Re: [PATCH v6 08/11] x86/tdx: Add APIs to support Dynamic PAMT ops from KVM's fault path
From: "Edgecombe, Rick P" <rick.p.edgecombe@intel.com>
Date: 2026-07-10 01:34:53
Also in:
kvm, linux-coco, lkml
On Thu, 2026-07-09 at 15:17 +0800, Yan Zhao wrote:
On Mon, May 25, 2026 at 07:35:12PM -0700, Rick Edgecombe wrote:quoted
When handling an EPT violation, KVM holds a spinlock while manipulating the EPT. Before entering the spinlock it doesn't know how many EPT page tables will need to be installed or whether a huge page will be used. For this reason it allocates a worst case number of page tables that it might need as part of servicing the EPT violation. Under Dynamic PAMT these pre-allocated pages will potentially need to have Dynamic PAMT backing pages installed for them. KVM already has helpers to manage topping up page caches before taking the MMU lock, but they cannot be passed from KVM to arch/x86 code. The problem of how and when to install the DPAMT backing pages for the pages given to the TDX module during the fault path has had a lot of design attempts. - Extracting KVM's MMU caches requires too much inlined code added to headers. - A few varieties of installing Dynamic PAMT backing when allocating the S-EPT page tables. [0][1]IIUC, [0][1] here refer to design attempts that had various problems, right? However, [1] looks exactly like the one being adopted in v6? Did you paste a wrong link? Should [1] instead be https://lore.kernel.org/kvm/20260129011517.3545883-21-seanjc@google.com (local) or https://lore.kernel.org/kvm/aYYCOiMvWfSJR1AL@google.com (local) ?
Oh yea... I think it should be: Kai's original idea: https://lore.kernel.org/kvm/aXENNKjAKTM9UJNH@google.com/ (local) Sean's fixup of it: https://lore.kernel.org/kvm/20260129011517.3545883-20-seanjc@google.com/ (local) The problem with Sean's: https://lore.kernel.org/kvm/aYW5CbUvZrLogsWF@yzhao56-desk.sh.intel.com/ (local) TBH I'm a little on the fence about how useful the links will be in general. If someone tries to rip it out, it would be good breadcrumbs I guess
quoted
- Using mempool_t to transfer the pages between KVM and arch/x86 doesn't work because it is the component is designed more around maintaining a pool of pages, rather than topping up a continually drained cache. So don't do these as they all had various problems. Instead just create a small simple data structure to use for handing a pre-allocated list of pages between KVM and arch/x86 code. Model this on KVM's existing MMU memory caches. Add a tdx_pamt_cache arg to tdx_pamt_get() so it can draw pages from a cache when needed. Not all DPAMT page installations will happen under spinlock, for example control pages. So have tdx_pamt_get() maintain theNit: In patch 9, S-EPT pages are regarded as control pages as well. So maybe "..., for example some control pages." or
Yea that is better. The patch 9 changes are after this, so it's technically correct, but we can make it clearer: ..., for example TD and vCPU scoped control pages for
"..., for example control pages other than S-EPT pages." ?quoted
existing behavior of allocating from the page allocator when NULL is passed for the struct tdx_pamt_cache arg. This prevents excess allocations for cases where it can be avoided. Export the new helpers for KVM. Assisted-by: GitHub Copilot:claude-opus-4-6 Claude:claude-opus-4-7 Co-developed-by: Sean Christopherson <seanjc@google.com> Signed-off-by: Sean Christopherson <seanjc@google.com> Signed-off-by: Rick Edgecombe <rick.p.edgecombe@intel.com> Link: https://lore.kernel.org/kvm/de05853257e9cc66998101943f78a4b7e6e3d741.camel@intel.com/ (local) [0] Link: https://lore.kernel.org/kvm/aYprxnSHKHUtk7pt@google.com/ (local) [1] --- v6: - Filled out log from Sean's series --- arch/x86/include/asm/tdx.h | 17 ++++++++++ arch/x86/virt/vmx/tdx/tdx.c | 65 +++++++++++++++++++++++++++++++++---- 2 files changed, 76 insertions(+), 6 deletions(-)diff --git a/arch/x86/include/asm/tdx.h b/arch/x86/include/asm/tdx.h index 74e75db5728c7..191da84bbf2a1 100644 --- a/arch/x86/include/asm/tdx.h +++ b/arch/x86/include/asm/tdx.h@@ -155,6 +155,23 @@ static inline bool tdx_supports_dynamic_pamt(const struct tdx_sys_info *sysinfo) return false; /* To be enabled when kernel is ready */ } +/* Simple structure for pre-allocating Dynamic PAMT pages outside of locks. */outside of spinlocks? Pre-allocating Dynamic PAMT pages are still inside mutex, e.g., inside of kvm->slots_lock, vcpu->mutex...
Ok.
quoted
+struct tdx_pamt_cache { + struct list_head page_list; + int cnt; +};The rest LGTM. Reviewed-by: Yan Zhao <redacted>
Thanks!