kvm.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Sean Christopherson <seanjc@google.com>
To: Zeng Chi <zeng_chi911@163.com>
Cc: chao.p.peng@linux.intel.com, kvm@vger.kernel.org,
	 linux-kernel@vger.kernel.org, pbonzini@redhat.com,
	zengchi@kylinos.cn
Subject: Re: [PATCH v2] KVM: Don't treat reserved xarray entries as having memory attributes
Date: Fri, 28 Aug 2026 11:17:43 -0700	[thread overview]
Message-ID: <apHQxz5fCPf6JQAg@google.com> (raw)
In-Reply-To: <apHCG78KyLuzPrNa@google.com>

On Fri, Aug 28, 2026, Sean Christopherson wrote:
> So after way, waaay too much fiddling, this?  As a bonus, the changelog can call
> out that xas_next_entry() is essentially an optimized version of xas_find(),
> e.g. to communicate that the effective diff is actually just adding xas_retry().
> 
> diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
> index 65eb26a0520d..cc94d9881582 100644
> --- a/virt/kvm/kvm_main.c
> +++ b/virt/kvm/kvm_main.c
> @@ -2447,14 +2447,39 @@ bool kvm_range_has_memory_attributes(struct kvm *kvm, gfn_t start, gfn_t end,
>  		return (kvm_get_memory_attributes(kvm, start) & mask) == attrs;
>  
>  	guard(rcu)();
> -	if (!attrs)
> -		return !xas_find(&xas, end - 1);
>  
> +	/*
> +	 * Lookup the entry for each index instead of iterating over the xarray
> +	 * as KVM deletes/nullifies entries to represent "no attributes", and
> +	 * the xas index is effectively invalid when no entry is found.  I.e.
> +	 * matching non-zero attributes for *every* entry effectively requires
> +	 * a manually lookup for each index.
> +	 *
> +	 * Skip pre-allocated, reserved entries, or restart the lookup if the
> +	 * xarray was concurrently modified, via xas_retry() ("retry" means the
> +	 * entry holds an internal xarray value, i.e. is either invalid or NULL
> +	 * from the caller's perspective.
> +	 *
> +	 * Use xas_next() when looking for non-zero attributes to optimize for
> +	 * the case where the start of the range (or the entire range) doesn't
> +	 * have any attributes, as xas_next() returns literally the next entry,
> +	 * whereas xas_next_entry() returns the next non-NULL entry (bounded by
> +	 * a maximum index).
> +	 */
>  	for (index = start; index < end; index++) {
>  		do {
> -			entry = xas_next(&xas);
> +			entry = attrs ? xas_next(&xas) :
> +					xas_next_entry(&xas, end - 1);
>  		} while (xas_retry(&xas, entry));
>  
> +		/*
> +		 * Don't check the index if there's no entry; as above, the xas
> +		 * index is invalid (and if no entry was found, then the entire
> +		 * range has no attributes).
> +		 */
> +		if (!entry)
> +			return !attrs;

One "flaw" with this exact code is that if KVM managed to get a non-null, '0'
entry into the xarray, the index check could mismatch and this function could
technically get a false negative.

Swapping the checks would also work:

		if (!attrs)
			return !entry;

but I don't love that that violates the "don't check the index because it's bogus"
statement above.  And practically speaking, KVM should *never* observe a non-NULL
entry with a value of zero, assuming xas_retry() works as I think it does.  So to
harden against KVM changes/goofs, maybe do this as well?

diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
index cc94d9881582..f009cb3e687d 100644
--- a/virt/kvm/kvm_main.c
+++ b/virt/kvm/kvm_main.c
@@ -2480,6 +2480,8 @@ bool kvm_range_has_memory_attributes(struct kvm *kvm, gfn_t start, gfn_t end,
 		if (!entry)
 			return !attrs;
 
+		WARN_ON_ONCE(!xa_to_value(entry));
+
 		if (xas.xa_index != index ||
 		    (xa_to_value(entry) & mask) != attrs)
 			return false;


> +
>  		if (xas.xa_index != index ||
>  		    (xa_to_value(entry) & mask) != attrs)
>  			return false;
> 

  reply	other threads:[~2026-08-28 18:17 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-27 11:05 [PATCH] KVM: Release reserved xarray entries if reserving memory attributes fails Zeng Chi
2026-08-27 11:17 ` sashiko-bot
2026-08-27 18:37 ` Sean Christopherson
2026-08-28 10:27   ` [PATCH v2] KVM: Don't treat reserved xarray entries as having memory attributes Zeng Chi
2026-08-28 10:41     ` sashiko-bot
2026-08-28 17:15     ` Sean Christopherson
2026-08-28 18:17       ` Sean Christopherson [this message]
2026-08-28 10:51   ` [PATCH] KVM: Release reserved xarray entries if reserving memory attributes fails Zeng Chi

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apHQxz5fCPf6JQAg@google.com \
    --to=seanjc@google.com \
    --cc=chao.p.peng@linux.intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=pbonzini@redhat.com \
    --cc=zeng_chi911@163.com \
    --cc=zengchi@kylinos.cn \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).