drivers/xen/balloon.c | 29 +++++++++++++++++++---------- 1 file changed, 19 insertions(+), 10 deletions(-)
The handling of extra memory regions done in balloon_add_regions() is not
correct for PV guests, since the initial target is set to reflect the real
memory the system has, not what's described on the memory map, which can be
higher if memory != maxmem.
Introduce separate logic for addition vs subtraction in
balloon_add_regions() and handle extra regions correctly by adding them to
the total amount of pages, instead of subtracting from the current and
target pages amounts.
In the common case PV domU/dom0 and PVH dom0 will use the addition path,
since the initial target reflects the real assigned memory. HVM and PVH
domUs use the subtraction path, since the target is set based on the amount
of memory reported in the memory map, without accounting for released
regions.
Fixes: 87af633689ce ("x86/xen: fix balloon target initialization for PVH dom0")
Fixes: 0949c646d646 ("Partial revert "x86/xen: fix balloon target initialization for PVH dom0"")
Signed-off-by: Roger Pau Monné <roger@xenproject.org>
Cc: stable@vger.kernel.org
---
Cc: Yannick Martin <yannick.martin@okazoo.eu>
Cc: "Thorsten Leemhuis" <regressions@leemhuis.info>
Cc: Matthias Goergens <matthias.goergens@gmail.com>
---
Changes since v1:
- Also fix PVH dom0 without unpopulated pages support.
- Account for XENMEM_current_reservation possibly failing.
---
drivers/xen/balloon.c | 29 +++++++++++++++++++----------
1 file changed, 19 insertions(+), 10 deletions(-)
diff --git a/drivers/xen/balloon.c b/drivers/xen/balloon.c
index e7f1d4ca6d75..e7f74ea7cd5e 100644
--- a/drivers/xen/balloon.c
+++ b/drivers/xen/balloon.c
@@ -679,7 +679,7 @@ void xen_free_ballooned_pages(unsigned int nr_pages, struct page **pages)
}
EXPORT_SYMBOL(xen_free_ballooned_pages);
-static int __init balloon_add_regions(void)
+static int __init balloon_add_regions(bool append)
{
unsigned long start_pfn, pages;
unsigned long pfn, extra_pfn_end;
@@ -703,19 +703,26 @@ static int __init balloon_add_regions(void)
balloon_append(pfn_to_page(pfn));
/*
- * Extra regions are accounted for in the physmap, but need
- * decreasing from current_pages and target_pages to balloon
- * down the initial allocation, because they are already
- * accounted for in total_pages.
+ * There are two different use-cases depending on how the
+ * initial memory target is fetched. For PVH dom0 and PV the
+ * target is usually set to reflect the domain assigned memory,
+ * and hence extra regions need adding.
+ *
+ * OTOH for HVM and PVH domU the target is set to the amount of
+ * RAM reported in the memory map, and hence extra regions need
+ * subtracting to reflect the real memory usage.
*/
pages = extra_pfn_end - start_pfn;
- if (pages >= balloon_stats.current_pages ||
- pages >= balloon_stats.target_pages) {
+ if (append) {
+ balloon_stats.total_pages += pages;
+ } else if (pages >= balloon_stats.current_pages ||
+ pages >= balloon_stats.target_pages) {
WARN(1, "Extra pages underflow current target");
return -ERANGE;
+ } else {
+ balloon_stats.current_pages -= pages;
+ balloon_stats.target_pages -= pages;
}
- balloon_stats.current_pages -= pages;
- balloon_stats.target_pages -= pages;
}
return 0;
@@ -726,6 +733,7 @@ static int __init balloon_init(void)
struct task_struct *task;
long current_pages = 0;
domid_t domid = DOMID_SELF;
+ bool append = true;
int rc;
if (!xen_domain())
@@ -745,6 +753,7 @@ static int __init balloon_init(void)
} else {
if (xen_unpopulated_pages >= get_num_physpages())
goto underflow;
+ append = false;
current_pages = get_num_physpages() -
xen_unpopulated_pages;
}
@@ -767,7 +776,7 @@ static int __init balloon_init(void)
register_sysctl_init("xen/balloon", balloon_table);
#endif
- rc = balloon_add_regions();
+ rc = balloon_add_regions(append);
if (rc)
return rc;
--
2.53.0
On 05.08.26 11:40, Roger Pau Monne wrote:
> The handling of extra memory regions done in balloon_add_regions() is not
> correct for PV guests, since the initial target is set to reflect the real
> memory the system has, not what's described on the memory map, which can be
> higher if memory != maxmem.
>
> Introduce separate logic for addition vs subtraction in
> balloon_add_regions() and handle extra regions correctly by adding them to
> the total amount of pages, instead of subtracting from the current and
> target pages amounts.
>
> In the common case PV domU/dom0 and PVH dom0 will use the addition path,
> since the initial target reflects the real assigned memory. HVM and PVH
> domUs use the subtraction path, since the target is set based on the amount
> of memory reported in the memory map, without accounting for released
> regions.
>
> Fixes: 87af633689ce ("x86/xen: fix balloon target initialization for PVH dom0")
> Fixes: 0949c646d646 ("Partial revert "x86/xen: fix balloon target initialization for PVH dom0"")
> Signed-off-by: Roger Pau Monné <roger@xenproject.org>
Reviewed-by: Juergen Gross <jgross@suse.com>
Juergen
Hi Roger, v2 looks good to me. Keying append on the source of the initial count covers every case I can construct: by inspection, a domU always enters the fallback branch (current_pages stays 0), so HVM/PVH domU and the dom0 hypercall-failure path share the subtraction branch, while the PV start_info path and a successful dom0 XENMEM_current_reservation append. I also ran it on a nested-KVM Xen rig (Xen 4.23-unstable, Linux 11028ab62899e as dom0, static busybox initramfs): - PV dom0, dom0_mem=2048M,max:4096M and 3072M,max:4096M, CONFIG_XEN_UNPOPULATED_ALLOC=n: no WARN, current_kb matches dom0_mem (2 and 3 GiB respectively). Same with =y. - PVH dom0, same two memory configurations, =n: v1 WARNed in balloon_init and returned -ERANGE in exactly these cases; v2 completes cleanly and the balloon driver initialises. (Scope note: PVH dom0 userspace stalls later in boot under nested KVM for an unrelated reason, so the PVH evidence is boot-time dmesg and the balloon sysfs state.) Tested-by: Matthias Goergens <matthias.goergens@gmail.com> Thanks, Matthias
© 2016 - 2026 Red Hat, Inc.