From nobody Thu Jul 23 21:13:37 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272357; cv=pass; d=zohomail.com; s=zohoarc; b=dVaJ80OaxE1frW40+FKA6dbk1PKDZEiWmSJ6/tozyuCyWYLlcjq3RLXt0NGHFDD3is/6tULJb6zOmoboG78OfJ0UZmZdIkWdzRBLEVKZZXPgPVrJpdktvTcRgFQobIbSyZLvO6SVFG/Lu6Jq61t2pkhFjmmuaupb/C9w73BVaBc= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272357; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=7eIyVAq2TjvKOCUTXCBrr0CN8dsLL7rvIdBMxGGR0TQ=; b=VfUmq/Id0PMwDwqni+rpUrpkAzDjniyFfOduOGpXfTvydgT9B/nBCwCfxW5zWuTLFWR9xIrffqhJhY/CPLekC8Te4CVuFpcgZdEiWUy1shJbD+ouyUPW3rsB4x58oR13vYbHwzzqfYaODOLxRlH+XQVgnJELPzTPNBKtO/+N5mk= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272357433679.8407429333049; Fri, 17 Jul 2026 00:12:37 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364687.1615702 (Exim 4.92) (envelope-from ) id 1wkcjr-0005Zo-TT; Fri, 17 Jul 2026 07:12:03 +0000 Received: by outflank-mailman (output) from mailman id 1364687.1615702; Fri, 17 Jul 2026 07:12:03 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjr-0005Zh-Px; Fri, 17 Jul 2026 07:12:03 +0000 Received: by outflank-mailman (input) for mailman id 1364687; Fri, 17 Jul 2026 07:12:03 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjr-0005ZD-3s for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:03 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjq-00H0XY-F2 for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:02 +0200 Received: from [10.42.69.10] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5bd-e002-0a2a0a5209dd-0a2a450adb1a-28 for ; Fri, 17 Jul 2026 09:12:02 +0200 Received: from [52.101.70.78] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-4011c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c1-f2d2-0a2a450a0019-3465464e3484-3 for ; Fri, 17 Jul 2026 09:12:02 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:00 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:00 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=RAPvapBvKI/vJeqAF8+wLuMaGeMkUX9WztCw5aUp4I4qNkn9p3zlHnA2EnNTzkqCz3sYCwvV6KiC6+wwaRr+k0X7SJ2dPLeNky2CZD859H6zQgKvPjTTO2RsB9q6c50Zx9OkfvrZAiK3raIo09//ayyIj4Lpdw2nIISbL85NLlWZucIqyvzqf6GxohJZmNb2uR7Ib4bwy0y56M8mCwgruklWl99nqV9P2IXzcPXoZe5QPDqZ6ELT3w3keOnDy0PEH/2sRDvAp0sQyhApeJW775ZkkuQ/ARMN8jUY3Xrktuk5o37vF/OI4NTLqka8pPQbR+fg8RYQ0JhxKjJnhWDTug== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=7eIyVAq2TjvKOCUTXCBrr0CN8dsLL7rvIdBMxGGR0TQ=; b=MS40/3/8pfVf8GZ5J3ymAm7Yj1AVx/jNi2y6P2SLchVB0kcz/z8UobXpxOJqHEL6B4x7jSYHxfUTbJnXkOeoc1sOr9P2BYYDbvuws11QVAVOF5b20lxDIwCf27xRd2WA2R6mQPV3R1btgFO4+KDSOKg+dRcmWaGi7IK2qKhiAul9NQCJFgU2yDJqHJKlxngDJeV9ptHzNMCXcNAS2yo8DHOFz3l4k93c00zXf9pKeqkNo5VXbmz2YSD5V2YsXrxMaQFTobCuEw/sYBRW0Y+o4kaYl7mIT4m4Ti7i5Asv5Z0C/Tj1pPzobgLKz7f96GxN+scySPXv52r9IHoHEL990g== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=7eIyVAq2TjvKOCUTXCBrr0CN8dsLL7rvIdBMxGGR0TQ=; b=I90weMGKpg+9zA5Lq5VTwOGvw0DcX8gjUJ0jXSykhCtc5wvH3n+KaLZFTQ5NY+KSzCXz3F6uyPbM6uZdEx2baznEB0TSx5Z574hbF6O08AEvyCyVWzQQ4LbKmW6BEr9TIsvZCH9Q5sHA4smRhOVJ39MMZ7OC/m4Hm4dWEotx9OPyTvfGx9/HBgClfHkbHov+T+STHjGKZsNUV/gI2CsbVbyZTT4l4Qw3Efqzm4VDjX0NE7jI00yVJBo/oEZ+eLw3n3IXn7dmQxD4HZGFwqHWlJS1FzhGAmYsUyIpX+DzS4TpUc39ViOYe72kREV87lLp/0Bn0FypP+4a6tBNyzZ74g== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 1/6] reqs: clarify guest GICv3 virtual register model Date: Fri, 17 Jul 2026 10:11:22 +0300 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: 8b7515d2-d55d-44e5-f3af-08dee3d2b241 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|3023799007|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: u1v/VZp6qSNzK1R/S0FC+3SiHzkNrRJvh7Dhnjc/HZGWjQISjWS69bnlffr8ooo8ss5c1QC+Vm9N0LG7KXJrligtA8vz8yzDkPvQFX9GDImWnQHRcDxL7l3dcY8MlrJtDfuL4aDPBAMeIFjfHJQ8Myjyh61Ecc0Nj3k6TM9kHsMsIYxYPoMtiOZXb8TIcBheMwUSmxtYepJ5OeZmw6eadHRyHqDNwceYy799mTTp2qvN6+VzjFE+E/StA/6ARMIQitJVW13/OtZgMcBt5N5bBv8UoP/eGWY4tlQnpBHLJ8Y9WXUoag4LILqZ1spv+BnhQ0xKzhl5NO7CGslJzDkhhm4Q2Py2+XulCAUUlckI70eXVoNHUxuHEQGKfXolC0e2qcWBbrCMcmhedR+OYuAg94HPDfocdecnP1SYLY1iyF8k3duWM5CC528B5Etl39QW59F7NC8DP03BJPKPA2pMFanjrLkMwWKp/CTMYg8lH8Pfe1XWgSAFRMmKvp1/Jb15jatE4MJLxlwaxFvSBdDeO3hAiIwthAILwuNAFT6ycO7oi/ErjxIp3W4P2CxymtYIGPpAOjearbd87Eih1QScMNmDZIeYaoF7ma1mCgxNDPaGKTdVZ1UsYVgY1xLl+mX7b4NXovL5D8YovesgMCD65uVz/gHDO0nfJtiIiw+HD2o= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(3023799007)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?8nXAO71SHAC0BFLsD+5BSIo4QxdDOCJO2r93b+czLLWYZSGyxU9CScwY3nep?= =?us-ascii?Q?X6cIRq3xXmJQdlGquBWY3dJyLr0N5fD9DIgIk6h8vtxkTYZkTPplcig2ACQA?= =?us-ascii?Q?gywR9Do7Zb1YxWlJdyyHS73qccQd9gYrkbEkR8XNeIVdR1OlVJ2pQ4xjxGhb?= =?us-ascii?Q?TMS3QdPp/Or9Zu3nGg7O8ONar/aGcw56ZqcH89pL+mpu/xta3mqLXA9b6iet?= =?us-ascii?Q?NsOpXFinLJLIZJnmUnKEBSxRsT8JEqwCOeRRmxRKBvR2BqTM2JVhkqvFvwWP?= =?us-ascii?Q?xmCfrzy2ze7gPu6+DFV2TsK3OfN7LD5TPFXNWgX0CDTbNrgVh9oYUlY9wChi?= =?us-ascii?Q?U/qA//nrUuxbEKt6lSF5TAwza3abD59nULdpPe4D3Uv1G9+jyteSE5x6+Y3L?= =?us-ascii?Q?uEHth3Atj/H/vd9YXrnuc4e6sboaFkb7oEds8k06ZC9TbAAE0XsQii0Xunse?= =?us-ascii?Q?BsIPbf54b43r2PjrsXgGCfsol/knbQOcMe0EeKIn5e+JUbTguCqbpxTcm+SG?= =?us-ascii?Q?91CDRqOgNLoU/eyJlIeryjJI0wRiF7/XT/xj23ddxfB2EHQfagwTmxF1o4II?= =?us-ascii?Q?fG6d7j2rfibi9nDNBja6AG0VBOv7QibgecElEO9Skq5y/M5FTcwV0jVJMUjl?= =?us-ascii?Q?qSSfub0TzoXGUcRYJibdIxHhuHhecUi6NamXVnSZ5Tmmif4ZthN+AS6AmVGN?= =?us-ascii?Q?EoBicKNGY0F30z4FeTbjtxmfy4QC3NeYrIfhu2sOuQDv6JUMsC+pXZe4Ysxq?= =?us-ascii?Q?3ms8UNloIclUv1/8cdouEsurgILSG4xQi5nT1EtLQoZK7vSSnIkNajSZBtA7?= =?us-ascii?Q?VIuassPPHXTLU8KjRm3UIEBQymZm2UfZt7lshWT4PVool5drceJs0UmRwsOn?= =?us-ascii?Q?7MSSL6gfonb6QShZ5KKI8uGB+tWI3p9S5lBoRk9bvpVtBWyXTRWIxjW4dbuQ?= =?us-ascii?Q?YhJydiJYN4oUXcGf1v0j0oVm/sA93su0P/Kd6tZRE9qt2DKCfjf4TkWNV2PR?= =?us-ascii?Q?04+kDNYVW9hDYhvlj7Au+bnm1zlAafgLcme6WG6mN6DCF8LECz5GQAzu9UVp?= =?us-ascii?Q?5YMxTM2Q8c01a0WbaHM93unuseZ6524yoidkiszJ6KysHIyb3QGdGhKnkehq?= =?us-ascii?Q?O5thocu39xM2aarPyFexZFoz+XUJX7IjLrPkV4prwuhXAXhc427H78PC3o25?= =?us-ascii?Q?O5qbWyttjhqlp8k/WFfAq9qoNWcB2AISimmJnIhnAyq3G9tvpH4C7kUd0mRD?= =?us-ascii?Q?6GHSGLGQ8OQIOUu/9LClPbLkZb0pgGs2aHNXcQq0btbkhZHDmARx/oUO92jF?= =?us-ascii?Q?A9YbGvLB1uVIrSU0gnj2IxDWyQ0sWXSVuR7a1IM9DW6OWQJbbk5osXC4pu4q?= =?us-ascii?Q?zIp2UHJjfrOCEvN6ej/3Ea+DD7jBeZxL4PRVc09u+4l+zsfNJEkbFanljAbe?= =?us-ascii?Q?P/kW/5OcYQ9EtKQ3nHIDrWvt0ufEwmlqQ8/ODwKaJVlSHvRmoznvuPP8zbny?= =?us-ascii?Q?Hczmoz1T5mvkB3yyAukLbGZ5vlF12aa0uHQs7ndp/bgv4sz30goD4cqpocpB?= =?us-ascii?Q?jfcSJ58br36NSBzXMbuNUCxzfzvUn4jqWOVmMfbcM9/1yKVcKQ6zN2WVe/04?= =?us-ascii?Q?5UU+BLIZdRuWwbwY1bItqs9lM/yu2fKugrBQgGaN63P0Rw7QVc00FFurPA0z?= =?us-ascii?Q?7+DUU9Sbd3eg/zokWh1jws2CzZaOVbHkItIs7h5TknB1M+vaOdnMfSoyIUAT?= =?us-ascii?Q?oYdrj5Zf6w=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: 8b7515d2-d55d-44e5-f3af-08dee3d2b241 X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:00.7752 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 7bOEACeAciWAE6Qx8o9UPgcSInTIVgIAEOZKI6OmqTT8UK2ezxg2YTVvqE5EQrBNmtufdtHZAvdua5Cb9W5bZg== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-4011c0/1784272322-51AC4CFC-159338FB/0/0 X-purgate-type: clean X-purgate-size: 4020 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272359068158500 Content-Type: text/plain; charset="utf-8" Clarify the guest GICv3 requirements by adding an Assumption of Use for Xen= 's limited virtual GICv3 pending-state and active-state MMIO observation model. Xen exposes a virtual GICv3 ABI rather than a complete emulation of the physical GICv3 Distributor and Redistributor programmer's model. Virtual interrupt lifecycle state is maintained through Xen virtual interrupt state= and through the virtual CPU interface acknowledge and completion path. Do not add AoU coverage for DS, security-extension registers, legacy SGI MM= IO, WAKER or unimplemented ePPI/eSPI bits. Those cases follow architectural acc= ess or capability rules rather than a Xen-specific guest compatibility assumpti= on. Keep exposed eSPI pending-state and active-state MMIO register groups in the AoU, because Xen can expose and allow guest use of eSPIs while still provid= ing limited pending/active MMIO observation semantics for those INTIDs. Signed-off-by: Mykola Kvach --- Changes in v2: - rephrase XenAoU~arm64_vm_compat_xen_virt_gicv3_reg_model~1 add details about Xen implementation. --- .../arm64/gicv3.rst | 37 +++++++++++++------ 1 file changed, 26 insertions(+), 11 deletions(-) diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/gicv3.rst b/software_safety_reqs/domain_creati= on_and_runtime/domain_partially_emulated_resources/arm64/gicv3.rst index 2ce30e5..e16576f 100644 --- a/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/gicv3.rst +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/gicv3.rst @@ -23,22 +23,37 @@ Rationale: Assumption of Use on a VM ^^^^^^^^^^^^^^^^^^^^^^^^^ =20 -Domain shall not write to GICD_ISACTIVER registers ------------------------------------------------------ +Guest compatibility with limited interrupt-state MMIO observation +----------------------------------------------------------------- =20 -`XenAoU~arm64_vm_no_write_gicd_isactiver~1` +`XenAoU~arm64_vm_compat_xen_virt_gicv3_reg_model~1` =20 Description: -Domains shall not write to GICD_ISACTIVER registers. +Guest software shall not rely on the GICv3 Distributor or Redistributor +pending-state and active-state set/clear register aliases as an +authoritative view of virtual interrupt state. + +This applies to GICD_ISPENDR, GICD_ICPENDR, +GICD_ISACTIVER, GICD_ICACTIVER, their extended-SPI equivalents +when exposed, and GICR_ISPENDR0, GICR_ICPENDR0, +GICR_ISACTIVER0 and GICR_ICACTIVER0. + +For these registers: + + - reads return zero regardless of Xen's internal pending or active state; + - set-pending writes are supported; + - clear-pending and clear-active writes are ignored; + - set-active writes are unsupported and result in a guest data abort. + +Guest software shall use the virtual CPU interface acknowledge and +completion path for interrupt lifecycle handling. =20 Rationale: -Xen does not support the emulation of these registers, therefore the domain -write accesses to GICD_ISACTIVER registers will result in a fault injec= tion. -Also the domain write accesses to GICD_ICACTIVER registers will be igno= red. -The more, the reading of an active status of the interrupts via said regis= ters -is not supported as well and Xen always exposes all bits in them as RAZ wh= ich -might be an incorrect state of the GIC and confuse the domain's expectatio= ns. -The domain should not rely on these registers. +The virtual GICv3 implementation maintains interrupt state in Xen's +internal pending queues and hardware List Registers, but does not +reconstruct the above MMIO register state from those sources. Its +readback and write behavior therefore differs from the Arm GICv3 +programmer's model. =20 Domain shall not access ICC_SGI0R_EL1 and ICC_ASGI1R_EL1 registers ------------------------------------------------------------------ --=20 2.43.0 From nobody Thu Jul 23 21:13:37 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272357; cv=pass; d=zohomail.com; s=zohoarc; b=iSPZtHm/iiXZCqjjZEg/lxgRQiZa6TeiqgrJnJYUD8j+yi0wYJMukbu3/Y76QSewur8/2+QfmvUtoLBJ7CtIhrQj17F3EaSwUupL/PWoFTloJ4tb4uqHXgwnF7f4pObBuSmfD2DlQclIlEK3qfRWZmf+JpzhsPfabilaSeZ2TeY= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272357; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=SsnvCitpeI3GbiUP5GVRR+L9xj+M72SQ8QpfsJVVk30=; b=IRyh13d22/MLy8xihdttZZkfI7wEKtDZjrgxje82pkAHdpNOlaaymWFU6pbmXnRW7ocmIO67owG+hjTrZY3muqZrubSCOVa/UZkAaaHB5rFsm9Bz7dwT/C68chVzO75mNNPxftvj9CGR55lVppwZYGeBbL6Q9gWtCMh9YtVuQ1k= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272357706445.1371636374939; Fri, 17 Jul 2026 00:12:37 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364688.1615712 (Exim 4.92) (envelope-from ) id 1wkcju-0005o7-4Z; Fri, 17 Jul 2026 07:12:06 +0000 Received: by outflank-mailman (output) from mailman id 1364688.1615712; Fri, 17 Jul 2026 07:12:06 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcju-0005o0-0E; Fri, 17 Jul 2026 07:12:06 +0000 Received: by outflank-mailman (input) for mailman id 1364688; Fri, 17 Jul 2026 07:12:04 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjs-0005Zx-AS for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:04 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjr-008Yk2-G0 for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:03 +0200 Received: from [10.42.69.4] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5b9-5cb7-0a2a0a5109dd-0a2a4504e1ca-18 for ; Fri, 17 Jul 2026 09:12:03 +0200 Received: from [52.101.70.117] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-ebf023.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c3-b57f-0a2a45040019-3465467548ab-3 for ; Fri, 17 Jul 2026 09:12:03 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:02 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:02 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=TAQeiyYBkM3CBxaGqfx+WW3VYcOR+i1CqhCyA411/jIlCK0B5OO1fb06nWinesKclgV4yoVDORRmkqgjpRdIFiPm1Fed+hmur8qvnctVMu0OO0An9NKFYbc5txyvfSvDM9SUoK1+9v2wtPYXjJLsHPEh/ZyURIkFSGHVTsFzwot6E3Kgr3vjtH8FXPwc4lskwyDySvRpQ3Mp8pwpu2Wr2JrNycPpCHPlVcGvNlptlQm9IVHTlu9K90WTNREqrEHoaRfHVuWy7OJrRZNBa9WTlhz/wmW+jHBggSWQtKFGzqhBm6SC+iwEAvMIRFYmpRHLelAsThhfa20OEmhzr28QAA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=SsnvCitpeI3GbiUP5GVRR+L9xj+M72SQ8QpfsJVVk30=; b=Th+e8rvw7fHJKqTop1XIcNDGk6D3lJCS30iN9gJmfvVRol3wnhMbjbIVgb3gSArYk7RsluPPj3zFhC2sk2bUdSdY66IOvN/ksTmKLZXAUMX/rhU1HSBBJ9rx80BBqk6AnMz/4u5xf1ESiip+ObfVLt6WwSM2GrQKWKSD9ZjpRWBrwd3lxKM7ekNAY4oGPvcGeSvq76EJEi+uDKHILSD30PDmPllr6HfXqQ2FbnrXpWQo1SRMmdfOlvD0WPqY1PuHd9k+y0B3D5bI1Naa87oL2xTL1bfDVS/g/kkYwO2PyS9NtzsndNS9y06iTwSqvkY6avngUjg5dDFPdSDemPjtYQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=SsnvCitpeI3GbiUP5GVRR+L9xj+M72SQ8QpfsJVVk30=; b=gBDdom/oIxSR7vUj9i21u7Ey0vrWEQyk9GATF1mrKwLnCxKiGUv1MzGIU/HCsCL0BDKM8HgVg7+1LBQ3ZR770dAI6UgrPuELWPfLV7E2OYyWSI5TMHtLiuWIPtIpoYMMb1gXFwHahsudmh4JbMAvtY5JcBllW0TNpa0aguL8yEi0jEDSQ7LbHGmZXgfqApvS36uJ52v+G4oZq9XMzM39TmcaDgRkvIpIe/FB7ttcUo07HTX7R4v+pD02K9YEjTlA+fxkvb1Yn7VCdS1yd1W+TzpCKWnZDCCNxQPbVVPraRg/Cu+5GyuPvCa9k9OM3AlFSw4P01wfF2xVAlQQzJbcrA== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 2/6] reqs: add host GICv3 requirements Date: Fri, 17 Jul 2026 10:11:23 +0300 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: 67d73b72-f855-47d4-37ea-08dee3d2b2f1 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: eOyRAVX3NH+bW1VVbAtfuOlO9SLe+LOHGurvtntJYHekDfgo09UTClqaHh6Fmn8AWFkY24ZPJKMs3GMnDaGKb+LVVL8MjdLlQFuyx/BC8+oWLhIhkNWbYsAt2Fl+Dsj/4x3fCC8glXBS88bLF6yEFxXSYliUIj1hlj3CR8JIcDhmE6Xi2PA8HrKnWNCblD1S52ZdtMeew4MlSNqEPjHF9WlFpzwFvwCXD+ZG45YJY6IP/SRvIbRu9np+7MmZgceCvol7N072jXL/f9rD9lnRcCuVHOIDUWecIQeetjBV72/aYqkDVIPlzXXbipPm35xAwGTKiFD1eUwzQnFTaOn6K+lJEeDj9ccIM9VhIHwQoO+1fvtfLU9EBF5RtCOIYFpHI/VQFOtzPe9GBMnSxvVb2BXahQNNA/fmoquELSqF8tcTRuSt/frbE/WQ9Kg4HaUxPeYGpyF5PRGT/I4mdY9/mJy0rT8L2jvTy39rZV4ky1Xeh/HGonrHw6+1u8zfv7cafkUj8Fwxqh/jk3+0F3m2MbJtGtkR5A6QVATKNDGpRoA72ooy3f7/FFOkztWsUOSoQGIpTpBx8uq4dbDz9NdndXpqYAuxKUbl5Ygk7z4H5GKn7vjxgIZPosYZTsYW70nE63WHA1cIgzBPLB6GdP6UW47i4OP5STnGUabzI2lJhWA= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?HdMQEP+lPieDkQC+7QrBKRjw6LneRYOu0hMoz4c2a29WJQ4Ey+wV5Q+Qe2at?= =?us-ascii?Q?bLty+RB3WQADeYyGDVllCdU/MBMkLHZA1BI+GKJf/xPEll4C2oyPAAgqLYaK?= =?us-ascii?Q?E1H2tct0ms0l8vGxnwebxNsbBobu8rEF5s3iU9cK10XfzS01ndLFhjKTwKph?= =?us-ascii?Q?D41W6T3tEz/ONOGNK5yq6FYtn/n04WOZrpMdFUyT5Rk8jPXr1//hPHOkqVc0?= =?us-ascii?Q?fOAynmLGH3CcKEOWktJ/pmlWYqxoH43xN54AIbA5qlVKMXYDvzCyVlnWHA39?= =?us-ascii?Q?9X+itaAe7nyDrtOeiaw2OwKPcPBqEoItMlOjk4+vavhrUHZ5fUOxR7dU8f29?= =?us-ascii?Q?5lZyGocXf8qf1cOfAp6AOXUDl7Yyw5UV61G94Ca2POkqUhkTK9GWPnu71+KK?= =?us-ascii?Q?IjDVFG8i7QFWtpLqHV5CL5Wikbt+4VrxFPW1gWmqjnYv/uiJ83syTRvnTv1t?= =?us-ascii?Q?W+z820cS6y+QRtqy/my/6H9lQoTgy4dKOQE1j4gH8nkQYyxjByx1TRWiZ7fJ?= =?us-ascii?Q?OxolJyyPRxjgGorG8xIiV3aUBcHEuOxqHa4XPfBNIdrA5qJTLG7HTY5UTTt+?= =?us-ascii?Q?fvSX+x0Aw3JyHow1eP9mO7ziZkDSkLUrYE4aznmejt4Pz6jIxKUoWhb+Ass3?= =?us-ascii?Q?SXkYY1JFHqbmaiRU3Y+yrjQban5eUbbdmw0WA8kdN5f98AykoutExBqdXafp?= =?us-ascii?Q?vGu61uwJJhgs+XXqQpHsyD0YdImxgqRYar+1yGq15pbtsf/Ys64xjKNLYekl?= =?us-ascii?Q?bdb13v7zDHxOeXZVeWvzs0Hs67YsnHXIrHGVUjKdmbGsXSFBYmAWdoHa9E6S?= =?us-ascii?Q?MRrwmzjx3AWSVhlWZffn9bk08vU+BKGOUpPkVeh7fovT/iBVR2uqCpkh8B03?= =?us-ascii?Q?LnrrDBo8Okls+3XIRAgtEbTS40CtK/Wj41mQLDrk/72JIjPcxrBV+AGYeAhj?= =?us-ascii?Q?B2nFuky4i9diBa4UTfus4lF9FMhUGPDcNkvtmr/o8wJiSXp0w1r+w3echwEx?= =?us-ascii?Q?aITbu3vRm0/M/2ZmWA1Pr1+FXuBGl/b6+x+FneftmKwDp/afFz9CwO6G3x1p?= =?us-ascii?Q?J0bs4PyZwaIKlEbF7P4wAviN2C5Pb84/LOxJ2lDJPnQx1fWWXv8ud74kyiRX?= =?us-ascii?Q?+AHHRyt//ydLoaMwfnvs2J6fYDIRUZ00oEGdOvDPjiJgkYHNvKGWlP6JpmHy?= =?us-ascii?Q?IvTlvuv7bcQp4UEFQ+Wn7Wzi+eX2NXBQAFM+B7qXqBNVtfarHuO72gqc8zHW?= =?us-ascii?Q?lzYAdrizFidjt23BODrMck9er/+S0RcZB2fZ/ZxDoDj4tBjqEAdDsNkmAHgt?= =?us-ascii?Q?ZFa13H8uHLTr8RqTBXr8RddrPI79szpYWjC9y5J76j32WbJfFNpOwBci5uZw?= =?us-ascii?Q?NQkhdBXtMHtPPYcztO1V1pcEsUyyuqDXxs6SelJhvltaMjj7oIDfzycU07Af?= =?us-ascii?Q?x2PC4b3PrdLQoHAp9mm4dcCRl1VKZrtNDtzQnOXa4Irr3wEJuCR8e4iiy2Op?= =?us-ascii?Q?i5fEbpBZKEvwlwMF9Wl6h8ZtBKkX9KR8fBDUDhKwH8ghuYZ78ylOmkR5QEgF?= =?us-ascii?Q?exDjd/6LCt9c4T3r3g63+WyLGYAMFhpiRAdQh7qHO+DEsH2XZOw27umpgy4d?= =?us-ascii?Q?OeVtd1ah+jk8UV/sIcvyvMCun2FzrGbfYBP8KXwuc9fqagARSGNBMNfFTRX5?= =?us-ascii?Q?pmOR+XlTuxD4BfGuI0GaeFBroZ0ojceqyZGmmicou2WnZTcoSreWG28omFr1?= =?us-ascii?Q?1WxzP0mpSw=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: 67d73b72-f855-47d4-37ea-08dee3d2b2f1 X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:01.9861 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: H4CdNpaMWFnD9/m5wW02mF/LRD8t8odTrlMV8nmeIW8ht5ZSXH6fONCfL2KHpkku/2EDXC0dS11nCMvbG3KeVQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-ebf023/1784272323-534C3B50-63ACFD31/0/0 X-purgate-type: clean X-purgate-size: 18369 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272359327158500 Content-Type: text/plain; charset="utf-8" Add software requirements for the Device Tree-based host GICv3 path. The requirements cover GICv3-specific host behavior: Device Tree operation registration and description parsing, GICD/GICR architecture identification, supported SPI and extended SPI INTID handling, Distributor and Redistributor initialization, Redistributor enumeration and CPU association, CPU interface initialization, SPI and extended SPI routing, Group 1 interrupt acknowledge and completion, SGI delivery, and secondary pCPU interrupt readiness. Guest/vGIC state, ITS/LPI handling, host GICv4 behavior, and common interrupt-management behavior are covered by separate requirement groups. ACPI discovery is out of scope for this document. Signed-off-by: Mykola Kvach --- Changes in v2: - avoid passive voice in titles. --- .../physical_resources/arm64/gicv3.rst | 564 ++++++++++++++++++ .../physical_resources/arm64/index.rst | 1 + 2 files changed, 565 insertions(+) create mode 100644 software_safety_reqs/domain_creation_and_runtime/physic= al_resources/arm64/gicv3.rst diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/gicv3.rst b/software_safety_reqs/domain_creation_and_runtime/ph= ysical_resources/arm64/gicv3.rst new file mode 100644 index 0000000..6a43165 --- /dev/null +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/gicv3.rst @@ -0,0 +1,564 @@ +.. SPDX-License-Identifier: CC-BY-4.0 + +Host GICv3 requirements +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +The following requirements are related to Xen's host-side support for the +Arm Generic Interrupt Controller version 3 (GICv3) architecture [1]. + +These requirements cover Xen's management of the physical GICv3 interfaces, +including Distributor, Redistributor, CPU interface. + +Software Safety Requirements +^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +Host GICv3 Device Tree operation registration +--------------------------------------------- + +`XenSSR~arm64_register_gicv3_ops~1` + +Description: +Xen shall register the host GICv3 interrupt-controller operations for Devi= ce +Tree nodes that identify a GICv3 interrupt controller. + +Rationale: +Xen uses the registered GICv3 operations to initialize and operate the host +physical interrupt controller when the platform firmware describes a GICv3 +interrupt controller through Device Tree. + +Covers: + - `XenPRQ~boot~1` + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host GICv3 Device Tree description +---------------------------------- + +`XenSSR~arm64_gicv3_dt_description~1` + +Description: +Xen shall collect the GICv3 Distributor base and Redistributor region +description from the Device Tree before host GICv3 initialization. + +The relevant Device Tree state includes: + + - Distributor base address + - Redistributor region base addresses + - Redistributor region sizes + - ``#redistributor-regions`` + - ``redistributor-stride`` + +Rationale: +Xen uses the Device Tree GICv3 description to locate the Distributor and t= o walk +the Redistributor regions used by the host physical interrupt controller. + +Covers: + - `XenPRQ~boot~1` + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host GICv3 System register support +---------------------------------- + +`XenSSR~arm64_gicv3_sysreg_support~1` + +Description: +Xen shall select the host GICv3 driver after confirming GICv3 System regis= ter +support is available on the CPU. + +Rationale: +The host GICv3 driver uses the GICv3 CPU interface System registers for +physical interrupt handling. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host GICv3 architecture identification +-------------------------------------- + +`XenSSR~arm64_gicv3_arch_identification~1` + +Description: +Xen shall identify a host GIC Distributor or Redistributor frame as +GICv3-compatible only when its ``PIDR2`` architecture field reports GICv3 = or +GICv4. + +The relevant registers include: + + - ``GICD_PIDR2`` + - ``GICR_PIDR2`` + +Rationale: +Xen uses ``PIDR2`` to validate that the mapped frame belongs to a GICv3 or +GICv4-compatible interrupt controller before using that frame as a host GI= Cv3 +interface. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Distributor security-state preservation +-------------------------------------------- + +`XenSSR~arm64_gicv3_dist_are_ns_state_preservation~1` + +Description: +Xen shall preserve the ``GICD_CTLR.ARE_NS`` value when disabling Distribut= or +Group 1 physical interrupt delivery during initialization. + +Rationale: +The GIC architecture makes changing ``GICD_CTLR.ARE_NS`` from 1 to 0 +unpredictable. Xen preserves the field when preparing the Distributor for = host +GICv3 initialization. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host supported SPI and extended SPI INTID ranges +------------------------------------------------ + +`XenSSR~arm64_gicv3_supported_spi_and_espi_ranges~1` + +Description: +Xen shall initialize and operate only SPI and extended SPI INTIDs implemen= ted +by the host GICv3 Distributor, as reported by GICD_TYPER. + +Rationale: +Xen derives the supported Distributor-controlled physical interrupt range = from +the Distributor type information and uses that range when initializing and +operating global interrupt state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host extended SPI support +------------------------- + +`XenSSR~arm64_gicv3_espi_support~1` + +Description: +Xen shall initialize and operate extended SPI INTIDs only when the host GI= Cv3 +Distributor reports extended SPI support in GICD_TYPER. This shall include +use of the following registers: + + - ``GICD_TYPER`` + - ``GICD_ICFGRE`` + - ``GICD_IPRIORITYRE`` + - ``GICD_ICENABLERE`` + - ``GICD_ICACTIVERE`` + - ``GICD_IGROUPRE`` + - ``GICD_IROUTERE`` + +Rationale: +GICv3.1 defines an extended SPI range controlled through extended Distribu= tor +registers. Xen uses Distributor capability information to determine whether +extended SPIs are present before initializing their configuration, priorit= y, +enable, active, group, and routing state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Distributor Group 1 delivery +--------------------------------- + +`XenSSR~arm64_gicv3_dist_group1_delivery~1` + +Description: +Xen shall enable Distributor Group 1 physical interrupt delivery only after +supported SPI and extended SPI interrupt state has been initialized. The +initialized state shall include: + + - interrupt group state + - interrupt enable state + - interrupt active state + - interrupt priority state + - interrupt configuration state + - interrupt routing state + +Rationale: +Xen initializes supported Distributor-controlled interrupt state before +enabling Distributor forwarding so that physical interrupts are delivered = using +the configured group, enable, active, priority, configuration, and routing +state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Redistributor region enumeration +------------------------------------- + +`XenSSR~arm64_gicv3_redist_region_enumeration~1` + +Description: +Xen shall locate Redistributor frames only within discovered GICv3 +Redistributor regions and according to the region layout used for that +platform. This shall include use of the following Redistributor discovery +state: + + - Redistributor region base + - Redistributor region count + - Redistributor stride + - ``GICR_TYPER.Last`` + - ``GICR_TYPER.VLPIS`` + +Rationale: +GICv3 Redistributors can be described as one or more regions, and a region= can +contain Redistributor frames separated by the platform stride or by the +architectural frame layout. A GICv4-compatible Redistributor can include +additional VLPI and reserved frames after the RD and SGI frames. Xen uses = the +Redistributor region description to walk the available Redistributor frame= s and +to stop at the end of the described Redistributor sequence. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Redistributor CPU association +---------------------------------- + +`XenSSR~arm64_gicv3_redist_cpu_association~1` + +Description: +Xen shall associate each CPU with the GICv3 Redistributor that corresponds= to +that CPU before using Redistributor-local interrupt state for that CPU. Th= is +shall include use of Redistributor affinity information reported by: + + - ``GICR_TYPER`` + +Rationale: +Redistributor-local registers control SGI and PPI hardware state for one C= PU. +Xen uses Redistributor affinity information to select the Redistributor +associated with the CPU before programming local interrupt state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Redistributor local interrupt initialization +------------------------------------------------- + +`XenSSR~arm64_gicv3_redist_local_int_init~1` + +Description: +Xen shall initialize Redistributor-local SGI and PPI hardware state before +enabling local interrupt delivery on a CPU. The initialized state shall in= clude: + + - Redistributor wakeup state + - SGI and PPI priority state + - SGI and PPI active state + - SGI and PPI enable state + - SGI and PPI group state + +Rationale: +The common interrupt-management requirements cover per-CPU local IRQ softw= are +state. The host GICv3 driver initializes the Redistributor-local hardware = state +used for SGI and PPI delivery before local interrupt delivery is enabled o= n the +CPU. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host CPU interface initialization +--------------------------------- + +`XenSSR~arm64_gicv3_cpu_interface_init~1` + +Description: +Xen shall initialize the GICv3 CPU interface System register interface bef= ore +enabling Group 1 interrupt delivery on a CPU. This shall include use of the +following CPU interface System registers: + + - ``ICC_SRE_EL2`` + - ``ICC_BPR1_EL1`` + - ``ICC_PMR_EL1`` + - ``ICC_CTLR_EL1`` + +Rationale: +Xen uses the GICv3 CPU interface System registers to control access to the +System register interface, priority masking, priority drop, deactivation, = and +Group 1 interrupt delivery. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host CPU interface Group 1 delivery control +------------------------------------------- + +`XenSSR~arm64_gicv3_cpu_iface_group1_delivery_control~1` + +Description: +Xen shall use ``ICC_IGRPEN1_EL1`` to enable and disable host Group 1 physi= cal +interrupt delivery through the GICv3 CPU interface according to the per-CPU +GICv3 lifecycle state. + +Rationale: +The GICv3 CPU interface controls whether Group 1 physical interrupts can be +signaled to a CPU. Xen enables Group 1 delivery only after per-CPU GICv3 +initialization has completed and disables Group 1 delivery when shutting d= own +the per-CPU GICv3 physical CPU interface. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ-pcpu_off~1` + - `XenPRQ~pcpu_on~1` + - `XenPRQ~resume~1` + - `XenPRQ~suspend~1` + +Needs: + - XenVerTestCase + +Host SPI and extended SPI affinity routing +------------------------------------------ + +`XenSSR~arm64_gicv3_spi_and_espi_affinity_routing~1` + +Description: +Xen shall route a physical SPI or extended SPI to a CPU selected from the +requested CPU mask. This shall include use of the following Distributor ro= uting +register groups: + + - ``GICD_IROUTER`` + - ``GICD_IROUTERE`` + +Rationale: +The common interrupt-management requirements define the CPU-affinity contr= act +for physical interrupts. The host GICv3 driver realizes that contract for = SPIs +and extended SPIs by programming the corresponding GICv3 Distributor routi= ng +register group. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Group 1 interrupt acknowledge +---------------------------------- + +`XenSSR~arm64_gicv3_cpu_iface_group1_ack~1` + +Description: +Xen shall acknowledge host Group 1 physical interrupts through the GICv3 C= PU +interface. This shall include reading: ``ICC_IAR1_EL1``. + +Rationale: +``ICC_IAR1_EL1`` is the GICv3 CPU interface register used to acknowledge a +Group 1 physical interrupt and obtain the INTID selected by the CPU interf= ace. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host Xen-owned physical interrupt completion +-------------------------------------------- + +`XenSSR~arm64_gicv3_cpu_iface_host_int_completion~1` + +Description: +Xen shall complete a Xen-owned physical interrupt through the GICv3 CPU +interface when separate priority-drop and deactivate mode is used. This sh= all +include use of: + + - `ICC_EOIR1_EL1` + - `ICC_DIR_EL1` + +Rationale: +In separate priority-drop and deactivate mode, `ICC_EOIR1_EL1` drops the +priority of the interrupt and `ICC_DIR_EL1` deactivates the interrupt. Xen +uses both operations so that a Xen-owned physical interrupt is no longer a= ctive +after its handler has completed. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host SGI delivery +----------------- + +`XenSSR~arm64_gicv3_cpu_iface_sgi_delivery~1` + +Description: +Xen shall send a host SGI through ``ICC_SGI1R_EL1`` to the CPU targets sel= ected +by the requested SGI mode and CPU mask. + +Rationale: +``ICC_SGI1R_EL1`` encodes the SGI INTID and the target CPUs selected by Xe= n. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host secondary CPU physical interrupt readiness +----------------------------------------------- + +`XenSSR~arm64_gicv3_secondary_cpu_phys_int_readiness~1` + +Description: +Xen shall complete per-CPU host GICv3 physical interrupt initialization be= fore +accepting physical interrupts on a secondary CPU. + +Rationale: +The common interrupt-management requirements cover CPU hotplug notificatio= n and +per-CPU IRQ software state. The host GICv3 driver initializes the +Redistributor-local hardware state and physical CPU interface state requir= ed for +SGI, PPI and routed SPI delivery on the secondary CPU. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host suspend/resume +^^^^^^^^^^^^^^^^^^^ + +Suspend/resume GIC context +-------------------------- + +The Xen-owned GIC suspend/resume context covers the following register sta= te, +when the corresponding GIC version and optional feature is implemented and +enabled on the platform. + +CPU interface registers: + - ``ICC_CTLR_EL1`` + - ``ICC_PMR_EL1`` + - ``ICC_BPR1_EL1`` + - ``ICC_SRE_EL2`` + - ``ICC_IGRPEN1_EL1`` + - ``ICC_AP1R_EL1`` is checked for physical Group 1 active-priority + quiescence before suspend and is not restored as normal suspend context. + +Distributor registers: + - ``GICD_CTLR`` + - ``GICD_ISENABLER`` + - ``GICD_ISACTIVER`` + - ``GICD_IPRIORITYR`` + - ``GICD_IROUTER`` + - ``GICD_ICFGR`` + - ``GICD_IGROUPR`` is re-initialized as part of resume ordering where + required by the GICv3 restore sequence. + +Redistributor registers: + - ``GICR_CTLR`` + - ``GICR_IPRIORITYR`` for SGI/PPI priority state + - ``GICR_ISACTIVER0`` + - ``GICR_ISENABLER0`` + - ``GICR_IGROUPR0`` + - ``GICR_ICFGR1`` + +Distributor eSPI registers: + - ``GICD_ISENABLERnE`` + - ``GICD_ISACTIVERnE`` + - ``GICD_IPRIORITYRnE`` + - ``GICD_IROUTERnE`` + - ``GICD_ICFGRnE`` + - ``GICD_IGROUPRnE`` is re-initialized as part of the eSPI resume orde= ring + where required by the GICv3 restore sequence. + +The GIC suspend/resume context is limited to state owned by Xen. Guest-own= ed +virtual GIC state that is saved and restored on vCPU context switch is not= part +of the host-wide GIC suspend context. + +Save GIC state before on suspend +-------------------------------- + +`XenSSR~arm64_suspend_resume_gic_save_before_firmware~1` + +Description: +Xen shall save the Xen-owned GIC context before invoking firmware +``SYSTEM_SUSPEND``, it is required to restore host interrupt management +after firmware wakeup. + +The saved context is described in `Suspend/resume GIC context`_. + +Rationale: + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~suspend~1` + +Needs: + - XenVerTestCase + +Restore GIC state before unmasking local IRQ delivery +----------------------------------------------------- + +`XenSSR~arm64_suspend_resume_gic_restore_before_irq_unmask~1` + +Description: +Xen shall restore the Xen-owned GIC context after firmware resume or +host-suspend abort, it is required for host interrupt management before +local IRQ delivery is unmasked on the CPU executing the host resume or +abort path. + +The restored context is described in `Suspend/resume GIC context`_. + +Rationale: + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~resume~1` + +Needs: + - XenVerTestCase + +Quiescent GIC state before suspend point +---------------------------------------- + +`XenSSR~arm64_suspend_resume_gic_quiescent_state~1` + +Description: +Xen shall enter a GIC suspend point only after visible active-priority and +active interrupt state has reached a quiescent state suitable for saving t= he +GIC context. + +Rationale: +Saving interrupt-controller state while active state remains visible can m= ake +the saved GIC context inconsistent with the physical interrupt lifecycle a= nd +break interrupt restoration after resume. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~suspend~1` + +Needs: + - XenVerTestCase + +| [1] Arm Generic Interrupt Controller Architecture Specification (GIC arc= hitecture version 3 and version 4) diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/index.rst b/software_safety_reqs/domain_creation_and_runtime/ph= ysical_resources/arm64/index.rst index 8ba4601..71d8981 100644 --- a/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst @@ -6,6 +6,7 @@ Arm64 .. toctree:: :maxdepth: 1 =20 + gicv3 p2m pci_host_rcar scif --=20 2.43.0 From nobody Thu Jul 23 21:13:37 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272353; cv=pass; d=zohomail.com; s=zohoarc; b=hi7c+5y4R7gWBKgOjkb6MowQHYRdUu1jJPZvCyfGPatQ/uiXrk07Ysmk+Oz37rqcbb7JR6mw1kaUPbRmRS9uSJJA7c6EE/qM4e7SMXlcoqScrPEP6JSi570AHssGIlkdT0fJwpsbPNVecmd0qADn0jqUGnYRpUzaxDTkW7qwgIA= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272353; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=kIVFKNcVZQjluf7v8uIph/veqYCABO1SJTrjKkjRvQI=; b=Wp5uat19sDfgeNypW2yzYp/iAqBH+OyTf4/VPTzvnGm3R3IkEAuP7julBsxjAFGvClxX01YhUCFNExUnJBXUaYQvfVQ+dXjpTNKg87ox7oXjvk7xxIo1YuDgCu0EY+4R/kvos7U6D64aixtU6vk8dBIMcnQadLNWuxZF9GjZRMk= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272353389282.1151713603956; Fri, 17 Jul 2026 00:12:33 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364689.1615716 (Exim 4.92) (envelope-from ) id 1wkcju-0005rG-Es; Fri, 17 Jul 2026 07:12:06 +0000 Received: by outflank-mailman (output) from mailman id 1364689.1615716; Fri, 17 Jul 2026 07:12:06 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcju-0005qH-8X; Fri, 17 Jul 2026 07:12:06 +0000 Received: by outflank-mailman (input) for mailman id 1364689; Fri, 17 Jul 2026 07:12:05 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjt-0005n8-8m for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:05 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjs-0083h9-LZ for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:04 +0200 Received: from [10.42.69.12] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5b9-2eae-0a2a0a5409dd-0a2a450ccd0e-42 for ; Fri, 17 Jul 2026 09:12:04 +0200 Received: from [52.101.70.123] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-d25034.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c4-f479-0a2a450c0019-3465467ba3d5-3 for ; Fri, 17 Jul 2026 09:12:04 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:03 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:03 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=GeX8eAquuO6af4SypcfKt5melDVadpaEcg2+6aEx0r0JMUfAtGiJn1NBGbzV3wMvCF6y2K9F0zbHRdUqAtq6IclPEaNtfmyy0p4DddgU5hSdXDQ/kjdETuL6WvP/MoGvFr9rtbOwSYmLFcOx29EzutZrn4RVr1cFNc0t6PCwws015BGjRajm9EcDn0YfkhY9uwsCmbDTxyzJAVYSxY2fHzuW8LjB8ZkhL4DQER8T2AZ4Hy47xnzVYwX8lHthrNT25PXOcquo0MS0bzI2ZwG788PPxnlwH8MtjAW9VcoxCEXtudyWcSu6R9BwnQ/FXP8f3teLhoaK3uraB9I+5divng== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kIVFKNcVZQjluf7v8uIph/veqYCABO1SJTrjKkjRvQI=; b=BB7M9daJwYG0iuordhKGQch1PG37Ol3UOTVCnQlfLCZXMfWysO5IqATsAS9ly4Up8GpVUfz9R4vvpgI+5kDPv5Kb4qreV9/2tzv40NukR+6NTUStpqwkr+lYc5WBsN9VOWXG6qdPvFjaxxaTrhq9ZbdqmnQRYdKPy5x/gSupuVt9acizG3GJ8ZvZg1dBWA4HEWLvJvfc+IoA/PJape+ln2KNAjWiuu91fxpUZ+hGA6ScPYIKOvYX1dEnTDNhVegGJemknUyDB6k+CMr/bpodGHmnbYWf5dM+Arz+KYFXLXvNUQT5/ZkHpPquzmAyglI4YVhBCYOOcDFcHE46u6TbSA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kIVFKNcVZQjluf7v8uIph/veqYCABO1SJTrjKkjRvQI=; b=eDbsxh5jWuORdSpdTY9rR8bGkcbsJYR9wSzzMMlNUNfO/xiMDVxUAQgIkUceUAktrvbsDx408pWb2nWnhzm5xb8rd1YNKPe3FF463848MoUzJVlL8+jJwYR5mG4d5JU1wkKmph8nwv8K+yO9wEEItppQvSfxAmrI6NpM2vN6wPBVEtMMQeUD8RPc7zp+36EAHJJ5hSHThxJZh+t+jJDAhuniRJH+dSask1BbQrdE1l/xj6s5MZEkP62I4SVB+Ycw7G/02dZdUCbw+7VTTXJjGVOK2/3Mb7WXtWbE4YnCa54QFy7H+K0P+/5xqLkA8epXqqw+mWumuEnrI+n97xxkKg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 3/6] reqs: drop duplicate GIC version AoU Date: Fri, 17 Jul 2026 10:11:24 +0300 Message-ID: <338323dfeeba74f130f1c5ee336327ff07dd5cba.1784272211.git.mykola_kvach@epam.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: cead1757-b6e5-4a05-dbfe-08dee3d2b39b X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: ljLrVl+Y3cZISnv8vlKu0sNjht/CRA9vMJDDTfS9B+crYpCtbT2WHmsztUD7H/vplt7WcDFuDC6a6hub2+uNuE0KPQ7BsIUXDe2V73qyvD0DVXJrzvBBpTW944mruexFI2OZap6QOP4jWcqWr/5QB7AyvKebnzIZ+hnn9Fr4Cxpn1e566TThjL0AI5zkCpH14ps7d0ojQ7N76ygoLtR/uIdXsfBHubpbP0sra6WnVpe67LR8Fu1fjF/eOACNt8EZXek8sQNSy/gMcdZ2jzgbFfq9k6pdKcuowrSMXv51G6KJr9ZKmoee9fw+SmcwhlD72DS3kbVkGnkugXvjgaDGX+0SrE54qWf/bHnMZKF7qAL/yL4Fved8k0jgr9+aGUiTjWn73GsM55Vrw+iY+tLXePvZRAnZ6Bx/tE+++5jC0CYZo5VR5E+kJcAUJ+fqKskzsWwz7QuXLrrVfjpXY8N+WWeACLICYXmcxUjsTiSoTIOWDrvYk5n6zUiTJ+jJUdwDaVPzDqTAJVTa9zknBI4vRL4jWI0wTudm3CshO/8ecLd9ghYo2MRG6sc24tXsq9JoU5rJ7BpiWOkHuCOFS4Crruy73DuIKAHhJTVKqXPet3GzZM9NqlExMjhE2PxD7fFz+JVzDc2T/aGNZ7itCPpd1fnLdWClxEpEVZvTlHL8S4w= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?oKFXBw4RvmL93JhhVbpaK7TWotOBb6FeAtGWKah8xbyYItFTGBx3/mM6BurO?= =?us-ascii?Q?m5EpOVuF1IhaEA+7Nlp+52C9p1CQsPsd3jZaExLgDlGb1cRHw3qlMjKW2tL6?= =?us-ascii?Q?Ht1C3YVUlzfh5KsPA99vQ3Q0DfytGwObdqiACOBtOE7qYHNp/h0ll8RGDNc4?= =?us-ascii?Q?MlRZsFl2eUh/HY/YA0Bf0Dg/WBhuFtjfuIg3O8q8fCNTwW9bJDx9wE5sRv0j?= =?us-ascii?Q?jT4sH4b2DQEoJGdqaynCwYNKH+SLX8n1aKBaGdaP4r5zI5tUU6D4GbFWDW/n?= =?us-ascii?Q?HOB1U+wfLs0d+vapzPs/YXG28aX24cU5WFi5/2MuWZ+oEMhKrEnXs3FYtZHf?= =?us-ascii?Q?NjvOKZO1EO+6iwXxgvrSvTM1g2/IHDy1iAlpjZzUUYQ6XI9SMJdSqab5wbb5?= =?us-ascii?Q?JJFalxse39OAuqyOLLU6Tb7yrl8g/AfjK25BgdUtRMXFkH4YVJL7xuEhm6GD?= =?us-ascii?Q?QCIZ7AOKzVf+KNDiu3Nlx6p7k+pR+vxkDwwfgMZKEaxVe5Wp2lzj5+6hiefD?= =?us-ascii?Q?c2563JF9O/bXETJfcGX6sRMjvIXN/t/XWKvZWRtx9bmHIrNlw0tMIcRoDG3O?= =?us-ascii?Q?uZMAPqtQ42SM0QDf4jpl434RTs4I8tuvpoEER0m+5Vm3PuXDr4u2X5eJG65J?= =?us-ascii?Q?y89HmoaRhZroTMUVtXpQfIJM2gbJ3R/4Od0NLT5aKAJPGhWrPhR4nI0Om81u?= =?us-ascii?Q?6/cehhAKD5zjPkIetwLqzpeX6yNmHQ9NjgK8Anta24Nn+v6gF5Z4QlsVwbyX?= =?us-ascii?Q?n0N92FqLWaZIK5x+fOsJYGadHql67RQltLXYJ24t/yfOVoWNbdoxcp2F0EI5?= =?us-ascii?Q?Vv/zWMjEqaXCikrKgZZBLcMpuQJGXnvIALXDtK25EQK/ze4nBSwsuBSF855b?= =?us-ascii?Q?n6WQ3QII6b8c9w68RM68FqXEoAXeKbp4pPaQ21WSyMT1Q88NmXOoN+f8PkFD?= =?us-ascii?Q?e+qb0YPH0NSCBPOX1LfgYBg766OLJUM2TJe1A8ebzQ/3ukDKQ6M9qZA+mO98?= =?us-ascii?Q?bW+NC6+0AU8bi7NsgU+Hl3/w44yi4v/hQWN6zzKsEDqDsiI9Y5beNOMdGJLg?= =?us-ascii?Q?dY7/Ml5AE3E373KtxZf4ploS16iTKZ4+C2tf7MNy7S8JmpJ50HBWZulSZimk?= =?us-ascii?Q?7Kexm1BPj0gKFN7AwyD+hYDk40dPLEIY9B4nAeFF9S3ZmmmMrhx1o7hIAbfE?= =?us-ascii?Q?Tahwr/2k2JZ7Eiq49dU1668r1iKzQIr5TFCAWmnv4dahUOnk7Ik34nL/xfZW?= =?us-ascii?Q?xUIkxY+JpUG6a/Xn1hpYruCApaDE08o3rDdXQgcuGKbVSalS4glCOFTuz5Mf?= =?us-ascii?Q?OyESM0fnU8Y8WMXxGuJLNZBHmvBllxxrnTTGMaDTgOz29NpLMFbiNpqKlcGf?= =?us-ascii?Q?RaHiR9Cn8c+e62emiGm2w7k+gsGwbhBQZYFGtt83017zbnAiiTFgA4HjoFTm?= =?us-ascii?Q?qAiTir4MRXS+gGewvi3cTIVV4XGdh9CxYJIN08qIyrDDPZoh0pjkfNPQel62?= =?us-ascii?Q?+8fISf2hJJ1f3je6GtYpaTHqUMioaK3t1pCcup8xJzQbCt795RMIdfHjKJTk?= =?us-ascii?Q?5ckO0GUG2hzx/++7pXfQltiglRoUwF0bOHpT74gE69Pu4vnz5dsdv1s8bHGn?= =?us-ascii?Q?c2/GVWVF9GulyLSSrBptwDJbXhh2xgQVTaY0wgSHnR13koIHB3WkVULcygPR?= =?us-ascii?Q?1Lb9j/veLq7WAj4g5M+ATjivvGy7/iWlnLpNclSCV7MicvxwQAZ7PF/bG/Ap?= =?us-ascii?Q?eDLtZfRdAQ=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: cead1757-b6e5-4a05-dbfe-08dee3d2b39b X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:03.0269 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: +50zw0AcgzzdTUXo6LymYa1xBqnpqDw3uJVY5D3Jt8OeFBqNBRJnntRRWaVVwCvzi/NERU4o1R01YEyAkvWqMw== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-d25034/1784272324-030D9A5B-1B3E1569/0/0 X-purgate-type: clean X-purgate-size: 1502 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272355030158500 Content-Type: text/plain; charset="utf-8" reqs: drop duplicate GIC version AoU Drop the AoU requiring GICv3 hardware. The certification scope also includes GICv4.1, while the supported physical GIC version is already specified by the corresponding PRQ. Signed-off-by: Mykola Kvach --- Changes in v2: - drop AoU instead of moving. --- .../arm64/gicv3.rst | 13 ------------- 1 file changed, 13 deletions(-) diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/gicv3.rst b/software_safety_reqs/domain_creati= on_and_runtime/domain_partially_emulated_resources/arm64/gicv3.rst index e16576f..2c146f0 100644 --- a/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/gicv3.rst +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/gicv3.rst @@ -7,19 +7,6 @@ The following are the requirements related to ARM Generic = Interrupt Controller, version 3 [1] interface (hereafter, GICv3) exposed by Xen to Arm64 domains. =20 -Assumption of Use on the Physical Platform -^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ - -GICv3 shall be present in the hardware --------------------------------------- - -`XenAoU~arm64_platform_gicv3_presence~1` - -Description: -The physical platform shall have the ARM Generic Interrupt Controller, ver= sion 3. - -Rationale: - Assumption of Use on a VM ^^^^^^^^^^^^^^^^^^^^^^^^^ =20 --=20 2.43.0 From nobody Thu Jul 23 21:13:37 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272359; cv=pass; d=zohomail.com; s=zohoarc; b=YoxxwIonxipv+2FumN2BAk44VPzQV7oBZ3Nraigy3ynSc/qniyU0bNRFk5e3j5E+IdmmNWeKfBOjx6ub1rxqQjF6RPLpwN8bT2lyxsXt0jxIEZekh/eXt2Oh9kVoi4TINyc/lv/uH0r4EEvowUSlAR288odf12gooEI84o7zKAg= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272359; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Dr92w94V0rPtA/gfsJJq+CW+myR1yaLgep3VMkEZMFY=; b=lu6ICmrRgmcjplFizh0FMAqxFFQxLkO7aoqS5nlPH4eoXjJeIIZwt6jQPFgAq9Zj3HCs94N2dq1HND1LwCN3j6gOkN7TGfQEgX4TbNq9pTdgJz2od5ml772q5wfhJypMZuk/odSzdHypgNsRBDQQDjK2YOdm5nQtjytvHK5CnEQ= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272358939700.1226193276499; Fri, 17 Jul 2026 00:12:38 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364690.1615729 (Exim 4.92) (envelope-from ) id 1wkcjw-0006H0-Ri; Fri, 17 Jul 2026 07:12:08 +0000 Received: by outflank-mailman (output) from mailman id 1364690.1615729; Fri, 17 Jul 2026 07:12:08 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjw-0006Gt-Nr; Fri, 17 Jul 2026 07:12:08 +0000 Received: by outflank-mailman (input) for mailman id 1364690; Fri, 17 Jul 2026 07:12:06 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcju-0005q6-Dx for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:06 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjt-00H0XY-Q2 for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:05 +0200 Received: from [10.42.69.1] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5b8-e002-0a2a0a5209dd-0a2a4501c0f4-30 for ; Fri, 17 Jul 2026 09:12:05 +0200 Received: from [52.101.70.109] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-d62444.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c5-5984-0a2a45010019-3465466d3704-3 for ; Fri, 17 Jul 2026 09:12:05 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:04 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:04 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=pkN2og13ZaOs6pCSf2b6V13pUP00uvbFKfnmq/pOxzK2CxXFTFcLWS2Un7yzUHrjDObFUo76VL3squv/mUjGwcGgz/SXJPKmlZsCxaINt+/sFQ5wXwe9A35j/GrrU/tlI8CzmtmN9r2w9mH1EURMS8wKsRd7pFawqEun94c0qH7xtT0gaK0gzqofnDbNi7grcUHyyAtM/SiIcIPWF88i7u/lR1TwhDp0iEt+yZDnrngyV1VzPxOGx+F8oh6g0DYQcooLl8byIdqlOXsm2HWSAlzj3/UDdOC0POeMrhT5BrNC/IDibAMrqzrcVYorBEHd1tlXGuPykbRzTWGDZTmu9Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=Dr92w94V0rPtA/gfsJJq+CW+myR1yaLgep3VMkEZMFY=; b=G+aQZ8kgU9EqBDcqP0IGFlIbWyrJXZswLSJ2PpwDlWMR6dMJfMzHWQ27UEm/F4V3Xg03NsHHIBQeMy++zXw3LMqEhxdtWreJk+3vsOaXHoOPN9wMPOFTpa2QmLuzn4kksMUXr9Pk/H/RwT6i4LDF2r17xxQPeNoQsZPQGo8FAlGpQxWOweOKspm2Fv7Wtkq+LO/ogaVIvOsO+/pEH080jd0RBXfDPbKvfS8gJTK9p92EVRHJ4wZbgVPqD3nAm+0EBnwg2Dk1VVyhsBZwi/VaLBAIJejWU639TrCCC5pSOqWMb+t/hAzn8djsm8+lYhGEBYTrCQvKTSpD4/axzS/z9w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Dr92w94V0rPtA/gfsJJq+CW+myR1yaLgep3VMkEZMFY=; b=BhmdUUqufW6wRg7hNTXRK7IzcmYj4wQBYxR+YM1o7j9Ri6ArTwiz+f9a7ucnwZAFt3bXiZGDlOCQWZZZEX/+VCGUBoK/PX7MxXTUFQ+0FTu3Bqc3SmZl8Pr31LsP6/7g2f32agMBV39YZVGMyJ3Oy/HbhyCWRLIKTMgAvg26Jviv/gwb+oivK5JRCeeO2FzkWF+YenXCffxgzv3xyEodXZ+ePItOTptewp8E0eo0Xr1j51yu7Ue+pPCYxCcIRVtpUByRKWZ06FP8mVc6rE995dUbZoSL6kNNlpeRUvXFZSzlozctt/ykbzhWDDHAWHS8qIrjRnzjqj/iXb0OLD0UvQ== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 4/6] reqs: add host ITS/LPI requirements Date: Fri, 17 Jul 2026 10:11:25 +0300 Message-ID: <614929b338211f30efe8a51f61a4ad263ee862e6.1784272211.git.mykola_kvach@epam.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: 37012a48-e8f5-431d-1b3c-08dee3d2b447 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|3023799007|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: NNqpgIXR+oaO0M6dYKuPsmAMDyjTT87chavq+newrG6nqU7UvqpLxYIeSz5vcl5X07Tos2MaKxbD9mhnORCdBcRrpepVUgeIjdYIo80VkCLIs4kZo5TcCFjma726T/G2SAGGC46TZD6x1S5l/rX4wOeSVGJP7RDNKaqKMvzWsMZJAncLR225DKFOpch34me7i8wtH9EuCNCRNNBxSaAjmYHYI5zN5GCATki38Ak6857/W1PnhKRNIFgcllvNqu09xX837IhHVxhfB9eHlJeOkK/xcZViim17BvyFHEHscv7JgE/HMge9TJlYby26k709kntJ6zXFHNVBhslmMwZPAR1Ixvi0+szJKwXcVIoiBSC9KlwJQghpvDYHDvfVZl/1mpIGlgOQD7EtD2ZwBWkJX+VyEChtX+AyCMkp0iylsCFgBnc0VeHSRySORI6PQyxeQQ74YZKlJjyPEDD3c6fmPW7/ePtoHt5ziDOju8Pq2r/v60BFhrGa8CuSN69yWGLvNBwnlimb3o3tHiVEbYg9hiujkWVELyZ6wg7iLYHX+TGZ8EIvsh9mrPCXhdXfb6ef21raUHfMzTYUq2Mi6o5FwwNBwt98C1ubFpuglYGsQa8JKBLWgI50P/XSsg7xVRcEq2JaF3fg2fM9LPzPEWLeadgJhphRz/FFbrLKWZ9RWdM= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(3023799007)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?/xGa+0kVRo9yJU7+7D8NeepsMZf2LOgQeycSUlAA2owKwLMnm4qODSHOEMvL?= =?us-ascii?Q?dLe95/jb3abA9k4uLDdoJv7/JFwqxWZufue0xpcB/0Sbw1zzsxdlxxIr/C3c?= =?us-ascii?Q?BRiocUGEugeb9/Q+n5i4jN/a5h5H6PywtCZorBaCv9k8h8cEP070ZgtVtEM+?= =?us-ascii?Q?Q+XCe46yfg0Qhm3qkmhVfwQ2maLSmzNr9HPW9AytJqxOrrncAS0v5VLWNdCd?= =?us-ascii?Q?57t+RizY4fPb2a/gIFsApWG6zazuJ+6zSX+Ej0qkgRENn8deSinwX5xLrVzP?= =?us-ascii?Q?1PIdxaGDenKoo+eMuu+Bev4nVr+V6i5/WdkYv1VZJmFwa6fDlYrxADlY4Tox?= =?us-ascii?Q?O+IAnLR3Xw98yuEqPVNvsW7LpKBpl+YPY8SY9Y+DqyWLDoIwg7JTik9deiwK?= =?us-ascii?Q?BloU7K1tyohxwcRr81cqLEDotQLSvl3r0wWL+BszzSYUcp3fqnu+1ri7XHVC?= =?us-ascii?Q?QOEDoNIm3WIjqf5GPmChXwnBMCyG7XxgENaHeXpot70+bXNgmJK5LzzfGtv1?= =?us-ascii?Q?fuo+QdZ0qm3EOfoV+u9gpY0mJHplGdsupn6pMO+jFFCyx2fObhSv1k4/i1bN?= =?us-ascii?Q?/8m5HOEkqE7c8LQApWQ4WlunZtJttkMvHYAAP+GK5CJOV7VWfhesaAusTfJe?= =?us-ascii?Q?u94yfjh8yk6wzPZW3WqR7ABteNPA7sQpIXFo++D7N8omZaMWPrDZaaZeZW3I?= =?us-ascii?Q?7NhDWeZSd725os1ncW5ik+ao3bJm4Z+zwa2U5mOhJlKk7l8x3rXrPhQZfigX?= =?us-ascii?Q?7IvA4u3HgLNgXbS85KaSXBkYqKU9vtrP3u425DHlAjGtQseuRf4J01614NRi?= =?us-ascii?Q?suqEi3Jie67GGivJuhXpsggsUmvLmZAql8g5YzSzuZgIqrCC9MVGEq0DjAKc?= =?us-ascii?Q?kcRNp0ADwz9ktbwJZCabVmkcAQ3fqAzV2nsz+tqmvgxaQ8c1aaAsNe51u3ku?= =?us-ascii?Q?SoINrQznQ2o0NEdm6boZsol0G+pB5NOC7IFNfeD8KIUGEdhMSOEah7wPCEDF?= =?us-ascii?Q?Sx2iuYCXgGzO61VklJiAaSkRUCJ3wVeUQtMyjQww1H2blI9fw7/VP4QnB6UI?= =?us-ascii?Q?RH8eG4bHFGYDBUo8hRWm2w34zFbe7YwIAfvJ3lSIO+BxCq9OS1UcsyY3DwoW?= =?us-ascii?Q?WALw8dqODF2EkITHotPSgBMhR7UWnn984E3WTUM6BRf2a956OL60vEjZfFOZ?= =?us-ascii?Q?S2+btf86AUaoiG9VLMqa9TNfJphfa5ZmhEVBynVDzisKBbXzgXR4jgg1I+sN?= =?us-ascii?Q?ertLObqkgQ61ELUgq2oabVbmjeE9DfwTwQrDuA4oge1taxdw89UUsf49SsrK?= =?us-ascii?Q?IdHWDnf+jk8vSOUYnINh53hZXVif9Mr/O7Y2tRwiLska4cxf9ZCcOTd+NOuE?= =?us-ascii?Q?9e01vXh5qSRQ1MOYKiWixR7t1/VhcNblbV/1M5xfTfzb4+tMgq+s4++Ez6Ij?= =?us-ascii?Q?q8jV97wjkPHIzWtCAjQaE0dLR9SyJUgAVTfXcR00mixU9i8gmTJezaqt7Afm?= =?us-ascii?Q?PxZQf+fq0TVipo2XxZ2C0w/5TQDIR2MvM5d3kTe7epJDv3NIiL46+N2yd0re?= =?us-ascii?Q?mQroS7CRBVFXOMMg9pv5Fn93+ecOFSAorporJjTNn1YX0OTpFxWM/526V3W/?= =?us-ascii?Q?vZmQ533mwDRE4rL2dtWAQ8aH2lMGtyb7W6Z4a9pTBpVdxHrrkw/32XwHuQYP?= =?us-ascii?Q?03nnesXJSKH0H0yfKwmSwUed66C6AD6yUEnCOo3IdX6H6CFp/CKaCmU74Oka?= =?us-ascii?Q?Sttc/yPjzQ=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: 37012a48-e8f5-431d-1b3c-08dee3d2b447 X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:04.2570 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 2l+Geg4UxQ8vUh2DdX822quNRBtli7kl0kWRdtePj7anYxYHEH5L0hLttVQwuA/jqHXcSvaZshnQoGeBY8iqmQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-d62444/1784272325-BC95A757-4198AD93/0/0 X-purgate-type: clean X-purgate-size: 15908 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272361291158500 Content-Type: text/plain; charset="utf-8" Add software requirements for Xen's host-side ITS-backed LPI handling. Guest-visible ITS behaviour is covered by separate requirement. Signed-off-by: Mykola Kvach --- Changes in v2: - avoid passive voice in titles. --- .../physical_resources/arm64/index.rst | 1 + .../physical_resources/arm64/its.rst | 519 ++++++++++++++++++ 2 files changed, 520 insertions(+) create mode 100644 software_safety_reqs/domain_creation_and_runtime/physic= al_resources/arm64/its.rst diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/index.rst b/software_safety_reqs/domain_creation_and_runtime/ph= ysical_resources/arm64/index.rst index 71d8981..cd1aaca 100644 --- a/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst @@ -7,6 +7,7 @@ Arm64 :maxdepth: 1 =20 gicv3 + its p2m pci_host_rcar scif diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/its.rst b/software_safety_reqs/domain_creation_and_runtime/phys= ical_resources/arm64/its.rst new file mode 100644 index 0000000..6024259 --- /dev/null +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/its.rst @@ -0,0 +1,519 @@ +.. SPDX-License-Identifier: CC-BY-4.0 + +Host ITS/LPI requirements +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D + +The following requirements define Xen's host-side use of GICv3 ITS and LPI +interfaces [1]. Guest-visible ITS/vGIC state and GICv4 direct virtual LPI +delivery are covered by separate requirement groups. + +Host ITS Device Tree discovery +------------------------------ + +`XenSSR~arm64_gicv3_its_dt_discovery~1` + +Description: +Xen shall discover host ITS frames from Device Tree nodes compatible with +``arm,gic-v3-its``. This discovery shall include use of the following Devi= ce +Tree state: + + - ITS node compatibility + - ITS register frame base address + - ITS register frame size + +Rationale: +Xen uses host ITS frames to translate assigned-device MSI events into host +LPIs. + +Covers: + - `XenPRQ~boot~1` + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS initialization before use +---------------------------------- + +`XenSSR~arm64_gicv3_its_init_before_use~1` + +Description: +Xen shall initialize a discovered host ITS before using it for MSI/LPI +translation. + +Rationale: +A host ITS translates DeviceID and EventID values into LPIs routed to +Redistributors. Xen relies on initialized ITS state before creating host e= vent +mappings. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS quiescent state before configuration +--------------------------------------------- + +`XenSSR~arm64_gicv3_its_quiescent_before_config~1` + +Description: +Xen shall put a host ITS into the quiescent state before programming its +command queue or translation table base registers. This shall include use = of: + + - ``GITS_CTLR.Enabled`` + - ``GITS_CTLR.Quiescent`` + +Rationale: +A host ITS can retain outstanding commands or translations. Xen ensures th= at +previous ITS activity has completed before programming new host ITS state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS command queue readiness +-------------------------------- + +`XenSSR~arm64_gicv3_its_cmd_queue_ready~1` + +Description: +Xen shall configure the host ITS command queue before issuing host ITS +commands. This shall include use of: + + - ``GITS_CBASER`` + - ``GITS_CWRITER`` + - ``GITS_CREADR`` + +Rationale: +Xen issues host ITS commands through the ITS command queue. The command qu= eue +state determines where command entries are stored and how producer and con= sumer +positions are tracked. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS translation table readiness +------------------------------------ + +`XenSSR~arm64_gicv3_its_translation_table_ready~1` + +Description: +Xen shall configure the host ITS translation tables required by the select= ed +ITS before enabling that ITS. This shall include use of: + + - ``GITS_BASER`` + - ``GITS_TYPER`` + - ``GITS_CTLR`` + +Rationale: +The ITS uses translation tables to store Device, Collection and other +implementation-supported translation state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS command issue +---------------------- + +`XenSSR~arm64_gicv3_its_cmd_issue~1` + +Description: +Xen shall issue a host ITS command only after the command queue has space = for +the command entry. This shall include use of: + + - ``GITS_CREADR`` + - ``GITS_CWRITER`` + +Rationale: +The ITS command queue is a circular queue. Xen advances the command queue +producer position to expose command entries to the ITS. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS command completion +--------------------------- + +`XenSSR~arm64_gicv3_its_cmd_completion~1` + +Description: +Xen shall complete the host ITS command sequence required for a mapping be= fore +reporting that mapping as successful. Depending on the mapping operation, = this +shall include completion of the relevant command sequence using: + + - ``MAPC`` + - ``MAPD`` + - ``MAPTI`` + - ``INV`` + - ``SYNC`` + +Rationale: +Host ITS commands complete asynchronously. Mapping success depends on the = host +ITS completing the commands that create, update or invalidate interrupt +translation state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS command failure propagation +------------------------------------ + +`XenSSR~arm64_gicv3_its_cmd_failure_propagation~1` + +Description: +Xen shall propagate host ITS command issue or completion failure to the +operation that depends on that command. + +Rationale: +A host ITS command queue full condition, command issue failure or command +completion timeout means the dependent ITS translation state cannot be tre= ated +as committed. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS Redistributor target encoding +-------------------------------------- + +`XenSSR~arm64_gicv3_its_rd_target_encoding~1` + +Description: +Xen shall encode host ITS Redistributor targets using the RDbase format se= lected +by the host ITS. This shall include use of: + + - ``GITS_TYPER.PTA`` + +Rationale: +A host ITS can identify Redistributor targets by physical address or by +Redistributor processor number. Xen uses the selected ITS target address f= ormat +when encoding commands that refer to Redistributor targets. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS collection target setup +-------------------------------- + +`XenSSR~arm64_gicv3_its_collection_target_setup~1` + +Description: +Xen shall complete host ITS collection setup for a CPU before using that C= PU as +an LPI delivery target. This shall include completion of: + + - ``MAPC`` + - ``SYNC`` + +Rationale: +A host ITS collection identifies the Redistributor target used for LPI del= ivery +to a CPU. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS DeviceID and EventID range +----------------------------------- + +`XenSSR~arm64_gicv3_its_device_event_range~1` + +Description: +Xen shall map host ITS device events using DeviceID and EventID values wit= hin +the ranges supported by the selected host ITS. This shall include use of: + + - ``GITS_TYPER`` + +Rationale: +The host ITS uses DeviceID and EventID values to index interrupt translati= on +state. Xen derives the supported ranges from the selected host ITS capabil= ity +state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS assigned-device mapping setup +-------------------------------------- + +`XenSSR~arm64_gicv3_its_assigned_dev_mapping_setup~1` + +Description: +Xen shall complete host ITS device and event mapping before reporting an +assigned-device interrupt mapping as successful. Depending on the mapping +operation, this shall include completion of the relevant command sequence = using: + + - ``MAPD`` + - ``MAPTI`` + - ``INV`` + - ``SYNC`` + +Rationale: +Assigned-device interrupt delivery depends on a valid host device table en= try +and a valid EventID-to-host-LPI translation. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host ITS setup rollback +----------------------- + +`XenSSR~arm64_gicv3_its_setup_rollback~1` + +Description: +Xen shall remove host ITS and host LPI state created for an assigned-device +event setup when that setup fails before completion. + +Rationale: +Assigned-device interrupt setup can fail after some host ITS or host LPI s= tate +has been created. Xen removes the partial state so that later interrupts c= annot +use an incomplete mapping. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host LPI support selection +-------------------------- + +`XenSSR~arm64_gicv3_lpi_support_selection~1` + +Description: +Xen shall enable host LPI delivery only when the host GIC reports LPI supp= ort +and at least one host ITS has been discovered. + +Rationale: +The reviewed Xen host LPI implementation uses an ITS to translate MSI even= ts +into LPIs. Without a discovered host ITS, Xen does not configure Redistrib= utor +LPI delivery for host LPIs. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host LPI Redistributor state readiness +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +`XenSSR~arm64_gicv3_lpi_redist_state_readiness~1` + +Description: +Xen shall enable host LPI delivery for a Redistributor only after the LPI +Property table and a zeroed LPI Pending table for that Redistributor have = been +initialized successfully. This shall include use of: + + - GICR_PROPBASER + - GICR_PENDBASER + - GICR_CTLR + +Rationale: +The Redistributor uses the LPI Property table to determine LPI enable and +priority state, and the LPI Pending table to record physical LPI pending s= tate. +Xen enables host LPI delivery only after both tables have been initialized= so +that host LPIs are delivered using initialized Redistributor LPI state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host LPI INTID allocation +------------------------- + +`XenSSR~arm64_gicv3_lpi_intid_allocation~1` + +Description: +Xen shall allocate host LPI INTIDs from the physical LPI INTID range suppo= rted +by the host GIC. This shall include use of the following state: + + - ``GICD_TYPER.IDbits`` + - configured Xen host LPI limit + +Rationale: +Host LPIs are physical interrupt IDs used to represent assigned-device eve= nts. +Xen limits host LPI allocation to the implemented physical INTID range and= to +the configured host LPI limit. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host LPI ownership lookup +------------------------- + +`XenSSR~arm64_gicv3_lpi_delivery_ownership~1` + +Description: +Xen shall resolve a received host LPI to the domain and virtual LPI associ= ated +with the active host ITS mapping for that device event. + +Rationale: +A host LPI represents an assigned-device event after host ITS translation.= Xen +uses the host LPI ownership state to identify the target domain and virtua= l LPI +before handing the interrupt to the virtual interrupt delivery path. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Host suspend/resume +------------------- + +Suspend/resume ITS context +^^^^^^^^^^^^^^^^^^^^^^^^^^ + +The suspend/resume requirements below apply to Xen-owned host ITS state and +Redistributor LPI state. The covered context includes the following state,= when +the corresponding feature is implemented and enabled on the platform. + +ITS state: + + - ``GITS_CTLR`` + - ``GITS_CBASER`` + - ``GITS_BASER`` + - ``GITS_CWRITER`` is reset after restoring ``GITS_CBASER`` so that comma= nd + queue pointers are coherent after resume. + - ITS collection state is replayed only when the collection is held in th= e ITS + itself. Memory-backed collections are restored through the restored + ``GITS_BASER`` tables and are not remapped unconditionally. + +Redistributor LPI state: + + - ``GICR_PROPBASER`` + - ``GICR_PENDBASER`` + +Save host ITS/LPI state before suspend +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +`XenSSR~arm64_suspend_resume_its_lpi_save_before_firmware~1` + +Description: +Xen shall save the Xen-owned host ITS/LPI context required to restore host +MSI-to-LPI translation and LPI delivery after firmware wakeup before invok= ing +firmware ``SYSTEM_SUSPEND``. The saved context is described in the +`Suspend/resume ITS context`_. + +Rationale: +Firmware suspend can remove or reset host ITS and Redistributor LPI state.= Xen +saves the Xen-owned ITS/LPI state before entering firmware suspend so that= host +MSI-to-LPI translation and LPI delivery can be restored after wakeup. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~suspend~1` + +Needs: + - XenVerTestCase + +Restore host ITS/LPI state before use +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +`XenSSR~arm64_suspend_resume_its_lpi_restore_before_use~1` + +Description: +Xen shall restore the Xen-owned host ITS/LPI context after firmware resume= or +host-suspend abort before issuing host ITS commands or relying on host LPI +delivery. The restored context is described in the `Suspend/resume ITS con= text`_. + +Rationale: +Host ITS commands and host LPI delivery rely on initialized ITS tables, co= mmand +queue state, and Redistributor LPI state. Xen restores the Xen-owned ITS/L= PI +context before using the host ITS or relying on host LPI delivery after re= sume +or suspend abort. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~resume~1` + +Needs: + - XenVerTestCase + +Replay ITS-backed collection mappings when required +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +`XenSSR~arm64_suspend_resume_its_collection_replay_conditional~1` + +Description: +Xen shall replay host ITS collection mappings on resume only for collectio= n IDs +held in the ITS itself, as indicated by ``GITS_TYPER.HCC``. This shall inc= lude +use of: + + - ``GITS_TYPER.HCC`` + - ``MAPC`` + - ``SYNC`` + +Xen shall use the restored ``GITS_BASER`` translation table state as the +source of collection state for memory-backed collections. + +Rationale: +ITS collection state can be held either in the ITS itself or in memory-bac= ked +tables. Replaying collection mappings for memory-backed collections can +duplicate or overwrite state that has already been restored through +``GITS_BASER``. Conditioning replay on ``GITS_TYPER.HCC`` keeps the res= ume +path aligned with the ITS collection storage model. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~resume~1` + +Needs: + - XenVerTestCase + +Tolerate retained Redistributor LPI state +^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +`XenSSR~arm64_suspend_resume_its_retained_redist_lpi_state~1` + +Description: +Xen shall tolerate platforms where Redistributor LPI state is retained acr= oss +CPU_OFF/CPU_ON or host suspend/resume, and shall avoid reinitializing reta= ined +Redistributor LPI state as lost state. + +Rationale: +Some platforms retain Redistributor LPI state across CPU power transitions= or +host suspend/resume. Incorrect reinitialization can corrupt retained pendi= ng or +configured LPI state. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~pcpu_on~1` + - `XenPRQ~resume~1` + +Needs: + - XenVerTestCase + +| [1] Arm Generic Interrupt Controller Architecture Specification (GIC arc= hitecture version 3 and version 4) --=20 2.43.0 From nobody Thu Jul 23 21:13:37 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272347; cv=pass; d=zohomail.com; s=zohoarc; b=PqYE3B4zWFtVSq9KXw/i+2vkhSt8KeDzdeDVsiR629kIAGfd7r8IewyDwL/DsLJaz8N3LM/Fw9viZBFaQ8Mugqz8Eyyduuz414V+7l9w8jT+2wGJ3UMsPmmcd9efH7yZePpGVkBpfx7E2jaHHZvvHibmUSoe/HKVwqOGoMKrtwc= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272347; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=WIciFQaFNHypn0GkHYDK8/qC14CWFarWv6ht6FIi8uQ=; b=SRuUFyk7sxbvQ6lRU0yeYrQHvorrQ3nruKcA7onvgQfQPA+W4Ux9z3i1bS8QwM5VJFsyWbT7ZpmE0oU6mC+KWft8Hf1x4hHlWhVot+NtZSynbG8vpOs/VJ6Pjyf9kKW4p6CwTO6TBt30YYqtr6l+8cSnUxMjfNkR461AuGpMdLY= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272347633246.30141162391783; Fri, 17 Jul 2026 00:12:27 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364692.1615734 (Exim 4.92) (envelope-from ) id 1wkcjx-0006NE-A2; Fri, 17 Jul 2026 07:12:09 +0000 Received: by outflank-mailman (output) from mailman id 1364692.1615734; Fri, 17 Jul 2026 07:12:09 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjx-0006Lr-4r; Fri, 17 Jul 2026 07:12:09 +0000 Received: by outflank-mailman (input) for mailman id 1364692; Fri, 17 Jul 2026 07:12:08 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjw-0006Fh-2j for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:08 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjv-0083h9-FP for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:07 +0200 Received: from [10.42.69.7] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5be-2eae-0a2a0a5409dd-0a2a4507dbc4-18 for ; Fri, 17 Jul 2026 09:12:07 +0200 Received: from [52.101.70.127] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-ef75cf.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c6-b4ea-0a2a45070019-3465467f3013-3 for ; Fri, 17 Jul 2026 09:12:06 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:05 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:05 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=dUc/2qtKQ5ZlnX8XY9KtmUFGA/haDup8GMKT7p/Fn1YHlPR3i7YEcvElRzCTrO4kpJfBmRFRUKa2YNQiop40b5V7gQ2SAcqpeuJ5QLO2VQ/hITRkr1wT6DGaYRvJkdM6cCWgjly4aCzw4I+p1GPo40SORTyk7zexc8/pQvitMP4ULkrgTs1/GaFitVc7q7jE/K0jgyic7rMHptXHa1p+UZyp+AL6TiJ6GLB/iHJuaK3TdDYtM0f691MA51lAK5oYFqYlaemCQp9fEuRMLQDW0HJD0hn03TzhH5WIhjujDi/I0yI2UXo8sJhYS89PwQxoHn6yI5WRnhvTFhNPvJH2RA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=WIciFQaFNHypn0GkHYDK8/qC14CWFarWv6ht6FIi8uQ=; b=qPT+PUTDy7m493s1nop/LFySYEZK03l6giNDL7mW5C6oofJZQiVaWwxMmRZQhoyvSx7LLUaMdmoPvkb3aaxxp4u6f2+pD8hq9oTzJzZWF3PIoaXRUgmCba0NZI+9LLxmHg6/9HsShaz5HFlrKogc4T85IJt/LLJoAeKgQXR1txfwgdx98ROWV2ppcGm7q+43zKObPXAKEFR5ELJZTBItsQma0zVQn7s/UI837MFcYSwVBhPfuYIIxBu9UqhB/UpLK//NbAqmutSIneLe8O+NphGgqrP5BHCoWBHQvmhMMnpiHP847nwJVniv+NjP/Sug3Hj81LrkP93om548LKSDBg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=WIciFQaFNHypn0GkHYDK8/qC14CWFarWv6ht6FIi8uQ=; b=PMUkvUp7b52RVb6lef07/n8F3gyhIl0MbLFQqEW4Nhkd9KBlF0k0l3wK5ZTT2OeMneu8lLhlnZE3q9/Oi7k89a8/DvU1kPzHk4g8H9TYi78V3yk7LAAMKWJfoWS0VSeIcTweZ5G1Ef31IstobOTpOgKAVMGP+GEg6KDn0f4CVgCICWpYSTFZGcweRHk+X4v3th2KrGFxKX9quG4hX13rrrc5b/xVaIn+QvAa2wD1wdMF8PUtGHQNjgJpoTobjtVz+UYrt0kdtCp9r+AAX1ioXWrkTXp7gymTNB53HNLt+68QUWyuDMTO3M8QTK4exqd3QNEx4vn7PhTqpGJjYbDC5Q== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 5/6] reqs: add guest vITS requirements Date: Fri, 17 Jul 2026 10:11:26 +0300 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: 6ef09fd2-55b5-46bc-f819-08dee3d2b509 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|3023799007|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: wxuvcW1r/sYYWZ7zSAPumUSZPOTJw3hqV3caXFqE+lREK3pQkNRHNj8MpUeDAnX4ilaudkWYJnCrDgzKRsM5Od8QzwjizMApDcjKV/2EmS/4aQMQLkEA+h1+xqhOB98eiHm95f8KsNMFjSEAaYRg88fT/Cgc8A9iUb6X7iZCrSn2dM+bR6pXsgl3Yb5AfAGkl0/MQmeU8D0gwXZQyOu9vXPo959vygfk7gIKa7zCY94LpxlQjHDjjO7fejnz+0M/8C/4AY9+UdwqNUiFKGIHVyl1mzIsHWeeWuS1AzaP+4Wxf1gUh9DDjJNSZuqZFuLyd5OgjcCeaGvJgjvoghGHljS2/v6KrvTSGqSKd+74YGNY7IrrUgSqycZ01xaK+d4SUK3s2p/9aSlDabLIiWyDCgQcorE3ig6BcZwGccA5ANlBaPCm3djip3KHXDZUFc2uqPEvhQIl9VmmR/xou8aNQCN9425FDI17YQnpEC6yLZ3+iOOHUjQ57o1s4E90qDu3V5B2wo646PbB6PD8yYXg3oJ9+1kAJp6+2zNoxjKMK+O8vhiPCAZGDef8FWDgmwrUdAcSWNfANRIF8Uh/Mu7xc94YvqLIvQX2L2YytaPRL+LpjrqjMYwyi5Bzxvtyvnub6Q4by6MpNY9cGAiWv8Q72QxEOjgxnhUBRixsa3Py+0k= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(3023799007)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?dl4zlOGJfyesQ+vxuxRfcMWG51HP8SJ3IGmXW1gMfySyRf4+0uxGHv266QBC?= =?us-ascii?Q?sEiAcjTmQameAKJ4MATr33LC4AhjufPqbRv3sUudo6h1LALVxeximWAgln30?= =?us-ascii?Q?KiFBy71/dSzZwsivUR+/JVrjUJbNekchNCzaowskkif+/hEncwh35vN5lD0Q?= =?us-ascii?Q?aPY9E5Y7jpfLDaVwPbjn6OQLnORz4MA1MkNdj2VqCntmpMmJxHM3N+pwCgw7?= =?us-ascii?Q?TNihOjfj8rc8HYOmWhTBdwBH53LE3FGfc7QjYQAWd2cry4zvAndGYrUAiY0Y?= =?us-ascii?Q?hKd+WJ+s8LNCb/znEzMd3xrhFN4jyD5Hdfzy/WGgmler0tlEaGeroJiWE18z?= =?us-ascii?Q?GLZaQRW8q7JOJuhdkr62VEvzLUjxVFWzFaH7YP7FUbH5yM4Fh47ABknCBsi8?= =?us-ascii?Q?wD19ZwqQ1crvOA7r9Idb0HahAo1QWUgGa6CJ4SMkp5aybQ2lXTrEhpAaby1j?= =?us-ascii?Q?ay0Gjh/tCH9WuF0kAKd+gzogvfiLEYD9u3+uFB+kvTlIB29rrxFyRTUQJ7+w?= =?us-ascii?Q?+6CB/cTfFiy78QDsPOBGxdnWyKioJIHw7Fshm24gOXHrqC7x7i0fsNR047mt?= =?us-ascii?Q?TywqERus+LWY4m6otuKg8mLuQgQA+g9B7qxUBSE95/NBHuJcIs2dVmDxyghZ?= =?us-ascii?Q?ZK+gqVE727zika169ZDKDif0kw+XinoN5riu1Nbl4byimAYVrzxN9/36cTVM?= =?us-ascii?Q?R7dJjfXHgerpLUSvRo+yGX8UFBd0jrhSaKvXTViqzVtApjauWMw117BZT07t?= =?us-ascii?Q?uhCWcxkxy1FlLgTpObYD6kORZyHSKqrkOxkQC0W5EuSqs7B7UEnT61F3u/2P?= =?us-ascii?Q?pdQs6AzSdGIGBpCvn/X4DLTsZJ+VuAjHV4vDUJ4x/cCMRHjyNmhajgF+sCA4?= =?us-ascii?Q?0iNacngE+e7qcENqKhSUz4fwCJ85CZDfeFTZnVtAkgs24Y6sj5Uubor08oMm?= =?us-ascii?Q?uZxHdPfYv0Ju1mVHxe12+mmNbeJ8AaYca90rXBMo00jCD54ht9f42sDXqhtn?= =?us-ascii?Q?ia1kUXbzMpfiAsuRB1rA/plgGtm82VHT5jENifCpObcQIE56rO1sbSAvId8z?= =?us-ascii?Q?NlkxzlMYkJN3Dhp6BMLn4uO7QFKzXbiK2OM/R+TNyZ04ONX1e2E2C4GyBiu8?= =?us-ascii?Q?l5VSnvLBl5MR/TC9IwTMdZYjB4lKR9Z2okVZn/3xzG6y9TZjggTfm7n/Xv7/?= =?us-ascii?Q?ouLNZtzpg7OIf3UzqPD4POurEv5RiLYW2IhY0bG/bDcOmIX9NFXRaBs1sSrW?= =?us-ascii?Q?1/LoRl018Ll5g6+pjVEGTs3QWWKJrfg23+4xep7mlV6UX3LbGQvudHdHKY74?= =?us-ascii?Q?Zi9M3dNdsdxPBX2E36/lwtz7uGOxLs2enRhDTUr8p8JNq+R4hxKDrfFaolMG?= =?us-ascii?Q?jOWcqwc/vZpqqIf6hExwT0h7obmE4/JVM/ipxk8HSnAXpgXZZaQ4Adfa0QbH?= =?us-ascii?Q?v10uUi1MeU/AFSz++3sZbZ4ctmocot5wuYZOaV5ETn0H3X27oBe4aCI5NYQ2?= =?us-ascii?Q?4+m37fI4S9nGuJOwXzlaYDEXXVGm3B4Ux7oggu3zLjernBGJr2Vx7OtvV069?= =?us-ascii?Q?NZPUgzJrIGhUrU+wl5zUZ9ISqMZF91SLGHHecbGuB2FllQpG1AusWD7Chtqo?= =?us-ascii?Q?gxdLuyg6694owgoNRvVzWe/EYpLdeUR+lNBTsvKFW8OU54VRS8G9Qk1XzevX?= =?us-ascii?Q?3c34G69t8RBt/XiTlKw+htldNnWXPQ6KDA1nbCgrr4/H0ioWbVm95BfGApTo?= =?us-ascii?Q?Z2shvdUXMg=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: 6ef09fd2-55b5-46bc-f819-08dee3d2b509 X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:05.4821 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: 8HONH4tvVkR2pCLIsqbipnIN6/kj0lfCuazOs6cOf8fDVfPERtB0Vk1fLq+DVy+4IQERyWWmaeg8YtvksL1s7Q== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-ef75cf/1784272326-3C212AE4-EA0E1285/0/0 X-purgate-type: clean X-purgate-size: 12315 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272349112158500 Content-Type: text/plain; charset="utf-8" Add requirements for Xen's guest-visible virtual ITS model. The requirements cover virtual ITS instance creation, guest-visible ITS identification and capability registers, guest ITS table base programming, guest command queue processing, guest command validation, MAPD, MAPC, MAPTI, MAPI, INT, CLEAR, DISCARD, MOVI, INV and INVALL command semantics, command failure containment and virtual ITS MMIO access-width handling. Signed-off-by: Mykola Kvach --- .../arm64/index.rst | 1 + .../arm64/its.rst | 382 ++++++++++++++++++ 2 files changed, 383 insertions(+) create mode 100644 software_safety_reqs/domain_creation_and_runtime/domain= _partially_emulated_resources/arm64/its.rst diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/index.rst b/software_safety_reqs/domain_creati= on_and_runtime/domain_partially_emulated_resources/arm64/index.rst index 263fc09..7896770 100644 --- a/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/index.rst +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/index.rst @@ -8,5 +8,6 @@ Arm64 =20 generic_timer gicv3 + its tee viommu diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/its.rst b/software_safety_reqs/domain_creation= _and_runtime/domain_partially_emulated_resources/arm64/its.rst new file mode 100644 index 0000000..5258588 --- /dev/null +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/its.rst @@ -0,0 +1,382 @@ +.. SPDX-License-Identifier: CC-BY-4.0 + +vITS requirements +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +The following requirements define Xen's virtual ITS model exposed to the +hardware domain. Non-hardware domain virtual ITS exposure is outside the s= cope +of this requirement group. + +Assumption of use +^^^^^^^^^^^^^^^^^ + +Guest software virtual ITS command use +-------------------------------------- + +`XenAoU~arm64~vits_command_use~1` + +Description: +Guest software using Xen's virtual ITS interface shall be compatible with a +virtual ITS model where the following guest ITS command behaviours have li= mited +guest-visible semantics: + + - ``MOVALL`` is not used to move virtual LPI mappings between collections. + +Rationale: +Xen exposes a virtual ITS ABI, not a complete emulation of every physical = ITS +command side effect. + +Xen maintains virtual LPI translation state through Xen's virtual ITS devi= ce, +collection and event mapping state. Guest software is assumed to use the +supported virtual ITS command subset rather than relying on unsupported co= mmand +semantics or on asynchronous physical ITS command-processing behaviour. + +Software Safety Requirements +^^^^^^^^^^^^^^^^^^^^^^^^^^^^ + +Guest ITS instance creation +--------------------------- + +`XenSSR~arm64~vits_creation~1` + +Description: +Xen shall create a virtual ITS instance for the hardware domain when the +hardware domain is configured to observe an ITS. + +Rationale: +A virtual ITS provides the guest-visible ITS register interface and command +processing model used by the hardware domain to configure LPI translation. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS identification and capability registers +------------------------------------------------- + +`XenSSR~arm64~vits_ident_and_cap_regs~1` + +Description: +Xen shall expose guest ITS identification and capability registers accordi= ng to +the virtual ITS model implemented for the hardware domain. This shall incl= ude +use of: + + - ``GITS_IIDR`` + - ``GITS_TYPER`` + - ``GITS_PIDR2`` + +Rationale: +The hardware domain uses the virtual ITS identification and capability +registers to discover the virtual ITS interface, DeviceID width, EventID w= idth, +table entry size and supported translation behaviour. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS control and quiescent state +------------------------------------- + +`XenSSR~arm64~vits_ctlr_and_quiescent_state~1` + +Description: +Xen shall process guest ITS commands and report guest ITS quiescent state +according to the guest-visible ``GITS_CTLR`` state. + +Rationale: +``GITS_CTLR.Enable`` controls guest-visible ITS command processing. +``GITS_CTLR.Quiescent`` reports whether virtual ITS command queue processi= ng +has completed. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS table base programming +-------------------------------- + +`XenSSR~arm64~vits_table_base_programming~1` + +Description: +Xen shall apply guest ITS command queue and translation table base updates= only +while the virtual ITS is disabled. This shall include use of: + + - ``GITS_CBASER`` + - ``GITS_BASER0`` + - ``GITS_BASER1`` + +Rationale: +Guest ``GITS_CBASER`` and ``GITS_BASER`` values define the guest command +queue and guest translation tables consumed by the virtual ITS model. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS table model +--------------------- + +`XenSSR~arm64~vits_table_model~1` + +Description: +Xen shall expose guest Device and Collection tables supported by Xen's vir= tual +ITS model. This shall include use of: + + - ``GITS_BASER0`` for the guest Device table + - ``GITS_BASER1`` for the guest Collection table + +Rationale: +The virtual ITS uses guest Device and Collection table state to translate = guest +DeviceID, EventID and CollectionID values. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest command queue processing +------------------------------ + +`XenSSR~arm64~vits_command_queue_processing~1` + +Description: +Xen shall process guest ITS commands from the command queue range describe= d by +guest ``GITS_CBASER``, ``GITS_CREADR`` and ``GITS_CWRITER`` and advance +``GITS_CREADR`` for handled commands. + +Rationale: +The guest command queue is guest memory. The queue base and command queue +pointers define which commands the hardware domain submitted for processin= g, +and ``GITS_CREADR`` is the guest-visible command progress indicator. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS command validation +---------------------------- + +`XenSSR~arm64~vits_command_validation~1` + +Description: +Xen shall reject guest ITS commands whose fields do not identify valid vir= tual +ITS state visible to the hardware domain before applying the requested map= ping +change. + +Rationale: +Guest ITS commands contain guest-controlled DeviceID, EventID, CollectionI= D, +virtual LPI and table fields. Xen validates these fields before applying +mapping changes so that invalid commands do not create invalid virtual ITS +translation state. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest MAPD device mapping +------------------------- + +`XenSSR~arm64~vits_mapd_device_mapping~1` + +Description: +Xen shall apply a guest ``MAPD`` command with the valid bit set when the +DeviceID, ITT address and event range describe a guest Device table entry +supported by the virtual ITS model. + +Rationale: +``MAPD`` with the valid bit set establishes the guest DeviceID-to-ITT +relationship used by later event translation. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest MAPD device mapping removal +--------------------------------- + +`XenSSR~arm64~vits_mapd_device_mapping_removal~1` + +Description: +Xen shall apply a guest MAPD command with the valid bit clear by removing +the virtual ITS device mapping and the event mappings associated with that +DeviceID. + +Rationale: +MAPD with the valid bit clear removes the guest DeviceID-to-ITT +relationship. Event mappings that depend on the removed device mapping can= not +remain active after the device mapping has been removed. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest MAPC command +------------------ + +`XenSSR~arm64~vits_mapc_command~1` + +Description: +Xen shall apply a guest ``MAPC`` command when the CollectionID is valid an= d the +target Redistributor maps to a vCPU of the same hardware domain. + +Rationale: +A collection selects the target vCPU for translated LPIs. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest MAPTI and MAPI commands +----------------------------- + +`XenSSR~arm64~vits_mapti_and_mapi_commands~1` + +Description: +Xen shall apply guest ``MAPTI`` or ``MAPI`` commands when the DeviceID, +EventID, CollectionID and virtual LPI are valid for the hardware domain. + +Rationale: +``MAPTI`` and ``MAPI`` create the guest event-to-virtual-LPI mapping used = by +later event delivery. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest INT command +----------------- + +`XenSSR~arm64~vits_int_command~1` + +Description: +Xen shall inject a guest ``INT`` command as the virtual LPI selected by the +command's valid DeviceID and EventID translation. + +Rationale: +``INT`` requests delivery of a translated guest ITS event. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest CLEAR command +------------------- + +`XenSSR~arm64~vits_clear_command~1` + +Description: +Xen shall apply a guest ``CLEAR`` command to the pending state of the virt= ual +LPI selected by the command's DeviceID and EventID translation. + +Rationale: +``CLEAR`` removes pending state for a translated LPI. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest DISCARD command +--------------------- + +`XenSSR~arm64~vits_discard_command~1` + +Description: +Xen shall apply a guest ``DISCARD`` command by removing the virtual ITS ma= pping +for the command's DeviceID and EventID. + +Rationale: +``DISCARD`` makes the selected event unmapped in the guest ITS model and +removes the associated virtual LPI state from the active event mapping. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest MOVI command +------------------ + +`XenSSR~arm64~vits_movi_command~1` + +Description: +Xen shall apply a guest ``MOVI`` command to an existing mapped event when = the +destination CollectionID is valid for the same hardware domain. + +Rationale: +``MOVI`` changes the collection target for a translated event. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest LPI property invalidation +------------------------------- + +`XenSSR~arm64~vits_lpi_property_invalidation~1` + +Description: +Xen shall apply guest LPI property-table changes to virtual LPIs selected = by +guest ``INV`` and ``INVALL`` commands. This shall include use of: + + - ``INV`` + - ``INVALL`` + +Rationale: +The guest LPI property table is the guest-visible source of LPI enable and +priority state. ``INV`` refreshes one translated LPI and ``INVALL`` refres= hes +LPIs targeted to a selected collection. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest ITS MMIO access width +--------------------------- + +`XenSSR~arm64~vits_mmio_access_width~1` + +Description: +Xen shall apply a guest ITS MMIO access to an implemented virtual ITS regi= ster +only when the access width is supported by that register. + +Rationale: +The virtual ITS MMIO interface has register-specific access widths. Xen us= es +the target register definition to decode guest accesses so that unsupported +byte, halfword or unsupported-width accesses do not update implemented vir= tual +ITS register state incorrectly. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase --=20 2.43.0 From nobody Thu Jul 23 21:13:38 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass(p=quarantine dis=none) header.from=epam.com ARC-Seal: i=2; a=rsa-sha256; t=1784272364; cv=pass; d=zohomail.com; s=zohoarc; b=UDIDBrUYCgGjSvfGaUHdudM+GnBTvT24sb2G+oV1gNL+LGmR4xHAIb0xGbdtzB2dNsBAmreUZavkhilZdmrr+QTxU41UO1D9wd6DFzUWx/LWecqlgcoWinq9Lk6jWaVqdfG0oV+HjMy9zjTKOL4jteNa9uqLoZtHxI2tb+btx94= ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784272364; h=Content-Type:Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=kHZeubp6rodZIu6FKlqVypVjLIt2F/eJExuxnKnFRKc=; b=AfY/P+6hRsQOiqr8IKmMtYk9CslR5OoabL42gSilWKut4NgxYWrpqkDCoALhk2cQSrYZpzfxlEQlaHOqH762uKAs52REy9mWPoWhPCey1WCHz2F6wMHSgG6vTfR6Cif6LQkVXsBqFSidtA/RYXdD3mL29E+/QdQezedIvIqNbMM= ARC-Authentication-Results: i=2; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; arc=pass (i=1 dmarc=pass fromdomain=epam.com); dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1784272364693703.3279277617034; Fri, 17 Jul 2026 00:12:44 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1364693.1615747 (Exim 4.92) (envelope-from ) id 1wkcjy-0006kB-LG; Fri, 17 Jul 2026 07:12:10 +0000 Received: by outflank-mailman (output) from mailman id 1364693.1615747; Fri, 17 Jul 2026 07:12:10 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjy-0006jN-HV; Fri, 17 Jul 2026 07:12:10 +0000 Received: by outflank-mailman (input) for mailman id 1364693; Fri, 17 Jul 2026 07:12:09 +0000 Received: from mx.expurgate.net ([194.145.224.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1wkcjx-0006JV-6D for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 07:12:09 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1wkcjw-008Yk2-Ij for xen-devel@lists.xenproject.org; Fri, 17 Jul 2026 09:12:08 +0200 Received: from [10.42.69.12] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a59d5c7-5cb7-0a2a0a5109dd-0a2a450cc734-8 for ; Fri, 17 Jul 2026 09:12:08 +0200 Received: from [52.101.70.89] (helo=AS8PR04CU009.outbound.protection.outlook.com) by tlsNG-d25034.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a59d5c7-f479-0a2a450c0019-34654659d56c-3 for ; Fri, 17 Jul 2026 09:12:08 +0200 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) by AS8PR03MB7985.eurprd03.prod.outlook.com (2603:10a6:20b:428::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.13; Fri, 17 Jul 2026 07:12:06 +0000 Received: from AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7]) by AS8PR03MB9746.eurprd03.prod.outlook.com ([fe80::cf11:309:1384:58f7%6]) with mapi id 15.21.0223.011; Fri, 17 Jul 2026 07:12:06 +0000 X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=epam.com header.i="@epam.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=rqk4QIMBkIPpiWVVBexJ2xREhFStjddPGa75WEvkFwSKD2J6ZNCc7VxznNneQrPHtsokMiyxXmz+X6XLi+ok5ku3miETDxfF4vgB5ZxuDvthTk17L2dp+5nbWVqVpYGqMxDyWdAO6mwMXiMEEtBngJmYA6LQjh7rLXQxox1XZy/YAkO7Xr9r8GUa8fMS0Siwtmk4h/zpH8aYvjDK/b+hStwoLbLKZKcD6yoExEjm82fMBL8iM9sbn2Z+X0JlhHi9OMlx4l8Mr7uVkzr4pILtDBAHAuDglj4oiQB2aO2bXWvEd5r7+GJH/NMQaHiadQGEHl3TdztNIkZCelHlKZ403g== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kHZeubp6rodZIu6FKlqVypVjLIt2F/eJExuxnKnFRKc=; b=k64083KrxcN3MX0uVmWM9fptJbNWKxndtSZ1kxtUwPkHDT18nLjmlv6OoJeZZ/bV8K7tDJhfNe65c4qf3d/sZ6EPXrhNLzVdluV6G+s9NlWvCuOaCDfv0MheukcbS1ak8xx6mXr0gr0Alv+FYl6fBzHZ5uZB06s2GSXW/gNBLyqPI75SFdygaI3tkMYCzLikAdgjCivxmHucr6u1oS2ZHaMBjWFCZdVaJpvU6/+ihyZrXfpr0S+HR9NokzMIuQXq9gFNvoqODkZvOmbd5/u+bHn1rRfyqEvMlaSSWaILnkDEn0BwyYPdbbm39tggZJMSL4tsInwFDo/6wfxtvVSuIg== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=epam.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=kHZeubp6rodZIu6FKlqVypVjLIt2F/eJExuxnKnFRKc=; b=PA0SzqI2ZBGI/MLA6R7Bh8AwiRKFYl0fFDWtvcyoTdHC3uuctCwca1BQZ75NOao86exR6JWP0lC0UYua7V6QFMuZakXud0QPNTHtathmgoA0NkZyDcqZ/H5fIj5h7D5VRHXQ55u5YvEMmW9S9u1VYkMxZLDOO45IeiNvLhexBRfjG8cA8ZOdf89LCnEeUDL7Og6pA5XbVxxR4Rs7ReB1TGrtf82rymQP612SiXNqVHz3pWeKFI3ss8oYsmAInxu55H7aDqI8I3yxuB/EJoNfx3j5HN87aQo89FC2GFi2ffbtMwnK+lhtG/YbGWh13MbFp7gVkT7PMAozYrHRzh2rYg== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com; From: Mykola Kvach To: xen-devel@lists.xenproject.org Subject: [REQUIREMENTS][PATCH v2 6/6] reqs: add GICv4 direct-delivery requirements Date: Fri, 17 Jul 2026 10:11:27 +0300 Message-ID: <76e371b97b8376f552fbfeb51d1ef3a3dec38006.1784272211.git.mykola_kvach@epam.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: WA0P291CA0022.POLP291.PROD.OUTLOOK.COM (2603:10a6:1d0:1::22) To AS8PR03MB9746.eurprd03.prod.outlook.com (2603:10a6:20b:61d::18) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: AS8PR03MB9746:EE_|AS8PR03MB7985:EE_ X-MS-Office365-Filtering-Correlation-Id: 883cdd68-e1ab-4f0f-8260-08dee3d2b5b8 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|1800799024|366016|23010399003|376014|18002099003|22082099003|3023799007|10067099003|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: 9pR8ZLgg7KMHD+YgPDqsCiLbmMs5mHFAPq/Zc4t8ULLL+UB04B731vANgD2LWpVoO0KjgE2UeHpmjpUqaKEpp8q04pkSJHZn4rOLSBXgLGVsqq1NMO/iAG23Qsx3AmoafemuxESx5RiKHKNWPNZsbE2WdBxsGKhLDXNCWfc3EWv3gFbq0b3PrxAJ/1DAys1NTcC9mkSk8l5e50sse1q/2eQ7xw8twaZ1CNZ5glY3NArwOH6M1aWoImRSy8B+YgUD/RE6x36hxHPR5wJcytSrI1sWTxFD8x77Ph9r+rG4rmBSjhZPcSucbnBc4hCj/O20FSmtSmU+LAtz8GDRPLhOZmuvtyh7+gUK7Giahp41J0xnvZFsYcEiYovwp/Oj0rhGnjRX7AJmCW7yr7dlhVZdQqe8hOYG7cJHvIAWtXMvDFdlNYzjUb2c87yNmMAn+RBhcJQ2TIYlnFG0yNK+7mi5/MsNvAlC4IGDikf1PYdpcO/fGpRCDqvT7eUEafXWg9dwlPGOyX9Q1W45WQ2Jq0BZbppx8VbXPPZeJzGrdhEXKlP4plwaUSztSXWZhmk8mPFwY9TngGYaUjddt8dkEo6ejMIBOqasy/xRRoVL9xlLJpCiJs7hDBfHhiIJPxH40nY3PVxTq+ARQBs+71CKFfMR6g3gQbxLBE9puvXxqAyI4QE= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:AS8PR03MB9746.eurprd03.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(1800799024)(366016)(23010399003)(376014)(18002099003)(22082099003)(3023799007)(10067099003)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?tsJvBHiBAK3ICPqOAPxsMwFmWTylcz49y0ALc+B0n3XkcxtctFWMEzfdf2/7?= =?us-ascii?Q?FaM5wUQohl1yaLP6J4De4HYX/3ayRxDXMI0DRfrLBC54GoerjFqINShSGv2B?= =?us-ascii?Q?KdHvK0RDyUsBgGnDqKt6vG4NOl9Rdhq7t1N1cNxl/7slC1NQMgSFgFJJ+FYP?= =?us-ascii?Q?arSjzfvIlqnAk9L2eFJBp0474Sb/++joFOMHfh7pSsvpELyc5U+Y2MiUdZn7?= =?us-ascii?Q?PiqaV0WkumFRIG5vkwHDSN0xamQnBTqa905JDmLIDV5ZLw1iRN/hrIylL3Jm?= =?us-ascii?Q?xB7eRPOxBEH8pMdpsE8RFFl9XAvC8cMVzDUOZndhg2Sp5Xlm4s+WEa6prWqJ?= =?us-ascii?Q?xDUfjSTJkoyayMDJacdXnqW6iRnlkIOXAXNJlVN7AvrRTLugrkwiNqiT9WaB?= =?us-ascii?Q?aEs/tzTGAdakTq1ED9aJJnOCQsAb+O8uuOS5EaKv5amOrSJbPiSXpg0hbp8z?= =?us-ascii?Q?52G34TYCp3ZHeQvJeRkOsgi7AY9e33DIAPg7y6LwZtYG1SmnDVPiTe6Odjbq?= =?us-ascii?Q?XZlsA8U6YYH2r0G/lrMSRkI4ESexBNkbUl4ZINTUZscaI/h77MZXTHFXwjiu?= =?us-ascii?Q?40G/galNgg67lqgUKm7ZbZFSuSHS9v5shj9Kr+jHviAtWd8jHu4itReqNA/N?= =?us-ascii?Q?HMxnstN3F9dR0Vl6VKk071caPGgzMS7+F1zsldspyoj+P3H+atQEOOhLpm6Z?= =?us-ascii?Q?Ki2yg5klOXGC/keK9r8sptc77mMMX8Hri2vK5YAQ2Uh1Ow/cr2S2/P1sVQOI?= =?us-ascii?Q?t52oX/4d2okbhl45fyJM6VORifItWo2gmG0fdr50ImY1gWB2nqWceV6o1fWE?= =?us-ascii?Q?eADpvjJL/ibFd10uCcWvHw0a5xf3q85jtkstIW7oymqfqkMtKjETRSWGROaO?= =?us-ascii?Q?1lxE0WjjV4UXenHqv8/zsyJb1A6hyjdtYBF6wIzzETwVRqN4wZBi8pXud5lT?= =?us-ascii?Q?Uu2Fzda3p4yASCPM1WI6Wr/q5PDCdJmCDkneQ4LQnQbYA11I2Ea1jApneXo5?= =?us-ascii?Q?ErXaG/lH6zWWtRLwrG66AW+GwqCnSF9KzMwzVpg9jR7vo82Ww1ehpcqkhncE?= =?us-ascii?Q?SBG2KJOx/T4r8wequsp3ln+wXjKwxlooJk0Kf9GYYzcKcoQhfOYOY/5GqZhu?= =?us-ascii?Q?OMWb+xqBSuypeGKyMGUYHn8mAuATZ0EyHS9gf51IDSsqqgH0hPSf5UOkHru7?= =?us-ascii?Q?qKjL+b1mpTMPLnQWAAIKEONfC0+SK8+V5VS9oid4RQUyOcq7a7Z9yp2aYtBP?= =?us-ascii?Q?bGKPh3+xGs6mHaSThjPiEfDNgvdE0IVPmsAjV2Eq07Vj/2zm1ClbYX8XNhCw?= =?us-ascii?Q?0UeKDyqS+gdP1eoYZxW8CXkmqdIYHJl4LJTPXGinZ76HelLa/6Z+xqBVKou0?= =?us-ascii?Q?SpF9DNkpr7VpgjO8BxWlIWXCx8KFfZgwXS8AlOGPFbNiFQ0YxHRICmPGo5mz?= =?us-ascii?Q?g1HUFlDXqUqOUpn77xn5vTaxqW6cal0eg2SM+jLW76cwdUtqi9+rGSYFGQ+y?= =?us-ascii?Q?tWR3ZJIcCkcSxeZytD54BpR1fe/pevlwUDU7/FKbB4jVTvFz1beLLltbg+b8?= =?us-ascii?Q?L9TOQasQTDE3BXwU81QR98BsFXCvQY56rxMh961xI8Eu/BHt8iWTtcw7pef6?= =?us-ascii?Q?oycTv/8g0PESToDTvRi5qXgQD5KZlnjAiS1e+FGThl4Rm9yJEpqfgSc+RP+G?= =?us-ascii?Q?oNqAaxT2LYQNPjdpvm1VYD/8QQPZXv7EPdCGebQ4kbC/g+Xw/iCQrMAMu3TH?= =?us-ascii?Q?XPeo5mBXhg=3D=3D?= X-OriginatorOrg: epam.com X-MS-Exchange-CrossTenant-Network-Message-Id: 883cdd68-e1ab-4f0f-8260-08dee3d2b5b8 X-MS-Exchange-CrossTenant-AuthSource: AS8PR03MB9746.eurprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 17 Jul 2026 07:12:06.6446 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: b41b72d0-4e9f-4c26-8a69-f949f367c91d X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: H5F4VdULB19WUekUony4ySBbaczQQu2xw2zd4vLHujEM3lQLgjiGJlgkBtGv6VYZB+oQjeBH8mbs4+D9QZBj6A== X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR03MB7985 X-purgate-ID: tlsNG-d25034/1784272328-5290EA5B-50CEFA32/0/0 X-purgate-type: clean X-purgate-size: 24105 X-ZohoMail-DKIM: pass (identity @epam.com) X-ZM-MESSAGEID: 1784272367324158500 Content-Type: text/plain; charset="utf-8" Add software requirements for Xen's Arm GICv4 and GICv4.1 direct-delivery support. The host GICv4 requirements cover backend state such as vPE lifetime, residency, doorbells, direct vLPI mappings and GICv4 ITS command handling. The vGIC direct-delivery requirements cover guest-visible direct SGI capability, request control and direct-vSGI state handling. These requirements do not expose GICv4 as a guest interrupt-controller architecture and do not replace the existing GICv3, ITS, vITS or common interrupt-management requirements. Signed-off-by: Mykola Kvach --- .../arm64/index.rst | 1 + .../arm64/vgic_direct_delivery.rst | 166 ++++++ .../physical_resources/arm64/gicv4.rst | 515 ++++++++++++++++++ .../physical_resources/arm64/index.rst | 1 + 4 files changed, 683 insertions(+) create mode 100644 software_safety_reqs/domain_creation_and_runtime/domain= _partially_emulated_resources/arm64/vgic_direct_delivery.rst create mode 100644 software_safety_reqs/domain_creation_and_runtime/physic= al_resources/arm64/gicv4.rst diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/index.rst b/software_safety_reqs/domain_creati= on_and_runtime/domain_partially_emulated_resources/arm64/index.rst index 7896770..9d83bbf 100644 --- a/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/index.rst +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/index.rst @@ -10,4 +10,5 @@ Arm64 gicv3 its tee + vgic_direct_delivery viommu diff --git a/software_safety_reqs/domain_creation_and_runtime/domain_partia= lly_emulated_resources/arm64/vgic_direct_delivery.rst b/software_safety_req= s/domain_creation_and_runtime/domain_partially_emulated_resources/arm64/vgi= c_direct_delivery.rst new file mode 100644 index 0000000..dc364b1 --- /dev/null +++ b/software_safety_reqs/domain_creation_and_runtime/domain_partially_emu= lated_resources/arm64/vgic_direct_delivery.rst @@ -0,0 +1,166 @@ +.. SPDX-License-Identifier: CC-BY-4.0 + +vGIC direct-delivery requirements +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D + +The following requirements define guest-visible vGIC behavior that can be = backed +by GICv4 direct-delivery mechanisms [1]. + +These requirements do not expose GICv4 as a guest interrupt-controller +architecture. GICv4 remains a Xen backend used to implement selected +guest-visible vGIC behavior when the required host capabilities are availa= ble. + +Direct vSGI backend selection +----------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_backend_selection~1` + +Description: +Xen shall enable a direct-vSGI backend for a selected domain only when the +domain uses the virtual GICv3 model, the GICv4 vLPI backend is available, a +GICv4.1 host ITS is available, and the selected domain has initialized +per-domain GICv4 direct-delivery state. + +Rationale: +Direct vSGI delivery requires GICv4.1 support and vPE state. Enabling the +backend without the required host capabilities would expose a direct deliv= ery +mode that Xen cannot safely provide. + +Covers: + - `XenPRQ~intc~1` + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest direct SGI capability exposure +------------------------------------ + +`XenSSR~arm64_gicv4_direct_vsgi_cap_exposure~1` + +Description: +Xen shall derive the guest-visible ``GICD_TYPER2.nASSGIcap`` capability fr= om +direct-vSGI backend availability for the selected domain. + +Rationale: +``GICD_TYPER2.nASSGIcap`` is a guest-visible virtual Distributor capabilit= y. A +guest uses this field to determine whether it may request the direct SGI +active-state model through ``GICD_CTLR.nASSGIreq``. Xen derives this capab= ility +from the virtual GICv3 domain model and the GICv4.1 direct-vSGI backend +available for that domain. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Guest direct SGI active-state request control +--------------------------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_active_state_request_control~1` + +Description: +Xen shall accept a guest direct SGI active-state request through +``GICD_CTLR.nASSGIreq`` only when ``GICD_TYPER2.nASSGIcap`` is exposed for= the +selected domain. + +Rationale: +``GICD_CTLR.nASSGIreq`` is the guest-visible control that selects the SGI +active-state model when direct SGI capability is exposed. Xen uses this co= ntrol +to switch the domain between software-emulated SGI delivery and direct-vSGI +delivery while preserving the guest-visible virtual GIC state. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Direct vSGI configuration source +-------------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_conf_source~1` + +Description: +Xen shall derive direct-vSGI hardware configuration from the authoritative +guest-visible virtual GIC software state. + +Rationale: +Direct-vSGI hardware state is a delivery backend, not the guest-visible GIC +model. Xen needs guest register readback, software/direct mode switching a= nd +partial configuration updates to observe one coherent SGI model for enable, +priority, group and pending-state semantics. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Direct vSGI pending-state preservation +-------------------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_pending_state_preservation~1` + +Description: +Xen shall preserve guest-visible SGI pending state when switching a vCPU +between software-emulated SGI delivery and direct-vSGI delivery. + +Rationale: +SGIs are used for inter-vCPU communication. Losing pending state can hang a +guest, while duplicating pending state can break guest synchronization +assumptions. When leaving direct-vSGI mode, Xen needs completed hardware +pending-state information before reinjecting pending SGIs into the software +vGIC model. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Direct vSGI pending-state readback +---------------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_pending_state_readback~1` + +Description: +Xen shall consume direct-vSGI pending-state readback only after the +Redistributor reports that the query has completed and the queried vPEID a= nd +Redistributor are still the serialized target of the query. + +Rationale: +Direct-vSGI pending-state readback observes Redistributor-side state index= ed by +vPEID. Consuming a busy, stale or ambiguously targeted readback can lose a +pending vSGI, inject a spurious or duplicate vSGI, or transfer pending sta= te +from the wrong vPE. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +Direct vSGI send mediation +-------------------------- + +`XenSSR~arm64_gicv4_direct_vsgi_send_mediation~1` + +Description: +Xen shall mediate guest SGI generation through the selected domain's virtu= al +CPU topology before issuing any direct-vSGI hardware operation. + +Rationale: +Guest SGI generation contains guest-controlled affinity, target-list, grou= p and +SGI INTID fields. Xen translates those fields through the domain's virtual= CPU +topology and issues direct-vSGI operations only for vPEIDs owned by the se= nding +domain and selected by that topology. + +Covers: + - `XenPRQ~virtual_interrupt_controller~1` + +Needs: + - XenVerTestCase + +| [1] Arm Generic Interrupt Controller Architecture Specification (GIC arc= hitecture version 3 and version 4) diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/gicv4.rst b/software_safety_reqs/domain_creation_and_runtime/ph= ysical_resources/arm64/gicv4.rst new file mode 100644 index 0000000..8224a5c --- /dev/null +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/gicv4.rst @@ -0,0 +1,515 @@ +.. SPDX-License-Identifier: CC-BY-4.0 + +Host GICv4 requirements +=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D + +The following requirements are related to Xen's host-side support for the +Arm Generic Interrupt Controller version 4 (GICv4) architecture [1]. + +The GICv4 requirements describe Xen's direct-delivery backend state. In the +current vITS command path, guest ITS commands are exposed to the hardware +domain. + + +GICv4 direct-delivery backend selection +--------------------------------------- + +`XenSSR~arm64_gicv4_direct_delivery_backend_selection~1` + +Description: +Xen shall use a GICv4 direct-delivery backend only when the required host = ITS +and Redistributor capabilities are available for the selected domain, vPE = or +device-event mapping. + +Rationale: +GICv4 direct delivery is a Xen backend choice. A vPE can become resident on +different Redistributors during execution, and a device event is programmed +through the host ITS associated with the physical DeviceID and EventID. Us= ing a +direct-delivery backend when a required host component lacks the correspon= ding +capability can make interrupt delivery depend on unsupported runtime place= ment +or unsupported ITS command semantics. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +GICv4 ITS virtual command capability gating +------------------------------------------- + +`XenSSR~arm64_gicv4_its_virtual_command_capability_gating~1` + +Description: +Xen shall issue GICv4 ITS virtual interrupt commands only through a host I= TS +that reports virtual LPI support, and shall issue GICv4.1-only commands or +fields only through a host ITS that reports GICv4.1 support. This shall in= clude +use of: + + - ``VMAPP`` + - ``VMAPTI`` and ``VMAPI`` + - ``VMOVP`` and ``VMOVI`` + - ``VINVALL`` + - ``VSYNC`` + - ``VSGI`` + - ``INVDB`` + +Rationale: +GICv4 virtual interrupt commands depend on host ITS virtual LPI capability. +GICv4.1 commands and fields, including ``INVDB``, ``VSGI`` and GICv4.1 +``VMAPP`` lifetime and default-doorbell fields, are valid only on a GICv4.1 +ITS. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +GICv4 command completion +------------------------ + +`XenSSR~arm64_gicv4_command_completion~1` + +Description: +Xen shall treat a GICv4 direct-delivery state transition as successful only +after the required host ITS command sequence has been issued and completed +successfully. + +Rationale: +GICv4 ITS commands can create, update or remove hardware-visible virtual +interrupt state asynchronously. If a required command cannot be issued or = does +not complete, the dependent direct-delivery state cannot be treated as +committed. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPEID allocation and lifetime +----------------------------- + +`XenSSR~arm64_gicv4_vpeid_allocation_and_lifetime~1` + +Description: +Xen shall allocate a unique vPEID for each GICv4 vPE and shall release that +vPEID only after the hardware-visible vPE mapping that uses it has been +removed. + +Rationale: +A vPEID indexes hardware-visible virtual interrupt state. Reusing a vPEID +before old ITS and Redistributor references have been removed can deliver a +virtual interrupt to stale or wrong vPE state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPE table entry readiness +------------------------- + +`XenSSR~arm64_gicv4_vpe_table_entry_readiness~1` + +Description: +Xen shall allocate and initialize host GICv4 vPE table backing storage for= a +vPEID before programming a host ITS mapping that can reference that vPEID. + +Rationale: +The host ITS can use the vPEID to locate vPE table state. If the backing t= able +entry or its second-level storage is missing or uninitialized, direct deli= very +can consume invalid vPE state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +GICv4.1 shared vPE table common-affinity sharing +------------------------------------------------ + +`XenSSR~arm64_gicv4_1_shared_vpe_table_common_affinity_sharing~1` + +Description: +Xen shall share a GICv4.1 vPE table between host ITS or Redistributor +components only when their computed common LPI affinity matches. + +Rationale: +A shared vPE table can be consumed by multiple Redistributors or ITS +instances. Sharing outside the compatible common-LPI-affinity scope can ma= ke +different GIC components consume different vPE configuration state for the= same +vPEID. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +GICv4.1 VMAPP lifetime +---------------------- + +`XenSSR~arm64_gicv4_1_vmapp_lifetime~1` + +Description: +Xen shall encode GICv4.1 ``VMAPP`` lifetime state according to the +architectural lifetime of each vPEID mapping. + +Rationale: +In GICv4.1, ``VMAPP`` lifetime fields identify first-map and last-unmap +operations for virtual pending and configuration table state. Incorrect +lifetime programming can leave the interrupt routing infrastructure access= ing +stale vPE table, virtual pending table or virtual configuration table state +after Xen has removed the software owner. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPE publication after initialization +------------------------------------ + +`XenSSR~arm64_gicv4_vpe_publication_after_initialization~1` + +Description: +Xen shall make a GICv4 vPE available to direct-vLPI, doorbell and direct-v= SGI +paths only after the vPEID, virtual pending table, vPE table entry, host +VMAPP mappings and doorbell state required for that vPE have been +initialized successfully. + +Rationale: +A published vPE can be used by direct-vLPI, doorbell and direct-vSGI paths. +Making the vPE available before required backing state is ready can allow = later +direct-delivery operations to consume partial or invalid vPE state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Single vPE residency +-------------------- + +`XenSSR~arm64_gicv4_single_vpe_residency~1` + +Description: +Xen shall keep each GICv4 vPE resident on at most one Redistributor at any +time. + +Rationale: +A vPE represents one hardware-visible virtual CPU interrupt context. Makin= g the +same vPE resident on more than one Redistributor can cause duplicate deliv= ery, +cross-CPU delivery or ambiguous ownership of pending virtual interrupt sta= te. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPE residency synchronization +----------------------------- + +`XenSSR~arm64_gicv4_vpe_residency_synchronization~1` + +Description: +Xen shall rely on a vPE residency transition only after the architectural +completion state for that transition has been observed. + +Rationale: +The Redistributor can update or consume virtual pending state asynchronous= ly +during vPE residency transitions. Reusing a Redistributor, reusing vPE pen= ding +state, or freeing old vPE resources before synchronization can lose pending +virtual interrupts, duplicate virtual interrupts, corrupt the wrong pending +table, or make doorbell decisions from stale state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPE movement serialization +-------------------------- + +`XenSSR~arm64_gicv4_vpe_movement_serialization~1` + +Description: +Xen shall serialize vPE movement with GICv4 operations that depend on the +vPE's current Redistributor target. + +Rationale: +vPE movement changes the Redistributor that owns the vPE. Register-based +invalidation, doorbell handling, virtual LPI operations and direct-vSGI +pending-state readback can target Redistributor-resident state. Issuing su= ch +operations against a stale Redistributor can leave cached state unchanged = or +operate on the wrong state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Doorbell LPI ownership +---------------------- + +`XenSSR~arm64_gicv4_doorbell_lpi_ownership~1` + +Description: +Xen shall reserve physical LPIs used as GICv4 doorbells for Xen use and sh= all +associate each doorbell with the owning domain and vCPU. + +Rationale: +Doorbells are hypervisor wakeup signals for non-resident vPEs. Guest owner= ship +or reuse of a doorbell LPI can suppress, spoof or misroute hypervisor wake= ups. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Doorbell invalidation and readiness +----------------------------------- + +`XenSSR~arm64_gicv4_doorbell_invalidation_and_readiness~1` + +Description: +Xen shall update and invalidate GICv4 doorbell state through the +architecture-supported backend path before relying on the updated doorbell +state. + +Rationale: +Doorbell state can be cached by the GIC. Xen uses GICv4.1 ``INVDB``, +Redistributor register invalidation, or a proxy-device invalidation path +depending on the selected backend. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Doorbell LPI observation +------------------------ + +`XenSSR~arm64_gicv4_doorbell_lpi_observation~1` + +Description: +Xen shall mark the vPE as having pending virtual interrupt work and kick +the owning vCPU when Xen receives a GICv4 doorbell LPI for a non-resident = vPE. + +Rationale: +A doorbell is a hypervisor wakeup signal for a non-resident vPE. Marking t= he +vPE pending state and kicking the vCPU makes the wakeup visible to Xen's +scheduler. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +GICv4.1 non-resident pending-state indication +--------------------------------------------- + +`XenSSR~arm64_gicv4_1_non_resident_pending_state_indication~1` + +Description: +Xen shall record the architectural ``PendingLast`` indication reported by +``GICR_VPENDBASER`` before relying on the vPE non-resident state when maki= ng +a GICv4.1 vPE non-resident + +Rationale: +``PendingLast`` reports whether pending enabled virtual interrupts remain = after +the non-resident transition. Xen uses this state as part of its scheduling= and +wakeup handling for the vPE. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI mapping ownership +----------------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_mapping_ownership~1` + +Description: +Xen shall install a hardware-forwarded vLPI mapping only when the target +virtual INTID is valid for the selected domain and the mapping has one +domain/device/event/vPE/vINTID owner. + +Rationale: +GICv4 virtual LPI mappings are keyed by device events and vPE state. Reusi= ng a +DeviceID/EventID mapping, aliasing vPEID/vINTID ownership, or using an +out-of-range virtual INTID can cause wrong-owner delivery, duplicate deliv= ery, +missed invalidation or constrained unpredictable GIC behaviour. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI setup recovery +-------------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_setup_recovery~1` + +Description: +Xen shall restore the previous safe host LPI mapping or otherwise keep the +event unavailable when a direct vLPI setup operation fails after the previ= ous +mapping has been removed. + +Rationale: +Direct vLPI setup can discard the previous mapping before ``VMAPTI`` succe= eds. +If ``VMAPTI`` fails and the event is left without a safe mapping, subseque= nt +device events can be lost or delivered through stale state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI unmap ordering +-------------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_unmap_ordering~1` + +Description: +Xen shall remove a direct vLPI mapping, restore the host physical LPI mapp= ing, +invalidate the affected event state and then release the software vLPI map= ping +state. + +Rationale: +A mapped event can remain visible to the host ITS and Redistributor until = the +hardware mapping and cached state have been updated. Releasing software ma= pping +state before restoring and invalidating the host mapping can leave hardware +delivery targeting stale domain state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI movement +-------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_movement~1` + +Description: +Xen shall move a direct vLPI mapping to another vPE using the GICv4 virtual +movement operation and shall synchronize the old vPE before relying on a l= ater +movement of the same event. + +Rationale: +GICv4 movement updates the vPEID associated with the event and can move +pending state. The architecture requires synchronization between repeated = moves +of the same virtual interrupt to prevent pending-state loss or delivery to= the +old vPE. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI property update +--------------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_property_update~1` + +Description: +Xen shall update the virtual LPI property table and perform the required +direct-delivery invalidation before relying on updated virtual LPI enable = or +priority state. + +Rationale: +The GIC can cache virtual LPI property state. Updating the virtual property +table without completing the corresponding invalidation can make direct +delivery use stale enable or priority state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +Direct vLPI doorbell update +--------------------------- + +`XenSSR~arm64_gicv4_direct_vlpi_doorbell_update~1` + +Description: +Xen shall update the doorbell setting for an existing direct vLPI mapping = using +a GICv4 movement operation that preserves the existing event mapping. + +Rationale: +Re-issuing a mapping command for an already mapped DeviceID and EventID has +unpredictable architectural behaviour. Xen changes the doorbell associatio= n for +an existing mapping through a virtual movement operation targeting the same +vPE. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vLPI invalidation +----------------- + +`XenSSR~arm64_gicv4_vlpi_invalidation~1` + +Description: +Xen shall perform GICv4 virtual interrupt invalidation through the +architecture-supported path for the affected event or vPE and shall wait f= or +completion before relying on the invalidated state. + +Rationale: +GICv4 virtual interrupt state can be cached in Redistributors or ITS-visib= le +state. Xen uses ITS virtual invalidation, GICv4.1 register invalidation or +proxy invalidation according to backend capability. Relying on updated vir= tual +interrupt state before invalidation completion can preserve stale delivery +state. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +vPE teardown ordering +--------------------- + +`XenSSR~arm64_gicv4_vpe_teardown_ordering~1` + +Description: +Xen shall unmap a vPE from every host ITS that can reference the vPE before +freeing the vPEID or virtual pending table used by that vPE. + +Rationale: +A host ITS can retain hardware-visible references to vPEID and virtual pen= ding +table state until the corresponding ``VMAPP`` unmap operation has complete= d. +Freeing the vPEID or virtual pending table before the vPE has been unmapped +can create stale hardware-visible references. + +Covers: + - `XenPRQ~intc~1` + +Needs: + - XenVerTestCase + +| [1] Arm Generic Interrupt Controller Architecture Specification (GIC arc= hitecture version 3 and version 4) diff --git a/software_safety_reqs/domain_creation_and_runtime/physical_reso= urces/arm64/index.rst b/software_safety_reqs/domain_creation_and_runtime/ph= ysical_resources/arm64/index.rst index cd1aaca..da8cd1e 100644 --- a/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst +++ b/software_safety_reqs/domain_creation_and_runtime/physical_resources/a= rm64/index.rst @@ -7,6 +7,7 @@ Arm64 :maxdepth: 1 =20 gicv3 + gicv4 its p2m pci_host_rcar --=20 2.43.0