From: Michael Roth <michael.roth@amd.com>
To: <qemu-devel@nongnu.org>
Cc: <kvm@vger.kernel.org>, <pbonzini@redhat.com>,
<berrange@redhat.com>, <armbru@redhat.com>,
<pankaj.gupta@amd.com>, <xiaoyao.li@intel.com>,
<chao.p.peng@linux.intel.com>, <david@kernel.org>,
<ashish.kalra@amd.com>, <ackerleytng@google.com>,
<lpieralisi@kernel.org>
Subject: [PATCH v3 18/19] i386/sev: Add sev-snp-guest parameter to enable in-place conversion
Date: Wed, 7 Oct 2026 08:41:42 -0500 [thread overview]
Message-ID: <20261007134323.1606088-19-michael.roth@amd.com> (raw)
In-Reply-To: <20261007134323.1606088-1-michael.roth@amd.com>
The sev-snp-guest object is currently used to provide confidential guest
by using guest_memfd for private GPA ranges, and for shared GPA ranges
the normal memory backend is used, i.e. "out-of-place" conversion
between shared/private.
Now that "in-place" conversion support is available in QEMU, add a
parameter to select between these 2 modes of utilizing guest_memfd (it
cannot be enabled transparently due to noticeable differences in
behavior (e.g. memory usage accounting and lack of hugetlb support for
shared GPA ranges) that userspace needs to be aware of when selecting
the mode).
Note that the actual capability checks for in-place conversion support
in the host kernel will happen later in kvm_arch_init().
Signed-off-by: Michael Roth <michael.roth@amd.com>
---
qapi/qom.json | 8 +++++++-
target/i386/sev.c | 17 +++++++++++++++++
2 files changed, 24 insertions(+), 1 deletion(-)
diff --git a/qapi/qom.json b/qapi/qom.json
index 49f222796a..84166c2457 100644
--- a/qapi/qom.json
+++ b/qapi/qom.json
@@ -1099,6 +1099,11 @@
# @tsc-frequency: set secure TSC frequency. Only valid if Secure TSC
# is enabled (default: zero) (since 11.1)
#
+# @convert-in-place: If true, the same physical pages are reused
+# when memory is converted between shared and private states.
+# If false (default), separate allocations are used depending
+# on whether the page is private or shared. (since 11.2)
+#
# Since: 9.1
##
{ 'struct': 'SevSnpGuestProperties',
@@ -1112,7 +1117,8 @@
'*host-data': 'str',
'*vcek-disabled': 'bool',
'*secure-tsc': 'bool',
- '*tsc-frequency': 'uint32' } }
+ '*tsc-frequency': 'uint32',
+ '*convert-in-place': 'bool'} }
##
# @TdxGuestProperties:
diff --git a/target/i386/sev.c b/target/i386/sev.c
index e15e23c78d..e77ca12fc7 100644
--- a/target/i386/sev.c
+++ b/target/i386/sev.c
@@ -3270,6 +3270,20 @@ sev_snp_guest_set_tsc_frequency(Object *obj, Visitor *v, const char *name,
SEV_SNP_GUEST(obj)->tsc_khz = value / 1000;
}
+static bool
+sev_snp_guest_get_convert_in_place(Object *obj, Error **errp)
+{
+ return CONFIDENTIAL_GUEST_SUPPORT(obj)->convert_in_place;
+}
+
+static void
+sev_snp_guest_set_convert_in_place(Object *obj, bool value, Error **errp)
+{
+ ConfidentialGuestSupport *cgs = CONFIDENTIAL_GUEST_SUPPORT(obj);
+
+ cgs->convert_in_place = value;
+}
+
static void
sev_snp_guest_class_init(ObjectClass *oc, const void *data)
{
@@ -3311,6 +3325,9 @@ sev_snp_guest_class_init(ObjectClass *oc, const void *data)
object_class_property_add(oc, "tsc-frequency", "uint32",
sev_snp_guest_get_tsc_frequency,
sev_snp_guest_set_tsc_frequency, NULL, NULL);
+ object_class_property_add_bool(oc, "convert-in-place",
+ sev_snp_guest_get_convert_in_place,
+ sev_snp_guest_set_convert_in_place);
}
static void
--
2.43.0
next prev parent reply other threads:[~2026-10-07 13:47 UTC|newest]
Thread overview: 22+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 13:41 [PATCH v3 00/19] guest_memfd: support in-place memory conversion Michael Roth
2026-10-07 13:41 ` [PATCH v3 01/19] accel/kvm: Add helper for handling conversions of MMIO holes Michael Roth
2026-10-07 13:41 ` [PATCH v3 02/19] accel/kvm: Fix kvm_convert_memory() calls crossing memory regions Michael Roth
2026-10-07 13:41 ` [PATCH v3 03/19] accel/kvm: Fix handling of MMIO holes at start of conversion ranges Michael Roth
2026-10-07 13:41 ` [PATCH v3 04/19] accel/kvm: Fix handling of conversion ranges with multiple MMIO holes Michael Roth
2026-10-07 13:41 ` [PATCH v3 05/19] accel/kvm: Use dedicated helper for creating private-only gmem instances Michael Roth
2026-10-07 13:41 ` [PATCH v3 06/19] [NOT-FOR-MERGE] linux-headers: Update headers for v13 of in-place conversion kernel support Michael Roth
2026-10-07 13:41 ` [PATCH v3 07/19] accel/kvm: Add CGS flag to control in-place conversion support Michael Roth
2026-10-07 13:41 ` [PATCH v3 08/19] system/memory: Re-use memory-backend-guest-memfd inode for private memory Michael Roth
2026-10-07 13:41 ` [PATCH v3 09/19] accel/kvm: Handle guest_memfd flags internally when creating instances Michael Roth
2026-10-07 13:41 ` [PATCH v3 10/19] system/memory: Default to guest_memfd for RAM for in-place conversion Michael Roth
2026-10-07 13:41 ` [PATCH v3 11/19] accel/kvm: Move post-conversion updates to a separate helper Michael Roth
2026-10-07 13:41 ` [PATCH v3 12/19] accel/kvm: Re-order attribute notifications for in-place conversion Michael Roth
2026-10-07 13:41 ` [PATCH v3 13/19] accel/kvm: Support shared/private conversions via guest_memfd ioctls Michael Roth
2026-10-07 13:41 ` [PATCH v3 14/19] accel/kvm: Don't default to private attributes for in-place conversion Michael Roth
2026-10-07 13:41 ` [PATCH v3 15/19] i386/sev: Update SNP_LAUNCH_UPDATE " Michael Roth
2026-10-07 13:41 ` [PATCH v3 16/19] i386/sev: Update CPUID failure handling " Michael Roth
2026-10-07 13:41 ` [PATCH v3 17/19] accel/kvm: Disable discard " Michael Roth
2026-10-07 13:41 ` Michael Roth [this message]
2026-10-08 6:11 ` [PATCH v3 18/19] i386/sev: Add sev-snp-guest parameter to enable " Markus Armbruster
2026-10-07 13:41 ` [PATCH v3 19/19] hostmem: Automatically select set guest-memfd=on for " Michael Roth
2026-10-08 6:14 ` Markus Armbruster
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261007134323.1606088-19-michael.roth@amd.com \
--to=michael.roth@amd.com \
--cc=ackerleytng@google.com \
--cc=armbru@redhat.com \
--cc=ashish.kalra@amd.com \
--cc=berrange@redhat.com \
--cc=chao.p.peng@linux.intel.com \
--cc=david@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=lpieralisi@kernel.org \
--cc=pankaj.gupta@amd.com \
--cc=pbonzini@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=xiaoyao.li@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox