From nobody Thu Sep 3 07:03:32 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass(p=reject dis=none) header.from=oracle.com ARC-Seal: i=1; a=rsa-sha256; t=1787980099; cv=none; d=zohomail.com; s=zohoarc; b=LnX0AR7IW6bnUINX66PUsWrdulP1XvJG01DRKik1nRy/CT6uFEcfVpJNEbPaZar+ddrZbNqFP8rAoWzc5fXWY+v5vYgSBh09o7R9Y7pmhpM6h7CvMR57DojMx+eGYB0QioMHe+/1Ud3MwDKNa++bxaMw1q82z5oZG2UBcXUgOFU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1787980099; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=oW5UFRBVvmLX6waJJvDC7VRRMFdstu+Xd77ISLIKXY0=; b=PWBfCZx1dWEHDVz6QOUq0KvWSnmk8TZ1PaU7LxIvo2kfhZFHtCj4qtBf1WhrhBITpx5P9142qNjzcnQChBvx6k0NkcFniWTBt9xyI1ld7OhVxJfxjG4KGSELBUTbAj7O7rca8Bdy2BzOcmBPT3u4EUjfJhHg0hNrevCUwSJAAuY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 178798009933382.15011071528284; Fri, 28 Aug 2026 22:08:19 -0700 (PDT) Received: from list by lists.xenproject.org with outflank-mailman.1402615.1637620 (Exim 4.92) (envelope-from ) id 1x0BIM-0007H6-7e; Sat, 29 Aug 2026 05:07:58 +0000 Received: by outflank-mailman (output) from mailman id 1402615.1637620; Sat, 29 Aug 2026 05:07:58 +0000 Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x0BIM-0007Gy-3H; Sat, 29 Aug 2026 05:07:58 +0000 Received: by outflank-mailman (input) for mailman id 1402615; Sat, 29 Aug 2026 05:07:56 +0000 Received: from mx.expurgate.net ([195.190.135.20]) by lists.xenproject.org with esmtp (Exim 4.92) (envelope-from ) id 1x0BIK-0007Gc-DD for xen-devel@lists.xenproject.org; Sat, 29 Aug 2026 05:07:56 +0000 Received: from mx.expurgate.net (helo=localhost) by mx.expurgate.net with esmtp id 1x0BIJ-00GNLT-Ab for xen-devel@lists.xenproject.org; Sat, 29 Aug 2026 07:07:55 +0200 Received: from [10.42.69.9] (helo=localhost) by localhost with ESMTP (eXpurgate MTA 0.9.1) (envelope-from ) id 6a926906-8faa-0a2a0a5109dd-0a2a4509e760-34 for ; Sat, 29 Aug 2026 07:07:55 +0200 Received: from [205.220.165.32] (helo=mx0a-00069f02.pphosted.com) by tlsNG-bad1c0.mxtls.expurgate.net with ESMTPS (eXpurgate 4.57.1) (envelope-from ) id 6a926929-be1a-0a2a45090019-cddca5200b40-3 for ; Sat, 29 Aug 2026 07:07:54 +0200 Received: from pps.filterd (m0246617.ppops.net [127.0.0.1]) by mx0b-00069f02.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67T4j77Y024032; Sat, 29 Aug 2026 05:07:43 GMT Received: from phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta02.appoci.oracle.com [147.154.114.232]) by mx0b-00069f02.pphosted.com (PPS) with ESMTPS id 4gbqyrr0t3-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sat, 29 Aug 2026 05:07:42 +0000 (GMT) Received: from pps.filterd (phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (8.18.1.7/8.18.1.7) with ESMTP id 67T53x0n035474; Sat, 29 Aug 2026 05:07:41 GMT Received: from pps.reinject (localhost [127.0.0.1]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTPS id 4gbnvbawh6-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Sat, 29 Aug 2026 05:07:41 +0000 (GMT) Received: from phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com [127.0.0.1]) by pps.reinject (8.18.1.12/8.18.1.12) with ESMTP id 67T56FsB001517; Sat, 29 Aug 2026 05:07:41 GMT Received: from setje-aarch64-ol9-builds.osdevelopmeniad.oraclevcn.com (setje-aarch64-ol9-builds.allregionaliads.osdevelopmeniad.oraclevcn.com [100.100.248.24]) by phxpaimrmta02.imrmtpd1.prodappphxaev1.oraclevcn.com (PPS) with ESMTP id 4gbnvbaw2h-2; Sat, 29 Aug 2026 05:07:41 +0000 (GMT) X-Outflank-Mailman: Message body and most headers restored to incoming version X-BeenThere: xen-devel@lists.xenproject.org List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Errors-To: xen-devel-bounces@lists.xenproject.org Precedence: list Sender: "Xen-devel" Authentication-Results: eu.smtp.expurgate.cloud; dkim=pass header.s=corp-2025-04-25 header.d=oracle.com header.i="@oracle.com" header.h="Cc:Content-Transfer-Encoding:Date:From:In-Reply-To:Message-ID:MIME-Version:References:Subject:To" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oracle.com; h=cc :content-transfer-encoding:date:from:in-reply-to:message-id :mime-version:references:subject:to; s=corp-2025-04-25; bh=oW5UF RBVvmLX6waJJvDC7VRRMFdstu+Xd77ISLIKXY0=; b=MA/NCrF+vyWp+yHEkrcWa GomxF8CvVRgE10apE1Ze3cNUOPakmhN1r+cbQaZTUK4SP4NpcF3ijeuAW+qZ8TXq Na1pUxxP8Jug95OEo3U2rKjXUJayk/4Pt2Hgfm+0stcZOj9x6JO0G5N2ruFibLk7 gKh0ZwrWzWP/uoyn7eZ5qSTfgRTvvbP1KP7gzlWnZtK2D6DpfxeT/0Tt/8JKx3tN 9nBXpdqTOXS1ECowyDygIWyAeJ8miINgDecFbAbrsu/026/DkqVuor6pqjvGS30X dUPYxUQEe3IF0JamFKyyuT6R8PQCiPvFNgFKE1OabqLC/g2ZRBKocHDQXd4tHqCT g== From: Jan Setje-Eilers To: Jan Setje-Eilers , xen-devel@lists.xenproject.org Cc: Andrew Cooper , Anthony PERARD , Michal Orzel , Jan Beulich , Julien Grall , =?UTF-8?q?Roger=20Pau=20Monn=C3=A9?= , Stefano Stabellini , Bertrand Marquis , Volodymyr Babchuk Subject: [RFC PATCH 1/1] static-memory: allow skipping the cache flush Date: Sat, 29 Aug 2026 05:06:11 +0000 Message-ID: <20260829050611.3353566-2-Jan.SetjeEilers@oracle.com> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260829050611.3353566-1-Jan.SetjeEilers@oracle.com> References: <20260829050611.3353566-1-Jan.SetjeEilers@oracle.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-29_01,2026-08-27_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=notspam policy=default score=0 mlxlogscore=999 mlxscore=0 lowpriorityscore=0 suspectscore=0 adultscore=0 bulkscore=0 malwarescore=0 spamscore=0 phishscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.19.0-2606160000 definitions=main-2608290041 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODI5MDA0MiBTYWx0ZWRfX7kH/mzWCzH/7 PB9bV8u8p+USg+Nv8wdvNtKt6rxJDTUlXsktgYL3DsaweNV+H5yoveemIbaao8E1+S3Ed0cZ8Dn VRjALdWOPE6gHHHmAjfWezLPm9Mj9Orw1JAt1aCaMODJ/mwUq+xalokSMYnIVn/jdyewri3MFgq q9V/Zcfn7D1B8ZRznB31XiwbjfF8zAsM2AR4CmBTJnCL3EneUT0O0CPdhqvTGA3JWvf1HCYOJw4 QHJgRmz3eL2muPJoDMSc8vtmo/2qKXjFc/WTAkruDf/o8NTXfE4CvBRVabN3IUI0HwZiNiO7RXi BvwWO45Ekrn4wGJe3TbdYu9vpNdgL+6uCenUAWLOJaho87rKiKbCLYagLKLx8GTx98Dvqg6HCV6 5a5UejfzKBysNC6nPm0DYuiDO/VoHGACCEE9gvrKfHkhzPAstnoo4nI+Pbx8LwPtLUfl+e1piJZ Y2cSHVQDQ2Sji9OvS/A== X-Proofpoint-ORIG-GUID: JgDE75mghZLD7eF-8FUP-Rt00u3MJRls X-Authority-Analysis: v=2.4 cv=fbCdDUQF c=1 sm=1 tr=0 ts=6a92691e cx=c_pps a=OOZaFjgC48PWsiFpTAqLcw==:117 a=OOZaFjgC48PWsiFpTAqLcw==:17 a=Sv0fKeRqtYgA:10 a=VkNPw1HP01LnGYTKEx00:22 a=jiCTI4zE5U7BLdzWsZGv:22 a=7Gl3-_t3PgB9XO-mQDs3:22 a=yPCof4ZbAAAA:8 a=TQ28Xt2rEOyNch8bdtYA:9 X-Proofpoint-GUID: JgDE75mghZLD7eF-8FUP-Rt00u3MJRls X-Proofpoint-Spam-Info: AW1haW4tMjYwODI5MDA0MiBTYWx0ZWRfXw7lxSff8ipoI QuPrCIgOO5eUV7YTLWe6D1uvBha1OEopTfSl6AI7VRfEXC4WYsJlEuT/JBdwaX24obdNM9GqlpC 4ShqNCidQRu3RuEy/eo/lM946h/JOI5IZ9zPUv8HsL/U6lHpvCw5 X-purgate-ID: tlsNG-bad1c0/1787980075-FC817034-F07CCC95/0/0 X-purgate-type: clean X-purgate-size: 6323 X-ZohoMail-DKIM: pass (identity @oracle.com) X-ZM-MESSAGEID: 1787980102573154100 Content-Type: text/plain; charset="utf-8" Static memory acquisition follows the same cache-coherency policy as ordinary heap allocation. Xen therefore cleans and invalidates every page in each xen,static-mem bank before assigning it to a domain. Static-memory support is currently enabled only on Arm, but its implementation and this acquisition path are in common code. This cache maintenance is independent of boot scrubbing, which clears memory. With bootscrub=3D1 or the default bootscrub=3Didle, create_domUs() acquires static banks before heap_init_late() starts boot scrubbing. The pages are in-use by then, while boot scrubbing processes only free pages. Neither mode therefore clears an assigned static bank. Walking a large static bank can add several seconds to boot, including time spent flushing pages Xen does not touch during domain construction. If a platform permits those untouched pages to be cleared before guest start, the guest cannot depend on their incoming contents. This is a platform policy assumption, not a property established by Xen's boot scrubbing. Xen need not make that initial data coherent with RAM. Xen still cleans every page it writes while loading the guest kernel, initrd, and device tree. Add the default-on staticmem-cache-flush option. Specifying no-staticmem-cache-flush passes MEMF_no_cache_flush when acquiring a xen,static-mem bank. The existing behavior remains the default, and static shared memory is unaffected. Skipping the flush is safe only if the platform also guarantees that the untouched pages are absent from all caches and no other agent writes them before guest start. Such agents include firmware, non-coherent DMA, and EL3 runtime services. Assisted-by: Codex:GPT-5 Signed-off-by: Jan Setje-Eilers --- docs/misc/xen-command-line.pandoc | 26 ++++++++++++++++++++++++++ xen/common/device-tree/static-memory.c | 9 ++++++++- xen/common/page_alloc.c | 6 ++++-- xen/include/xen/mm.h | 2 ++ 4 files changed, 40 insertions(+), 3 deletions(-) diff --git a/docs/misc/xen-command-line.pandoc b/docs/misc/xen-command-line= .pandoc index 1c711fa980..3f5c27858c 100644 --- a/docs/misc/xen-command-line.pandoc +++ b/docs/misc/xen-command-line.pandoc @@ -2647,6 +2647,32 @@ On Sappire and Emerald Rapids CPUs with May 2025 mic= rocode or later, the `ibpb-alt=3D` option can be used to switch to the alternative mitigation f= or Intel SA-00982. Intel suggest that some workloads will benefit from this. =20 +### staticmem-cache-flush (arm) +> `=3D ` + +> Default: `true` + +Control the up-front per-page cache flush over dom0less `xen,static-mem` +banks. Specify `no-staticmem-cache-flush` to skip it. Xen still cleans the +guest kernel, initrd, and device tree pages it writes to guest RAM. + +Static-memory support is currently available only on Arm. Its implementati= on +and this option live in common code. + +Here, cleaning means cache maintenance, not boot scrubbing. With +`bootscrub=3D1` or the default `bootscrub=3Didle`, Xen assigns dom0less st= atic +banks before boot scrubbing starts. Assigned pages are no longer free, so +boot scrubbing does not clear them. This option is therefore independent of +`bootscrub`. + +Only disable this flush when the guest does not depend on the initial cont= ents +of pages Xen leaves untouched. For example, this may be true when the plat= form +permits those pages to be cleared before guest start. + +The platform must also ensure that those pages are absent from all caches = and +rule out other writers before guest start. Such writers may include +non-coherent DMA or EL3 runtime services active during domain construction. + ### sync_console > `=3D ` =20 diff --git a/xen/common/device-tree/static-memory.c b/xen/common/device-tre= e/static-memory.c index ffbc12aa24..ed155d162d 100644 --- a/xen/common/device-tree/static-memory.c +++ b/xen/common/device-tree/static-memory.c @@ -1,10 +1,15 @@ /* SPDX-License-Identifier: GPL-2.0-only */ =20 +#include +#include #include #include =20 #include =20 +static bool __initdata opt_staticmem_cache_flush =3D true; +boolean_param("staticmem-cache-flush", opt_staticmem_cache_flush); + static bool __init append_static_memory_to_bank(struct domain *d, struct membank *bank, mfn_t smfn, @@ -54,7 +59,9 @@ static mfn_t __init acquire_static_memory_bank(struct dom= ain *d, } =20 smfn =3D maddr_to_mfn(*pbase); - res =3D acquire_domstatic_pages(d, smfn, PFN_DOWN(*psize), 0); + res =3D acquire_domstatic_pages(d, smfn, PFN_DOWN(*psize), + opt_staticmem_cache_flush ? 0 : + MEMF_no_cache_flush); if ( res ) { printk(XENLOG_ERR diff --git a/xen/common/page_alloc.c b/xen/common/page_alloc.c index 1e47f38721..b2ede17bd2 100644 --- a/xen/common/page_alloc.c +++ b/xen/common/page_alloc.c @@ -3094,8 +3094,10 @@ static struct page_info * __init acquire_staticmem_p= ages(mfn_t smfn, * Ensure cache and RAM are consistent for platforms where the guest * can control its own visibility of/through the cache. */ - for ( i =3D 0; i < nr_mfns; i++ ) - flush_page_to_ram(mfn_x(smfn) + i, !(memflags & MEMF_no_icache_flu= sh)); + if ( !(memflags & MEMF_no_cache_flush) ) + for ( i =3D 0; i < nr_mfns; i++ ) + flush_page_to_ram(mfn_x(smfn) + i, + !(memflags & MEMF_no_icache_flush)); =20 return pg; } diff --git a/xen/include/xen/mm.h b/xen/include/xen/mm.h index fd8b0ba3f5..511bbc56e0 100644 --- a/xen/include/xen/mm.h +++ b/xen/include/xen/mm.h @@ -228,6 +228,8 @@ struct npfec { #define MEMF_no_icache_flush (1U<<_MEMF_no_icache_flush) #define _MEMF_no_scrub 8 #define MEMF_no_scrub (1U<<_MEMF_no_scrub) +#define _MEMF_no_cache_flush 9 +#define MEMF_no_cache_flush (1U<<_MEMF_no_cache_flush) #define _MEMF_node 16 #define MEMF_node_mask ((1U << (8 * sizeof(nodeid_t))) - 1) #define MEMF_node(n) ((((n) + 1) & MEMF_node_mask) << _MEMF_node) --=20 2.47.3