All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rick Edgecombe" <rick.p.edgecombe@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v8 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory
Date: Sat, 25 Jul 2026 00:46:57 +0000	[thread overview]
Message-ID: <20260725004658.3154F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260725002302.3337017-9-rick.p.edgecombe@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] PAMT and KVM MMU memory caches are depleted during transient hardware contention in KVM_TDX_INIT_MEM_REGION, leading to a fatal VM crash.
--

--- Patch [8]: [PATCH v8 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory ---
commit 204266ade892e48bf35565ec0b69b39fdcfacf67
Author: Kiryl Shutsemau <kas@kernel.org>

KVM: TDX: Get/put PAMT pages when (un)mapping private memory

This commit adds Dynamic PAMT support to KVM's S-EPT MMU. It allocates PAMT
pages on demand when adding guest memory and releases them when removing
memory. It also introduces per-vCPU PAMT caches which are topped up and used
during page faults.

> diff --git a/arch/x86/kvm/vmx/tdx.c b/arch/x86/kvm/vmx/tdx.c
> index 528ebb3cb0389..b3a8af8cd4335 100644
> --- a/arch/x86/kvm/vmx/tdx.c
> +++ b/arch/x86/kvm/vmx/tdx.c

[ ... ]

> @@ -1679,16 +1694,28 @@ static struct page *tdx_spte_to_sept_pt(struct kvm *kvm, gfn_t gfn,
>  static int tdx_sept_map_nonleaf_spte(struct kvm *kvm, gfn_t gfn,
>  				     enum pg_level level, u64 new_spte)
>  {
> +	struct kvm_vcpu *vcpu = kvm_get_running_vcpu();
>  	gpa_t gpa = gfn_to_gpa(gfn);
>  	u64 err, entry, level_state;
>  	struct page *sept_pt;
> +	int ret;
> +
> +	if (KVM_BUG_ON(!vcpu, kvm))
> +		return -EIO;
>  
>  	sept_pt = tdx_spte_to_sept_pt(kvm, gfn, new_spte, level);
>  	if (!sept_pt)
>  		return -EIO;
>  
> +	ret = tdx_pamt_get(page_to_pfn(sept_pt), &to_tdx(vcpu)->pamt_cache);
> +	if (KVM_BUG_ON(ret, kvm))
> +		return ret;
> +
>  	err = tdh_mem_sept_add(&to_kvm_tdx(kvm)->td, gpa, level, sept_pt,
>  			       &entry, &level_state);
> +	if (err)
> +		tdx_pamt_put(page_to_pfn(sept_pt));
> +
>  	if (unlikely(tdx_operand_busy(err)))
>  		return -EBUSY;

[Severity: High]
Can transient hardware contention crash the VM here by exhausting the
pamt_cache?

If tdh_mem_sept_add() fails with TDX_OPERAND_BUSY, this function returns -EBUSY
and the fault is retried. However, tdx_pamt_put() frees the PAMT page to the
system allocator instead of returning it to the per-vCPU pamt_cache.

Because the page fault retry loops do not call mmu_topup_memory_caches()
on every iteration, retrying a few times will drain the pamt_cache:

	do {
		...
		r = kvm_tdp_mmu_map(vcpu, &fault);
	} while (r == RET_PF_RETRY);

Once the cache is empty, the next tdx_pamt_get() will return -ENOMEM, causing
the KVM_BUG_ON() to evaluate to true and fatally crash the VM.

Should the cache be replenished during these retry loops, or should the put
operation return the page back to the cache to avoid depletion?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260725002302.3337017-1-rick.p.edgecombe@intel.com?part=8

  reply	other threads:[~2026-07-25  0:46 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-25  0:22 [PATCH v8 00/11] Dynamic PAMT Rick Edgecombe
2026-07-25  0:22 ` [PATCH v8 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-07-25  0:22 ` [PATCH v8 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-07-25  0:33   ` sashiko-bot
2026-07-25  0:22 ` [PATCH v8 03/11] x86/virt/tdx: Add tdx_alloc/free_control_page() helpers Rick Edgecombe
2026-07-25  0:35   ` sashiko-bot
2026-07-25  0:22 ` [PATCH v8 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-07-25  0:22 ` [PATCH v8 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
2026-07-25  0:22 ` [PATCH v8 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-07-25  0:35   ` sashiko-bot
2026-07-25  0:22 ` [PATCH v8 07/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-07-25  0:22 ` [PATCH v8 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-07-25  0:46   ` sashiko-bot [this message]
2026-07-25  0:22 ` [PATCH v8 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2026-07-25  0:23 ` [PATCH v8 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-07-25  0:23 ` [PATCH v8 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260725004658.3154F1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.