Re: [PATCH v22 05/23] KVM: arm64: Track the type of VM in kvm_arch
From: Gavin Shan
Date: Mon Oct 05 2026 - 23:55:54 EST
On 10/5/26 7:07 PM, Suzuki K Poulose wrote:
KVM arm64 has different types of VMs with all the different modes in which
the hypervisor code can be run. e.g., VHE, nVHE, pKVM etc. Then there is
protected VM and normal VMs with pKVM. We might soon add other types,
e.g., Arm CCA Realm. So in an effort to make the handling of these
different types of VMs a bit more friendly to the eyes, add a VM flavor to
the kvm_arch and we could then add handlers for different operations based
on the VM type.
Keep the flavor initialisation at the beginning to allow for the detection
early enough and fail out on any unsupported requests.
With that, add wrappers for checking the "type" of a VM and replace the
existing users with the new wrappers.
Given we already have the construct of "kvm_vm_is_protected" in the core
KVM code, use that for all confidential compute guests including Realms
that we are about to add. Adds __VM_PROTECTED marker vm flavor to draw the
boundary for "protected VMs". In later patches, we would add Realm VMs,
which would also be classified as protected.
Add a explicit helper to detect if a given VM is a "protected" VM under pKVM.
Change the existing users that precisely want to check the VM type. These
include :
- kvm_arch_prepare_memory_region - For preventing memslot changes after
pVM creation.
All the others are retained as a wider check for confidential guest VMs.
These are:
- kvm_vm_ioctl_set_counter_offset - For disallowing timer offset
configuration
- io_mem_abort for dabt handling without valid syndrome information
Both of which are true for Realms too.
Realms support is restricted to VHE host and thus "kvm_vm_is_protected()"
checks in the pkvm hyp specific code doesn't need to change, as the only
protected guests it deals with is "protected pKVM" guests. To tighten this
init_pkvm_hyp_vm() restricts the hyp copy of the vm_flavor to the ones it
supports.
vcpu_is_protected() usage from nVHE hyp code is tricky, as we need to
convert the vcpu->kvm to the HYP VA before checking the flavor. This
involves kern_hyp_va() usage in asm/kvm_host.h. To avoid build breaks,
include asm/kvm_mmu.h to arm64/kvm/mmio.c.
While at it move the psci_version around to keep the structure packed.
Suggested-by: Marc Zyngier <maz@xxxxxxxxxx>
Tested-by: Gavin Shan <gshan@xxxxxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
Changes since v21:
- Drop kern_hyp_va() and restrict nvhe code to always use vcpu_is_protected_pkvm()
- Drop kvm_vm_is_unprotected_pkvm() and open code the check
- Move psci_version field in kvm_arch around to keep the structure packed
---
arch/arm64/include/asm/kvm_host.h | 42 +++++++++++++++++++++++---
arch/arm64/include/asm/kvm_pkvm.h | 4 +--
arch/arm64/kvm/arm.c | 33 ++++++++++++++++----
arch/arm64/kvm/hyp/include/nvhe/pkvm.h | 2 +-
arch/arm64/kvm/hyp/nvhe/pkvm.c | 6 +++-
arch/arm64/kvm/hyp/nvhe/switch.c | 4 +--
arch/arm64/kvm/hyp/nvhe/timer-sr.c | 2 +-
arch/arm64/kvm/mmio.c | 1 +
arch/arm64/kvm/mmu.c | 2 +-
arch/arm64/kvm/pkvm.c | 6 ++--
10 files changed, 79 insertions(+), 23 deletions(-)
Reviewed-by: Gavin Shan <gshan@xxxxxxxxxx>