From nobody Mon Sep 28 04:53:45 2026 Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C94C036A03F for ; Wed, 26 Aug 2026 09:02:04 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734926; cv=none; b=Ve0QGsSikGIE+wo/S+wYr6WH4Y/Fp2irVp4lgiv5bx1a94ItGxIZS3TCBA5B5Dhr+Bf9nSuFEMvlL/3VpWmzhBX767hWgFDstuBOA5x8Yq6Yx8fMuOVsL0T9SoyCUku83QgDJhemZaxM6427qvx+gQgy5h8h15ZlWXrLFs9+MaY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734926; c=relaxed/simple; bh=tBQj3Zs/zFgJuqob5UUxqzp8WSGa3DX0/uF2e5leoMQ=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=QIDYt7bhQd0pzpX6P4YcbznOkrOxlau+wQCEc3xbsvV55wncsfVogIpAG/30fl46+FKufLIggSxaqGzrzI5xyDDvWtN11yAB4P6TNLKXR49Noqdz+S3eoIDBO+y3jYd+c3EYz9G2/yNS1wFRzqLGFvRKNQoJQHMWC7U+vlJl5qo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=p7MLEpKK; arc=none smtp.client-ip=209.85.216.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="p7MLEpKK" Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-3954def0191so1622169a91.3 for ; Wed, 26 Aug 2026 02:02:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787734924; x=1788339724; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=DUYw+bKmtZMKiUuqmTKklNQo1kdVyC2ASm9zrjeaODY=; b=p7MLEpKKeUZpVNX7qpkrV/b5uhkdrb+LxJ2BcsqAZgv5XKRUJytOE/hhRpzEhSkfzo rbkuwA5Bh0etx30osZvXXhx4ckcmZRw8Xk5tCWpQ45XQH5BwGKhl7w7MGtdHSEJf7St8 CXkC7SWzokp+FAq8NegC46kXUCs0wf+TMD+AxV48l1RskTfCp4Of+thPT+c3qgeKQNe7 Khp3rYzJWfaDmB7B5dUj9jda2gNyLHcT3fTW3GNWjTcqnKW2pdMPSfBn01Ebzz6osFOc 8RPGfxCLE6asYrLWQ4OK9ONLX4496OY3/+Ps7MUnA3s138Pja89psKvE+hqsR2a40CjP l2qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787734924; x=1788339724; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DUYw+bKmtZMKiUuqmTKklNQo1kdVyC2ASm9zrjeaODY=; b=WT7vZZeO4P766lVxRHpZZQi35r8ODJrZHPYQpQwSSEcaxorQ2DRQgVwONCYQi+DJKN tifCggS34NwmsYh4/4BQe0dSfoi9q/cMrB8QKCPj2NM7GpSoItbX8oeTP8ZaTOwI6S27 xrkhZbu60DSSJkrWfIJTbuSnt3a5BvjAFtQ+Jyld72u5vUPVFljCugPz9DIZMB/LhFaX 0yp4q9aflzSh37k7XBO85UcVqkG1U/5A8WABO/y9HsJstRfxZUoQfPLlSBKZ0t2kLADf gu9eAVtHNjmdkZAAU5ihG9F214IChDhPVs8R0Fa8y+jvbymGjIlGICl/JQAVeHg60Vvf CecQ== X-Forwarded-Encrypted: i=1; AHgh+Rqitw5UUo22dRGBOxgA9yGxErXqkMLACJBtZkVrrHgJSmE4UO9yQoWF4DPWmtbnEN/EtXs6X6YMu59ugrM=@vger.kernel.org X-Gm-Message-State: AFuF++kVy1aABs1Ai8/Zgpv9cxViu4Q/SVd7lb9HN4wb3OlPQY/gfhYr tlcja693KY/AnGiD8z27il6UzRuKMn/PnZfkqSe6EVXZuOy8natCysI4JtE90DGyII+TuXr1BR8 TT7Pr5T8Qa8cJ0YSfjlrqoEl8ig== X-Received: from plhk3.prod.google.com ([2002:a17:902:d583:b0:2cf:7c8c:cf2c]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90b:1c83:b0:393:19a3:4f1 with SMTP id 98e67ed59e1d1-3966d1a48b7mr9860233a91.6.1787734923676; Wed, 26 Aug 2026 02:02:03 -0700 (PDT) Date: Wed, 26 Aug 2026 09:01:46 +0000 In-Reply-To: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787734920; l=2054; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=tBQj3Zs/zFgJuqob5UUxqzp8WSGa3DX0/uF2e5leoMQ=; b=nHLIey2i5u9SSFrucSIZdJ1XmfoAN4s5aKHgC3ZELugP1EEPbj+x4Hm6gj03zMVF4F5nca+id ZU3e9ubiktdC65mxiZZgRyVvXsoN/yMoCRncYdGQyOWDEy2KAsc3df+ X-Mailer: b4 0.16.0 Message-ID: <20260826-gmem-no-return-page-v4-1-3bb9c1ddb4e3@google.com> Subject: [PATCH v4 1/5] KVM: SEV: Treat unassigned RMP entry as benign race on PSMASH failure From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve , Fuad Tabba Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When handling an RMP fault, KVM attempts to split a 2MB page via PSMASH. If PSMASH fails, the only expected return value is FAIL_BADADDR, which does not distinguish the reason for the bad address. Hence, another RMP entry lookup is required to determine whether the failure was benign. Specifically, KVM re-checks the RMP entry to determine if another CPU raced and already smashed the entry into 4KB pages. A concurrent operation (such as guest_memfd truncation or hole punching) can also race and transition the page to shared, removing the page from the RMP table and causing PSMASH to fail. This can happen even if the page is still referenced by KVM, because guest_memfd reclaim transitions the RMP entry to shared when the folio is removed from the page cache. Treat an unassigned RMP entry as an expected race when re-checking after a failed PSMASH, and skip logging an error warning. Fixes: c63cf135cc99 ("KVM: SEV: Add support to handle RMP nested page fault= s") Reviewed-by: Michael Roth Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 5705723f1f412..e198469eb074c 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -5090,10 +5090,11 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) /* * Look it up again. If it's 4K now then the PSMASH may have * raced with another process and the issue has already resolved - * itself. + * itself. If it's not assigned, then this must have raced with + * another process that made this page shared. */ if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && - assigned && rmp_level =3D=3D PG_LEVEL_4K) + ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) goto out; =20 pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN 0= x%llx ret %d\n", --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:53:45 2026 Received: from mail-pg1-f198.google.com (mail-pg1-f198.google.com [209.85.215.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4E38237F8C3 for ; Wed, 26 Aug 2026 09:02:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734930; cv=none; b=nFyoYHZpWAbE1911qxGi1hQnkAD5mh0jcAVRus8BfIE7fHXKXb5NqvxiMKicQS7bO1p5z3JGEJK9VAW21WgfvM0+V5PDWS3p+BfXs8WK2Hkc4N2gB92AzoVBWQUfjk8Lb/Ih0kXDEo2fq54fkDo7/yQ7nT8566a3fvZY5YcPyiY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734930; c=relaxed/simple; bh=M+i2SxvXQ8DSphNQ8ShtoJPE8ttDtKFUtUCnzxjFNwY=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=IgHM6uAKCy8Pz8g4o2E+lGd/4SvK7gs0qrZgMtCWH0hh3nnlB6aMjJP37i7NsIzCOMPoCZbc4Fyn3yQN56RmBx28IL/RCSuBubc9PxZs2+aKNoqndE5OClyHJCKSuMWYVEmSuFValvcphajFO/ZXNvDbuAMnOoc3H9ZRnet6uAk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=ki6qHcy5; arc=none smtp.client-ip=209.85.215.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="ki6qHcy5" Received: by mail-pg1-f198.google.com with SMTP id 41be03b00d2f7-cc1c5810451so701009a12.1 for ; Wed, 26 Aug 2026 02:02:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787734927; x=1788339727; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=EuS9O11vr193qDv9HWb04MHk5U9f4uvrgo/7abqfaWM=; b=ki6qHcy5sv+9OlMiVd5y7G1srwUw08k3MDmIca3r9dtpgS4QAGWdb4zN/Xr1StaHR/ ccLMYIwmH2jVp7dQoieMQHkb1WDkdhkM4Rt8tRALcKWtkSwz+wzBCFhhLIwykLfy+iu1 oxZYtIDVIGPzzjCmtXTnAoFx2ZxiIrmZ06OtRTxzz7iJYnae5eZtOXd8jmFykYJ6Q5In tfvIUoWzOEBgr0HJ1kedNNb43zqvhpVqHkk/weu1uyXzqdnsjq2BCGKmwP9bB1UVttbO FmwYcVllqWe29ZFUfzg/hNAaYpu8CalDkn9Q8nQTUQjogSlT+h0uIG6KJTnd8DdIwaeF 8MVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787734927; x=1788339727; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EuS9O11vr193qDv9HWb04MHk5U9f4uvrgo/7abqfaWM=; b=PR7AJoQ6m4gsW+8VOvBZQWqoMS0qWY8PHT96YVv3/oAco91EqhipJTRkudaG8oEoIS nfPdH8dFCyyLV+E4eVXlnQfnCYt0uQxrlOgT0gPpVRCARqDwOIF+Q1qxwPNbY0H7Pb6/ vhSLv8vy+03DN6VtuQuRYSk6BlBCueo68RdFlBl33gVz+ffiCEpjQqeKYw1wrgxDKnGv fXGaG4uk1oGrb0xxU/Yr+lgBAdbDWlHgWlB/i9IcPAcgsKKQMV2bzPmI8mjnJbM7w6gL Ka+tKSQ2cav28FlSZoRldKRwPolB+82LeDaNaErHZ3W9Kg1fuYjnLPvYT4MZr0D6JdzT xIqA== X-Forwarded-Encrypted: i=1; AHgh+RpUHUoa7mOK4FxhhRfpHALrAGpXABmsb29AU5X4gN1QGJXQymAIgFQ/zmzhm0KkujJQXTD+VJw/kgArwms=@vger.kernel.org X-Gm-Message-State: AFuF++labrQ+cWmHOx39oBVkCeuHEMgEUxejzkWSvVncoUzGyehDNmW0 aBM/rkRTQAJfq5XtPNN0AYYnIzPYidHOVh5RprT2Fe9QpE1b2qJWN6wVsMj7iMCXoStCzlYy0fE u+DlCu83DDY2tutGxi2zqFhQWgg== X-Received: from plbmz15.prod.google.com ([2002:a17:903:350f:b0:2cc:6063:a658]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a17:90a:e70e:b0:38e:524:8797 with SMTP id 98e67ed59e1d1-3966d4503ccmr11876759a91.13.1787734925365; Wed, 26 Aug 2026 02:02:05 -0700 (PDT) Date: Wed, 26 Aug 2026 09:01:47 +0000 In-Reply-To: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787734920; l=3858; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=ifBAzXs8dlmanG/v8Acwb5QccjLKb55JHzRk/esPfm4=; b=kJMdcnrib7/3q/fmH14PIC5RislnUwwDuforS4mPsCFG6U4RlmpkwZgDuAO6oLG+VTfDnsS8p VAKOV4a6zA9BcErbmRbTF6QWV2iI5gPuSe8RTZJyLl6TjYx7ftseQ1s X-Mailer: b4 0.16.0 Message-ID: <20260826-gmem-no-return-page-v4-2-3bb9c1ddb4e3@google.com> Subject: [PATCH v4 2/5] KVM: SEV: Drop page refcount early during RMP fault handling From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve , Fuad Tabba Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Sean Christopherson Rework KVM's handling of RMP faults to rely on MMU invalidation logic for safety, instead of the current approach of holding onto a folio reference until the RMP operations are complete. I.e. drop the reference gifted by guest_memfd immediately after getting the PFN, and instead do RMP updates under mmu_lock, after checking for relevant MMU invalidations. This will allow dropping guest_memfd's reference gifting entirely, which is ideally how KVM would operate for all "follow PFN" operations (GUP has many more complications, which is why KVM holds a reference across page faults *on top* of the standard MMU invalidation logic). Signed-off-by: Sean Christopherson Reviewed-by: Michael Roth Co-developed-by: Ackerley Tng Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 39 ++++++++++++++++++++++++--------------- 1 file changed, 24 insertions(+), 15 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index e198469eb074c..0d027cff734cf 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -5019,6 +5019,7 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa_= t gpa, u64 error_code) struct kvm_memory_slot *slot; struct kvm *kvm =3D vcpu->kvm; int order, rmp_level, ret; + unsigned long mmu_seq; struct page *page; bool assigned; kvm_pfn_t pfn; @@ -5046,18 +5047,22 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) return; } =20 + mmu_seq =3D kvm->mmu_invalidate_seq; + smp_rmb(); + ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &page, &order); if (ret) { pr_warn_ratelimited("SEV: Unexpected RMP fault, no backing page for priv= ate GPA 0x%llx\n", gpa); return; } + kvm_release_page_unused(page); =20 ret =3D snp_lookup_rmpentry(pfn, &assigned, &rmp_level); if (ret || !assigned) { pr_warn_ratelimited("SEV: Unexpected RMP fault, no assigned RMP entry fo= und for GPA 0x%llx PFN 0x%llx error %d\n", gpa, pfn, ret); - goto out_no_trace; + return; } =20 /* @@ -5085,27 +5090,31 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) if (rmp_level =3D=3D PG_LEVEL_4K) goto out; =20 - ret =3D snp_rmptable_psmash(pfn); - if (ret) { - /* - * Look it up again. If it's 4K now then the PSMASH may have - * raced with another process and the issue has already resolved - * itself. If it's not assigned, then this must have raced with - * another process that made this page shared. - */ - if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && - ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) + scoped_guard(read_lock, &kvm->mmu_lock) { + if (mmu_invalidate_retry_gfn(kvm, mmu_seq, gfn)) goto out; =20 - pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN 0= x%llx ret %d\n", - gpa, pfn, ret); + ret =3D snp_rmptable_psmash(pfn); + if (ret) { + /* + * Look it up again. If it's 4K now then the PSMASH may + * have raced with another process and the issue has + * already resolved itself. If it's not assigned, then + * this must have raced with another process that made + * this page shared. + */ + if (!snp_lookup_rmpentry(pfn, &assigned, &rmp_level) && + ((assigned && rmp_level =3D=3D PG_LEVEL_4K) || !assigned)) + goto out; + + pr_warn_ratelimited("SEV: Unable to split RMP entry for GPA 0x%llx PFN = 0x%llx ret %d\n", + gpa, pfn, ret); + } } =20 kvm_zap_gfn_range(kvm, gfn, gfn + PTRS_PER_PMD); out: trace_kvm_rmp_fault(vcpu, gpa, pfn, error_code, rmp_level, ret); -out_no_trace: - kvm_release_page_unused(page); } =20 static bool is_pfn_range_shared(kvm_pfn_t start, kvm_pfn_t end) --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:53:45 2026 Received: from mail-pl1-f200.google.com (mail-pl1-f200.google.com [209.85.214.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C32EF3502A9 for ; Wed, 26 Aug 2026 09:02:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.200 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734932; cv=none; b=X7svzviE9sLjaAr7ljhbTzl6+zmdidB+FMvVdC1Hj6g5C/oFQChtUTJcMuxNSLAv0D8rhgk/S+SWbjGGYgDs2VSQY+x9TuN/GeyIJem8GGV9IgggadymH8Pdge/Uq3Z3+X/EQQSV2zCmvhuwANmWCk8UMjO8lyLixARziyfBVLk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734932; c=relaxed/simple; bh=enAIdIfpjwlSqC1gWlXPx7NV0FU3Pk1m0whhjn5JXcU=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=dE27fuUaeTm8OZAXphO1NiH6x23fp6JIJMeo5qplTiDpHMoYOQbgwKlcHZLKyR2HuGciu73KEPwGii7MZ7gkIAxnoNN/jJP1fskfuYK567YYlT52UI6YIpUpDxFclUsBocxtsihzcBaV2FUE84KjW/qsxQbpxmyj/ZXuaXKYw5c= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=omNQ2Zev; arc=none smtp.client-ip=209.85.214.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="omNQ2Zev" Received: by mail-pl1-f200.google.com with SMTP id d9443c01a7336-2cfe48ca1efso12738415ad.0 for ; Wed, 26 Aug 2026 02:02:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787734928; x=1788339728; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=2t7yDZCgF5yF794oBaYJTVqMg1ClYWvzuDLcLD0bTKE=; b=omNQ2ZevgMHZhcbaewF0F5rgl/ZZ7aY3XQat85xaz5TYEKnmXmPykJxij/MIDFU/1R RPDWh4S+mRR6YqlaoLID+1BLRUhlzhPIkjknOR0wL69qJMxCe6Cm/hBdSOYDO3EKqAPP tnl2KpPs8NmZDns5D3Gxgltd/37uTtBUweA8dAJCAPOUUkFiofLO0MHHYxDh+MhqB8AD 9aonhCL2IEEC6hA6dL8K2K3kKWPcFE/Mk1WTxEdOHXrl0LZ2A2fBgXPNYTUkP1H/at/Z Q5hGgqak3B1vGqOO+m8kTZla/NJEWG8jX/5sgdBREvXNiu8mnr86+uYLYb/PeFdO5e3K XpKw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787734928; x=1788339728; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2t7yDZCgF5yF794oBaYJTVqMg1ClYWvzuDLcLD0bTKE=; b=B58UxbF23uJslQiQcAkFJn1ipbr6sQUGtx339m2akiQLn7DWNWIrROYpuE0lyxVNvC /dYCmNwVNuCX0/qJHv8X+++Q0KaaoRLl6vS0CfOi4cvrJ6BgesYFc8B2ixl282md3KMa g+pECLbwGxe7HFVAX2AylL4/qP4ZrwgY0z7RDxptE7UCgWK3QP+sr5fLc2EEb5aaRsAM wg5jJZcQWe3y8oRppZI805O1C50eBfjyALlf/tLaQglbHYzydOjRXcSc6JtzmNQ2et7D z6O1RGairEuAdJDNCFrXbtptsczkp6TJwpE9BtN15mnDIvT5diRqk7h266q5JDLix0yc okdw== X-Forwarded-Encrypted: i=1; AHgh+RqcEwCZtQqiIfPxsVbr9BCa6GNr8kiVD6GF10mIt1H43KEIy169dXorYctAVlQHFM5b428e/SdGAnI5q1s=@vger.kernel.org X-Gm-Message-State: AFuF++nWbJu6XGNqJBoyikD2iFJepEeaRamjIRQ978Kd927Jr+ZwtxIm TnAvZ3RvnPSDjK4/enExbE778+bI3WYJCSeQkzan0p/XtcVB0HJQzUDgq7wfEvy+Z/GmeK22h5o WHvnGnEkTwvgVDQeegCEd41zgFw== X-Received: from plae17.prod.google.com ([2002:a17:902:e0d1:b0:2ca:cba4:f740]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:3910:b0:2ce:faa6:7cbb with SMTP id d9443c01a7336-2d707a3ed87mr93106385ad.4.1787734927046; Wed, 26 Aug 2026 02:02:07 -0700 (PDT) Date: Wed, 26 Aug 2026 09:01:48 +0000 In-Reply-To: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787734920; l=1785; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=enAIdIfpjwlSqC1gWlXPx7NV0FU3Pk1m0whhjn5JXcU=; b=X/J0naFXaXcacGRfyWJDRGmjT1pR6S35RpMfjdWjFbARTVW571RbgREp+itIh0+NkYxsS2pCt 0GRcegdOuePAemCvojQPvh6N2NgBYZnP3n8QANxjyBigz32FysjP3WD X-Mailer: b4 0.16.0 Message-ID: <20260826-gmem-no-return-page-v4-3-3bb9c1ddb4e3@google.com> Subject: [PATCH v4 3/5] KVM: SEV: Check for invalidation before warning on unassigned RMP entry From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve , Fuad Tabba Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When handling an RMP fault, KVM looks up the RMP entry for the backing PFN to determine if a 2MB page needs to be split via PSMASH. If the RMP entry is not assigned (or lookup fails), KVM logs a rate-limited warning under the assumption that private memory should always have an assigned RMP entry. However, a concurrent invalidation (such as guest_memfd hole punching) can race with RMP fault handling and transition the page to shared, unassigning the RMP entry after KVM fetched the PFN. In such cases, not finding an assigned RMP entry is benign. Check mmu_invalidate_retry_gfn() under mmu_lock before warning about a missing or unassigned RMP entry, and suppress the spurious warning if an invalidation occurred for the faulting GFN. Fixes: c63cf135cc99 ("KVM: SEV: Add support to handle RMP nested page fault= s") Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index 0d027cff734cf..f9dce8acac8eb 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -5060,8 +5060,12 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa= _t gpa, u64 error_code) =20 ret =3D snp_lookup_rmpentry(pfn, &assigned, &rmp_level); if (ret || !assigned) { - pr_warn_ratelimited("SEV: Unexpected RMP fault, no assigned RMP entry fo= und for GPA 0x%llx PFN 0x%llx error %d\n", - gpa, pfn, ret); + guard(read_lock)(&kvm->mmu_lock); + + if (!mmu_invalidate_retry_gfn(kvm, mmu_seq, gfn)) + pr_warn_ratelimited("SEV: Unexpected RMP fault, no assigned RMP entry f= ound for GPA 0x%llx PFN 0x%llx error %d\n", + gpa, pfn, ret); + return; } =20 --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:53:45 2026 Received: from mail-oi1-f198.google.com (mail-oi1-f198.google.com [209.85.167.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 37E72388881 for ; Wed, 26 Aug 2026 09:02:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734932; cv=none; b=Xt9Qzt0YePwbSTCWaEekoHovIvJrHlwkoOFCbeE2EQr5axsya5Vxb0y3m4/gWh1kMSae0t1SYhi+mXaFukfTg2jBwo78yGtXKfUrmP02yf/QyjXVDEVi7NlfG/PMpGzzc0jBjmKCDgqtfjc9bJiFcU88mH5ELha62W9j5wg5UfY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734932; c=relaxed/simple; bh=wJOyfULGjQ7JJwE+0qiErJO6uCXLldGcRp+nAP+aV5k=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=bM8snXx+pUZfyeDDe9Jxg8IjrokfKOSX8+mj36peEfYq3+kQxjqVruLgsRhBfKX5eg9DGwrGEpBgnC3CEVS5K8dn8gk2oGffnswZRebUmrByhH+A/BqGa4TWtziXcg3odlWrboOchEAuDD8z2LvxizUePVeKa25mw+Wky6iRPqQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=PUJa1ljA; arc=none smtp.client-ip=209.85.167.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="PUJa1ljA" Received: by mail-oi1-f198.google.com with SMTP id 5614622812f47-4959c49e054so734183b6e.3 for ; Wed, 26 Aug 2026 02:02:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787734929; x=1788339729; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TNaAio5F1cBCNtxlrEFoP4xklnbz677Jx5ey+mk7fOE=; b=PUJa1ljACwtONDi052/ABCvaWucEVkKwtyCF606XGMgd3k+0d+LMjn/UwcygA9W4kG o7SYCEF9AeYQLo9XRIs6jyknlIXFsciefvaJ7dak0mpMbuYMiBd6UJpYQHUkjg+4loEn 9Zl1LL3jbH3pweW47ijxMJslEVWtWRUOeGzxJ4dwU3bCzZLCuPfPTH9EfD6EZHwP/gh/ qAmqXKzGkgplzJUCDngTU1D+T4oD+PHLQ/ZQnRtkQ1+OxiedNFM1e13UxvboBYciun+U Fw57Rf8ZKgJSgT4IRyVZ5t/LT/1JavO7DkF3zW7024KNw9xI8Rjm9vcnwIZ3MeZC7qff oWxw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787734929; x=1788339729; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=TNaAio5F1cBCNtxlrEFoP4xklnbz677Jx5ey+mk7fOE=; b=QDjWxWIIwou2/Ryz/YmFENAP3CmjhHc1/CmAbmuF53uesXEinQBBktd6s3M7cADYNR PlQYd+RXVDezTCnRB/eq41aa+g19kG+wd4pAqOhQ4pzh4+3Ww6MWgSJEb4mp2rCneniE lfesnsZDh8BWlfKmRyUv1qlv0vz1En+5XIN89h3B5IBDgMSB4nh9eI+ugZeC40PUjk9Q U4Kg8mIlwrPdlgAIS3eCDHeRHdvtgAvQ706rPziizJ+hfIb6TFPNZbhxcsx/PxGcxo68 +ucPy8TLIk812RE/LrhWuHM5bZDTev7gGcKla6VEupSLQEPFU6FFnzpnMIDuNIxoh+YJ L3SQ== X-Forwarded-Encrypted: i=1; AHgh+Rr4M+3dx/WjsARv/XTpy5lpFLM/8hQSn0pTZRs7LWNKOxqg1BtAVIGF5WFr15aqM9SpLQPlhF2Pem+IWEk=@vger.kernel.org X-Gm-Message-State: AFuF++k/XJXg8Ol0Es2aNCW0rNjLrGkPn+9jDPFuulJ/tFak8GafUNor XMsleYITH+3Nk3eV9yvmHhKKes+P22kXSjJt2LiMaYIxpp9Hu8ioCuOTp0xYk7yfOQZgkMLi0hi HhoEtL8P0zDC0gAW1nq+L4v34tA== X-Received: from pgnm16.prod.google.com ([2002:a63:7d50:0:b0:c88:90c8:13c5]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6808:2f18:b0:496:11f1:f2b5 with SMTP id 5614622812f47-4b366a4fac4mr6019140b6e.10.1787734928803; Wed, 26 Aug 2026 02:02:08 -0700 (PDT) Date: Wed, 26 Aug 2026 09:01:49 +0000 In-Reply-To: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787734920; l=1353; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=wJOyfULGjQ7JJwE+0qiErJO6uCXLldGcRp+nAP+aV5k=; b=z/jEqpUrNgcyUxL/Z8M0h+X83m4nMTDrvNZG71fmUEG3iFGsl8CB+iONKXlWeTPtqJt/DJfsA fXBzpO0jrAZBZvXSyzkSiu1twbOvJ+XRsMxmMGFlpjbWacNRwyM4Zwe X-Mailer: b4 0.16.0 Message-ID: <20260826-gmem-no-return-page-v4-4-3bb9c1ddb4e3@google.com> Subject: [PATCH v4 4/5] KVM: SEV: Drop page refcount early in VMSA reload From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve , Fuad Tabba Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable When reloading the guest VMSA for an SEV-SNP vCPU, KVM retrieves the PFN from guest_memfd. Drop the page reference immediately after retrieving the PFN instead of holding it across MMU lock acquisition in preparation for a follow-up patch to stop returning page pointers from guest_memfd PFN lookups. This is safe because the page's validity and presence are governed by KVM's MMU invalidation protocol rather than the page reference. No functional change intended. Reviewed-by: Michael Roth Signed-off-by: Ackerley Tng --- arch/x86/kvm/svm/sev.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index f9dce8acac8eb..f094b19226b92 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -4078,6 +4078,7 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) */ if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, &page, NULL)) return; + kvm_release_page_clean(page); =20 read_lock(&kvm->mmu_lock); /* @@ -4092,8 +4093,6 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) else svm->vmcb->control.vmsa_pa =3D pfn_to_hpa(pfn); read_unlock(&kvm->mmu_lock); - - kvm_release_page_clean(page); } =20 /* --=20 2.55.0.887.g758fc8c411-goog From nobody Mon Sep 28 04:53:45 2026 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 90CBE34A791 for ; Wed, 26 Aug 2026 09:02:11 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734938; cv=none; b=VSv05S2rJc+lp5yZkmOjtYXcQKOICjshpdiahXrnDqGDLAak29WbA1Bfh4fLslgceC48EjN3UmPS6KACrW8Mhz022+7p3/y9p0RiyPuf3OkUtViN9GcoJy9l73zzsSuMcTNu53UmvspBZDDaL1LZHRqeu/bOnbRM+50yilbd8kk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787734938; c=relaxed/simple; bh=EuG4Bw/IwxonT7NoYlGbm2ezLAZ4QQJbygHjHjvFx1U=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=cZZv+soYA2RLVRRq7Kim+xowaBgepIJ22zOIHMQvcmBB+0SCx+LkzxpfySaGTM0iI255ALP1DZpv6euJGTOct+TvXn9cTaMlZjhVgr6VndeTvRsrp/eTx5FapQMBFyTx0e4q9yuV2rXPeXfHeVNSOWNlFdfBohzsSmd7NrKZ8VA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=Xge4M0Oh; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--ackerleytng.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="Xge4M0Oh" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d63c16fc5bso17852315ad.1 for ; Wed, 26 Aug 2026 02:02:11 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1787734931; x=1788339731; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=jLtAYTqZ8m2gVWkFMzaTBxqNZtYSobzX0FvE5dD3wNU=; b=Xge4M0OhEijZg++Kf/SLxP8tRSngRa6etBXaPP4OG8Akx3J6Yt3U4trhjwbF70Cx1c AVjjP2SSYCbzYT6FZIc87t4y1R8XTHDz/8+UsEnEuUyr1v4+Ye0K76e7GasUrOizp3UW cuFh4ATg1ehqdOXaP/hzxSj1DJOlPpq2jhgZ+04QDPPM9B4xQ1izLJTXmJr2WqhlBINC r1C6K4K5pZehP461nOUkEvoJ4bsWplRWCPsAvVPoKsV3EKzRngI8XxFVOyeIOGOChyLY 4XcyhdjKgIHLbADdLIAngLiFOIriRPVpMxan0fZBBeLShoglAtf7b/hyGpmcM/puUI0M h5jg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787734931; x=1788339731; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=jLtAYTqZ8m2gVWkFMzaTBxqNZtYSobzX0FvE5dD3wNU=; b=VKPUzNxy9jLTGbleo3KLafc/OUA201OOZoATHibMNRhm9FALcNiTSANAR5cwbEYEav CEU7WF+7lQk5KSQcfKOqjYiULWB6tW8puWrgjrgw1oDULgtN6BNqeqqFdLvdVhAmHnOt 4xCdyUt5vooPFkLrdbZnCEOFOhhXpW1TNHuOFBgGQhkmNfMhA1LhK3RLQzKDUj8OlnvS fOyUSgBF+QYqhxkJikJAuHC8m+62kEX9M5YPZgWnKZp+D/ADJUfyFt+/3hPS8IcYVjPK e8EGD6RY2vlYe21v5LxbQM6NaTHPjuWetbNH4GucocpCu+waCdmHrcEoEA5jOAY+AxTy ydYQ== X-Forwarded-Encrypted: i=1; AHgh+RpL49dsZ+7MEe5SCCsfFUOSZYzmVUWFwNi3g5GOVreE2E6fRwb+cmuWGUWpoO6QnBDaF6+6uZok9cBpCKc=@vger.kernel.org X-Gm-Message-State: AFuF++mVveeqc3kZPp6C0Ibcg/WW9Aprf8GAmC3aa/Jxp/8xbkKezEog 91dh+/N8NzoMW0SCURifMflzFrwYZHJfc1EBiDF8KKnhbuIcDVSkq/dHoQJAzZwe+NeoTHLiqBn aoXTifTZ6EYcyINEp9A0rRuqejw== X-Received: from plkq13.prod.google.com ([2002:a17:902:edcd:b0:2cb:6ca0:1248]) (user=ackerleytng job=prod-delivery.src-stubby-dispatcher) by 2002:a17:902:cf0f:b0:2cf:ccc2:6088 with SMTP id d9443c01a7336-2d7079d7abdmr97226905ad.4.1787734930475; Wed, 26 Aug 2026 02:02:10 -0700 (PDT) Date: Wed, 26 Aug 2026 09:01:50 +0000 In-Reply-To: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260826-gmem-no-return-page-v4-0-3bb9c1ddb4e3@google.com> X-Developer-Key: i=ackerleytng@google.com; a=ed25519; pk=sAZDYXdm6Iz8FHitpHeFlCMXwabodTm7p8/3/8xUxuU= X-Developer-Signature: v=1; a=ed25519-sha256; t=1787734920; l=8731; i=ackerleytng@google.com; s=20260225; h=from:subject:message-id; bh=nQHQvdfVTe8YWF07i/KIfGAKndM7sUZ07Zir0Zm3JhM=; b=7O/YDRidiYyfgNPRedNkaCXKwFh2juYusyUvJu78qdc3QMByvSs6i/jUYXaHo7huBUVQkQgYa OlaPL1guJ3aBqO9gSzVN8dFDMXou2keyNE93y8J56B67HXEqHhNIYMx X-Mailer: b4 0.16.0 Message-ID: <20260826-gmem-no-return-page-v4-5-3bb9c1ddb4e3@google.com> Subject: [PATCH v4 5/5] KVM: guest_memfd: Stop returning struct page from PFN lookup From: Ackerley Tng To: Sean Christopherson , Paolo Bonzini , Thomas Gleixner , Ingo Molnar , Borislav Petkov , Dave Hansen , x86@kernel.org, "H. Peter Anvin" , Ashish Kalra , Michael Roth , Brijesh Singh , Marc Zyngier , Oliver Upton , Joey Gouly , Steffen Eiden , Suzuki K Poulose , Zenghui Yu , Catalin Marinas , Will Deacon , David Hildenbrand , Yan Zhao , "Edgecombe, Rick P" , Vishal Annapurve , Fuad Tabba Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, kvmarm@lists.linux.dev, Ackerley Tng Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable From: Sean Christopherson KVM currently expects guest_memfd PFN lookups to return a refcounted struct page, which callers hold across fault handling. Drop the page's refcount before returning from kvm_gmem_get_pfn() to prepare for the in-place conversions series. CoCo shared-to-private conversion handling must inspect folio refcounts to ensure exclusive ownership by guest_memfd. A concurrent guest page fault taking a temporary reference on the folio causes conversions to fail due to an elevated refcount. While this refcount is also taken on host userspace page faults, that refcount is taken on behalf of the host userspace page tables. This refcount will be dropped when conversions unmaps the page. Either way, once there's an mmap() or userspace mapping, the pages are open to way more refcounts, transient or not. This patch focuses on just dropping refcounts before handing KVM a page. guest_memfd already notifies KVM of page invalidations, so callers within KVM only need to respect the MMU invalidation protocol to safely rely on guest_memfd for page presence. Since the page refcounts are dropped, don't return the struct page pointer. Not returning the struct page from the guest_memfd PFN lookup moves KVM closer toward supporting memory backends that are not backed by struct page. Here are some notes on the cleanup in the callers of kvm_gmem_get_pfn(): kvm_release_faultin_page() in ARM's gmem_abort() originally also serves to set the page dirty and accessed under some conditions. The dirty and accessed flags don't matter for guest_memfd anyway, so it is safe to just drop the call to kvm_release_faultin_page(). For ARM's kvm_translate_vncr(), the local page pointer must be initialized to NULL so that the shared cleanup path that releases faulted-in pages safely no-ops for guest_memfd. For x86, no additional changes are required in the MMU fault path because the page fault tracking structure is zero-initialized at the start of page fault handling, ensuring the refcounted page pointer is already NULL. Reported-by: Yan Zhao Closes: https://lore.kernel.org/all/anZ4W9o5pTWIEgMY@yzhao56-desk.sh.intel.= com/ Signed-off-by: Sean Christopherson Co-developed-by: Yan Zhao Signed-off-by: Yan Zhao Reviewed-by: Suzuki K Poulose Reviewed-by: Michael Roth Tested-by: Michael Roth Tested-by: Yan Zhao Reviewed-by: Fuad Tabba Tested-by: Fuad Tabba Co-developed-by: Ackerley Tng Signed-off-by: Ackerley Tng --- arch/arm64/kvm/mmu.c | 4 +--- arch/arm64/kvm/nested.c | 4 ++-- arch/x86/kvm/mmu/mmu.c | 2 +- arch/x86/kvm/svm/sev.c | 8 ++------ include/linux/kvm_host.h | 6 ++---- virt/kvm/guest_memfd.c | 9 ++------- 6 files changed, 10 insertions(+), 23 deletions(-) diff --git a/arch/arm64/kvm/mmu.c b/arch/arm64/kvm/mmu.c index 9ba86450fe4af..d57f8181f1b7d 100644 --- a/arch/arm64/kvm/mmu.c +++ b/arch/arm64/kvm/mmu.c @@ -1613,7 +1613,6 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) enum kvm_pgtable_prot prot =3D KVM_PGTABLE_PROT_R; struct kvm_pgtable *pgt =3D s2fd->vcpu->arch.hw_mmu->pgt; unsigned long mmu_seq; - struct page *page; struct kvm *kvm =3D s2fd->vcpu->kvm; void *memcache =3D NULL; kvm_pfn_t pfn; @@ -1641,7 +1640,7 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) /* Pairs with the smp_wmb() in kvm_mmu_invalidate_end(). */ smp_rmb(); =20 - ret =3D kvm_gmem_get_pfn(kvm, s2fd->memslot, gfn, &pfn, &page, NULL); + ret =3D kvm_gmem_get_pfn(kvm, s2fd->memslot, gfn, &pfn, NULL); if (ret) { kvm_prepare_memory_fault_exit(s2fd->vcpu, s2fd->fault_ipa, PAGE_SIZE, write_fault, exec_fault, false); @@ -1681,7 +1680,6 @@ static int gmem_abort(const struct kvm_s2_fault_desc = *s2fd) } =20 out_unlock: - kvm_release_faultin_page(kvm, page, !!ret, prot & KVM_PGTABLE_PROT_W); kvm_fault_unlock(kvm); =20 if ((prot & KVM_PGTABLE_PROT_W) && !ret) diff --git a/arch/arm64/kvm/nested.c b/arch/arm64/kvm/nested.c index 17123f0b6daba..dd62840d36741 100644 --- a/arch/arm64/kvm/nested.c +++ b/arch/arm64/kvm/nested.c @@ -1415,7 +1415,7 @@ static int kvm_translate_vncr(struct kvm_vcpu *vcpu, = bool *is_gmem) bool write_fault, writable; unsigned long mmu_seq; struct vncr_tlb *vt; - struct page *page; + struct page *page =3D NULL; u64 va, pfn, gfn; int ret; =20 @@ -1471,7 +1471,7 @@ static int kvm_translate_vncr(struct kvm_vcpu *vcpu, = bool *is_gmem) return -EFAULT; } } else { - ret =3D kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, &page, NULL); + ret =3D kvm_gmem_get_pfn(vcpu->kvm, memslot, gfn, &pfn, NULL); if (ret) { kvm_prepare_memory_fault_exit(vcpu, vt->wr.pa, PAGE_SIZE, write_fault, false, false); diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c index 064ecc33b9267..947c9cd843450 100644 --- a/arch/x86/kvm/mmu/mmu.c +++ b/arch/x86/kvm/mmu/mmu.c @@ -4628,7 +4628,7 @@ static int kvm_mmu_faultin_pfn_gmem(struct kvm_vcpu *= vcpu, } =20 r =3D kvm_gmem_get_pfn(vcpu->kvm, fault->slot, fault->gfn, &fault->pfn, - &fault->refcounted_page, &max_order); + &max_order); if (r) { kvm_mmu_prepare_memory_fault_exit(vcpu, fault); return r; diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index f094b19226b92..0a887f8e05d3a 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -4032,7 +4032,6 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) struct kvm *kvm =3D vcpu->kvm; gfn_t gfn =3D gpa_to_gfn(gpa); unsigned long mmu_seq; - struct page *page; kvm_pfn_t pfn; =20 lockdep_assert_held(&svm->sev_es.snp_vmsa_mutex); @@ -4076,9 +4075,8 @@ static void __sev_snp_reload_vmsa(struct kvm_vcpu *vc= pu, gpa_t gpa) * The new VMSA will be private memory guest memory, so retrieve the * PFN from the gmem backend. */ - if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, &page, NULL)) + if (kvm_gmem_get_pfn(vcpu->kvm, slot, gfn, &pfn, NULL)) return; - kvm_release_page_clean(page); =20 read_lock(&kvm->mmu_lock); /* @@ -5019,7 +5017,6 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gpa_= t gpa, u64 error_code) struct kvm *kvm =3D vcpu->kvm; int order, rmp_level, ret; unsigned long mmu_seq; - struct page *page; bool assigned; kvm_pfn_t pfn; gfn_t gfn; @@ -5049,13 +5046,12 @@ void sev_handle_rmp_fault(struct kvm_vcpu *vcpu, gp= a_t gpa, u64 error_code) mmu_seq =3D kvm->mmu_invalidate_seq; smp_rmb(); =20 - ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &page, &order); + ret =3D kvm_gmem_get_pfn(kvm, slot, gfn, &pfn, &order); if (ret) { pr_warn_ratelimited("SEV: Unexpected RMP fault, no backing page for priv= ate GPA 0x%llx\n", gpa); return; } - kvm_release_page_unused(page); =20 ret =3D snp_lookup_rmpentry(pfn, &assigned, &rmp_level); if (ret || !assigned) { diff --git a/include/linux/kvm_host.h b/include/linux/kvm_host.h index 03bfc92864b6e..502465119ca0c 100644 --- a/include/linux/kvm_host.h +++ b/include/linux/kvm_host.h @@ -2586,13 +2586,11 @@ static inline bool kvm_mem_is_private(struct kvm *k= vm, gfn_t gfn) =20 #ifdef CONFIG_KVM_GUEST_MEMFD int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, - gfn_t gfn, kvm_pfn_t *pfn, struct page **page, - int *max_order); + gfn_t gfn, kvm_pfn_t *pfn, int *max_order); #else static inline int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, gfn_t gfn, - kvm_pfn_t *pfn, struct page **page, - int *max_order) + kvm_pfn_t *pfn, int *max_order) { KVM_BUG_ON(1, kvm); return -EIO; diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index b596486d184ca..589762140c3ef 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -751,8 +751,7 @@ static struct folio *__kvm_gmem_get_pfn(struct file *fi= le, } =20 int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memory_slot *slot, - gfn_t gfn, kvm_pfn_t *pfn, struct page **page, - int *max_order) + gfn_t gfn, kvm_pfn_t *pfn, int *max_order) { pgoff_t index =3D kvm_gmem_get_index(slot, gfn); struct folio *folio; @@ -780,11 +779,7 @@ int kvm_gmem_get_pfn(struct kvm *kvm, struct kvm_memor= y_slot *slot, #endif =20 folio_unlock(folio); - - if (!r) - *page =3D folio_file_page(folio, index); - else - folio_put(folio); + folio_put(folio); =20 return r; } --=20 2.55.0.887.g758fc8c411-goog