Re: [PATCH v19 20/20] KVM: arm64: CCA: Control user register access for Realms
From: Gavin Shan
Date: Sun Sep 27 2026 - 21:30:27 EST
On 9/21/26 7:28 AM, Suzuki K Poulose wrote:
From: Jean-Philippe Brucker <jean-philippe@xxxxxxxxxx>
The RMM restricts the access to the register states that the host can
read/modify for a given Realm.
e.g., At VCPU creation, can modify GPRS (x0-x30) and PC.
While servicing SMCCC calls via RSI_HOST_CALL or servicing PSCI
requests.
MMIO emulation in the unprotected space.
Additionally we use the sysreg configuration to advertise/configure the
following Realm parameters, which are required before the Realm Descriptor
:w
is created:
- SVE Vector Length
- Number of HW Breakpoints/Watchpoints
- PMU Counters.
Thus KVM also additionally allows access to ID_AA64DFR0_EL1 and SVE_VLS for
the configuration of Realm creation parameters. We don't support PMUs for
the Realm VMs yet, so PMCR is not exposed.
The RMM makes similar restrictions for reading of the guest's registers
(this is *confidential* compute after all), however we don't impose the
restriction here. This allows the VMM to read (stale) values from the
registers which might be useful to read back the initial values even if
the RMM doesn't provide the latest version. For migration of a realm VM,
a new interface will be needed so that the VMM can receive an
(encrypted) blob of the VM's state.
Reflect the above in KVM_GET_REG_LIST, KVM_SET_ONE_REG calls.
Signed-off-by: Jean-Philippe Brucker <jean-philippe@xxxxxxxxxx>
Co-developed-by: Steven Price <steven.price@xxxxxxx>
Signed-off-by: Steven Price <steven.price@xxxxxxx>
Co-developed-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v18:
- Don't expose PMCR_EL0 to the userspace now, we could do that when we
support PMU
- Fix check patch warnings
Changes since v17:
- Merge related changes into one single patch for the user set/get registers
I have retained the Review tags, as the code hasn't changed, just the patches
were merged into a single one with the same tags.
- Limit KVM_GET_REG_LIST to the allowed CORE registers.
---
arch/arm64/kvm/guest.c | 63 +++++++++++++++++++++++++++++++++++++
arch/arm64/kvm/hypercalls.c | 4 +--
arch/arm64/kvm/sys_regs.c | 28 +++++++++++++----
3 files changed, 87 insertions(+), 8 deletions(-)
Reviewed-by: Gavin Shan <gshan@xxxxxxxxxx>