[PATCH v6 0/7] KVM: arm64: nv: Implement nested stage-2 reverse map
From: Wei-Lin Chang
Date: Tue Sep 15 2026 - 12:28:57 EST
Hi,
This is v6 of optimizing the shadow s2 mmu unmapping during MMU
notifiers.
This version fixes a few issues, and adds Marc's space optimization
for kvm_guest_s2_mapping [1]. Please see the changelog for the details.
Tested by booting L3, and running in-kernel targetted tests described
in [2]. v5 got some tested-by's from Itaru and Wang (thanks), I didn't
carry them over since some bugs fixed in v6 are non-obvious. Some
retest would be much appreciated!
Series based on v7.3-rc3 + Marc's nested mmu lifecycle fixes [3].
* Changes from v5 [4]:
- Align the addresses down to the mapping size when recording the
guest s2 mappings. s2fd->fault_ipa isn't necessarily PAGE_SIZE aligned.
- Record guest s2 mappings even when page table maps return -EAGAIN.
kvm_pgtable_stage2_map() can create mappings while returning -EAGAIN.
For example, a 2M block map (A) could race with a 4K page map (B):
1. (A) maps the 2M block in kvm_pgtable_visitor_cb()
2. (B) breaks that block into a table and maps 4K
3. (A) reloads and finds the table after kvm_pgtable_visitor_cb(),
then descends into it.
4. (A) maps some 4K, but before it finishes reads entry mapped by (B).
5. (A) returns -EAGAIN although it had mapped a few pages.
In this case, we don't know what subrange is mapped, just track the whole
requested mapping range.
- Don't remove tracked mappings from the interval trees if they only
partially overlap the removal range. Because of the previous bullet point
we can have a 4K shadow mapping tracked as a 2M range in the interval
trees. It would be wrong to remove the 2M range when a guest TLBI doesn't
touch the 4K mapped.
- Check mmu->pgt during mmu unmap notifier, as it could race against
MMU teardown.
- Make guest_s2_tracking_destroy() canonical mmu only. We simply don't
need to detach the nodes from the nested mmus' trees. Freeing them
during canonical mmu's teardown is enough.
Thanks!
[1]: https://lore.kernel.org/kvmarm/86h5jv7qrd.wl-maz@xxxxxxxxxx/
[2]: https://lore.kernel.org/kvmarm/gerjpm62a2gszzggc6vuai22bf3prfquvfsp7ueumps7vz2ev3@odlmovaklg2b/
[3]: https://lore.kernel.org/kvmarm/20260911162203.1919330-1-maz@xxxxxxxxxx/
[4]: https://lore.kernel.org/kvmarm/20260810205038.118843-1-weilin.chang@xxxxxxx/
Marc Zyngier (1):
KVM: arm64: nv: Drop kvm_s2_mmu pointer from kvm_guest_s2_mapping
Wei-Lin Chang (6):
KVM: arm64: Use a variable for the canonical IPA in kvm_s2_fault_map()
KVM: arm64: nv: Introduce guest stage-2 tracking structures
KVM: arm64: nv: Track guest stage-2 mapping creation
KVM: arm64: nv: Track guest stage-2 mapping removal
KVM: arm64: nv: Avoid full shadow stage-2 unmap
KVM: arm64: Refactor kvm_unmap_gfn_range() with common variables
arch/arm64/include/asm/kvm_host.h | 31 +++++-
arch/arm64/include/asm/kvm_nested.h | 7 ++
arch/arm64/kvm/mmu.c | 109 +++++++++++++++++++---
arch/arm64/kvm/nested.c | 140 +++++++++++++++++++++++++++-
4 files changed, 269 insertions(+), 18 deletions(-)
--
2.43.0