@google.com>,
linux-coco@lists.linux.dev,
Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
Gavin Shan <gshan@redhat.com>,
Shanker Donthineni <sdonthineni@nvidia.com>,
Alper Gun <alpergun@google.com>,
"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>,
Emi Kisanuki <fj0570is@fujitsu.com>,
Vishal Annapurve <vannapurve@google.com>,
WeiLin.Chang@arm.com, Lorenzo Pieralisi <lpieralisi@kernel.org>
Subject: Re: [PATCH v16 44/45] KVM: arm64: CCA: Require ICH_HCR_EL2.TDIR for realms
Date: Thu, 27 Aug 2026 21:45:17 +0900 [thread overview]
Message-ID: <apAwQeTW-JvCISEt@FCCLS0092175.localdomain> (raw)
In-Reply-To: <bdd0cf41-05e8-4d66-930b-5a7a1b3e643a@arm.com>
On 08/24 15:50, Steven Price wrote:
> On 10/08/2026 05:58, Kohei Enju wrote:
> > On 08/03 14:44, Steven Price wrote:
> >> KVM advertises realm support when the RMM is available, and allows
> >> userspace to create a VM with KVM_VM_TYPE_ARM_REALM on that basis.
> >>
> >> On CPUs that lack ICH_HCR_EL2.TDIR, KVM uses ICH_HCR_EL2.TC for
> >> normal guests so that ICC_DIR_EL1 is still trapped via the common GICv3
> >> CPU interface trap. Realms cannot rely on the normal hyp-side trap
> >> handling for that fallback, so advertising RMI support on such systems
> >> lets userspace create a realm that cannot safely run.
> >>
> >> Require the finalized ARM64_HAS_ICH_HCR_EL2_TDIR capability when
> >> reporting KVM_CAP_ARM_RMI and when accepting KVM_VM_TYPE_ARM_REALM.
> >> This leaves normal VM creation unchanged on systems that need the TC
> >> workaround.
> >
> > Hi Steven,
>
> Hi Kohei,
>
> Sorry for the slow response.
>
> > Thanks for your work on upstreaming CCA.
> >
> > In the v15 discussion [0], you asked whether the system I was testing was a
> > "hacked up test system" or closer to "production hardware", and I said I would
> > share more when the time came. I can now say that this is not a hacked-up test
> > system. At Fujitsu, we have real hardware (FUJITSU-MONAKA) which implements CCA
> > (FEAT_RME) but does not implement FEAT_GICv3_TDIR. The hardware details are as
> > follows:
>
> Cool, I suspected that might be the case - it's good to know there's
> real hardware on it's way.
>
> > - GICv4.2 compliant implementation
> > - Supports FEAT_GICv3, FEAT_GICv3p1, FEAT_GICv4, FEAT_GICv4p1, and FEAT_GICv3_NMI
> > - Does not support FEAT_GICv3_LEGACY (deprecated)
> > - Does not support FEAT_GICv3_TDIR (ICH_VTR_EL2.TDS == 0)
> >
> > For reference, compared with Arm Neoverse V3, the virtual GIC configuration is
> > largely equivalent. The only missing non-deprecated architectural feature is
> > FEAT_GICv3_TDIR.
> >
> > The issue I see is that the CCA KVM code currently does not support a
> > configuration (non-TDIR/common-trap) that normal KVM already supports. For
> > normal guests, KVM handles systems without TDIR by using ICH_HCR_EL2.TC and the
> > existing GICv3 CPU interface emulation path. However, Realm guests currently
> > fail because the CCA path bypasses that existing emulation path, as Marc also
> > pointed out in [1].
> >
> > Also, this is not limited to systems that actually lack TDIR. The same failure
> > can be reproduced on a TDIR-capable system by booting with:
> > kvm-arm.vgic_v3_common_trap=1
>
> As Marc says that's a debugging option - handy for those of us who don't
> have a platform without TDIR to test with.
>
> > So it seems that the current CCA KVM implementation does not yet cover a
> > configuration that normal KVM already supports today, rather than this being a
> > limitation of the RMM specification or the underlying hardware.
> >
> > I've included a patch below which reuses the existing GICv3 early emulation
> > path for Realm sysreg exits. This patch does not add any new vGIC emulation
> > code, and leaves the existing vGIC emulation code unchanged. So I believe this
> > is in line with Marc's request in [1]. With this patch, Realm guests can run
> > when the common CPU interface trap path is enabled.
> >
> > I tested the exact patch both on our real silicon and on QEMU, and
> > confirmed that all Realm-related tests in kvm-unit-tests-cca passed.
> >
> > I'm not attached to this exact implementation, and I'm happy if the solution is
> > reworked to better fit into the next revision.
> >
> > Given that this configuration can be supported by reusing the existing KVM
> > emulation infrastructure, I think it would be reasonable for CCA to support the
> > non-TDIR/common-trap configuration rather than requiring ICH_HCR_EL2.TDIR
> > unconditionally for Realm support.
> >
> > Supporting this configuration would also allow us to validate the upstream CCA
> > KVM implementation on real silicon using upstream code paths, and contribute
> > additional real-hardware testing coverage as the implementation
> > evolves.
> >
> > I'd be very interested in hearing your thoughts.
>
> So personally I think your patch is a good compromise. It gets the
> hardware working and I'm keen to enable real-hardware testing. Marc has
> a very valid point that in terms of performance this could be very bad.
> Pseudo NMI in particular will be terrible because accesses to GIC
> registers are used to "emulate" the NMI so the number of traps will be
> large, and the traps are much more expensive with CCA.
Yes, in that case ICV_PMR_EL1 would be accessed frequently, and the
resulting traps would be expensive.
>
> So I'll attempt to incorporate the changes in your patch, but obviously
> you'll have to decide for yourself whether the performance of the
> product is suitable.
Thanks for the clarification.
I agree with the performance concern, and I'll run some benchmarks on
our hardware.
Thanks,
Kohei
>
> Thanks,
> Steve
>
next prev parent reply other threads:[~2026-08-27 12:45 UTC|newest]
Thread overview: 98+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-03 13:43 [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Steven Price
2026-08-03 13:43 ` [PATCH v16 01/45] firmware: arm_rmm: Add SMC definitions for calling the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 02/45] firmware: arm_rmm: Add wrappers for direct RMI calls Steven Price
2026-08-03 13:43 ` [PATCH v16 03/45] firmware: arm_rmm: Check for RMI support at init Steven Price
2026-08-03 13:43 ` [PATCH v16 04/45] firmware: arm_rmm: Configure the RMM with the host's page size Steven Price
2026-08-03 13:43 ` [PATCH v16 05/45] firmware: arm_rmm: Add support for SRO Steven Price
2026-08-03 13:43 ` [PATCH v16 06/45] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Steven Price
2026-08-09 6:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 07/45] arm64: mm: Handle Granule Protection Faults (GPFs) Steven Price
2026-08-11 14:44 ` Catalin Marinas
2026-08-11 15:11 ` Suzuki K Poulose
2026-08-12 12:42 ` Pavan Kondeti
2026-08-12 13:51 ` Catalin Marinas
2026-08-13 10:11 ` Will Deacon
2026-08-13 14:10 ` Pavan Kondeti
2026-08-13 15:28 ` Will Deacon
2026-08-14 8:45 ` Pavan Kondeti
2026-08-14 9:20 ` Will Deacon
2026-08-03 13:43 ` [PATCH v16 08/45] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2026-08-03 13:43 ` [PATCH v16 09/45] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Steven Price
2026-08-03 13:43 ` [PATCH v16 10/45] KVM: arm64: CCA: Add wrappers for realm related RMIs Steven Price
2026-08-03 13:43 ` [PATCH v16 11/45] KVM: arm64: CCA: Check for RMI support at KVM init Steven Price
2026-08-04 14:55 ` Fuad Tabba
2026-08-04 14:59 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 12/45] KVM: arm64: CCA: Check for LPA2 support Steven Price
2026-08-03 13:43 ` [PATCH v16 13/45] KVM: arm64: CCA: Define the user ABI Steven Price
2026-08-03 13:43 ` [PATCH v16 14/45] KVM: arm64: CCA: Add basic infrastructure for creating a realm Steven Price
2026-08-03 13:43 ` [PATCH v16 15/45] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Steven Price
2026-08-03 13:43 ` [PATCH v16 16/45] KVM: arm64: CCA: Allow passing the machine type in KVM creation Steven Price
2026-08-03 13:43 ` [PATCH v16 17/45] KVM: arm64: CCA: Tear down RTTs Steven Price
2026-08-03 22:29 ` Alper Gun
2026-08-04 12:16 ` Suzuki K Poulose
2026-08-11 14:51 ` Suzuki K Poulose
2026-08-13 14:38 ` Steven Price
2026-08-03 13:43 ` [PATCH v16 18/45] KVM: arm64: CCA: Allocate and free RECs to match vCPUs Steven Price
2026-08-03 13:43 ` [PATCH v16 19/45] KVM: arm64: CCA: Support the VGIC in realms Steven Price
2026-08-03 13:43 ` [PATCH v16 20/45] KVM: arm64: CCA: Support timers in realm RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 21/45] KVM: arm64: CCA: Handle realm enter/exit Steven Price
2026-08-04 8:57 ` Aneesh Kumar K.V
2026-08-13 14:38 ` Steven Price
2026-08-04 13:36 ` Aneesh Kumar K.V
2026-08-13 14:38 ` Steven Price
2026-08-10 8:03 ` Kohei Enju
2026-08-13 14:38 ` Steven Price
2026-08-03 13:43 ` [PATCH v16 22/45] KVM: arm64: CCA: Handle RMI_EXIT_RIPAS_CHANGE Steven Price
2026-08-05 15:59 ` Ackerley Tng
2026-08-06 8:42 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 23/45] KVM: arm64: CCA: Handle realm MMIO emulation Steven Price
2026-08-03 13:43 ` [PATCH v16 24/45] KVM: arm64: Expose support for private memory Steven Price
2026-08-05 16:02 ` Ackerley Tng
2026-08-07 10:12 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 25/45] KVM: arm64: CCA: Create the realm descriptor Steven Price
2026-08-03 13:43 ` [PATCH v16 26/45] KVM: arm64: CCA: Activate realms on first vCPU run Steven Price
2026-08-03 13:43 ` [PATCH v16 27/45] KVM: arm64: CCA: Allow populating initial contents Steven Price
2026-08-06 22:43 ` Ackerley Tng
2026-08-07 10:58 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 28/45] KVM: arm64: CCA: Set RIPAS of initial memslots Steven Price
2026-08-03 13:43 ` [PATCH v16 29/45] KVM: arm64: CCA: Support runtime faulting of memory Steven Price
2026-08-06 23:11 ` Ackerley Tng
2026-08-11 15:42 ` Catalin Marinas
2026-08-12 9:01 ` Suzuki K Poulose
2026-08-12 14:06 ` Catalin Marinas
2026-08-12 15:40 ` Suzuki K Poulose
2026-08-03 13:43 ` [PATCH v16 30/45] KVM: arm64: CCA: Handle realm vCPU load Steven Price
2026-08-10 14:46 ` Kohei Enju
2026-08-03 13:43 ` [PATCH v16 31/45] KVM: arm64: CCA: Validate register access for Realm VMs Steven Price
2026-08-03 13:43 ` [PATCH v16 32/45] KVM: arm64: CCA: Handle Realm PSCI requests Steven Price
2026-08-03 13:43 ` [PATCH v16 33/45] KVM: arm64: WARN on injected undef exceptions Steven Price
2026-08-03 13:43 ` [PATCH v16 34/45] KVM: arm64: CCA: Allow userspace to inject aborts Steven Price
2026-08-03 13:43 ` [PATCH v16 35/45] KVM: arm64: CCA: Support RSI_HOST_CALL Steven Price
2026-08-03 13:43 ` [PATCH v16 36/45] KVM: arm64: CCA: Allow checking SVE on VM instance Steven Price
2026-08-03 13:43 ` [PATCH v16 37/45] KVM: arm64: CCA: Prevent Device mappings for realms Steven Price
2026-08-03 13:43 ` [PATCH v16 38/45] KVM: arm64: CCA: Propagate breakpoint and watchpoint counts to userspace Steven Price
2026-08-03 13:43 ` [PATCH v16 39/45] KVM: arm64: CCA: Set breakpoint parameters through SET_ONE_REG Steven Price
2026-08-03 13:43 ` [PATCH v16 40/45] KVM: arm64: CCA: Propagate max SVE vector length from the RMM Steven Price
2026-08-03 13:43 ` [PATCH v16 41/45] KVM: arm64: CCA: Configure max SVE vector length for a Realm Steven Price
2026-08-03 13:43 ` [PATCH v16 42/45] KVM: arm64: CCA: Provide register list for unfinalized RECs Steven Price
2026-08-03 13:43 ` [PATCH v16 43/45] KVM: arm64: CCA: Provide an accurate register list Steven Price
2026-08-03 13:44 ` [PATCH v16 44/45] KVM: arm64: CCA: Require ICH_HCR_EL2.TDIR for realms Steven Price
2026-08-10 4:58 ` Kohei Enju
2026-08-10 9:41 ` Marc Zyngier
2026-08-27 12:09 ` Kohei Enju
2026-08-24 14:50 ` Steven Price
2026-08-27 12:45 ` Kohei Enju [this message]
2026-08-03 13:44 ` [PATCH v16 45/45] KVM: arm64: CCA: Enable realms to be created Steven Price
2026-08-03 15:01 ` [PATCH v16 00/45] arm64: Support for Arm CCA in KVM Marc Zyngier
2026-08-03 15:06 ` Steven Price
2026-08-03 15:20 ` Marc Zyngier
2026-08-03 15:45 ` Steven Price
2026-08-04 14:24 ` Fuad Tabba
2026-08-06 22:05 ` Suzuki K Poulose
2026-08-11 4:44 ` Gavin Shan
2026-08-11 11:12 ` Suzuki K Poulose
2026-08-12 3:07 ` Gavin Shan
2026-08-12 3:25 ` Alper Gun
2026-08-12 6:04 ` Suzuki K Poulose
2026-08-12 10:35 ` Gavin Shan
2026-08-12 12:18 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apAwQeTW-JvCISEt@FCCLS0092175.localdomain \
--to=enju.kohei@fujitsu.com \
--cc=WeiLin.Chang@arm.com \
--cc=alexandru.elisei@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=christoffer.dall@arm.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=james.morse@arm.com \
--cc=joey.gouly@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vannapurve@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox