From: Robin Murphy <robin.murphy@arm.com>
To: Jason Gunthorpe <jgg@nvidia.com>
Cc: Mostafa Saleh <smostafa@google.com>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
Marek Szyprowski <m.szyprowski@samsung.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Steven Price <steven.price@arm.com>,
Suzuki K Poulose <Suzuki.Poulose@arm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Jiri Pirko <jiri@resnulli.us>, Petr Tesarik <ptesarik@suse.com>,
Alexey Kardashevskiy <aik@amd.com>,
Dan Williams <dan.j.williams@intel.com>,
Xu Yilun <yilun.xu@linux.intel.com>,
linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>,
Nicholas Piggin <npiggin@gmail.com>,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Sven Schnelle <svens@linux.ibm.com>,
x86@kernel.org, Michael Kelley <mhklinux@outlook.com>
Subject: Re: [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference
Date: Mon, 10 Aug 2026 15:18:03 +0100 [thread overview]
Message-ID: <21813ccf-96e5-4a7e-a3b3-aaaec7e0d23c@arm.com> (raw)
In-Reply-To: <20260807170104.GB158689@nvidia.com>
On 07/08/2026 6:01 pm, Jason Gunthorpe wrote:
> On Fri, Aug 07, 2026 at 04:54:35PM +0100, Robin Murphy wrote:
>
>>> We will need to teach GIC to understand if/when the device uses a T=0
>>> translation for MSI and then use a shared physical address for the ITS
>>> IOVA instead of getting an IOVA translation from the iommu. The
>>> hypervisor will setup the S2 for the T=0 SMMU translation to be
>>> identity with all shared memory and the ITS page will be shared
>>> memory.
>>
>> IIRC, for MSI or unlocked MSI-X it should look and work pretty much exactly
>> like regular VFIO, as everything can be mediated by the VMM and host kernel.
>
> Right
>
>>> Presumably in future we will have HW to handle a T=1 ITS page access
>>> and some way to negotiate with devices if they should use a T=1 path
>>> for MSI or not.
>>
>> Locked MSI-X would be a pain right now as we cannot intercept the Realm
>> programming the MSI-X cap with a doorbell address and EventID value decided
>> by the ITS driver in the Realm guest, so we'd somehow have to sniff those
>> values out of the VMM's vITS emulation then try to configure an equivalent
>> NS LPI to match, or have a hook in the ITS driver that knows when it's in a
>> Realm and do some RSI handshake to proxy-allocate NS MSI vectors on the host
>> and pass the real values back into the Realm.
>
> Yes, we'd need to move to a model where the guest programs MSI
> directly and we learn the configuration required to emulate through
> the vGIC, not through MSI trapping. This broadly is the "righter" way
> to do interrupt routing but it will be hard to get there, if ever.
>
>> I'm still hoping we (both CCA and possibly Linux in general) can get away
>> with just refusing to support Locked MSI-X without GICv5, as once we have
>> proper Realm MSIs with direct injection then all the problems go away (or at
>> least become much smaller RMM problems that remain invisible to the host -
>> the one "big" problem being that the RMM has to begrudgingly implement an
>> entire GIC driver since it now has its own whole GIC to look after).
>
> Yeah, I'm fine with this, if GICv5 can allow direct MSI-X programming
> then great.
>
> Devices are going to need some way to negotiate if MSI-X is locked, and
> if MSI is T=1 or not, I don't know if PCI has something for that
> already..
>
>>> There won't be a vSMMU attached to the T=0 instance at all, it is just
>>> wired to be bypass.
>>
>> If that's all anyone will ever want then it does allow some degree of
>> hackery like mirroring the whole of Realm S2 in an equivalent NS IOMMUFD
>> domain, then forcing IOMMU_DOMAIN_IDENTITY for unaccepted devices within the
>> guest. However I was under the impression that folks want to make meaningful
>> use of devices while still in their untrusted pre-acceptance state (but
>> maybe still switch them later), so it seems almost inevitable that
>> eventually someone says "actually, we would like S1 vSMMU for untrusted
>> scatter-gather as well..."
>
> So far almost all VMs today don't use vIOMMU at all, the ones that do
> are using it for things like PASID (or interrupt remapping on x86),
> not for translation. The cases where a vIOMMU is deliberately needed
> for translation seem to be mostly around SVA and PASID which isn't
> going to meaningfully work out of the box on a T=0 device.
>
> My prediction is this is fine.
>
> At least it is sufficiently hard to make two parallel vSMMU's
> controlling the same PCI device, and to make the ITS routing also
> somehow work right, that it isn't worth doing at this point when there
> is so much other more basic stuff to get done.
Cool. So in fact that puts us in an interesting position for now where
non-CoCo "untrusted" (i.e. external) devices should have IOMMU
translation forced on by default, while CoCo "unaccepted" devices (i.e.
those which do have a mechanism to transition into a T=1 or equivalent
state) should *not* try to use an associated IOMMU, on the assumption
that it may only work for T=1 traffic. All the more reason to sort these
abstractions out so we can make the right distinctions clearly :)
(And while untrusted vIOMMUs for purely-untrusted devices in CoCo
environments would be pretty straightforward as well, I guess we might
need some sort of acceptance status for trusted vIOMMU devices
themselves? Hmm...)
Cheers,
Robin.
> I imagine the ACPI might someday gain a description of the T=0 vSMMU
> in a way that is invisible to todays Linux and a future Linux could
> understand how to juggle the two iommu drivers for the same struct
> device, somehow.
>
> Regards,
> Jason
next prev parent reply other threads:[~2026-08-10 14:18 UTC|newest]
Thread overview: 97+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-17 18:04 [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 01/23] dma-direct: return struct page from dma_direct_alloc_from_pool() Aneesh Kumar K.V (Arm)
2026-07-21 11:54 ` Leon Romanovsky
2026-07-21 14:20 ` Aneesh Kumar K.V
2026-07-21 14:29 ` Leon Romanovsky
2026-07-21 15:10 ` Aneesh Kumar K.V
2026-07-21 15:33 ` Leon Romanovsky
2026-07-22 19:59 ` Jason Gunthorpe
2026-07-23 7:57 ` Leon Romanovsky
2026-07-25 14:34 ` Jason Gunthorpe
2026-07-26 8:17 ` Leon Romanovsky
2026-07-27 4:23 ` Jason Gunthorpe
2026-07-27 11:40 ` Leon Romanovsky
2026-07-28 12:31 ` Aneesh Kumar K.V
2026-07-28 14:24 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 02/23] dma-pool: fix page leak in atomic_pool_expand() cleanup Aneesh Kumar K.V (Arm)
2026-07-21 12:31 ` Leon Romanovsky
2026-07-21 14:41 ` Aneesh Kumar K.V
2026-07-21 15:34 ` Leon Romanovsky
2026-07-17 18:04 ` [PATCH v8 03/23] iommu/dma: Check atomic pool allocation result directly Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 04/23] dma: free atomic pool pages by physical address Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 05/23] swiotlb: Preserve allocation virtual address for dynamic pools Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 06/23] s390: Expose protected virtualization through cc_platform_has() Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 07/23] dma-direct: swiotlb: handle swiotlb alloc/free outside __dma_direct_alloc_pages Aneesh Kumar K.V (Arm)
2026-07-28 14:26 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 08/23] coco: arm64: s390: powerpc: Mark secure guests with CC_ATTR_GUEST_MEM_ENCRYPT Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 09/23] dma-mapping: Add internal shared allocation attribute Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 10/23] dma-direct: use __DMA_ATTR_ALLOC_CC_SHARED in alloc/free paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 11/23] dma-pool: track decrypted atomic pools and select them via attrs Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference Aneesh Kumar K.V (Arm)
2026-07-28 14:41 ` Mostafa Saleh
2026-07-29 9:05 ` Aneesh Kumar K.V
2026-07-29 10:08 ` Mostafa Saleh
2026-07-29 12:42 ` Aneesh Kumar K.V
2026-08-04 14:20 ` Jason Gunthorpe
2026-08-05 9:10 ` Mostafa Saleh
2026-08-05 12:30 ` Jason Gunthorpe
2026-08-07 11:03 ` Robin Murphy
2026-08-07 11:55 ` Jason Gunthorpe
2026-08-07 15:54 ` Robin Murphy
2026-08-07 17:01 ` Jason Gunthorpe
2026-08-10 14:18 ` Robin Murphy [this message]
2026-08-10 15:08 ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 13/23] dma: swiotlb: track pool encryption state and honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 14/23] dma-mapping: make dma_pgprot() honor __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 15/23] dma-direct: pass attrs to dma_capable() for DMA_ATTR_CC_SHARED checks Aneesh Kumar K.V (Arm)
2026-07-28 14:30 ` Mostafa Saleh
2026-07-29 9:09 ` Aneesh Kumar K.V
2026-07-30 21:05 ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 16/23] dma-direct: Move dma_direct_map_phys() to dma/direct.c Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 17/23] dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-08-07 9:26 ` [PATCH] arm64: swiotlb: Keep the default size for protected guests Aneesh Kumar K.V (Arm)
2026-08-07 9:35 ` sashiko-bot
2026-08-07 11:58 ` Will Deacon
2026-08-07 13:03 ` Aneesh Kumar K.V
2026-08-07 13:18 ` Will Deacon
2026-08-07 13:58 ` Jason Gunthorpe
2026-08-07 15:34 ` Mostafa Saleh
2026-08-07 16:47 ` Jason Gunthorpe
2026-08-07 18:13 ` Mostafa Saleh
2026-08-07 18:20 ` Jason Gunthorpe
2026-08-10 9:13 ` Marek Szyprowski
2026-08-10 9:29 ` Aneesh Kumar K.V
2026-08-10 10:20 ` Will Deacon
2026-08-10 11:37 ` Marek Szyprowski
2026-08-10 11:46 ` Will Deacon
2026-08-10 13:08 ` Jason Gunthorpe
2026-08-10 14:08 ` Robin Murphy
2026-08-10 14:14 ` Will Deacon
2026-08-10 15:44 ` Catalin Marinas
2026-08-10 15:58 ` Will Deacon
2026-08-10 16:21 ` Catalin Marinas
2026-08-10 14:33 ` Aneesh Kumar K.V
2026-08-07 18:00 ` Aneesh Kumar K.V
2026-08-10 5:00 ` Michael Kelley
2026-08-10 13:15 ` Robin Murphy
2026-08-07 17:59 ` Aneesh Kumar K.V
2026-07-17 18:04 ` [PATCH v8 18/23] dma-direct: set decrypted flag for remapped DMA allocations Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 19/23] dma-direct: select DMA address encoding from __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-28 14:31 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 20/23] dma-direct: rename ret to cpu_addr in alloc helpers Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 21/23] dma: swiotlb: free dynamic pools from process context Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 22/23] dma: swiotlb: handle set_memory_decrypted() failures Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 23/23] swiotlb: remove unused SWIOTLB_FORCE flag Aneesh Kumar K.V (Arm)
2026-07-21 12:40 ` [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Leon Romanovsky
2026-07-22 19:57 ` Jason Gunthorpe
2026-07-23 7:51 ` Leon Romanovsky
2026-07-25 14:32 ` Jason Gunthorpe
2026-07-25 7:09 ` Aneesh Kumar K.V
2026-07-31 7:33 ` Marek Szyprowski
2026-08-07 9:21 ` Aneesh Kumar K.V
2026-08-07 9:51 ` Mostafa Saleh
2026-08-07 10:04 ` Marek Szyprowski
2026-07-28 14:22 ` Mostafa Saleh
2026-07-29 9:12 ` Aneesh Kumar K.V
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=21813ccf-96e5-4a7e-a3b3-aaaec7e0d23c@arm.com \
--to=robin.murphy@arm.com \
--cc=Suzuki.Poulose@arm.com \
--cc=agordeev@linux.ibm.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=borntraeger@linux.ibm.com \
--cc=catalin.marinas@arm.com \
--cc=chleroy@kernel.org \
--cc=dan.j.williams@intel.com \
--cc=gerald.schaefer@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@nvidia.com \
--cc=jiri@resnulli.us \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=m.szyprowski@samsung.com \
--cc=maddy@linux.ibm.com \
--cc=maz@kernel.org \
--cc=mhklinux@outlook.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=ptesarik@suse.com \
--cc=smostafa@google.com \
--cc=steven.price@arm.com \
--cc=svens@linux.ibm.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.