Re: [PATCH v3 6/6] KVM: guest_memfd: GUP source pages prior to populating guest memory

From: Sean Christopherson

Date: Tue Jan 13 2026 - 14:21:31 EST


On Thu, Jan 08, 2026, Michael Roth wrote:
> @@ -842,47 +881,38 @@ long kvm_gmem_populate(struct kvm *kvm, gfn_t start_gfn, void __user *src, long
> if (!file)
> return -EFAULT;
>
> - filemap_invalidate_lock(file->f_mapping);
> -
> npages = min_t(ulong, slot->npages - (start_gfn - slot->base_gfn), npages);
> for (i = 0; i < npages; i++) {
> - struct folio *folio;
> - gfn_t gfn = start_gfn + i;
> - pgoff_t index = kvm_gmem_get_index(slot, gfn);
> - kvm_pfn_t pfn;
> + struct page *src_page = NULL;
> + void __user *p;
>
> if (signal_pending(current)) {
> ret = -EINTR;
> break;
> }
>
> - folio = __kvm_gmem_get_pfn(file, slot, index, &pfn, NULL);
> - if (IS_ERR(folio)) {
> - ret = PTR_ERR(folio);
> - break;
> - }
> + p = src ? src + i * PAGE_SIZE : NULL;
>
> - folio_unlock(folio);
> + if (p) {

Computing 'p' when src==NULL is unnecessary and makes it hard to see that gup()
is done if and only if src!=NULL.

Anyone object to this fixup?

diff --git a/virt/kvm/guest_memfd.c b/virt/kvm/guest_memfd.c
index 18ae59b92257..66afab8f08a3 100644
--- a/virt/kvm/guest_memfd.c
+++ b/virt/kvm/guest_memfd.c
@@ -884,17 +884,16 @@ long kvm_gmem_populate(struct kvm *kvm, gfn_t start_gfn, void __user *src, long
npages = min_t(ulong, slot->npages - (start_gfn - slot->base_gfn), npages);
for (i = 0; i < npages; i++) {
struct page *src_page = NULL;
- void __user *p;

if (signal_pending(current)) {
ret = -EINTR;
break;
}

- p = src ? src + i * PAGE_SIZE : NULL;
+ if (src) {
+ unsigned long uaddr = (unsigned long)src + i * PAGE_SIZE;

- if (p) {
- ret = get_user_pages_fast((unsigned long)p, 1, 0, &src_page);
+ ret = get_user_pages_fast(uaddr, 1, 0, &src_page);
if (ret < 0)
break;
if (ret != 1) {

To end up with:

struct page *src_page = NULL;

if (signal_pending(current)) {
ret = -EINTR;
break;
}

if (src) {
unsigned long uaddr = (unsigned long)src + i * PAGE_SIZE;

ret = get_user_pages_fast(uaddr, 1, 0, &src_page);
if (ret < 0)
break;
if (ret != 1) {
ret = -ENOMEM;
break;
}
}

...