From: Jason Andryuk <jason.andryuk@amd.com>
To: "Daniel P. Smith" <dpsmith@apertussolutions.com>,
<xen-devel@lists.xenproject.org>
Cc: christopher.w.clark@gmail.com, stefano.stabellini@amd.com,
"Jan Beulich" <jbeulich@suse.com>,
"Andrew Cooper" <andrew.cooper3@citrix.com>,
"Roger Pau Monné" <roger.pau@citrix.com>
Subject: Re: [PATCH v9 2/6] x86/boot: introduce module release
Date: Fri, 15 Nov 2024 12:18:49 -0500 [thread overview]
Message-ID: <f3aee76b-7ac1-4558-a036-c2c19c5b9154@amd.com> (raw)
In-Reply-To: <3f61cc43-c29a-40e0-ac40-4f273fd4461e@apertussolutions.com>
On 2024-11-15 12:16, Daniel P. Smith wrote:
> On 11/15/24 11:50, Jason Andryuk wrote:
>> On 2024-11-15 08:12, Daniel P. Smith wrote:
>>> A precarious approach was used to release the pages used to hold a
>>> boot module.
>>> The precariousness stemmed from the fact that in the case of PV dom0,
>>> the
>>> initrd module pages may be either mapped or copied into the dom0
>>> address space.
>>> In the former case, the PV dom0 construction code will set the size
>>> of the
>>> module to zero, relying on discard_initial_images() to skip any
>>> modules with a
>>> size of zero. In the latter case, the pages are freed by the PV dom0
>>> construction code. This freeing of pages is done so that in either
>>> case, the
>>> initrd variable can be reused for tracking the initrd location in
>>> dom0 memory
>>> through the remaining dom0 construction code.
>>>
>>> To encapsulate the logical action of releasing a boot module, the
>>> function
>>> release_boot_module() is introduced along with the `released` flag
>>> added to
>>> boot module. The boot module flag `released` allows the tracking of
>>> when a boot
>>> module has been released by release_boot_module().
>>>
>>> As part of adopting release_boot_module() the function
>>> discard_initial_images()
>>> is renamed to free_boot_modules(), a name that better reflects the
>>> functions
>>> actions.
>>>
>>> Signed-off-by: Daniel P. Smith <dpsmith@apertussolutions.com>
>>> ---
>>> Changes since v8:
>>> - completely reworked the commit
>>> - switch backed to a releasing all but pv initrd approach
>>> - renamed discard_initial_images to free_boot_modules
>>> ---
>>> xen/arch/x86/hvm/dom0_build.c | 2 +-
>>> xen/arch/x86/include/asm/bootinfo.h | 2 ++
>>> xen/arch/x86/include/asm/setup.h | 4 +++-
>>> xen/arch/x86/pv/dom0_build.c | 27 +++++++++++++--------------
>>> xen/arch/x86/setup.c | 27 +++++++++++++++------------
>>> 5 files changed, 34 insertions(+), 28 deletions(-)
>>>
>>> diff --git a/xen/arch/x86/hvm/dom0_build.c b/xen/arch/x86/hvm/
>>> dom0_build.c
>>> index d1bdf1b14601..d1410e1a02b0 100644
>>> --- a/xen/arch/x86/hvm/dom0_build.c
>>> +++ b/xen/arch/x86/hvm/dom0_build.c
>>> @@ -755,7 +755,7 @@ static int __init pvh_load_kernel(
>>> }
>>> /* Free temporary buffers. */
>>> - discard_initial_images();
>>> + free_boot_modules();
>>
>> This...
>>
>>> if ( cmdline != NULL )
>>> {
>>
>>> diff --git a/xen/arch/x86/pv/dom0_build.c b/xen/arch/x86/pv/dom0_build.c
>>> index 6be3d7745fab..2580162f3df4 100644
>>> --- a/xen/arch/x86/pv/dom0_build.c
>>> +++ b/xen/arch/x86/pv/dom0_build.c
>>
>>> @@ -875,7 +874,7 @@ static int __init dom0_construct(struct boot_info
>>> *bi, struct domain *d)
>>> }
>>> /* Free temporary buffers. */
>>> - discard_initial_images();
>>> + free_boot_modules();
>>
>> ...and this. I think Andrew requested/suggested moving to a single
>> free_boot_modules call:
>> They're both right at the end of construction, so it would
>> make far more sense for __start_xen() to do this after
>> create_dom0(). That also avoids needing to export the function.
>
> I wanted to do this and had it written this way. Then I started testing
> it and the pvhshim test failed due to not enough ram to build the domU
> inside pvshim. I started splitting this commit to see where it broke the
> test case, and for an unknown reason, replacing these two calls with a
> single call in __start_xen() just after create_dom0() is the cause.
> Instead of trying to tear apart the construction logic to determine why,
> I backed this part of the change out for the time being.
Ah, ok. Thanks for the info.
>>> /* Set up start info area. */
>>> si = (start_info_t *)vstartinfo_start;
>>> diff --git a/xen/arch/x86/setup.c b/xen/arch/x86/setup.c
>>> index 495e90a7e132..0bda1326a485 100644
>>> --- a/xen/arch/x86/setup.c
>>> +++ b/xen/arch/x86/setup.c
>>
>>> +void __init free_boot_modules(void)
>>> {
>>> struct boot_info *bi = &xen_boot_info;
>>> unsigned int i;
>>> for ( i = 0; i < bi->nr_modules; ++i )
>>> {
>>> - uint64_t start = pfn_to_paddr(bi->mods[i].mod->mod_start);
>>> - uint64_t size = bi->mods[i].mod->mod_end;
>>> -
>>> - /*
>>> - * Sometimes the initrd is mapped, rather than copied, into
>>> dom0.
>>> - * Size being 0 is how we're instructed to leave the module
>>> alone.
>>> - */
>>> - if ( size == 0 )
>>> + if ( bi->mods[i].released )
>>> continue;
>>> - init_domheap_pages(start, start + PAGE_ALIGN(size));
>>> + release_boot_module(&bi->mods[i]);
>>> }
>>> -
>>> - bi->nr_modules = 0;
>>
>> IIUC, zero-ing here was a safety feature to ensure boot modules could
>> not be used after this point. Should it be retained?
>
> The released flag displaced the need for this, but I realized it would
> make it stronger if in bootstrap_map_bm() we add a check that the
> released flag is not set before mapping. I think this is a stronger
> approach without loosing information like the number of boot modules
> were passed.
Andrew> Clobbering this prevents the loop constructs from working.
I thought the boot modules are unusable after free_boot_modules() is
called, so I'm not clear on the utility of keeping the boot modules
around and/or keeping the loop constructs working. I wondered about,
but didn't write, clearing the boot_module info in release_boot_module()
to eliminate stale data hanging around.
Yes, a bootstrap_map_bm() check is a good idea. Having said that, there
is a lack of checking the return value of bootstrap_map_bm(), so would
you panic?
Regards,
Jason
next prev parent reply other threads:[~2024-11-15 17:30 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-11-15 13:11 [PATCH v9 0/6] Boot modules for Hyperlaunch Daniel P. Smith
2024-11-15 13:11 ` [PATCH v9 1/6] x86/boot: convert domain construction to use boot info Daniel P. Smith
2024-11-15 14:25 ` Andrew Cooper
2024-11-15 14:32 ` Daniel P. Smith
2024-11-15 16:33 ` Jason Andryuk
2024-11-15 17:01 ` Andrew Cooper
2024-11-15 17:02 ` Jason Andryuk
2024-11-15 13:12 ` [PATCH v9 2/6] x86/boot: introduce module release Daniel P. Smith
2024-11-15 16:50 ` Jason Andryuk
2024-11-15 17:09 ` Andrew Cooper
2024-11-15 17:16 ` Daniel P. Smith
2024-11-15 17:18 ` Jason Andryuk [this message]
2024-11-18 16:13 ` Andrew Cooper
2024-11-15 13:12 ` [PATCH v9 3/6] x86/boot: add start and size fields to struct boot_module Daniel P. Smith
2024-11-15 17:31 ` Jason Andryuk
2024-11-15 13:12 ` [PATCH v9 4/6] x86/boot: introduce boot domain Daniel P. Smith
2024-11-27 10:22 ` Jan Beulich
2024-12-04 16:24 ` Daniel P. Smith
2024-11-15 13:12 ` [PATCH v9 5/6] x86/boot: introduce domid field to struct boot_domain Daniel P. Smith
2024-11-15 15:31 ` Daniel P. Smith
2024-11-27 10:32 ` Jan Beulich
2024-12-04 16:45 ` Daniel P. Smith
2024-12-09 8:55 ` Jan Beulich
2024-12-11 0:57 ` Daniel P. Smith
2024-11-15 13:12 ` [PATCH v9 6/6] x86/boot: add cmdline " Daniel P. Smith
2024-11-15 15:12 ` Daniel P. Smith
2024-11-15 16:34 ` Daniel P. Smith
2024-11-15 18:20 ` Jason Andryuk
2024-11-20 17:57 ` Daniel P. Smith
2024-11-20 22:32 ` Jason Andryuk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f3aee76b-7ac1-4558-a036-c2c19c5b9154@amd.com \
--to=jason.andryuk@amd.com \
--cc=andrew.cooper3@citrix.com \
--cc=christopher.w.clark@gmail.com \
--cc=dpsmith@apertussolutions.com \
--cc=jbeulich@suse.com \
--cc=roger.pau@citrix.com \
--cc=stefano.stabellini@amd.com \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.