From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E4FD82931F5 for ; Mon, 21 Sep 2026 00:48:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951731; cv=none; b=G9QBhEE1N40T8NG77eCBQocgBL74skpqrFP0Sed7MoNvApW1EXfem7tyFCXB+ZNjXvKGSnuD2x9F93S3Ud6/2tN2AJIIQqdNFNw+DvHUL1khnzlQjp8I0ZirQL62XFQYw2EIbNB4iNF0w5O0FehGMtxgNjkVxEIxwaD/vheZZSA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951731; c=relaxed/simple; bh=nPezMDYp5xpL65qddw2WVC7a5eW4PH+MLRIAj/7Q7y8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=SLZ7xU74g0Zm1OSipTzaVWKz10q0Bj+T4kOcTQUPhV4/uodqtjwxIfSMFY3sjatOunVA2FfXvJkpjzlbNx1ptBommZ9tjETMSct7tDsHLmJ7C5qBkSo6C2RV09Cc7g1sBZ/XFHtLLj0y2C0s73gnXUyZwudd2qwIwM6bUJmXa+U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=uh8Huy7z; arc=none smtp.client-ip=209.85.214.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="uh8Huy7z" Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2dd667770efso35434895ad.0 for ; Sun, 20 Sep 2026 17:48:47 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789951725; x=1790556525; darn=lists.linux.dev; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UKH4Gc6Z+bMWga98+CS78z+EWlxfzC75QI3yKAEUybQ=; b=uh8Huy7zpPJPKZPINxChiuOQnLKWel5ceMxN7fGsFKL5R1epwJYBYbfqG0eC0z8UUd K+GqLxlpImuF9xInLkRxtMlJP2yJXs6XlV/qV83xLtsctcJXExlBvkMlkEGdPISTE8WB uZatEYhnFIBpwBHtm/WC7bCYhkGg0M+a4i7cN/w+xrBJ3I9rFYUGFtQPjsPdYuWA8Fi3 L88pgD9hhoPHGiWbfNxOhBkJ0/iDPD/wqKtBY6cmwGxNfeFGHL5Al8zfTM4UqRL8o9Uk c+pHgVmQ0X+3bNIr7itbchsfWfxzz0s2m9MoALRpA6y9HQeVfTWmyrrwkoK8ofB6Hlzp 2w6g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789951725; x=1790556525; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UKH4Gc6Z+bMWga98+CS78z+EWlxfzC75QI3yKAEUybQ=; b=lt3OPupvKbU9wR6NXcjmwOPrhjm/5B610w++3DVsn3bwd+asMA+uIez1/2VACAl2BA dNSmwvGw4NMhX6q753G/2G5JbEFbDZgGJZq2+eBiaYtlxrn1r8PK9voauzUDlKG0zTae F3r4zAby6X/f8ygXGPQm08k3CVgmL+sYUxSWo0kMNKLWA0iDpz5/GTF4/PdoPcbJQrzf 7y2LIznUHebLLXrd/MbVgy+f424N3SC8oEXQbSVYqDG0/NAaHfTVMieusX1zM/9R8hIl NbryZ+Kq0VF9pUFspmlMViKF33a16Qyj6iqd7oPxJbh7qlXC8p60YiUV2liJjiLwuzuk Pqkw== X-Forwarded-Encrypted: i=1; AKwUvBwESup4qoUa/mNG5opB1Orx7JBeH/QxyWDCOciF2m6GST/ZIZma5Y7hDD1CNXs96krpXVa2kQ==@lists.linux.dev X-Gm-Message-State: AFuF++n2JTXlwatijIwSy053VzU3OMQt5d9UtEN1A2vSyzaVaQtn8i+X Ab+oU8vfJaCqcPGYzXoV2TO+GWuZPQypQh9r/nNmr+Gli9vhuY4QhZmH3RorZfkLtheDbItswpb Fd4cGclurK7qcVA== X-Received: from plao7.prod.google.com ([2002:a17:903:3007:b0:2df:4e63:c417]) (user=skhawaja job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:3b86:b0:2dd:c100:251d with SMTP id d9443c01a7336-2ddc10025a3mr60411435ad.38.1789951725377; Sun, 20 Sep 2026 17:48:45 -0700 (PDT) Date: Mon, 21 Sep 2026 00:48:21 +0000 In-Reply-To: <20260921004834.2601285-1-skhawaja@google.com> Precedence: bulk X-Mailing-List: iommu@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921004834.2601285-1-skhawaja@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921004834.2601285-6-skhawaja@google.com> Subject: [PATCH v5 05/18] iommu: Implement IOMMU domain preservation From: Samiullah Khawaja To: David Woodhouse , Lu Baolu , Joerg Roedel , Will Deacon , Jason Gunthorpe Cc: Samiullah Khawaja , Pranjal Shrivastava , Robin Murphy , Kevin Tian , Alex Williamson , Shuah Khan , iommu@lists.linux.dev, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Pratyush Yadav , Pasha Tatashin , David Matlack , Andrew Morton , Vipin Sharma Content-Type: text/plain; charset="UTF-8" Add IOMMU domain ops that can be implemented by the IOMMU drivers if they support IOMMU domain preservation across liveupdate. The new IOMMU domain preserve, unpreserve and restore APIs call these ops to perform respective live update operations. Reviewed-by: Pranjal Shrivastava Signed-off-by: Samiullah Khawaja --- drivers/iommu/liveupdate.c | 128 +++++++++++++++++++++++++++++++ include/linux/iommu-liveupdate.h | 11 +++ include/linux/iommu.h | 5 ++ 3 files changed, 144 insertions(+) diff --git a/drivers/iommu/liveupdate.c b/drivers/iommu/liveupdate.c index b644f4792532..be542efbb023 100644 --- a/drivers/iommu/liveupdate.c +++ b/drivers/iommu/liveupdate.c @@ -37,11 +37,15 @@ #define pr_fmt(fmt) "iommu: liveupdate: " fmt #include +#include #include #include #include #include +#define iommu_max_objs_per_page(_array) \ + ((PAGE_SIZE - sizeof(struct iommu_array_hdr_ser)) / sizeof((_array)->objects[0])) + struct iommu_flb_obj { struct mutex lock; struct iommu_flb_ser *ser; @@ -251,3 +255,127 @@ void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler) liveupdate_unregister_flb(handler, &iommu_flb); } EXPORT_SYMBOL(iommu_liveupdate_unregister_flb); + +static int alloc_object_ser(void **curr_array_ptr, u64 max_objs) +{ + struct iommu_array_hdr_ser *curr_array = *curr_array_ptr; + struct iommu_array_hdr_ser *next_array; + + /* + * The objects marked as deleted are not reused to avoid traversal of + * linked-list and arrays. + */ + if (curr_array->nr_objects >= max_objs) { + next_array = kho_alloc_preserve(PAGE_SIZE); + if (IS_ERR(next_array)) + return PTR_ERR(next_array); + + curr_array->next_array_phys = virt_to_phys(next_array); + *curr_array_ptr = next_array; + curr_array = next_array; + } + + return curr_array->nr_objects++; +} + +static struct iommu_domain_ser *alloc_iommu_domain_ser(struct iommu_flb_obj *flb) +{ + int idx; + + idx = alloc_object_ser((void **) &flb->curr_domain_array, + iommu_max_objs_per_page(flb->curr_domain_array)); + if (idx < 0) + return ERR_PTR(idx); + + flb->curr_domain_array->objects[idx].hdr.ref_count = 1; + return &flb->curr_domain_array->objects[idx]; +} + +/** + * iommu_preserve_domain() - Preserve an IOMMU domain across live update + * @domain: Domain to preserve + * @ser: Pointer to receive the virtual serialized domain state handle + * + * Return: 0 on success, or negative error code. + */ +int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser) +{ + struct pt_iommu *pt = iommupt_from_domain(domain); + struct iommu_domain_ser *domain_ser; + struct iommu_flb_obj *flb_obj; + int ret; + + if (!pt || !pt->ops->preserve || !pt->ops->unpreserve) + return -EOPNOTSUPP; + + ret = liveupdate_flb_get_outgoing(&iommu_flb, (void **)&flb_obj); + if (ret) + return ret; + + mutex_lock(&flb_obj->lock); + if (domain->preserved_state) { + ret = -EBUSY; + goto out_unlock; + } + + domain_ser = alloc_iommu_domain_ser(flb_obj); + if (IS_ERR(domain_ser)) { + ret = PTR_ERR(domain_ser); + goto out_unlock; + } + + ret = pt->ops->preserve(pt, domain_ser); + if (ret) { + domain_ser->hdr.flags |= IOMMU_SER_FLAG_DELETED; + goto out_unlock; + } + + domain->preserved_state = domain_ser; + *ser = domain_ser; + ret = 0; +out_unlock: + mutex_unlock(&flb_obj->lock); + liveupdate_flb_put_outgoing(&iommu_flb); + return ret; +} +EXPORT_SYMBOL_GPL(iommu_preserve_domain); + +/** + * iommu_unpreserve_domain() - Unpreserve a preserved IOMMU domain + * @domain: Domain to unpreserve + */ +void iommu_unpreserve_domain(struct iommu_domain *domain) +{ + struct pt_iommu *pt = iommupt_from_domain(domain); + struct iommu_domain_ser *domain_ser; + struct iommu_flb_obj *flb_obj; + int ret; + + if (WARN_ON(!pt || !pt->ops->unpreserve)) + return; + + ret = liveupdate_flb_get_outgoing(&iommu_flb, (void **)&flb_obj); + if (WARN_ON(ret)) + return; + + mutex_lock(&flb_obj->lock); + if (!domain->preserved_state) + goto out_unlock; + + /* + * There is no check for attached devices here. The correctness relies + * on the Live Update Orchestrator's session lifecycle. All resources + * (iommufd, vfio devices) are preserved within a single session. If the + * session is torn down, the .unpreserve callbacks for all files will be + * invoked, ensuring a consistent cleanup without needing explicit + * refcounting for the serialized objects here. + */ + domain_ser = domain->preserved_state; + pt->ops->unpreserve(pt, domain_ser); + domain_ser->hdr.flags |= IOMMU_SER_FLAG_DELETED; + domain->preserved_state = NULL; +out_unlock: + mutex_unlock(&flb_obj->lock); + liveupdate_flb_put_outgoing(&iommu_flb); +} +EXPORT_SYMBOL_GPL(iommu_unpreserve_domain); diff --git a/include/linux/iommu-liveupdate.h b/include/linux/iommu-liveupdate.h index 4755ab3cd67a..caa9778eee2d 100644 --- a/include/linux/iommu-liveupdate.h +++ b/include/linux/iommu-liveupdate.h @@ -15,6 +15,8 @@ #ifdef CONFIG_IOMMU_LIVEUPDATE int iommu_liveupdate_register_flb(struct liveupdate_file_handler *handler); void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler); +int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser); +void iommu_unpreserve_domain(struct iommu_domain *domain); #else static inline int iommu_liveupdate_register_flb(struct liveupdate_file_handler *handler) { @@ -24,5 +26,14 @@ static inline int iommu_liveupdate_register_flb(struct liveupdate_file_handler * static inline void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler) { } + +static inline int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser) +{ + return -EOPNOTSUPP; +} + +static inline void iommu_unpreserve_domain(struct iommu_domain *domain) +{ +} #endif #endif /* _LINUX_IOMMU_LIVEUPDATE_H */ diff --git a/include/linux/iommu.h b/include/linux/iommu.h index ac43b8b93f14..26de40d5a98e 100644 --- a/include/linux/iommu.h +++ b/include/linux/iommu.h @@ -14,6 +14,7 @@ #include #include #include +#include #include #define IOMMU_READ (1 << 0) @@ -249,6 +250,10 @@ struct iommu_domain { struct list_head next; }; }; + +#ifdef CONFIG_IOMMU_LIVEUPDATE + struct iommu_domain_ser *preserved_state; +#endif }; static inline bool iommu_is_dma_domain(struct iommu_domain *domain) -- 2.55.0.1082.g2b9226bbc0-goog