[PATCH v17 00/20] KVM: arm64: CCA: Add basic plumbing for Realms

Suzuki K Poulose suzuki.poulose at arm.com
Tue Sep 8 09:22:03 PDT 2026


This series is a trimmed down version of the Arm CCA KVM support, previously
posted here [0]. Since the last version, we have tried to split the entire
series into the following chunks, while also addressing the review comments on
that version.

 1) Base RMM RMI support under drivers/firmware/arm_rmm -> [1]
 2) Linux Host support for handling GPFs - [2]
 3) NEW: Enlighten KVM arm64 about the different VM types and use call backs for
   the VM type, rather than spilling the is_this_type_of_vm() everywhere. This is
   not complete yet, but it is largely functional. Adds VCPU and Stage2 MMU related
   callbacks with support for the existing VM types. There are other places where
   we may be able to abstract, but those need careful performance evaluations to
   make sure they are fit (e.g., vcpu_run)
   Also adds classification of "Confidential" VMs (which includes Protected VM
   and Realms), which allows us to handle common themes without having to do
   things like :
     if (kvm_vm_is_protected() || kvm_vm_is_realm()),
     instead:
     if (kvm_vm_is_confidential())
   The S2 MMU abstraction layer is kept at the end of this series. The Realm S2
   related implementations cannot be added meaningfully without the RMI commands.
 4) Bare minimal Realm VM support without the actual functionality to run a Realm.
   This would help the maintainers to review the series in smaller chunks. This
   doesn't depend on [1] and can be independently merged, without being "functional".
 5) Core implementation of the RMI driver for KVM and actual enablement of the
    Realm support. This depends on (1), (2) and the guest-memfd-in-place
    conversion series v12 from Ackerley. This is available here at the integration
    branch [3]

This series is comprised of (3) and (4) above.

The integration branch has been tested with the following components:
  tf-RMM:   main branch (commit 5e6e2acd) compliant to RMM-v2.0-beta3 [4]
  kvmtool: git at git.gitlab.arm.com:linux-arm/kvmtool-cca.git cca/kvm-v17

[0] Arm CCA KVM Support v16 : https://lore.kernel.org/all/20260803134403.80630-1-steven.price@arm.com
[1] Linux firmware RMI https://lore.kernel.org/all/20260907095942.1140734-1-suzuki.poulose@arm.com
[2] Linux GPF Host https://lore.kernel.org/all/20260907162204.1479401-1-suzuki.poulose@arm.com
[3] https://git.gitlab.arm.com/linux-arm/linux-cca/ cca/cca-host/kvm-v17/integration
[4] https://support.arm.com/documentation/den0137/2-0bet3/

Jean-Philippe Brucker (2):
  KVM: arm64: CCA: Provide register list for unfinalized RECs
  KVM: arm64: CCA: Provide an accurate register list

Steven Price (4):
  KVM: arm64: Avoid including linux/kvm_host.h in kvm_pgtable.h
  KVM: arm64: CCA: Introduce Realms
  KVM: arm64: CCA: Support timers in realm RECs
  KVM: arm64: CCA: WARN on injected undef exceptions

Suzuki K Poulose (14):
  KVM: arm64: Include kvm_emulate.h in kvm/arm_psci.h
  KVM: arm64: Track the type of VM in kvm_arch
  KVM: arm64: Refactor the vcpu_load to allow for VM specific callbacks
  KVM: arm64: Add vcpu load/put call backs for flavors
  KVM: arm64: CCA: Add a new mode for supporting Realm guests
  KVM: arm64: coco:  Add a helper to check if a VM is confidential
    compute guest
  KVM: arm64: coco: arch_timer: Prevent timer offset configuration
  KVM: arm64: coco: Disable Steal time accounting for coco guests
  KVM: arm64: coco: Don't handle MMIO with no ISV
  KVM: arm64: CCA: Add VCPU load/put for Realms
  KVM: arm64: CCA: Don't expose unsupported capabilities for realm
    guests
  KVM: arm64: Reuse kvm_stage2_unmap_range in kvm_unmap_gfn_range
  KVM: arm64: Add VM specific callback for S2 MMU operations
  KVM: arm64: Abstract out memory abort handling

 .../admin-guide/kernel-parameters.txt         |   3 +
 arch/arm64/include/asm/kvm_emulate.h          |  16 ++
 arch/arm64/include/asm/kvm_host.h             |  58 +++-
 arch/arm64/include/asm/kvm_pgtable.h          |   6 +-
 arch/arm64/include/asm/kvm_pkvm.h             |   2 +-
 arch/arm64/include/asm/kvm_rmi.h              |  61 ++++
 arch/arm64/include/asm/virt.h                 |   1 +
 arch/arm64/kvm/Makefile                       |   2 +-
 arch/arm64/kvm/arch_timer.c                   |  28 +-
 arch/arm64/kvm/arm.c                          | 267 +++++++++++++++---
 arch/arm64/kvm/guest.c                        |  16 +-
 arch/arm64/kvm/hyp/nvhe/pkvm.c                |   2 +-
 arch/arm64/kvm/hyp/pgtable.c                  |   1 +
 arch/arm64/kvm/hypercalls.c                   |   4 +-
 arch/arm64/kvm/inject_fault.c                 |   1 +
 arch/arm64/kvm/mmio.c                         |   4 +-
 arch/arm64/kvm/mmu.c                          | 173 +++++++++---
 arch/arm64/kvm/pkvm.c                         |   1 -
 arch/arm64/kvm/pvtime.c                       |  10 +-
 arch/arm64/kvm/rmi.c                          |  18 ++
 arch/arm64/kvm/sys_regs.c                     |  27 +-
 include/kvm/arm_psci.h                        |   2 +
 22 files changed, 581 insertions(+), 122 deletions(-)
 create mode 100644 arch/arm64/include/asm/kvm_rmi.h
 create mode 100644 arch/arm64/kvm/rmi.c

-- 
2.43.0




More information about the linux-arm-kernel mailing list