Branch: refs/heads/master
  Home:   https://github.com/tianocore/edk2
  Commit: 99fbe6b57507fc15ebf97967a001c7874ec08425
      
https://github.com/tianocore/edk2/commit/99fbe6b57507fc15ebf97967a001c7874ec08425
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M ArmVirtPkg/ArmVirtPkg.dec
    A ArmVirtPkg/Include/Protocol/RealmApertureManagementProtocol.h
    A 
ArmVirtPkg/RealmApertureManagementProtocolDxe/RealmApertureManagementProtocolDxe.c
    A 
ArmVirtPkg/RealmApertureManagementProtocolDxe/RealmApertureManagementProtocolDxe.inf

  Log Message:
  -----------
  ArmVirtPkg: Introduce Realm Aperture Management Protocol

The Realm Aperture Management Protocol (RAMP) is used to manage
the sharing of buffers between the Guest and Host. It configures
the memory regions as Protected EMPTY or Protected RAM by calling
RSI_IPA_STATE_SET command. The RAMP provides interfaces that device
drivers can use to open/close apertures for sharing buffers.

The RAMP also keeps track of the apertures that have been opened
and closes them on ExitBootServices. It also registers for reset
notification and closes all open apertures before the platform
resets the system.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


  Commit: ebd5e0faa94a601e5abd9d24aac586876e7179e7
      
https://github.com/tianocore/edk2/commit/ebd5e0faa94a601e5abd9d24aac586876e7179e7
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    A ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmu.c
    A ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmu.h
    A ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmuDxe.c
    A ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmuDxe.inf

  Log Message:
  -----------
  ArmVirtPkg: IoMMU driver to DMA from Realms

On Arm CCA systems the access to pages inside the Realm is protected.

However, software executing in a Realm needs to interact with the
external world. This may be done using para virtualisation of the
disk, network interfaces, etc. For this to work the buffers in the
Realm need to be shared with the Host. The sharing and management
of the Realm buffers is done by the Realm Aperture Management
Protocol, which invokes the necessary Realm Service Interfaces
to transition the buffers from Protected IPA to Unprotected IPA.

The ArmCcaIoMmu driver provides the necessary hooks so that DMA
operations can be performed by bouncing buffers using pages shared
with the Host. It uses the Realm Aperture Management protocol to
share the buffers with the Host.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


  Commit: 15f9d3cf1d87fd064a8f7d39e8d1d8dbab75cd72
      
https://github.com/tianocore/edk2/commit/15f9d3cf1d87fd064a8f7d39e8d1d8dbab75cd72
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmu.c

  Log Message:
  -----------
  ArmVirtPkg: ArmCcaIoMmu: Provide an implementation for SetAttribute

The patch at "049695a0b1e2 MdeModulePkg/PciBusDxe: Add feedback
status for PciIoMap" adds support to propagate the error code
following the invocation of the IoMmu protocol SetAttribute()
operation.

Since the ArmCcaIoMmuDxe implementation of the SetAttribute()
function returned EFI_UNSUPPORTED, it resulted in the virtio
disk not being mounted.

Although there is nothing to be done in SetAttribute(), follow
the approach as done by the patch at "97c3f5b8d272  Provide an
implementation for SetAttribute" to validate the IoMmu access
method being requested against the IoMmu mapping operation and
return a suitable return code.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


  Commit: 9f9247d0a201437c5a0c786df9c696169e6fbbf8
      
https://github.com/tianocore/edk2/commit/9f9247d0a201437c5a0c786df9c696169e6fbbf8
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmu.c
    M ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmuDxe.inf

  Log Message:
  -----------
  ArmVirtPkg: ArmCcaIoMmuDxe: unmap all mappings on reset

Add support to tear down all mappings on reset.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


  Commit: b7f7fc95fa33934641f43ea318b31152c3c70aa3
      
https://github.com/tianocore/edk2/commit/b7f7fc95fa33934641f43ea318b31152c3c70aa3
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M ArmVirtPkg/ArmCcaIoMmuDxe/ArmCcaIoMmuDxe.inf
    M ArmVirtPkg/ArmVirtPkg.dec
    M 
ArmVirtPkg/RealmApertureManagementProtocolDxe/RealmApertureManagementProtocolDxe.c
    M 
ArmVirtPkg/RealmApertureManagementProtocolDxe/RealmApertureManagementProtocolDxe.inf

  Log Message:
  -----------
  ArmVirtPkg: Install Realm Aperture Mgmt Absent Protocol if not Realm

The ArmCcaIoMmuDxe install the IoMmu protocol and has a dependency
on the Realm Aperture Management protocol to be installed before
it can be dispatched. When the execution context is not a Realm
the ArmCcaIoMmuDxe is never dispatches and therefore the protocol
gIoMmuAbsentProtocolGuid is never installed.

For some firmware builds this prevents the modules that depend
on either the gEdkiiIoMmuProtocolGuid or gIoMmuAbsentProtocolGuid
from being dispatched.

Therefore, introduce gEfiRealmApertureManagementAbsentProtocolGuid
so that the ArmCcaIoMmuDxe can be dispatched and can install the
gIoMmuAbsentProtocolGuid, thereby allowing dependent modules to be
dispatched.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


  Commit: 30d6a2713e635bfa7b2a3040f80490e36b9e492e
      
https://github.com/tianocore/edk2/commit/30d6a2713e635bfa7b2a3040f80490e36b9e492e
  Author: Sami Mujawar <[email protected]>
  Date:   2026-10-01 (Thu, 01 Oct 2026)

  Changed paths:
    M ArmVirtPkg/ArmVirtKvmTool.dsc
    M ArmVirtPkg/ArmVirtKvmTool.fdf

  Log Message:
  -----------
  ArmVirtPkg: Enable Virtio communication for Arm CCA

Arm CCA Realms protect the access to memory from outside the
Realm. For Virtio to work the Realm Guest and the Host should
be able to share buffers.

Realm Aperture Management protocol (RAMP) manages the sharing
of buffers between the Realm Guest and the Host, while the
ArmCcaIoMmuDxe implements the EDKII_IOMMU_PROTOCOL which
provides the necessary hooks so that DMA accesses can be
performed by bouncing buffers using pages shared with the
host.

Therefore, enable the support for Realm Aperture Management
Protocol and ArmCcaIoMmuDxe for Kvmtool Guest firmware.

Note: The ArmCcaIoMmuDxe and RAMP check if the code is executing
in a Realm before installing the respective protocols. If the
code is not executing in a Realm the gIoMmuAbsentProtocolGuid is
installed, thereby allowing the same firmware to be used both for
normal and Realm Guest firmware.

Cc: Ard Biesheuvel <[email protected]>
Cc: Leif Lindholm <[email protected]>
Cc: Gerd Hoffmann <[email protected]>
Signed-off-by: Sami Mujawar <[email protected]>


Compare: https://github.com/tianocore/edk2/compare/2df45784c3ff...30d6a2713e63

To unsubscribe from these emails, change your notification settings at 
https://github.com/tianocore/edk2/settings/notifications


_______________________________________________
edk2-commits mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/edk2-commits

Reply via email to