From: Jacob Pan <jacob.pan@linux.microsoft.com>
To: Yi Liu <yi.l.liu@intel.com>
Cc: Alex Williamson <alex@shazbot.org>,
<linux-kernel@vger.kernel.org>,
"iommu@lists.linux.dev" <iommu@lists.linux.dev>,
Jason Gunthorpe <jgg@nvidia.com>, Joerg Roedel <joro@8bytes.org>,
Mostafa Saleh <smostafa@google.com>,
David Matlack <dmatlack@google.com>,
Robin Murphy <robin.murphy@arm.com>,
Nicolin Chen <nicolinc@nvidia.com>,
"Tian, Kevin" <kevin.tian@intel.com>,
Saurabh Sengar <ssengar@linux.microsoft.com>,
<skhawaja@google.com>, <pasha.tatashin@soleen.com>,
Will Deacon <will@kernel.org>,
Baolu Lu <baolu.lu@linux.intel.com>,
jacob.pan@linux.microsoft.com
Subject: Re: [PATCH v5 7/9] vfio: Enable cdev noiommu mode under iommufd
Date: Thu, 21 May 2026 09:49:57 -0700 [thread overview]
Message-ID: <20260521094957.000030f5@linux.microsoft.com> (raw)
In-Reply-To: <95235a41-f9b3-4b5b-9a34-489a9ff7eac5@intel.com>
Hi Yi,
On Wed, 20 May 2026 15:20:26 +0800
Yi Liu <yi.l.liu@intel.com> wrote:
> >>
> >> -#ifdef CONFIG_VFIO_GROUP_NOIOMMU
> >> +#if IS_ENABLED(CONFIG_VFIO_GROUP_NOIOMMU) ||
> >> IS_ENABLED(CONFIG_VFIO_CDEV_NOIOMMU)
> >
> > Have you considered what happens when these are y/n or n/y?
> >
> > I think in the former case we can create cdev devices for
> > group-noiommu devices that are not labeled noiommu, skip the
> > CAP_SYS_RAWIO test, but will fail to bind. In the latter case, I
> > think we fail to setup an iommufd_device and unbind will segfault.
> >
> > We really don't need to support independently setting GROUP vs CDEV
> > NOIOMMU, the suggestion was to try to get NOIOMMU from depending on
> > VFIO_GROUP. We can do that other ways though and I think we can do
> > it without the rename in patch 1 that will inevitably result in
> > some lost config options for NOIOMMU on upgrade.
> >
> > The Kconfig may get messy, perhaps something like:
> >
> > config VFIO_NOIOMMU
> > bool "VFIO No-IOMMU support"
> > depends on VFIO_GROUP || VFIO_DEVICE_CDEV
> > depends on !VFIO_GROUP || VFIO_CONTAINER ||
> > IOMMUFD_VFIO_CONTAINER depends on !VFIO_DEVICE_CDEV ||
> > !GENERIC_ATOMIC64 select IOMMUFD_NOIOMMU if VFIO_DEVICE_CDEV
> >
> > Sorry if the previous suggestion sent us astray, but the subtleties
> > of independent support look tricky. Thanks,
>
> this also looks better to me. Less kconfigs. :)
Just to recap our discussions, we agreed with Alex's Kconfig
and the breakdown cases are as follows:
Container = VFIO_CONTAINER || IOMMUFD_VFIO_CONTAINER
# GROUP Container CDEV NOIOMMU Notes
- ----- --------- ---- ------- -----------------------
1 y y n yes Group noiommu works
2 y n n no Blocked - no container
3 y y y yes Both paths work
4 y n y no Blocked - no container
5 n - y yes Cdev-only works
6 n - n no No access path
Note that we sacrifice #4. The tradeoff: case 4
sacrifices cdev noiommu to avoid the useless group node
problem purely in Kconfig. The practical impact is small -
if someone wants cdev noiommu without container, they just
set GROUP=n. This greatly simplifies the code since NULL
group checks are not needed.
OTOH, if we want #4, we can loosen the Kconfig:
depends on !VFIO_GROUP || VFIO_DEVICE_CDEV || \
VFIO_CONTAINER || IOMMUFD_VFIO_CONTAINER
but that would allow creating useless group nodes without a
container backend. Enforcing VFIO_GROUP=n purely via Kconfig
is not possible since it would cause a circular dependency
(CONTAINER depends on GROUP).
I will send v6 shortly.
Thanks,
Jacob
next prev parent reply other threads:[~2026-05-21 16:49 UTC|newest]
Thread overview: 48+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-11 18:41 [PATCH v5 0/9] iommufd: Enable noiommu mode for cdev Jacob Pan
2026-05-11 18:41 ` [PATCH v5 1/9] vfio: Rename VFIO_NOIOMMU to VFIO_GROUP_NOIOMMU Jacob Pan
2026-05-19 23:34 ` Jason Gunthorpe
2026-05-11 18:41 ` [PATCH v5 2/9] iommufd: Support a HWPT without an iommu driver for noiommu Jacob Pan
2026-05-13 6:58 ` Baolu Lu
2026-05-13 21:30 ` Jacob Pan
2026-05-13 19:18 ` Samiullah Khawaja
2026-05-20 7:19 ` Yi Liu
2026-05-20 16:15 ` Jacob Pan
2026-05-11 18:41 ` [PATCH v5 3/9] iommufd: Move igroup allocation to a function Jacob Pan
2026-05-13 7:18 ` Baolu Lu
2026-05-11 18:41 ` [PATCH v5 4/9] iommufd: Allow binding to a noiommu device Jacob Pan
2026-05-13 7:37 ` Baolu Lu
2026-05-13 22:08 ` Jacob Pan
2026-05-14 6:51 ` Baolu Lu
2026-05-19 21:25 ` Jacob Pan
2026-05-20 7:20 ` Yi Liu
2026-05-20 15:54 ` Jacob Pan
2026-05-21 3:27 ` Yi Liu
2026-05-11 18:41 ` [PATCH v5 5/9] iommufd: Add an ioctl to query PA from IOVA for noiommu mode Jacob Pan
2026-05-11 18:58 ` Jacob Pan
2026-05-13 7:53 ` Baolu Lu
2026-05-13 12:22 ` Jason Gunthorpe
2026-05-13 22:20 ` Jacob Pan
2026-05-13 23:26 ` Jason Gunthorpe
2026-05-20 7:20 ` Yi Liu
2026-05-20 7:31 ` Yi Liu
2026-05-20 14:22 ` Jason Gunthorpe
2026-05-20 14:39 ` Yi Liu
2026-05-20 17:02 ` Jacob Pan
2026-05-11 18:41 ` [PATCH v5 6/9] vfio/group: Add VFIO_CDEV_NOIOMMU Kconfig and tolerate NULL group Jacob Pan
2026-05-20 3:45 ` Alex Williamson
2026-05-20 17:08 ` Jacob Pan
2026-05-11 18:41 ` [PATCH v5 7/9] vfio: Enable cdev noiommu mode under iommufd Jacob Pan
2026-05-19 23:40 ` Jason Gunthorpe
2026-05-20 2:56 ` Jacob Pan
2026-05-20 3:46 ` Alex Williamson
2026-05-20 7:20 ` Yi Liu
2026-05-20 18:15 ` Jacob Pan
2026-05-21 3:25 ` Yi Liu
2026-05-21 16:49 ` Jacob Pan [this message]
2026-05-11 18:41 ` [PATCH v5 8/9] selftests/vfio: Add iommufd noiommu mode selftest for cdev Jacob Pan
2026-05-11 18:41 ` [PATCH v5 9/9] Documentation: Update VFIO NOIOMMU mode Jacob Pan
2026-05-20 7:20 ` Yi Liu
2026-05-20 16:26 ` Jacob Pan
2026-05-21 3:24 ` Yi Liu
2026-05-19 18:01 ` [PATCH v5 0/9] iommufd: Enable noiommu mode for cdev Jason Gunthorpe
2026-05-19 21:03 ` Jacob Pan
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260521094957.000030f5@linux.microsoft.com \
--to=jacob.pan@linux.microsoft.com \
--cc=alex@shazbot.org \
--cc=baolu.lu@linux.intel.com \
--cc=dmatlack@google.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@nvidia.com \
--cc=joro@8bytes.org \
--cc=kevin.tian@intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=nicolinc@nvidia.com \
--cc=pasha.tatashin@soleen.com \
--cc=robin.murphy@arm.com \
--cc=skhawaja@google.com \
--cc=smostafa@google.com \
--cc=ssengar@linux.microsoft.com \
--cc=will@kernel.org \
--cc=yi.l.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.