[PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active

From: Suzuki K Poulose

Date: Tue Sep 29 2026 - 18:21:59 EST


RMM can be deactivated only after all delegated granules have been
reclaimed. If a new kernel is entered while any granules remain in the
Realm PAS, accesses to that memory can raise a Granule Protection Fault
and be fatal to the new kernel.

Crash kexec/kdump needs separate handling. It can be supported only once
the crash kernel can tolerate delegated memory inherited from the primary
kernel. i.e., be able to read the pages safely and fixup the GPF. Until
then disable the kexec completely.

Hibernate has a similar problem. The image cannot be safely saved for
delegated pages, as the RMM doesn't support exporting the pages.

Disable both kexec and hiberation while the RMM is active.

Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v19:
- New patch to disable kexec and hibernation with RMM
---
arch/arm64/kernel/hibernate.c | 6 ++++++
arch/arm64/kernel/machine_kexec.c | 11 +++++++++++
2 files changed, 17 insertions(+)

diff --git a/arch/arm64/kernel/hibernate.c b/arch/arm64/kernel/hibernate.c
index 7bf1174277772..d02f01c17febf 100644
--- a/arch/arm64/kernel/hibernate.c
+++ b/arch/arm64/kernel/hibernate.c
@@ -10,6 +10,7 @@
* Copyright (C) 2006 Rafael J. Wysocki <rjw@xxxxxxx>
*/
#define pr_fmt(x) "hibernate: " x
+#include <linux/arm-rmi-cmds.h>
#include <linux/cpu.h>
#include <linux/kvm_host.h>
#include <linux/pm.h>
@@ -341,6 +342,11 @@ int swsusp_arch_suspend(void)
return -EBUSY;
}

+ if (is_rmm_active()) {
+ pr_err("Can't hibernate: RMM is active.\n");
+ return -EBUSY;
+ }
+
flags = local_daif_save();

if (__cpu_suspend_enter(&state)) {
diff --git a/arch/arm64/kernel/machine_kexec.c b/arch/arm64/kernel/machine_kexec.c
index 8f9bc2327dc85..48f343704cb54 100644
--- a/arch/arm64/kernel/machine_kexec.c
+++ b/arch/arm64/kernel/machine_kexec.c
@@ -6,6 +6,7 @@
* Copyright (C) Huawei Futurewei Technologies.
*/

+#include <linux/arm-rmi-cmds.h>
#include <linux/interrupt.h>
#include <linux/irq.h>
#include <linux/kernel.h>
@@ -59,6 +60,16 @@ int machine_kexec_prepare(struct kimage *kimage)
return -EBUSY;
}

+ /*
+ * We will be able to allow kdump to proceed, once we have the support
+ * for handling GPF from vmcore accesses to delegated pages. Until then
+ * block kexec completely.
+ */
+ if (is_rmm_active()) {
+ pr_err("Can't kexec: RMM is active.\n");
+ return -EBUSY;
+ }
+
return 0;
}

--
2.43.0