From: Avi Kivity <avi@qumranet.com>
To: Marcelo Tosatti <mtosatti@redhat.com>
Cc: kvm-devel@lists.sourceforge.net
Subject: Re: [patch 4/5] KVM: ignore zapped root pagetables
Date: Sun, 17 Feb 2008 10:52:58 +0200 [thread overview]
Message-ID: <47B7F5EA.9010208@qumranet.com> (raw)
In-Reply-To: <20080216221221.002948712@redhat.com>>
Marcelo Tosatti wrote:
> Mark zapped root pagetables as invalid and ignore such pages during lookup.
>
> This is a problem with the cr3-target feature, where a zapped root table fools
> the faulting code into creating a read-only mapping. The result is a lockup
> if the instruction can't be emulated.
>
> @@ -796,8 +797,10 @@ static void kvm_mmu_zap_page(struct kvm
> if (!sp->root_count) {
> hlist_del(&sp->hash_link);
> kvm_mmu_free_page(kvm, sp);
> - } else
> + } else {
> list_move(&sp->link, &kvm->arch.active_mmu_pages);
> + sp->role.invalid = 1;
> + }
> kvm_mmu_reset_last_pte_updated(kvm)
There's an smp issue here. You're marking a shadow page as invalid, but
it may be currently in use by another vcpu. So the shadow page and the
guest page may be out of sync.
A fix is to send an IPI to all vcpus in such a situation, and request
them to unload the mmu.
Also, we can't rely on memory pressure to flush out the invalid shadow
pages, because for many workloads the shadow cache is large enough (the
"mmu_recycled" counter never increments). So a check for (root_count ==
0 && role.invalid) when decrementing root_count can help to zap those pages.
--
Any sufficiently difficult bug is indistinguishable from a feature.
-------------------------------------------------------------------------
This SF.net email is sponsored by: Microsoft
Defy all challenges. Microsoft(R) Visual Studio 2008.
http://clk.atdmt.com/MRT/go/vse0120000070mrt/direct/01/
next prev parent reply other threads:[~2008-02-17 8:52 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <20080216220924.733723618@redhat.com>
2008-02-16 22:09 ` [patch 1/5] KVM: add basic paravirt support Marcelo Tosatti
2008-02-16 22:09 ` [patch 2/5] KVM: hypercall based pte updates and TLB flushes Marcelo Tosatti
2008-02-16 22:09 ` [patch 3/5] KVM: hypercall batching Marcelo Tosatti
2008-02-16 22:09 ` [patch 4/5] KVM: ignore zapped root pagetables Marcelo Tosatti
2008-02-16 22:09 ` [patch 5/5] KVM: VMX cr3 cache support Marcelo Tosatti
2008-02-16 23:37 ` [patch 0/5] KVM paravirt MMU updates and cr3 caching Anthony Liguori
2008-02-17 2:24 ` Marcelo Tosatti
[not found] ` <20080216221220.843135254@redhat.com>
2008-02-17 8:28 ` [patch 2/5] KVM: hypercall based pte updates and TLB flushes Avi Kivity
2008-02-17 13:13 ` Avi Kivity
2008-02-17 14:51 ` Marcelo Tosatti
2008-02-17 14:57 ` Avi Kivity
2008-02-18 5:00 ` Marcelo Tosatti
2008-02-17 8:32 ` Avi Kivity
[not found] ` <20080216221221.002948712@redhat.com>
2008-02-17 8:52 ` Avi Kivity [this message]
[not found] ` <20080216221220.924823582@redhat.com>
2008-02-17 8:40 ` [patch 3/5] KVM: hypercall batching Avi Kivity
2008-02-18 16:47 ` Marcelo Tosatti
2008-02-17 18:40 ` Hollis Blanchard
2008-02-18 8:06 ` Avi Kivity
2008-02-18 8:43 ` Christian Borntraeger
2008-02-18 8:47 ` Avi Kivity
[not found] ` <1203361276.3428.6.camel@basalt>
2008-02-19 8:30 ` Avi Kivity
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=47B7F5EA.9010208@qumranet.com \
--to=avi@qumranet.com \
--cc=kvm-devel@lists.sourceforge.net \
--cc=mtosatti@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox