All of lore.kernel.org
 help / color / mirror / Atom feed
From: Jason Gunthorpe <jgg@nvidia.com>
To: "Aneesh Kumar K.V" <aneesh.kumar@kernel.org>
Cc: linux-coco@lists.linux.dev, iommu@lists.linux.dev,
	linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
	Alexey Kardashevskiy <aik@amd.com>,
	Bjorn Helgaas <helgaas@kernel.org>,
	Joerg Roedel <joro@8bytes.org>,
	Jonathan Cameron <jic23@kernel.org>,
	Kevin Tian <kevin.tian@intel.com>,
	Nicolin Chen <nicolinc@nvidia.com>,
	Samuel Ortiz <sameo@rivosinc.com>,
	Steven Price <steven.price@arm.com>,
	Suzuki K Poulose <Suzuki.Poulose@arm.com>,
	Will Deacon <will@kernel.org>,
	Xu Yilun <yilun.xu@linux.intel.com>,
	Shameer Kolothum <shameerali.kolothum.thodi@huawei.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [RFC PATCH v6 09/11] iommufd: Add the vdevice TSM request ioctl
Date: Wed, 30 Sep 2026 11:08:37 -0300	[thread overview]
Message-ID: <20260930140837.GT1616761@nvidia.com> (raw)
In-Reply-To: <yq5a7bk3upx6.fsf@kernel.org>

On Wed, Sep 30, 2026 at 01:33:17PM +0530, Aneesh Kumar K.V wrote:
> > Why would it ever not be tied to userspace pointers? I don't want
> > an in kernel user ever using this kind of struct?
> 
> The previous discussion suggested that another kernel subsystem might
> need to use this low-level TSM interface, although no concrete example
> was identified. In other words, an opaque guest request could be issued
> from either userspace or kernel space. 

Don't do it without a user then.

Directly coupling KVM to iommufd is some other future topic. I don't
think KVM should be coupled to TSM.

> > That seems wrong.. The hypervisor should not have control over T=1
> > DMA.
>
> This was added specifically for AMD SEV, which requires an IOMMU-side
> update to enable DMA.

See my remarks to Vasant. I want to take a very careful look at this
list eventually, but for now lets focus on the other parts and keep
this seperate.

> We have gone through several iterations to identify the guest
> passthrough request facility we need. IIUC, both TDX and CCA give the
> hypervisor some control over the request type, while SEV-TIO is more
> opaque.

Is there a record? I would be interested to read a summary

Maybe you can summarize the details in the comments. Eg define exactly
what spec operation each arch will implement under every proposed
call?

> >> +/**
> >> + * struct iommu_vdevice_tsm_req - ioctl(IOMMU_VDEVICE_TSM_REQ)
> >> + * @size: sizeof(struct iommu_vdevice_tsm_req)
> >> + * @vdevice_id: vDevice ID the guest request is for
> >> + * @op: One of enum iommu_vdevice_tsm_guest_req_op
> >> + * @tvm_arch: One of enum iommu_vdevice_tsm_guest_tvm_arch
> >> + * @req_len: Size in bytes of the input payload at @req_uptr
> >> + * @resp_len: Size in bytes of the output buffer at @resp_uptr
> >> + * @req_uptr: Userspace pointer to the guest-provided request payload
> >> + * @resp_uptr: Userspace pointer to the guest response buffer
> >> + * @tsm_code: TSM-specific result code returned by the TSM implementation
> >> + *
> >> + * Forward a TSM request to the TSM bound vDevice. This is intended for
> >> + * guest TSM/TDISP message transport where the host kernel only marshals
> >> + * bytes between userspace and the TSM implementation.
> >> + *
> >> + * The request operation is guest initiated. The TSM backend validates
> >> + * @tvm_arch against its bound TVM architecture assumptions.
> >> + *
> >> + * The request payload is read from @req_uptr/@req_len. If a response is
> >> + * expected, userspace provides @resp_uptr/@resp_len as writable storage for
> >> + * response bytes returned by the TSM path.
> >> + *
> >> + * The ioctl is only suitable for commands and results that the host kernel
> >> + * has no use, the host is only facilitating guest to TSM communication.
> >> + */
> >> +struct iommu_vdevice_tsm_req {
> >> +	__u32 size;
> >> +	__u32 vdevice_id;
> >> +	__u32 op;
> >> +	__u32 tvm_arch;
> >> +	__u32 req_len;
> >> +	__u32 resp_len;
> >> +	__aligned_u64 req_uptr;
> >> +	__aligned_u64 resp_uptr;
> >> +	__aligned_u64 tsm_code;
> >
> > out_tsm_code
> >
> 
> That is required for SEV-TIO.

I mean spell it 'out_tsm_code' since it is written as an output, that
is the convention in iommufd structs

Separately I also don't know why we'd need it since we have an entire
resp_uptr. If the arch specific action needs an arch specific code, it
can go in the arch specific resp struct.

Jason

  parent reply	other threads:[~2026-09-30 14:08 UTC|newest]

Thread overview: 72+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 14:01 [RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 01/11] vfio: cache KVM VM file references instead of raw struct kvm pointers Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-30  7:19     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 02/11] vfio: cdev: Reject duplicate bind before updating KVM file Aneesh Kumar K.V (Arm)
2026-09-24  7:53   ` Tian, Kevin
2026-09-25  5:49     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 03/11] iommufd/device: Associate KVM file pointer with iommufd_device Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 04/11] iommufd/viommu: Keep a reference to the KVM file Aneesh Kumar K.V (Arm)
2026-09-30 13:28   ` Vasant Hegde
2026-10-02  5:26     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 05/11] iommu: Add a helper to validate a vIOMMU parent Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  5:48     ` Aneesh Kumar K.V
2026-09-25 12:23       ` Jason Gunthorpe
2026-09-28 10:36         ` Aneesh Kumar K.V
2026-09-28 12:11           ` Jason Gunthorpe
2026-09-28 15:39             ` Aneesh Kumar K.V
2026-09-28 16:17               ` Jason Gunthorpe
2026-09-28 18:08                 ` Jacob Pan
2026-09-28 18:20                   ` Jason Gunthorpe
2026-09-28 22:24                     ` Jacob Pan
2026-09-28 23:03                       ` Jason Gunthorpe
2026-09-29  5:55                         ` Jacob Pan
2026-09-29 12:30                           ` Jason Gunthorpe
2026-09-29 23:15                             ` Jacob Pan
2026-09-29 23:30                               ` Jason Gunthorpe
2026-09-17 14:01 ` [RFC PATCH v6 06/11] iommu: Add a helper to query vIOMMU hardware parameters Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  5:59     ` Aneesh Kumar K.V
2026-09-25 12:29       ` Jason Gunthorpe
2026-09-17 14:01 ` [RFC PATCH v6 07/11] coco: tsm: Expose active-user lifetime references Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 08/11] iommufd: Add vIOMMU provider support Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  6:08     ` Aneesh Kumar K.V
2026-09-25 12:39       ` Jason Gunthorpe
2026-09-28  3:41         ` Tian, Kevin
2026-09-29  6:14           ` Aneesh Kumar K.V
2026-09-29 12:17             ` Jason Gunthorpe
2026-09-29 12:45               ` Aneesh Kumar K.V
2026-09-29 13:06                 ` Jason Gunthorpe
2026-09-29 15:58                   ` Aneesh Kumar K.V
2026-09-29 19:10                     ` Jason Gunthorpe
2026-09-28 10:51         ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 09/11] iommufd: Add the vdevice TSM request ioctl Aneesh Kumar K.V (Arm)
2026-09-18 13:09   ` Alexey Kardashevskiy
2026-09-18 13:13     ` Jason Gunthorpe
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-30  8:03     ` Aneesh Kumar K.V
2026-09-30 13:26       ` Vasant Hegde
2026-09-30 14:03         ` Jason Gunthorpe
2026-09-30 14:08       ` Jason Gunthorpe [this message]
2026-09-17 14:01 ` [RFC PATCH v6 10/11] PCI/TSM: Remove the legacy guest request interface Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 11/11] PCI/TSM: Add reference-counted contexts for vdevice providers Aneesh Kumar K.V (Arm)
2026-09-24  8:17   ` Tian, Kevin
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  8:15     ` Aneesh Kumar K.V
2026-09-28 18:47   ` Sonang Patel
2026-09-28 23:08     ` Jason Gunthorpe
2026-10-02  6:14       ` Aneesh Kumar K.V
2026-10-02 13:06         ` Jason Gunthorpe
2026-09-17 14:17 ` [RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests Aneesh Kumar K.V
2026-09-24  7:48 ` Tian, Kevin
2026-09-24 19:20   ` Jason Gunthorpe
2026-09-28  3:35     ` Tian, Kevin
2026-09-28 13:08       ` Jason Gunthorpe
2026-09-25  8:29   ` Aneesh Kumar K.V
2026-09-28  3:41     ` Tian, Kevin
2026-09-28  3:55       ` Tian, Kevin
2026-09-24 19:09 ` Jason Gunthorpe
2026-09-25  6:46   ` Aneesh Kumar K.V
2026-09-25 12:45     ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930140837.GT1616761@nvidia.com \
    --to=jgg@nvidia.com \
    --cc=Suzuki.Poulose@arm.com \
    --cc=aik@amd.com \
    --cc=aneesh.kumar@kernel.org \
    --cc=helgaas@kernel.org \
    --cc=iommu@lists.linux.dev \
    --cc=jic23@kernel.org \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nicolinc@nvidia.com \
    --cc=pbonzini@redhat.com \
    --cc=sameo@rivosinc.com \
    --cc=shameerali.kolothum.thodi@huawei.com \
    --cc=steven.price@arm.com \
    --cc=will@kernel.org \
    --cc=yilun.xu@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.