Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [Medium] init: KVM hypervisor detection fails in Realms due to late 
rsi_present init
--

commit 26246cc162e7aa368ba4bffb04d1af1a21a168c0
Author: Kameron Carr <[email protected]>

firmware: smccc: Detect hypervisor via RSI host call in CCA Realms

This commit modifies arm_smccc_hypervisor_has_uuid() to check if the system
is running in a Realm environment. If so, it uses an RSI host call to query
the hypervisor vendor UUID instead of a direct SMC or HVC call.

> diff --git a/drivers/firmware/smccc/smccc.c b/drivers/firmware/smccc/smccc.c
> index afc2e4d602ba6..7e7717076eeb0 100644
> --- a/drivers/firmware/smccc/smccc.c
> +++ b/drivers/firmware/smccc/smccc.c

[ ... ]

> @@ -69,12 +75,45 @@ s32 arm_smccc_get_soc_id_revision(void)
>  bool arm_smccc_hypervisor_has_uuid(const uuid_t *hyp_uuid)
>  {
>       struct arm_smccc_res res = {};
>       uuid_t uuid;
>  
> -     arm_smccc_1_1_invoke(ARM_SMCCC_VENDOR_HYP_CALL_UID_FUNC_ID, &res);
> +#ifdef CONFIG_ARM64
> +     if (is_realm_world())

[Severity: Medium]
Does this Realm detection fail for early callers like KVM initialization?

The is_realm_world() check relies on the rsi_present static key being set.
However, during early boot in setup_arch(), arm64_rsi_init() is called
after the PSCI initialization:

arch/arm64/kernel/setup.c:setup_arch() {
        ...
        if (acpi_disabled)
                psci_dt_init();
        else
                psci_acpi_init();

        arm64_rsi_init();
        ...
}

The PSCI initialization path eventually calls kvm_init_hyp_services(), which
uses arm_smccc_hypervisor_has_uuid() to detect the hypervisor. Since the
rsi_present key has not been set yet, is_realm_world() will return false.

This causes a fallback to the direct SMC invocation, which is intercepted and
fails in Realm environments, preventing the initialization of KVM
paravirtualization features for Realm guests.

> +             arm_smccc_realm_get_hypervisor_uuid(&res);
> +     else
> +#endif
> +             arm_smccc_1_1_invoke(ARM_SMCCC_VENDOR_HYP_CALL_UID_FUNC_ID,
> +                                  &res);
> +
>       if (res.a0 == SMCCC_RET_NOT_SUPPORTED)
>               return false;
>

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=2

Reply via email to