From: Rick Edgecombe <rick.p.edgecombe@intel.com>
To: bp@alien8.de, chao.gao@intel.com, dave.hansen@intel.com,
isaku.yamahata@intel.com, kai.huang@intel.com, kas@kernel.org,
kvm@vger.kernel.org, linux-coco@lists.linux.dev,
linux-kernel@vger.kernel.org, mingo@redhat.com,
pbonzini@redhat.com, seanjc@google.com, tglx@linutronix.de,
vannapurve@google.com, x86@kernel.org, yan.y.zhao@intel.com,
xiaoyao.li@intel.com, binbin.wu@intel.com
Cc: rick.p.edgecombe@intel.com
Subject: [PATCH v4 00/16] TDX: Enable Dynamic PAMT
Date: Thu, 20 Nov 2025 16:51:09 -0800 [thread overview]
Message-ID: <20251121005125.417831-1-rick.p.edgecombe@intel.com> (raw)
Hi,
This is 4th revision of Dynamic PAMT, which is a new feature that reduces
the memory use of TDX. For background information, see the v3
coverletter[0]. V4 mostly consists of incorporating the feedback from v3.
Notably what it *doesn’t* change is the solution for pre-allocating DPAMT
backing pages. (more info below in “Changes”)
I think this series isn’t quite ready to ask for merging just yet. I’d
appreciate another round of review especially looking for any issues in the
refcount allocation/mapping and the pamt get/put lock-refcount dance. And
hopefully collect some RBs.
Sean/Paolo, we have mostly banished this all to TDX code except for “KVM:
TDX: Add x86 ops for external spt cache” patch. That and “x86/virt/tdx:
Add helpers to allow for pre-allocating pages” are probably the remaining
possibly controversial parts of your domain. If you only have a short time
to spend at this point, I’d point you at those two patches.
Since most of the changes are in arch/x86, I’d think this feature could be
a candidate for eventually merging through tip with Sean or Paolo’s ack.
But it is currently based on kvm-x86/next in order to build on top of the
post-populate cleanup series. Next time I’ll probably target tip if people
think that is a good way forward.
Changes
=======
There were two good suggestions around the pre-allocated pages solution
last time, but neither ended up working out:
1. Dave suggested to use mempool_t instead of the linked list based
structure, in order to not re-invent the wheel. This turned out to not
quite fit. The problems were that there wasn’t really a “topup” mechanism,
or an atomic fallback (which matches the kvm cache behavior). This results
in very similar code being built around mempool that was built around the
linked list. It was an overall harder to follow solution for not much code
savings.
I strongly considered going back to Kiryl’s original solution which passed
a callback function pointer for allocating DPAMT pages, and an opaque
void * that the callback could use to find the kvm_mmu_memory_cache. I
thought that readability issues of passing the opaque void * between
subsystems outweighed the small code duplication in the simple, familiar
patterned linked list-based code. So I ended up leaving it.
2. Kai suggested (but later retracted the idea) that since the external
page table cache was moved to TDX code, it could simply install DPAMT
pages for the cache at topup time. Then the installation of DPAMT backing
for S-EPT page tables could be done outside of the mmu_lock. It could also
be argued that it makes the design simpler in a way, because the external
page table cache acts like it did before. Anything in there could be simply
used.
At the time my argument against this was that whether a huge page would be
installed (and thus, whether DPAMT backing was needed) for the guest
private memory would not be known until later, so early install solution
would need special late handling for TDX huge pages. After some internal
discussions I at looked how we could simplify the series by punting on TDX
huge pages needs.
But it turns out that this other design was actually more complex and had
more LOC than the previous solution. So it was dropped, and again, I went
back to the original solution.
I’m really starting to think that, while the overall solution here isn’t
the most elegant, we might not have much more to squeeze from it. So
design-wise, I think we should think about calling it done.
Testing
=======
Based on kvm-x86/next (4531ff85d925). Testing was the usual, except I also
tested with TDX modules that don't support DPAMT, and with the two
optimization patches removed: “Improve PAMT refcounters allocation for
sparse memory” and “x86/virt/tdx: Optimize tdx_alloc/free_page() helpers”.
[0] https://lore.kernel.org/kvm/20250918232224.2202592-1-rick.p.edgecombe@intel.com/
Kirill A. Shutemov (13):
x86/tdx: Move all TDX error defines into <asm/shared/tdx_errno.h>
x86/tdx: Add helpers to check return status codes
x86/virt/tdx: Allocate page bitmap for Dynamic PAMT
x86/virt/tdx: Allocate reference counters for PAMT memory
x86/virt/tdx: Improve PAMT refcounts allocation for sparse memory
x86/virt/tdx: Add tdx_alloc/free_page() helpers
x86/virt/tdx: Optimize tdx_alloc/free_page() helpers
KVM: TDX: Allocate PAMT memory for TD control structures
KVM: TDX: Allocate PAMT memory for vCPU control structures
KVM: TDX: Handle PAMT allocation in fault path
KVM: TDX: Reclaim PAMT memory
x86/virt/tdx: Enable Dynamic PAMT
Documentation/x86: Add documentation for TDX's Dynamic PAMT
Rick Edgecombe (3):
x86/virt/tdx: Simplify tdmr_get_pamt_sz()
KVM: TDX: Add x86 ops for external spt cache
x86/virt/tdx: Add helpers to allow for pre-allocating pages
Documentation/arch/x86/tdx.rst | 21 +
arch/x86/coco/tdx/tdx.c | 10 +-
arch/x86/include/asm/kvm-x86-ops.h | 3 +
arch/x86/include/asm/kvm_host.h | 14 +-
arch/x86/include/asm/shared/tdx.h | 8 +
arch/x86/include/asm/shared/tdx_errno.h | 104 ++++
arch/x86/include/asm/tdx.h | 78 ++-
arch/x86/include/asm/tdx_global_metadata.h | 1 +
arch/x86/kvm/mmu/mmu.c | 6 +-
arch/x86/kvm/mmu/mmu_internal.h | 2 +-
arch/x86/kvm/vmx/tdx.c | 160 ++++--
arch/x86/kvm/vmx/tdx.h | 3 +-
arch/x86/kvm/vmx/tdx_errno.h | 40 --
arch/x86/virt/vmx/tdx/tdx.c | 587 +++++++++++++++++---
arch/x86/virt/vmx/tdx/tdx.h | 5 +-
arch/x86/virt/vmx/tdx/tdx_global_metadata.c | 7 +
16 files changed, 854 insertions(+), 195 deletions(-)
create mode 100644 arch/x86/include/asm/shared/tdx_errno.h
delete mode 100644 arch/x86/kvm/vmx/tdx_errno.h
--
2.51.2
next reply other threads:[~2025-11-21 0:51 UTC|newest]
Thread overview: 106+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-11-21 0:51 Rick Edgecombe [this message]
2025-11-21 0:51 ` [PATCH v4 01/16] x86/tdx: Move all TDX error defines into <asm/shared/tdx_errno.h> Rick Edgecombe
2025-11-25 22:30 ` Huang, Kai
2025-11-25 22:44 ` Huang, Kai
2025-11-26 23:15 ` Edgecombe, Rick P
2025-11-26 23:14 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 02/16] x86/tdx: Add helpers to check return status codes Rick Edgecombe
2025-11-24 8:56 ` Binbin Wu
2025-11-24 19:31 ` Edgecombe, Rick P
2025-11-25 23:07 ` Huang, Kai
2025-11-26 23:26 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 03/16] x86/virt/tdx: Simplify tdmr_get_pamt_sz() Rick Edgecombe
2025-11-24 9:26 ` Binbin Wu
2025-11-24 19:47 ` Edgecombe, Rick P
2025-11-25 1:27 ` Binbin Wu
2025-11-21 0:51 ` [PATCH v4 04/16] x86/virt/tdx: Allocate page bitmap for Dynamic PAMT Rick Edgecombe
2025-11-25 1:50 ` Binbin Wu
2025-11-26 17:56 ` Edgecombe, Rick P
2025-12-24 9:10 ` Xu Yilun
2026-01-05 22:06 ` Edgecombe, Rick P
2026-01-06 4:01 ` Xu Yilun
2026-01-06 17:00 ` Edgecombe, Rick P
2026-01-07 6:01 ` Xu Yilun
2026-01-07 14:41 ` Edgecombe, Rick P
2026-01-08 12:53 ` Xu Yilun
2026-01-08 16:52 ` Edgecombe, Rick P
2026-01-09 2:18 ` Xu Yilun
2026-01-09 16:05 ` Edgecombe, Rick P
2026-01-12 0:24 ` Xu Yilun
2025-11-21 0:51 ` [PATCH v4 05/16] x86/virt/tdx: Allocate reference counters for PAMT memory Rick Edgecombe
2025-11-21 0:51 ` [PATCH v4 06/16] x86/virt/tdx: Improve PAMT refcounts allocation for sparse memory Rick Edgecombe
2025-11-25 3:15 ` Binbin Wu
2025-11-26 20:47 ` Edgecombe, Rick P
2025-11-27 15:57 ` Kiryl Shutsemau
2025-12-01 22:14 ` Edgecombe, Rick P
2025-11-26 14:45 ` Nikolay Borisov
2025-11-26 20:47 ` Edgecombe, Rick P
2025-11-27 7:36 ` Nikolay Borisov
2025-12-11 0:07 ` Edgecombe, Rick P
2025-11-27 16:04 ` Kiryl Shutsemau
2025-11-21 0:51 ` [PATCH v4 07/16] x86/virt/tdx: Add tdx_alloc/free_page() helpers Rick Edgecombe
2025-11-25 8:09 ` Binbin Wu
2025-11-26 22:28 ` Edgecombe, Rick P
2026-01-29 1:19 ` Sean Christopherson
2026-01-29 17:18 ` Edgecombe, Rick P
2026-01-29 19:09 ` Sean Christopherson
2026-01-29 19:12 ` Edgecombe, Rick P
2025-11-26 1:21 ` Huang, Kai
2025-11-26 22:28 ` Edgecombe, Rick P
2025-11-27 12:29 ` Nikolay Borisov
2025-12-01 22:31 ` Edgecombe, Rick P
2025-11-27 16:11 ` Nikolay Borisov
2025-12-01 22:39 ` Edgecombe, Rick P
2025-12-02 7:38 ` Nikolay Borisov
2025-12-02 20:02 ` Edgecombe, Rick P
2025-12-03 13:46 ` Kiryl Shutsemau
2025-12-03 13:48 ` Nikolay Borisov
2025-12-03 15:41 ` Dave Hansen
2025-12-03 18:15 ` Edgecombe, Rick P
2025-12-03 18:21 ` Dave Hansen
2025-12-03 19:59 ` Edgecombe, Rick P
2025-12-03 20:13 ` Dave Hansen
2025-12-03 21:39 ` Edgecombe, Rick P
2025-12-03 21:40 ` Dave Hansen
2025-12-08 9:15 ` Yan Zhao
2025-12-08 20:27 ` Edgecombe, Rick P
2026-01-16 23:17 ` Sean Christopherson
2026-01-16 23:25 ` Edgecombe, Rick P
2026-01-16 23:40 ` Dave Hansen
2025-11-21 0:51 ` [PATCH v4 08/16] x86/virt/tdx: Optimize " Rick Edgecombe
2025-11-21 0:51 ` [PATCH v4 09/16] KVM: TDX: Allocate PAMT memory for TD control structures Rick Edgecombe
2025-11-25 9:11 ` Binbin Wu
2025-11-21 0:51 ` [PATCH v4 10/16] KVM: TDX: Allocate PAMT memory for vCPU " Rick Edgecombe
2025-11-25 9:14 ` Binbin Wu
2025-11-21 0:51 ` [PATCH v4 11/16] KVM: TDX: Add x86 ops for external spt cache Rick Edgecombe
2026-01-17 0:53 ` Sean Christopherson
2026-01-19 2:31 ` Yan Zhao
2026-01-20 8:42 ` Huang, Kai
2026-01-20 9:18 ` Yan Zhao
2026-01-20 10:00 ` Huang, Kai
2026-01-20 19:53 ` Edgecombe, Rick P
2026-01-21 22:12 ` Sean Christopherson
2026-01-21 22:34 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 12/16] x86/virt/tdx: Add helpers to allow for pre-allocating pages Rick Edgecombe
2025-11-26 3:40 ` Binbin Wu
2025-11-26 5:21 ` Binbin Wu
2025-11-26 22:33 ` Edgecombe, Rick P
2025-11-27 2:38 ` Binbin Wu
2026-01-20 7:10 ` Huang, Kai
2026-01-20 7:46 ` Yan Zhao
2026-01-20 8:01 ` Huang, Kai
2026-01-17 1:02 ` Sean Christopherson
2026-01-21 0:52 ` Sean Christopherson
2026-01-21 0:58 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 13/16] KVM: TDX: Handle PAMT allocation in fault path Rick Edgecombe
2025-11-26 5:56 ` Binbin Wu
2025-11-26 22:33 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 14/16] KVM: TDX: Reclaim PAMT memory Rick Edgecombe
2025-11-26 8:53 ` Binbin Wu
2025-11-26 22:58 ` Edgecombe, Rick P
2025-11-21 0:51 ` [PATCH v4 15/16] x86/virt/tdx: Enable Dynamic PAMT Rick Edgecombe
2025-11-21 0:51 ` [PATCH v4 16/16] Documentation/x86: Add documentation for TDX's " Rick Edgecombe
2025-11-26 10:33 ` Binbin Wu
2025-11-26 20:05 ` Edgecombe, Rick P
2025-11-24 20:18 ` [PATCH v4 00/16] TDX: Enable " Sagi Shahar
2025-11-25 20:19 ` Vishal Annapurve
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20251121005125.417831-1-rick.p.edgecombe@intel.com \
--to=rick.p.edgecombe@intel.com \
--cc=binbin.wu@intel.com \
--cc=bp@alien8.de \
--cc=chao.gao@intel.com \
--cc=dave.hansen@intel.com \
--cc=isaku.yamahata@intel.com \
--cc=kai.huang@intel.com \
--cc=kas@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=mingo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=tglx@linutronix.de \
--cc=vannapurve@google.com \
--cc=x86@kernel.org \
--cc=xiaoyao.li@intel.com \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome