xref: /linux/tools/testing/selftests/kvm/lib/kvm_util.c (revision b02a4f8c4284e2cbbf539a95b27647687adae816)
1 // SPDX-License-Identifier: GPL-2.0-only
2 /*
3  * tools/testing/selftests/kvm/lib/kvm_util.c
4  *
5  * Copyright (C) 2018, Google LLC.
6  */
7 #include "test_util.h"
8 #include "kvm_syscalls.h"
9 #include "kvm_util.h"
10 #include "processor.h"
11 #include "ucall_common.h"
12 
13 #include <assert.h>
14 #include <sched.h>
15 #include <sys/resource.h>
16 #include <sys/types.h>
17 #include <sys/stat.h>
18 #include <unistd.h>
19 #include <linux/kernel.h>
20 
21 #define KVM_UTIL_MIN_PFN	2
22 
23 u32 guest_random_seed;
24 struct guest_random_state guest_rng;
25 static u32 last_guest_seed;
26 
27 static size_t vcpu_mmap_sz(void);
28 
29 int __open_path_or_exit(const char *path, int flags, const char *enoent_help)
30 {
31 	int fd;
32 
33 	fd = open(path, flags);
34 	if (fd < 0)
35 		goto error;
36 
37 	return fd;
38 
39 error:
40 	if (errno == EACCES || errno == ENOENT)
41 		ksft_exit_skip("- Cannot open '%s': %s.  %s\n",
42 			       path, strerror(errno),
43 			       errno == EACCES ? "Root required?" : enoent_help);
44 	TEST_FAIL("Failed to open '%s'", path);
45 }
46 
47 int open_path_or_exit(const char *path, int flags)
48 {
49 	return __open_path_or_exit(path, flags, "");
50 }
51 
52 /*
53  * Open KVM_DEV_PATH if available, otherwise exit the entire program.
54  *
55  * Input Args:
56  *   flags - The flags to pass when opening KVM_DEV_PATH.
57  *
58  * Return:
59  *   The opened file descriptor of /dev/kvm.
60  */
61 static int _open_kvm_dev_path_or_exit(int flags)
62 {
63 	return __open_path_or_exit(KVM_DEV_PATH, flags, "Is KVM loaded and enabled?");
64 }
65 
66 int open_kvm_dev_path_or_exit(void)
67 {
68 	return _open_kvm_dev_path_or_exit(O_RDONLY);
69 }
70 
71 static ssize_t get_module_param(const char *module_name, const char *param,
72 				void *buffer, size_t buffer_size)
73 {
74 	const int path_size = 128;
75 	char path[path_size];
76 	ssize_t bytes_read;
77 	int fd, r;
78 
79 	/* Verify KVM is loaded, to provide a more helpful SKIP message. */
80 	fd = open_kvm_dev_path_or_exit();
81 	kvm_free_fd(fd);
82 
83 	r = snprintf(path, path_size, "/sys/module/%s/parameters/%s",
84 		     module_name, param);
85 	TEST_ASSERT(r < path_size,
86 		    "Failed to construct sysfs path in %d bytes.", path_size);
87 
88 	fd = open_path_or_exit(path, O_RDONLY);
89 
90 	bytes_read = read(fd, buffer, buffer_size);
91 	TEST_ASSERT(bytes_read > 0, "read(%s) returned %ld, wanted %ld bytes",
92 		    path, bytes_read, buffer_size);
93 
94 	kvm_free_fd(fd);
95 	return bytes_read;
96 }
97 
98 int kvm_get_module_param_integer(const char *module_name, const char *param)
99 {
100 	/*
101 	 * 16 bytes to hold a 64-bit value (1 byte per char), 1 byte for the
102 	 * NUL char, and 1 byte because the kernel sucks and inserts a newline
103 	 * at the end.
104 	 */
105 	char value[16 + 1 + 1];
106 	ssize_t r;
107 
108 	memset(value, '\0', sizeof(value));
109 
110 	r = get_module_param(module_name, param, value, sizeof(value));
111 	TEST_ASSERT(value[r - 1] == '\n',
112 		    "Expected trailing newline, got char '%c'", value[r - 1]);
113 
114 	/*
115 	 * Squash the newline, otherwise atoi_paranoid() will complain about
116 	 * trailing non-NUL characters in the string.
117 	 */
118 	value[r - 1] = '\0';
119 	return atoi_paranoid(value);
120 }
121 
122 bool kvm_get_module_param_bool(const char *module_name, const char *param)
123 {
124 	char value;
125 	ssize_t r;
126 
127 	r = get_module_param(module_name, param, &value, sizeof(value));
128 	TEST_ASSERT_EQ(r, 1);
129 
130 	if (value == 'Y')
131 		return true;
132 	else if (value == 'N')
133 		return false;
134 
135 	TEST_FAIL("Unrecognized value '%c' for boolean module param", value);
136 }
137 
138 /*
139  * Capability
140  *
141  * Input Args:
142  *   cap - Capability
143  *
144  * Output Args: None
145  *
146  * Return:
147  *   On success, the Value corresponding to the capability (KVM_CAP_*)
148  *   specified by the value of cap.  On failure a TEST_ASSERT failure
149  *   is produced.
150  *
151  * Looks up and returns the value corresponding to the capability
152  * (KVM_CAP_*) given by cap.
153  */
154 unsigned int kvm_check_cap(long cap)
155 {
156 	int ret;
157 	int kvm_fd;
158 
159 	kvm_fd = open_kvm_dev_path_or_exit();
160 	ret = __kvm_ioctl(kvm_fd, KVM_CHECK_EXTENSION, (void *)cap);
161 	TEST_ASSERT(ret >= 0, KVM_IOCTL_ERROR(KVM_CHECK_EXTENSION, ret));
162 
163 	kvm_free_fd(kvm_fd);
164 
165 	return (unsigned int)ret;
166 }
167 
168 void vm_enable_dirty_ring(struct kvm_vm *vm, u32 ring_size)
169 {
170 	if (vm_check_cap(vm, KVM_CAP_DIRTY_LOG_RING_ACQ_REL))
171 		vm_enable_cap(vm, KVM_CAP_DIRTY_LOG_RING_ACQ_REL, ring_size);
172 	else
173 		vm_enable_cap(vm, KVM_CAP_DIRTY_LOG_RING, ring_size);
174 	vm->dirty_ring_size = ring_size;
175 }
176 
177 static void vm_open(struct kvm_vm *vm)
178 {
179 	vm->kvm_fd = _open_kvm_dev_path_or_exit(O_RDWR);
180 
181 	TEST_REQUIRE(kvm_has_cap(KVM_CAP_IMMEDIATE_EXIT));
182 
183 	vm->fd = __kvm_ioctl(vm->kvm_fd, KVM_CREATE_VM, (void *)vm->type);
184 	TEST_ASSERT(vm->fd >= 0, KVM_IOCTL_ERROR(KVM_CREATE_VM, vm->fd));
185 
186 	if (kvm_has_cap(KVM_CAP_BINARY_STATS_FD))
187 		vm->stats.fd = vm_get_stats_fd(vm);
188 	else
189 		vm->stats.fd = -1;
190 }
191 
192 const char *vm_guest_mode_string(u32 i)
193 {
194 	static const char * const strings[] = {
195 		[VM_MODE_P52V48_4K]	= "PA-bits:52,  VA-bits:48,  4K pages",
196 		[VM_MODE_P52V48_16K]	= "PA-bits:52,  VA-bits:48, 16K pages",
197 		[VM_MODE_P52V48_64K]	= "PA-bits:52,  VA-bits:48, 64K pages",
198 		[VM_MODE_P48V48_4K]	= "PA-bits:48,  VA-bits:48,  4K pages",
199 		[VM_MODE_P48V48_16K]	= "PA-bits:48,  VA-bits:48, 16K pages",
200 		[VM_MODE_P48V48_64K]	= "PA-bits:48,  VA-bits:48, 64K pages",
201 		[VM_MODE_P40V48_4K]	= "PA-bits:40,  VA-bits:48,  4K pages",
202 		[VM_MODE_P40V48_16K]	= "PA-bits:40,  VA-bits:48, 16K pages",
203 		[VM_MODE_P40V48_64K]	= "PA-bits:40,  VA-bits:48, 64K pages",
204 		[VM_MODE_PXXVYY_4K]	= "PA-bits:ANY, VA-bits:48 or 57, 4K pages",
205 		[VM_MODE_P47V64_4K]	= "PA-bits:47,  VA-bits:64,  4K pages",
206 		[VM_MODE_P44V64_4K]	= "PA-bits:44,  VA-bits:64,  4K pages",
207 		[VM_MODE_P36V48_4K]	= "PA-bits:36,  VA-bits:48,  4K pages",
208 		[VM_MODE_P36V48_16K]	= "PA-bits:36,  VA-bits:48, 16K pages",
209 		[VM_MODE_P36V48_64K]	= "PA-bits:36,  VA-bits:48, 64K pages",
210 		[VM_MODE_P47V47_16K]	= "PA-bits:47,  VA-bits:47, 16K pages",
211 		[VM_MODE_P36V47_16K]	= "PA-bits:36,  VA-bits:47, 16K pages",
212 		[VM_MODE_P56V57_4K]	= "PA-bits:56,  VA-bits:57,  4K pages",
213 		[VM_MODE_P56V48_4K]	= "PA-bits:56,  VA-bits:48,  4K pages",
214 		[VM_MODE_P56V39_4K]	= "PA-bits:56,  VA-bits:39,  4K pages",
215 		[VM_MODE_P50V57_4K]	= "PA-bits:50,  VA-bits:57,  4K pages",
216 		[VM_MODE_P50V48_4K]	= "PA-bits:50,  VA-bits:48,  4K pages",
217 		[VM_MODE_P50V39_4K]	= "PA-bits:50,  VA-bits:39,  4K pages",
218 		[VM_MODE_P41V57_4K]	= "PA-bits:41,  VA-bits:57,  4K pages",
219 		[VM_MODE_P41V48_4K]	= "PA-bits:41,  VA-bits:48,  4K pages",
220 		[VM_MODE_P41V39_4K]	= "PA-bits:41,  VA-bits:39,  4K pages",
221 	};
222 	_Static_assert(sizeof(strings)/sizeof(char *) == NUM_VM_MODES,
223 		       "Missing new mode strings?");
224 
225 	TEST_ASSERT(i < NUM_VM_MODES, "Guest mode ID %d too big", i);
226 
227 	return strings[i];
228 }
229 
230 const struct vm_guest_mode_params vm_guest_mode_params[] = {
231 	[VM_MODE_P52V48_4K]	= { 52, 48,  0x1000, 12 },
232 	[VM_MODE_P52V48_16K]	= { 52, 48,  0x4000, 14 },
233 	[VM_MODE_P52V48_64K]	= { 52, 48, 0x10000, 16 },
234 	[VM_MODE_P48V48_4K]	= { 48, 48,  0x1000, 12 },
235 	[VM_MODE_P48V48_16K]	= { 48, 48,  0x4000, 14 },
236 	[VM_MODE_P48V48_64K]	= { 48, 48, 0x10000, 16 },
237 	[VM_MODE_P40V48_4K]	= { 40, 48,  0x1000, 12 },
238 	[VM_MODE_P40V48_16K]	= { 40, 48,  0x4000, 14 },
239 	[VM_MODE_P40V48_64K]	= { 40, 48, 0x10000, 16 },
240 	[VM_MODE_PXXVYY_4K]	= {  0,  0,  0x1000, 12 },
241 	[VM_MODE_P47V64_4K]	= { 47, 64,  0x1000, 12 },
242 	[VM_MODE_P44V64_4K]	= { 44, 64,  0x1000, 12 },
243 	[VM_MODE_P36V48_4K]	= { 36, 48,  0x1000, 12 },
244 	[VM_MODE_P36V48_16K]	= { 36, 48,  0x4000, 14 },
245 	[VM_MODE_P36V48_64K]	= { 36, 48, 0x10000, 16 },
246 	[VM_MODE_P47V47_16K]	= { 47, 47,  0x4000, 14 },
247 	[VM_MODE_P36V47_16K]	= { 36, 47,  0x4000, 14 },
248 	[VM_MODE_P56V57_4K]	= { 56, 57,  0x1000, 12 },
249 	[VM_MODE_P56V48_4K]	= { 56, 48,  0x1000, 12 },
250 	[VM_MODE_P56V39_4K]	= { 56, 39,  0x1000, 12 },
251 	[VM_MODE_P50V57_4K]	= { 50, 57,  0x1000, 12 },
252 	[VM_MODE_P50V48_4K]	= { 50, 48,  0x1000, 12 },
253 	[VM_MODE_P50V39_4K]	= { 50, 39,  0x1000, 12 },
254 	[VM_MODE_P41V57_4K]	= { 41, 57,  0x1000, 12 },
255 	[VM_MODE_P41V48_4K]	= { 41, 48,  0x1000, 12 },
256 	[VM_MODE_P41V39_4K]	= { 41, 39,  0x1000, 12 },
257 };
258 _Static_assert(sizeof(vm_guest_mode_params)/sizeof(struct vm_guest_mode_params) == NUM_VM_MODES,
259 	       "Missing new mode params?");
260 
261 /*
262  * Initializes vm->vpages_valid to match the canonical VA space of the
263  * architecture.
264  *
265  * The default implementation is valid for architectures which split the
266  * range addressed by a single page table into a low and high region
267  * based on the MSB of the VA. On architectures with this behavior
268  * the VA region spans [0, 2^(va_bits - 1)), [-(2^(va_bits - 1), -1].
269  */
270 __weak void vm_populate_gva_bitmap(struct kvm_vm *vm)
271 {
272 	sparsebit_set_num(vm->vpages_valid,
273 		0, (1ULL << (vm->va_bits - 1)) >> vm->page_shift);
274 	sparsebit_set_num(vm->vpages_valid,
275 		(~((1ULL << (vm->va_bits - 1)) - 1)) >> vm->page_shift,
276 		(1ULL << (vm->va_bits - 1)) >> vm->page_shift);
277 }
278 
279 struct kvm_vm *____vm_create(struct vm_shape shape)
280 {
281 	struct kvm_vm *vm;
282 
283 	vm = calloc(1, sizeof(*vm));
284 	TEST_ASSERT(vm != NULL, "Insufficient Memory");
285 
286 	INIT_LIST_HEAD(&vm->vcpus);
287 	vm->regions.gpa_tree = RB_ROOT;
288 	vm->regions.hva_tree = RB_ROOT;
289 	hash_init(vm->regions.slot_hash);
290 
291 	vm->mode = shape.mode;
292 	vm->type = shape.type;
293 
294 	vm->pa_bits = vm_guest_mode_params[vm->mode].pa_bits;
295 	vm->va_bits = vm_guest_mode_params[vm->mode].va_bits;
296 	vm->page_size = vm_guest_mode_params[vm->mode].page_size;
297 	vm->page_shift = vm_guest_mode_params[vm->mode].page_shift;
298 
299 	/* Setup mode specific traits. */
300 	switch (vm->mode) {
301 	case VM_MODE_P52V48_4K:
302 		vm->mmu.pgtable_levels = 4;
303 		break;
304 	case VM_MODE_P52V48_64K:
305 		vm->mmu.pgtable_levels = 3;
306 		break;
307 	case VM_MODE_P48V48_4K:
308 		vm->mmu.pgtable_levels = 4;
309 		break;
310 	case VM_MODE_P48V48_64K:
311 		vm->mmu.pgtable_levels = 3;
312 		break;
313 	case VM_MODE_P40V48_4K:
314 	case VM_MODE_P36V48_4K:
315 		vm->mmu.pgtable_levels = 4;
316 		break;
317 	case VM_MODE_P40V48_64K:
318 	case VM_MODE_P36V48_64K:
319 		vm->mmu.pgtable_levels = 3;
320 		break;
321 	case VM_MODE_P52V48_16K:
322 	case VM_MODE_P48V48_16K:
323 	case VM_MODE_P40V48_16K:
324 	case VM_MODE_P36V48_16K:
325 		vm->mmu.pgtable_levels = 4;
326 		break;
327 	case VM_MODE_P47V47_16K:
328 	case VM_MODE_P36V47_16K:
329 		vm->mmu.pgtable_levels = 3;
330 		break;
331 	case VM_MODE_PXXVYY_4K:
332 #ifdef __x86_64__
333 		kvm_get_cpu_address_width(&vm->pa_bits, &vm->va_bits);
334 		kvm_init_vm_address_properties(vm);
335 
336 		pr_debug("Guest physical address width detected: %d\n",
337 			 vm->pa_bits);
338 		pr_debug("Guest virtual address width detected: %d\n",
339 			 vm->va_bits);
340 
341 		if (vm->va_bits == 57) {
342 			vm->mmu.pgtable_levels = 5;
343 		} else {
344 			TEST_ASSERT(vm->va_bits == 48,
345 				    "Unexpected guest virtual address width: %d",
346 				    vm->va_bits);
347 			vm->mmu.pgtable_levels = 4;
348 		}
349 #else
350 		TEST_FAIL("VM_MODE_PXXVYY_4K not supported on non-x86 platforms");
351 #endif
352 		break;
353 	case VM_MODE_P47V64_4K:
354 		vm->mmu.pgtable_levels = 5;
355 		break;
356 	case VM_MODE_P44V64_4K:
357 		vm->mmu.pgtable_levels = 5;
358 		break;
359 	case VM_MODE_P56V57_4K:
360 	case VM_MODE_P50V57_4K:
361 	case VM_MODE_P41V57_4K:
362 		vm->mmu.pgtable_levels = 5;
363 		break;
364 	case VM_MODE_P56V48_4K:
365 	case VM_MODE_P50V48_4K:
366 	case VM_MODE_P41V48_4K:
367 		vm->mmu.pgtable_levels = 4;
368 		break;
369 	case VM_MODE_P56V39_4K:
370 	case VM_MODE_P50V39_4K:
371 	case VM_MODE_P41V39_4K:
372 		vm->mmu.pgtable_levels = 3;
373 		break;
374 	default:
375 		TEST_FAIL("Unknown guest mode: 0x%x", vm->mode);
376 	}
377 
378 #ifdef __aarch64__
379 	TEST_ASSERT(!vm->type, "ARM doesn't support test-provided types");
380 	if (vm->pa_bits != 40)
381 		vm->type = KVM_VM_TYPE_ARM_IPA_SIZE(vm->pa_bits);
382 #endif
383 
384 	vm_open(vm);
385 
386 	/* Limit to VA-bit canonical virtual addresses. */
387 	vm->vpages_valid = sparsebit_alloc();
388 	vm_populate_gva_bitmap(vm);
389 
390 	/* Limit physical addresses to PA-bits. */
391 	vm->max_gfn = vm_compute_max_gfn(vm);
392 
393 	/* Allocate and setup memory for guest. */
394 	vm->vpages_mapped = sparsebit_alloc();
395 
396 	return vm;
397 }
398 
399 static u64 vm_nr_pages_required(enum vm_guest_mode mode,
400 				u32 nr_runnable_vcpus,
401 				u64 extra_mem_pages)
402 {
403 	u64 page_size = vm_guest_mode_params[mode].page_size;
404 	u64 nr_pages;
405 
406 	TEST_ASSERT(nr_runnable_vcpus,
407 		    "Use vm_create_barebones() for VMs that _never_ have vCPUs");
408 
409 	TEST_ASSERT(nr_runnable_vcpus <= kvm_check_cap(KVM_CAP_MAX_VCPUS),
410 		    "nr_vcpus = %d too large for host, max-vcpus = %d",
411 		    nr_runnable_vcpus, kvm_check_cap(KVM_CAP_MAX_VCPUS));
412 
413 	/*
414 	 * Arbitrarily allocate 512 pages (2mb when page size is 4kb) for the
415 	 * test code and other per-VM assets that will be loaded into memslot0.
416 	 */
417 	nr_pages = 512;
418 
419 	/* Account for the per-vCPU stacks on behalf of the test. */
420 	nr_pages += nr_runnable_vcpus * DEFAULT_STACK_PGS;
421 
422 	/*
423 	 * Account for the number of pages needed for the page tables.  The
424 	 * maximum page table size for a memory region will be when the
425 	 * smallest page size is used. Considering each page contains x page
426 	 * table descriptors, the total extra size for page tables (for extra
427 	 * N pages) will be: N/x+N/x^2+N/x^3+... which is definitely smaller
428 	 * than N/x*2.
429 	 */
430 	nr_pages += (nr_pages + extra_mem_pages) / PTES_PER_MIN_PAGE * 2;
431 
432 	/* Account for the number of pages needed by ucall. */
433 	nr_pages += ucall_nr_pages_required(page_size);
434 
435 	return vm_adjust_num_guest_pages(mode, nr_pages);
436 }
437 
438 void kvm_set_files_rlimit(u32 nr_vcpus)
439 {
440 	/*
441 	 * Each vCPU will open two file descriptors: the vCPU itself and the
442 	 * vCPU's binary stats file descriptor.  Add an arbitrary amount of
443 	 * buffer for all other files a test may open.
444 	 */
445 	int nr_fds_wanted = nr_vcpus * 2 + 100;
446 	struct rlimit rl;
447 
448 	/*
449 	 * Check that we're allowed to open nr_fds_wanted file descriptors and
450 	 * try raising the limits if needed.
451 	 */
452 	TEST_ASSERT(!getrlimit(RLIMIT_NOFILE, &rl), "getrlimit() failed!");
453 
454 	if (rl.rlim_cur < nr_fds_wanted) {
455 		rl.rlim_cur = nr_fds_wanted;
456 		if (rl.rlim_max < nr_fds_wanted) {
457 			int old_rlim_max = rl.rlim_max;
458 
459 			rl.rlim_max = nr_fds_wanted;
460 			__TEST_REQUIRE(setrlimit(RLIMIT_NOFILE, &rl) >= 0,
461 				       "RLIMIT_NOFILE hard limit is too low (%d, wanted %d)",
462 				       old_rlim_max, nr_fds_wanted);
463 		} else {
464 			TEST_ASSERT(!setrlimit(RLIMIT_NOFILE, &rl), "setrlimit() failed!");
465 		}
466 	}
467 
468 }
469 
470 static bool is_guest_memfd_required(struct vm_shape shape)
471 {
472 #ifdef __x86_64__
473 	return shape.type == KVM_X86_SNP_VM;
474 #else
475 	return false;
476 #endif
477 }
478 
479 struct kvm_vm *__vm_create(struct vm_shape shape, u32 nr_runnable_vcpus,
480 			   u64 nr_extra_pages)
481 {
482 	u64 nr_pages = vm_nr_pages_required(shape.mode, nr_runnable_vcpus,
483 						 nr_extra_pages);
484 	struct userspace_mem_region *slot0;
485 	struct kvm_vm *vm;
486 	int i, flags;
487 
488 	kvm_set_files_rlimit(nr_runnable_vcpus);
489 
490 	pr_debug("%s: mode='%s' type='%d', pages='%ld'\n", __func__,
491 		 vm_guest_mode_string(shape.mode), shape.type, nr_pages);
492 
493 	vm = ____vm_create(shape);
494 
495 	/*
496 	 * Force GUEST_MEMFD for the primary memory region if necessary, e.g.
497 	 * for CoCo VMs that require GUEST_MEMFD backed private memory.
498 	 */
499 	flags = 0;
500 	if (is_guest_memfd_required(shape))
501 		flags |= KVM_MEM_GUEST_MEMFD;
502 
503 	vm_userspace_mem_region_add(vm, VM_MEM_SRC_ANONYMOUS, 0, 0, nr_pages, flags);
504 	for (i = 0; i < NR_MEM_REGIONS; i++)
505 		vm->memslots[i] = 0;
506 
507 	kvm_vm_elf_load(vm, program_invocation_name);
508 
509 	/*
510 	 * TODO: Add proper defines to protect the library's memslots, and then
511 	 * carve out memslot1 for the ucall MMIO address.  KVM treats writes to
512 	 * read-only memslots as MMIO, and creating a read-only memslot for the
513 	 * MMIO region would prevent silently clobbering the MMIO region.
514 	 */
515 	slot0 = memslot2region(vm, 0);
516 	ucall_init(vm, slot0->region.guest_phys_addr + slot0->region.memory_size);
517 
518 	if (guest_random_seed != last_guest_seed) {
519 		pr_info("Random seed: 0x%x\n", guest_random_seed);
520 		last_guest_seed = guest_random_seed;
521 	}
522 	guest_rng = new_guest_random_state(guest_random_seed);
523 	sync_global_to_guest(vm, guest_rng);
524 
525 	kvm_arch_vm_post_create(vm, nr_runnable_vcpus);
526 
527 	return vm;
528 }
529 
530 /*
531  * VM Create with customized parameters
532  *
533  * Input Args:
534  *   mode - VM Mode (e.g. VM_MODE_P52V48_4K)
535  *   nr_vcpus - VCPU count
536  *   extra_mem_pages - Non-slot0 physical memory total size
537  *   guest_code - Guest entry point
538  *   vcpuids - VCPU IDs
539  *
540  * Output Args: None
541  *
542  * Return:
543  *   Pointer to opaque structure that describes the created VM.
544  *
545  * Creates a VM with the mode specified by mode (e.g. VM_MODE_P52V48_4K).
546  * extra_mem_pages is only used to calculate the maximum page table size,
547  * no real memory allocation for non-slot0 memory in this function.
548  */
549 struct kvm_vm *__vm_create_with_vcpus(struct vm_shape shape, u32 nr_vcpus,
550 				      u64 extra_mem_pages,
551 				      void *guest_code, struct kvm_vcpu *vcpus[])
552 {
553 	struct kvm_vm *vm;
554 	int i;
555 
556 	TEST_ASSERT(!nr_vcpus || vcpus, "Must provide vCPU array");
557 
558 	vm = __vm_create(shape, nr_vcpus, extra_mem_pages);
559 
560 	for (i = 0; i < nr_vcpus; ++i)
561 		vcpus[i] = vm_vcpu_add(vm, i, guest_code);
562 
563 	kvm_arch_vm_finalize_vcpus(vm);
564 	return vm;
565 }
566 
567 struct kvm_vm *__vm_create_shape_with_one_vcpu(struct vm_shape shape,
568 					       struct kvm_vcpu **vcpu,
569 					       u64 extra_mem_pages,
570 					       void *guest_code)
571 {
572 	struct kvm_vcpu *vcpus[1];
573 	struct kvm_vm *vm;
574 
575 	vm = __vm_create_with_vcpus(shape, 1, extra_mem_pages, guest_code, vcpus);
576 
577 	*vcpu = vcpus[0];
578 	return vm;
579 }
580 
581 /*
582  * VM Restart
583  *
584  * Input Args:
585  *   vm - VM that has been released before
586  *
587  * Output Args: None
588  *
589  * Reopens the file descriptors associated to the VM and reinstates the
590  * global state, such as the irqchip and the memory regions that are mapped
591  * into the guest.
592  */
593 void kvm_vm_restart(struct kvm_vm *vmp)
594 {
595 	int ctr;
596 	struct userspace_mem_region *region;
597 
598 	vm_open(vmp);
599 	if (vmp->has_irqchip)
600 		vm_create_irqchip(vmp);
601 
602 	hash_for_each(vmp->regions.slot_hash, ctr, region, slot_node) {
603 		int ret = ioctl(vmp->fd, KVM_SET_USER_MEMORY_REGION2, &region->region);
604 
605 		TEST_ASSERT(ret == 0, "KVM_SET_USER_MEMORY_REGION2 IOCTL failed,\n"
606 			    "  rc: %i errno: %i\n"
607 			    "  slot: %u flags: 0x%x\n"
608 			    "  guest_phys_addr: 0x%llx size: 0x%llx",
609 			    ret, errno, region->region.slot,
610 			    region->region.flags,
611 			    region->region.guest_phys_addr,
612 			    region->region.memory_size);
613 	}
614 }
615 
616 __weak struct kvm_vcpu *vm_arch_vcpu_recreate(struct kvm_vm *vm,
617 					      u32 vcpu_id)
618 {
619 	return __vm_vcpu_add(vm, vcpu_id);
620 }
621 
622 struct kvm_vcpu *vm_recreate_with_one_vcpu(struct kvm_vm *vm)
623 {
624 	kvm_vm_restart(vm);
625 
626 	return vm_vcpu_recreate(vm, 0);
627 }
628 
629 int __pin_task_to_cpu(pthread_t task, int cpu)
630 {
631 	cpu_set_t cpuset;
632 
633 	CPU_ZERO(&cpuset);
634 	CPU_SET(cpu, &cpuset);
635 
636 	return pthread_setaffinity_np(task, sizeof(cpuset), &cpuset);
637 }
638 
639 static u32 parse_pcpu(const char *cpu_str, const cpu_set_t *allowed_mask)
640 {
641 	u32 pcpu = atoi_non_negative("CPU number", cpu_str);
642 
643 	TEST_ASSERT(CPU_ISSET(pcpu, allowed_mask),
644 		    "Not allowed to run on pCPU '%d', check cgroups?", pcpu);
645 	return pcpu;
646 }
647 
648 void kvm_print_vcpu_pinning_help(void)
649 {
650 	const char *name = program_invocation_name;
651 
652 	printf(" -c: Pin tasks to physical CPUs.  Takes a list of comma separated\n"
653 	       "     values (target pCPU), one for each vCPU, plus an optional\n"
654 	       "     entry for the main application task (specified via entry\n"
655 	       "     <nr_vcpus + 1>).  If used, entries must be provided for all\n"
656 	       "     vCPUs, i.e. pinning vCPUs is all or nothing.\n\n"
657 	       "     E.g. to create 3 vCPUs, pin vCPU0=>pCPU22, vCPU1=>pCPU23,\n"
658 	       "     vCPU2=>pCPU24, and pin the application task to pCPU50:\n\n"
659 	       "         %s -v 3 -c 22,23,24,50\n\n"
660 	       "     To leave the application task unpinned, drop the final entry:\n\n"
661 	       "         %s -v 3 -c 22,23,24\n\n"
662 	       "     (default: no pinning)\n", name, name);
663 }
664 
665 void kvm_parse_vcpu_pinning(const char *pcpus_string, u32 vcpu_to_pcpu[],
666 			    int nr_vcpus)
667 {
668 	cpu_set_t allowed_mask;
669 	char *cpu, *cpu_list;
670 	char delim[2] = ",";
671 	int i, r;
672 
673 	cpu_list = strdup(pcpus_string);
674 	TEST_ASSERT(cpu_list, "strdup() allocation failed.");
675 
676 	r = sched_getaffinity(0, sizeof(allowed_mask), &allowed_mask);
677 	TEST_ASSERT(!r, "sched_getaffinity() failed");
678 
679 	cpu = strtok(cpu_list, delim);
680 
681 	/* 1. Get all pcpus for vcpus. */
682 	for (i = 0; i < nr_vcpus; i++) {
683 		TEST_ASSERT(cpu, "pCPU not provided for vCPU '%d'", i);
684 		vcpu_to_pcpu[i] = parse_pcpu(cpu, &allowed_mask);
685 		cpu = strtok(NULL, delim);
686 	}
687 
688 	/* 2. Check if the main worker needs to be pinned. */
689 	if (cpu) {
690 		pin_self_to_cpu(parse_pcpu(cpu, &allowed_mask));
691 		cpu = strtok(NULL, delim);
692 	}
693 
694 	TEST_ASSERT(!cpu, "pCPU list contains trailing garbage characters '%s'", cpu);
695 	free(cpu_list);
696 }
697 
698 /*
699  * Userspace Memory Region Find
700  *
701  * Input Args:
702  *   vm - Virtual Machine
703  *   start - Starting VM physical address
704  *   end - Ending VM physical address, inclusive.
705  *
706  * Output Args: None
707  *
708  * Return:
709  *   Pointer to overlapping region, NULL if no such region.
710  *
711  * Searches for a region with any physical memory that overlaps with
712  * any portion of the guest physical addresses from start to end
713  * inclusive.  If multiple overlapping regions exist, a pointer to any
714  * of the regions is returned.  Null is returned only when no overlapping
715  * region exists.
716  */
717 static struct userspace_mem_region *
718 userspace_mem_region_find(struct kvm_vm *vm, u64 start, u64 end)
719 {
720 	struct rb_node *node;
721 
722 	for (node = vm->regions.gpa_tree.rb_node; node; ) {
723 		struct userspace_mem_region *region =
724 			container_of(node, struct userspace_mem_region, gpa_node);
725 		u64 existing_start = region->region.guest_phys_addr;
726 		u64 existing_end = region->region.guest_phys_addr
727 			+ region->region.memory_size - 1;
728 		if (start <= existing_end && end >= existing_start)
729 			return region;
730 
731 		if (start < existing_start)
732 			node = node->rb_left;
733 		else
734 			node = node->rb_right;
735 	}
736 
737 	return NULL;
738 }
739 
740 static void kvm_stats_release(struct kvm_binary_stats *stats)
741 {
742 	if (stats->fd < 0)
743 		return;
744 
745 	if (stats->desc) {
746 		free(stats->desc);
747 		stats->desc = NULL;
748 	}
749 
750 	kvm_free_fd(stats->fd);
751 }
752 
753 __weak void vcpu_arch_free(struct kvm_vcpu *vcpu)
754 {
755 
756 }
757 
758 /*
759  * VM VCPU Remove
760  *
761  * Input Args:
762  *   vcpu - VCPU to remove
763  *
764  * Output Args: None
765  *
766  * Return: None, TEST_ASSERT failures for all error conditions
767  *
768  * Removes a vCPU from a VM and frees its resources.
769  */
770 static void vm_vcpu_rm(struct kvm_vm *vm, struct kvm_vcpu *vcpu)
771 {
772 	if (vcpu->dirty_gfns) {
773 		kvm_munmap(vcpu->dirty_gfns, vm->dirty_ring_size);
774 		vcpu->dirty_gfns = NULL;
775 	}
776 
777 	kvm_munmap(vcpu->run, vcpu_mmap_sz());
778 
779 	kvm_free_fd(vcpu->fd);
780 	kvm_stats_release(&vcpu->stats);
781 
782 	list_del(&vcpu->list);
783 
784 	vcpu_arch_free(vcpu);
785 	free(vcpu);
786 }
787 
788 void kvm_vm_release(struct kvm_vm *vmp)
789 {
790 	struct kvm_vcpu *vcpu, *tmp;
791 
792 	list_for_each_entry_safe(vcpu, tmp, &vmp->vcpus, list)
793 		vm_vcpu_rm(vmp, vcpu);
794 
795 	kvm_free_fd(vmp->fd);
796 	kvm_free_fd(vmp->kvm_fd);
797 
798 	/* Free cached stats metadata and close FD */
799 	kvm_stats_release(&vmp->stats);
800 
801 	kvm_arch_vm_release(vmp);
802 }
803 
804 static void __vm_mem_region_delete(struct kvm_vm *vm,
805 				   struct userspace_mem_region *region)
806 {
807 	rb_erase(&region->gpa_node, &vm->regions.gpa_tree);
808 	rb_erase(&region->hva_node, &vm->regions.hva_tree);
809 	hash_del(&region->slot_node);
810 
811 	sparsebit_free(&region->unused_phy_pages);
812 	sparsebit_free(&region->protected_phy_pages);
813 	kvm_munmap(region->mmap_start, region->mmap_size);
814 	if (region->fd >= 0) {
815 		/* There's an extra map when using shared memory. */
816 		kvm_munmap(region->mmap_alias, region->mmap_size);
817 		kvm_free_fd(region->fd);
818 	}
819 	if ((int)region->region.guest_memfd >= 0)
820 		kvm_free_fd(region->region.guest_memfd);
821 
822 	free(region);
823 }
824 
825 /*
826  * Destroys and frees the VM pointed to by vmp.
827  */
828 void kvm_vm_free(struct kvm_vm *vmp)
829 {
830 	int ctr;
831 	struct hlist_node *node;
832 	struct userspace_mem_region *region;
833 
834 	if (vmp == NULL)
835 		return;
836 
837 	/* Free userspace_mem_regions. */
838 	hash_for_each_safe(vmp->regions.slot_hash, ctr, node, region, slot_node)
839 		__vm_mem_region_delete(vmp, region);
840 
841 	/* Free sparsebit arrays. */
842 	sparsebit_free(&vmp->vpages_valid);
843 	sparsebit_free(&vmp->vpages_mapped);
844 
845 	kvm_vm_release(vmp);
846 
847 	/* Free the structure describing the VM. */
848 	free(vmp);
849 }
850 
851 int kvm_memfd_alloc(size_t size, bool hugepages)
852 {
853 	int memfd_flags = MFD_CLOEXEC;
854 	int fd;
855 
856 	if (hugepages)
857 		memfd_flags |= MFD_HUGETLB;
858 
859 	fd = memfd_create("kvm_selftest", memfd_flags);
860 	TEST_ASSERT(fd != -1, __KVM_SYSCALL_ERROR("memfd_create()", fd));
861 
862 	kvm_ftruncate(fd, size);
863 	kvm_fallocate(fd, FALLOC_FL_PUNCH_HOLE | FALLOC_FL_KEEP_SIZE, 0, size);
864 
865 	return fd;
866 }
867 
868 static void vm_userspace_mem_region_gpa_insert(struct rb_root *gpa_tree,
869 					       struct userspace_mem_region *region)
870 {
871 	struct rb_node **cur, *parent;
872 
873 	for (cur = &gpa_tree->rb_node, parent = NULL; *cur; ) {
874 		struct userspace_mem_region *cregion;
875 
876 		cregion = container_of(*cur, typeof(*cregion), gpa_node);
877 		parent = *cur;
878 		if (region->region.guest_phys_addr <
879 		    cregion->region.guest_phys_addr)
880 			cur = &(*cur)->rb_left;
881 		else {
882 			TEST_ASSERT(region->region.guest_phys_addr !=
883 				    cregion->region.guest_phys_addr,
884 				    "Duplicate GPA in region tree");
885 
886 			cur = &(*cur)->rb_right;
887 		}
888 	}
889 
890 	rb_link_node(&region->gpa_node, parent, cur);
891 	rb_insert_color(&region->gpa_node, gpa_tree);
892 }
893 
894 static void vm_userspace_mem_region_hva_insert(struct rb_root *hva_tree,
895 					       struct userspace_mem_region *region)
896 {
897 	struct rb_node **cur, *parent;
898 
899 	for (cur = &hva_tree->rb_node, parent = NULL; *cur; ) {
900 		struct userspace_mem_region *cregion;
901 
902 		cregion = container_of(*cur, typeof(*cregion), hva_node);
903 		parent = *cur;
904 		if (region->host_mem < cregion->host_mem)
905 			cur = &(*cur)->rb_left;
906 		else {
907 			TEST_ASSERT(region->host_mem !=
908 				    cregion->host_mem,
909 				    "Duplicate HVA in region tree");
910 
911 			cur = &(*cur)->rb_right;
912 		}
913 	}
914 
915 	rb_link_node(&region->hva_node, parent, cur);
916 	rb_insert_color(&region->hva_node, hva_tree);
917 }
918 
919 
920 int __vm_set_user_memory_region(struct kvm_vm *vm, u32 slot, u32 flags,
921 				gpa_t gpa, u64 size, void *hva)
922 {
923 	struct kvm_userspace_memory_region region = {
924 		.slot = slot,
925 		.flags = flags,
926 		.guest_phys_addr = gpa,
927 		.memory_size = size,
928 		.userspace_addr = (uintptr_t)hva,
929 	};
930 
931 	return ioctl(vm->fd, KVM_SET_USER_MEMORY_REGION, &region);
932 }
933 
934 void vm_set_user_memory_region(struct kvm_vm *vm, u32 slot, u32 flags,
935 			       gpa_t gpa, u64 size, void *hva)
936 {
937 	int ret = __vm_set_user_memory_region(vm, slot, flags, gpa, size, hva);
938 
939 	TEST_ASSERT(!ret, "KVM_SET_USER_MEMORY_REGION failed, errno = %d (%s)",
940 		    errno, strerror(errno));
941 }
942 
943 #define TEST_REQUIRE_SET_USER_MEMORY_REGION2()			\
944 	__TEST_REQUIRE(kvm_has_cap(KVM_CAP_USER_MEMORY2),	\
945 		       "KVM selftests now require KVM_SET_USER_MEMORY_REGION2 (introduced in v6.8)")
946 
947 int __vm_set_user_memory_region2(struct kvm_vm *vm, u32 slot, u32 flags,
948 				 gpa_t gpa, u64 size, void *hva,
949 				 u32 guest_memfd, u64 guest_memfd_offset)
950 {
951 	struct kvm_userspace_memory_region2 region = {
952 		.slot = slot,
953 		.flags = flags,
954 		.guest_phys_addr = gpa,
955 		.memory_size = size,
956 		.userspace_addr = (uintptr_t)hva,
957 		.guest_memfd = guest_memfd,
958 		.guest_memfd_offset = guest_memfd_offset,
959 	};
960 
961 	TEST_REQUIRE_SET_USER_MEMORY_REGION2();
962 
963 	return ioctl(vm->fd, KVM_SET_USER_MEMORY_REGION2, &region);
964 }
965 
966 void vm_set_user_memory_region2(struct kvm_vm *vm, u32 slot, u32 flags,
967 				gpa_t gpa, u64 size, void *hva,
968 				u32 guest_memfd, u64 guest_memfd_offset)
969 {
970 	int ret = __vm_set_user_memory_region2(vm, slot, flags, gpa, size, hva,
971 					       guest_memfd, guest_memfd_offset);
972 
973 	TEST_ASSERT(!ret, "KVM_SET_USER_MEMORY_REGION2 failed, errno = %d (%s)",
974 		    errno, strerror(errno));
975 }
976 
977 
978 /* FIXME: This thing needs to be ripped apart and rewritten. */
979 void vm_mem_add(struct kvm_vm *vm, enum vm_mem_backing_src_type src_type,
980 		gpa_t gpa, u32 slot, u64 npages, u32 flags,
981 		int guest_memfd, u64 guest_memfd_offset)
982 {
983 	int ret;
984 	struct userspace_mem_region *region;
985 	size_t backing_src_pagesz = get_backing_src_pagesz(src_type);
986 	size_t mem_size = npages * vm->page_size;
987 	size_t alignment = 1;
988 
989 	TEST_REQUIRE_SET_USER_MEMORY_REGION2();
990 
991 	TEST_ASSERT(vm_adjust_num_guest_pages(vm->mode, npages) == npages,
992 		"Number of guest pages is not compatible with the host. "
993 		"Try npages=%d", vm_adjust_num_guest_pages(vm->mode, npages));
994 
995 	TEST_ASSERT((gpa % vm->page_size) == 0, "Guest physical "
996 		"address not on a page boundary.\n"
997 		"  gpa: 0x%lx vm->page_size: 0x%x",
998 		gpa, vm->page_size);
999 	TEST_ASSERT((((gpa >> vm->page_shift) + npages) - 1)
1000 		<= vm->max_gfn, "Physical range beyond maximum "
1001 		"supported physical address,\n"
1002 		"  gpa: 0x%lx npages: 0x%lx\n"
1003 		"  vm->max_gfn: 0x%lx vm->page_size: 0x%x",
1004 		gpa, npages, vm->max_gfn, vm->page_size);
1005 
1006 	/*
1007 	 * Confirm a mem region with an overlapping address doesn't
1008 	 * already exist.
1009 	 */
1010 	region = (struct userspace_mem_region *) userspace_mem_region_find(
1011 		vm, gpa, (gpa + npages * vm->page_size) - 1);
1012 	if (region != NULL)
1013 		TEST_FAIL("overlapping userspace_mem_region already "
1014 			"exists\n"
1015 			"  requested gpa: 0x%lx npages: 0x%lx page_size: 0x%x\n"
1016 			"  existing gpa: 0x%lx size: 0x%lx",
1017 			gpa, npages, vm->page_size,
1018 			(u64)region->region.guest_phys_addr,
1019 			(u64)region->region.memory_size);
1020 
1021 	/* Confirm no region with the requested slot already exists. */
1022 	hash_for_each_possible(vm->regions.slot_hash, region, slot_node,
1023 			       slot) {
1024 		if (region->region.slot != slot)
1025 			continue;
1026 
1027 		TEST_FAIL("A mem region with the requested slot "
1028 			"already exists.\n"
1029 			"  requested slot: %u gpa: 0x%lx npages: 0x%lx\n"
1030 			"  existing slot: %u gpa: 0x%lx size: 0x%lx",
1031 			slot, gpa, npages, region->region.slot,
1032 			(u64)region->region.guest_phys_addr,
1033 			(u64)region->region.memory_size);
1034 	}
1035 
1036 	/* Allocate and initialize new mem region structure. */
1037 	region = calloc(1, sizeof(*region));
1038 	TEST_ASSERT(region != NULL, "Insufficient Memory");
1039 	region->mmap_size = mem_size;
1040 
1041 	/*
1042 	 * When using THP mmap is not guaranteed to returned a hugepage aligned
1043 	 * address so we have to pad the mmap. Padding is not needed for HugeTLB
1044 	 * because mmap will always return an address aligned to the HugeTLB
1045 	 * page size.
1046 	 */
1047 	if (src_type == VM_MEM_SRC_ANONYMOUS_THP)
1048 		alignment = max(backing_src_pagesz, alignment);
1049 
1050 	TEST_ASSERT_EQ(gpa, align_up(gpa, backing_src_pagesz));
1051 
1052 	/* Add enough memory to align up if necessary */
1053 	if (alignment > 1)
1054 		region->mmap_size += alignment;
1055 
1056 	region->fd = -1;
1057 	if (backing_src_is_shared(src_type))
1058 		region->fd = kvm_memfd_alloc(region->mmap_size,
1059 					     src_type == VM_MEM_SRC_SHARED_HUGETLB);
1060 
1061 	region->mmap_start = kvm_mmap(region->mmap_size, PROT_READ | PROT_WRITE,
1062 				      vm_mem_backing_src_alias(src_type)->flag,
1063 				      region->fd);
1064 
1065 	TEST_ASSERT(!is_backing_src_hugetlb(src_type) ||
1066 		    region->mmap_start == align_ptr_up(region->mmap_start, backing_src_pagesz),
1067 		    "mmap_start %p is not aligned to HugeTLB page size 0x%lx",
1068 		    region->mmap_start, backing_src_pagesz);
1069 
1070 	/* Align host address */
1071 	region->host_mem = align_ptr_up(region->mmap_start, alignment);
1072 
1073 	/* As needed perform madvise */
1074 	if ((src_type == VM_MEM_SRC_ANONYMOUS ||
1075 	     src_type == VM_MEM_SRC_ANONYMOUS_THP) && thp_configured()) {
1076 		ret = madvise(region->host_mem, mem_size,
1077 			      src_type == VM_MEM_SRC_ANONYMOUS ? MADV_NOHUGEPAGE : MADV_HUGEPAGE);
1078 		TEST_ASSERT(ret == 0, "madvise failed, addr: %p length: 0x%lx src_type: %s",
1079 			    region->host_mem, mem_size,
1080 			    vm_mem_backing_src_alias(src_type)->name);
1081 	}
1082 
1083 	region->backing_src_type = src_type;
1084 
1085 	if (flags & KVM_MEM_GUEST_MEMFD) {
1086 		if (guest_memfd < 0) {
1087 			u32 guest_memfd_flags = 0;
1088 			TEST_ASSERT(!guest_memfd_offset,
1089 				    "Offset must be zero when creating new guest_memfd");
1090 			guest_memfd = vm_create_guest_memfd(vm, mem_size, guest_memfd_flags);
1091 		} else {
1092 			/*
1093 			 * Install a unique fd for each memslot so that the fd
1094 			 * can be closed when the region is deleted without
1095 			 * needing to track if the fd is owned by the framework
1096 			 * or by the caller.
1097 			 */
1098 			guest_memfd = kvm_dup(guest_memfd);
1099 		}
1100 
1101 		region->region.guest_memfd = guest_memfd;
1102 		region->region.guest_memfd_offset = guest_memfd_offset;
1103 	} else {
1104 		region->region.guest_memfd = -1;
1105 	}
1106 
1107 	region->unused_phy_pages = sparsebit_alloc();
1108 	if (vm_arch_has_protected_memory(vm))
1109 		region->protected_phy_pages = sparsebit_alloc();
1110 	sparsebit_set_num(region->unused_phy_pages, gpa >> vm->page_shift, npages);
1111 	region->region.slot = slot;
1112 	region->region.flags = flags;
1113 	region->region.guest_phys_addr = gpa;
1114 	region->region.memory_size = npages * vm->page_size;
1115 	region->region.userspace_addr = (uintptr_t) region->host_mem;
1116 	ret = __vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &region->region);
1117 	TEST_ASSERT(ret == 0, "KVM_SET_USER_MEMORY_REGION2 IOCTL failed,\n"
1118 		"  rc: %i errno: %i\n"
1119 		"  slot: %u flags: 0x%x\n"
1120 		"  guest_phys_addr: 0x%lx size: 0x%llx guest_memfd: %d",
1121 		ret, errno, slot, flags, gpa, region->region.memory_size,
1122 		region->region.guest_memfd);
1123 
1124 	/* Add to quick lookup data structures */
1125 	vm_userspace_mem_region_gpa_insert(&vm->regions.gpa_tree, region);
1126 	vm_userspace_mem_region_hva_insert(&vm->regions.hva_tree, region);
1127 	hash_add(vm->regions.slot_hash, &region->slot_node, slot);
1128 
1129 	/* If shared memory, create an alias. */
1130 	if (region->fd >= 0) {
1131 		region->mmap_alias = kvm_mmap(region->mmap_size,
1132 					      PROT_READ | PROT_WRITE,
1133 					      vm_mem_backing_src_alias(src_type)->flag,
1134 					      region->fd);
1135 
1136 		/* Align host alias address */
1137 		region->host_alias = align_ptr_up(region->mmap_alias, alignment);
1138 	}
1139 }
1140 
1141 void vm_userspace_mem_region_add(struct kvm_vm *vm,
1142 				 enum vm_mem_backing_src_type src_type,
1143 				 gpa_t gpa, u32 slot, u64 npages, u32 flags)
1144 {
1145 	vm_mem_add(vm, src_type, gpa, slot, npages, flags, -1, 0);
1146 }
1147 
1148 /*
1149  * Memslot to region
1150  *
1151  * Input Args:
1152  *   vm - Virtual Machine
1153  *   memslot - KVM memory slot ID
1154  *
1155  * Output Args: None
1156  *
1157  * Return:
1158  *   Pointer to memory region structure that describe memory region
1159  *   using kvm memory slot ID given by memslot.  TEST_ASSERT failure
1160  *   on error (e.g. currently no memory region using memslot as a KVM
1161  *   memory slot ID).
1162  */
1163 struct userspace_mem_region *
1164 memslot2region(struct kvm_vm *vm, u32 memslot)
1165 {
1166 	struct userspace_mem_region *region;
1167 
1168 	hash_for_each_possible(vm->regions.slot_hash, region, slot_node,
1169 			       memslot)
1170 		if (region->region.slot == memslot)
1171 			return region;
1172 
1173 	fprintf(stderr, "No mem region with the requested slot found,\n"
1174 		"  requested slot: %u\n", memslot);
1175 	fputs("---- vm dump ----\n", stderr);
1176 	vm_dump(stderr, vm, 2);
1177 	TEST_FAIL("Mem region not found");
1178 	return NULL;
1179 }
1180 
1181 /*
1182  * VM Memory Region Flags Set
1183  *
1184  * Input Args:
1185  *   vm - Virtual Machine
1186  *   flags - Starting guest physical address
1187  *
1188  * Output Args: None
1189  *
1190  * Return: None
1191  *
1192  * Sets the flags of the memory region specified by the value of slot,
1193  * to the values given by flags.
1194  */
1195 void vm_mem_region_set_flags(struct kvm_vm *vm, u32 slot, u32 flags)
1196 {
1197 	int ret;
1198 	struct userspace_mem_region *region;
1199 
1200 	region = memslot2region(vm, slot);
1201 
1202 	region->region.flags = flags;
1203 
1204 	ret = __vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &region->region);
1205 
1206 	TEST_ASSERT(ret == 0, "KVM_SET_USER_MEMORY_REGION2 IOCTL failed,\n"
1207 		"  rc: %i errno: %i slot: %u flags: 0x%x",
1208 		ret, errno, slot, flags);
1209 }
1210 
1211 void vm_mem_region_reload(struct kvm_vm *vm, u32 slot)
1212 {
1213 	struct userspace_mem_region *region = memslot2region(vm, slot);
1214 	struct kvm_userspace_memory_region2 tmp = region->region;
1215 
1216 	tmp.memory_size = 0;
1217 	vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &tmp);
1218 	vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &region->region);
1219 }
1220 
1221 /*
1222  * VM Memory Region Move
1223  *
1224  * Input Args:
1225  *   vm - Virtual Machine
1226  *   slot - Slot of the memory region to move
1227  *   new_gpa - Starting guest physical address
1228  *
1229  * Output Args: None
1230  *
1231  * Return: None
1232  *
1233  * Change the gpa of a memory region.
1234  */
1235 void vm_mem_region_move(struct kvm_vm *vm, u32 slot, u64 new_gpa)
1236 {
1237 	struct userspace_mem_region *region;
1238 	int ret;
1239 
1240 	region = memslot2region(vm, slot);
1241 
1242 	region->region.guest_phys_addr = new_gpa;
1243 
1244 	ret = __vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &region->region);
1245 
1246 	TEST_ASSERT(!ret, "KVM_SET_USER_MEMORY_REGION2 failed\n"
1247 		    "ret: %i errno: %i slot: %u new_gpa: 0x%lx",
1248 		    ret, errno, slot, new_gpa);
1249 }
1250 
1251 /*
1252  * VM Memory Region Delete
1253  *
1254  * Input Args:
1255  *   vm - Virtual Machine
1256  *   slot - Slot of the memory region to delete
1257  *
1258  * Output Args: None
1259  *
1260  * Return: None
1261  *
1262  * Delete a memory region.
1263  */
1264 void vm_mem_region_delete(struct kvm_vm *vm, u32 slot)
1265 {
1266 	struct userspace_mem_region *region = memslot2region(vm, slot);
1267 
1268 	region->region.memory_size = 0;
1269 	vm_ioctl(vm, KVM_SET_USER_MEMORY_REGION2, &region->region);
1270 
1271 	__vm_mem_region_delete(vm, region);
1272 }
1273 
1274 void vm_guest_mem_fallocate(struct kvm_vm *vm, u64 base, u64 size,
1275 			    bool punch_hole)
1276 {
1277 	const int mode = FALLOC_FL_KEEP_SIZE | (punch_hole ? FALLOC_FL_PUNCH_HOLE : 0);
1278 	struct userspace_mem_region *region;
1279 	u64 end = base + size;
1280 	gpa_t gpa, len;
1281 	off_t fd_offset;
1282 	int ret;
1283 
1284 	for (gpa = base; gpa < end; gpa += len) {
1285 		u64 offset;
1286 
1287 		region = userspace_mem_region_find(vm, gpa, gpa);
1288 		TEST_ASSERT(region && region->region.flags & KVM_MEM_GUEST_MEMFD,
1289 			    "Private memory region not found for GPA 0x%lx", gpa);
1290 
1291 		offset = gpa - region->region.guest_phys_addr;
1292 		fd_offset = region->region.guest_memfd_offset + offset;
1293 		len = min_t(u64, end - gpa, region->region.memory_size - offset);
1294 
1295 		ret = fallocate(region->region.guest_memfd, mode, fd_offset, len);
1296 		TEST_ASSERT(!ret, "fallocate() failed to %s at %lx (len = %lu), fd = %d, mode = %x, offset = %lx",
1297 			    punch_hole ? "punch hole" : "allocate", gpa, len,
1298 			    region->region.guest_memfd, mode, fd_offset);
1299 	}
1300 }
1301 
1302 /* Returns the size of a vCPU's kvm_run structure. */
1303 static size_t vcpu_mmap_sz(void)
1304 {
1305 	int dev_fd, ret;
1306 
1307 	dev_fd = open_kvm_dev_path_or_exit();
1308 
1309 	ret = ioctl(dev_fd, KVM_GET_VCPU_MMAP_SIZE, NULL);
1310 	TEST_ASSERT(ret >= 0 && ret >= sizeof(struct kvm_run),
1311 		    KVM_IOCTL_ERROR(KVM_GET_VCPU_MMAP_SIZE, ret));
1312 
1313 	kvm_free_fd(dev_fd);
1314 
1315 	return ret;
1316 }
1317 
1318 static bool vcpu_exists(struct kvm_vm *vm, u32 vcpu_id)
1319 {
1320 	struct kvm_vcpu *vcpu;
1321 
1322 	list_for_each_entry(vcpu, &vm->vcpus, list) {
1323 		if (vcpu->id == vcpu_id)
1324 			return true;
1325 	}
1326 
1327 	return false;
1328 }
1329 
1330 /*
1331  * Adds a virtual CPU to the VM specified by vm with the ID given by vcpu_id.
1332  * No additional vCPU setup is done.  Returns the vCPU.
1333  */
1334 struct kvm_vcpu *__vm_vcpu_add(struct kvm_vm *vm, u32 vcpu_id)
1335 {
1336 	struct kvm_vcpu *vcpu;
1337 
1338 	/* Confirm a vcpu with the specified id doesn't already exist. */
1339 	TEST_ASSERT(!vcpu_exists(vm, vcpu_id), "vCPU%d already exists", vcpu_id);
1340 
1341 	/* Allocate and initialize new vcpu structure. */
1342 	vcpu = calloc(1, sizeof(*vcpu));
1343 	TEST_ASSERT(vcpu != NULL, "Insufficient Memory");
1344 
1345 	vcpu->vm = vm;
1346 	vcpu->id = vcpu_id;
1347 	vcpu->fd = __vm_ioctl(vm, KVM_CREATE_VCPU, (void *)(unsigned long)vcpu_id);
1348 	TEST_ASSERT_VM_VCPU_IOCTL(vcpu->fd >= 0, KVM_CREATE_VCPU, vcpu->fd, vm);
1349 
1350 	TEST_ASSERT(vcpu_mmap_sz() >= sizeof(*vcpu->run), "vcpu mmap size "
1351 		"smaller than expected, vcpu_mmap_sz: %zi expected_min: %zi",
1352 		vcpu_mmap_sz(), sizeof(*vcpu->run));
1353 	vcpu->run = kvm_mmap(vcpu_mmap_sz(), PROT_READ | PROT_WRITE,
1354 			     MAP_SHARED, vcpu->fd);
1355 
1356 	if (kvm_has_cap(KVM_CAP_BINARY_STATS_FD))
1357 		vcpu->stats.fd = vcpu_get_stats_fd(vcpu);
1358 	else
1359 		vcpu->stats.fd = -1;
1360 
1361 	/* Add to linked-list of VCPUs. */
1362 	list_add(&vcpu->list, &vm->vcpus);
1363 
1364 	return vcpu;
1365 }
1366 
1367 /*
1368  * Within the VM specified by @vm, locates the lowest starting guest virtual
1369  * address >= @min_gva, that has at least @sz unallocated bytes.  A
1370  * TEST_ASSERT failure occurs for invalid input or no area of at least
1371  * @sz unallocated bytes >= @min_gva is available.
1372  */
1373 gva_t vm_unused_gva_gap(struct kvm_vm *vm, size_t sz, gva_t min_gva)
1374 {
1375 	u64 pages = (sz + vm->page_size - 1) >> vm->page_shift;
1376 
1377 	/* Determine lowest permitted virtual page index. */
1378 	u64 pgidx_start = (min_gva + vm->page_size - 1) >> vm->page_shift;
1379 	if ((pgidx_start * vm->page_size) < min_gva)
1380 		goto no_va_found;
1381 
1382 	/* Loop over section with enough valid virtual page indexes. */
1383 	if (!sparsebit_is_set_num(vm->vpages_valid,
1384 		pgidx_start, pages))
1385 		pgidx_start = sparsebit_next_set_num(vm->vpages_valid,
1386 			pgidx_start, pages);
1387 	do {
1388 		/*
1389 		 * Are there enough unused virtual pages available at
1390 		 * the currently proposed starting virtual page index.
1391 		 * If not, adjust proposed starting index to next
1392 		 * possible.
1393 		 */
1394 		if (sparsebit_is_clear_num(vm->vpages_mapped,
1395 			pgidx_start, pages))
1396 			goto va_found;
1397 		pgidx_start = sparsebit_next_clear_num(vm->vpages_mapped,
1398 			pgidx_start, pages);
1399 		if (pgidx_start == 0)
1400 			goto no_va_found;
1401 
1402 		/*
1403 		 * If needed, adjust proposed starting virtual address,
1404 		 * to next range of valid virtual addresses.
1405 		 */
1406 		if (!sparsebit_is_set_num(vm->vpages_valid,
1407 			pgidx_start, pages)) {
1408 			pgidx_start = sparsebit_next_set_num(
1409 				vm->vpages_valid, pgidx_start, pages);
1410 			if (pgidx_start == 0)
1411 				goto no_va_found;
1412 		}
1413 	} while (pgidx_start != 0);
1414 
1415 no_va_found:
1416 	TEST_FAIL("No gva of specified pages available, pages: 0x%lx", pages);
1417 
1418 	/* NOT REACHED */
1419 	return -1;
1420 
1421 va_found:
1422 	TEST_ASSERT(sparsebit_is_set_num(vm->vpages_valid,
1423 		pgidx_start, pages),
1424 		"Unexpected, invalid virtual page index range,\n"
1425 		"  pgidx_start: 0x%lx\n"
1426 		"  pages: 0x%lx",
1427 		pgidx_start, pages);
1428 	TEST_ASSERT(sparsebit_is_clear_num(vm->vpages_mapped,
1429 		pgidx_start, pages),
1430 		"Unexpected, pages already mapped,\n"
1431 		"  pgidx_start: 0x%lx\n"
1432 		"  pages: 0x%lx",
1433 		pgidx_start, pages);
1434 
1435 	return pgidx_start * vm->page_size;
1436 }
1437 
1438 static gva_t ____vm_alloc(struct kvm_vm *vm, size_t sz, gva_t min_gva,
1439 			  enum kvm_mem_region_type type, bool protected)
1440 {
1441 	u64 pages = (sz >> vm->page_shift) + ((sz % vm->page_size) != 0);
1442 
1443 	virt_pgd_alloc(vm);
1444 	gpa_t gpa = __vm_phy_pages_alloc(vm, pages,
1445 					   KVM_UTIL_MIN_PFN * vm->page_size,
1446 					   vm->memslots[type], protected);
1447 
1448 	/*
1449 	 * Find an unused range of virtual page addresses of at least
1450 	 * pages in length.
1451 	 */
1452 	gva_t gva_start = vm_unused_gva_gap(vm, sz, min_gva);
1453 
1454 	/* Map the virtual pages. */
1455 	for (gva_t gva = gva_start; pages > 0;
1456 		pages--, gva += vm->page_size, gpa += vm->page_size) {
1457 
1458 		virt_pg_map(vm, gva, gpa);
1459 	}
1460 
1461 	return gva_start;
1462 }
1463 
1464 gva_t __vm_alloc(struct kvm_vm *vm, size_t sz, gva_t min_gva,
1465 		 enum kvm_mem_region_type type)
1466 {
1467 	return ____vm_alloc(vm, sz, min_gva, type,
1468 			    vm_arch_has_protected_memory(vm));
1469 }
1470 
1471 gva_t vm_alloc_shared(struct kvm_vm *vm, size_t sz, gva_t min_gva,
1472 		      enum kvm_mem_region_type type)
1473 {
1474 	return ____vm_alloc(vm, sz, min_gva, type, false);
1475 }
1476 
1477 /*
1478  * Allocates at least sz bytes within the virtual address space of the VM
1479  * given by @vm.  The allocated bytes are mapped to a virtual address >= the
1480  * address given by @min_gva.  Note that each allocation uses a a unique set
1481  * of pages, with the minimum real allocation being at least a page. The
1482  * allocated physical space comes from the TEST_DATA memory region.
1483  */
1484 gva_t vm_alloc(struct kvm_vm *vm, size_t sz, gva_t min_gva)
1485 {
1486 	return __vm_alloc(vm, sz, min_gva, MEM_REGION_TEST_DATA);
1487 }
1488 
1489 gva_t vm_alloc_pages(struct kvm_vm *vm, int nr_pages)
1490 {
1491 	return vm_alloc(vm, nr_pages * getpagesize(), KVM_UTIL_MIN_VADDR);
1492 }
1493 
1494 gva_t __vm_alloc_page(struct kvm_vm *vm, enum kvm_mem_region_type type)
1495 {
1496 	return __vm_alloc(vm, getpagesize(), KVM_UTIL_MIN_VADDR, type);
1497 }
1498 
1499 gva_t vm_alloc_page(struct kvm_vm *vm)
1500 {
1501 	return vm_alloc_pages(vm, 1);
1502 }
1503 
1504 /*
1505  * Map a range of VM virtual address to the VM's physical address.
1506  *
1507  * Within the VM given by @vm, creates a virtual translation for @npages
1508  * starting at @gva to the page range starting at @gpa.
1509  */
1510 void virt_map(struct kvm_vm *vm, gva_t gva, gpa_t gpa, unsigned int npages)
1511 {
1512 	size_t page_size = vm->page_size;
1513 	size_t size = npages * page_size;
1514 
1515 	TEST_ASSERT(gva + size > gva, "Vaddr overflow");
1516 	TEST_ASSERT(gpa + size > gpa, "Paddr overflow");
1517 
1518 	while (npages--) {
1519 		virt_pg_map(vm, gva, gpa);
1520 
1521 		gva += page_size;
1522 		gpa += page_size;
1523 	}
1524 }
1525 
1526 /*
1527  * Address VM Physical to Host Virtual
1528  *
1529  * Input Args:
1530  *   vm - Virtual Machine
1531  *   gpa - VM physical address
1532  *
1533  * Output Args: None
1534  *
1535  * Return:
1536  *   Equivalent host virtual address
1537  *
1538  * Locates the memory region containing the VM physical address given
1539  * by gpa, within the VM given by vm.  When found, the host virtual
1540  * address providing the memory to the vm physical address is returned.
1541  * A TEST_ASSERT failure occurs if no region containing gpa exists.
1542  */
1543 void *addr_gpa2hva(struct kvm_vm *vm, gpa_t gpa)
1544 {
1545 	struct userspace_mem_region *region;
1546 
1547 	gpa = vm_untag_gpa(vm, gpa);
1548 
1549 	region = userspace_mem_region_find(vm, gpa, gpa);
1550 	if (!region) {
1551 		TEST_FAIL("No vm physical memory at 0x%lx", gpa);
1552 		return NULL;
1553 	}
1554 
1555 	return (void *)((uintptr_t)region->host_mem
1556 		+ (gpa - region->region.guest_phys_addr));
1557 }
1558 
1559 /*
1560  * Address Host Virtual to VM Physical
1561  *
1562  * Input Args:
1563  *   vm - Virtual Machine
1564  *   hva - Host virtual address
1565  *
1566  * Output Args: None
1567  *
1568  * Return:
1569  *   Equivalent VM physical address
1570  *
1571  * Locates the memory region containing the host virtual address given
1572  * by hva, within the VM given by vm.  When found, the equivalent
1573  * VM physical address is returned. A TEST_ASSERT failure occurs if no
1574  * region containing hva exists.
1575  */
1576 gpa_t addr_hva2gpa(struct kvm_vm *vm, void *hva)
1577 {
1578 	struct rb_node *node;
1579 
1580 	for (node = vm->regions.hva_tree.rb_node; node; ) {
1581 		struct userspace_mem_region *region =
1582 			container_of(node, struct userspace_mem_region, hva_node);
1583 
1584 		if (hva >= region->host_mem) {
1585 			if (hva <= (region->host_mem
1586 				+ region->region.memory_size - 1))
1587 				return (gpa_t)((uintptr_t)
1588 					region->region.guest_phys_addr
1589 					+ (hva - (uintptr_t)region->host_mem));
1590 
1591 			node = node->rb_right;
1592 		} else
1593 			node = node->rb_left;
1594 	}
1595 
1596 	TEST_FAIL("No mapping to a guest physical address, hva: %p", hva);
1597 	return -1;
1598 }
1599 
1600 /*
1601  * Address VM physical to Host Virtual *alias*.
1602  *
1603  * Input Args:
1604  *   vm - Virtual Machine
1605  *   gpa - VM physical address
1606  *
1607  * Output Args: None
1608  *
1609  * Return:
1610  *   Equivalent address within the host virtual *alias* area, or NULL
1611  *   (without failing the test) if the guest memory is not shared (so
1612  *   no alias exists).
1613  *
1614  * Create a writable, shared virtual=>physical alias for the specific GPA.
1615  * The primary use case is to allow the host selftest to manipulate guest
1616  * memory without mapping said memory in the guest's address space. And, for
1617  * userfaultfd-based demand paging, to do so without triggering userfaults.
1618  */
1619 void *addr_gpa2alias(struct kvm_vm *vm, gpa_t gpa)
1620 {
1621 	struct userspace_mem_region *region;
1622 	uintptr_t offset;
1623 
1624 	region = userspace_mem_region_find(vm, gpa, gpa);
1625 	if (!region)
1626 		return NULL;
1627 
1628 	if (!region->host_alias)
1629 		return NULL;
1630 
1631 	offset = gpa - region->region.guest_phys_addr;
1632 	return (void *) ((uintptr_t) region->host_alias + offset);
1633 }
1634 
1635 /* Create an interrupt controller chip for the specified VM. */
1636 void vm_create_irqchip(struct kvm_vm *vm)
1637 {
1638 	int r;
1639 
1640 	/*
1641 	 * Allocate a fully in-kernel IRQ chip by default, but fall back to a
1642 	 * split model (x86 only) if that fails (KVM x86 allows compiling out
1643 	 * support for KVM_CREATE_IRQCHIP).
1644 	 */
1645 	r = __vm_ioctl(vm, KVM_CREATE_IRQCHIP, NULL);
1646 	if (r && errno == ENOTTY && kvm_has_cap(KVM_CAP_SPLIT_IRQCHIP))
1647 		vm_enable_cap(vm, KVM_CAP_SPLIT_IRQCHIP, 24);
1648 	else
1649 		TEST_ASSERT_VM_VCPU_IOCTL(!r, KVM_CREATE_IRQCHIP, r, vm);
1650 
1651 	vm->has_irqchip = true;
1652 }
1653 
1654 int _vcpu_run(struct kvm_vcpu *vcpu)
1655 {
1656 	int rc;
1657 
1658 	do {
1659 		rc = __vcpu_run(vcpu);
1660 	} while (rc == -1 && errno == EINTR);
1661 
1662 	if (!rc)
1663 		assert_on_unhandled_exception(vcpu);
1664 
1665 	return rc;
1666 }
1667 
1668 /*
1669  * Invoke KVM_RUN on a vCPU until KVM returns something other than -EINTR.
1670  * Assert if the KVM returns an error (other than -EINTR).
1671  */
1672 void vcpu_run(struct kvm_vcpu *vcpu)
1673 {
1674 	int ret = _vcpu_run(vcpu);
1675 
1676 	TEST_ASSERT(!ret, KVM_IOCTL_ERROR(KVM_RUN, ret));
1677 }
1678 
1679 void vcpu_run_complete_io(struct kvm_vcpu *vcpu)
1680 {
1681 	int ret;
1682 
1683 	vcpu->run->immediate_exit = 1;
1684 	ret = __vcpu_run(vcpu);
1685 	vcpu->run->immediate_exit = 0;
1686 
1687 	TEST_ASSERT(ret == -1 && errno == EINTR,
1688 		    "KVM_RUN IOCTL didn't exit immediately, rc: %i, errno: %i",
1689 		    ret, errno);
1690 }
1691 
1692 /*
1693  * Get the list of guest registers which are supported for
1694  * KVM_GET_ONE_REG/KVM_SET_ONE_REG ioctls.  Returns a kvm_reg_list pointer,
1695  * it is the caller's responsibility to free the list.
1696  */
1697 struct kvm_reg_list *vcpu_get_reg_list(struct kvm_vcpu *vcpu)
1698 {
1699 	struct kvm_reg_list reg_list_n = { .n = 0 }, *reg_list;
1700 	int ret;
1701 
1702 	ret = __vcpu_ioctl(vcpu, KVM_GET_REG_LIST, &reg_list_n);
1703 	TEST_ASSERT(ret == -1 && errno == E2BIG, "KVM_GET_REG_LIST n=0");
1704 
1705 	reg_list = calloc(1, sizeof(*reg_list) + reg_list_n.n * sizeof(__u64));
1706 	reg_list->n = reg_list_n.n;
1707 	vcpu_ioctl(vcpu, KVM_GET_REG_LIST, reg_list);
1708 	return reg_list;
1709 }
1710 
1711 void *vcpu_map_dirty_ring(struct kvm_vcpu *vcpu)
1712 {
1713 	u32 page_size = getpagesize();
1714 	u32 size = vcpu->vm->dirty_ring_size;
1715 
1716 	TEST_ASSERT(size > 0, "Should enable dirty ring first");
1717 
1718 	if (!vcpu->dirty_gfns) {
1719 		void *addr;
1720 
1721 		addr = mmap(NULL, size, PROT_READ, MAP_PRIVATE, vcpu->fd,
1722 			    page_size * KVM_DIRTY_LOG_PAGE_OFFSET);
1723 		TEST_ASSERT(addr == MAP_FAILED, "Dirty ring mapped private");
1724 
1725 		addr = mmap(NULL, size, PROT_READ | PROT_EXEC, MAP_PRIVATE, vcpu->fd,
1726 			    page_size * KVM_DIRTY_LOG_PAGE_OFFSET);
1727 		TEST_ASSERT(addr == MAP_FAILED, "Dirty ring mapped exec");
1728 
1729 		addr = __kvm_mmap(size, PROT_READ | PROT_WRITE, MAP_SHARED, vcpu->fd,
1730 				  page_size * KVM_DIRTY_LOG_PAGE_OFFSET);
1731 
1732 		vcpu->dirty_gfns = addr;
1733 		vcpu->dirty_gfns_count = size / sizeof(struct kvm_dirty_gfn);
1734 	}
1735 
1736 	return vcpu->dirty_gfns;
1737 }
1738 
1739 /*
1740  * Device Ioctl
1741  */
1742 
1743 int __kvm_has_device_attr(int dev_fd, u32 group, u64 attr)
1744 {
1745 	struct kvm_device_attr attribute = {
1746 		.group = group,
1747 		.attr = attr,
1748 		.flags = 0,
1749 	};
1750 
1751 	return ioctl(dev_fd, KVM_HAS_DEVICE_ATTR, &attribute);
1752 }
1753 
1754 int __kvm_test_create_device(struct kvm_vm *vm, u64 type)
1755 {
1756 	struct kvm_create_device create_dev = {
1757 		.type = type,
1758 		.flags = KVM_CREATE_DEVICE_TEST,
1759 	};
1760 
1761 	return __vm_ioctl(vm, KVM_CREATE_DEVICE, &create_dev);
1762 }
1763 
1764 int __kvm_create_device(struct kvm_vm *vm, u64 type)
1765 {
1766 	struct kvm_create_device create_dev = {
1767 		.type = type,
1768 		.fd = -1,
1769 		.flags = 0,
1770 	};
1771 	int err;
1772 
1773 	err = __vm_ioctl(vm, KVM_CREATE_DEVICE, &create_dev);
1774 	TEST_ASSERT(err <= 0, "KVM_CREATE_DEVICE shouldn't return a positive value");
1775 	return err ? : create_dev.fd;
1776 }
1777 
1778 int __kvm_device_attr_get(int dev_fd, u32 group, u64 attr, void *val)
1779 {
1780 	struct kvm_device_attr kvmattr = {
1781 		.group = group,
1782 		.attr = attr,
1783 		.flags = 0,
1784 		.addr = (uintptr_t)val,
1785 	};
1786 
1787 	return __kvm_ioctl(dev_fd, KVM_GET_DEVICE_ATTR, &kvmattr);
1788 }
1789 
1790 int __kvm_device_attr_set(int dev_fd, u32 group, u64 attr, void *val)
1791 {
1792 	struct kvm_device_attr kvmattr = {
1793 		.group = group,
1794 		.attr = attr,
1795 		.flags = 0,
1796 		.addr = (uintptr_t)val,
1797 	};
1798 
1799 	return __kvm_ioctl(dev_fd, KVM_SET_DEVICE_ATTR, &kvmattr);
1800 }
1801 
1802 /*
1803  * IRQ related functions.
1804  */
1805 
1806 int _kvm_irq_line(struct kvm_vm *vm, u32 irq, int level)
1807 {
1808 	struct kvm_irq_level irq_level = {
1809 		.irq    = irq,
1810 		.level  = level,
1811 	};
1812 
1813 	return __vm_ioctl(vm, KVM_IRQ_LINE, &irq_level);
1814 }
1815 
1816 void kvm_irq_line(struct kvm_vm *vm, u32 irq, int level)
1817 {
1818 	int ret = _kvm_irq_line(vm, irq, level);
1819 
1820 	TEST_ASSERT(ret >= 0, KVM_IOCTL_ERROR(KVM_IRQ_LINE, ret));
1821 }
1822 
1823 struct kvm_irq_routing *kvm_gsi_routing_create(void)
1824 {
1825 	struct kvm_irq_routing *routing;
1826 	size_t size;
1827 
1828 	size = sizeof(struct kvm_irq_routing);
1829 	/* Allocate space for the max number of entries: this wastes 196 KBs. */
1830 	size += KVM_MAX_IRQ_ROUTES * sizeof(struct kvm_irq_routing_entry);
1831 	routing = calloc(1, size);
1832 	assert(routing);
1833 
1834 	return routing;
1835 }
1836 
1837 void kvm_gsi_routing_irqchip_add(struct kvm_irq_routing *routing,
1838 		u32 gsi, u32 pin)
1839 {
1840 	int i;
1841 
1842 	assert(routing);
1843 	assert(routing->nr < KVM_MAX_IRQ_ROUTES);
1844 
1845 	i = routing->nr;
1846 	routing->entries[i].gsi = gsi;
1847 	routing->entries[i].type = KVM_IRQ_ROUTING_IRQCHIP;
1848 	routing->entries[i].flags = 0;
1849 	routing->entries[i].u.irqchip.irqchip = 0;
1850 	routing->entries[i].u.irqchip.pin = pin;
1851 	routing->nr++;
1852 }
1853 
1854 int _kvm_gsi_routing_write(struct kvm_vm *vm, struct kvm_irq_routing *routing)
1855 {
1856 	int ret;
1857 
1858 	assert(routing);
1859 	ret = __vm_ioctl(vm, KVM_SET_GSI_ROUTING, routing);
1860 	free(routing);
1861 
1862 	return ret;
1863 }
1864 
1865 void kvm_gsi_routing_write(struct kvm_vm *vm, struct kvm_irq_routing *routing)
1866 {
1867 	int ret;
1868 
1869 	ret = _kvm_gsi_routing_write(vm, routing);
1870 	TEST_ASSERT(!ret, KVM_IOCTL_ERROR(KVM_SET_GSI_ROUTING, ret));
1871 }
1872 
1873 /*
1874  * VM Dump
1875  *
1876  * Input Args:
1877  *   vm - Virtual Machine
1878  *   indent - Left margin indent amount
1879  *
1880  * Output Args:
1881  *   stream - Output FILE stream
1882  *
1883  * Return: None
1884  *
1885  * Dumps the current state of the VM given by vm, to the FILE stream
1886  * given by stream.
1887  */
1888 void vm_dump(FILE *stream, struct kvm_vm *vm, u8 indent)
1889 {
1890 	int ctr;
1891 	struct userspace_mem_region *region;
1892 	struct kvm_vcpu *vcpu;
1893 
1894 	fprintf(stream, "%*smode: 0x%x\n", indent, "", vm->mode);
1895 	fprintf(stream, "%*sfd: %i\n", indent, "", vm->fd);
1896 	fprintf(stream, "%*spage_size: 0x%x\n", indent, "", vm->page_size);
1897 	fprintf(stream, "%*sMem Regions:\n", indent, "");
1898 	hash_for_each(vm->regions.slot_hash, ctr, region, slot_node) {
1899 		fprintf(stream, "%*sguest_phys: 0x%lx size: 0x%lx "
1900 			"host_virt: %p\n", indent + 2, "",
1901 			(u64)region->region.guest_phys_addr,
1902 			(u64)region->region.memory_size,
1903 			region->host_mem);
1904 		fprintf(stream, "%*sunused_phy_pages: ", indent + 2, "");
1905 		sparsebit_dump(stream, region->unused_phy_pages, 0);
1906 		if (region->protected_phy_pages) {
1907 			fprintf(stream, "%*sprotected_phy_pages: ", indent + 2, "");
1908 			sparsebit_dump(stream, region->protected_phy_pages, 0);
1909 		}
1910 	}
1911 	fprintf(stream, "%*sMapped Virtual Pages:\n", indent, "");
1912 	sparsebit_dump(stream, vm->vpages_mapped, indent + 2);
1913 	fprintf(stream, "%*spgd_created: %u\n", indent, "",
1914 		vm->mmu.pgd_created);
1915 	if (vm->mmu.pgd_created) {
1916 		fprintf(stream, "%*sVirtual Translation Tables:\n",
1917 			indent + 2, "");
1918 		virt_dump(stream, vm, indent + 4);
1919 	}
1920 	fprintf(stream, "%*sVCPUs:\n", indent, "");
1921 
1922 	list_for_each_entry(vcpu, &vm->vcpus, list)
1923 		vcpu_dump(stream, vcpu, indent + 2);
1924 }
1925 
1926 #define KVM_EXIT_STRING(x) {KVM_EXIT_##x, #x}
1927 
1928 /* Known KVM exit reasons */
1929 static struct exit_reason {
1930 	unsigned int reason;
1931 	const char *name;
1932 } exit_reasons_known[] = {
1933 	KVM_EXIT_STRING(UNKNOWN),
1934 	KVM_EXIT_STRING(EXCEPTION),
1935 	KVM_EXIT_STRING(IO),
1936 	KVM_EXIT_STRING(HYPERCALL),
1937 	KVM_EXIT_STRING(DEBUG),
1938 	KVM_EXIT_STRING(HLT),
1939 	KVM_EXIT_STRING(MMIO),
1940 	KVM_EXIT_STRING(IRQ_WINDOW_OPEN),
1941 	KVM_EXIT_STRING(SHUTDOWN),
1942 	KVM_EXIT_STRING(FAIL_ENTRY),
1943 	KVM_EXIT_STRING(INTR),
1944 	KVM_EXIT_STRING(SET_TPR),
1945 	KVM_EXIT_STRING(TPR_ACCESS),
1946 	KVM_EXIT_STRING(S390_SIEIC),
1947 	KVM_EXIT_STRING(S390_RESET),
1948 	KVM_EXIT_STRING(DCR),
1949 	KVM_EXIT_STRING(NMI),
1950 	KVM_EXIT_STRING(INTERNAL_ERROR),
1951 	KVM_EXIT_STRING(OSI),
1952 	KVM_EXIT_STRING(PAPR_HCALL),
1953 	KVM_EXIT_STRING(S390_UCONTROL),
1954 	KVM_EXIT_STRING(WATCHDOG),
1955 	KVM_EXIT_STRING(S390_TSCH),
1956 	KVM_EXIT_STRING(EPR),
1957 	KVM_EXIT_STRING(SYSTEM_EVENT),
1958 	KVM_EXIT_STRING(S390_STSI),
1959 	KVM_EXIT_STRING(IOAPIC_EOI),
1960 	KVM_EXIT_STRING(HYPERV),
1961 	KVM_EXIT_STRING(ARM_NISV),
1962 	KVM_EXIT_STRING(X86_RDMSR),
1963 	KVM_EXIT_STRING(X86_WRMSR),
1964 	KVM_EXIT_STRING(DIRTY_RING_FULL),
1965 	KVM_EXIT_STRING(AP_RESET_HOLD),
1966 	KVM_EXIT_STRING(X86_BUS_LOCK),
1967 	KVM_EXIT_STRING(XEN),
1968 	KVM_EXIT_STRING(RISCV_SBI),
1969 	KVM_EXIT_STRING(RISCV_CSR),
1970 	KVM_EXIT_STRING(NOTIFY),
1971 	KVM_EXIT_STRING(LOONGARCH_IOCSR),
1972 	KVM_EXIT_STRING(MEMORY_FAULT),
1973 	KVM_EXIT_STRING(ARM_SEA),
1974 };
1975 
1976 /*
1977  * Exit Reason String
1978  *
1979  * Input Args:
1980  *   exit_reason - Exit reason
1981  *
1982  * Output Args: None
1983  *
1984  * Return:
1985  *   Constant string pointer describing the exit reason.
1986  *
1987  * Locates and returns a constant string that describes the KVM exit
1988  * reason given by exit_reason.  If no such string is found, a constant
1989  * string of "Unknown" is returned.
1990  */
1991 const char *exit_reason_str(unsigned int exit_reason)
1992 {
1993 	unsigned int n1;
1994 
1995 	for (n1 = 0; n1 < ARRAY_SIZE(exit_reasons_known); n1++) {
1996 		if (exit_reason == exit_reasons_known[n1].reason)
1997 			return exit_reasons_known[n1].name;
1998 	}
1999 
2000 	return "Unknown";
2001 }
2002 
2003 /*
2004  * Physical Contiguous Page Allocator
2005  *
2006  * Input Args:
2007  *   vm - Virtual Machine
2008  *   num - number of pages
2009  *   min_gpa - Physical address minimum
2010  *   memslot - Memory region to allocate page from
2011  *   protected - True if the pages will be used as protected/private memory
2012  *
2013  * Output Args: None
2014  *
2015  * Return:
2016  *   Starting physical address
2017  *
2018  * Within the VM specified by vm, locates a range of available physical
2019  * pages at or above min_gpa. If found, the pages are marked as in use
2020  * and their base address is returned. A TEST_ASSERT failure occurs if
2021  * not enough pages are available at or above min_gpa.
2022  */
2023 gpa_t __vm_phy_pages_alloc(struct kvm_vm *vm, size_t num,
2024 			   gpa_t min_gpa, u32 memslot,
2025 			   bool protected)
2026 {
2027 	struct userspace_mem_region *region;
2028 	sparsebit_idx_t pg, base;
2029 
2030 	TEST_ASSERT(num > 0, "Must allocate at least one page");
2031 
2032 	TEST_ASSERT((min_gpa % vm->page_size) == 0, "Min physical address "
2033 		"not divisible by page size.\n"
2034 		"  min_gpa: 0x%lx page_size: 0x%x",
2035 		min_gpa, vm->page_size);
2036 
2037 	region = memslot2region(vm, memslot);
2038 	TEST_ASSERT(!protected || region->protected_phy_pages,
2039 		    "Region doesn't support protected memory");
2040 
2041 	base = pg = min_gpa >> vm->page_shift;
2042 	do {
2043 		for (; pg < base + num; ++pg) {
2044 			if (!sparsebit_is_set(region->unused_phy_pages, pg)) {
2045 				base = pg = sparsebit_next_set(region->unused_phy_pages, pg);
2046 				break;
2047 			}
2048 		}
2049 	} while (pg && pg != base + num);
2050 
2051 	if (pg == 0) {
2052 		fprintf(stderr, "No guest physical page available, "
2053 			"min_gpa: 0x%lx page_size: 0x%x memslot: %u\n",
2054 			min_gpa, vm->page_size, memslot);
2055 		fputs("---- vm dump ----\n", stderr);
2056 		vm_dump(stderr, vm, 2);
2057 		abort();
2058 	}
2059 
2060 	for (pg = base; pg < base + num; ++pg) {
2061 		sparsebit_clear(region->unused_phy_pages, pg);
2062 		if (protected)
2063 			sparsebit_set(region->protected_phy_pages, pg);
2064 	}
2065 
2066 	return base * vm->page_size;
2067 }
2068 
2069 gpa_t vm_phy_page_alloc(struct kvm_vm *vm, gpa_t min_gpa, u32 memslot)
2070 {
2071 	return vm_phy_pages_alloc(vm, 1, min_gpa, memslot);
2072 }
2073 
2074 gpa_t vm_alloc_page_table(struct kvm_vm *vm)
2075 {
2076 	return vm_phy_page_alloc(vm, KVM_GUEST_PAGE_TABLE_MIN_PADDR,
2077 				 vm->memslots[MEM_REGION_PT]);
2078 }
2079 
2080 /*
2081  * Address Guest Virtual to Host Virtual
2082  *
2083  * Input Args:
2084  *   vm - Virtual Machine
2085  *   gva - VM virtual address
2086  *
2087  * Output Args: None
2088  *
2089  * Return:
2090  *   Equivalent host virtual address
2091  */
2092 void *addr_gva2hva(struct kvm_vm *vm, gva_t gva)
2093 {
2094 	return addr_gpa2hva(vm, addr_gva2gpa(vm, gva));
2095 }
2096 
2097 unsigned long __weak vm_compute_max_gfn(struct kvm_vm *vm)
2098 {
2099 	return ((1ULL << vm->pa_bits) >> vm->page_shift) - 1;
2100 }
2101 
2102 static unsigned int vm_calc_num_pages(unsigned int num_pages,
2103 				      unsigned int page_shift,
2104 				      unsigned int new_page_shift,
2105 				      bool ceil)
2106 {
2107 	unsigned int n = 1 << (new_page_shift - page_shift);
2108 
2109 	if (page_shift >= new_page_shift)
2110 		return num_pages * (1 << (page_shift - new_page_shift));
2111 
2112 	return num_pages / n + !!(ceil && num_pages % n);
2113 }
2114 
2115 static inline int getpageshift(void)
2116 {
2117 	return __builtin_ffs(getpagesize()) - 1;
2118 }
2119 
2120 unsigned int
2121 vm_num_host_pages(enum vm_guest_mode mode, unsigned int num_guest_pages)
2122 {
2123 	return vm_calc_num_pages(num_guest_pages,
2124 				 vm_guest_mode_params[mode].page_shift,
2125 				 getpageshift(), true);
2126 }
2127 
2128 unsigned int
2129 vm_num_guest_pages(enum vm_guest_mode mode, unsigned int num_host_pages)
2130 {
2131 	return vm_calc_num_pages(num_host_pages, getpageshift(),
2132 				 vm_guest_mode_params[mode].page_shift, false);
2133 }
2134 
2135 unsigned int vm_calc_num_guest_pages(enum vm_guest_mode mode, size_t size)
2136 {
2137 	unsigned int n;
2138 	n = DIV_ROUND_UP(size, vm_guest_mode_params[mode].page_size);
2139 	return vm_adjust_num_guest_pages(mode, n);
2140 }
2141 
2142 /*
2143  * Read binary stats descriptors
2144  *
2145  * Input Args:
2146  *   stats_fd - the file descriptor for the binary stats file from which to read
2147  *   header - the binary stats metadata header corresponding to the given FD
2148  *
2149  * Output Args: None
2150  *
2151  * Return:
2152  *   A pointer to a newly allocated series of stat descriptors.
2153  *   Caller is responsible for freeing the returned kvm_stats_desc.
2154  *
2155  * Read the stats descriptors from the binary stats interface.
2156  */
2157 struct kvm_stats_desc *read_stats_descriptors(int stats_fd,
2158 					      struct kvm_stats_header *header)
2159 {
2160 	struct kvm_stats_desc *stats_desc;
2161 	ssize_t desc_size, total_size, ret;
2162 
2163 	desc_size = get_stats_descriptor_size(header);
2164 	total_size = header->num_desc * desc_size;
2165 
2166 	stats_desc = calloc(header->num_desc, desc_size);
2167 	TEST_ASSERT(stats_desc, "Allocate memory for stats descriptors");
2168 
2169 	ret = pread(stats_fd, stats_desc, total_size, header->desc_offset);
2170 	TEST_ASSERT(ret == total_size, "Read KVM stats descriptors");
2171 
2172 	return stats_desc;
2173 }
2174 
2175 /*
2176  * Read stat data for a particular stat
2177  *
2178  * Input Args:
2179  *   stats_fd - the file descriptor for the binary stats file from which to read
2180  *   header - the binary stats metadata header corresponding to the given FD
2181  *   desc - the binary stat metadata for the particular stat to be read
2182  *   max_elements - the maximum number of 8-byte values to read into data
2183  *
2184  * Output Args:
2185  *   data - the buffer into which stat data should be read
2186  *
2187  * Read the data values of a specified stat from the binary stats interface.
2188  */
2189 void read_stat_data(int stats_fd, struct kvm_stats_header *header,
2190 		    struct kvm_stats_desc *desc, u64 *data,
2191 		    size_t max_elements)
2192 {
2193 	size_t nr_elements = min_t(ssize_t, desc->size, max_elements);
2194 	size_t size = nr_elements * sizeof(*data);
2195 	ssize_t ret;
2196 
2197 	TEST_ASSERT(desc->size, "No elements in stat '%s'", desc->name);
2198 	TEST_ASSERT(max_elements, "Zero elements requested for stat '%s'", desc->name);
2199 
2200 	ret = pread(stats_fd, data, size,
2201 		    header->data_offset + desc->offset);
2202 
2203 	TEST_ASSERT(ret >= 0, "pread() failed on stat '%s', errno: %i (%s)",
2204 		    desc->name, errno, strerror(errno));
2205 	TEST_ASSERT(ret == size,
2206 		    "pread() on stat '%s' read %ld bytes, wanted %lu bytes",
2207 		    desc->name, size, ret);
2208 }
2209 
2210 void kvm_get_stat(struct kvm_binary_stats *stats, const char *name,
2211 		  u64 *data, size_t max_elements)
2212 {
2213 	struct kvm_stats_desc *desc;
2214 	size_t size_desc;
2215 	int i;
2216 
2217 	if (!stats->desc) {
2218 		read_stats_header(stats->fd, &stats->header);
2219 		stats->desc = read_stats_descriptors(stats->fd, &stats->header);
2220 	}
2221 
2222 	size_desc = get_stats_descriptor_size(&stats->header);
2223 
2224 	for (i = 0; i < stats->header.num_desc; ++i) {
2225 		desc = (void *)stats->desc + (i * size_desc);
2226 
2227 		if (strcmp(desc->name, name))
2228 			continue;
2229 
2230 		read_stat_data(stats->fd, &stats->header, desc, data, max_elements);
2231 		return;
2232 	}
2233 
2234 	TEST_FAIL("Unable to find stat '%s'", name);
2235 }
2236 
2237 __weak void kvm_arch_vm_post_create(struct kvm_vm *vm, unsigned int nr_vcpus)
2238 {
2239 }
2240 
2241 __weak void kvm_arch_vm_finalize_vcpus(struct kvm_vm *vm)
2242 {
2243 }
2244 
2245 __weak void kvm_arch_vm_release(struct kvm_vm *vm)
2246 {
2247 }
2248 
2249 __weak void kvm_selftest_arch_init(void)
2250 {
2251 }
2252 
2253 static void report_unexpected_signal(int signum)
2254 {
2255 #define KVM_CASE_SIGNUM(sig)					\
2256 	case sig: TEST_FAIL("Unexpected " #sig " (%d)\n", signum)
2257 
2258 	switch (signum) {
2259 	KVM_CASE_SIGNUM(SIGBUS);
2260 	KVM_CASE_SIGNUM(SIGSEGV);
2261 	KVM_CASE_SIGNUM(SIGILL);
2262 	KVM_CASE_SIGNUM(SIGFPE);
2263 	default:
2264 		TEST_FAIL("Unexpected signal %d\n", signum);
2265 	}
2266 }
2267 
2268 void __attribute((constructor)) kvm_selftest_init(void)
2269 {
2270 	struct sigaction sig_sa = {
2271 		.sa_handler = report_unexpected_signal,
2272 	};
2273 
2274 	/* Tell stdout not to buffer its content. */
2275 	setbuf(stdout, NULL);
2276 
2277 	sigaction(SIGBUS, &sig_sa, NULL);
2278 	sigaction(SIGSEGV, &sig_sa, NULL);
2279 	sigaction(SIGILL, &sig_sa, NULL);
2280 	sigaction(SIGFPE, &sig_sa, NULL);
2281 
2282 	guest_random_seed = last_guest_seed = random();
2283 	pr_info("Random seed: 0x%x\n", guest_random_seed);
2284 
2285 	kvm_selftest_arch_init();
2286 }
2287 
2288 bool vm_is_gpa_protected(struct kvm_vm *vm, gpa_t gpa)
2289 {
2290 	sparsebit_idx_t pg = 0;
2291 	struct userspace_mem_region *region;
2292 
2293 	if (!vm_arch_has_protected_memory(vm))
2294 		return false;
2295 
2296 	region = userspace_mem_region_find(vm, gpa, gpa);
2297 	TEST_ASSERT(region, "No vm physical memory at 0x%lx", gpa);
2298 
2299 	pg = gpa >> vm->page_shift;
2300 	return sparsebit_is_set(region->protected_phy_pages, pg);
2301 }
2302 
2303 __weak bool kvm_arch_has_default_irqchip(void)
2304 {
2305 	return false;
2306 }
2307