freenode
Kernel & Low-Level

KVM arm64 gets basic plumbing for Arm CCA Realms

A trimmed v22 series adds VM-type abstractions and non-runnable Realm scaffolding so confidential guests can share common paths with pKVM.

Arm engineers have posted a twenty-third-round, trimmed series that lays foundational KVM plumbing on arm64 for Confidential Compute Architecture (CCA) Realms, without yet making Realm guests runnable.

The work, led by Suzuki K Poulose with co-development from Steven Price and Jean-Philippe Brucker, splits earlier CCA enablement into reviewable chunks. The headline change for KVM itself is a VM-flavor model: instead of scattering type checks through the hypervisor, arm64 KVM gains per-flavor callbacks for VCPU and stage-2 MMU behavior covering ordinary guests, protected pKVM VMs, and the new Realm type.

That abstraction also widens the existing notion of a protected VM so common confidential-compute policies (timer offset locks, abort handling, and similar host restrictions) apply to Realms and pKVM guests alike, while precise helpers still distinguish unprotected pKVM cases where needed. Realm support is aimed at VHE hosts; pKVM hyp paths stay limited to the protected guests they already understand.

Bare Realm scaffolding follows: a new VM flavor, realm state tracking shared in a union with pKVM protected state, early rejection of incompatible VCPU features such as 32-bit EL1 and nested virt, and register-list and ONE_REG rules that match RMM limits on what the host may configure before a Realm is sealed (including SVE vector length). Timer IRQs for Realms are forced onto software resampling because the RMM rejects hardware-backed list entries. Actual RMI driver hookup, guest-memfd integration, and the ability to create and run Realms remain later dependencies.

Marc Zyngier and Gavin Shan are reviewing the type-model and callback split on the KVM arm64 path. Until the firmware library and remaining UABI pieces land, the series is structural prep rather than a usable confidential-compute feature.