From: Vasant Hegde <vasant.hegde@amd.com>
To: Yi Liu <yi.l.liu@intel.com>, iommu@lists.linux.dev, joro@8bytes.org
Cc: will@kernel.org, robin.murphy@arm.com, suravee.suthikulpanit@amd.com
Subject: Re: [PATCH] iommu/amd: Add Secure ATS support
Date: Wed, 26 Feb 2025 10:03:38 +0530 [thread overview]
Message-ID: <80875f62-b341-4d25-a83f-6713f3f69551@amd.com> (raw)
In-Reply-To: <be9d2ad2-0f9e-4d06-952b-4cfd6ae53447@intel.com>
Hi Yi,
On 2/25/2025 6:00 PM, Yi Liu wrote:
> On 2025/2/25 18:58, Vasant Hegde wrote:
>> AMD IOMMU supports processing ATS requests as Secure ATS requests when IOTLB
>> is supported and enabled (See section "2.11 Secure ATS Supports" in AMD IOMMU
>> spec [1] for more detail).
>
> glad to see it. I'm also working on Secure ATS for VT-d. Intel Secure ATS
> has an extra table named HPT (Host Permission Table) chapter 4.2.4 in
> revision 5.0 spec. IOMMU uses this table to check the address in the
> translated transactions to ensure the device has access permission.
>
> We plan to support the HPT on S2 when nested translation is configured. But
> we may let the userspace VMM to decide if it wants SATS on specific device.
> The reason is that some devices might be considered as trusted. e.g.
> integrated devices.
Yeah. That's another option (ATS for trusted SoC devices and secure ATS for
other devices).
>
> My thought is to add a flag in iommufd_hw_capabilities to report the
> capability, and add a flag in iommufd_hwpt_alloc_flags to let iommu driver
> know if HPT is needed when allocating S2 domain. Userspace attaches the
> un-trusted devices to the domains with HPT. While trusted devices can be
> attached to 'normal' S2 domains. Will to send it out soon.:)
>
>> With Secure ATS, for ATS requests IOMMU return GPA to device instead of SPA.
>
> I suppose AMD Secure ATS only works under nested translation configuration.
> is it? I guess admin may want some flexibility to opt-in it. :)
AMD Secure ATS works under 3 scenarios :
- Baremetal case w/ AMD Host (V1) page table (this include VFIO passthrough)
- HW Nested setup where both page table is configured
In above two setup, its opt-in feature
- SNP (Secure Nested Paging) is ON
Secure ATS is mandatory.
-Vasant
prev parent reply other threads:[~2025-02-26 4:33 UTC|newest]
Thread overview: 68+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-02-25 10:58 [PATCH] iommu/amd: Add Secure ATS support Vasant Hegde
2025-02-25 12:30 ` Yi Liu
2025-02-25 13:18 ` Robin Murphy
2025-02-25 13:57 ` Yi Liu
2025-02-25 14:55 ` Jason Gunthorpe
2025-02-26 1:09 ` Yi Liu
2025-02-26 1:13 ` Jason Gunthorpe
2025-02-26 1:27 ` Yi Liu
2025-02-26 2:52 ` Tian, Kevin
2025-02-26 1:12 ` Tian, Kevin
2025-02-26 1:17 ` Jason Gunthorpe
2025-02-26 2:50 ` Tian, Kevin
2025-02-26 12:57 ` Jason Gunthorpe
2025-02-26 7:05 ` Tian, Kevin
2025-02-26 12:58 ` Jason Gunthorpe
2025-02-27 15:27 ` Vasant Hegde
2025-02-28 6:32 ` Tian, Kevin
2025-02-28 7:43 ` Yi Liu
2025-02-28 8:30 ` Vasant Hegde
2025-02-28 8:47 ` Yi Liu
2025-02-28 8:47 ` Vasant Hegde
2025-03-02 8:10 ` Yi Liu
2025-03-03 3:00 ` Tian, Kevin
2025-03-04 6:58 ` Yi Liu
2025-03-03 11:42 ` Vasant Hegde
2025-03-05 3:24 ` Tian, Kevin
2025-03-10 17:07 ` Vasant Hegde
2025-03-12 7:15 ` Tian, Kevin
2025-03-17 8:56 ` Vasant Hegde
2025-04-07 5:28 ` Tian, Kevin
2025-03-03 18:38 ` Jason Gunthorpe
2025-03-04 2:16 ` Baolu Lu
2025-03-04 14:18 ` Jason Gunthorpe
2025-03-05 2:45 ` Baolu Lu
2025-03-05 2:46 ` Tian, Kevin
2025-03-04 6:50 ` Yi Liu
2025-03-04 10:46 ` Vasant Hegde
2025-03-04 14:20 ` Jason Gunthorpe
2025-03-05 2:50 ` Tian, Kevin
2025-03-05 17:22 ` Jason Gunthorpe
2025-03-06 2:41 ` Tian, Kevin
2025-03-14 12:54 ` Yi Liu
2025-03-04 10:15 ` Vasant Hegde
2025-03-04 14:24 ` Jason Gunthorpe
2025-03-10 16:35 ` Vasant Hegde
2025-03-14 12:09 ` Yi Liu
2025-03-19 19:52 ` Jason Gunthorpe
2025-03-14 12:22 ` Yi Liu
2025-02-28 8:26 ` Vasant Hegde
2025-02-28 14:56 ` Jason Gunthorpe
2025-03-03 2:55 ` Tian, Kevin
2025-03-10 14:13 ` Vasant Hegde
2025-03-12 6:55 ` Tian, Kevin
2025-03-03 11:56 ` Vasant Hegde
2025-02-26 4:47 ` Vasant Hegde
2025-02-26 7:10 ` Tian, Kevin
2025-02-26 13:01 ` Jason Gunthorpe
2025-02-26 22:42 ` Jerry Snitselaar
2025-02-27 16:04 ` Vasant Hegde
2025-02-28 0:04 ` Jason Gunthorpe
2025-02-28 6:18 ` Tian, Kevin
2025-02-28 1:47 ` Baolu Lu
2025-02-28 6:15 ` Tian, Kevin
2025-02-28 8:53 ` Vasant Hegde
2025-02-28 14:53 ` Jason Gunthorpe
2025-03-03 2:43 ` Tian, Kevin
2025-02-28 8:38 ` Vasant Hegde
2025-02-26 4:33 ` Vasant Hegde [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=80875f62-b341-4d25-a83f-6713f3f69551@amd.com \
--to=vasant.hegde@amd.com \
--cc=iommu@lists.linux.dev \
--cc=joro@8bytes.org \
--cc=robin.murphy@arm.com \
--cc=suravee.suthikulpanit@amd.com \
--cc=will@kernel.org \
--cc=yi.l.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.