[PATCH v22 17/23] KVM: arm64: CCA: Add bare minimal S2 operations for Realm

From: Suzuki K Poulose

Date: Mon Oct 05 2026 - 05:17:48 EST


Add bare minimal MMU operation hooks for Realms. The mem_abort handling
is chosen as the default KVM variant. However this cannot be reached for
Realms yet and we would need real RMI command support to make it fully
functional. Similarly, unmapping stage2 requires RMI command support.
Until then reuse follow protected pKVM hook and ignore unmapping.
This will be addressed in the later series.

RMM takes care of the TLB flushing as required, when the Stage2 is
modified. So host doesn't need to do anything explicitly. RMM doesn't
support access flags for the stage2, even for the shared IPA.

Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v21:
- Reuse no_age_gfn for Realms. Also use no_stage2_unmap_range for
now, until we get proper RMI backed driver.
---
arch/arm64/kvm/mmu.c | 23 +++++++++++++++++++++++
1 file changed, 23 insertions(+)

diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c
index 909ea3f545e83..58bc6a85f48b4 100644
--- a/arch/arm64/kvm/mmu.c
+++ b/arch/arm64/kvm/mmu.c
@@ -180,6 +180,12 @@ static int kvm_vm_flush_remote_tlbs(struct kvm *kvm)
return 0;
}

+static int realm_flush_remote_tlbs(struct kvm *kvm)
+{
+ /* Nothing to do here, RMM does the job */
+ return 0;
+}
+
/**
* kvm_arch_flush_remote_tlbs() - flush all VM TLB entries for v7/8
* @kvm: pointer to kvm structure.
@@ -207,6 +213,13 @@ static int kvm_vm_flush_remote_tlbs_range(struct kvm *kvm,
return 0;
}

+static int realm_flush_remote_tlbs_range(struct kvm *kvm,
+ gfn_t gfn, u64 nr_pages)
+{
+ /* Nothing to do here, RMM does the job */
+ return 0;
+}
+
int kvm_arch_flush_remote_tlbs_range(struct kvm *kvm,
gfn_t gfn, u64 nr_pages)
{
@@ -2896,6 +2909,16 @@ static const struct kvm_vm_s2_ops kvm_default_vm_s2_ops = {
.vm_mem_abort = kvm_vm_mem_abort,
};

+static const struct kvm_vm_s2_ops realm_vm_s2_ops = {
+ .vm_flush_remote_tlbs = realm_flush_remote_tlbs,
+ .vm_flush_remote_tlbs_range = realm_flush_remote_tlbs_range,
+ .vm_age_gfn = no_age_gfn,
+ .vm_test_age_gfn = no_age_gfn,
+ /* Until we get proper support for unmap */
+ .vm_stage2_unmap_range = no_stage2_unmap_range,
+ .vm_mem_abort = kvm_vm_mem_abort,
+};
+
#define KVM_VM_S2_OPS(flavor, ops) \
[flavor] = &(ops)

--
2.43.0