[PATCH v5 10/10] arm64: realm: Expose the CCA shared granule size through mem_encrypt ops
From: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Date: 2026-07-06 06:05:59
Also in:
kvmarm, linux-coco, linux-iommu, lkml
Subsystem:
arm64 port (aarch64 architecture), the rest · Maintainers:
Catalin Marinas, Will Deacon, Linus Torvalds
CCA guests must align shared/private memory transitions to the size reported by the host for IPA state changes. This size can be larger than PAGE_SIZE, so allowing a guest to convert only a PAGE_SIZE-sized subrange can leave the remaining part of that host-sized range in the wrong state. Cache the RHI-reported IPA sate change alignment during Realm initialization and expose it through a new arm64 mem_encrypt callback. Use PAGE_SIZE as the default shared granule size when no backend callback is registered. Validate both the address and byte size passed to set_memory_encrypted() and set_memory_decrypted() against mem_cc_shared_granule_size() before calling into the backend. This prevents callers from converting only part of a host-managed page. Signed-off-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org> --- arch/arm64/include/asm/mem_encrypt.h | 4 ++++ arch/arm64/kernel/rsi.c | 13 ++++++++++- arch/arm64/mm/mem_encrypt.c | 32 ++++++++++++++++++++++++---- 3 files changed, 44 insertions(+), 5 deletions(-)
diff --git a/arch/arm64/include/asm/mem_encrypt.h b/arch/arm64/include/asm/mem_encrypt.h
index f6325f30e844..5018581fed87 100644
--- a/arch/arm64/include/asm/mem_encrypt.h
+++ b/arch/arm64/include/asm/mem_encrypt.h@@ -9,6 +9,7 @@ struct device; struct arm64_mem_crypt_ops { int (*encrypt)(unsigned long addr, int numpages); int (*decrypt)(unsigned long addr, int numpages); + size_t (*cc_shared_granule_size)(void); }; int arm64_mem_crypt_ops_register(const struct arm64_mem_crypt_ops *ops);
@@ -17,6 +18,9 @@ int set_memory_encrypted(unsigned long addr, int numpages); int set_memory_decrypted(unsigned long addr, int numpages); int __set_memory_enc_dec(unsigned long addr, int numpages, bool encrypt); +#define mem_cc_shared_granule_size mem_cc_shared_granule_size +size_t mem_cc_shared_granule_size(void); + static inline bool force_dma_unencrypted(struct device *dev) { return is_realm_world();
diff --git a/arch/arm64/kernel/rsi.c b/arch/arm64/kernel/rsi.c
index f52f240bb44c..54fb929067c9 100644
--- a/arch/arm64/kernel/rsi.c
+++ b/arch/arm64/kernel/rsi.c@@ -20,6 +20,7 @@ static struct realm_config config; static struct kobject *cca_kobj; +static unsigned long ipa_state_change_granule_size; unsigned long prot_ns_shared; EXPORT_SYMBOL(prot_ns_shared);
@@ -168,9 +169,17 @@ static int realm_set_memory_decrypted(unsigned long addr, int numpages) return ret; } +static size_t realm_cc_shared_granule_size(void) +{ + if (is_realm_world()) + return ipa_state_change_granule_size; + return PAGE_SIZE; +} + static const struct arm64_mem_crypt_ops realm_crypt_ops = { .encrypt = realm_set_memory_encrypted, .decrypt = realm_set_memory_decrypted, + .cc_shared_granule_size = realm_cc_shared_granule_size, }; static int realm_register_memory_enc_ops(void)
@@ -180,7 +189,7 @@ static int realm_register_memory_enc_ops(void) /* we need an aligned struct for rsi_host_call. slab is not yet ready */ static struct rsi_host_call hostconf_call __initdata; -static unsigned long __maybe_unused __init get_ipa_state_change_alignment(void) +static unsigned long __init get_ipa_state_change_alignment(void) { long ret; unsigned long shared_granule_size;
@@ -230,6 +239,8 @@ void __init arm64_rsi_init(void) return; if (WARN_ON(rsi_get_realm_config(lm_alias(&config)))) return; + + ipa_state_change_granule_size = get_ipa_state_change_alignment(); prot_ns_shared = __phys_to_pte_val(BIT(config.ipa_bits - 1)); if (arm64_ioremap_prot_hook_register(realm_ioremap_hook))
diff --git a/arch/arm64/mm/mem_encrypt.c b/arch/arm64/mm/mem_encrypt.c
index ee3c0ab04384..69783c6a3c08 100644
--- a/arch/arm64/mm/mem_encrypt.c
+++ b/arch/arm64/mm/mem_encrypt.c@@ -17,8 +17,7 @@ #include <linux/compiler.h> #include <linux/err.h> #include <linux/mm.h> - -#include <asm/mem_encrypt.h> +#include <linux/mem_encrypt.h> static const struct arm64_mem_crypt_ops *crypt_ops;
@@ -33,18 +32,43 @@ int arm64_mem_crypt_ops_register(const struct arm64_mem_crypt_ops *ops) int set_memory_encrypted(unsigned long addr, int numpages) { - if (likely(!crypt_ops) || WARN_ON(!PAGE_ALIGNED(addr))) + unsigned long size = (unsigned long)numpages << PAGE_SHIFT; + + if (likely(!crypt_ops)) return 0; + if (WARN_ON(!IS_ALIGNED(addr, mem_cc_shared_granule_size()))) + return -EINVAL; + + if (WARN_ON(!IS_ALIGNED(size, mem_cc_shared_granule_size()))) + return -EINVAL; + return crypt_ops->encrypt(addr, numpages); } EXPORT_SYMBOL_GPL(set_memory_encrypted); int set_memory_decrypted(unsigned long addr, int numpages) { - if (likely(!crypt_ops) || WARN_ON(!PAGE_ALIGNED(addr))) + unsigned long size = (unsigned long)numpages << PAGE_SHIFT; + + if (likely(!crypt_ops)) return 0; + if (WARN_ON(!IS_ALIGNED(addr, mem_cc_shared_granule_size()))) + return -EINVAL; + + if (WARN_ON(!IS_ALIGNED(size, mem_cc_shared_granule_size()))) + return -EINVAL; + return crypt_ops->decrypt(addr, numpages); } EXPORT_SYMBOL_GPL(set_memory_decrypted); + +size_t mem_cc_shared_granule_size(void) +{ + if (likely(!crypt_ops) || !crypt_ops->cc_shared_granule_size) + return PAGE_SIZE; + + return crypt_ops->cc_shared_granule_size(); +} +EXPORT_SYMBOL_GPL(mem_cc_shared_granule_size);
--
2.43.0