[PATCH v18 20/23] KVM: arm64: CCA: Don't expose unsupported capabilities for realm guests
From: Suzuki K Poulose <suzuki.poulose@arm.com>
Date: 2026-09-15 16:02:54
Also in:
kvm, kvmarm, linux-arm-kernel, lkml
Subsystem:
arm64 port (aarch64 architecture), kernel virtual machine for arm64 (kvm/arm64), the rest · Maintainers:
Catalin Marinas, Will Deacon, Marc Zyngier, Oliver Upton, Linus Torvalds
Limit the capabilities that are allowed for Realm VMs. Similarly block the vm_ioctls backed by the capabilities. Repurpose the kvm_pkvm_ioctl_allowed() to support both pKVM and Realm ioctls. Rename the helper to kvm_arch_vm_ioctl_allowed() and move it into arch/arm64/kvm/arm.c. Also add a generic kvm_arch_vm_ext_allowed() to handle pKVM and Realm capability filtering. Signed-off-by: Suzuki K Poulose <suzuki.poulose@arm.com> --- Changes since v17: * Drop superfluous !kvm check from kvm_vm_ioctl_enable_cap() - Sashiko * Drop KVM_CAP_CREATE_IRQCHIP, as we don't support VGIC_V2 for Realms * Filter out the vm_ioctls that are based on blocked cap. * Repurpose the pkvm plumbing for filtering the caps and ioctl to generic and plumb the Realm support in Changes since v13: * Add missing check in kvm_vm_ioctl_enable_cap(). Changes since v10: * Add a kvm_realm_ext_allowed() function which limits which extensions are exposed to an allowlist. This removes the need for special casing various extensions. Changes since v7: * Remove the helper functions and inline the kvm_is_realm() check with a ternary operator. * Rewrite the commit message to explain this patch. --- arch/arm64/include/asm/kvm_pkvm.h | 19 ---------- arch/arm64/kvm/arm.c | 58 +++++++++++++++++++++++++++++-- 2 files changed, 55 insertions(+), 22 deletions(-)
diff --git a/arch/arm64/include/asm/kvm_pkvm.h b/arch/arm64/include/asm/kvm_pkvm.h
index e4ea80711bec6..1bc4fe2726e9b 100644
--- a/arch/arm64/include/asm/kvm_pkvm.h
+++ b/arch/arm64/include/asm/kvm_pkvm.h@@ -53,25 +53,6 @@ static inline bool kvm_pkvm_ext_allowed(struct kvm *kvm, long ext) } } -/* - * Check whether the KVM VM IOCTL is allowed in pKVM. - * - * Certain features are allowed only for non-protected VMs in pKVM, which is why - * this takes the VM (kvm) as a parameter. - */ -static inline bool kvm_pkvm_ioctl_allowed(struct kvm *kvm, unsigned int ioctl) -{ - long ext; - int r; - - r = kvm_get_cap_for_kvm_ioctl(ioctl, &ext); - - if (WARN_ON_ONCE(r < 0)) - return false; - - return kvm_pkvm_ext_allowed(kvm, ext); -} - extern struct memblock_region kvm_nvhe_sym(hyp_memory)[]; extern unsigned int kvm_nvhe_sym(hyp_memblock_nr);
diff --git a/arch/arm64/kvm/arm.c b/arch/arm64/kvm/arm.c
index 8ed7dd1ce446c..df0aa66b6f5ed 100644
--- a/arch/arm64/kvm/arm.c
+++ b/arch/arm64/kvm/arm.c@@ -136,6 +136,58 @@ int kvm_arch_vcpu_should_kick(struct kvm_vcpu *vcpu) return kvm_vcpu_exiting_guest_mode(vcpu) == IN_GUEST_MODE; } +static inline bool kvm_realm_ext_allowed(long ext) +{ + switch (ext) { + case KVM_CAP_ARM_PSCI: + case KVM_CAP_ARM_PSCI_0_2: + case KVM_CAP_NR_VCPUS: + case KVM_CAP_MAX_VCPUS: + case KVM_CAP_MAX_VCPU_ID: + case KVM_CAP_MSI_DEVID: + case KVM_CAP_ARM_VM_IPA_SIZE: + case KVM_CAP_ARM_SVE: + case KVM_CAP_ONE_REG: + case KVM_CAP_ARM_PTRAUTH_ADDRESS: + case KVM_CAP_ARM_PTRAUTH_GENERIC: + case KVM_CAP_SYNC_MMU: + return true; + } + return false; +} + +static inline bool kvm_arch_vm_ext_allowed(struct kvm *kvm, long ext) +{ + /* + * We could be called with kvm as NULL, so can't use kvm_vm_* for pKVM + * flavors + */ + if (is_protected_kvm_enabled()) + return kvm_pkvm_ext_allowed(kvm, ext); + else if (kvm && kvm_vm_is_realm(kvm)) + return kvm_realm_ext_allowed(ext); + else + return true; +} + +/* + * Check whether the KVM VM IOCTL is allowed. + * + * Certain features are allowed only for non-protected VMs in pKVM, which is why + * this takes the VM (kvm) as a parameter. + */ +static inline bool kvm_arch_vm_ioctl_allowed(struct kvm *kvm, unsigned int ioctl) +{ + long ext; + int r; + + r = kvm_get_cap_for_kvm_ioctl(ioctl, &ext); + if (WARN_ON_ONCE(r < 0)) + return false; + + return kvm_arch_vm_ext_allowed(kvm, ext); +} + int kvm_vm_ioctl_enable_cap(struct kvm *kvm, struct kvm_enable_cap *cap) {
@@ -144,7 +196,7 @@ int kvm_vm_ioctl_enable_cap(struct kvm *kvm, if (cap->flags) return -EINVAL; - if (is_protected_kvm_enabled() && !kvm_pkvm_ext_allowed(kvm, cap->cap)) + if (!kvm_arch_vm_ext_allowed(kvm, cap->cap)) return -EINVAL; switch (cap->cap) {
@@ -418,7 +470,7 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext) { int r; - if (is_protected_kvm_enabled() && !kvm_pkvm_ext_allowed(kvm, ext)) + if (!kvm_arch_vm_ext_allowed(kvm, ext)) return 0; switch (ext) {
@@ -2150,7 +2202,7 @@ int kvm_arch_vm_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg) void __user *argp = (void __user *)arg; struct kvm_device_attr attr; - if (is_protected_kvm_enabled() && !kvm_pkvm_ioctl_allowed(kvm, ioctl)) + if (!kvm_arch_vm_ioctl_allowed(kvm, ioctl)) return -EINVAL; switch (ioctl) {
--
2.43.0