From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5E4B1C3ABCC for ; Tue, 13 May 2025 16:35:13 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 8C39C6B00DC; Tue, 13 May 2025 12:35:01 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 83EE36B00DE; Tue, 13 May 2025 12:35:01 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 693E56B00DF; Tue, 13 May 2025 12:35:01 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id 444F96B00DC for ; Tue, 13 May 2025 12:35:01 -0400 (EDT) Received: from smtpin22.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay09.hostedemail.com (Postfix) with ESMTP id 99BC6811FF for ; Tue, 13 May 2025 16:35:02 +0000 (UTC) X-FDA: 83438434044.22.0474E42 Received: from mail-wm1-f73.google.com (mail-wm1-f73.google.com [209.85.128.73]) by imf28.hostedemail.com (Postfix) with ESMTP id B8691C0003 for ; Tue, 13 May 2025 16:35:00 +0000 (UTC) Authentication-Results: imf28.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=3VqgPRYF; spf=pass (imf28.hostedemail.com: domain of 3s3QjaAUKCHIjQRRQWeeWbU.SecbYdkn-ccalQSa.ehW@flex--tabba.bounces.google.com designates 209.85.128.73 as permitted sender) smtp.mailfrom=3s3QjaAUKCHIjQRRQWeeWbU.SecbYdkn-ccalQSa.ehW@flex--tabba.bounces.google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1747154100; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=NxKl/6+BAKCXIdE2T+YrAbctmttt0hBq+hOPemAaBUg=; b=QlzxEWJdQY16WS2FFpan3L49JhBz0vHi4bHj1S3iGoVraUvi2fx7sNCeilBwfVJiVv0Omh yVpeoGTg/j0/KSjkuwDlqZzl68YrADvpnm8xEeXlt6w3lvN1Gg2VroAajny3yfPwIxElVe w2cnflhJdlUC6QrX5fBH5UusQXuF9y4= ARC-Authentication-Results: i=1; imf28.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=3VqgPRYF; spf=pass (imf28.hostedemail.com: domain of 3s3QjaAUKCHIjQRRQWeeWbU.SecbYdkn-ccalQSa.ehW@flex--tabba.bounces.google.com designates 209.85.128.73 as permitted sender) smtp.mailfrom=3s3QjaAUKCHIjQRRQWeeWbU.SecbYdkn-ccalQSa.ehW@flex--tabba.bounces.google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1747154100; a=rsa-sha256; cv=none; b=kpDlHNgb6hWuggrU6k6Gctu4s/tuGQ2Q9bov0eqZGpYwdt3HCiemFNTwHvPc3mGejrIQ8H gM0sp7ANzbxe6OqOxZr/jPSh5QrFa9BErwuoRFMNO0E7c7q2XqKd8sD0KDe9+5vxVvAhH+ nfyexdfnHzr9sXGyiWLU1GFAj2bO1Cw= Received: by mail-wm1-f73.google.com with SMTP id 5b1f17b1804b1-43efa869b19so39945485e9.2 for ; Tue, 13 May 2025 09:35:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1747154099; x=1747758899; darn=kvack.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=NxKl/6+BAKCXIdE2T+YrAbctmttt0hBq+hOPemAaBUg=; b=3VqgPRYFgsJoArI/Q5S+vuYmCKN/86ewAelq1SoONpFsLZZlvjNiNO2fhHEDdOANxB K56mlQybL6rM/zr5zN9w0nDiq7GESbPH2ibj1bVpZp7ZbttoYf31Il5SFse/ju+AESIC 0hBaUwHnQNwHKPf1pezGQOPpNt5mUPS2LeD9ouDOSEdEN5i5Uz7ZT1f88Z1hwaG4Wxja xuU5O3ognjCGqWs9gfXFEorzOr3QEecfsr5Dzkmv4CWf6vFNnQkI1F40HhaMx0o7CQr2 hV3r2zE4oNV9XA8ohjcQjWLR++vbJicyXCDXtmQvyEqzj8Fvd7NfdDb6n3FAQCEkzpND 8hew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1747154099; x=1747758899; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=NxKl/6+BAKCXIdE2T+YrAbctmttt0hBq+hOPemAaBUg=; b=H3063q8X9J/Q2DoJlh28vJG797MGvfMXtFHpwPdTddqPrL2kWkoftCB7vnu2dj16kb SblHhuimiiBONFN02Xq/2z5FIbC9N63ImvG0mY8wniR45SLl4ECKIalXALsLIhXKJvn/ dycTbNxdUrWCSpXp5PLayRYbhVcsu+r4I29B6BK9eEs1SVvHMd09VitvaJo/wpgdBdk/ +P5J4mgEFxOpakDBJrLwDEHKdJ0TO2K+T/gGS5PIZr8Z+VsZG0V2nukVYopBt+6uCSd2 O1+obSDWyZtWIzJc5endlWlhvraFhSD/Xh/L7xYgnYKY+oYFOY8gtkMBa20K/FXLAxX8 iEJg== X-Forwarded-Encrypted: i=1; AJvYcCVPml6fixMGIEVyzMiFDezW+mdVqKCUNFo9FRcuFuiry16Sx55yuUszmotGOfNMFuARHDK2kkXyeQ==@kvack.org X-Gm-Message-State: AOJu0Yy6EgcLLaj5NhxvLGzhwjrKudBovWzsmVNGQS2PSH6y7eh8rvdr ZiFBiKUE5Wvw6tMAA6FicpjWlOw6Hj7cK0SxW+oNDgnk8IGVhUhGIPoC4amhcZk2r6PbsMNIjA= = X-Google-Smtp-Source: AGHT+IG3vTrR9dlx8h1Y7WqXSbJ03o3LWkHYex4QcV7npEMOKy25lzrViPjnVXRCx5B9hTFNZlwSiNnOEw== X-Received: from wmsd3.prod.google.com ([2002:a05:600c:3ac3:b0:442:dc9b:b569]) (user=tabba job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:8284:b0:43c:fa52:7d2d with SMTP id 5b1f17b1804b1-442d6dd2478mr132398425e9.20.1747154099254; Tue, 13 May 2025 09:34:59 -0700 (PDT) Date: Tue, 13 May 2025 17:34:30 +0100 In-Reply-To: <20250513163438.3942405-1-tabba@google.com> Mime-Version: 1.0 References: <20250513163438.3942405-1-tabba@google.com> X-Mailer: git-send-email 2.49.0.1045.g170613ef41-goog Message-ID: <20250513163438.3942405-10-tabba@google.com> Subject: [PATCH v9 09/17] KVM: x86/mmu: Handle guest page faults for guest_memfd with shared memory From: Fuad Tabba To: kvm@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-mm@kvack.org Cc: pbonzini@redhat.com, chenhuacai@kernel.org, mpe@ellerman.id.au, anup@brainfault.org, paul.walmsley@sifive.com, palmer@dabbelt.com, aou@eecs.berkeley.edu, seanjc@google.com, viro@zeniv.linux.org.uk, brauner@kernel.org, willy@infradead.org, akpm@linux-foundation.org, xiaoyao.li@intel.com, yilun.xu@intel.com, chao.p.peng@linux.intel.com, jarkko@kernel.org, amoorthy@google.com, dmatlack@google.com, isaku.yamahata@intel.com, mic@digikod.net, vbabka@suse.cz, vannapurve@google.com, ackerleytng@google.com, mail@maciej.szmigiero.name, david@redhat.com, michael.roth@amd.com, wei.w.wang@intel.com, liam.merwick@oracle.com, isaku.yamahata@gmail.com, kirill.shutemov@linux.intel.com, suzuki.poulose@arm.com, steven.price@arm.com, quic_eberman@quicinc.com, quic_mnalajal@quicinc.com, quic_tsoni@quicinc.com, quic_svaddagi@quicinc.com, quic_cvanscha@quicinc.com, quic_pderrin@quicinc.com, quic_pheragu@quicinc.com, catalin.marinas@arm.com, james.morse@arm.com, yuzenghui@huawei.com, oliver.upton@linux.dev, maz@kernel.org, will@kernel.org, qperret@google.com, keirf@google.com, roypat@amazon.co.uk, shuah@kernel.org, hch@infradead.org, jgg@nvidia.com, rientjes@google.com, jhubbard@nvidia.com, fvdl@google.com, hughd@google.com, jthoughton@google.com, peterx@redhat.com, pankaj.gupta@amd.com, ira.weiny@intel.com, tabba@google.com Content-Type: text/plain; charset="UTF-8" X-Rspamd-Queue-Id: B8691C0003 X-Rspam-User: X-Rspamd-Server: rspam11 X-Stat-Signature: s3zbwxdeq9sq597euey9nftu65g6r6ka X-HE-Tag: 1747154100-64763 X-HE-Meta: U2FsdGVkX1+Y4BcdZq3DK7YjlPcgAX+FWMqQ+SCwTHsyfQBuXoVr4nBp77zZjJkAx4YqxKqHO7OZdXg3b+ZODftIA84iT/wPv2GElj0uHRqsj2jW9uwaSYkgcrMKPGIjN1UlSOxRfIsgUBKGWKYsSQtdNHybh8rKYc/TOTSjt/zgNw/ti4NvewVEQzDdWoKELjsvTCHaZc2nM/Ecmk7LepGSdTGaH3vIEZi+iiprHwho0pl6O8mHa0aKzRVNE2GHcvdNJGvDRLnQlM9sZVxOOMqY4MS0Ph5yxkDr70/GZRB8rNuZJVFYQnBHOs4wxWeYZqlfMiQ8sCnyu/2X6FOFrVQsZL1NEsmj/6u05cqJaueFVqBFn3OeuV0sw2tTCeiNCRfUFsRvoEXdZzR3q3fxij3zwL4yDO0fYGExe4K39hcH+mIj/+faHjWL7B9VJD+8AIKIHCI7WIi8h2XcXxW3SyCi8+JCXStJWt0es1O53q524M7F5HNmocHKd5olk1URUcYw1sRqTvXrDjSK3BZEKTI3VdZS6BQ5hmRjyFU3WrmLQLv0zXFcz1HP1oo3XlNgFQOm+wmxKsSkhxw3pvQHQheiDLEZC4wQ/BceHZaC1Yxv6ZMLsza/vS+/Ruub3Or6LeBU5j+eHy5FbnvLO90/Htm6v6aSTqSthahPsXhJJ1kIoPpDe/RlsTaouF/PW9CUhdcOx2aSKz5Ahx+U+3MWvNvWawQ7eIyi16Zh5WGrhacAgWi2s4kfOH//qQeTzW3devRpv/lnVzOEk2fqMJdrxSOET3ksIuCI/eF7OmTmWCVjmhtAyOd6wNu45Byajw0HUaBIFEc0Luke3baCg3mn94vYUn82FDMypvKuRZtt6j+0zxLfLD0r08EoNpQT4fAAN4dEPuZlftdrPTxIX5KrHQc4YPySFd6NXHro6s+fTiJ8QOcRH8JGdwexWgAjEG3iRGAfGYy/HD9da0A48HC QTzBmtPP 24efrt95mg1JnA5b+haRa4a+dvssv8tZD/e8insH0VmFwqYTrGGLsq8V3G1TMeP3CsGrXaZUIf2vMWevV+sewHGCJhgbWze3LmZfeR1Vlm942Buvp/iifAcK5QG5o07dZo8UHDLIOje2tX2Mu5e9WDRzj8RBRX40Txhsmc8DpCoUXcVvOfLAiDix+pXkQz/FZl8jHncdYD6x7pNZG0ZknMs6A3XVJ5psxsTGsyKTopSmPaOMBHvLn44UCrYZekDyhK1yXya333kiIBk/QbXMZZpQq5p5TfTb8f+qccaM+zfRgkdgjEbZ6Fkemh+tIXN7wXmC9IMcJ/soPK4kr6VEGnkhP7yYOdNYBNVw72QIUaxc1apTsrA9EguoK0F5liZziHUNJKGFgLFDJqfUEbmyP4qbxfdTnyZVPK6jIcK+1pIbPVaQZKQQh2noLudE32wm/3FOfcggs1KRRW1ezdKSkegsuiX4v1mRjc01SOrpanSFRCKKdnyJiFus17TZ/kIWVNstrF0WHZ4QjkEInQoxqpi6BsjezsbnoHwpqAGH5Uiictoa35DZmECE+YheBtM9Nr2ELmYKI8LKN/Ya2dNEO1o6jsLKx+iD8WTtVHH5BN+/gmrea6ufrsFmsGFcu7LhHk4jUC+nipGetuLie/+PAZrLqozIGypjrCMmO8bUiM895lEk= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: From: Ackerley Tng For memslots backed by guest_memfd with shared mem support, the KVM MMU always faults-in pages from guest_memfd, and not from the userspace_addr. Towards this end, this patch also introduces a new guest_memfd flag, GUEST_MEMFD_FLAG_SUPPORT_SHARED, which indicates that the guest_memfd instance supports in-place shared memory. This flag is only supported if the VM creating the guest_memfd instance belongs to certain types determined by architecture. Only non-CoCo VMs are permitted to use guest_memfd with shared mem, for now. Function names have also been updated for accuracy - kvm_mem_is_private() returns true only when the current private/shared state (in the CoCo sense) of the memory is private, and returns false if the current state is shared explicitly or impicitly, e.g., belongs to a non-CoCo VM. kvm_mmu_faultin_pfn_gmem() is updated to indicate that it can be used to fault in not just private memory, but more generally, from guest_memfd. Co-developed-by: Fuad Tabba Signed-off-by: Fuad Tabba Co-developed-by: David Hildenbrand Signed-off-by: David Hildenbrand Signed-off-by: Ackerley Tng --- arch/x86/kvm/mmu/mmu.c | 33 ++++++++++++++++++--------------- include/linux/kvm_host.h | 33 +++++++++++++++++++++++++++++++-- virt/kvm/guest_memfd.c | 17 +++++++++++++++++ 3 files changed, 66 insertions(+), 17 deletions(-) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 2b6376986f96..cfbb471f7c70 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -4465,21 +4465,25 @@ static inline u8 kvm_max_level_for_order(int order) return PG_LEVEL_4K; } -static u8 kvm_max_private_mapping_level(struct kvm *kvm, kvm_pfn_t pfn, - u8 max_level, int gmem_order) +static u8 kvm_max_level_for_fault_and_order(struct kvm *kvm, + struct kvm_page_fault *fault, + int order) { - u8 req_max_level; + u8 max_level = fault->max_level; if (max_level == PG_LEVEL_4K) return PG_LEVEL_4K; - max_level = min(kvm_max_level_for_order(gmem_order), max_level); + max_level = min(kvm_max_level_for_order(order), max_level); if (max_level == PG_LEVEL_4K) return PG_LEVEL_4K; - req_max_level = kvm_x86_call(private_max_mapping_level)(kvm, pfn); - if (req_max_level) - max_level = min(max_level, req_max_level); + if (fault->is_private) { + u8 level = kvm_x86_call(private_max_mapping_level)(kvm, fault->pfn); + + if (level) + max_level = min(max_level, level); + } return max_level; } @@ -4491,10 +4495,10 @@ static void kvm_mmu_finish_page_fault(struct kvm_vcpu *vcpu, r == RET_PF_RETRY, fault->map_writable); } -static int kvm_mmu_faultin_pfn_private(struct kvm_vcpu *vcpu, - struct kvm_page_fault *fault) +static int kvm_mmu_faultin_pfn_gmem(struct kvm_vcpu *vcpu, + struct kvm_page_fault *fault) { - int max_order, r; + int gmem_order, r; if (!kvm_slot_has_gmem(fault->slot)) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); @@ -4502,15 +4506,14 @@ static int kvm_mmu_faultin_pfn_private(struct kvm_vcpu *vcpu, } r = kvm_gmem_get_pfn(vcpu->kvm, fault->slot, fault->gfn, &fault->pfn, - &fault->refcounted_page, &max_order); + &fault->refcounted_page, &gmem_order); if (r) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); return r; } fault->map_writable = !(fault->slot->flags & KVM_MEM_READONLY); - fault->max_level = kvm_max_private_mapping_level(vcpu->kvm, fault->pfn, - fault->max_level, max_order); + fault->max_level = kvm_max_level_for_fault_and_order(vcpu->kvm, fault, gmem_order); return RET_PF_CONTINUE; } @@ -4520,8 +4523,8 @@ static int __kvm_mmu_faultin_pfn(struct kvm_vcpu *vcpu, { unsigned int foll = fault->write ? FOLL_WRITE : 0; - if (fault->is_private) - return kvm_mmu_faultin_pfn_private(vcpu, fault); + if (fault->is_private || kvm_gmem_memslot_supports_shared(fault->slot)) + return kvm_mmu_faultin_pfn_gmem(vcpu, fault); foll |= FOLL_NOWAIT; fault->pfn = __kvm_faultin_pfn(fault->slot, fault->gfn, foll, diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h index 2ec89c214978..de7b46ee1762 100644 --- a/include/linux/kvm_host.h +++ b/include/linux/kvm_host.h @@ -2502,6 +2502,15 @@ static inline void kvm_prepare_memory_fault_exit(struct kvm_vcpu *vcpu, vcpu->run->memory_fault.flags |= KVM_MEMORY_EXIT_FLAG_PRIVATE; } +#ifdef CONFIG_KVM_GMEM_SHARED_MEM +bool kvm_gmem_memslot_supports_shared(const struct kvm_memory_slot *slot); +#else +static inline bool kvm_gmem_memslot_supports_shared(const struct kvm_memory_slot *slot) +{ + return false; +} +#endif /* CONFIG_KVM_GMEM_SHARED_MEM */ + #ifdef CONFIG_KVM_GENERIC_MEMORY_ATTRIBUTES static inline unsigned long kvm_get_memory_attributes(struct kvm *kvm, gfn_t gfn) { @@ -2515,10 +2524,30 @@ bool kvm_arch_pre_set_memory_attributes(struct kvm *kvm, bool kvm_arch_post_set_memory_attributes(struct kvm *kvm, struct kvm_gfn_range *range); +/* + * Returns true if the given gfn's private/shared status (in the CoCo sense) is + * private. + * + * A return value of false indicates that the gfn is explicitly or implicity + * shared (i.e., non-CoCo VMs). + */ static inline bool kvm_mem_is_private(struct kvm *kvm, gfn_t gfn) { - return IS_ENABLED(CONFIG_KVM_GMEM) && - kvm_get_memory_attributes(kvm, gfn) & KVM_MEMORY_ATTRIBUTE_PRIVATE; + struct kvm_memory_slot *slot; + + if (!IS_ENABLED(CONFIG_KVM_GMEM)) + return false; + + slot = gfn_to_memslot(kvm, gfn); + if (kvm_slot_has_gmem(slot) && kvm_gmem_memslot_supports_shared(slot)) { + /* + * For now, memslots only support in-place shared memory if the + * host is allowed to mmap memory (i.e., non-Coco VMs). + */ + return false; + } + + return kvm_get_memory_attributes(kvm, gfn) & KVM_MEMORY_ATTRIBUTE_PRIVATE; } #else static inline bool kvm_mem_is_private(struct kvm *kvm, gfn_t gfn) diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index 2f499021df66..fe0245335c96 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -388,6 +388,23 @@ static int kvm_gmem_mmap(struct file *file, struct vm_area_struct *vma) return 0; } + +bool kvm_gmem_memslot_supports_shared(const struct kvm_memory_slot *slot) +{ + struct file *file; + bool ret; + + file = kvm_gmem_get_file((struct kvm_memory_slot *)slot); + if (!file) + return false; + + ret = kvm_gmem_supports_shared(file_inode(file)); + + fput(file); + return ret; +} +EXPORT_SYMBOL_GPL(kvm_gmem_memslot_supports_shared); + #else #define kvm_gmem_mmap NULL #endif /* CONFIG_KVM_GMEM_SHARED_MEM */ -- 2.49.0.1045.g170613ef41-goog