From: Samiullah Khawaja <skhawaja@google.com>
To: Alex Williamson <alex.williamson@nvidia.com>
Cc: kvm <kvm@vger.kernel.org>, Alex Williamson <alex@shazbot.org>,
Jason Gunthorpe <jgg@ziepe.ca>,
Bjorn Helgaas <bhelgaas@google.com>,
Kevin Tian <kevin.tian@intel.com>,
linux-kernel <linux-kernel@vger.kernel.org>,
linux-pci <linux-pci@vger.kernel.org>
Subject: Re: [RFC PATCH 1/5] PCI: Refuse function reset of an SR-IOV PF with enabled VFs
Date: Fri, 14 Aug 2026 15:54:11 +0000 [thread overview]
Message-ID: <an81s9PcW7OFVj8M@google.com> (raw)
In-Reply-To: <20260814083737.66bb83fb@nvidia.com>
On Fri, Aug 14, 2026 at 08:37:37AM -0600, Alex Williamson wrote:
>On Thu, 13 Aug 2026 23:22:33 +0000
>Samiullah Khawaja <skhawaja@google.com> wrote:
>
>> >
[snip]
>> >+ if (pci_num_vf(dev) > 0) {
>> >+ pci_dev_unlock(dev);
>> >+ return -ENOTTY;
>> >+ }
>>
>> I am wondering whether we should return EAGAIN from here, since this
>> function is used by vfio_pci_core_enable() during open and it doesn't
>> fail the open on ENOTTY. Basically whether we should allow the user to
>> reopen the device if the reset was skipped previously? In the previous
>> instance of open, the device was setup with vfio/iommufd and the vfio fd
>> was abruptly closed and the reset was skipped. But the device went back
>> to the IOMMU default domain and that is probably an Identity domain. If
>> we allow the device to be opened and re-enable busmaster without a
>> reset, is there a chance that device would continue to DMA based on its
>> previous setup/context? Probably unlikely?
>>
>> Note this is different from the current vfio-pci behaviour where device
>> is always reset during close.
>>
>> Maybe thinking with too much paranoia about it :D.
>
>Devices are only ever opened into a user owned domain, the IOMMU
>context switch happens before this and regardless of the reset. Close
>also disables bus-master regardless of reset, so there's no risk of
Yes the close side makes sense, I was more concerned about the reopen.
>ongoing DMA if the device is placed into an identity domain between
>close and re-open.
>
>Actually, I think -ENOTTY is a leftover from a previous iteration where
>this test was pushed into the individual reset methods. -ENOTTY allows
>continuing to the next reset method. With the test guarding all the
>reset methods in this version, we should probably use -EBUSY. -EAGAIN
>would conflate the try-lock contention error, which is actually a usage
>race, versus the PF is not in a state to handle the request.
This sounds good to me.
>
>If the user owns the PF, as evidenced by them being able to get to
>vfio_pci_core_enable(), and reset is blocked by the SR-IOV state of the
>PF, I think there are arguments both that the user implicitly opted in
>to the best-effort reset, as well as a use case that allows the PF
>driver to fail and re-open the PF demands this behavior.
That is fair.
Thanks for clarifying.
Sami
next prev parent reply other threads:[~2026-08-14 15:54 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-12 4:53 [RFC PATCH 0/5] PCI/vfio-pci: Guard resets against active SR-IOV VFs Alex Williamson
2026-08-12 4:53 ` [RFC PATCH 1/5] PCI: Refuse function reset of an SR-IOV PF with enabled VFs Alex Williamson
2026-08-12 5:01 ` sashiko-bot
2026-08-13 23:22 ` Samiullah Khawaja
2026-08-14 14:37 ` Alex Williamson
2026-08-14 15:54 ` Samiullah Khawaja [this message]
2026-08-12 4:53 ` [RFC PATCH 2/5] PCI: Add pci_reset_bus_cond() for a caller-gated slot or bus reset Alex Williamson
2026-08-12 5:00 ` sashiko-bot
2026-08-12 4:53 ` [RFC PATCH 3/5] vfio/pci: Refuse to reset an SR-IOV PF with enabled VFs Alex Williamson
2026-08-12 5:02 ` sashiko-bot
2026-08-12 4:53 ` [RFC PATCH 4/5] PCI: Export pci_reset_supported() Alex Williamson
2026-08-12 4:59 ` sashiko-bot
2026-08-12 4:53 ` [RFC PATCH 5/5] vfio/pci: Use pci_reset_supported() in place of reset_works Alex Williamson
2026-08-12 4:59 ` sashiko-bot
2026-08-12 21:45 ` [RFC PATCH 0/5] PCI/vfio-pci: Guard resets against active SR-IOV VFs Bjorn Helgaas
2026-08-12 22:53 ` Alex Williamson
2026-08-13 22:30 ` Samiullah Khawaja
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=an81s9PcW7OFVj8M@google.com \
--to=skhawaja@google.com \
--cc=alex.williamson@nvidia.com \
--cc=alex@shazbot.org \
--cc=bhelgaas@google.com \
--cc=jgg@ziepe.ca \
--cc=kevin.tian@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.