Linux Confidential Computing Development
 help / color / mirror / Atom feed
From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com,
	linux-kernel@vger.kernel.org,
	linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
	aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com,
	joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com,
	linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
	sdonthineni@nvidia.com, alpergun@google.com,
	fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
	lpieralisi@kernel.org, enju.kohei@fujitsu.com,
	Jean-Philippe Brucker <jean-philippe@linaro.org>,
	Suzuki K Poulose <suzuki.poulose@arm.com>
Subject: [PATCH v18 22/23] KVM: arm64: CCA: Expose SVE VL register before VCPU finalization
Date: Tue, 15 Sep 2026 17:01:40 +0100	[thread overview]
Message-ID: <20260915160141.3543048-23-suzuki.poulose@arm.com> (raw)
In-Reply-To: <20260915160141.3543048-1-suzuki.poulose@arm.com>

From: Jean-Philippe Brucker <jean-philippe@linaro.org>

Userspace must configure the SVE vector length before the Realm is created
(as it is part of the parameter for Realm creation), but the Realm VCPUs
cannot be finalized until after the Realm Descriptor has been created.

KVM_GET_REG_LIST currently rejects the unfinalized VCPUs, which prevents
the userspace from discovering and configuring the VLs for  the Realm.

Allow KVM_GET_REG_LIST for unfinalized RECs and make the SVE register
enumeration handle the unfinalized case explicitly. i.e., only expose
KVM_REG_ARM64_SVE_VLS before SVE is finalized.

One adverse side effect of this change is that a KVM_GET_REG_LIST call that
only probes for the array size will now succeed even if SVE is not finalized,
but that seems harmless since the following KVM_GET_REG_LIST with the full
array will fail.

Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Signed-off-by: Steven Price <steven.price@arm.com>
Reviewed-by: Gavin Shan <gshan@redhat.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
---
Changes since v17:
 - Rewrite the commit description to clearly describe the purpose
---
 arch/arm64/kvm/arm.c   | 15 ++++++++++++++-
 arch/arm64/kvm/guest.c | 10 +++++-----
 2 files changed, 19 insertions(+), 6 deletions(-)

diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index df0aa66b6f5ed..3d8ede8460e96 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c
@@ -2017,6 +2017,19 @@ static int kvm_arm_vcpu_set_events(struct kvm_vcpu *vcpu,
 	return __kvm_arm_vcpu_set_events(vcpu, events);
 }
 
+/*
+ * Realm VCPUs can be finalized only after the Realm descriptor is created.
+ * But in order to seal the SVE VL, we need to allow the userspace to read/write
+ * to the SVE_VL, before everything is finalized.
+ * Allow the register list for RECs before the VCPUs are finalized.
+ */
+static bool kvm_arm_vcpu_reg_list_allowed(struct kvm_vcpu *vcpu)
+{
+	if (kvm_arm_vcpu_is_finalized(vcpu))
+		return true;
+	return vcpu_is_rec(vcpu);
+}
+
 long kvm_arch_vcpu_ioctl(struct file *filp,
 			 unsigned int ioctl, unsigned long arg)
 {
@@ -2072,7 +2085,7 @@ long kvm_arch_vcpu_ioctl(struct file *filp,
 			break;
 
 		r = -EPERM;
-		if (!kvm_arm_vcpu_is_finalized(vcpu))
+		if (!kvm_arm_vcpu_reg_list_allowed(vcpu))
 			break;
 
 		r = -EFAULT;
diff --git a/arch/arm64/kvm/guest.c b/arch/arm64/kvm/guest.c
index b01d6622b8720..c3ca369882273 100644
--- a/arch/arm64/kvm/guest.c
+++ b/arch/arm64/kvm/guest.c
@@ -598,8 +598,8 @@ static unsigned long num_sve_regs(const struct kvm_vcpu *vcpu)
 	if (!vcpu_has_sve(vcpu))
 		return 0;
 
-	/* Policed by KVM_GET_REG_LIST: */
-	WARN_ON(!kvm_arm_vcpu_sve_finalized(vcpu));
+	if (!kvm_arm_vcpu_sve_finalized(vcpu))
+		return 1; /* KVM_REG_ARM64_SVE_VLS */
 
 	return slices * (SVE_NUM_PREGS + SVE_NUM_ZREGS + 1 /* FFR */)
 		+ 1; /* KVM_REG_ARM64_SVE_VLS */
@@ -616,9 +616,6 @@ static int copy_sve_reg_indices(const struct kvm_vcpu *vcpu,
 	if (!vcpu_has_sve(vcpu))
 		return 0;
 
-	/* Policed by KVM_GET_REG_LIST: */
-	WARN_ON(!kvm_arm_vcpu_sve_finalized(vcpu));
-
 	/*
 	 * Enumerate this first, so that userspace can save/restore in
 	 * the order reported by KVM_GET_REG_LIST:
@@ -628,6 +625,9 @@ static int copy_sve_reg_indices(const struct kvm_vcpu *vcpu,
 		return -EFAULT;
 	++num_regs;
 
+	if (!kvm_arm_vcpu_sve_finalized(vcpu))
+		return num_regs;
+
 	for (i = 0; i < slices; i++) {
 		for (n = 0; n < SVE_NUM_ZREGS; n++) {
 			reg = KVM_REG_ARM64_SVE_ZREG(n, i);
-- 
2.43.0


  parent reply	other threads:[~2026-09-15 16:03 UTC|newest]

Thread overview: 48+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 16:01 [PATCH v18 00/23] KVM: arm64: CCA: Add basic plumbing for Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 01/23] KVM: arm64: protected VM: Handle set_one_reg CNTVCT_EL0/CNTPCT_EL0 Suzuki K Poulose
2026-09-15 16:46   ` Marc Zyngier
2026-09-15 17:48     ` Suzuki K Poulose
2026-09-15 21:20       ` Suzuki K Poulose
2026-09-16  8:16         ` Marc Zyngier
2026-09-16  8:27           ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 02/23] KVM: arm64: Disable Steal time accounting for protected guests Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 03/23] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 04/23] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 05/23] KVM: arm64: Track the type of VM in kvm_arch Suzuki K Poulose
2026-09-17 11:24   ` Fuad Tabba
2026-09-18  8:59     ` Suzuki K Poulose
2026-09-18  9:14       ` Fuad Tabba
2026-09-18  9:47         ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 06/23] KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 07/23] KVM: arm64: Add vcpu load/put call backs for flavors Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 08/23] KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 09/23] KVM: arm64: Add VM specific callback for S2 MMU operations Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 10/23] KVM: arm64: Abstract out memory abort handling Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 11/23] KVM: arm64: Use kvm_vm_is_unprotected() for !kvm_vm_is_protected() Suzuki K Poulose
2026-09-17 11:47   ` Fuad Tabba
2026-09-17 16:47     ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 12/23] KVM: arm64: Widen the scope of "protected" VMs Suzuki K Poulose
2026-09-17 11:44   ` Marc Zyngier
2026-09-17 17:06     ` Suzuki K Poulose
2026-09-17 11:51   ` Fuad Tabba
2026-09-17 16:48     ` Suzuki K Poulose
2026-09-17 14:16   ` Joey Gouly
2026-09-15 16:01 ` [PATCH v18 13/23] KVM: arm64: Add a helper for VMs running on hyp that don't trust the host Suzuki K Poulose
2026-09-17 11:55   ` Fuad Tabba
2026-09-15 16:01 ` [PATCH v18 14/23] KVM: arm64: CCA: Add a new mode for supporting Realm guests Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 15/23] KVM: arm64: CCA: Add VCPU load/put for Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 16/23] KVM: arm64: CCA: Add bare minimal S2 operations for Realm Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 17/23] KVM: arm64: CCA: Introduce Realms Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 18/23] KVM: arm64: CCA: Mandate VGIC_V3 for Realms Suzuki K Poulose
2026-09-17 12:57   ` Fuad Tabba
2026-09-15 16:01 ` [PATCH v18 19/23] KVM: arm64: CCA: Support timers in realm RECs Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 20/23] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Suzuki K Poulose
2026-09-17 13:16   ` Fuad Tabba
2026-09-17 14:56     ` Suzuki K Poulose
2026-09-15 16:01 ` [PATCH v18 21/23] KVM: arm64: CCA: WARN on injected undef exceptions Suzuki K Poulose
2026-09-15 16:01 ` Suzuki K Poulose [this message]
2026-09-15 16:01 ` [PATCH v18 23/23] KVM: arm64: CCA: Control user register access for Realms Suzuki K Poulose
2026-09-16 19:23 ` [PATCH v18 00/23] KVM: arm64: CCA: Add basic plumbing " Mathieu Poirier
2026-09-22  9:22   ` Aneesh Kumar K.V
2026-09-23 14:32     ` Mathieu Poirier
2026-09-17 14:32 ` Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260915160141.3543048-23-suzuki.poulose@arm.com \
    --to=suzuki.poulose@arm.com \
    --cc=WeiLin.Chang@arm.com \
    --cc=alpergun@google.com \
    --cc=aneesh.kumar@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=enju.kohei@fujitsu.com \
    --cc=fj0570is@fujitsu.com \
    --cc=gankulkarni@os.amperecomputing.com \
    --cc=gshan@redhat.com \
    --cc=jean-philippe@linaro.org \
    --cc=joey.gouly@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lpieralisi@kernel.org \
    --cc=maz@kernel.org \
    --cc=oupton@kernel.org \
    --cc=sdonthineni@nvidia.com \
    --cc=steven.price@arm.com \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox