|
|
Log in / Subscribe / Register

KVM: x86: nSVM: Improve PAT virtualization

From:  Jim Mattson <jmattson-AT-google.com>
To:  Paolo Bonzini <pbonzini-AT-redhat.com>, Jonathan Corbet <corbet-AT-lwn.net>, Shuah Khan <skhan-AT-linuxfoundation.org>, Sean Christopherson <seanjc-AT-google.com>, Thomas Gleixner <tglx-AT-kernel.org>, Ingo Molnar <mingo-AT-redhat.com>, Borislav Petkov <bp-AT-alien8.de>, Dave Hansen <dave.hansen-AT-linux.intel.com>, x86-AT-kernel.org, "H. Peter Anvin" <hpa-AT-zytor.com>, kvm-AT-vger.kernel.org, linux-doc-AT-vger.kernel.org, linux-kernel-AT-vger.kernel.org, linux-kselftest-AT-vger.kernel.org, Yosry Ahmed <yosry-AT-kernel.org>
Subject:  [PATCH v6 00/10] KVM: x86: nSVM: Improve PAT virtualization
Date:  Thu, 26 Mar 2026 10:49:18 -0700
Message-ID:  <20260326174944.3820245-1-jmattson@google.com>
Cc:  Jim Mattson <jmattson-AT-google.com>
Archive-link:  Article

Currently, KVM's implementation of nested SVM treats the PAT MSR the same
way whether or not nested NPT is enabled: L1 and L2 share a single
PAT. However, the AMD APM specifies that when nested NPT is enabled, the host
(L1) and the guest (L2) should have independent PATs: hPAT for L1 and gPAT
for L2.

This patch series implements independent PATs for L1 and L2 when nested NPT
is enabled, but only when a new quirk, KVM_X86_QUIRK_NESTED_SVM_SHARED_PAT,
is disabled. By default, the quirk is enabled, preserving KVM's legacy
behavior. When the quirk is disabled, KVM correctly virtualizes a separate
PAT register for L2, using the g_pat field in the VMCB.

Guest accesses to the IA32_PAT MSR are redirected to either hPAT or gPAT
depending on the current mode and whether nested NPT is enabled. All other
accesses, including userspace accesses via KVM_{GET,SET}_MSRS, continue to
reference hPAT. L2's gPAT is saved and restored via a new 'gpat' field in
kvm_svm_nested_state_hdr, which is within the existing padding of the header
to maintain ABI compatibility.

v1: https://lore.kernel.org/kvm/20260113003016.3511895-1-jmat...
v2: https://lore.kernel.org/kvm/20260115232154.3021475-1-jmat...
v3: https://lore.kernel.org/kvm/20260205214326.1029278-1-jmat...
v4: https://lore.kernel.org/kvm/20260212155905.3448571-1-jmat...
v5: https://lore.kernel.org/kvm/20260224005500.1471972-1-jmat...

  v5 -> v6:
  * Drop the patch to remove vmcb_is_dirty() [already accepted]
  * Introduce a new x86 quirk, KVM_X86_QUIRK_NESTED_SVM_SHARED_PAT
  * Drop forward and backward compatibility. Save/restore across
    a quirk change is now the responsibility of userspace
  * Document the kvm_svm_nested_state_hdr change
  * Update the selftest to use the new quirk

Jim Mattson (10):
  KVM: x86: Define KVM_X86_QUIRK_NESTED_SVM_SHARED_PAT
  KVM: x86: nSVM: Clear VMCB_NPT clean bit when updating hPAT from guest
    mode
  KVM: x86: nSVM: Cache and validate vmcb12 g_pat
  KVM: x86: nSVM: Set vmcb02.g_pat correctly for nested NPT
  KVM: x86: nSVM: Redirect IA32_PAT accesses to either hPAT or gPAT
  KVM: x86: Remove common handling of MSR_IA32_CR_PAT
  KVM: x86: nSVM: Save gPAT to vmcb12.g_pat on VMEXIT
  KVM: Documentation: document KVM_{GET,SET}_NESTED_STATE for SVM
  KVM: x86: nSVM: Save/restore gPAT with KVM_{GET,SET}_NESTED_STATE
  KVM: selftests: nSVM: Add svm_nested_pat test

 Documentation/virt/kvm/api.rst                |  26 ++
 arch/x86/include/asm/kvm_host.h               |   3 +-
 arch/x86/include/uapi/asm/kvm.h               |   2 +
 arch/x86/kvm/svm/nested.c                     |  55 +++-
 arch/x86/kvm/svm/svm.c                        |  54 +++-
 arch/x86/kvm/svm/svm.h                        |  15 +-
 arch/x86/kvm/vmx/vmx.c                        |   9 +-
 arch/x86/kvm/x86.c                            |   9 -
 tools/arch/x86/include/uapi/asm/kvm.h         |   2 +
 tools/testing/selftests/kvm/Makefile.kvm      |   1 +
 .../selftests/kvm/x86/svm_nested_pat_test.c   | 304 ++++++++++++++++++
 11 files changed, 443 insertions(+), 37 deletions(-)
 create mode 100644 tools/testing/selftests/kvm/x86/svm_nested_pat_test.c

base-commit: 3d6cdcc8883b5726513d245eef0e91cabfc397f7
-- 
2.53.0.1018.g2bb0e51243-goog




Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds