From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0C0D33F4104 for ; Tue, 2 Jun 2026 14:29:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780410558; cv=none; b=A6YIezaari4QIwJLADRuhTkVGdpvxKNXo4Af7HqVVE+1DOpijtQxkDSUoaW38yzhD7jdJaEnVusZEhtf6UFrR0eR5EkL9/Gb9ZB8+W4Kr7VXIgT7OK5p0XfZOhrz682r0e5SPsu6I76DbvaBmR+T+RxrfH9BL5+iAxgoL8GbV7Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780410558; c=relaxed/simple; bh=+A2uELDsnAGCdCh735goL76/wUe90FvZW4Lez3TfFeI=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=BiQHw+40Z0ohsTGasfsgyBZ1LtJ+eoS3ahb3dVQtvijDhw9Uu3lBVCdJMyZ4Z+G1rdTDvopRZXxV7dc77fDP/enJTGzLq6dHrPFTPQK0HzuRsuyz3KFYydh2URjAFbQMFwTHwm+uIZW03GXdMXNuwjwsx8fQdXiuQBcJwNEeDWE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=ZcFVWvKH; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=oR1PDYUu; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="ZcFVWvKH"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="oR1PDYUu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780410556; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0p3FJ0ShKCAizMIlCc8mStOg9WAQBwwXAaeLW6j6j6k=; b=ZcFVWvKHI1TSTZidrFbMcykRwvbXUqOW2pmuscopNxphYyMu03rhHOGHd5y787inGz2yas XJ842FjGxT88qKQ977Ji2F9hXK4Mpc7cf8u4Lghs9e2JNgmC1UBSyizwCzTIcPtlU/ZgYq 5clpmMJ1Pmt7Fe8HFKMmFXDL+YnXAp8= Received: from mail-qk1-f199.google.com (mail-qk1-f199.google.com [209.85.222.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-190-G7cW-GpHOUKV5IY8TMaINg-1; Tue, 02 Jun 2026 10:29:15 -0400 X-MC-Unique: G7cW-GpHOUKV5IY8TMaINg-1 X-Mimecast-MFC-AGG-ID: G7cW-GpHOUKV5IY8TMaINg_1780410554 Received: by mail-qk1-f199.google.com with SMTP id af79cd13be357-91574ad681eso303452785a.0 for ; Tue, 02 Jun 2026 07:29:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1780410554; x=1781015354; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=0p3FJ0ShKCAizMIlCc8mStOg9WAQBwwXAaeLW6j6j6k=; b=oR1PDYUuULDytM99Se4oAiLg5kE8HwY0NtfYS6zsBR9Iy8m8v40HHKP1zOunGf6zbR 26QxNJ78BmDD8twIIzYtiiFCgjOmxZa23k2+FN04aAlFtcs1TPVpsL2NzyUsB641hFp9 Snj0+an5hGSNZDOLbLvSuWOH24fZLgVW73rTphTIwbJjdu27HYrhlNCgg4TM/nz0cv3G bBuD3fDIomsWqciuAjJy9+6Z8kya6suFpCD1bOwCKcGV3gcIzK00ixT6bm4LpFePwWPk ZkeS+E4/a3wW4r3bYLOFAWK4Jbs6t3gyZurYCdTh2E88gy+d2eZWI+FeDMx1wK6CrbT9 vvAA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780410554; x=1781015354; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=0p3FJ0ShKCAizMIlCc8mStOg9WAQBwwXAaeLW6j6j6k=; b=NLUPddjjfw8Dp037VMHaZP6zHfsGfef9oTyI2VMcWsxnof8H0m7ah5VVISDbOncv8G qKwyV/l+J0PDcRTEL+99sapXBxIAHlrwUp+HdLnkEvcw0tZpyqSVhYjqT1LZcbpPR1DW 0AeP7HceHWAJGa4rA7ZMttHFEWlXX0A1d2+1I2+9dE/8sTmLRmFpnNHs4DfQas/iVeyv COr7jELe7RJHk75E038GIQpvzKse2rhAVxD0L+0LRcHVjFf1NnRA2PyxyZA8X+kZxAQU hMCrM3txwBbrLmIRvXtVkUy4CuB/p92rU+Ld3RK0DRJfMTdaGZ5GfTndAo85aKe8Nl/S WwPQ== X-Forwarded-Encrypted: i=1; AFNElJ9a6AEd8PS7Kzzb2ig4ra3fpzqrQ+xGiwE3JsDEv2VzjvAhnwu5wUe/pmGNSbyIbvS7/PZMG0i++i5asT4=@vger.kernel.org X-Gm-Message-State: AOJu0YwOaAbiNX7ozHoYS7uFlNawGTBwLElk3QnUoyDdw+nY9uZYFDfQ 1rLzvv7huH2S5KIZWrx5GZeGnVscWDPqZhX5UglYsBeKcAiYySxyWiXJVL0gs/x23ihQfeWbDXI k0F+6Sm53Jf0QtFS5cydZ9nDBBnkHEm2pbtuUtpC8i31uUpgvlEcO4tWxat7Yr4i/UA== X-Gm-Gg: Acq92OHnYumd/QWCXxFHWrngCZDouZAZShLD8HACi22zUgvINiI/tebBITpmr6LkyMt 9zFtweq2RojljZZP/LAWYFpGQwSTJGbDT/2IWo6SyhLlDQGMqTHUE40WMgtWzHnS80dX4dbJGB/ 4KmDHg97pXX+cIwTFscs5TFPncqH2DptbOdBtO2Xak8QMtPhuhmt1djfe8NKuoKxasW32JMs14C IivP2Io0yOx5WWEiE+ajqcSuXuA+ieIFzWWE7G77PHLW23QA1K2JI25EqsTP4inXahe6G7Ie20v l7nTBzIT6UnhqZToBdHClc470HMaCfXgW5dXPARI+DsCoINjIiRm50y2cHS7pqsRiJfFpj7gGob 8phw8QW4jM3Y6f5Q295TVzI+ibZyERYhAiTEbUwU= X-Received: by 2002:a05:620a:241a:20b0:914:c61f:c699 with SMTP id af79cd13be357-9153d938cd3mr1742905485a.13.1780410554327; Tue, 02 Jun 2026 07:29:14 -0700 (PDT) X-Received: by 2002:a05:620a:241a:20b0:914:c61f:c699 with SMTP id af79cd13be357-9153d938cd3mr1742900285a.13.1780410553748; Tue, 02 Jun 2026 07:29:13 -0700 (PDT) Received: from intellaptop.lan ([2607:fea8:fc01:88aa:f1de:f35:7935:804f]) by smtp.gmail.com with ESMTPSA id af79cd13be357-91566f4abf3sm459120485a.27.2026.06.02.07.29.12 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 07:29:13 -0700 (PDT) Message-ID: <48424fff4d8e760817def1842427f7bffab5ab16.camel@redhat.com> Subject: Re: [PATCH 21/28] KVM: x86/mmu: propagate access mask from root pages down From: mlevitsk@redhat.com To: Paolo Bonzini , linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: d.riley@proxmox.com, jon@nutanix.com Date: Tue, 02 Jun 2026 10:29:12 -0400 In-Reply-To: <20260505195226.563317-22-pbonzini@redhat.com> References: <20260505195226.563317-1-pbonzini@redhat.com> <20260505195226.563317-22-pbonzini@redhat.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.52.4 (3.52.4-2.fc40) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Tue, 2026-05-05 at 21:52 +0200, Paolo Bonzini wrote: > Until now, all SPTEs have had all kinds of access allowed; however, > for GMET to be enabled all the pages have to have ACC_USER_MASK > disabled.=C2=A0 By marking them as supervisor pages, the processor > allows execution from either user or supervisor mode (unlike > for normal paging, NPT ignores the U bit for reads and writes). Hi! AFAIK, according to the AMD's APM, NPT forces U bit to be 1, so it might be= worth it to update the commit message to state that NPT ignores U bit when GMET is enab= led. "A page is considered user in the guest only if it's marked as user at the = guest level.=C2=A0 The page must be marked user in the nested page table to allow any guest ac= cess at all." I haven't found anything else about this in the APM (Rev. 3.44=E2=80=94Marc= h 2026). Using common sense, I agree that with GMET enabled, the U bit must be ignor= ed for read/writes though, but once again, I haven't found anything about it in the APM. > That will mean that the root page's role has ACC_USER_MASK > cleared and that has to be propagated down through the kvm_mmu_page > tree. >=20 > Do that, and pass the required access to the > kvm_mmu_spte_requested tracepoint since it's not ACC_ALL > anymore. It might be worth it to mention that other than changes to the tracepoints, this patch doesn't yet change any functionality (everything is still ACC_AL= L) Reviewed-by: Maxim Levitsky Best regards, Maxim Levitsky >=20 > Tested-by: David Riley > Signed-off-by: Paolo Bonzini > --- > =C2=A0arch/x86/kvm/mmu/mmu.c=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0 |=C2=A0 9 +++++---- > =C2=A0arch/x86/kvm/mmu/mmutrace.h=C2=A0=C2=A0=C2=A0 | 10 ++++++---- > =C2=A0arch/x86/kvm/mmu/paging_tmpl.h |=C2=A0 2 +- > =C2=A0arch/x86/kvm/mmu/tdp_mmu.c=C2=A0=C2=A0=C2=A0=C2=A0 |=C2=A0 6 +++--- > =C2=A04 files changed, 15 insertions(+), 12 deletions(-) >=20 > diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c > index ededc26c6675..156bab8afbc6 100644 > --- a/arch/x86/kvm/mmu/mmu.c > +++ b/arch/x86/kvm/mmu/mmu.c > @@ -3446,12 +3446,13 @@ static int direct_map(struct kvm_vcpu *vcpu, stru= ct kvm_page_fault *fault) > =C2=A0{ > =C2=A0 struct kvm_shadow_walk_iterator it; > =C2=A0 struct kvm_mmu_page *sp; > - int ret; > + int ret, access; > =C2=A0 gfn_t base_gfn =3D fault->gfn; > =C2=A0 > =C2=A0 kvm_mmu_hugepage_adjust(vcpu, fault); > =C2=A0 > - trace_kvm_mmu_spte_requested(fault); > + access =3D vcpu->arch.mmu->root_role.access; > + trace_kvm_mmu_spte_requested(fault, access); > =C2=A0 for_each_shadow_entry(vcpu, fault->addr, it) { > =C2=A0 /* > =C2=A0 * We cannot overwrite existing page tables with an NX > @@ -3464,7 +3465,7 @@ static int direct_map(struct kvm_vcpu *vcpu, struct= kvm_page_fault *fault) > =C2=A0 if (it.level =3D=3D fault->goal_level) > =C2=A0 break; > =C2=A0 > - sp =3D kvm_mmu_get_child_sp(vcpu, it.sptep, base_gfn, true, ACC_ALL); > + sp =3D kvm_mmu_get_child_sp(vcpu, it.sptep, base_gfn, true, access); > =C2=A0 if (sp =3D=3D ERR_PTR(-EEXIST)) > =C2=A0 continue; > =C2=A0 > @@ -3477,7 +3478,7 @@ static int direct_map(struct kvm_vcpu *vcpu, struct= kvm_page_fault *fault) > =C2=A0 if (WARN_ON_ONCE(it.level !=3D fault->goal_level)) > =C2=A0 return -EFAULT; > =C2=A0 > - ret =3D mmu_set_spte(vcpu, fault->slot, it.sptep, ACC_ALL, > + ret =3D mmu_set_spte(vcpu, fault->slot, it.sptep, access, > =C2=A0 =C2=A0=C2=A0 base_gfn, fault->pfn, fault); > =C2=A0 if (ret =3D=3D RET_PF_SPURIOUS) > =C2=A0 return ret; > diff --git a/arch/x86/kvm/mmu/mmutrace.h b/arch/x86/kvm/mmu/mmutrace.h > index 3429c1413f42..fa01719baf8d 100644 > --- a/arch/x86/kvm/mmu/mmutrace.h > +++ b/arch/x86/kvm/mmu/mmutrace.h > @@ -373,23 +373,25 @@ TRACE_EVENT( > =C2=A0 > =C2=A0TRACE_EVENT( > =C2=A0 kvm_mmu_spte_requested, > - TP_PROTO(struct kvm_page_fault *fault), > - TP_ARGS(fault), > + TP_PROTO(struct kvm_page_fault *fault, u8 access), > + TP_ARGS(fault, access), > =C2=A0 > =C2=A0 TP_STRUCT__entry( > =C2=A0 __field(u64, gfn) > =C2=A0 __field(u64, pfn) > =C2=A0 __field(u8, level) > + __field(u8, access) > =C2=A0 ), > =C2=A0 > =C2=A0 TP_fast_assign( > =C2=A0 __entry->gfn =3D fault->gfn; > =C2=A0 __entry->pfn =3D fault->pfn | (fault->gfn & (KVM_PAGES_PER_HPAGE(f= ault->goal_level) - 1)); > =C2=A0 __entry->level =3D fault->goal_level; > + __entry->access =3D access; > =C2=A0 ), > =C2=A0 > - TP_printk("gfn %llx pfn %llx level %d", > - =C2=A0 __entry->gfn, __entry->pfn, __entry->level > + TP_printk("gfn %llx pfn %llx level %d access %x", > + =C2=A0 __entry->gfn, __entry->pfn, __entry->level, __entry->access > =C2=A0 ) > =C2=A0); > =C2=A0 > diff --git a/arch/x86/kvm/mmu/paging_tmpl.h b/arch/x86/kvm/mmu/paging_tmp= l.h > index f741f7d4cc2d..047400af924d 100644 > --- a/arch/x86/kvm/mmu/paging_tmpl.h > +++ b/arch/x86/kvm/mmu/paging_tmpl.h > @@ -734,7 +734,7 @@ static int FNAME(fetch)(struct kvm_vcpu *vcpu, struct= kvm_page_fault *fault, > =C2=A0 */ > =C2=A0 kvm_mmu_hugepage_adjust(vcpu, fault); > =C2=A0 > - trace_kvm_mmu_spte_requested(fault); > + trace_kvm_mmu_spte_requested(fault, gw->pte_access); > =C2=A0 > =C2=A0 for (; shadow_walk_okay(&it); shadow_walk_next(&it)) { > =C2=A0 /* > diff --git a/arch/x86/kvm/mmu/tdp_mmu.c b/arch/x86/kvm/mmu/tdp_mmu.c > index 7b1102d26f9c..5a2f8ce9a32b 100644 > --- a/arch/x86/kvm/mmu/tdp_mmu.c > +++ b/arch/x86/kvm/mmu/tdp_mmu.c > @@ -1185,9 +1185,9 @@ static int tdp_mmu_map_handle_target_level(struct k= vm_vcpu *vcpu, > =C2=A0 } > =C2=A0 > =C2=A0 if (unlikely(!fault->slot)) > - new_spte =3D make_mmio_spte(vcpu, iter->gfn, ACC_ALL); > + new_spte =3D make_mmio_spte(vcpu, iter->gfn, sp->role.access); > =C2=A0 else > - wrprot =3D make_spte(vcpu, sp, fault->slot, ACC_ALL, iter->gfn, > + wrprot =3D make_spte(vcpu, sp, fault->slot, sp->role.access, iter->gfn, > =C2=A0 =C2=A0=C2=A0 fault->pfn, iter->old_spte, fault->prefetch, > =C2=A0 =C2=A0=C2=A0 false, fault->map_writable, &new_spte); > =C2=A0 > @@ -1272,7 +1272,7 @@ int kvm_tdp_mmu_map(struct kvm_vcpu *vcpu, struct k= vm_page_fault *fault) > =C2=A0 > =C2=A0 kvm_mmu_hugepage_adjust(vcpu, fault); > =C2=A0 > - trace_kvm_mmu_spte_requested(fault); > + trace_kvm_mmu_spte_requested(fault, root->role.access); > =C2=A0 > =C2=A0 rcu_read_lock(); > =C2=A0