From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f201.google.com (mail-pf1-f201.google.com [209.85.210.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B57D0221F03 for ; Thu, 29 Jan 2026 15:32:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769700777; cv=none; b=n9xq+ESQtTKyF4QwQYkkVW8DqEQa51IHUQymLs3R1E6Hy+HcTX0etPkLg4OxJWoaoPxFes0Wn7Oj3vueSjUP31MwWNmioZ3nkCaB+AM7HkSKjTqPTyiikKm6O6mgwGxcfHbo4OeOERivUGXiy0cbRCPByM+iJl+tNlzk2R8Gcnk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769700777; c=relaxed/simple; bh=9S2As/HXzHxL2v62TjOZCZxd2DQ7lWQ3rjtr/Gdhi8c=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Content-Type; b=BkELukiFAxyeR3lcpIA70xh6mAeTV3vb7f3LojUUhA+iblEc1qcjp4GLtLb2djlfRcQxdNLjJw9JkW2db7djrQJw9UjAJnD33Dc93F03rvVSnpDNAit8TDcjeiwtT/YVZyPLm/vX58Y81QEW5EaTzqvf75IyorfmjBuTUbiNdAY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=uBC3IBWu; arc=none smtp.client-ip=209.85.210.201 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="uBC3IBWu" Received: by mail-pf1-f201.google.com with SMTP id d2e1a72fcca58-81e81fbbb8cso987508b3a.3 for ; Thu, 29 Jan 2026 07:32:55 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1769700775; x=1770305575; darn=vger.kernel.org; h=to:from:subject:message-id:references:mime-version:in-reply-to:date :from:to:cc:subject:date:message-id:reply-to; bh=pUYJw4c3pdE7hwG9tr+c2v9CH1+8NBV9hRmRkDwEMLY=; b=uBC3IBWu+I5Oo6rXFv0OIL4cdA6PKbOFjoFI1aUeIVbCRFnGAsO8y5NfsQFcJxEWsl SRLcvaQ5ndWUT1mm46nNvIlfSuDYQP6W3/j7UlfPzfwl3y/8aUNxQ90mUdRgfS+Inv2g Ll9HpG8Pf5lJxlwqqC4Rx4zMug2I23Y/WhtRNNeAR2fJvVSSPBfSv1GZEKTL0n8L7sAT wzrGUKc0vBYF1fo+7qUDoRI6MNM0PvwzLzVQxSmdp9MMXmNzdwxcl8YxJ4/thVA4djP1 KRjia1ezE2K9eGPDYSEx62uW4KBAC1ux78Xp2mb8FDZX6Sa8Fkb1MMxc0+owCCVfvYFV gvPQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769700775; x=1770305575; h=to:from:subject:message-id:references:mime-version:in-reply-to:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=pUYJw4c3pdE7hwG9tr+c2v9CH1+8NBV9hRmRkDwEMLY=; b=anR/9Qzv2FVH8VyMkMjbpfAlb+xw5XKIRn2RZ8OCzeWq/AecoQQ3fCZ13DyOCQHRIf cuH/5n/UjoR5Vc8sQzJGSV7qQfKvsSe96nmBU495tlJsn/fAdITnIsonEIzxvoNBA5zu ZXwvwDlp2IrXGnDasgUPvCbxSg+6iCmE5kfmdZizpI2pEfV733cpsFWZk+FhtzXxRaSV hLyt0ltUeEP89QyYJ/R4VD07oIlG+PCMheBOjt54AGAVgTaecwetv4SN/2zVdGNH6LNN VXW1KctK2U6eMEnOa81S4lIml3vmkHsKjRQwa8rrk9J0XTy1AQuS2GE4Qq/ek09yAxXy Tw5A== X-Forwarded-Encrypted: i=1; AJvYcCWBYSRIHv9U36wbOHgDBF/fq3ZCZYW5aa8VMmWu6cG7P4RoQf9lLbD4UC27VD0E1XTEhcL+rwHbHtxZseg=@vger.kernel.org X-Gm-Message-State: AOJu0Yw9FPU3W5SEz+lUbyHQ8rz7UP0afERlxtKrSNxQekBLWcj759k5 7/8R5lAfabPHkcVM3kWJyCV+WfFEAmIQbQutJsX/QyS/AUTpw2h94bJiqkBN3uQWylHy+avJp3d IzUBCZQ== X-Received: from pfbi1-n1.prod.google.com ([2002:a05:6a00:a501:10b0:7b8:e204:9940]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:3a1a:b0:7ac:edc4:fb82 with SMTP id d2e1a72fcca58-8236915f3eemr8019448b3a.5.1769700774790; Thu, 29 Jan 2026 07:32:54 -0800 (PST) Date: Thu, 29 Jan 2026 07:32:53 -0800 In-Reply-To: <20260129011517.3545883-42-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260129011517.3545883-1-seanjc@google.com> <20260129011517.3545883-42-seanjc@google.com> Message-ID: Subject: Re: [RFC PATCH v5 41/45] KVM: TDX: Honor the guest's accept level contained in an EPT violation From: Sean Christopherson To: Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, Kiryl Shutsemau , Paolo Bonzini , linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev, kvm@vger.kernel.org, Kai Huang , Rick Edgecombe , Yan Zhao , Vishal Annapurve , Ackerley Tng , Sagi Shahar , Binbin Wu , Xiaoyao Li , Isaku Yamahata Content-Type: text/plain; charset="us-ascii" On Wed, Jan 28, 2026, Sean Christopherson wrote: > +int kvm_tdp_mmu_split_huge_pages(struct kvm_vcpu *vcpu, gfn_t start, gfn_t end, > + int target_level) > +{ > + struct kvm_mmu_page *root = root_to_sp(vcpu->arch.mmu->root.hpa); This is wrong, mmu->root.hpa is the shared root, not the mirror root. Dittof for the sanity check in tdx_handle_mismatched_accept(). Rather than operate on the vCPU's root, I think it makes sense to add an API to operate on all mirror roots. In practice, there can only be one valid mirror root, so KVM isn't actually doing more work. Then TDX can reuse that API for splitting the head+tail pages when preparing for a partial shared=>private conversion. Slotted in before this patch: --- From: Sean Christopherson Date: Thu, 29 Jan 2026 15:21:30 +0000 Subject: [PATCH] KVM: x86/mmu: Add a TDP MMU API to split hugepages for mirror roots Add an exported API to split hugepages in mirror roots for a given gfn range. TDX will use the API to split hugepages in preparation for partially converting a hugepage from private to shared, and for splitting a hugepage to match the guest's ACCEPT level. For all intents and purposes, no functional change intended. Signed-off-by: Sean Christopherson --- arch/x86/kvm/mmu/tdp_mmu.c | 39 ++++++++++++++++++++++++++++---------- arch/x86/kvm/mmu/tdp_mmu.h | 2 ++ 2 files changed, 31 insertions(+), 10 deletions(-) diff --git a/arch/x86/kvm/mmu/tdp_mmu.c b/arch/x86/kvm/mmu/tdp_mmu.c index e32034bfca5a..a45d8ee91481 100644 --- a/arch/x86/kvm/mmu/tdp_mmu.c +++ b/arch/x86/kvm/mmu/tdp_mmu.c @@ -1597,6 +1597,26 @@ static int tdp_mmu_split_huge_pages_root(struct kvm *kvm, return 0; } +static int tdp_mmu_split_huge_pages(struct kvm *kvm, int as_id, + enum kvm_tdp_mmu_root_types type, + gfn_t start, gfn_t end, + int target_level, bool shared) +{ + struct kvm_mmu_page *root; + int r; + + kvm_lockdep_assert_mmu_lock_held(kvm, shared); + + __for_each_tdp_mmu_root_yield_safe(kvm, root, as_id, type) { + r = tdp_mmu_split_huge_pages_root(kvm, root, start, end, + target_level, shared); + if (r) { + kvm_tdp_mmu_put_root(kvm, root); + return r; + } + } + return 0; +} /* * Try to split all huge pages mapped by the TDP MMU down to the target level. @@ -1606,18 +1626,17 @@ void kvm_tdp_mmu_try_split_huge_pages(struct kvm *kvm, gfn_t start, gfn_t end, int target_level, bool shared) { - struct kvm_mmu_page *root; - int r = 0; + tdp_mmu_split_huge_pages(kvm, slot->as_id, KVM_VALID_ROOTS, start, end, + target_level, shared); +} - kvm_lockdep_assert_mmu_lock_held(kvm, shared); - for_each_valid_tdp_mmu_root_yield_safe(kvm, root, slot->as_id) { - r = tdp_mmu_split_huge_pages_root(kvm, root, start, end, target_level, shared); - if (r) { - kvm_tdp_mmu_put_root(kvm, root); - break; - } - } +int kvm_tdp_mmu_mirrors_split_huge_pages(struct kvm *kvm, gfn_t start, + gfn_t end, int target_level) +{ + return tdp_mmu_split_huge_pages(kvm, 0, KVM_MIRROR_ROOTS, start, end, + target_level, false); } +EXPORT_SYMBOL_FOR_KVM_INTERNAL(kvm_tdp_mmu_mirrors_split_huge_pages); static bool tdp_mmu_need_write_protect(struct kvm *kvm, struct kvm_mmu_page *sp) { diff --git a/arch/x86/kvm/mmu/tdp_mmu.h b/arch/x86/kvm/mmu/tdp_mmu.h index bd62977c9199..a6919de10ca2 100644 --- a/arch/x86/kvm/mmu/tdp_mmu.h +++ b/arch/x86/kvm/mmu/tdp_mmu.h @@ -97,6 +97,8 @@ void kvm_tdp_mmu_try_split_huge_pages(struct kvm *kvm, const struct kvm_memory_slot *slot, gfn_t start, gfn_t end, int target_level, bool shared); +int kvm_tdp_mmu_mirrors_split_huge_pages(struct kvm *kvm, gfn_t start, + gfn_t end, int target_level); static inline void kvm_tdp_mmu_walk_lockless_begin(void) { base-commit: 86c3bb72bf5c6201636529ee4609334b0887c6e3 --