Re: [PATCH 2/2] KVM: x86/mmu: Use CMPXCHG when clearing Accessed bit in the shadow MMU
From: Huang, Kai
Date: Wed Jul 29 2026 - 07:20:13 EST
On Mon, 2026-07-27 at 17:22 -0700, Sean Christopherson wrote:
> Use CMPXCHG instead of clear_bit(), which currently emits a LOCK BTR since
> the to-be-cleared bit isn't a compiled-time constant, when aging SPTEs in
^
compile-time ?
> the shadow MMU to align with the approach taken by the TDP MMU, and because
> using CMPXCHG is far more robust against bugs in KVM. E.g. if the SPTE is
> somehow no longer an SPTE due to a KVM bug, CMPXCHG will fail gracefully,
> whereas clear_bit() would potentially corrupt/clobber memory.
>
> Clearing the Accessed bit without atomically ensuring the SPTE is still the
> old SPTE is "fine", as holding the rmap's lock ensures zapping the old SPTE
> can't fully complete, which in turn ensures a new, different SPTE can't be
> installed. But that chain of logic isn't exactly obvious, and there's zero
> reason to avoid CMPXCHG as its cost on modern hardware is within ~1-2 uops
> of LOCK BTR (and may even be cheaper on some microarchitectures). Doing a
> 64-bit CMPXCHG on 32-bit kernels does requires a more expensive CMPXCHG8B,
^
require
> but 32-bit KVM is all but dead at this point.
>
> Cc: James Houghton <jthoughton@xxxxxxxxxx>
> Signed-off-by: Sean Christopherson <seanjc@xxxxxxxxxx>
Reviewed-by: Kai Huang <kai.huang@xxxxxxxxx>