From nobody Mon Sep 28 13:59:18 2026 Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86030399CED for ; Thu, 20 Aug 2026 23:32:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268763; cv=none; b=TWqUC+FNzPdJpfQuhmSHla+IivZehb3xq8rSCsrCiAcrN65hEidni6Xnae2GvwTYObwGog+RggkwzB1nuKDnlkX+FhkZo3gA2Uej6oEQheDV+GXcn2c8vilF7KWqD7/xF0C3leA3ViJrorcg6bMBkYrxIc84SWoGfytuoT4f0AQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268763; c=relaxed/simple; bh=mNa+pOHnNs9fqxuQsPFY+ubnJ/wGpTSJgDScv2kh/cw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=GFy//iDwPCcIo0c6OMobXqBcIkzfNOANu8nsrV93zfUBGKnDZ6PILPNcXQdx1f1Gz4+gpkkvzvZ2t12ja/gbunnbFRnM/IlReSSOuqxQkzacoVHFL+2Vo4V3BxQHYSr3xOsJLYuW0OCxX7dY3jy7DwSveVuBHiVjPLP4IkplwnE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=hvEkbvE2; arc=none smtp.client-ip=209.85.210.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="hvEkbvE2" Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-84842381150so378039b3a.3 for ; Thu, 20 Aug 2026 16:32:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787268762; x=1787873562; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=GOtJGHo3/D29WlRaeSux3KPdmxoRq/W1Kkt3/Ky2TK4=; b=hvEkbvE25vc9nz9jmZFRPmNbsPbZTtIzB8iTTIowOgD6INXhwv8/lj8kxmh0uliBVa kwuMNWwi8UKNUYFZbCm17u315eeFWzPvkNXWmf1vqvbJweZA7JqtfdMRKMtGpIc6bY6c aeRcQZGWXSmnXIUnkixmTvKvhRLuy5RWHrQgX4dS7okNi8RIcnqOsDZpfKXhjjcHqU3G 84QEomPr2zRNLsueq1SQIaeq08oaI2p+brPdET0eLLQUfgcT3w5Bu34k2imYmaZoKhws kHr+Eo1GufialTD/Abd5lao1TDD1NDzhGCqyzkmf80TMBvJCEHgMoPx3Bf2mYPnY0Liz 9vnA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787268762; x=1787873562; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=GOtJGHo3/D29WlRaeSux3KPdmxoRq/W1Kkt3/Ky2TK4=; b=OHpeZPk4jQDd1GXq/6hbP0Y8sbX7tkt595iJFcmXh1p8JrZNhRsoyPh10aWbnYn0Y0 /hqw83lUl++m8TYHQdqvuZ7ufrHCpVCBaJQe1088TNv0hyBIzYuVXCQ275dgtv6nrEu0 8B3IqkI+AZOzCQKTjYW8wJ/2yFw6idNGxCSgCu8xCtl0MCclBlAr7VCaA7WK9ifEBjs7 rSfovSIloDxApKPVObs6LhX0brkRwGRKRD+S0mDwhqA9y596NFkTu+/tS/5ZWK6sHp8N vmB6Itsd9lRgjCfxj83Z4lu+nKb9g2neRzo7Jx0Y6EhaBwI7XvDf9D8YuBMaZeTeqfWB zOwQ== X-Forwarded-Encrypted: i=1; AHgh+RokH5h9eEsiwcHg8l55I31njNqG0NXmSneaKvzWyL95B3fiu2W8519hv14NbrOtt3tDTVwJtQS26La0ot0=@vger.kernel.org X-Gm-Message-State: AFuF++k8Hy9VToNyuGhW+ljdRYp5XY/Do3IqN+Nbvpnnp7k8IVet6UC7 u6VygiR9egHBnVU7HlO/diXVn2W6d2rWFyC09QlIYt5oWQccZGq9T2XX1yPEKTGWn6WhcUaLx2G ZueqXnCX9s6sS+X/z6cNAlKTv0g== X-Received: from pgp16-n2.prod.google.com ([2002:a05:6a02:62d0:20b0:c86:5f41:8c94]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:bb91:b0:84e:2382:f4f0 with SMTP id d2e1a72fcca58-851f9a4b169mr3008115b3a.4.1787268761627; Thu, 20 Aug 2026 16:32:41 -0700 (PDT) Date: Thu, 20 Aug 2026 23:32:34 +0000 In-Reply-To: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787268758; l=2054; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=mNa+pOHnNs9fqxuQsPFY+ubnJ/wGpTSJgDScv2kh/cw=; b=6jdqB/w2bbq3ZNh0ffVDxVWzMNTWlrX73bzku35jkm0BU43Yrh40zgvuTo6drlCXWWiORe1p+ oG8cHQn44j5ACK9QKezxII+AIYAkCbRDpSItfDEuBO1ZfxEg/YLwW8A X-Mailer: b4 0.16.0 Message-ID: <20260820-gmem-no-return-page-v3-1-3bf8f80a7b4d@google.com> Subject: [PATCH v3 1/4] KVM: SEV: Treat unassigned RMP entry as benign race on PSMASH failure From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Fuad Tabba , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When handling an RMP fault, KVM attempts to split a 2MB page via PSMASH. If PSMASH fails, the only expected return value is FAIL_BADADDR, which does not distinguish the reason for the bad address. Hence, another RMP entry lookup is required to determine whether the failure was benign. Specifically, KVM re-checks the RMP entry to determine if another CPU raced and already smashed the entry into 4KB pages. A concurrent operation (such as guest_memfd truncation or hole punching) can also race and transition the page to shared, removing the page from the RMP table and causing PSMASH to fail. This can happen even if the page is still referenced by KVM, because guest_memfd reclaim transitions the RMP entry to shared when the folio is removed from the page cache. Treat an unassigned RMP entry as an expected race when re-checking after a failed PSMASH, and skip logging an error warning. Fixes: c63cf135cc99 ("KVM: SEV: Add support to handle RMP nested page fault= s") Reviewed-by: Michael Roth Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index fcb41dfde4c02..b2738362a928b 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -5074,10 +5074,11 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) /* * Look it up again. If it's 4K now then the PSMASH may have * raced with another process and the issue has already resolved - * itself. + * itself. If it's not assigned, then this must have raced with + * another process that made this page shared. */ if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && - assigned && rmp_level =3D=3D PG_LEVEL_4K) + ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) goto out; =20 pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN 0= x%llx ret %d\n", --=20 2.55.0.766.g2966f0265a-goog From nobody Mon Sep 28 13:59:18 2026 Received: from mail-pf1-f199.google.com (mail-pf1-f199.google.com [209.85.210.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 501D538F258 for ; Thu, 20 Aug 2026 23:32:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.199 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268770; cv=none; b=Say5SOQE/aDUc+YglS16M1Y8Hiy2UtVuh10tXED2uvuBPoPc/XE21X5+M2fuh695hjTm81eLGr9pRc4NncL8LQCPz7sgXhXXJuRDsEScVfuMijQfbID+qq/m6D8U21pOFINkR8WpkMuA7u9+Tc27y4CzVo0rKFZfEnKW1wMaymk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268770; c=relaxed/simple; bh=LtICGHiNmjgfsS++ex4KQnpy0xO35NrIf5VSNcMhCjw=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=SvjArTRJxtUhhgSirvtJ6Sp3kBL2ObvC6pqSjQ1gM1WFfpnznUWiEtvpEcvAysA1HQPJ13dFBtgfwRUwXKEpFF/AVmXFGMfRrJg/6kW4ZitAP6kc86Eh4Qd2yqC3DwO2dw7dmpa/ikgTQSYOKOjSsO3mLLU+le0ZU4ycb6kRyi4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=MZ0GTzHl; arc=none smtp.client-ip=209.85.210.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="MZ0GTzHl" Received: by mail-pf1-f199.google.com with SMTP id d2e1a72fcca58-848d21bbb55so532249b3a.0 for ; Thu, 20 Aug 2026 16:32:44 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787268763; x=1787873563; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=ZIY2AhPPQzV0SpGVac6m1vEhtgYyPU90RiUZoPMOP+0=; b=MZ0GTzHlTyR8FhQN35ku/wfFhcaJgFY+bFo7qpq56Y2N0R0JtnvnKYBCvQdug5mmmt 0Xsvad8DppOFqyrxSdz1QDpumpbEsqSQHzcS4QwSMicBt+F+Z7ddqOaiA7R+ypPsLAcE C/6+lt1vLgadMZ3bAnvaJo69DW/hQNexhJtyLPVUy8jL0Cn2mo+pBrpo0ribkVRqH4Ur i0oZFnwZuIi32PmjCCgqdiGDEVfVGs2ARh2SmufCJc7CDHJbSocQ4yqG9+xRVuzbhDqw +NnyJ1y91y8wn4N3ZbhAWSo2F/ppU1tn6OmwZ6mI7fGdYPTTpX50zjGTodkQPrl5mjtw neUA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787268763; x=1787873563; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ZIY2AhPPQzV0SpGVac6m1vEhtgYyPU90RiUZoPMOP+0=; b=T6YoM+oUFOxWfv66Qz370N9+r8ApHR7AjqYCdG4/bJ5hKfbtQ3B+vTYZP1oQdXykR3 0M2ugeeYIBbRJC+ZYUH+f+qoca5J0bVvM+hmmAQKjffvAHY/OL2EOIOMGfiKaaovfgo7 lzTwhB6aI/6o685vLF9iTiNHyb9wevMszKkonzIEdo5WVTpouiqmWWB6FBDxM0fcjU1z wHOclOTangcciKksXJbci8+a8jjCcPFjYokfinU/BAoj7qFwGDWD+7cIPd/ChO0lzBtb xdWeG7ViRRl8u2czyNH3nmsuQydVUTNi8iYVXlQoTWhdBMjXiuuVbVoV0xXDfyhhJ28i Ugog== X-Forwarded-Encrypted: i=1; AHgh+RqqBh6kTLd8u/r2V0zSUEMY7Vzs7J4vuXduJF3otGUCoVJTPUEM6W/wyvO6m0BHmB/LlbVT33tPNlww8N0=@vger.kernel.org X-Gm-Message-State: AOJu0YzAV+o0mB1v3M51yT3Pbx8O/Yb5JeqUtRFJeAe57vq7GzokqZ2U q/gWIvohDOouUO8vmvUcwnQ4xQhSNXha3Po227oY/Q1UiKShkcqeJ0WKNWhd2nhg3FmguH3irZz O/gF7hjCnakg3/G6arXjrngsLug== X-Received: from pgbdn2.prod.google.com ([2002:a05:6a02:e02:b0:cc1:577a:be35]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:3511:b0:3bf:6acf:2940 with SMTP id adf61e73a8af0-3cd30060d76mr4159740637.11.1787268763335; Thu, 20 Aug 2026 16:32:43 -0700 (PDT) Date: Thu, 20 Aug 2026 23:32:35 +0000 In-Reply-To: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787268758; l=4467; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=gmGK5vSp2T3AX5rxyH8TZSoWy4Yohm1Gq2bGrUFDfX0=; b=uZp0bfS9zqFoFKgb9NG/wM0fl/ZiJb3zgvRPUCdq8MfxfHKHAx6mFHPHhfUBhuv0P/o7ih6Az Be0oeIuNnL1BRBWOzUneSjBWLU2ui04EGXoIzvLkwmam2EaiBS3N1/F X-Mailer: b4 0.16.0 Message-ID: <20260820-gmem-no-return-page-v3-2-3bf8f80a7b4d@google.com> Subject: [PATCH v3 2/4] KVM: SEV: Drop page refcount early during RMP fault handling From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Fuad Tabba , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Sean Christopherson When handling an RMP fault, KVM retrieves the PFN for a private GPA from guest_memfd. Drop the page reference immediately after retrieving the PFN instead of holding it across the entire handler, and adopt the KVM MMU invalidation protocol. To avoid wrongly warning about not finding an assigned RMP entry if an invalidation had taken place, check for invalidations before warning. When the RMP level is 4K, the function exits. That doesn't need checking for invalidations, since if it is 4K and there was an invalidation, not psmashing and not zapping is the right thing to do. If the RMP level is 2M (the only other option), use the invalidation protocol before attempting to psmash. This ensures that if the page is truncated and freed, and then re-allocated to another SNP VM (the RMP entry is now assigned, but to another SNP VM), psmashing would be correctly skipped. A later patch will follow up with completely not returning refcounted pages from kvm_gmem_get_pfn(). Signed-off-by: Sean Christopherson Reviewed-by: Michael Roth Co-developed-by: Ackerley Tng Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 47 ++++++++++++++++++++++++++++++----------------- 1 file changed, 30 insertions(+), 17 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index b2738362a928b..563870342a2ba 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -5003,6 +5003,7 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa_= t gpa, u64 error_code) struct kvm_memory_slot *slot; struct kvm *kvm =3D vcpu->kvm; int order, rmp_level, ret; + unsigned long mmu_seq; struct page *page; bool assigned; kvm_pfn_t pfn; @@ -5030,18 +5031,26 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) return; } =20 + mmu_seq =3D kvm->mmu_invalidate_seq; + smp_rmb(); + ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &page, &order); if (ret) { pr_warn_ratelimited("SEV: Unexpected RMP fault, no backing page for priv= ate GPA 0x%llx\n", gpa); return; } + kvm_release_page_unused(page); =20 ret =3D snp_lookup_rmpentry(pfn, &assigned, &rmp_level); if (ret || !assigned) { - pr_warn_ratelimited("SEV: Unexpected RMP fault, no assigned RMP entry fo= und for GPA 0x%llx PFN 0x%llx error %d\n", - gpa, pfn, ret); - goto out_no_trace; + guard(read_lock)(&kvm->mmu_lock); + + if (!mmu_invalidate_retry_gfn(kvm, mmu_seq, gfn)) + pr_warn_ratelimited("SEV: Unexpected RMP fault, no assigned RMP entry f= ound for GPA 0x%llx PFN 0x%llx error %d\n", + gpa, pfn, ret); + + return; } =20 /* @@ -5069,27 +5078,31 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) if (rmp_level =3D=3D PG_LEVEL_4K) goto out; =20 - ret =3D snp_rmptable_psmash(pfn); - if (ret) { - /* - * Look it up again. If it's 4K now then the PSMASH may have - * raced with another process and the issue has already resolved - * itself. If it's not assigned, then this must have raced with - * another process that made this page shared. - */ - if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && - ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) + scoped_guard(read_lock, &kvm->mmu_lock) { + if (mmu_invalidate_retry_gfn(kvm, mmu_seq, gfn)) goto out; =20 - pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN 0= x%llx ret %d\n", - gpa, pfn, ret); + ret =3D snp_rmptable_psmash(pfn); + if (ret) { + /* + * Look it up again. If it's 4K now then the PSMASH may + * have raced with another process and the issue has + * already resolved itself. If it's not assigned, then + * this must have raced with another process that made + * this page shared. + */ + if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && + ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) + goto out; + + pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN = 0x%llx ret %d\n", + gpa, pfn, ret); + } } =20 kvm_zap_gfn_range(kvm, gfn, gfn + PTRS_PER_PMD); out: trace_kvm_rmp_fault(vcpu, gpa, pfn, error_code, rmp_level, ret); -out_no_trace: - kvm_release_page_unused(page); } =20 static bool is_pfn_range_shared(kvm_pfn_t start, kvm_pfn_t end) --=20 2.55.0.766.g2966f0265a-goog From nobody Mon Sep 28 13:59:18 2026 Received: from mail-pf1-f197.google.com (mail-pf1-f197.google.com [209.85.210.197]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DDAC23A16A1 for ; Thu, 20 Aug 2026 23:32:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.197 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268770; cv=none; b=d73U1WcFL4/YB2PLO5vaxNRbvyhBpd5KyDi9wKKCk+LRBRuN993F3IeRbGbPacw61xE6W1X0ZtNhuyr8w/RJS0g2qKHm138E3pKMlLDqKzAzKTwpKCEwykDuPgrRNaFeUiGmpCedEKnZSszj2FhnySNkZ2n8eeU+HyR3UZL9mDk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268770; c=relaxed/simple; bh=1sJotEgA8ehiPs3J9DAGu4AbZ2bnjjEWvNkwbMlJckU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=m18BUd4By0ESP5K0EXXFemFaIeOdjIv3EGnjSIHLzmAh2uryi8CgQ9gv11FrcygJU2j44IcolIelj5bBt8MGc5HOb4nsdtsqMKlUMrM7uJZLBFg3yIQ1QfXcyujgjo9P8+Qqf4BxNjFH7SRkcEw03HFXRXcrgDLzA8A97516gQE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=k6T6Wv+7; arc=none smtp.client-ip=209.85.210.197 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="k6T6Wv+7" Received: by mail-pf1-f197.google.com with SMTP id d2e1a72fcca58-84857446424so630517b3a.1 for ; Thu, 20 Aug 2026 16:32:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787268765; x=1787873565; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=D9DlHJtu4nYE/0Q7Tlo35sv+3vAygx91goMAZ3ynrq4=; b=k6T6Wv+7k/owLB+flVvGutMx1PlrVtxMdLjFhSbvL/j7uz/Q4R3lJ7Edl64397L5eW mlOBHIRyCozdIVxe4jRhFXEY/a6zC3vgUPH7sFYxXg/qYj75rYJab6CPY8BFaIizPykJ 0WaHeZc2nJl4CfM3vNXubTp7TtduOSGzI0beLNl8qstNwzB+3ex9WYaSmcj04bTjVw5O bjHjqXzC/VzMmjFwitr+3GmMoHJbyM9nFM3Z7o60P3On0DLs/O33V6y4uuZZrf98BbaC 4Dp016aRTR2i4tleuK8+UDu1t9ch/7+X75Z+CkNHe0r/aRa0Eft9vuvWGFwgz2fgAxBs vLzQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787268765; x=1787873565; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=D9DlHJtu4nYE/0Q7Tlo35sv+3vAygx91goMAZ3ynrq4=; b=FvZWjIaamjKBQbUuKew6vhLjXfkX3LEhZi83FQ6Zt4jr7p4a+fkCvDlbs5ija538IM m7OEN2VDDvC3lfpb3yeLAzMAPUcP1lD/qZskH7QE9ZaoGYOZjSP71t+A4REG0dSiznZh i3es51dXGUSOdYvRXzLLL30yKozrtGUC/Fatl4hmRi9TcgVmzCEyAzsscMfB4FDIM5M9 7Xg8A0xUUyZv+/seM+/LMzLlS3YmsKJKlMADANtpF2pBaefuLojbxG8atRZnoX1Ic4HL P8bGlTolsIEaTM6wIwXoJ+KdIkyDMo5ECz6jo84kK00Qkm3b4wHmbQrCyDfm6APIO8Uk xiYA== X-Forwarded-Encrypted: i=1; AHgh+RqmNjLdsz6uqtebb7MY8jPHGn4OS3FWybBQyj8/ZdkFz6sMC5E8o8dyV1AK5eoPd6IRN9wgaFI8V+SJ3sk=@vger.kernel.org X-Gm-Message-State: AFuF++nYc80vGgfabAoTWt6joyjK/f3sTLuz5R8PohePJquCwBftqqZr W3pfdKhZhrMCYj3ymQCU05kZawXKQACS7YlzQUP/KYnIkJM/SQfKo6Qkh2ByAInsHRD2rMb/G0F OVqT+tnOizTOvS7E01cm0pMGZgw== X-Received: from pgsb12.prod.google.com ([2002:a65:67cc:0:b0:cc1:4df5:5acb]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:8010:b0:84f:a170:4f5b with SMTP id d2e1a72fcca58-851f9aa7714mr2971480b3a.8.1787268764952; Thu, 20 Aug 2026 16:32:44 -0700 (PDT) Date: Thu, 20 Aug 2026 23:32:36 +0000 In-Reply-To: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787268758; l=1353; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=1sJotEgA8ehiPs3J9DAGu4AbZ2bnjjEWvNkwbMlJckU=; b=x9w/WvPH12uIL2DGAb5DL+tydH0mG6AFPF/kocY0XpSFzUkQYU6qgERR2lFjs4T457yY7MM0c q7HGbnpu+exD47dSoIA22tQ/jsBNKwgkYwIbWfbJghtPXWJ6s+RH79A X-Mailer: b4 0.16.0 Message-ID: <20260820-gmem-no-return-page-v3-3-3bf8f80a7b4d@google.com> Subject: [PATCH v3 3/4] KVM: SEV: Drop page refcount early in VMSA reload From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Fuad Tabba , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When reloading the guest VMSA for an SEV-SNP vCPU, KVM retrieves the PFN from guest_memfd. Drop the page reference immediately after retrieving the PFN instead of holding it across MMU lock acquisition in preparation for a follow-up patch to stop returning page pointers from guest_memfd PFN lookups. This is safe because the page's validity and presence are governed by KVM's MMU invalidation protocol rather than the page reference. No functional change intended. Reviewed-by: Michael Roth Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 563870342a2ba..0375ef709ee2c 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -4062,6 +4062,7 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) */ if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, &page, NULL)) return; + kvm_release_page_clean(page); =20 read_lock(&kvm->mmu_lock); /* @@ -4076,8 +4077,6 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) else svm->vmcb->control.vmsa_pa =3D pfn_to_hpa(pfn); read_unlock(&kvm->mmu_lock); - - kvm_release_page_clean(page); } =20 /* --=20 2.55.0.766.g2966f0265a-goog From nobody Mon Sep 28 13:59:18 2026 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5436823C516 for ; Thu, 20 Aug 2026 23:32:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268771; cv=none; b=OsJKQh6EeitysvCpBmwkbAsZ1krD7IK6dBU0KKGOzGnMohGNDirgMgmCQvwBnACYeV/ZpO6nB+YrwYD0/77A4lKBCslhMOy1Pb8qIIt+VfpyewkOiSWULFis7wV0BU9PxD5BVv+7cHNu1pfwOQ4pm9TxBJY6C3UXx44oKkVKXK0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787268771; c=relaxed/simple; bh=V0844XDUaiC4ETf5m0/3GwaxcmEs1sPKQ6XCUhjT6uU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=dRH+zS5eEIl8a95rRExsflfzKWCoXKQn01xKUfY4ZLuJwiPW+SKF6QIwOPcNX5w39GFxBrFkLbEtwqoAvf7DoqU6FkeWGcscTFeVJvYGnJo3P2qrfT5hjF/RhPjrqvnF3lovgqmwuoevk8gDydKXYo8wWKy7SEr1XJT8Mfp+X0w= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=HAy6Pv6n; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="HAy6Pv6n" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cb4bd11ddf8so552841a12.3 for ; Thu, 20 Aug 2026 16:32:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787268767; x=1787873567; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9NvhMH8LFCh3/0u1wEtokGC4+3va98pYMprwb3y631M=; b=HAy6Pv6n85yDDBkFdhIf70ER+DpGVJsVnDz/H3su5RtGaYkZ2A/zyFpxlOYRkkv5Ov xvai9c4KeQwa41OJBsf6aOVvxw4FItsk8GhsmZWOhAABakS9xEudukBisvdIFjT0BfxG fexKtBaUNZCTh8ezCUKHuXyx9ALttC5GPa76MHQNolHFCfqMylOVQNNXJ9XGixY+UJs2 NXNxKo4DYyNydca/xvk8MR0Ia9vC8d+IZanB+l8PQncN9hre6H8sOMAOaWaI0SYALEcS VclKoNF+MTBHHwXIHb1Yi3Nxbl9uQCdzcuE1wxSbwYE6svRFf3D6UIwj5pPAZeHsGT/I PENQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787268767; x=1787873567; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9NvhMH8LFCh3/0u1wEtokGC4+3va98pYMprwb3y631M=; b=ny3azR0wMWDLWhawbYWOm9stm4WDPsckWloOzPlY3VM+HfADXUQ698U7Y955tt7yGX 0Aa6TeTor92d+Thej5aZN5hs1taTav5a+Q6MytPBMZfqJxTjfhFherz1C5SEg+MUUWfI UN7AZ3SXP8164bRxQhQ7bAZ6Td1tm3lADIyPN4tZXO6sge4FJI2JljSM1A7Om/dxoWyd nrTpLpUHrwkrCo1DcM56/Rz9gyQ74qZpCDCFNMdVJ3FIxF1ZqihPI6H0Ias193Ome4G7 SnS28yLonykChmPClt0iquSTs0dRT31hm5RxTOKvoww5a49VOsGWhCr+CptqGqBoPx05 1KWw== X-Forwarded-Encrypted: i=1; AHgh+RovyR+tqNXU7DhRvaezj+reXq8Ghb7ZMdP669d3fJDKYWhLddQAbH8AHH/tYnMpNJIznA+cI8xSOk/Ju0I=@vger.kernel.org X-Gm-Message-State: AOJu0YxhyUTxBrZ0vyDy5SeD+ZwUijGyGZfIOo/6BC/j1pJAOPF/VZTK yeP4YMWWXD0XN8zVke6KoLI9aMufGP4h56RXZYNoUtXg6ILJ2dwoj85R69MZVgd/d90slS4ViXN P0FiTNDORnE059zQUAWB/+/cuVw== X-Received: from pgjy4.prod.google.com ([2002:a63:e244:0:b0:cbe:e120:3788]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a21:398f:b0:3cc:927e:354c with SMTP id adf61e73a8af0-3cd2ff856eemr3908156637.9.1787268766599; Thu, 20 Aug 2026 16:32:46 -0700 (PDT) Date: Thu, 20 Aug 2026 23:32:37 +0000 In-Reply-To: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260820-gmem-no-return-page-v3-0-3bf8f80a7b4d@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787268758; l=8695; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=lcx/24pBzxlhDBLvNFneOWtKer1iGrC3lCfSbNoE1G0=; b=L25LalXat+4IJQtZBKTQDY5PKYB5/a2gKB/oT9uzNrzfjgKHFT0zNxAKJrMso425248SEaQnV 1i6Mmgk5aOtDARee023YcLu9d5IyDft7uGiLX3IsGph58jOXZ2ousBY X-Mailer: b4 0.16.0 Message-ID: <20260820-gmem-no-return-page-v3-4-3bf8f80a7b4d@google.com> Subject: [PATCH v3 4/4] KVM: guest_memfd: Stop returning struct page from PFN lookup From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Fuad Tabba , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Sean Christopherson KVM currently expects guest_memfd PFN lookups to return a refcounted struct page, which callers hold across fault handling. Drop the page's refcount before returning from kvm_gmem_get_pfn() to prepare for the in-place conversions series. CoCo shared-to-private conversion handling must inspect folio refcounts to ensure exclusive ownership by guest_memfd. A concurrent guest page fault taking a temporary reference on the folio causes conversions to fail due to an elevated refcount. While this refcount is also taken on host userspace page faults, that refcount is taken on behalf of the host userspace page tables. This refcount will be dropped when conversions unmaps the page. Either way, once there's an mmap() or userspace mapping, the pages are open to way more refcounts, transient or not. This patch focuses on just dropping refcounts before handing KVM a page. guest_memfd already notifies KVM of page invalidations, so callers within KVM only need to respect the MMU invalidation protocol to safely rely on guest_memfd for page presence. Since the page refcounts are dropped, don't return the struct page pointer. Not returning the struct page from the guest_memfd PFN lookup moves KVM closer toward supporting memory backends that are not backed by struct page. Here are some notes on the cleanup in the callers of kvm_gmem_get_pfn(): kvm_release_faultin_page() in ARM's gmem_abort() originally also serves to set the page dirty and accessed under some conditions. The dirty and accessed flags don't matter for guest_memfd anyway, so it is safe to just drop the call to kvm_release_faultin_page(). For ARM's kvm_translate_vncr(), the local page pointer must be initialized to NULL so that the shared cleanup path that releases faulted-in pages safely no-ops for guest_memfd. For x86, no additional changes are required in the MMU fault path because the page fault tracking structure is zero-initialized at the start of page fault handling, ensuring the refcounted page pointer is already NULL. Reported-by: Yan Zhao Closes: https://lore.kernel.org/all/anZ4W9o5pTWIEgMY@yzhao56-desk.sh.intel.= com/ Signed-off-by: Sean Christopherson Co-developed-by: Yan Zhao Signed-off-by: Yan Zhao Reviewed-by: Suzuki K Poulose Reviewed-by: Michael Roth Tested-by: Michael Roth Tested-by: Yan Zhao Co-developed-by: Ackerley Tng Signed-off-by: Ackerley Tng --- arch/arm64/kvm/mmu.c | 4 +--- arch/arm64/kvm/nested.c | 4 ++-- arch/x86/kvm/mmu/mmu.c | 2 +- arch/x86/kvm/svm/sev.c | 8 ++------ include/linux/kvm_host.h | 6 ++---- virt/kvm/guest_memfd.c | 9 ++------- 6 files changed, 10 insertions(+), 23 deletions(-) diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c index 6c941aaa10c63..d5aa197d2cbfd 100644 --- a/arch/arm64/kvm/mmu.c +++ b/arch/arm64/kvm/mmu.c @@ -1613,7 +1613,6 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) enum kvm_pgtable_prot prot =3D KVM_PGTABLE_PROT_R; struct kvm_pgtable *pgt =3D s2fd->vcpu->arch.hw_mmu->pgt; unsigned long mmu_seq; - struct page *page; struct kvm *kvm =3D s2fd->vcpu->kvm; void *memcache =3D NULL; kvm_pfn_t pfn; @@ -1641,7 +1640,7 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) /* Pairs with the smp_wmb() in kvm_mmu_invalidate_end(). */ smp_rmb(); =20 - ret =3D kvm_gmem_get_pfn(kvm, s2fd->memslot, gfn, &pfn, &page, NULL); + ret =3D kvm_gmem_get_pfn(kvm, s2fd->memslot, gfn, &pfn, NULL); if (ret) { kvm_prepare_memory_fault_exit(s2fd->vcpu, s2fd->fault_ipa, PAGE_SIZE, write_fault, exec_fault, false); @@ -1681,7 +1680,6 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) } =20 out_unlock: - kvm_release_faultin_page(kvm, page, !!ret, prot & KVM_PGTABLE_PROT_W); kvm_fault_unlock(kvm); =20 if ((prot & KVM_PGTABLE_PROT_W) && !ret) diff --git a/arch/arm64/kvm/nested.c b/arch/arm64/kvm/nested.c index fb54f6dad995c..43523bb17621a 100644 --- a/arch/arm64/kvm/nested.c +++ b/arch/arm64/kvm/nested.c @@ -1360,7 +1360,7 @@ static int kvm_translate_vncr(struct kvm_vcpu *vcpu, = bool *is_gmem) bool write_fault, writable; unsigned long mmu_seq; struct vncr_tlb *vt; - struct page *page; + struct page *page =3D NULL; u64 va, pfn, gfn; int ret; =20 @@ -1411,7 +1411,7 @@ static int kvm_translate_vncr(struct kvm_vcpu *vcpu, = bool *is_gmem) if (is_error_noslot_pfn(pfn) || (write_fault && !writable)) return -EFAULT; } else { - ret =3D kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, &page, NULL); + ret =3D kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, NULL); if (ret) { kvm_prepare_memory_fault_exit(vcpu, vt->wr.pa, PAGE_SIZE, write_fault, false, false); diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index c519e8e8d646f..129d403308051 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -4604,7 +4604,7 @@ static int kvm_mmu_faultin_pfn_gmem(struct kvm_vcpu *= vcpu, } =20 r =3D kvm_gmem_get_pfn(vcpu->kvm, fault->slot, fault->gfn, &fault->pfn, - &fault->refcounted_page, &max_order); + &max_order); if (r) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); return r; diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 0375ef709ee2c..0c91c904573cc 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -4016,7 +4016,6 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) struct kvm *kvm =3D vcpu->kvm; gfn_t gfn =3D gpa_to_gfn(gpa); unsigned long mmu_seq; - struct page *page; kvm_pfn_t pfn; =20 lockdep_assert_held(&svm->sev_es.snp_vmsa_mutex); @@ -4060,9 +4059,8 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) * The new VMSA will be private memory guest memory, so retrieve the * PFN from the gmem backend. */ - if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, &page, NULL)) + if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, NULL)) return; - kvm_release_page_clean(page); =20 read_lock(&kvm->mmu_lock); /* @@ -5003,7 +5001,6 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa_= t gpa, u64 error_code) struct kvm *kvm =3D vcpu->kvm; int order, rmp_level, ret; unsigned long mmu_seq; - struct page *page; bool assigned; kvm_pfn_t pfn; gfn_t gfn; @@ -5033,13 +5030,12 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) mmu_seq =3D kvm->mmu_invalidate_seq; smp_rmb(); =20 - ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &page, &order); + ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &order); if (ret) { pr_warn_ratelimited("SEV: Unexpected RMP fault, no backing page for priv= ate GPA 0x%llx\n", gpa); return; } - kvm_release_page_unused(page); =20 ret =3D snp_lookup_rmpentry(pfn, &assigned, &rmp_level); if (ret || !assigned) { diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h index 03bfc92864b6e..502465119ca0c 100644 --- a/include/linux/kvm_host.h +++ b/include/linux/kvm_host.h @@ -2586,13 +2586,11 @@ static inline bool kvm_mem_is_private(struct kvm *k= vm, gfn_t gfn) =20 #ifdef CONFIG_KVM_GUEST_MEMFD int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, - gfn_t gfn, kvm_pfn_t *pfn, struct page **page, - int *max_order); + gfn_t gfn, kvm_pfn_t *pfn, int *max_order); #else static inline int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, gfn_t gfn, - kvm_pfn_t *pfn, struct page **page, - int *max_order) + kvm_pfn_t *pfn, int *max_order) { KVM_BUG_ON(1, kvm); return -EIO; diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index b596486d184ca..589762140c3ef 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -751,8 +751,7 @@ static struct folio *__kvm_gmem_get_pfn(struct file *fi= le, } =20 int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, - gfn_t gfn, kvm_pfn_t *pfn, struct page **page, - int *max_order) + gfn_t gfn, kvm_pfn_t *pfn, int *max_order) { pgoff_t index =3D kvm_gmem_get_index(slot, gfn); struct folio *folio; @@ -780,11 +779,7 @@ int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memor= y_slot *slot, #endif =20 folio_unlock(folio); - - if (!r) - *page =3D folio_file_page(folio, index); - else - folio_put(folio); + folio_put(folio); =20 return r; } --=20 2.55.0.766.g2966f0265a-goog