Re: [PATCH v7 0/3] KVM: arm64: Support FF-A direct messaging interfaces

From: Fuad Tabba

Date: Mon Sep 14 2026 - 15:24:54 EST


Hi Per,

On Mon, 31 Aug 2026 at 00:08, Per Larsen via B4 Relay
<devnull+perlarsen.google.com@xxxxxxxxxx> wrote:
>
> Block host-initiated FF-A direct responses.
> Support FFA_MSG_SEND_DIRECT_REQ unconditionally.
> Support FFA_MSG_SEND_DIRECT_REQ2 if hypervisor negotiated version 1.2+.
>
> Framework messages (FF-A control plane) are filtered out. For
> FFA_MSG_SEND_DIRECT_REQ, we look at flags in w2. Messages using the REQ2
> interface are always partition messages.
>
> The third patch was part of a previous patch set [0] but was dropped
> since the use case was unclear. A clear use case has now appeared: use
> TPM device with CRB over FF-A when kernel boots with pkvm [1].

tpm_crb_ffa already uses sync_send_receive2() for partitions that
support REQ2, and on a pKVM host that returns -EOPNOTSUPP today: the
FF-A driver sets msg_direct_req2_supp when either FFA_FEATURES(REQ2)
or FFA_FEATURES(RESP2) succeeds, and before patch 3 the hypervisor
answers NOT_SUPPORTED to both. Patch 3 lets the REQ2 query through to
firmware, which is enough for the OR. Worth citing that in the cover
instead of [1]?

> Tested by booting Android under QEMU.

Which firmware was that, and what did it negotiate for FFA_VERSION?
The proxy doesn't initialise unless firmware answers that call, so I'd
like to know whether a REQ2 in particular round-tripped.

>
> Best Regards,
> Per
>
> [0]: https://lore.kernel.org/all/20250730-virtio-msg-ffa-v9-0-7f1b55c8d149@xxxxxxxxxx/
> [1]: https://lore.kernel.org/all/20251027191729.1704744-1-yeoreum.yun@xxxxxxx/
>
> Signed-off-by: Per Larsen <perlarsen@xxxxxxxxxx>
> ---
> Changes in v7:
> - New patch 1/3: block FFA_FN64_MSG_SEND_DIRECT_RESP. Only the 32-bit
> variant was denied, so the host could send unvalidated 64-bit direct
> responses to EL3, including a forged sender endpoint ID
> - Use hyp_smccc_1_2_smc() so the call is bracketed by hyp_exit/hyp_enter;
> the pass-through path already traced these calls
> - Declare endp/flags as u64 and reject a non-zero x1[63:32]: these are
> w1/w2, but the raw 64-bit registers are forwarded to EL3
> - Pass the canonicalised func_id to do_ffa_direct_msg() rather than
> re-reading x0, which still carries ARM_SMCCC_CALL_HINTS
> - Link to v6: https://lore.kernel.org/r/20260501-host-direct-messages-v6-0-3f4af727ed85@xxxxxxxxxx
>
> Changes in v6:
> - 1/2: validate that bits 31:16 of w1 is HOST_FFA_ID.
> - Link to v5: https://lore.kernel.org/r/20260121-host-direct-messages-v5-0-2c1614c94e80@xxxxxxxxxx
>
> Changes in v5:
> - 1/2: do_ffa_direct_msg: validate that sender is HOST_FFA_ID.
> - Link to v4: https://lore.kernel.org/r/20260109-host-direct-messages-v4-0-95da4221d186@xxxxxxxxxx
>
> Changes in v4:
> - 1/2: do_ffa_direct_msg: check that flag in w2 is zero; drop unused vm_handle parameter.
> - 2/2: ffa_call_supported: simplify logic by reordering cases.
> - do_ffa_direct_msg: switch polarity of check and update comment.
> - Link to v3: https://lore.kernel.org/r/20251119-host-direct-messages-v3-0-c74d04944b26@xxxxxxxxxx
>
> Changes in v3:
> - Filter out framework messages as suggested by Will Deacon. Update cover letter accordingly.
> - Update trailers: Reviewed-by: Yeoreum Yun <yeoreum.yun@xxxxxxx>
> - Link to v2: https://lore.kernel.org/r/20251030-host-direct-messages-v2-0-9f27cef36730@xxxxxxxxxx
>
> Changes in v2:
> - 1/2: Drop support for FFA_ID_GET interface in host handler.
> - Link to v1: https://lore.kernel.org/r/20251030-host-direct-messages-v1-0-463e57871c8f@xxxxxxxxxx
>
> ---
> Per Larsen (2):
> KVM: arm64: Block host-initiated FF-A direct responses
> KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ2 in host handler
>
> Sebastian Ene (1):
> KVM: arm64: Support FFA_MSG_SEND_DIRECT_REQ in host handler
>
> arch/arm64/kvm/hyp/nvhe/ffa.c | 44 +++++++++++++++++++++++++++++++++++++++++--
> include/linux/arm_ffa.h | 2 ++
> 2 files changed, 44 insertions(+), 2 deletions(-)
> ---
> base-commit: cee9395acd8043be0644b25c34bfa86623f2b935
> change-id: 20251029-host-direct-messages-5201d7f55abd
>
> Best regards,
> --
> Per Larsen <perlarsen@xxxxxxxxxx>
>
>