From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4D061EE6423 for ; Fri, 15 Sep 2023 06:59:46 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id E31D86B031E; Fri, 15 Sep 2023 02:59:45 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id DE31A6B0320; Fri, 15 Sep 2023 02:59:45 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id CAAA86B0321; Fri, 15 Sep 2023 02:59:45 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) by kanga.kvack.org (Postfix) with ESMTP id BA8FF6B031E for ; Fri, 15 Sep 2023 02:59:45 -0400 (EDT) Received: from smtpin21.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id 8A813160F1E for ; Fri, 15 Sep 2023 06:59:45 +0000 (UTC) X-FDA: 81237931530.21.741914E Received: from mgamail.intel.com (mgamail.intel.com [192.55.52.136]) by imf04.hostedemail.com (Postfix) with ESMTP id 7842440013 for ; Fri, 15 Sep 2023 06:59:42 +0000 (UTC) Authentication-Results: imf04.hostedemail.com; dkim=pass header.d=intel.com header.s=Intel header.b="gd/rX94a"; dmarc=pass (policy=none) header.from=intel.com; spf=pass (imf04.hostedemail.com: domain of xiaoyao.li@intel.com designates 192.55.52.136 as permitted sender) smtp.mailfrom=xiaoyao.li@intel.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1694761183; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=KkE9lRGllcQe8z+tTpzHIJw3iKtQEYrEe5r0Zkc3ZuU=; b=s5z3RZ8JkB7mQ34FqpKrTvXpxSFhT6+QOi8EOOdaovabcqytBghUxPme/TL+cTVb5uGsV+ eJxSmj39wlB3eAFRZAahFRami0mSlGNwKG/5feRFAcKcUQIiYQW8IXVFtWXMOLiV4iy7sL y9+kq2L4R3mPwH+jqdm0pbpumrWl0w0= ARC-Authentication-Results: i=1; imf04.hostedemail.com; dkim=pass header.d=intel.com header.s=Intel header.b="gd/rX94a"; dmarc=pass (policy=none) header.from=intel.com; spf=pass (imf04.hostedemail.com: domain of xiaoyao.li@intel.com designates 192.55.52.136 as permitted sender) smtp.mailfrom=xiaoyao.li@intel.com ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1694761183; a=rsa-sha256; cv=none; b=4vCroMwO7BYITOKsXEnPKFMrQAAh6WNNCPAhVdGCNB8wY7lupvZ8vDmddOi2R4FKQso97B Fe6H/w6RpWdHYvNJ1fHgcfyjKhEZpRhn/EnE+aPzNr6FG8m0znf3RZ+EN0E9rcjlJWLtya 2BdXH1bvpUO0NH7+RE8OhjuMJDDGXdM= DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1694761182; x=1726297182; h=message-id:date:mime-version:subject:to:cc:references: from:in-reply-to:content-transfer-encoding; bh=dPtcah0OyDGwjZpZkbV34b0j98rPVMmEo0QNnYG6xIQ=; b=gd/rX94agg7iCCpYIlXDbZijqSYqAxbDSmlsKqJ2TM86J+1NCOo8Tp8t E+3iEwM7jdbCuCxmqO5at2queTIJGv7RCBUajOpnf49bARCzLW9uIKQRp 2BzbgeoHZiGIHrL9w0iicfN14StT3WqlYQBQW02gHBPndW+ls006fQBVl p55BooW1Si4put5fdRX/Q0gnee/fknw8DXt2Va7DVrxpqqZ/EGawwp/po aC7MaigkRDJWIMDqG2GRCcpWe/1QwYPRqCP7J8PqPUBe7LKRDSO1oCxqY NoczkHjJrnmgcz8g6IFTB03VZAz4KhRL9gW49jfYPNoqD2DACfKNUgIN8 A==; X-IronPort-AV: E=McAfee;i="6600,9927,10833"; a="358591072" X-IronPort-AV: E=Sophos;i="6.02,148,1688454000"; d="scan'208";a="358591072" Received: from fmsmga001.fm.intel.com ([10.253.24.23]) by fmsmga106.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Sep 2023 23:59:39 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=McAfee;i="6600,9927,10833"; a="888124710" X-IronPort-AV: E=Sophos;i="6.02,148,1688454000"; d="scan'208";a="888124710" Received: from xiaoyaol-hp-g830.ccr.corp.intel.com (HELO [10.93.29.154]) ([10.93.29.154]) by fmsmga001-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 14 Sep 2023 23:58:52 -0700 Message-ID: <17947d72-22fb-b600-aada-c5a4008e3995@intel.com> Date: Fri, 15 Sep 2023 14:59:23 +0800 MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Firefox/102.0 Thunderbird/102.15.1 Subject: Re: [RFC PATCH v12 06/33] KVM: Introduce KVM_SET_USER_MEMORY_REGION2 Content-Language: en-US To: Sean Christopherson , Paolo Bonzini , Marc Zyngier , Oliver Upton , Huacai Chen , Michael Ellerman , Anup Patel , Paul Walmsley , Palmer Dabbelt , Albert Ou , "Matthew Wilcox (Oracle)" , Andrew Morton , Paul Moore , James Morris , "Serge E. Hallyn" Cc: kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-mips@vger.kernel.org, linuxppc-dev@lists.ozlabs.org, kvm-riscv@lists.infradead.org, linux-riscv@lists.infradead.org, linux-fsdevel@vger.kernel.org, linux-mm@kvack.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, Chao Peng , Fuad Tabba , Jarkko Sakkinen , Anish Moorthy , Yu Zhang , Isaku Yamahata , Xu Yilun , Vlastimil Babka , Vishal Annapurve , Ackerley Tng , Maciej Szmigiero , David Hildenbrand , Quentin Perret , Michael Roth , Wang , Liam Merwick , Isaku Yamahata , "Kirill A . Shutemov" References: <20230914015531.1419405-1-seanjc@google.com> <20230914015531.1419405-7-seanjc@google.com> From: Xiaoyao Li In-Reply-To: <20230914015531.1419405-7-seanjc@google.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Rspam-User: X-Stat-Signature: t4icjqfmdtx5j1fuq9dzk5yut64cmmds X-Rspamd-Server: rspam07 X-Rspamd-Queue-Id: 7842440013 X-HE-Tag: 1694761182-564825 X-HE-Meta: U2FsdGVkX19dNHbAWNFk5OKxWsNhmM5l2hZMWRjdkw7E8pbr89j42hiqig35+9kDLJcxItCHVoh0TDaFl9BzQpPzlbViDbBqbSZL1mZQNnQtHqiF8FuK5BkKOdSSiSyuwrHpnZm+1jX7bapTmCGTO9a0J+G0m08MToaLrcBXhAEU9vVqHrqLvU6SDA2YiZWVGjHLSFE/cbYNgTuRqbvKBW25rTWwhWXZi5QiM3kiVzDlKcqL73ZF+iwO22NQgywU0wQIMi/Ac1QF8cW/ndVdlLSDYdmowQBkEr59F5VNlEgkBPlCPYRHvb2lDzYKGvEOydmwB0cOdRhrPuViX3gMWBZr/hciQuVslNpSUlSkj6dOB6Uhtrq2SA/DANJfpUCpKEufSuufj2RSlbPK8yqXMOWJZmvtHfHYQ8wLBvVOhaBXsibTYAoZc02Wkh57MRTIFMfrEuRdUg0+1f9vJO+DJzxw/aFljTdBw57RAJB2M6DWjdynOHtzA+s5sIOMPPveX93OLCxjcYcnyi1Kr583S270sDVb0AkRuhTcub+fMNRiJlBm/0Un9SqiWF/81PtzR1us65AsC71G05wPuIt4RcxeBEv1vzGyuKtmm/NgB15nbV1bn3ok7wahU6Ht/RTh4ZjF74s7ikH2pxIRDP3PAbO6hsL4HCveK6LNm0iPaQiuIHuevHgKUIccWPBr4ShRgWrUhZvxSeCCg7crfZIPpcVfTb/xccury34YpR36FqODOZflcun8rc29SSPTKLim29nODTdo6nkcVTS9H4EIQxJKUVeRTS6PI7AHW4wKQwnQsQOfSyR0F3L+Ckfwx4gm/FMY4Zy2Y8wK3O9i0DmRSfgOYTy4G45d0kYf0sz21Ssdck/d12AXDU30X79Un5scWIBqgSfZ29W+610Qlkm5QIxjzgNgphn88bdkH1+FcpaYnC17Afe3hUG/HH7/ny5GVHuWEDVxUm0cFD4KXTj eAAthyNZ XW65NSXeJ3apZXNVROmVNIMkzDH3pOMmr/4fnAmZStV5yt9SxRq+451tokQukQREd1chA0U0a/6iZ2KKJAP5CPaMfcE3GYmrQZgegsJcVzA521gYnLRVFKXybITdbAMwiX9ADxGfUMcUhbFyA+VTu2Iu8gF7XzkMMofEWxYS9BTX4PEf3r6dcbngCtq/e6n2FBJ3fU1ovamCz4yJGVX/xMpdVgTgfMOBDC1pJqtgjY5/SaAwuPGVGyNMpaMr0yXen937q5CmPFChfUeOaXRjOSKeFtD8bznEqZQnexdQePHXPRCe2KTWwHUxnb/woMX+vmOwz9ZZm+kK3XyD5NohaVd4zfShzFQZbACY3dPN4Rni0NyoojzJ5uQcwyH373GKeVtri8sh1E3AGjIU= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: On 9/14/2023 9:55 AM, Sean Christopherson wrote: > Introduce a "version 2" of KVM_SET_USER_MEMORY_REGION so that additional > information can be supplied without setting userspace up to fail. The > padding in the new kvm_userspace_memory_region2 structure will be used to > pass a file descriptor in addition to the userspace_addr, i.e. allow > userspace to point at a file descriptor and map memory into a guest that > is NOT mapped into host userspace. > > Alternatively, KVM could simply add "struct kvm_userspace_memory_region2" > without a new ioctl(), but as Paolo pointed out, adding a new ioctl() > makes detection of bad flags a bit more robust, e.g. if the new fd field > is guarded only by a flag and not a new ioctl(), then a userspace bug > (setting a "bad" flag) would generate out-of-bounds access instead of an > -EINVAL error. > > Cc: Jarkko Sakkinen > Reviewed-by: Paolo Bonzini Reviewed-by: Xiaoyao Li > Signed-off-by: Sean Christopherson > --- > arch/x86/kvm/x86.c | 2 +- > include/linux/kvm_host.h | 4 ++-- > include/uapi/linux/kvm.h | 13 +++++++++++++ > virt/kvm/kvm_main.c | 38 ++++++++++++++++++++++++++++++-------- > 4 files changed, 46 insertions(+), 11 deletions(-) > > diff --git a/arch/x86/kvm/x86.c b/arch/x86/kvm/x86.c > index 6c9c81e82e65..8356907079e1 100644 > --- a/arch/x86/kvm/x86.c > +++ b/arch/x86/kvm/x86.c > @@ -12447,7 +12447,7 @@ void __user * __x86_set_memory_region(struct kvm *kvm, int id, gpa_t gpa, > } > > for (i = 0; i < KVM_ADDRESS_SPACE_NUM; i++) { > - struct kvm_userspace_memory_region m; > + struct kvm_userspace_memory_region2 m; > > m.slot = id | (i << 16); > m.flags = 0; > diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h > index 5faba69403ac..4e741ff27af3 100644 > --- a/include/linux/kvm_host.h > +++ b/include/linux/kvm_host.h > @@ -1146,9 +1146,9 @@ enum kvm_mr_change { > }; > > int kvm_set_memory_region(struct kvm *kvm, > - const struct kvm_userspace_memory_region *mem); > + const struct kvm_userspace_memory_region2 *mem); > int __kvm_set_memory_region(struct kvm *kvm, > - const struct kvm_userspace_memory_region *mem); > + const struct kvm_userspace_memory_region2 *mem); > void kvm_arch_free_memslot(struct kvm *kvm, struct kvm_memory_slot *slot); > void kvm_arch_memslots_updated(struct kvm *kvm, u64 gen); > int kvm_arch_prepare_memory_region(struct kvm *kvm, > diff --git a/include/uapi/linux/kvm.h b/include/uapi/linux/kvm.h > index 13065dd96132..bd1abe067f28 100644 > --- a/include/uapi/linux/kvm.h > +++ b/include/uapi/linux/kvm.h > @@ -95,6 +95,16 @@ struct kvm_userspace_memory_region { > __u64 userspace_addr; /* start of the userspace allocated memory */ > }; > > +/* for KVM_SET_USER_MEMORY_REGION2 */ > +struct kvm_userspace_memory_region2 { > + __u32 slot; > + __u32 flags; > + __u64 guest_phys_addr; > + __u64 memory_size; > + __u64 userspace_addr; > + __u64 pad[16]; > +}; > + > /* > * The bit 0 ~ bit 15 of kvm_userspace_memory_region::flags are visible for > * userspace, other bits are reserved for kvm internal use which are defined > @@ -1192,6 +1202,7 @@ struct kvm_ppc_resize_hpt { > #define KVM_CAP_COUNTER_OFFSET 227 > #define KVM_CAP_ARM_EAGER_SPLIT_CHUNK_SIZE 228 > #define KVM_CAP_ARM_SUPPORTED_BLOCK_SIZES 229 > +#define KVM_CAP_USER_MEMORY2 230 > > #ifdef KVM_CAP_IRQ_ROUTING > > @@ -1473,6 +1484,8 @@ struct kvm_vfio_spapr_tce { > struct kvm_userspace_memory_region) > #define KVM_SET_TSS_ADDR _IO(KVMIO, 0x47) > #define KVM_SET_IDENTITY_MAP_ADDR _IOW(KVMIO, 0x48, __u64) > +#define KVM_SET_USER_MEMORY_REGION2 _IOW(KVMIO, 0x49, \ > + struct kvm_userspace_memory_region2) > > /* enable ucontrol for s390 */ > struct kvm_s390_ucas_mapping { > diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c > index 8d21757cd5e9..7c0e38752526 100644 > --- a/virt/kvm/kvm_main.c > +++ b/virt/kvm/kvm_main.c > @@ -1571,7 +1571,7 @@ static void kvm_replace_memslot(struct kvm *kvm, > } > } > > -static int check_memory_region_flags(const struct kvm_userspace_memory_region *mem) > +static int check_memory_region_flags(const struct kvm_userspace_memory_region2 *mem) > { > u32 valid_flags = KVM_MEM_LOG_DIRTY_PAGES; > > @@ -1973,7 +1973,7 @@ static bool kvm_check_memslot_overlap(struct kvm_memslots *slots, int id, > * Must be called holding kvm->slots_lock for write. > */ > int __kvm_set_memory_region(struct kvm *kvm, > - const struct kvm_userspace_memory_region *mem) > + const struct kvm_userspace_memory_region2 *mem) > { > struct kvm_memory_slot *old, *new; > struct kvm_memslots *slots; > @@ -2077,7 +2077,7 @@ int __kvm_set_memory_region(struct kvm *kvm, > EXPORT_SYMBOL_GPL(__kvm_set_memory_region); > > int kvm_set_memory_region(struct kvm *kvm, > - const struct kvm_userspace_memory_region *mem) > + const struct kvm_userspace_memory_region2 *mem) > { > int r; > > @@ -2089,7 +2089,7 @@ int kvm_set_memory_region(struct kvm *kvm, > EXPORT_SYMBOL_GPL(kvm_set_memory_region); > > static int kvm_vm_ioctl_set_memory_region(struct kvm *kvm, > - struct kvm_userspace_memory_region *mem) > + struct kvm_userspace_memory_region2 *mem) > { > if ((u16)mem->slot >= KVM_USER_MEM_SLOTS) > return -EINVAL; > @@ -4559,6 +4559,7 @@ static int kvm_vm_ioctl_check_extension_generic(struct kvm *kvm, long arg) > { > switch (arg) { > case KVM_CAP_USER_MEMORY: > + case KVM_CAP_USER_MEMORY2: > case KVM_CAP_DESTROY_MEMORY_REGION_WORKS: > case KVM_CAP_JOIN_MEMORY_REGIONS_WORKS: > case KVM_CAP_INTERNAL_ERROR_DATA: > @@ -4814,6 +4815,14 @@ static int kvm_vm_ioctl_get_stats_fd(struct kvm *kvm) > return fd; > } > > +#define SANITY_CHECK_MEM_REGION_FIELD(field) \ > +do { \ > + BUILD_BUG_ON(offsetof(struct kvm_userspace_memory_region, field) != \ > + offsetof(struct kvm_userspace_memory_region2, field)); \ > + BUILD_BUG_ON(sizeof_field(struct kvm_userspace_memory_region, field) != \ > + sizeof_field(struct kvm_userspace_memory_region2, field)); \ > +} while (0) > + > static long kvm_vm_ioctl(struct file *filp, > unsigned int ioctl, unsigned long arg) > { > @@ -4836,15 +4845,28 @@ static long kvm_vm_ioctl(struct file *filp, > r = kvm_vm_ioctl_enable_cap_generic(kvm, &cap); > break; > } > + case KVM_SET_USER_MEMORY_REGION2: > case KVM_SET_USER_MEMORY_REGION: { > - struct kvm_userspace_memory_region kvm_userspace_mem; > + struct kvm_userspace_memory_region2 mem; > + unsigned long size; > + > + if (ioctl == KVM_SET_USER_MEMORY_REGION) > + size = sizeof(struct kvm_userspace_memory_region); > + else > + size = sizeof(struct kvm_userspace_memory_region2); > + > + /* Ensure the common parts of the two structs are identical. */ > + SANITY_CHECK_MEM_REGION_FIELD(slot); > + SANITY_CHECK_MEM_REGION_FIELD(flags); > + SANITY_CHECK_MEM_REGION_FIELD(guest_phys_addr); > + SANITY_CHECK_MEM_REGION_FIELD(memory_size); > + SANITY_CHECK_MEM_REGION_FIELD(userspace_addr); > > r = -EFAULT; > - if (copy_from_user(&kvm_userspace_mem, argp, > - sizeof(kvm_userspace_mem))) > + if (copy_from_user(&mem, argp, size)) > goto out; > > - r = kvm_vm_ioctl_set_memory_region(kvm, &kvm_userspace_mem); > + r = kvm_vm_ioctl_set_memory_region(kvm, &mem); > break; > } > case KVM_GET_DIRTY_LOG: {