freenode
Kernel & Low-Level

KVM nSVM work assigns L2 per-vCPU ASIDs to cut TLB flushes

Yosry Ahmed's series drops dynamic ASID allocation on modern AMD CPUs and brings nested SVM closer to VMX VPID handling.

Yosry Ahmed has submitted a large KVM series that reworks TLB flush handling for nested AMD SVM guests. Instead of sharing one ASID between L1 and L2 and flushing on every nested transition, each vCPU now keeps a separate L2 ASID, the same basic idea KVM already uses for VPIDs under Intel VMX.

Shared ASIDs forced broad invalidations whenever a nested hypervisor entered or left L2, even when mappings could safely stay cached. The new model treats L1 and L2 as distinct TLB domains in the common case, so flushes become conditional rather than automatic. The series also retires KVM's dynamic ASID allocator in favor of a static ASID per vCPU (two when nested). Ahmed points out that current AMD server parts, Rome through Turin, advertise 32K ASIDs, which makes runtime recycling unnecessary.

Supporting changes cover L1 TLB_CONTROL requests on nested entry and exit, correct INVLPGA behavior once the two levels no longer share an ASID, nested NPT resync when an ASID is flushed or replaced, and Hyper-V flush FIFO handling for both contexts. Hyper-V pieces were build-tested only; SEV coverage used existing selftests. A new selftest exercises L1 and KVM-triggered flushes for both SVM and VMX and already exposed a real bug during rebasing onto related MMU work.

The net effect is fewer forced TLB and MMU syncs on nested transitions, aligning nSVM practice with the lighter path nVMX has long taken and removing a structural tax on AMD nested virtualization.