2026.9.1
Links
Tagged documentation: https://shrinkwrap.docs.arm.com/en/2026.9.1/
Tagged source code: https://gitlab.arm.com/tooling/shrinkwrap/-/tags/2026.9.1
Tagged container images:
Release Highlights
This bugfix release corrects CCA Realm launch guidance and adds automated Realm validation while retaining all component revisions from 2026.9.0.
Obsolete kvmtool options are removed from the documented Realm commands.
Realm disks shared with the host through 9p are copied to host-local storage before launch.
Direct kernel boot configures a 64 MiB SWIOTLB for Realm virtio I/O. The EDK2 path already retains the kernel’s 64 MiB default.
The long-running CCA test boots Realm Linux and then invokes the upstream KVM unit-test runner through a small kvmtool compatibility adapter.
CCA Validation Limitations
The release keeps the 2026.9.0 CCA stack: Linux cca-host/v13, kvmtool
cca/v11, TF-RMM tf-rmm-v0.9.0, and kvm-unit-tests
cca/rmm-v1.0-rel0. The adapter removes the runner’s obsolete
--restricted_mem option.
The automated KVM unit-test subset runs
selftest.flat -p "setup smp=2 mem=16". This verifies that the Realm sees
two CPUs and 16 MiB of memory. Repeated Realm launches are unstable on this
retained stack, so other upstream invocations are reported as outside the
current-stack smoke subset rather than unsupported. memstress is
explicitly skipped because its shared 4K case reproducibly triggers a host
Granule Protection Fault.
Test Report Summary
All 20 automated unit tests pass locally. Ruff formatting and lint checks, the Sphinx warnings-as-errors documentation build, and Python wheel and source distribution validation also pass.
Publication is gated on the full, non-smoke GitLab pipeline, including the long-running CCA Realm validation on both supported host architectures.