Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Sriram Nambakam <snambakam@linux.microsoft.com>
To: kvm@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [RFC PATCH v1 13/42] Add a inter-plane communication mechanism through KVM. - model this to use a single page similar to SEV-SNP
Date: Wed,  5 Aug 2026 04:02:55 -0700	[thread overview]
Message-ID: <20260805110324.25067-14-snambakam@linux.microsoft.com> (raw)
In-Reply-To: <20260805110324.25067-1-snambakam@linux.microsoft.com>

---
 security/vbs/kvm_planes.c | 102 +++++++++++++++++++-------------------
 1 file changed, 51 insertions(+), 51 deletions(-)

diff --git a/security/vbs/kvm_planes.c b/security/vbs/kvm_planes.c
index 3526f7c429c3..3eec3abb56ee 100644
--- a/security/vbs/kvm_planes.c
+++ b/security/vbs/kvm_planes.c
@@ -31,26 +31,30 @@
  */
 #define KVM_HC_VBS_VTL_CALL		15
 
-/* ── shared-memory request / response layout ──────────────────────────── */
+/* ── shared-memory calling area (modelled after the SVSM CAA) ─────── */
 
-struct vbs_kvm_request {
-	__u32	call_id;	/* enum vbs_call_id			*/
-	__u32	arg_size;	/* bytes of payload following this hdr	*/
-	__u8	payload[];	/* variable-length argument data		*/
+/*
+ * Single shared page used for both request and response data.
+ * The protocol is synchronous: plane-0 writes the request, issues a
+ * hypercall, blocks until QEMU returns, then reads the response from
+ * the same page.  No concurrent access is possible.
+ *
+ * Layout (within one 4 KiB page):
+ *   [ call_pending | call_id | status | arg_size | resp_size | buffer ]
+ */
+struct vbs_kvm_ca {
+	__u8	call_pending;	/* 1 while call is in flight		*/
+	__u8	rsvd[3];
+	__u32	call_id;	/* enum vbs_call_id (set by caller)	*/
+	__s32	status;		/* return code (set by responder)	*/
+	__u32	arg_size;	/* request payload size			*/
+	__u32	resp_size;	/* response payload size			*/
+	__u8	buffer[];	/* request data in, response data out	*/
 } __packed;
 
-struct vbs_kvm_response {
-	__s32	status;		/* 0 = success, negative errno		*/
-	__u32	resp_size;	/* bytes of payload following this hdr	*/
-	__u8	payload[];	/* variable-length response data		*/
-} __packed;
+#define VBS_CA_BUF_SIZE	(PAGE_SIZE - sizeof(struct vbs_kvm_ca))
 
-/*
- * A single page is used for each direction.  That gives ~4 KiB of
- * payload per call, which is enough for all current VBS operations.
- */
-static void *kvm_req_page;	/* request  (plane-0 writes, plane-1 reads)  */
-static void *kvm_resp_page;	/* response (plane-1 writes, plane-0 reads)  */
+static void *kvm_ca_page;	/* single calling-area page		*/
 
 /* ── low-level VTL call ───────────────────────────────────────────────── */
 
@@ -58,41 +62,44 @@ static int kvm_planes_vtl_call(enum vbs_call_id id,
 			       const void *arg, size_t arg_size,
 			       void *resp, size_t resp_size)
 {
-	struct vbs_kvm_request *req;
-	struct vbs_kvm_response *rsp;
+	struct vbs_kvm_ca *ca;
 	long hc_ret;
 
-	if (!kvm_req_page || !kvm_resp_page)
+	if (!kvm_ca_page)
 		return -ENOMEM;
 
-	if (arg_size > PAGE_SIZE - sizeof(*req))
+	if (arg_size > VBS_CA_BUF_SIZE)
 		return -E2BIG;
 
-	/* Build request in the shared page */
-	req = kvm_req_page;
-	req->call_id  = id;
-	req->arg_size = arg_size;
+	ca = kvm_ca_page;
+
+	/* Build request */
+	ca->call_id  = id;
+	ca->arg_size = arg_size;
+	ca->status   = 0;
+	ca->resp_size = 0;
 	if (arg_size && arg)
-		memcpy(req->payload, arg, arg_size);
+		memcpy(ca->buffer, arg, arg_size);
+	ca->call_pending = 1;
+
+	/* Issue hypercall: pass physical address of the calling area */
+	hc_ret = kvm_hypercall1(KVM_HC_VBS_VTL_CALL,
+				virt_to_phys(kvm_ca_page));
+	ca->call_pending = 0;
 
-	/* Issue hypercall: pass physical addresses of req & resp pages */
-	hc_ret = kvm_hypercall2(KVM_HC_VBS_VTL_CALL,
-				virt_to_phys(kvm_req_page),
-				virt_to_phys(kvm_resp_page));
 	if (hc_ret) {
 		pr_err_ratelimited("vbs-kvm: hypercall failed (%ld)\n", hc_ret);
 		return -EIO;
 	}
 
-	/* Read response */
-	rsp = kvm_resp_page;
-	if (rsp->status)
-		return rsp->status;
+	if (ca->status)
+		return ca->status;
 
-	if (resp && resp_size) {
-		size_t copy = min_t(size_t, resp_size, rsp->resp_size);
+	/* Read response from the same buffer */
+	if (resp && resp_size && ca->resp_size) {
+		size_t copy = min_t(size_t, resp_size, ca->resp_size);
 
-		memcpy(resp, rsp->payload, copy);
+		memcpy(resp, ca->buffer, copy);
 	}
 	return 0;
 }
@@ -192,34 +199,27 @@ static int kvm_planes_init(void)
 {
 	int ret;
 
-	kvm_req_page  = (void *)__get_free_page(GFP_KERNEL | __GFP_ZERO);
-	kvm_resp_page = (void *)__get_free_page(GFP_KERNEL | __GFP_ZERO);
-	if (!kvm_req_page || !kvm_resp_page) {
-		ret = -ENOMEM;
-		goto fail;
-	}
+	kvm_ca_page = (void *)__get_free_page(GFP_KERNEL | __GFP_ZERO);
+	if (!kvm_ca_page)
+		return -ENOMEM;
 
 	ret = kvm_planes_vtl_call(VBS_CALL_INIT, NULL, 0, NULL, 0);
 	if (ret) {
 		pr_err("vbs-kvm: plane-1 INIT call failed (%d)\n", ret);
-		goto fail;
+		free_page((unsigned long)kvm_ca_page);
+		kvm_ca_page = NULL;
+		return ret;
 	}
 
 	pr_info("vbs-kvm: connected to plane-1 secure kernel\n");
 	return 0;
-fail:
-	free_page((unsigned long)kvm_req_page);
-	free_page((unsigned long)kvm_resp_page);
-	kvm_req_page = kvm_resp_page = NULL;
-	return ret;
 }
 
 static void kvm_planes_shutdown(void)
 {
 	kvm_planes_vtl_call(VBS_CALL_SHUTDOWN, NULL, 0, NULL, 0);
-	free_page((unsigned long)kvm_req_page);
-	free_page((unsigned long)kvm_resp_page);
-	kvm_req_page = kvm_resp_page = NULL;
+	free_page((unsigned long)kvm_ca_page);
+	kvm_ca_page = NULL;
 }
 
 /* ── ops table & registration ─────────────────────────────────────────── */
-- 
2.55.0


  parent reply	other threads:[~2026-08-05 11:03 UTC|newest]

Thread overview: 43+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-05 11:02 [RFC PATCH v1 00/42] VBS/VSM-on-KVM: VBS integration for KVM VM planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 01/42] Fix merge issue - Remove duplicate definition for kvm_arch_has_irq_bypass Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 02/42] Fix compilation Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 03/42] Fix compile error Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 04/42] Fix compile errors Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 05/42] Initial support for VM Planes - Add kernel config for CONFIG_VM_PLANES - Parse vm plane config from initrd for plane configuration - Make hypercalls to allocate memory for the vm planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 06/42] Use vcpu count from the plane configuration Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 07/42] skip processing plane configuration for plane 0 - plane 0 is the boot plane Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 08/42] Add plane config param to specify kernel image format Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 09/42] Activate the VM Planes through the Hypervisor - Using KVM as the VMM Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 10/42] allow the command line to be specified for kernels in other planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 11/42] Various changes to support VM Planes Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 12/42] Add a Virtualization Based Security (VBS) framework. - Add backends for AMD SEV-SNP, Intel TDX, Arm CCA and KVM Planes. - Support VTL on Hyper-V in addition to Planes on KVM Sriram Nambakam
2026-08-05 11:02 ` Sriram Nambakam [this message]
2026-08-05 11:02 ` [RFC PATCH v1 14/42] KVM: Add per-plane memory attribute support for cross-plane EPT protection Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 15/42] KVM: x86: Add KVM_HC_VBS_VTL_CALL hypercall for VBS inter-plane calls Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 16/42] vbs: Add HEKI kernel sealing and fix KVM plane memory attribute guards Sriram Nambakam
2026-08-05 11:02 ` [RFC PATCH v1 17/42] vbs: Add module authentication via VBS/HEKI Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 18/42] vbs: Add kexec validation and make module auth non-fatal Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 19/42] Merge branch 'master' into vm-planes Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 20/42] kvm: x86: fix merged plane API/stat build regressions Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 21/42] KVM: x86: exit VM planes and VBS hypercalls to userspace Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 22/42] kexec: block legacy kexec_load when VBS is active Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 23/42] kvm: x86: fix merged plane API/stat build regressions Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 24/42] KVM: planes: expose memory-attribute setting to in-kernel callers Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 25/42] vm_planes: drop unused per-plane vcpu_count Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 26/42] drivers/virt: add VBS secure-plane park loop Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 27/42] KVM: planes: add arch-neutral in-kernel plane switch helper Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 28/42] KVM: x86: add VBS VTL call/return and cross-plane set-mem-attrs hypercalls Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 29/42] init/vm_planes: set up planes from rootfs_initcall and load ELF payloads Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 30/42] security/vbs: run backend probe and HEKI seal at rootfs_initcall Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 31/42] security/vbs: pin the VTL call hypercall to CPU0 Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 32/42] security/vbs: add secure-plane monitor backend Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 33/42] drivers/virt: rename VBS park loop to secure_monitor Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 34/42] x86/realmode: skip the sub-1M trampoline for the VBS secure plane Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 35/42] KVM: x86: deny normal-plane access to secure-plane memory Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 36/42] KVM: plane: handle KVM_CHECK_EXTENSION on the plane fd Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 37/42] KVM: selftests: run plane tests with a split IRQ chip Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 38/42] kvm: x86: drop obsolete kvm_cache_regs.h Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 39/42] kvm: arch: finalize plane hooks and kvm_arch_vcpu_create signature Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 40/42] kvm: x86: use kvm_vcpu scheduling-state accessors and struct stat fields Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 41/42] kvm: x86: finalize per-plane APIC state and CPUID placement Sriram Nambakam
2026-08-05 11:03 ` [RFC PATCH v1 42/42] kvm: planes: reconcile core plane state, UAPI and hypercall exit Sriram Nambakam

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260805110324.25067-14-snambakam@linux.microsoft.com \
    --to=snambakam@linux.microsoft.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox