xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
From: Mukesh Rathor <mukesh.rathor@oracle.com>
To: Tim Deegan <tim@xen.org>
Cc: Jan Beulich <JBeulich@suse.com>,
	George.Dunlap@eu.citrix.com, eddie.dong@intel.com,
	keir.xen@gmail.com, jun.nakajima@intel.com,
	xen-devel@lists.xenproject.org
Subject: Re: [V9 PATCH 6/8] pvh dom0: Add and remove foreign pages
Date: Thu, 24 Apr 2014 19:09:25 -0700	[thread overview]
Message-ID: <20140424190925.62843681@mantra.us.oracle.com> (raw)
In-Reply-To: <20140424094641.GA48969@deinos.phlegethon.org>

On Thu, 24 Apr 2014 11:46:41 +0200
Tim Deegan <tim@xen.org> wrote:

> At 19:21 -0700 on 23 Apr (1398277311), Mukesh Rathor wrote:
> > On Thu, 17 Apr 2014 14:58:42 +0100
> > "Jan Beulich" <JBeulich@suse.com> wrote:
> > 
> > > >>> On 17.04.14 at 14:36, <tim@xen.org> wrote:
> > > > At 07:50 +0100 on 17 Apr (1397717440), Jan Beulich wrote:
> > > >> >>> On 17.04.14 at 03:37, <mukesh.rathor@oracle.com> wrote:
> > > >> > On Wed, 16 Apr 2014 17:00:35 +0100
> > > >> > "Jan Beulich" <JBeulich@suse.com> wrote:
......
> > > > That said, it should be easy enough only to refcount on leaf
> > > > entries, right?  I can't see how that would be incompatible
> > > > with the intermediate-node changes that Jan is working on.
> > > 
> > > Right - keeping the macro as is and introducing a derived
> > > function to handle the extra requirements on leaf entries would
> > > seem quite okay, so long as error propagation can be done
> > > properly.
> > 
> > Ok, how about something like the following? In case of get_page
> > failure, not sure EINVAL is the best one to return, EBUSY?
> 
> This goes back to having refcounts open-coded.  Having the refcounts
> open-coded around the atomic_write_ept_entry() in ept_set_entry()
> means there are now places where the epte can change without
> maintaining the refcount invariants: ept_change_entry_type_page(), for
> example.

Correct, altho, at present I've checks in p2m paths to not allow foreign
types to come down to such calls.

> I would _much_ prefer to have atomic_write_ept_entry() DTRT -- it
> would have to know the difference between leaf and non-leaf entries,
> and return an error code.  I'd also be OK with having two
> atomic_write ops, one for leaf and one for non-leaf, with appropriate
> ASSERT()s on the contents.

Ok, how about something like shown further below?  (I think
it would be more simpler to have one atomic_write ops, instead of two)

One thing, on returning error code, since at present there are no
paths allowing superpages for foreign types, it appears I'd not need 
to worry about undoing the ept_split_super_page(), so I added
assert in there. Sound right?

Finally, I can leave other callers of atomic_write_ept_entry as is, or 
add ASSERTs for rc == 0. LMK.

thanks for patience,
mukesh


diff --git a/xen/arch/x86/mm/p2m-ept.c b/xen/arch/x86/mm/p2m-ept.c
index 1fa839a..41a8c40 100644
--- a/xen/arch/x86/mm/p2m-ept.c
+++ b/xen/arch/x86/mm/p2m-ept.c
@@ -36,8 +36,6 @@
 
 #define atomic_read_ept_entry(__pepte)                              \
     ( (ept_entry_t) { .epte = read_atomic(&(__pepte)->epte) } )
-#define atomic_write_ept_entry(__pepte, __epte)                     \
-    write_atomic(&(__pepte)->epte, (__epte).epte)
 
 #define is_epte_present(ept_entry)      ((ept_entry)->epte & 0x7)
 #define is_epte_superpage(ept_entry)    ((ept_entry)->sp)
@@ -46,6 +44,43 @@ static inline bool_t is_epte_valid(ept_entry_t *e)
     return (e->epte != 0 && e->sa_p2mt != p2m_invalid);
 }
 
+/* returns : 0 for success, -errno otherwise */
+static int atomic_write_ept_entry(ept_entry_t *entryptr, ept_entry_t new)
+{
+    unsigned long oldmfn;
+    struct domain *fdom;
+    bool_t new_foreign = p2m_is_foreign(new.sa_p2mt);
+    bool_t old_foreign = p2m_is_foreign(entryptr->sa_p2mt);
+
+    if (is_epte_superpage(entryptr) || likely(!new_foreign && !old_foreign) )
+    {
+        write_atomic(&entryptr->epte, new.epte);
+        return 0;
+    }
+    
+    if ( new_foreign )
+    {
+        if ( !mfn_valid(new.mfn) )
+            return -EINVAL;
+
+        fdom = page_get_owner(mfn_to_page(new.mfn));
+        if ( fdom == NULL )
+            return -ESRCH;
+
+        /* get refcount on the page */
+        if ( !get_page(mfn_to_page(new.mfn), fdom) )
+            return -EBUSY;
+    }
+
+    oldmfn = entryptr->mfn;
+    write_atomic(&entryptr->epte, new.epte);
+
+    if ( old_foreign )
+        put_page(mfn_to_page(oldmfn));
+
+    return 0;
+}
+
 static void ept_p2m_type_to_flags(ept_entry_t *entry, p2m_type_t type, p2m_access_t access)
 {
     /* First apply type permissions */
@@ -494,6 +529,7 @@ ept_set_entry(struct p2m_domain *p2m, unsigned long gfn, mfn_t mfn,
         ept_entry_t split_ept_entry;
 
         ASSERT(is_epte_superpage(ept_entry));
+        ASSERT(!p2m_is_foreign(p2mt));
 
         split_ept_entry = atomic_read_ept_entry(ept_entry);
 
@@ -545,7 +581,7 @@ ept_set_entry(struct p2m_domain *p2m, unsigned long gfn, mfn_t mfn,
         ept_p2m_type_to_flags(&new_entry, p2mt, p2ma);
     }
 
-    atomic_write_ept_entry(ept_entry, new_entry);
+    rc = atomic_write_ept_entry(ept_entry, new_entry);
 
     /* Track the highest gfn for which we have ever had a valid mapping */
     if ( p2mt != p2m_invalid &&

  reply	other threads:[~2014-04-25  2:09 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2014-04-16  0:12 [V9 PATCH 0/8] pvh dom0 patches Mukesh Rathor
2014-04-16  0:12 ` [V9 PATCH 1/8] pvh dom0: move some pv specific code to static functions Mukesh Rathor
2014-04-16  0:12 ` [V9 PATCH 2/8] pvh dom0: construct_dom0 changes Mukesh Rathor
2014-04-16  0:12 ` [V9 PATCH 3/8] pvh dom0: Introduce p2m_map_foreign Mukesh Rathor
2014-04-16  0:12 ` [V9 PATCH 4/8] pvh dom0: Add checks and restrictions for p2m_is_foreign Mukesh Rathor
2014-04-16 15:28   ` Jan Beulich
2014-04-16  0:12 ` [V9 PATCH 5/8] pvh dom0: make xsm_map_gmfn_foreign available for x86 Mukesh Rathor
2014-04-16 14:29   ` Daniel De Graaf
2014-04-16  0:12 ` [V9 PATCH 6/8] pvh dom0: Add and remove foreign pages Mukesh Rathor
2014-04-16 16:00   ` Jan Beulich
2014-04-17  1:37     ` Mukesh Rathor
2014-04-17  6:50       ` Jan Beulich
2014-04-17 12:36         ` Tim Deegan
2014-04-17 13:58           ` Jan Beulich
2014-04-19  0:59             ` Mukesh Rathor
2014-04-21 16:10               ` Jan Beulich
2014-04-24  2:21             ` Mukesh Rathor
2014-04-24  6:44               ` Jan Beulich
2014-04-24  9:46               ` Tim Deegan
2014-04-25  2:09                 ` Mukesh Rathor [this message]
2014-04-25  6:49                   ` Jan Beulich
2014-04-25 23:23                     ` Mukesh Rathor
2014-04-26  0:06                     ` Mukesh Rathor
2014-04-28  7:23                       ` Jan Beulich
2014-04-25  8:55                   ` Tim Deegan
2014-04-25 23:29                     ` Mukesh Rathor
2014-04-26  1:34                   ` Mukesh Rathor
2014-04-28  8:54                     ` Jan Beulich
2014-04-28  9:09                       ` Tim Deegan
2014-04-22  0:19       ` Mukesh Rathor
2014-04-22  7:28         ` Jan Beulich
2014-04-23  0:28           ` Mukesh Rathor
2014-04-23  9:03             ` Jan Beulich
2014-04-23 16:13               ` Andres Lagar-Cavilla
2014-04-24 16:37                 ` Tim Deegan
2014-04-16  0:12 ` [V9 PATCH 7/8] pvh dom0: check for vioapic null ptr in vioapic_range Mukesh Rathor
2014-04-16 16:05   ` Jan Beulich
2014-04-17  1:44     ` Mukesh Rathor
2014-04-17  6:54       ` Jan Beulich
2014-04-22  0:59         ` Mukesh Rathor
2014-04-22  7:33           ` Jan Beulich
2014-04-23  0:11             ` Mukesh Rathor
2014-04-23  9:07               ` Jan Beulich
2014-04-23 21:18                 ` Mukesh Rathor
2014-04-24  6:49                   ` Jan Beulich
2014-04-24 23:28                     ` Mukesh Rathor
2014-05-06  0:19                     ` Mukesh Rathor
2014-05-06  7:44                       ` Jan Beulich
2014-05-07  1:07                         ` Mukesh Rathor
2014-05-07  6:47                           ` Jan Beulich
2014-05-07 23:52                             ` Mukesh Rathor
2014-05-08  6:33                               ` Jan Beulich
2014-04-16  0:12 ` [V9 PATCH 8/8] pvh dom0: add opt_dom0pvh to setup.c Mukesh Rathor
2014-04-16 12:57   ` Konrad Rzeszutek Wilk
2014-04-16 13:01   ` Andrew Cooper
2014-04-16 16:09   ` Jan Beulich
2014-04-16 14:57 ` [V9 PATCH 0/8] pvh dom0 patches Roger Pau Monné
2014-04-16 21:15   ` Mukesh Rathor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20140424190925.62843681@mantra.us.oracle.com \
    --to=mukesh.rathor@oracle.com \
    --cc=George.Dunlap@eu.citrix.com \
    --cc=JBeulich@suse.com \
    --cc=eddie.dong@intel.com \
    --cc=jun.nakajima@intel.com \
    --cc=keir.xen@gmail.com \
    --cc=tim@xen.org \
    --cc=xen-devel@lists.xenproject.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).