From: Nikolay Borisov <nik.borisov@suse.com>
To: Rick Edgecombe <rick.p.edgecombe@intel.com>,
bp@alien8.de, dave.hansen@intel.com, hpa@zytor.com,
kas@kernel.org, kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org,
mingo@redhat.com, pbonzini@redhat.com, seanjc@google.com,
tglx@kernel.org, vannapurve@google.com, x86@kernel.org,
chao.gao@intel.com, yan.y.zhao@intel.com, kai.huang@intel.com,
tony.lindgren@linux.intel.com, binbin.wu@intel.com
Cc: Binbin Wu <binbin.wu@linux.intel.com>
Subject: Re: [PATCH v7 07/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path
Date: Wed, 22 Jul 2026 13:50:31 +0300 [thread overview]
Message-ID: <c16ef391-845a-40b1-a05c-245ddee6da51@suse.com> (raw)
In-Reply-To: <20260718014500.2231262-8-rick.p.edgecombe@intel.com>
On 7/18/26 04:44, Rick Edgecombe wrote:
> When handling an EPT violation, KVM holds a spinlock while manipulating
> the EPT. Before entering the spinlock it doesn't know how many EPT page
> tables will need to be installed or whether a huge page will be used. For
> this reason it allocates a worst case number of page tables that it might
> need as part of servicing the EPT violation.
>
> Under Dynamic PAMT these pre-allocated pages will potentially need to have
> Dynamic PAMT backing pages installed for them. KVM already has helpers to
> manage topping up page caches before taking the MMU lock, but they cannot
> be passed from KVM to arch/x86 code.
>
> The problem of how and when to install the Dynamic PAMT backing pages for
> the pages given to the TDX module during the fault path has had a lot of
> design attempts.
> - Extracting KVM's MMU caches requires too much inlined code added to
> headers.
> - A few varieties of installing Dynamic PAMT backing when allocating the
> S-EPT page tables. (see links)
> - Using mempool_t to transfer the pages between KVM and arch/x86 doesn't
> work because the component is designed more around maintaining a pool
> of pages, rather than topping up a continually drained cache.
>
> So don't do these as they all had various problems. Instead just create a
> small simple data structure to use for handing a pre-allocated list of
> pages between KVM and arch/x86 code. Model this on KVM's existing MMU
> memory caches.
>
> Add a tdx_pamt_cache arg to tdx_pamt_get() so it can draw pages from a
> cache when needed. Not all Dynamic PAMT page installations will happen
> under spinlock, for example TD and vCPU scoped control pages. So have
> tdx_pamt_get() maintain the existing behavior of allocating from the page
> allocator when NULL is passed for the struct tdx_pamt_cache arg. This
> prevents excess allocations for cases where it can be avoided.
>
> Export the new helpers for KVM.
>
> AI was used under supervision to review code and workshop logs.
>
> Co-developed-by: Sean Christopherson <seanjc@google.com>
> Signed-off-by: Sean Christopherson <seanjc@google.com>
> Signed-off-by: Rick Edgecombe <rick.p.edgecombe@intel.com>
> Reviewed-by: Kiryl Shutsemau (Meta) <kas@kernel.org>
> Reviewed-by: Binbin Wu <binbin.wu@linux.intel.com>
> Reviewed-by: Chao Gao <chao.gao@intel.com>
> Reviewed-by: Yan Zhao <yan.y.zhao@intel.com>
> Reviewed-by: Tony Lindgren <tony.lindgren@linux.intel.com>
> Link: https://lore.kernel.org/kvm/aXENNKjAKTM9UJNH@google.com/
> Link: https://lore.kernel.org/kvm/20260129011517.3545883-20-seanjc@google.com/
> Link: https://lore.kernel.org/kvm/aYW5CbUvZrLogsWF@yzhao56-desk.sh.intel.com/
> ---
Reviewed-by: Nikolay Borisov <nik.borisov@suse.com>
next prev parent reply other threads:[~2026-07-22 10:50 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-18 1:44 [PATCH v7 00/11] Dynamic PAMT Rick Edgecombe
2026-07-18 1:44 ` [PATCH v7 01/11] x86/virt/tdx: Simplify PAMT layout calculation Rick Edgecombe
2026-07-18 1:44 ` [PATCH v7 02/11] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2026-07-18 1:44 ` [PATCH v7 03/11] x86/virt/tdx: Add tdx_alloc/free_control_page() helpers Rick Edgecombe
2026-07-18 1:44 ` [PATCH v7 04/11] x86/virt/tdx: Allocate refcounts for Dynamic PAMT memory Rick Edgecombe
2026-07-18 1:44 ` [PATCH v7 05/11] x86/virt/tdx: Handle multiple callers in tdx_pamt_get/put() Rick Edgecombe
2026-07-21 15:32 ` Nikolay Borisov
2026-07-18 1:44 ` [PATCH v7 06/11] KVM: TDX: Allocate PAMT memory for TD and vCPU control structures Rick Edgecombe
2026-07-22 7:59 ` Nikolay Borisov
2026-07-18 1:44 ` [PATCH v7 07/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path Rick Edgecombe
2026-07-22 10:50 ` Nikolay Borisov [this message]
2026-07-18 1:44 ` [PATCH v7 08/11] KVM: TDX: Get/put PAMT pages when (un)mapping private memory Rick Edgecombe
[not found] ` <20260718061050.E17B01F000E9@smtp.kernel.org>
2026-07-20 16:48 ` Edgecombe, Rick P
2026-07-22 13:46 ` Nikolay Borisov
2026-07-22 14:25 ` Sean Christopherson
2026-07-18 1:44 ` [PATCH v7 09/11] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
[not found] ` <20260718015627.21D9F1F000E9@smtp.kernel.org>
2026-07-20 18:34 ` Edgecombe, Rick P
2026-07-18 1:44 ` [PATCH v7 10/11] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2026-07-18 1:45 ` [PATCH v7 11/11] x86/virt/tdx: Optimize tdx_pamt_get/put() Rick Edgecombe
[not found] ` <20260718020053.C2FC81F000E9@smtp.kernel.org>
2026-07-20 18:33 ` Edgecombe, Rick P
2026-07-21 20:59 ` [PATCH v7 00/11] Dynamic PAMT Sohil Mehta
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c16ef391-845a-40b1-a05c-245ddee6da51@suse.com \
--to=nik.borisov@suse.com \
--cc=binbin.wu@intel.com \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@intel.com \
--cc=hpa@zytor.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=seanjc@google.com \
--cc=tglx@kernel.org \
--cc=tony.lindgren@linux.intel.com \
--cc=vannapurve@google.com \
--cc=x86@kernel.org \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox