[PATCH v4 0/3] virt: bao: add Bao hypervisor IPC and I/O dispatcher drivers

João Peixoto jpeixoto at osyx.tech
Sun Sep 27 04:49:21 PDT 2026


This series adds guest-side drivers for the Bao static-partitioning
hypervisor: an IPC shared-memory driver, an I/O dispatcher that lets a
backend guest service VirtIO I/O for frontend guests, their UAPI and a
MAINTAINERS entry.

Bao is a lightweight static-partitioning hypervisor for embedded and
safety-critical systems (https://github.com/bao-project).

- The IPC shared-memory driver lets Bao guests exchange data through a
  shared-memory region split into a read and a write channel, exposed
  as a misc character device (read(), write(), mmap()).
- The I/O dispatcher bridges Bao's Remote I/O mechanism to a userspace
  VMM: the VMM creates each device model from /dev/bao, receives the
  frontend's MMIO accesses and completes them, with ioeventfd/irqfd
  support for the fast paths.

Changes since v3
----------------
The two design comments on v3 changed the shape of the series, which
went from six patches to three.

- No device tree (Krzysztof Kozlowski): both bindings and the "bao"
  vendor prefix are dropped. The IPC channels are a software contract
  between the hypervisor and the guest and are now declared on the
  kernel command line (bao_ipcshmem.channels=...). The set of device
  models a backend serves is a contract between the hypervisor and the
  VMM, so, following drivers/virt/acrn, the I/O dispatcher exposes a
  single /dev/bao control device and the VMM creates each device model
  with BAO_IOCTL_CREATE_DM (shared-memory region + notification line),
  which returns a per-DM file descriptor; the DM lives as long as the
  descriptor. The notification line is resolved against the device
  tree's root interrupt parent, like any device's interrupt.
- No architecture code (Will Deacon): the hypercall helpers moved to
  drivers/virt/bao/bao_hypercall.h and use arm_smccc_hvc() for the IPC
  hypercall and, because the Remote I/O hypercall returns the request
  in x1-x6, the SMCCC v1.2 arm_smccc_1_2_hvc(). RISC-V uses sbi_ecall()
  for IPC and a local ecall for Remote I/O (see open items). 32-bit Arm
  has no SMCCC v1.2 helper, so the I/O dispatcher is limited to arm64
  and RISC-V for now; the IPC driver still supports 32-bit Arm through
  SMCCC v1.1 (HAVE_ARM_SMCCC).
- The standalone "consolidate the IPC hypercall ID" patch is folded into
  the driver patches (Andrew Jones).
- All findings of the Sashiko review of v3 are addressed, among them:
  the DM id is taken from the file descriptor instead of userspace; the
  irqfd/ioeventfd teardown races and the ioeventfd deassign fall-through
  are fixed; the interrupt handler is per DM and the request_irq() name
  is persistent; queued requests are capped and requests that cannot be
  delivered are completed back to the hypervisor; the UAPI structures
  have no implicit padding; signals return -ERESTARTSYS; the IPC driver
  orders the shared-memory writes before the notify hypercall, refuses
  writable mappings of the read region, validates page-aligned regions
  and has an llseek. Details are in the per-patch changelogs.
- The ioctl type is now 0xA7: 7.3-rc1 registered 0xA6 for memory
  allocation profiling.
- Found while testing: the two modules were both named bao.ko (now
  bao_ipcshmem and bao_io_dispatcher), the ioeventfd kernel thread could
  exit before kthread_stop(), per-DM dispatcher state was kept in static
  arrays, a list walk used the wrong structure type, the UAPI header did
  not include linux/ioctl.h, and the dispatcher workqueue now passes
  WQ_PERCPU as required since 7.x.

Testing
-------
Built on v7.3-rc1 with GCC (W=1, sparse) for arm64, arm and riscv, as
modules and built-in, and with clang for arm64 and riscv. Run-time tested
under Bao v2.0.0 on QEMU aarch64 virt and QEMU riscv64 virt with the
bao-demos demos: the IPC driver exchanging messages in both directions
between a Linux 7.3-rc1 guest and a FreeRTOS guest (linux+freertos demo),
and the I/O dispatcher with a Linux backend serving console, network and
block device models to a FreeRTOS guest and two Linux guests (virtio
demo). 32-bit Arm is compile-tested only.

Open items
----------
- RISC-V: the Bao SBI extension still uses the experimental extension
  space (0x08000ba0), and the Remote I/O hypercall returns the request
  in a2-a7, which does not follow the SBI calling convention (Andrew
  Jones, v2). Changing that means a hypervisor ABI change (status in
  a0/a1, request through shared memory); the RISC-V support is marked
  experimental until then, or it can be split out of this series if
  preferred.
- Bao does not implement the SMCCC vendor-hypervisor UID call, so the
  drivers cannot detect the hypervisor yet; adding it is planned on the
  hypervisor side.

v3: https://lore.kernel.org/all/cover.1786010512.git.jpeixoto@osyx.tech/

João Peixoto (3):
  virt: bao: add IPC shared-memory driver
  virt: bao: add I/O dispatcher driver
  MAINTAINERS: add Bao hypervisor entry

 .../userspace-api/ioctl/ioctl-number.rst      |   2 +
 MAINTAINERS                                   |   8 +
 drivers/virt/Kconfig                          |   2 +
 drivers/virt/Makefile                         |   1 +
 drivers/virt/bao/Kconfig                      |   5 +
 drivers/virt/bao/Makefile                     |   4 +
 drivers/virt/bao/bao_hypercall.h              | 190 ++++++++
 drivers/virt/bao/io-dispatcher/Kconfig        |  20 +
 drivers/virt/bao/io-dispatcher/Makefile       |   4 +
 drivers/virt/bao/io-dispatcher/bao_drv.h      | 389 ++++++++++++++++
 drivers/virt/bao/io-dispatcher/dm.c           | 334 ++++++++++++++
 drivers/virt/bao/io-dispatcher/driver.c       |  70 +++
 drivers/virt/bao/io-dispatcher/intc.c         | 150 +++++++
 drivers/virt/bao/io-dispatcher/io_client.c    | 423 ++++++++++++++++++
 .../virt/bao/io-dispatcher/io_dispatcher.c    | 159 +++++++
 drivers/virt/bao/io-dispatcher/ioeventfd.c    | 326 ++++++++++++++
 drivers/virt/bao/io-dispatcher/irqfd.c        | 315 +++++++++++++
 drivers/virt/bao/ipcshmem/Kconfig             |  16 +
 drivers/virt/bao/ipcshmem/Makefile            |   3 +
 drivers/virt/bao/ipcshmem/ipcshmem.c          | 358 +++++++++++++++
 include/uapi/linux/bao.h                      | 116 +++++
 21 files changed, 2895 insertions(+)
 create mode 100644 drivers/virt/bao/Kconfig
 create mode 100644 drivers/virt/bao/Makefile
 create mode 100644 drivers/virt/bao/bao_hypercall.h
 create mode 100644 drivers/virt/bao/io-dispatcher/Kconfig
 create mode 100644 drivers/virt/bao/io-dispatcher/Makefile
 create mode 100644 drivers/virt/bao/io-dispatcher/bao_drv.h
 create mode 100644 drivers/virt/bao/io-dispatcher/dm.c
 create mode 100644 drivers/virt/bao/io-dispatcher/driver.c
 create mode 100644 drivers/virt/bao/io-dispatcher/intc.c
 create mode 100644 drivers/virt/bao/io-dispatcher/io_client.c
 create mode 100644 drivers/virt/bao/io-dispatcher/io_dispatcher.c
 create mode 100644 drivers/virt/bao/io-dispatcher/ioeventfd.c
 create mode 100644 drivers/virt/bao/io-dispatcher/irqfd.c
 create mode 100644 drivers/virt/bao/ipcshmem/Kconfig
 create mode 100644 drivers/virt/bao/ipcshmem/Makefile
 create mode 100644 drivers/virt/bao/ipcshmem/ipcshmem.c
 create mode 100644 include/uapi/linux/bao.h


base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
-- 
2.43.0




More information about the linux-riscv mailing list