Linux-mm Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: "Brendan Jackman" <brendan.jackman@linux.dev>
To: "Mike Rapoport" <rppt@kernel.org>, "Yosry Ahmed" <yosry@kernel.org>
Cc: "Brendan Jackman" <jackmanb@google.com>,
	"Borislav Petkov" <bp@alien8.de>,
	"Dave Hansen" <dave.hansen@linux.intel.com>,
	"Peter Zijlstra" <peterz@infradead.org>,
	"Andrew Morton" <akpm@linux-foundation.org>,
	"David Hildenbrand" <david@kernel.org>,
	"Vlastimil Babka" <vbabka@kernel.org>,
	"Wei Xu" <weixugc@google.com>,
	"Johannes Weiner" <hannes@cmpxchg.org>, "Zi Yan" <ziy@nvidia.com>,
	"Lorenzo Stoakes" <ljs@kernel.org>, <linux-mm@kvack.org>,
	<linux-kernel@vger.kernel.org>, <x86@kernel.org>,
	"Sumit Garg" <sumit.garg@oss.qualcomm.com>,
	"Will Deacon" <will@kernel.org>, <rientjes@google.com>,
	"Kalyazin, Nikita" <kalyazin@amazon.co.uk>,
	<patrick.roy@linux.dev>,
	"Itazuri, Takahiro" <itazur@amazon.co.uk>,
	"Andy Lutomirski" <luto@kernel.org>,
	"David Kaplan" <david.kaplan@amd.com>,
	"Thomas Gleixner" <tglx@kernel.org>,
	"Patrick Bellasi" <derkling@google.com>,
	"Reiji Watanabe" <reijiw@google.com>,
	"Sean Christopherson" <seanjc@google.com>,
	"Nikita Kalyazin" <nikita.kalyazin@linux.dev>
Subject: Re: [PATCH v3 01/26] set_memory: add folio_{zap,restore}_direct_map helpers
Date: Fri, 31 Jul 2026 11:57:33 +0000	[thread overview]
Message-ID: <DKCQL9KO4PD1.27SYU4GD2NH8Y@linux.dev> (raw)
In-Reply-To: <amwwwe4eYeXtniFu@kernel.org>

On Fri Jul 31, 2026 at 5:21 AM UTC, Mike Rapoport wrote:
> On Thu, Jul 30, 2026 at 08:34:57PM +0000, Yosry Ahmed wrote:
>> On Sun, Jul 26, 2026 at 10:22:34PM +0000, Brendan Jackman wrote:
>> > From: Nikita Kalyazin <nikita.kalyazin@linux.dev>
>> > 
>> > Let's provide folio_{zap,restore}_direct_map helpers as preparation for
>> > supporting removal of the direct map for guest_memfd folios.
>> > In folio_zap_direct_map(), flush TLB to make sure the data is not
>> > accessible.  On some architectures, there may be a double TLB flush
>> > issued because set_direct_map_valid_noflush already performs a flush
>> > internally.
>> > 
>> > The new helpers need to be accessible to KVM on architectures that
>> > support guest_memfd (x86 and arm64).
>> > 
>> > Direct map removal gives guest_memfd the same protection that
>> > memfd_secret does, such as hardening against Spectre-like attacks
>> > through in-kernel gadgets.
>> > 
>> > Acked-by: David Hildenbrand (Arm) <david@kernel.org>
>> > Signed-off-by: Nikita Kalyazin <nikita.kalyazin@linux.dev>
>> > [Added comment, dropped modified set_direct_map API, added highmem check]
>> > Signed-off-by: Brendan Jackman <jackmanb@google.com>
>> > ---
>> >  include/linux/set_memory.h | 13 +++++++++++++
>> >  mm/memory.c                | 46 ++++++++++++++++++++++++++++++++++++++++++++++
>> >  2 files changed, 59 insertions(+)
>> > 
>> > diff --git a/include/linux/set_memory.h b/include/linux/set_memory.h
>> > index 3030d9245f5ac..1bf2a15bca118 100644
>> > --- a/include/linux/set_memory.h
>> > +++ b/include/linux/set_memory.h
>> > @@ -40,6 +40,15 @@ static inline int set_direct_map_valid_noflush(struct page *page,
>> >  	return 0;
>> >  }
>> >  
>> > +static inline int folio_zap_direct_map(struct folio *folio)
>> > +{
>> > +	return 0;
>> 
>> Should this return an error (e.g. -EOPNOTSUPP)? Seems like it would
>> silently succeed if the arch doesn't actually support removing from the
>> direct map.
>
> That's the pattern we have now for all set_memory APIs.

Yeah. And I think that's fine, the risk of silent failure is mitigated
by:

#define can_set_direct_map() false

So yes code could call folio_zap_direct_map() directly and get
confusing results on unsupported configs, but that code would be broken
on arm64 regardless (coz it didn't respect can_set_direct_map()), plus
later in this series is:

#ifdef CONFIG_PAGE_ALLOC_UNMAPPED
#define ALLOC_UNMAPPED	       0x2000
#endif

So higher-level code will fail to compile it if uses ALLOC_UNMAPPED on a
completely unsupported config.


  reply	other threads:[~2026-07-31 11:58 UTC|newest]

Thread overview: 40+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-26 22:22 [PATCH v3 00/26] mm: Add ALLOC_UNMAPPED and AS_NO_DIRECT_MAP Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 01/26] set_memory: add folio_{zap,restore}_direct_map helpers Brendan Jackman
2026-07-27 10:33   ` Mike Rapoport
2026-07-29 11:42     ` Brendan Jackman
2026-07-30 20:34   ` Yosry Ahmed
2026-07-31  5:21     ` Mike Rapoport
2026-07-31 11:57       ` Brendan Jackman [this message]
2026-07-26 22:22 ` [PATCH v3 02/26] mm/secretmem: make use of folio_{zap,restore}_direct_map Brendan Jackman
2026-07-27 10:40   ` Mike Rapoport
2026-07-26 22:22 ` [PATCH v3 03/26] mm: introduce AS_NO_DIRECT_MAP Brendan Jackman
2026-07-30 21:06   ` Yosry Ahmed
2026-07-31 12:15     ` Brendan Jackman
2026-07-31 19:28       ` Yosry Ahmed
2026-07-26 22:22 ` [PATCH v3 04/26] x86/mm: split out preallocate_sub_pgd() Brendan Jackman
2026-07-31 22:10   ` Yosry Ahmed
2026-07-26 22:22 ` [PATCH v3 05/26] x86: move PAE PMD preallocation defines to header Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 06/26] x86/tlb: Expose some flush function declarations to modules Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 07/26] x86/mm: introduce mm-local region Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 08/26] x86/mm: move LDT remap into " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 09/26] mm: Create flags arg for __apply_to_page_range() Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 10/26] mm: Add more flags " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 11/26] x86/mm: introduce the mermap Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 12/26] mm: KUnit tests for " Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 13/26] mm: introduce freetype_t Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 14/26] mm: move migratetype definitions to freetype.h Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 15/26] mm/page_alloc: add support for freetypes with no freelist Brendan Jackman
2026-07-31 14:13   ` Vlastimil Babka (SUSE)
2026-07-26 22:22 ` [PATCH v3 16/26] mm: add definitions for allocating unmapped pages Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 17/26] mm: encode freetype flags in pageblock flags Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 18/26] mm/page_alloc: separate pcplists by freetype flags Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 19/26] mm/page_alloc: rename ALLOC_NON_BLOCK back to _HARDER Brendan Jackman
2026-07-31 14:52   ` Vlastimil Babka (SUSE)
2026-07-26 22:22 ` [PATCH v3 20/26] mm/page_alloc: introduce ALLOC_NOBLOCK Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 21/26] mm/page_alloc: implement FREETYPE_UNMAPPED allocations Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 22/26] mm: Minimal KUnit tests for some new page_alloc logic Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 23/26] mm: Split out NR_FREE_PAGES_BLOCKS_[UN]MAPPED Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 24/26] mm/page_alloc: always direct compact for unmapped allocs Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 25/26] mm: plumb alloc flags into some alloc funcs Brendan Jackman
2026-07-26 22:22 ` [PATCH v3 26/26] mm: add fast path for AS_NO_DIRECT_MAP Brendan Jackman
2026-07-29 11:52 ` [PATCH v3 00/26] mm: Add ALLOC_UNMAPPED and AS_NO_DIRECT_MAP Brendan Jackman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=DKCQL9KO4PD1.27SYU4GD2NH8Y@linux.dev \
    --to=brendan.jackman@linux.dev \
    --cc=akpm@linux-foundation.org \
    --cc=bp@alien8.de \
    --cc=dave.hansen@linux.intel.com \
    --cc=david.kaplan@amd.com \
    --cc=david@kernel.org \
    --cc=derkling@google.com \
    --cc=hannes@cmpxchg.org \
    --cc=itazur@amazon.co.uk \
    --cc=jackmanb@google.com \
    --cc=kalyazin@amazon.co.uk \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mm@kvack.org \
    --cc=ljs@kernel.org \
    --cc=luto@kernel.org \
    --cc=nikita.kalyazin@linux.dev \
    --cc=patrick.roy@linux.dev \
    --cc=peterz@infradead.org \
    --cc=reijiw@google.com \
    --cc=rientjes@google.com \
    --cc=rppt@kernel.org \
    --cc=seanjc@google.com \
    --cc=sumit.garg@oss.qualcomm.com \
    --cc=tglx@kernel.org \
    --cc=vbabka@kernel.org \
    --cc=weixugc@google.com \
    --cc=will@kernel.org \
    --cc=x86@kernel.org \
    --cc=yosry@kernel.org \
    --cc=ziy@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox