mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v20 0/9] firmware: arm_rmm: Add RMM v2.0 base RMI support
@ 2026-09-29 22:16 Suzuki K Poulose
  2026-09-29 22:16 ` [PATCH v20 1/9] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
                   ` (8 more replies)
  0 siblings, 9 replies; 23+ messages in thread
From: Suzuki K Poulose @ 2026-09-29 22:16 UTC (permalink / raw)
  To: kvm, kvmarm
  Cc: maz, will, catalin.marinas, linux-kernel, linux-arm-kernel,
	steven.price, aneesh.kumar, oupton, gshan, joey.gouly, tabba,
	yuzenghui, linux-coco, gankulkarni, sdonthineni, alpergun,
	fj0570is, WeiLin.Chang, lpieralisi, enju.kohei, sudeep.holla,
	jonathan.cameron, Suzuki K Poulose

This series adds the generic firmware layer for talking to the Realm
Management Monitor (RMM), as specified by the RMM v2.0-bet3
specification[1]. It is the first part of the Arm CCA host support that
was previously posted as part of the larger KVM series.

The split allows this RMM support to be used as a base for other work,
including Aneesh's PCI IDE support with Arm CCA RMM as the TSM,
 without depending on the KVM Realm support that will follow as separate
 series. (See more on that below)

The series adds:

 * The RMI SMC definitions and direct-call wrappers.

 * RMM discovery and version checks during firmware init.

 * RMM host configuration, including the host page size.

 * Stateful RMI Operation (SRO) infrastructure for commands which the RMM
   can complete across multiple SMC calls while requesting or returning
   memory to the host.

 * Verification that granule tracking is available at fine granularity.
   Fine-grained tracking allows each granule in the system to be tracked
   independently, which is required before individual granules can be
   delegated. A future series will add support for dynamically supplying
   memory to the RMM for this tracking.

 * Support for fully firmware-managed systems, where the Granule Protection
   Tables for memory regions are allocated and managed by firmware. RMM v2.0
   also allows dynamic GPT creation on demand; support for that will be added
   in a later series.

 * Wrappers for the RMI commands that are used for managing the "Realm VM"
   lifecycle. This is added in to make it easier for the on-going KVM support
   to evolve in parallel pieces.

If the platform firmware cannot manage the granule tracking or the GPTs, we
bail out and deactivate the RMM, reclaiming any memory that we have donated.

The RMM v2.0 spec introduces Stateful RMI Operations (SROs), which allow
the RMM to complete an operation over several SMC calls while requesting
or returning memory to the host. This allows interrupts to be handled in
the middle of an operation and lets the RMM dynamically allocate memory
for internal tracking purposes. For example, RMI_REC_CREATE no longer
needs auxiliary granules to be provided up front, and can instead
request memory during the operation.

This series applies on v7.3-rc2 and a branch is available at [2]. The KVM
CCA support that builds on this series is available at [3] as an integration
branch. The KVM support depends on guest-memfd-in-place conversion support v13
from Ackerley [4], we plan to split that into parts, which apply cleanly on
v7.3-rcx without any dependency and is in progress. This will be made available
as soon as it is ready. Until then [3] shows how this base series enables KVM
CCA support. You may find the tf-RMM [5] and kvmtool support [6] below.
The kvm integration branch has been tested with kvm-unit-tests [7] and Linux
kernel booting with PCI device assigned as an untrusted device.

[1] RMM spec : https://support.arm.com/documentation/den0137/2-0bet3/
[2] This series: https://gitlab.arm.com/linux-arm/linux-cca.git cca/cca-host/fw_rmm/v20
[3] KVM CCA v21 integration branch: https://gitlab.arm.com/linux-arm/linux-cca.git cca/cca/cca-host/kvm-v21/integration
[4] Gmem inplace conversion https://github.com/googleprodkernel/linux-cc/tree/guest_memfd-inplace-conversion-v13
[5] TF-RMM https://git.trustedfirmware.org/TF-RMM/tf-rmm.git main (commit: 134266ae)
[6] kvmtool https://gitlab.arm.com/linux-arm/kvmtool-cca.git tag:cca-kvm-v20 (Also cca/kvm-v18)
[7] kvm-unit-tests https://gitlab.arm.com/linux-arm/kvm-unit-tests-cca.git tag: cca-rmm-v2.0

Known issues: RMMv2.0 spec.
==========================
Here are some of the known issues affecting the code here. I have included the
ticket number associated with the issues, which will be available in the RMM
spec, when a public release is available. (So that it is easier to see if the
issues has been fixed in the spec and easily spot them)

 * RmiOpMemDonateReq:count (Uint14) is incompatible with RmiAddrRangeDesc4KB
  (Uint10) and RmiAddrRangeDesc16KB (Uint12). i.e., a larger contiguous request
  may not be satisfiable by the host. This is resolved in the RMM spec, by clamping
  the upper limit on the number to match the RmiAddrRangeDesc* and will be published
  in the next release. (FENIMORE-1744)
 * RMM to clarify the scenarios that triggers the RMI_BLOCKED and the
   recommendations to limit the cases. (FENIMORE-1783)
 * RMM to clarify the "PE bound" SRO context pool to really mean global pool
   (FENIMORE-1802)
 * Clarify RMI_RTT_DATA_UNMAP, output_count, output_range are only valid when
   result is RMI_SUCCESS (FENIMORE-1746)

Changes since v19:
 https://lore.kernel.org/all/0260924135201.850038-1-suzuki.poulose@arm.com

 ** Patch 1 - RMI SMCCC definitions
  - Fold 'padding' only union in rec_exit to the previous group of fields
  - Add static_assert to make sure the struct field offsets match the spec
  - Rename 'padding' fields to 'sizer' which they really are
  - Add MAINTAINERS entry for the new header file under ARM64
 ** Patch 2 - firmware: arm_rmm: Check for RMI support at init
  - Fix comment : s/RmiFeatureRegister5/RmiFeatureRegister4/
  - rmi_feat_reg() s/unsigned long/unsigned int for index
  - linux/arm-rmi-cmds.h -> Mark the "#endif"
  - Use += rmi.o in Makefile
  - Mask the ID_AA64PFR0_EL1_RME field for KVM guests
  - Add MAINTAINERS entry for header file and arm_rmm directory
 ** Patch 3 - firmware: arm_rmm: Configure the RMM with the host's page size
  - Don't initialize 'ret' in rmi_configure, add explicit return 0/-EINVAL
 ** Patch 4 - firmware: arm_rmm: Add support for SRO
  - Fix typos s/-ECANCELLED/ECANCELED/ rmi_sro_execute()
  - Drop duplicate, incorrect assignment of sro_handle in rmi_sro_execute()
  - Drop int i, redeclartion in for() for rmi_sro_donate_noncontig()
  - Drop donated_granules for rmi_sro_donate_contig()
  - Drop "inline" and be consistent with the rest of the code
  - Avoid nesting if..else in rmi_*delegate_range by breaking out on error
  - Consistent styling in comments, wrap to 80space, spelling corrections
  - s/\*\*/\*/ for comment above functions
  - Reorder the functions to appear as rmi_*_delegate* followed by rmi_*_undelegate*
  - WARN_ON if the RMM MemDonateReq:count exceeds the RmiAddrRangeDesc:count
  - Reject requests larger than MAX_PAGE_ORDER
  - Reject "donate" requests with states other than DELEGATED or UNDELEGATED
 ** Patch 6 - firmware: arm_rmm: Ensure the RMM has GPT entries for memory
  - Wrap comments to 80spaces.
  - Add a comment on ALIGN_DOWN the end of memory range.
  - Add is_rmm_active() to report if the RMM is in ACTIVE state
  - Switch errors to -ENODEV from -ENOMEM when RMM doesn't manage the region
  - Print error messages when RMI_GPT_INFO/RMI_GRANULE_TRACKIN_GET fails
 ** Patch 7 : arm64: Block hibernate and kexec while RMM is active
  - New patch in v20.
 ** Patch 8 : firmware: arm_rmm: Add wrappers for Realm related RMI commands
  - Use rmi_sro_memxfr_command() for rec_create - Catalin
 ** Patch 9 : firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE
  - New patch in v20, relax the memory hotplug checking

Changes since v18:
 - Use _ULL version for masks spanning beyond 32bits
 - Add GENMASK, FIELD_* friends for RMI_ABI_VERSION_*
 - Consistent naming for masks and order the fields by MSB to LSB (missed out
   ones.
 - Rename RMI_RETURN_ => RMI_RESULT, RMI_RETURN_INDEX => RMI_RESULT_DATA_LEVEL
   and add relevant Rmi types for clear indication on what they represent.
 - Read and cache all implemented RmiFeatureRegisters (5), use ARRAY_SIZE()
   droping the macro for the number of registers.
 - Fold sinlge caller rmi calls to the caller (rmi_features)
 - Drop "default y" from Kconfig
 - Don't loop forever with RMI_BLOCKED, instead retry once and return to the
   caller.
 - Move rmi_config_set closer to rmi_configure.
 - Use __free() cleanup for rmm_config object
 - SRO: Clamp the mem donate request count to RMI_MAX_ADDR_LIST (the max we can
   hold in the struct sro, to prevent overflows in handling non_contig requests
 - Donate gathered memory when sro list runs out of space for non_contig case
   and donate the rest in the next iteration
 - Fix handling of buggy RMM for rmi_delegate_range()
 - Add comments for the exported interfaces rmi_delegate_range(), rmi_undelegate_range()
 - Move rmi_granule_{,un}delegate_range() closer to their callers
 - Clarify the requirements for rmi_granule_delegate_range()
 - Fix return result to -ENXIO if the MEM_OP is unknown
 - Handle unsupported RMI_OP_MEM_CONDITIONAL, bail out early
 - Rename "out" lable to mem_donate, where the actual donation happens
 - Switch to use readable loop construct in donate_noncontig, add comments
   to explain what we do.
 - Add comment, make the code reader friendly for caching the entries not
   consumed by RMM.
 - Add documentatoin for rmi_sro_execute()
 - Avoid mixing gotos with __free cleanups for arm64_init_rmi()
 - Convert the remaining nested if for results to early return based.
 - Pass out_top for RMI_ERROR_RTT in rmi_rtt_destroy() [ This boosts the
   Realm tear down ]


Steven Price (7):
  firmware: arm_rmm: Add SMC definitions for calling the RMM
  firmware: arm_rmm: Check for RMI support at init
  firmware: arm_rmm: Configure the RMM with the host's page size
  firmware: arm_rmm: Add support for SRO
  firmware: arm_rmm: Activate the RMM
  firmware: arm_rmm: Ensure the RMM has GPT entries for memory
  firmware: arm_rmm: Add wrappers for Realm related RMI commands

Suzuki K Poulose (2):
  arm64: Block hibernate and kexec while RMM is active
  firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE

 MAINTAINERS                       |    3 +
 arch/arm64/Kconfig                |    1 +
 arch/arm64/kernel/cpufeature.c    |    1 +
 arch/arm64/kernel/hibernate.c     |    6 +
 arch/arm64/kernel/machine_kexec.c |   11 +
 arch/arm64/kvm/sys_regs.c         |    2 +
 drivers/firmware/Kconfig          |    1 +
 drivers/firmware/Makefile         |    1 +
 drivers/firmware/arm_rmm/Kconfig  |   25 +
 drivers/firmware/arm_rmm/Makefile |    1 +
 drivers/firmware/arm_rmm/rmi.c    | 1129 +++++++++++++++++++++++++++++
 include/linux/arm-rmi-cmds.h      |  567 +++++++++++++++
 include/linux/arm-smccc-rmi.h     |  516 +++++++++++++
 13 files changed, 2264 insertions(+)
 create mode 100644 drivers/firmware/arm_rmm/Kconfig
 create mode 100644 drivers/firmware/arm_rmm/Makefile
 create mode 100644 drivers/firmware/arm_rmm/rmi.c
 create mode 100644 include/linux/arm-rmi-cmds.h
 create mode 100644 include/linux/arm-smccc-rmi.h

-- 
2.43.0


^ permalink raw reply	[flat|nested] 23+ messages in thread

end of thread, other threads:[~2026-09-30 16:06 UTC | newest]

Thread overview: 23+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 22:16 [PATCH v20 0/9] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 1/9] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-09-30  9:51   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 2/9] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 3/9] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-09-30 11:10   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 4/9] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-09-30 13:15   ` Catalin Marinas
2026-09-30 13:48     ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 5/9] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-09-30 13:20   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 6/9] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-09-30 13:39   ` Catalin Marinas
2026-09-30 14:44   ` Sudeep Holla
2026-09-30 15:55     ` Suzuki K Poulose
2026-09-29 22:16 ` [PATCH v20 7/9] arm64: Block hibernate and kexec while RMM is active Suzuki K Poulose
2026-09-30 16:06   ` Jonathan Cameron
2026-09-29 22:16 ` [PATCH v20 8/9] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-09-30 15:51   ` Catalin Marinas
2026-09-29 22:16 ` [PATCH v20 9/9] firmware: arm_rmm: hotplug: Skip memory added to ZONE_MOVABLE Suzuki K Poulose
2026-09-30 12:22   ` David Hildenbrand (Arm)
2026-09-30 12:47     ` Suzuki K Poulose
2026-09-30 15:53   ` Catalin Marinas

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®