mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH bpf-next 0/5] bpf: Expose pinned arenas as sized bpffs files
@ 2026-10-10 22:45 Andrea Righi
  2026-10-10 22:45 ` [PATCH 1/5] bpf: Add an arena flag to retain allocated pages Andrea Righi
                   ` (4 more replies)
  0 siblings, 5 replies; 10+ messages in thread
From: Andrea Righi @ 2026-10-10 22:45 UTC (permalink / raw)
  To: Alexei Starovoitov, Daniel Borkmann, Andrii Nakryiko,
	Eduard Zingerman, Kumar Kartikeya Dwivedi
  Cc: Martin KaFai Lau, Song Liu, Yonghong Song, Jiri Olsa,
	Emil Tsalapatis, Ihor Solodrai, John Fastabend, Josh Don,
	Vineeth Pillai, Balbir Singh, Shameer Kolothum,
	Himadri Chhaya-Shailesh, NchangRoy, bpf, linux-kernel

As discussed in the BPF track and the sched_ext microconference at Linux
Plumbers 2026 [1][2], shared BPF arenas can provide a generic channel
for bidirectional zero-copy communication between BPF programs running
on a host and its guests. One potential use is to exchange scheduling
hints between host and guest sched_ext schedulers through shared memory.

The goal is to let both schedulers access the same underlying pages as
BPF arena memory. Exchanging hints then requires no copies between
separate host and guest buffers. With the arena file interface proposed
here, the setup uses existing QEMU/KVM memory backends and guest NUMA
interfaces, without further kernel or hypervisor changes to implement
the communication channel.

A host scheduler's userspace component can create and pin an arena map,
then use an arena allocator to partition it into per-guest chunks.
Userspace passes each chunk to QEMU as a shared file-backed memory
backend, using a bounded offset and length in the sized bpffs file.
QEMU exposes only that chunk as a NUMA node inside the corresponding
guest; the rest of the host arena is not mapped into guest RAM.

The guest scheduler can create its own arena and allocate pages from
that NUMA node. Those guest physical pages are backed by the host arena,
so host and guest BPF programs can access the same memory through their
respective arenas. After identifying the corresponding arena offsets,
both sides exchange data through direct BPF loads and stores. Arena
pointers are not relocated between mappings; a shared protocol can use
validated slice-relative offsets instead.

QEMU is one potential consumer. The interface is generic: it exposes a
pinned BPF arena as a sized bpffs file that ordinary userspace consumers
can open and mmap, including consumers that require a file size when
setting up shared memory.

The series separates page retention from file export:

* BPF_F_ARENA_NO_FREE makes BPF page-free operations no-ops, retaining
  allocated pages until the map is destroyed. This flag alone preserves
  ordinary arena pin behavior.
* BPF_F_ARENA_EXPORT exposes the pin as a sized file and requires
  BPF_F_ARENA_NO_FREE, so BPF programs cannot remove backing pages while
  external consumers may still use them.

The map FD retains the canonical BPF address range. Exported mappings
can select different virtual addresses and map disjoint slices. Faults
resolve by file offset, and page zaps cover only the overlapping range
in each exported VMA. Consumers establish the canonical range through
map_extra or a full-capacity map FD mapping before mapping the pin.
For exported arenas, the canonical range matches the fixed file size;
ordinary and retention-only arenas still allow shorter mappings.

Pin permissions distinguish readers from writers. O_RDONLY consumers
can create read-only shared mappings, but cannot request writable
mappings or acquire write permission through mprotect(). Private
mappings and file size changes are rejected. Open files and mappings
retain the arena after unpinning until the last reference is released.
The capacity is initialized before inode publication and can be queried
with fstat() or lseek(fd, 0, SEEK_END).

Exported mappings retain the arena's lifecycle restrictions: they are
not inherited across fork and cannot be split, expanded, or relocated.
The documentation describes these limits and native tests exercise them.

Access through open() and mmap() intentionally uses filesystem
permissions and the applicable file, mmap, and BPF map LSM checks.
olicies specific to the bpf() syscall, including seccomp filters on that
syscall, do not govern this file interface.

[1] https://lpc.events/event/20/contributions/2429/
[2] https://lpc.events/event/20/contributions/2482/

Git tree: git://git.kernel.org/pub/scm/linux/kernel/git/arighi/linux.git bpf-pinned-arena

Andrea Righi (5):
  bpf: Add an arena flag to retain allocated pages
  bpf: Expose pinned arenas as sized bpffs files
  docs/bpf: Document pinned arena file mappings
  selftests/bpf: Test pinned arena file mappings
  selftests/bpf: Test two-way arena access with two guests

 Documentation/bpf/map_arena.rst               | 131 +++++
 include/uapi/linux/bpf.h                      |   6 +
 kernel/bpf/arena.c                            |  75 ++-
 kernel/bpf/inode.c                            |  95 +++-
 tools/include/uapi/linux/bpf.h                |   6 +
 tools/testing/selftests/bpf/.gitignore        |   2 +
 tools/testing/selftests/bpf/Makefile          |  27 +-
 tools/testing/selftests/bpf/arena_kvm.py      | 448 ++++++++++++++++++
 .../selftests/bpf/arena_kvm_guest.bpf.c       |  89 ++++
 tools/testing/selftests/bpf/arena_kvm_guest.c | 224 +++++++++
 .../selftests/bpf/arena_kvm_host.bpf.c        |  89 ++++
 tools/testing/selftests/bpf/arena_kvm_host.c  | 147 ++++++
 .../testing/selftests/bpf/arena_kvm_shared.h  |  60 +++
 .../selftests/bpf/prog_tests/arena_pinned.c   | 442 +++++++++++++++++
 14 files changed, 1819 insertions(+), 22 deletions(-)
 create mode 100644 Documentation/bpf/map_arena.rst
 create mode 100755 tools/testing/selftests/bpf/arena_kvm.py
 create mode 100644 tools/testing/selftests/bpf/arena_kvm_guest.bpf.c
 create mode 100644 tools/testing/selftests/bpf/arena_kvm_guest.c
 create mode 100644 tools/testing/selftests/bpf/arena_kvm_host.bpf.c
 create mode 100644 tools/testing/selftests/bpf/arena_kvm_host.c
 create mode 100644 tools/testing/selftests/bpf/arena_kvm_shared.h
 create mode 100644 tools/testing/selftests/bpf/prog_tests/arena_pinned.c

-- 
2.56.0

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2026-10-10 23:40 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-10 22:45 [PATCH bpf-next 0/5] bpf: Expose pinned arenas as sized bpffs files Andrea Righi
2026-10-10 22:45 ` [PATCH 1/5] bpf: Add an arena flag to retain allocated pages Andrea Righi
2026-10-10 22:45 ` [PATCH 2/5] bpf: Expose pinned arenas as sized bpffs files Andrea Righi
2026-10-10 23:40   ` bot+bpf-ci
2026-10-10 22:45 ` [PATCH 3/5] docs/bpf: Document pinned arena file mappings Andrea Righi
2026-10-10 23:19   ` bot+bpf-ci
2026-10-10 22:45 ` [PATCH 4/5] selftests/bpf: Test " Andrea Righi
2026-10-10 23:40   ` bot+bpf-ci
2026-10-10 22:46 ` [PATCH 5/5] selftests/bpf: Test two-way arena access with two guests Andrea Righi
2026-10-10 23:40   ` bot+bpf-ci

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®