From nobody Sun Oct 5 21:49:28 2025 Received: from mail-pl1-f202.google.com (mail-pl1-f202.google.com [209.85.214.202]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 112A8287500 for ; Tue, 29 Jul 2025 22:56:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.202 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753829773; cv=none; b=EXcx6BCD9UpNY07Vo1M1dc9seCSoD5pcT1ovlZaEyyApD/DmQqVEEgz7S1epgCHearO3kYzE3Tyazg6gHmjsGxq1KUDwM8wM2DbVKTIipdB6UCEoMbYii876gRgZgcZYrAehEUiHyBrbafX87e8mdErDCcN1cLfNRtzPFs0aCtk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1753829773; c=relaxed/simple; bh=qqogocRbIPYi2SUEz/6ntDBaPGUsbNkvJFBtuswKct0=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=eVx3HP5hO72BW9sxslbBAKIWrAkvMJWTiGSina/iMfnGt3zazNSPNYeorLNwUuuxdB0qPifx6EkXQsYc15ScEqWv9O8sUt2bTSkhLWThXZQW/XH3Uvy730c0i2OKFYa00ptr98Q42T7LTsHfy5Xe9GITevfm0MpN6DRDDyiw2zw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=s9xSX7MV; arc=none smtp.client-ip=209.85.214.202 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--seanjc.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="s9xSX7MV" Received: by mail-pl1-f202.google.com with SMTP id d9443c01a7336-24011ceafc8so2491145ad.3 for ; Tue, 29 Jul 2025 15:56:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1753829771; x=1754434571; darn=vger.kernel.org; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:from:to:cc:subject:date:message-id:reply-to; bh=iJsEx4FG6bZLukMaYebCB5jI3mya4Bwx9n+hJfoOxy0=; b=s9xSX7MVuGvgRulGqAbBN0BHU5muZ070wf3EqmIYw0YVhHyi00aBoUHrnjZrFM2//k nhRy2ubaSHuEIrE9XeMeVDgBAbtyPf1H/ugYPW5MVglJcOk2KOSpxcccFBlAmhJxdYiZ kmwKhB2yIRVj14+PY3qOQO7w4iXotBkInuM2HcRFavUMuJPyTJoD/0hPVr04wAsNnuhl 9Xr/yq6Hv4vrdgl+jZGgLcZ9127jmKbRMu8eSIfK2WFZMff5GzJPvtcqhFGDrFyfCXyV n91aU/Q4lays16Op2E2NHR+Zkb1bKXQtZLeWUVmQlH2keq2OGCGsJcAXh+QXoe1omqqJ JjCw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1753829771; x=1754434571; h=cc:to:from:subject:message-id:references:mime-version:in-reply-to :date:reply-to:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=iJsEx4FG6bZLukMaYebCB5jI3mya4Bwx9n+hJfoOxy0=; b=qXLrxLVGEJ1qQbHbpSbrqRv/FLxLPPpTqWz0FvG6bigxst9IRZBT9dF6/bm1QSO/uw QsOAKBHuouIWE0yNvislhmqtbrZL4oEi9A3qYWskCT7iR+lqVU3QowGGGkc9ZK72Wxmr AbkjPLASIIth4jwq68BgViwVb2xM822yaVHK7I3Nq8KFZBpzgnPwmbV8eMdPVjxutRfC z5rrKTwczPt9d2ROu9PtbVPG7YucmPYUOAfLhoSGD3md5MOb4pccShzJ9m61OxNwdHSS N2sRJxHoMxWO6CgW2P2vms3EkH1svbxah/f0zn23G1ETJoQ/ax9PoHGTCtAl4dHuL//o nM8g== X-Forwarded-Encrypted: i=1; AJvYcCWbYx0SN1ENh8X31GKTOQG+lO/YIBFdSkK4YgXlaqm2SoweB6yotg6ZYJp+pmh28pheRiywTBgMLCIKPhc=@vger.kernel.org X-Gm-Message-State: AOJu0YzAKdQtIqbrROpG+o/kae2rXjh2D5fHaL7mtiR01/8dArVQv1CX M/EDfP6M+r9M5vUzwP0MQPFtgWuYiFZZgTiS/n6msKYhTCkHETL6uYGYZW4NIONLRrAD4EpP6fH +OZBRlA== X-Google-Smtp-Source: AGHT+IFuvJKbK3bsSX0xIb/YEbZhFW6DEC02S7h04mcxkIxVOmzeLRPCwAt9nWckZ/hRC4rRu0zMmk/gJ8c= X-Received: from pjyr14.prod.google.com ([2002:a17:90a:e18e:b0:31c:2fe4:33b7]) (user=seanjc job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:f652:b0:240:79d5:8df4 with SMTP id d9443c01a7336-24096b499fcmr13337365ad.53.1753829771053; Tue, 29 Jul 2025 15:56:11 -0700 (PDT) Reply-To: Sean Christopherson Date: Tue, 29 Jul 2025 15:54:54 -0700 In-Reply-To: <20250729225455.670324-1-seanjc@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20250729225455.670324-1-seanjc@google.com> X-Mailer: git-send-email 2.50.1.552.g942d659e1b-goog Message-ID: <20250729225455.670324-24-seanjc@google.com> Subject: [PATCH v17 23/24] KVM: selftests: guest_memfd mmap() test when mmap is supported From: Sean Christopherson To: Paolo Bonzini , Marc Zyngier , Oliver Upton , Sean Christopherson Cc: kvm@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, linux-kernel@vger.kernel.org, Ira Weiny , Gavin Shan , Shivank Garg , Vlastimil Babka , Xiaoyao Li , David Hildenbrand , Fuad Tabba , Ackerley Tng , Tao Chan , James Houghton Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" From: Fuad Tabba Expand the guest_memfd selftests to comprehensively test host userspace mmap functionality for guest_memfd-backed memory when supported by the VM type. Introduce new test cases to verify the following: * Successful mmap operations: Ensure that MAP_SHARED mappings succeed when guest_memfd mmap is enabled. * Data integrity: Validate that data written to the mmap'd region is correctly persistent and readable. * fallocate interaction: Test that fallocate(FALLOC_FL_PUNCH_HOLE) correctly zeros out mapped pages. * Out-of-bounds access: Verify that accessing memory beyond the guest_memfd's size correctly triggers a SIGBUS signal. * Unsupported mmap: Confirm that mmap attempts fail as expected when guest_memfd mmap support is not enabled for the specific guest_memfd instance or VM type. * Flag validity: Introduce test_vm_type_gmem_flag_validity() to systematically test that only allowed guest_memfd creation flags are accepted for different VM types (e.g., GUEST_MEMFD_FLAG_MMAP for default VMs, no flags for CoCo VMs). The existing tests for guest_memfd creation (multiple instances, invalid sizes), file read/write, file size, and invalid punch hole operations are integrated into the new test_with_type() framework to allow testing across different VM types. Cc: James Houghton Cc: Gavin Shan Cc: Shivank Garg Co-developed-by: Ackerley Tng Signed-off-by: Ackerley Tng Signed-off-by: Fuad Tabba Co-developed-by: Sean Christopherson Signed-off-by: Sean Christopherson Reviewed-by: Shivank Garg Reviewed-by: Xiaoyao Li --- .../testing/selftests/kvm/guest_memfd_test.c | 161 +++++++++++++++--- 1 file changed, 139 insertions(+), 22 deletions(-) diff --git a/tools/testing/selftests/kvm/guest_memfd_test.c b/tools/testing= /selftests/kvm/guest_memfd_test.c index 341ba616cf55..088053d5f0f5 100644 --- a/tools/testing/selftests/kvm/guest_memfd_test.c +++ b/tools/testing/selftests/kvm/guest_memfd_test.c @@ -13,6 +13,8 @@ =20 #include #include +#include +#include #include #include #include @@ -34,12 +36,83 @@ static void test_file_read_write(int fd) "pwrite on a guest_mem fd should fail"); } =20 -static void test_mmap(int fd, size_t page_size) +static void test_mmap_supported(int fd, size_t page_size, size_t total_siz= e) +{ + const char val =3D 0xaa; + char *mem; + size_t i; + int ret; + + mem =3D mmap(NULL, total_size, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0= ); + TEST_ASSERT(mem =3D=3D MAP_FAILED, "Copy-on-write not allowed by guest_me= mfd."); + + mem =3D mmap(NULL, total_size, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); + TEST_ASSERT(mem !=3D MAP_FAILED, "mmap() for guest_memfd should succeed."= ); + + memset(mem, val, total_size); + for (i =3D 0; i < total_size; i++) + TEST_ASSERT_EQ(READ_ONCE(mem[i]), val); + + ret =3D fallocate(fd, FALLOC_FL_KEEP_SIZE | FALLOC_FL_PUNCH_HOLE, 0, + page_size); + TEST_ASSERT(!ret, "fallocate the first page should succeed."); + + for (i =3D 0; i < page_size; i++) + TEST_ASSERT_EQ(READ_ONCE(mem[i]), 0x00); + for (; i < total_size; i++) + TEST_ASSERT_EQ(READ_ONCE(mem[i]), val); + + memset(mem, val, page_size); + for (i =3D 0; i < total_size; i++) + TEST_ASSERT_EQ(READ_ONCE(mem[i]), val); + + ret =3D munmap(mem, total_size); + TEST_ASSERT(!ret, "munmap() should succeed."); +} + +static sigjmp_buf jmpbuf; +void fault_sigbus_handler(int signum) +{ + siglongjmp(jmpbuf, 1); +} + +static void test_fault_overflow(int fd, size_t page_size, size_t total_siz= e) +{ + struct sigaction sa_old, sa_new =3D { + .sa_handler =3D fault_sigbus_handler, + }; + size_t map_size =3D total_size * 4; + const char val =3D 0xaa; + char *mem; + size_t i; + int ret; + + mem =3D mmap(NULL, map_size, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); + TEST_ASSERT(mem !=3D MAP_FAILED, "mmap() for guest_memfd should succeed."= ); + + sigaction(SIGBUS, &sa_new, &sa_old); + if (sigsetjmp(jmpbuf, 1) =3D=3D 0) { + memset(mem, 0xaa, map_size); + TEST_ASSERT(false, "memset() should have triggered SIGBUS."); + } + sigaction(SIGBUS, &sa_old, NULL); + + for (i =3D 0; i < total_size; i++) + TEST_ASSERT_EQ(READ_ONCE(mem[i]), val); + + ret =3D munmap(mem, map_size); + TEST_ASSERT(!ret, "munmap() should succeed."); +} + +static void test_mmap_not_supported(int fd, size_t page_size, size_t total= _size) { char *mem; =20 mem =3D mmap(NULL, page_size, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); TEST_ASSERT_EQ(mem, MAP_FAILED); + + mem =3D mmap(NULL, total_size, PROT_READ | PROT_WRITE, MAP_SHARED, fd, 0); + TEST_ASSERT_EQ(mem, MAP_FAILED); } =20 static void test_file_size(int fd, size_t page_size, size_t total_size) @@ -120,26 +193,19 @@ static void test_invalid_punch_hole(int fd, size_t pa= ge_size, size_t total_size) } } =20 -static void test_create_guest_memfd_invalid(struct kvm_vm *vm) +static void test_create_guest_memfd_invalid_sizes(struct kvm_vm *vm, + uint64_t guest_memfd_flags, + size_t page_size) { - size_t page_size =3D getpagesize(); - uint64_t flag; size_t size; int fd; =20 for (size =3D 1; size < page_size; size++) { - fd =3D __vm_create_guest_memfd(vm, size, 0); - TEST_ASSERT(fd =3D=3D -1 && errno =3D=3D EINVAL, + fd =3D __vm_create_guest_memfd(vm, size, guest_memfd_flags); + TEST_ASSERT(fd < 0 && errno =3D=3D EINVAL, "guest_memfd() with non-page-aligned page size '0x%lx' should fail = with EINVAL", size); } - - for (flag =3D BIT(0); flag; flag <<=3D 1) { - fd =3D __vm_create_guest_memfd(vm, page_size, flag); - TEST_ASSERT(fd =3D=3D -1 && errno =3D=3D EINVAL, - "guest_memfd() with flag '0x%lx' should fail with EINVAL", - flag); - } } =20 static void test_create_guest_memfd_multiple(struct kvm_vm *vm) @@ -171,30 +237,81 @@ static void test_create_guest_memfd_multiple(struct k= vm_vm *vm) close(fd1); } =20 -int main(int argc, char *argv[]) +static void test_guest_memfd_flags(struct kvm_vm *vm, uint64_t valid_flags) { - size_t page_size; - size_t total_size; + size_t page_size =3D getpagesize(); + uint64_t flag; int fd; + + for (flag =3D BIT(0); flag; flag <<=3D 1) { + fd =3D __vm_create_guest_memfd(vm, page_size, flag); + if (flag & valid_flags) { + TEST_ASSERT(fd >=3D 0, + "guest_memfd() with flag '0x%lx' should succeed", + flag); + close(fd); + } else { + TEST_ASSERT(fd < 0 && errno =3D=3D EINVAL, + "guest_memfd() with flag '0x%lx' should fail with EINVAL", + flag); + } + } +} + +static void test_guest_memfd(unsigned long vm_type) +{ + uint64_t flags =3D 0; struct kvm_vm *vm; - - TEST_REQUIRE(kvm_has_cap(KVM_CAP_GUEST_MEMFD)); + size_t total_size; + size_t page_size; + int fd; =20 page_size =3D getpagesize(); total_size =3D page_size * 4; =20 - vm =3D vm_create_barebones(); + vm =3D vm_create_barebones_type(vm_type); + + if (vm_check_cap(vm, KVM_CAP_GUEST_MEMFD_MMAP)) + flags |=3D GUEST_MEMFD_FLAG_MMAP; =20 - test_create_guest_memfd_invalid(vm); test_create_guest_memfd_multiple(vm); + test_create_guest_memfd_invalid_sizes(vm, flags, page_size); =20 - fd =3D vm_create_guest_memfd(vm, total_size, 0); + fd =3D vm_create_guest_memfd(vm, total_size, flags); =20 test_file_read_write(fd); - test_mmap(fd, page_size); + + if (flags & GUEST_MEMFD_FLAG_MMAP) { + test_mmap_supported(fd, page_size, total_size); + test_fault_overflow(fd, page_size, total_size); + } else { + test_mmap_not_supported(fd, page_size, total_size); + } + test_file_size(fd, page_size, total_size); test_fallocate(fd, page_size, total_size); test_invalid_punch_hole(fd, page_size, total_size); =20 + test_guest_memfd_flags(vm, flags); + close(fd); + kvm_vm_free(vm); +} + +int main(int argc, char *argv[]) +{ + unsigned long vm_types, vm_type; + + TEST_REQUIRE(kvm_has_cap(KVM_CAP_GUEST_MEMFD)); + + /* + * Not all architectures support KVM_CAP_VM_TYPES. However, those that + * support guest_memfd have that support for the default VM type. + */ + vm_types =3D kvm_check_cap(KVM_CAP_VM_TYPES); + if (!vm_types) + vm_types =3D VM_TYPE_DEFAULT; + + for_each_set_bit(vm_type, &vm_types, BITS_PER_TYPE(vm_types)) + test_guest_memfd(vm_type); } --=20 2.50.1.552.g942d659e1b-goog