From: Xiaoyao Li <xiaoyao.li@intel.com>
To: Sean Christopherson <seanjc@google.com>,
Ackerley Tng <ackerleytng@google.com>
Cc: Michael Roth <michael.roth@amd.com>,
Suzuki K Poulose <suzuki.poulose@arm.com>,
"David Hildenbrand (Arm)" <david@kernel.org>,
aik@amd.com, andrew.jones@linux.dev, binbin.wu@linux.intel.com,
brauner@kernel.org, chao.p.peng@linux.intel.com,
jmattson@google.com, jthoughton@google.com, oupton@kernel.org,
pankaj.gupta@amd.com, qperret@google.com,
rick.p.edgecombe@intel.com, rientjes@google.com,
shivankg@amd.com, steven.price@arm.com, tabba@google.com,
willy@infradead.org, wyihan@google.com, yan.y.zhao@intel.com,
forkloop@google.com, pratyush@kernel.org,
aneesh.kumar@kernel.org, liam@infradead.org,
Paolo Bonzini <pbonzini@redhat.com>,
Thomas Gleixner <tglx@kernel.org>, Ingo Molnar <mingo@redhat.com>,
Borislav Petkov <bp@alien8.de>,
Dave Hansen <dave.hansen@linux.intel.com>,
x86@kernel.org, "H. Peter Anvin" <hpa@zytor.com>,
Steven Rostedt <rostedt@goodmis.org>,
Masami Hiramatsu <mhiramat@kernel.org>,
Mathieu Desnoyers <mathieu.desnoyers@efficios.com>,
Jonathan Corbet <corbet@lwn.net>,
Shuah Khan <skhan@linuxfoundation.org>,
Shuah Khan <shuah@kernel.org>,
Vishal Annapurve <vannapurve@google.com>,
Andrew Morton <akpm@linux-foundation.org>,
Chris Li <chrisl@kernel.org>, Kairui Song <kasong@tencent.com>,
Kemeng Shi <shikemeng@huaweicloud.com>,
Nhat Pham <nphamcs@gmail.com>, Barry Song <baohua@kernel.org>,
Axel Rasmussen <axelrasmussen@google.com>,
Yuanchu Xie <yuanchu@google.com>, Wei Xu <weixugc@google.com>,
Youngjun Park <youngjun.park@lge.com>,
Qi Zheng <qi.zheng@linux.dev>,
Shakeel Butt <shakeel.butt@linux.dev>,
Kiryl Shutsemau <kas@kernel.org>,
Baoquan He <baoquan.he@linux.dev>, Jason Gunthorpe <jgg@ziepe.ca>,
John Hubbard <jhubbard@nvidia.com>, Peter Xu <peterx@redhat.com>,
tarunsahu@google.com, Vlastimil Babka <vbabka@kernel.org>,
kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-trace-kernel@vger.kernel.org, linux-doc@vger.kernel.org,
linux-kselftest@vger.kernel.org, linux-mm@kvack.org,
linux-coco@lists.linux.dev
Subject: Re: [PATCH v10 09/41] KVM: guest_memfd: Filter both shared and private when invalidating
Date: Thu, 27 Aug 2026 12:34:11 +0800 [thread overview]
Message-ID: <a151b52d-0afb-4b32-a871-4da67210f416@intel.com> (raw)
In-Reply-To: <ao7vwx3nMqCjCHZU@google.com>
On 8/26/2026 9:53 PM, Sean Christopherson wrote:
<snip>
>> Is this just a case of user error? That with gmem_in_place_conversion,
>> userspace should not use userspace_addr from something other than the
>> gmem for the same memslot?
>
> Yes. It's not just invalidations that will go sideways,
> KVM accesses to guest
> memory won't hit the same physical page as actual guest accesses.
Side topic.
If KVM enforces KVM_MEMSLOT_GMEM_ONLY when gmem_in_place_conversion is
true like below proposal, should we update KVM's guest memory accessors
to access gmem directly? If still use the existing code of accessing
userspace_addr of the memslot, I think KVM needs to document clearly
that when KVM_CAP_GUEST_MEMFD_MEMORY_ATTRIBUTES is enumerated, if
configuring the guest_memfd for a memslot, the userspace_addr passed in
needs to be the mmaped address of the guest_memfd.
> Huh. But that isn't strictly guaranteed, because userspace could bind to a
> memslot that isn't configured with GUEST_MEMFD_FLAG_MMAP, in which case SHARED
> faults will go through the VMA, not kvm_mmu_faultin_pfn_gmem(). It's a bit early
> in the morning, but off the top of my head, I can't think of any reason we need
> to support such a setup. If userspace really, really wants to use a separate
> mapping, they could DELETE+CREATE an equivalent memslot without the guest_memfd
> file descriptor.
>
> So I think we should do this?
>
> diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c
> index 9c2d52bdf25e..86f53e53a136 100644
> --- a/virt/kvm/guest_memfd.c
> +++ b/virt/kvm/guest_memfd.c
> @@ -1013,7 +1013,7 @@ int kvm_gmem_bind(struct kvm *kvm, struct kvm_memory_slot *slot,
> */
> WRITE_ONCE(slot->gmem.file, file);
> slot->gmem.pgoff = start;
> - if (kvm_gmem_supports_mmap(inode))
> + if (gmem_in_place_conversion || kvm_gmem_supports_mmap(inode))
> slot->flags |= KVM_MEMSLOT_GMEM_ONLY;
I like this idea. It makes gmem_in_place_conversion a step closer to
what its name implies, though in-place conversion is not truly 100%
guaranteed[*].
[*] https://lore.kernel.org/all/akUbz_kJvYulaboo@google.com/
> xa_store_range(&f->bindings, start, end - 1, slot, GFP_KERNEL);
>
> Regardless, the key aspect of all this is that in-place conversion is brand new
> functionality, so we don't have to ensure backwards compatibility.
next prev parent reply other threads:[~2026-08-27 4:34 UTC|newest]
Thread overview: 144+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-07 21:52 [PATCH v10 00/41] guest_memfd: In-place conversion support Ackerley Tng via B4 Relay
2026-08-07 21:52 ` [PATCH v10 01/41] KVM: guest_memfd: Use kvm_mem_is_private() when populating guest_memfd memory Ackerley Tng via B4 Relay
2026-08-12 3:12 ` Binbin Wu
2026-08-12 8:16 ` Xiaoyao Li
2026-08-12 13:34 ` Fuad Tabba
2026-08-07 21:52 ` [PATCH v10 02/41] KVM: guest_memfd: Introduce per-gmem attributes, use to guard user mappings Ackerley Tng via B4 Relay
2026-08-10 15:12 ` Sean Christopherson
2026-08-12 3:27 ` Binbin Wu
2026-08-07 21:52 ` [PATCH v10 03/41] KVM: Rename KVM_GENERIC_MEMORY_ATTRIBUTES to KVM_VM_MEMORY_ATTRIBUTES Ackerley Tng via B4 Relay
2026-08-07 21:52 ` [PATCH v10 04/41] KVM: Enumerate support for PRIVATE memory iff kvm_arch_has_private_mem is defined Ackerley Tng via B4 Relay
2026-08-12 8:23 ` Xiaoyao Li
2026-08-07 21:52 ` [PATCH v10 05/41] KVM: Rename memory attribute APIs to prepare for in-place gmem conversion Ackerley Tng via B4 Relay
2026-08-12 5:23 ` Binbin Wu
2026-08-07 21:52 ` [PATCH v10 06/41] KVM: Provide generic interface for checking memory private/shared status Ackerley Tng via B4 Relay
2026-08-12 5:33 ` Binbin Wu
2026-08-07 21:52 ` [PATCH v10 07/41] KVM: guest_memfd: Stub in ability to enable in-place shared<=>private conversion Ackerley Tng via B4 Relay
2026-08-10 8:49 ` David Hildenbrand (Arm)
2026-08-10 15:01 ` Sean Christopherson
2026-08-12 9:42 ` Xiaoyao Li
2026-08-13 18:40 ` Ackerley Tng
2026-08-20 0:50 ` Sean Christopherson
2026-08-12 10:53 ` David Hildenbrand (Arm)
2026-08-12 21:34 ` Sean Christopherson
2026-08-13 18:30 ` Ackerley Tng
2026-08-12 9:45 ` Xiaoyao Li
2026-08-12 13:35 ` Fuad Tabba
2026-08-21 3:05 ` Xiaoyao Li
2026-08-24 14:45 ` Ackerley Tng
2026-08-25 3:46 ` Xiaoyao Li
2026-08-25 4:22 ` Ackerley Tng
2026-08-25 21:18 ` Sean Christopherson
2026-08-26 6:53 ` Ackerley Tng
2026-08-07 21:52 ` [PATCH v10 08/41] KVM: Consolidate private memory and guest_memfd ifdeffery in kvm_host.h Ackerley Tng via B4 Relay
2026-08-10 8:50 ` David Hildenbrand (Arm)
2026-08-07 21:52 ` [PATCH v10 09/41] KVM: guest_memfd: Filter both shared and private when invalidating Ackerley Tng via B4 Relay
2026-08-10 9:06 ` David Hildenbrand (Arm)
2026-08-10 9:27 ` Suzuki K Poulose
2026-08-10 19:11 ` Ackerley Tng
2026-08-20 1:32 ` Sean Christopherson
2026-08-25 8:06 ` Xiaoyao Li
2026-08-25 13:16 ` Sean Christopherson
2026-08-25 16:13 ` Xiaoyao Li
2026-08-25 18:46 ` Michael Roth
2026-08-25 18:55 ` Sean Christopherson
2026-08-26 2:28 ` Xiaoyao Li
2026-08-26 9:18 ` Ackerley Tng
2026-08-26 13:53 ` Sean Christopherson
2026-08-27 4:34 ` Xiaoyao Li [this message]
2026-08-12 13:35 ` Fuad Tabba
2026-08-07 21:52 ` [PATCH v10 10/41] KVM: guest_memfd: Add base support for KVM_SET_MEMORY_ATTRIBUTES2 Ackerley Tng via B4 Relay
2026-08-07 21:52 ` [PATCH v10 11/41] KVM: guest_memfd: Ensure pages are not in use before conversion Ackerley Tng via B4 Relay
2026-08-08 0:29 ` Yan Zhao
2026-08-09 21:51 ` Yan Zhao
2026-08-10 21:06 ` Ackerley Tng
2026-08-11 1:04 ` Yan Zhao
2026-08-11 2:17 ` Ackerley Tng
2026-08-11 4:50 ` Yan Zhao
2026-08-11 17:35 ` Ackerley Tng
2026-08-11 17:47 ` Edgecombe, Rick P
2026-08-13 18:51 ` Ackerley Tng
2026-08-13 20:26 ` Edgecombe, Rick P
2026-08-13 23:20 ` Sean Christopherson
2026-08-13 23:30 ` Edgecombe, Rick P
2026-08-17 6:18 ` Yan Zhao
2026-08-17 20:12 ` Sean Christopherson
2026-08-17 21:47 ` Ackerley Tng
2026-08-17 22:20 ` Sean Christopherson
2026-08-18 8:22 ` Ackerley Tng
2026-08-10 9:19 ` David Hildenbrand (Arm)
2026-08-10 21:41 ` Ackerley Tng
2026-08-10 22:26 ` Sean Christopherson
2026-08-11 17:56 ` David Hildenbrand (Arm)
2026-08-16 23:13 ` Ackerley Tng
2026-08-07 21:52 ` [PATCH v10 12/41] KVM: guest_memfd: Call arch make_shared callback for to-shared conversion Ackerley Tng via B4 Relay
2026-08-13 6:56 ` Binbin Wu
2026-08-13 15:55 ` Sean Christopherson
2026-08-13 21:01 ` Ackerley Tng
2026-08-13 22:08 ` Sean Christopherson
2026-08-14 0:05 ` Ackerley Tng
2026-08-14 15:04 ` Sean Christopherson
2026-08-16 22:46 ` Ackerley Tng
2026-08-17 19:47 ` Sean Christopherson
2026-08-17 20:16 ` Sean Christopherson
2026-08-17 21:10 ` Ackerley Tng
2026-08-07 21:52 ` [PATCH v10 13/41] KVM: guest_memfd: Return early if range already has requested attributes Ackerley Tng via B4 Relay
2026-08-14 2:30 ` Binbin Wu
2026-08-25 8:25 ` Xiaoyao Li
2026-08-07 21:52 ` [PATCH v10 14/41] mm/gup: factor out LRU cache draining for folio into lru_cache_drain_for_folio() Ackerley Tng via B4 Relay
2026-08-10 9:22 ` David Hildenbrand (Arm)
2026-08-12 13:37 ` Fuad Tabba
2026-08-07 21:52 ` [PATCH v10 15/41] KVM: guest_memfd: Handle lru_add fbatch refcounts during conversion safety check Ackerley Tng via B4 Relay
2026-08-10 9:25 ` David Hildenbrand (Arm)
2026-08-10 21:29 ` Ackerley Tng
2026-08-12 13:36 ` Fuad Tabba
2026-08-14 3:25 ` Binbin Wu
2026-08-16 23:02 ` Ackerley Tng
2026-08-07 21:52 ` [PATCH v10 16/41] KVM: guest_memfd: Zero page while getting pfn Ackerley Tng via B4 Relay
2026-08-10 9:30 ` David Hildenbrand (Arm)
2026-08-10 23:41 ` Ackerley Tng
2026-08-11 0:18 ` Sean Christopherson
2026-08-11 17:51 ` David Hildenbrand (Arm)
2026-08-14 5:18 ` Binbin Wu
2026-08-07 21:52 ` [PATCH v10 17/41] KVM: SEV: Make 'uaddr' parameter optional for KVM_SEV_SNP_LAUNCH_UPDATE Ackerley Tng via B4 Relay
2026-08-07 21:52 ` [PATCH v10 18/41] KVM: TDX: Make source page optional for KVM_TDX_INIT_MEM_REGION Ackerley Tng via B4 Relay
2026-08-14 5:57 ` Binbin Wu
2026-08-14 17:57 ` Sean Christopherson
2026-08-24 9:05 ` Yan Zhao
2026-08-25 8:26 ` Xiaoyao Li
2026-08-07 21:52 ` [PATCH v10 19/41] KVM: Move KVM_VM_MEMORY_ATTRIBUTES config definition to x86 Ackerley Tng via B4 Relay
2026-08-10 9:32 ` David Hildenbrand (Arm)
2026-08-07 21:52 ` [PATCH v10 20/41] KVM: Let userspace disable per-VM mem attributes, enable per-gmem attributes Ackerley Tng via B4 Relay
2026-08-10 9:36 ` David Hildenbrand (Arm)
2026-08-13 21:23 ` Ackerley Tng
2026-08-17 9:15 ` David Hildenbrand (Arm)
2026-08-14 6:30 ` Binbin Wu
2026-08-14 18:13 ` Sean Christopherson
2026-08-07 21:53 ` [PATCH v10 21/41] KVM: guest_memfd: Enable INIT_SHARED on guest_memfd for x86 Coco VMs Ackerley Tng via B4 Relay
2026-08-14 6:36 ` Binbin Wu
2026-08-07 21:53 ` [PATCH v10 22/41] KVM: selftests: Create gmem fd before "regular" fd when adding memslot Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 23/41] KVM: selftests: Rename guest_memfd{,_offset} to gmem_{fd,offset} Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 24/41] KVM: selftests: Add support for mmap() on guest_memfd in core library Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 25/41] KVM: selftests: Add selftests global for guest memory attributes capability Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 26/41] KVM: selftests: Add helpers for calling ioctls on guest_memfd Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 27/41] KVM: selftests: Test basic single-page conversion flow Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 28/41] KVM: selftests: Test conversion flow when INIT_SHARED Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 29/41] KVM: selftests: Test conversion precision in guest_memfd Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 30/41] KVM: selftests: Test conversion before allocation Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 31/41] KVM: selftests: Convert with allocated folios in different layouts Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 32/41] KVM: selftests: Test that truncation does not change shared/private status Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 33/41] KVM: selftests: Test that shared/private status is consistent across processes Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 34/41] KVM: selftests: Add helpers to pin pages with CONFIG_GUP_TEST Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 35/41] KVM: selftests: Test conversion with elevated page refcount Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 36/41] KVM: selftests: Reset shared memory after hole-punching Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 37/41] KVM: selftests: Provide function to look up guest_memfd details from gpa Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 38/41] KVM: selftests: Provide common function to set memory attributes Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 39/41] KVM: selftests: Make TEST_EXPECT_SIGBUS thread-safe Ackerley Tng via B4 Relay
2026-08-07 21:53 ` [PATCH v10 40/41] KVM: selftests: Update private_mem_conversions_test to mmap() guest_memfd Ackerley Tng via B4 Relay
2026-08-21 3:11 ` Xiaoyao Li
2026-08-21 12:30 ` Sean Christopherson
2026-08-25 9:32 ` Ackerley Tng
2026-08-25 10:06 ` Xiaoyao Li
2026-08-25 14:20 ` Ackerley Tng
2026-08-07 21:53 ` [PATCH v10 41/41] KVM: selftests: Update private memory exits test to work with per-gmem attributes Ackerley Tng via B4 Relay
2026-08-10 8:43 ` [PATCH v10 00/41] guest_memfd: In-place conversion support David Hildenbrand (Arm)
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a151b52d-0afb-4b32-a871-4da67210f416@intel.com \
--to=xiaoyao.li@intel.com \
--cc=ackerleytng@google.com \
--cc=aik@amd.com \
--cc=akpm@linux-foundation.org \
--cc=andrew.jones@linux.dev \
--cc=aneesh.kumar@kernel.org \
--cc=axelrasmussen@google.com \
--cc=baohua@kernel.org \
--cc=baoquan.he@linux.dev \
--cc=binbin.wu@linux.intel.com \
--cc=bp@alien8.de \
--cc=brauner@kernel.org \
--cc=chao.p.peng@linux.intel.com \
--cc=chrisl@kernel.org \
--cc=corbet@lwn.net \
--cc=dave.hansen@linux.intel.com \
--cc=david@kernel.org \
--cc=forkloop@google.com \
--cc=hpa@zytor.com \
--cc=jgg@ziepe.ca \
--cc=jhubbard@nvidia.com \
--cc=jmattson@google.com \
--cc=jthoughton@google.com \
--cc=kas@kernel.org \
--cc=kasong@tencent.com \
--cc=kvm@vger.kernel.org \
--cc=liam@infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-kselftest@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-trace-kernel@vger.kernel.org \
--cc=mathieu.desnoyers@efficios.com \
--cc=mhiramat@kernel.org \
--cc=michael.roth@amd.com \
--cc=mingo@redhat.com \
--cc=nphamcs@gmail.com \
--cc=oupton@kernel.org \
--cc=pankaj.gupta@amd.com \
--cc=pbonzini@redhat.com \
--cc=peterx@redhat.com \
--cc=pratyush@kernel.org \
--cc=qi.zheng@linux.dev \
--cc=qperret@google.com \
--cc=rick.p.edgecombe@intel.com \
--cc=rientjes@google.com \
--cc=rostedt@goodmis.org \
--cc=seanjc@google.com \
--cc=shakeel.butt@linux.dev \
--cc=shikemeng@huaweicloud.com \
--cc=shivankg@amd.com \
--cc=shuah@kernel.org \
--cc=skhan@linuxfoundation.org \
--cc=steven.price@arm.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=tarunsahu@google.com \
--cc=tglx@kernel.org \
--cc=vannapurve@google.com \
--cc=vbabka@kernel.org \
--cc=weixugc@google.com \
--cc=willy@infradead.org \
--cc=wyihan@google.com \
--cc=x86@kernel.org \
--cc=yan.y.zhao@intel.com \
--cc=youngjun.park@lge.com \
--cc=yuanchu@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox