Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Xu Yilun <yilun.xu@linux.intel.com>
To: sashiko-reviews@lists.linux.dev
Cc: kvm@vger.kernel.org
Subject: Re: [PATCH v3 6/6] x86/virt/tdx: Support DPAMT when adding memory for the extensions
Date: Thu, 8 Oct 2026 12:31:15 +0800	[thread overview]
Message-ID: <ascck27BOXu2QZPR@yilunxu-OptiPlex-7050> (raw)
In-Reply-To: <20261005175713.8B8701F00893@smtp.kernel.org>

On Mon, Oct 05, 2026 at 05:57:13PM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [Medium] tdx: allocator thrashing due to unconditional DPAMT allocations
> --
> 
> commit 02adad93d9f4243664b0cea8f1ad9c0b433e79a8
> Author: Xu Yilun <yilun.xu@linux.intel.com>
> 
> x86/virt/tdx: Support DPAMT when adding memory for the extensions
> 
> This commit updates the TDX module extension memory setup to install a 4K
> Dynamic PAMT (DPAMT) for each page before adding it. It calls tdx_pamt_get()
> for each page within the memory chunk.
> 
> > diff --git a/arch/x86/virt/vmx/tdx/tdx.c b/arch/x86/virt/vmx/tdx/tdx.c
> > index 5d5f9da1ab028..27a7039ee443c 100644
> > --- a/arch/x86/virt/vmx/tdx/tdx.c
> > +++ b/arch/x86/virt/vmx/tdx/tdx.c
> > @@ -1330,8 +1330,15 @@ static __init int tdx_ext_mem_setup(void)
> >  		struct page *chunk = page + added_pages;
> >  		unsigned int i;
> >  
> > -		for (i = 0; i < chunk_pages; i++)
> > +		for (i = 0; i < chunk_pages; i++) {
> > +			ret = tdx_pamt_get(page_to_pfn(chunk + i), NULL);
> 
> [Severity: Medium]
> Will calling tdx_pamt_get() sequentially without a DPAMT cache cause severe
> allocator thrashing during boot?
> 
> Looking at tdx_pamt_get(), providing a NULL cache forces an unconditional 
> allocation of DPAMT backing pages before checking the reference count:
> 
> arch/x86/virt/vmx/tdx/tdx.c:tdx_pamt_get() {
>     ...
> 	ret = alloc_pamt_array(pamt_pages, cache);
> 	if (ret)
> 		return ret;
> 
> 	dpamt_refcount = tdx_find_dpamt_refcount(pfn);
> 
> 	spin_lock(&dpamt_lock);
> 
> 	/*
> 	 * If the DPAMT entry is already added (i.e. refcount >= 1),
> 	 * then just increment the refcount.
> 	 */
> 	if (atomic_inc_not_zero(dpamt_refcount))
> 		goto out_free;
>     ...
> out_free:
> 	spin_unlock(&dpamt_lock);
> 	free_pamt_array(pamt_pages);
>     ...
> }
> 
> Since 511 out of 512 pages in each 2MB block will find the entry already
> present, the newly allocated pages are immediately freed. For tens of
> megabytes of extensions, this results in thousands of unnecessary allocations
> and frees. Furthermore, free_pamt_array() performs expensive memory resets,
> leading to unnecessary boot delays.
> 
> Could a struct tdx_pamt_cache be allocated locally in tdx_ext_mem_setup() and
> passed into tdx_pamt_get() to avoid this thrashing?

tdx_pamt_cache is for cases where memory allocation is not possible when
adding DPAMT. I don't think it's good to use tdx_pamt_cache in normal
cases.

> 
> > +			if (ret) {
> > +				WARN(1, "DPAMT setup error for extensions, stranded all pages\n");
> > +				goto out_free_hpa_list;
> > +			}
> > +
> >  			hpa_list->phys[i] = page_to_phys(chunk + i);
> > +		}
> >  
> >  		ret = tdx_ext_mem_add(hpa_list, chunk_pages);
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20261006-tdx-module-ext-v3-0-db52cb05b918@linux.intel.com?part=6

  reply	other threads:[~2026-10-08  4:34 UTC|newest]

Thread overview: 23+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 17:41 [PATCH v3 0/6] Enable TDX module extensions Xu Yilun
2026-10-05 17:41 ` [PATCH v3 1/6] x86/virt/tdx: Move TDH.SYS.CONFIG operations into a wrapper Xu Yilun
2026-10-06 23:27   ` Edgecombe, Rick P
2026-10-05 17:41 ` [PATCH v3 2/6] x86/virt/tdx: Configure add-on features on TDX module init Xu Yilun
2026-10-06 23:56   ` Edgecombe, Rick P
2026-10-08  4:18     ` Xu Yilun
2026-10-08 16:06       ` Edgecombe, Rick P
2026-10-05 17:41 ` [PATCH v3 3/6] x86/virt/tdx: Add extra memory to TDX module for the extensions Xu Yilun
2026-10-05 17:56   ` sashiko-bot
2026-10-05 17:41 ` [PATCH v3 4/6] x86/virt/tdx: Make TDX module initialize " Xu Yilun
2026-10-05 18:00   ` sashiko-bot
2026-10-08  4:25     ` Xu Yilun
2026-10-05 17:41 ` [PATCH v3 5/6] x86/virt/tdx: Re-initialize the extensions on runtime TDX module update Xu Yilun
2026-10-05 17:58   ` sashiko-bot
2026-10-08  4:47     ` Xu Yilun
2026-10-06  4:32   ` Tony Lindgren
2026-10-05 17:41 ` [PATCH v3 6/6] x86/virt/tdx: Support DPAMT when adding memory for the extensions Xu Yilun
2026-10-05 17:57   ` sashiko-bot
2026-10-08  4:31     ` Xu Yilun [this message]
2026-10-08 18:19       ` Edgecombe, Rick P
2026-10-06  4:36   ` Tony Lindgren
2026-10-08  4:39     ` Xu Yilun
2026-10-08  5:37       ` Tony Lindgren

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ascck27BOXu2QZPR@yilunxu-OptiPlex-7050 \
    --to=yilun.xu@linux.intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox