[PATCH v15 27/37] KVM: arm64: CCA: Allow userspace to inject aborts
Suzuki K Poulose
suzuki.poulose at arm.com
Thu Jul 16 03:19:39 PDT 2026
On 15/07/2026 15:28, Steven Price wrote:
> From: Joey Gouly <joey.gouly at arm.com>
>
> Extend KVM_SET_VCPU_EVENTS to support realms, where KVM cannot set the
> system registers, and the RMM must perform it on next REC entry.
>
> Signed-off-by: Joey Gouly <joey.gouly at arm.com>
> Signed-off-by: Steven Price <steven.price at arm.com>
> Reviewed-by: Gavin Shan <gshan at redhat.com>
> ---
Reviewed-by: Suzuki K Poulose <suzuki.poulose at arm.com>
> Documentation/virt/kvm/api.rst | 2 ++
> arch/arm64/kvm/guest.c | 24 ++++++++++++++++++++++++
> 2 files changed, 26 insertions(+)
>
> diff --git a/Documentation/virt/kvm/api.rst b/Documentation/virt/kvm/api.rst
> index e39d146b34a3..85bec9b4f021 100644
> --- a/Documentation/virt/kvm/api.rst
> +++ b/Documentation/virt/kvm/api.rst
> @@ -1314,6 +1314,8 @@ User space may need to inject several types of events to the guest.
> Set the pending SError exception state for this VCPU. It is not possible to
> 'cancel' an Serror that has been made pending.
>
> +User space cannot inject SErrors into Realms.
> +
> If the guest performed an access to I/O memory which could not be handled by
> userspace, for example because of missing instruction syndrome decode
> information or because there is no device mapped at the accessed IPA, then
> diff --git a/arch/arm64/kvm/guest.c b/arch/arm64/kvm/guest.c
> index 3e970c4f6214..5469c9a97fad 100644
> --- a/arch/arm64/kvm/guest.c
> +++ b/arch/arm64/kvm/guest.c
> @@ -827,6 +827,30 @@ int __kvm_arm_vcpu_set_events(struct kvm_vcpu *vcpu,
> u64 esr = events->exception.serror_esr;
> int ret = 0;
>
> + if (vcpu_is_rec(vcpu)) {
> + /* Cannot inject SError into a Realm. */
> + if (serror_pending)
> + return -EINVAL;
> +
> + /*
> + * If a data abort is pending, set the flag and let the RMM
> + * inject an SEA when the REC is scheduled to be run.
> + */
> + if (ext_dabt_pending) {
> + /*
> + * Can only inject SEA into a Realm if the previous exit
> + * was due to a data abort of an Unprotected IPA.
> + */
> + if (!(vcpu->arch.rec.run->enter.flags & REC_ENTER_FLAG_EMULATED_MMIO))
> + return -EINVAL;
> +
> + vcpu->arch.rec.run->enter.flags &= ~REC_ENTER_FLAG_EMULATED_MMIO;
> + vcpu->arch.rec.run->enter.flags |= REC_ENTER_FLAG_INJECT_SEA;
> + }
> +
> + return 0;
> + }
> +
> /*
> * Immediately commit the pending SEA to the vCPU's architectural
> * state which is necessary since we do not return a pending SEA
More information about the linux-arm-kernel
mailing list