mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Steven Price <steven.price@arm.com>
To: kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: Steven Price <steven.price@arm.com>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Marc Zyngier <maz@kernel.org>, Will Deacon <will@kernel.org>,
	James Morse <james.morse@arm.com>,
	Oliver Upton <oliver.upton@linux.dev>,
	Suzuki K Poulose <suzuki.poulose@arm.com>,
	Zenghui Yu <yuzenghui@huawei.com>,
	linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org, Joey Gouly <joey.gouly@arm.com>,
	Alexandru Elisei <alexandru.elisei@arm.com>,
	Christoffer Dall <christoffer.dall@arm.com>,
	Fuad Tabba <tabba@google.com>,
	linux-coco@lists.linux.dev,
	Ganapatrao Kulkarni <gankulkarni@os.amperecomputing.com>
Subject: [PATCH v3 20/43] arm64: RME: Allow populating initial contents
Date: Mon, 10 Jun 2024 14:41:39 +0100	[thread overview]
Message-ID: <20240610134202.54893-21-steven.price@arm.com> (raw)
In-Reply-To: <20240610134202.54893-1-steven.price@arm.com>

The VMM needs to populate the realm with some data before starting (e.g.
a kernel and initrd). This is measured by the RMM and used as part of
the attestation later on.

For now only 4k mappings are supported, future work may add support for
larger mappings.

Co-developed-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
---
v3: Minor changes to simplify the code. Make the 4k only RMM mapping
support more obvious with a 'FIXME' in the code.
---
 arch/arm64/kvm/rme.c | 223 +++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 223 insertions(+)

diff --git a/arch/arm64/kvm/rme.c b/arch/arm64/kvm/rme.c
index fd4162af551d..2c4e28b457be 100644
--- a/arch/arm64/kvm/rme.c
+++ b/arch/arm64/kvm/rme.c
@@ -4,6 +4,7 @@
  */
 
 #include <linux/kvm_host.h>
+#include <linux/hugetlb.h>
 
 #include <asm/kvm_emulate.h>
 #include <asm/kvm_mmu.h>
@@ -570,6 +571,216 @@ void kvm_realm_unmap_range(struct kvm *kvm, unsigned long ipa, u64 size,
 		realm_fold_rtt_range(realm, ipa, end);
 }
 
+static int realm_create_protected_data_page(struct realm *realm,
+					    unsigned long ipa,
+					    struct page *dst_page,
+					    struct page *src_page,
+					    unsigned long flags)
+{
+	phys_addr_t dst_phys, src_phys;
+	int ret;
+
+	dst_phys = page_to_phys(dst_page);
+	src_phys = page_to_phys(src_page);
+
+	if (rmi_granule_delegate(dst_phys))
+		return -ENXIO;
+
+	ret = rmi_data_create(virt_to_phys(realm->rd), dst_phys, ipa, src_phys,
+			      flags);
+
+	if (RMI_RETURN_STATUS(ret) == RMI_ERROR_RTT) {
+		/* Create missing RTTs and retry */
+		int level = RMI_RETURN_INDEX(ret);
+
+		ret = realm_create_rtt_levels(realm, ipa, level,
+					      RME_RTT_MAX_LEVEL, NULL);
+		if (ret)
+			goto err;
+
+		ret = rmi_data_create(virt_to_phys(realm->rd), dst_phys, ipa,
+				      src_phys, flags);
+	}
+
+	if (!ret)
+		return 0;
+
+err:
+	if (WARN_ON(rmi_granule_undelegate(dst_phys))) {
+		/* Page can't be returned to NS world so is lost */
+		get_page(dst_page);
+	}
+	return -ENXIO;
+}
+
+static int fold_rtt(struct realm *realm, unsigned long addr, int level)
+{
+	phys_addr_t rtt_addr;
+	int ret;
+
+	ret = realm_rtt_fold(realm, addr, level + 1, &rtt_addr);
+	if (ret)
+		return ret;
+
+	free_delegated_page(realm, rtt_addr);
+
+	return 0;
+}
+
+static int populate_par_region(struct kvm *kvm,
+			       phys_addr_t ipa_base,
+			       phys_addr_t ipa_end,
+			       u32 flags)
+{
+	struct realm *realm = &kvm->arch.realm;
+	struct kvm_memory_slot *memslot;
+	gfn_t base_gfn, end_gfn;
+	int idx;
+	phys_addr_t ipa;
+	int ret = 0;
+	struct page *tmp_page;
+	unsigned long data_flags = 0;
+
+	base_gfn = gpa_to_gfn(ipa_base);
+	end_gfn = gpa_to_gfn(ipa_end);
+
+	if (flags & KVM_ARM_RME_POPULATE_FLAGS_MEASURE)
+		data_flags = RMI_MEASURE_CONTENT;
+
+	idx = srcu_read_lock(&kvm->srcu);
+	memslot = gfn_to_memslot(kvm, base_gfn);
+	if (!memslot) {
+		ret = -EFAULT;
+		goto out;
+	}
+
+	/* We require the region to be contained within a single memslot */
+	if (memslot->base_gfn + memslot->npages < end_gfn) {
+		ret = -EINVAL;
+		goto out;
+	}
+
+	tmp_page = alloc_page(GFP_KERNEL);
+	if (!tmp_page) {
+		ret = -ENOMEM;
+		goto out;
+	}
+
+	mmap_read_lock(current->mm);
+
+	ipa = ipa_base;
+	while (ipa < ipa_end) {
+		struct vm_area_struct *vma;
+		unsigned long map_size;
+		unsigned int vma_shift;
+		unsigned long offset;
+		unsigned long hva;
+		struct page *page;
+		kvm_pfn_t pfn;
+		int level;
+
+		hva = gfn_to_hva_memslot(memslot, gpa_to_gfn(ipa));
+		vma = vma_lookup(current->mm, hva);
+		if (!vma) {
+			ret = -EFAULT;
+			break;
+		}
+
+		/* FIXME: Currently we only support 4k sized mappings */
+		vma_shift = PAGE_SHIFT;
+
+		map_size = 1 << vma_shift;
+
+		ipa = ALIGN_DOWN(ipa, map_size);
+
+		switch (map_size) {
+		case RME_L2_BLOCK_SIZE:
+			level = 2;
+			break;
+		case PAGE_SIZE:
+			level = 3;
+			break;
+		default:
+			WARN_ONCE(1, "Unsupport vma_shift %d", vma_shift);
+			ret = -EFAULT;
+			break;
+		}
+
+		pfn = gfn_to_pfn_memslot(memslot, gpa_to_gfn(ipa));
+
+		if (is_error_pfn(pfn)) {
+			ret = -EFAULT;
+			break;
+		}
+
+		if (level < RME_RTT_MAX_LEVEL) {
+			/*
+			 * A temporary RTT is needed during the map, precreate
+			 * it, however if there is an error (e.g. missing
+			 * parent tables) this will be handled in the
+			 * realm_create_protected_data_page() call.
+			 */
+			realm_create_rtt_levels(realm, ipa, level,
+						RME_RTT_MAX_LEVEL, NULL);
+		}
+
+		page = pfn_to_page(pfn);
+
+		for (offset = 0; offset < map_size && !ret;
+		     offset += PAGE_SIZE, page++) {
+			phys_addr_t page_ipa = ipa + offset;
+
+			ret = realm_create_protected_data_page(realm, page_ipa,
+							       page, tmp_page,
+							       data_flags);
+		}
+		if (ret)
+			goto err_release_pfn;
+
+		if (level == 2)
+			fold_rtt(realm, ipa, level);
+
+		ipa += map_size;
+		kvm_release_pfn_dirty(pfn);
+err_release_pfn:
+		if (ret) {
+			kvm_release_pfn_clean(pfn);
+			break;
+		}
+	}
+
+	mmap_read_unlock(current->mm);
+	__free_page(tmp_page);
+
+out:
+	srcu_read_unlock(&kvm->srcu, idx);
+	return ret;
+}
+
+static int kvm_populate_realm(struct kvm *kvm,
+			      struct kvm_cap_arm_rme_populate_realm_args *args)
+{
+	phys_addr_t ipa_base, ipa_end;
+
+	if (kvm_realm_state(kvm) != REALM_STATE_NEW)
+		return -EINVAL;
+
+	if (!IS_ALIGNED(args->populate_ipa_base, PAGE_SIZE) ||
+	    !IS_ALIGNED(args->populate_ipa_size, PAGE_SIZE))
+		return -EINVAL;
+
+	if (args->flags & ~RMI_MEASURE_CONTENT)
+		return -EINVAL;
+
+	ipa_base = args->populate_ipa_base;
+	ipa_end = ipa_base + args->populate_ipa_size;
+
+	if (ipa_end < ipa_base)
+		return -EINVAL;
+
+	return populate_par_region(kvm, ipa_base, ipa_end, args->flags);
+}
+
 static int find_map_level(struct realm *realm,
 			  unsigned long start,
 			  unsigned long end)
@@ -840,6 +1051,18 @@ int kvm_realm_enable_cap(struct kvm *kvm, struct kvm_enable_cap *cap)
 		r = kvm_init_ipa_range_realm(kvm, &args);
 		break;
 	}
+	case KVM_CAP_ARM_RME_POPULATE_REALM: {
+		struct kvm_cap_arm_rme_populate_realm_args args;
+		void __user *argp = u64_to_user_ptr(cap->args[1]);
+
+		if (copy_from_user(&args, argp, sizeof(args))) {
+			r = -EFAULT;
+			break;
+		}
+
+		r = kvm_populate_realm(kvm, &args);
+		break;
+	}
 	default:
 		r = -EINVAL;
 		break;
-- 
2.34.1


  parent reply	other threads:[~2024-06-10 13:43 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-06-10 13:41 [PATCH v3 00/43] arm64: Support for Arm CCA in KVM Steven Price
2024-06-10 13:41 ` [PATCH v3 01/43] KVM: Prepare for handling only shared mappings in mmu_notifier events Steven Price
2024-06-10 13:41 ` [PATCH v3 02/43] kvm: arm64: pgtable: Track the number of pages in the entry level Steven Price
2024-06-10 13:41 ` [PATCH v3 03/43] kvm: arm64: Include kvm_emulate.h in kvm/arm_psci.h Steven Price
2024-06-10 13:41 ` [PATCH v3 04/43] arm64: RME: Handle Granule Protection Faults (GPFs) Steven Price
2024-06-10 13:41 ` [PATCH v3 05/43] arm64: RME: Add SMC definitions for calling the RMM Steven Price
2024-06-10 13:41 ` [PATCH v3 06/43] arm64: RME: Add wrappers for RMI calls Steven Price
2024-06-10 13:41 ` [PATCH v3 07/43] arm64: RME: Check for RME support at KVM init Steven Price
2024-06-10 13:41 ` [PATCH v3 08/43] arm64: RME: Define the user ABI Steven Price
2024-06-10 13:41 ` [PATCH v3 09/43] arm64: RME: ioctls to create and configure realms Steven Price
2024-06-10 13:41 ` [PATCH v3 10/43] kvm: arm64: Expose debug HW register numbers for Realm Steven Price
2024-06-10 13:41 ` [PATCH v3 11/43] arm64: kvm: Allow passing machine type in KVM creation Steven Price
2024-06-10 13:41 ` [PATCH v3 12/43] arm64: RME: Keep a spare page delegated to the RMM Steven Price
2024-06-10 13:41 ` [PATCH v3 13/43] arm64: RME: RTT tear down Steven Price
2024-06-10 13:41 ` [PATCH v3 14/43] arm64: RME: Allocate/free RECs to match vCPUs Steven Price
2024-06-10 13:41 ` [PATCH v3 15/43] arm64: RME: Support for the VGIC in realms Steven Price
2024-06-10 13:41 ` [PATCH v3 16/43] KVM: arm64: Support timers in realm RECs Steven Price
2024-06-10 13:41 ` [PATCH v3 17/43] arm64: RME: Allow VMM to set RIPAS Steven Price
2024-06-10 13:41 ` [PATCH v3 18/43] arm64: RME: Handle realm enter/exit Steven Price
2024-06-10 13:41 ` [PATCH v3 19/43] KVM: arm64: Handle realm MMIO emulation Steven Price
2024-06-10 13:41 ` Steven Price [this message]
2024-06-10 13:41 ` [PATCH v3 21/43] arm64: RME: Runtime faulting of memory Steven Price
2024-06-10 13:41 ` [PATCH v3 22/43] KVM: arm64: Handle realm VCPU load Steven Price
2024-06-10 13:41 ` [PATCH v3 23/43] KVM: arm64: Validate register access for a Realm VM Steven Price
2024-06-10 13:41 ` [PATCH v3 24/43] KVM: arm64: Handle Realm PSCI requests Steven Price
2024-06-10 13:41 ` [PATCH v3 25/43] KVM: arm64: WARN on injected undef exceptions Steven Price
2024-06-10 13:41 ` [PATCH v3 26/43] arm64: Don't expose stolen time for realm guests Steven Price
2024-06-10 13:41 ` [PATCH v3 27/43] arm64: rme: allow userspace to inject aborts Steven Price
2024-06-10 13:41 ` [PATCH v3 28/43] arm64: rme: support RSI_HOST_CALL Steven Price
2024-06-10 13:41 ` [PATCH v3 29/43] arm64: rme: Allow checking SVE on VM instance Steven Price
2024-06-10 13:41 ` [PATCH v3 30/43] arm64: RME: Always use 4k pages for realms Steven Price
2024-06-10 13:41 ` [PATCH v3 31/43] arm64: rme: Prevent Device mappings for Realms Steven Price
2024-06-10 13:41 ` [PATCH v3 32/43] arm_pmu: Provide a mechanism for disabling the physical IRQ Steven Price
2024-06-10 13:41 ` [PATCH v3 33/43] arm64: rme: Enable PMU support with a realm guest Steven Price
2024-06-10 13:41 ` [PATCH v3 34/43] kvm: rme: Hide KVM_CAP_READONLY_MEM for realm guests Steven Price
2024-06-10 13:41 ` [PATCH v3 35/43] arm64: RME: Propagate number of breakpoints and watchpoints to userspace Steven Price
2024-06-10 13:41 ` [PATCH v3 36/43] arm64: RME: Set breakpoint parameters through SET_ONE_REG Steven Price
2024-06-10 13:41 ` [PATCH v3 37/43] arm64: RME: Initialize PMCR.N with number counter supported by RMM Steven Price
2024-06-10 13:41 ` [PATCH v3 38/43] arm64: RME: Propagate max SVE vector length from RMM Steven Price
2024-06-10 13:41 ` [PATCH v3 39/43] arm64: RME: Configure max SVE vector length for a Realm Steven Price
2024-06-10 13:41 ` [PATCH v3 40/43] arm64: RME: Provide register list for unfinalized RME RECs Steven Price
2024-06-10 13:42 ` [PATCH v3 41/43] arm64: RME: Provide accurate register list Steven Price
2024-06-10 13:42 ` [PATCH v3 42/43] arm64: kvm: Expose support for private memory Steven Price
2024-06-10 13:42 ` [PATCH v3 43/43] KVM: arm64: Allow activating realms Steven Price

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240610134202.54893-21-steven.price@arm.com \
    --to=steven.price@arm.com \
    --cc=alexandru.elisei@arm.com \
    --cc=catalin.marinas@arm.com \
    --cc=christoffer.dall@arm.com \
    --cc=gankulkarni@os.amperecomputing.com \
    --cc=james.morse@arm.com \
    --cc=joey.gouly@arm.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=maz@kernel.org \
    --cc=oliver.upton@linux.dev \
    --cc=suzuki.poulose@arm.com \
    --cc=tabba@google.com \
    --cc=will@kernel.org \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®