mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Huang, Kai" <kai.huang@intel.com>
To: "kvm@vger.kernel.org" <kvm@vger.kernel.org>,
	"pbonzini@redhat.com" <pbonzini@redhat.com>,
	"linux-kernel@vger.kernel.org" <linux-kernel@vger.kernel.org>
Cc: "amit.shah@amd.com" <amit.shah@amd.com>,
	"Kohler, Jon" <jon@nutanix.com>,
	"seanjc@google.com" <seanjc@google.com>,
	"mtosatti@redhat.com" <mtosatti@redhat.com>,
	"nikunj@amd.com" <nikunj@amd.com>
Subject: Re: [PATCH 04/22] KVM: x86/mmu: shuffle high bits of SPTEs in preparation for MBEC
Date: Wed, 25 Mar 2026 04:35:22 +0000	[thread overview]
Message-ID: <59cb97dbac0527e0ba8153116af942f972e4aea5.camel@intel.com> (raw)
In-Reply-To: <20260321000931.1947084-5-pbonzini@redhat.com>

On Sat, 2026-03-21 at 01:09 +0100, Paolo Bonzini wrote:
> Access tracking will need to save bit 10 when MBEC is enabled.
> Right now it is simply shifting the R and X bits into bits 54 and 56,
> but bit 10 would not fit with the same scheme.  Reorganize the
> high bits so that access tracking will use bits 52, 54 and 62.

So that we can continue to do a simple:

      spte |= (spte & SHADOW_ACC_TRACK_SAVED_BITS_MASK) <<
                SHADOW_ACC_TRACK_SAVED_BITS_SHIFT;
?

> As a side effect, the free bits are compacted slightly, with
> 56-59 still unused.
> 
> Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
> ---
>  arch/x86/kvm/mmu/spte.h | 20 +++++++++++++++-----
>  1 file changed, 15 insertions(+), 5 deletions(-)
> 
> diff --git a/arch/x86/kvm/mmu/spte.h b/arch/x86/kvm/mmu/spte.h
> index b60666778f61..7223a61b1260 100644
> --- a/arch/x86/kvm/mmu/spte.h
> +++ b/arch/x86/kvm/mmu/spte.h
> @@ -17,10 +17,20 @@
>   */
>  #define SPTE_MMU_PRESENT_MASK		BIT_ULL(11)
>  
> +/*
> + * The ignored high bits are allocated as follows:
> + * - bits 52, 54: saved X-R bits for access tracking when EPT does not have A/D
> + * - bits 53 (EPT only): host writable
> + * - bits 55 (EPT only): MMU-writable
> + * - bits 56-59: unused
> + * - bits 60-61: type of A/D tracking
> + * - bits 62: unused
> + */
> +
>  /*
>   * TDP SPTES (more specifically, EPT SPTEs) may not have A/D bits, and may also
>   * be restricted to using write-protection (for L2 when CPU dirty logging, i.e.
> - * PML, is enabled).  Use bits 52 and 53 to hold the type of A/D tracking that
> + * PML, is enabled).  Use bits 60 and 61 to hold the type of A/D tracking that
>   * is must be employed for a given TDP SPTE.
>   *
>   * Note, the "enabled" mask must be '0', as bits 62:52 are _reserved_ for PAE
> @@ -29,7 +39,7 @@
>   * TDP with CPU dirty logging (PML).  If NPT ever gains PML-like support, it
>   * must be restricted to 64-bit KVM.
>   */
> -#define SPTE_TDP_AD_SHIFT		52
> +#define SPTE_TDP_AD_SHIFT		60
>  #define SPTE_TDP_AD_MASK		(3ULL << SPTE_TDP_AD_SHIFT)
>  #define SPTE_TDP_AD_ENABLED		(0ULL << SPTE_TDP_AD_SHIFT)
>  #define SPTE_TDP_AD_DISABLED		(1ULL << SPTE_TDP_AD_SHIFT)
> @@ -65,7 +75,7 @@ static_assert(SPTE_TDP_AD_ENABLED == 0);
>   */
>  #define SHADOW_ACC_TRACK_SAVED_BITS_MASK (SPTE_EPT_READABLE_MASK | \
>  					  SPTE_EPT_EXECUTABLE_MASK)
> -#define SHADOW_ACC_TRACK_SAVED_BITS_SHIFT 54
> +#define SHADOW_ACC_TRACK_SAVED_BITS_SHIFT 52
>  #define SHADOW_ACC_TRACK_SAVED_MASK	(SHADOW_ACC_TRACK_SAVED_BITS_MASK << \
>  					 SHADOW_ACC_TRACK_SAVED_BITS_SHIFT)
>  static_assert(!(SPTE_TDP_AD_MASK & SHADOW_ACC_TRACK_SAVED_MASK));
> @@ -84,8 +94,8 @@ static_assert(!(SPTE_TDP_AD_MASK & SHADOW_ACC_TRACK_SAVED_MASK));
>   * to not overlap the A/D type mask or the saved access bits of access-tracked
>   * SPTEs when A/D bits are disabled.
>   */
> -#define EPT_SPTE_HOST_WRITABLE		BIT_ULL(57)
> -#define EPT_SPTE_MMU_WRITABLE		BIT_ULL(58)
> +#define EPT_SPTE_HOST_WRITABLE		BIT_ULL(53)
> +#define EPT_SPTE_MMU_WRITABLE		BIT_ULL(55)

It's a bit dangerous to put HOST_WRITABLE bit between the R-X bits, but we
don't keep the W bit of the to-be-tracked SPTE and we are going to do a
simple shift to preserve the R, X and XU bits anyway, so should be fine.

Acked-by: Kai Huang <kai.huang@intel.com>


  reply	other threads:[~2026-03-25  4:35 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-03-21  0:09 [RFC PATCH 00/22] KVM: combined patchset for MBEC/GMET support Paolo Bonzini
2026-03-21  0:09 ` [PATCH 01/22] KVM: TDX/VMX: rework EPT_VIOLATION_EXEC_FOR_RING3_LIN into PROT_MASK Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-25  4:29   ` Huang, Kai
2026-03-21  0:09 ` [PATCH 02/22] KVM: x86/mmu: remove SPTE_PERM_MASK Paolo Bonzini
2026-03-25  4:29   ` Huang, Kai
2026-03-21  0:09 ` [PATCH 03/22] KVM: x86/mmu: adjust MMIO generation bit allocation and allowed mask Paolo Bonzini
2026-03-24  3:48   ` Huang, Kai
2026-03-24  9:11     ` Paolo Bonzini
2026-03-21  0:09 ` [PATCH 04/22] KVM: x86/mmu: shuffle high bits of SPTEs in preparation for MBEC Paolo Bonzini
2026-03-25  4:35   ` Huang, Kai [this message]
2026-03-21  0:09 ` [PATCH 05/22] KVM: x86/mmu: remove SPTE_EPT_* Paolo Bonzini
2026-03-25  4:36   ` Huang, Kai
2026-03-21  0:09 ` [PATCH 06/22] KVM: x86/mmu: merge make_spte_{non,}executable Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-21  0:09 ` [PATCH 07/22] KVM: x86/mmu: rename and clarify BYTE_MASK Paolo Bonzini
2026-03-21  0:09 ` [PATCH 08/22] KVM: x86/mmu: introduce ACC_READ_MASK Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-23 14:49   ` Jon Kohler
2026-03-21  0:09 ` [PATCH 09/22] KVM: x86/mmu: separate more EPT/non-EPT permission_fault() Paolo Bonzini
2026-03-21  0:09 ` [PATCH 10/22] KVM: x86/mmu: split XS/XU bits for MBEC Paolo Bonzini
2026-03-24 10:45   ` Huang, Kai
2026-03-24 11:24     ` Paolo Bonzini
2026-03-25  4:28       ` Huang, Kai
2026-03-21  0:09 ` [PATCH 11/22] KVM: x86/mmu: move cr4_smep to base role Paolo Bonzini
2026-03-21  0:09 ` [PATCH 12/22] KVM: VMX: enable use of MBEC Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-21  0:09 ` [PATCH 13/22] KVM: x86/mmu: add support for nested MBEC Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-21  0:09 ` [PATCH 14/22] KVM: nVMX: advertise MBEC to nested guests Paolo Bonzini
2026-03-23 14:49   ` Jon Kohler
2026-03-21  0:09 ` [PATCH 15/22] KVM: nVMX: allow MBEC with EVMCS Paolo Bonzini
2026-03-21  0:09 ` [PATCH 16/22] KVM: x86/tdp_mmu: propagate access mask from kvm_mmu_page to PTE Paolo Bonzini
2026-03-21  0:09 ` [PATCH 17/22] KVM: x86/mmu: introduce cpu_role bit for availability of PFEC.I/D Paolo Bonzini
2026-03-21  0:09 ` [PATCH 18/22] KVM: SVM: add GMET bit definitions Paolo Bonzini
2026-03-21 11:58   ` Borislav Petkov
2026-03-21 13:51     ` Paolo Bonzini
2026-03-21 15:42       ` Borislav Petkov
2026-03-23  7:53         ` Paolo Bonzini
2026-03-23 12:17           ` Borislav Petkov
2026-03-23 12:22             ` Paolo Bonzini
2026-03-23 12:26               ` Borislav Petkov
2026-03-23 12:19           ` Borislav Petkov
2026-03-23 12:26   ` Borislav Petkov
2026-03-21  0:09 ` [PATCH 19/22] KVM: x86/mmu: add support for NPT GMET Paolo Bonzini
2026-03-21  0:09 ` [PATCH 20/22] KVM: SVM: enable GMET and set it in MMU role Paolo Bonzini
2026-03-25  9:25   ` Nikunj A. Dadhania
2026-03-25  9:29     ` Paolo Bonzini
2026-03-25  9:39       ` Nikunj A. Dadhania
2026-03-25 10:08         ` Paolo Bonzini
2026-03-21  0:09 ` [PATCH 21/22] KVM: SVM: work around errata 1218 Paolo Bonzini
2026-03-21  0:09 ` [PATCH 22/22] KVM: nSVM: enable GMET for guests Paolo Bonzini
2026-03-24 19:57   ` Jon Kohler
2026-03-25  5:22     ` Nikunj A. Dadhania
2026-03-25 12:55     ` Paolo Bonzini
2026-03-21 13:54 ` [RFC PATCH 00/22] KVM: combined patchset for MBEC/GMET support Paolo Bonzini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=59cb97dbac0527e0ba8153116af942f972e4aea5.camel@intel.com \
    --to=kai.huang@intel.com \
    --cc=amit.shah@amd.com \
    --cc=jon@nutanix.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=mtosatti@redhat.com \
    --cc=nikunj@amd.com \
    --cc=pbonzini@redhat.com \
    --cc=seanjc@google.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®