All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Brendan Jackman" <brendan.jackman@linux.dev>
To: "Mike Rapoport" <rppt@kernel.org>, "Yosry Ahmed" <yosry@kernel.org>
Cc: "Brendan Jackman" <jackmanb@google.com>,
	"Borislav Petkov" <bp@alien8.de>,
	"Dave Hansen" <dave.hansen@linux.intel.com>,
	"Peter Zijlstra" <peterz@infradead.org>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"David Hildenbrand" <david@kernel.org>,
	"Vlastimil Babka" <vbabka@kernel.org>,
	"Wei Xu" <weixugc@google.com>,
	"Johannes Weiner" <hannes@cmpxchg.org>, "Zi Yan" <ziy@nvidia.com>,
	"Lorenzo Stoakes" <ljs@kernel.org>, <linux-mm@kvack.org>,
	<linux-kernel@vger.kernel.org>, <x86@kernel.org>,
	"Sumit Garg" <sumit.garg@oss.qualcomm.com>,
	"Will Deacon" <will@kernel.org>, <rientjes@google.com>,
	"Kalyazin, Nikita" <kalyazin@amazon.co.uk>,
	<patrick.roy@linux.dev>,
	"Itazuri, Takahiro" <itazur@amazon.co.uk>,
	"Andy Lutomirski" <luto@kernel.org>,
	"David Kaplan" <david.kaplan@amd.com>,
	"Thomas Gleixner" <tglx@kernel.org>,
	"Patrick Bellasi" <derkling@google.com>,
	"Reiji Watanabe" <reijiw@google.com>,
	"Sean Christopherson" <seanjc@google.com>,
	"Nikita Kalyazin" <nikita.kalyazin@linux.dev>
Subject: Re: [PATCH v3 01/26] set_memory: add folio_{zap,restore}_direct_map helpers
Date: Fri, 31 Jul 2026 11:57:33 +0000	[thread overview]
Message-ID: <DKCQL9KO4PD1.27SYU4GD2NH8Y@linux.dev> (raw)
In-Reply-To: <amwwwe4eYeXtniFu@kernel.org>

On Fri Jul 31, 2026 at 5:21 AM UTC, Mike Rapoport wrote:
> On Thu, Jul 30, 2026 at 08:34:57PM +0000, Yosry Ahmed wrote:
>> On Sun, Jul 26, 2026 at 10:22:34PM +0000, Brendan Jackman wrote:
>> > From: Nikita Kalyazin <nikita.kalyazin@linux.dev>
>> > 
>> > Let's provide folio_{zap,restore}_direct_map helpers as preparation for
>> > supporting removal of the direct map for guest_memfd folios.
>> > In folio_zap_direct_map(), flush TLB to make sure the data is not
>> > accessible.  On some architectures, there may be a double TLB flush
>> > issued because set_direct_map_valid_noflush already performs a flush
>> > internally.
>> > 
>> > The new helpers need to be accessible to KVM on architectures that
>> > support guest_memfd (x86 and arm64).
>> > 
>> > Direct map removal gives guest_memfd the same protection that
>> > memfd_secret does, such as hardening against Spectre-like attacks
>> > through in-kernel gadgets.
>> > 
>> > Acked-by: David Hildenbrand (Arm) <david@kernel.org>
>> > Signed-off-by: Nikita Kalyazin <nikita.kalyazin@linux.dev>
>> > [Added comment, dropped modified set_direct_map API, added highmem check]
>> > Signed-off-by: Brendan Jackman <jackmanb@google.com>
>> > ---
>> >  include/linux/set_memory.h | 13 +++++++++++++
>> >  mm/memory.c                | 46 ++++++++++++++++++++++++++++++++++++++++++++++
>> >  2 files changed, 59 insertions(+)
>> > 
>> > diff --git a/include/linux/set_memory.h b/include/linux/set_memory.h
>> > index 3030d9245f5ac..1bf2a15bca118 100644
>> > --- a/include/linux/set_memory.h
>> > +++ b/include/linux/set_memory.h
>> > @@ -40,6 +40,15 @@ static inline int set_direct_map_valid_noflush(struct page *page,
>> >  	return 0;
>> >  }
>> >  
>> > +static inline int folio_zap_direct_map(struct folio *folio)
>> > +{
>> > +	return 0;
>> 
>> Should this return an error (e.g. -EOPNOTSUPP)? Seems like it would
>> silently succeed if the arch doesn't actually support removing from the
>> direct map.
>
> That's the pattern we have now for all set_memory APIs.

Yeah. And I think that's fine, the risk of silent failure is mitigated
by:

#define can_set_direct_map() false

So yes code could call folio_zap_direct_map() directly and get
confusing results on unsupported configs, but that code would be broken
on arm64 regardless (coz it didn't respect can_set_direct_map()), plus
later in this series is:

#ifdef CONFIG_PAGE_ALLOC_UNMAPPED
#define ALLOC_UNMAPPED	       0x2000
#endif

So higher-level code will fail to compile it if uses ALLOC_UNMAPPED on a
completely unsupported config.

  reply	other threads:[~2026-07-31 11:57 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26 22:22 [PATCH v3 00/26] mm: Add ALLOC_UNMAPPED and AS_NO_DIRECT_MAP Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 01/26] set_memory: add folio_{zap,restore}_direct_map helpers Brendan Jackman
2026-07-27 10:33   ` Mike Rapoport
2026-07-29 11:42     ` Brendan Jackman
2026-07-30 20:34   ` Yosry Ahmed
2026-07-31  5:21     ` Mike Rapoport
2026-07-31 11:57       ` Brendan Jackman [this message]
2026-07-26 22:22 ` [PATCH v3 02/26] mm/secretmem: make use of folio_{zap,restore}_direct_map Brendan Jackman
2026-07-27 10:40   ` Mike Rapoport
2026-07-26 22:22 ` [PATCH v3 03/26] mm: introduce AS_NO_DIRECT_MAP Brendan Jackman
2026-07-30 21:06   ` Yosry Ahmed
2026-07-31 12:15     ` Brendan Jackman
2026-07-31 19:28       ` Yosry Ahmed
2026-07-26 22:22 ` [PATCH v3 04/26] x86/mm: split out preallocate_sub_pgd() Brendan Jackman
2026-07-31 22:10   ` Yosry Ahmed
2026-07-26 22:22 ` [PATCH v3 05/26] x86: move PAE PMD preallocation defines to header Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 06/26] x86/tlb: Expose some flush function declarations to modules Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 07/26] x86/mm: introduce mm-local region Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 08/26] x86/mm: move LDT remap into " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 09/26] mm: Create flags arg for __apply_to_page_range() Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 10/26] mm: Add more flags " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 11/26] x86/mm: introduce the mermap Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 12/26] mm: KUnit tests for " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 13/26] mm: introduce freetype_t Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 14/26] mm: move migratetype definitions to freetype.h Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 15/26] mm/page_alloc: add support for freetypes with no freelist Brendan Jackman
2026-07-31 14:13   ` Vlastimil Babka (SUSE)
2026-07-26 22:22 ` [PATCH v3 16/26] mm: add definitions for allocating unmapped pages Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 17/26] mm: encode freetype flags in pageblock flags Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 18/26] mm/page_alloc: separate pcplists by freetype flags Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 19/26] mm/page_alloc: rename ALLOC_NON_BLOCK back to _HARDER Brendan Jackman
2026-07-31 14:52   ` Vlastimil Babka (SUSE)
2026-07-26 22:22 ` [PATCH v3 20/26] mm/page_alloc: introduce ALLOC_NOBLOCK Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 21/26] mm/page_alloc: implement FREETYPE_UNMAPPED allocations Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 22/26] mm: Minimal KUnit tests for some new page_alloc logic Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 23/26] mm: Split out NR_FREE_PAGES_BLOCKS_[UN]MAPPED Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 24/26] mm/page_alloc: always direct compact for unmapped allocs Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 25/26] mm: plumb alloc flags into some alloc funcs Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 26/26] mm: add fast path for AS_NO_DIRECT_MAP Brendan Jackman
2026-07-29 11:52 ` [PATCH v3 00/26] mm: Add ALLOC_UNMAPPED and AS_NO_DIRECT_MAP Brendan Jackman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKCQL9KO4PD1.27SYU4GD2NH8Y@linux.dev \
    --to=brendan.jackman@linux.dev \
    --cc=akpm@linux-foundation.org \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=david.kaplan@amd.com \
    --cc=david@kernel.org \
    --cc=derkling@google.com \
    --cc=hannes@cmpxchg.org \
    --cc=itazur@amazon.co.uk \
    --cc=jackmanb@google.com \
    --cc=kalyazin@amazon.co.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=luto@kernel.org \
    --cc=nikita.kalyazin@linux.dev \
    --cc=patrick.roy@linux.dev \
    --cc=peterz@infradead.org \
    --cc=reijiw@google.com \
    --cc=rientjes@google.com \
    --cc=rppt@kernel.org \
    --cc=seanjc@google.com \
    --cc=sumit.garg@oss.qualcomm.com \
    --cc=tglx@kernel.org \
    --cc=vbabka@kernel.org \
    --cc=weixugc@google.com \
    --cc=will@kernel.org \
    --cc=x86@kernel.org \
    --cc=yosry@kernel.org \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.