ARM:

* Nested virtualization support for VGICv3, giving the nested
hypervisor control of the VGIC hardware when running an L2 VM

* Removal of 'late' nested virtualization feature register masking,
  making the supported feature set directly visible to userspace

* Support for emulating FEAT_PMUv3 on Apple silicon, taking advantage
  of an IMPLEMENTATION DEFINED trap that covers all PMUv3 registers

* Paravirtual interface for discovering the set of CPU implementations
  where a VM may run, addressing a longstanding issue of guest CPU
  errata awareness in big-little systems and cross-implementation VM
  migration

* Userspace control of the registers responsible for identifying a
  particular CPU implementation (MIDR_EL1, REVIDR_EL1, AIDR_EL1),
  allowing VMs to be migrated cross-implementation

* pKVM updates, including support for tracking stage-2 page table
  allocations in the protected hypervisor in the 'SecPageTable' stat

* Fixes to vPMU, ensuring that userspace updates to the vPMU after
  KVM_RUN are reflected into the backing perf events

LoongArch:

* Remove unnecessary header include path

* Assume constant PGD during VM context switch

* Add perf events support for guest VM

RISC-V:

* Disable the kernel perf counter during configure

* KVM selftests improvements for PMU

* Fix warning at the time of KVM module removal

x86:

* Add support for aging of SPTEs without holding mmu_lock.  Not taking mmu_lock
  allows multiple aging actions to run in parallel, and more importantly avoids
  stalling vCPUs.  This includes an implementation of per-rmap-entry locking;
  aging the gfn is done with only a per-rmap single-bin spinlock taken, whereas
  locking an rmap for write requires taking both the per-rmap spinlock and
  the mmu_lock.

  Note that this decreases slightly the accuracy of accessed-page information,
  because changes to the SPTE outside aging might not use atomic operations
  even if they could race against a clear of the Accessed bit.  This is
  deliberate because KVM and mm/ tolerate false positives/negatives for
  accessed information, and testing has shown that reducing the latency of
  aging is far more beneficial to overall system performance than providing
  "perfect" young/old information.

* Defer runtime CPUID updates until KVM emulates a CPUID instruction, to
  coalesce updates when multiple pieces of vCPU state are changing, e.g. as
  part of a nested transition.

* Fix a variety of nested emulation bugs, and add VMX support for synthesizing
  nested VM-Exit on interception (instead of injecting #UD into L2).

* Drop "support" for async page faults for protected guests that do not set
  SEND_ALWAYS (i.e. that only want async page faults at CPL3)

* Bring a bit of sanity to x86's VM teardown code, which has accumulated
  a lot of cruft over the years.  Particularly, destroy vCPUs before
  the MMU, despite the latter being a VM-wide operation.

* Add common secure TSC infrastructure for use within SNP and in the
  future TDX

* Block KVM_CAP_SYNC_REGS if guest state is protected.  It does not make
  sense to use the capability if the relevant registers are not
  available for reading or writing.

* Don't take kvm->lock when iterating over vCPUs in the suspend notifier to
  fix a largely theoretical deadlock.

* Use the vCPU's actual Xen PV clock information when starting the Xen timer,
  as the cached state in arch.hv_clock can be stale/bogus.

* Fix a bug where KVM could bleed PVCLOCK_GUEST_STOPPED across different
  PV clocks; restrict PVCLOCK_GUEST_STOPPED to kvmclock, as KVM's suspend
  notifier only accounts for kvmclock, and there's no evidence that the
  flag is actually supported by Xen guests.

* Clean up the per-vCPU "cache" of its reference pvclock, and instead only
  track the vCPU's TSC scaling (multipler+shift) metadata (which is moderately
  expensive to compute, and rarely changes for modern setups).

* Don't write to the Xen hypercall page on MSR writes that are initiated by
  the host (userspace or KVM) to fix a class of bugs where KVM can write to
  guest memory at unexpected times, e.g. during vCPU creation if userspace has
  set the Xen hypercall MSR index to collide with an MSR that KVM emulates.

* Restrict the Xen hypercall MSR index to the unofficial synthetic range to
  reduce the set of possible collisions with MSRs that are emulated by KVM
  (collisions can still happen as KVM emulates Hyper-V MSRs, which also reside
  in the synthetic range).

* Clean up and optimize KVM's handling of Xen MSR writes and xen_hvm_config.

* Update Xen TSC leaves during CPUID emulation instead of modifying the CPUID
  entries when updating PV clocks; there is no guarantee PV clocks will be
  updated between TSC frequency changes and CPUID emulation, and guest reads
  of the TSC leaves should be rare, i.e. are not a hot path.

x86 (Intel):

* Fix a bug where KVM unnecessarily reads XFD_ERR from hardware and thus
  modifies the vCPU's XFD_ERR on a #NM due to CR0.TS=1.

* Pass XFD_ERR as the payload when injecting #NM, as a preparatory step
  for upcoming FRED virtualization support.

* Decouple the EPT entry RWX protection bit macros from the EPT Violation
  bits, both as a general cleanup and in anticipation of adding support for
  emulating Mode-Based Execution Control (MBEC).

* Reject KVM_RUN if userspace manages to gain control and stuff invalid guest
  state while KVM is in the middle of emulating nested VM-Enter.

* Add a macro to handle KVM's sanity checks on entry/exit VMCS control pairs
  in anticipation of adding sanity checks for secondary exit controls (the
  primary field is out of bits).

x86 (AMD):

* Ensure the PSP driver is initialized when both the PSP and KVM modules are
  built-in (the initcall framework doesn't handle dependencies).

* Use long-term pins when registering encrypted memory regions, so that the
  pages are migrated out of MIGRATE_CMA/ZONE_MOVABLE and don't lead to
  excessive fragmentation.

* Add macros and helpers for setting GHCB return/error codes.

* Add support for Idle HLT interception, which elides interception if the vCPU
  has a pending, unmasked virtual IRQ when HLT is executed.

* Fix a bug in INVPCID emulation where KVM fails to check for a non-canonical
  address.

* Don't attempt VMRUN for SEV-ES+ guests if the vCPU's VMSA is invalid, e.g.
  because the vCPU was "destroyed" via SNP's AP Creation hypercall.

* Reject SNP AP Creation if the requested SEV features for the vCPU don't
  match the VM's configured set of features.

Selftests:

* Fix again the Intel PMU counters test; add a data load and do CLFLUSH{OPT} on the data
  instead of executing code.  The theory is that modern Intel CPUs have
  learned new code prefetching tricks that bypass the PMU counters.

* Fix a flaw in the Intel PMU counters test where it asserts that an event is
  counting correctly without actually knowing what the event counts on the
  underlying hardware.

* Fix a variety of flaws, bugs, and false failures/passes dirty_log_test, and
  improve its coverage by collecting all dirty entries on each iteration.

* Fix a few minor bugs related to handling of stats FDs.

* Add infrastructure to make vCPU and VM stats FDs available to tests by
  default (open the FDs during VM/vCPU creation).

* Relax an assertion on the number of HLT exits in the xAPIC IPI test when
  running on a CPU that supports AMD's Idle HLT (which elides interception of
  HLT if a virtual IRQ is pending and unmasked).
Merge branch 'kvm-pre-tdx' into HEAD

- Add common secure TSC infrastructure for use within SNP and in the
  future TDX

- Block KVM_CAP_SYNC_REGS if guest state is protected.  It does not make
  sense to use the capability if the relevant registers are not
  available for reading or writing.