All of lore.kernel.org
 help / color / mirror / Atom feed
From: Michael Roth <michael.roth@amd.com>
To: <qemu-devel@nongnu.org>
Cc: <kvm@vger.kernel.org>, <pbonzini@redhat.com>,
	<berrange@redhat.com>, <armbru@redhat.com>,
	<pankaj.gupta@amd.com>, <isaku.yamahata@intel.com>,
	<xiaoyao.li@intel.com>, <chao.p.peng@linux.intel.com>,
	<david@kernel.org>, <ashish.kalra@amd.com>,
	<ackerleytng@google.com>, <lpieralisi@kernel.org>
Subject: [PATCH v2 09/19] accel/kvm: Handle guest_memfd flags internally when creating instances
Date: Tue, 8 Sep 2026 15:48:29 -0500	[thread overview]
Message-ID: <20260908205236.838281-10-michael.roth@amd.com> (raw)
In-Reply-To: <20260908205236.838281-1-michael.roth@amd.com>

Current hostmem code (which is callable even outside of KVM) specifies
guest_memfd flags directly, which requires pulling in kernel headers.
Additionally, it will eventually require additional knowledge that is
more suitable for KVM-aware code (e.g. whether or not to default to
private memory for confidential VMs).

Instead, push the determination for what flags are needed down into the
KVM/guest_memfd code so they can be handled internally based on VM
type/configuration and avoid further potential leakage of KVM-specific
code to general code.

Signed-off-by: Michael Roth <michael.roth@amd.com>
---
 accel/kvm/kvm-all.c      | 26 ++++++++++++++++++++++++--
 accel/stubs/kvm-stub.c   |  2 +-
 backends/hostmem-memfd.c |  6 +-----
 include/system/kvm.h     |  2 +-
 4 files changed, 27 insertions(+), 9 deletions(-)

diff --git a/accel/kvm/kvm-all.c b/accel/kvm/kvm-all.c
index 2b838eb690..bf81a19423 100644
--- a/accel/kvm/kvm-all.c
+++ b/accel/kvm/kvm-all.c
@@ -4857,7 +4857,8 @@ void kvm_mark_guest_state_protected(void)
     kvm_state->guest_state_protected = true;
 }
 
-int kvm_create_guest_memfd(uint64_t size, uint64_t flags, Error **errp)
+static int kvm_create_guest_memfd_flags(uint64_t size, uint64_t flags,
+                                        Error **errp)
 {
     int fd;
     struct kvm_create_guest_memfd guest_memfd = {
@@ -4898,6 +4899,27 @@ int kvm_create_guest_memfd(uint64_t size, uint64_t flags, Error **errp)
     return fd;
 }
 
+int kvm_create_guest_memfd(uint64_t size, Error **errp)
+{
+    /*
+     * There isn't currently any use for non-mmap()'able gmem instances
+     * outside of kvm_create_guest_memfd_private(), so hardcode it here
+     * for general use.
+     *
+     * Additionally, *_INIT_SHARED is needed for non-confidential VMs, and
+     * confidential VMs will default to this as well to allow similar flows
+     * for initializing the VM's initial memory contents as with normal
+     * guests. In the future, the initial state may become a global policy
+     * decision based on the confidential VM configuration, in which case
+     * this would likely be the right place to decide whether or not to set
+     * the flag since it would likely be a globally-configured option.
+     */
+    return kvm_create_guest_memfd_flags(size,
+                                        GUEST_MEMFD_FLAG_MMAP |
+                                        GUEST_MEMFD_FLAG_INIT_SHARED,
+                                        errp);
+}
+
 int kvm_create_guest_memfd_private(uint64_t size, Error **errp)
 {
     if (!(kvm_supported_memory_attributes & KVM_MEMORY_ATTRIBUTE_PRIVATE)) {
@@ -4905,5 +4927,5 @@ int kvm_create_guest_memfd_private(uint64_t size, Error **errp)
         return -1;
     }
 
-    return kvm_create_guest_memfd(size, 0, errp);
+    return kvm_create_guest_memfd_flags(size, 0, errp);
 }
diff --git a/accel/stubs/kvm-stub.c b/accel/stubs/kvm-stub.c
index 9fe58efe91..26003b01a3 100644
--- a/accel/stubs/kvm-stub.c
+++ b/accel/stubs/kvm-stub.c
@@ -139,7 +139,7 @@ bool kvm_hwpoisoned_mem(void)
     return false;
 }
 
-int kvm_create_guest_memfd(uint64_t size, uint64_t flags, Error **errp)
+int kvm_create_guest_memfd(uint64_t size, Error **errp)
 {
     error_setg(errp, "KVM is not enabled");
     return -ENOSYS;
diff --git a/backends/hostmem-memfd.c b/backends/hostmem-memfd.c
index a9759e682b..de51cf738a 100644
--- a/backends/hostmem-memfd.c
+++ b/backends/hostmem-memfd.c
@@ -19,7 +19,6 @@
 #include "qom/object.h"
 #include "migration/cpr.h"
 #include "system/kvm.h"
-#include <linux/kvm.h>
 
 OBJECT_DECLARE_SIMPLE_TYPE(HostMemoryBackendMemfd, MEMORY_BACKEND_MEMFD)
 
@@ -69,10 +68,7 @@ memfd_backend_memory_alloc(HostMemoryBackend *backend, Error **errp)
             return false;
         }
 
-        fd = kvm_create_guest_memfd(backend->size,
-                                    GUEST_MEMFD_FLAG_MMAP |
-                                    GUEST_MEMFD_FLAG_INIT_SHARED,
-                                    errp);
+        fd = kvm_create_guest_memfd(backend->size, errp);
     } else {
         fd = qemu_memfd_create(TYPE_MEMORY_BACKEND_MEMFD, backend->size,
                                m->hugetlb, m->hugetlbsize, m->seal ?
diff --git a/include/system/kvm.h b/include/system/kvm.h
index b1e43ddc93..2a1501bba6 100644
--- a/include/system/kvm.h
+++ b/include/system/kvm.h
@@ -547,7 +547,7 @@ void kvm_mark_guest_state_protected(void);
  */
 bool kvm_hwpoisoned_mem(void);
 
-int kvm_create_guest_memfd(uint64_t size, uint64_t flags, Error **errp);
+int kvm_create_guest_memfd(uint64_t size, Error **errp);
 int kvm_create_guest_memfd_private(uint64_t size, Error **errp);
 
 int kvm_set_memory_attributes_private(hwaddr start, uint64_t size);
-- 
2.43.0


  parent reply	other threads:[~2026-09-08 20:53 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-08 20:48 [PATCH v2 00/19] guest_memfd: support in-place memory conversion Michael Roth
2026-09-08 20:48 ` [PATCH v2 01/19] accel/kvm: Add helper for handling conversions of MMIO holes Michael Roth
2026-09-08 20:48 ` [PATCH v2 02/19] accel/kvm: Fix kvm_convert_memory() calls crossing memory regions Michael Roth
2026-09-08 20:48 ` [PATCH v2 03/19] accel/kvm: Fix handling of MMIO holes at start of conversion ranges Michael Roth
2026-09-08 20:48 ` [PATCH v2 04/19] accel/kvm: Fix handling of conversion ranges with multiple MMIO holes Michael Roth
2026-09-08 20:48 ` [PATCH v2 05/19] accel/kvm: Use dedicated helper for creating private-only gmem instances Michael Roth
2026-09-08 20:48 ` [PATCH v2 06/19] linux-headers: Update headers for v12 of in-place conversion kernel support Michael Roth
2026-09-08 20:48 ` [PATCH v2 07/19] accel/kvm: Add CGS option to control in-place conversion support Michael Roth
2026-09-09  6:20   ` Markus Armbruster
2026-09-11 17:22     ` Michael Roth
2026-09-12  5:52       ` Markus Armbruster
2026-09-12 14:52         ` Michael Roth
2026-09-08 20:48 ` [PATCH v2 08/19] system/memory: Re-use memory-backend-guest-memfd inode for private memory Michael Roth
2026-09-10  8:39   ` David Hildenbrand
2026-09-11 19:07     ` Michael Roth
2026-09-08 20:48 ` Michael Roth [this message]
2026-09-08 20:48 ` [PATCH v2 10/19] system/memory: Default to guest_memfd for RAM for in-place conversion Michael Roth
2026-09-08 20:48 ` [PATCH v2 11/19] accel/kvm: Move post-conversion updates to a separate helper Michael Roth
2026-09-08 20:48 ` [PATCH v2 12/19] accel/kvm: Re-order attribute notifications for in-place conversion Michael Roth
2026-09-08 20:48 ` [PATCH v2 13/19] accel/kvm: Support shared/private conversions via guest_memfd ioctls Michael Roth
2026-09-08 20:48 ` [PATCH v2 14/19] accel/kvm: Don't default to private attributes for in-place conversion Michael Roth
2026-09-08 20:48 ` [PATCH v2 15/19] i386/sev: Update SNP_LAUNCH_UPDATE " Michael Roth
2026-09-08 20:48 ` [PATCH v2 16/19] i386/sev: Allow in-place conversion for SEV-SNP guests Michael Roth
2026-09-08 20:48 ` [PATCH v2 17/19] i386/sev: Update CPUID failure handling for in-place conversion Michael Roth
2026-09-08 20:48 ` [PATCH v2 18/19] accel/kvm: Disable discard " Michael Roth
2026-09-08 22:16   ` Michael Roth
2026-09-08 20:48 ` [PATCH v2 19/19] hostmem: Automatically select set guest-memfd=on " Michael Roth
2026-09-09  6:30   ` Markus Armbruster
2026-09-11 19:16     ` Michael Roth

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260908205236.838281-10-michael.roth@amd.com \
    --to=michael.roth@amd.com \
    --cc=ackerleytng@google.com \
    --cc=armbru@redhat.com \
    --cc=ashish.kalra@amd.com \
    --cc=berrange@redhat.com \
    --cc=chao.p.peng@linux.intel.com \
    --cc=david@kernel.org \
    --cc=isaku.yamahata@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=lpieralisi@kernel.org \
    --cc=pankaj.gupta@amd.com \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=xiaoyao.li@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.