public inbox for linux-s390@vger.kernel.org
 help / color / mirror / Atom feed
From: Claudio Imbrenda <imbrenda@linux.ibm.com>
To: kvm@vger.kernel.org
Cc: linux-kernel@vger.kernel.org, linux-s390@vger.kernel.org,
	borntraeger@de.ibm.com, frankja@linux.ibm.com, nsg@linux.ibm.com,
	nrb@linux.ibm.com, seiden@linux.ibm.com, gra@linux.ibm.com,
	schlameuss@linux.ibm.com, hca@linux.ibm.com, svens@linux.ibm.com,
	agordeev@linux.ibm.com, gor@linux.ibm.com, david@redhat.com,
	gerald.schaefer@linux.ibm.com
Subject: [PATCH v6 28/28] KVM: s390: Storage key manipulation IOCTL
Date: Mon, 22 Dec 2025 17:50:33 +0100	[thread overview]
Message-ID: <20251222165033.162329-29-imbrenda@linux.ibm.com> (raw)
In-Reply-To: <20251222165033.162329-1-imbrenda@linux.ibm.com>

Add a new IOCTL to allow userspace to manipulate storage keys directly.

This will make it easier to write selftests related to storage keys.

Signed-off-by: Claudio Imbrenda <imbrenda@linux.ibm.com>
---
 arch/s390/kvm/kvm-s390.c | 57 ++++++++++++++++++++++++++++++++++++++++
 include/uapi/linux/kvm.h | 10 +++++++
 2 files changed, 67 insertions(+)

diff --git a/arch/s390/kvm/kvm-s390.c b/arch/s390/kvm/kvm-s390.c
index 47f2794af2fb..7f28b556b460 100644
--- a/arch/s390/kvm/kvm-s390.c
+++ b/arch/s390/kvm/kvm-s390.c
@@ -554,6 +554,37 @@ static void __kvm_s390_exit(void)
 	debug_unregister(kvm_s390_dbf_uv);
 }
 
+static int kvm_s390_keyop(struct kvm_s390_mmu_cache *mc, struct kvm *kvm, int op,
+			  unsigned long addr, union skey skey)
+{
+	union asce asce = kvm->arch.gmap->asce;
+	gfn_t gfn = gpa_to_gfn(addr);
+	int r;
+
+	guard(read_lock)(&kvm->mmu_lock);
+
+	switch (op) {
+	case KVM_S390_KEYOP_SSKE:
+		r = dat_cond_set_storage_key(mc, asce, gfn, skey, &skey, 0, 0, 0);
+		if (r >= 0)
+			return skey.skey;
+		break;
+	case KVM_S390_KEYOP_ISKE:
+		r = dat_get_storage_key(asce, gfn, &skey);
+		if (!r)
+			return skey.skey;
+		break;
+	case KVM_S390_KEYOP_RRBE:
+		r = dat_reset_reference_bit(asce, gfn);
+		if (r > 0)
+			return r << 1;
+		break;
+	default:
+		return -EINVAL;
+	}
+	return r;
+}
+
 /* Section: device related */
 long kvm_arch_dev_ioctl(struct file *filp,
 			unsigned int ioctl, unsigned long arg)
@@ -2931,6 +2962,32 @@ int kvm_arch_vm_ioctl(struct file *filp, unsigned int ioctl, unsigned long arg)
 			r = -EFAULT;
 		break;
 	}
+	case KVM_S390_KEYOP: {
+		struct kvm_s390_mmu_cache *mc;
+		struct kvm_s390_keyop kop;
+		union skey skey;
+
+		if (copy_from_user(&kop, argp, sizeof(kop))) {
+			r = -EFAULT;
+			break;
+		}
+		skey.skey = kop.key;
+
+		mc = kvm_s390_new_mmu_cache();
+		if (!mc)
+			return -ENOMEM;
+
+		r = kvm_s390_keyop(mc, kvm, kop.operation, kop.user_addr, skey);
+		kvm_s390_free_mmu_cache(mc);
+		if (r < 0)
+			break;
+
+		kop.key = r;
+		r = 0;
+		if (copy_to_user(argp, &kop, sizeof(kop)))
+			r = -EFAULT;
+		break;
+	}
 	case KVM_S390_ZPCI_OP: {
 		struct kvm_s390_zpci_op args;
 
diff --git a/include/uapi/linux/kvm.h b/include/uapi/linux/kvm.h
index dddb781b0507..845417e56778 100644
--- a/include/uapi/linux/kvm.h
+++ b/include/uapi/linux/kvm.h
@@ -1219,6 +1219,15 @@ struct kvm_vfio_spapr_tce {
 	__s32	tablefd;
 };
 
+#define KVM_S390_KEYOP_SSKE 0x01
+#define KVM_S390_KEYOP_ISKE 0x02
+#define KVM_S390_KEYOP_RRBE 0x03
+struct kvm_s390_keyop {
+	__u64 user_addr;
+	__u8  key;
+	__u8  operation;
+};
+
 /*
  * KVM_CREATE_VCPU receives as a parameter the vcpu slot, and returns
  * a vcpu fd.
@@ -1238,6 +1247,7 @@ struct kvm_vfio_spapr_tce {
 #define KVM_S390_UCAS_MAP        _IOW(KVMIO, 0x50, struct kvm_s390_ucas_mapping)
 #define KVM_S390_UCAS_UNMAP      _IOW(KVMIO, 0x51, struct kvm_s390_ucas_mapping)
 #define KVM_S390_VCPU_FAULT	 _IOW(KVMIO, 0x52, unsigned long)
+#define KVM_S390_KEYOP           _IOWR(KVMIO, 0x53, struct kvm_s390_keyop)
 
 /* Device model IOC */
 #define KVM_CREATE_IRQCHIP        _IO(KVMIO,   0x60)
-- 
2.52.0


  parent reply	other threads:[~2025-12-22 16:51 UTC|newest]

Thread overview: 31+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-12-22 16:50 [PATCH v6 00/28] KVM: s390: gmap rewrite, the real deal Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 01/28] KVM: s390: Refactor pgste lock and unlock functions Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 02/28] KVM: s390: add P bit in table entry bitfields, move union vaddress Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 03/28] s390: Make UV folio operations work on whole folio Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 04/28] s390: Move sske_frame() to a header Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 05/28] KVM: s390: Add gmap_helper_set_unused() Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 06/28] KVM: s390: Introduce import_lock Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 07/28] KVM: s390: Export two functions Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 08/28] s390/mm: Warn if uv_convert_from_secure_pte() fails Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 09/28] KVM: s390: vsie: Pass gmap explicitly as parameter Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 10/28] KVM: s390: Enable KVM_GENERIC_MMU_NOTIFIER Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 11/28] KVM: s390: Rename some functions in gaccess.c Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 12/28] KVM: s390: KVM-specific bitfields and helper functions Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 13/28] KVM: s390: KVM page table management functions: allocation Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 14/28] KVM: s390: KVM page table management functions: clear and replace Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 15/28] KVM: s390: KVM page table management functions: walks Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 16/28] KVM: s390: KVM page table management functions: storage keys Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 17/28] KVM: s390: KVM page table management functions: lifecycle management Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 18/28] KVM: s390: KVM page table management functions: CMMA Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 19/28] KVM: s390: New gmap code Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 20/28] KVM: s390: Add helper functions for fault handling Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 21/28] KVM: s390: Add some helper functions needed for vSIE Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 22/28] KVM: s390: Stop using CONFIG_PGSTE Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 23/28] KVM: s390: Storage key functions refactoring Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 24/28] KVM: s390: Switch to new gmap Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 25/28] KVM: s390: Remove gmap from s390/mm Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 26/28] KVM: S390: Remove PGSTE code from linux/s390 mm Claudio Imbrenda
2025-12-22 16:50 ` [PATCH v6 27/28] KVM: s390: Enable 1M pages for gmap Claudio Imbrenda
2025-12-22 16:50 ` Claudio Imbrenda [this message]
2026-01-14  9:33   ` [PATCH v6 28/28] KVM: s390: Storage key manipulation IOCTL Christoph Schlameuss
2026-01-14  9:53     ` Claudio Imbrenda

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251222165033.162329-29-imbrenda@linux.ibm.com \
    --to=imbrenda@linux.ibm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=borntraeger@de.ibm.com \
    --cc=david@redhat.com \
    --cc=frankja@linux.ibm.com \
    --cc=gerald.schaefer@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=gra@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=nrb@linux.ibm.com \
    --cc=nsg@linux.ibm.com \
    --cc=schlameuss@linux.ibm.com \
    --cc=seiden@linux.ibm.com \
    --cc=svens@linux.ibm.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox