Re: [PATCH v5 08/10] arm64: realm: Move Realm memory encryption ops to RSI code

Will Deacon <[email protected]>
Newsgroups dev.linux.lists.iommu,dev.linux.lists.kvmarm,dev.linux.lists.linux-coco,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel
Message-ID <al_svOwkb5SleTWg@willie-the-truck>
On Mon, Jul 06, 2026 at 11:34:30AM +0530, Aneesh Kumar K.V (Arm) wrote:
> Realm memory encryption callbacks are CCA-specific. Keep the Realm callback
> registration with the RSI initialization code instead of pageattr.c, which
> only needs to provide the low-level page-attribute transition helper.
> 
> Export __set_memory_enc_dec() within arm64 so the RSI code can wrap it with
> the Realm-specific encrypt/decrypt callbacks and warning policy.
> 
> No functional changes in this patch.
> 
> Signed-off-by: Aneesh Kumar K.V (Arm) <[email protected]>
> ---
>  arch/arm64/include/asm/mem_encrypt.h |  3 +--
>  arch/arm64/kernel/rsi.c              | 34 +++++++++++++++++++++++++
>  arch/arm64/mm/pageattr.c             | 38 +---------------------------
>  3 files changed, 36 insertions(+), 39 deletions(-)
> 
> diff --git a/arch/arm64/include/asm/mem_encrypt.h b/arch/arm64/include/asm/mem_encrypt.h
> index 314b2b52025f..f6325f30e844 100644
> --- a/arch/arm64/include/asm/mem_encrypt.h
> +++ b/arch/arm64/include/asm/mem_encrypt.h
> @@ -15,8 +15,7 @@ int arm64_mem_crypt_ops_register(const struct arm64_mem_crypt_ops *ops);
>  
>  int set_memory_encrypted(unsigned long addr, int numpages);
>  int set_memory_decrypted(unsigned long addr, int numpages);
> -
> -int realm_register_memory_enc_ops(void);
> +int __set_memory_enc_dec(unsigned long addr, int numpages, bool encrypt);
>  
>  static inline bool force_dma_unencrypted(struct device *dev)
>  {
> diff --git a/arch/arm64/kernel/rsi.c b/arch/arm64/kernel/rsi.c
> index 1fb2abd79800..5c566700974c 100644
> --- a/arch/arm64/kernel/rsi.c
> +++ b/arch/arm64/kernel/rsi.c
> @@ -143,6 +143,40 @@ static int realm_ioremap_hook(phys_addr_t phys, size_t size, pgprot_t *prot)
>  	return 0;
>  }
>  
> +static int realm_set_memory_encrypted(unsigned long addr, int numpages)
> +{
> +	int ret = __set_memory_enc_dec(addr, numpages, true);
> +
> +	/*
> +	 * If the request to change state fails, then the only sensible cause
> +	 * of action for the caller is to leak the memory
> +	 */
> +	WARN(ret, "Failed to encrypt memory, %d pages will be leaked",
> +	     numpages);
> +
> +	return ret;
> +}
> +
> +static int realm_set_memory_decrypted(unsigned long addr, int numpages)
> +{
> +	int ret = __set_memory_enc_dec(addr, numpages, false);
> +
> +	WARN(ret, "Failed to decrypt memory, %d pages will be leaked",
> +	     numpages);
> +
> +	return ret;
> +}
> +
> +static const struct arm64_mem_crypt_ops realm_crypt_ops = {
> +	.encrypt = realm_set_memory_encrypted,
> +	.decrypt = realm_set_memory_decrypted,
> +};
> +
> +static int realm_register_memory_enc_ops(void)
> +{
> +	return arm64_mem_crypt_ops_register(&realm_crypt_ops);
> +}

It's good to move these out of pageattr.c but I still don't think any
of this stuff should be in arch/arm64. This is a firmware interface,
just like PSCI, so it should live in drivers/firmware/ along with all
the other Arm firmware interfaces (SDEI, FFA, SCMI, PSCI, SMCCC, ...).

Will
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.