[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v5 4/6] xen/arm: remove XEN_DOMCTL_CONFIG_GIC_NATIVE from the ABI


  • To: Julian Vetter <julian.vetter@xxxxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: "Orzel, Michal" <michal.orzel@xxxxxxx>
  • Date: Wed, 16 Sep 2026 16:11:45 +0200
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=temperror (sender ip is 165.204.84.17) smtp.rcpttodomain=vates.tech smtp.mailfrom=amd.com; dmarc=temperror action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+qbHj1a5FX6YNk34OUl1j8Kb3V0wSr32WDkvEzQcPtA=; b=w0YPdKMumpPI23dBJIkTOVvpTTfb0x1cT1Tic0+5etJunbEW386MAckvTVvTFATNHj7hOFQdnsMop1DM7GuYrxstlsd+pDljngy7zkYKXcPc5fZSJRP49XmRyWpzsZLaXKxGZnth1iWFAshou2Ks/URqGfROqBqdZRnQV5ZeU4dCM44EJlLhJlIJL5M8soKpPk00zyMp8rKClkoHB9zzi9OwE8VvIvjiDO97hybLZTjZij+dbe+qN99OEhrgXKwugSrg3iymvvQGwcFKiYhtglVVv9h+fUMui2sZAf/qEzAW3lzWfAtGmJIkcasFtkm1NIDdxZhq9r3Mu/+vWgAgwA==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=BxtC3XKwMrnaNmc0YhBoOnEAs4XCIVBhFc7g/lcZedXv9HP64/v310VxpLB8Zd9D5l9kc+5Dga5p9VWZ4y/mv2tdo59t20K8K70EG4HNhxt71d4KqYaJNG6V7n0fSGPeHaYybIh66U0+qMgzBEN3M6RI/tpIgxNglpRxtQtAZjBN5noe1CswwEIaNO66vnQEwvrHcCjHrR2aKC/DpYjR+FPqAcUZfuL+ZH8FsoZ6UCywtimFdeXqqhVslj/7/OtwFVLtch00Pd+eRC61g9fHKGhTYhzbiuPcrKrpawR849SLe4WJOUraLN/d6AYD9wj9mX10cPauZ9MAaCh76EPx3w==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=amd.com header.i="@amd.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Cc: Oleksii Kurochko <oleksii.kurochko@xxxxxxxxx>, Community Manager <community.manager@xxxxxxxxxxxxxx>, Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Roger Pau Monné <roger@xxxxxxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Juergen Gross <jgross@xxxxxxxx>, Andrii Sultanov <andriy.sultanov@xxxxxxxxxx>, Guillaume Thouvenin <guillaume.thouvenin@xxxxxxxxxx>, Marek Marczykowski-Górecki <marmarek@xxxxxxxxxxxxxxxxxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Oleksii Moisieiev <oleksii_moisieiev@xxxxxxxx>, Timothy Pearson <tpearson@xxxxxxxxxxxxxxxxxxxxx>, Alistair Francis <alistair.francis@xxxxxxx>, Connor Davis <connojdavis@xxxxxxxxx>, Teddy Astie <teddy.astie@xxxxxxxxxx>
  • Delivery-date: Wed, 16 Sep 2026 14:12:13 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>


On 11-Sep-26 14:47, Julian Vetter wrote:
> Now that the toolstack always resolves a concrete GIC_V2 or GIC_V3
> before calling createdomain, nothing on the Xen side needs to resolve
> GIC_NATIVE either:
> 
>  * A new gic_domctl_hw_version() helper returns the
>    XEN_DOMCTL_CONFIG_GIC_* value matching the host's gic_hw_version().
>  * arch_sanitise_domain_config() uses it to validate the requested
>    version against the hardware, rather than resolving GIC_NATIVE and
>    writing the result back into config->arch.gic_version. A guest must
>    use the host's GIC version, except that a GICv3 host with the GICv2
>    compatibility mode enabled may also run GICv2 guests. This is the
>    same information that XEN_SYSCTL_physinfo reports to the toolstack.
>  * create_dom0() and arch_parse_dom0less_node(), which both always want
>    a vGIC that exactly matches the hardware, use the same helper instead
>    of GIC_NATIVE.
> 
> With nothing left resolving or relying on it, drop
> XEN_DOMCTL_CONFIG_GIC_NATIVE from the public ABI. Every caller must now
> request a concrete GIC_V2 or GIC_V3.
> 
> This is an incompatible change for any toolstack still passing 0
> (formerly GIC_NATIVE) expecting Xen to auto-select a version. Add a
> CHANGELOG.md entry, noting that available GIC versions can be queried
> via XEN_SYSCTL_physinfo.
> 
> Signed-off-by: Julian Vetter <julian.vetter@xxxxxxxxxx>
> ---
> Changes in v5:
> - Rename gic_domctl_version() to gic_domctl_hw_version()
> - Accept a GICv2 guest on a GICv3 host with GICv2 compatibility mode
>   enabled, instead of requiring an exact match with the host GIC version
> ---
>  CHANGELOG.md                   |  4 ++++
>  xen/arch/arm/dom0less-build.c  |  3 ++-
>  xen/arch/arm/domain.c          | 27 +++++++++++----------------
>  xen/arch/arm/domain_build.c    |  3 ++-
>  xen/arch/arm/gic.c             | 16 ++++++++++++++++
>  xen/arch/arm/include/asm/gic.h |  6 ++++++
>  xen/include/public/arch-arm.h  |  2 +-
>  7 files changed, 42 insertions(+), 19 deletions(-)
> 
> diff --git a/CHANGELOG.md b/CHANGELOG.md
> index aa1a777dd4..78d1b13f3f 100644
> --- a/CHANGELOG.md
> +++ b/CHANGELOG.md
> @@ -18,6 +18,10 @@ The format is based on [Keep a 
> Changelog](https://keepachangelog.com/en/1.0.0/)
>  ### Added
>  
>  ### Removed
> + - On Arm:
> +   - XEN_DOMCTL_CONFIG_GIC_NATIVE has been removed. Toolstacks must now
> +     explicitly request GIC_V2 or GIC_V3 when creating a domain.
> +     Available GIC versions can be queried via XEN_SYSCTL_physinfo.
>   - On x86:
>     - The kexec "v1" interface, which was declared obsolete in Xen 4.4 (2013).
>       The only known user was the classic-xen fork of Linux.  This does not
> diff --git a/xen/arch/arm/dom0less-build.c b/xen/arch/arm/dom0less-build.c
> index 3f48f74226..7bbb2eafb6 100644
> --- a/xen/arch/arm/dom0less-build.c
> +++ b/xen/arch/arm/dom0less-build.c
> @@ -23,6 +23,7 @@
>  #include <asm/arm64/sve.h>
>  #include <asm/domain_build.h>
>  #include <asm/firmware/sci.h>
> +#include <asm/gic.h>
>  #include <asm/grant_table.h>
>  #include <asm/setup.h>
>  
> @@ -368,7 +369,7 @@ int __init arch_parse_dom0less_node(struct dt_device_node 
> *node,
>      unsigned int flags = bd->create_flags;
>      uint32_t val;
>  
> -    d_cfg->arch.gic_version = XEN_DOMCTL_CONFIG_GIC_NATIVE;
> +    d_cfg->arch.gic_version = gic_domctl_hw_version();
>      d_cfg->flags |= XEN_DOMCTL_CDF_hvm | XEN_DOMCTL_CDF_hap;
>  
>      if ( domu_dt_sci_parse(node, d_cfg) )
> diff --git a/xen/arch/arm/domain.c b/xen/arch/arm/domain.c
> index a739dd157e..6f5f92876e 100644
> --- a/xen/arch/arm/domain.c
> +++ b/xen/arch/arm/domain.c
> @@ -609,23 +609,18 @@ int arch_sanitise_domain_config(struct 
> xen_domctl_createdomain *config)
>          return -EINVAL;
>      }
>  
> -    /* Fill in the native GIC version, passed back to the toolstack. */
> -    if ( config->arch.gic_version == XEN_DOMCTL_CONFIG_GIC_NATIVE )
> +    /*
> +     * A guest can only use the host's GIC version, except that a GICv3 host
> +     * with the GICv2 compatibility mode enabled can also run GICv2 guests.
> +     * This mirrors what XEN_SYSCTL_physinfo reports to the toolstack.
> +     */
> +    if ( config->arch.gic_version != gic_domctl_hw_version() &&
> +         !(config->arch.gic_version == XEN_DOMCTL_CONFIG_GIC_V2 &&
> +           vgic_v2_hw_enabled()) )
>      {
> -        switch ( gic_hw_version() )
> -        {
> -        case GIC_V2:
> -            config->arch.gic_version = XEN_DOMCTL_CONFIG_GIC_V2;
> -            break;
> -
> -        case GIC_V3:
> -            config->arch.gic_version = XEN_DOMCTL_CONFIG_GIC_V3;
> -            break;
> -
> -        default:
> -            ASSERT_UNREACHABLE();
> -            return -EINVAL;
> -        }
> +        dprintk(XENLOG_INFO, "Unsupported GIC version %u\n",
There is a check below for max_vcpus being 0. With this check added, it becomes
dead (unless vgic_max_vcpus() is changed), so add ASSERT_UNREACHABLE() there.

> +                config->arch.gic_version);
> +        return -EINVAL;
>      }
>  
>      /* max_vcpus depends on the GIC version, and Xen's compiled limit. */
> diff --git a/xen/arch/arm/domain_build.c b/xen/arch/arm/domain_build.c
> index 72d5316180..cf7e1100bd 100644
> --- a/xen/arch/arm/domain_build.c
> +++ b/xen/arch/arm/domain_build.c
> @@ -26,6 +26,7 @@
>  #include <xen/warning.h>
>  #include <xen/static-shmem.h>
>  #include <asm/device.h>
> +#include <asm/gic.h>
>  #include <asm/setup.h>
>  #include <asm/tee/tee.h>
>  #include <asm/pci.h>
> @@ -1960,7 +1961,7 @@ void __init create_dom0(void)
>      int rc;
>  
>      /* The vGIC for DOM0 is exactly emulating the hardware GIC */
> -    dom0_cfg.arch.gic_version = XEN_DOMCTL_CONFIG_GIC_NATIVE;
> +    dom0_cfg.arch.gic_version = gic_domctl_hw_version();
>      dom0_cfg.arch.nr_spis = vgic_def_nr_spis();
>      dom0_cfg.arch.tee_type = tee_get_type();
>      dom0_cfg.max_vcpus = dom0_max_vcpus();
> diff --git a/xen/arch/arm/gic.c b/xen/arch/arm/gic.c
> index 078049e741..997b6ee6ed 100644
> --- a/xen/arch/arm/gic.c
> +++ b/xen/arch/arm/gic.c
> @@ -56,6 +56,22 @@ enum gic_version gic_hw_version(void)
>     return gic_hw_ops->info->hw_version;
>  }
>  
> +uint8_t gic_domctl_hw_version(void)
> +{
> +    switch ( gic_hw_version() )
> +    {
> +    case GIC_V2:
> +        return XEN_DOMCTL_CONFIG_GIC_V2;
> +
> +    case GIC_V3:
> +        return XEN_DOMCTL_CONFIG_GIC_V3;
> +
> +    default:
> +        ASSERT_UNREACHABLE();
We should BUG() here instead to protect both builds given that you return just 0
(ASSERT would be ok provided you propagate somehow the error).

> +        return 0;
> +    }
> +}
> +
>  unsigned int gic_number_lines(void)
>  {
>      return gic_hw_ops->info->nr_lines;
> diff --git a/xen/arch/arm/include/asm/gic.h b/xen/arch/arm/include/asm/gic.h
> index ee2c26adb4..434b888e69 100644
> --- a/xen/arch/arm/include/asm/gic.h
> +++ b/xen/arch/arm/include/asm/gic.h
> @@ -262,6 +262,12 @@ DECLARE_PER_CPU(uint64_t, lr_mask);
>  
>  extern enum gic_version gic_hw_version(void);
>  
> +/*
> + * The XEN_DOMCTL_CONFIG_GIC_* value matching the GIC version actually
> + * present on this host.
> + */
> +extern uint8_t gic_domctl_hw_version(void);
No need for extern for prototypes.

> +
>  /* Program the IRQ type into the GIC */
>  void gic_set_irq_type(struct irq_desc *desc, unsigned int type);
>  
> diff --git a/xen/include/public/arch-arm.h b/xen/include/public/arch-arm.h
> index 00de30b896..9d3bf11cbd 100644
> --- a/xen/include/public/arch-arm.h
> +++ b/xen/include/public/arch-arm.h
> @@ -319,7 +319,7 @@ DEFINE_XEN_GUEST_HANDLE(vcpu_guest_context_t);
>   * struct xen_arch_domainconfig's ABI is covered by
>   * XEN_DOMCTL_INTERFACE_VERSION.
>   */
> -#define XEN_DOMCTL_CONFIG_GIC_NATIVE    0
> +/*      XEN_DOMCTL_CONFIG_GIC_NATIVE    0 - removed in Xen 4.23 */
You should also update the comment below saying that gic_version is IN only.

Otherwise, LGTM.

~Michal




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.