Re: [PATCH v7 07/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path

Nikolay Borisov <[email protected]> Wed, 22 Jul 2026 13:50:31 +0300
Newsgroups dev.linux.lists.linux-coco,org.kernel.vger.kvm,org.kernel.vger.linux-doc,org.kernel.vger.linux-kernel
Message-ID <[email protected]>

On 7/18/26 04:44, Rick Edgecombe wrote:
> When handling an EPT violation, KVM holds a spinlock while manipulating
> the EPT. Before entering the spinlock it doesn't know how many EPT page
> tables will need to be installed or whether a huge page will be used. For
> this reason it allocates a worst case number of page tables that it might
> need as part of servicing the EPT violation.
> 
> Under Dynamic PAMT these pre-allocated pages will potentially need to have
> Dynamic PAMT backing pages installed for them. KVM already has helpers to
> manage topping up page caches before taking the MMU lock, but they cannot
> be passed from KVM to arch/x86 code.
> 
> The problem of how and when to install the Dynamic PAMT backing pages for
> the pages given to the TDX module during the fault path has had a lot of
> design attempts.
>   - Extracting KVM's MMU caches requires too much inlined code added to
>     headers.
>   - A few varieties of installing Dynamic PAMT backing when allocating the
>     S-EPT page tables. (see links)
>   - Using mempool_t to transfer the pages between KVM and arch/x86 doesn't
>     work because the component is designed more around maintaining a pool
>     of pages, rather than topping up a continually drained cache.
> 
> So don't do these as they all had various problems. Instead just create a
> small simple data structure to use for handing a pre-allocated list of
> pages between KVM and arch/x86 code. Model this on KVM's existing MMU
> memory caches.
> 
> Add a tdx_pamt_cache arg to tdx_pamt_get() so it can draw pages from a
> cache when needed. Not all Dynamic PAMT page installations will happen
> under spinlock, for example TD and vCPU scoped control pages. So have
> tdx_pamt_get() maintain the existing behavior of allocating from the page
> allocator when NULL is passed for the struct tdx_pamt_cache arg. This
> prevents excess allocations for cases where it can be avoided.
> 
> Export the new helpers for KVM.
> 
> AI was used under supervision to review code and workshop logs.
> 
> Co-developed-by: Sean Christopherson <[email protected]>
> Signed-off-by: Sean Christopherson <[email protected]>
> Signed-off-by: Rick Edgecombe <[email protected]>
> Reviewed-by: Kiryl Shutsemau (Meta) <[email protected]>
> Reviewed-by: Binbin Wu <[email protected]>
> Reviewed-by: Chao Gao <[email protected]>
> Reviewed-by: Yan Zhao <[email protected]>
> Reviewed-by: Tony Lindgren <[email protected]>
> Link: https://lore.kernel.org/kvm/[email protected]/
> Link: https://lore.kernel.org/kvm/[email protected]/
> Link: https://lore.kernel.org/kvm/[email protected]/
> ---

Reviewed-by: Nikolay Borisov <[email protected]>