From patchwork Thu May 18 23:14:25 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Kirill A. Shutemov" X-Patchwork-Id: 13247506 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id BC002C7EE2C for ; Thu, 18 May 2023 23:14:59 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 3DC54900004; Thu, 18 May 2023 19:14:56 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 36631900006; Thu, 18 May 2023 19:14:56 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 1928A900004; Thu, 18 May 2023 19:14:56 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0014.hostedemail.com [216.40.44.14]) by kanga.kvack.org (Postfix) with ESMTP id D47DD900006 for ; Thu, 18 May 2023 19:14:55 -0400 (EDT) Received: from smtpin21.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay07.hostedemail.com (Postfix) with ESMTP id 94160160977 for ; Thu, 18 May 2023 23:14:55 +0000 (UTC) X-FDA: 80804932950.21.76AB006 Received: from mga01.intel.com (mga01.intel.com [192.55.52.88]) by imf25.hostedemail.com (Postfix) with ESMTP id 6905EA0006 for ; Thu, 18 May 2023 23:14:53 +0000 (UTC) Authentication-Results: imf25.hostedemail.com; dkim=pass header.d=intel.com header.s=Intel header.b="dw/85lOD"; spf=none (imf25.hostedemail.com: domain of kirill.shutemov@linux.intel.com has no SPF policy when checking 192.55.52.88) smtp.mailfrom=kirill.shutemov@linux.intel.com; dmarc=pass (policy=none) header.from=intel.com ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1684451693; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-transfer-encoding:content-transfer-encoding: in-reply-to:references:dkim-signature; bh=xLT9LPFU1AQssZaFH7RBBlC56RoGAicrWKrEOB1dAMM=; b=wENSOUwUxbfFigF7plkcM7uoht1H1Xc5Rf0XWWrARKYJtWWBVlTp6y6Ua/yuCnMrqyGIv4 CpJYDJxncgeHHMVTbOeRWlgG2mgAzXAA88p/Qti/FX+3QOSkJ2SLFKHB+8h8xXyJaZ9K11 GaLatf6Zuk8rbRuChpRHSUKP6dfczbs= ARC-Seal: i=1; s=arc-20220608; d=hostedemail.com; t=1684451693; a=rsa-sha256; cv=none; b=Vr5oaern/LQ6rH9B5YkijmLogJ8sjJio6mMgHVED5q/KGUFQbiwxk3xCDj7uSXTL5PYncs NF8xWB03QB6s5NBatfO3EOfjddZA0b4Dva0nRxQmXvNJwrLiv4un1WhwB6y6gmE+XhMs0j 4meh60NJWpkyjzaAtui5Z709k2IWN8Y= ARC-Authentication-Results: i=1; imf25.hostedemail.com; dkim=pass header.d=intel.com header.s=Intel header.b="dw/85lOD"; spf=none (imf25.hostedemail.com: domain of kirill.shutemov@linux.intel.com has no SPF policy when checking 192.55.52.88) smtp.mailfrom=kirill.shutemov@linux.intel.com; dmarc=pass (policy=none) header.from=intel.com DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1684451693; x=1715987693; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=7GnZb9XnzUgaFxnvYHGDvO+ncC5iDTvqFCQt/jljqXM=; b=dw/85lOD24ECEqq+yAgkHVDg1sjej9ZYQ9HiczRwrM3TjeY1cbtp0kV1 U1PHs1dVurqP7Jm8Dx4zMguM70ghLdv/e3m/SBs2+DIrReZ4iW4hX2uO5 1u7jsDlMDpr7UkAjoBujtl40CDMtbGsx2S1Q4yozlMd0c3nqs8SaOsSOR aiTMfYLudIcd3OSu/07h1ul97qo5c4pDtQfarS3KqcHCL1WibpnJi7b1m +fk+TNvP3zrSGGhYomkMs4UInz3mWk6Hx3WFx7AfAnwZe5xoV8a8z0uFM Oq79WCjVVSNv36uNeSTCqq/E2tV2He9SRnNnWlWTxGO5Jxqebgg5F2uRs w==; X-IronPort-AV: E=McAfee;i="6600,9927,10714"; a="380431706" X-IronPort-AV: E=Sophos;i="6.00,175,1681196400"; d="scan'208";a="380431706" Received: from fmsmga001.fm.intel.com ([10.253.24.23]) by fmsmga101.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 May 2023 16:14:50 -0700 X-ExtLoop1: 1 X-IronPort-AV: E=McAfee;i="6600,9927,10714"; a="846669539" X-IronPort-AV: E=Sophos;i="6.00,175,1681196400"; d="scan'208";a="846669539" Received: from rkiyama-mobl1.amr.corp.intel.com (HELO box.shutemov.name) ([10.251.222.16]) by fmsmga001-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 18 May 2023 16:14:42 -0700 Received: by box.shutemov.name (Postfix, from userid 1000) id 1420310DFC4; Fri, 19 May 2023 02:14:40 +0300 (+03) From: "Kirill A. Shutemov" To: Borislav Petkov , Andy Lutomirski , Dave Hansen , Sean Christopherson , Andrew Morton , Joerg Roedel , Ard Biesheuvel Cc: Andi Kleen , Kuppuswamy Sathyanarayanan , David Rientjes , Vlastimil Babka , Tom Lendacky , Thomas Gleixner , Peter Zijlstra , Paolo Bonzini , Ingo Molnar , Dario Faggioli , Mike Rapoport , David Hildenbrand , Mel Gorman , marcelo.cerri@canonical.com, tim.gardner@canonical.com, khalid.elmously@canonical.com, philip.cox@canonical.com, aarcange@redhat.com, peterx@redhat.com, x86@kernel.org, linux-mm@kvack.org, linux-coco@lists.linux.dev, linux-efi@vger.kernel.org, linux-kernel@vger.kernel.org, "Kirill A. Shutemov" Subject: [PATCHv12 0/9] mm, x86/cc, efi: Implement support for unaccepted memory Date: Fri, 19 May 2023 02:14:25 +0300 Message-Id: <20230518231434.26080-1-kirill.shutemov@linux.intel.com> X-Mailer: git-send-email 2.39.3 MIME-Version: 1.0 X-Stat-Signature: ncroecd9zxn5wgs6asoeyme3mxjyeju5 X-Rspamd-Server: rspam10 X-Rspamd-Queue-Id: 6905EA0006 X-Rspam-User: X-HE-Tag: 1684451693-682659 X-HE-Meta: U2FsdGVkX18n4sBYHVEUpnUd6rRLwrUc2k8V0dQPMOyYr3dCx2j/pzIsvNPZUbXgOnQx1WlDdX+v+cT4qABCteScWQi4R6itjMTEkxFJ6lw8ivICwTPe8BRqJ/fq7byRKyfI4047rh0JdBVf6nSQLl9olV4twx1H0MuNgMpfImFZA4VY5VGEHNJNpkh1Ob3p6B4adM+uXlIR+4xqhviM0BD2xIpZyP/7kBmImcB0eJpil/Xaic8zj06D9AvaP76azhrFcAj0LnQab0Kp//TARAkjldv0QNud9qSQe+rUHlX76pOqejJViKA9OYVVmwnzmkd1nQKcAx0ip/NIEoXa2fCxkdqJN2B7oXRlnEQPPY/CKiMjPufGgClR3368p6H6LK24HHcHc7kUn7MKhaheSeo4GlhpHzuEcvyBUBjBCRTbzYIt/9oidw43Ev0qFDGthYO+Q+IJHw/iukKvF+rmEVUCjhmVy//4nKMLzNHPF0dKV9yaC7zWtWnMECMUY+/ZREBwbvHx2xTKuMlaucN0+/trtvVPESspgZ2aroNtO90AkFdu/vFFFQMZGehPSf//2/Q4VmcVwx1dJQiGWeFLmsn/fARJPf2sWM/JnUR1xqh4bt9edVRJQ05UtpkZW+Yf0wgoHcGAYnJtTo2gVJXFUlS1l/MAlJO9eBTazenm0X4BT0rwEy3HoAztBAHZQySmxEncDEIKXnm7beH1toKuofcejcY537w9kmn3q/E4+URR6ZilQZ0Lu6rz1N6s4MLxAX3/JQUDWIkO+Xy2OK2QApDDr8jYQ0zx8npuS4t255MNQFgli6nJq/9sRHyzVmP4YIaA/paYrSxImd5wKYwzKhGmNkPlWJwiV97X9wOaQk7RtEIcwMtSiHPt4GhM7ubMdfP0PL2RgPdfzSOGx+oHLZtft1mOXKQ+Q5dpporkg1aFz/5KKEpnc87vsJotBlExhQU+A4P8P4NEKtdNmYu 8iAZBCXB Qp74/WUyxJ92X1PBewkrTBKzRuO9TQ0wPwj6tdOH88XzzMH92XPljKtuW2aORLw2i2sO0Azzxo6Euouyac7aSwiEtQpWz9tHe5UuVerOuR9MCaOvAYuhxrLCrbrFCSAIBAZOB+IWgV0dK8C6W3I05SBLqXZhY2JCgF94mcgj3ntvQwzf6VNKTfNOlwF+nUO5SDMU1NcYyaBnR6YWiqiSb8P7pw5q8K3lszIQy X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: UEFI Specification version 2.9 introduces the concept of memory acceptance: some Virtual Machine platforms, such as Intel TDX or AMD SEV-SNP, requiring memory to be accepted before it can be used by the guest. Accepting happens via a protocol specific for the Virtual Machine platform. Accepting memory is costly and it makes VMM allocate memory for the accepted guest physical address range. It's better to postpone memory acceptance until memory is needed. It lowers boot time and reduces memory overhead. The kernel needs to know what memory has been accepted. Firmware communicates this information via memory map: a new memory type -- EFI_UNACCEPTED_MEMORY -- indicates such memory. Range-based tracking works fine for firmware, but it gets bulky for the kernel: e820 has to be modified on every page acceptance. It leads to table fragmentation, but there's a limited number of entries in the e820 table Another option is to mark such memory as usable in e820 and track if the range has been accepted in a bitmap. One bit in the bitmap represents 2MiB in the address space: one 4k page is enough to track 64GiB or physical address space. In the worst-case scenario -- a huge hole in the middle of the address space -- It needs 256MiB to handle 4PiB of the address space. Any unaccepted memory that is not aligned to 2M gets accepted upfront. The approach lowers boot time substantially. Boot to shell is ~2.5x faster for 4G TDX VM and ~4x faster for 64G. TDX-specific code isolated from the core of unaccepted memory support. It supposed to help to plug-in different implementation of unaccepted memory such as SEV-SNP. -- Fragmentation study -- Vlastimil and Mel were concern about effect of unaccepted memory on fragmentation prevention measures in page allocator. I tried to evaluate it, but it is tricky. As suggested I tried to run multiple parallel kernel builds and follow how often kmem:mm_page_alloc_extfrag gets hit. See results in the v9 of the patchset[1][2] [1] https://lore.kernel.org/all/20230330114956.20342-1-kirill.shutemov@linux.intel.com [2] https://lore.kernel.org/all/20230416191940.ex7ao43pmrjhru2p@box.shutemov.name --- The tree can be found here: https://github.com/intel/tdx.git guest-unaccepted-memory The patchset depends on MAX_ORDER changes in MM tree. v12: - Re-initialize 'unaccepted_table' variable from decompressor to cover some boot scenarios; - Add missing memblock_reserve() for the unaccepted memory configuration table (Mika); - Add efi.unaccepted into efi_tables (Tom); - Do not build tdx-shared.o for !TDX (Tom); - Typo fix (Liam) - Whitespace fix; - Reviewed-bys from Liam, Tom and Ard; v11: - Restructure the code to make it less x86-specific (suggested by Ard): + use EFI configuration table instead of zero-page to pass down bitmap; + do not imply 1bit == 2M in bitmap; + move bulk of the code under driver/firmware/efi; - The bitmap only covers unaccpeted memory now. All memory that is not covered by the bitmap assumed accepted; - Reviewed-by from Ard; v10: - Restructure code around zones_with_unaccepted_pages static brach to avoid unnecessary function calls (Suggested by Vlastimil); - Drop mentions of PageUnaccepted(); - Drop patches that add fake unaccepted memory support and sysfs handle to accept memory manually; - Add Reviewed-by from Vlastimil; v9: - Accept memory up to high watermark when kernel runs out of free memory; - Treat unaccepted memory as unusable in __zone_watermark_unusable_free(); - Per-zone unaccepted memory accounting; - All pages on unaccepted list are MAX_ORDER now; - accept_memory=eager in cmdline to pre-accept memory during the boot; - Implement fake unaccepted memory; - Sysfs handle to accept memory manually; - Drop PageUnaccepted(); - Rename unaccepted_pages static key to zones_with_unaccepted_pages; v8: - Rewrite core-mm support for unaccepted memory (patch 02/14); - s/UnacceptedPages/Unaccepted/ in meminfo; - Drop arch/x86/boot/compressed/compiler.h; - Fix build errors; - Adjust commit messages and comments; - Reviewed-bys from Dave and Borislav; - Rebased to tip/master. v7: - Rework meminfo counter to use PageUnaccepted() and move to generic code; - Fix range_contains_unaccepted_memory() on machines without unaccepted memory; - Add Reviewed-by from David; v6: - Fix load_unaligned_zeropad() on machine with unaccepted memory; - Clear PageUnaccepted() on merged pages, leaving it only on head; - Clarify error handling in allocate_e820(); - Fix build with CONFIG_UNACCEPTED_MEMORY=y, but without TDX; - Disable kexec at boottime instead of build conflict; - Rebased to tip/master; - Spelling fixes; - Add Reviewed-by from Mike and David; v5: - Updates comments and commit messages; + Explain options for unaccepted memory handling; - Expose amount of unaccepted memory in /proc/meminfo - Adjust check in page_expected_state(); - Fix error code handling in allocate_e820(); - Centralize __pa()/__va() definitions in the boot stub; - Avoid includes from the main kernel in the boot stub; - Use an existing hole in boot_param for unaccepted_memory, instead of adding to the end of the structure; - Extract allocate_unaccepted_memory() form allocate_e820(); - Complain if there's unaccepted memory, but kernel does not support it; - Fix vmstat counter; - Split up few preparatory patches; - Random readability adjustments; v4: - PageBuddyUnaccepted() -> PageUnaccepted; - Use separate page_type, not shared with offline; - Rework interface between core-mm and arch code; - Adjust commit messages; - Ack from Mike; Kirill A. Shutemov (9): mm: Add support for unaccepted memory efi/x86: Get full memory map in allocate_e820() efi/libstub: Implement support for unaccepted memory x86/boot/compressed: Handle unaccepted memory efi: Add unaccepted memory support efi/unaccepted: Avoid load_unaligned_zeropad() stepping into unaccepted memory x86/tdx: Make _tdx_hypercall() and __tdx_module_call() available in boot stub x86/tdx: Refactor try_accept_one() x86/tdx: Add unaccepted memory support arch/x86/Kconfig | 2 + arch/x86/boot/compressed/Makefile | 3 +- arch/x86/boot/compressed/efi.h | 10 + arch/x86/boot/compressed/error.c | 19 ++ arch/x86/boot/compressed/error.h | 1 + arch/x86/boot/compressed/kaslr.c | 35 ++- arch/x86/boot/compressed/mem.c | 63 +++++ arch/x86/boot/compressed/misc.c | 7 + arch/x86/boot/compressed/misc.h | 6 + arch/x86/boot/compressed/tdx-shared.c | 2 + arch/x86/boot/compressed/tdx.c | 37 +++ arch/x86/coco/tdx/Makefile | 2 +- arch/x86/coco/tdx/tdx-shared.c | 95 +++++++ arch/x86/coco/tdx/tdx.c | 118 +-------- arch/x86/include/asm/efi.h | 2 + arch/x86/include/asm/shared/tdx.h | 53 ++++ arch/x86/include/asm/tdx.h | 21 +- arch/x86/include/asm/unaccepted_memory.h | 23 ++ arch/x86/platform/efi/efi.c | 3 + drivers/base/node.c | 7 + drivers/firmware/efi/Kconfig | 14 ++ drivers/firmware/efi/Makefile | 1 + drivers/firmware/efi/efi.c | 26 ++ drivers/firmware/efi/libstub/Makefile | 2 + drivers/firmware/efi/libstub/bitmap.c | 41 +++ drivers/firmware/efi/libstub/efistub.h | 6 + drivers/firmware/efi/libstub/find.c | 43 ++++ .../firmware/efi/libstub/unaccepted_memory.c | 234 ++++++++++++++++++ drivers/firmware/efi/libstub/x86-stub.c | 39 +-- drivers/firmware/efi/unaccepted_memory.c | 138 +++++++++++ fs/proc/meminfo.c | 5 + include/linux/efi.h | 13 +- include/linux/mm.h | 19 ++ include/linux/mmzone.h | 8 + mm/memblock.c | 9 + mm/mm_init.c | 7 + mm/page_alloc.c | 173 +++++++++++++ mm/vmstat.c | 3 + 38 files changed, 1125 insertions(+), 165 deletions(-) create mode 100644 arch/x86/boot/compressed/mem.c create mode 100644 arch/x86/boot/compressed/tdx-shared.c create mode 100644 arch/x86/coco/tdx/tdx-shared.c create mode 100644 arch/x86/include/asm/unaccepted_memory.h create mode 100644 drivers/firmware/efi/libstub/bitmap.c create mode 100644 drivers/firmware/efi/libstub/find.c create mode 100644 drivers/firmware/efi/libstub/unaccepted_memory.c create mode 100644 drivers/firmware/efi/unaccepted_memory.c