Linux Confidential Computing Development
 help / color / mirror / Atom feed
From: Marc Zyngier <maz@kernel.org>
To: Steven Price <steven.price@arm.com>
Cc: kvm@vger.kernel.org, kvmarm@lists.linux.dev,
	Catalin Marinas <catalin.marinas@arm.com>,
	Will Deacon <will@kernel.org>, James Morse <james.morse@arm.com>,
	Oliver Upton <oliver.upton@linux.dev>,
	Suzuki K Poulose <suzuki.poulose@arm.com>,
	Zenghui Yu <yuzenghui@huawei.com>,
	linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
	Alexandru Elisei <alexandru.elisei@arm.com>,
	Christoffer Dall <christoffer.dall@arm.com>,
	Fuad Tabba <tabba@google.com>,
	linux-coco@lists.linux.dev,
	Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>,
	Gavin Shan <gshan@redhat.com>,
	Shanker Donthineni <sdonthineni@nvidia.com>,
	Alper Gun <alpergun@google.com>,
	"Aneesh Kumar K . V" <aneesh.kumar@kernel.org>,
	Emi Kisanuki <fj0570is@fujitsu.com>,
	Vishal Annapurve <vannapurve@google.com>,
	WeiLin.Chang@arm.com, Lorenzo Pieralisi <lpieralisi@kernel.org>
Subject: Re: [PATCH v15 16/37] KVM: arm64: CCA: Handle realm MMIO emulation
Date: Mon, 03 Aug 2026 12:27:35 +0100	[thread overview]
Message-ID: <864ihbcul4.wl-maz@kernel.org> (raw)
In-Reply-To: <20260715142841.80544-17-steven.price@arm.com>

On Wed, 15 Jul 2026 15:28:18 +0100,
Steven Price <steven.price@arm.com> wrote:
> 
> MMIO emulation for a realm cannot be done directly with the VM's
> registers as they are protected from the host. However, for emulatable
> data aborts, the RMM uses GPRS[0] to provide the read/written value.
> We can transfer this from/to the equivalent VCPU's register entry and
> then depend on the generic MMIO handling code in KVM.
> 
> For a MMIO read, the value is placed in the shared RecExit structure
> during kvm_handle_mmio_return() rather than in the VCPU's register
> entry.
> 
> Signed-off-by: Steven Price <steven.price@arm.com>
> Reviewed-by: Gavin Shan <gshan@redhat.com>
> Reviewed-by: Suzuki K Poulose <suzuki.poulose@arm.com>
> ---
> Changes since v7:
>  * New comment for rec_exit_sync_dabt() explaining the call to
>    vcpu_set_reg().
> Changes since v5:
>  * Inject SEA to the guest is an emulatable MMIO access triggers a data
>    abort.
>  * kvm_handle_mmio_return() - disable kvm_incr_pc() for a REC (as the PC
>    isn't under the host's control) and move the REC_ENTER_EMULATED_MMIO
>    flag setting to this location (as that tells the RMM to skip the
>    instruction).
> ---
>  arch/arm64/kvm/inject_fault.c |  4 +++-
>  arch/arm64/kvm/mmio.c         | 16 ++++++++++++----
>  arch/arm64/kvm/rmi-exit.c     | 15 +++++++++++++++
>  3 files changed, 30 insertions(+), 5 deletions(-)
> 
> diff --git a/arch/arm64/kvm/inject_fault.c b/arch/arm64/kvm/inject_fault.c
> index 89982bd3345f..6492397b73d7 100644
> --- a/arch/arm64/kvm/inject_fault.c
> +++ b/arch/arm64/kvm/inject_fault.c
> @@ -228,7 +228,9 @@ static void inject_abt32(struct kvm_vcpu *vcpu, bool is_pabt, u32 addr)
>  
>  static void __kvm_inject_sea(struct kvm_vcpu *vcpu, bool iabt, u64 addr)
>  {
> -	if (vcpu_el1_is_32bit(vcpu))
> +	if (unlikely(vcpu_is_rec(vcpu)))
> +		vcpu->arch.rec.run->enter.flags |= REC_ENTER_FLAG_INJECT_SEA;
> +	else if (vcpu_el1_is_32bit(vcpu))
>  		inject_abt32(vcpu, iabt, addr);
>  	else
>  		inject_abt64(vcpu, iabt, addr);

Why don't you let inject_dabt64() do its job and reconcile the REC
stuff at run time?

> diff --git a/arch/arm64/kvm/mmio.c b/arch/arm64/kvm/mmio.c
> index e2285ed8c91d..a8c125205695 100644
> --- a/arch/arm64/kvm/mmio.c
> +++ b/arch/arm64/kvm/mmio.c
> @@ -6,6 +6,7 @@
>  
>  #include <linux/kvm_host.h>
>  #include <asm/kvm_emulate.h>
> +#include <linux/arm-smccc-rmi.h>
>  #include <trace/events/kvm.h>
>  
>  #include "trace.h"
> @@ -138,14 +139,21 @@ int kvm_handle_mmio_return(struct kvm_vcpu *vcpu)
>  		trace_kvm_mmio(KVM_TRACE_MMIO_READ, len, run->mmio.phys_addr,
>  			       &data);
>  		data = vcpu_data_host_to_guest(vcpu, data, len);
> -		vcpu_set_reg(vcpu, kvm_vcpu_dabt_get_rd(vcpu), data);
> +
> +		if (vcpu_is_rec(vcpu))
> +			vcpu->arch.rec.run->enter.gprs[0] = data;
> +		else
> +			vcpu_set_reg(vcpu, kvm_vcpu_dabt_get_rd(vcpu), data);

This is yet another example of things I do not want to see. KVM works
on the GPRs described in the vcpu structure. And that's it.

So let the ESR information be correct for CCA, the data being written
back to x0, and once you're ready to enter the guest again, copy
whatever you need into the CCA data structure.

But not any of this stuff.

>  	}
>  
>  	/*
>  	 * The MMIO instruction is emulated and should not be re-executed
>  	 * in the guest.
>  	 */
> -	kvm_incr_pc(vcpu);
> +	if (vcpu_is_rec(vcpu))
> +		vcpu->arch.rec.run->enter.flags |= REC_ENTER_FLAG_EMULATED_MMIO;
> +	else
> +		kvm_incr_pc(vcpu);

Same thing. kvm_incr_pc() sets a flag. Use that to reconcile the state
with CCA.

	M.

-- 
Without deviation from the norm, progress is not possible.

  reply	other threads:[~2026-08-03 11:27 UTC|newest]

Thread overview: 89+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-15 14:28 [PATCH v15 00/37] arm64: Support for Arm CCA in KVM Steven Price
2026-07-15 14:28 ` [PATCH v15 01/37] KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2026-07-15 14:28 ` [PATCH v15 02/37] KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h Steven Price
2026-07-15 15:59   ` Marc Zyngier
2026-07-15 16:22     ` Steven Price
2026-07-15 14:28 ` [PATCH v15 03/37] arm64: mm: Handle Granule Protection Faults (GPFs) Steven Price
2026-07-15 14:28 ` [PATCH v15 04/37] KVM: arm64: CCA: Check for RMI support at KVM init Steven Price
2026-07-15 14:28 ` [PATCH v15 05/37] KVM: arm64: CCA: Check for LPA2 support Steven Price
2026-07-16  9:23   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 06/37] KVM: arm64: CCA: Define the user ABI Steven Price
2026-07-16  9:40   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 07/37] KVM: arm64: CCA: Add basic infrastructure for creating a realm Steven Price
2026-07-15 14:28 ` [PATCH v15 08/37] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests Steven Price
2026-07-15 14:28 ` [PATCH v15 09/37] KVM: arm64: CCA: Allow passing the machine type in KVM creation Steven Price
2026-07-15 16:14   ` Marc Zyngier
2026-07-16  9:17     ` Steven Price
2026-07-16  9:37       ` Marc Zyngier
2026-07-15 14:28 ` [PATCH v15 10/37] KVM: arm64: CCA: Tear down RTTs Steven Price
2026-07-15 14:28 ` [PATCH v15 11/37] KVM: arm64: CCA: Allocate and free RECs to match vCPUs Steven Price
2026-07-15 14:28 ` [PATCH v15 12/37] KVM: arm64: CCA: Support the VGIC in realms Steven Price
2026-07-22  8:27   ` Kohei Enju
2026-07-22  9:27     ` Marc Zyngier
2026-07-23  6:38       ` Kohei Enju
2026-07-23  8:07         ` Marc Zyngier
2026-07-23  9:02           ` Kohei Enju
2026-07-22 13:31     ` Steven Price
2026-07-23  6:56       ` Kohei Enju
2026-07-23 14:46         ` Steven Price
2026-07-24  5:40           ` Kohei Enju
2026-07-15 14:28 ` [PATCH v15 13/37] KVM: arm64: CCA: Support timers in realm RECs Steven Price
2026-07-27  9:21   ` Marc Zyngier
2026-07-29 10:47     ` Steven Price
2026-07-29 10:58       ` Marc Zyngier
2026-07-30  8:47         ` Steven Price
2026-07-15 14:28 ` [PATCH v15 14/37] KVM: arm64: CCA: Handle realm enter/exit Steven Price
2026-07-27  8:14   ` Kohei Enju
2026-07-30 13:58     ` Steven Price
2026-07-30 14:57       ` Suzuki K Poulose
2026-07-31  0:57         ` Kohei Enju
2026-07-27 15:01   ` Marc Zyngier
2026-07-30 16:17     ` Steven Price
2026-07-15 14:28 ` [PATCH v15 15/37] KVM: arm64: CCA: Handle RMI_EXIT_RIPAS_CHANGE Steven Price
2026-08-03 11:09   ` Marc Zyngier
2026-08-03 14:04     ` Steven Price
2026-08-03 14:48       ` Marc Zyngier
2026-08-03 15:30         ` Suzuki K Poulose
2026-08-04 12:20           ` Fuad Tabba
2026-08-04 13:19             ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 16/37] KVM: arm64: CCA: Handle realm MMIO emulation Steven Price
2026-08-03 11:27   ` Marc Zyngier [this message]
2026-08-03 14:57     ` Steven Price
2026-07-15 14:28 ` [PATCH v15 17/37] KVM: arm64: Expose support for private memory Steven Price
2026-07-16 10:25   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 18/37] KVM: arm64: CCA: Create the realm descriptor Steven Price
2026-07-15 14:28 ` [PATCH v15 19/37] KVM: arm64: CCA: Activate realms on first vCPU run Steven Price
2026-08-03 12:29   ` Marc Zyngier
2026-08-03 15:18     ` Steven Price
2026-07-15 14:28 ` [PATCH v15 20/37] KVM: arm64: CCA: Allow populating initial contents Steven Price
2026-08-03 12:43   ` Marc Zyngier
2026-08-03 15:30     ` Steven Price
2026-07-15 14:28 ` [PATCH v15 21/37] KVM: arm64: CCA: Set RIPAS of initial memslots Steven Price
2026-07-15 14:28 ` [PATCH v15 22/37] KVM: arm64: CCA: Support runtime faulting of memory Steven Price
2026-07-15 14:28 ` [PATCH v15 23/37] KVM: arm64: CCA: Handle realm vCPU load Steven Price
2026-07-15 14:28 ` [PATCH v15 24/37] KVM: arm64: CCA: Validate register access for Realm VMs Steven Price
2026-07-15 14:28 ` [PATCH v15 25/37] KVM: arm64: CCA: Handle Realm PSCI requests Steven Price
2026-07-16 10:38   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 26/37] KVM: arm64: WARN on injected undef exceptions Steven Price
2026-07-15 15:46   ` Marc Zyngier
2026-07-15 16:15     ` Steven Price
2026-07-15 16:25       ` Marc Zyngier
2026-07-15 16:31         ` Steven Price
2026-07-15 16:43           ` Marc Zyngier
2026-07-16  9:17             ` Steven Price
2026-07-15 14:28 ` [PATCH v15 27/37] KVM: arm64: CCA: Allow userspace to inject aborts Steven Price
2026-07-16 10:19   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 28/37] KVM: arm64: CCA: Support RSI_HOST_CALL Steven Price
2026-07-16 10:22   ` Suzuki K Poulose
2026-07-15 14:28 ` [PATCH v15 29/37] KVM: arm64: CCA: Allow checking SVE on VM instance Steven Price
2026-07-15 14:28 ` [PATCH v15 30/37] KVM: arm64: CCA: Prevent Device mappings for realms Steven Price
2026-07-15 14:28 ` [PATCH v15 31/37] KVM: arm64: CCA: Propagate breakpoint and watchpoint counts to userspace Steven Price
2026-07-15 14:28 ` [PATCH v15 32/37] KVM: arm64: CCA: Set breakpoint parameters through SET_ONE_REG Steven Price
2026-07-15 14:28 ` [PATCH v15 33/37] KVM: arm64: CCA: Propagate max SVE vector length from the RMM Steven Price
2026-07-15 14:28 ` [PATCH v15 34/37] KVM: arm64: CCA: Configure max SVE vector length for a Realm Steven Price
2026-07-15 14:28 ` [PATCH v15 35/37] KVM: arm64: CCA: Provide register list for unfinalized RECs Steven Price
2026-07-15 14:28 ` [PATCH v15 36/37] KVM: arm64: CCA: Provide an accurate register list Steven Price
2026-07-15 14:28 ` [PATCH v15 37/37] KVM: arm64: CCA: Enable realms to be created Steven Price
2026-07-16  8:36 ` [PATCH v15 00/37] arm64: Support for Arm CCA in KVM Marc Zyngier
2026-07-16  9:20   ` Steven Price
2026-07-16  9:42     ` Marc Zyngier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=864ihbcul4.wl-maz@kernel.org \
    --to=maz@kernel.org \
    --cc=WeiLin.Chang@arm.com \
    --cc=alexandru.elisei@arm.com \
    --cc=alpergun@google.com \
    --cc=aneesh.kumar@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=christoffer.dall@arm.com \
    --cc=fj0570is@fujitsu.com \
    --cc=gankulkarni@os.amperecomputing.com \
    --cc=gshan@redhat.com \
    --cc=james.morse@arm.com \
    --cc=joey.gouly@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lpieralisi@kernel.org \
    --cc=oliver.upton@linux.dev \
    --cc=sdonthineni@nvidia.com \
    --cc=steven.price@arm.com \
    --cc=suzuki.poulose@arm.com \
    --cc=tabba@google.com \
    --cc=vannapurve@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox