From: Tony Lindgren <tony.lindgren@linux.intel.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [RFC PATCH v2 2/4] KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD
Date: Tue, 1 Sep 2026 09:03:22 +0300 [thread overview]
Message-ID: <apZqqi0V-CEKgZbC@tlindgre-MOBL1> (raw)
In-Reply-To: <20260831072311.CF2DA1F000E9@smtp.kernel.org>
On Mon, Aug 31, 2026 at 07:23:11AM +0000, sashiko-bot@kernel.org wrote:
> Author: Tony Lindgren <tony.lindgren@linux.intel.com>
> > --- a/arch/x86/kvm/x86.c
> > +++ b/arch/x86/kvm/x86.c
> > @@ -7614,6 +7617,28 @@ int kvm_arch_vm_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg)
> > r = kvm_vm_ioctl_set_msr_filter(kvm, &filter);
> > break;
> > }
> > + case KVM_MIGRATE_CMD: {
> > + struct kvm_migrate_cmd cmd;
> > +
> > + if (!kvm_x86_ops.migrate_cmd ||
> > + !kvm_x86_call(cap_live_migration)(kvm))
> > + return -ENOTTY;
> > +
> > + if (copy_from_user(&cmd, argp, sizeof(cmd)))
> > + return -EFAULT;
> > +
> > + if (cmd.reserved || cmd.buf.reserved)
> > + return -EINVAL;
>
> [Severity: High]
> Does this code also need to validate that the new flags field is zero?
>
> If uninitialized memory or garbage is passed by userspace in cmd.flags, it
> will currently be silently ignored. When a future kernel introduces a new
> flag, old userspace applications passing uninitialized flags will inadvertently
> enable it, which could permanently break backwards compatibility.
Could be zero, or we could check for the known flags.
We are currently using the following flags for KVM_MIGRATE_CMD
sub-commands for TDX:
1. KVM_MIGRATE_SETUP
====================
TDX_MIGRATE_SETUP_SESSION exchange the migration keys
TDX_MIGRATE_IMMUTABLE_STATE transfer the TDX immutable state
2. KVM_MIGRATE_ITERATION
========================
TDX_MIGRATE_IN_ORDER_DONE end the in-order migration
3. KVM_MIGRATE_STOP_AND_COPY
============================
TDX_MIGRATE_STOP_COPY_PAUSE pause the TD
TDX_MIGRATE_STOP_COPY_TD_STATE transfer the mutable TD state
4. KVM_MIGRATE_END
==================
TDX_MIGRATE_ABORT abort migration
Maybe all the above TDX specific flags could be turned into generic
flags for the sub-commands.
next prev parent reply other threads:[~2026-09-01 6:03 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 7:13 [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Tony Lindgren
2026-08-31 7:13 ` [RFC PATCH v2 1/4] Documentation: KVM: Add live migration API for confidential guests Tony Lindgren
2026-08-31 7:20 ` sashiko-bot
2026-08-31 7:13 ` [RFC PATCH v2 2/4] KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD Tony Lindgren
2026-08-31 7:23 ` sashiko-bot
2026-09-01 6:03 ` Tony Lindgren [this message]
2026-09-07 11:53 ` Tony Lindgren
2026-09-07 13:15 ` Jörg Rödel
2026-09-07 13:32 ` Artem Bityutskiy
2026-09-08 4:15 ` Tony Lindgren
2026-09-08 4:43 ` Tony Lindgren
2026-09-09 0:22 ` Kishen Maloor
2026-09-09 6:57 ` Tony Lindgren
2026-09-10 1:11 ` Kishen Maloor
2026-09-10 6:33 ` Tony Lindgren
2026-09-11 1:40 ` Kishen Maloor
2026-09-11 4:23 ` Tony Lindgren
2026-08-31 7:13 ` [RFC PATCH v2 3/4] KVM: x86: Add optional KVM_EXPORT_MEMORY and KVM_IMPORT_MEMORY Tony Lindgren
2026-08-31 7:23 ` sashiko-bot
2026-09-01 6:10 ` Tony Lindgren
2026-08-31 7:13 ` [RFC PATCH v2 4/4] KVM: x86: Add optional KVM_EXPORT_VCPU and KVM_IMPORT_VCPU Tony Lindgren
2026-08-31 7:23 ` sashiko-bot
2026-09-01 6:12 ` Tony Lindgren
2026-09-04 18:24 ` [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Artem Bityutskiy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=apZqqi0V-CEKgZbC@tlindgre-MOBL1 \
--to=tony.lindgren@linux.intel.com \
--cc=kvm@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.