All of lore.kernel.org
 help / color / mirror / Atom feed
From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Lisa Wang <wyihan@google.com>,
	Andrew Jones <ajones@ventanamicro.com>,
	Ackerley Tng <ackerleytng@google.com>,
	Binbin Wu <binbin.wu@linux.intel.com>,
	Chao Gao <chao.gao@intel.com>,
	Chenyi Qiang <chenyi.qiang@intel.com>,
	Dave Hansen <dave.hansen@linux.intel.com>,
	Erdem Aktas <erdemaktas@google.com>,
	Ira Weiny <ira.weiny@intel.com>,
	Isaku Yamahata <isaku.yamahata@intel.com>,
	Kiryl Shutsemau <kas@kernel.org>,
	linux-kselftest@vger.kernel.org,
	Paolo Bonzini <pbonzini@redhat.com>,
	"Pratik R. Sampat" <pratikrajesh.sampat@amd.com>,
	Reinette Chatre <reinette.chatre@intel.com>,
	Rick Edgecombe <rick.p.edgecombe@intel.com>,
	Roger Wang <runanwang@google.com>,
	Ryan Afranji <afranji@google.com>, Sagi Shahar <sagis@google.com>,
	Sean Christopherson <seanjc@google.com>,
	Shuah Khan <shuah@kernel.org>, Oliver Upton <oupton@kernel.org>
Cc: Jeremiah McReynolds <jmcrey@google.com>,
	kvm@vger.kernel.org, linux-coco@lists.linux.dev,
	linux-kernel@vger.kernel.org, x86@kernel.org
Subject: Re: [PATCH v14 18/22] KVM: selftests: Add helpers to init TDX memory and finalize VM
Date: Mon, 17 Aug 2026 14:47:10 +0800	[thread overview]
Message-ID: <befe73e1-3287-440e-90de-6c62f6c19d47@intel.com> (raw)
In-Reply-To: <20260722-tdx-selftests-v14-18-15ad654a50db@google.com>

On 7/23/2026 7:13 AM, Lisa Wang wrote:
> From: Ackerley Tng <ackerleytng@google.com>
> 
> TDX protected memory needs to be measured and encrypted before it can be
> used by the guest. Traverse the VM's memory regions and initialize all
> the protected ranges by calling KVM_TDX_INIT_MEM_REGION.
> 
> Once all the memory is initialized, the VM can be finalized by calling
> KVM_TDX_FINALIZE_VM.
> 
> Signed-off-by: Ackerley Tng <ackerleytng@google.com>
> Co-developed-by: Erdem Aktas <erdemaktas@google.com>
> Signed-off-by: Erdem Aktas <erdemaktas@google.com>
> Co-developed-by: Sagi Shahar <sagis@google.com>
> Signed-off-by: Sagi Shahar <sagis@google.com>
> Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
> Reviewed-by: Ira Weiny <ira.weiny@intel.com>
> Co-developed-by: Lisa Wang <wyihan@google.com>
> Signed-off-by: Lisa Wang <wyihan@google.com>
> ---
>   .../selftests/kvm/include/x86/tdx/tdx_util.h       |  2 +
>   tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c | 63 ++++++++++++++++++++++
>   2 files changed, 65 insertions(+)
> 
> diff --git a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h
> index 307e2c0bc9c9..35f0b2b7ac40 100644
> --- a/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h
> +++ b/tools/testing/selftests/kvm/include/x86/tdx/tdx_util.h
> @@ -72,4 +72,6 @@ void tdx_vm_load_common_boot_parameters(struct kvm_vm *vm);
>   void tdx_vcpu_load_boot_parameters(struct kvm_vm *vm, struct kvm_vcpu *vcpu);
>   void tdx_vcpu_set_entry_point(struct kvm_vcpu *vcpu, void *guest_code);
>   
> +void tdx_vm_finalize(struct kvm_vm *vm);
> +
>   #endif /* SELFTESTS_TDX_TDX_UTIL_H */
> diff --git a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
> index be63d8652a02..831b0e5160df 100644
> --- a/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
> +++ b/tools/testing/selftests/kvm/lib/x86/tdx/tdx_util.c
> @@ -1,5 +1,7 @@
>   // SPDX-License-Identifier: GPL-2.0-only
>   
> +#include <linux/align.h>
> +
>   #include "processor.h"
>   #include "tdx/td_boot.h"
>   #include "tdx/tdx_util.h"
> @@ -251,3 +253,64 @@ void tdx_init_vm(struct kvm_vm *vm, u64 attributes)
>   
>   	free(init_vm);
>   }
> +
> +static void tdx_init_mem_region(struct kvm_vm *vm, void *source_pages,
> +				u64 gpa, u64 size)
> +{
> +	u32 flags = KVM_TDX_MEASURE_MEMORY_REGION;
> +	struct kvm_tdx_init_mem_region mem_region = {
> +		.source_addr = (u64)source_pages,
> +		.gpa = gpa,
> +		.nr_pages = size / PAGE_SIZE,
> +	};
> +	struct kvm_vcpu *vcpu;
> +
> +	vcpu = list_first_entry_or_null(&vm->vcpus, struct kvm_vcpu, list);
> +
> +	TEST_ASSERT(size && IS_ALIGNED(size, PAGE_SIZE),
> +		"Cannot add partial pages to the guest memory.\n");
> +	TEST_ASSERT(IS_ALIGNED((u64)source_pages, PAGE_SIZE),
> +		"Source memory buffer is not page aligned\n");
> +	tdx_vcpu_ioctl(vcpu, KVM_TDX_INIT_MEM_REGION, flags, &mem_region);
> +}
> +
> +static void tdx_load_private_memory(struct kvm_vm *vm)
> +{
> +	struct userspace_mem_region *region;
> +	int ctr;
> +
> +	hash_for_each(vm->regions.slot_hash, ctr, region, slot_node) {
> +		const struct sparsebit *protected_pages = region->protected_phy_pages;
> +		const gpa_t gpa_base = region->region.guest_phys_addr;
> +		const u64 hva_base = region->region.userspace_addr;
> +		const sparsebit_idx_t lowest_page_in_region = gpa_base >> vm->page_shift;
> +		void *source_pages = NULL;
> +		sparsebit_idx_t i, j;
> +
> +		if (!sparsebit_any_set(protected_pages))

sparebit_any_set() doens't check if the input is NULL. So we need to 
check it here.

> +			continue;
> +
> +		TEST_ASSERT(region->region.guest_memfd != -1,
> +			    "TD private memory must be backed by guest_memfd");
> +
> +		sparsebit_for_each_set_range(protected_pages, i, j) {
> +			const u64 size_to_load = (j - i + 1) * vm->page_size;
> +			const u64 offset =
> +				(i - lowest_page_in_region) * vm->page_size;
> +			const u64 hva = hva_base + offset;
> +			const u64 gpa = gpa_base + offset;
> +
> +			if (!kvm_has_gmem_attributes)
> +				source_pages = (void *)hva;
> +

> +			vm_mem_set_private(vm, gpa, size_to_load);

So vm_mem_set_private() has to be called at this late stage when run 
with in-place gmem. But for non in-place gmem, we can actually call 
vm_mem_set_private() in __vm_phy_pages_alloc().

Calling vm_mem_set_private() here instead of in __vm_phy_pages_alloc() 
looks like a trick to me. That is, we cannot set the page as private 
when allocating a guest physical page as protected because if doing so, 
we cannot write the initial content to it.

This is the topic about how to implement the infras for in-place gmem, 
not the issue of this series. Let me go read the selftest patches of 
gmem in-place series and we can discuss there.

> +			tdx_init_mem_region(vm, source_pages, gpa, size_to_load);
> +		}
> +	}
> +}
> +
> +void tdx_vm_finalize(struct kvm_vm *vm)
> +{
> +	tdx_load_private_memory(vm);
> +	tdx_vm_ioctl(vm, KVM_TDX_FINALIZE_VM, 0, NULL);
> +}
> 


  reply	other threads:[~2026-08-17  6:47 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22 23:13 [PATCH v14 00/22] TDX KVM selftests Lisa Wang
2026-07-22 23:13 ` [PATCH v14 01/22] KVM: selftests: Add macros to simplify creating VM shapes for non-default types Lisa Wang
2026-07-22 23:13 ` [PATCH v14 02/22] KVM: selftests: Update kvm_init_vm_address_properties() for TDX Lisa Wang
2026-08-13 23:17   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 03/22] KVM: selftests: Initialize the TDX VM Lisa Wang
2026-07-23  8:44   ` Xiaoyao Li
2026-08-13 23:41     ` Edgecombe, Rick P
2026-08-15  9:17       ` Xiaoyao Li
2026-08-13 23:41   ` Edgecombe, Rick P
2026-08-14 21:18     ` Peter Fang
2026-07-22 23:13 ` [PATCH v14 04/22] KVM: selftests: TDX: Use KVM_TDX_CAPABILITIES to validate TDs' attribute configuration Lisa Wang
2026-08-13 23:45   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 05/22] KVM: selftests: Expose segment definitions to assembly files Lisa Wang
2026-08-13 23:50   ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 06/22] tools: include: Add kbuild.h for assembly structure offsets Lisa Wang
2026-07-22 23:13 ` [PATCH v14 07/22] KVM: selftests: Introduce structures for TDX guest boot parameters Lisa Wang
2026-07-22 23:13 ` [PATCH v14 08/22] KVM: selftests: Add TDX boot code Lisa Wang
2026-07-23 11:17   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 09/22] KVM: selftests: Expose functions to get default sregs values Lisa Wang
2026-07-23 10:19   ` Xiaoyao Li
2026-08-14  0:44   ` Edgecombe, Rick P
2026-08-14  2:36     ` Xiaoyao Li
2026-08-14 15:14       ` Edgecombe, Rick P
2026-07-22 23:13 ` [PATCH v14 10/22] KVM: selftests: Set up TDX boot code region Lisa Wang
2026-07-23 10:24   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 11/22] KVM: selftests: Set up TDX boot parameters region Lisa Wang
2026-07-23 10:34   ` Xiaoyao Li
2026-08-11  6:32   ` Binbin Wu
2026-07-22 23:13 ` [PATCH v14 12/22] KVM: selftests: Require guest_memfd for TDX VMs Lisa Wang
2026-08-11  7:43   ` Binbin Wu
2026-08-14  7:42   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 13/22] KVM: selftests: Support guest_memfd in-place conversion Lisa Wang
2026-07-22 23:13 ` [PATCH v14 14/22] KVM: selftests: Expose function to allocate vCPU stack Lisa Wang
2026-08-14  8:10   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 15/22] KVM: selftests: Call KVM_TDX_INIT_VCPU when creating a new TDX vcpu Lisa Wang
2026-08-14  8:32   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 16/22] KVM: selftests: Load per-vCPU guest stack in TDX boot parameters Lisa Wang
2026-08-14  8:39   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 17/22] KVM: selftests: Set entry point for TDX guest code Lisa Wang
2026-08-14  8:43   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 18/22] KVM: selftests: Add helpers to init TDX memory and finalize VM Lisa Wang
2026-08-17  6:47   ` Xiaoyao Li [this message]
2026-08-17 13:52     ` Ackerley Tng
2026-07-22 23:13 ` [PATCH v14 19/22] KVM: selftests: Finalize TD memory as part of kvm_arch_vm_finalize_vcpus Lisa Wang
2026-08-17  7:04   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 20/22] KVM: selftests: Implement MMIO WRITE for the TDX VM Lisa Wang
2026-07-28 22:56   ` Ackerley Tng
2026-08-17  8:56   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 21/22] KVM: selftests: Add ucall support for TDX Lisa Wang
2026-08-17  8:38   ` Xiaoyao Li
2026-07-22 23:13 ` [PATCH v14 22/22] KVM: selftests: Add TDX lifecycle test Lisa Wang
2026-08-17  9:04   ` Xiaoyao Li
2026-08-13 22:47 ` [PATCH v14 00/22] TDX KVM selftests Edgecombe, Rick P
2026-08-13 23:05   ` Edgecombe, Rick P
2026-08-17  4:19     ` Ackerley Tng
2026-08-17 17:54       ` Edgecombe, Rick P

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=befe73e1-3287-440e-90de-6c62f6c19d47@intel.com \
    --to=xiaoyao.li@intel.com \
    --cc=ackerleytng@google.com \
    --cc=afranji@google.com \
    --cc=ajones@ventanamicro.com \
    --cc=binbin.wu@linux.intel.com \
    --cc=chao.gao@intel.com \
    --cc=chenyi.qiang@intel.com \
    --cc=dave.hansen@linux.intel.com \
    --cc=erdemaktas@google.com \
    --cc=ira.weiny@intel.com \
    --cc=isaku.yamahata@intel.com \
    --cc=jmcrey@google.com \
    --cc=kas@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-kselftest@vger.kernel.org \
    --cc=oupton@kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=pratikrajesh.sampat@amd.com \
    --cc=reinette.chatre@intel.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=runanwang@google.com \
    --cc=sagis@google.com \
    --cc=seanjc@google.com \
    --cc=shuah@kernel.org \
    --cc=wyihan@google.com \
    --cc=x86@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.