From: Shanker Donthineni <sdonthineni@nvidia.com>
To: Suzuki K Poulose <suzuki.poulose@arm.com>,
kvm@vger.kernel.org, kvmarm@lists.linux.dev
Cc: maz@kernel.org, will@kernel.org, catalin.marinas@arm.com,
linux-kernel@vger.kernel.org,
linux-arm-kernel@lists.infradead.org, steven.price@arm.com,
aneesh.kumar@kernel.org, oupton@kernel.org, gshan@redhat.com,
joey.gouly@arm.com, tabba@google.com, yuzenghui@huawei.com,
linux-coco@lists.linux.dev, gankulkarni@os.amperecomputing.com,
alpergun@google.com, fj0570is@fujitsu.com, WeiLin.Chang@arm.com,
lpieralisi@kernel.org, enju.kohei@fujitsu.com,
sudeep.holla@arm.com, jonathan.cameron@oss.qualcomm.com
Subject: Re: [PATCH v19 6/7] firmware: arm_rmm: Ensure the RMM has GPT entries for memory
Date: Tue, 29 Sep 2026 17:29:41 -0500 [thread overview]
Message-ID: <a27970c6-a7d2-4abc-84c3-7e50225f0a1a@nvidia.com> (raw)
In-Reply-To: <20260924135201.850038-7-suzuki.poulose@arm.com>
Hi Suzuki,
On 9/24/2026 8:52 AM, Suzuki K Poulose wrote:
> External email: Use caution opening links or attachments
>
>
> From: Steven Price <steven.price@arm.com>
>
> The RMM maintains the state of all the granules in the system to make
> sure that the host is abiding by the rules. This state can be maintained
> at different granularity, per page (TRACKING_FINE) or per region
> (TRACKING_COARSE or TRACKING_INTERMEDIATE). The region size depends on the
> underlying "RMI_GRANULE_SIZE". For a "coarse"/"intermediate" region,
> all pages in the region must be of the same state, this implies we need to
> have "fine" tracking for DRAM, so that we can delegate individual pages.
>
> For now we only support a statically carved out memory for tracking
> granules for the "fine" regions. This can be extended in the future to
> allow modifying the tracking granularity and remove the need for a
> static allocation by the firmware.
>
> Similarly, the firmware may create L0 GPT entries describing the total
> address space. But if we change the "PAS" (Physical Address Space) of a
> granule, then the firmware may need to create L1 tables to track the PAS
> at a finer granularity. Linux therefore checks if the platform firmware
> manages the PAR region. i.e., the firmware is in charge of managing the
> L1 GPTs (creation and the required memory for the GPT tables - via static
> carveouts) without host intervention. Support for dynamic GPT creation by
> the host will be added later.
>
> If the firmware requires us to manage the tracking or GPT memory,
> deactivate the RMM and reclaim any memory donated at RMM activation.
>
> Apply the same checks when hotplugged memory is brought online.
>
> Signed-off-by: Steven Price <steven.price@arm.com>
> [ Switch to RMI_GPT_L1_INFO for checking GPTs and deactivate RMM ]
> Co-developed-by: Suzuki K Poulose <suzuki.poulose@arm.com>
> Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com>
> ---
> Changes since v19:
> * Avoid mixing gotos with __free cleanups for arm64_init_rmi()
> Changes since v18:
> * Handle buggy RMM to make forward progress for RMI_GPT_INFO and
> RMI_GRANULE_TRACKING_GET
> * Make sure the memory ranges are not inverted and reject such ranges.
> * Move granule_tracking_get/gpt_info wrappers closer to the callers
> Drop "inline", let the compiler do its job
> Changes since v17:
> * Move wrappers that may not be used elsewhere, out of arm-rmi-cmds.h
> Changes since v16:
> * Check fine tracking and create L1 GPTs for hotplug-added memory.
> * Clarify the L1 GPT setup and move the explanatory comment.
> * Switch to using RMI_GPT_INFO command for checking the GPTs.
> * Deactivate the RMM and reclaim the memory if we can't proceed.
> Changes since v15:
> * Skip firmware-reserved NOMAP memory in rmi_init_metadata()
> * Handle negative error codes from wrappers.
> Changes since v14:
> * Move the implementation into drivers/firmware/arm_rmm.
> Changes since v13:
> * Moved out of KVM
> ---
> drivers/firmware/arm_rmm/rmi.c | 218 ++++++++++++++++++++++++++++++++-
> include/linux/arm-rmi-cmds.h | 2 +
> 2 files changed, 219 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/firmware/arm_rmm/rmi.c b/drivers/firmware/arm_rmm/rmi.c
> index 0859f256e192b..1a8f3debd844a 100644
> --- a/drivers/firmware/arm_rmm/rmi.c
> +++ b/drivers/firmware/arm_rmm/rmi.c
> @@ -5,6 +5,7 @@
>
> #include <linux/cpufeature.h>
> #include <linux/memblock.h>
> +#include <linux/memory.h>
> #include <linux/arm-rmi-cmds.h>
> #include <linux/slab.h>
>
> @@ -13,6 +14,7 @@
>
> /* RMM defines RmiFeatureRegister0 to RmiFeatureRegister5. */
> static unsigned long rmi_feat_reg_cache[5] __ro_after_init;
> +static bool arm64_rmi_is_available;
>
> /**
> * rmi_granule_range_undelegate() - Undelegate a range of granules
> @@ -817,6 +819,210 @@ static int rmi_configure(void)
> return ret;
> }
>
> +/**
> + * rmi_granule_tracking_get() - Get configuration of a Granule tracking region
> + * @start: Base PA of the tracking region
> + * @end: End of the PA region
> + * @out_category: Memory category
> + * @out_state: Tracking region state
> + * @out_top: Top of the memory region
> + *
> + * Return: RMI return code
> + */
> +static int rmi_granule_tracking_get(unsigned long start,
> + unsigned long end,
> + unsigned long *out_category,
> + unsigned long *out_state,
> + unsigned long *out_top)
> +{
> + struct arm_smccc_1_2_regs regs = {
> + SMC_RMI_GRANULE_TRACKING_GET, start, end,
> + };
> +
> + rmi_smccc_invoke(®s);
> +
> + if (regs.a0 != RMI_SUCCESS)
> + return regs.a0;
> +
> + if (out_category)
> + *out_category = regs.a1;
> + if (out_state)
> + *out_state = regs.a2;
> + if (out_top)
> + *out_top = regs.a3;
> +
> + return RMI_SUCCESS;
> +}
> +
> +/*
> + * Make sure the area is tracked by RMM at FINE granularity.
> + * We do not support changing the tracking yet.
> + */
> +static int rmi_verify_memory_tracking(phys_addr_t start, phys_addr_t end)
> +{
> + while (start < end) {
> + unsigned long ret, category, state, next;
> +
> + ret = rmi_granule_tracking_get(start, end, &category, &state, &next);
> + if (ret != RMI_SUCCESS)
> + return -ENOMEM;
> +
> + if (WARN_ON(next <= start))
> + return -ENXIO;
> +
> + if (state != RMI_TRACKING_FINE ||
> + category != RMI_MEM_CATEGORY_CONVENTIONAL) {
> + /* TODO: Set granule tracking in this case */
> + pr_err("Granule tracking for region isn't fine/conventional: %llx-%lx\n",
> + start, next);
> + return -ENODEV;
> + }
> + start = next;
> + }
> +
> + return 0;
> +}
> +
> +/*
> + * rmi_gpt_info - Query the GPT info for the given PAR.
> + * @start: Base of the physical address region
> + * @end: Top of the physical address region
> + * @out_top: Top of the physical address region for which
> + * the GPT @out_gpt_par_state is valid
> + * @out_gpt_par_state: State of the GPT covered by [start, out_top)
> + */
> +static long rmi_gpt_info(unsigned long start, unsigned long end,
> + unsigned long *out_top,
> + unsigned long *out_gpt_par_state)
> +{
> + struct arm_smccc_1_2_regs regs = {
> + SMC_RMI_GPT_INFO, start, end,
> + };
> +
> + rmi_smccc_invoke(®s);
> + if (regs.a0 != RMI_SUCCESS)
> + return regs.a0;
> +
> + if (out_top)
> + *out_top = regs.a1;
> + if (out_gpt_par_state)
> + *out_gpt_par_state = regs.a2;
> +
> + return RMI_SUCCESS;
> +}
> +
> +/*
> + * We do not support creating L1 GPTs yet. So, make sure that
> + * all the regions are managed by the firmware.
> + */
> +static int rmi_verify_gpt_firmware_managed(phys_addr_t start, phys_addr_t end)
> +{
> + unsigned long l0gpt_sz;
> + unsigned long next, par_state;
> +
> + l0gpt_sz = 1UL << (30 + FIELD_GET(RMI_FEATURE_REGISTER_1_L0GPTSZ,
> + rmi_feat_reg(1)));
> + start = ALIGN_DOWN(start, l0gpt_sz);
> + end = ALIGN(end, l0gpt_sz);
> +
> + while (start < end) {
> + long ret = rmi_gpt_info(start, end, &next, &par_state);
> +
> + if (ret != RMI_SUCCESS)
> + return -ENOMEM;
> +
> + if (WARN_ON(next <= start))
> + return -ENXIO;
> +
> + if (par_state != RMI_GPT_PAR_PLAT) {
> + pr_err("GPT for the region is not managed by firmware %llx-%lx\n",
> + start, next);
> + return -ENOMEM;
Accepting only RMI_GPT_PAR_PLAT rules out the host ever creating its own
L1 GPTs. On NVIDIA platforms the PARs backing system RAM come up as
RMI_GPT_PAR_HOST_NOT_CREATED, so this returns -ENOMEM and CCA cannot be
enabled at all.
With local changes to promote granule tracking via RMI_GRANULE_TRACKING_SET
and to create the host L1 GPTs, I was able to boot a Realm with multiple
vCPUs and exercise basic boot functionality on NVIDIA silicon.
-Shanker
> + }
> + start = next;
> + }
> +
> + return 0;
> +}
> +
> +static int rmi_prepare_memory(phys_addr_t start, phys_addr_t end)
> +{
> + int ret;
> +
> + if (start >= end)
> + return -EINVAL;
> +
> + ret = rmi_verify_memory_tracking(start, end);
> + if (ret)
> + return ret;
> +
> + return rmi_verify_gpt_firmware_managed(start, end);
> +}
> +
> +static int rmi_init_metadata(void)
> +{
> + phys_addr_t start, end;
> + struct memblock_region *r;
> +
> + for_each_mem_region(r) {
> + int ret;
> +
> + /* Firmware-reserved NOMAP regions are not usable system RAM */
> + if (memblock_is_nomap(r))
> + continue;
> +
> + start = PAGE_ALIGN(r->base);
> + end = PAGE_ALIGN_DOWN(r->base + r->size);
> + /* Too small ? */
> + if (start >= end)
> + continue;
> +
> + ret = rmi_prepare_memory(start, end);
> + if (ret)
> + return ret;
> + }
> +
> + return 0;
> +}
> +
> +static int rmi_memory_notifier(struct notifier_block *nb,
> + unsigned long action, void *data)
> +{
> + struct memory_notify *arg = data;
> + phys_addr_t start, end;
> + int ret;
> +
> + if (action != MEM_GOING_ONLINE)
> + return NOTIFY_DONE;
> +
> + start = PFN_PHYS(arg->start_pfn);
> + end = PFN_PHYS(arg->start_pfn + arg->nr_pages);
> + ret = rmi_prepare_memory(start, end);
> +
> + return notifier_from_errno(ret);
> +}
> +
> +static struct notifier_block rmi_memory_nb = {
> + .notifier_call = rmi_memory_notifier,
> +};
> +
> +bool is_rmi_available(void)
> +{
> + return arm64_rmi_is_available;
> +}
> +EXPORT_SYMBOL_GPL(is_rmi_available);
> +
> +static int rmi_init_memory(void)
> +{
> + int ret;
> +
> + ret = rmi_init_metadata();
> + if (ret)
> + return ret;
> +
> + return register_memory_notifier(&rmi_memory_nb);
> +}
> +
> static int __init arm64_init_rmi(void)
> {
> int ret;
> @@ -843,9 +1049,19 @@ static int __init arm64_init_rmi(void)
> if (ret) {
> pr_err("RMM activate failed (%d)\n", ret);
> ret = ret < 0 ? ret : -ENXIO;
> + return ret;
> }
>
> - return ret;
> + ret = rmi_init_memory();
> + if (ret) {
> + /* Deactivate the RMM */
> + WARN_ON(rmi_sro_memxfer_cmd(sro, GFP_KERNEL, SMC_RMI_RMM_DEACTIVATE));
> + return ret;
> + }
> +
> + arm64_rmi_is_available = true;
> + pr_info("RMI configured\n");
> + return 0;
> }
>
> /*
> diff --git a/include/linux/arm-rmi-cmds.h b/include/linux/arm-rmi-cmds.h
> index b03974fd8168c..5b177bb176326 100644
> --- a/include/linux/arm-rmi-cmds.h
> +++ b/include/linux/arm-rmi-cmds.h
> @@ -70,6 +70,8 @@ static inline int rmi_undelegate_page(phys_addr_t phys)
> return rmi_undelegate_range(phys, PAGE_SIZE);
> }
>
> +bool is_rmi_available(void);
> +
> long rmi_sro_memxfer_execute(struct rmi_sro_state *sro, gfp_t gfp);
> void rmi_sro_free(struct rmi_sro_state *sro);
> long rmi_sro_execute(struct arm_smccc_1_2_regs *regs);
> --
> 2.43.0
>
next prev parent reply other threads:[~2026-09-29 22:29 UTC|newest]
Thread overview: 60+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 13:51 [PATCH v19 0/7] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 1/7] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-09-24 16:57 ` Jonathan Cameron
2026-09-24 22:15 ` Suzuki K Poulose
2026-09-24 17:05 ` Ackerley Tng
2026-09-24 22:49 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 2/7] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-09-24 16:58 ` Jonathan Cameron
2026-09-25 0:00 ` Gavin Shan
2026-09-25 8:51 ` Suzuki K Poulose
2026-09-25 5:43 ` Gavin Shan
2026-09-25 8:50 ` Suzuki K Poulose
2026-09-25 10:42 ` Catalin Marinas
2026-09-25 15:23 ` Suzuki K Poulose
2026-09-27 9:29 ` Marc Zyngier
2026-09-28 8:05 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 3/7] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-09-24 17:03 ` Jonathan Cameron
[not found] ` <d4b768e5-c942-43cf-aea2-c266a8bab353@oss.qualcomm.com>
2026-09-25 14:56 ` Suzuki K Poulose
2026-09-26 13:38 ` Venkata Rao Kakani
2026-09-25 0:03 ` Gavin Shan
2026-09-24 13:51 ` [PATCH v19 4/7] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-09-24 19:13 ` Jonathan Cameron
2026-09-24 23:10 ` Suzuki K Poulose
2026-09-25 5:24 ` Gavin Shan
2026-09-29 12:52 ` Suzuki K Poulose
2026-09-25 11:50 ` Catalin Marinas
2026-09-25 15:11 ` Suzuki K Poulose
2026-09-28 9:28 ` Catalin Marinas
2026-09-28 10:13 ` Suzuki K Poulose
2026-09-28 17:28 ` Catalin Marinas
2026-09-28 20:45 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 5/7] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-09-25 12:17 ` Catalin Marinas
2026-09-25 15:02 ` Suzuki K Poulose
2026-09-25 15:34 ` Alper Gun
2026-09-25 16:42 ` Catalin Marinas
2026-09-25 17:50 ` Suzuki K Poulose
2026-09-28 9:08 ` Suzuki K Poulose
2026-09-28 13:55 ` Suzuki K Poulose
2026-09-28 18:01 ` Catalin Marinas
2026-09-28 18:28 ` Suzuki K Poulose
2026-09-29 11:15 ` Catalin Marinas
2026-09-24 13:52 ` [PATCH v19 6/7] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-09-24 21:38 ` Jonathan Cameron
2026-09-24 23:30 ` Suzuki K Poulose
2026-09-25 15:30 ` Jonathan Cameron
2026-09-25 0:07 ` Gavin Shan
2026-09-29 11:01 ` Catalin Marinas
2026-09-29 12:15 ` Suzuki K Poulose
2026-09-29 22:17 ` Shanker Donthineni
2026-09-29 22:25 ` Suzuki K Poulose
2026-09-29 22:29 ` Shanker Donthineni [this message]
2026-09-24 13:52 ` [PATCH v19 7/7] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-09-25 11:56 ` Catalin Marinas
2026-09-29 12:15 ` Suzuki K Poulose
2026-09-25 6:29 ` [PATCH v19 0/7] firmware: arm_rmm: Add RMM v2.0 base RMI support Gavin Shan
2026-09-25 9:03 ` Suzuki K Poulose
2026-09-29 10:50 ` Catalin Marinas
2026-09-29 12:14 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a27970c6-a7d2-4abc-84c3-7e50225f0a1a@nvidia.com \
--to=sdonthineni@nvidia.com \
--cc=WeiLin.Chang@arm.com \
--cc=alpergun@google.com \
--cc=aneesh.kumar@kernel.org \
--cc=catalin.marinas@arm.com \
--cc=enju.kohei@fujitsu.com \
--cc=fj0570is@fujitsu.com \
--cc=gankulkarni@os.amperecomputing.com \
--cc=gshan@redhat.com \
--cc=joey.gouly@arm.com \
--cc=jonathan.cameron@oss.qualcomm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=steven.price@arm.com \
--cc=sudeep.holla@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®