From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B155D3EC2E6 for ; Tue, 2 Jun 2026 14:31:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780410705; cv=none; b=jjJ5ES+PMjHubuhrjeS1xTVCHIiZZ0DklQrEC6HjkuApV6nhJMDJP2F8rIlcAnkr8T2sB/nW5PwERr223/wkV9lrcflUvVdg/WkCCU/d3VVwkeH4i7qf+VnRmLEtxQ6/UydWCQskXEo7Q/snGi0GVzE3Hl2cv5gAtV7fKozx1JM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780410705; c=relaxed/simple; bh=TFypjZfLo9DnzPpOKLzpfkjiZrHA9SKY8YB0TyK9fXk=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=D9Jm64kWH2fZRUM/BmloXn1udOLJ6f1PRVesyYDsPhzkMOc48fAkyd8Ltb+4g+1mSq5L8PCHioAIUHqY2WAgHiay+dDouMfhGQo0YJiyA8iMoThpP6gWuGZn/gfZfgen1KGUyvC4C467fcVMfOYFZsGZU81pdrtjExn3qw92JWo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=DR/lVqiO; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=Rzki6W5k; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="DR/lVqiO"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="Rzki6W5k" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1780410703; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fjMoXrkd1B8wpID54sGKDOMLgz88p/WNA39to9hP/mM=; b=DR/lVqiONZXJVXViVbKqDq22V73YRrUlnbUIR23NcBVllO8WWLe8WKENqO7U5N33wrg9vs Q6QMzG6N6Sq2ImJamC0xF2Z/rLIyuYPaQZqimqXXHnTV4A52LXs6aMb5xQ/1t6TeQxItCr bLH1kr2t8XPU1AdtXMrBOZBuTrBEryY= Received: from mail-yw1-f199.google.com (mail-yw1-f199.google.com [209.85.128.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-414-hbfXBHeoPBqPw0n0UZALcw-1; Tue, 02 Jun 2026 10:31:40 -0400 X-MC-Unique: hbfXBHeoPBqPw0n0UZALcw-1 X-Mimecast-MFC-AGG-ID: hbfXBHeoPBqPw0n0UZALcw_1780410700 Received: by mail-yw1-f199.google.com with SMTP id 00721157ae682-7e11b8111a3so50970507b3.2 for ; Tue, 02 Jun 2026 07:31:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1780410700; x=1781015500; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:from:to:cc:subject :date:message-id:reply-to; bh=fjMoXrkd1B8wpID54sGKDOMLgz88p/WNA39to9hP/mM=; b=Rzki6W5kBxC/gt6zp9W0dbI5RKhKkjnrCZXDbQ/tvQkdCUwRIjQVslqa2dY4WEh6Ne /BHrT099y5TimQ/xlx8tx8oqhFRmtM94oJYzF//+qFGw1Wlo5e0y4jP9refRTvItUBiM pEBRmiKosLjr48kzVYFuew+lNZM+hhsVR67FgCv4oDh5A//2zaqFPv3vjAyFu8HZ3wuT uNGtt87P/YVAGosAbGKo2wlYIXKj/XDTrmUfI4jw1lnJqgVY/pZ1rwekzabZNxuw6pXh oW7tn7/1rVt53b5HHLI8ru2Xnhw8aYBbuFd3uiu3C6GKU4OPF7z0i4xQyMselYAy3K0e HtZQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780410700; x=1781015500; h=mime-version:user-agent:content-transfer-encoding:references :in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=fjMoXrkd1B8wpID54sGKDOMLgz88p/WNA39to9hP/mM=; b=i2saYwZ4FBEE/G7YIvDWG36xekKhz+PVUHrIuCBtdRxd3HAfE15HCzFh7rzfXDH40U wlPfnO8K3wso1T/7tFTHdzIN96Femk5QhBrWzNt0xn6hYU38iD4sIudw/fNl+eZc7ETM VUP0HkBUbAjzseZF7xJfXNHEb/CJG2o5TE7I0yAGD9nsog1mKxi5xY15Jv/5fLPu358b 2Pe0NnO38A9twQBlqI/kRgibF2WovH8553LvLKdWPvO/IxBArkYbu5eoanO7wJVFY1Qh /efCjnxiGriAq1imBnqwcKzuGHDmMxYaMCqvPToZAui31HGK1PlE/XjseqxeTtBuInPd zVSw== X-Forwarded-Encrypted: i=1; AFNElJ8GgP0/5Gd/P/OT72KNwnaEmKqVAK3pWlxXEm/7RFWa+Gy6SsqIW1hUeesWnHWM/GDGKtrronrydQm6VvU=@vger.kernel.org X-Gm-Message-State: AOJu0YxfI7NNayetNyHoZcEEIO++3c7xrYWlL4QrfhIVBuv2+LQyReXh VZbySQHcJvcHFdWupKapLeZg4OYjq22t4QZ3wmd925jQ6vOvFdyBAR/CUT2q/in2mPqgD1kDozm Z1ANPjQy6Q8eCw6iguSVmPHL465wzjD/dxAFBu2/9xmSIbunJGHtTg3NXrv+ZHaTVJA== X-Gm-Gg: Acq92OEiFtsROUL7DvNK8jMsmbUQl0VOcfewoFzGsIL+DEtB5nZ/yk6fbKBjVAwefYe 3SMXGi6SRIwldlo9QSqVGPNpJ2KV6/06O7a/073aabhZLDsVasTbQITlgp0F1H4sMKMHbPW01Nv vj6Op5eWevPso5a/8bYgqVASxNGG4Ei04KLSL0O5jNwAvaiTXBvHocgHdpe3t5yIbx7cTs+U96e 9oCbbrEI54ui4Pur5D/Z1vE+0l3SDhIMpNQTdms9Tj1jlfdncrZflOp/zFMiBvChJKQdPfRbkrW leNJEYrCE70sZS37SFJ64fAzqey5rjjevzS5L7JGKWksCrqf/8Ns5+KuFIczN6LkRWfHbv8hT7d vTmXRFCqYV9XG3cPJpDUq+WQbbILHpegVN0BuOp0= X-Received: by 2002:a05:690e:1402:b0:660:7b4d:1ac9 with SMTP id 956f58d0204a3-6607b4d2483mr8879382d50.38.1780410700085; Tue, 02 Jun 2026 07:31:40 -0700 (PDT) X-Received: by 2002:a05:690e:1402:b0:660:7b4d:1ac9 with SMTP id 956f58d0204a3-6607b4d2483mr8879325d50.38.1780410699493; Tue, 02 Jun 2026 07:31:39 -0700 (PDT) Received: from intellaptop.lan ([2607:fea8:fc01:88aa:f1de:f35:7935:804f]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51758107935sm44332221cf.31.2026.06.02.07.31.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 02 Jun 2026 07:31:38 -0700 (PDT) Message-ID: Subject: Re: [PATCH 26/28] KVM: SVM: enable GMET and set it in MMU role From: mlevitsk@redhat.com To: Paolo Bonzini , linux-kernel@vger.kernel.org, kvm@vger.kernel.org Cc: d.riley@proxmox.com, jon@nutanix.com Date: Tue, 02 Jun 2026 10:31:37 -0400 In-Reply-To: <20260505195226.563317-27-pbonzini@redhat.com> References: <20260505195226.563317-1-pbonzini@redhat.com> <20260505195226.563317-27-pbonzini@redhat.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.52.4 (3.52.4-2.fc40) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 On Tue, 2026-05-05 at 21:52 +0200, Paolo Bonzini wrote: > Set the GMET bit in the nested control field.=C2=A0 This has effectively > no impact as long as NPT page tables are changed to have U=3D0. >=20 > Tested-by: David Riley > Signed-off-by: Paolo Bonzini > --- > =C2=A0arch/x86/kvm/mmu/mmu.c=C2=A0=C2=A0=C2=A0 |=C2=A0 6 +++++- > =C2=A0arch/x86/kvm/svm/nested.c |=C2=A0 9 ++++++--- > =C2=A0arch/x86/kvm/svm/svm.c=C2=A0=C2=A0=C2=A0 | 16 ++++++++++++++++ > =C2=A0arch/x86/kvm/svm/svm.h=C2=A0=C2=A0=C2=A0 |=C2=A0 1 + > =C2=A04 files changed, 28 insertions(+), 4 deletions(-) >=20 > diff --git a/arch/x86/kvm/mmu/mmu.c b/arch/x86/kvm/mmu/mmu.c > index a283b5078c61..8b6122b66f06 100644 > --- a/arch/x86/kvm/mmu/mmu.c > +++ b/arch/x86/kvm/mmu/mmu.c > @@ -5855,7 +5855,6 @@ kvm_calc_tdp_mmu_root_page_role(struct kvm_vcpu *vc= pu, > =C2=A0{ > =C2=A0 union kvm_mmu_page_role role =3D {0}; > =C2=A0 > - role.access =3D ACC_ALL; > =C2=A0 role.cr0_wp =3D true; > =C2=A0 role.cr4_smep =3D kvm_x86_call(tdp_has_smep)(vcpu->kvm); > =C2=A0 role.efer_nx =3D true; > @@ -5866,6 +5865,11 @@ kvm_calc_tdp_mmu_root_page_role(struct kvm_vcpu *v= cpu, > =C2=A0 role.direct =3D true; > =C2=A0 role.has_4_byte_gpte =3D false; > =C2=A0 > + /* All TDP pages are supervisor-executable */ > + role.access =3D ACC_ALL; > + if (role.cr4_smep && shadow_user_mask) > + role.access &=3D ~ACC_USER_MASK; > + > =C2=A0 return role; > =C2=A0} > =C2=A0 > diff --git a/arch/x86/kvm/svm/nested.c b/arch/x86/kvm/svm/nested.c > index 7adfa7da210d..74a1df1cb84f 100644 > --- a/arch/x86/kvm/svm/nested.c > +++ b/arch/x86/kvm/svm/nested.c > @@ -858,7 +858,7 @@ static void nested_vmcb02_prepare_control(struct vcpu= _svm *svm) > =C2=A0 * the latter, L1 runs L2 with shadow page tables that translate L2= GVAs > =C2=A0 * to L1 GPAs, so the same NPTs can be used for L1 and L2. > =C2=A0 */ > - vmcb02->control.misc_ctl =3D vmcb01->control.misc_ctl & SVM_MISC_ENABLE= _NP; > + vmcb02->control.misc_ctl =3D vmcb01->control.misc_ctl & (SVM_MISC_ENABL= E_NP | SVM_MISC_ENABLE_GMET); > =C2=A0 vmcb02->control.iopm_base_pa =3D vmcb01->control.iopm_base_pa; > =C2=A0 vmcb02->control.msrpm_base_pa =3D vmcb01->control.msrpm_base_pa; > =C2=A0 vmcb_mark_dirty(vmcb02, VMCB_PERM_MAP); > @@ -895,9 +895,12 @@ static void nested_vmcb02_prepare_control(struct vcp= u_svm *svm) > =C2=A0 /* Also overwritten later if necessary.=C2=A0 */ > =C2=A0 vmcb02->control.tlb_ctl =3D TLB_CONTROL_DO_NOTHING; > =C2=A0 > - /* nested_cr3.=C2=A0 */ > - if (nested_npt_enabled(svm)) > + /* Use vmcb01 MMU and format if guest does not use nNPT */ > + if (nested_npt_enabled(svm)) { > + vmcb02->control.misc_ctl &=3D ~SVM_MISC_ENABLE_GMET; Hi! Since this touches nesting without actually doing anything yet, do you think it makes sense to move these two hunks to the last patch? > + > =C2=A0 nested_svm_init_mmu_context(vcpu); > + } > =C2=A0 > =C2=A0 vcpu->arch.tsc_offset =3D kvm_calc_nested_tsc_offset(vcpu->arch.l1= _tsc_offset, > =C2=A0 =C2=A0=C2=A0 vmcb12_ctrl->tsc_offset, > diff --git a/arch/x86/kvm/svm/svm.c b/arch/x86/kvm/svm/svm.c > index e7fdd7a9c280..3895d8794366 100644 > --- a/arch/x86/kvm/svm/svm.c > +++ b/arch/x86/kvm/svm/svm.c > @@ -138,6 +138,9 @@ module_param(pause_filter_count_max, ushort, 0444); > =C2=A0bool __ro_after_init npt_enabled =3D true; > =C2=A0module_param_named(npt, npt_enabled, bool, 0444); > =C2=A0 > +bool gmet_enabled =3D true; > +module_param_named(gmet, gmet_enabled, bool, 0444); > + > =C2=A0/* allow nested virtualization in KVM/SVM */ > =C2=A0static int __ro_after_init nested =3D true; > =C2=A0module_param(nested, int, 0444); > @@ -1209,6 +1212,10 @@ static void init_vmcb(struct kvm_vcpu *vcpu, bool = init_event) > =C2=A0 save->g_pat =3D vcpu->arch.pat; > =C2=A0 save->cr3 =3D 0; > =C2=A0 } > + > + if (gmet_enabled) > + control->misc_ctl |=3D SVM_MISC_ENABLE_GMET; > + > =C2=A0 svm->current_vmcb->asid_generation =3D 0; > =C2=A0 svm->asid =3D 0; > =C2=A0 > @@ -4612,6 +4619,11 @@ svm_patch_hypercall(struct kvm_vcpu *vcpu, unsigne= d char *hypercall) > =C2=A0 hypercall[2] =3D 0xd9; > =C2=A0} > =C2=A0 > +static bool svm_tdp_has_smep(struct kvm *kvm) > +{ > + return gmet_enabled; > +} > + > =C2=A0/* > =C2=A0 * The kvm parameter can be NULL (module initialization, or invocat= ion before > =C2=A0 * VM creation). Be sure to check the kvm parameter before using it= . > @@ -5355,6 +5367,7 @@ struct kvm_x86_ops svm_x86_ops __initdata =3D { > =C2=A0 .write_tsc_multiplier =3D svm_write_tsc_multiplier, > =C2=A0 > =C2=A0 .load_mmu_pgd =3D svm_load_mmu_pgd, > + .tdp_has_smep =3D svm_tdp_has_smep, > =C2=A0 > =C2=A0 .check_intercept =3D svm_check_intercept, > =C2=A0 .handle_exit_irqoff =3D svm_handle_exit_irqoff, > @@ -5588,6 +5601,9 @@ static __init int svm_hardware_setup(void) > =C2=A0 if (!boot_cpu_has(X86_FEATURE_NPT)) > =C2=A0 npt_enabled =3D false; > =C2=A0 > + if (!npt_enabled || !boot_cpu_has(X86_FEATURE_GMET)) > + gmet_enabled =3D false; > + > =C2=A0 /* Force VM NPT level equal to the host's paging level */ > =C2=A0 kvm_configure_mmu(npt_enabled, get_npt_level(), > =C2=A0 =C2=A0 get_npt_level(), PG_LEVEL_1G); > diff --git a/arch/x86/kvm/svm/svm.h b/arch/x86/kvm/svm/svm.h > index a10668d17a16..dd93b3daefa9 100644 > --- a/arch/x86/kvm/svm/svm.h > +++ b/arch/x86/kvm/svm/svm.h > @@ -44,6 +44,7 @@ static inline struct page *__sme_pa_to_page(unsigned lo= ng pa) > =C2=A0#define IOPM_SIZE PAGE_SIZE * 3 > =C2=A0#define MSRPM_SIZE PAGE_SIZE * 2 > =C2=A0 > +extern bool gmet_enabled; > =C2=A0extern bool npt_enabled; > =C2=A0extern int nrips; > =C2=A0extern int vgif; Reviewed-by: Maxim Levitsky Best regards, Maxim Levitsky