[PATCH v18 1/7] firmware: arm_rmm: Add SMC definitions for calling the RMM

Suzuki K Poulose suzuki.poulose at arm.com
Mon Sep 21 03:02:56 PDT 2026


On 21/09/2026 10:27, Suzuki K Poulose wrote:
> On 19/09/2026 02:27, Jonathan Cameron wrote:
>>> The RMM (Realm Management Monitor) provides functionality that can be
>>> accessed by SMC calls from the host.
>>>
>>> The SMC definitions are based on DEN0137[1] version 2.0-bet3
>>>
>>> [1] https://developer.arm.com/documentation/den0137/2-0bet3/
>>>
>>> Signed-off-by: Steven Price <steven.price at arm.com>
>>> Signed-off-by: Suzuki K Poulose <suzuki.poulose at arm.com>
>>
>> With Gavin's nitpicks and the GENMASK_ULL() from sashiko, just a few
>> comments inline.  Mostly on subtle inconsistencies that really don't
>> matter that much.
>>
>>>   include/linux/arm-smccc-rmi.h | 497 ++++++++++++++++++++++++++++++++++
>>>   1 file changed, 497 insertions(+)
>>>   create mode 100644 include/linux/arm-smccc-rmi.h
>>>
>>> diff --git a/include/linux/arm-smccc-rmi.h b/include/linux/arm-smccc- 
>>> rmi.h
>>> new file mode 100644
>>> index 000000000000..214d6228dfc2
>>> --- /dev/null
>>> +++ b/include/linux/arm-smccc-rmi.h
>>> @@ -0,0 +1,497 @@
>>> +/* SPDX-License-Identifier: GPL-2.0 */
>>> +/*
>>> + * Copyright (C) 2023-2026 ARM Ltd.
>>> + *
>>> + * The values and structures in this file are from the Realm 
>>> Management Monitor
>>> + * specification (DEN0137) version 2.0-bet3:
>>> + * https://developer.arm.com/documentation/den0137/2-0bet3/
>>> + */
>>> +
>>> +#ifndef __LINUX_ARM_SMCCC_RMI_H_
>>> +#define __LINUX_ARM_SMCCC_RMI_H_
>>> +
>>> +#include <linux/arm-smccc.h>
>>> +#include <linux/bitfield.h>
>>> +#include <linux/bits.h>
>>> +#include <linux/build_bug.h>
>>> +#include <linux/sizes.h>
>>> +
>>> +#include <asm/page.h>
>>> +
>>> +#define SMC_RMI_CALL(func)                \
>>> +    ARM_SMCCC_CALL_VAL(ARM_SMCCC_FAST_CALL,        \
>>> +               ARM_SMCCC_SMC_64,        \
>>> +               ARM_SMCCC_OWNER_STANDARD,    \
>>> +               (func))
>>
>> Obviously it is v18 so probably a future thing but nothing about this
>> is RMI specific.  Could be used for ARM_SMCCC_TRNG_RND64 for instance.
>> I'm not entirely sure what we'd call such a macro
>>
>> ARM_SMCCC_CALL_VAL64_STD() maybe?
> 
> ARM_SMCCC_STD_CALL64_VAL() ?
> 
> But, I would leave it as a wider cleanup in the tree as a separate
> series.
> 
>>
>> I'm not just not keen on macros whose names to me hint at something
>> special. FWIW this also matches SMC_RSI_FID() and FFA_SMC64().
>> Isn't it nice when we have a predictable naming scheme :)
>>
>> FID (for Function IDentifier) is in the spec, so maybe?
>>
>> Anyhow, I don't really care that much.
>>
>>> +
>>> +#define SMC_RMI_VERSION                SMC_RMI_CALL(0x0150)
>>> +
>>
>>
>>> +#define RMI_ABI_MAJOR_VERSION    2
>>> +#define RMI_ABI_MINOR_VERSION    0
>>> +
>>> +#define RMI_ABI_VERSION_GET_MAJOR(version) ((version) >> 16)
>>
>> I'd mask it.  Mostly because that would shout that it is only 15 bits.
>>
> 
> Ack
> 
>>> +#define RMI_ABI_VERSION_GET_MINOR(version) ((version) & 0xFFFF)
>>> +#define RMI_ABI_VERSION(major, minor)      (((major) << 16) | (minor))
>>
>> I'd go all in on FIELD_PREP() / FIELD_GET() + GENMASK just for the
>> sake of consistency + not having to be careful that everything is
>> checked for fit to keep the LLM bots happy.
>>
>>> +
>>> +#define RMI_RETURN_STATUS_MASK        GENMASK(7, 0)
>>> +#define RMI_RETURN_INDEX_MASK        GENMASK(15, 8)
>>> +#define RMI_RETURN_MEMREQ_MASK        GENMASK(9, 8)
>>> +#define RMI_RETURN_CAN_CANCEL_MASK    BIT(10)
>>> +
>>> +#define RMI_RETURN_STATUS(ret)        
>>> FIELD_GET(RMI_RETURN_STATUS_MASK, ret)
>>> +#define RMI_RETURN_INDEX(ret)        
>>> FIELD_GET(RMI_RETURN_INDEX_MASK, ret)
>>
>> What's this one?  I can't find anything in the spec that matches it
>> and as far as I can tell you don't use it in this series.
> 
> This is coming from RmiResultDataLevel. See RmiResult type.
> This was renamed after we introduce the RmiResultDataIncomplete.
> It is used in the KVM code to find the "level" where a command
> failed/walked.
> 
> I could rename it to RMI_RESULT_DATA_LEVEL() ?
> Similarly RMI_RESULT_STATUS instead of RMI_RETURN_*
> 
>>
>>> +#define RMI_RETURN_MEMREQ(ret)        
>>> FIELD_GET(RMI_RETURN_MEMREQ_MASK, ret)
>>> +#define RMI_RETURN_CAN_CANCEL(ret)    
>>> FIELD_GET(RMI_RETURN_CAN_CANCEL_MASK, ret)
> 
>> These are obscure enough to find in the spec I'd give a comment just
>> to save the sanity of anyone looking for them.
> 
> As above, they are really RMI_RESULT_DATA_INCOMPLETE_*
> 
>>
>>> +/*
>>> + * Note many of these fields are smaller than u64 but all fields 
>>> have u64
>>> + * alignment, so use u64 to ensure correct alignment.
>>
>> Obviously this is only going to run on arm64 so it's not critical, but
>> more generally u64s aren't always 64 bit aligned.  So if you 'really'
>> care aligned_u64 is there to ensure it.  Meh, arm64 so fine.
> 
> Agreed, I am worried about the churn in the consumer code. Also, like
> you said, this is only for ARM64. So, I would pass it.
> 
>>
>>> + */
>>> +struct rmm_config {
>>> +    union { /* 0x0 */
>>> +        struct {
>>> +            u64 tracking_region_size;
>>> +            u64 rmi_granule_size;
>>> +        };
>>> +        u8 sizer[SZ_4K];
>>> +    };
>>> +};
>>> +
>>> +static_assert(sizeof(struct rmm_config) == SZ_4K);
>>> +
>>> +#define RMI_REALM_PARAM_FLAG_SVE        BIT(1)
>>> +#define RMI_REALM_PARAM_FLAG_PMU        BIT(2)
>>> +#define RMI_REALM_PARAM_FLAG_DA            BIT(3)
>>> +#define RMI_REALM_PARAM_FLAG_LFA_POLICY        GENMASK(6, 5)
>>> +#define RMI_REALM_PARAM_FLAG_MEC_POLICY        GENMASK(8, 7)
>>
>> Tiny bit inconsistent. When do you decide _MASK is needed and when
>> not?  Seems a little too random for multibit fields.
> 
> I will try to clean this up.

Actually, this is used when we don't consume them from RMM. i.e.,
we never call FIELD_GET() on them. But thats not a reason for
not being consistent in naming. I can fix it

Cheers
Suzuki




More information about the linux-arm-kernel mailing list