Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-27 Thread Christian Borntraeger
On 24.11.20 20:16, Sean Christopherson wrote: > On Fri, Nov 13, 2020, David Rientjes wrote: > >> >> >> On Mon, 2 Nov 2020, Sean Christopherson wrote:

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Sean Christopherson
On Tue, Nov 24, 2020, Vipin Sharma wrote: > On Tue, Nov 24, 2020 at 09:27:25PM +, Sean Christopherson wrote: > > Is a root level stat file needed? Can't the infrastructure do .max - > > .current > > on the root cgroup to calculate the number of available ids in the system? > > For an efficie

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Vipin Sharma
On Tue, Nov 24, 2020 at 09:27:25PM +, Sean Christopherson wrote: > On Tue, Nov 24, 2020, Vipin Sharma wrote: > > On Tue, Nov 24, 2020 at 12:18:45PM -0800, David Rientjes wrote: > > > On Tue, 24 Nov 2020, Vipin Sharma wrote: > > > > > > > > > Looping Janosch and Christian back into the thread.

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Sean Christopherson
On Tue, Nov 24, 2020, Vipin Sharma wrote: > On Tue, Nov 24, 2020 at 12:18:45PM -0800, David Rientjes wrote: > > On Tue, 24 Nov 2020, Vipin Sharma wrote: > > > > > > > Looping Janosch and Christian back into the thread. > > > > > > > > > >

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Vipin Sharma
On Tue, Nov 24, 2020 at 12:18:45PM -0800, David Rientjes wrote: > On Tue, 24 Nov 2020, Vipin Sharma wrote: > > > > > Looping Janosch and Christian back into the thread. > > > > > > > > > > > >

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread David Rientjes
On Tue, 24 Nov 2020, Vipin Sharma wrote: > > > Looping Janosch and Christian back into the thread. > > > > > > > > > > > > I interpret this suggestion as

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Vipin Sharma
On Tue, Nov 24, 2020 at 07:16:29PM +, Sean Christopherson wrote: > On Fri, Nov 13, 2020, David Rientjes wrote: > > > > > > > On Mon, 2 Nov 2020, Sean Christopherson wrote:

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-24 Thread Sean Christopherson
On Fri, Nov 13, 2020, David Rientjes wrote: > > On Mon, 2 Nov 2020, Sean Christopherson wrote: >

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-13 Thread David Rientjes
On Mon, 2 Nov 2020, Sean Christopherson wrote: > On Fri, Oct 02, 2020 at 01:48:10PM -0700, Vipin Sharma wrote: > > On Fri, Sep 25, 2020 at 03:22:20PM -0700, Vipin Sharma wrote: > > > I agree with you that the abstract name is better than the concrete > > > name, I also feel that we must provide HW

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-11-02 Thread Sean Christopherson
On Fri, Oct 02, 2020 at 01:48:10PM -0700, Vipin Sharma wrote: > On Fri, Sep 25, 2020 at 03:22:20PM -0700, Vipin Sharma wrote: > > I agree with you that the abstract name is better than the concrete > > name, I also feel that we must provide HW extensions. Here is one > > approach: > > > > Cgroup n

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-10-02 Thread Vipin Sharma
On Fri, Sep 25, 2020 at 03:22:20PM -0700, Vipin Sharma wrote: > On Thu, Sep 24, 2020 at 02:55:18PM -0500, Tom Lendacky wrote: > > On 9/24/20 2:21 PM, Sean Christopherson wrote: > > > On Tue, Sep 22, 2020 at 02:14:04PM -0700, Vipin Sharma wrote: > > > > On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-10-01 Thread Tom Lendacky
On 10/1/20 1:08 PM, Peter Gonda wrote: On Thu, Sep 24, 2020 at 1:55 PM Tom Lendacky wrote: On 9/24/20 2:21 PM, Sean Christopherson wrote: On Tue, Sep 22, 2020 at 02:14:04PM -0700, Vipin Sharma wrote: On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean Christopherson wrote: On Mon, Sep 21, 2020 a

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-10-01 Thread Peter Gonda
On Thu, Sep 24, 2020 at 1:55 PM Tom Lendacky wrote: > > On 9/24/20 2:21 PM, Sean Christopherson wrote: > > On Tue, Sep 22, 2020 at 02:14:04PM -0700, Vipin Sharma wrote: > >> On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean Christopherson wrote: > >>> On Mon, Sep 21, 2020 at 05:40:22PM -0700, Vipin S

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-28 Thread Christian Borntraeger
On 28.09.20 11:12, Janosch Frank wrote: > On 9/23/20 2:47 PM, Paolo Bonzini wrote: >> On 22/09/20 03:48, Sean Christopherson wrote: >>> This should be genericized to not be SEV specific. TDX has a similar >>> scarcity issue in the form of key IDs, which IIUC are analogous to SEV ASIDs >>> (gave my

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-28 Thread Janosch Frank
On 9/23/20 2:47 PM, Paolo Bonzini wrote: > On 22/09/20 03:48, Sean Christopherson wrote: >> This should be genericized to not be SEV specific. TDX has a similar >> scarcity issue in the form of key IDs, which IIUC are analogous to SEV ASIDs >> (gave myself a quick crash course on SEV ASIDs). Func

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-25 Thread Vipin Sharma
On Thu, Sep 24, 2020 at 02:55:18PM -0500, Tom Lendacky wrote: > On 9/24/20 2:21 PM, Sean Christopherson wrote: > > On Tue, Sep 22, 2020 at 02:14:04PM -0700, Vipin Sharma wrote: > > > On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean Christopherson wrote: > > > > On Mon, Sep 21, 2020 at 05:40:22PM -070

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-24 Thread Tom Lendacky
On 9/24/20 2:21 PM, Sean Christopherson wrote: On Tue, Sep 22, 2020 at 02:14:04PM -0700, Vipin Sharma wrote: On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean Christopherson wrote: On Mon, Sep 21, 2020 at 05:40:22PM -0700, Vipin Sharma wrote: Hello, This patch series adds a new SEV controller fo

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-23 Thread Paolo Bonzini
On 22/09/20 03:48, Sean Christopherson wrote: > This should be genericized to not be SEV specific. TDX has a similar > scarcity issue in the form of key IDs, which IIUC are analogous to SEV ASIDs > (gave myself a quick crash course on SEV ASIDs). Functionally, I doubt it > would change anything,

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-22 Thread Vipin Sharma
On Mon, Sep 21, 2020 at 06:48:38PM -0700, Sean Christopherson wrote: > On Mon, Sep 21, 2020 at 05:40:22PM -0700, Vipin Sharma wrote: > > Hello, > > > > This patch series adds a new SEV controller for tracking and limiting > > the usage of SEV ASIDs on the AMD SVM platform. > > > > SEV ASIDs are u

Re: [RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-21 Thread Sean Christopherson
On Mon, Sep 21, 2020 at 05:40:22PM -0700, Vipin Sharma wrote: > Hello, > > This patch series adds a new SEV controller for tracking and limiting > the usage of SEV ASIDs on the AMD SVM platform. > > SEV ASIDs are used in creating encrypted VM and lightweight sandboxes > but this resource is in ve

[RFC Patch 0/2] KVM: SVM: Cgroup support for SVM SEV ASIDs

2020-09-21 Thread Vipin Sharma
Hello, This patch series adds a new SEV controller for tracking and limiting the usage of SEV ASIDs on the AMD SVM platform. SEV ASIDs are used in creating encrypted VM and lightweight sandboxes but this resource is in very limited quantity on a host. This limited quantity creates issues like SE