Re: [PATCH v6 0/7] KVM: arm64: nv: Implement nested stage-2 reverse map

From: Itaru Kitayama

Date: Tue Sep 15 2026 - 17:50:57 EST


On Tue, Sep 15, 2026 at 04:42:58PM +0100, Wei-Lin Chang wrote:
> Hi,
>
> This is v6 of optimizing the shadow s2 mmu unmapping during MMU
> notifiers.
>
> This version fixes a few issues, and adds Marc's space optimization
> for kvm_guest_s2_mapping [1]. Please see the changelog for the details.
>
> Tested by booting L3, and running in-kernel targetted tests described
> in [2]. v5 got some tested-by's from Itaru and Wang (thanks), I didn't
> carry them over since some bugs fixed in v6 are non-obvious. Some
> retest would be much appreciated!

How did you boot into L3, with KVM selftest or recrusively boot on HW?

Thanks,
Itaru.

>
> Series based on v7.3-rc3 + Marc's nested mmu lifecycle fixes [3].
>
> * Changes from v5 [4]:
>
> - Align the addresses down to the mapping size when recording the
> guest s2 mappings. s2fd->fault_ipa isn't necessarily PAGE_SIZE aligned.
>
> - Record guest s2 mappings even when page table maps return -EAGAIN.
> kvm_pgtable_stage2_map() can create mappings while returning -EAGAIN.
> For example, a 2M block map (A) could race with a 4K page map (B):
> 1. (A) maps the 2M block in kvm_pgtable_visitor_cb()
> 2. (B) breaks that block into a table and maps 4K
> 3. (A) reloads and finds the table after kvm_pgtable_visitor_cb(),
> then descends into it.
> 4. (A) maps some 4K, but before it finishes reads entry mapped by (B).
> 5. (A) returns -EAGAIN although it had mapped a few pages.
> In this case, we don't know what subrange is mapped, just track the whole
> requested mapping range.
>
> - Don't remove tracked mappings from the interval trees if they only
> partially overlap the removal range. Because of the previous bullet point
> we can have a 4K shadow mapping tracked as a 2M range in the interval
> trees. It would be wrong to remove the 2M range when a guest TLBI doesn't
> touch the 4K mapped.
>
> - Check mmu->pgt during mmu unmap notifier, as it could race against
> MMU teardown.
>
> - Make guest_s2_tracking_destroy() canonical mmu only. We simply don't
> need to detach the nodes from the nested mmus' trees. Freeing them
> during canonical mmu's teardown is enough.
>
> Thanks!
>
> [1]: https://lore.kernel.org/kvmarm/86h5jv7qrd.wl-maz@xxxxxxxxxx/
> [2]: https://lore.kernel.org/kvmarm/gerjpm62a2gszzggc6vuai22bf3prfquvfsp7ueumps7vz2ev3@odlmovaklg2b/
> [3]: https://lore.kernel.org/kvmarm/20260911162203.1919330-1-maz@xxxxxxxxxx/
> [4]: https://lore.kernel.org/kvmarm/20260810205038.118843-1-weilin.chang@xxxxxxx/
>
> Marc Zyngier (1):
> KVM: arm64: nv: Drop kvm_s2_mmu pointer from kvm_guest_s2_mapping
>
> Wei-Lin Chang (6):
> KVM: arm64: Use a variable for the canonical IPA in kvm_s2_fault_map()
> KVM: arm64: nv: Introduce guest stage-2 tracking structures
> KVM: arm64: nv: Track guest stage-2 mapping creation
> KVM: arm64: nv: Track guest stage-2 mapping removal
> KVM: arm64: nv: Avoid full shadow stage-2 unmap
> KVM: arm64: Refactor kvm_unmap_gfn_range() with common variables
>
> arch/arm64/include/asm/kvm_host.h | 31 +++++-
> arch/arm64/include/asm/kvm_nested.h | 7 ++
> arch/arm64/kvm/mmu.c | 109 +++++++++++++++++++---
> arch/arm64/kvm/nested.c | 140 +++++++++++++++++++++++++++-
> 4 files changed, 269 insertions(+), 18 deletions(-)
>
> --
> 2.43.0
>