[PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends

Michael Roth posted 12 patches 1 week, 6 days ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260812201938.198915-1-michael.roth@amd.com
Maintainers: Paolo Bonzini <pbonzini@redhat.com>, David Hildenbrand <david@kernel.org>, Igor Mammedov <imammedo@redhat.com>, Gerd Hoffmann <kraxel@redhat.com>, Stefano Garzarella <sgarzare@redhat.com>, Ani Sinha <anisinha@redhat.com>, "Philippe Mathieu-Daudé" <philmd@mailo.com>, Zhao Liu <zhao1.liu@intel.com>, "Michael S. Tsirkin" <mst@redhat.com>, Richard Henderson <richard.henderson@linaro.org>, Peter Xu <peterx@redhat.com>, "Daniel P. Berrangé" <berrange@redhat.com>, Eric Blake <eblake@redhat.com>, Markus Armbruster <armbru@redhat.com>, Marcelo Tosatti <mtosatti@redhat.com>, Fabiano Rosas <farosas@suse.de>, Laurent Vivier <lvivier@redhat.com>
qapi/qom.json                         |  6 ++-
include/hw/boards.h                   |  2 +-
include/system/hostmem.h              |  2 +-
include/system/kvm.h                  |  1 +
include/system/memory.h               | 27 ++++++------
include/system/ram_addr.h             |  2 +-
include/system/ramblock.h             |  7 +++-
tests/qtest/migration/framework.h     |  4 ++
accel/kvm/kvm-all.c                   | 33 ++++++++++++---
accel/stubs/kvm-stub.c                |  6 +++
backends/hostmem-file.c               |  2 +-
backends/hostmem-memfd.c              | 55 +++++++++++++++++++++---
backends/hostmem-ram.c                |  2 +-
backends/hostmem-shm.c                |  2 +-
backends/hostmem.c                    |  2 +-
backends/igvm.c                       |  4 +-
hw/core/machine.c                     |  2 +-
hw/i386/pc.c                          |  6 +--
hw/i386/pc_sysfw.c                    |  8 ++--
hw/i386/x86-common.c                  |  8 ++--
system/memory.c                       | 17 ++++----
system/physmem.c                      | 37 ++++++++++-------
target/i386/kvm/kvm.c                 |  3 +-
tests/qtest/migration/framework.c     | 60 +++++++++++++++++++++++++++
tests/qtest/migration/precopy-tests.c | 12 ++++++
25 files changed, 239 insertions(+), 71 deletions(-)
[PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends
Posted by Michael Roth 1 week, 6 days ago
v1: https://lore.kernel.org/r/20251023185913.2923322-1-peterx@redhat.com
v2: https://lore.kernel.org/r/20251119172913.577392-1-peterx@redhat.com
v3: https://lore.kernel.org/r/20251215205203.1185099-1-peterx@redhat.com/
v4:
- Picked up v3 series from Peter Xu and rebased on 11.1.0
- Collected pending Reviewed-by's
- Per-patch changes:
  [01/12] Fix blank space (Xiaoyao)
          Fix commit message typos
  [02/12] Drop duplicated error-handling for capability checks
  [05/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
  [07/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
  [08/12] Disallow 'seal' and 'hugetlb' options based on guest-memfd=on
          Fix minor typo in comment
  [11/12] Fix up typo in g_test_skip() reason
          Pending: Move kvm_guest_memfd_init_shared_supported() to
            migration-util.c (Fabiano)

This patchset is also available at:

  https://github.com/amdese/qemu/commits/gmem-shared-mem-v4

and is based on top of v11.1.0


OVERVIEW
========

(cover letter shamelessly adapted from Peter's prior postings)

Recent kernels allow guest_memfd to be initialized with an 'init-shared'
flag that will default to allocating normal/non-private memory that can be
used to back non-confidential VMs.

This allows QEMU to make use of these init-shared guest_memfd instances via
a common memory backend that's usable for either provide a common memory
backend.

On the QEMU side, before this series, guest_memfd was only used for private
guest memory (and thus only applied to confidential VMs), and the guest_memfd
FDs would be created implicitly whenever a confidential environment was
detected/specified.

With this series, users can now explicitly configure QEMU to use guest_memfd
for non-private memory; thus, it can be used for non-confidential
VMs. It also has implications for confidential VMs, since with this series an
init-shared guest_memfd instance can now be specified for the shared memory
while the internally-allocated guest_memfd continues to be used for private
memory. This same infrastructure will also be used as the base for enabling
in-place conversion for confidential VMs, where these separate shared/private
paths will be modified to act on the same underlying guest_memfd instance and
use a unified pool of shared/private memory.

IMPLEMENTATION
==============

In the current patchset, I reused the memory-backend-memfd object, rather
than creating a new type of object.  After all, guest-memfd (at least from
userspace POV) works similarly like a memfd, except that it was tailored
for VM's use case. While there is potential that new guest_memfd features
may eventually necessitate introducing a dedicated guest_memfd memory
backend object, for now the memory-backend-memfd object is a good fit for
the current feature set.

This will also make it easier when in-place conversion comes around, since
confidential VMs typically already use memory-backend-memfd for their shared
memory, so by also making using that approach to specify the guest_memfd
backend for in-place conversion the command-line syntax remains similar, and
even allow choosing between memfd vs. guest_memfd to be handled automatically
based on whether or not we're dealing with a Confidential VM with in-place
conversion enabled.

This approach so far also does not involve gmem bindings to KVM instances,
hence it is not prone to issues when the same chunk of RAM will be attached
to more than one KVM memslots.

Now, instead of using a normal memfd backend using:

  -object memory-backend-memfd,id=ID,size=SIZE,share=on

One can also boot a VM with guest-memfd:

  -object memory-backend-memfd,id=ID,size=SIZE,share=on,guest-memfd=on

The init-shared guest-memfd relies on a recent kernel (6.18+). When run it on
an older qemu, you'll see errors like:

  qemu-system-x86_64: KVM does not support guest_memfd

One thing to mention is live migration is by default supported, however
postcopy is still currently not supported.  The postcopy support will have
some kernel dependency work to be merged in Linux first.

Thanks,

Peter Xu (11):
  kvm: Detect guest-memfd flags supported
  kvm: Provide explicit error for kvm_create_guest_memfd()
  ramblock: Rename guest_memfd to guest_memfd_private
  memory: Rename RAM_GUEST_MEMFD to RAM_GUEST_MEMFD_PRIVATE
  memory: Rename memory_region_has_guest_memfd() to *_private()
  hostmem: Rename guest_memfd to guest_memfd_private
  hostmem: Support fully shared guest memfd to back a VM
  machine: Rename machine_require_guest_memfd() to *_private()
  memory: Rename memory_region_init_ram_guest_memfd() to *_private()
  tests/migration-test: Support guest-memfd init shared mem type
  tests/migration-test: Add a precopy test for guest-memfd

Xiaoyao Li (1):
  kvm: Decouple memory attribute check from kvm_guest_memfd_supported

 qapi/qom.json                         |  6 ++-
 include/hw/boards.h                   |  2 +-
 include/system/hostmem.h              |  2 +-
 include/system/kvm.h                  |  1 +
 include/system/memory.h               | 27 ++++++------
 include/system/ram_addr.h             |  2 +-
 include/system/ramblock.h             |  7 +++-
 tests/qtest/migration/framework.h     |  4 ++
 accel/kvm/kvm-all.c                   | 33 ++++++++++++---
 accel/stubs/kvm-stub.c                |  6 +++
 backends/hostmem-file.c               |  2 +-
 backends/hostmem-memfd.c              | 55 +++++++++++++++++++++---
 backends/hostmem-ram.c                |  2 +-
 backends/hostmem-shm.c                |  2 +-
 backends/hostmem.c                    |  2 +-
 backends/igvm.c                       |  4 +-
 hw/core/machine.c                     |  2 +-
 hw/i386/pc.c                          |  6 +--
 hw/i386/pc_sysfw.c                    |  8 ++--
 hw/i386/x86-common.c                  |  8 ++--
 system/memory.c                       | 17 ++++----
 system/physmem.c                      | 37 ++++++++++-------
 target/i386/kvm/kvm.c                 |  3 +-
 tests/qtest/migration/framework.c     | 60 +++++++++++++++++++++++++++
 tests/qtest/migration/precopy-tests.c | 12 ++++++
 25 files changed, 239 insertions(+), 71 deletions(-)

-- 
2.50.1
Re: [PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends
Posted by Peter Xu 4 days, 16 hours ago
On Wed, Aug 12, 2026 at 03:16:38PM -0500, Michael Roth wrote:
> v1: https://lore.kernel.org/r/20251023185913.2923322-1-peterx@redhat.com
> v2: https://lore.kernel.org/r/20251119172913.577392-1-peterx@redhat.com
> v3: https://lore.kernel.org/r/20251215205203.1185099-1-peterx@redhat.com/
> v4:
> - Picked up v3 series from Peter Xu and rebased on 11.1.0
> - Collected pending Reviewed-by's
> - Per-patch changes:
>   [01/12] Fix blank space (Xiaoyao)
>           Fix commit message typos
>   [02/12] Drop duplicated error-handling for capability checks
>   [05/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
>   [07/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
>   [08/12] Disallow 'seal' and 'hugetlb' options based on guest-memfd=on
>           Fix minor typo in comment
>   [11/12] Fix up typo in g_test_skip() reason
>           Pending: Move kvm_guest_memfd_init_shared_supported() to
>             migration-util.c (Fabiano)
> 
> This patchset is also available at:
> 
>   https://github.com/amdese/qemu/commits/gmem-shared-mem-v4
> 
> and is based on top of v11.1.0

Should I just pick this up?  I'll touch up the commit log that Phil
requested.  Objections welcomed before next week.

-- 
Peter Xu
Re: [PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends
Posted by Michael Roth 2 days, 14 hours ago
On Fri, Aug 21, 2026 at 10:18:26AM -0400, Peter Xu wrote:
> On Wed, Aug 12, 2026 at 03:16:38PM -0500, Michael Roth wrote:
> > v1: https://lore.kernel.org/r/20251023185913.2923322-1-peterx@redhat.com
> > v2: https://lore.kernel.org/r/20251119172913.577392-1-peterx@redhat.com
> > v3: https://lore.kernel.org/r/20251215205203.1185099-1-peterx@redhat.com/
> > v4:
> > - Picked up v3 series from Peter Xu and rebased on 11.1.0
> > - Collected pending Reviewed-by's
> > - Per-patch changes:
> >   [01/12] Fix blank space (Xiaoyao)
> >           Fix commit message typos
> >   [02/12] Drop duplicated error-handling for capability checks
> >   [05/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> >   [07/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> >   [08/12] Disallow 'seal' and 'hugetlb' options based on guest-memfd=on
> >           Fix minor typo in comment
> >   [11/12] Fix up typo in g_test_skip() reason
> >           Pending: Move kvm_guest_memfd_init_shared_supported() to
> >             migration-util.c (Fabiano)
> > 
> > This patchset is also available at:
> > 
> >   https://github.com/amdese/qemu/commits/gmem-shared-mem-v4
> > 
> > and is based on top of v11.1.0
> 
> Should I just pick this up?  I'll touch up the commit log that Phil
> requested.  Objections welcomed before next week.

Hi Peter,

No objection here, although I'll be posting new version of the in-place
conversion support later this week (~Wed-ish) and was planning to an
updated version of this series roughly the same time so which ever way
is best for you.

If you do post one though there's also the missing 'return false' and
dropping the seal=off enforcement that Daniel noticed before we started
talking about introspection fun.

Thanks!

-Mike

> 
> -- 
> Peter Xu
>
Re: [PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends
Posted by Peter Xu 1 day, 17 hours ago
On Sun, Aug 23, 2026 at 10:52:13AM -0500, Michael Roth wrote:
> On Fri, Aug 21, 2026 at 10:18:26AM -0400, Peter Xu wrote:
> > On Wed, Aug 12, 2026 at 03:16:38PM -0500, Michael Roth wrote:
> > > v1: https://lore.kernel.org/r/20251023185913.2923322-1-peterx@redhat.com
> > > v2: https://lore.kernel.org/r/20251119172913.577392-1-peterx@redhat.com
> > > v3: https://lore.kernel.org/r/20251215205203.1185099-1-peterx@redhat.com/
> > > v4:
> > > - Picked up v3 series from Peter Xu and rebased on 11.1.0
> > > - Collected pending Reviewed-by's
> > > - Per-patch changes:
> > >   [01/12] Fix blank space (Xiaoyao)
> > >           Fix commit message typos
> > >   [02/12] Drop duplicated error-handling for capability checks
> > >   [05/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> > >   [07/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> > >   [08/12] Disallow 'seal' and 'hugetlb' options based on guest-memfd=on
> > >           Fix minor typo in comment
> > >   [11/12] Fix up typo in g_test_skip() reason
> > >           Pending: Move kvm_guest_memfd_init_shared_supported() to
> > >             migration-util.c (Fabiano)
> > > 
> > > This patchset is also available at:
> > > 
> > >   https://github.com/amdese/qemu/commits/gmem-shared-mem-v4
> > > 
> > > and is based on top of v11.1.0
> > 
> > Should I just pick this up?  I'll touch up the commit log that Phil
> > requested.  Objections welcomed before next week.
> 
> Hi Peter,

Hi, Michael,

> 
> No objection here, although I'll be posting new version of the in-place
> conversion support later this week (~Wed-ish) and was planning to an
> updated version of this series roughly the same time so which ever way
> is best for you.
> 
> If you do post one though there's also the missing 'return false' and
> dropping the seal=off enforcement that Daniel noticed before we started
> talking about introspection fun.

I didn't mean to repost this series, I meant to pick it up for a pull.
Sorry if it was confusing..

I want to make sure balls are rolling.  From our side, we weren't rush on
this one to land, as we'll need to wait for 1G to settle anyway, but if we
have others (like your in-place series upcoming) pending, I think we should
just land it sooner.

You're right, we need to fix things, I noticed it right after I sent the
email and then I found CI / unit test failing.. but I haven't got a chance
to say..  If you repost please check migration-test with --full, otherwise
the gmemfd test will be skipped.

I have two fixups queued locally, I'll attach it here, please use it
whatever way you like, I'll wait for your repost.  NOTE: I touched up the
hugetlb failure message when I fixed it up myself, but since you'll repost
you can decide; please just treat it as a comment then, I just think the
new err message is less strong because we will support it.

Thanks,

===8<===


From 0a0dd0f808d4f668ac099945ab35a981e1a07bfb Mon Sep 17 00:00:00 2001
From: Peter Xu <peterx@redhat.com>
Date: Fri, 21 Aug 2026 12:16:15 -0400
Subject: [PATCH 1/2] fixup! hostmem: Support fully shared guest memfd to back
 a VM

Signed-off-by: Peter Xu <peterx@redhat.com>
---
 backends/hostmem-memfd.c | 10 ++++++----
 1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/backends/hostmem-memfd.c b/backends/hostmem-memfd.c
index fbe65b00be..6576331441 100644
--- a/backends/hostmem-memfd.c
+++ b/backends/hostmem-memfd.c
@@ -57,14 +57,16 @@ memfd_backend_memory_alloc(HostMemoryBackend *backend, Error **errp)
     }
 
     if (m->guest_memfd) {
+        /*
+         * NOTE: guest-memfd ignores seal=on/off because it always
+         * implicitly seals the FD by definition.
+         */
         if (!backend->share) {
             error_setg(errp, "guest-memfd=on must be used with share=on");
             return false;
-        } else if (m->seal) {
-            error_setg(errp, "guest-memfd=on must be used with seal=off");
-            return false;
         } else if (m->hugetlb) {
-            error_setg(errp, "guest-memfd=on must be used with hugetlb=off");
+            error_setg(errp, "guest-memfd=on doesn't support hugetlb=on yet");
+            return false;
         }
 
         fd = kvm_create_guest_memfd(backend->size,
-- 
2.54.0



From 66ac7b3f2268430106bfe8034ef8460215e9db91 Mon Sep 17 00:00:00 2001
From: Peter Xu <peterx@redhat.com>
Date: Fri, 21 Aug 2026 13:00:09 -0400
Subject: [PATCH 2/2] fixup! tests/migration-test: Add a precopy test for
 guest-memfd

Signed-off-by: Peter Xu <peterx@redhat.com>
---
 tests/qtest/migration/precopy-tests.c | 1 -
 1 file changed, 1 deletion(-)

diff --git a/tests/qtest/migration/precopy-tests.c b/tests/qtest/migration/precopy-tests.c
index 8146f37d61..d57ffcac23 100644
--- a/tests/qtest/migration/precopy-tests.c
+++ b/tests/qtest/migration/precopy-tests.c
@@ -184,7 +184,6 @@ static void test_precopy_tcp_plain(char *name, MigrateCommon *args)
 
 static void test_precopy_tcp_plain_gmemfd(char *name, MigrateCommon *args)
 {
-    args->uri = "tcp:127.0.0.1:0";
     args->start.mem_type = MEM_TYPE_GUEST_MEMFD;
 
     test_precopy_common(args);
-- 
2.54.0


-- 
Peter Xu
Re: [PATCH v4 00/12] KVM/hostmem: Support init-shared guest-memfd as VM backends
Posted by Michael Roth 1 day, 4 hours ago
On Mon, Aug 24, 2026 at 09:17:48AM -0400, Peter Xu wrote:
> On Sun, Aug 23, 2026 at 10:52:13AM -0500, Michael Roth wrote:
> > On Fri, Aug 21, 2026 at 10:18:26AM -0400, Peter Xu wrote:
> > > On Wed, Aug 12, 2026 at 03:16:38PM -0500, Michael Roth wrote:
> > > > v1: https://lore.kernel.org/r/20251023185913.2923322-1-peterx@redhat.com
> > > > v2: https://lore.kernel.org/r/20251119172913.577392-1-peterx@redhat.com
> > > > v3: https://lore.kernel.org/r/20251215205203.1185099-1-peterx@redhat.com/
> > > > v4:
> > > > - Picked up v3 series from Peter Xu and rebased on 11.1.0
> > > > - Collected pending Reviewed-by's
> > > > - Per-patch changes:
> > > >   [01/12] Fix blank space (Xiaoyao)
> > > >           Fix commit message typos
> > > >   [02/12] Drop duplicated error-handling for capability checks
> > > >   [05/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> > > >   [07/12] Fix up commit message, disambigurate "in-place" terminology (Xiaoyao)
> > > >   [08/12] Disallow 'seal' and 'hugetlb' options based on guest-memfd=on
> > > >           Fix minor typo in comment
> > > >   [11/12] Fix up typo in g_test_skip() reason
> > > >           Pending: Move kvm_guest_memfd_init_shared_supported() to
> > > >             migration-util.c (Fabiano)
> > > > 
> > > > This patchset is also available at:
> > > > 
> > > >   https://github.com/amdese/qemu/commits/gmem-shared-mem-v4
> > > > 
> > > > and is based on top of v11.1.0
> > > 
> > > Should I just pick this up?  I'll touch up the commit log that Phil
> > > requested.  Objections welcomed before next week.
> > 
> > Hi Peter,
> 
> Hi, Michael,
> 
> > 
> > No objection here, although I'll be posting new version of the in-place
> > conversion support later this week (~Wed-ish) and was planning to an
> > updated version of this series roughly the same time so which ever way
> > is best for you.
> > 
> > If you do post one though there's also the missing 'return false' and
> > dropping the seal=off enforcement that Daniel noticed before we started
> > talking about introspection fun.
> 
> I didn't mean to repost this series, I meant to pick it up for a pull.
> Sorry if it was confusing..

Ahh ok :) No problem!

> 
> I want to make sure balls are rolling.  From our side, we weren't rush on
> this one to land, as we'll need to wait for 1G to settle anyway, but if we
> have others (like your in-place series upcoming) pending, I think we should
> just land it sooner.

Agreed, LGTM!

> 
> You're right, we need to fix things, I noticed it right after I sent the
> email and then I found CI / unit test failing.. but I haven't got a chance
> to say..  If you repost please check migration-test with --full, otherwise
> the gmemfd test will be skipped.

Ok, I had seen migration-test passing but I didn't run it with full so
I'll look into what's going on there.

> 
> I have two fixups queued locally, I'll attach it here, please use it
> whatever way you like, I'll wait for your repost.  NOTE: I touched up the
> hugetlb failure message when I fixed it up myself, but since you'll repost
> you can decide; please just treat it as a comment then, I just think the
> new err message is less strong because we will support it.

Ok, I'll get these rolled in as well.

Thanks!

-Mike

> 
> Thanks,
> 
> ===8<===
> 
> 
> From 0a0dd0f808d4f668ac099945ab35a981e1a07bfb Mon Sep 17 00:00:00 2001
> From: Peter Xu <peterx@redhat.com>
> Date: Fri, 21 Aug 2026 12:16:15 -0400
> Subject: [PATCH 1/2] fixup! hostmem: Support fully shared guest memfd to back
>  a VM
> 
> Signed-off-by: Peter Xu <peterx@redhat.com>
> ---
>  backends/hostmem-memfd.c | 10 ++++++----
>  1 file changed, 6 insertions(+), 4 deletions(-)
> 
> diff --git a/backends/hostmem-memfd.c b/backends/hostmem-memfd.c
> index fbe65b00be..6576331441 100644
> --- a/backends/hostmem-memfd.c
> +++ b/backends/hostmem-memfd.c
> @@ -57,14 +57,16 @@ memfd_backend_memory_alloc(HostMemoryBackend *backend, Error **errp)
>      }
>  
>      if (m->guest_memfd) {
> +        /*
> +         * NOTE: guest-memfd ignores seal=on/off because it always
> +         * implicitly seals the FD by definition.
> +         */
>          if (!backend->share) {
>              error_setg(errp, "guest-memfd=on must be used with share=on");
>              return false;
> -        } else if (m->seal) {
> -            error_setg(errp, "guest-memfd=on must be used with seal=off");
> -            return false;
>          } else if (m->hugetlb) {
> -            error_setg(errp, "guest-memfd=on must be used with hugetlb=off");
> +            error_setg(errp, "guest-memfd=on doesn't support hugetlb=on yet");
> +            return false;
>          }
>  
>          fd = kvm_create_guest_memfd(backend->size,
> -- 
> 2.54.0
> 
> 
> 
> From 66ac7b3f2268430106bfe8034ef8460215e9db91 Mon Sep 17 00:00:00 2001
> From: Peter Xu <peterx@redhat.com>
> Date: Fri, 21 Aug 2026 13:00:09 -0400
> Subject: [PATCH 2/2] fixup! tests/migration-test: Add a precopy test for
>  guest-memfd
> 
> Signed-off-by: Peter Xu <peterx@redhat.com>
> ---
>  tests/qtest/migration/precopy-tests.c | 1 -
>  1 file changed, 1 deletion(-)
> 
> diff --git a/tests/qtest/migration/precopy-tests.c b/tests/qtest/migration/precopy-tests.c
> index 8146f37d61..d57ffcac23 100644
> --- a/tests/qtest/migration/precopy-tests.c
> +++ b/tests/qtest/migration/precopy-tests.c
> @@ -184,7 +184,6 @@ static void test_precopy_tcp_plain(char *name, MigrateCommon *args)
>  
>  static void test_precopy_tcp_plain_gmemfd(char *name, MigrateCommon *args)
>  {
> -    args->uri = "tcp:127.0.0.1:0";
>      args->start.mem_type = MEM_TYPE_GUEST_MEMFD;
>  
>      test_precopy_common(args);
> -- 
> 2.54.0
> 
> 
> -- 
> Peter Xu
>