From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:38:00
Hello,
On the POWER9 processor, the XIVE interrupt controller can control
interrupt sources using MMIOs to trigger events, to EOI or to turn off
the sources. Priority management and interrupt acknowledgment is also
controlled by MMIO in the CPU presenter subengine.
PowerNV/baremetal Linux runs natively under XIVE but sPAPR guests need
special support from the hypervisor to do the same. This is called the
XIVE native exploitation mode and today, it can be activated under the
PowerPC Hypervisor, pHyp. However, Linux/KVM lacks XIVE native support
and still offers the old interrupt mode interface using a KVM device
implementing the XICS hcalls over XIVE.
The following series is proposal to add the same support under KVM.
A new KVM device is introduced for the XIVE native exploitation
mode. It reuses most of the XICS-over-XIVE glue implementation
structures which are internal to KVM but has a completely different
interface. A set of KVM device ioctls provide support for the
hypervisor calls, all handled in QEMU, to configure the sources and
the event queues. From there, all interrupt control is transferred to
the guest which can use MMIOs.
These MMIO regions (ESB and TIMA) are exposed to guests in QEMU,
similarly to VFIO, and the associated VMAs are populated dynamically
with the appropriate pages using a fault handler. These are now
implemented using mmap()s of the KVM device fd.
Migration has its own specific needs regarding memory. The patchset
provides a specific control to quiesce XIVE before capturing the
memory. The save and restore of the internal state is based on the
same ioctls used for the hcalls.
On a POWER9 sPAPR machine, the Client Architecture Support (CAS)
negotiation process determines whether the guest operates with a
interrupt controller using the XICS legacy model, as found on POWER8,
or in XIVE exploitation mode. Which means that the KVM interrupt
device should be created at runtime, after the machine has started.
This requires extra support from KVM to destroy KVM devices. It is
introduced at the end of the patcshet as it still requires some
attention and a XIVE-only VM would not need.
This is 5.2 material. I expect a couple of respin for fixes, and the
OPAL patches have not yet been merged.
GitHub trees available here :
QEMU sPAPR:
https://github.com/legoater/qemu/commits/xive-next
Linux/KVM:
https://github.com/legoater/linux/commits/xive-5.0
OPAL:
https://github.com/legoater/skiboot/commits/xive
Thanks,
C.
Changes since v1:
- Better documentation (was missing)
- Nested support. XIVE not advertised on non PowerNV platforms. This
is a good way to test the fallback on QEMU emulated devices.
- ESB and TIMA special mapping done using the KVM device fd
- All hcalls moved to QEMU. Dropped the patch moving the hcall flags.
- Reworked of the KVM device ioctl controls to support hcalls and
migration needs to capture/save states
- Merged the control syncing XIVE and marking the EQ page dirty
- Fixed passthrough support using the KVM device file address_space
to clear the ESB pages from the mapping
- Misc enhancements and fixes
Cédric Le Goater (16):
powerpc/xive: add OPAL extensions for the XIVE native exploitation
support
KVM: PPC: Book3S HV: add a new KVM device for the XIVE native
exploitation mode
KVM: PPC: Book3S HV: XIVE: introduce a new capability
KVM_CAP_PPC_IRQ_XIVE
KVM: PPC: Book3S HV: XIVE: add a control to initialize a source
KVM: PPC: Book3S HV: XIVE: add a control to configure a source
KVM: PPC: Book3S HV: XIVE: add controls for the EQ configuration
KVM: PPC: Book3S HV: XIVE: add a global reset control
KVM: PPC: Book3S HV: XIVE: add a control to sync the sources
KVM: PPC: Book3S HV: XIVE: add a control to dirty the XIVE EQ pages
KVM: PPC: Book3S HV: XIVE: add get/set accessors for the VP XIVE state
KVM: introduce a 'mmap' method for KVM devices
KVM: PPC: Book3S HV: XIVE: add a TIMA mapping
KVM: PPC: Book3S HV: XIVE: add a mapping for the source ESB pages
KVM: PPC: Book3S HV: XIVE: add passthrough support
KVM: introduce a KVM_DESTROY_DEVICE ioctl
KVM: PPC: Book3S HV: XIVE: clear the vCPU interrupt presenters
arch/powerpc/include/asm/kvm_host.h | 2 +
arch/powerpc/include/asm/kvm_ppc.h | 32 +
arch/powerpc/include/asm/opal-api.h | 11 +-
arch/powerpc/include/asm/opal.h | 7 +
arch/powerpc/include/asm/xive.h | 17 +
arch/powerpc/include/uapi/asm/kvm.h | 48 +
arch/powerpc/kvm/book3s_xive.h | 31 +
include/linux/kvm_host.h | 1 +
include/uapi/linux/kvm.h | 10 +
arch/powerpc/kvm/book3s.c | 31 +-
arch/powerpc/kvm/book3s_xics.c | 19 +
arch/powerpc/kvm/book3s_xive.c | 149 ++-
arch/powerpc/kvm/book3s_xive_native.c | 1171 +++++++++++++++++
arch/powerpc/kvm/powerpc.c | 33 +
arch/powerpc/sysdev/xive/native.c | 110 ++
virt/kvm/kvm_main.c | 49 +
Documentation/virtual/kvm/api.txt | 28 +
Documentation/virtual/kvm/devices/xive.txt | 190 +++
arch/powerpc/kvm/Makefile | 2 +-
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
20 files changed, 1896 insertions(+), 48 deletions(-)
create mode 100644 arch/powerpc/kvm/book3s_xive_native.c
create mode 100644 Documentation/virtual/kvm/devices/xive.txt
--
2.20.1
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:32:59
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/opal-api.h | 11 ++-
arch/powerpc/include/asm/opal.h | 7 ++
arch/powerpc/include/asm/xive.h | 14 +++
arch/powerpc/sysdev/xive/native.c | 99 +++++++++++++++++++
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
5 files changed, 130 insertions(+), 4 deletions(-)
@@ -711,3 +717,96 @@ bool xive_native_has_single_escalation(void)returnxive_has_single_esc;}EXPORT_SYMBOL_GPL(xive_native_has_single_escalation);++intxive_native_get_queue_info(u32vp_id,u32prio,+u64*out_qpage,+u64*out_qsize,+u64*out_qeoi_page,+u32*out_escalate_irq,+u64*out_qflags)+{+__be64qpage;+__be64qsize;+__be64qeoi_page;+__be32escalate_irq;+__be64qflags;+s64rc;++rc=opal_xive_get_queue_info(vp_id,prio,&qpage,&qsize,+&qeoi_page,&escalate_irq,&qflags);+if(rc){+pr_err("OPAL failed to get queue info for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++if(out_qpage)+*out_qpage=be64_to_cpu(qpage);+if(out_qsize)+*out_qsize=be32_to_cpu(qsize);+if(out_qeoi_page)+*out_qeoi_page=be64_to_cpu(qeoi_page);+if(out_escalate_irq)+*out_escalate_irq=be32_to_cpu(escalate_irq);+if(out_qflags)+*out_qflags=be64_to_cpu(qflags);++return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_queue_info);++intxive_native_get_queue_state(u32vp_id,u32prio,u32*qtoggle,u32*qindex)+{+__be32opal_qtoggle;+__be32opal_qindex;+s64rc;++rc=opal_xive_get_queue_state(vp_id,prio,&opal_qtoggle,+&opal_qindex);+if(rc){+pr_err("OPAL failed to get queue state for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++if(qtoggle)+*qtoggle=be32_to_cpu(opal_qtoggle);+if(qindex)+*qindex=be32_to_cpu(opal_qindex);++return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_queue_state);++intxive_native_set_queue_state(u32vp_id,u32prio,u32qtoggle,u32qindex)+{+s64rc;++rc=opal_xive_set_queue_state(vp_id,prio,qtoggle,qindex);+if(rc){+pr_err("OPAL failed to set queue state for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++return0;+}+EXPORT_SYMBOL_GPL(xive_native_set_queue_state);++intxive_native_get_vp_state(u32vp_id,u64*out_state)+{+__be64state;+s64rc;++rc=opal_xive_get_vp_state(vp_id,&state);+if(rc){+pr_err("OPAL failed to get vp state for VCPU %d : %lld\n",+vp_id,rc);+return-EIO;+}++if(out_state)+*out_state=be64_to_cpu(state);+return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_vp_state);
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:34:30
This is the basic framework for the new KVM device supporting the XIVE
native exploitation mode. The user interface exposes a new KVM device
to be created by QEMU when running on a L0 hypervisor only. Support
for nested guests is not available yet.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 8 +
arch/powerpc/include/uapi/asm/kvm.h | 3 +
include/uapi/linux/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 7 +-
arch/powerpc/kvm/book3s_xive_native.c | 191 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 ++
arch/powerpc/kvm/Makefile | 2 +-
8 files changed, 231 insertions(+), 2 deletions(-)
create mode 100644 arch/powerpc/kvm/book3s_xive_native.c
create mode 100644 Documentation/virtual/kvm/devices/xive.txt
@@ -0,0 +1,191 @@+// SPDX-License-Identifier: GPL-2.0+/*+*Copyright(c)2017-2019,IBMCorporation.+*/++#define pr_fmt(fmt) "xive-kvm: " fmt++#include<linux/anon_inodes.h>+#include<linux/kernel.h>+#include<linux/kvm_host.h>+#include<linux/err.h>+#include<linux/gfp.h>+#include<linux/spinlock.h>+#include<linux/delay.h>+#include<linux/percpu.h>+#include<linux/cpumask.h>+#include<asm/uaccess.h>+#include<asm/kvm_book3s.h>+#include<asm/kvm_ppc.h>+#include<asm/hvcall.h>+#include<asm/xics.h>+#include<asm/xive.h>+#include<asm/xive-regs.h>+#include<asm/debug.h>+#include<asm/debugfs.h>+#include<asm/time.h>+#include<asm/opal.h>++#include<linux/debugfs.h>+#include<linux/seq_file.h>++#include"book3s_xive.h"++staticintkvmppc_xive_native_set_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticintkvmppc_xive_native_get_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+return-ENXIO;+}++staticintkvmppc_xive_native_has_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticvoidkvmppc_xive_native_free(structkvm_device*dev)+{+structkvmppc_xive*xive=dev->private;+structkvm*kvm=xive->kvm;++debugfs_remove(xive->dentry);++pr_devel("Destroying xive native device\n");++if(kvm)+kvm->arch.xive=NULL;++if(xive->vp_base!=XIVE_INVALID_VP)+xive_native_free_vp_block(xive->vp_base);++kfree(xive);+kfree(dev);+}++staticintkvmppc_xive_native_create(structkvm_device*dev,u32type)+{+structkvmppc_xive*xive;+structkvm*kvm=dev->kvm;+intret=0;++pr_devel("Creating xive native device\n");++if(kvm->arch.xive)+return-EEXIST;++xive=kzalloc(sizeof(*xive),GFP_KERNEL);+if(!xive)+return-ENOMEM;++dev->private=xive;+xive->dev=dev;+xive->kvm=kvm;+kvm->arch.xive=xive;++/* We use the default queue size set by the host */+xive->q_order=xive_native_default_eq_shift();+if(xive->q_order<PAGE_SHIFT)+xive->q_page_order=0;+else+xive->q_page_order=xive->q_order-PAGE_SHIFT;++/*+*AllocateabunchofVPs.KVM_MAX_VCPUSisalargevaluefor+*adefault.GettingthemaxnumberofCPUstheVMwas+*configuredwithwouldimproveourusageoftheXIVEVPspace.+*/+xive->vp_base=xive_native_alloc_vp_block(KVM_MAX_VCPUS);+pr_devel("VP_Base=%x\n",xive->vp_base);++if(xive->vp_base==XIVE_INVALID_VP)+ret=-ENOMEM;++xive->single_escalation=xive_native_has_single_escalation();++if(ret)+kfree(xive);++returnret;+}++staticintxive_native_debug_show(structseq_file*m,void*private)+{+structkvmppc_xive*xive=m->private;+structkvm*kvm=xive->kvm;++if(!kvm)+return0;++return0;+}++staticintxive_native_debug_open(structinode*inode,structfile*file)+{+returnsingle_open(file,xive_native_debug_show,inode->i_private);+}++staticconststructfile_operationsxive_native_debug_fops={+.open=xive_native_debug_open,+.read=seq_read,+.llseek=seq_lseek,+.release=single_release,+};++staticvoidxive_native_debugfs_init(structkvmppc_xive*xive)+{+char*name;++name=kasprintf(GFP_KERNEL,"kvm-xive-%p",xive);+if(!name){+pr_err("%s: no memory for name\n",__func__);+return;+}++xive->dentry=debugfs_create_file(name,0444,powerpc_debugfs_root,+xive,&xive_native_debug_fops);++pr_debug("%s: created %s\n",__func__,name);+kfree(name);+}++staticvoidkvmppc_xive_native_init(structkvm_device*dev)+{+structkvmppc_xive*xive=(structkvmppc_xive*)dev->private;++/* Register some debug interfaces */+xive_native_debugfs_init(xive);+}++structkvm_device_opskvm_xive_native_ops={+.name="kvm-xive-native",+.create=kvmppc_xive_native_create,+.init=kvmppc_xive_native_init,+.destroy=kvmppc_xive_native_free,+.set_attr=kvmppc_xive_native_set_attr,+.get_attr=kvmppc_xive_native_get_attr,+.has_attr=kvmppc_xive_native_has_attr,+};++voidkvmppc_xive_native_init_module(void)+{+;+}++voidkvmppc_xive_native_exit_module(void)+{+;+}
@@ -0,0 +1,19 @@+POWER9 eXternal Interrupt Virtualization Engine (XIVE Gen1)+==========================================================++Device types supported:+ KVM_DEV_TYPE_XIVE POWER9 XIVE Interrupt Controller generation 1++This device acts as a VM interrupt controller. It provides the KVM+interface to configure the interrupt sources of a VM in the underlying+POWER9 XIVE interrupt controller.++Only one XIVE instance may be instantiated. A guest XIVE device+requires a POWER9 host and the guest OS should have support for the+XIVE native exploitation interrupt mode. If not, it should run using+the legacy interrupt mode, referred as XICS (POWER7/8).++* Groups:++ 1. KVM_DEV_XIVE_GRP_CTRL+ Provides global controls on the device
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:36:21
This control will be used by the H_INT_SET_SOURCE_CONFIG hcall from
QEMU and also to restore the configuration of the source in the KVM
device.
The XIVE internal IRQ structure is extended with the value of the
Effective Interrupt Source Number. The EISN is the interrupt number
pushed in the event queue that the guest OS will use to dispatch
events internally. Caching the EISN value in KVM ease the test when
checking if a reconfiguration is indeed needed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 11 +++
arch/powerpc/kvm/book3s_xive.h | 4 +
arch/powerpc/kvm/book3s_xive.c | 5 +-
arch/powerpc/kvm/book3s_xive_native.c | 97 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 20 +++++
5 files changed, 135 insertions(+), 2 deletions(-)
@@ -32,3 +32,23 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENOMEM: Could not create a new source block -EFAULT: Invalid user pointer for attr->addr. -ENXIO: Could not allocate underlying HW interrupt++ 3. KVM_DEV_XIVE_GRP_SOURCE_CONFIG (write only)+ Configures source targeting+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 33 | 32 | 31 .. 3 | 2 .. 0+ values: | eisn | mask | server | priority+ - priority: 0-7 interrupt priority level+ - server: CPU number chosen to handle the interrupt+ - mask: mask flag (unused)+ - eisn: Effective Interrupt Source Number+ Errors:+ -ENOENT: Unknown source number+ -EINVAL: Not initialized source number, invalid priority or+ invalid CPU number.+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: CPU event queues not configured or configuration of the+ underlying HW interrupt failed+ -EBUSY: No CPU available to serve interrupt
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:39:33
The associated HW interrupt source is simply allocated at the OPAL/HW
level and then MASKED. KVM only needs to know about its type: LSI or
MSI.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 5 +
arch/powerpc/kvm/book3s_xive.h | 10 ++
arch/powerpc/kvm/book3s_xive.c | 8 +-
arch/powerpc/kvm/book3s_xive_native.c | 114 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 +++
5 files changed, 148 insertions(+), 4 deletions(-)
@@ -153,12 +176,89 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,+u64addr)+{+structkvmppc_xive_src_block*sb;+structkvmppc_xive_irq_state*state;+u64__user*ubufp=(u64__user*)addr;+u64val;+u16idx;++pr_devel("%s irq=0x%lx\n",__func__,irq);++if(irq<KVMPPC_XIVE_FIRST_IRQ||irq>=KVMPPC_XIVE_NR_IRQS)+return-E2BIG;++sb=kvmppc_xive_find_source(xive,irq,&idx);+if(!sb){+pr_debug("No source, creating source block...\n");+sb=kvmppc_xive_create_src_block(xive,irq);+if(!sb){+pr_err("Failed to create block...\n");+return-ENOMEM;+}+}+state=&sb->irq_state[idx];++if(get_user(val,ubufp)){+pr_err("fault getting user info !\n");+return-EFAULT;+}++/*+*Ifthesourcedoesn'talreadyhaveanIPI,allocate+*oneandgetthecorrespondingdata+*/+if(!state->ipi_number){+state->ipi_number=xive_native_alloc_irq();+if(state->ipi_number==0){+pr_err("Failed to allocate IRQ !\n");+return-ENXIO;+}+xive_native_populate_irq_data(state->ipi_number,+&state->ipi_data);+pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n",__func__,+state->ipi_number,irq);+}++arch_spin_lock(&sb->lock);++/* Restore LSI state */+if(val&KVM_XIVE_LEVEL_SENSITIVE){+state->lsi=true;+if(val&KVM_XIVE_LEVEL_ASSERTED)+state->asserted=true;+pr_devel(" LSI ! Asserted=%d\n",state->asserted);+}++/* Mask IRQ to start with */+state->act_server=0;+state->act_priority=MASKED;+xive_vm_esb_load(&state->ipi_data,XIVE_ESB_SET_PQ_01);+xive_native_configure_irq(state->ipi_number,0,MASKED,0);++/* Increment the number of valid sources and mark this one valid */+if(!state->valid)+xive->src_count++;+state->valid=true;++arch_spin_unlock(&sb->lock);++return0;+}+staticintkvmppc_xive_native_set_attr(structkvm_device*dev,structkvm_device_attr*attr){+structkvmppc_xive*xive=dev->private;+switch(attr->group){caseKVM_DEV_XIVE_GRP_CTRL:break;+caseKVM_DEV_XIVE_GRP_SOURCE:+returnkvmppc_xive_native_set_source(xive,attr->attr,+attr->addr);}return-ENXIO;}
@@ -175,6 +275,11 @@ static int kvmppc_xive_native_has_attr(struct kvm_device *dev,switch(attr->group){caseKVM_DEV_XIVE_GRP_CTRL:break;+caseKVM_DEV_XIVE_GRP_SOURCE:+if(attr->attr>=KVMPPC_XIVE_FIRST_IRQ&&+attr->attr<KVMPPC_XIVE_NR_IRQS)+return0;+break;}return-ENXIO;}
@@ -17,3 +17,18 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device++ 2. KVM_DEV_XIVE_GRP_SOURCE (write only)+ Initializes a new source in the XIVE device and mask it.+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 2 | 1 | 0+ values: | unused | level | type+ - type: 0:MSI 1:LSI+ - level: assertion level in case of an LSI.+ Errors:+ -E2BIG: Interrupt source number is out of range+ -ENOMEM: Could not create a new source block+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: Could not allocate underlying HW interrupt
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:41:24
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
Internally, the interface to the new KVM device is protected with a
new interrupt mode: KVMPPC_IRQ_XIVE.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 13 +++
arch/powerpc/kvm/book3s_xive.h | 6 ++
include/uapi/linux/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive.c | 67 +++++++-----
arch/powerpc/kvm/book3s_xive_native.c | 144 ++++++++++++++++++++++++++
arch/powerpc/kvm/powerpc.c | 33 ++++++
Documentation/virtual/kvm/api.txt | 9 ++
8 files changed, 246 insertions(+), 28 deletions(-)
@@ -31,6 +31,128 @@#include"book3s_xive.h"+staticvoidkvmppc_xive_native_cleanup_queue(structkvm_vcpu*vcpu,intprio)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+structxive_q*q=&xc->queues[prio];++xive_native_disable_queue(xc->vp_id,q,prio);+if(q->qpage){+put_page(virt_to_page(q->qpage));+q->qpage=NULL;+}+}++voidkvmppc_xive_native_cleanup_vcpu(structkvm_vcpu*vcpu)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+inti;++if(!kvmppc_xive_enabled(vcpu))+return;++if(!xc)+return;++pr_devel("native_cleanup_vcpu(cpu=%d)\n",xc->server_num);++/* Ensure no interrupt is still routed to that VP */+xc->valid=false;+kvmppc_xive_disable_vcpu_interrupts(vcpu);++/* Disable the VP */+xive_native_disable_vp(xc->vp_id);++/* Free the queues & associated interrupts */+for(i=0;i<KVMPPC_XIVE_Q_COUNT;i++){+/* Free the escalation irq */+if(xc->esc_virq[i]){+free_irq(xc->esc_virq[i],vcpu);+irq_dispose_mapping(xc->esc_virq[i]);+kfree(xc->esc_virq_names[i]);+xc->esc_virq[i]=0;+}++/* Free the queue */+kvmppc_xive_native_cleanup_queue(vcpu,i);+}++/* Free the VP */+kfree(xc);++/* Cleanup the vcpu */+vcpu->arch.irq_type=KVMPPC_IRQ_DEFAULT;+vcpu->arch.xive_vcpu=NULL;+}++intkvmppc_xive_native_connect_vcpu(structkvm_device*dev,+structkvm_vcpu*vcpu,u32cpu)+{+structkvmppc_xive*xive=dev->private;+structkvmppc_xive_vcpu*xc;+intrc;++pr_devel("native_connect_vcpu(cpu=%d)\n",cpu);++if(dev->ops!=&kvm_xive_native_ops){+pr_devel("Wrong ops !\n");+return-EPERM;+}+if(xive->kvm!=vcpu->kvm)+return-EPERM;+if(vcpu->arch.irq_type!=KVMPPC_IRQ_DEFAULT)+return-EBUSY;+if(kvmppc_xive_find_server(vcpu->kvm,cpu)){+pr_devel("Duplicate !\n");+return-EEXIST;+}+if(cpu>=KVM_MAX_VCPUS){+pr_devel("Out of bounds !\n");+return-EINVAL;+}+xc=kzalloc(sizeof(*xc),GFP_KERNEL);+if(!xc)+return-ENOMEM;++mutex_lock(&vcpu->kvm->lock);+vcpu->arch.xive_vcpu=xc;+xc->xive=xive;+xc->vcpu=vcpu;+xc->server_num=cpu;+xc->vp_id=xive->vp_base+cpu;+xc->valid=true;++rc=xive_native_get_vp_info(xc->vp_id,&xc->vp_cam,&xc->vp_chip_id);+if(rc){+pr_err("Failed to get VP info from OPAL: %d\n",rc);+gotobail;+}++/*+*EnabletheVPfirstasthesingleescalationmodewill+*affectescalationinterruptsnumbering+*/+rc=xive_native_enable_vp(xc->vp_id,xive->single_escalation);+if(rc){+pr_err("Failed to enable VP in OPAL: %d\n",rc);+gotobail;+}++/* Configure VCPU fields for use by assembly push/pull */+vcpu->arch.xive_saved_state.w01=cpu_to_be64(0xff000000);+vcpu->arch.xive_cam_word=cpu_to_be32(xc->vp_cam|TM_QW1W2_VO);++/* TODO: initialize queues ? */++bail:+vcpu->arch.irq_type=KVMPPC_IRQ_XIVE;+mutex_unlock(&vcpu->kvm->lock);+if(rc)+kvmppc_xive_native_cleanup_vcpu(vcpu);++returnrc;+}+staticintkvmppc_xive_native_set_attr(structkvm_device*dev,structkvm_device_attr*attr){
@@ -126,10 +248,32 @@ static int xive_native_debug_show(struct seq_file *m, void *private){structkvmppc_xive*xive=m->private;structkvm*kvm=xive->kvm;+structkvm_vcpu*vcpu;+unsignedinti;if(!kvm)return0;+seq_puts(m,"=========\nVCPU state\n=========\n");++kvm_for_each_vcpu(i,vcpu,kvm){+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;++if(!xc)+continue;++seq_printf(m,"cpu server %#x NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x\n",+xc->server_num,+vcpu->arch.xive_saved_state.nsr,+vcpu->arch.xive_saved_state.cppr,+vcpu->arch.xive_saved_state.ipb,+vcpu->arch.xive_saved_state.pipr,+vcpu->arch.xive_saved_state.w01,+(u32)vcpu->arch.xive_cam_word);++kvmppc_xive_debug_show_queues(m,vcpu);+}+return0;}
@@ -570,6 +570,12 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)caseKVM_CAP_PPC_GET_CPU_CHAR:r=1;break;+#ifdef CONFIG_KVM_XIVE+caseKVM_CAP_PPC_IRQ_XIVE:+/* only for PowerNV */+r=!!cpu_has_feature(CPU_FTR_HVMODE);+break;+#endifcaseKVM_CAP_PPC_ALLOC_HTAB:r=hv_enabled;
@@ -4458,6 +4458,15 @@ struct kvm_sync_regs { struct kvm_vcpu_events events; };+6.75 KVM_CAP_PPC_IRQ_XIVE++Architectures: ppc+Target: vcpu+Parameters: args[0] is the XIVE device fd+ args[1] is the XIVE CPU number (server ID) for this vcpu++This capability connects the vcpu to an in-kernel XIVE device.+ 7. Capabilities that can be enabled on VMs ------------------------------------------
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:43:05
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/xive.h | 2 +
arch/powerpc/include/uapi/asm/kvm.h | 21 +++
arch/powerpc/kvm/book3s_xive.h | 2 +
arch/powerpc/kvm/book3s_xive.c | 15 +-
arch/powerpc/kvm/book3s_xive_native.c | 207 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 +++
6 files changed, 270 insertions(+), 6 deletions(-)
@@ -73,6 +73,8 @@ struct xive_q {u32esc_irq;atomic_tcount;atomic_tpending_count;+u64guest_qpage;+u32guest_qsize;};/* Global enable flags for the XIVE support */
@@ -52,3 +52,32 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENXIO: CPU event queues not configured or configuration of the underlying HW interrupt failed -EBUSY: No CPU available to serve interrupt++ 4. KVM_DEV_XIVE_GRP_EQ_CONFIG (read-write)+ Configures an event queue of a CPU+ Attributes:+ EQ descriptor identifier (64-bit)+ The EQ descriptor identifier is a tuple (server, priority) :+ bits: | 63 .... 32 | 31 .. 3 | 2 .. 0+ values: | unused | server | priority+ The kvm_device_attr.addr points to :+ struct kvm_ppc_xive_eq {+ __u32 flags;+ __u32 qsize;+ __u64 qpage;+ __u32 qtoggle;+ __u32 qindex;+ __u8 pad[40];+ };+ - flags: queue flags+ - qsize: queue size (power of 2)+ - qpage: real address of queue+ - qtoggle: current queue toggle bit+ - qindex: current queue index+ - pad: reserved for future use+ Errors:+ -ENOENT: Invalid CPU number+ -EINVAL: Invalid priority or invalid queue size+ -EFAULT: Invalid user pointer for attr->addr.+ -ENOMEM: Invalid queue address+ -EIO: Configuration of the underlying HW failed
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:45:15
At a VCPU level, the state of the thread interrupt management
registers needs to be collected. These registers are cached under the
'xive_saved_state.w01' field of the VCPU when the VPCU context is
pulled from the HW thread. An OPAL call retrieves the backup of the
IPB register in the underlying XIVE NVT structure and merges it in the
KVM state.
The structures of the interface between QEMU and KVM provisions some
extra room (two u64) for further extensions if more state needs to be
transferred back to QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_ppc.h | 11 +++
arch/powerpc/include/uapi/asm/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 24 +++++++
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 +++++
5 files changed, 138 insertions(+)
@@ -845,6 +845,88 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)returnret;}+/*+*InterruptPendingBuffer(IPB)offset+*/+#define TM_IPB_SHIFT 40+#define TM_IPB_MASK (((u64) 0xFF) << TM_IPB_SHIFT)++intkvmppc_xive_native_get_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+u64opal_state;+intrc;++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc)+return-ENOENT;++/* Thread context registers. We only care about IPB and CPPR */+val->xive_timaval[0]=vcpu->arch.xive_saved_state.w01;++/*+*ReturntheOSCAMlinetoprintouttheVPidentifierin+*theQEMUmonitor.Thisisnotrestored.+*/+val->xive_timaval[1]=vcpu->arch.xive_cam_word;++/* Get the VP state from OPAL */+rc=xive_native_get_vp_state(xc->vp_id,&opal_state);+if(rc)+returnrc;++/*+*CapturethebackupofIPBregisterintheNVTstructureand+*mergeitinourKVMVPstate.+*/+val->xive_timaval[0]|=cpu_to_be64(opal_state&TM_IPB_MASK);++pr_devel("%s NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x opal=%016llx\n",+__func__,+vcpu->arch.xive_saved_state.nsr,+vcpu->arch.xive_saved_state.cppr,+vcpu->arch.xive_saved_state.ipb,+vcpu->arch.xive_saved_state.pipr,+vcpu->arch.xive_saved_state.w01,+(u32)vcpu->arch.xive_cam_word,opal_state);++return0;+}++intkvmppc_xive_native_set_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+structkvmppc_xive*xive=vcpu->kvm->arch.xive;++pr_devel("%s w01=%016llx vp=%016llx\n",__func__,+val->xive_timaval[0],val->xive_timaval[1]);++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc||!xive)+return-ENOENT;++/* We can't update the state of a "pushed" VCPU */+if(WARN_ON(vcpu->arch.xive_pushed))+return-EIO;++/*+*Restorethethreadcontextregisters.IPBandCPPRshould+*betheonlyonesthatmatter.+*/+vcpu->arch.xive_saved_state.w01=val->xive_timaval[0];++/*+*ThereisnoneedtorestoretheXIVEinternalstate(IPB+*storedintheNVT)astheIPBregisterwasmergedinKVMVP+*statewhencaptured.+*/+return0;+}+staticintxive_native_debug_show(structseq_file*m,void*private){structkvmppc_xive*xive=m->private;
@@ -102,6 +102,25 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EINVAL: Not initialized source number, invalid priority or invalid CPU number.+* VCPU state++ The XIVE IC maintains VP interrupt state in an internal structure+ called the NVT. When a VP is not dispatched on a HW processor+ thread, this structure can be updated by HW if the VP is the target+ of an event notification.++ It is important for migration to capture the cached IPB from the NVT+ as it synthesizes the priorities of the pending interrupts. We+ capture a bit more to report debug information.++ KVM_REG_PPC_VP_STATE (4 * 64bits)+ bits: | 63 .... 32 | 31 .... 0 |+ values: | TIMA word0 | TIMA word1 |+ bits: | 127 .......... 64 |+ values: | VP CAM Line |+ bits: | 255 .......... 128 |+ values: | unused |+ * Migration: Saving the state of a VM using the XIVE native exploitation mode
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:47:07
Each thread has an associated Thread Interrupt Management context
composed of a set of registers. These registers let the thread handle
priority management and interrupt acknowledgment. The most important
are :
- Interrupt Pending Buffer (IPB)
- Current Processor Priority (CPPR)
- Notification Source Register (NSR)
They are exposed to software in four different pages each proposing a
view with a different privilege. The first page is for the physical
thread context and the second for the hypervisor. Only the third
(operating system) and the fourth (user level) are exposed the guest.
A custom VM fault handler will populate the VMA with the appropriate
pages, which should only be the OS page for now.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/xive.h | 1 +
arch/powerpc/include/uapi/asm/kvm.h | 2 ++
arch/powerpc/kvm/book3s_xive_native.c | 39 ++++++++++++++++++++++
arch/powerpc/sysdev/xive/native.c | 11 ++++++
Documentation/virtual/kvm/devices/xive.txt | 23 +++++++++++++
5 files changed, 76 insertions(+)
@@ -176,6 +176,44 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintxive_native_tima_fault(structvm_fault*vmf)+{+structvm_area_struct*vma=vmf->vma;++switch(vmf->pgoff-vma->vm_pgoff){+case0:/* HW - forbid access */+case1:/* HV - forbid access */+returnVM_FAULT_SIGBUS;+case2:/* OS */+vmf_insert_pfn(vma,vmf->address,xive_tima_os>>PAGE_SHIFT);+returnVM_FAULT_NOPAGE;+case3:/* USER - TODO */+default:+returnVM_FAULT_SIGBUS;+}+}++staticconststructvm_operations_structxive_native_tima_vmops={+.fault=xive_native_tima_fault,+};++staticintkvmppc_xive_native_mmap(structkvm_device*dev,+structvm_area_struct*vma)+{+/* We only allow mappings at fixed offset for now */+if(vma->vm_pgoff==KVM_XIVE_TIMA_PAGE_OFFSET){+if(vma_pages(vma)>4)+return-EINVAL;+vma->vm_ops=&xive_native_tima_vmops;+}else{+return-EINVAL;+}++vma->vm_flags|=VM_IO|VM_PFNMAP;+vma->vm_page_prot=pgprot_noncached_wc(vma->vm_page_prot);+return0;+}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,u64addr){
@@ -573,6 +576,14 @@ bool __init xive_native_init(void)for_each_possible_cpu(cpu)kvmppc_set_xive_tima(cpu,r.start,tima);+/* Resource 2 is OS window */+if(of_address_to_resource(np,2,&r)){+pr_err("Failed to get thread mgmnt area resource\n");+returnfalse;+}++xive_tima_os=r.start;+/* Grab size of provisionning pages */xive_parse_provisioning(np);
@@ -13,6 +13,29 @@ requires a POWER9 host and the guest OS should have support for the XIVE native exploitation interrupt mode. If not, it should run using the legacy interrupt mode, referred as XICS (POWER7/8).+* Device Mappings++ The KVM device exposes different MMIO ranges of the XIVE HW which+ are required for interrupt management. These are exposed to the+ guest in VMAs populated with a custom VM fault handler.++ 1. Thread Interrupt Management Area (TIMA)++ Each thread has an associated Thread Interrupt Management context+ composed of a set of registers. These registers let the thread+ handle priority management and interrupt acknowledgment. The most+ important are :++ - Interrupt Pending Buffer (IPB)+ - Current Processor Priority (CPPR)+ - Notification Source Register (NSR)++ They are exposed to software in four different pages each proposing+ a view with a different privilege. The first page is for the+ physical thread context and the second for the hypervisor. Only the+ third (operating system) and the fourth (user level) are exposed the+ guest.+ * Groups: 1. KVM_DEV_XIVE_GRP_CTRL
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:49:05
This control will be used by the H_INT_SYNC hcall from QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 34 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 9 ++++++
3 files changed, 44 insertions(+)
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:50:48
Some KVM devices will want to handle special mappings related to the
underlying HW. For instance, the XIVE interrupt controller of the
POWER9 processor has MMIO pages for thread interrupt management and
for interrupt source control that need to be exposed to the guest when
the OS has the required support.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
include/linux/kvm_host.h | 1 +
virt/kvm/kvm_main.c | 11 +++++++++++
2 files changed, 12 insertions(+)
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:52:27
When migration of a VM is initiated, a first copy of the RAM is
transferred to the destination before the VM is stopped, but there is
no guarantee that the EQ pages in which the event notification are
queued have not been modified.
To make sure migration will capture a consistent memory state, the
XIVE device should perform a XIVE quiesce sequence to stop the flow of
event notifications and stabilize the EQs. This is the purpose of the
KVM_DEV_XIVE_EQ_SYNC control which will also marks the EQ pages dirty
to force their transfer.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 67 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 ++++++++++
3 files changed, 97 insertions(+)
@@ -23,6 +23,12 @@ the legacy interrupt mode, referred as XICS (POWER7/8). queues. To be used by kexec and kdump. Errors: none+ 1.2 KVM_DEV_XIVE_EQ_SYNC (write only)+ Sync all the sources and queues and mark the EQ pages dirty. This+ to make sure that a consistent memory state is captured when+ migrating the VM.+ Errors: none+ 2. KVM_DEV_XIVE_GRP_SOURCE (write only) Initializes a new source in the XIVE device and mask it. Attributes:
@@ -95,3 +101,26 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENOENT: Unknown source number -EINVAL: Not initialized source number, invalid priority or invalid CPU number.++* Migration:++ Saving the state of a VM using the XIVE native exploitation mode+ should follow a specific sequence. When the VM is stopped :++ 1. Mask all sources (PQ=01) to stop the flow of events.++ 2. Sync the XIVE device with the KVM control KVM_DEV_XIVE_EQ_SYNC to+ flush any in-flight event notification and to stabilize the EQs. At+ this stage, the EQ pages are marked dirty to make sure they are+ transferred in the migration sequence.++ 3. Capture the state of the source targeting, the EQs configuration+ and the state of thread interrupt context registers.++ Restore is similar :++ 1. Restore the EQ configuration. As targeting depends on it.+ 2. Restore targeting+ 3. Restore the thread interrupt contexts+ 4. Restore the source states+ 5. Let the vCPU run
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:54:10
The 'destroy' method is currently used to destroy all devices when the
VM is destroyed after the vCPUs have been freed.
This new KVM ioctl exposes the same KVM device method. It acts as a
software reset of the VM to 'destroy' selected devices when necessary
and perform the required cleanups on the vCPUs. Called with the
kvm->lock.
The 'destroy' method could be improved by returning an error code.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
include/uapi/linux/kvm.h | 7 ++++++
virt/kvm/kvm_main.c | 38 +++++++++++++++++++++++++++++++
Documentation/virtual/kvm/api.txt | 19 ++++++++++++++++
3 files changed, 64 insertions(+)
@@ -3857,6 +3857,25 @@ number of valid entries in the 'entries' array, which is then filled. 'index' and 'flags' fields in 'struct kvm_cpuid_entry2' are currently reserved, userspace should not expect to get any particular value there.+4.119 KVM_DESTROY_DEVICE++Capability: KVM_CAP_DEVICE_CTRL+Type: vm ioctl+Parameters: struct kvm_destroy_device (in)+Returns: 0 on success, -1 on error+Errors:+ ENODEV: The device type is unknown or unsupported++ Other error conditions may be defined by individual device types or+ have their standard meanings.++Destroys an emulated device in the kernel.++struct kvm_destroy_device {+ __u32 fd; /* in: device handle */+ __u32 flags; /* unused */+};+ 5. The kvm_run structure ------------------------
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:56:14
When the VM boots, the CAS negotiation process determines which
interrupt mode to use and invokes a machine reset. At that time, the
previous KVM interrupt device is 'destroyed' before the chosen one is
created. Upon destruction, the vCPU interrupt presenters using the KVM
device should be cleared first, the machine will reconnect them later
to the new device after it is created.
When using the KVM device, there is still a race window with the early
checks in kvmppc_native_connect_vcpu(). Yet to be fixed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xics.c | 19 +++++++++++++
arch/powerpc/kvm/book3s_xive.c | 39 +++++++++++++++++++++++++--
arch/powerpc/kvm/book3s_xive_native.c | 16 +++++++++++
3 files changed, 72 insertions(+), 2 deletions(-)
@@ -1105,11 +1105,19 @@ void kvmppc_xive_disable_vcpu_interrupts(struct kvm_vcpu *vcpu)voidkvmppc_xive_cleanup_vcpu(structkvm_vcpu*vcpu){structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;-structkvmppc_xive*xive=xc->xive;+structkvmppc_xive*xive;inti;+if(!kvmppc_xics_enabled(vcpu))+return;++if(!xc)+return;+pr_devel("cleanup_vcpu(cpu=%d)\n",xc->server_num);+xive=xc->xive;+/* Ensure no interrupt is still routed to that VP */xc->valid=false;kvmppc_xive_disable_vcpu_interrupts(vcpu);
@@ -1146,6 +1154,10 @@ void kvmppc_xive_cleanup_vcpu(struct kvm_vcpu *vcpu)}/* Free the VP */kfree(xc);++/* Cleanup the vcpu */+vcpu->arch.irq_type=KVMPPC_IRQ_DEFAULT;+vcpu->arch.xive_vcpu=NULL;}intkvmppc_xive_connect_vcpu(structkvm_device*dev,
@@ -1163,7 +1175,7 @@ int kvmppc_xive_connect_vcpu(struct kvm_device *dev,}if(xive->kvm!=vcpu->kvm)return-EPERM;-if(vcpu->arch.irq_type)+if(vcpu->arch.irq_type!=KVMPPC_IRQ_DEFAULT)return-EBUSY;if(kvmppc_xive_find_server(vcpu->kvm,cpu)){pr_devel("Duplicate !\n");
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:58:03
Each source is associated with an Event State Buffer (ESB) with a
even/odd pair of pages which provides commands to manage the source:
to trigger, to EOI, to turn off the source for instance.
The custom VM fault handler will deduce the guest IRQ number from the
offset of the fault, and the ESB page of the associated XIVE interrupt
will be inserted into the VMA using the internal structure caching
information on the interrupts.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 57 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 7 +++
3 files changed, 65 insertions(+)
@@ -36,6 +36,13 @@ the legacy interrupt mode, referred as XICS (POWER7/8). third (operating system) and the fourth (user level) are exposed the guest.+ 2. Event State Buffer (ESB)++ Each source is associated with an Event State Buffer (ESB) with+ either a pair of even/odd pair of pages which provides commands to+ manage the source: to trigger, to EOI, to turn off the source for+ instance.+ * Groups: 1. KVM_DEV_XIVE_GRP_CTRL
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 11:59:45
The KVM XICS-over-XIVE device and the proposed KVM XIVE native device
implement an IRQ space for the guest using the generic IPI interrupts
of the XIVE IC controller. These interrupts are allocated at the OPAL
level and "mapped" into the guest IRQ number space in the range 0-0x1FFF.
Interrupt management is performed in the XIVE way: using loads and
stores on the addresses of the XIVE IPI interrupt ESB pages.
Both KVM devices share the same internal structure caching information
on the interrupts, among which the xive_irq_data struct containing the
addresses of the IPI ESB pages and an extra one in case of passthrough.
The later contains the addresses of the ESB pages of the underlying HW
controller interrupts, PHB4 in all cases for now.
A guest, when running in the XICS legacy interrupt mode, lets the KVM
XICS-over-XIVE device "handle" interrupt management, that is to
perform the loads and stores on the addresses of the ESB pages of the
guest interrupts. However, when running in XIVE native exploitation
mode, the KVM XIVE native device exposes the interrupt ESB pages to
the guest and lets the guest perform directly the loads and stores.
The VMA exposing the ESB pages make use of a custom VM fault handler
which role is to populate the VMA with appropriate pages. When a fault
occurs, the guest IRQ number is deduced from the offset, and the ESB
pages of associated XIVE IPI interrupt are inserted in the VMA (using
the internal structure caching information on the interrupts).
Supporting device passthrough in the guest running in XIVE native
exploitation mode adds some extra refinements because the ESB pages
of a different HW controller (PHB4) need to be exposed to the guest
along with the initial IPI ESB pages of the XIVE IC controller. But
the overall mechanic is the same.
When the device HW irqs are mapped into or unmapped from the guest
IRQ number space, the passthru_irq helpers, kvmppc_xive_set_mapped()
and kvmppc_xive_clr_mapped(), are called to record or clear the
passthrough interrupt information and to perform the switch.
The approach taken by this patch is to clear the ESB pages of the
guest IRQ number being mapped and let the VM fault handler repopulate.
The handler will insert the ESB page corresponding to the HW interrupt
of the device being passed-through or the initial IPI ESB page if the
device is being removed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xive.h | 9 +++++
arch/powerpc/kvm/book3s_xive.c | 15 ++++++++
arch/powerpc/kvm/book3s_xive_native.c | 41 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 ++++++++
4 files changed, 80 insertions(+)
@@ -942,6 +942,13 @@ int kvmppc_xive_set_mapped(struct kvm *kvm, unsigned long guest_irq,/* Turn the IPI hard off */xive_vm_esb_load(&state->ipi_data,XIVE_ESB_SET_PQ_01);+/*+*ResetESBguestmapping.NeededwhenESBpagesareexposed+*totheguestinXIVEnativemode+*/+if(xive->ops&&xive->ops->reset_mapped)+xive->ops->reset_mapped(kvm,guest_irq);+/* Grab info about irq */state->pt_number=hw_irq;state->pt_data=irq_data_get_irq_handler_data(host_data);
@@ -1027,6 +1034,14 @@ int kvmppc_xive_clr_mapped(struct kvm *kvm, unsigned long guest_irq,state->pt_number=0;state->pt_data=NULL;+/*+*ResetESBguestmapping.NeededwhenESBpagesareexposed+*totheguestinXIVEnativemode+*/+if(xive->ops&&xive->ops->reset_mapped){+xive->ops->reset_mapped(kvm,guest_irq);+}+/* Reconfigure the IPI */xive_native_configure_irq(state->ipi_number,xive_vp(xive,state->act_server),
@@ -176,6 +177,35 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+/*+*Devicepassthroughsupport+*/+staticintkvmppc_xive_native_reset_mapped(structkvm*kvm,unsignedlongirq)+{+structkvmppc_xive*xive=kvm->arch.xive;++if(irq>=KVMPPC_XIVE_NR_IRQS)+return-EINVAL;++/*+*CleartheESBpagesoftheIRQnumberbeingmapped(or+*unmapped)intotheguestandletthetheVMfaulthandler+*repopulatewiththeappropriateESBpages(deviceorIC)+*/+pr_debug("clearing esb pages for girq 0x%lx\n",irq);+mutex_lock(&xive->mapping_lock);+if(xive->mapping)+unmap_mapping_range(xive->mapping,+irq*(2ull<<PAGE_SHIFT),+2ull<<PAGE_SHIFT,1);+mutex_unlock(&xive->mapping_lock);+return0;+}++staticstructkvmppc_xive_opskvmppc_xive_native_ops={+.reset_mapped=kvmppc_xive_native_reset_mapped,+};+staticintxive_native_esb_fault(structvm_fault*vmf){structvm_area_struct*vma=vmf->vma;
@@ -253,6 +283,8 @@ static const struct vm_operations_struct xive_native_tima_vmops = {staticintkvmppc_xive_native_mmap(structkvm_device*dev,structvm_area_struct*vma){+structkvmppc_xive*xive=dev->private;+/* We only allow mappings at fixed offset for now */if(vma->vm_pgoff==KVM_XIVE_TIMA_PAGE_OFFSET){if(vma_pages(vma)>4)
@@ -268,6 +300,13 @@ static int kvmppc_xive_native_mmap(struct kvm_device *dev,vma->vm_flags|=VM_IO|VM_PFNMAP;vma->vm_page_prot=pgprot_noncached_wc(vma->vm_page_prot);++/*+*GrabtheKVMdevicefileaddress_spacetobeabletoclear+*theESBpagesmappingwhenadeviceispassed-throughinto+*theguest.+*/+xive->mapping=vma->vm_file->f_mapping;return0;}
@@ -913,6 +952,7 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)xive->dev=dev;xive->kvm=kvm;kvm->arch.xive=xive;+mutex_init(&xive->mapping_lock);/* We use the default queue size set by the host */xive->q_order=xive_native_default_eq_shift();
@@ -43,6 +43,21 @@ the legacy interrupt mode, referred as XICS (POWER7/8). manage the source: to trigger, to EOI, to turn off the source for instance.+ 3. Device passthrough++ When a device is passed-through into the guest, the source+ interrupts are from a different HW controller (PHB4) and the ESB+ pages exposed to the guest should accommadate this change.++ The passthru_irq helpers, kvmppc_xive_set_mapped() and+ kvmppc_xive_clr_mapped() are called when the device HW irqs are+ mapped into or unmapped from the guest IRQ number space. The KVM+ device extends these helpers to clear the ESB pages of the guest IRQ+ number being mapped and then lets the VM fault handler repopulate.+ The handler will insert the ESB page corresponding to the HW+ interrupt of the device being passed-through or the initial IPI ESB+ page if the device has being removed.+ * Groups: 1. KVM_DEV_XIVE_GRP_CTRL
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-22 12:01:51
This control is to be used by the H_INT_RESET hcall from QEMU. Its
purpose is to clear all configuration of the sources and EQs. This is
necessary in case of a kexec (for a kdump kernel for instance) to make
sure that no remaining configuration is left from the previous boot
setup so that the new kernel can start safely from a clean state.
The queue 7 is ignored when the KVM device is configured to run in
single escalation mode. Prio 7 is used by escalations.
The XIVE VP is kept enabled as the vCPU is still active and connected
to the XIVE device.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 5 ++
3 files changed, 88 insertions(+)
@@ -536,6 +536,80 @@ static int kvmppc_xive_native_get_queue_config(struct kvmppc_xive *xive,return0;}+staticvoidkvmppc_xive_reset_sources(structkvmppc_xive_src_block*sb)+{+inti;++for(i=0;i<KVMPPC_XICS_IRQ_PER_ICS;i++){+structkvmppc_xive_irq_state*state=&sb->irq_state[i];++if(!state->valid)+continue;++if(state->act_priority==MASKED)+continue;++arch_spin_lock(&sb->lock);+state->eisn=0;+state->act_server=0;+state->act_priority=MASKED;+xive_vm_esb_load(&state->ipi_data,XIVE_ESB_SET_PQ_01);+xive_native_configure_irq(state->ipi_number,0,MASKED,0);+if(state->pt_number){+xive_vm_esb_load(state->pt_data,XIVE_ESB_SET_PQ_01);+xive_native_configure_irq(state->pt_number,+0,MASKED,0);+}+arch_spin_unlock(&sb->lock);+}+}++staticintkvmppc_xive_reset(structkvmppc_xive*xive)+{+structkvm*kvm=xive->kvm;+structkvm_vcpu*vcpu;+unsignedinti;++pr_devel("%s\n",__func__);++mutex_lock(&kvm->lock);++kvm_for_each_vcpu(i,vcpu,kvm){+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+unsignedintprio;++if(!xc)+continue;++kvmppc_xive_disable_vcpu_interrupts(vcpu);++for(prio=0;prio<KVMPPC_XIVE_Q_COUNT;prio++){++/* Single escalation, no queue 7 */+if(prio==7&&xive->single_escalation)+break;++if(xc->esc_virq[prio]){+free_irq(xc->esc_virq[prio],vcpu);+irq_dispose_mapping(xc->esc_virq[prio]);+kfree(xc->esc_virq_names[prio]);+xc->esc_virq[prio]=0;+}++kvmppc_xive_native_cleanup_queue(vcpu,prio);+}+}++for(i=0;i<=xive->max_sbid;i++){+if(xive->src_blocks[i])+kvmppc_xive_reset_sources(xive->src_blocks[i]);+}++mutex_unlock(&kvm->lock);++return0;+}+staticintkvmppc_xive_native_set_attr(structkvm_device*dev,structkvm_device_attr*attr){
@@ -543,6 +617,10 @@ static int kvmppc_xive_native_set_attr(struct kvm_device *dev,switch(attr->group){caseKVM_DEV_XIVE_GRP_CTRL:+switch(attr->attr){+caseKVM_DEV_XIVE_RESET:+returnkvmppc_xive_reset(xive);+}break;caseKVM_DEV_XIVE_GRP_SOURCE:returnkvmppc_xive_native_set_source(xive,attr->attr,
@@ -575,6 +653,10 @@ static int kvmppc_xive_native_has_attr(struct kvm_device *dev,{switch(attr->group){caseKVM_DEV_XIVE_GRP_CTRL:+switch(attr->attr){+caseKVM_DEV_XIVE_RESET:+return0;+}break;caseKVM_DEV_XIVE_GRP_SOURCE:caseKVM_DEV_XIVE_GRP_SOURCE_CONFIG:
@@ -17,6 +17,11 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device+ Attributes:+ 1.1 KVM_DEV_XIVE_RESET (write only)+ Resets the interrupt controller configuration for sources and event+ queues. To be used by kexec and kdump.+ Errors: none 2. KVM_DEV_XIVE_GRP_SOURCE (write only) Initializes a new source in the XIVE device and mask it.
From: Michael Ellerman <mpe@ellerman.id.au> Date: 2019-02-25 03:52:42
Cédric Le Goater [off-list ref] writes:
quoted hunk
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/opal-api.h | 11 ++-
arch/powerpc/include/asm/opal.h | 7 ++
arch/powerpc/include/asm/xive.h | 14 +++
arch/powerpc/sysdev/xive/native.c | 99 +++++++++++++++++++
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
5 files changed, 130 insertions(+), 4 deletions(-)
You should only be defining the calls you need, leaving gaps for other
things, and you need to retain OPAL_LAST. So it should look more like:
-#define OPAL_LAST 167
+#define OPAL_XIVE_GET_VP_STATE 170
+#define OPAL_LAST 170
Also I can't merge this until it's merged into skiboot.
cheers
From: David Gibson <hidden> Date: 2019-02-25 03:59:11
On Fri, Feb 22, 2019 at 12:28:27PM +0100, Cédric Le Goater wrote:
quoted hunk
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
Internally, the interface to the new KVM device is protected with a
new interrupt mode: KVMPPC_IRQ_XIVE.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 13 +++
arch/powerpc/kvm/book3s_xive.h | 6 ++
include/uapi/linux/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive.c | 67 +++++++-----
arch/powerpc/kvm/book3s_xive_native.c | 144 ++++++++++++++++++++++++++
arch/powerpc/kvm/powerpc.c | 33 ++++++
Documentation/virtual/kvm/api.txt | 9 ++
8 files changed, 246 insertions(+), 28 deletions(-)
@@ -31,6 +31,128 @@#include"book3s_xive.h"+staticvoidkvmppc_xive_native_cleanup_queue(structkvm_vcpu*vcpu,intprio)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+structxive_q*q=&xc->queues[prio];++xive_native_disable_queue(xc->vp_id,q,prio);+if(q->qpage){+put_page(virt_to_page(q->qpage));+q->qpage=NULL;+}+}++voidkvmppc_xive_native_cleanup_vcpu(structkvm_vcpu*vcpu)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+inti;++if(!kvmppc_xive_enabled(vcpu))+return;++if(!xc)+return;++pr_devel("native_cleanup_vcpu(cpu=%d)\n",xc->server_num);++/* Ensure no interrupt is still routed to that VP */+xc->valid=false;+kvmppc_xive_disable_vcpu_interrupts(vcpu);++/* Disable the VP */+xive_native_disable_vp(xc->vp_id);++/* Free the queues & associated interrupts */+for(i=0;i<KVMPPC_XIVE_Q_COUNT;i++){+/* Free the escalation irq */+if(xc->esc_virq[i]){+free_irq(xc->esc_virq[i],vcpu);+irq_dispose_mapping(xc->esc_virq[i]);+kfree(xc->esc_virq_names[i]);+xc->esc_virq[i]=0;+}++/* Free the queue */+kvmppc_xive_native_cleanup_queue(vcpu,i);+}++/* Free the VP */+kfree(xc);++/* Cleanup the vcpu */+vcpu->arch.irq_type=KVMPPC_IRQ_DEFAULT;+vcpu->arch.xive_vcpu=NULL;+}++intkvmppc_xive_native_connect_vcpu(structkvm_device*dev,+structkvm_vcpu*vcpu,u32cpu)+{+structkvmppc_xive*xive=dev->private;+structkvmppc_xive_vcpu*xc;+intrc;++pr_devel("native_connect_vcpu(cpu=%d)\n",cpu);++if(dev->ops!=&kvm_xive_native_ops){+pr_devel("Wrong ops !\n");+return-EPERM;+}+if(xive->kvm!=vcpu->kvm)+return-EPERM;+if(vcpu->arch.irq_type!=KVMPPC_IRQ_DEFAULT)+return-EBUSY;+if(kvmppc_xive_find_server(vcpu->kvm,cpu)){
You haven't taken the kvm->lock yet, so couldn't a race mean a
duplicate server gets inserted after you make this check?
Hrm. This ties the internal VP id to the userspace chosen server
number, which isn't ideal. It puts a constraint on those server
numbers that you wouldn't otherwise have.
quoted hunk
+ xc->valid = true;
+
+ rc = xive_native_get_vp_info(xc->vp_id, &xc->vp_cam, &xc->vp_chip_id);
+ if (rc) {
+ pr_err("Failed to get VP info from OPAL: %d\n", rc);
+ goto bail;
+ }
+
+ /*
+ * Enable the VP first as the single escalation mode will
+ * affect escalation interrupts numbering
+ */
+ rc = xive_native_enable_vp(xc->vp_id, xive->single_escalation);
+ if (rc) {
+ pr_err("Failed to enable VP in OPAL: %d\n", rc);
+ goto bail;
+ }
+
+ /* Configure VCPU fields for use by assembly push/pull */
+ vcpu->arch.xive_saved_state.w01 = cpu_to_be64(0xff000000);
+ vcpu->arch.xive_cam_word = cpu_to_be32(xc->vp_cam | TM_QW1W2_VO);
+
+ /* TODO: initialize queues ? */
+
+bail:
+ vcpu->arch.irq_type = KVMPPC_IRQ_XIVE;
+ mutex_unlock(&vcpu->kvm->lock);
+ if (rc)
+ kvmppc_xive_native_cleanup_vcpu(vcpu);
+
+ return rc;
+}
+
static int kvmppc_xive_native_set_attr(struct kvm_device *dev,
struct kvm_device_attr *attr)
{
@@ -570,6 +570,12 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)caseKVM_CAP_PPC_GET_CPU_CHAR:r=1;break;+#ifdef CONFIG_KVM_XIVE+caseKVM_CAP_PPC_IRQ_XIVE:+/* only for PowerNV */+r=!!cpu_has_feature(CPU_FTR_HVMODE);+break;+#endifcaseKVM_CAP_PPC_ALLOC_HTAB:r=hv_enabled;
@@ -4458,6 +4458,15 @@ struct kvm_sync_regs { struct kvm_vcpu_events events; };+6.75 KVM_CAP_PPC_IRQ_XIVE++Architectures: ppc+Target: vcpu+Parameters: args[0] is the XIVE device fd+ args[1] is the XIVE CPU number (server ID) for this vcpu++This capability connects the vcpu to an in-kernel XIVE device.+ 7. Capabilities that can be enabled on VMs ------------------------------------------
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:00:38
On Fri, Feb 22, 2019 at 12:28:26PM +0100, Cédric Le Goater wrote:
quoted hunk
This is the basic framework for the new KVM device supporting the XIVE
native exploitation mode. The user interface exposes a new KVM device
to be created by QEMU when running on a L0 hypervisor only. Support
for nested guests is not available yet.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 8 +
arch/powerpc/include/uapi/asm/kvm.h | 3 +
include/uapi/linux/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 7 +-
arch/powerpc/kvm/book3s_xive_native.c | 191 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 ++
arch/powerpc/kvm/Makefile | 2 +-
8 files changed, 231 insertions(+), 2 deletions(-)
create mode 100644 arch/powerpc/kvm/book3s_xive_native.c
create mode 100644 Documentation/virtual/kvm/devices/xive.txt
@@ -0,0 +1,191 @@+// SPDX-License-Identifier: GPL-2.0+/*+*Copyright(c)2017-2019,IBMCorporation.+*/++#define pr_fmt(fmt) "xive-kvm: " fmt++#include<linux/anon_inodes.h>+#include<linux/kernel.h>+#include<linux/kvm_host.h>+#include<linux/err.h>+#include<linux/gfp.h>+#include<linux/spinlock.h>+#include<linux/delay.h>+#include<linux/percpu.h>+#include<linux/cpumask.h>+#include<asm/uaccess.h>+#include<asm/kvm_book3s.h>+#include<asm/kvm_ppc.h>+#include<asm/hvcall.h>+#include<asm/xics.h>+#include<asm/xive.h>+#include<asm/xive-regs.h>+#include<asm/debug.h>+#include<asm/debugfs.h>+#include<asm/time.h>+#include<asm/opal.h>++#include<linux/debugfs.h>+#include<linux/seq_file.h>++#include"book3s_xive.h"++staticintkvmppc_xive_native_set_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticintkvmppc_xive_native_get_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+return-ENXIO;+}++staticintkvmppc_xive_native_has_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticvoidkvmppc_xive_native_free(structkvm_device*dev)+{+structkvmppc_xive*xive=dev->private;+structkvm*kvm=xive->kvm;++debugfs_remove(xive->dentry);++pr_devel("Destroying xive native device\n");++if(kvm)+kvm->arch.xive=NULL;++if(xive->vp_base!=XIVE_INVALID_VP)+xive_native_free_vp_block(xive->vp_base);++kfree(xive);+kfree(dev);+}++staticintkvmppc_xive_native_create(structkvm_device*dev,u32type)+{+structkvmppc_xive*xive;+structkvm*kvm=dev->kvm;+intret=0;++pr_devel("Creating xive native device\n");++if(kvm->arch.xive)+return-EEXIST;++xive=kzalloc(sizeof(*xive),GFP_KERNEL);+if(!xive)+return-ENOMEM;++dev->private=xive;+xive->dev=dev;+xive->kvm=kvm;+kvm->arch.xive=xive;++/* We use the default queue size set by the host */
IIUC the queue is examined directly by the guest, so the guest must
know its size. In which case letting the host decide the size would
be a problem for migration.
quoted hunk
+ xive->q_order = xive_native_default_eq_shift();
+ if (xive->q_order < PAGE_SHIFT)
+ xive->q_page_order = 0;
+ else
+ xive->q_page_order = xive->q_order - PAGE_SHIFT;
+
+ /*
+ * Allocate a bunch of VPs. KVM_MAX_VCPUS is a large value for
+ * a default. Getting the max number of CPUs the VM was
+ * configured with would improve our usage of the XIVE VP space.
+ */
+ xive->vp_base = xive_native_alloc_vp_block(KVM_MAX_VCPUS);
+ pr_devel("VP_Base=%x\n", xive->vp_base);
+
+ if (xive->vp_base == XIVE_INVALID_VP)
+ ret = -ENOMEM;
+
+ xive->single_escalation = xive_native_has_single_escalation();
+
+ if (ret)
+ kfree(xive);
+
+ return ret;
+}
+
+static int xive_native_debug_show(struct seq_file *m, void *private)
+{
+ struct kvmppc_xive *xive = m->private;
+ struct kvm *kvm = xive->kvm;
+
+ if (!kvm)
+ return 0;
+
+ return 0;
+}
+
+static int xive_native_debug_open(struct inode *inode, struct file *file)
+{
+ return single_open(file, xive_native_debug_show, inode->i_private);
+}
+
+static const struct file_operations xive_native_debug_fops = {
+ .open = xive_native_debug_open,
+ .read = seq_read,
+ .llseek = seq_lseek,
+ .release = single_release,
+};
+
+static void xive_native_debugfs_init(struct kvmppc_xive *xive)
+{
+ char *name;
+
+ name = kasprintf(GFP_KERNEL, "kvm-xive-%p", xive);
+ if (!name) {
+ pr_err("%s: no memory for name\n", __func__);
+ return;
+ }
+
+ xive->dentry = debugfs_create_file(name, 0444, powerpc_debugfs_root,
+ xive, &xive_native_debug_fops);
+
+ pr_debug("%s: created %s\n", __func__, name);
+ kfree(name);
+}
+
+static void kvmppc_xive_native_init(struct kvm_device *dev)
+{
+ struct kvmppc_xive *xive = (struct kvmppc_xive *)dev->private;
+
+ /* Register some debug interfaces */
+ xive_native_debugfs_init(xive);
+}
+
+struct kvm_device_ops kvm_xive_native_ops = {
+ .name = "kvm-xive-native",
+ .create = kvmppc_xive_native_create,
+ .init = kvmppc_xive_native_init,
+ .destroy = kvmppc_xive_native_free,
+ .set_attr = kvmppc_xive_native_set_attr,
+ .get_attr = kvmppc_xive_native_get_attr,
+ .has_attr = kvmppc_xive_native_has_attr,
+};
+
+void kvmppc_xive_native_init_module(void)
+{
+ ;
+}
+
+void kvmppc_xive_native_exit_module(void)
+{
+ ;
+}
@@ -0,0 +1,19 @@+POWER9 eXternal Interrupt Virtualization Engine (XIVE Gen1)+==========================================================++Device types supported:+ KVM_DEV_TYPE_XIVE POWER9 XIVE Interrupt Controller generation 1++This device acts as a VM interrupt controller. It provides the KVM+interface to configure the interrupt sources of a VM in the underlying+POWER9 XIVE interrupt controller.++Only one XIVE instance may be instantiated. A guest XIVE device+requires a POWER9 host and the guest OS should have support for the+XIVE native exploitation interrupt mode. If not, it should run using+the legacy interrupt mode, referred as XICS (POWER7/8).++* Groups:++ 1. KVM_DEV_XIVE_GRP_CTRL+ Provides global controls on the device
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:02:12
On Fri, Feb 22, 2019 at 12:28:29PM +0100, Cédric Le Goater wrote:
This control will be used by the H_INT_SET_SOURCE_CONFIG hcall from
QEMU and also to restore the configuration of the source in the KVM
device.
The XIVE internal IRQ structure is extended with the value of the
Effective Interrupt Source Number. The EISN is the interrupt number
pushed in the event queue that the guest OS will use to dispatch
events internally. Caching the EISN value in KVM ease the test when
checking if a reconfiguration is indeed needed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
@@ -32,3 +32,23 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENOMEM: Could not create a new source block -EFAULT: Invalid user pointer for attr->addr. -ENXIO: Could not allocate underlying HW interrupt++ 3. KVM_DEV_XIVE_GRP_SOURCE_CONFIG (write only)+ Configures source targeting+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 33 | 32 | 31 .. 3 | 2 .. 0+ values: | eisn | mask | server | priority+ - priority: 0-7 interrupt priority level+ - server: CPU number chosen to handle the interrupt+ - mask: mask flag (unused)+ - eisn: Effective Interrupt Source Number+ Errors:+ -ENOENT: Unknown source number+ -EINVAL: Not initialized source number, invalid priority or+ invalid CPU number.+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: CPU event queues not configured or configuration of the+ underlying HW interrupt failed+ -EBUSY: No CPU available to serve interrupt
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:03:41
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
quoted hunk
The associated HW interrupt source is simply allocated at the OPAL/HW
level and then MASKED. KVM only needs to know about its type: LSI or
MSI.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 5 +
arch/powerpc/kvm/book3s_xive.h | 10 ++
arch/powerpc/kvm/book3s_xive.c | 8 +-
arch/powerpc/kvm/book3s_xive_native.c | 114 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 +++
5 files changed, 148 insertions(+), 4 deletions(-)
We do align these in qemu, but I don't see that the kernel part
cares: as far as it's concerned only one of XICS or XIVE is active at
a time, and the irq numbers are chosen by userspace.
quoted hunk
+ */
+#define KVMPPC_XIVE_FIRST_IRQ 0
+#define KVMPPC_XIVE_NR_IRQS KVMPPC_XICS_NR_IRQS
+
/*
* State for one guest irq source.
*
I wonder if we should rename this book3s_xics_on_xive.c or something
at some point, I keep getting confused because I forget that this is
only dealing with host xive, not guest xive.
quoted hunk
@@ -1485,8 +1485,8 @@ static int xive_get_source(struct kvmppc_xive *xive, long irq, u64 addr) return 0; }-static struct kvmppc_xive_src_block *xive_create_src_block(struct kvmppc_xive *xive,- int irq)+struct kvmppc_xive_src_block *kvmppc_xive_create_src_block(+ struct kvmppc_xive *xive, int irq) { struct kvm *kvm = xive->kvm; struct kvmppc_xive_src_block *sb;
It's odd that this function, now used from the xive-on-xive path as
well as the xics-on-xive path references KVMPPC_XICS_ICS_SHIFT a few
lines down from this change.
quoted hunk
@@ -1565,7 +1565,7 @@ static int xive_set_source(struct kvmppc_xive *xive, long irq, u64 addr) sb = kvmppc_xive_find_source(xive, irq, &idx); if (!sb) { pr_devel("No source, creating source block...\n");- sb = xive_create_src_block(xive, irq);+ sb = kvmppc_xive_create_src_block(xive, irq); if (!sb) { pr_devel("Failed to create block...\n"); return -ENOMEM;
@@ -153,12 +176,89 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,+u64addr)+{+structkvmppc_xive_src_block*sb;+structkvmppc_xive_irq_state*state;+u64__user*ubufp=(u64__user*)addr;+u64val;+u16idx;++pr_devel("%s irq=0x%lx\n",__func__,irq);++if(irq<KVMPPC_XIVE_FIRST_IRQ||irq>=KVMPPC_XIVE_NR_IRQS)+return-E2BIG;++sb=kvmppc_xive_find_source(xive,irq,&idx);+if(!sb){+pr_debug("No source, creating source block...\n");+sb=kvmppc_xive_create_src_block(xive,irq);+if(!sb){+pr_err("Failed to create block...\n");+return-ENOMEM;+}+}+state=&sb->irq_state[idx];++if(get_user(val,ubufp)){+pr_err("fault getting user info !\n");+return-EFAULT;+}
You should validate the value loaded here to check it doesn't have any
bits set we don't know about.
+
+ /*
+ * If the source doesn't already have an IPI, allocate
+ * one and get the corresponding data
+ */
+ if (!state->ipi_number) {
+ state->ipi_number = xive_native_alloc_irq();
+ if (state->ipi_number == 0) {
+ pr_err("Failed to allocate IRQ !\n");
+ return -ENXIO;
+ }
+ xive_native_populate_irq_data(state->ipi_number,
+ &state->ipi_data);
+ pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n", __func__,
+ state->ipi_number, irq);
+ }
+
+ arch_spin_lock(&sb->lock);
Why the direct call to arch_spin_lock() rather than just spin_lock()?
quoted hunk
+
+ /* Restore LSI state */
+ if (val & KVM_XIVE_LEVEL_SENSITIVE) {
+ state->lsi = true;
+ if (val & KVM_XIVE_LEVEL_ASSERTED)
+ state->asserted = true;
+ pr_devel(" LSI ! Asserted=%d\n", state->asserted);
+ }
+
+ /* Mask IRQ to start with */
+ state->act_server = 0;
+ state->act_priority = MASKED;
+ xive_vm_esb_load(&state->ipi_data, XIVE_ESB_SET_PQ_01);
+ xive_native_configure_irq(state->ipi_number, 0, MASKED, 0);
+
+ /* Increment the number of valid sources and mark this one valid */
+ if (!state->valid)
+ xive->src_count++;
+ state->valid = true;
+
+ arch_spin_unlock(&sb->lock);
+
+ return 0;
+}
+
static int kvmppc_xive_native_set_attr(struct kvm_device *dev,
struct kvm_device_attr *attr)
{
+ struct kvmppc_xive *xive = dev->private;
+
switch (attr->group) {
case KVM_DEV_XIVE_GRP_CTRL:
break;
+ case KVM_DEV_XIVE_GRP_SOURCE:
+ return kvmppc_xive_native_set_source(xive, attr->attr,
+ attr->addr);
}
return -ENXIO;
}
@@ -175,6 +275,11 @@ static int kvmppc_xive_native_has_attr(struct kvm_device *dev, switch (attr->group) { case KVM_DEV_XIVE_GRP_CTRL: break;+ case KVM_DEV_XIVE_GRP_SOURCE:+ if (attr->attr >= KVMPPC_XIVE_FIRST_IRQ &&+ attr->attr < KVMPPC_XIVE_NR_IRQS)+ return 0;+ break; } return -ENXIO; }
@@ -17,3 +17,18 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device++ 2. KVM_DEV_XIVE_GRP_SOURCE (write only)+ Initializes a new source in the XIVE device and mask it.+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 2 | 1 | 0+ values: | unused | level | type+ - type: 0:MSI 1:LSI+ - level: assertion level in case of an LSI.+ Errors:+ -E2BIG: Interrupt source number is out of range+ -ENOMEM: Could not create a new source block+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: Could not allocate underlying HW interrupt
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:05:10
On Fri, Feb 22, 2019 at 12:28:25PM +0100, Cédric Le Goater wrote:
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
@@ -711,3 +717,96 @@ bool xive_native_has_single_escalation(void)returnxive_has_single_esc;}EXPORT_SYMBOL_GPL(xive_native_has_single_escalation);++intxive_native_get_queue_info(u32vp_id,u32prio,+u64*out_qpage,+u64*out_qsize,+u64*out_qeoi_page,+u32*out_escalate_irq,+u64*out_qflags)+{+__be64qpage;+__be64qsize;+__be64qeoi_page;+__be32escalate_irq;+__be64qflags;+s64rc;++rc=opal_xive_get_queue_info(vp_id,prio,&qpage,&qsize,+&qeoi_page,&escalate_irq,&qflags);+if(rc){+pr_err("OPAL failed to get queue info for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++if(out_qpage)+*out_qpage=be64_to_cpu(qpage);+if(out_qsize)+*out_qsize=be32_to_cpu(qsize);+if(out_qeoi_page)+*out_qeoi_page=be64_to_cpu(qeoi_page);+if(out_escalate_irq)+*out_escalate_irq=be32_to_cpu(escalate_irq);+if(out_qflags)+*out_qflags=be64_to_cpu(qflags);++return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_queue_info);++intxive_native_get_queue_state(u32vp_id,u32prio,u32*qtoggle,u32*qindex)+{+__be32opal_qtoggle;+__be32opal_qindex;+s64rc;++rc=opal_xive_get_queue_state(vp_id,prio,&opal_qtoggle,+&opal_qindex);+if(rc){+pr_err("OPAL failed to get queue state for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++if(qtoggle)+*qtoggle=be32_to_cpu(opal_qtoggle);+if(qindex)+*qindex=be32_to_cpu(opal_qindex);++return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_queue_state);++intxive_native_set_queue_state(u32vp_id,u32prio,u32qtoggle,u32qindex)+{+s64rc;++rc=opal_xive_set_queue_state(vp_id,prio,qtoggle,qindex);+if(rc){+pr_err("OPAL failed to set queue state for VCPU %d/%d : %lld\n",+vp_id,prio,rc);+return-EIO;+}++return0;+}+EXPORT_SYMBOL_GPL(xive_native_set_queue_state);++intxive_native_get_vp_state(u32vp_id,u64*out_state)+{+__be64state;+s64rc;++rc=opal_xive_get_vp_state(vp_id,&state);+if(rc){+pr_err("OPAL failed to get vp state for VCPU %d : %lld\n",+vp_id,rc);+return-EIO;+}++if(out_state)+*out_state=be64_to_cpu(state);+return0;+}+EXPORT_SYMBOL_GPL(xive_native_get_vp_state);
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:06:53
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted hunk
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/xive.h | 2 +
arch/powerpc/include/uapi/asm/kvm.h | 21 +++
arch/powerpc/kvm/book3s_xive.h | 2 +
arch/powerpc/kvm/book3s_xive.c | 15 +-
arch/powerpc/kvm/book3s_xive_native.c | 207 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 +++
6 files changed, 270 insertions(+), 6 deletions(-)
@@ -73,6 +73,8 @@ struct xive_q {u32esc_irq;atomic_tcount;atomic_tpending_count;+u64guest_qpage;+u32guest_qsize;};/* Global enable flags for the XIVE support */
@@ -341,6 +341,201 @@ static int kvmppc_xive_native_set_source_config(struct kvmppc_xive *xive,priority,eisn);}+staticintxive_native_validate_queue_size(u32qsize)+{+switch(qsize){+case12:+case16:+case21:+case24:+case0:+return0;+default:+return-EINVAL;+}+}++staticintkvmppc_xive_native_set_queue_config(structkvmppc_xive*xive,+longeq_idx,u64addr)+{+structkvm*kvm=xive->kvm;+structkvm_vcpu*vcpu;+structkvmppc_xive_vcpu*xc;+void__user*ubufp=(u64__user*)addr;+u32server;+u8priority;+structkvm_ppc_xive_eqkvm_eq;+intrc;+__be32*qaddr=0;+structpage*page;+structxive_q*q;++/*+*Demanglepriority/servertuplefromtheEQindex+*/+priority=(eq_idx&KVM_XIVE_EQ_PRIORITY_MASK)>>+KVM_XIVE_EQ_PRIORITY_SHIFT;+server=(eq_idx&KVM_XIVE_EQ_SERVER_MASK)>>+KVM_XIVE_EQ_SERVER_SHIFT;++if(copy_from_user(&kvm_eq,ubufp,sizeof(kvm_eq)))+return-EFAULT;++vcpu=kvmppc_xive_find_server(kvm,server);+if(!vcpu){+pr_err("Can't find server %d\n",server);+return-ENOENT;+}+xc=vcpu->arch.xive_vcpu;++if(priority!=xive_prio_from_guest(priority)){+pr_err("Trying to restore invalid queue %d for VCPU %d\n",+priority,server);+return-EINVAL;+}+q=&xc->queues[priority];
You need to validate the 'flags' field (AFAICT we don't actually have
any flags yet, so it's only valid it if is 0.
Nit: I don't think ENOMEM is the right error here. ENOMEM indicates
that the kernel couldn't allocate enough memory to complete whatever
you asked. Here the problem is the user supplied a bad guest address,
which is a rather different error. EFAULT is closer, but still not
quite right, since it could be a valid user address but not a valid
guest address. There are probably existing KVM calls that could hit
this problem, I wonder what they use.
@@ -52,3 +52,32 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENXIO: CPU event queues not configured or configuration of the underlying HW interrupt failed -EBUSY: No CPU available to serve interrupt++ 4. KVM_DEV_XIVE_GRP_EQ_CONFIG (read-write)+ Configures an event queue of a CPU+ Attributes:+ EQ descriptor identifier (64-bit)+ The EQ descriptor identifier is a tuple (server, priority) :+ bits: | 63 .... 32 | 31 .. 3 | 2 .. 0+ values: | unused | server | priority+ The kvm_device_attr.addr points to :+ struct kvm_ppc_xive_eq {+ __u32 flags;+ __u32 qsize;+ __u64 qpage;+ __u32 qtoggle;+ __u32 qindex;+ __u8 pad[40];+ };+ - flags: queue flags+ - qsize: queue size (power of 2)+ - qpage: real address of queue+ - qtoggle: current queue toggle bit+ - qindex: current queue index+ - pad: reserved for future use+ Errors:+ -ENOENT: Invalid CPU number+ -EINVAL: Invalid priority or invalid queue size+ -EFAULT: Invalid user pointer for attr->addr.+ -ENOMEM: Invalid queue address+ -EIO: Configuration of the underlying HW failed
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:08:18
On Fri, Feb 22, 2019 at 12:28:31PM +0100, Cédric Le Goater wrote:
quoted hunk
This control is to be used by the H_INT_RESET hcall from QEMU. Its
purpose is to clear all configuration of the sources and EQs. This is
necessary in case of a kexec (for a kdump kernel for instance) to make
sure that no remaining configuration is left from the previous boot
setup so that the new kernel can start safely from a clean state.
The queue 7 is ignored when the KVM device is configured to run in
single escalation mode. Prio 7 is used by escalations.
The XIVE VP is kept enabled as the vCPU is still active and connected
to the XIVE device.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 5 ++
3 files changed, 88 insertions(+)
@@ -17,6 +17,11 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device+ Attributes:+ 1.1 KVM_DEV_XIVE_RESET (write only)+ Resets the interrupt controller configuration for sources and event+ queues. To be used by kexec and kdump.+ Errors: none 2. KVM_DEV_XIVE_GRP_SOURCE (write only) Initializes a new source in the XIVE device and mask it.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:09:44
On Fri, Feb 22, 2019 at 12:28:32PM +0100, Cédric Le Goater wrote:
quoted hunk
This control will be used by the H_INT_SYNC hcall from QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 34 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 9 ++++++
3 files changed, 44 insertions(+)
@@ -86,3 +86,12 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EFAULT: Invalid user pointer for attr->addr. -ENOMEM: Invalid queue address -EIO: Configuration of the underlying HW failed++ 5. KVM_DEV_XIVE_GRP_SOURCE_SYNC (write only)+ Synchronize the source to flush event notification+ Attributes:+ Interrupt source number (64-bit)+ Errors:+ -ENOENT: Unknown source number+ -EINVAL: Not initialized source number, invalid priority or+ invalid CPU number.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:11:15
On Fri, Feb 22, 2019 at 12:28:33PM +0100, Cédric Le Goater wrote:
quoted hunk
When migration of a VM is initiated, a first copy of the RAM is
transferred to the destination before the VM is stopped, but there is
no guarantee that the EQ pages in which the event notification are
queued have not been modified.
To make sure migration will capture a consistent memory state, the
XIVE device should perform a XIVE quiesce sequence to stop the flow of
event notifications and stabilize the EQs. This is the purpose of the
KVM_DEV_XIVE_EQ_SYNC control which will also marks the EQ pages dirty
to force their transfer.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 67 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 ++++++++++
3 files changed, 97 insertions(+)
@@ -640,6 +640,70 @@ static int kvmppc_xive_reset(struct kvmppc_xive *xive)return0;}+staticvoidkvmppc_xive_native_sync_sources(structkvmppc_xive_src_block*sb)+{+intj;++for(j=0;j<KVMPPC_XICS_IRQ_PER_ICS;j++){+structkvmppc_xive_irq_state*state=&sb->irq_state[j];+structxive_irq_data*xd;+u32hw_num;++if(!state->valid)+continue;+if(state->act_priority==MASKED)
Is this correct? If you masked an irq, then immediately did a sync,
couldn't there still be some of the irqs in flight? I thought the
reason we needed a sync was that masking and other such operations
_didn't_ implicitly synchronize.
@@ -23,6 +23,12 @@ the legacy interrupt mode, referred as XICS (POWER7/8). queues. To be used by kexec and kdump. Errors: none+ 1.2 KVM_DEV_XIVE_EQ_SYNC (write only)+ Sync all the sources and queues and mark the EQ pages dirty. This+ to make sure that a consistent memory state is captured when+ migrating the VM.+ Errors: none+ 2. KVM_DEV_XIVE_GRP_SOURCE (write only) Initializes a new source in the XIVE device and mask it. Attributes:
@@ -95,3 +101,26 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENOENT: Unknown source number -EINVAL: Not initialized source number, invalid priority or invalid CPU number.++* Migration:++ Saving the state of a VM using the XIVE native exploitation mode+ should follow a specific sequence. When the VM is stopped :++ 1. Mask all sources (PQ=01) to stop the flow of events.++ 2. Sync the XIVE device with the KVM control KVM_DEV_XIVE_EQ_SYNC to+ flush any in-flight event notification and to stabilize the EQs. At+ this stage, the EQ pages are marked dirty to make sure they are+ transferred in the migration sequence.++ 3. Capture the state of the source targeting, the EQs configuration+ and the state of thread interrupt context registers.++ Restore is similar :++ 1. Restore the EQ configuration. As targeting depends on it.+ 2. Restore targeting+ 3. Restore the thread interrupt contexts+ 4. Restore the source states+ 5. Let the vCPU run
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:12:40
On Fri, Feb 22, 2019 at 12:28:34PM +0100, Cédric Le Goater wrote:
quoted hunk
At a VCPU level, the state of the thread interrupt management
registers needs to be collected. These registers are cached under the
'xive_saved_state.w01' field of the VCPU when the VPCU context is
pulled from the HW thread. An OPAL call retrieves the backup of the
IPB register in the underlying XIVE NVT structure and merges it in the
KVM state.
The structures of the interface between QEMU and KVM provisions some
extra room (two u64) for further extensions if more state needs to be
transferred back to QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_ppc.h | 11 +++
arch/powerpc/include/uapi/asm/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 24 +++++++
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 +++++
5 files changed, 138 insertions(+)
@@ -845,6 +845,88 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)returnret;}+/*+*InterruptPendingBuffer(IPB)offset+*/+#define TM_IPB_SHIFT 40+#define TM_IPB_MASK (((u64) 0xFF) << TM_IPB_SHIFT)++intkvmppc_xive_native_get_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+u64opal_state;+intrc;++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc)+return-ENOENT;++/* Thread context registers. We only care about IPB and CPPR */+val->xive_timaval[0]=vcpu->arch.xive_saved_state.w01;++/*+*ReturntheOSCAMlinetoprintouttheVPidentifierin+*theQEMUmonitor.Thisisnotrestored.+*/+val->xive_timaval[1]=vcpu->arch.xive_cam_word;
I'm pretty dubious about this mixing of vital state information with
what's basically debug information. Doubly so since it requires
changing the ABI to increase the one_reg union's size.
Might be better to have this control only return the 0th and 2nd u64s
from the TIMA, with the CAM debug information returned via some other
mechanism.
+
+ /* Get the VP state from OPAL */
+ rc = xive_native_get_vp_state(xc->vp_id, &opal_state);
+ if (rc)
+ return rc;
+
+ /*
+ * Capture the backup of IPB register in the NVT structure and
+ * merge it in our KVM VP state.
+ */
+ val->xive_timaval[0] |= cpu_to_be64(opal_state & TM_IPB_MASK);
+
+ pr_devel("%s NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x opal=%016llx\n",
+ __func__,
+ vcpu->arch.xive_saved_state.nsr,
+ vcpu->arch.xive_saved_state.cppr,
+ vcpu->arch.xive_saved_state.ipb,
+ vcpu->arch.xive_saved_state.pipr,
+ vcpu->arch.xive_saved_state.w01,
+ (u32) vcpu->arch.xive_cam_word, opal_state);
Hrm.. except you don't seem to be using the last half of the timaval
field anyway.
+
+ return 0;
+}
+
+int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu, union kvmppc_one_reg *val)
+{
+ struct kvmppc_xive_vcpu *xc = vcpu->arch.xive_vcpu;
+ struct kvmppc_xive *xive = vcpu->kvm->arch.xive;
+
+ pr_devel("%s w01=%016llx vp=%016llx\n", __func__,
+ val->xive_timaval[0], val->xive_timaval[1]);
+
+ if (!kvmppc_xive_enabled(vcpu))
+ return -EPERM;
+
+ if (!xc || !xive)
+ return -ENOENT;
+
+ /* We can't update the state of a "pushed" VCPU */
+ if (WARN_ON(vcpu->arch.xive_pushed))
What prevents userspace from tripping this WARN_ON()?
+ return -EIO;
EBUSY might be more appropriate here.
quoted hunk
+
+ /*
+ * Restore the thread context registers. IPB and CPPR should
+ * be the only ones that matter.
+ */
+ vcpu->arch.xive_saved_state.w01 = val->xive_timaval[0];
+
+ /*
+ * There is no need to restore the XIVE internal state (IPB
+ * stored in the NVT) as the IPB register was merged in KVM VP
+ * state when captured.
+ */
+ return 0;
+}
+
static int xive_native_debug_show(struct seq_file *m, void *private)
{
struct kvmppc_xive *xive = m->private;
@@ -102,6 +102,25 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EINVAL: Not initialized source number, invalid priority or invalid CPU number.+* VCPU state++ The XIVE IC maintains VP interrupt state in an internal structure+ called the NVT. When a VP is not dispatched on a HW processor+ thread, this structure can be updated by HW if the VP is the target+ of an event notification.++ It is important for migration to capture the cached IPB from the NVT+ as it synthesizes the priorities of the pending interrupts. We+ capture a bit more to report debug information.++ KVM_REG_PPC_VP_STATE (4 * 64bits)+ bits: | 63 .... 32 | 31 .... 0 |+ values: | TIMA word0 | TIMA word1 |+ bits: | 127 .......... 64 |+ values: | VP CAM Line |+ bits: | 255 .......... 128 |+ values: | unused |+ * Migration: Saving the state of a VM using the XIVE native exploitation mode
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:14:07
On Fri, Feb 22, 2019 at 12:28:35PM +0100, Cédric Le Goater wrote:
Some KVM devices will want to handle special mappings related to the
underlying HW. For instance, the XIVE interrupt controller of the
POWER9 processor has MMIO pages for thread interrupt management and
for interrupt source control that need to be exposed to the guest when
the OS has the required support.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Ah, when I suggested mmap() on the base device fd, I hadn't realized
there wasn't a facility for that yet.
Have you discussed this with Paolo? We'll need some core KVM buy in
to merge this.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:15:31
On Fri, Feb 22, 2019 at 12:28:37PM +0100, Cédric Le Goater wrote:
Each source is associated with an Event State Buffer (ESB) with a
even/odd pair of pages which provides commands to manage the source:
to trigger, to EOI, to turn off the source for instance.
The custom VM fault handler will deduce the guest IRQ number from the
offset of the fault, and the ESB page of the associated XIVE interrupt
will be inserted into the VMA using the internal structure caching
information on the interrupts.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Reviewed-by: David Gibson <redacted>
With the same caveat as the previous patch.
@@ -36,6 +36,13 @@ the legacy interrupt mode, referred as XICS (POWER7/8). third (operating system) and the fourth (user level) are exposed the guest.+ 2. Event State Buffer (ESB)++ Each source is associated with an Event State Buffer (ESB) with+ either a pair of even/odd pair of pages which provides commands to+ manage the source: to trigger, to EOI, to turn off the source for+ instance.+ * Groups: 1. KVM_DEV_XIVE_GRP_CTRL
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 04:17:16
On Fri, Feb 22, 2019 at 12:28:36PM +0100, Cédric Le Goater wrote:
Each thread has an associated Thread Interrupt Management context
composed of a set of registers. These registers let the thread handle
priority management and interrupt acknowledgment. The most important
are :
- Interrupt Pending Buffer (IPB)
- Current Processor Priority (CPPR)
- Notification Source Register (NSR)
They are exposed to software in four different pages each proposing a
view with a different privilege. The first page is for the physical
thread context and the second for the hypervisor. Only the third
(operating system) and the fourth (user level) are exposed the guest.
A custom VM fault handler will populate the VMA with the appropriate
pages, which should only be the OS page for now.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Reviewed-by: David Gibson <redacted>
Subject to possible modification depending on whether we go with the
generic change to allow mmap() on kvm devices.
@@ -176,6 +176,44 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintxive_native_tima_fault(structvm_fault*vmf)+{+structvm_area_struct*vma=vmf->vma;++switch(vmf->pgoff-vma->vm_pgoff){+case0:/* HW - forbid access */+case1:/* HV - forbid access */+returnVM_FAULT_SIGBUS;+case2:/* OS */+vmf_insert_pfn(vma,vmf->address,xive_tima_os>>PAGE_SHIFT);+returnVM_FAULT_NOPAGE;+case3:/* USER - TODO */+default:+returnVM_FAULT_SIGBUS;+}+}++staticconststructvm_operations_structxive_native_tima_vmops={+.fault=xive_native_tima_fault,+};++staticintkvmppc_xive_native_mmap(structkvm_device*dev,+structvm_area_struct*vma)+{+/* We only allow mappings at fixed offset for now */+if(vma->vm_pgoff==KVM_XIVE_TIMA_PAGE_OFFSET){+if(vma_pages(vma)>4)+return-EINVAL;+vma->vm_ops=&xive_native_tima_vmops;+}else{+return-EINVAL;+}++vma->vm_flags|=VM_IO|VM_PFNMAP;+vma->vm_page_prot=pgprot_noncached_wc(vma->vm_page_prot);+return0;+}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,u64addr){
@@ -573,6 +576,14 @@ bool __init xive_native_init(void)for_each_possible_cpu(cpu)kvmppc_set_xive_tima(cpu,r.start,tima);+/* Resource 2 is OS window */+if(of_address_to_resource(np,2,&r)){+pr_err("Failed to get thread mgmnt area resource\n");+returnfalse;+}++xive_tima_os=r.start;+/* Grab size of provisionning pages */xive_parse_provisioning(np);
@@ -13,6 +13,29 @@ requires a POWER9 host and the guest OS should have support for the XIVE native exploitation interrupt mode. If not, it should run using the legacy interrupt mode, referred as XICS (POWER7/8).+* Device Mappings++ The KVM device exposes different MMIO ranges of the XIVE HW which+ are required for interrupt management. These are exposed to the+ guest in VMAs populated with a custom VM fault handler.++ 1. Thread Interrupt Management Area (TIMA)++ Each thread has an associated Thread Interrupt Management context+ composed of a set of registers. These registers let the thread+ handle priority management and interrupt acknowledgment. The most+ important are :++ - Interrupt Pending Buffer (IPB)+ - Current Processor Priority (CPPR)+ - Notification Source Register (NSR)++ They are exposed to software in four different pages each proposing+ a view with a different privilege. The first page is for the+ physical thread context and the second for the hypervisor. Only the+ third (operating system) and the fourth (user level) are exposed the+ guest.+ * Groups: 1. KVM_DEV_XIVE_GRP_CTRL
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
Hrm. This ties the internal VP id to the userspace chosen server
number, which isn't ideal. It puts a constraint on those server
numbers that you wouldn't otherwise have.
We should probably do the same as the xics-on-xive code, which is to
put the server number through kvmppc_pack_vcpu_id(), which is a
folding function that maps the QEMU vcpu id (which is the server
number) down to the range 0..KVM_MAX_VCPUS-1, and works for the
allocation patterns used in the various vSMT modes.
Paul.
From: Paul Mackerras <hidden> Date: 2019-02-25 05:02:57
On Fri, Feb 22, 2019 at 12:28:27PM +0100, Cédric Le Goater wrote:
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
If a bisection happened to land on this commit, we would have KVM
saying it had the ability to support guests using XIVE natively, but
it wouldn't actually work since we don't have all the code that is in
the following patches.
Thus, in order to avoid breaking bisection, you should either add the
capability now but have it always return false until the rest of the
code is in place, or else defer the addition of the capability until
the end of the patch series.
@@ -570,6 +570,12 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)caseKVM_CAP_PPC_GET_CPU_CHAR:r=1;break;+#ifdef CONFIG_KVM_XIVE+caseKVM_CAP_PPC_IRQ_XIVE:+/* only for PowerNV */+r=!!cpu_has_feature(CPU_FTR_HVMODE);
Shouldn't this be r = xive_enabled() && !!cpu_has_feature(CPU_FTR_HVMODE)
(or alternatively r = xics_on_xive(), though that would be confusing
to the reader)?
As it stands this would report true on POWER8, unless I'm missing
something.
Paul.
From: David Gibson <hidden> Date: 2019-02-25 05:13:50
On Fri, Feb 22, 2019 at 12:28:39PM +0100, Cédric Le Goater wrote:
The 'destroy' method is currently used to destroy all devices when the
VM is destroyed after the vCPUs have been freed.
This new KVM ioctl exposes the same KVM device method. It acts as a
software reset of the VM to 'destroy' selected devices when necessary
and perform the required cleanups on the vCPUs. Called with the
kvm->lock.
The 'destroy' method could be improved by returning an error code.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Again, has this been discussed with Paolo and/or other KVM core
people?
@@ -3270,6 +3294,20 @@ static long kvm_vm_ioctl(struct file *filp, r = 0; break; }+ case KVM_DESTROY_DEVICE: {+ struct kvm_destroy_device dd;++ r = -EFAULT;+ if (copy_from_user(&dd, argp, sizeof(dd)))+ goto out;++ r = kvm_ioctl_destroy_device(kvm, &dd);+ if (r)+ goto out;++ r = 0;+ break;+ } case KVM_CHECK_EXTENSION: r = kvm_vm_ioctl_check_extension_generic(kvm, arg); break;
@@ -3857,6 +3857,25 @@ number of valid entries in the 'entries' array, which is then filled. 'index' and 'flags' fields in 'struct kvm_cpuid_entry2' are currently reserved, userspace should not expect to get any particular value there.+4.119 KVM_DESTROY_DEVICE++Capability: KVM_CAP_DEVICE_CTRL+Type: vm ioctl+Parameters: struct kvm_destroy_device (in)+Returns: 0 on success, -1 on error+Errors:+ ENODEV: The device type is unknown or unsupported++ Other error conditions may be defined by individual device types or+ have their standard meanings.++Destroys an emulated device in the kernel.++struct kvm_destroy_device {+ __u32 fd; /* in: device handle */+ __u32 flags; /* unused */+};+ 5. The kvm_run structure ------------------------
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 05:15:21
On Fri, Feb 22, 2019 at 12:28:40PM +0100, Cédric Le Goater wrote:
quoted hunk
When the VM boots, the CAS negotiation process determines which
interrupt mode to use and invokes a machine reset. At that time, the
previous KVM interrupt device is 'destroyed' before the chosen one is
created. Upon destruction, the vCPU interrupt presenters using the KVM
device should be cleared first, the machine will reconnect them later
to the new device after it is created.
When using the KVM device, there is still a race window with the early
checks in kvmppc_native_connect_vcpu(). Yet to be fixed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xics.c | 19 +++++++++++++
arch/powerpc/kvm/book3s_xive.c | 39 +++++++++++++++++++++++++--
arch/powerpc/kvm/book3s_xive_native.c | 16 +++++++++++
3 files changed, 72 insertions(+), 2 deletions(-)
@@ -1163,7 +1175,7 @@ int kvmppc_xive_connect_vcpu(struct kvm_device *dev, } if (xive->kvm != vcpu->kvm) return -EPERM;- if (vcpu->arch.irq_type)+ if (vcpu->arch.irq_type != KVMPPC_IRQ_DEFAULT) return -EBUSY; if (kvmppc_xive_find_server(vcpu->kvm, cpu)) { pr_devel("Duplicate !\n");
@@ -1833,8 +1845,31 @@ static void kvmppc_xive_free(struct kvm_device *dev) { struct kvmppc_xive *xive = dev->private; struct kvm *kvm = xive->kvm;+ struct kvm_vcpu *vcpu; int i;+ /*+ * When destroying the VM, the vCPUs are destroyed first and+ * the vCPU list should be empty. If this is not the case,+ * then we are simply destroying the device and we should+ * clean up the vCPU interrupt presenters first.+ */+ if (atomic_read(&kvm->online_vcpus) != 0) {+ /*+ * call kick_all_cpus_sync() to ensure that all CPUs+ * have executed any pending interrupts+ */+ if (is_kvmppc_hv_enabled(kvm))+ kick_all_cpus_sync();++ /*+ * TODO: There is still a race window with the early+ * checks in kvmppc_native_connect_vcpu()+ */+ kvm_for_each_vcpu(i, vcpu, kvm)+ kvmppc_xive_cleanup_vcpu(vcpu);+ }+ debugfs_remove(xive->dentry); if (kvm)
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-25 05:16:48
On Fri, Feb 22, 2019 at 12:28:38PM +0100, Cédric Le Goater wrote:
quoted hunk
The KVM XICS-over-XIVE device and the proposed KVM XIVE native device
implement an IRQ space for the guest using the generic IPI interrupts
of the XIVE IC controller. These interrupts are allocated at the OPAL
level and "mapped" into the guest IRQ number space in the range 0-0x1FFF.
Interrupt management is performed in the XIVE way: using loads and
stores on the addresses of the XIVE IPI interrupt ESB pages.
Both KVM devices share the same internal structure caching information
on the interrupts, among which the xive_irq_data struct containing the
addresses of the IPI ESB pages and an extra one in case of passthrough.
The later contains the addresses of the ESB pages of the underlying HW
controller interrupts, PHB4 in all cases for now.
A guest, when running in the XICS legacy interrupt mode, lets the KVM
XICS-over-XIVE device "handle" interrupt management, that is to
perform the loads and stores on the addresses of the ESB pages of the
guest interrupts. However, when running in XIVE native exploitation
mode, the KVM XIVE native device exposes the interrupt ESB pages to
the guest and lets the guest perform directly the loads and stores.
The VMA exposing the ESB pages make use of a custom VM fault handler
which role is to populate the VMA with appropriate pages. When a fault
occurs, the guest IRQ number is deduced from the offset, and the ESB
pages of associated XIVE IPI interrupt are inserted in the VMA (using
the internal structure caching information on the interrupts).
Supporting device passthrough in the guest running in XIVE native
exploitation mode adds some extra refinements because the ESB pages
of a different HW controller (PHB4) need to be exposed to the guest
along with the initial IPI ESB pages of the XIVE IC controller. But
the overall mechanic is the same.
When the device HW irqs are mapped into or unmapped from the guest
IRQ number space, the passthru_irq helpers, kvmppc_xive_set_mapped()
and kvmppc_xive_clr_mapped(), are called to record or clear the
passthrough interrupt information and to perform the switch.
The approach taken by this patch is to clear the ESB pages of the
guest IRQ number being mapped and let the VM fault handler repopulate.
The handler will insert the ESB page corresponding to the HW interrupt
of the device being passed-through or the initial IPI ESB page if the
device is being removed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xive.h | 9 +++++
arch/powerpc/kvm/book3s_xive.c | 15 ++++++++
arch/powerpc/kvm/book3s_xive_native.c | 41 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 ++++++++
4 files changed, 80 insertions(+)
@@ -942,6 +942,13 @@ int kvmppc_xive_set_mapped(struct kvm *kvm, unsigned long guest_irq,/* Turn the IPI hard off */xive_vm_esb_load(&state->ipi_data,XIVE_ESB_SET_PQ_01);+/*+*ResetESBguestmapping.NeededwhenESBpagesareexposed+*totheguestinXIVEnativemode+*/+if(xive->ops&&xive->ops->reset_mapped)+xive->ops->reset_mapped(kvm,guest_irq);+/* Grab info about irq */state->pt_number=hw_irq;state->pt_data=irq_data_get_irq_handler_data(host_data);
@@ -1027,6 +1034,14 @@ int kvmppc_xive_clr_mapped(struct kvm *kvm, unsigned long guest_irq,state->pt_number=0;state->pt_data=NULL;+/*+*ResetESBguestmapping.NeededwhenESBpagesareexposed+*totheguestinXIVEnativemode+*/+if(xive->ops&&xive->ops->reset_mapped){+xive->ops->reset_mapped(kvm,guest_irq);+}+/* Reconfigure the IPI */xive_native_configure_irq(state->ipi_number,xive_vp(xive,state->act_server),
@@ -176,6 +177,35 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+/*+*Devicepassthroughsupport+*/+staticintkvmppc_xive_native_reset_mapped(structkvm*kvm,unsignedlongirq)+{+structkvmppc_xive*xive=kvm->arch.xive;++if(irq>=KVMPPC_XIVE_NR_IRQS)+return-EINVAL;++/*+*CleartheESBpagesoftheIRQnumberbeingmapped(or+*unmapped)intotheguestandletthetheVMfaulthandler+*repopulatewiththeappropriateESBpages(deviceorIC)+*/+pr_debug("clearing esb pages for girq 0x%lx\n",irq);+mutex_lock(&xive->mapping_lock);+if(xive->mapping)+unmap_mapping_range(xive->mapping,+irq*(2ull<<PAGE_SHIFT),+2ull<<PAGE_SHIFT,1);+mutex_unlock(&xive->mapping_lock);+return0;+}++staticstructkvmppc_xive_opskvmppc_xive_native_ops={+.reset_mapped=kvmppc_xive_native_reset_mapped,+};+staticintxive_native_esb_fault(structvm_fault*vmf){structvm_area_struct*vma=vmf->vma;
@@ -253,6 +283,8 @@ static const struct vm_operations_struct xive_native_tima_vmops = {staticintkvmppc_xive_native_mmap(structkvm_device*dev,structvm_area_struct*vma){+structkvmppc_xive*xive=dev->private;+/* We only allow mappings at fixed offset for now */if(vma->vm_pgoff==KVM_XIVE_TIMA_PAGE_OFFSET){if(vma_pages(vma)>4)
@@ -268,6 +300,13 @@ static int kvmppc_xive_native_mmap(struct kvm_device *dev,vma->vm_flags|=VM_IO|VM_PFNMAP;vma->vm_page_prot=pgprot_noncached_wc(vma->vm_page_prot);++/*+*GrabtheKVMdevicefileaddress_spacetobeabletoclear+*theESBpagesmappingwhenadeviceispassed-throughinto+*theguest.+*/+xive->mapping=vma->vm_file->f_mapping;return0;}
@@ -913,6 +952,7 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)xive->dev=dev;xive->kvm=kvm;kvm->arch.xive=xive;+mutex_init(&xive->mapping_lock);/* We use the default queue size set by the host */xive->q_order=xive_native_default_eq_shift();
@@ -43,6 +43,21 @@ the legacy interrupt mode, referred as XICS (POWER7/8). manage the source: to trigger, to EOI, to turn off the source for instance.+ 3. Device passthrough++ When a device is passed-through into the guest, the source+ interrupts are from a different HW controller (PHB4) and the ESB+ pages exposed to the guest should accommadate this change.++ The passthru_irq helpers, kvmppc_xive_set_mapped() and+ kvmppc_xive_clr_mapped() are called when the device HW irqs are+ mapped into or unmapped from the guest IRQ number space. The KVM+ device extends these helpers to clear the ESB pages of the guest IRQ+ number being mapped and then lets the VM fault handler repopulate.+ The handler will insert the ESB page corresponding to the HW+ interrupt of the device being passed-through or the initial IPI ESB+ page if the device has being removed.
I think it might be worth emphasizing that this all happens with KVM
and userspace / the guest doesn't need to do anything about this
remapping. Really this is an informational aside, not something a
user of the device actually needs to know.
* Groups:
1. KVM_DEV_XIVE_GRP_CTRL
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Paul Mackerras <hidden> Date: 2019-02-25 05:32:07
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
The associated HW interrupt source is simply allocated at the OPAL/HW
level and then MASKED. KVM only needs to know about its type: LSI or
MSI.
I think it would be helpful to explain to the reader here that with
XIVE, all interrupts have a hardware source, even IPIs and virtual
device interrupts, for which we allocate a software-triggerable
interrupt source in the XIVE hardware.
@@ -253,6 +260,9 @@ extern int (*__xive_vm_h_eoi)(struct kvm_vcpu *vcpu, unsigned long xirr);*/voidkvmppc_xive_disable_vcpu_interrupts(structkvm_vcpu*vcpu);intkvmppc_xive_debug_show_queues(structseq_file*m,structkvm_vcpu*vcpu);+structkvmppc_xive_src_block*kvmppc_xive_create_src_block(+structkvmppc_xive*xive,intirq);+voidkvmppc_xive_free_sources(structkvmppc_xive_src_block*sb);
So we're using the same source block data structure (effectively a
2-level tree) that the XICS-on-XIVE code uses. That would be worth
mentioning as a design choice in the patch description.
Ben originally defined the __x_* macros so that he could use the same
source code twice, once for real mode and once for virtual mode.
Since you're not doing that, is there really any reason for this
indirection? Why not just __raw_readq, __raw_writeq etc. directly?
Paul.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-25 10:14:12
On 2/25/19 4:50 AM, Michael Ellerman wrote:
Cédric Le Goater [off-list ref] writes:
quoted
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/opal-api.h | 11 ++-
arch/powerpc/include/asm/opal.h | 7 ++
arch/powerpc/include/asm/xive.h | 14 +++
arch/powerpc/sysdev/xive/native.c | 99 +++++++++++++++++++
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
5 files changed, 130 insertions(+), 4 deletions(-)
You should only be defining the calls you need, leaving gaps for other
things, and you need to retain OPAL_LAST. So it should look more like:
-#define OPAL_LAST 167
+#define OPAL_XIVE_GET_VP_STATE 170
+#define OPAL_LAST 170
Also I can't merge this until it's merged into skiboot.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-02-25 11:14:45
Hello Paolo,
On 2/25/19 4:33 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:35PM +0100, Cédric Le Goater wrote:
quoted
Some KVM devices will want to handle special mappings related to the
underlying HW. For instance, the XIVE interrupt controller of the
POWER9 processor has MMIO pages for thread interrupt management and
for interrupt source control that need to be exposed to the guest when
the OS has the required support.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Ah, when I suggested mmap() on the base device fd, I hadn't realized
there wasn't a facility for that yet.
Have you discussed this with Paolo?
Not yet.
We'll need some core KVM buy in to merge this.
Here is an extension of the KVM device to allow special mappings.
Something we would need for the support of the POWER9 XIVE interrupt
controller.
There are two MMIOs we need to expose to the guest :
1. HW MMIO controlling of the interrupt presenter registers (TIMA)
2. HW MMIO of the interrupt sources for interrupt management (ESB)
The TIMA could have been exposed with a page offset in the vCPU mapping
but as it only makes sense when the XIVE interrupt mode is active, we
chose to use directly the KVM device fd for that. Is that ok ?
An alternate solution is to use a device ioctl to allocate an anon fd
and do the mapping, but that seems like extra fuss for the same result.
Thanks,
C.
From: David Gibson <hidden> Date: 2019-02-26 04:26:14
On Mon, Feb 25, 2019 at 11:11:58AM +0100, Cédric Le Goater wrote:
On 2/25/19 4:50 AM, Michael Ellerman wrote:
quoted
Cédric Le Goater [off-list ref] writes:
quoted
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/opal-api.h | 11 ++-
arch/powerpc/include/asm/opal.h | 7 ++
arch/powerpc/include/asm/xive.h | 14 +++
arch/powerpc/sysdev/xive/native.c | 99 +++++++++++++++++++
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
5 files changed, 130 insertions(+), 4 deletions(-)
You should only be defining the calls you need, leaving gaps for other
things, and you need to retain OPAL_LAST. So it should look more like:
-#define OPAL_LAST 167
+#define OPAL_XIVE_GET_VP_STATE 170
+#define OPAL_LAST 170
Also I can't merge this until it's merged into skiboot.
OK. Let's start with skiboot.
Yeah.. where are we at with skiboot in general. We can't test this
downstream until we have a released skiboot with the necessary
support.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Paul Mackerras <hidden> Date: 2019-02-26 05:26:26
On Mon, Feb 25, 2019 at 01:10:12PM +1100, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
quoted
+ /*
+ * If the source doesn't already have an IPI, allocate
+ * one and get the corresponding data
+ */
+ if (!state->ipi_number) {
+ state->ipi_number = xive_native_alloc_irq();
+ if (state->ipi_number == 0) {
+ pr_err("Failed to allocate IRQ !\n");
+ return -ENXIO;
+ }
+ xive_native_populate_irq_data(state->ipi_number,
+ &state->ipi_data);
+ pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n", __func__,
+ state->ipi_number, irq);
+ }
+
+ arch_spin_lock(&sb->lock);
Why the direct call to arch_spin_lock() rather than just spin_lock()?
He's sharing data structures with the xics-on-xive code, and that code
has a real-mode variant, and in real mode we don't want to risk
invoking lockdep code. Hence sb->lock is an arch_spinlock_t, and he
has to use arch_spin_lock() on it.
Paul.
From: Paul Mackerras <hidden> Date: 2019-02-26 05:28:09
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
This is confusing. What's the difference between an "eq attribute"
and an "eq attribute value"? Is the first actually a queue index or
a queue identifier?
Also, the kvm_ppc_xive_eq is not 64 bits, so the comment above it is
wrong. Maybe you meant "64-byte"?
[snip]
+ page = gfn_to_page(kvm, gpa_to_gfn(kvm_eq.qpage));
+ if (is_error_page(page)) {
+ pr_warn("Couldn't get guest page for %llx!\n", kvm_eq.qpage);
+ return -ENOMEM;
+ }
+ qaddr = page_to_virt(page) + (kvm_eq.qpage & ~PAGE_MASK);
Isn't this assuming that we can map the whole queue with a single
gfn_to_page? That would only be true if kvm_eq.qsize <= PAGE_SHIFT.
What happens if kvm_eq.qsize > PAGE_SHIFT?
Paul.
From: Paolo Bonzini <pbonzini@redhat.com> Date: 2019-02-26 12:54:35
On 25/02/19 11:57, Cédric Le Goater wrote:
Hello Paolo,
On 2/25/19 4:33 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:35PM +0100, Cédric Le Goater wrote:
quoted
Some KVM devices will want to handle special mappings related to the
underlying HW. For instance, the XIVE interrupt controller of the
POWER9 processor has MMIO pages for thread interrupt management and
for interrupt source control that need to be exposed to the guest when
the OS has the required support.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Ah, when I suggested mmap() on the base device fd, I hadn't realized
there wasn't a facility for that yet.
Have you discussed this with Paolo?
Not yet.
quoted
We'll need some core KVM buy in to merge this.
Here is an extension of the KVM device to allow special mappings.
Something we would need for the support of the POWER9 XIVE interrupt
controller.
There are two MMIOs we need to expose to the guest :
1. HW MMIO controlling of the interrupt presenter registers (TIMA)
2. HW MMIO of the interrupt sources for interrupt management (ESB)
The TIMA could have been exposed with a page offset in the vCPU mapping
but as it only makes sense when the XIVE interrupt mode is active, we
chose to use directly the KVM device fd for that. Is that ok ?
An alternate solution is to use a device ioctl to allocate an anon fd
and do the mapping, but that seems like extra fuss for the same result.
It's okay, it's a natural extension to dev_ops - but thanks for asking
anyway. :)
Paolo
From: David Gibson <hidden> Date: 2019-02-26 23:38:34
On Tue, Feb 26, 2019 at 03:25:15PM +1100, Paul Mackerras wrote:
On Mon, Feb 25, 2019 at 01:10:12PM +1100, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
quoted
+ /*
+ * If the source doesn't already have an IPI, allocate
+ * one and get the corresponding data
+ */
+ if (!state->ipi_number) {
+ state->ipi_number = xive_native_alloc_irq();
+ if (state->ipi_number == 0) {
+ pr_err("Failed to allocate IRQ !\n");
+ return -ENXIO;
+ }
+ xive_native_populate_irq_data(state->ipi_number,
+ &state->ipi_data);
+ pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n", __func__,
+ state->ipi_number, irq);
+ }
+
+ arch_spin_lock(&sb->lock);
Why the direct call to arch_spin_lock() rather than just spin_lock()?
He's sharing data structures with the xics-on-xive code, and that code
has a real-mode variant, and in real mode we don't want to risk
invoking lockdep code. Hence sb->lock is an arch_spinlock_t, and he
has to use arch_spin_lock() on it.
Ah, right.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-02-26 23:40:05
On Tue, Feb 26, 2019 at 01:52:39PM +0100, Paolo Bonzini wrote:
On 25/02/19 11:57, Cédric Le Goater wrote:
quoted
Hello Paolo,
On 2/25/19 4:33 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:35PM +0100, Cédric Le Goater wrote:
quoted
Some KVM devices will want to handle special mappings related to the
underlying HW. For instance, the XIVE interrupt controller of the
POWER9 processor has MMIO pages for thread interrupt management and
for interrupt source control that need to be exposed to the guest when
the OS has the required support.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Ah, when I suggested mmap() on the base device fd, I hadn't realized
there wasn't a facility for that yet.
Have you discussed this with Paolo?
Not yet.
quoted
We'll need some core KVM buy in to merge this.
Here is an extension of the KVM device to allow special mappings.
Something we would need for the support of the POWER9 XIVE interrupt
controller.
There are two MMIOs we need to expose to the guest :
1. HW MMIO controlling of the interrupt presenter registers (TIMA)
2. HW MMIO of the interrupt sources for interrupt management (ESB)
The TIMA could have been exposed with a page offset in the vCPU mapping
but as it only makes sense when the XIVE interrupt mode is active, we
chose to use directly the KVM device fd for that. Is that ok ?
An alternate solution is to use a device ioctl to allocate an anon fd
and do the mapping, but that seems like extra fuss for the same result.
It's okay, it's a natural extension to dev_ops - but thanks for asking
anyway. :)
Ok, cool.
Given that, do you want to merge directly - since this looks sound
enough, even though the rest of the series needs some polish? Or
would you prefer it to come in via Paulus' tree?
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-12 11:26:16
On 2/25/19 1:08 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:26PM +0100, Cédric Le Goater wrote:
quoted
This is the basic framework for the new KVM device supporting the XIVE
native exploitation mode. The user interface exposes a new KVM device
to be created by QEMU when running on a L0 hypervisor only. Support
for nested guests is not available yet.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 8 +
arch/powerpc/include/uapi/asm/kvm.h | 3 +
include/uapi/linux/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 7 +-
arch/powerpc/kvm/book3s_xive_native.c | 191 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 ++
arch/powerpc/kvm/Makefile | 2 +-
8 files changed, 231 insertions(+), 2 deletions(-)
create mode 100644 arch/powerpc/kvm/book3s_xive_native.c
create mode 100644 Documentation/virtual/kvm/devices/xive.txt
@@ -0,0 +1,191 @@+// SPDX-License-Identifier: GPL-2.0+/*+*Copyright(c)2017-2019,IBMCorporation.+*/++#define pr_fmt(fmt) "xive-kvm: " fmt++#include<linux/anon_inodes.h>+#include<linux/kernel.h>+#include<linux/kvm_host.h>+#include<linux/err.h>+#include<linux/gfp.h>+#include<linux/spinlock.h>+#include<linux/delay.h>+#include<linux/percpu.h>+#include<linux/cpumask.h>+#include<asm/uaccess.h>+#include<asm/kvm_book3s.h>+#include<asm/kvm_ppc.h>+#include<asm/hvcall.h>+#include<asm/xics.h>+#include<asm/xive.h>+#include<asm/xive-regs.h>+#include<asm/debug.h>+#include<asm/debugfs.h>+#include<asm/time.h>+#include<asm/opal.h>++#include<linux/debugfs.h>+#include<linux/seq_file.h>++#include"book3s_xive.h"++staticintkvmppc_xive_native_set_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticintkvmppc_xive_native_get_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+return-ENXIO;+}++staticintkvmppc_xive_native_has_attr(structkvm_device*dev,+structkvm_device_attr*attr)+{+switch(attr->group){+caseKVM_DEV_XIVE_GRP_CTRL:+break;+}+return-ENXIO;+}++staticvoidkvmppc_xive_native_free(structkvm_device*dev)+{+structkvmppc_xive*xive=dev->private;+structkvm*kvm=xive->kvm;++debugfs_remove(xive->dentry);++pr_devel("Destroying xive native device\n");++if(kvm)+kvm->arch.xive=NULL;++if(xive->vp_base!=XIVE_INVALID_VP)+xive_native_free_vp_block(xive->vp_base);++kfree(xive);+kfree(dev);+}++staticintkvmppc_xive_native_create(structkvm_device*dev,u32type)+{+structkvmppc_xive*xive;+structkvm*kvm=dev->kvm;+intret=0;++pr_devel("Creating xive native device\n");++if(kvm->arch.xive)+return-EEXIST;++xive=kzalloc(sizeof(*xive),GFP_KERNEL);+if(!xive)+return-ENOMEM;++dev->private=xive;+xive->dev=dev;+xive->kvm=kvm;+kvm->arch.xive=xive;++/* We use the default queue size set by the host */
IIUC the queue is examined directly by the guest, so the guest must
know its size. In which case letting the host decide the size would
be a problem for migration.
yes. This is a left over from the XICS-over-XIVE KVM device. I will
remove the code, we don't use it.
Thanks,
C.
quoted
+ xive->q_order = xive_native_default_eq_shift();
+ if (xive->q_order < PAGE_SHIFT)
+ xive->q_page_order = 0;
+ else
+ xive->q_page_order = xive->q_order - PAGE_SHIFT;
+
+ /*
+ * Allocate a bunch of VPs. KVM_MAX_VCPUS is a large value for
+ * a default. Getting the max number of CPUs the VM was
+ * configured with would improve our usage of the XIVE VP space.
+ */
+ xive->vp_base = xive_native_alloc_vp_block(KVM_MAX_VCPUS);
+ pr_devel("VP_Base=%x\n", xive->vp_base);
+
+ if (xive->vp_base == XIVE_INVALID_VP)
+ ret = -ENOMEM;
+
+ xive->single_escalation = xive_native_has_single_escalation();
+
+ if (ret)
+ kfree(xive);
+
+ return ret;
+}
+
+static int xive_native_debug_show(struct seq_file *m, void *private)
+{
+ struct kvmppc_xive *xive = m->private;
+ struct kvm *kvm = xive->kvm;
+
+ if (!kvm)
+ return 0;
+
+ return 0;
+}
+
+static int xive_native_debug_open(struct inode *inode, struct file *file)
+{
+ return single_open(file, xive_native_debug_show, inode->i_private);
+}
+
+static const struct file_operations xive_native_debug_fops = {
+ .open = xive_native_debug_open,
+ .read = seq_read,
+ .llseek = seq_lseek,
+ .release = single_release,
+};
+
+static void xive_native_debugfs_init(struct kvmppc_xive *xive)
+{
+ char *name;
+
+ name = kasprintf(GFP_KERNEL, "kvm-xive-%p", xive);
+ if (!name) {
+ pr_err("%s: no memory for name\n", __func__);
+ return;
+ }
+
+ xive->dentry = debugfs_create_file(name, 0444, powerpc_debugfs_root,
+ xive, &xive_native_debug_fops);
+
+ pr_debug("%s: created %s\n", __func__, name);
+ kfree(name);
+}
+
+static void kvmppc_xive_native_init(struct kvm_device *dev)
+{
+ struct kvmppc_xive *xive = (struct kvmppc_xive *)dev->private;
+
+ /* Register some debug interfaces */
+ xive_native_debugfs_init(xive);
+}
+
+struct kvm_device_ops kvm_xive_native_ops = {
+ .name = "kvm-xive-native",
+ .create = kvmppc_xive_native_create,
+ .init = kvmppc_xive_native_init,
+ .destroy = kvmppc_xive_native_free,
+ .set_attr = kvmppc_xive_native_set_attr,
+ .get_attr = kvmppc_xive_native_get_attr,
+ .has_attr = kvmppc_xive_native_has_attr,
+};
+
+void kvmppc_xive_native_init_module(void)
+{
+ ;
+}
+
+void kvmppc_xive_native_exit_module(void)
+{
+ ;
+}
@@ -0,0 +1,19 @@+POWER9 eXternal Interrupt Virtualization Engine (XIVE Gen1)+==========================================================++Device types supported:+ KVM_DEV_TYPE_XIVE POWER9 XIVE Interrupt Controller generation 1++This device acts as a VM interrupt controller. It provides the KVM+interface to configure the interrupt sources of a VM in the underlying+POWER9 XIVE interrupt controller.++Only one XIVE instance may be instantiated. A guest XIVE device+requires a POWER9 host and the guest OS should have support for the+XIVE native exploitation interrupt mode. If not, it should run using+the legacy interrupt mode, referred as XICS (POWER7/8).++* Groups:++ 1. KVM_DEV_XIVE_GRP_CTRL+ Provides global controls on the device
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-12 14:24:13
On 2/25/19 1:35 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:27PM +0100, Cédric Le Goater wrote:
quoted
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
Internally, the interface to the new KVM device is protected with a
new interrupt mode: KVMPPC_IRQ_XIVE.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_host.h | 1 +
arch/powerpc/include/asm/kvm_ppc.h | 13 +++
arch/powerpc/kvm/book3s_xive.h | 6 ++
include/uapi/linux/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive.c | 67 +++++++-----
arch/powerpc/kvm/book3s_xive_native.c | 144 ++++++++++++++++++++++++++
arch/powerpc/kvm/powerpc.c | 33 ++++++
Documentation/virtual/kvm/api.txt | 9 ++
8 files changed, 246 insertions(+), 28 deletions(-)
@@ -31,6 +31,128 @@#include"book3s_xive.h"+staticvoidkvmppc_xive_native_cleanup_queue(structkvm_vcpu*vcpu,intprio)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+structxive_q*q=&xc->queues[prio];++xive_native_disable_queue(xc->vp_id,q,prio);+if(q->qpage){+put_page(virt_to_page(q->qpage));+q->qpage=NULL;+}+}++voidkvmppc_xive_native_cleanup_vcpu(structkvm_vcpu*vcpu)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+inti;++if(!kvmppc_xive_enabled(vcpu))+return;++if(!xc)+return;++pr_devel("native_cleanup_vcpu(cpu=%d)\n",xc->server_num);++/* Ensure no interrupt is still routed to that VP */+xc->valid=false;+kvmppc_xive_disable_vcpu_interrupts(vcpu);++/* Disable the VP */+xive_native_disable_vp(xc->vp_id);++/* Free the queues & associated interrupts */+for(i=0;i<KVMPPC_XIVE_Q_COUNT;i++){+/* Free the escalation irq */+if(xc->esc_virq[i]){+free_irq(xc->esc_virq[i],vcpu);+irq_dispose_mapping(xc->esc_virq[i]);+kfree(xc->esc_virq_names[i]);+xc->esc_virq[i]=0;+}++/* Free the queue */+kvmppc_xive_native_cleanup_queue(vcpu,i);+}++/* Free the VP */+kfree(xc);++/* Cleanup the vcpu */+vcpu->arch.irq_type=KVMPPC_IRQ_DEFAULT;+vcpu->arch.xive_vcpu=NULL;+}++intkvmppc_xive_native_connect_vcpu(structkvm_device*dev,+structkvm_vcpu*vcpu,u32cpu)+{+structkvmppc_xive*xive=dev->private;+structkvmppc_xive_vcpu*xc;+intrc;++pr_devel("native_connect_vcpu(cpu=%d)\n",cpu);++if(dev->ops!=&kvm_xive_native_ops){+pr_devel("Wrong ops !\n");+return-EPERM;+}+if(xive->kvm!=vcpu->kvm)+return-EPERM;+if(vcpu->arch.irq_type!=KVMPPC_IRQ_DEFAULT)+return-EBUSY;+if(kvmppc_xive_find_server(vcpu->kvm,cpu)){
You haven't taken the kvm->lock yet, so couldn't a race mean a
duplicate server gets inserted after you make this check?
Similarly you don't verify this is NULL after taking the lock, so
couldn't another thread race and make a connect which gets clobbered
here?
Yes. this is not very safe ... We need to clean up all the KVM device
methods doing the connection of the presenter to the vCPU AFAICT.
I will fix the XIVE native one for now.
And also, this CPU parameter is useless. There is no reason to connect
a vCPU from another vCPU.
Hrm. This ties the internal VP id to the userspace chosen server
number, which isn't ideal. It puts a constraint on those server
numbers that you wouldn't otherwise have.
Ah yes. I should be using the kvmppc_pack_vcpu_id() like we do for
the XICS-over-XIVE device probably. I need to check that it is correct
in this mode.
Thanks,
C.
quoted
+ xc->valid = true;
+
+ rc = xive_native_get_vp_info(xc->vp_id, &xc->vp_cam, &xc->vp_chip_id);
+ if (rc) {
+ pr_err("Failed to get VP info from OPAL: %d\n", rc);
+ goto bail;
+ }
+
+ /*
+ * Enable the VP first as the single escalation mode will
+ * affect escalation interrupts numbering
+ */
+ rc = xive_native_enable_vp(xc->vp_id, xive->single_escalation);
+ if (rc) {
+ pr_err("Failed to enable VP in OPAL: %d\n", rc);
+ goto bail;
+ }
+
+ /* Configure VCPU fields for use by assembly push/pull */
+ vcpu->arch.xive_saved_state.w01 = cpu_to_be64(0xff000000);
+ vcpu->arch.xive_cam_word = cpu_to_be32(xc->vp_cam | TM_QW1W2_VO);
+
+ /* TODO: initialize queues ? */
+
+bail:
+ vcpu->arch.irq_type = KVMPPC_IRQ_XIVE;
+ mutex_unlock(&vcpu->kvm->lock);
+ if (rc)
+ kvmppc_xive_native_cleanup_vcpu(vcpu);
+
+ return rc;
+}
+
static int kvmppc_xive_native_set_attr(struct kvm_device *dev,
struct kvm_device_attr *attr)
{
@@ -570,6 +570,12 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)caseKVM_CAP_PPC_GET_CPU_CHAR:r=1;break;+#ifdef CONFIG_KVM_XIVE+caseKVM_CAP_PPC_IRQ_XIVE:+/* only for PowerNV */+r=!!cpu_has_feature(CPU_FTR_HVMODE);+break;+#endifcaseKVM_CAP_PPC_ALLOC_HTAB:r=hv_enabled;
@@ -4458,6 +4458,15 @@ struct kvm_sync_regs { struct kvm_vcpu_events events; };+6.75 KVM_CAP_PPC_IRQ_XIVE++Architectures: ppc+Target: vcpu+Parameters: args[0] is the XIVE device fd+ args[1] is the XIVE CPU number (server ID) for this vcpu++This capability connects the vcpu to an in-kernel XIVE device.+ 7. Capabilities that can be enabled on VMs ------------------------------------------
Hrm. This ties the internal VP id to the userspace chosen server
number, which isn't ideal. It puts a constraint on those server
numbers that you wouldn't otherwise have.
We should probably do the same as the xics-on-xive code, which is to
put the server number through kvmppc_pack_vcpu_id(), which is a
folding function that maps the QEMU vcpu id (which is the server
number) down to the range 0..KVM_MAX_VCPUS-1, and works for the
allocation patterns used in the various vSMT modes.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-12 15:29:06
On 2/25/19 3:10 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
quoted
The associated HW interrupt source is simply allocated at the OPAL/HW
level and then MASKED. KVM only needs to know about its type: LSI or
MSI.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 5 +
arch/powerpc/kvm/book3s_xive.h | 10 ++
arch/powerpc/kvm/book3s_xive.c | 8 +-
arch/powerpc/kvm/book3s_xive_native.c | 114 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 +++
5 files changed, 148 insertions(+), 4 deletions(-)
We do align these in qemu, but I don't see that the kernel part
cares: as far as it's concerned only one of XICS or XIVE is active at
a time, and the irq numbers are chosen by userspace.
There is some relation with userspace nevertheless. The KVM device does
not remap the numbers to some other range today and the limits are fixed
values. Checks are being done in the has_attr() and the set_attr().
quoted
+ */
+#define KVMPPC_XIVE_FIRST_IRQ 0
+#define KVMPPC_XIVE_NR_IRQS KVMPPC_XICS_NR_IRQS
+
/*
* State for one guest irq source.
*
I wonder if we should rename this book3s_xics_on_xive.c or something
at some point, I keep getting confused because I forget that this is
only dealing with host xive, not guest xive.
I am fine with renaming. Any objections ? book3s_xics_p9.c ?
quoted
@@ -1485,8 +1485,8 @@ static int xive_get_source(struct kvmppc_xive *xive, long irq, u64 addr) return 0; }-static struct kvmppc_xive_src_block *xive_create_src_block(struct kvmppc_xive *xive,- int irq)+struct kvmppc_xive_src_block *kvmppc_xive_create_src_block(+ struct kvmppc_xive *xive, int irq) { struct kvm *kvm = xive->kvm; struct kvmppc_xive_src_block *sb;
It's odd that this function, now used from the xive-on-xive path as
well as the xics-on-xive path references KVMPPC_XICS_ICS_SHIFT a few
lines down from this change.
Yes. This is because of the definition of the struct kvmppc_xive_src_block.
We could introduce new defines for XIVE or a common set of defines for
XICS and XIVE.
quoted
@@ -1565,7 +1565,7 @@ static int xive_set_source(struct kvmppc_xive *xive, long irq, u64 addr) sb = kvmppc_xive_find_source(xive, irq, &idx); if (!sb) { pr_devel("No source, creating source block...\n");- sb = xive_create_src_block(xive, irq);+ sb = kvmppc_xive_create_src_block(xive, irq); if (!sb) { pr_devel("Failed to create block...\n"); return -ENOMEM;
@@ -153,12 +176,89 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,+u64addr)+{+structkvmppc_xive_src_block*sb;+structkvmppc_xive_irq_state*state;+u64__user*ubufp=(u64__user*)addr;+u64val;+u16idx;++pr_devel("%s irq=0x%lx\n",__func__,irq);++if(irq<KVMPPC_XIVE_FIRST_IRQ||irq>=KVMPPC_XIVE_NR_IRQS)+return-E2BIG;++sb=kvmppc_xive_find_source(xive,irq,&idx);+if(!sb){+pr_debug("No source, creating source block...\n");+sb=kvmppc_xive_create_src_block(xive,irq);+if(!sb){+pr_err("Failed to create block...\n");+return-ENOMEM;+}+}+state=&sb->irq_state[idx];++if(get_user(val,ubufp)){+pr_err("fault getting user info !\n");+return-EFAULT;+}
You should validate the value loaded here to check it doesn't have any
bits set we don't know about.
ok
quoted
+
+ /*
+ * If the source doesn't already have an IPI, allocate
+ * one and get the corresponding data
+ */
+ if (!state->ipi_number) {
+ state->ipi_number = xive_native_alloc_irq();
+ if (state->ipi_number == 0) {
+ pr_err("Failed to allocate IRQ !\n");
+ return -ENXIO;
+ }
+ xive_native_populate_irq_data(state->ipi_number,
+ &state->ipi_data);
+ pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n", __func__,
+ state->ipi_number, irq);
+ }
+
+ arch_spin_lock(&sb->lock);
Why the direct call to arch_spin_lock() rather than just spin_lock()?
Paul answered this question but may be I should make the effort to
decouple both devices on this aspect.
Thanks,
C.
quoted
+
+ /* Restore LSI state */
+ if (val & KVM_XIVE_LEVEL_SENSITIVE) {
+ state->lsi = true;
+ if (val & KVM_XIVE_LEVEL_ASSERTED)
+ state->asserted = true;
+ pr_devel(" LSI ! Asserted=%d\n", state->asserted);
+ }
+
+ /* Mask IRQ to start with */
+ state->act_server = 0;
+ state->act_priority = MASKED;
+ xive_vm_esb_load(&state->ipi_data, XIVE_ESB_SET_PQ_01);
+ xive_native_configure_irq(state->ipi_number, 0, MASKED, 0);
+
+ /* Increment the number of valid sources and mark this one valid */
+ if (!state->valid)
+ xive->src_count++;
+ state->valid = true;
+
+ arch_spin_unlock(&sb->lock);
+
+ return 0;
+}
+
static int kvmppc_xive_native_set_attr(struct kvm_device *dev,
struct kvm_device_attr *attr)
{
+ struct kvmppc_xive *xive = dev->private;
+
switch (attr->group) {
case KVM_DEV_XIVE_GRP_CTRL:
break;
+ case KVM_DEV_XIVE_GRP_SOURCE:
+ return kvmppc_xive_native_set_source(xive, attr->attr,
+ attr->addr);
}
return -ENXIO;
}
@@ -175,6 +275,11 @@ static int kvmppc_xive_native_has_attr(struct kvm_device *dev, switch (attr->group) { case KVM_DEV_XIVE_GRP_CTRL: break;+ case KVM_DEV_XIVE_GRP_SOURCE:+ if (attr->attr >= KVMPPC_XIVE_FIRST_IRQ &&+ attr->attr < KVMPPC_XIVE_NR_IRQS)+ return 0;+ break; } return -ENXIO; }
@@ -17,3 +17,18 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device++ 2. KVM_DEV_XIVE_GRP_SOURCE (write only)+ Initializes a new source in the XIVE device and mask it.+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 2 | 1 | 0+ values: | unused | level | type+ - type: 0:MSI 1:LSI+ - level: assertion level in case of an LSI.+ Errors:+ -E2BIG: Interrupt source number is out of range+ -ENOMEM: Could not create a new source block+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: Could not allocate underlying HW interrupt
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-12 17:02:43
On 2/25/19 3:39 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
I think we need to add some kind of flags to differentiate the hcall
H_INT_SET_QUEUE_CONFIG from the restore of the EQ. The hcall does
not need OPAL support call and this could help in the code transition.
But without OPAL support, we won't have migration. Would that be of
any use ?
@@ -73,6 +73,8 @@ struct xive_q {u32esc_irq;atomic_tcount;atomic_tpending_count;+u64guest_qpage;+u32guest_qsize;};/* Global enable flags for the XIVE support */
@@ -341,6 +341,201 @@ static int kvmppc_xive_native_set_source_config(struct kvmppc_xive *xive,priority,eisn);}+staticintxive_native_validate_queue_size(u32qsize)+{+switch(qsize){+case12:+case16:+case21:+case24:+case0:+return0;+default:+return-EINVAL;+}+}++staticintkvmppc_xive_native_set_queue_config(structkvmppc_xive*xive,+longeq_idx,u64addr)+{+structkvm*kvm=xive->kvm;+structkvm_vcpu*vcpu;+structkvmppc_xive_vcpu*xc;+void__user*ubufp=(u64__user*)addr;+u32server;+u8priority;+structkvm_ppc_xive_eqkvm_eq;+intrc;+__be32*qaddr=0;+structpage*page;+structxive_q*q;++/*+*Demanglepriority/servertuplefromtheEQindex+*/+priority=(eq_idx&KVM_XIVE_EQ_PRIORITY_MASK)>>+KVM_XIVE_EQ_PRIORITY_SHIFT;+server=(eq_idx&KVM_XIVE_EQ_SERVER_MASK)>>+KVM_XIVE_EQ_SERVER_SHIFT;++if(copy_from_user(&kvm_eq,ubufp,sizeof(kvm_eq)))+return-EFAULT;++vcpu=kvmppc_xive_find_server(kvm,server);+if(!vcpu){+pr_err("Can't find server %d\n",server);+return-ENOENT;+}+xc=vcpu->arch.xive_vcpu;++if(priority!=xive_prio_from_guest(priority)){+pr_err("Trying to restore invalid queue %d for VCPU %d\n",+priority,server);+return-EINVAL;+}+q=&xc->queues[priority];
You need to validate the 'flags' field (AFAICT we don't actually have
any flags yet, so it's only valid it if is 0.
Well, we should set the ESCALATE flags and ALWAYS_NOTIFY also but this
is already set by xive_native_configure_queue(). I will take a closer look
and document.
Nit: I don't think ENOMEM is the right error here. ENOMEM indicates
that the kernel couldn't allocate enough memory to complete whatever
you asked. Here the problem is the user supplied a bad guest address,
which is a rather different error. EFAULT is closer, but still not
quite right, since it could be a valid user address but not a valid
guest address. There are probably existing KVM calls that could hit
this problem, I wonder what they use.
I have seen a -EINVAL (s390) and a -EFAULT (x86)
Thanks,
C.
@@ -52,3 +52,32 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENXIO: CPU event queues not configured or configuration of the underlying HW interrupt failed -EBUSY: No CPU available to serve interrupt++ 4. KVM_DEV_XIVE_GRP_EQ_CONFIG (read-write)+ Configures an event queue of a CPU+ Attributes:+ EQ descriptor identifier (64-bit)+ The EQ descriptor identifier is a tuple (server, priority) :+ bits: | 63 .... 32 | 31 .. 3 | 2 .. 0+ values: | unused | server | priority+ The kvm_device_attr.addr points to :+ struct kvm_ppc_xive_eq {+ __u32 flags;+ __u32 qsize;+ __u64 qpage;+ __u32 qtoggle;+ __u32 qindex;+ __u8 pad[40];+ };+ - flags: queue flags+ - qsize: queue size (power of 2)+ - qpage: real address of queue+ - qtoggle: current queue toggle bit+ - qindex: current queue index+ - pad: reserved for future use+ Errors:+ -ENOENT: Invalid CPU number+ -EINVAL: Invalid priority or invalid queue size+ -EFAULT: Invalid user pointer for attr->addr.+ -ENOMEM: Invalid queue address+ -EIO: Configuration of the underlying HW failed
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-12 18:27:34
On 2/26/19 5:21 AM, David Gibson wrote:
On Mon, Feb 25, 2019 at 11:11:58AM +0100, Cédric Le Goater wrote:
quoted
On 2/25/19 4:50 AM, Michael Ellerman wrote:
quoted
Cédric Le Goater [off-list ref] writes:
quoted
The support for XIVE native exploitation mode in Linux/KVM needs a
couple more OPAL calls to configure the sPAPR guest and to get/set the
state of the XIVE internal structures.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/opal-api.h | 11 ++-
arch/powerpc/include/asm/opal.h | 7 ++
arch/powerpc/include/asm/xive.h | 14 +++
arch/powerpc/sysdev/xive/native.c | 99 +++++++++++++++++++
.../powerpc/platforms/powernv/opal-wrappers.S | 3 +
5 files changed, 130 insertions(+), 4 deletions(-)
You should only be defining the calls you need, leaving gaps for other
things, and you need to retain OPAL_LAST. So it should look more like:
-#define OPAL_LAST 167
+#define OPAL_XIVE_GET_VP_STATE 170
+#define OPAL_LAST 170
Also I can't merge this until it's merged into skiboot.
OK. Let's start with skiboot.
Yeah.. where are we at with skiboot in general. We can't test this
downstream until we have a released skiboot with the necessary
support.
If we add a flag to remove the OPAL call when setting the EQ, you could
test, without migration though.
C.
Similarly you don't verify this is NULL after taking the lock, so
couldn't another thread race and make a connect which gets clobbered
here?
Yes. this is not very safe ... We need to clean up all the KVM device
methods doing the connection of the presenter to the vCPU AFAICT.
I will fix the XIVE native one for now.
And also, this CPU parameter is useless. There is no reason to connect
a vCPU from another vCPU.
Hmm.. I thought the point of the 'cpu' parameter (not a great name) is
that it lets userspace chose the guest visible irq server ID. I think
that's preferable to tying it to an existing cpu id, if possible.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-13 04:35:58
On Tue, Mar 12, 2019 at 06:00:38PM +0100, Cédric Le Goater wrote:
On 2/25/19 3:39 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
I think we need to add some kind of flags to differentiate the hcall
H_INT_SET_QUEUE_CONFIG from the restore of the EQ. The hcall does
not need OPAL support call and this could help in the code
transition.
Hrm. What's the actual difference in the semantics between the two
cases. The guest shouldn't have awareness of whether or not OPAL is
involved.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 08:12:40
On 2/25/19 5:15 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:39PM +0100, Cédric Le Goater wrote:
quoted
The 'destroy' method is currently used to destroy all devices when the
VM is destroyed after the vCPUs have been freed.
This new KVM ioctl exposes the same KVM device method. It acts as a
software reset of the VM to 'destroy' selected devices when necessary
and perform the required cleanups on the vCPUs. Called with the
kvm->lock.
The 'destroy' method could be improved by returning an error code.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
Again, has this been discussed with Paolo and/or other KVM core
people?
And there, I should problably drop a ref count on the VM. I am not sure
of that.
Thanks,
C.
quoted
+ return 0;
+}
+
static long kvm_vm_ioctl_check_extension_generic(struct kvm *kvm, long arg)
{
switch (arg) {
@@ -3270,6 +3294,20 @@ static long kvm_vm_ioctl(struct file *filp, r = 0; break; }+ case KVM_DESTROY_DEVICE: {+ struct kvm_destroy_device dd;++ r = -EFAULT;+ if (copy_from_user(&dd, argp, sizeof(dd)))+ goto out;++ r = kvm_ioctl_destroy_device(kvm, &dd);+ if (r)+ goto out;++ r = 0;+ break;+ } case KVM_CHECK_EXTENSION: r = kvm_vm_ioctl_check_extension_generic(kvm, arg); break;
@@ -3857,6 +3857,25 @@ number of valid entries in the 'entries' array, which is then filled. 'index' and 'flags' fields in 'struct kvm_cpuid_entry2' are currently reserved, userspace should not expect to get any particular value there.+4.119 KVM_DESTROY_DEVICE++Capability: KVM_CAP_DEVICE_CTRL+Type: vm ioctl+Parameters: struct kvm_destroy_device (in)+Returns: 0 on success, -1 on error+Errors:+ ENODEV: The device type is unknown or unsupported++ Other error conditions may be defined by individual device types or+ have their standard meanings.++Destroys an emulated device in the kernel.++struct kvm_destroy_device {+ __u32 fd; /* in: device handle */+ __u32 flags; /* unused */+};+ 5. The kvm_run structure ------------------------
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 08:19:36
On 2/25/19 5:18 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:40PM +0100, Cédric Le Goater wrote:
quoted
When the VM boots, the CAS negotiation process determines which
interrupt mode to use and invokes a machine reset. At that time, the
previous KVM interrupt device is 'destroyed' before the chosen one is
created. Upon destruction, the vCPU interrupt presenters using the KVM
device should be cleared first, the machine will reconnect them later
to the new device after it is created.
When using the KVM device, there is still a race window with the early
checks in kvmppc_native_connect_vcpu(). Yet to be fixed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xics.c | 19 +++++++++++++
arch/powerpc/kvm/book3s_xive.c | 39 +++++++++++++++++++++++++--
arch/powerpc/kvm/book3s_xive_native.c | 16 +++++++++++
3 files changed, 72 insertions(+), 2 deletions(-)
This is the KVM XICS-on-XIVE device and its IRQ type is KVMPPC_IRQ_XICS.
So this is correct :/
May be we should introduce a KVMPPC_IRQ_XICS_ON_XIVE macro to clarify.
quoted
+ return;
+
+ if (!xc)
+ return;
+
pr_devel("cleanup_vcpu(cpu=%d)\n", xc->server_num);
+ xive = xc->xive;
+
/* Ensure no interrupt is still routed to that VP */
xc->valid = false;
kvmppc_xive_disable_vcpu_interrupts(vcpu);
@@ -1163,7 +1175,7 @@ int kvmppc_xive_connect_vcpu(struct kvm_device *dev, } if (xive->kvm != vcpu->kvm) return -EPERM;- if (vcpu->arch.irq_type)+ if (vcpu->arch.irq_type != KVMPPC_IRQ_DEFAULT) return -EBUSY; if (kvmppc_xive_find_server(vcpu->kvm, cpu)) { pr_devel("Duplicate !\n");
@@ -1833,8 +1845,31 @@ static void kvmppc_xive_free(struct kvm_device *dev) { struct kvmppc_xive *xive = dev->private; struct kvm *kvm = xive->kvm;+ struct kvm_vcpu *vcpu; int i;+ /*+ * When destroying the VM, the vCPUs are destroyed first and+ * the vCPU list should be empty. If this is not the case,+ * then we are simply destroying the device and we should+ * clean up the vCPU interrupt presenters first.+ */+ if (atomic_read(&kvm->online_vcpus) != 0) {+ /*+ * call kick_all_cpus_sync() to ensure that all CPUs+ * have executed any pending interrupts+ */+ if (is_kvmppc_hv_enabled(kvm))+ kick_all_cpus_sync();++ /*+ * TODO: There is still a race window with the early+ * checks in kvmppc_native_connect_vcpu()+ */+ kvm_for_each_vcpu(i, vcpu, kvm)+ kvmppc_xive_cleanup_vcpu(vcpu);+ }+ debugfs_remove(xive->dentry); if (kvm)
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 08:47:59
On 3/13/19 5:03 AM, David Gibson wrote:
On Tue, Mar 12, 2019 at 06:00:38PM +0100, Cédric Le Goater wrote:
quoted
On 2/25/19 3:39 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
I think we need to add some kind of flags to differentiate the hcall
H_INT_SET_QUEUE_CONFIG from the restore of the EQ. The hcall does
not need OPAL support call and this could help in the code
transition.
Hrm. What's the actual difference in the semantics between the two
cases.
None.
But we don't need to set the EQ state in the case of the HCALL and it's
(very) practical to run guests with XIVE enabled without the OPAL support.
The latter is the main reason clearly.
Thinking of it, I could test the EQ toggle bit and index passed to KVM
and skip the OPAL call which restores the EQ state if they are zero.
This is because I know that the OPAL call configuring the EQ resets them.
That will do. No need for a flag.
The guest shouldn't have awareness of whether or not OPAL is involved.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 09:58:55
On 2/26/19 6:24 AM, Paul Mackerras wrote:
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
This is confusing. What's the difference between an "eq attribute"
and an "eq attribute value"? Is the first actually a queue index or
a queue identifier?
The "attribute" qualifier comes from the {get,set,has}_addr methods
of the KVM device. But it is not a well chosen name for the group
KVM_DEV_XIVE_GRP_EQ_CONFIG.
I should be using "eq identifier" and "eq values" or "eq state".
Also, the kvm_ppc_xive_eq is not 64 bits, so the comment above it is
wrong. Maybe you meant "64-byte"?
That was a bad copy paste. I have padded the structure to twice the size
of the XIVE END (the XIVE EQ descriptor in HW) which size is 32 bytes.
I thought that one extra u64 was not enough room for future.
[snip]
quoted
+ page = gfn_to_page(kvm, gpa_to_gfn(kvm_eq.qpage));
+ if (is_error_page(page)) {
+ pr_warn("Couldn't get guest page for %llx!\n", kvm_eq.qpage);
+ return -ENOMEM;
+ }
+ qaddr = page_to_virt(page) + (kvm_eq.qpage & ~PAGE_MASK);
Isn't this assuming that we can map the whole queue with a single
gfn_to_page? That would only be true if kvm_eq.qsize <= PAGE_SHIFT.
What happens if kvm_eq.qsize > PAGE_SHIFT?
Ah yes. Theoretically, it should not happen because we only advertise
64K in the DT for the moment. I should at least add a check. So I will
change the helper xive_native_validate_queue_size() to return -EINVAL
for other page sizes.
Do you think it would be complex to support XIVE EQs using a page larger
than the default one on the guest ?
Thanks,
C.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 11:04:19
On 2/25/19 5:35 AM, Paul Mackerras wrote:
On Fri, Feb 22, 2019 at 12:28:27PM +0100, Cédric Le Goater wrote:
quoted
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
If a bisection happened to land on this commit, we would have KVM
saying it had the ability to support guests using XIVE natively, but
it wouldn't actually work since we don't have all the code that is in
the following patches.
OK. I didn't think migration was a must-have for bisection. I will move
the enablement at end.
Thus, in order to avoid breaking bisection, you should either add the
capability now but have it always return false until the rest of the
code is in place, or else defer the addition of the capability until
the end of the patch series.
I will introduce the capability early in the patchset and return false
as you are proposing. It seems to be the best approach.
@@ -570,6 +570,12 @@ int kvm_vm_ioctl_check_extension(struct kvm *kvm, long ext)caseKVM_CAP_PPC_GET_CPU_CHAR:r=1;break;+#ifdef CONFIG_KVM_XIVE+caseKVM_CAP_PPC_IRQ_XIVE:+/* only for PowerNV */+r=!!cpu_has_feature(CPU_FTR_HVMODE);
Shouldn't this be r = xive_enabled() && !!cpu_has_feature(CPU_FTR_HVMODE)
yes. we need the '__xive_enabled' toggle to be set also :/
It can set to off with the "xive=off" on the command line and on old P9
skiboot. That could be simplified one day.
(or alternatively r = xics_on_xive(), though that would be confusing
to the reader)?
This is correct. I didn't want to use the xics_on_xive() which is not
the capability we are activating.
I will keep the open-coded version.
As it stands this would report true on POWER8, unless I'm missing
something.
Ah yes. I forgot this combination also.
This should not be too complex to fix.
Thanks,
C.
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 12:31:29
On 2/25/19 3:53 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:33PM +0100, Cédric Le Goater wrote:
quoted
When migration of a VM is initiated, a first copy of the RAM is
transferred to the destination before the VM is stopped, but there is
no guarantee that the EQ pages in which the event notification are
queued have not been modified.
To make sure migration will capture a consistent memory state, the
XIVE device should perform a XIVE quiesce sequence to stop the flow of
event notifications and stabilize the EQs. This is the purpose of the
KVM_DEV_XIVE_EQ_SYNC control which will also marks the EQ pages dirty
to force their transfer.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 67 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 ++++++++++
3 files changed, 97 insertions(+)
@@ -640,6 +640,70 @@ static int kvmppc_xive_reset(struct kvmppc_xive *xive)return0;}+staticvoidkvmppc_xive_native_sync_sources(structkvmppc_xive_src_block*sb)+{+intj;++for(j=0;j<KVMPPC_XICS_IRQ_PER_ICS;j++){+structkvmppc_xive_irq_state*state=&sb->irq_state[j];+structxive_irq_data*xd;+u32hw_num;++if(!state->valid)+continue;+if(state->act_priority==MASKED)
Is this correct? If you masked an irq, then immediately did a sync,
couldn't there still be some of the irqs in flight? I thought the
reason we needed a sync was that masking and other such operations
_didn't_ implicitly synchronize.
The struct kvmppc_xive_irq_state reflects the state of the EAS
configuration and not the state of the source. The source is masked
setting the PQ bits to '-Q', which is what is being done before calling
the KVM_DEV_XIVE_EQ_SYNC control.
If a source EAS is configured, OPAL syncs the XIVE IC of the source and
the XIVE IC of the previous target if any.
So I think we are fine.
C.
@@ -23,6 +23,12 @@ the legacy interrupt mode, referred as XICS (POWER7/8). queues. To be used by kexec and kdump. Errors: none+ 1.2 KVM_DEV_XIVE_EQ_SYNC (write only)+ Sync all the sources and queues and mark the EQ pages dirty. This+ to make sure that a consistent memory state is captured when+ migrating the VM.+ Errors: none+ 2. KVM_DEV_XIVE_GRP_SOURCE (write only) Initializes a new source in the XIVE device and mask it. Attributes:
@@ -95,3 +101,26 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -ENOENT: Unknown source number -EINVAL: Not initialized source number, invalid priority or invalid CPU number.++* Migration:++ Saving the state of a VM using the XIVE native exploitation mode+ should follow a specific sequence. When the VM is stopped :++ 1. Mask all sources (PQ=01) to stop the flow of events.++ 2. Sync the XIVE device with the KVM control KVM_DEV_XIVE_EQ_SYNC to+ flush any in-flight event notification and to stabilize the EQs. At+ this stage, the EQ pages are marked dirty to make sure they are+ transferred in the migration sequence.++ 3. Capture the state of the source targeting, the EQs configuration+ and the state of thread interrupt context registers.++ Restore is similar :++ 1. Restore the EQ configuration. As targeting depends on it.+ 2. Restore targeting+ 3. Restore the thread interrupt contexts+ 4. Restore the source states+ 5. Let the vCPU run
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-13 13:21:36
On 2/25/19 4:31 AM, David Gibson wrote:
On Fri, Feb 22, 2019 at 12:28:34PM +0100, Cédric Le Goater wrote:
quoted
At a VCPU level, the state of the thread interrupt management
registers needs to be collected. These registers are cached under the
'xive_saved_state.w01' field of the VCPU when the VPCU context is
pulled from the HW thread. An OPAL call retrieves the backup of the
IPB register in the underlying XIVE NVT structure and merges it in the
KVM state.
The structures of the interface between QEMU and KVM provisions some
extra room (two u64) for further extensions if more state needs to be
transferred back to QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_ppc.h | 11 +++
arch/powerpc/include/uapi/asm/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 24 +++++++
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 +++++
5 files changed, 138 insertions(+)
@@ -272,6 +272,7 @@ union kvmppc_one_reg {u64addr;u64length;}vpaval;+u64xive_timaval[4];
This is doubling the size of the userspace visible one_reg union. Is
that safe?
'safe' as in compatibility on an older KVM which would still use the old
kvmppc_one_reg definition ?
It should be fine as KVM_REG_PPC_VP_STATE would not be handled. Am I wrong ?
quoted
};
struct kvmppc_ops {
@@ -604,6 +605,10 @@ extern int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev, extern void kvmppc_xive_native_cleanup_vcpu(struct kvm_vcpu *vcpu); extern void kvmppc_xive_native_init_module(void); extern void kvmppc_xive_native_exit_module(void);+extern int kvmppc_xive_native_get_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val);+extern int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val); #else static inline int kvmppc_xive_set_xive(struct kvm *kvm, u32 irq, u32 server,
@@ -845,6 +845,88 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)returnret;}+/*+*InterruptPendingBuffer(IPB)offset+*/+#define TM_IPB_SHIFT 40+#define TM_IPB_MASK (((u64) 0xFF) << TM_IPB_SHIFT)++intkvmppc_xive_native_get_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+u64opal_state;+intrc;++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc)+return-ENOENT;++/* Thread context registers. We only care about IPB and CPPR */+val->xive_timaval[0]=vcpu->arch.xive_saved_state.w01;++/*+*ReturntheOSCAMlinetoprintouttheVPidentifierin+*theQEMUmonitor.Thisisnotrestored.+*/+val->xive_timaval[1]=vcpu->arch.xive_cam_word;
I'm pretty dubious about this mixing of vital state information with
what's basically debug information.
I think QEMU deserves to know about the OS CAM line value. I was even
thinking about adding the POOL CAM line value for future use (nested)
Doubly so since it requires changing the ABI to increase
the one_reg union's size.
OK. That's one argument.
Might be better to have this control only return the 0th and 2nd u64s
from the TIMA, with the CAM debug information returned via some other
mechanism.
Like an extra reg : KVM_REG_PPC_VP_CAM ?
quoted
+
+ /* Get the VP state from OPAL */
+ rc = xive_native_get_vp_state(xc->vp_id, &opal_state);
+ if (rc)
+ return rc;
+
+ /*
+ * Capture the backup of IPB register in the NVT structure and
+ * merge it in our KVM VP state.
+ */
+ val->xive_timaval[0] |= cpu_to_be64(opal_state & TM_IPB_MASK);
+
+ pr_devel("%s NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x opal=%016llx\n",
+ __func__,
+ vcpu->arch.xive_saved_state.nsr,
+ vcpu->arch.xive_saved_state.cppr,
+ vcpu->arch.xive_saved_state.ipb,
+ vcpu->arch.xive_saved_state.pipr,
+ vcpu->arch.xive_saved_state.w01,
+ (u32) vcpu->arch.xive_cam_word, opal_state);
Hrm.. except you don't seem to be using the last half of the timaval
field anyway.
Yes. The two u64 are extras. We can do without.
Would that be ok if I stored the w01 regs in the first u64, the CAM line(s)
in the second and remove the extra two u64 ?
quoted
+
+ return 0;
+}
+
+int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu, union kvmppc_one_reg *val)
+{
+ struct kvmppc_xive_vcpu *xc = vcpu->arch.xive_vcpu;
+ struct kvmppc_xive *xive = vcpu->kvm->arch.xive;
+
+ pr_devel("%s w01=%016llx vp=%016llx\n", __func__,
+ val->xive_timaval[0], val->xive_timaval[1]);
+
+ if (!kvmppc_xive_enabled(vcpu))
+ return -EPERM;
+
+ if (!xc || !xive)
+ return -ENOENT;
+
+ /* We can't update the state of a "pushed" VCPU */
+ if (WARN_ON(vcpu->arch.xive_pushed))
What prevents userspace from tripping this WARN_ON()?
if the vCPU is executing a vCPU ioctl, it means that it exited the guest
and that its interrupt context has been pulled out of XIVE.
quoted
+ return -EIO;
EBUSY might be more appropriate here.
OK.
Thanks,
C.
quoted
+
+ /*
+ * Restore the thread context registers. IPB and CPPR should
+ * be the only ones that matter.
+ */
+ vcpu->arch.xive_saved_state.w01 = val->xive_timaval[0];
+
+ /*
+ * There is no need to restore the XIVE internal state (IPB
+ * stored in the NVT) as the IPB register was merged in KVM VP
+ * state when captured.
+ */
+ return 0;
+}
+
static int xive_native_debug_show(struct seq_file *m, void *private)
{
struct kvmppc_xive *xive = m->private;
@@ -102,6 +102,25 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EINVAL: Not initialized source number, invalid priority or invalid CPU number.+* VCPU state++ The XIVE IC maintains VP interrupt state in an internal structure+ called the NVT. When a VP is not dispatched on a HW processor+ thread, this structure can be updated by HW if the VP is the target+ of an event notification.++ It is important for migration to capture the cached IPB from the NVT+ as it synthesizes the priorities of the pending interrupts. We+ capture a bit more to report debug information.++ KVM_REG_PPC_VP_STATE (4 * 64bits)+ bits: | 63 .... 32 | 31 .... 0 |+ values: | TIMA word0 | TIMA word1 |+ bits: | 127 .......... 64 |+ values: | VP CAM Line |+ bits: | 255 .......... 128 |+ values: | unused |+ * Migration: Saving the state of a VM using the XIVE native exploitation mode
From: David Gibson <hidden> Date: 2019-03-14 03:03:50
On Wed, Mar 13, 2019 at 12:48:57PM +0100, Cédric Le Goater wrote:
On 2/25/19 3:53 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:33PM +0100, Cédric Le Goater wrote:
quoted
When migration of a VM is initiated, a first copy of the RAM is
transferred to the destination before the VM is stopped, but there is
no guarantee that the EQ pages in which the event notification are
queued have not been modified.
To make sure migration will capture a consistent memory state, the
XIVE device should perform a XIVE quiesce sequence to stop the flow of
event notifications and stabilize the EQs. This is the purpose of the
KVM_DEV_XIVE_EQ_SYNC control which will also marks the EQ pages dirty
to force their transfer.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 1 +
arch/powerpc/kvm/book3s_xive_native.c | 67 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 29 ++++++++++
3 files changed, 97 insertions(+)
@@ -640,6 +640,70 @@ static int kvmppc_xive_reset(struct kvmppc_xive *xive)return0;}+staticvoidkvmppc_xive_native_sync_sources(structkvmppc_xive_src_block*sb)+{+intj;++for(j=0;j<KVMPPC_XICS_IRQ_PER_ICS;j++){+structkvmppc_xive_irq_state*state=&sb->irq_state[j];+structxive_irq_data*xd;+u32hw_num;++if(!state->valid)+continue;+if(state->act_priority==MASKED)
Is this correct? If you masked an irq, then immediately did a sync,
couldn't there still be some of the irqs in flight? I thought the
reason we needed a sync was that masking and other such operations
_didn't_ implicitly synchronize.
The struct kvmppc_xive_irq_state reflects the state of the EAS
configuration and not the state of the source. The source is masked
setting the PQ bits to '-Q', which is what is being done before calling
the KVM_DEV_XIVE_EQ_SYNC control.
If a source EAS is configured, OPAL syncs the XIVE IC of the source and
the XIVE IC of the previous target if any.
So I think we are fine.
Ok.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:05:21
On Wed, Mar 13, 2019 at 10:40:19AM +0100, Cédric Le Goater wrote:
On 2/26/19 6:24 AM, Paul Mackerras wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
This is confusing. What's the difference between an "eq attribute"
and an "eq attribute value"? Is the first actually a queue index or
a queue identifier?
The "attribute" qualifier comes from the {get,set,has}_addr methods
of the KVM device. But it is not a well chosen name for the group
KVM_DEV_XIVE_GRP_EQ_CONFIG.
I should be using "eq identifier" and "eq values" or "eq state".
Yeah, that seems clearer.
quoted
Also, the kvm_ppc_xive_eq is not 64 bits, so the comment above it is
wrong. Maybe you meant "64-byte"?
That was a bad copy paste. I have padded the structure to twice the size
of the XIVE END (the XIVE EQ descriptor in HW) which size is 32 bytes.
I thought that one extra u64 was not enough room for future.
quoted
[snip]
quoted
+ page = gfn_to_page(kvm, gpa_to_gfn(kvm_eq.qpage));
+ if (is_error_page(page)) {
+ pr_warn("Couldn't get guest page for %llx!\n", kvm_eq.qpage);
+ return -ENOMEM;
+ }
+ qaddr = page_to_virt(page) + (kvm_eq.qpage & ~PAGE_MASK);
Isn't this assuming that we can map the whole queue with a single
gfn_to_page? That would only be true if kvm_eq.qsize <= PAGE_SHIFT.
What happens if kvm_eq.qsize > PAGE_SHIFT?
Ah yes. Theoretically, it should not happen because we only advertise
64K in the DT for the moment. I should at least add a check. So I will
change the helper xive_native_validate_queue_size() to return -EINVAL
for other page sizes.
Ok.
Do you think it would be complex to support XIVE EQs using a page larger
than the default one on the guest ?
Hm. The queue has to be physically contiguous from the host point of
view, in order for the XIVE hardware to write to it, doesn't it? If
so then supporting queues bigger than the guest page size would be
very difficult.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:06:52
On Wed, Mar 13, 2019 at 09:17:17AM +0100, Cédric Le Goater wrote:
On 2/25/19 5:18 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:40PM +0100, Cédric Le Goater wrote:
quoted
When the VM boots, the CAS negotiation process determines which
interrupt mode to use and invokes a machine reset. At that time, the
previous KVM interrupt device is 'destroyed' before the chosen one is
created. Upon destruction, the vCPU interrupt presenters using the KVM
device should be cleared first, the machine will reconnect them later
to the new device after it is created.
When using the KVM device, there is still a race window with the early
checks in kvmppc_native_connect_vcpu(). Yet to be fixed.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/kvm/book3s_xics.c | 19 +++++++++++++
arch/powerpc/kvm/book3s_xive.c | 39 +++++++++++++++++++++++++--
arch/powerpc/kvm/book3s_xive_native.c | 16 +++++++++++
3 files changed, 72 insertions(+), 2 deletions(-)
This is the KVM XICS-on-XIVE device and its IRQ type is KVMPPC_IRQ_XICS.
So this is correct :/
Ah, right, sorry.
May be we should introduce a KVMPPC_IRQ_XICS_ON_XIVE macro to
clarify.
Yeah, maybe.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:08:16
On Tue, Mar 12, 2019 at 04:19:35PM +0100, Cédric Le Goater wrote:
On 2/25/19 3:10 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:28PM +0100, Cédric Le Goater wrote:
quoted
The associated HW interrupt source is simply allocated at the OPAL/HW
level and then MASKED. KVM only needs to know about its type: LSI or
MSI.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/uapi/asm/kvm.h | 5 +
arch/powerpc/kvm/book3s_xive.h | 10 ++
arch/powerpc/kvm/book3s_xive.c | 8 +-
arch/powerpc/kvm/book3s_xive_native.c | 114 +++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 15 +++
5 files changed, 148 insertions(+), 4 deletions(-)
We do align these in qemu, but I don't see that the kernel part
cares: as far as it's concerned only one of XICS or XIVE is active at
a time, and the irq numbers are chosen by userspace.
There is some relation with userspace nevertheless. The KVM device does
not remap the numbers to some other range today and the limits are fixed
values. Checks are being done in the has_attr() and the set_attr().
Hrm. I still think the comment needs to describe what the constraint
is from the point of view of the kernel, which this isn't. Maybe, "we
allow irqs in the range X..Y (allowing userspace to do ...)"
quoted
quoted
+ */
+#define KVMPPC_XIVE_FIRST_IRQ 0
+#define KVMPPC_XIVE_NR_IRQS KVMPPC_XICS_NR_IRQS
+
/*
* State for one guest irq source.
*
I wonder if we should rename this book3s_xics_on_xive.c or something
at some point, I keep getting confused because I forget that this is
only dealing with host xive, not guest xive.
I am fine with renaming. Any objections ? book3s_xics_p9.c ?
Hm, maybe?
quoted
quoted
@@ -1485,8 +1485,8 @@ static int xive_get_source(struct kvmppc_xive *xive, long irq, u64 addr) return 0; }-static struct kvmppc_xive_src_block *xive_create_src_block(struct kvmppc_xive *xive,- int irq)+struct kvmppc_xive_src_block *kvmppc_xive_create_src_block(+ struct kvmppc_xive *xive, int irq) { struct kvm *kvm = xive->kvm; struct kvmppc_xive_src_block *sb;
It's odd that this function, now used from the xive-on-xive path as
well as the xics-on-xive path references KVMPPC_XICS_ICS_SHIFT a few
lines down from this change.
Yes. This is because of the definition of the struct kvmppc_xive_src_block.
We could introduce new defines for XIVE or a common set of defines for
XICS and XIVE.
I think making common definitions would be best, if possible.
quoted
quoted
@@ -1565,7 +1565,7 @@ static int xive_set_source(struct kvmppc_xive *xive, long irq, u64 addr) sb = kvmppc_xive_find_source(xive, irq, &idx); if (!sb) { pr_devel("No source, creating source block...\n");- sb = xive_create_src_block(xive, irq);+ sb = kvmppc_xive_create_src_block(xive, irq); if (!sb) { pr_devel("Failed to create block...\n"); return -ENOMEM;
@@ -153,12 +176,89 @@ int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev,returnrc;}+staticintkvmppc_xive_native_set_source(structkvmppc_xive*xive,longirq,+u64addr)+{+structkvmppc_xive_src_block*sb;+structkvmppc_xive_irq_state*state;+u64__user*ubufp=(u64__user*)addr;+u64val;+u16idx;++pr_devel("%s irq=0x%lx\n",__func__,irq);++if(irq<KVMPPC_XIVE_FIRST_IRQ||irq>=KVMPPC_XIVE_NR_IRQS)+return-E2BIG;++sb=kvmppc_xive_find_source(xive,irq,&idx);+if(!sb){+pr_debug("No source, creating source block...\n");+sb=kvmppc_xive_create_src_block(xive,irq);+if(!sb){+pr_err("Failed to create block...\n");+return-ENOMEM;+}+}+state=&sb->irq_state[idx];++if(get_user(val,ubufp)){+pr_err("fault getting user info !\n");+return-EFAULT;+}
You should validate the value loaded here to check it doesn't have any
bits set we don't know about.
ok
quoted
quoted
+
+ /*
+ * If the source doesn't already have an IPI, allocate
+ * one and get the corresponding data
+ */
+ if (!state->ipi_number) {
+ state->ipi_number = xive_native_alloc_irq();
+ if (state->ipi_number == 0) {
+ pr_err("Failed to allocate IRQ !\n");
+ return -ENXIO;
+ }
+ xive_native_populate_irq_data(state->ipi_number,
+ &state->ipi_data);
+ pr_debug("%s allocated hw_irq=0x%x for irq=0x%lx\n", __func__,
+ state->ipi_number, irq);
+ }
+
+ arch_spin_lock(&sb->lock);
Why the direct call to arch_spin_lock() rather than just spin_lock()?
Paul answered this question but may be I should make the effort to
decouple both devices on this aspect.
Thanks,
C.
quoted
quoted
+
+ /* Restore LSI state */
+ if (val & KVM_XIVE_LEVEL_SENSITIVE) {
+ state->lsi = true;
+ if (val & KVM_XIVE_LEVEL_ASSERTED)
+ state->asserted = true;
+ pr_devel(" LSI ! Asserted=%d\n", state->asserted);
+ }
+
+ /* Mask IRQ to start with */
+ state->act_server = 0;
+ state->act_priority = MASKED;
+ xive_vm_esb_load(&state->ipi_data, XIVE_ESB_SET_PQ_01);
+ xive_native_configure_irq(state->ipi_number, 0, MASKED, 0);
+
+ /* Increment the number of valid sources and mark this one valid */
+ if (!state->valid)
+ xive->src_count++;
+ state->valid = true;
+
+ arch_spin_unlock(&sb->lock);
+
+ return 0;
+}
+
static int kvmppc_xive_native_set_attr(struct kvm_device *dev,
struct kvm_device_attr *attr)
{
+ struct kvmppc_xive *xive = dev->private;
+
switch (attr->group) {
case KVM_DEV_XIVE_GRP_CTRL:
break;
+ case KVM_DEV_XIVE_GRP_SOURCE:
+ return kvmppc_xive_native_set_source(xive, attr->attr,
+ attr->addr);
}
return -ENXIO;
}
@@ -175,6 +275,11 @@ static int kvmppc_xive_native_has_attr(struct kvm_device *dev, switch (attr->group) { case KVM_DEV_XIVE_GRP_CTRL: break;+ case KVM_DEV_XIVE_GRP_SOURCE:+ if (attr->attr >= KVMPPC_XIVE_FIRST_IRQ &&+ attr->attr < KVMPPC_XIVE_NR_IRQS)+ return 0;+ break; } return -ENXIO; }
@@ -17,3 +17,18 @@ the legacy interrupt mode, referred as XICS (POWER7/8). 1. KVM_DEV_XIVE_GRP_CTRL Provides global controls on the device++ 2. KVM_DEV_XIVE_GRP_SOURCE (write only)+ Initializes a new source in the XIVE device and mask it.+ Attributes:+ Interrupt source number (64-bit)+ The kvm_device_attr.addr points to a __u64 value:+ bits: | 63 .... 2 | 1 | 0+ values: | unused | level | type+ - type: 0:MSI 1:LSI+ - level: assertion level in case of an LSI.+ Errors:+ -E2BIG: Interrupt source number is out of range+ -ENOMEM: Could not create a new source block+ -EFAULT: Invalid user pointer for attr->addr.+ -ENXIO: Could not allocate underlying HW interrupt
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:09:39
On Wed, Mar 13, 2019 at 09:34:53AM +0100, Cédric Le Goater wrote:
On 2/25/19 5:35 AM, Paul Mackerras wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:27PM +0100, Cédric Le Goater wrote:
quoted
The user interface exposes a new capability to let QEMU connect the
vCPU to the XIVE KVM device if required. The capability is only
advertised on a PowerNV Hypervisor as support for nested guests
(pseries KVM Hypervisor) is not yet available.
If a bisection happened to land on this commit, we would have KVM
saying it had the ability to support guests using XIVE natively, but
it wouldn't actually work since we don't have all the code that is in
the following patches.
OK. I didn't think migration was a must-have for bisection. I will move
the enablement at end.
Any temporary feature regression potentially breaks bisection, because
you don't know what we'll want to bisect for. Obviously we're never
going to get that perfectly right, but that doesn't mean we shouldn't
try when we do see the problem in advance.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:17:56
On Wed, Mar 13, 2019 at 02:19:13PM +0100, Cédric Le Goater wrote:
On 2/25/19 4:31 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:34PM +0100, Cédric Le Goater wrote:
quoted
At a VCPU level, the state of the thread interrupt management
registers needs to be collected. These registers are cached under the
'xive_saved_state.w01' field of the VCPU when the VPCU context is
pulled from the HW thread. An OPAL call retrieves the backup of the
IPB register in the underlying XIVE NVT structure and merges it in the
KVM state.
The structures of the interface between QEMU and KVM provisions some
extra room (two u64) for further extensions if more state needs to be
transferred back to QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_ppc.h | 11 +++
arch/powerpc/include/uapi/asm/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 24 +++++++
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 +++++
5 files changed, 138 insertions(+)
@@ -272,6 +272,7 @@ union kvmppc_one_reg {u64addr;u64length;}vpaval;+u64xive_timaval[4];
This is doubling the size of the userspace visible one_reg union. Is
that safe?
'safe' as in compatibility on an older KVM which would still use the old
kvmppc_one_reg definition ?
I was more thinking of old qemu with a new kernel.
It should be fine as KVM_REG_PPC_VP_STATE would not be handled. Am I
wrong ?
Looks like it should be ok, because we only partially copy the
structure to/from userspace due to the one_reg_size() logic. If the
whole union was always copied, it would be hilariously unsafe.
quoted
quoted
};
struct kvmppc_ops {
@@ -604,6 +605,10 @@ extern int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev, extern void kvmppc_xive_native_cleanup_vcpu(struct kvm_vcpu *vcpu); extern void kvmppc_xive_native_init_module(void); extern void kvmppc_xive_native_exit_module(void);+extern int kvmppc_xive_native_get_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val);+extern int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val); #else static inline int kvmppc_xive_set_xive(struct kvm *kvm, u32 irq, u32 server,
@@ -845,6 +845,88 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)returnret;}+/*+*InterruptPendingBuffer(IPB)offset+*/+#define TM_IPB_SHIFT 40+#define TM_IPB_MASK (((u64) 0xFF) << TM_IPB_SHIFT)++intkvmppc_xive_native_get_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+u64opal_state;+intrc;++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc)+return-ENOENT;++/* Thread context registers. We only care about IPB and CPPR */+val->xive_timaval[0]=vcpu->arch.xive_saved_state.w01;++/*+*ReturntheOSCAMlinetoprintouttheVPidentifierin+*theQEMUmonitor.Thisisnotrestored.+*/+val->xive_timaval[1]=vcpu->arch.xive_cam_word;
I'm pretty dubious about this mixing of vital state information with
what's basically debug information.
I think QEMU deserves to know about the OS CAM line value. I was even
thinking about adding the POOL CAM line value for future use (nested)
quoted
Doubly so since it requires changing the ABI to increase
the one_reg union's size.
OK. That's one argument.
quoted
Might be better to have this control only return the 0th and 2nd u64s
from the TIMA, with the CAM debug information returned via some other
mechanism.
Like an extra reg : KVM_REG_PPC_VP_CAM ?
That would be the obvious choice, yes.
quoted
quoted
+
+ /* Get the VP state from OPAL */
+ rc = xive_native_get_vp_state(xc->vp_id, &opal_state);
+ if (rc)
+ return rc;
+
+ /*
+ * Capture the backup of IPB register in the NVT structure and
+ * merge it in our KVM VP state.
+ */
+ val->xive_timaval[0] |= cpu_to_be64(opal_state & TM_IPB_MASK);
+
+ pr_devel("%s NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x opal=%016llx\n",
+ __func__,
+ vcpu->arch.xive_saved_state.nsr,
+ vcpu->arch.xive_saved_state.cppr,
+ vcpu->arch.xive_saved_state.ipb,
+ vcpu->arch.xive_saved_state.pipr,
+ vcpu->arch.xive_saved_state.w01,
+ (u32) vcpu->arch.xive_cam_word, opal_state);
Hrm.. except you don't seem to be using the last half of the timaval
field anyway.
Yes. The two u64 are extras. We can do without.
Would that be ok if I stored the w01 regs in the first u64, the CAM line(s)
in the second and remove the extra two u64 ?
I'd still prefer them in separate regs. They kind of belong to
different categories of information, and I can't think of any
particular reason you'd have to update or fetch them as a unit.
quoted
quoted
+
+ return 0;
+}
+
+int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu, union kvmppc_one_reg *val)
+{
+ struct kvmppc_xive_vcpu *xc = vcpu->arch.xive_vcpu;
+ struct kvmppc_xive *xive = vcpu->kvm->arch.xive;
+
+ pr_devel("%s w01=%016llx vp=%016llx\n", __func__,
+ val->xive_timaval[0], val->xive_timaval[1]);
+
+ if (!kvmppc_xive_enabled(vcpu))
+ return -EPERM;
+
+ if (!xc || !xive)
+ return -ENOENT;
+
+ /* We can't update the state of a "pushed" VCPU */
+ if (WARN_ON(vcpu->arch.xive_pushed))
What prevents userspace from tripping this WARN_ON()?
if the vCPU is executing a vCPU ioctl, it means that it exited the guest
and that its interrupt context has been pulled out of XIVE.
But couldn't one user thread call the vcpu ioctl() while another is
inside the guest?
quoted
quoted
+ return -EIO;
EBUSY might be more appropriate here.
OK.
Thanks,
C.
quoted
quoted
+
+ /*
+ * Restore the thread context registers. IPB and CPPR should
+ * be the only ones that matter.
+ */
+ vcpu->arch.xive_saved_state.w01 = val->xive_timaval[0];
+
+ /*
+ * There is no need to restore the XIVE internal state (IPB
+ * stored in the NVT) as the IPB register was merged in KVM VP
+ * state when captured.
+ */
+ return 0;
+}
+
static int xive_native_debug_show(struct seq_file *m, void *private)
{
struct kvmppc_xive *xive = m->private;
@@ -102,6 +102,25 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EINVAL: Not initialized source number, invalid priority or invalid CPU number.+* VCPU state++ The XIVE IC maintains VP interrupt state in an internal structure+ called the NVT. When a VP is not dispatched on a HW processor+ thread, this structure can be updated by HW if the VP is the target+ of an event notification.++ It is important for migration to capture the cached IPB from the NVT+ as it synthesizes the priorities of the pending interrupts. We+ capture a bit more to report debug information.++ KVM_REG_PPC_VP_STATE (4 * 64bits)+ bits: | 63 .... 32 | 31 .... 0 |+ values: | TIMA word0 | TIMA word1 |+ bits: | 127 .......... 64 |+ values: | VP CAM Line |+ bits: | 255 .......... 128 |+ values: | unused |+ * Migration: Saving the state of a VM using the XIVE native exploitation mode
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: David Gibson <hidden> Date: 2019-03-14 03:53:54
On Wed, Mar 13, 2019 at 09:46:08AM +0100, Cédric Le Goater wrote:
On 3/13/19 5:03 AM, David Gibson wrote:
quoted
On Tue, Mar 12, 2019 at 06:00:38PM +0100, Cédric Le Goater wrote:
quoted
On 2/25/19 3:39 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
I think we need to add some kind of flags to differentiate the hcall
H_INT_SET_QUEUE_CONFIG from the restore of the EQ. The hcall does
not need OPAL support call and this could help in the code
transition.
Hrm. What's the actual difference in the semantics between the two
cases.
None.
But we don't need to set the EQ state in the case of the HCALL and it's
(very) practical to run guests with XIVE enabled without the OPAL support.
The latter is the main reason clearly.
Thinking of it, I could test the EQ toggle bit and index passed to KVM
and skip the OPAL call which restores the EQ state if they are zero.
This is because I know that the OPAL call configuring the EQ resets them.
That will do. No need for a flag.
That's a much better idea.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-14 07:10:32
On 3/14/19 4:09 AM, David Gibson wrote:
On Wed, Mar 13, 2019 at 02:19:13PM +0100, Cédric Le Goater wrote:
quoted
On 2/25/19 4:31 AM, David Gibson wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:34PM +0100, Cédric Le Goater wrote:
quoted
At a VCPU level, the state of the thread interrupt management
registers needs to be collected. These registers are cached under the
'xive_saved_state.w01' field of the VCPU when the VPCU context is
pulled from the HW thread. An OPAL call retrieves the backup of the
IPB register in the underlying XIVE NVT structure and merges it in the
KVM state.
The structures of the interface between QEMU and KVM provisions some
extra room (two u64) for further extensions if more state needs to be
transferred back to QEMU.
Signed-off-by: Cédric Le Goater <clg@kaod.org>
---
arch/powerpc/include/asm/kvm_ppc.h | 11 +++
arch/powerpc/include/uapi/asm/kvm.h | 2 +
arch/powerpc/kvm/book3s.c | 24 +++++++
arch/powerpc/kvm/book3s_xive_native.c | 82 ++++++++++++++++++++++
Documentation/virtual/kvm/devices/xive.txt | 19 +++++
5 files changed, 138 insertions(+)
@@ -272,6 +272,7 @@ union kvmppc_one_reg {u64addr;u64length;}vpaval;+u64xive_timaval[4];
This is doubling the size of the userspace visible one_reg union. Is
that safe?
'safe' as in compatibility on an older KVM which would still use the old
kvmppc_one_reg definition ?
I was more thinking of old qemu with a new kernel.
quoted
It should be fine as KVM_REG_PPC_VP_STATE would not be handled. Am I
wrong ?
Looks like it should be ok, because we only partially copy the
structure to/from userspace due to the one_reg_size() logic. If the
whole union was always copied, it would be hilariously unsafe.
quoted
quoted
quoted
};
struct kvmppc_ops {
@@ -604,6 +605,10 @@ extern int kvmppc_xive_native_connect_vcpu(struct kvm_device *dev, extern void kvmppc_xive_native_cleanup_vcpu(struct kvm_vcpu *vcpu); extern void kvmppc_xive_native_init_module(void); extern void kvmppc_xive_native_exit_module(void);+extern int kvmppc_xive_native_get_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val);+extern int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu,+ union kvmppc_one_reg *val); #else static inline int kvmppc_xive_set_xive(struct kvm *kvm, u32 irq, u32 server,
@@ -845,6 +845,88 @@ static int kvmppc_xive_native_create(struct kvm_device *dev, u32 type)returnret;}+/*+*InterruptPendingBuffer(IPB)offset+*/+#define TM_IPB_SHIFT 40+#define TM_IPB_MASK (((u64) 0xFF) << TM_IPB_SHIFT)++intkvmppc_xive_native_get_vp(structkvm_vcpu*vcpu,unionkvmppc_one_reg*val)+{+structkvmppc_xive_vcpu*xc=vcpu->arch.xive_vcpu;+u64opal_state;+intrc;++if(!kvmppc_xive_enabled(vcpu))+return-EPERM;++if(!xc)+return-ENOENT;++/* Thread context registers. We only care about IPB and CPPR */+val->xive_timaval[0]=vcpu->arch.xive_saved_state.w01;++/*+*ReturntheOSCAMlinetoprintouttheVPidentifierin+*theQEMUmonitor.Thisisnotrestored.+*/+val->xive_timaval[1]=vcpu->arch.xive_cam_word;
I'm pretty dubious about this mixing of vital state information with
what's basically debug information.
I think QEMU deserves to know about the OS CAM line value. I was even
thinking about adding the POOL CAM line value for future use (nested)
quoted
Doubly so since it requires changing the ABI to increase
the one_reg union's size.
OK. That's one argument.
quoted
Might be better to have this control only return the 0th and 2nd u64s
from the TIMA, with the CAM debug information returned via some other
mechanism.
Like an extra reg : KVM_REG_PPC_VP_CAM ?
That would be the obvious choice, yes.
OK. Let's keep that in mind but I think it is overkill. I would rather
have one reg per ring instead.
quoted
quoted
quoted
+
+ /* Get the VP state from OPAL */
+ rc = xive_native_get_vp_state(xc->vp_id, &opal_state);
+ if (rc)
+ return rc;
+
+ /*
+ * Capture the backup of IPB register in the NVT structure and
+ * merge it in our KVM VP state.
+ */
+ val->xive_timaval[0] |= cpu_to_be64(opal_state & TM_IPB_MASK);
+
+ pr_devel("%s NSR=%02x CPPR=%02x IBP=%02x PIPR=%02x w01=%016llx w2=%08x opal=%016llx\n",
+ __func__,
+ vcpu->arch.xive_saved_state.nsr,
+ vcpu->arch.xive_saved_state.cppr,
+ vcpu->arch.xive_saved_state.ipb,
+ vcpu->arch.xive_saved_state.pipr,
+ vcpu->arch.xive_saved_state.w01,
+ (u32) vcpu->arch.xive_cam_word, opal_state);
Hrm.. except you don't seem to be using the last half of the timaval
field anyway.
Yes. The two u64 are extras. We can do without.
Would that be ok if I stored the w01 regs in the first u64, the CAM line(s)
in the second and remove the extra two u64 ?
I'd still prefer them in separate regs. They kind of belong to
different categories of information, and I can't think of any
particular reason you'd have to update or fetch them as a unit.
Because they belong to the same thread interrupt context and the same
ring (OS) even if only the hypervisor can set the OS CAM line. The OS
can only set the CPPR. QEMU operates at the hypervisor level so it is
not violating any privilege level.
quoted
quoted
quoted
+
+ return 0;
+}
+
+int kvmppc_xive_native_set_vp(struct kvm_vcpu *vcpu, union kvmppc_one_reg *val)
+{
+ struct kvmppc_xive_vcpu *xc = vcpu->arch.xive_vcpu;
+ struct kvmppc_xive *xive = vcpu->kvm->arch.xive;
+
+ pr_devel("%s w01=%016llx vp=%016llx\n", __func__,
+ val->xive_timaval[0], val->xive_timaval[1]);
+
+ if (!kvmppc_xive_enabled(vcpu))
+ return -EPERM;
+
+ if (!xc || !xive)
+ return -ENOENT;
+
+ /* We can't update the state of a "pushed" VCPU */
+ if (WARN_ON(vcpu->arch.xive_pushed))
What prevents userspace from tripping this WARN_ON()?
if the vCPU is executing a vCPU ioctl, it means that it exited the guest
and that its interrupt context has been pulled out of XIVE.
But couldn't one user thread call the vcpu ioctl() while another is
inside the guest?
Not while setting the VP state. The guest is not resumed.
Thanks,
C.
quoted
quoted
quoted
+ return -EIO;
EBUSY might be more appropriate here.
OK.
Thanks,
C.
quoted
quoted
+
+ /*
+ * Restore the thread context registers. IPB and CPPR should
+ * be the only ones that matter.
+ */
+ vcpu->arch.xive_saved_state.w01 = val->xive_timaval[0];
+
+ /*
+ * There is no need to restore the XIVE internal state (IPB
+ * stored in the NVT) as the IPB register was merged in KVM VP
+ * state when captured.
+ */
+ return 0;
+}
+
static int xive_native_debug_show(struct seq_file *m, void *private)
{
struct kvmppc_xive *xive = m->private;
@@ -102,6 +102,25 @@ the legacy interrupt mode, referred as XICS (POWER7/8). -EINVAL: Not initialized source number, invalid priority or invalid CPU number.+* VCPU state++ The XIVE IC maintains VP interrupt state in an internal structure+ called the NVT. When a VP is not dispatched on a HW processor+ thread, this structure can be updated by HW if the VP is the target+ of an event notification.++ It is important for migration to capture the cached IPB from the NVT+ as it synthesizes the priorities of the pending interrupts. We+ capture a bit more to report debug information.++ KVM_REG_PPC_VP_STATE (4 * 64bits)+ bits: | 63 .... 32 | 31 .... 0 |+ values: | TIMA word0 | TIMA word1 |+ bits: | 127 .......... 64 |+ values: | VP CAM Line |+ bits: | 255 .......... 128 |+ values: | unused |+ * Migration: Saving the state of a VM using the XIVE native exploitation mode
From: Cédric Le Goater <clg@kaod.org> Date: 2019-03-14 07:13:02
On 3/14/19 3:32 AM, David Gibson wrote:
On Wed, Mar 13, 2019 at 10:40:19AM +0100, Cédric Le Goater wrote:
quoted
On 2/26/19 6:24 AM, Paul Mackerras wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
This is confusing. What's the difference between an "eq attribute"
and an "eq attribute value"? Is the first actually a queue index or
a queue identifier?
The "attribute" qualifier comes from the {get,set,has}_addr methods
of the KVM device. But it is not a well chosen name for the group
KVM_DEV_XIVE_GRP_EQ_CONFIG.
I should be using "eq identifier" and "eq values" or "eq state".
Yeah, that seems clearer.
quoted
quoted
Also, the kvm_ppc_xive_eq is not 64 bits, so the comment above it is
wrong. Maybe you meant "64-byte"?
That was a bad copy paste. I have padded the structure to twice the size
of the XIVE END (the XIVE EQ descriptor in HW) which size is 32 bytes.
I thought that one extra u64 was not enough room for future.
quoted
[snip]
quoted
+ page = gfn_to_page(kvm, gpa_to_gfn(kvm_eq.qpage));
+ if (is_error_page(page)) {
+ pr_warn("Couldn't get guest page for %llx!\n", kvm_eq.qpage);
+ return -ENOMEM;
+ }
+ qaddr = page_to_virt(page) + (kvm_eq.qpage & ~PAGE_MASK);
Isn't this assuming that we can map the whole queue with a single
gfn_to_page? That would only be true if kvm_eq.qsize <= PAGE_SHIFT.
What happens if kvm_eq.qsize > PAGE_SHIFT?
Ah yes. Theoretically, it should not happen because we only advertise
64K in the DT for the moment. I should at least add a check. So I will
change the helper xive_native_validate_queue_size() to return -EINVAL
for other page sizes.
Ok.
quoted
Do you think it would be complex to support XIVE EQs using a page larger
than the default one on the guest ?
Hm. The queue has to be physically contiguous from the host point of
view, in order for the XIVE hardware to write to it, doesn't it? If
so then supporting queues bigger than the guest page size would be
very difficult.
From: David Gibson <hidden> Date: 2019-03-15 04:30:51
On Thu, Mar 14, 2019 at 08:11:17AM +0100, Cédric Le Goater wrote:
On 3/14/19 3:32 AM, David Gibson wrote:
quoted
On Wed, Mar 13, 2019 at 10:40:19AM +0100, Cédric Le Goater wrote:
quoted
On 2/26/19 6:24 AM, Paul Mackerras wrote:
quoted
On Fri, Feb 22, 2019 at 12:28:30PM +0100, Cédric Le Goater wrote:
quoted
These controls will be used by the H_INT_SET_QUEUE_CONFIG and
H_INT_GET_QUEUE_CONFIG hcalls from QEMU. They will also be used to
restore the configuration of the XIVE EQs in the KVM device and to
capture the internal runtime state of the EQs. Both 'get' and 'set'
rely on an OPAL call to access from the XIVE interrupt controller the
EQ toggle bit and EQ index which are updated by the HW when event
notifications are enqueued in the EQ.
The value of the guest physical address of the event queue is saved in
the XIVE internal xive_q structure for later use. That is when
migration needs to mark the EQ pages dirty to capture a consistent
memory state of the VM.
To be noted that H_INT_SET_QUEUE_CONFIG does not require the extra
OPAL call setting the EQ toggle bit and EQ index to configure the EQ,
but restoring the EQ state will.
This is confusing. What's the difference between an "eq attribute"
and an "eq attribute value"? Is the first actually a queue index or
a queue identifier?
The "attribute" qualifier comes from the {get,set,has}_addr methods
of the KVM device. But it is not a well chosen name for the group
KVM_DEV_XIVE_GRP_EQ_CONFIG.
I should be using "eq identifier" and "eq values" or "eq state".
Yeah, that seems clearer.
quoted
quoted
Also, the kvm_ppc_xive_eq is not 64 bits, so the comment above it is
wrong. Maybe you meant "64-byte"?
That was a bad copy paste. I have padded the structure to twice the size
of the XIVE END (the XIVE EQ descriptor in HW) which size is 32 bytes.
I thought that one extra u64 was not enough room for future.
quoted
[snip]
quoted
+ page = gfn_to_page(kvm, gpa_to_gfn(kvm_eq.qpage));
+ if (is_error_page(page)) {
+ pr_warn("Couldn't get guest page for %llx!\n", kvm_eq.qpage);
+ return -ENOMEM;
+ }
+ qaddr = page_to_virt(page) + (kvm_eq.qpage & ~PAGE_MASK);
Isn't this assuming that we can map the whole queue with a single
gfn_to_page? That would only be true if kvm_eq.qsize <= PAGE_SHIFT.
What happens if kvm_eq.qsize > PAGE_SHIFT?
Ah yes. Theoretically, it should not happen because we only advertise
64K in the DT for the moment. I should at least add a check. So I will
change the helper xive_native_validate_queue_size() to return -EINVAL
for other page sizes.
Ok.
quoted
Do you think it would be complex to support XIVE EQs using a page larger
than the default one on the guest ?
Hm. The queue has to be physically contiguous from the host point of
view, in order for the XIVE hardware to write to it, doesn't it? If
so then supporting queues bigger than the guest page size would be
very difficult.
The queue is only *one* page.
Right, but it's one *host* page, right, which is by nature host
physically contiguous. If the guest page size is different a single
guest page might not be host physically contiguous.
--
David Gibson | I'll have my music baroque, and my code
david AT gibson.dropbear.id.au | minimalist, thank you. NOT _the_ _other_
| _way_ _around_!
http://www.ozlabs.org/~dgibson
From: Paolo Bonzini <pbonzini@redhat.com> Date: 2019-03-15 17:58:46
On 13/03/19 09:02, Cédric Le Goater wrote:
The 'destroy' method is currently used to destroy all devices when the
VM is destroyed after the vCPUs have been freed.
This new KVM ioctl exposes the same KVM device method. It acts as a
software reset of the VM to 'destroy' selected devices when necessary
and perform the required cleanups on the vCPUs. Called with the
kvm->lock.
The 'destroy' method could be improved by returning an error code.
Signed-off-by: Cédric Le Goater <clg@kaod.org>