Loongarch:

- Add more CPUCFG mask bits.

- Improve feature detection.

- Add lazy load support for FPU and binary translation (LBT) register state.

- Fix return value for memory reads from and writes to in-kernel devices.

- Add support for detecting preemption from within a guest.

- Add KVM steal time test case to tools/selftests.

ARM:

- Add support for FEAT_IDST, allowing ID registers that are not
  implemented to be reported as a normal trap rather than as an UNDEF
  exception.

- Add sanitisation of the VTCR_EL2 register, fixing a number of
  UXN/PXN/XN bugs in the process.

- Full handling of RESx bits, instead of only RES0, and resulting in
  SCTLR_EL2 being added to the list of sanitised registers.

- More pKVM fixes for features that are not supposed to be exposed to
  guests.

- Make sure that MTE being disabled on the pKVM host doesn't give it
  the ability to attack the hypervisor.

- Allow pKVM's host stage-2 mappings to use the Force Write Back
  version of the memory attributes by using the "pass-through'
  encoding.

- Fix trapping of ICC_DIR_EL1 on GICv5 hosts emulating GICv3 for the
  guest.

- Preliminary work for guest GICv5 support.

- A bunch of debugfs fixes, removing pointless custom iterators stored
  in guest data structures.

- A small set of FPSIMD cleanups.

- Selftest fixes addressing the incorrect alignment of page
  allocation.

- Other assorted low-impact fixes and spelling fixes.

RISC-V:

- Fixes for issues discoverd by KVM API fuzzing in
  kvm_riscv_aia_imsic_has_attr(), kvm_riscv_aia_imsic_rw_attr(),
  and kvm_riscv_vcpu_aia_imsic_update()

- Allow Zalasr, Zilsd and Zclsd extensions for Guest/VM

- Transparent huge page support for hypervisor page tables

- Adjust the number of available guest irq files based on MMIO
  register sizes found in the device tree or the ACPI tables

- Add RISC-V specific paging modes to KVM selftests

- Detect paging mode at runtime for selftests

s390:

- Performance improvement for vSIE (aka nested virtualization)

- Completely new memory management.  s390 was a special snowflake that enlisted
  help from the architecture's page table management to build hypervisor
  page tables, in particular enabling sharing the last level of page
  tables.  This however was a lot of code (~3K lines) in order to support
  KVM, and also blocked several features.  The biggest advantages is
  that the page size of userspace is completely independent of the
  page size used by the guest: userspace can mix normal pages, THPs and
  hugetlbfs as it sees fit, and in fact transparent hugepages were not
  possible before.  It's also now possible to have nested guests and
  guests with huge pages running on the same host.

- Maintainership change for s390 vfio-pci

- Small quality of life improvement for protected guests

x86:

- Add support for giving the guest full ownership of PMU hardware (contexted
  switched around the fastpath run loop) and allowing direct access to data
  MSRs and PMCs (restricted by the vPMU model).  KVM still intercepts
  access to control registers, e.g. to enforce event filtering and to
  prevent the guest from profiling sensitive host state.  This is more
  accurate, since it has no risk of contention and thus dropped events, and
  also has significantly less overhead.

  For more information, see the commit message for merge commit bf2c3138ae36
  ("Merge tag 'kvm-x86-pmu-6.20' of https://github.com/kvm-x86/linux into HEAD").

- Disallow changing the virtual CPU model if L2 is active, for all the same
  reasons KVM disallows change the model after the first KVM_RUN.

- Fix a bug where KVM would incorrectly reject host accesses to PV MSRs
  when running with KVM_CAP_ENFORCE_PV_FEATURE_CPUID enabled, even if those
  were advertised as supported to userspace,

- Fix a bug with protected guest state (SEV-ES/SNP and TDX) VMs, where KVM
  would attempt to read CR3 configuring an async #PF entry.

- Fail the build if EXPORT_SYMBOL_GPL or EXPORT_SYMBOL is used in KVM (for x86
  only) to enforce usage of EXPORT_SYMBOL_FOR_KVM_INTERNAL.  Only a few exports
  that are intended for external usage, and those are allowed explicitly.

- When checking nested events after a vCPU is unblocked, ignore -EBUSY instead
  of WARNing.  Userspace can sometimes put the vCPU into what should be an
  impossible state, and spurious exit to userspace on -EBUSY does not really
  do anything to solve the issue.

- Also throw in the towel and drop the WARN on INIT/SIPI being blocked when vCPU
  is in Wait-For-SIPI, which also resulted in playing whack-a-mole with syzkaller
  stuffing architecturally impossible states into KVM.

- Add support for new Intel instructions that don't require anything beyond
  enumerating feature flags to userspace.

- Grab SRCU when reading PDPTRs in KVM_GET_SREGS2.

- Add WARNs to guard against modifying KVM's CPU caps outside of the intended
  setup flow, as nested VMX in particular is sensitive to unexpected changes
  in KVM's golden configuration.

- Add a quirk to allow userspace to opt-in to actually suppress EOI broadcasts
  when the suppression feature is enabled by the guest (currently limited to
  split IRQCHIP, i.e. userspace I/O APIC).  Sadly, simply fixing KVM to honor
  Suppress EOI Broadcasts isn't an option as some userspaces have come to rely
  on KVM's buggy behavior (KVM advertises Supress EOI Broadcast irrespective
  of whether or not userspace I/O APIC supports Directed EOIs).

- Clean up KVM's handling of marking mapped vCPU pages dirty.

- Drop a pile of *ancient* sanity checks hidden behind in KVM's unused
  ASSERT() macro, most of which could be trivially triggered by the guest
  and/or user, and all of which were useless.

- Fold "struct dest_map" into its sole user, "struct rtc_status", to make it
  more obvious what the weird parameter is used for, and to allow fropping
  these RTC shenanigans if CONFIG_KVM_IOAPIC=n.

- Bury all of ioapic.h, i8254.h and related ioctls (including
  KVM_CREATE_IRQCHIP) behind CONFIG_KVM_IOAPIC=y.

- Add a regression test for recent APICv update fixes.

- Handle "hardware APIC ISR", a.k.a. SVI, updates in kvm_apic_update_apicv()
  to consolidate the updates, and to co-locate SVI updates with the updates
  for KVM's own cache of ISR information.

- Drop a dead function declaration.

- Minor cleanups.

x86 (Intel):

- Rework KVM's handling of VMCS updates while L2 is active to temporarily
  switch to vmcs01 instead of deferring the update until the next nested
  VM-Exit.  The deferred updates approach directly contributed to several
  bugs, was proving to be a maintenance burden due to the difficulty in
  auditing the correctness of deferred updates, and was polluting
  "struct nested_vmx" with a growing pile of booleans.

- Fix an SGX bug where KVM would incorrectly try to handle EPCM page faults,
  and instead always reflect them into the guest.  Since KVM doesn't shadow
  EPCM entries, EPCM violations cannot be due to KVM interference and
  can't be resolved by KVM.

- Fix a bug where KVM would register its posted interrupt wakeup handler even
  if loading kvm-intel.ko ultimately failed.

- Disallow access to vmcb12 fields that aren't fully supported, mostly to
  avoid weirdness and complexity for FRED and other features, where KVM wants
  enable VMCS shadowing for fields that conditionally exist.

- Print out the "bad" offsets and values if kvm-intel.ko refuses to load (or
  refuses to online a CPU) due to a VMCS config mismatch.

x86 (AMD):

- Drop a user-triggerable WARN on nested_svm_load_cr3() failure.

- Add support for virtualizing ERAPS.  Note, correct virtualization of ERAPS
  relies on an upcoming, publicly announced change in the APM to reduce the
  set of conditions where hardware (i.e. KVM) *must* flush the RAP.

- Ignore nSVM intercepts for instructions that are not supported according to
  L1's virtual CPU model.

- Add support for expedited writes to the fast MMIO bus, a la VMX's fastpath
  for EPT Misconfig.

- Don't set GIF when clearing EFER.SVME, as GIF exists independently of SVM,
  and allow userspace to restore nested state with GIF=0.

- Treat exit_code as an unsigned 64-bit value through all of KVM.

- Add support for fetching SNP certificates from userspace.

- Fix a bug where KVM would use vmcb02 instead of vmcb01 when emulating VMLOAD
  or VMSAVE on behalf of L2.

- Misc fixes and cleanups.

x86 selftests:

- Add a regression test for TPR<=>CR8 synchronization and IRQ masking.

- Overhaul selftest's MMU infrastructure to genericize stage-2 MMU support,
  and extend x86's infrastructure to support EPT and NPT (for L2 guests).

- Extend several nested VMX tests to also cover nested SVM.

- Add a selftest for nested VMLOAD/VMSAVE.

- Rework the nested dirty log test, originally added as a regression test for
  PML where KVM logged L2 GPAs instead of L1 GPAs, to improve test coverage
  and to hopefully make the test easier to understand and maintain.

guest_memfd:

- Remove kvm_gmem_populate()'s preparation tracking and half-baked hugepage
  handling.  SEV/SNP was the only user of the tracking and it can do it via
  the RMP.

- Retroactively document and enforce (for SNP) that KVM_SEV_SNP_LAUNCH_UPDATE
  and KVM_TDX_INIT_MEM_REGION require the source page to be 4KiB aligned, to
  avoid non-trivial complexity for something that no known VMM seems to be
  doing and to avoid an API special case for in-place conversion, which
  simply can't support unaligned sources.

- When populating guest_memfd memory, GUP the source page in common code and
  pass the refcounted page to the vendor callback, instead of letting vendor
  code do the heavy lifting.  Doing so avoids a looming deadlock bug with
  in-place due an AB-BA conflict betwee mmap_lock and guest_memfd's filemap
  invalidate lock.

Generic:

- Fix a bug where KVM would ignore the vCPU's selected address space when
  creating a vCPU-specific mapping of guest memory.  Actually this bug
  could not be hit even on x86, the only architecture with multiple
  address spaces, but it's a bug nevertheless.
Merge tag 'kvm-s390-next-7.0-1' of https://git.kernel.org/pub/scm/linux/kernel/git/kvms390/linux into HEAD

- gmap rewrite: completely new memory management for kvm/s390
- vSIE improvement
- maintainership change for s390 vfio-pci
- small quality of life improvement for protected guests