From: Eric Auger <eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
To: "eric.auger.pro-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org,
eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org,
linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
kvmarm-FPEHb7Xf0XXUo1n7N8X6UoWGPAHP3yOg@public.gmane.org,
joro-zLv9SwRftAIdnm+yROfE0A@public.gmane.org,
alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
jean-philippe.brucker-5wv7dgnIgG8@public.gmane.org,
jacob.jun.pan-VuQAYsv1563Yd54FQh9/CA@public.gmane.org,
yi.l.liu"@linux.intel.com,
will.deacon-5wv7dgnIgG8@public.gmane.org,
robin.murphy-5wv7dgnIgG8@public.gmane.org
Cc: marc.zyngier-5wv7dgnIgG8@public.gmane.org,
peter.maydell-QSEj5FYQhm4dnm+yROfE0A@public.gmane.org,
christoffer.dall-5wv7dgnIgG8@public.gmane.org
Subject: [RFC 07/13] vfio: Document nested stage control
Date: Thu, 23 Aug 2018 14:17:30 +0200 [thread overview]
Message-ID: <1535026656-8450-8-git-send-email-eric.auger@redhat.com> (raw)
In-Reply-To: <1535026656-8450-1-git-send-email-eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
New iotcls were introduced to pass information about guest stage1
to the host through VFIO. Let's document the nested stage control.
Signed-off-by: Eric Auger <eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
---
fault reporting is current missing to the picture
---
Documentation/vfio.txt | 45 +++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 45 insertions(+)
diff --git a/Documentation/vfio.txt b/Documentation/vfio.txt
index f1a4d3c..858a363 100644
--- a/Documentation/vfio.txt
+++ b/Documentation/vfio.txt
@@ -239,6 +239,51 @@ group and can access them as follows::
/* Gratuitous device reset and go... */
ioctl(device, VFIO_DEVICE_RESET);
+IOMMU Dual Stage Control
+------------------------
+
+Some IOMMUs support 2 stages of translation. This is useful when the
+guest is exposed with a virtual IOMMU and some devices are assigned
+to the guest through VFIO. Then the guest OS can use stage 1 (IOVA -> GPA),
+while the hypervisor uses stage 2 for VM isolation (GPA -> HPA).
+
+The guest gets ownership of the stage 1 page tables and also owns stage 1
+configuration structures. The hypervisor owns the root configuration structure
+(for security reason), including stage 2 configuration. This works as long
+configuration structures and page table format are compatible between the
+virtual IOMMU and the physical IOMMU.
+
+Assuming the HW supports it, this nested mode is selected by choosing the
+VFIO_TYPE1_NESTING_IOMMU type through:
+
+ioctl(container, VFIO_SET_IOMMU, VFIO_TYPE1_NESTING_IOMMU);
+
+This forces the hypervisor to use the stage 2, leaving stage 1 available for
+guest usage.
+
+Once groups are attached to the container, the guest stage 1 translation
+configuration data can be passed to VFIO by using
+
+ioctl(container, VFIO_IOMMU_BIND_GUEST_STAGE, &guest_stage_info);
+
+This allows to combine guest stage1 configuration structure along with hypervisor
+stage 2 configuration structure. stage 1 configuration structures are dependent
+on the IOMMU type.
+
+When the guest invalidates stage 1 entries, IOTLB invalidations must be forwarded
+to the host through
+ioctl(container, VFIO_IOMMU_TLB_INVALIDATE, &inv_data);
+Those invalidations can happen at various granularity levels, page, context, ...
+
+The ARM SMMU specification introduces another challenge: MSIs are translated by
+both the virtual SMMU and the physical SMMU. To build a nested mapping for the
+IOVA programmed into the assigned device, the guest needs to pass its IOVA/MSI
+doorbell GPA binding to the host. Then the hypervisor can build a nested stage 2
+binding eventually translating into the physical MSI doorbell.
+
+This is achieved by
+ioctl(container, VFIO_IOMMU_BIND_MSI, &guest_binding);
+
VFIO User API
-------------------------------------------------------------------------------
--
2.5.5
next prev parent reply other threads:[~2018-08-23 12:17 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-08-23 12:17 [RFC 00/13] SMMUv3 Nested Stage Setup Eric Auger
2018-08-23 12:17 ` [RFC 01/13] iommu: Introduce bind_guest_stage API Eric Auger
2018-08-23 12:17 ` [RFC 02/13] iommu: Introduce tlb_invalidate API Eric Auger
2018-08-23 12:17 ` [RFC 03/13] iommu: Introduce bind_guest_msi Eric Auger
[not found] ` <1535026656-8450-1-git-send-email-eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-08-23 12:17 ` [RFC 01/13] iommu: Introduce bind_guest_stage API Eric Auger
2018-08-23 15:25 ` Auger Eric
2018-08-31 13:11 ` Jean-Philippe Brucker
[not found] ` <b7909f1b-57ce-f4db-d916-140a63283232-5wv7dgnIgG8@public.gmane.org>
2018-08-31 13:52 ` Auger Eric
2018-08-31 13:52 ` Auger Eric
2018-09-03 12:19 ` Jean-Philippe Brucker
[not found] ` <4309832b-27ed-597a-b5a1-f439fbea9843-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-04 7:57 ` Tian, Kevin
2018-09-04 7:57 ` Tian, Kevin
2018-09-04 8:10 ` Auger Eric
[not found] ` <220e4c2a-d31c-d8fb-2d77-d902d2f13bb2-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-04 8:34 ` Tian, Kevin
2018-09-04 8:34 ` Tian, Kevin
2018-09-04 8:41 ` Auger Eric
2018-09-04 8:41 ` Auger Eric
2018-09-04 8:43 ` Tian, Kevin
2018-09-04 9:53 ` Jean-Philippe Brucker
2018-09-05 0:36 ` Tian, Kevin
2018-09-05 0:36 ` Tian, Kevin
[not found] ` <A2975661238FB949B60364EF0F2C257439CCE9EE@SHSMSX104.ccr.corp.intel.com>
2018-08-24 13:20 ` Auger Eric
2018-08-24 13:20 ` Auger Eric
2018-08-23 12:17 ` [RFC 02/13] iommu: Introduce tlb_invalidate API Eric Auger
2018-08-31 13:17 ` Jean-Philippe Brucker
2018-08-31 13:17 ` Jean-Philippe Brucker
2018-08-31 14:07 ` Auger Eric
2018-09-03 12:28 ` Jean-Philippe Brucker
2018-09-03 12:41 ` Auger Eric
2018-09-03 13:41 ` Jean-Philippe Brucker
2018-08-23 12:17 ` [RFC 03/13] iommu: Introduce bind_guest_msi Eric Auger
2018-08-23 12:17 ` [RFC 04/13] vfio: VFIO_IOMMU_BIND_GUEST_STAGE Eric Auger
2018-08-23 12:17 ` [RFC 05/13] vfio: VFIO_IOMMU_TLB_INVALIDATE Eric Auger
2018-08-23 12:17 ` [RFC 06/13] vfio: VFIO_IOMMU_BIND_MSI Eric Auger
2018-08-23 12:17 ` Eric Auger [this message]
2018-08-23 12:17 ` [RFC 08/13] iommu/arm-smmu-v3: Link domains and devices Eric Auger
2018-08-23 12:17 ` [RFC 09/13] iommu/smmuv3: Get prepared for nested stage support Eric Auger
2018-08-31 13:20 ` Jean-Philippe Brucker
2018-08-31 13:20 ` Jean-Philippe Brucker
2018-08-31 14:11 ` Auger Eric
[not found] ` <012d4950-7a06-2d59-85a0-44d511ad893b-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-03 12:29 ` Jean-Philippe Brucker
2018-09-03 12:29 ` Jean-Philippe Brucker
2018-09-03 12:48 ` Auger Eric
2018-09-03 12:48 ` Auger Eric
2018-08-23 12:17 ` [RFC 10/13] iommu/smmuv3: Implement bind_guest_stage Eric Auger
2018-08-23 12:17 ` [RFC 11/13] iommu/smmuv3: Implement tlb_invalidate Eric Auger
2018-08-23 12:17 ` [RFC 12/13] dma-iommu: Implement NESTED_MSI cookie Eric Auger
2018-08-23 12:17 ` [RFC 13/13] iommu/smmuv3: Implement bind_guest_msi Eric Auger
2018-08-23 12:17 ` [RFC 04/13] vfio: VFIO_IOMMU_BIND_GUEST_STAGE Eric Auger
2018-08-23 12:17 ` [RFC 05/13] vfio: VFIO_IOMMU_TLB_INVALIDATE Eric Auger
2018-08-23 12:17 ` [RFC 06/13] vfio: VFIO_IOMMU_BIND_MSI Eric Auger
2018-08-23 12:17 ` [RFC 07/13] vfio: Document nested stage control Eric Auger
2018-08-23 12:17 ` [RFC 08/13] iommu/arm-smmu-v3: Link domains and devices Eric Auger
2018-08-23 12:17 ` [RFC 09/13] iommu/smmuv3: Get prepared for nested stage support Eric Auger
2018-08-23 12:17 ` [RFC 10/13] iommu/smmuv3: Implement bind_guest_stage Eric Auger
2018-08-23 12:17 ` [RFC 11/13] iommu/smmuv3: Implement tlb_invalidate Eric Auger
2018-08-23 12:17 ` [RFC 12/13] dma-iommu: Implement NESTED_MSI cookie Eric Auger
2018-08-23 12:17 ` [RFC 13/13] iommu/smmuv3: Implement bind_guest_msi Eric Auger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1535026656-8450-8-git-send-email-eric.auger@redhat.com \
--to=eric.auger-h+wxahxf7alqt0dzr+alfa@public.gmane.org \
--cc="eric.auger.pro-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org, eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org, linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, kvmarm-FPEHb7Xf0XXUo1n7N8X6UoWGPAHP3yOg@public.gmane.org, joro-zLv9SwRftAIdnm+yROfE0A@public.gmane.org, alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, jean-philippe.brucker-5wv7dgnIgG8@public.gmane.org, jacob.jun.pan-VuQAYsv1563Yd54FQh9/CA@public.gmane.org, yi.l.liu"@linux.intel.com \
--cc=christoffer.dall-5wv7dgnIgG8@public.gmane.org \
--cc=marc.zyngier-5wv7dgnIgG8@public.gmane.org \
--cc=peter.maydell-QSEj5FYQhm4dnm+yROfE0A@public.gmane.org \
--cc=robin.murphy-5wv7dgnIgG8@public.gmane.org \
--cc=will.deacon-5wv7dgnIgG8@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.