Re: [PATCH v19 6/7] firmware: arm_rmm: Ensure the RMM has GPT entries for memory

From: Gavin Shan

Date: Thu Sep 24 2026 - 20:07:50 EST


On 9/24/26 11:52 PM, Suzuki K Poulose wrote:
From: Steven Price <steven.price@xxxxxxx>

The RMM maintains the state of all the granules in the system to make
sure that the host is abiding by the rules. This state can be maintained
at different granularity, per page (TRACKING_FINE) or per region
(TRACKING_COARSE or TRACKING_INTERMEDIATE). The region size depends on the
underlying "RMI_GRANULE_SIZE". For a "coarse"/"intermediate" region,
all pages in the region must be of the same state, this implies we need to
have "fine" tracking for DRAM, so that we can delegate individual pages.

For now we only support a statically carved out memory for tracking
granules for the "fine" regions. This can be extended in the future to
allow modifying the tracking granularity and remove the need for a
static allocation by the firmware.

Similarly, the firmware may create L0 GPT entries describing the total
address space. But if we change the "PAS" (Physical Address Space) of a
granule, then the firmware may need to create L1 tables to track the PAS
at a finer granularity. Linux therefore checks if the platform firmware
manages the PAR region. i.e., the firmware is in charge of managing the
L1 GPTs (creation and the required memory for the GPT tables - via static
carveouts) without host intervention. Support for dynamic GPT creation by
the host will be added later.

If the firmware requires us to manage the tracking or GPT memory,
deactivate the RMM and reclaim any memory donated at RMM activation.

Apply the same checks when hotplugged memory is brought online.

Signed-off-by: Steven Price <steven.price@xxxxxxx>
[ Switch to RMI_GPT_L1_INFO for checking GPTs and deactivate RMM ]
Co-developed-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v19:
* Avoid mixing gotos with __free cleanups for arm64_init_rmi()
Changes since v18:
* Handle buggy RMM to make forward progress for RMI_GPT_INFO and
RMI_GRANULE_TRACKING_GET
* Make sure the memory ranges are not inverted and reject such ranges.
* Move granule_tracking_get/gpt_info wrappers closer to the callers
Drop "inline", let the compiler do its job
Changes since v17:
* Move wrappers that may not be used elsewhere, out of arm-rmi-cmds.h
Changes since v16:
* Check fine tracking and create L1 GPTs for hotplug-added memory.
* Clarify the L1 GPT setup and move the explanatory comment.
* Switch to using RMI_GPT_INFO command for checking the GPTs.
* Deactivate the RMM and reclaim the memory if we can't proceed.
Changes since v15:
* Skip firmware-reserved NOMAP memory in rmi_init_metadata()
* Handle negative error codes from wrappers.
Changes since v14:
* Move the implementation into drivers/firmware/arm_rmm.
Changes since v13:
* Moved out of KVM
---
drivers/firmware/arm_rmm/rmi.c | 218 ++++++++++++++++++++++++++++++++-
include/linux/arm-rmi-cmds.h | 2 +
2 files changed, 219 insertions(+), 1 deletion(-)


With Jonathan's comments addressed:

Reviewed-by: Gavin Shan <gshan@xxxxxxxxxx>

Thanks,
Gavin