[PATCH v8 0/8] KVM: x86: nSVM: Improve PAT virtualization

Jim Mattson posted 8 patches 1 week, 1 day ago
Documentation/virt/kvm/api.rst  | 26 ++++++++++++++
arch/x86/include/asm/kvm_host.h |  3 +-
arch/x86/include/uapi/asm/kvm.h |  2 ++
arch/x86/kvm/svm/nested.c       | 64 ++++++++++++++++++++++++---------
arch/x86/kvm/svm/svm.c          | 41 +++++++++++++++++----
arch/x86/kvm/svm/svm.h          | 18 +++++++++-
6 files changed, 130 insertions(+), 24 deletions(-)
[PATCH v8 0/8] KVM: x86: nSVM: Improve PAT virtualization
Posted by Jim Mattson 1 week, 1 day ago
Currently, KVM's implementation of nested SVM treats the PAT MSR the same
way whether or not nested NPT is enabled: L1 and L2 share a single
PAT. However, the AMD APM specifies that when nested NPT is enabled, the host
(L1) and the guest (L2) should have independent PATs: hPAT for L1 and gPAT
for L2.

This patch series implements independent PATs for L1 and L2 when nested NPT
is enabled, but only when a new quirk, KVM_X86_QUIRK_NESTED_SVM_SHARED_PAT,
is disabled. By default, the quirk is enabled, preserving KVM's legacy
behavior. When the quirk is disabled, KVM correctly virtualizes a separate
PAT register for L2, using the g_pat field in the VMCB.

Guest accesses to the IA32_PAT MSR are redirected to either hPAT or gPAT
depending on the current mode and whether nested NPT is enabled. All other
accesses, including userspace accesses via KVM_{GET,SET}_MSRS, continue to
reference hPAT. L2's gPAT is saved and restored via a new 'gpat' field in
kvm_svm_nested_state_hdr, which is within the existing padding of the header
to maintain ABI compatibility.

v1: https://lore.kernel.org/kvm/20260113003016.3511895-1-jmattson@google.com/
v2: https://lore.kernel.org/kvm/20260115232154.3021475-1-jmattson@google.com/
v3: https://lore.kernel.org/kvm/20260205214326.1029278-1-jmattson@google.com/
v4: https://lore.kernel.org/kvm/20260212155905.3448571-1-jmattson@google.com/
v5: https://lore.kernel.org/kvm/20260224005500.1471972-1-jmattson@google.com/
v6: https://lore.kernel.org/kvm/20260326174944.3820245-1-jmattson@google.com/
v7: https://lore.kernel.org/kvm/20260327234023.2659476-1-jmattson@google.com/

  v7 -> v8:
* Indentation changes to conform to Sean's aesthetic [Sean]
* Updated comment in svm_pat_accesses_gpat() [Sean]
* Restored the common behavior for get/set IA32_PAT [Sean]
* Reordered declarations in svm_set_nested_state() for ASCII art [Sean]
* Dropped the selftest [Sean]

Jim Mattson (8):
  KVM: x86: Define KVM_X86_QUIRK_NESTED_SVM_SHARED_PAT
  KVM: x86: nSVM: Clear VMCB_NPT clean bit when updating hPAT from guest
    mode
  KVM: x86: nSVM: Cache and validate vmcb12 g_pat
  KVM: x86: nSVM: Set vmcb02.g_pat correctly for nested NPT
  KVM: x86: nSVM: Redirect IA32_PAT accesses to either hPAT or gPAT
  KVM: x86: nSVM: Save gPAT to vmcb12.g_pat on VMEXIT
  KVM: Documentation: document KVM_{GET,SET}_NESTED_STATE for SVM
  KVM: x86: nSVM: Save/restore gPAT with KVM_{GET,SET}_NESTED_STATE

 Documentation/virt/kvm/api.rst  | 26 ++++++++++++++
 arch/x86/include/asm/kvm_host.h |  3 +-
 arch/x86/include/uapi/asm/kvm.h |  2 ++
 arch/x86/kvm/svm/nested.c       | 64 ++++++++++++++++++++++++---------
 arch/x86/kvm/svm/svm.c          | 41 +++++++++++++++++----
 arch/x86/kvm/svm/svm.h          | 18 +++++++++-
 6 files changed, 130 insertions(+), 24 deletions(-)

-- 
2.53.0.1213.gd9a14994de-goog