Kernel KVM virtualization development
 help / color / mirror / Atom feed
From: Kishen Maloor <kishen.maloor@intel.com>
To: Tony Lindgren <tony.lindgren@linux.intel.com>
Cc: "Paolo Bonzini" <pbonzini@redhat.com>,
	"Sean Christopherson" <seanjc@google.com>,
	"Peter Xu" <peterx@redhat.com>,
	"Artem Bityutskiy" <artem.bityutskiy@linux.intel.com>,
	"Fabiano Rosas" <farosas@suse.de>,
	"Jon Grimm" <Jon.Grimm@amd.com>,
	"Pankaj Gupta" <pankaj.gupta@amd.com>,
	"Tom Lendacky" <thomas.lendacky@amd.com>,
	"Marc Zyngier" <maz@kernel.org>,
	"Oliver Upton" <oliver.upton@linux.dev>,
	"Steven Price" <steven.price@arm.com>,
	"Anup Patel" <anup@brainfault.org>,
	"Samuel Ortiz" <sameo@rivosinc.com>,
	"Jakub Růžička" <jakub.ruzicka@matfyz.cz>,
	"Jörg Rödel" <joro@8bytes.org>,
	"Vishal Annapurve" <vannapurve@google.com>,
	"Elena Reshetova" <elena.reshetova@intel.com>,
	"Kai Huang" <kai.huang@intel.com>,
	"Mika Westerberg" <mika.westerberg@linux.intel.com>,
	"Peter Fang" <peter.fang@intel.com>,
	"Rick Edgecombe" <rick.p.edgecombe@intel.com>,
	"Xiaoyao Li" <xiaoyao.li@intel.com>,
	"Xu Yilun" <yilun.xu@linux.intel.com>,
	kvm@vger.kernel.org
Subject: Re: [RFC PATCH v2 2/4] KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD
Date: Wed, 23 Sep 2026 22:34:14 -0700	[thread overview]
Message-ID: <b6afcf8b-5cde-4c70-93fc-86127d1884e1@intel.com> (raw)
In-Reply-To: <arN20-sGytS6BlZc@tlindgre-MOBL1>

On 9/22/26 11:50 PM, Tony Lindgren wrote:
> On Tue, Sep 22, 2026 at 05:37:33PM -0700, Kishen Maloor wrote:
>> On 9/21/26 11:27 PM, Tony Lindgren wrote:
>>> Oh right thanks. I think this is really the maximum transfer buffer size
>>> Peter asked, not just a hint to userspace :)
>>
>> It is a strict upper bound. Maybe it's semantics, but I called 
>> it a "hint" because allocating for that entire size could be optional.
>> If a userspace driver for say TDX wants to send smaller batches (say 128) then 
>> it can refer to the spec, do the math, and allocate 131 pages and the kernel 
>> should permit that; it's not wrong. If userspace ever allocates less room than 
>> a call requires, it would fail. A different userspace driver could simply 
>> allocate that max size and be done; no need to refer to the spec or do the math. 
>> It is for this second case where I thought returning the upper bound would be 
>> useful. Hence the earlier suggestion.
> 
> OK 
>  
>>>>>>>> +struct kvm_transfer_buffer {
>>>>>>>> +	__u64 address;
>>>>>>>> +	__u32 size;
>>>>>>>> +	__u32 reserved;
>>>>>>>> +};
>>>>>>>
>>>>>>> Should this struct include a 'capacity' field (u32) that is set on each command?
>>>>>>> It would be the number of bytes writable at address.
>>>>>>> size would be the input length on entry (0 if the command passes none), and the
>>>>>>> number of bytes produced on return (0 if none).
>>>>>>
>>>>>> Hmm so the transfer command return value can return how many bytes were
>>>>>> written of the input. But yeah we don't know how many bytes were written
>>>>>> back to the transfer buffer as result of the transfer command.
>>>>
>>>> The transfer command return value could return how many bytes were written into the buffer.
>>>> But in an input-output call, the kernel handler wouldn't know how many bytes it could write,
>>>> or for that matter even how many pages to pin up front in case it needs to return an output
>>>> because 'size' couldn't simultaneously convey the input length and buffer capacity. That was
>>>> the gap that I thought a read-only 'capacity' field could bridge. Of course, this
>>>> assumes that the output is written in-place.
>>>
>>> Hmm yeah this inplace capacity vs transferred issue remains still. So I
>>> agree we need to specify the capacity in struct kvm_transfer_buffer like
>>> you suggested.
>>
>> To be clear, I think the in/out split for the buffers along with the convention 
>> I laid out closes that gap I saw without needing a 'capacity' field.
>> Because out/size could now unambiguously convey capacity on entry and output
>> length on return.
> 
> But for an inplace buffer use with some input data smaller than the output
> data, would it work? To me it seems you need both buffer size and data
> size for that.

Yes, with two kvm_transfer_buffers in the transfer struct, it would work, whether
the call uses a single userspace buffer or two.

>  
>>> To me size is already the size of the buffer though. So instead of changing
>>> size to capacity, how about something like datasize or len for the input
>>> and output transfer length?
>>
>> But I understand that (and please correct me if I'm wrong):
>> a) You'd still prefer to not have 'size' serve that double duty.
>> b) 'size' in your mental model already means buffer capacity.
> 
> Heh yes correct for the above.
>  
>> In that case, we could add a 'datasize' field to convey the length
>> of valid data in the buffer, like this:
>>
>> struct kvm_transfer_buffer {
>>     __u64 address;
>>     __u32 size;
>>     __u32 datasize;
>>     __u64 reserved;
>> };
> 
> Maybe bufsize and datasize? Then the difference would be obvious while
> reading the code.

Sure.

> 
>> The convention then becomes:
>> - A non-zero 'datasize' on 'in' at call entry conveys that there is input.
>> - A non-zero 'datasize' on 'out' at call exit conveys that there is output.
>> - out/datasize on call entry is ignored.
>> - in/size and out/size are seeded with the buffer capacity.
>>
>>>
>>>>>> How about if we add the bytes returned to the transfer struct? Then the
>>>>>> kvm_transfer_buffer can stay as just a buffer. 
>>>>>
>>>>> Actually, for the possible cases with input+output, we could reserve space
>>>>> in the transfer struct for another struct kvm_transfer_buffer for the
>>>>> results?
>>>>
>>>> Yes, say an 'in' and 'out' kvm_transfer_buffer inside struct kvm_migrate_cmd should
>>>> close this out and shouldn't require a 'capacity' field. Maybe we then establish this
>>>> convention:
>>>> - A non-zero 'size' on 'in' at call entry would signal that there is input.
>>>> - A non-zero 'size' on 'out' at call entry would convey the buffer capacity.
>>>> - A non-zero 'size' on 'out' at call exit would convey that there is output.
>>>> - A zeroed 'size' on 'out' at call exit would convey that there is no output.
>>>
>>> Looks doable to me but with the inplace issue as above.. Sounds like we just
>>> need to reserve space for a case with a separate output buffer though.
>>
>> To be clear, this is what I thought we were talking about :)
> 
> Heh yeah we're talking two things with the inplace use vs two buffers :)
> 
>> To add a 2nd kvm_transfer_buffer to kvm_migrate_cmd, like this:
>>
>> struct kvm_migrate_cmd {
>>      __u16 command;
>>      __u16 flags;
>>      __u32 reserved;
>>      struct kvm_transfer_buffer in;
>>      struct kvm_transfer_buffer out;
>> };
>>
>> If there is agreement on this model, then yeah, we'd want to define
>> these fields now, since the struct can't grow later without a new ioctl
>> number.
> 
> Based on what we've discussed, my preference is the following:
> 
> Keep the current buf naming. For the EXPORT/IMPORT type functions the use
> should be obvious from the transfer type. 
> 
> Reserve enough space for a separate output buffer or results buffer or
> whatever it might get called if such a use case ever pops up.

Reserved space can be named later without changing sizeof, so either way
works. I'd mildly prefer to declare the second kvm_transfer_buffer just
because declaring both would settle the second buffer's semantics now. Not
something I'd push hard on though if you prefer reserving.

> Add the datasize to struct kvm_transfer_buffer like you suggested and
> rename size to bufsize.

  reply	other threads:[~2026-09-24  5:34 UTC|newest]

Thread overview: 84+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-31  7:13 [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 1/4] Documentation: KVM: Add live migration API for confidential guests Tony Lindgren
2026-08-31  7:20   ` sashiko-bot
2026-09-18 11:35   ` Peter Xu
2026-09-21  4:20     ` Tony Lindgren
2026-09-24  1:50     ` Wei Wang
2026-09-24  4:51       ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 2/4] KVM: x86: Add optional KVM_CAP_LIVE_MIGRATION and KVM_MIGRATE_CMD Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:03     ` Tony Lindgren
2026-09-07 11:53   ` Tony Lindgren
2026-09-07 13:15     ` Jörg Rödel
2026-09-07 13:32       ` Artem Bityutskiy
2026-09-08  4:15         ` Tony Lindgren
2026-09-08  4:43         ` Tony Lindgren
2026-09-09  0:22           ` Kishen Maloor
2026-09-09  6:57             ` Tony Lindgren
2026-09-10  1:11               ` Kishen Maloor
2026-09-10  6:33                 ` Tony Lindgren
2026-09-11  1:40                   ` Kishen Maloor
2026-09-11  4:23                     ` Tony Lindgren
2026-09-15  0:14                       ` Kishen Maloor
2026-09-15  4:44                         ` Tony Lindgren
2026-09-15 15:53                           ` Kishen Maloor
2026-09-16  5:09                             ` Tony Lindgren
2026-09-17  3:31                               ` Kishen Maloor
2026-09-17  6:42                                 ` Tony Lindgren
2026-09-18  4:32                                   ` Kishen Maloor
2026-09-18  5:58                                     ` Tony Lindgren
2026-09-21  0:13                                       ` Kishen Maloor
2026-09-21  6:52                                         ` Tony Lindgren
2026-09-21  9:24                                           ` Tony Lindgren
2026-09-21 10:58                                             ` Tony Lindgren
2026-09-22  3:57                                           ` Kishen Maloor
2026-09-22  5:25                                             ` Tony Lindgren
2026-09-23  0:38                                               ` Kishen Maloor
2026-09-23  6:04                                                 ` Tony Lindgren
2026-09-24  5:53                                                   ` Kishen Maloor
2026-09-24  6:59                                                     ` Tony Lindgren
2026-09-18  4:33   ` Kishen Maloor
2026-09-21  5:58     ` Tony Lindgren
2026-09-21  6:56       ` Tony Lindgren
2026-09-22  3:56         ` Kishen Maloor
2026-09-22  6:27           ` Tony Lindgren
2026-09-23  0:37             ` Kishen Maloor
2026-09-23  6:50               ` Tony Lindgren
2026-09-24  5:34                 ` Kishen Maloor [this message]
2026-09-24  7:15                   ` Tony Lindgren
2026-10-08  9:22                     ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 3/4] KVM: x86: Add optional KVM_EXPORT_MEMORY and KVM_IMPORT_MEMORY Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:10     ` Tony Lindgren
2026-08-31  7:13 ` [RFC PATCH v2 4/4] KVM: x86: Add optional KVM_EXPORT_VCPU and KVM_IMPORT_VCPU Tony Lindgren
2026-08-31  7:23   ` sashiko-bot
2026-09-01  6:12     ` Tony Lindgren
2026-09-04 18:24 ` [RFC PATCH v2 0/4] Add KVM API for confidential guest live migration Artem Bityutskiy
2026-09-17 21:27   ` Peter Xu
2026-09-18 12:46     ` Artem Bityutskiy
2026-09-18 15:53       ` Peter Xu
2026-09-22  8:09         ` Artem Bityutskiy
2026-09-22  9:42           ` Tony Lindgren
2026-09-22 11:54             ` Artem Bityutskiy
2026-09-23  4:20               ` Tony Lindgren
2026-09-22 21:18           ` Peter Xu
2026-09-23 12:05             ` Artem Bityutskiy
2026-09-24 21:19               ` Peter Xu
2026-09-28 14:15                 ` Artem Bityutskiy
2026-09-29 21:05                   ` Peter Xu
2026-10-02 19:57                     ` Artem Bityutskiy
2026-10-07 20:00                       ` Peter Xu
2026-09-23 15:28           ` Serge Hallyn (AMD)
2026-09-20 23:56     ` Kishen Maloor
2026-09-23 21:36       ` Peter Xu
2026-09-24  4:27         ` Kishen Maloor
2026-09-25 14:18           ` Peter Xu
2026-09-29  1:28             ` Kishen Maloor
2026-09-30 20:42               ` Peter Xu
2026-10-07  4:27                 ` Kishen Maloor
2026-10-07 20:13                   ` Peter Xu
2026-10-08  6:23                     ` Tony Lindgren
2026-09-18 18:36 ` Ionut Mihalcea
2026-09-21  4:35   ` Tony Lindgren
2026-09-25 16:03 ` Serge Hallyn (AMD)
2026-09-28  3:24   ` Kishen Maloor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=b6afcf8b-5cde-4c70-93fc-86127d1884e1@intel.com \
    --to=kishen.maloor@intel.com \
    --cc=Jon.Grimm@amd.com \
    --cc=anup@brainfault.org \
    --cc=artem.bityutskiy@linux.intel.com \
    --cc=elena.reshetova@intel.com \
    --cc=farosas@suse.de \
    --cc=jakub.ruzicka@matfyz.cz \
    --cc=joro@8bytes.org \
    --cc=kai.huang@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=maz@kernel.org \
    --cc=mika.westerberg@linux.intel.com \
    --cc=oliver.upton@linux.dev \
    --cc=pankaj.gupta@amd.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.fang@intel.com \
    --cc=peterx@redhat.com \
    --cc=rick.p.edgecombe@intel.com \
    --cc=sameo@rivosinc.com \
    --cc=seanjc@google.com \
    --cc=steven.price@arm.com \
    --cc=thomas.lendacky@amd.com \
    --cc=tony.lindgren@linux.intel.com \
    --cc=vannapurve@google.com \
    --cc=xiaoyao.li@intel.com \
    --cc=yilun.xu@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox