From: Matthew Wilcox <willy@infradead.org>
To: Paolo Bonzini <pbonzini@redhat.com>
Cc: Yosry Ahmed <yosryahmed@google.com>,
Sean Christopherson <seanjc@google.com>,
linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
michael.roth@amd.com, isaku.yamahata@intel.com,
thomas.lendacky@amd.com
Subject: Re: [PATCH 17/21] filemap: add FGP_CREAT_ONLY
Date: Wed, 28 Feb 2024 19:24:34 +0000 [thread overview]
Message-ID: <Zd-Icopo09aUmOvT@casper.infradead.org> (raw)
In-Reply-To: <CABgObfZ9LFDrtLkMaT5LVwy0Z2QMk6SqJ104+D=w7o9i0gEu+g@mail.gmail.com>
On Wed, Feb 28, 2024 at 02:28:45PM +0100, Paolo Bonzini wrote:
> Since you're here: KVM would like to add a ioctl to encrypt and
> install a page into guest_memfd, in preparation for launching an
> encrypted guest. For this API we want to rule out the possibility of
> overwriting a page that is already in the guest_memfd's filemap,
> therefore this API would pass FGP_CREAT_ONLY|FGP_CREAT
> into__filemap_get_folio. Do you think this is bogus...
Would it work to start out by either asserting the memfd is empty of
pages, or by evicting any existing pages? Both those seem nicer than
starting, realising you've got some unencrypted memory and aborting.
> > This looks bogus to me, and if it's not bogus, it's incomplete.
>
> ... or if not, what incompleteness can you spot?
The part where we race another caller passing FGP_CREAT_ONLY and one gets
an EEXIST back from filemap_add_folio(). Maybe that's not something
that can happen in your use case, but it's at least semantics that
need documenting.
next prev parent reply other threads:[~2024-02-28 19:24 UTC|newest]
Thread overview: 76+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-02-27 23:20 [PATCH 00/21] TDX/SNP part 1 of n, for 6.9 Paolo Bonzini
2024-02-27 23:20 ` [PATCH 01/21] KVM: x86: Split core of hypercall emulation to helper function Paolo Bonzini
2024-02-28 2:09 ` Xiaoyao Li
2024-03-05 6:24 ` Binbin Wu
2024-02-27 23:20 ` [PATCH 02/21] KVM: Allow page-sized MMU caches to be initialized with custom 64-bit values Paolo Bonzini
2024-02-29 13:46 ` Xiaoyao Li
2024-03-05 6:55 ` Binbin Wu
2024-03-26 15:56 ` Binbin Wu
2024-05-13 20:38 ` Isaku Yamahata
2024-05-13 20:51 ` Isaku Yamahata
2024-05-13 20:56 ` Sean Christopherson
2024-02-27 23:20 ` [PATCH 03/21] KVM: x86/mmu: Replace hardcoded value 0 for the initial value for SPTE Paolo Bonzini
2024-02-29 13:50 ` Xiaoyao Li
2024-03-05 7:09 ` Binbin Wu
2024-02-27 23:20 ` [PATCH 04/21] KVM: x86/mmu: Allow non-zero value for non-present SPTE and removed SPTE Paolo Bonzini
2024-02-29 7:00 ` Xu Yilun
2024-02-29 13:55 ` Xiaoyao Li
2024-03-11 23:26 ` Huang, Kai
2024-02-27 23:20 ` [PATCH 05/21] KVM: x86/mmu: Add Suppress VE bit to EPT shadow_mmio_mask/shadow_present_mask Paolo Bonzini
2024-03-01 7:26 ` Xiaoyao Li
2024-03-05 13:17 ` Binbin Wu
2024-02-27 23:20 ` [PATCH 06/21] KVM: x86/mmu: Track shadow MMIO value on a per-VM basis Paolo Bonzini
2024-03-01 7:44 ` Xiaoyao Li
2024-03-05 8:35 ` Binbin Wu
2024-03-12 1:21 ` Huang, Kai
2024-02-27 23:20 ` [PATCH 07/21] KVM: VMX: Introduce test mode related to EPT violation VE Paolo Bonzini
2024-02-28 1:56 ` Sean Christopherson
2024-03-12 1:35 ` Huang, Kai
2024-03-12 16:54 ` Sean Christopherson
2024-03-12 21:03 ` Huang, Kai
2024-02-27 23:20 ` [PATCH 08/21] KVM: VMX: Move out vmx_x86_ops to 'main.c' to dispatch VMX and TDX Paolo Bonzini
2024-02-27 23:20 ` [PATCH 09/21] KVM: VMX: Modify NMI and INTR handlers to take intr_info as function argument Paolo Bonzini
2024-03-04 8:09 ` Xiaoyao Li
2024-03-05 13:42 ` Binbin Wu
2024-03-12 1:43 ` Huang, Kai
2024-02-27 23:20 ` [PATCH 10/21] KVM: SEV: Use a VMSA physical address variable for populating VMCB Paolo Bonzini
2024-02-28 2:00 ` Sean Christopherson
2024-02-28 17:32 ` Paolo Bonzini
2024-02-29 16:02 ` Sean Christopherson
2024-02-27 23:20 ` [PATCH 11/21] KVM: x86/tdp_mmu: Init role member of struct kvm_mmu_page at allocation Paolo Bonzini
2024-03-03 4:47 ` Xu Yilun
2024-03-25 23:32 ` Edgecombe, Rick P
2024-02-27 23:20 ` [PATCH 12/21] KVM: x86/tdp_mmu: Sprinkle __must_check Paolo Bonzini
2024-03-04 8:29 ` Xiaoyao Li
2024-02-27 23:20 ` [PATCH 13/21] KVM: x86/mmu: Pass around full 64-bit error code for KVM page faults Paolo Bonzini
2024-03-04 8:56 ` Xiaoyao Li
2024-03-04 15:39 ` Sean Christopherson
2024-04-05 17:57 ` Paolo Bonzini
2024-02-27 23:20 ` [PATCH 14/21] KVM: x86/mmu: pass error code back to MMU when async pf is ready Paolo Bonzini
2024-02-28 2:03 ` Sean Christopherson
2024-02-28 13:13 ` Paolo Bonzini
2024-02-27 23:20 ` [PATCH 15/21] KVM: x86/mmu: Use PFERR_GUEST_ENC_MASK to indicate fault is private Paolo Bonzini
2024-02-27 23:20 ` [PATCH 16/21] KVM: guest_memfd: pass error up from filemap_grab_folio Paolo Bonzini
2024-03-03 14:41 ` Xu Yilun
2024-02-27 23:20 ` [PATCH 17/21] filemap: add FGP_CREAT_ONLY Paolo Bonzini
2024-02-28 2:14 ` Sean Christopherson
2024-02-28 2:17 ` Yosry Ahmed
2024-02-28 13:15 ` Matthew Wilcox
2024-02-28 13:28 ` Paolo Bonzini
2024-02-28 19:24 ` Matthew Wilcox [this message]
2024-02-28 20:17 ` Paolo Bonzini
2024-03-04 2:55 ` Xu Yilun
2024-02-27 23:20 ` [PATCH 18/21] KVM: x86: Add gmem hook for initializing memory Paolo Bonzini
2024-02-28 20:29 ` Isaku Yamahata
2024-02-27 23:20 ` [PATCH 19/21] KVM: guest_memfd: add API to undo kvm_gmem_get_uninit_pfn Paolo Bonzini
2024-03-04 4:44 ` Xu Yilun
2024-02-27 23:20 ` [PATCH 20/21] KVM: x86: Add gmem hook for invalidating memory Paolo Bonzini
2024-02-27 23:21 ` [PATCH 21/21] KVM: x86: Add gmem hook for determining max NPT mapping level Paolo Bonzini
2024-03-12 0:39 ` Binbin Wu
2024-03-12 0:48 ` Binbin Wu
2024-02-28 1:24 ` [PATCH 00/21] TDX/SNP part 1 of n, for 6.9 Sean Christopherson
2024-02-28 13:29 ` Paolo Bonzini
2024-02-28 16:39 ` Sean Christopherson
2024-02-28 17:20 ` Paolo Bonzini
2024-02-28 18:04 ` Sean Christopherson
2024-02-28 2:11 ` Sean Christopherson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=Zd-Icopo09aUmOvT@casper.infradead.org \
--to=willy@infradead.org \
--cc=isaku.yamahata@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=michael.roth@amd.com \
--cc=pbonzini@redhat.com \
--cc=seanjc@google.com \
--cc=thomas.lendacky@amd.com \
--cc=yosryahmed@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome