From: "Nikunj A. Dadhania" <nikunj@amd.com>
To: Sean Christopherson <seanjc@google.com>
Cc: <sashiko-reviews@lists.linux.dev>, <kvm@vger.kernel.org>
Subject: Re: [PATCH v8 8/8] KVM: SVM: Add Page modification logging support
Date: Mon, 21 Sep 2026 10:53:30 +0530 [thread overview]
Message-ID: <4b931b35-0890-466f-9ee3-09b4bb9ca4b7@amd.com> (raw)
In-Reply-To: <aqH4SpA_567soglf@google.com>
On 9/10/2026 5:52 AM, Sean Christopherson wrote:
> On Tue, Sep 08, 2026, Nikunj A. Dadhania wrote:
>>
>>
>> On 9/7/2026 12:30 PM, sashiko-bot@kernel.org wrote:
>>
>>>> diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c
>>>> index 73f37b050d0a0..da417c4c59154 100644
>>>> --- a/arch/x86/kvm/svm/nested.c
>>>> +++ b/arch/x86/kvm/svm/nested.c
>>>> @@ -901,6 +901,13 @@ static void nested_vmcb02_prepare_control(struct vcpu_svm *svm)
>>>> vmcb02->control.msrpm_base_pa = vmcb01->control.msrpm_base_pa;
>>>> vmcb_mark_dirty(vmcb02, VMCB_PERM_MAP);
>>>>
>>>> + /*
>>>> + * PML is never enabled in hardware for L2. Make sure that an
>>>> + * unexpected PML write would trigger a PML_FULL VM-Exit.
>>>> + */
>>>> + if (pml)
>>>> + vmcb02->control.pml_index = -1;
>>>
>>> [Severity: Critical]
>>> By intentionally leaving hardware PML disabled for nested L2 guests in
>>> nested_vmcb02_prepare_control without informing the KVM MMU, doesn't this
>>> cause all memory dirtied by L2 to be silently lost?
>>
>> No, kvm_mmu_page_ad_need_write_protect() returns true when
>> cpu_dirty_log_size is set and the shadow page is in guest_mode,
>> which forces write-protection on L2 SPTEs instead of relying on
>> hardware PML. L2 dirty pages are tracked via write faults, not PML.
>> This is the same approach VMX uses for nested guests.
>
> And FWIW, because Sashiko's hallucinations made me double check, this series
> doesn't advertise PML to L1, i.e. doesn't need to implement and wire up
> kvm_x86_nested_ops.write_log_dirty() for SVM.
Yes, SVM nested PML is on my radar, I have been working on it along with
selftest coverage in nested_dirty_log_test. The test covers nVMX as well
-- dirty_log_perf_test -n runs an L2, but never enables PML for it, so
KVM's existing nVMX PML emulation doesn't appear to be exercised today.
Will post it once it's ready for review.
Regards,
Nikunj
next prev parent reply other threads:[~2026-09-21 5:23 UTC|newest]
Thread overview: 18+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 6:38 [PATCH v8 0/8] KVM: SVM: Add Page Modification Logging (PML) support Nikunj A Dadhania
2026-09-07 6:38 ` [PATCH v8 1/8] KVM: VMX: Pass @vcpu, not @vmx to init_vmcs() Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 2/8] KVM: x86: Move PML page to common vcpu arch structure Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 3/8] KVM: x86: Carve out PML flush routine Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 4/8] KVM: VMX: Use cpu_dirty_log_size instead of enable_pml for PML checks Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 5/8] KVM: x86: Carve out common dirty logging update Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 6/8] x86/cpufeatures: Add Page modification logging Nikunj A Dadhania
2026-09-07 6:47 ` sashiko-bot
2026-09-07 9:49 ` Nikunj A. Dadhania
2026-09-07 6:39 ` [PATCH v8 7/8] KVM: SVM: Use BIT_ULL for 64-bit misc_ctl bit definitions Nikunj A Dadhania
2026-09-07 6:39 ` [PATCH v8 8/8] KVM: SVM: Add Page modification logging support Nikunj A Dadhania
2026-09-07 7:00 ` sashiko-bot
2026-09-08 4:08 ` Nikunj A. Dadhania
2026-09-10 0:22 ` Sean Christopherson
2026-09-21 5:23 ` Nikunj A. Dadhania [this message]
2026-09-29 5:27 ` [PATCH v8 0/8] KVM: SVM: Add Page Modification Logging (PML) support Nikunj A Dadhania
2026-10-02 21:07 ` Sean Christopherson
2026-10-05 3:31 ` Nikunj A. Dadhania
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4b931b35-0890-466f-9ee3-09b4bb9ca4b7@amd.com \
--to=nikunj@amd.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=seanjc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.