From: Christoph Hellwig <hch@infradead.org>
To: Shivank Garg <shivankg@amd.com>
Cc: seanjc@google.com, david@redhat.com, vbabka@suse.cz,
willy@infradead.org, akpm@linux-foundation.org, shuah@kernel.org,
pbonzini@redhat.com, ackerleytng@google.com, paul@paul-moore.com,
jmorris@namei.org, serge@hallyn.com, pvorel@suse.cz,
bfoster@redhat.com, tabba@google.com, vannapurve@google.com,
chao.gao@intel.com, bharata@amd.com, nikunj@amd.com,
michael.day@amd.com, yan.y.zhao@intel.com,
Neeraj.Upadhyay@amd.com, thomas.lendacky@amd.com,
michael.roth@amd.com, aik@amd.com, jgg@nvidia.com,
kalyazin@amazon.com, peterx@redhat.com,
linux-fsdevel@vger.kernel.org, linux-mm@kvack.org,
linux-kernel@vger.kernel.org,
linux-security-module@vger.kernel.org, kvm@vger.kernel.org,
linux-kselftest@vger.kernel.org, linux-coco@lists.linux.dev
Subject: Re: [PATCH RFC v7 5/8] KVM: guest_memfd: Make guest mem use guest mem inodes instead of anonymous inodes
Date: Thu, 10 Apr 2025 01:42:38 -0700 [thread overview]
Message-ID: <Z_eEfjrkspAt4ACP@infradead.org> (raw)
In-Reply-To: <20250408112402.181574-6-shivankg@amd.com>
On Tue, Apr 08, 2025 at 11:23:59AM +0000, Shivank Garg wrote:
> From: Ackerley Tng <ackerleytng@google.com>
>
> Using guest mem inodes allows us to store metadata for the backing
> memory on the inode. Metadata will be added in a later patch to support
> HugeTLB pages.
>
> Metadata about backing memory should not be stored on the file, since
> the file represents a guest_memfd's binding with a struct kvm, and
> metadata about backing memory is not unique to a specific binding and
> struct kvm.
>
> Signed-off-by: Ackerley Tng <ackerleytng@google.com>
> Signed-off-by: Fuad Tabba <tabba@google.com>
> Signed-off-by: Shivank Garg <shivankg@amd.com>
> ---
> include/uapi/linux/magic.h | 1 +
> virt/kvm/guest_memfd.c | 133 +++++++++++++++++++++++++++++++------
> 2 files changed, 113 insertions(+), 21 deletions(-)
>
> diff --git a/include/uapi/linux/magic.h b/include/uapi/linux/magic.h
> index bb575f3ab45e..169dba2a6920 100644
> --- a/include/uapi/linux/magic.h
> +++ b/include/uapi/linux/magic.h
> @@ -103,5 +103,6 @@
> #define DEVMEM_MAGIC 0x454d444d /* "DMEM" */
> #define SECRETMEM_MAGIC 0x5345434d /* "SECM" */
> #define PID_FS_MAGIC 0x50494446 /* "PIDF" */
> +#define GUEST_MEMORY_MAGIC 0x474d454d /* "GMEM" */
>
> #endif /* __LINUX_MAGIC_H__ */
> diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c
> index 88453b040926..002328569c9e 100644
> --- a/virt/kvm/guest_memfd.c
> +++ b/virt/kvm/guest_memfd.c
> @@ -1,12 +1,17 @@
> // SPDX-License-Identifier: GPL-2.0
> +#include <linux/fs.h>
> +#include <linux/mount.h>
> #include <linux/backing-dev.h>
> #include <linux/falloc.h>
> #include <linux/kvm_host.h>
> +#include <linux/pseudo_fs.h>
> #include <linux/pagemap.h>
> #include <linux/anon_inodes.h>
>
> #include "kvm_mm.h"
>
> +static struct vfsmount *kvm_gmem_mnt;
> +
> struct kvm_gmem {
> struct kvm *kvm;
> struct xarray bindings;
> @@ -312,6 +317,38 @@ static pgoff_t kvm_gmem_get_index(struct kvm_memory_slot *slot, gfn_t gfn)
> return gfn - slot->base_gfn + slot->gmem.pgoff;
> }
>
> +static const struct super_operations kvm_gmem_super_operations = {
> + .statfs = simple_statfs,
> +};
> +
> +static int kvm_gmem_init_fs_context(struct fs_context *fc)
> +{
> + struct pseudo_fs_context *ctx;
> +
> + if (!init_pseudo(fc, GUEST_MEMORY_MAGIC))
> + return -ENOMEM;
> +
> + ctx = fc->fs_private;
> + ctx->ops = &kvm_gmem_super_operations;
> +
> + return 0;
> +}
> +
> +static struct file_system_type kvm_gmem_fs = {
> + .name = "kvm_guest_memory",
> + .init_fs_context = kvm_gmem_init_fs_context,
> + .kill_sb = kill_anon_super,
> +};
> +
> +static void kvm_gmem_init_mount(void)
> +{
> + kvm_gmem_mnt = kern_mount(&kvm_gmem_fs);
> + BUG_ON(IS_ERR(kvm_gmem_mnt));
> +
> + /* For giggles. Userspace can never map this anyways. */
> + kvm_gmem_mnt->mnt_flags |= MNT_NOEXEC;
> +}
> +
> static struct file_operations kvm_gmem_fops = {
> .open = generic_file_open,
> .release = kvm_gmem_release,
> @@ -321,11 +358,13 @@ static struct file_operations kvm_gmem_fops = {
> void kvm_gmem_init(struct module *module)
> {
> kvm_gmem_fops.owner = module;
> +
> + kvm_gmem_init_mount();
> }
>
> void kvm_gmem_exit(void)
> {
> -
> + kern_unmount(kvm_gmem_mnt);
> }
>
> static int kvm_gmem_migrate_folio(struct address_space *mapping,
> @@ -407,11 +446,79 @@ static const struct inode_operations kvm_gmem_iops = {
> .setattr = kvm_gmem_setattr,
> };
>
> +static struct inode *kvm_gmem_inode_make_secure_inode(const char *name,
> + loff_t size, u64 flags)
> +{
> + const struct qstr qname = QSTR_INIT(name, strlen(name));
> + struct inode *inode;
> + int err;
> +
> + inode = alloc_anon_inode(kvm_gmem_mnt->mnt_sb);
> + if (IS_ERR(inode))
> + return inode;
> +
> + err = security_inode_init_security_anon(inode, &qname, NULL);
> + if (err) {
> + iput(inode);
> + return ERR_PTR(err);
> + }
So why do other alloc_anon_inode callers not need
security_inode_init_security_anon?
next prev parent reply other threads:[~2025-04-10 8:42 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-04-08 11:23 [PATCH RFC v7 0/8] Add NUMA mempolicy support for KVM guest-memfd Shivank Garg
2025-04-08 11:23 ` [PATCH RFC v7 1/8] mm/filemap: Add mempolicy support to the filemap layer Shivank Garg
2025-04-08 11:23 ` [PATCH RFC v7 2/8] mm/mempolicy: Export memory policy symbols Shivank Garg
2025-04-08 11:23 ` [PATCH RFC v7 3/8] security: Export security_inode_init_security_anon for KVM guest_memfd Shivank Garg
2025-04-09 20:19 ` Paul Moore
2025-04-11 6:07 ` Shivank Garg
2025-04-22 16:49 ` David Hildenbrand
2025-04-10 8:41 ` Christoph Hellwig
2025-04-11 6:51 ` Shivank Garg
2025-04-22 17:25 ` David Hildenbrand
2025-05-08 6:37 ` Shivank Garg
2025-04-08 11:23 ` [PATCH RFC v7 4/8] KVM: Add kvm_gmem_exit() cleanup function Shivank Garg
2025-04-08 11:23 ` [PATCH RFC v7 5/8] KVM: guest_memfd: Make guest mem use guest mem inodes instead of anonymous inodes Shivank Garg
2025-04-10 8:42 ` Christoph Hellwig [this message]
2025-04-10 13:53 ` Ackerley Tng
2025-04-10 14:23 ` Christoph Hellwig
2025-04-08 11:24 ` [PATCH RFC v7 6/8] KVM: guest_memfd: Add slab-allocated inode cache Shivank Garg
2025-04-08 11:24 ` [PATCH RFC v7 7/8] KVM: guest_memfd: Enforce NUMA mempolicy using shared policy Shivank Garg
2025-04-10 13:40 ` Ackerley Tng
2025-04-11 6:42 ` Shivank Garg
2025-04-08 11:24 ` [PATCH RFC v7 8/8] KVM: guest_memfd: selftests: Add tests for mmap and NUMA policy support Shivank Garg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Z_eEfjrkspAt4ACP@infradead.org \
--to=hch@infradead.org \
--cc=Neeraj.Upadhyay@amd.com \
--cc=ackerleytng@google.com \
--cc=aik@amd.com \
--cc=akpm@linux-foundation.org \
--cc=bfoster@redhat.com \
--cc=bharata@amd.com \
--cc=chao.gao@intel.com \
--cc=david@redhat.com \
--cc=jgg@nvidia.com \
--cc=jmorris@namei.org \
--cc=kalyazin@amazon.com \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-fsdevel@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-security-module@vger.kernel.org \
--cc=michael.day@amd.com \
--cc=michael.roth@amd.com \
--cc=nikunj@amd.com \
--cc=paul@paul-moore.com \
--cc=pbonzini@redhat.com \
--cc=peterx@redhat.com \
--cc=pvorel@suse.cz \
--cc=seanjc@google.com \
--cc=serge@hallyn.com \
--cc=shivankg@amd.com \
--cc=shuah@kernel.org \
--cc=tabba@google.com \
--cc=thomas.lendacky@amd.com \
--cc=vannapurve@google.com \
--cc=vbabka@suse.cz \
--cc=willy@infradead.org \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.