Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: "Serge Hallyn (AMD)" <sergeh@kernel.org>
To: Tony Lindgren <tony.lindgren@linux.intel.com>
Cc: "Paolo Bonzini" <pbonzini@redhat.com>,
	"Sean Christopherson" <seanjc@google.com>,
	"Peter Xu" <peterx@redhat.com>,
	"Artem Bityutskiy" <artem.bityutskiy@linux.intel.com>,
	"Fabiano Rosas" <farosas@suse.de>,
	"Jon Grimm" <Jon.Grimm@amd.com>,
	"Pankaj Gupta" <pankaj.gupta@amd.com>,
	"Tom Lendacky" <thomas.lendacky@amd.com>,
	"Marc Zyngier" <maz@kernel.org>,
	"Oliver Upton" <oliver.upton@linux.dev>,
	"Steven Price" <steven.price@arm.com>,
	"Anup Patel" <anup@brainfault.org>,
	"Samuel Ortiz" <sameo@rivosinc.com>,
	"Jakub Růžička" <jakub.ruzicka@matfyz.cz>,
	"Jörg Rödel" <joro@8bytes.org>,
	"Vishal Annapurve" <vannapurve@google.com>,
	"Elena Reshetova" <elena.reshetova@intel.com>,
	"Kai Huang" <kai.huang@intel.com>,
	"Kishen Maloor" <kishen.maloor@intel.com>,
	"Mika Westerberg" <mika.westerberg@linux.intel.com>,
	"Peter Fang" <peter.fang@intel.com>,
	"Rick Edgecombe" <rick.p.edgecombe@intel.com>,
	"Xiaoyao Li" <xiaoyao.li@intel.com>,
	"Xu Yilun" <yilun.xu@linux.intel.com>,
	kvm@vger.kernel.org
Subject: Re: [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration
Date: Fri, 25 Sep 2026 11:03:49 -0500	[thread overview]
Message-ID: <arabZS5cIkPgw6ef@shallyn-amd> (raw)
In-Reply-To: <20260831071304.762939-1-tony.lindgren@linux.intel.com>

On Mon, Aug 31, 2026 at 10:13:00AM +0300, Tony Lindgren wrote:
> Hi all,
> 
> As discussed in a recent PUCK call, Sean suggested we post what Intel is
> using for the KVM live migration API for TDX as an example to see if we
> can come up with APIs that are not vendor specific.
> 
> The goal of this patch series is to start a discussion about live migration
> kernel APIs for CoCo guests.
> 
> Tom, since you mentioned that AMD SEV-SNP and Intel TDX live migration
> sound similar, can you please take a look how the API might work for
> SEV-SNP?
> 
> For CoCo VMs, the guest memory and vCPU states are not accessible to the
> userspace or KVM for live migration. The memory and vCPU states need to be
> extracted into encrypted blobs on the source, and decrypted on the
> destination. Before live migration, an encryption key needs to be
> negotiated between the source and destination.
> 
> The layer handling the encryption for live migration is implementation
> specific. It can be the TDX module or Coconut-SVSM for example.
> 
> For CoCo VMs, the KVM_MEMORY_ENCRYPT_OP ioctl() has been used with vendor
> specific sub-commands. Adding more vendor specific sub-commands is an
> option also for live migration. However, depending on how similar the KVM
> needs are, it may be possible to have a common API.
> 
> For TDX, we're using a group of ioctl()s that might be possible to adapt
> also for other CoCo implementations.
> 
> Artem has put together a brief description below of the example API and the
> migration flow:

Hi Tony,

is there any pubically available qemu git branch or patchset to show
how you currently are driving this?

> Example API
> ===========
> 
> - KVM_CAP_LIVE_MIGRATION - if a VM supports live migration through this
>   uAPI.
> - KVM_MIGRATE_CMD - the main ioctl that drives the migration phases. Each
>   command takes vendor-specific flags and a buffer for the blob that travels
>   between the hosts.
>   - KVM_MIGRATE_SETUP - establish the migration session and transfer the
>     immutable VM state.
>   - KVM_MIGRATE_ITERATION - close a memory copy round.
>   - KVM_MIGRATE_STOP_AND_COPY - pause the VM and transfer the remaining VM
>     state.
>   - KVM_MIGRATE_END - complete the migration, or abort it.
> - KVM_EXPORT_MEMORY - export memory pages on the source host.
> - KVM_IMPORT_MEMORY - import memory pages on the destination host.
> - KVM_EXPORT_VCPU - export vCPU state on the source host.
> - KVM_IMPORT_VCPU - import vCPU state on the destination host.
> 
> Dirty page tracking does not add a new uAPI. Userspace keeps using
> KVM_GET_DIRTY_LOG and KVM_CLEAR_DIRTY_LOG.
> 
> Migration flow
> ==============
> 
>  Source host                                      Destination host
>  ===========                                      ================
> 
>  CMD(SETUP/SESSION)          <--- setup msgs ---> CMD(SETUP/SESSION)
>        |    (repeated)                                  |
>  CMD(SETUP/IMMUTABLE_STATE)  - immutable state -> CMD(SETUP/IMMUTABLE_STATE)
>        |                                                |
>  KVM_GET_DIRTY_LOG                                      |
>  KVM_EXPORT_MEMORY           --- memory data ---> KVM_IMPORT_MEMORY
>  CMD(ITERATION)              --- epoch token ---> CMD(ITERATION)
>        |    (repeat until convergence)                  |
>  CMD(STOP_AND_COPY/PAUSE)                               |
>  CMD(STOP_AND_COPY/TD_STATE) --- VM state ------> CMD(STOP_AND_COPY/TD_STATE)
>  KVM_EXPORT_VCPU             --- vCPU state ----> KVM_IMPORT_VCPU
>  KVM_EXPORT_MEMORY           -- final memory ---> KVM_IMPORT_MEMORY
>  CMD(ITERATION/DONE)         --- start token ---> CMD(ITERATION)
>        |                                                |
>  CMD(END)                                         CMD(END)
> 
> For the TDX implementation, the above map to the TDX module SEAMCALLs.
> 
> Regards,
> 
> Tony
> 
> Changes since v1 at [0] below:
> 
> - Drop KVM_MIGRATE_CMD sub-command PREPARE, SETUP sub-command has been
>   enough for TDX at least
> 
> - Rename KVM_MIGRATE_CMD sub-command KVM_MIGRATE_TOKEN to
>   KVM_MIGRATE_ITERATION
> 
> - Rename KVM_MIGRATE_CMD sub-command KVM_MIGRATE_SOURCE_BLACKOUT to
>   KVM_MIGRATE_STOP_AND_COPY
> 
> - Add x86 ioctl handling
> 
> [0] https://lore.kernel.org/kvm/20251006113524.1573116-1-tony.lindgren@linux.intel.com/
> 
> 
> Tony Lindgren (4):
>   Documentation: KVM: Add live migration API for confidential guests
>   KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD
>   KVM: x86: Add optional KVM_EXPORT_MEMORY and KVM_IMPORT_MEMORY
>   KVM: x86: Add optional KVM_EXPORT_VCPU and KVM_IMPORT_VCPU
> 
>  Documentation/virt/kvm/api.rst     | 205 +++++++++++++++++++++++++++++
>  arch/x86/include/asm/kvm-x86-ops.h |   6 +
>  arch/x86/include/asm/kvm_host.h    |   6 +
>  arch/x86/kvm/x86.c                 | 102 ++++++++++++++
>  include/uapi/linux/kvm.h           |  43 ++++++
>  5 files changed, 362 insertions(+)
> 
> 
> base-commit: dc59e4fea9d83f03bad6bddf3fa2e52491777482
> -- 
> 2.43.0
> 

  parent reply	other threads:[~2026-09-25 16:04 UTC|newest]

Thread overview: 84+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31  7:13 [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 1/4] Documentation: KVM: Add live migration API for confidential guests Tony Lindgren
2026-08-31  7:20   ` sashiko-bot
2026-09-18 11:35   ` Peter Xu
2026-09-21  4:20     ` Tony Lindgren
2026-09-24  1:50     ` Wei Wang
2026-09-24  4:51       ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 2/4] KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:03     ` Tony Lindgren
2026-09-07 11:53   ` Tony Lindgren
2026-09-07 13:15     ` Jörg Rödel
2026-09-07 13:32       ` Artem Bityutskiy
2026-09-08  4:15         ` Tony Lindgren
2026-09-08  4:43         ` Tony Lindgren
2026-09-09  0:22           ` Kishen Maloor
2026-09-09  6:57             ` Tony Lindgren
2026-09-10  1:11               ` Kishen Maloor
2026-09-10  6:33                 ` Tony Lindgren
2026-09-11  1:40                   ` Kishen Maloor
2026-09-11  4:23                     ` Tony Lindgren
2026-09-15  0:14                       ` Kishen Maloor
2026-09-15  4:44                         ` Tony Lindgren
2026-09-15 15:53                           ` Kishen Maloor
2026-09-16  5:09                             ` Tony Lindgren
2026-09-17  3:31                               ` Kishen Maloor
2026-09-17  6:42                                 ` Tony Lindgren
2026-09-18  4:32                                   ` Kishen Maloor
2026-09-18  5:58                                     ` Tony Lindgren
2026-09-21  0:13                                       ` Kishen Maloor
2026-09-21  6:52                                         ` Tony Lindgren
2026-09-21  9:24                                           ` Tony Lindgren
2026-09-21 10:58                                             ` Tony Lindgren
2026-09-22  3:57                                           ` Kishen Maloor
2026-09-22  5:25                                             ` Tony Lindgren
2026-09-23  0:38                                               ` Kishen Maloor
2026-09-23  6:04                                                 ` Tony Lindgren
2026-09-24  5:53                                                   ` Kishen Maloor
2026-09-24  6:59                                                     ` Tony Lindgren
2026-09-18  4:33   ` Kishen Maloor
2026-09-21  5:58     ` Tony Lindgren
2026-09-21  6:56       ` Tony Lindgren
2026-09-22  3:56         ` Kishen Maloor
2026-09-22  6:27           ` Tony Lindgren
2026-09-23  0:37             ` Kishen Maloor
2026-09-23  6:50               ` Tony Lindgren
2026-09-24  5:34                 ` Kishen Maloor
2026-09-24  7:15                   ` Tony Lindgren
2026-10-08  9:22                     ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 3/4] KVM: x86: Add optional KVM_EXPORT_MEMORY and KVM_IMPORT_MEMORY Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:10     ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 4/4] KVM: x86: Add optional KVM_EXPORT_VCPU and KVM_IMPORT_VCPU Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:12     ` Tony Lindgren
2026-09-04 18:24 ` [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Artem Bityutskiy
2026-09-17 21:27   ` Peter Xu
2026-09-18 12:46     ` Artem Bityutskiy
2026-09-18 15:53       ` Peter Xu
2026-09-22  8:09         ` Artem Bityutskiy
2026-09-22  9:42           ` Tony Lindgren
2026-09-22 11:54             ` Artem Bityutskiy
2026-09-23  4:20               ` Tony Lindgren
2026-09-22 21:18           ` Peter Xu
2026-09-23 12:05             ` Artem Bityutskiy
2026-09-24 21:19               ` Peter Xu
2026-09-28 14:15                 ` Artem Bityutskiy
2026-09-29 21:05                   ` Peter Xu
2026-10-02 19:57                     ` Artem Bityutskiy
2026-10-07 20:00                       ` Peter Xu
2026-09-23 15:28           ` Serge Hallyn (AMD)
2026-09-20 23:56     ` Kishen Maloor
2026-09-23 21:36       ` Peter Xu
2026-09-24  4:27         ` Kishen Maloor
2026-09-25 14:18           ` Peter Xu
2026-09-29  1:28             ` Kishen Maloor
2026-09-30 20:42               ` Peter Xu
2026-10-07  4:27                 ` Kishen Maloor
2026-10-07 20:13                   ` Peter Xu
2026-10-08  6:23                     ` Tony Lindgren
2026-09-18 18:36 ` Ionut Mihalcea
2026-09-21  4:35   ` Tony Lindgren
2026-09-25 16:03 ` Serge Hallyn (AMD) [this message]
2026-09-28  3:24   ` Kishen Maloor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=arabZS5cIkPgw6ef@shallyn-amd \
    --to=sergeh@kernel.org \
    --cc=Jon.Grimm@amd.com \
    --cc=anup@brainfault.org \
    --cc=artem.bityutskiy@linux.intel.com \
    --cc=elena.reshetova@intel.com \
    --cc=farosas@suse.de \
    --cc=jakub.ruzicka@matfyz.cz \
    --cc=joro@8bytes.org \
    --cc=kai.huang@intel.com \
    --cc=kishen.maloor@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=maz@kernel.org \
    --cc=mika.westerberg@linux.intel.com \
    --cc=oliver.upton@linux.dev \
    --cc=pankaj.gupta@amd.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.fang@intel.com \
    --cc=peterx@redhat.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sameo@rivosinc.com \
    --cc=seanjc@google.com \
    --cc=steven.price@arm.com \
    --cc=thomas.lendacky@amd.com \
    --cc=tony.lindgren@linux.intel.com \
    --cc=vannapurve@google.com \
    --cc=xiaoyao.li@intel.com \
    --cc=yilun.xu@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox