Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rick Edgecombe" <rick.p.edgecombe@intel.com>
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v9 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory
Date: Thu, 06 Aug 2026 02:21:57 +0000	[thread overview]
Message-ID: <20260806022158.586A11F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260806020850.1221381-5-rick.p.edgecombe@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] vzalloc() lacks __GFP_RETRY_MAYFAIL, causing it to invoke the OOM killer and panic the kernel during boot on systems with sparse memory layouts.
--

--- Patch [4]: [PATCH v9 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory ---
commit b63d4342b3d95af2bbe50ca5c66ac1ecbf04dedc
Author: Kiryl Shutsemau <kas@kernel.org>

x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory

This commit allocates reference counters for every 2MB memory range to track
TDX memory usage. The allocation size is based on max_pfn and can be very 
large on platforms with sparse memory layouts. If allocation fails, it is
intended to return -ENOMEM and fail TDX initialization.

> diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> index 4d3427b8a5b71..b0ebd74a69fe2 100644
> --- a/arch/x86/virt/vmx/tdx/tdx.c
> +++ b/arch/x86/virt/vmx/tdx/tdx.c
[ ... ]
> @@ -252,6 +261,42 @@ static struct syscore tdx_syscore = {
>  	.ops = &tdx_syscore_ops,
>  };
>  
> +/*
> + * Allocate PAMT reference counters for all physical memory.
> + *
> + * It consumes 2MB for every 1TB of physical memory.
> + */
> +static __init int init_pamt_refcounts(void)
> +{
> +	size_t size = DIV_ROUND_UP(max_pfn, PTRS_PER_PTE) * sizeof(*pamt_refcounts);
> +
> +	if (!tdx_supports_dynamic_pamt(&tdx_sysinfo))
> +		return 0;
> +
> +	pamt_refcounts = vzalloc(size);
> +	if (!pamt_refcounts)
> +		return -ENOMEM;

[Severity: High]
Could this vzalloc() call trigger a kernel panic on systems with sparse
memory layouts instead of gracefully disabling TDX?

The allocation size based on max_pfn can be extremely large (up to 8GB).
Because vzalloc() does not include __GFP_RETRY_MAYFAIL, an allocation
failure will invoke the page allocator slow path and the OOM killer. Since
this runs during early boot before any killable user processes exist, the
OOM killer will unconditionally call panic() instead of returning NULL.

Would it be safer to use __vmalloc() with GFP_KERNEL | __GFP_ZERO |
__GFP_RETRY_MAYFAIL | __GFP_NOWARN to ensure the allocator returns NULL
when memory is exhausted?

> +
> +	return 0;
> +}

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260806020850.1221381-1-rick.p.edgecombe@intel.com?part=4

  reply	other threads:[~2026-08-06  2:21 UTC|newest]

Thread overview: 29+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06  2:08 [PATCH v9 00/11] Dynamic PAMT Rick Edgecombe
2026-08-06  2:08 ` [PATCH v9 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-08-06 20:58   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-08-06 20:58   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 03/11] x86/virt/tdx: Add tdx_alloc/free_control_page() helpers Rick Edgecombe
2026-08-06 17:17   ` Dave Hansen
2026-08-06 17:20     ` Dave Hansen
2026-08-06 22:22     ` Edgecombe, Rick P
2026-08-06 22:42       ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-08-06  2:21   ` sashiko-bot [this message]
2026-08-06 22:02     ` Edgecombe, Rick P
2026-08-06 22:09       ` Dave Hansen
2026-08-06 20:56   ` Dave Hansen
2026-08-06 21:56     ` Edgecombe, Rick P
2026-08-06  2:08 ` [PATCH v9 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
2026-08-06 22:17   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-08-06 22:19   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 07/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-08-06 22:19   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
2026-08-06  7:16   ` sashiko-bot
2026-08-06 21:54     ` Edgecombe, Rick P
2026-08-06 23:48   ` Dave Hansen
2026-08-06  2:08 ` [PATCH v9 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2026-08-06  2:08 ` [PATCH v9 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-08-06  2:08 ` [PATCH v9 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260806022158.586A11F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=kvm@vger.kernel.org \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox