[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[RFC PATCH v1 13/26] xen/arm/cca: destroy RECs during Realm relinquish


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Koichiro Den <den@xxxxxxxxxxxxx>
  • Date: Fri, 15 May 2026 13:07:59 +0900
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=valinux.co.jp; dmarc=pass action=none header.from=valinux.co.jp; dkim=pass header.d=valinux.co.jp; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=u3FWv0GhzR6Z08YwvEAu3rWkS08OimUL4UXo8Xw0smY=; b=GI1JsAnORKFapx3wQt4vFhLnrC9C04au+YIaXMiz49egE0CXAkzbVl8arOAiMiwpu/c/O1xuQrmI/I5wN+mD/IO4NOYPeL9EIwzEL7mFrkdU0qbTmS7girWrh7vbuGKnXZQhX6jjSwZG0rOYYqpaMTTuK2HENuXVznNdGC1Y5btIGU2848fKmfN8ZIAANH5/KyWnsBUyLzqpi5Qpta459duVfA8C/Pcpe1RzoPDZgZ/zXSy1S20cb0544/afEnk3AO/ZV5hBSuGVbj1qaTdFzw4OWFaCMvT63hapgZlpsICWDvp75c7yyIDFEL/dKeF5MT9TUwHDNOVDYY1YZ1nkmA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=IXjTWfZR+3kWly/5vOglg3MtVqix3dpi2eQw9ah7we8HlVQth7Xk+L8xkCNEi29EsQ7UBg7uTqCJt05gV6mlRcEnM4NhtbTyqod6iY+Oi9eR8zLL5AERzfXj2XCwtAz3s3dILLePV/OZEKgrNH3EDeS1a5dYtwCNId6QqjJ1Q8f0JmWSOIwzzjL1w7iRz2vpGZofgnGxfKfX9c5lJIXPdoPplNVOuTgZvNJf/NVGEytqlxm45IyOpfdLsIpe1FFHldRGfBlLNrdGazqzIUtOF3eZovvCrH7Auuy0cztcOhqJuW7fRw/zBT/GI9cx09x4TcA8WGh7fXxlreFGbKJASQ==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=valinux.co.jp header.i="@valinux.co.jp" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=valinux.co.jp;
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger.pau@xxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, "Daniel P. Smith" <dpsmith@xxxxxxxxxxxxxxxxxxxx>, Juergen Gross <jgross@xxxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>
  • Delivery-date: Fri, 15 May 2026 04:12:36 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

Destroy each REC, reclaim its auxiliary pages through SRO, then release
the REC granule after the RMM has returned it.

Signed-off-by: Koichiro Den <den@xxxxxxxxxxxxx>
---
 xen/arch/arm/cca/state.c | 81 ++++++++++++++++++++++++++++++++++++++++
 1 file changed, 81 insertions(+)

diff --git a/xen/arch/arm/cca/state.c b/xen/arch/arm/cca/state.c
index c85ef56a1297..72dbb83841d7 100644
--- a/xen/arch/arm/cca/state.c
+++ b/xen/arch/arm/cca/state.c
@@ -122,6 +122,22 @@ static int arm_cca_relinquish_abandoned_pages(struct 
domain *d)
     return 0;
 }
 
+static int arm_cca_rmi_rec_destroy_complete(struct vcpu *v)
+{
+    struct arm_cca_sro_mem_xfer xfer = {
+        .pages = v->arch.cca.aux_pages,
+        .nr_pages = &v->arch.cca.nr_aux,
+        .abandoned_pages = &v->domain->arch.cca.abandoned_pages,
+    };
+    struct arm_smccc_res res;
+    int rc;
+
+    rc = arm_cca_rmi_rec_destroy(v->arch.cca.rec, &res);
+    rc = arm_cca_sro_complete_mem_transfer(rc, &res, &xfer);
+
+    return rc;
+}
+
 static int arm_cca_rmi_realm_destroy_complete(struct domain *d)
 {
     struct arm_cca_sro_mem_xfer xfer = {
@@ -269,6 +285,67 @@ static int arm_cca_teardown_rtts(struct domain *d)
     return 0;
 }
 
+static int arm_cca_vcpu_free_rec_page(struct vcpu *v)
+{
+    int rc;
+
+    if ( !v->arch.cca.rec_page )
+        return 0;
+
+    rc = arm_cca_undelegate_granule(page_to_maddr(v->arch.cca.rec_page));
+    if ( rc != 0 )
+        return rc;
+
+    free_domheap_page(v->arch.cca.rec_page);
+    v->arch.cca.rec_page = NULL;
+
+    return 0;
+}
+
+static int arm_cca_vcpu_relinquish_resources(struct vcpu *v)
+{
+    int rc;
+
+    if ( v->arch.cca.rec != INVALID_PADDR )
+    {
+        rc = arm_cca_rmi_rec_destroy_complete(v);
+        if ( rc != 0 )
+            return rc;
+
+        v->arch.cca.rec = INVALID_PADDR;
+    }
+
+    /*
+     * arm_cca_sro_complete_mem_transfer() consumes REC_DESTROY reclaim
+     * requests.  Remaining REC auxiliary pages would mean Xen cannot prove
+     * that the granules have been returned by the RMM.
+     */
+    if ( v->arch.cca.nr_aux != 0 )
+        return -EIO;
+
+    return arm_cca_vcpu_free_rec_page(v);
+}
+
+static int arm_cca_teardown_recs(struct domain *d)
+{
+    unsigned int i;
+    int rc;
+
+    for ( i = 0; i < d->max_vcpus; ++i )
+    {
+        struct vcpu *v = d->vcpu[i];
+
+        if ( v == NULL )
+            continue;
+
+        rc = arm_cca_vcpu_relinquish_resources(v);
+        if ( rc != 0 )
+            return rc;
+    }
+
+    return 0;
+}
+
 static int arm_cca_destroy_realm(struct domain *d)
 {
     int rc;
@@ -330,6 +407,10 @@ int arm_cca_domain_relinquish_resources(struct domain *d)
     if ( rc != 0 )
         return rc;
 
+    rc = arm_cca_teardown_recs(d);
+    if ( rc != 0 )
+        return rc;
+
     rc = arm_cca_destroy_realm(d);
     if ( rc != 0 )
         return rc;
-- 
2.51.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.