Part of the arm64 port. Highest-risk item: errors here take the host down.
GICv3 has exactly one distributor. Stock gic_dist_init() in drivers/irqchip/irq-gic-v3.c writes GICD_CTLR and resets every SPI's priority, config and routing; a spawn running it would reset the host's interrupts. Redistributors and CPU interfaces are per-CPU and unaffected.
Add a tenant mode to the GICv3 driver, selected by a DT property on the GIC node in the instance DTB (e.g. linux,multikernel-tenant) plus granted SPI ranges (linux,multikernel-spis = <start count>...):
- Skip gic_dist_init(); assume the host has GICD enabled with ARE and Group1 configured (verify by reading GICD_CTLR and bail loudly if not).
- Initialise only the redistributors whose MPIDR is in this kernel's CPU set (gic_populate_rdist() is already per-CPU; the rdist region walk must tolerate RDs it will never own).
- Restrict the SPI irqdomain translate/alloc to the granted ranges; reject everything else with -EPERM.
- gic_set_affinity() unchanged (writes the SPI's own GICD_IROUTER), but validate the target CPU belongs to this kernel.
- Never touch GICD_CTLR, global GICD_IGROUPR/GICD_ICFGR outside the granted ranges, or GICD_ICACTIVER sweeps.
- SGIs and PPIs: per-RD, stock behaviour.
- No LPIs/ITS in this issue (see ITS issue); with tenant mode alone the spawn gets wired SPIs only.
Host side: mk_manifest carries the SPI ranges per instance; the host's own driver must mask SPIs it hands out (and re-take them on teardown via irq_set_affinity back to a host CPU and re-init of the SPI state).
Test on QEMU virt with gic-version=3: host keeps its UART/virtio SPIs live while a spawn owns a disjoint range.
Reactions are currently unavailable
Part of the arm64 port. Highest-risk item: errors here take the host down.
GICv3 has exactly one distributor. Stock gic_dist_init() in drivers/irqchip/irq-gic-v3.c writes GICD_CTLR and resets every SPI's priority, config and routing; a spawn running it would reset the host's interrupts. Redistributors and CPU interfaces are per-CPU and unaffected.
Add a tenant mode to the GICv3 driver, selected by a DT property on the GIC node in the instance DTB (e.g. linux,multikernel-tenant) plus granted SPI ranges (linux,multikernel-spis = <start count>...):
Host side: mk_manifest carries the SPI ranges per instance; the host's own driver must mask SPIs it hands out (and re-take them on teardown via irq_set_affinity back to a host CPU and re-init of the SPI state).
Test on QEMU virt with gic-version=3: host keeps its UART/virtio SPIs live while a spawn owns a disjoint range.