From: Sean Christopherson <seanjc@google.com>
To: Sean Christopherson <seanjc@google.com>,
Paolo Bonzini <pbonzini@redhat.com>
Cc: kvm@vger.kernel.org, linux-kernel@vger.kernel.org,
Rick Edgecombe <rick.p.edgecombe@intel.com>,
Kai Huang <kai.huang@intel.com>, Yan Zhao <yan.y.zhao@intel.com>,
Sashiko Bot <sashiko-bot@kernel.org>
Subject: [PATCH v2 0/4] KVM: x86/mmu: Fix pre-fault and map private loops
Date: Wed, 26 Aug 2026 09:42:10 -0700 [thread overview]
Message-ID: <20260826164214.756512-1-seanjc@google.com> (raw)
Fix a bug in the pre-fault path where KVM fails to reload an invalidated
MMU root, which puts the KVM_PRE_FAULT_MEMORY task into an infinite loop
(although it's breakable, so not fatal to the host). My best guess is that
the test started failing once PREEMPT_LAZY was enabled by default. Note,
the bug is *really* easy to repro with a to-be-proposed patch to have KVM
do auto-pre-faulting[*], i.e. prefetch surrounding pages on fault.
Then harden the similar "map private PFN" to also guard against unexpected
root invalidations, because Sashiko keeps pointing out that it's theoretically
possible for that code to end up in the same type of infinite loop.
[*] https://lore.kernel.org/all/ao4CufEI_pRCjbMF@google.com
v2:
- Collect reviews. [Rick, Kai]
- Tweak the slots_comment in kvm_tdp_mmu_map_private_pfn() to better capture
the nuances of KVM_REQ_MMU_FREE_OBSOLETE_ROOTS. [Rick]
- Call out in the changelog for patch 2 that simply warning on
KVM_REQ_MMU_FREE_OBSOLETE_ROOTS is flawed, but handled in a subsequent
patch. [Sashiko]
- Make it more clear that encountering retry in kvm_tdp_mmu_map_private_pfn()
can only happen if there are KVM bugs. [Rick]
- Set r to RET_PF_RETRY when a stale page fault is detected. [Sashiko]
v1: https://lore.kernel.org/all/20260806214050.78058-1-seanjc@google.com
Sean Christopherson (4):
KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration
KVM: x86/mmu: Harden "map private PFN" against unexpected root
invalidation
KVM: x86/mmu: Top-up memory caches when retrying "map private PFN"
KVM: x86/mmu: Add sanity check to detect stale page faults in "map
private PFN"
arch/x86/kvm/mmu/mmu.c | 48 ++++++++++++++++++++++++++++--------------
1 file changed, 32 insertions(+), 16 deletions(-)
base-commit: 76671054f9a1ff6abb976583cd8da37650acdc97
--
2.55.0.860.g4b6b3295ed-goog
next reply other threads:[~2026-08-26 16:42 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-26 16:42 Sean Christopherson [this message]
2026-08-26 16:42 ` [PATCH v2 1/4] KVM: x86/mmu: Reload MMU on *every* page pre-fault attempt/iteration Sean Christopherson
2026-08-26 16:42 ` [PATCH v2 2/4] KVM: x86/mmu: Harden "map private PFN" against unexpected root invalidation Sean Christopherson
2026-08-26 16:42 ` [PATCH v2 3/4] KVM: x86/mmu: Top-up memory caches when retrying "map private PFN" Sean Christopherson
2026-08-26 16:42 ` [PATCH v2 4/4] KVM: x86/mmu: Add sanity check to detect stale page faults in " Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260826164214.756512-1-seanjc@google.com \
--to=seanjc@google.com \
--cc=kai.huang@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=pbonzini@redhat.com \
--cc=rick.p.edgecombe@intel.com \
--cc=sashiko-bot@kernel.org \
--cc=yan.y.zhao@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®