On 8/8/2026 5:52 AM, Ackerley Tng via B4 Relay wrote: > From: Ackerley Tng <[email protected]> > > Make gmem_in_place_conversion a module parameter so that userspace can > configure enable or disable the use of VM-level memory attributes. The > module parameter is only available if CONFIG_KVM_VM_MEMORY_ATTRIBUTES is > enabled. > > To avoid inconsistencies in the way memory attributes are tracked in KVM > and guest_memfd, the vm_memory_attributes module_param is made
The description is stale, since there is no module_param called vm_memory_attributes? > read-only (0444). > > Since selecting CONFIG_KVM_VM_MEMORY_ATTRIBUTES disables in-place > conversion, "selecting CONFIG_KVM_VM_MEMORY_ATTRIBUTES" doesn't necessarily disable in-place conversion, it also depends on the setting of gmem_in_place_conversion. To be accurate, maybe add "by default"? actually make CONFIG_KVM_VM_MEMORY_ATTRIBUTES selectable. Make > the config only selectable for (CoCo) VM types that might use > vm_memory_attributes. > > Since memory attributes are trackable in guest_memfd, the concept of having > private memory is no longer dependent on > CONFIG_KVM_VM_MEMORY_ATTRIBUTES. Define kvm_arch_has_private_mem() based on > platform config, so that having private memory is dependent on (CoCo) VM > type. > > Signed-off-by: Sean Christopherson <[email protected]> > Reviewed-by: Fuad Tabba <[email protected]> > Tested-by: Shivank Garg <[email protected]> > [Define module_param only if CONFIG_KVM_VM_MEMORY_ATTRIBUTES is enabled] > Suggested-by: Xiaoyao Li <[email protected]> > Reviewed-by: Xiaoyao Li <[email protected]> > Signed-off-by: Ackerley Tng <[email protected]> > --- > arch/x86/include/asm/kvm_host.h | 4 +++- > arch/x86/kvm/Kconfig | 14 ++++++++++---- > virt/kvm/kvm_main.c | 5 ++++- > 3 files changed, 17 insertions(+), 6 deletions(-) > > diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h > index 497da6aaf2942..bb2c1ade62cf9 100644 > --- a/arch/x86/include/asm/kvm_host.h > +++ b/arch/x86/include/asm/kvm_host.h > @@ -1851,7 +1851,9 @@ enum kvm_intr_type { > ((vcpu) && (vcpu)->arch.handling_intr_from_guest && \ > (!!in_nmi() == ((vcpu)->arch.handling_intr_from_guest == > KVM_HANDLING_NMI))) > > -#ifdef CONFIG_KVM_VM_MEMORY_ATTRIBUTES > +#if defined(CONFIG_KVM_SW_PROTECTED_VM) || \ > + defined(CONFIG_KVM_INTEL_TDX) || \ > + defined(CONFIG_KVM_AMD_SEV) > #define kvm_arch_has_private_mem(kvm) ((kvm)->arch.has_private_mem) > #endif > > diff --git a/arch/x86/kvm/Kconfig b/arch/x86/kvm/Kconfig > index abb108886733a..2c3c22aeafa54 100644 > --- a/arch/x86/kvm/Kconfig > +++ b/arch/x86/kvm/Kconfig > @@ -81,13 +81,21 @@ config KVM_WERROR > If in doubt, say "N". > > config KVM_VM_MEMORY_ATTRIBUTES > - bool > + bool "Enable per-VM PRIVATE vs. SHARED attributes (for CoCo VMs)" > + depends on KVM_SW_PROTECTED_VM || KVM_INTEL_TDX || KVM_AMD_SEV > + help > + Enable support for tracking PRIVATE vs. SHARED memory using per-VM > + memory attributes. Using per-VM attributes is deprecated in favor of > + tracking PRIVATE state in guest_memfd. Select this if you need to run > + CoCo VMs using a VMM that doesn't support guest_memfd memory > + attributes. > + > + If unsure, say N. > > config KVM_SW_PROTECTED_VM > bool "Enable support for KVM software-protected VMs" > depends on EXPERT > depends on KVM_X86 && X86_64 > - select KVM_VM_MEMORY_ATTRIBUTES > help > Enable support for KVM software-protected VMs. Currently, software- > protected VMs are purely a development and testing vehicle for > @@ -138,7 +146,6 @@ config KVM_INTEL_TDX > bool "Intel Trust Domain Extensions (TDX) support" > default y > depends on INTEL_TDX_HOST > - select KVM_VM_MEMORY_ATTRIBUTES > select HAVE_KVM_ARCH_GMEM_POPULATE > help > Provides support for launching Intel Trust Domain Extensions (TDX) > @@ -162,7 +169,6 @@ config KVM_AMD_SEV > depends on KVM_AMD && X86_64 > depends on CRYPTO_DEV_SP_PSP && !(KVM_AMD=y && CRYPTO_DEV_CCP_DD=m) > select ARCH_HAS_CC_PLATFORM > - select KVM_VM_MEMORY_ATTRIBUTES > select HAVE_KVM_ARCH_GMEM_CONVERT > select HAVE_KVM_ARCH_GMEM_RECLAIM > select HAVE_KVM_ARCH_GMEM_INVALIDATE > diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c > index c8faf1cb82167..85dfc3f5af805 100644 > --- a/virt/kvm/kvm_main.c > +++ b/virt/kvm/kvm_main.c > @@ -103,7 +103,10 @@ static bool __ro_after_init allow_unsafe_mappings; > module_param(allow_unsafe_mappings, bool, 0444); > > #ifdef kvm_arch_has_private_mem > -bool __ro_after_init gmem_in_place_conversion = false; > +bool __ro_after_init gmem_in_place_conversion = > !IS_ENABLED(CONFIG_KVM_VM_MEMORY_ATTRIBUTES); > +#ifdef CONFIG_KVM_VM_MEMORY_ATTRIBUTES > +module_param(gmem_in_place_conversion, bool, 0444); > +#endif > EXPORT_SYMBOL_FOR_KVM_INTERNAL(gmem_in_place_conversion); > #endif > >
