From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id D249ACA0EE4 for ; Sat, 23 Aug 2025 10:43:47 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1uplip-0007oq-Gi; Sat, 23 Aug 2025 06:43:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1uplil-0007ld-Ol for qemu-arm@nongnu.org; Sat, 23 Aug 2025 06:43:41 -0400 Received: from mail-wm1-x332.google.com ([2a00:1450:4864:20::332]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1uplik-0005dx-4m for qemu-arm@nongnu.org; Sat, 23 Aug 2025 06:43:39 -0400 Received: by mail-wm1-x332.google.com with SMTP id 5b1f17b1804b1-459fc675d11so26875e9.1 for ; Sat, 23 Aug 2025 03:43:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20230601; t=1755945816; x=1756550616; darn=nongnu.org; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date:from:to :cc:subject:date:message-id:reply-to; bh=AIOyF8h41AAN01tpKcBE3Z7P7M8oJ+cDqLaohjVDWgQ=; b=m82lk5yzCgQcX8Miv6riAhauGglp07MHxF4gQVto4tpQ2t1FOxqqexC99lyjO4fUkJ uy7iKaYvgc4dxR00/Xh8Z+fXonF3+73yzjR+qUWqt+sB0olocyL17om44+6UygzbgVQM /hjSiB4prU2zI79QeKyF8LZBjb8N4z7WHrWsLC3AAWTZrGyoLe0sj0uhiodgXySEhAOL X119t2AtbaSgMPj1XmphWEVGdJaSw1KDIttf8IVJn5lizMxWFLsP3wCswQ11vJotKF81 B1eRyzeHWKvn3Eqvy7er8NjkChPFQu102dyLP89/SvQH1WLHdEfmz5llq/X7GxFS0w0q 6wBw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1755945816; x=1756550616; h=in-reply-to:content-transfer-encoding:content-disposition :mime-version:references:message-id:subject:cc:to:from:date :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to; bh=AIOyF8h41AAN01tpKcBE3Z7P7M8oJ+cDqLaohjVDWgQ=; b=Mg7qxN8Cf2PuBAx7PPNY5TIW4mwf5V5mptbQWLtJ7CvDFW3VNPg2g0vVBke4XcVeJG G5eXb5CqtcGvaCoJ7sw8k+Jr6K6AyOorv96Yhxp9wQvyA/Ub1Vo+NStqTP3ZmA+8IFff bVIQ/C7vfGGWOSo+wck7WMFvraRBHUVZVGgAKrdaqHN0b53DfODOn5Fc5rCVpNXzPymu mK98ZgIrnN1uiqf0aBg7srIjLF+B+SpyXi2duS1jbuvSGWqPK3GMP5wSeEu1IoKtVsdA ctwnLaEAkCaE1qiLtPeMDpojz4I5iTH5Tw6esaIljssTmGGP6vdwzlhvLUPerWd8Rsbo qPWw== X-Gm-Message-State: AOJu0YwGl/19AnT3ahDLDSU+IJger+50cj1JMuTNX3jipZa4uTvNemkd 62JcI8+LooOaW57rcLsX375lPqbw/BRhIsmJp+45eJrv1PIm/+qzKE+Pig3BC4xZEg== X-Gm-Gg: ASbGnctE7I4oBaKvRpwenv3HykcQS/i7WMuLuBXV8sx+VzR7JMTOFzP8FTUjKdY3NSa RfNo88lBzRVOeIISgmRzQFe2M9bmnBm9BlcbKA6LfrGm74EyQt6CjHmCcOOjfcviNi7LEgS7IQp zpT5AFS9M6IsMxaHz9/m7RtYs4eyJ4U4YFxp94XNQvjmphCC4BBWwIckvLLOlQJ2S/i1b6u6TxS 6NvBFKvNdXzAVPZ/NH2X2EGsIrM1T5zzy73ccpfBQACSTyd8oAaoALWvesNxmdP5KSa7kWeLNRQ U7F8jLNklhJTIwIeKvSWvWw9SHcU60DZoFXChd6r+kcPb4gZcWGSHLykS7k8DsY/2aGNJSMT69+ 7Srs6qdtdeWD62Avmd9AhfxKgi6fgOFf8eBCfkoIw7HAffU3tKZ6KFNxQoWNbfbO8liQ= X-Google-Smtp-Source: AGHT+IFphaBK0vNlYF3H3FCXhE4KC+N388B6IwsWD8PalUoQWFFaW9jKmiIrMTqLkTT7NwtCR63z1A== X-Received: by 2002:a05:600c:8217:b0:453:672b:5b64 with SMTP id 5b1f17b1804b1-45b57c2981cmr1178885e9.2.1755945816345; Sat, 23 Aug 2025 03:43:36 -0700 (PDT) Received: from google.com (248.27.205.35.bc.googleusercontent.com. [35.205.27.248]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-3c70ef55bddsm3105521f8f.22.2025.08.23.03.43.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 23 Aug 2025 03:43:35 -0700 (PDT) Date: Sat, 23 Aug 2025 10:43:32 +0000 From: Mostafa Saleh To: Tao Tang Cc: qemu-arm@nongnu.org, qemu-devel@nongnu.org, Eric Auger , Peter Maydell , Chen Baozi , jean-philippe@linaro.org, Philippe =?iso-8859-1?Q?Mathieu-Daud=E9?= , Pierrick Bouvier Subject: Re: [RFC 06/11] hw/arm/smmuv3: Plumb security state through core functions Message-ID: References: <20250806151134.365755-1-tangtao1634@phytium.com.cn> <20250806151134.365755-7-tangtao1634@phytium.com.cn> <7b8acb9a-e3fe-461b-8495-42c7501a6a80@phytium.com.cn> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <7b8acb9a-e3fe-461b-8495-42c7501a6a80@phytium.com.cn> Received-SPF: pass client-ip=2a00:1450:4864:20::332; envelope-from=smostafa@google.com; helo=mail-wm1-x332.google.com X-Spam_score_int: -175 X-Spam_score: -17.6 X-Spam_bar: ----------------- X-Spam_report: (-17.6 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, ENV_AND_HDR_SPF_MATCH=-0.5, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5, USER_IN_DEF_SPF_WL=-7.5 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-arm@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-arm-bounces+qemu-arm=archiver.kernel.org@nongnu.org Sender: qemu-arm-bounces+qemu-arm=archiver.kernel.org@nongnu.org On Thu, Aug 21, 2025 at 12:25:40AM +0800, Tao Tang wrote: > > On 2025/8/19 05:28, Mostafa Saleh wrote: > > On Wed, Aug 06, 2025 at 11:11:29PM +0800, Tao Tang wrote: > > > To support parallel processing of secure and non-secure streams, the > > > SMMUv3 model needs to differentiate between the two contexts throughout > > > its core logic. This commit is the foundational step to make the code > > > security-state aware. > > > > > > An is_secure flag, which will be used in subsequent patches to represent > > > the transaction's security state, is now plumbed through the main > > > processing paths. > > > > > > This change is purely preparatory and introduces no functional changes > > > for the existing non-secure path. All current call sites are updated > > > to pass is_secure = false. > > > > > > This refactoring paves the way for upcoming patches that will introduce > > > separate TLB entries for secure transactions and enable a fully > > > parallel secure/non-secure SMMU model. > > > > > I think it’s easier to review if this patch was split (STE parsing, > > page table handling and translation, TLB invalidation) > > Also based on my comment on patch 2, stage-2 handling doesn’t seem correct to me. > > > > Thanks, > > Mostafa > > > Hi Mostafa, > > Thank you your suggestion. > > You've made a very good point. This patch is indeed too large and tries to > cover too many different areas. For the v2 series, I will break this patch > down into logical parts as you suggested (STE parsing, page table handling, > etc.). > > I also acknowledge your concern about the stage-2 handling logic from your > comment on patch 2. I have sent a separate, detailed reply to your feedback > on patch #2 that outlines my new understanding. > > And as you commented on patch #01: > > > > Inside this TCG VM, a KVM guest was launched, and the same NVMe device was > > > re-assigned to it via VFIO. > > > Command line of KVM VM inside TCG VM is below: > > > > > > sudo qemu-system-aarch64 \ > > > -enable-kvm -m 1024 -cpu host -M virt \ > > > -machine virt,gic-version=3 \ > > > -cpu max -append "nokaslr" -smp 1 \ > > > -monitor stdio \ > > > -kernel 5.15.Image \ > > > -initrd rootfs.cpio.gz \ > > > -display vnc=:22,id=primary \ > > > -device vfio-pci,host=00:01.0 > > > > > > The KVM guest was able to perform I/O on the device > > > correctly, confirming that the non-secure path is not broken. > > I gave the patches a quick test and they seem to have broken my > > nested setup, I will look more into it and let you know what I find. > > > > Thanks, > > Mostafa > > > I'm sorry to hear that it has broken your environment. Please don't hesitate > to share any details, logs, or reproduction steps when you find them. I am > more than happy to help reproduce the issue on my end to get it fixed as > quickly as possible. > > > I would be delighted to hear back from you on any of the topics we've > discussed, as any further guidance you can offer would be invaluable. > So far, I couldn’t repro, I remember getting permission errors, I will keep the patches in my stack, and will let you know if I hit that again. Thanks, Mostafa > Thanks, > > Tao > > >