Hi Sean, Ackerley,

On Mon, 31 Aug 2026 at 01:25, Ackerley Tng via B4 Relay
<[email protected]> wrote:
...
> +       kvm.gmem_in_place_conversion=
> +                       [KVM] Controls whether KVM enables in-place conversion
> +                       support for guest_memfd and tracks the private/shared
> +                       state of memory per guest_memfd instead of per VM.
> +
> +                       If enabled, KVM enables the KVM_SET_MEMORY_ATTRIBUTES2
> +                       ioctl on guest_memfd file descriptors and disables the
> +                       legacy VM-scoped KVM_SET_MEMORY_ATTRIBUTES ioctl for
> +                       private memory state tracking. Only the
> +                       KVM_MEMORY_ATTRIBUTE_PRIVATE attribute moves to
> +                       per-guest_memfd tracking; other attributes remain
> +                       per-VM.
> +
> +                       This parameter toggles KVM's in-place conversion
> +                       capability support. Whether a VMM uses separate 
> backends
> +                       or out-of-place memory management is determined by
> +                       userspace VMM design.
> +
> +                       Note, this parameter is only available when
> +                       CONFIG_KVM_VM_MEMORY_ATTRIBUTES=y. When
> +                       CONFIG_KVM_VM_MEMORY_ATTRIBUTES is not set, in-place
> +                       conversion is unconditionally enabled.
> +
> +                       Default is Y (on).

The parameter is only settable when CONFIG_KVM_VM_MEMORY_ATTRIBUTES=y, and
in that config gmem_in_place_conversion initialises to
!IS_ENABLED(CONFIG_KVM_VM_MEMORY_ATTRIBUTES), i.e. N, not Y. Is the doc line
wrong, or is N-by-default not what was intended here?

Cheers,
/fuad

> +
>         kvm.nx_huge_pages=
>                         [KVM] Controls the software workaround for the
>                         X86_BUG_ITLB_MULTIHIT bug.
> diff --git a/arch/x86/include/asm/kvm_host.h b/arch/x86/include/asm/kvm_host.h
> index 83e26ce45fb79..e840418427a1d 100644
> --- a/arch/x86/include/asm/kvm_host.h
> +++ b/arch/x86/include/asm/kvm_host.h
> @@ -1851,7 +1851,9 @@ enum kvm_intr_type {
>         ((vcpu) && (vcpu)->arch.handling_intr_from_guest && \
>          (!!in_nmi() == ((vcpu)->arch.handling_intr_from_guest == 
> KVM_HANDLING_NMI)))
>
> -#ifdef CONFIG_KVM_VM_MEMORY_ATTRIBUTES
> +#if defined(CONFIG_KVM_SW_PROTECTED_VM) ||     \
> +    defined(CONFIG_KVM_INTEL_TDX) ||           \
> +    defined(CONFIG_KVM_AMD_SEV)
>  #define kvm_arch_has_private_mem(kvm) ((kvm)->arch.has_private_mem)
>  #endif
>  #ifdef CONFIG_HAVE_KVM_ARCH_GMEM_CONVERT
> diff --git a/arch/x86/kvm/Kconfig b/arch/x86/kvm/Kconfig
> index abb108886733a..2c3c22aeafa54 100644
> --- a/arch/x86/kvm/Kconfig
> +++ b/arch/x86/kvm/Kconfig
> @@ -81,13 +81,21 @@ config KVM_WERROR
>           If in doubt, say "N".
>
>  config KVM_VM_MEMORY_ATTRIBUTES
> -       bool
> +       bool "Enable per-VM PRIVATE vs. SHARED attributes (for CoCo VMs)"
> +       depends on KVM_SW_PROTECTED_VM || KVM_INTEL_TDX || KVM_AMD_SEV
> +       help
> +         Enable support for tracking PRIVATE vs. SHARED memory using per-VM
> +         memory attributes.  Using per-VM attributes is deprecated in favor 
> of
> +         tracking PRIVATE state in guest_memfd.  Select this if you need to 
> run
> +         CoCo VMs using a VMM that doesn't support guest_memfd memory
> +         attributes.
> +
> +         If unsure, say N.
>
>  config KVM_SW_PROTECTED_VM
>         bool "Enable support for KVM software-protected VMs"
>         depends on EXPERT
>         depends on KVM_X86 && X86_64
> -       select KVM_VM_MEMORY_ATTRIBUTES
>         help
>           Enable support for KVM software-protected VMs.  Currently, software-
>           protected VMs are purely a development and testing vehicle for
> @@ -138,7 +146,6 @@ config KVM_INTEL_TDX
>         bool "Intel Trust Domain Extensions (TDX) support"
>         default y
>         depends on INTEL_TDX_HOST
> -       select KVM_VM_MEMORY_ATTRIBUTES
>         select HAVE_KVM_ARCH_GMEM_POPULATE
>         help
>           Provides support for launching Intel Trust Domain Extensions (TDX)
> @@ -162,7 +169,6 @@ config KVM_AMD_SEV
>         depends on KVM_AMD && X86_64
>         depends on CRYPTO_DEV_SP_PSP && !(KVM_AMD=y && CRYPTO_DEV_CCP_DD=m)
>         select ARCH_HAS_CC_PLATFORM
> -       select KVM_VM_MEMORY_ATTRIBUTES
>         select HAVE_KVM_ARCH_GMEM_CONVERT
>         select HAVE_KVM_ARCH_GMEM_RECLAIM
>         select HAVE_KVM_ARCH_GMEM_INVALIDATE
> diff --git a/virt/kvm/kvm_main.c b/virt/kvm/kvm_main.c
> index 05c518c9b8078..929fd3e1a01e6 100644
> --- a/virt/kvm/kvm_main.c
> +++ b/virt/kvm/kvm_main.c
> @@ -103,7 +103,10 @@ static bool __ro_after_init allow_unsafe_mappings;
>  module_param(allow_unsafe_mappings, bool, 0444);
>
>  #ifdef kvm_arch_has_private_mem
> -bool __ro_after_init gmem_in_place_conversion = false;
> +bool __ro_after_init gmem_in_place_conversion = 
> !IS_ENABLED(CONFIG_KVM_VM_MEMORY_ATTRIBUTES);
> +#ifdef CONFIG_KVM_VM_MEMORY_ATTRIBUTES
> +module_param(gmem_in_place_conversion, bool, 0444);
> +#endif
>  EXPORT_SYMBOL_FOR_KVM_INTERNAL(gmem_in_place_conversion);
>  #endif
>
>
> --
> 2.55.0.897.gb25b4bd76c-goog
>
>

Reply via email to