From patchwork Mon Jul 26 09:28:49 2021 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Quentin Perret X-Patchwork-Id: 12398923 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.5 required=3.0 tests=BAYES_00,DKIMWL_WL_HIGH, DKIM_ADSP_CUSTOM_MED,DKIM_SIGNED,DKIM_VALID,HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH,MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED, USER_AGENT_GIT autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0A7B0C4338F for ; Mon, 26 Jul 2021 09:31:38 +0000 (UTC) Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id CE2A460238 for ; Mon, 26 Jul 2021 09:31:37 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.4.1 mail.kernel.org CE2A460238 Authentication-Results: mail.kernel.org; dmarc=fail (p=reject dis=none) header.from=google.com Authentication-Results: mail.kernel.org; spf=none smtp.mailfrom=lists.infradead.org DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender: Content-Transfer-Encoding:Content-Type:List-Subscribe:List-Help:List-Post: List-Archive:List-Unsubscribe:List-Id:Cc:To:From:Subject:Mime-Version: Message-Id:Date:Reply-To:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Owner; bh=lS2g1+/ATw+2odJMFS0yXtLJzHkv93GUKE118WlzSAs=; b=gYx NHYkzzumedJ8ustQPqB8YCa8THV3o8CYcM0wTYY16VLQmJZLtm3HkhN5H2gCF1hRPRc+ce1NwpEGn /OquG2hRyE0ygzb335CpCXROYsIEj2BUtRt9OZOl5KLqMGmE1kUhUQUiW6egDp4NjXWLmmBWGQvor rxLS990uRWRIR1rLnyWkIktp1uuO6h4nNM4MswRmoMyte7k+npkzgtEbcnw95NCB1/bwV8VQ24bRJ 6oyihAH/M1OwoKZ2x/GR28ntQmb5uDg1EhFlRZcxIcvSeqZmkaaKI3glbThv2/rRRgvI03MG7CbT0 Cp667twAaT7kBH+Q1v87ba3J9CuLakw==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.94.2 #2 (Red Hat Linux)) id 1m7wvF-00ARVk-5q; Mon, 26 Jul 2021 09:29:17 +0000 Received: from mail-ed1-x54a.google.com ([2a00:1450:4864:20::54a]) by bombadil.infradead.org with esmtps (Exim 4.94.2 #2 (Red Hat Linux)) id 1m7wvB-00ARVB-JN for linux-arm-kernel@lists.infradead.org; Mon, 26 Jul 2021 09:29:15 +0000 Received: by mail-ed1-x54a.google.com with SMTP id d12-20020a50fe8c0000b02903a4b519b413so4409280edt.9 for ; Mon, 26 Jul 2021 02:29:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:message-id:mime-version:subject:from:to:cc; bh=DCvP66qXTBgcdbjyYQwVaIHGbmeDnGwgmndjPCUFZv0=; b=LszyL0ac2kAjWuiZPWogQnvnhJe8WWxuAssQ2tOcCSO63Y+EpNy9srxlU7ETxbVzrL jsonb/tmICqfScnrKqzEL/v8OaT5iihwGykqbQrXqhuDK/KoyT05kQEkJ4gfuxm8uT7j /wrabJ7Jxqvl6MMAKROuFiCwv0wFJ9occQnnfhptzoDPo+r+B3Y5kM3YnLjY0QwHyqus o0xsGG19XNfNfD/0CnhjCwgUkyr+o9ob7e79XzMQazCTd9XpcKWiFBxx+h40mnAvon9b I+bghqZiBtUczZE4qs3TIgu+PJWesXlNkAl4m+wsv+rpDdItgjfW8vt2g4EwKpuOEHXU G3+Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=DCvP66qXTBgcdbjyYQwVaIHGbmeDnGwgmndjPCUFZv0=; b=mjkdBU48P5hlQoh6z+GiwbYgSCGVIJJMyoIx+mwFfNgUDfqybuz1+8GJ9h1Ag8z4Vz mv2iu3QqaX4ywHTIdXWLHGAK9pTitAnSaLjw74LSIGkJmIZ1JS+DHI8/G+wdEHvyl0av owg/uXQ1E7wQ7VnTKqKMDj9IMJfikPw067SwzEvWNYnkRPYqkQgoJpoq+xoypWnYfJAT 8cNdVVeJUSF1YU9r61K94R+kX1o1YyDJMrekubDt8zxGzvMN5HBD+VzSYbW53OuDLrE2 +PJLywlGkSj4kpyyxsVqjBmRoS1wEvk2aChvqlSv+OYzvYcpmdygKYEJpAdfZjYHFPsj 78tg== X-Gm-Message-State: AOAM530aqWtkJa48XAsTuTMZr/IIsEHCmdTevY95gbxs+/i1zb9enHmj KSonXrPsS7kWs5XK2NXGwvlgQ8Qwu0Fy X-Google-Smtp-Source: ABdhPJzYf6PYxoyOLxQsDMRWgbQljCu/i20aLfGHMDpPArbaJdKVDGYqVf1Kcrk75PpRPPEhGP1AhJYC5bQR X-Received: from luke.lon.corp.google.com ([2a00:79e0:d:210:23a0:2f14:433:e6cb]) (user=qperret job=sendgmr) by 2002:a17:906:b89a:: with SMTP id hb26mr16162211ejb.492.1627291750860; Mon, 26 Jul 2021 02:29:10 -0700 (PDT) Date: Mon, 26 Jul 2021 10:28:49 +0100 Message-Id: <20210726092905.2198501-1-qperret@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.32.0.432.gabb21c7263-goog Subject: [PATCH v2 00/16] Track shared pages at EL2 in protected mode From: Quentin Perret To: maz@kernel.org, james.morse@arm.com, alexandru.elisei@arm.com, suzuki.poulose@arm.com, catalin.marinas@arm.com, will@kernel.org Cc: linux-arm-kernel@lists.infradead.org, kvmarm@lists.cs.columbia.edu, linux-kernel@vger.kernel.org, ardb@kernel.org, qwandor@google.com, tabba@google.com, dbrazdil@google.com, kernel-team@android.com, Quentin Perret X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.8.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20210726_022913_697029_96ACC0DD X-CRM114-Status: GOOD ( 17.07 ) X-BeenThere: linux-arm-kernel@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "linux-arm-kernel" Errors-To: linux-arm-kernel-bounces+linux-arm-kernel=archiver.kernel.org@lists.infradead.org Hi all, This is v2 of the patch series first posted here: https://lore.kernel.org/kvmarm/20210719104735.3681732-1-qperret@google.com/ This series aims to improve how the nVHE hypervisor tracks ownership of memory pages when running in protected mode ("kvm-arm.mode=protected" on the kernel command line). The main issue with the existing ownership tracking code is that it is completely binary: a page is either owned by an entity (e.g. the host) or not. However, we'll need something smarter to track shared pages, as is needed for virtio, or even just host/hypervisor communications. This series introduces a few changes to the kvm page-table library to allow annotating shared pages in ignored bits (a.k.a. software bits) of leaf entries, and makes use of that infrastructure to track all pages that are shared between the host and the hypervisor. We will obviously want to apply the same treatment to guest stage-2 page-tables, but that is not really possible to do until EL2 manages them directly, so I'll keep that for another series. The series is based on the latest kvmarm/fixes branch, and has been tested on AML-S905X-CC (Le Potato) and using various Qemu configurations. Changes since v1: - Changed the 'share' hypercall to accept a single page at a time; - Dropped the patch allowing to continue stage-2 map when hitting the EAGAIN case; - Dropped some of the custom pgtable walkers and used Marc's get_leaf() patch instead; - Changed pgtable API to manipulate SW bits directly rather than specifying shared pages; - Added comments and documentations all over; - Cleanups and small refactoring. Thanks, Quentin Marc Zyngier (1): KVM: arm64: Introduce helper to retrieve a PTE and its level Quentin Perret (15): KVM: arm64: Provide the host_stage2_try() helper macro KVM: arm64: Expose page-table helpers KVM: arm64: Optimize host memory aborts KVM: arm64: Rename KVM_PTE_LEAF_ATTR_S2_IGNORED KVM: arm64: Don't overwrite software bits with owner id KVM: arm64: Tolerate re-creating hyp mappings to set software bits KVM: arm64: Enable forcing page-level stage-2 mappings KVM: arm64: Allow populating software bits KVM: arm64: Add helpers to tag shared pages in SW bits KVM: arm64: Introduce and export host_stage2_idmap_locked() KVM: arm64: Mark host bss and rodata section as shared KVM: arm64: Enable retrieving protections attributes of PTEs KVM: arm64: Refactor protected nVHE stage-1 locking KVM: arm64: Restrict EL2 stage-1 changes in protected mode KVM: arm64: Make __pkvm_create_mappings static arch/arm64/include/asm/kvm_asm.h | 2 +- arch/arm64/include/asm/kvm_pgtable.h | 153 ++++++++---- arch/arm64/kvm/hyp/include/nvhe/mem_protect.h | 29 +++ arch/arm64/kvm/hyp/include/nvhe/mm.h | 3 +- arch/arm64/kvm/hyp/nvhe/hyp-main.c | 11 +- arch/arm64/kvm/hyp/nvhe/mem_protect.c | 188 ++++++++++++-- arch/arm64/kvm/hyp/nvhe/mm.c | 21 +- arch/arm64/kvm/hyp/nvhe/setup.c | 52 +++- arch/arm64/kvm/hyp/pgtable.c | 234 ++++++++++-------- arch/arm64/kvm/mmu.c | 28 ++- 10 files changed, 525 insertions(+), 196 deletions(-)