Re: [PATCH v4 3/3] balloon: add VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE

Manos Pitsidianakis <[email protected]> Fri, 15 May 2026 12:09:24 +0300
Newsgroups dev.linux.lists.virtio-comment
Message-ID <CAAjaMXZggBhThMSrR8-YWx=AZDi00hm9or6CSB+v3xgjvbaotg@mail.gmail.com>
On Thu, May 7, 2026 at 10:52=E2=80=AFAM Michael S. Tsirkin <[email protected]>=
 wrote:
>
> Add VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE (bit 7): the device
> initializes inflated pages and returns a per-page bitmap indicating
> which pages were successfully initialized.
>
> Update Security Considerations Data Integrity subsection to cover
> both DEVICE_INIT_REPORTED and DEVICE_INIT_ON_INFLATE.
>
> Fixes: https://github.com/oasis-tcs/virtio-spec/issues/242
> Signed-off-by: Michael S. Tsirkin <[email protected]>
> ---
>  device-types/balloon/description.tex | 73 +++++++++++++++++++++++++++-
>  1 file changed, 71 insertions(+), 2 deletions(-)
>
> diff --git a/device-types/balloon/description.tex b/device-types/balloon/=
description.tex
> index fa33105..7afdb24 100644
> --- a/device-types/balloon/description.tex
> +++ b/device-types/balloon/description.tex
> @@ -52,6 +52,9 @@ \subsection{Feature bits}\label{sec:Device Types / Memo=
ry Balloon Device / Featu
>  \item[ VIRTIO_BALLOON_F_DEVICE_INIT_REPORTED(6) ] The device initializes
>      reported pages.
>
> +\item[ VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE(7) ] The device initializ=
es
> +    inflated pages.
> +
>  \end{description}
>
>  \subsubsection{Feature bit requirements}\label{sec:Device Types / Memory=
 Balloon Device / Feature bits / Feature bit requirements}
> @@ -249,6 +252,10 @@ \subsection{Device Operation}\label{sec:Device Types=
 / Memory Balloon Device / D
>  and before detecting its physical number in a deflate request
>  and acknowledging the deflate request.
>
> +If VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE is negotiated, the
> +device MUST NOT modify a page after reporting it as initialized
> +in the bitmap.
> +
>  \paragraph{Legacy Interface: Device Operation}\label{sec:Device
>  Types / Memory Balloon Device / Device Operation / Legacy
>  Interface: Device Operation}
> @@ -672,6 +679,67 @@ \subsubsection{Device Initialized Reported Pages}\la=
bel{sec:Device Types / Memor
>  If VIRTIO_BALLOON_F_PAGE_POISON is not negotiated, the device
>  MUST fill each initialized page with zeros.
>
> +\subsubsection{Device Initialized Pages on Inflate}\label{sec:Device Typ=
es / Memory Balloon Device / Device Operation / Device Initialized Pages on=
 Inflate}
> +
> +When VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE is negotiated, the
> +device initializes inflated pages and reports which pages were
> +successfully initialized via a per-page bitmap.
> +
> +The driver appends a device-writable bitmap buffer to each inflate
> +descriptor chain, after the PFN outbuf.

Maybe we could say "page physical number" instead of PFN to stay
consistent with the rest of the balloon spec.

> The bitmap contains one
> +bit per balloon page (4KB), where bit N corresponds to the Nth PFN
> +in the inflate request (0-indexed). Bit N is stored as bit (N mod 8)
> +of byte (N / 8), with bit 0 being the least significant bit.
> +The device sets a bit to 1 if it successfully initialized the
> +corresponding page, or 0 if it did not.

Does this mean page size cannot be larger than 4kb?

> +
> +If VIRTIO_BALLOON_F_PAGE_POISON is also negotiated, the device fills
> +pages with \field{poison_val}; otherwise, the device fills pages
> +with zeros.
> +
> +When the driver later deflates these pages, it may skip
> +initialization for pages that were marked as initialized in the
> +inflate bitmap.
> +
> +\drivernormative{\paragraph}{Device Initialized Pages on Inflate}{Device=
 Types / Memory Balloon Device / Device Operation / Device Initialized Page=
s on Inflate}
> +
> +Normative statements in this section apply if the
> +VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE feature has been negotiated.
> +
> +The driver MUST append a device-writable bitmap buffer to each
> +inflate descriptor chain. The bitmap buffer MUST be at least
> +$\lceil N/8 \rceil$ bytes, where N is the number of PFNs in the
> +inflate request.
> +
> +The driver MUST NOT treat an inflated page as initialized unless
> +the corresponding bit in the bitmap is set to 1.
> +
> +The driver MAY skip initializing a deflated page if the
> +corresponding inflate bitmap bit was set to 1. This overrides
> +the VIRTIO_BALLOON_F_PAGE_POISON requirement to initialize
> +deflated pages with \field{poison_val} for such pages.
> +
> +\devicenormative{\paragraph}{Device Initialized Pages on Inflate}{Device=
 Types / Memory Balloon Device / Device Operation / Device Initialized Page=
s on Inflate}
> +
> +Normative statements in this section apply if the
> +VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE feature has been negotiated.
> +
> +The device MUST provide an inflateq supporting at least 2 buffers.
> +
> +The device MUST set bit N in the bitmap to 1 if it successfully
> +initialized PFN N, or to 0 otherwise. Bits not covered by the
> +used length are treated as 0 by the driver.
> +
> +The device MAY write fewer or more bytes than $\lceil N/8 \rceil$.
> +Any bits written beyond those corresponding to PFNs in the request
> +MUST be set to 0.
> +
> +If VIRTIO_BALLOON_F_PAGE_POISON is also negotiated, the device
> +MUST fill each successfully initialized page with \field{poison_val}.
> +
> +If VIRTIO_BALLOON_F_PAGE_POISON is not negotiated, the device
> +MUST fill each successfully initialized page with zeros.
> +
>  \subsection{Security Considerations}\label{sec:Device Types / Memory Bal=
loon Device / Security Considerations}
>
>  In environments where the device is not trusted, such as
> @@ -697,14 +765,15 @@ \subsubsection{Data Integrity}\label{sec:Device Typ=
es / Memory Balloon Device /
>  When the device is untrusted, the driver cannot rely on the device
>  to correctly initialize pages. An untrusted device can report a
>  non-zero used length for VIRTIO_BALLOON_F_DEVICE_INIT_REPORTED
> +or set bits in the VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE bitmap
>  without actually initializing the corresponding pages. If the
>  driver treats such pages as initialized (e.g., marking them as
>  zeroed), this could lead to information leakage between guest
>  processes or other security violations.
>
>  Drivers operating in environments with untrusted devices are
> -expected to avoid negotiating
> -VIRTIO_BALLOON_F_DEVICE_INIT_REPORTED, and to initialize
> +expected to avoid negotiating VIRTIO_BALLOON_F_DEVICE_INIT_REPORTED
> +or VIRTIO_BALLOON_F_DEVICE_INIT_ON_INFLATE, and to initialize
>  all pages themselves.
>
>  \subsubsection{Denial of Service}\label{sec:Device Types / Memory Balloo=
n Device / Security Considerations / Denial of Service}
> --
> MST
>
>