All of lore.kernel.org
 help / color / mirror / Atom feed
From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Ackerley Tng <ackerleytng@google.com>,
	Fuad Tabba <tabba@google.com>,
	kvm@vger.kernel.org, linux-arm-msm@vger.kernel.org,
	linux-mm@kvack.org, kvmarm@lists.linux.dev
Cc: pbonzini@redhat.com, chenhuacai@kernel.org, mpe@ellerman.id.au,
	anup@brainfault.org, paul.walmsley@sifive.com,
	palmer@dabbelt.com, aou@eecs.berkeley.edu, seanjc@google.com,
	viro@zeniv.linux.org.uk, brauner@kernel.org, willy@infradead.org,
	akpm@linux-foundation.org, yilun.xu@intel.com,
	chao.p.peng@linux.intel.com, jarkko@kernel.org,
	amoorthy@google.com, dmatlack@google.com,
	isaku.yamahata@intel.com, mic@digikod.net, vbabka@suse.cz,
	vannapurve@google.com, mail@maciej.szmigiero.name,
	david@redhat.com, michael.roth@amd.com, wei.w.wang@intel.com,
	liam.merwick@oracle.com, isaku.yamahata@gmail.com,
	kirill.shutemov@linux.intel.com, suzuki.poulose@arm.com,
	steven.price@arm.com, quic_eberman@quicinc.com,
	quic_mnalajal@quicinc.com, quic_tsoni@quicinc.com,
	quic_svaddagi@quicinc.com, quic_cvanscha@quicinc.com,
	quic_pderrin@quicinc.com, quic_pheragu@quicinc.com,
	catalin.marinas@arm.com, james.morse@arm.com,
	yuzenghui@huawei.com, oliver.upton@linux.dev, maz@kernel.org,
	will@kernel.org, qperret@google.com, keirf@google.com,
	roypat@amazon.co.uk, shuah@kernel.org, hch@infradead.org,
	jgg@nvidia.com, rientjes@google.com, jhubbard@nvidia.com,
	fvdl@google.com, hughd@google.com, jthoughton@google.com,
	peterx@redhat.com, pankaj.gupta@amd.com, ira.weiny@intel.com
Subject: Re: [PATCH v14 04/21] KVM: x86: Introduce kvm->arch.supports_gmem
Date: Thu, 17 Jul 2025 09:48:10 +0800	[thread overview]
Message-ID: <fef1d856-8c13-4d97-ba8b-f443edb9beac@intel.com> (raw)
In-Reply-To: <diqzwm87fzfc.fsf@ackerleytng-ctop.c.googlers.com>

On 7/17/2025 8:12 AM, Ackerley Tng wrote:
> Xiaoyao Li <xiaoyao.li@intel.com> writes:
> 
>> On 7/15/2025 5:33 PM, Fuad Tabba wrote:
>>> Introduce a new boolean member, supports_gmem, to kvm->arch.
>>>
>>> Previously, the has_private_mem boolean within kvm->arch was implicitly
>>> used to indicate whether guest_memfd was supported for a KVM instance.
>>> However, with the broader support for guest_memfd, it's not exclusively
>>> for private or confidential memory. Therefore, it's necessary to
>>> distinguish between a VM's general guest_memfd capabilities and its
>>> support for private memory.
>>>
>>> This new supports_gmem member will now explicitly indicate guest_memfd
>>> support for a given VM, allowing has_private_mem to represent only
>>> support for private memory.
>>>
>>> Reviewed-by: Ira Weiny <ira.weiny@intel.com>
>>> Reviewed-by: Gavin Shan <gshan@redhat.com>
>>> Reviewed-by: Shivank Garg <shivankg@amd.com>
>>> Reviewed-by: Vlastimil Babka <vbabka@suse.cz>
>>> Co-developed-by: David Hildenbrand <david@redhat.com>
>>> Signed-off-by: David Hildenbrand <david@redhat.com>
>>> Signed-off-by: Fuad Tabba <tabba@google.com>
>>
>> Reviewed-by: Xiaoyao Li <xiaoyao.li@intel.com>
>>
>> Btw, it seems that supports_gmem can be enabled for all the types of VM?
>>
> 
> For now, not really, because supports_gmem allows mmap support, and mmap
> support enables KVM_MEMSLOT_GMEM_ONLY, and KVM_MEMSLOT_GMEM_ONLY will
> mean that shared faults also get faulted from guest_memfd.

No, mmap support is checked by kvm_arch_supports_gmem_mmap() which is 
independent to whether gmem is supported.

> A TDX VM that wants to use guest_memfd for private memory and some other
> backing memory for shared memory (let's call this use case "legacy CoCo
> VMs") will not work if supports_gmem is just enabled for all types of
> VMs, because then shared faults will also go to kvm_gmem_get_pfn().

This is not what this patch does. Please go back read this patch.

This patch sets kvm->arch.supports_gmem to true for 
KVM_X86_SNP_VM/tdx/KVM_X86_SW_PROTECTED_VM.

Further in patch 14, it sets kvm->arch.supports_gmem for KVM_X86_DEFAULT_VM.

After this series, supports_gmem remains false only for KVM_X86_SEV_VM 
and KVM_X86_SEV_ES_VM. And I don't see why cannot enable supports_gmem 
for them.

> This will be cleaned up when guest_memfd supports conversion
> (guest_memfd stage 2). There, a TDX VM will have .supports_gmem = true.
> 
> With guest_memfd stage-2 there will also be a
> KVM_CAP_DISABLE_LEGACY_PRIVATE_TRACKING.
> KVM_CAP_DISABLE_LEGACY_PRIVATE_TRACKING defaults to false, so for legacy
> CoCo VMs, shared faults will go to the other non-guest_memfd memory
> source that is configured in userspace_addr as before.
> 
> With guest_memfd stage-2, KVM_MEMSLOT_GMEM_ONLY will direct all EPT
> faults to kvm_gmem_get_pfn(), but KVM_MEMSLOT_GMEM_ONLY will only be
> allowed if KVM_CAP_DISABLE_LEGACY_PRIVATE_TRACKING is true. TDX VMs
> wishing to use guest_memfd as the only source of memory for the guest
> should set KVM_CAP_DISABLE_LEGACY_PRIVATE_TRACKING to true before
> creating the guest_memfd.
> 
>> Even without mmap support, allow all the types of VM to create
>> guest_memfd seems not something wrong. It's just that the guest_memfd
>> allocated might not be used, e.g., for KVM_X86_DEFAULT_VM.
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> 
> p


  reply	other threads:[~2025-07-17  1:48 UTC|newest]

Thread overview: 59+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-07-15  9:33 [PATCH v14 00/21] KVM: Enable host userspace mapping for guest_memfd-backed memory for non-CoCo VMs Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 01/21] KVM: Rename CONFIG_KVM_PRIVATE_MEM to CONFIG_KVM_GMEM Fuad Tabba
2025-07-16  3:43   ` Xiaoyao Li
2025-07-15  9:33 ` [PATCH v14 02/21] KVM: Rename CONFIG_KVM_GENERIC_PRIVATE_MEM to CONFIG_KVM_GENERIC_GMEM_POPULATE Fuad Tabba
2025-07-16  4:08   ` Xiaoyao Li
2025-07-16  8:11     ` Fuad Tabba
2025-07-16  8:31       ` Xiaoyao Li
2025-07-16 10:25         ` David Hildenbrand
2025-07-16 11:02           ` Xiaoyao Li
2025-07-16 11:05             ` Fuad Tabba
2025-07-16 11:15               ` David Hildenbrand
2025-07-16 12:01                 ` Xiaoyao Li
2025-07-16 12:13                   ` Fuad Tabba
2025-07-16 12:14                   ` David Hildenbrand
2025-07-16 12:24                     ` Fuad Tabba
2025-07-16 12:39                       ` Xiaoyao Li
2025-07-16 12:54                         ` Fuad Tabba
2025-07-16 12:59                           ` David Hildenbrand
2025-07-15  9:33 ` [PATCH v14 03/21] KVM: Introduce kvm_arch_supports_gmem() Fuad Tabba
2025-07-16  5:07   ` Xiaoyao Li
2025-07-15  9:33 ` [PATCH v14 04/21] KVM: x86: Introduce kvm->arch.supports_gmem Fuad Tabba
2025-07-16  5:18   ` Xiaoyao Li
2025-07-17  0:12     ` Ackerley Tng
2025-07-17  1:48       ` Xiaoyao Li [this message]
2025-07-17  8:49         ` Fuad Tabba
2025-07-17  9:00           ` Xiaoyao Li
2025-07-17 16:50         ` Ackerley Tng
2025-07-17 16:59           ` Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 05/21] KVM: Rename kvm_slot_can_be_private() to kvm_slot_has_gmem() Fuad Tabba
2025-07-16  5:19   ` Xiaoyao Li
2025-07-15  9:33 ` [PATCH v14 06/21] KVM: Fix comments that refer to slots_lock Fuad Tabba
2025-07-16  5:20   ` Xiaoyao Li
2025-07-15  9:33 ` [PATCH v14 07/21] KVM: Fix comment that refers to kvm uapi header path Fuad Tabba
2025-07-16  5:24   ` Xiaoyao Li
2025-07-15  9:33 ` [PATCH v14 08/21] KVM: guest_memfd: Allow host to map guest_memfd pages Fuad Tabba
2025-07-16  5:40   ` Xiaoyao Li
2025-07-16  8:15     ` Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 09/21] KVM: guest_memfd: Track guest_memfd mmap support in memslot Fuad Tabba
2025-07-16  6:10   ` Xiaoyao Li
2025-07-16  8:21     ` Fuad Tabba
2025-07-16  8:52       ` Xiaoyao Li
2025-07-16 10:31       ` David Hildenbrand
2025-07-16 10:59         ` Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 10/21] KVM: x86/mmu: Generalize private_max_mapping_level x86 op to max_mapping_level Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 11/21] KVM: x86/mmu: Allow NULL-able fault in kvm_max_private_mapping_level Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 12/21] KVM: x86/mmu: Consult guest_memfd when computing max_mapping_level Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 13/21] KVM: x86/mmu: Handle guest page faults for guest_memfd with shared memory Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 14/21] KVM: x86: Enable guest_memfd mmap for default VM type Fuad Tabba
2025-07-16 10:32   ` David Hildenbrand
2025-07-15  9:33 ` [PATCH v14 15/21] KVM: arm64: Refactor user_mem_abort() Fuad Tabba
2025-07-16 10:36   ` David Hildenbrand
2025-07-16 11:26     ` Fuad Tabba
2025-07-16 15:08       ` Marc Zyngier
2025-07-15  9:33 ` [PATCH v14 16/21] KVM: arm64: Handle guest_memfd-backed guest page faults Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 17/21] KVM: arm64: nv: Handle VNCR_EL2-triggered faults backed by guest_memfd Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 18/21] KVM: arm64: Enable host mapping of shared guest_memfd memory Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 19/21] KVM: Introduce the KVM capability KVM_CAP_GMEM_MMAP Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 20/21] KVM: selftests: Do not use hardcoded page sizes in guest_memfd test Fuad Tabba
2025-07-15  9:33 ` [PATCH v14 21/21] KVM: selftests: guest_memfd mmap() test when mmap is supported Fuad Tabba

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=fef1d856-8c13-4d97-ba8b-f443edb9beac@intel.com \
    --to=xiaoyao.li@intel.com \
    --cc=ackerleytng@google.com \
    --cc=akpm@linux-foundation.org \
    --cc=amoorthy@google.com \
    --cc=anup@brainfault.org \
    --cc=aou@eecs.berkeley.edu \
    --cc=brauner@kernel.org \
    --cc=catalin.marinas@arm.com \
    --cc=chao.p.peng@linux.intel.com \
    --cc=chenhuacai@kernel.org \
    --cc=david@redhat.com \
    --cc=dmatlack@google.com \
    --cc=fvdl@google.com \
    --cc=hch@infradead.org \
    --cc=hughd@google.com \
    --cc=ira.weiny@intel.com \
    --cc=isaku.yamahata@gmail.com \
    --cc=isaku.yamahata@intel.com \
    --cc=james.morse@arm.com \
    --cc=jarkko@kernel.org \
    --cc=jgg@nvidia.com \
    --cc=jhubbard@nvidia.com \
    --cc=jthoughton@google.com \
    --cc=keirf@google.com \
    --cc=kirill.shutemov@linux.intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=kvmarm@lists.linux.dev \
    --cc=liam.merwick@oracle.com \
    --cc=linux-arm-msm@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=mail@maciej.szmigiero.name \
    --cc=maz@kernel.org \
    --cc=mic@digikod.net \
    --cc=michael.roth@amd.com \
    --cc=mpe@ellerman.id.au \
    --cc=oliver.upton@linux.dev \
    --cc=palmer@dabbelt.com \
    --cc=pankaj.gupta@amd.com \
    --cc=paul.walmsley@sifive.com \
    --cc=pbonzini@redhat.com \
    --cc=peterx@redhat.com \
    --cc=qperret@google.com \
    --cc=quic_cvanscha@quicinc.com \
    --cc=quic_eberman@quicinc.com \
    --cc=quic_mnalajal@quicinc.com \
    --cc=quic_pderrin@quicinc.com \
    --cc=quic_pheragu@quicinc.com \
    --cc=quic_svaddagi@quicinc.com \
    --cc=quic_tsoni@quicinc.com \
    --cc=rientjes@google.com \
    --cc=roypat@amazon.co.uk \
    --cc=seanjc@google.com \
    --cc=shuah@kernel.org \
    --cc=steven.price@arm.com \
    --cc=suzuki.poulose@arm.com \
    --cc=tabba@google.com \
    --cc=vannapurve@google.com \
    --cc=vbabka@suse.cz \
    --cc=viro@zeniv.linux.org.uk \
    --cc=wei.w.wang@intel.com \
    --cc=will@kernel.org \
    --cc=willy@infradead.org \
    --cc=yilun.xu@intel.com \
    --cc=yuzenghui@huawei.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.