From: Sean Christopherson <seanjc@google.com>
To: Shivam Kumar <shivam.kumar1@nutanix.com>
Cc: pbonzini@redhat.com, kvm@vger.kernel.org,
Shaju Abraham <shaju.abraham@nutanix.com>,
Manish Mishra <manish.mishra@nutanix.com>,
Anurag Madnawat <anurag.madnawat@nutanix.com>
Subject: Re: [PATCH v3 2/3] KVM: Documentation: Update kvm_run structure for dirty quota
Date: Thu, 31 Mar 2022 15:24:37 +0000 [thread overview]
Message-ID: <YkXHtc2MiwUxpMFU@google.com> (raw)
In-Reply-To: <ae21aee2-41e1-3ad3-41ef-edda67a8449a@nutanix.com>
On Thu, Mar 31, 2022, Shivam Kumar wrote:
>
> On 31/03/22 6:10 am, Sean Christopherson wrote:
> > On Sun, Mar 06, 2022, Shivam Kumar wrote:
> > > Update the kvm_run structure with a brief description of dirty
> > > quota members and how dirty quota throttling works.
> > This should be squashed with patch 1. I actually had to look ahead to this patch
> > because I forgot the details since I last reviewed this :-)
> Ack. Thanks.
> > > + __u64 dirty_quota;
> > > +Please note that this quota cannot be strictly enforced if PML is enabled, and
> > > +the VCPU may end up dirtying pages more than its quota. The difference however
> > > +is bounded by the PML buffer size.
> > If you want to be pedantic, I doubt KVM can strictly enforce the quota even if PML
> > is disabled. E.g. I can all but guarantee that it's possible to dirty multiple
> > pages during a single exit. Probably also worth spelling out PML and genericizing
> > things. Maybe
> >
> > Please note that enforcing the quota is best effort, as the guest may dirty
> > multiple pages before KVM can recheck the quota. However, unless KVM is using
> > a hardware-based dirty ring buffer, e.g. Intel's Page Modification Logging,
> > KVM will detect quota exhaustion within a handful of dirtied page. If a
> > hardware ring buffer is used, the overrun is bounded by the size of the buffer
> > (512 entries for PML).
> Thank you for the blurb. Looks good to me, though I'm curious about the exits
> that can dirty multiple pages.
Anything that touches multiple pages. nested_mark_vmcs12_pages_dirty() is an
easy example. Emulating L2 with nested TDP. An emulated instruction that splits
a page. I'm pretty sure FNAME(sync_page) could dirty an entire page worth of
SPTEs, and that's waaay too deep to bail from.
Oof, loking at sync_page(), that's a bug in patch 1. make_spte() guards the call
to mark_page_dirty_in_slot() with kvm_slot_dirty_track_enabled(), which means it
won't honor the dirty quota unless dirty logging is enabled. Probably not an issue
for the intended use case, but it'll result in wrong stats, and technically the
dirty quota can be enabled without dirty logging being enabled.
diff --git a/arch/x86/kvm/mmu/spte.c b/arch/x86/kvm/mmu/spte.c
index 4739b53c9734..df0349be388b 100644
--- a/arch/x86/kvm/mmu/spte.c
+++ b/arch/x86/kvm/mmu/spte.c
@@ -182,7 +182,7 @@ bool make_spte(struct kvm_vcpu *vcpu, struct kvm_mmu_page *sp,
"spte = 0x%llx, level = %d, rsvd bits = 0x%llx", spte, level,
get_rsvd_bits(&vcpu->arch.mmu->shadow_zero_check, spte, level));
- if ((spte & PT_WRITABLE_MASK) && kvm_slot_dirty_track_enabled(slot)) {
+ if (spte & PT_WRITABLE_MASK) {
/* Enforced by kvm_mmu_hugepage_adjust. */
WARN_ON(level > PG_LEVEL_4K);
mark_page_dirty_in_slot(vcpu->kvm, slot, gfn);
And thinking more about silly edge cases, VMX's big emulation loop for invalid
guest state when unrestricted guest is disabled should probably explicitly check
the dirty quota. Again, I doubt it matters to anyone's use case, but it is treated
as a full run loop for things like pending signals, it'd be good to be consistent.
diff --git a/arch/x86/kvm/vmx/vmx.c b/arch/x86/kvm/vmx/vmx.c
index 84a7500cd80c..5e1ae373634c 100644
--- a/arch/x86/kvm/vmx/vmx.c
+++ b/arch/x86/kvm/vmx/vmx.c
@@ -5511,6 +5511,9 @@ static int handle_invalid_guest_state(struct kvm_vcpu *vcpu)
*/
if (__xfer_to_guest_mode_work_pending())
return 1;
+
+ if (!kvm_vcpu_check_dirty_quota(vcpu))
+ return 0;
}
return 1;
next prev parent reply other threads:[~2022-03-31 15:24 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-03-06 22:08 [PATCH v3 0/3] KVM: Dirty quota-based throttling Shivam Kumar
2022-03-06 22:08 ` [PATCH v3 1/3] KVM: Implement dirty quota-based throttling of vcpus Shivam Kumar
2022-03-31 0:28 ` Sean Christopherson
2022-03-31 7:20 ` Shivam Kumar
2022-03-31 15:37 ` Sean Christopherson
2022-04-06 12:32 ` Shivam Kumar
2022-05-02 22:14 ` Peter Xu
2022-05-03 7:22 ` Shivam Kumar
2022-05-03 13:43 ` Peter Xu
2022-05-04 6:33 ` Shivam Kumar
2022-05-04 17:26 ` Peter Xu
2022-05-05 15:17 ` Shivam Kumar
2022-03-06 22:08 ` [PATCH v3 2/3] KVM: Documentation: Update kvm_run structure for dirty quota Shivam Kumar
2022-03-31 0:40 ` Sean Christopherson
2022-03-31 7:30 ` Shivam Kumar
2022-03-31 15:24 ` Sean Christopherson [this message]
2022-04-01 13:49 ` Sean Christopherson
2022-04-06 12:39 ` Shivam Kumar
2022-04-06 12:44 ` Shivam Kumar
2022-03-06 22:08 ` [PATCH v3 3/3] KVM: selftests: Add selftests for dirty quota throttling Shivam Kumar
2022-04-18 4:55 ` Shivam Kumar
2022-04-18 4:59 ` Shivam Kumar
2022-04-18 16:17 ` Sean Christopherson
2022-04-28 7:00 ` Shivam Kumar
2022-04-28 23:59 ` Sean Christopherson
2022-03-19 18:21 ` [PATCH v3 0/3] KVM: Dirty quota-based throttling Shivam Kumar
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=YkXHtc2MiwUxpMFU@google.com \
--to=seanjc@google.com \
--cc=anurag.madnawat@nutanix.com \
--cc=kvm@vger.kernel.org \
--cc=manish.mishra@nutanix.com \
--cc=pbonzini@redhat.com \
--cc=shaju.abraham@nutanix.com \
--cc=shivam.kumar1@nutanix.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).