From: Avi Kivity <avi@redhat.com>
To: Xiao Guangrong <xiaoguangrong@cn.fujitsu.com>
Cc: Marcelo Tosatti <mtosatti@redhat.com>,
LKML <linux-kernel@vger.kernel.org>, KVM <kvm@vger.kernel.org>
Subject: Re: [PATCH 01/11] KVM: MMU: avoid pte_list_desc run out in kvm_mmu_pte_write
Date: Wed, 27 Jul 2011 12:00:28 +0300 [thread overview]
Message-ID: <4E2FD3AC.1000701@redhat.com> (raw)
In-Reply-To: <4E2EA41A.3080606@cn.fujitsu.com>
On 07/26/2011 02:25 PM, Xiao Guangrong wrote:
> kvm_mmu_pte_write is unsafe since we need to alloc pte_list_desc in the
> function when spte is prefetched, unfortunately, we can not know how many
> spte need to be prefetched on this path, that means we can use out of the
> free pte_list_desc object in the cache, and BUG_ON() is triggered, also some
> path does not fill the cache, such as INS instruction emulated that does not
> trigger page fault
>
>
> void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
> const u8 *new, int bytes,
> bool guest_initiated)
> @@ -3583,6 +3596,7 @@ void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
> break;
> }
>
> + mmu_topup_memory_caches(vcpu);
Please add a comment here describing why it's okay to ignore the error
return.
> spin_lock(&vcpu->kvm->mmu_lock);
> if (atomic_read(&vcpu->kvm->arch.invlpg_counter) != invlpg_counter)
> gentry = 0;
> @@ -3653,7 +3667,7 @@ void kvm_mmu_pte_write(struct kvm_vcpu *vcpu, gpa_t gpa,
> mmu_page_zap_pte(vcpu->kvm, sp, spte);
> if (gentry&&
> !((sp->role.word ^ vcpu->arch.mmu.base_role.word)
> - & mask.word))
> + & mask.word)&& get_free_pte_list_desc_nr(vcpu))
> mmu_pte_write_new_pte(vcpu, sp, spte,&gentry);
Wow, this bug was here since 2.6.23. Good catch.
Please wrap or rename get_free_pte_list_desc_nr() in rmap_can_add(vcpu)
so it's clearer why we're doing this.
--
error compiling committee.c: too many arguments to function
next prev parent reply other threads:[~2011-07-27 9:00 UTC|newest]
Thread overview: 34+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-07-26 11:24 [PATCH 0/11] KVM: x86: optimize for guest page written Xiao Guangrong
2011-07-26 11:25 ` [PATCH 01/11] KVM: MMU: avoid pte_list_desc run out in kvm_mmu_pte_write Xiao Guangrong
2011-07-27 9:00 ` Avi Kivity [this message]
2011-07-27 9:37 ` Xiao Guangrong
2011-07-26 11:25 ` [PATCH 02/11] KVM: x86: cleanup pio/pout emulated Xiao Guangrong
2011-07-26 11:26 ` [PATCH 03/11] KVM: x86: fast emulate repeat string write instructions Xiao Guangrong
2011-07-26 12:27 ` Gleb Natapov
2011-07-26 13:53 ` Avi Kivity
2011-07-27 1:47 ` Xiao Guangrong
2011-07-27 4:26 ` Gleb Natapov
2011-07-27 6:32 ` Xiao Guangrong
2011-07-27 7:51 ` Gleb Natapov
2011-07-27 9:36 ` Xiao Guangrong
2011-07-27 9:04 ` Avi Kivity
2011-07-27 9:37 ` Xiao Guangrong
2011-07-26 11:28 ` [PATCH 04/11] KVM: MMU: do not mark access bit on pte write path Xiao Guangrong
2011-07-27 9:08 ` Avi Kivity
2011-07-27 10:04 ` Xiao Guangrong
2011-07-26 11:28 ` [PATCH 05/11] KVM: MMU: cleanup FNAME(invlpg) Xiao Guangrong
2011-07-26 11:29 ` [PATCH 06/11] KVM: MMU: fast prefetch spte on invlpg path Xiao Guangrong
2011-07-26 11:29 ` [PATCH 07/11] KVM: MMU: remove unnecessary kvm_mmu_free_some_pages Xiao Guangrong
2011-07-26 11:30 ` [PATCH 08/11] KVM: MMU: split kvm_mmu_pte_write function Xiao Guangrong
2011-07-26 11:31 ` [PATCH 09/11] KVM: MMU: remove the mismatch shadow page Xiao Guangrong
2011-07-27 9:11 ` Avi Kivity
2011-07-27 9:13 ` Avi Kivity
2011-07-27 10:05 ` Xiao Guangrong
2011-07-26 11:31 ` [PATCH 10/11] KVM: MMU: fix detecting misaligned accessed Xiao Guangrong
2011-07-27 9:15 ` Avi Kivity
2011-07-27 10:10 ` Xiao Guangrong
2011-07-26 11:32 ` [PATCH 11/11] KVM: MMU: improve write flooding detected Xiao Guangrong
2011-07-27 9:23 ` Avi Kivity
2011-07-27 10:20 ` Xiao Guangrong
2011-07-27 11:08 ` Avi Kivity
2011-07-28 2:43 ` Xiao Guangrong
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4E2FD3AC.1000701@redhat.com \
--to=avi@redhat.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mtosatti@redhat.com \
--cc=xiaoguangrong@cn.fujitsu.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox