Re: [PATCH v23 13/14] KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms
From: Suzuki K Poulose
Date: Thu Oct 08 2026 - 04:59:37 EST
On 07/10/2026 14:45, Fuad Tabba wrote:
Hi Suzuki,
On Wed, 07 Oct 2026 08:35:36 +0100, Suzuki K Poulose
<suzuki.poulose@xxxxxxx> wrote:
pKVM does not trust the host. Realm VMs follow a similar trust model, with
the Realm Management Monitor owning the protected state instead of the
host. Add a helper to identify VMs that run under a host-distrusting
hypervisor.
When I reviewed this in v21, the Realm patches that use this came
later in the same series. Without them, kvm_vm_hyp_is_distrusting() is
true exactly when is_protected_kvm_enabled() is, and protected mode
already doesn't register a GICv2, so this patch doesn't change
anything on its own. Should it move to the series that adds Realms?
But the second part of the changes are required for pKVM today, right ?
and you requested that here. The check as such is useful, except that
it is using kvm_vm_hyp_is_distrusting() rather than is_protected_kvm_enabled(). I don't see this as a problem as this is
not a hotpath anyway.
https://lore.kernel.org/all/CA+EHjTzKjjEuAuoOuzGG0uKyVZE-r+CEreca2H2kEQYuRPpgUw@xxxxxxxxxxxxxx
Cheers
Suzuki>
Cheers,
/fuad