[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v3 4/6] x86: extend do_mmu_update() to support returning the old PTE value


  • To: xen-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Kevin Lampis <kevin.lampis@xxxxxxxxxx>
  • Date: Thu, 1 Oct 2026 18:47:47 +0100
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=citrix.com; dmarc=pass action=none header.from=citrix.com; dkim=pass header.d=citrix.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=9yukoTJTvfx2/TW/Z+5HPZvKVMIqRm9iNuXR7qMg8Uk=; b=Zz5lxKZIHVIC0Zfo9eIn9kAAXY8xDgQ3omLk0dsDHjHEOXRLxe9PpLDHp8TfA+aoYnHCYjgeD6lJYcuPZwBjwfzBXnm32FzZq967MXH22DsmZdlLQlscOgN1QTOBREaypTikt6TTEn53zz3LNaaAPhswwWfTWG3FvkHvYBE41x56VeRUX7/ith+NPxVB2nZ1eDTRvnW+QekVX6KFwRq1x9AVtW6xxIv+2UUW0sZczXeyKIgN+k0NGTiTGQtzzzuX7mSfdLfYbo6AJ0QRoge2XO6sNRYPmsebMiGXFsL7npiRsqIHhm06YFGZ7WSSaydeLYWeE+Lmlw9iad862fjIwg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=MH+CSoYzPrJyCfvoCgbuT0z1KY38FDEP9Cq3/BwZZR1XPVHSBp9EUuEjR33eYWGzVa1JHahL4SNSqdCSx2fnN9kwfDyrixYGXIy3WfziZceUaNZUjNd3+bI3kN7LOrQOExe8pwDih76PjHxz7aAOMMiFREIybynw3SBJ2rAVdObLnOjNl9JeForvlPOUsj3YRDYWnbph9N6WhAqASv+XMoPq7dZotgxaCEBbN20ICgdYIN6IobFD9ElCpJ3WiYheUUyUyGVUOuMHb/1urXWZD8PIbwNgviqdx6EbjxycJcqOp/JX0tuG+dBN0DSPAKFR0cNxt+r+0b4d8WcMjG8Rzg==
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=citrix.com header.i="@citrix.com" header.h="From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck"
  • Authentication-results: mx.microsoft.com 1; dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=citrix.com;
  • Cc: jbeulich@xxxxxxxx, andrew.cooper3@xxxxxxxxxx, teddy.astie@xxxxxxxxxx, Kevin Lampis <kevin.lampis@xxxxxxxxxx>
  • Delivery-date: Thu, 01 Oct 2026 17:46:18 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

A new sub-op MMU_PT_UPDATE_SWAP when used will do an atomic swap to set
the new value and return the old PTE value through the req.val field.

- The old PTE value is passed back to the guest through the req.val field

If MMU_PT_UPDATE_SWAP is not set then the old behavior is preserved
  do_mmu_update -> mod_l*_entry -> UPDATE_ENTRY -> paging_write_guest_entry

The new MMU_PT_UPDATE_SWAP call chain looks like this
  do_mmu_update -> mod_l*_entry -> UPDATE_ENTRY -> paging_cmpxchg_guest_entry

Signed-off-by: Kevin Lampis <kevin.lampis@xxxxxxxxxx>
---
Changes in v3:
- Do swap for l2, l3, l4
- Allow all values not just 0

Changes in v2:
- Add a sub-op to mmu_update instead of new hypercall
- Rename to "swap" instead of "clear", although only `0` is accepted
- Remove spurious curly brace from `case PGT_l1_page_table:`
- Restructure `case PGT_l1_page_table:` to avoid diff churn
- Add missing `MMU_PT_UPDATE_SWAP` check for the second
  `PGT_writable_page` block
---
 xen/arch/x86/mm.c        | 80 ++++++++++++++++++++++++++++++++++++----
 xen/include/public/xen.h |  1 +
 2 files changed, 74 insertions(+), 7 deletions(-)

diff --git a/xen/arch/x86/mm.c b/xen/arch/x86/mm.c
index 535a62139cad..a2d05d6c7113 100644
--- a/xen/arch/x86/mm.c
+++ b/xen/arch/x86/mm.c
@@ -4111,6 +4111,7 @@ long do_mmu_update(
         case MMU_NORMAL_PT_UPDATE:
         case MMU_PT_UPDATE_PRESERVE_AD:
         case MMU_PT_UPDATE_NO_TRANSLATE:
+        case MMU_PT_UPDATE_SWAP:
         {
             p2m_type_t p2mt;
 
@@ -4172,10 +4173,27 @@ long do_mmu_update(
                      update_flags = PTE_UPDATE_PRESERVE_AD;
                 else if ( cmd == MMU_PT_UPDATE_NO_TRANSLATE )
                      update_flags = PTE_UPDATE_NO_TRANSLATE;
+                else if ( cmd == MMU_PT_UPDATE_SWAP )
+                     update_flags = PTE_UPDATE_SWAP;
 
                 switch ( page->u.inuse.type_info & PGT_type_mask )
                 {
                 case PGT_l1_page_table:
+                    if ( cmd == MMU_PT_UPDATE_SWAP )
+                    {
+                        l1_pgentry_t ol1e;
+                        rc = mod_l1_entry(va, l1e_from_intpte(req.val), mfn,
+                                          update_flags, v, pg_owner, &ol1e);
+
+                        if ( !rc )
+                        {
+                            req.val = ol1e.l1;
+                            if ( unlikely(copy_to_guest(ureqs, &req, 1)) )
+                                rc = -EFAULT;
+                        }
+                        break;
+                    }
+
                     rc = mod_l1_entry(va, l1e_from_intpte(req.val), mfn,
                                       update_flags, v, pg_owner, NULL);
                     break;
@@ -4183,8 +4201,22 @@ long do_mmu_update(
                 case PGT_l2_page_table:
                     if ( unlikely(pg_owner != pt_owner) )
                         break;
-                    rc = mod_l2_entry(va, l2e_from_intpte(req.val), mfn,
-                                      update_flags, v, NULL);
+                    if ( cmd == MMU_PT_UPDATE_SWAP )
+                    {
+                        l2_pgentry_t ol2e;
+                        rc = mod_l2_entry(va, l2e_from_intpte(req.val), mfn,
+                                          update_flags, v, &ol2e);
+
+                        if ( !rc )
+                        {
+                            req.val = ol2e.l2;
+                            if ( unlikely(copy_to_guest(ureqs, &req, 1)) )
+                                rc = -EFAULT;
+                        }
+                    }
+                    else
+                        rc = mod_l2_entry(va, l2e_from_intpte(req.val), mfn,
+                                          update_flags, v, NULL);
                     if ( !rc )
                         flush_linear_pt = true;
                     break;
@@ -4192,8 +4224,22 @@ long do_mmu_update(
                 case PGT_l3_page_table:
                     if ( unlikely(pg_owner != pt_owner) )
                         break;
-                    rc = mod_l3_entry(va, l3e_from_intpte(req.val), mfn,
-                                      update_flags, v, NULL);
+                    if ( cmd == MMU_PT_UPDATE_SWAP )
+                    {
+                        l3_pgentry_t ol3e;
+                        rc = mod_l3_entry(va, l3e_from_intpte(req.val), mfn,
+                                          update_flags, v, &ol3e);
+
+                        if ( !rc )
+                        {
+                            req.val = ol3e.l3;
+                            if ( unlikely(copy_to_guest(ureqs, &req, 1)) )
+                                rc = -EFAULT;
+                        }
+                    }
+                    else
+                        rc = mod_l3_entry(va, l3e_from_intpte(req.val), mfn,
+                                          update_flags, v, NULL);
                     if ( !rc )
                         flush_linear_pt = true;
                     break;
@@ -4201,8 +4247,22 @@ long do_mmu_update(
                 case PGT_l4_page_table:
                     if ( unlikely(pg_owner != pt_owner) )
                         break;
-                    rc = mod_l4_entry(va, l4e_from_intpte(req.val), mfn,
-                                      update_flags, v, NULL);
+                    if ( cmd == MMU_PT_UPDATE_SWAP )
+                    {
+                        l4_pgentry_t ol4e;
+                        rc = mod_l4_entry(va, l4e_from_intpte(req.val), mfn,
+                                          update_flags, v, &ol4e);
+
+                        if ( !rc )
+                        {
+                            req.val = ol4e.l4;
+                            if ( unlikely(copy_to_guest(ureqs, &req, 1)) )
+                                rc = -EFAULT;
+                        }
+                    }
+                    else
+                        rc = mod_l4_entry(va, l4e_from_intpte(req.val), mfn,
+                                          update_flags, v, NULL);
                     if ( !rc )
                         flush_linear_pt = true;
                     if ( !rc && pt_owner->arch.pv.xpti )
@@ -4230,6 +4290,11 @@ long do_mmu_update(
                     break;
 
                 case PGT_writable_page:
+                    if ( unlikely(cmd == MMU_PT_UPDATE_SWAP) )
+                    {
+                        rc = -EINVAL;
+                        break;
+                    }
                     perfc_incr(writable_mmu_updates);
                     paging_write_guest_entry(v, va, req.val, mfn);
                     rc = 0;
@@ -4239,7 +4304,8 @@ long do_mmu_update(
                 if ( rc == -EINTR )
                     rc = -ERESTART;
             }
-            else if ( get_page_type(page, PGT_writable_page) )
+            else if ( likely(cmd != MMU_PT_UPDATE_SWAP) &&
+                      get_page_type(page, PGT_writable_page) )
             {
                 perfc_incr(writable_mmu_updates);
                 paging_write_guest_entry(v, va, req.val, mfn);
diff --git a/xen/include/public/xen.h b/xen/include/public/xen.h
index 2149b8dd3808..2c403ca47ed6 100644
--- a/xen/include/public/xen.h
+++ b/xen/include/public/xen.h
@@ -349,6 +349,7 @@ DEFINE_XEN_GUEST_HANDLE(xen_ulong_t);
 #define MMU_PT_UPDATE_PRESERVE_AD  2 /* atomically: *ptr = val | (*ptr&(A|D)) 
*/
 #define MMU_PT_UPDATE_NO_TRANSLATE 3 /* checked '*ptr = val'. ptr is MA.      
*/
                                      /* val never translated.                 
*/
+#define MMU_PT_UPDATE_SWAP         4 /* Update and return the old value. */
 
 /*
  * MMU EXTENDED OPERATIONS
-- 
2.52.0




 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.