[GIT PULL 0/6] KVM/vfio: Use file-based reference counting for KVM

From: Christian Borntraeger

Date: Fri Oct 09 2026 - 10:42:38 EST



Paolo,

The following changes since commit df2908090cda368b01ff43709f51890076c56157:

Linux 7.3-rc2 (2026-09-06 15:07:20 -0700)

are available in the Git repository at:

git://git.kernel.org/pub/scm/linux/kernel/git/kvms390/linux.git tags/kvm-s390-next-7.4-1

for you to fetch changes up to c22295d0d75f5590fdde5493cb90e2d50d5f508e:

KVM: Remove unused file_is_kvm (2026-10-02 10:40:01 +0200)


The tag points to the vfio_file_reference branch of the kvms390 repo
https://git.kernel.org/pub/scm/linux/kernel/git/kvms390/linux.git/log/?h=vfio_file_reference



----------------------------------------------------------------
KVM/vfio: Use file-based reference counting for KVM

This series switches the KVM-VFIO interface and external consumers over to
standard file-based reference counting, eliminating all external KVM symbol
exports.

Currently, VFIO integrates with KVM by looking up kvm_get_kvm_safe() and
kvm_put_kvm() dynamically using symbol_get(), manually tracking module
reference counts and storing a put_kvm function pointer in struct
vfio_device.

In the ARM64-on-s390 architecture, a second concurrent KVM module
(kvm-arm64) is introduced alongside native KVM to host hardware-accelerated
ARM64 guests. Having exported global symbols (like kvm_get_kvm/kvm_put_kvm)
creates symbol conflicts and prevents clean coexistence of two KVM modules.

Additionally, the file based counting simplifies the code and reuses
the existing fs refcounting.

Instead of passing raw KVM pointers and managing module symbols manually, the
interface now passes the underlying VM file descriptor throughout VFIO and
associated architecture subsystems. To safely extract the KVM instance from a
file, an architecture-namespaced helper mechanism is introduced that verifies
the file belongs to the expected KVM implementation before accessing its
internal state. A back-pointer from the KVM instance to its associated file is
maintained across its lifecycle so subsystems can safely acquire file
references on demand. Finally, with VFIO, architecture page tracking, and
device hooks converted to use file references, the remaining KVM reference-
counting exports are restricted strictly to internal KVM modules.

----------------------------------------------------------------
Steffen Eiden (6):
KVM: Introduce file_to_kvm_<arch>() infrastructure
KVM: Add file back-pointer to struct kvm
KVM: x86: Use file_to_kvm_x86() in SEV
KVM/vfio: Use file-based reference counting for KVM
KVM: Restrict kvm_get_kvm/kvm_put_kvm export to internal KVM modules
KVM: Remove unused file_is_kvm

arch/s390/include/asm/kvm_host_s390.h | 4 ++-
arch/s390/kvm/s390/pci.c | 9 ++++--
arch/x86/include/asm/kvm_host.h | 2 ++
arch/x86/include/asm/kvm_page_track.h | 10 +++---
arch/x86/kvm/Makefile | 4 +--
arch/x86/kvm/mmu/page_track.c | 22 +++++++++-----
arch/x86/kvm/svm/sev.c | 8 ++---
drivers/s390/crypto/vfio_ap_ops.c | 20 ++++++++----
drivers/vfio/device_cdev.c | 2 +-
drivers/vfio/group.c | 13 ++++++--
drivers/vfio/vfio.h | 14 ++++-----
drivers/vfio/vfio_main.c | 57 +++++++++++------------------------
include/linux/kvm_host.h | 19 +++++++++++-
include/linux/vfio.h | 5 ++-
virt/kvm/kvm_main.c | 21 +++++++++----
virt/kvm/vfio.c | 13 +++++---
16 files changed, 132 insertions(+), 91 deletions(-)