* [PATCH v21 7/9] arm64: Block hibernate and kexec while RMM is active [not found] <20261001084555.1456543-1-suzuki.poulose@arm.com> @ 2026-10-01 8:45 ` Suzuki K Poulose 2026-10-01 11:05 ` Catalin Marinas 0 siblings, 1 reply; 3+ messages in thread From: Suzuki K Poulose @ 2026-10-01 8:45 UTC (permalink / raw) To: kvm, kvmarm Cc: maz, will, catalin.marinas, linux-kernel, linux-arm-kernel, steven.price, aneesh.kumar, oupton, gshan, joey.gouly, tabba, yuzenghui, linux-coco, gankulkarni, sdonthineni, alpergun, fj0570is, WeiLin.Chang, lpieralisi, enju.kohei, sudeep.holla, jonathan.cameron, Suzuki K Poulose, Rafael J. Wysocki, Len Brown, Pavel Machek, linux-pm RMM can be deactivated only after all delegated granules have been reclaimed. If a new kernel is entered while any granules remain in the Realm PAS, accesses to that memory can raise a Granule Protection Fault and be fatal to the new kernel. Crash kexec/kdump needs separate handling. It can be supported only once the crash kernel can tolerate delegated memory inherited from the primary kernel. i.e., be able to read the pages safely and fixup the GPF. Until then disable the kexec completely. Hibernate has a similar problem. The image cannot be safely saved for delegated pages, as the RMM doesn't support exporting the pages. Disable both kexec and hiberation while the RMM is active. Cc: "Rafael J. Wysocki" <rafael@kernel.org> Cc: Len Brown <lenb@kernel.org> Cc: Pavel Machek <pavel@kernel.org> Cc: linux-pm@vger.kernel.org Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com> --- Changes since v20: - Add arch_hibernation_available() hook for archs to have a say and drop the other checks. Changes since v19: - New patch to disable kexec and hibernation with RMM --- arch/arm64/kernel/hibernate.c | 14 ++++++++++++++ arch/arm64/kernel/machine_kexec.c | 11 +++++++++++ include/linux/suspend.h | 1 + kernel/power/hibernate.c | 8 +++++++- 4 files changed, 33 insertions(+), 1 deletion(-) diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c index 7bf1174277772..08e03d24b93a8 100644 --- a/arch/arm64/kernel/hibernate.c +++ b/arch/arm64/kernel/hibernate.c @@ -10,6 +10,8 @@ * Copyright (C) 2006 Rafael J. Wysocki <rjw@sisk.pl> */ #define pr_fmt(x) "hibernate: " x + +#include <linux/arm-rmi-cmds.h> #include <linux/cpu.h> #include <linux/kvm_host.h> #include <linux/pm.h> @@ -105,6 +107,18 @@ void notrace restore_processor_state(void) { } +bool arch_hibernation_available(void) +{ + /* + * If we have activated the RMM, there could be pages that are + * delegated to the RMM. Trying to save them to the image will be fatal. + * Also, we donate pages to the RMM at activation and restoring data + * to those pages are going to be fatal. + * Hence, disable the hibernation when the RMM is active + */ + return !cpus_are_stuck_in_kernel() && !is_rmm_active(); +} + int arch_hibernation_header_save(void *addr, unsigned int max_size) { struct arch_hibernate_hdr *hdr = addr; diff --git a/arch/arm64/kernel/machine_kexec.c b/arch/arm64/kernel/machine_kexec.c index 8f9bc2327dc85..48f343704cb54 100644 --- a/arch/arm64/kernel/machine_kexec.c +++ b/arch/arm64/kernel/machine_kexec.c @@ -6,6 +6,7 @@ * Copyright (C) Huawei Futurewei Technologies. */ +#include <linux/arm-rmi-cmds.h> #include <linux/interrupt.h> #include <linux/irq.h> #include <linux/kernel.h> @@ -59,6 +60,16 @@ int machine_kexec_prepare(struct kimage *kimage) return -EBUSY; } + /* + * We will be able to allow kdump to proceed, once we have the support + * for handling GPF from vmcore accesses to delegated pages. Until then + * block kexec completely. + */ + if (is_rmm_active()) { + pr_err("Can't kexec: RMM is active.\n"); + return -EBUSY; + } + return 0; } diff --git a/include/linux/suspend.h b/include/linux/suspend.h index b02876f1ae38a..a3815027773c5 100644 --- a/include/linux/suspend.h +++ b/include/linux/suspend.h @@ -401,6 +401,7 @@ int hibernate_quiet_exec(int (*func)(void *data), void *data); int hibernate_resume_nonboot_cpu_disable(void); int arch_hibernation_header_save(void *addr, unsigned int max_size); int arch_hibernation_header_restore(void *addr); +bool arch_hibernation_available(void); #else /* CONFIG_HIBERNATION */ static inline void register_nosave_region(unsigned long b, unsigned long e) {} diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c index d2479c69d71a4..9d9d53828542f 100644 --- a/kernel/power/hibernate.c +++ b/kernel/power/hibernate.c @@ -106,11 +106,17 @@ bool hibernation_in_progress(void) return !atomic_read(&hibernate_atomic); } +__weak bool arch_hibernation_available(void) +{ + return true; +} + bool hibernation_available(void) { return nohibernate == 0 && !security_locked_down(LOCKDOWN_HIBERNATION) && - !secretmem_active() && !cxl_mem_active(); + !secretmem_active() && !cxl_mem_active() && + arch_hibernation_available(); } /** -- 2.43.0 ^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH v21 7/9] arm64: Block hibernate and kexec while RMM is active 2026-10-01 8:45 ` [PATCH v21 7/9] arm64: Block hibernate and kexec while RMM is active Suzuki K Poulose @ 2026-10-01 11:05 ` Catalin Marinas 2026-10-01 11:39 ` Suzuki K Poulose 0 siblings, 1 reply; 3+ messages in thread From: Catalin Marinas @ 2026-10-01 11:05 UTC (permalink / raw) To: Suzuki K Poulose Cc: kvm, kvmarm, maz, will, linux-kernel, linux-arm-kernel, steven.price, aneesh.kumar, oupton, gshan, joey.gouly, tabba, yuzenghui, linux-coco, gankulkarni, sdonthineni, alpergun, fj0570is, WeiLin.Chang, lpieralisi, enju.kohei, sudeep.holla, jonathan.cameron, Rafael J. Wysocki, Len Brown, Pavel Machek, linux-pm On Thu, Oct 01, 2026 at 09:45:53AM +0100, Suzuki K Poulose wrote: > RMM can be deactivated only after all delegated granules have been > reclaimed. If a new kernel is entered while any granules remain in the > Realm PAS, accesses to that memory can raise a Granule Protection Fault > and be fatal to the new kernel. > > Crash kexec/kdump needs separate handling. It can be supported only once > the crash kernel can tolerate delegated memory inherited from the primary > kernel. i.e., be able to read the pages safely and fixup the GPF. Until > then disable the kexec completely. > > Hibernate has a similar problem. The image cannot be safely saved for > delegated pages, as the RMM doesn't support exporting the pages. > > Disable both kexec and hiberation while the RMM is active. I would mention that this adds a new arch_hibernation_available() hook called from hibernation_available(), otherwise the hibernation maintainers may not realise why they've been cc'ed. Alternatively, just introduce the hook as a separate patch without any arch code. > Cc: "Rafael J. Wysocki" <rafael@kernel.org> > Cc: Len Brown <lenb@kernel.org> > Cc: Pavel Machek <pavel@kernel.org> > Cc: linux-pm@vger.kernel.org > Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com> > --- > Changes since v20: > - Add arch_hibernation_available() hook for archs to have a say and drop the > other checks. > Changes since v19: > - New patch to disable kexec and hibernation with RMM > --- > arch/arm64/kernel/hibernate.c | 14 ++++++++++++++ > arch/arm64/kernel/machine_kexec.c | 11 +++++++++++ > include/linux/suspend.h | 1 + > kernel/power/hibernate.c | 8 +++++++- > 4 files changed, 33 insertions(+), 1 deletion(-) > > diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c > index 7bf1174277772..08e03d24b93a8 100644 > --- a/arch/arm64/kernel/hibernate.c > +++ b/arch/arm64/kernel/hibernate.c > @@ -10,6 +10,8 @@ > * Copyright (C) 2006 Rafael J. Wysocki <rjw@sisk.pl> > */ > #define pr_fmt(x) "hibernate: " x > + > +#include <linux/arm-rmi-cmds.h> > #include <linux/cpu.h> > #include <linux/kvm_host.h> > #include <linux/pm.h> > @@ -105,6 +107,18 @@ void notrace restore_processor_state(void) > { > } > > +bool arch_hibernation_available(void) > +{ > + /* > + * If we have activated the RMM, there could be pages that are > + * delegated to the RMM. Trying to save them to the image will be fatal. > + * Also, we donate pages to the RMM at activation and restoring data > + * to those pages are going to be fatal. > + * Hence, disable the hibernation when the RMM is active > + */ > + return !cpus_are_stuck_in_kernel() && !is_rmm_active(); > +} For now, I would keep is_rmm_active() only in here as not to change the behaviour for pKVM. "disk" would disappear from /sys/power/state with this patch. I think it's the correct thing to do for pKVM as well but we can discuss this separately once this goes in (I also think pKVM using cpus_are_stuck_in_kernel() is a bit of a bodge but it's a handy hook called in the right places). > + > int arch_hibernation_header_save(void *addr, unsigned int max_size) > { > struct arch_hibernate_hdr *hdr = addr; > diff --git a/arch/arm64/kernel/machine_kexec.c b/arch/arm64/kernel/machine_kexec.c > index 8f9bc2327dc85..48f343704cb54 100644 > --- a/arch/arm64/kernel/machine_kexec.c > +++ b/arch/arm64/kernel/machine_kexec.c > @@ -6,6 +6,7 @@ > * Copyright (C) Huawei Futurewei Technologies. > */ > > +#include <linux/arm-rmi-cmds.h> > #include <linux/interrupt.h> > #include <linux/irq.h> > #include <linux/kernel.h> > @@ -59,6 +60,16 @@ int machine_kexec_prepare(struct kimage *kimage) > return -EBUSY; > } > > + /* > + * We will be able to allow kdump to proceed, once we have the support > + * for handling GPF from vmcore accesses to delegated pages. Until then > + * block kexec completely. > + */ > + if (is_rmm_active()) { > + pr_err("Can't kexec: RMM is active.\n"); > + return -EBUSY; > + } > + > return 0; > } > > diff --git a/include/linux/suspend.h b/include/linux/suspend.h > index b02876f1ae38a..a3815027773c5 100644 > --- a/include/linux/suspend.h > +++ b/include/linux/suspend.h > @@ -401,6 +401,7 @@ int hibernate_quiet_exec(int (*func)(void *data), void *data); > int hibernate_resume_nonboot_cpu_disable(void); > int arch_hibernation_header_save(void *addr, unsigned int max_size); > int arch_hibernation_header_restore(void *addr); > +bool arch_hibernation_available(void); > > #else /* CONFIG_HIBERNATION */ > static inline void register_nosave_region(unsigned long b, unsigned long e) {} > diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c > index d2479c69d71a4..9d9d53828542f 100644 > --- a/kernel/power/hibernate.c > +++ b/kernel/power/hibernate.c > @@ -106,11 +106,17 @@ bool hibernation_in_progress(void) > return !atomic_read(&hibernate_atomic); > } > > +__weak bool arch_hibernation_available(void) > +{ > + return true; > +} > + > bool hibernation_available(void) > { > return nohibernate == 0 && > !security_locked_down(LOCKDOWN_HIBERNATION) && > - !secretmem_active() && !cxl_mem_active(); > + !secretmem_active() && !cxl_mem_active() && > + arch_hibernation_available(); > } With the comments above addressed: Reviewed-by: Catalin Marinas <catalin.marinas@arm.com> ^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH v21 7/9] arm64: Block hibernate and kexec while RMM is active 2026-10-01 11:05 ` Catalin Marinas @ 2026-10-01 11:39 ` Suzuki K Poulose 0 siblings, 0 replies; 3+ messages in thread From: Suzuki K Poulose @ 2026-10-01 11:39 UTC (permalink / raw) To: Catalin Marinas Cc: kvm, kvmarm, maz, will, linux-kernel, linux-arm-kernel, steven.price, aneesh.kumar, oupton, gshan, joey.gouly, tabba, yuzenghui, linux-coco, gankulkarni, sdonthineni, alpergun, fj0570is, WeiLin.Chang, lpieralisi, enju.kohei, sudeep.holla, jonathan.cameron, Rafael J. Wysocki, Len Brown, Pavel Machek, linux-pm On 01/10/2026 12:05, Catalin Marinas wrote: > On Thu, Oct 01, 2026 at 09:45:53AM +0100, Suzuki K Poulose wrote: >> RMM can be deactivated only after all delegated granules have been >> reclaimed. If a new kernel is entered while any granules remain in the >> Realm PAS, accesses to that memory can raise a Granule Protection Fault >> and be fatal to the new kernel. >> >> Crash kexec/kdump needs separate handling. It can be supported only once >> the crash kernel can tolerate delegated memory inherited from the primary >> kernel. i.e., be able to read the pages safely and fixup the GPF. Until >> then disable the kexec completely. >> >> Hibernate has a similar problem. The image cannot be safely saved for >> delegated pages, as the RMM doesn't support exporting the pages. >> >> Disable both kexec and hiberation while the RMM is active. > > I would mention that this adds a new arch_hibernation_available() hook > called from hibernation_available(), otherwise the hibernation > maintainers may not realise why they've been cc'ed. > > Alternatively, just introduce the hook as a separate patch without any > arch code. I will go for this approach, adding the hook in a prep patch and then the arm64 version with kexec changes. > >> Cc: "Rafael J. Wysocki" <rafael@kernel.org> >> Cc: Len Brown <lenb@kernel.org> >> Cc: Pavel Machek <pavel@kernel.org> >> Cc: linux-pm@vger.kernel.org >> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com> >> --- >> Changes since v20: >> - Add arch_hibernation_available() hook for archs to have a say and drop the >> other checks. >> Changes since v19: >> - New patch to disable kexec and hibernation with RMM >> --- >> arch/arm64/kernel/hibernate.c | 14 ++++++++++++++ >> arch/arm64/kernel/machine_kexec.c | 11 +++++++++++ >> include/linux/suspend.h | 1 + >> kernel/power/hibernate.c | 8 +++++++- >> 4 files changed, 33 insertions(+), 1 deletion(-) >> >> diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c >> index 7bf1174277772..08e03d24b93a8 100644 >> --- a/arch/arm64/kernel/hibernate.c >> +++ b/arch/arm64/kernel/hibernate.c >> @@ -10,6 +10,8 @@ >> * Copyright (C) 2006 Rafael J. Wysocki <rjw@sisk.pl> >> */ >> #define pr_fmt(x) "hibernate: " x >> + >> +#include <linux/arm-rmi-cmds.h> >> #include <linux/cpu.h> >> #include <linux/kvm_host.h> >> #include <linux/pm.h> >> @@ -105,6 +107,18 @@ void notrace restore_processor_state(void) >> { >> } >> >> +bool arch_hibernation_available(void) >> +{ >> + /* >> + * If we have activated the RMM, there could be pages that are >> + * delegated to the RMM. Trying to save them to the image will be fatal. >> + * Also, we donate pages to the RMM at activation and restoring data >> + * to those pages are going to be fatal. >> + * Hence, disable the hibernation when the RMM is active >> + */ >> + return !cpus_are_stuck_in_kernel() && !is_rmm_active(); >> +} > > For now, I would keep is_rmm_active() only in here as not to change the > behaviour for pKVM. "disk" would disappear from /sys/power/state with > this patch. I think it's the correct thing to do for pKVM as well but we > can discuss this separately once this goes in (I also think pKVM using > cpus_are_stuck_in_kernel() is a bit of a bodge but it's a handy hook > called in the right places). I was in double mind about this. Yes, I agree, makes sense to deal the pKVM case separately. > >> + >> int arch_hibernation_header_save(void *addr, unsigned int max_size) >> { >> struct arch_hibernate_hdr *hdr = addr; >> diff --git a/arch/arm64/kernel/machine_kexec.c b/arch/arm64/kernel/machine_kexec.c >> index 8f9bc2327dc85..48f343704cb54 100644 >> --- a/arch/arm64/kernel/machine_kexec.c >> +++ b/arch/arm64/kernel/machine_kexec.c >> @@ -6,6 +6,7 @@ >> * Copyright (C) Huawei Futurewei Technologies. >> */ >> >> +#include <linux/arm-rmi-cmds.h> >> #include <linux/interrupt.h> >> #include <linux/irq.h> >> #include <linux/kernel.h> >> @@ -59,6 +60,16 @@ int machine_kexec_prepare(struct kimage *kimage) >> return -EBUSY; >> } >> >> + /* >> + * We will be able to allow kdump to proceed, once we have the support >> + * for handling GPF from vmcore accesses to delegated pages. Until then >> + * block kexec completely. >> + */ >> + if (is_rmm_active()) { >> + pr_err("Can't kexec: RMM is active.\n"); >> + return -EBUSY; >> + } >> + >> return 0; >> } >> >> diff --git a/include/linux/suspend.h b/include/linux/suspend.h >> index b02876f1ae38a..a3815027773c5 100644 >> --- a/include/linux/suspend.h >> +++ b/include/linux/suspend.h >> @@ -401,6 +401,7 @@ int hibernate_quiet_exec(int (*func)(void *data), void *data); >> int hibernate_resume_nonboot_cpu_disable(void); >> int arch_hibernation_header_save(void *addr, unsigned int max_size); >> int arch_hibernation_header_restore(void *addr); >> +bool arch_hibernation_available(void); >> >> #else /* CONFIG_HIBERNATION */ >> static inline void register_nosave_region(unsigned long b, unsigned long e) {} >> diff --git a/kernel/power/hibernate.c b/kernel/power/hibernate.c >> index d2479c69d71a4..9d9d53828542f 100644 >> --- a/kernel/power/hibernate.c >> +++ b/kernel/power/hibernate.c >> @@ -106,11 +106,17 @@ bool hibernation_in_progress(void) >> return !atomic_read(&hibernate_atomic); >> } >> >> +__weak bool arch_hibernation_available(void) >> +{ >> + return true; >> +} >> + >> bool hibernation_available(void) >> { >> return nohibernate == 0 && >> !security_locked_down(LOCKDOWN_HIBERNATION) && >> - !secretmem_active() && !cxl_mem_active(); >> + !secretmem_active() && !cxl_mem_active() && >> + arch_hibernation_available(); >> } > > With the comments above addressed: > > Reviewed-by: Catalin Marinas <catalin.marinas@arm.com> Thank you! Suzuki ^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-01 11:39 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <20261001084555.1456543-1-suzuki.poulose@arm.com>
2026-10-01 8:45 ` [PATCH v21 7/9] arm64: Block hibernate and kexec while RMM is active Suzuki K Poulose
2026-10-01 11:05 ` Catalin Marinas
2026-10-01 11:39 ` Suzuki K Poulose
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox