[PATCH 00/17] KVM: arm64: Confine protected VM vCPU state to EL2

Fuad Tabba fuad.tabba at linux.dev
Mon Aug 31 12:27:38 PDT 2026


On Mon, 31 Aug 2026 at 17:34, Fuad Tabba <fuad.tabba at linux.dev> wrote:
...
>
> The kvmtool changes that go with this will be posted separately, and I
> will reply here with a link.

... and here they are:
https://lore.kernel.org/all/20260831192406.1341841-1-fuad.tabba@linux.dev/

Cheers,
/fuad

>
> Patch 1 is the HCR_EL2.VSE fix posted separately [2]. It is not part
> of this series; it is carried so the series applies as is and Sashiko
> can run on it.
>
> The KVM_ARM_PREFERRED_TARGET documentation fix [3] went out just ahead
> of this series. Nothing here needs it to apply, but patch 17 documents
> vCPU feature availability as something the capabilities report, while
> api.rst 4.83 still points userspace at a bitmap that has always been
> empty.
>
> The series is structured as follows:
>
>   01:     The HCR_EL2.VSE fix, posted separately.
>   02-03:  Capability allowlist and the PVTIME rejection.
>   04-05:  Per-exception-class entry handlers; EL2 owns a protected
>           vCPU's trap configuration.
>   06-08:  Timer state, system register reset and HVC handling at EL2.
>   09-10:  PSCI at EL2, and the KVM_ARM_VCPU_INIT and PSCI version
>           restrictions.
>   11-14:  Host PC adjustments blocked; an UNDEF at EL2 for exit
>           classes the host does not emulate; per-class state
>           marshalling; a protected guest's SError pended with
>           HCR_EL2.VSE.
>   15-16:  Host access to private state, and host power-on of a vCPU
>           EL2 holds powered off, rejected.
>   17:     Documentation.
>
> Still to come: selftests, self-hosted debug, SVE for protected guests,
> and much more, as separate series.
>
> Based on v7.3-rc1 (cee9395acd804).
>
> Cheers,
> /fuad
>
> P.S. Sashiko, bring it on!
>
> [1] https://lore.kernel.org/all/20260729131823.2021516-1-fuad.tabba@linux.dev/
> [2] https://lore.kernel.org/all/20260829071120.2522788-1-fuad.tabba@linux.dev/
> [3] https://lore.kernel.org/all/20260831162815.269851-1-fuad.tabba@linux.dev/
>
> Fuad Tabba (15):
>   KVM: arm64: Sync HCR_EL2.VSE back to the host vCPU under pKVM
>   KVM: arm64: Advertise the capabilities that protected VMs support
>   KVM: arm64: Reject the PVTIME vCPU attribute for protected VMs
>   KVM: arm64: Skip fixed-feature state flush for protected vCPUs
>   KVM: arm64: Add system register reset framework for protected VMs
>   KVM: arm64: Implement HVC handling for protected guests at EL2
>   KVM: arm64: Handle PSCI calls for protected VMs at EL2
>   KVM: arm64: Restrict KVM_ARM_VCPU_INIT and PSCI version for protected
>     VMs
>   KVM: arm64: Prevent host PC adjustments for protected vCPUs
>   KVM: arm64: Inject an UNDEF at EL2 for unhandled protected guest exits
>   KVM: arm64: Add per-EC entry/exit state marshalling for protected
>     guests
>   KVM: arm64: Pend a protected guest's SError with HCR_EL2.VSE only
>   KVM: arm64: Reject host access to protected VM private state
>   KVM: arm64: Reject host power-on of a vCPU that EL2 holds powered off
>   KVM: arm64: Document the protected VM userspace API
>
> Marc Zyngier (2):
>   KVM: arm64: Introduce per-EC entry handlers for pKVM
>   KVM: arm64: Add {flush,sync}_hyp_timer_state() primitives
>
>  Documentation/virt/kvm/api.rst                |  22 +-
>  .../virt/kvm/arm/fw-pseudo-registers.rst      |   2 +
>  Documentation/virt/kvm/arm/pkvm.rst           | 141 ++++-
>  Documentation/virt/kvm/devices/vcpu.rst       |   4 +-
>  arch/arm64/include/asm/kvm_asm.h              |   1 +
>  arch/arm64/include/asm/kvm_host.h             |  21 +
>  arch/arm64/include/asm/kvm_pkvm.h             |  34 +-
>  arch/arm64/kvm/arm.c                          |  40 ++
>  arch/arm64/kvm/guest.c                        |  29 +
>  arch/arm64/kvm/hyp/exception.c                |  27 +-
>  arch/arm64/kvm/hyp/include/nvhe/pkvm.h        |  18 +
>  arch/arm64/kvm/hyp/nvhe/hyp-main.c            | 564 +++++++++++++++++-
>  arch/arm64/kvm/hyp/nvhe/pkvm.c                | 401 ++++++++++++-
>  arch/arm64/kvm/hyp/nvhe/switch.c              |  29 +-
>  arch/arm64/kvm/hyp/nvhe/sys_regs.c            |  91 ++-
>  arch/arm64/kvm/hypercalls.c                   |   7 +
>  arch/arm64/kvm/inject_fault.c                 |   5 +-
>  arch/arm64/kvm/pkvm.c                         |  21 +-
>  arch/arm64/kvm/psci.c                         |   3 +
>  19 files changed, 1378 insertions(+), 82 deletions(-)
>
>
> base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
> --
> 2.39.5
>



More information about the linux-arm-kernel mailing list