Re: [PATCH v22 14/23] KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms

From: Gavin Shan

Date: Mon Oct 05 2026 - 23:10:43 EST


On 10/5/26 7:07 PM, Suzuki K Poulose wrote:
pKVM does not trust the host. Realm VMs follow a similar trust model, with
the Realm Management Monitor owning the protected state instead of the
host. Add a helper to identify VMs that run under a host-distrusting
hypervisor.

Use this for blocking ioremap of vgic-v2 into stage2 and prevent creation
of VGIC other than v3.

Reviewed-by: Jonathan Cameron <jonathan.cameron@xxxxxxxxxxxxxxxx>
Reviewed-by: Fuad Tabba <fuad.tabba@xxxxxxxxx>
Tested-by: Gavin Shan <gshan@xxxxxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
arch/arm64/include/asm/kvm_host.h | 4 ++++
arch/arm64/kvm/mmu.c | 2 +-
arch/arm64/kvm/vgic/vgic-init.c | 2 ++
3 files changed, 7 insertions(+), 1 deletion(-)

Reviewed-by: Gavin Shan <gshan@xxxxxxxxxx>