From: Yu Zhang <zhangyu1@linux.microsoft.com>
To: linux-kernel@vger.kernel.org, linux-hyperv@vger.kernel.org,
iommu@lists.linux.dev, linux-pci@vger.kernel.org,
linux-arch@vger.kernel.org, x86@kernel.org
Cc: wei.liu@kernel.org, kys@microsoft.com, haiyangz@microsoft.com,
decui@microsoft.com, longli@microsoft.com, joro@8bytes.org,
will@kernel.org, robin.murphy@arm.com, bhelgaas@google.com,
kwilczynski@kernel.org, lpieralisi@kernel.org, mani@kernel.org,
robh@kernel.org, arnd@arndb.de, jgg@ziepe.ca,
mhklinux@outlook.com, jacob.pan@linux.microsoft.com,
tgopinath@linux.microsoft.com,
easwar.hariharan@linux.microsoft.com,
mrathor@linux.microsoft.com, baolu.lu@linux.intel.com,
suravee.suthikulpanit@amd.com, vasant.hegde@amd.com
Subject: [PATCH v3 0/5] Hyper-V: Add para-virtualized IOMMU support for Linux guests
Date: Tue, 11 Aug 2026 23:50:16 +0800 [thread overview]
Message-ID: <20260811155022.108148-1-zhangyu1@linux.microsoft.com> (raw)
This patch series introduces a para-virtualized IOMMU driver for
Linux guests running on Microsoft Hyper-V. The driver enables two
primary use cases:
1) In-kernel DMA protection for devices assigned to the guest.
2) Device assignment to guest user space (e.g., via VFIO).
The driver implements the following core functionality:
* Hypercall-based Enumeration
Unlike traditional ACPI-based discovery (e.g., DMAR/IVRS),
this driver enumerates the Hyper-V IOMMU capabilities directly
via hypercalls. This approach allows the guest to discover
IOMMU presence and features without requiring specific virtual
firmware extensions or modifications.
* Domain Management
The driver manages IOMMU domains through a new set of Hyper-V
hypercall interfaces, handling domain allocation and attachment
for endpoint devices.
* Nested Translation Support
This implementation leverages guest-managed stage-1 I/O page
tables nested with host stage-2 translations. It is built
upon the consolidated IOMMU page table framework (IOMMU_PT).
This design eliminates the need for emulating map operations.
Both Intel VT-d and AMD IOMMU platforms are supported.
* IOTLB Invalidation
IOTLB invalidation requests are marshaled and issued to the
hypervisor through the same hypercall mechanism. Both domain-
selective and page-selective flushes are supported.
Implementation Notes:
* Platform Support
The current implementation targets x86 platforms with Intel
VT-d and AMD IOMMU hardware.
* MSI Region Handling
The standard x86 MSI interrupt range
(0xfee00000 - 0xfeefffff) is reserved from normal IOVA mappings.
Future updates may allow this configuration to be queried via
hypercalls if new hardware platforms are to be supported.
* Reserved Regions (RMRR)
There is currently no requirement to support assigned devices with
ACPI RMRR limitations. Consequently, this patch series does not
specify or query reserved memory regions.
* Guest Hibernation
Guest hibernation and resume are not supported by this initial
implementation. The current pvIOMMU interface does not define how
Hyper-V device-domain objects and device attachments are restored.
Testing:
Validated with the following configurations:
- NVMe devices assigned to the guest on AMD platforms, tested
with fio.
- Intel DSA devices assigned to the guest, tested with dmatest.
- dma_map_benchmark for DMA mapping performance evaluation.
Changelog:
v2[1] -> v3:
- Added a separate patch defining the common x86 architectural MSI
reserved range and converted the Intel, AMD, and Hyper-V IOMMU
drivers to use it.
- hyperv: hypercall interfaces:
- Used BIT_ULL() for 64-bit capability flags.
- Matched the create-device-domain input layout to the 32-byte
Hyper-V ABI.
- Corrected the page-selective flush range layout to 6/6/52 bits.
- hv: logical device ID registry:
- Replaced the linear list with an rhashtable for the sparse PCI
domain number mapping.
- Used RCU-protected lookup and deferred freeing on removal.
- Simplified the registration and cleanup paths.
- iommu/hyperv: para-virtualized IOMMU:
- Renamed the guest driver source to hv-iommu-guest.c.
- Enabled ATS only after a device-domain attachment succeeds, and
disabled ATS before attaching the blocking domain.
- Removed the obsolete deferred-flush capability, unused geometry,
and redundant device-private-data clearing.
- Made the Hyper-V domain settings explicit at each caller instead
of deriving them from the Linux domain type.
- Added transactional create/configure domain handling with rollback.
- Required only the base page size and masked the domain page-size
bitmap with the Hyper-V-supported bitmap.
- Silenced detection for unsupported hosts while retaining errors
for actual hypercall and capability failures.
- Clarified Kconfig support for assigned PCI devices and documented
the lack of guest hibernation/resume support.
- iommu/hyperv: page-selective IOTLB flush:
- Removed the inclusive-end overflow and kept the range calculation
in byte addresses until the final page conversion.
- Cleared both the fixed hypercall header and the range entry.
- Warned on selective-flush failure before falling back to a
full-domain flush.
v1[2] -> v2:
- Dropped the "move to subdirectory" patch; the directory now exists
upstream.
- hv: logical device ID registry:
- Moved the registry to hv_common.c so it can be shared, and derived
the prefix via a shared helper instead of caching it in pci-hyperv's
private struct.
- Moved the lookup out of the irq-disabled region (PREEMPT_RT).
- iommu/hyperv: para-virtualized IOMMU:
- Removed the unused detach_dev op.
- Rejected a hypervisor not advertising x86 page sizes instead of
masking and warning.
- Statically initialized the identity and blocking domains.
- Gave the blocking domain its own attach op, which returns the hypercall
status and WARNs on failure.
- iommu/hyperv: page-selective IOTLB flush:
- Used a single descriptor covering a slightly larger power-of-two
range, instead of splitting the range into multiple descriptors.
- Fixed the inclusive-end corner case in the flush range calculation.
RFC v1[3] -> v1[2]:
- Scoped platform support to x86 only (Intel VT-d and AMD IOMMU);
initialization now uses x86_init.iommu.iommu_init
- Added page-selective IOTLB flush support
- Disable device ATS in hv_iommu_release_device()
- Addressed review comments from Michael Kelley:
- Reversed dependency: pvIOMMU exports registration API for
pci-hyperv to call, instead of pci-hyperv exporting
hv_build_logical_dev_id()
- Dropped separate output page allocation patch; hypercall input
and output now share the same per-CPU page
- Cleaned up Kconfig (removed PCI_HYPERV dependency, unnecessary
selects)
- Removed dev_list, per-domain spinlock, and syscore_ops
- Removed forward declarations by reordering functions
- Fixed typos, cleaned up Kconfig selects, improved pr_info
messages, etc.
[1] v2:
https://lore.kernel.org/linux-hyperv/20260702160518.311234-1-zhangyu1@linux.microsoft.com/
[2] v1:
https://lore.kernel.org/linux-hyperv/20260511162408.1180069-1-zhangyu1@linux.microsoft.com/
[3] RFC v1:
https://lore.kernel.org/linux-hyperv/20251209051128.76913-1-zhangyu1@linux.microsoft.com/
Wei Liu (1):
hyperv: Introduce new hypercall interfaces used by Hyper-V guest IOMMU
Yu Zhang (4):
Drivers: hv: Add logical device ID registry for vPCI devices
iommu/x86: Share the architectural MSI reserved range
iommu/hyperv: Add para-virtualized IOMMU support for Hyper-V guest
iommu/hyperv: Add page-selective IOTLB flush support
arch/x86/hyperv/hv_init.c | 4 +
arch/x86/include/asm/iommu.h | 3 +
arch/x86/include/asm/mshyperv.h | 4 +
drivers/hv/hv_common.c | 123 +++++
drivers/iommu/Kconfig | 1 +
drivers/iommu/amd/iommu.c | 7 +-
drivers/iommu/hyperv/Kconfig | 16 +
drivers/iommu/hyperv/Makefile | 1 +
drivers/iommu/hyperv/hv-iommu-guest.c | 703 ++++++++++++++++++++++++++
drivers/iommu/hyperv/iommu.h | 50 ++
drivers/iommu/intel/iommu.c | 7 +-
drivers/pci/controller/pci-hyperv.c | 21 +-
include/asm-generic/mshyperv.h | 14 +
include/hyperv/hvgdk_mini.h | 9 +
include/hyperv/hvhdk_mini.h | 143 ++++++
include/linux/hyperv.h | 8 +
16 files changed, 1101 insertions(+), 13 deletions(-)
create mode 100644 drivers/iommu/hyperv/Kconfig
create mode 100644 drivers/iommu/hyperv/hv-iommu-guest.c
create mode 100644 drivers/iommu/hyperv/iommu.h
--
2.52.0
next reply other threads:[~2026-08-11 15:50 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-11 15:50 Yu Zhang [this message]
2026-08-11 15:50 ` [PATCH v3 1/5] hyperv: Introduce new hypercall interfaces used by Hyper-V guest IOMMU Yu Zhang
2026-08-11 15:50 ` [PATCH v3 2/5] Drivers: hv: Add logical device ID registry for vPCI devices Yu Zhang
2026-08-11 15:50 ` [PATCH v3 3/5] iommu/x86: Share the architectural MSI reserved range Yu Zhang
2026-08-11 16:21 ` Jason Gunthorpe
2026-08-11 15:50 ` [PATCH v3 4/5] iommu/hyperv: Add para-virtualized IOMMU support for Hyper-V guest Yu Zhang
2026-08-11 15:50 ` [PATCH v3 5/5] iommu/hyperv: Add page-selective IOTLB flush support Yu Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260811155022.108148-1-zhangyu1@linux.microsoft.com \
--to=zhangyu1@linux.microsoft.com \
--cc=arnd@arndb.de \
--cc=baolu.lu@linux.intel.com \
--cc=bhelgaas@google.com \
--cc=decui@microsoft.com \
--cc=easwar.hariharan@linux.microsoft.com \
--cc=haiyangz@microsoft.com \
--cc=iommu@lists.linux.dev \
--cc=jacob.pan@linux.microsoft.com \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=kwilczynski@kernel.org \
--cc=kys@microsoft.com \
--cc=linux-arch@vger.kernel.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=longli@microsoft.com \
--cc=lpieralisi@kernel.org \
--cc=mani@kernel.org \
--cc=mhklinux@outlook.com \
--cc=mrathor@linux.microsoft.com \
--cc=robh@kernel.org \
--cc=robin.murphy@arm.com \
--cc=suravee.suthikulpanit@amd.com \
--cc=tgopinath@linux.microsoft.com \
--cc=vasant.hegde@amd.com \
--cc=wei.liu@kernel.org \
--cc=will@kernel.org \
--cc=x86@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.