From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0BE29C54ED1 for ; Tue, 27 May 2025 18:03:20 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id CCFB76B009F; Tue, 27 May 2025 14:03:10 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id CA7E96B00A0; Tue, 27 May 2025 14:03:10 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id B96BC6B00A1; Tue, 27 May 2025 14:03:10 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0011.hostedemail.com [216.40.44.11]) by kanga.kvack.org (Postfix) with ESMTP id 990476B009F for ; Tue, 27 May 2025 14:03:10 -0400 (EDT) Received: from smtpin01.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay04.hostedemail.com (Postfix) with ESMTP id 602CD1A132A for ; Tue, 27 May 2025 18:03:10 +0000 (UTC) X-FDA: 83489459340.01.A79E980 Received: from mail-wm1-f73.google.com (mail-wm1-f73.google.com [209.85.128.73]) by imf11.hostedemail.com (Postfix) with ESMTP id 8AA2240003 for ; Tue, 27 May 2025 18:03:08 +0000 (UTC) Authentication-Results: imf11.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=wRnDHODu; spf=pass (imf11.hostedemail.com: domain of 3W_41aAUKCHgpWXXWckkcha.Ykihejqt-iigrWYg.knc@flex--tabba.bounces.google.com designates 209.85.128.73 as permitted sender) smtp.mailfrom=3W_41aAUKCHgpWXXWckkcha.Ykihejqt-iigrWYg.knc@flex--tabba.bounces.google.com; dmarc=pass (policy=reject) header.from=google.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1748368988; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=AHMe2ivL10UxaXIME2XPKI1qy/qjD/O9SD6HXriTp0g=; b=b2eCbhjrvjvgQZcVt/HYXIxNwWXuVvDpe1CgOyR3RB6+39zYcBH2KNXY/5uQokbjNMflf7 bGTSgObCaayZKaRbtteC5ffHgaTTwC/JHeurdZNKv7ZdI8pw9NHznSGYeKwmUo7eLsiKJR YeBa4SjZqLnRjjmq7iNadkmdk8ZlBO8= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1748368988; a=rsa-sha256; cv=none; b=m8uYUhWsMqF5cZZeHqmzRjJan2q1kLHImNaTGOg6Mx4vXCMYNLiRtmiXXn8R4SMcMKsIiH G/WYxbaP+evDDf+BtxHDPjvWa2zovVLy7x9QSSPdbMf8NRNExyJ9oDv5wpusJMCNdv5ply ooB22PiLKQ3cxZdPI8mtd7nkwerpVVk= ARC-Authentication-Results: i=1; imf11.hostedemail.com; dkim=pass header.d=google.com header.s=20230601 header.b=wRnDHODu; spf=pass (imf11.hostedemail.com: domain of 3W_41aAUKCHgpWXXWckkcha.Ykihejqt-iigrWYg.knc@flex--tabba.bounces.google.com designates 209.85.128.73 as permitted sender) smtp.mailfrom=3W_41aAUKCHgpWXXWckkcha.Ykihejqt-iigrWYg.knc@flex--tabba.bounces.google.com; dmarc=pass (policy=reject) header.from=google.com Received: by mail-wm1-f73.google.com with SMTP id 5b1f17b1804b1-43d4d15058dso27584545e9.0 for ; Tue, 27 May 2025 11:03:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1748368987; x=1748973787; darn=kvack.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:from:to:cc:subject:date:message-id:reply-to; bh=AHMe2ivL10UxaXIME2XPKI1qy/qjD/O9SD6HXriTp0g=; b=wRnDHODusdLUx9yev5tZPvh6bUDEw1FVmp7dv5zWrohnLfd16bXEfaWLr8D78SIlC3 /kuAwaDBl7ZuhPa8t79bMEXEiZIfBeEPjRggGDQcrUiZHd1/7FYcs7MMm1Y55ExlAlog O2Zz2AH4jefVDi028gB9ckAQwqH58fnHqgntVjxwAJJgRY8UdBf4Hp5keYHOwdAtuAcc oTvtyfDHTmi5FVSVTH8xbidpMSIi8lRdOP3XrsunWiT9KW5hIrcNKr4Arv/C4lQoTQoG VCVxnqeRkAUAjQYRkwcKzZddAJAla6EBlIf8vX7VyYtOQHHEGbhfutrGTE1NB9Fm3wXf 17fQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1748368987; x=1748973787; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=AHMe2ivL10UxaXIME2XPKI1qy/qjD/O9SD6HXriTp0g=; b=aiiPcwbJ92ddL1vdVPNbeGIluf6EndAXkfVIYtDe2F5iwEgYIjhiMPhKaFTk2C3TEB IJIF2IC3LAd6MFPnjrcBF3GSan5tMV3I7k4cmMpSUbE3HZzAoTSEdYFs8VsiD843d1JJ bwI+tbmIY/ELbzb7nshuFY7YJuz701pIqnv1VIPfH0Qj5e02ZpQu5amviAmjjq7qG3Zo UnUxwF/aEbHDcUcMcHH+HX2RmLuGA31CagjH2fBSxN0lCL+WIt2Dw5TvJePws8hIoB4u Yqm251snkKgX6aZ/PxSvtOU8HJgT7VlviXtqjSb980GEAseJSkrCIfMLvvU4DHmWjjQx 6fRg== X-Forwarded-Encrypted: i=1; AJvYcCWQ50/VWOng8KoAvwbdkfJOBFqJXwFd8ce1kndwH/gHb0/McW7Ez066ZG+gzp9LafeK5H32B2wycg==@kvack.org X-Gm-Message-State: AOJu0YxhwacE6EH2/mtYXJySDpmIiOVuRlukfgLGZLaZy1xTTY6kOq6I cH0AYVMt1MJCgjCz3jUEdYFmqbYP1cOsbj621pEcKltZg2q9/TJfLT0DXR22F0qB6nP56GvlUqv aSg== X-Google-Smtp-Source: AGHT+IEKYiZEDz0prHFVSs9gInuvUtJLkC94yEGH1e3gdJ5/OHkOpkzRY2s3mFtBGtEiZnGp3d719P4v5Q== X-Received: from wmben7.prod.google.com ([2002:a05:600c:8287:b0:445:1cd2:5e5f]) (user=tabba job=prod-delivery.src-stubby-dispatcher) by 2002:a05:600c:35d3:b0:43d:47b7:b32d with SMTP id 5b1f17b1804b1-44c92f21eafmr120874665e9.25.1748368987086; Tue, 27 May 2025 11:03:07 -0700 (PDT) Date: Tue, 27 May 2025 19:02:39 +0100 In-Reply-To: <20250527180245.1413463-1-tabba@google.com> Mime-Version: 1.0 References: <20250527180245.1413463-1-tabba@google.com> X-Mailer: git-send-email 2.49.0.1164.gab81da1b16-goog Message-ID: <20250527180245.1413463-11-tabba@google.com> Subject: [PATCH v10 10/16] KVM: x86/mmu: Handle guest page faults for guest_memfd with shared memory From: Fuad Tabba To: kvm@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-mm@kvack.org Cc: pbonzini@redhat.com, chenhuacai@kernel.org, mpe@ellerman.id.au, anup@brainfault.org, paul.walmsley@sifive.com, palmer@dabbelt.com, aou@eecs.berkeley.edu, seanjc@google.com, viro@zeniv.linux.org.uk, brauner@kernel.org, willy@infradead.org, akpm@linux-foundation.org, xiaoyao.li@intel.com, yilun.xu@intel.com, chao.p.peng@linux.intel.com, jarkko@kernel.org, amoorthy@google.com, dmatlack@google.com, isaku.yamahata@intel.com, mic@digikod.net, vbabka@suse.cz, vannapurve@google.com, ackerleytng@google.com, mail@maciej.szmigiero.name, david@redhat.com, michael.roth@amd.com, wei.w.wang@intel.com, liam.merwick@oracle.com, isaku.yamahata@gmail.com, kirill.shutemov@linux.intel.com, suzuki.poulose@arm.com, steven.price@arm.com, quic_eberman@quicinc.com, quic_mnalajal@quicinc.com, quic_tsoni@quicinc.com, quic_svaddagi@quicinc.com, quic_cvanscha@quicinc.com, quic_pderrin@quicinc.com, quic_pheragu@quicinc.com, catalin.marinas@arm.com, james.morse@arm.com, yuzenghui@huawei.com, oliver.upton@linux.dev, maz@kernel.org, will@kernel.org, qperret@google.com, keirf@google.com, roypat@amazon.co.uk, shuah@kernel.org, hch@infradead.org, jgg@nvidia.com, rientjes@google.com, jhubbard@nvidia.com, fvdl@google.com, hughd@google.com, jthoughton@google.com, peterx@redhat.com, pankaj.gupta@amd.com, ira.weiny@intel.com, tabba@google.com Content-Type: text/plain; charset="UTF-8" X-Rspamd-Server: rspam06 X-Rspamd-Queue-Id: 8AA2240003 X-Stat-Signature: iraerhohh871q67x48aa6tkbgukqu4no X-Rspam-User: X-HE-Tag: 1748368988-643924 X-HE-Meta: U2FsdGVkX19S55LZqAAbnD/d4LsxOfX9HMHUriMD5ZxbTzceNNeL1OC+Uqwa0k4qEyqukng4UGt30MJOC+TrtmRGkNMwR+fCh54788dTLt/aCIEwKpHYShm//8t4t+u0evAjY63LRXUZ0BBe4D2H9nBXXfgwDZxsOq+OZETC9FLLV6oVrHjYZhWuKYCz8z8qJId1JhQCHG8l2DQ0yjSYuwaw7RXc4EmM14+ntLa0od/6hpUhFXLbkLXQJ3KSWby3SyiWUKkkDe0ABv749kVaU6KwYCLmLo2h1/Tyj3eUhsNtMmoXQEm7Yf2Twr0566+RDAHeZbWbRfkLRf2qblX0ErBSwcacVHDZmd9TTehfVdxzLkDx1cG7bJQGFqL6Jr2vT45lq6O5To7UtNKE3/XjpuWupzT2ldsXyqJQzCs0wS7XBRaJ9sSDZOzwiU3ODjFfnAl6c9Le6TktMeRyLrm7KVudXlPaMVNhV6lku+vMIZF8HsjAI9bxFVpgivtOv2F6Jk9erC1Zu26GwEXNaH5DvVDJDB+c8zkEY9M22dBSVZVdkjzILbcFelNtGcOH6Q3+fu5cHTySTkkH8mEKTEQs+Z763UXFpEF3ymFTsqB9YnXIB5x6TTvdMYl70aH7bpw8Dh+1BiutIYA13gkhMRcbvcb2GUZHpzM9sqTAupMa/BkdcFBOTcI0Z7QJ+72gtJan9x5VZ/JGBDz3aRNWJoFK4KfLgQvtyEzrnrOBpu2/7FWPP0r1bK8aAlqAS+D7ZDSpobVhf/L6GRRtUelRLYMGGs0LCmgVuGeSLWR8c/2CBy/W173Fe+y1QCeZzOPZ5ApVxGZ5eYWh09nFkcG6VrAcpB7VO2U8EI3WH296qs0olal20sZfBQU2p8hiEQd3Oldag71ObE4EuSexp9Q9HD4jTi4dnLl2iQXKxowacn+95L8XcgN6R6SzM/rHRLzrNjmruxDw1js1x4N59igyXVR 6miXjJin 9xMtjMuP5ueTKG/YrGFVSbXF3bsOFPzPeLBzch+nrTxbRYFvMn81cW8UUUs8BwLJMFxqbIWuoGTUK2ePCmgvd/6EhBofZrvJthXofb1t4F08sfPfQx10AzEp14gkj78g/fLgAtSvLNw9bfjH0T/rFTZQlx9BMJ7h+3OvzoqLU9JCh6kMXSFxBl+q3IWjIVZUBwt3vzbuCrJojH7JHZBV5WGo3r0oVXre3TL19lom2ZGDYThlFjMORHT0478z886XaGFvj5pYVhmOCud346NNE6qwa2/obQgcFgPYpb5fxAroFabdfp/Jl4U79Y0mlBFRWLj+zz0MLzH5etZye/ghpfIiMQzlE7NFx+H/jG8I4+QQQWw0U4ugej1kzI3sHdSkxpNpQCfcUYmTXw2g4LyJLYtbUNL4gLuCMlQXMqylWUs/Es+z1iCyUfXRtddBrYloy5ZUGe9zMOEWi2Yv+CtYmMfY0gkBPwgCEeFFiNnZ8kC4wXvhU+iVWXwz0vOYgVqoOFZ1eQ2QLd+Fgg1iv8UfH44IpQDFegwBOrZzWMRv4Cga4No9d4FbVjdO/kQZdQlbcpmMU63AQPXKWIg+oRw4gNKRiyQkO+hdvW9raHNVCt9kbz+G6CuIK/IL46CsyNAnvmuPh+30R5AdkE+D2GFV/mp55U5OqzPiDjKm3ofLKiwiUfXY= X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: From: Ackerley Tng For memslots backed by guest_memfd with shared mem support, the KVM MMU always faults-in pages from guest_memfd, and not from the userspace_addr. Function names have also been updated for accuracy - kvm_mem_is_private() returns true only when the current private/shared state (in the CoCo sense) of the memory is private, and returns false if the current state is shared explicitly or impicitly, e.g., belongs to a non-CoCo VM. kvm_mmu_faultin_pfn_gmem() is updated to indicate that it can be used to fault in not just private memory, but more generally, from guest_memfd. Co-developed-by: Fuad Tabba Signed-off-by: Fuad Tabba Co-developed-by: David Hildenbrand Signed-off-by: David Hildenbrand Signed-off-by: Ackerley Tng --- arch/x86/kvm/mmu/mmu.c | 38 +++++++++++++++++++++++--------------- include/linux/kvm_host.h | 25 +++++++++++++++++++++++-- 2 files changed, 46 insertions(+), 17 deletions(-) diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 2b6376986f96..5b7df2905aa9 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -3289,6 +3289,11 @@ int kvm_mmu_max_mapping_level(struct kvm *kvm, return __kvm_mmu_max_mapping_level(kvm, slot, gfn, PG_LEVEL_NUM, is_private); } +static inline bool fault_from_gmem(struct kvm_page_fault *fault) +{ + return fault->is_private || kvm_gmem_memslot_supports_shared(fault->slot); +} + void kvm_mmu_hugepage_adjust(struct kvm_vcpu *vcpu, struct kvm_page_fault *fault) { struct kvm_memory_slot *slot = fault->slot; @@ -4465,21 +4470,25 @@ static inline u8 kvm_max_level_for_order(int order) return PG_LEVEL_4K; } -static u8 kvm_max_private_mapping_level(struct kvm *kvm, kvm_pfn_t pfn, - u8 max_level, int gmem_order) +static u8 kvm_max_level_for_fault_and_order(struct kvm *kvm, + struct kvm_page_fault *fault, + int order) { - u8 req_max_level; + u8 max_level = fault->max_level; if (max_level == PG_LEVEL_4K) return PG_LEVEL_4K; - max_level = min(kvm_max_level_for_order(gmem_order), max_level); + max_level = min(kvm_max_level_for_order(order), max_level); if (max_level == PG_LEVEL_4K) return PG_LEVEL_4K; - req_max_level = kvm_x86_call(private_max_mapping_level)(kvm, pfn); - if (req_max_level) - max_level = min(max_level, req_max_level); + if (fault->is_private) { + u8 level = kvm_x86_call(private_max_mapping_level)(kvm, fault->pfn); + + if (level) + max_level = min(max_level, level); + } return max_level; } @@ -4491,10 +4500,10 @@ static void kvm_mmu_finish_page_fault(struct kvm_vcpu *vcpu, r == RET_PF_RETRY, fault->map_writable); } -static int kvm_mmu_faultin_pfn_private(struct kvm_vcpu *vcpu, - struct kvm_page_fault *fault) +static int kvm_mmu_faultin_pfn_gmem(struct kvm_vcpu *vcpu, + struct kvm_page_fault *fault) { - int max_order, r; + int gmem_order, r; if (!kvm_slot_has_gmem(fault->slot)) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); @@ -4502,15 +4511,14 @@ static int kvm_mmu_faultin_pfn_private(struct kvm_vcpu *vcpu, } r = kvm_gmem_get_pfn(vcpu->kvm, fault->slot, fault->gfn, &fault->pfn, - &fault->refcounted_page, &max_order); + &fault->refcounted_page, &gmem_order); if (r) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); return r; } fault->map_writable = !(fault->slot->flags & KVM_MEM_READONLY); - fault->max_level = kvm_max_private_mapping_level(vcpu->kvm, fault->pfn, - fault->max_level, max_order); + fault->max_level = kvm_max_level_for_fault_and_order(vcpu->kvm, fault, gmem_order); return RET_PF_CONTINUE; } @@ -4520,8 +4528,8 @@ static int __kvm_mmu_faultin_pfn(struct kvm_vcpu *vcpu, { unsigned int foll = fault->write ? FOLL_WRITE : 0; - if (fault->is_private) - return kvm_mmu_faultin_pfn_private(vcpu, fault); + if (fault_from_gmem(fault)) + return kvm_mmu_faultin_pfn_gmem(vcpu, fault); foll |= FOLL_NOWAIT; fault->pfn = __kvm_faultin_pfn(fault->slot, fault->gfn, foll, diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h index edb3795a64b9..b1786ef6d8ea 100644 --- a/include/linux/kvm_host.h +++ b/include/linux/kvm_host.h @@ -2524,10 +2524,31 @@ bool kvm_arch_pre_set_memory_attributes(struct kvm *kvm, bool kvm_arch_post_set_memory_attributes(struct kvm *kvm, struct kvm_gfn_range *range); +/* + * Returns true if the given gfn's private/shared status (in the CoCo sense) is + * private. + * + * A return value of false indicates that the gfn is explicitly or implicitly + * shared (i.e., non-CoCo VMs). + */ static inline bool kvm_mem_is_private(struct kvm *kvm, gfn_t gfn) { - return IS_ENABLED(CONFIG_KVM_GMEM) && - kvm_get_memory_attributes(kvm, gfn) & KVM_MEMORY_ATTRIBUTE_PRIVATE; + struct kvm_memory_slot *slot; + + if (!IS_ENABLED(CONFIG_KVM_GMEM)) + return false; + + slot = gfn_to_memslot(kvm, gfn); + if (kvm_slot_has_gmem(slot) && kvm_gmem_memslot_supports_shared(slot)) { + /* + * Without in-place conversion support, if a guest_memfd memslot + * supports shared memory, then all the slot's memory is + * considered not private, i.e., implicitly shared. + */ + return false; + } + + return kvm_get_memory_attributes(kvm, gfn) & KVM_MEMORY_ATTRIBUTE_PRIVATE; } #else static inline bool kvm_mem_is_private(struct kvm *kvm, gfn_t gfn) -- 2.49.0.1164.gab81da1b16-goog