There is no need to copy in the data for initial guest memory payload in the case of shareable gmem instances since userspace can just initialize the contents directly. Ignore the 'uaddr' parameter in cases where KVM_MEMSLOT_SUPPORTS_SHARED is set for the GPA's memslot. Also incorporate similar expectations into kvm_gmem_populate() to avoid dealing with potential issues where guest_memfd's shared fault handler might trigger when issuing callbacks to populate pages and not know how to deal the index being marked as private. Signed-off-by: Michael Roth <michael.roth@xxxxxxx> --- .../virt/kvm/x86/amd-memory-encryption.rst | 4 +++- arch/x86/kvm/svm/sev.c | 14 ++++++++++---- virt/kvm/guest_memfd.c | 8 ++++++++ 3 files changed, 21 insertions(+), 5 deletions(-) diff --git a/Documentation/virt/kvm/x86/amd-memory-encryption.rst b/Documentation/virt/kvm/x86/amd-memory-encryption.rst index 1ddb6a86ce7f..399b331a523f 100644 --- a/Documentation/virt/kvm/x86/amd-memory-encryption.rst +++ b/Documentation/virt/kvm/x86/amd-memory-encryption.rst @@ -513,7 +513,9 @@ calling this command until those fields indicate the entire range has been processed, e.g. ``len`` is 0, ``gfn_start`` is equal to the last GFN in the range plus 1, and ``uaddr`` is the last byte of the userspace-provided source buffer address plus 1. In the case where ``type`` is KVM_SEV_SNP_PAGE_TYPE_ZERO, -``uaddr`` will be ignored completely. +``uaddr`` will be ignored completely. If the guest_memfd instance backing the +GFN range has the GUEST_MEMFD_FLAG_SUPPORT_SHARED flag set, then ``uaddr`` will +be ignored for all KVM_SEV_SNP_PAGE_TYPE_*'s. Parameters (in): struct kvm_sev_snp_launch_update diff --git a/arch/x86/kvm/svm/sev.c b/arch/x86/kvm/svm/sev.c index ed85634eb2bd..6e4473e8db6d 100644 --- a/arch/x86/kvm/svm/sev.c +++ b/arch/x86/kvm/svm/sev.c @@ -2174,6 +2174,7 @@ struct sev_gmem_populate_args { __u8 type; int sev_fd; int fw_error; + bool gmem_supports_shared; }; static int sev_gmem_post_populate(struct kvm *kvm, gfn_t gfn_start, kvm_pfn_t pfn, @@ -2185,7 +2186,8 @@ static int sev_gmem_post_populate(struct kvm *kvm, gfn_t gfn_start, kvm_pfn_t pf int npages = (1 << order); gfn_t gfn; - if (WARN_ON_ONCE(sev_populate_args->type != KVM_SEV_SNP_PAGE_TYPE_ZERO && !src)) + if (WARN_ON_ONCE(sev_populate_args->type != KVM_SEV_SNP_PAGE_TYPE_ZERO && + !sev_populate_args->gmem_supports_shared && !src)) return -EINVAL; for (gfn = gfn_start, i = 0; gfn < gfn_start + npages; gfn++, i++) { @@ -2275,7 +2277,7 @@ static int snp_launch_update(struct kvm *kvm, struct kvm_sev_cmd *argp) struct kvm_sev_snp_launch_update params; struct kvm_memory_slot *memslot; long npages, count; - void __user *src; + void __user *src = NULL; int ret = 0; if (!sev_snp_guest(kvm) || !sev->snp_context) @@ -2326,7 +2328,10 @@ static int snp_launch_update(struct kvm *kvm, struct kvm_sev_cmd *argp) sev_populate_args.sev_fd = argp->sev_fd; sev_populate_args.type = params.type; - src = params.type == KVM_SEV_SNP_PAGE_TYPE_ZERO ? NULL : u64_to_user_ptr(params.uaddr); + sev_populate_args.gmem_supports_shared = kvm_gmem_memslot_supports_shared(memslot); + + if (!kvm_gmem_memslot_supports_shared(memslot)) + src = params.type == KVM_SEV_SNP_PAGE_TYPE_ZERO ? NULL : u64_to_user_ptr(params.uaddr); count = kvm_gmem_populate(kvm, params.gfn_start, src, npages, sev_gmem_post_populate, &sev_populate_args); @@ -2338,7 +2343,8 @@ static int snp_launch_update(struct kvm *kvm, struct kvm_sev_cmd *argp) } else { params.gfn_start += count; params.len -= count * PAGE_SIZE; - if (params.type != KVM_SEV_SNP_PAGE_TYPE_ZERO) + if (!kvm_gmem_memslot_supports_shared(memslot) && + params.type != KVM_SEV_SNP_PAGE_TYPE_ZERO) params.uaddr += count * PAGE_SIZE; ret = 0; diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c index a912b00776f1..309455e44e96 100644 --- a/virt/kvm/guest_memfd.c +++ b/virt/kvm/guest_memfd.c @@ -1462,6 +1462,14 @@ long kvm_gmem_populate(struct kvm *kvm, gfn_t start_gfn, void __user *src, long } } else { max_order = 0; + + /* + * If shared memory is available, it is expected that + * userspace will populate memory contents directly and + * not provide an intermediate buffer to copy from. + */ + if (src) + return -EINVAL; } p = src ? src + i * PAGE_SIZE : NULL; -- 2.25.1