[PATCH v3 0/4] Stop returning struct page from guest_memfd PFN lookup
Ackerley Tng <[email protected]>
| Newsgroups | org.kernel.vger.kvm,dev.linux.lists.kvmarm,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
KVM currently expects kvm_gmem_get_pfn() to return a refcounted struct page. Callers (such as x86 TDP MMU, arm64 Stage-2 fault handler, and SEV-SNP VMSA / RMP handlers) hold this refcount across page fault handling. CoCo shared-to-private conversion handling must inspect folio refcounts to ensure exclusive ownership by guest_memfd. A concurrent guest page fault taking a temporary reference on the folio causes conversions to fail due to an elevated refcount. While this refcount is also taken on host userspace page faults, that refcount is taken on behalf of the host userspace page tables. This refcount will be dropped when conversions unmaps the page. Either way, once there's an mmap() or userspace mapping, the pages are open to way more refcounts, transient or not. This series focuses on just dropping refcounts before handing KVM a page. guest_memfd already notifies KVM of page invalidations, so callers within KVM only need to respect the MMU invalidation protocol to safely rely on guest_memfd for page presence. guest_memfd already notifies KVM of page invalidations, so users of guest_memfd within KVM only need to respect the MMU invalidation protocol to safely rely on guest_memfd to ensure page presence. This series first prepares the SEV-SNP handlers by treating unassigned RMP entries as benign races on PSMASH failure (which can occur on concurrent truncation) and dropping page references early in the RMP fault and VMSA reload paths. It then updates kvm_gmem_get_pfn() to drop the folio reference internally and stop returning a struct page pointer across x86 and arm64. Removing struct page from kvm_gmem_get_pfn() also moves KVM closer toward supporting memory backends that are not backed by struct page. This is built off Sean's sample code [1]. [1] https://lore.kernel.org/all/[email protected]/ Thank you everybody for your quick reviews and testing, I really appreciate it! Changes from v2: + Picked up Reviewed-bys and Tested-bys + Addressed comments v2: https://patch.msgid.link/[email protected] v1: https://patch.msgid.link/[email protected] Signed-off-by: Ackerley Tng <[email protected]> --- Ackerley Tng (2): KVM: SEV: Treat unassigned RMP entry as benign race on PSMASH failure KVM: SEV: Drop page refcount early in VMSA reload Sean Christopherson (2): KVM: SEV: Drop page refcount early during RMP fault handling KVM: guest_memfd: Stop returning struct page from PFN lookup arch/arm64/kvm/mmu.c | 4 +--- arch/arm64/kvm/nested.c | 4 ++-- arch/x86/kvm/mmu/mmu.c | 2 +- arch/x86/kvm/svm/sev.c | 53 ++++++++++++++++++++++++++++-------------------- include/linux/kvm_host.h | 6 ++---- virt/kvm/guest_memfd.c | 9 ++------ 6 files changed, 39 insertions(+), 39 deletions(-) --- base-commit: 1b731e5ded480bd1e5546aed35584238661ce72e change-id: 20260818-gmem-no-return-page-614927a29f97 Best regards, -- Ackerley Tng <[email protected]>