Re: [PATCH v22 14/23] KVM: arm64: Mandate VGIC v3 for pKVM VMs and Realms
From: Gavin Shan
Date: Mon Oct 05 2026 - 23:10:43 EST
On 10/5/26 7:07 PM, Suzuki K Poulose wrote:
pKVM does not trust the host. Realm VMs follow a similar trust model, withReviewed-by: Gavin Shan <gshan@xxxxxxxxxx>
the Realm Management Monitor owning the protected state instead of the
host. Add a helper to identify VMs that run under a host-distrusting
hypervisor.
Use this for blocking ioremap of vgic-v2 into stage2 and prevent creation
of VGIC other than v3.
Reviewed-by: Jonathan Cameron <jonathan.cameron@xxxxxxxxxxxxxxxx>
Reviewed-by: Fuad Tabba <fuad.tabba@xxxxxxxxx>
Tested-by: Gavin Shan <gshan@xxxxxxxxxx>
Signed-off-by: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
---
arch/arm64/include/asm/kvm_host.h | 4 ++++
arch/arm64/kvm/mmu.c | 2 +-
arch/arm64/kvm/vgic/vgic-init.c | 2 ++
3 files changed, 7 insertions(+), 1 deletion(-)