From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com,
linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com,
joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com,
linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
sdonthineni@nvidia.com, alpergun@google.com,
fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
lpieralisi@kernel.org, enju.kohei@fujitsu.com,
sudeep.holla@arm.com, jonathan.cameron@oss.qualcomm.com,
Suzuki K Poulose <suzuki.poulose@arm.com>
Subject: [PATCH v22 08/10] arm64: Block hibernate and kexec while RMM is active
Date: Fri, 2 Oct 2026 07:15:04 +0100 [thread overview]
Message-ID: <20261002061507.1600269-9-suzuki.poulose@arm.com> (raw)
In-Reply-To: <20261002061507.1600269-1-suzuki.poulose@arm.com>
RMM can be deactivated only after all delegated granules have been
reclaimed. If a new kernel is entered while any granules remain in the
Realm PAS, accesses to that memory can raise a Granule Protection Fault
and be fatal to the new kernel.
Crash kexec/kdump needs separate handling. It can be supported only once
the crash kernel can tolerate delegated memory inherited from the primary
kernel. i.e., be able to read the pages safely and fixup the GPF. Until
then disable the kexec completely.
Hibernate has a similar problem. The image cannot be safely saved for
delegated pages, as the RMM doesn't support exporting the pages.
Also, on the resume path, if the RMM is active, there could be delegated
granules and overwriting them is fatal.
Disable both kexec and hiberation while the RMM is active.
Reviewed-by: Catalin Marinas <catalin.marinas@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
---
Changes since v21:
- Drop cpus_are_stuck_in_kernel() from arch_hibernation_available()
- Split arch_hibernation_available() hook as a separate patch
Changes since v20:
- Add arch_hibernation_available() hook for archs to have a say and drop the
other checks.
Changes since v19:
- New patch to disable kexec and hibernation with RMM
---
arch/arm64/kernel/hibernate.c | 14 ++++++++++++++
arch/arm64/kernel/machine_kexec.c | 11 +++++++++++
2 files changed, 25 insertions(+)
diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 7bf1174277772..327e62a259aa7 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -10,6 +10,8 @@
* Copyright (C) 2006 Rafael J. Wysocki <rjw@sisk.pl>
*/
#define pr_fmt(x) "hibernate: " x
+
+#include <linux/arm-rmi-cmds.h>
#include <linux/cpu.h>
#include <linux/kvm_host.h>
#include <linux/pm.h>
@@ -105,6 +107,18 @@ void notrace restore_processor_state(void)
{
}
+bool arch_hibernation_available(void)
+{
+ /*
+ * If we have activated the RMM, there could be pages that are
+ * delegated to the RMM. Trying to save them to the image will be fatal.
+ * Also, we donate pages to the RMM at activation and restoring data
+ * to those pages are going to be fatal.
+ * Hence, disable the hibernation when the RMM is active
+ */
+ return !is_rmm_active();
+}
+
int arch_hibernation_header_save(void *addr, unsigned int max_size)
{
struct arch_hibernate_hdr *hdr = addr;
diff --git a/arch/arm64/kernel/machine_kexec.c b/arch/arm64/kernel/machine_kexec.c
index 8f9bc2327dc85..48f343704cb54 100644
--- a/arch/arm64/kernel/machine_kexec.c
+++ b/arch/arm64/kernel/machine_kexec.c
@@ -6,6 +6,7 @@
* Copyright (C) Huawei Futurewei Technologies.
*/
+#include <linux/arm-rmi-cmds.h>
#include <linux/interrupt.h>
#include <linux/irq.h>
#include <linux/kernel.h>
@@ -59,6 +60,16 @@ int machine_kexec_prepare(struct kimage *kimage)
return -EBUSY;
}
+ /*
+ * We will be able to allow kdump to proceed, once we have the support
+ * for handling GPF from vmcore accesses to delegated pages. Until then
+ * block kexec completely.
+ */
+ if (is_rmm_active()) {
+ pr_err("Can't kexec: RMM is active.\n");
+ return -EBUSY;
+ }
+
return 0;
}
--
2.43.0
next prev parent reply other threads:[~2026-10-02 6:16 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 6:14 [PATCH v22 00/10] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-10-02 6:14 ` [PATCH v22 01/10] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-10-02 6:14 ` [PATCH v22 02/10] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-10-02 6:14 ` [PATCH v22 03/10] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-10-02 6:15 ` [PATCH v22 04/10] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-10-02 6:15 ` [PATCH v22 05/10] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-10-02 6:15 ` [PATCH v22 06/10] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-10-02 6:15 ` [PATCH v22 07/10] kernel: hibernate: Add an arch hook for preventing hiberation Suzuki K Poulose
2026-10-02 11:03 ` Catalin Marinas
2026-10-02 15:29 ` Suzuki K Poulose
2026-10-02 13:32 ` Sudeep Holla
2026-10-02 6:15 ` Suzuki K Poulose [this message]
2026-10-02 6:15 ` [PATCH v22 09/10] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-10-02 11:05 ` Catalin Marinas
2026-10-02 15:28 ` Suzuki K Poulose
2026-10-02 6:15 ` [PATCH v22 10/10] firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE Suzuki K Poulose
2026-10-02 7:57 ` David Hildenbrand (Arm)
2026-10-02 18:49 ` [PATCH v22 00/10] firmware: arm_rmm: Add RMM v2.0 base RMI support Catalin Marinas
2026-10-03 5:57 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002061507.1600269-9-suzuki.poulose@arm.com \
--to=suzuki.poulose@arm.com \
--cc=WeiLin.Chang@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=enju.kohei@fujitsu.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=joey.gouly@arm.com \
--cc=jonathan.cameron@oss.qualcomm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sdonthineni@nvidia.com \
--cc=steven.price@arm.com \
--cc=sudeep.holla@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox