Re: [PATCH v16 17/45] KVM: arm64: CCA: Tear down RTTs

Alper Gun <[email protected]> Mon, 3 Aug 2026 15:29:53 -0700
Newsgroups dev.linux.lists.kvmarm,dev.linux.lists.linux-coco,org.infradead.lists.linux-arm-kernel,org.kernel.vger.kvm,org.kernel.vger.linux-kernel
Message-ID <CABpDEun3NPr7Na85pmOvdfYQ1DB-2nCcocsyDESXM15bzJU1og@mail.gmail.com>
On Mon, Aug 3, 2026 at 6:45=E2=80=AFAM Steven Price <[email protected]> =
wrote:
> [...]
> +static void realm_unmap_stage2(struct kvm *kvm)
> +{
> +       struct realm *realm =3D &kvm->arch.realm;
> +
> +       lockdep_assert_held(&kvm->arch.config_lock);
> +
> +       if (realm->stage2_unmapped)
> +               return;
> +
> +       write_lock(&kvm->mmu_lock);
> +       kvm_stage2_unmap_range(&kvm->arch.mmu, 0,
> +                              BIT(realm->ia_bits - 1), true);
> +       write_unlock(&kvm->mmu_lock);
> +
> +       realm->stage2_unmapped =3D true;
> +}
> +
> +int kvm_realm_teardown_stage2(struct kvm *kvm)
> +{
> +       lockdep_assert_held(&kvm->arch.config_lock);
> +
> +       realm_unmap_stage2(kvm);
> +       return realm_destroy_rtts(kvm);
> +}

Hi Steven,

I noticed a warning in dmesg when destroying a realm:

  [  158.533495] Call trace:
  [  158.535927]  kvm_destroy_realm+0x208/0x218
  [  158.540356]  kvm_arch_destroy_vm+0xc8/0xd8
  [  158.544439]  kvm_put_kvm+0x324/0x4b0
  [  158.548002]  kvm_vm_stats_release+0x1c/0x38

I traced this and found the following:

At this point, calling realm_destroy_rtts() may fail destroying the RTTs
because RECs are still active and the Realm is not terminated, but the
walk finishes and still sets realm->rtts_destroyed =3D true.

Later, kvm_destroy_realm() calls rmi_realm_terminate() and then calls
realm_destroy_rtts(kvm) again. But because realm->rtts_destroyed is already
set to true, it exits early without tearing down the RTTs.

Consequently, rmi_realm_destroy() is invoked while the RTT tables still
exist in RMM, which fails and triggers WARN_ON(rmi_realm_destroy).

The fix I used was to remove realm_destroy_rtts() from
kvm_realm_teardown_stage2():
--- a/arch/arm64/kvm/rmi.c
+++ b/arch/arm64/kvm/rmi.c
@@ -434,7 +434,7 @@ int kvm_realm_teardown_stage2(struct kvm *kvm)
  lockdep_assert_held(&kvm->arch.config_lock);

  realm_unmap_stage2(kvm);
- return realm_destroy_rtts(kvm);
+ return 0;
 }

I think we don't need RTT destruction here as it will be handled cleanly in
kvm_destroy_realm() later.

Thanks,
Alper