The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Avi Kivity <avi@qumranet.com>
To: kvm@vger.kernel.org
Cc: linux-kernel@vger.kernel.org
Subject: [PATCH 13/50] KVM: MMU: Fix false flooding when a pte points to page table
Date: Thu, 26 Jun 2008 15:27:55 +0300	[thread overview]
Message-ID: <1214483312-9265-14-git-send-email-avi@qumranet.com> (raw)
In-Reply-To: <1214483312-9265-1-git-send-email-avi@qumranet.com>

The KVM MMU tries to detect when a speculative pte update is not actually
used by demand fault, by checking the accessed bit of the shadow pte.  If
the shadow pte has not been accessed, we deem that page table flooded and
remove the shadow page table, allowing further pte updates to proceed
without emulation.

However, if the pte itself points at a page table and only used for write
operations, the accessed bit will never be set since all access will happen
through the emulator.

This is exactly what happens with kscand on old (2.4.x) HIGHMEM kernels.
The kernel points a kmap_atomic() pte at a page table, and then
proceeds with read-modify-write operations to look at the dirty and accessed
bits.  We get a false flood trigger on the kmap ptes, which results in the
mmu spending all its time setting up and tearing down shadows.

Fix by setting the shadow accessed bit on emulated accesses.

Signed-off-by: Avi Kivity <avi@qumranet.com>
---
 arch/x86/kvm/mmu.c         |   17 ++++++++++++++++-
 arch/x86/kvm/mmu.h         |    3 ++-
 include/asm-x86/kvm_host.h |    1 +
 3 files changed, 19 insertions(+), 2 deletions(-)

diff --git a/arch/x86/kvm/mmu.c b/arch/x86/kvm/mmu.c
index 8e449db..53f1ed8 100644
--- a/arch/x86/kvm/mmu.c
+++ b/arch/x86/kvm/mmu.c
@@ -1122,8 +1122,10 @@ static void mmu_set_spte(struct kvm_vcpu *vcpu, u64 *shadow_pte,
 		else
 			kvm_release_pfn_clean(pfn);
 	}
-	if (!ptwrite || !*ptwrite)
+	if (speculative) {
 		vcpu->arch.last_pte_updated = shadow_pte;
+		vcpu->arch.last_pte_gfn = gfn;
+	}
 }
 
 static void nonpaging_new_cr3(struct kvm_vcpu *vcpu)
@@ -1671,6 +1673,18 @@ static void mmu_guess_page_from_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
 	vcpu->arch.update_pte.pfn = pfn;
 }
 
+static void kvm_mmu_access_page(struct kvm_vcpu *vcpu, gfn_t gfn)
+{
+	u64 *spte = vcpu->arch.last_pte_updated;
+
+	if (spte
+	    && vcpu->arch.last_pte_gfn == gfn
+	    && shadow_accessed_mask
+	    && !(*spte & shadow_accessed_mask)
+	    && is_shadow_present_pte(*spte))
+		set_bit(PT_ACCESSED_SHIFT, (unsigned long *)spte);
+}
+
 void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
 		       const u8 *new, int bytes)
 {
@@ -1694,6 +1708,7 @@ void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
 	pgprintk("%s: gpa %llx bytes %d\n", __func__, gpa, bytes);
 	mmu_guess_page_from_pte_write(vcpu, gpa, new, bytes);
 	spin_lock(&vcpu->kvm->mmu_lock);
+	kvm_mmu_access_page(vcpu, gfn);
 	kvm_mmu_free_some_pages(vcpu);
 	++vcpu->kvm->stat.mmu_pte_write;
 	kvm_mmu_audit(vcpu, "pre pte write");
diff --git a/arch/x86/kvm/mmu.h b/arch/x86/kvm/mmu.h
index 1730757..258e5d5 100644
--- a/arch/x86/kvm/mmu.h
+++ b/arch/x86/kvm/mmu.h
@@ -15,7 +15,8 @@
 #define PT_USER_MASK (1ULL << 2)
 #define PT_PWT_MASK (1ULL << 3)
 #define PT_PCD_MASK (1ULL << 4)
-#define PT_ACCESSED_MASK (1ULL << 5)
+#define PT_ACCESSED_SHIFT 5
+#define PT_ACCESSED_MASK (1ULL << PT_ACCESSED_SHIFT)
 #define PT_DIRTY_MASK (1ULL << 6)
 #define PT_PAGE_SIZE_MASK (1ULL << 7)
 #define PT_PAT_MASK (1ULL << 7)
diff --git a/include/asm-x86/kvm_host.h b/include/asm-x86/kvm_host.h
index 844f2a8..c2d066e 100644
--- a/include/asm-x86/kvm_host.h
+++ b/include/asm-x86/kvm_host.h
@@ -243,6 +243,7 @@ struct kvm_vcpu_arch {
 	gfn_t last_pt_write_gfn;
 	int   last_pt_write_count;
 	u64  *last_pte_updated;
+	gfn_t last_pte_gfn;
 
 	struct {
 		gfn_t gfn;	/* presumed gfn during guest pte update */
-- 
1.5.6


  parent reply	other threads:[~2008-06-26 12:46 UTC|newest]

Thread overview: 51+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-06-26 12:27 [PATCH 00/50] KVM patches review for the 2.6.27 merge window Avi Kivity
2008-06-26 12:27 ` [PATCH 01/50] KVM: remove long -> void *user -> long cast Avi Kivity
2008-06-26 12:27 ` [PATCH 02/50] KVM: add statics were possible, function definition in lapic.h Avi Kivity
2008-06-26 12:27 ` [PATCH 03/50] KVM: VMX: move APIC_ACCESS trace entry to generic code Avi Kivity
2008-06-26 12:27 ` [PATCH 04/50] KVM: SVM: implement dedicated NMI exit handler Avi Kivity
2008-06-26 12:27 ` [PATCH 05/50] KVM: SVM: implement dedicated INTR " Avi Kivity
2008-06-26 12:27 ` [PATCH 06/50] KVM: add missing kvmtrace bits Avi Kivity
2008-06-26 12:27 ` [PATCH 07/50] KVM: SVM: add missing kvmtrace markers Avi Kivity
2008-06-26 12:27 ` [PATCH 08/50] KVM: SVM: add tracing support for TDP page faults Avi Kivity
2008-06-26 12:27 ` [PATCH 09/50] KVM: Handle vma regions with no backing page Avi Kivity
2008-06-26 12:27 ` [PATCH 10/50] KVM: PIT: support mode 3 Avi Kivity
2008-06-26 12:27 ` [PATCH 11/50] KVM: SVM: Fake MSR_K7 performance counters Avi Kivity
2008-06-26 12:27 ` [PATCH 12/50] KVM: VMX: Trivial vmcs_write64() code simplification Avi Kivity
2008-06-26 12:27 ` Avi Kivity [this message]
2008-06-26 12:27 ` [PATCH 14/50] KVM: Handle virtualization instruction #UD faults during reboot Avi Kivity
2008-06-26 12:27 ` [PATCH 15/50] KVM: VMX: Add list of potentially locally cached vcpus Avi Kivity
2008-06-26 12:27 ` [PATCH 16/50] KVM: Remove decache_vcpus_on_cpu() and related callbacks Avi Kivity
2008-06-26 12:27 ` [PATCH 17/50] KVM: Remove unnecessary ->decache_regs() call Avi Kivity
2008-06-26 12:28 ` [PATCH 18/50] KVM: IOAPIC/LAPIC: Enable NMI support Avi Kivity
2008-06-26 12:28 ` [PATCH 19/50] KVM: VMX: Enable NMI with in-kernel irqchip Avi Kivity
2008-06-26 12:28 ` [PATCH 20/50] KVM: Order segment register constants in the same way as cpu operand encoding Avi Kivity
2008-06-26 12:28 ` [PATCH 21/50] KVM: MTRR support Avi Kivity
2008-06-26 12:28 ` [PATCH 22/50] KVM: Prefixes segment functions that will be exported with "kvm_" Avi Kivity
2008-06-26 12:28 ` [PATCH 23/50] KVM: x86 emulator: Update c->dst.bytes in decode instruction Avi Kivity
2008-06-26 12:28 ` [PATCH 24/50] KVM: x86 emulator: add support for jmp far 0xea Avi Kivity
2008-06-26 12:28 ` [PATCH 25/50] KVM: x86 emulator: adds support to mov r,imm (opcode 0xb8) instruction Avi Kivity
2008-06-26 12:28 ` [PATCH 26/50] KVM: x86 emulator: Add support for mov seg, r (0x8e) instruction Avi Kivity
2008-06-26 12:28 ` [PATCH 27/50] KVM: x86 emulator: Add support for mov r, sreg (0x8c) instruction Avi Kivity
2008-06-26 12:28 ` [PATCH 28/50] KVM: MMU: Optimize prefetch_page() Avi Kivity
2008-06-26 12:28 ` [PATCH 29/50] KVM: x86 emulator: simplify push imm8 emulation Avi Kivity
2008-06-26 12:28 ` [PATCH 30/50] KVM: x86 emulator: implement 'push imm' (opcode 0x68) Avi Kivity
2008-06-26 12:28 ` [PATCH 31/50] KVM: MMU: Move nonpaging_prefetch_page() Avi Kivity
2008-06-26 12:28 ` [PATCH 32/50] KVM: MMU: Avoid page prefetch on SVM Avi Kivity
2008-06-26 12:28 ` [PATCH 33/50] KVM: kvm_io_device: extend in_range() to manage len and write attribute Avi Kivity
2008-06-26 12:28 ` [PATCH 34/50] KVM: Add coalesced MMIO support (common part) Avi Kivity
2008-06-26 12:28 ` [PATCH 35/50] KVM: Add coalesced MMIO support (x86 part) Avi Kivity
2008-06-26 12:28 ` [PATCH 36/50] KVM: Add coalesced MMIO support (powerpc part) Avi Kivity
2008-06-26 12:28 ` [PATCH 37/50] KVM: Add coalesced MMIO support (ia64 part) Avi Kivity
2008-06-26 12:28 ` [PATCH 38/50] KVM: only abort guest entry if timer count goes from 0->1 Avi Kivity
2008-06-26 12:28 ` [PATCH 39/50] KVM: Do not calculate linear rip in emulation failure report Avi Kivity
2008-06-26 12:28 ` [PATCH 40/50] KVM: Support mixed endian machines Avi Kivity
2008-06-26 12:28 ` [PATCH 41/50] KVM: Use printk_rlimit() instead of reporting emulation failures just once Avi Kivity
2008-06-26 12:28 ` [PATCH 42/50] KVM: x86 emulator: emulate nop and xchg reg, acc (opcodes 0x90 - 0x97) Avi Kivity
2008-06-26 12:28 ` [PATCH 43/50] KVM: x86 emulator: handle undecoded rex.b with r/m = 5 in certain cases Avi Kivity
2008-06-26 12:28 ` [PATCH 44/50] KVM: x86 emulator: simplify sib decoding Avi Kivity
2008-06-26 12:28 ` [PATCH 45/50] KVM: x86 emulator: simplify r/m decoding Avi Kivity
2008-06-26 12:28 ` [PATCH 46/50] KVM: x86 emulator: simplify rip relative decoding Avi Kivity
2008-06-26 12:28 ` [PATCH 47/50] KVM: x86 emulator: avoid segment base adjust for lea Avi Kivity
2008-06-26 12:28 ` [PATCH 48/50] KVM: x86 emulator: lazily evaluate segment registers Avi Kivity
2008-06-26 12:28 ` [PATCH 49/50] KVM: MMU: When debug is enabled, make it a run-time parameter Avi Kivity
2008-06-26 12:28 ` [PATCH 50/50] KVM: MMU: Fix printk format Avi Kivity

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1214483312-9265-14-git-send-email-avi@qumranet.com \
    --to=avi@qumranet.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox