All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vasant Hegde <vasant.hegde@amd.com>
To: "Tian, Kevin" <kevin.tian@intel.com>,
	Baolu Lu <baolu.lu@linux.intel.com>,
	Jason Gunthorpe <jgg@ziepe.ca>,
	Robin Murphy <robin.murphy@arm.com>
Cc: "Liu, Yi L" <yi.l.liu@intel.com>,
	"iommu@lists.linux.dev" <iommu@lists.linux.dev>,
	"joro@8bytes.org" <joro@8bytes.org>,
	"will@kernel.org" <will@kernel.org>,
	"suravee.suthikulpanit@amd.com" <suravee.suthikulpanit@amd.com>
Subject: Re: [PATCH] iommu/amd: Add Secure ATS support
Date: Fri, 28 Feb 2025 14:23:27 +0530	[thread overview]
Message-ID: <bb359e20-2d96-4277-b341-c8fe9c16dad6@amd.com> (raw)
In-Reply-To: <BN9PR11MB5276D09A00E44AE7D220D7C18CCC2@BN9PR11MB5276.namprd11.prod.outlook.com>

Kevin,


On 2/28/2025 11:45 AM, Tian, Kevin wrote:
>> From: Baolu Lu <baolu.lu@linux.intel.com>
>> Sent: Friday, February 28, 2025 9:48 AM
>>
>> On 2/28/25 00:04, Vasant Hegde wrote:
>>> On 2/26/2025 12:40 PM, Tian, Kevin wrote:
>>>>> From: Vasant Hegde<vasant.hegde@amd.com>
>>>>> Sent: Wednesday, February 26, 2025 12:47 PM
>>>>>
>>>>>>   3) TA is an IOVA and the IOMMU runs it through the full translation
>>>>>>      to validate it. ATS is just used to signal non-present
>>>>> Yes. AMD does this when Host page table is configured.
>>>> Here 'signal non-present' implies to support PRI.
>>>>
>>>> But...
>>>>
>>>>> We need to consider various scenarios. For AMD:
>>>>>    - Currently on baremetal, we cannot enable SVA and Secure ATS
>>>> ... here it says SVA/SATS are incompatible. Any more background?
>>> Sorry. I should have explained it better.
>>>
>>> To support SVA (PASID/PRI), we have to configure domain with AMD Guest
>> (v2) Page
>>> table and host page table will not be set (DTE[Mode]=0).
>>>
>>>    GVA -> GPA contains translation and GPA = SPA.
>>>
>>> On ATS request it will send GPA back to device (which is actually a SPA). We
>> can
>>> support secure ATS, but ATS response will contain the SPA.
>>
>> So, the hardware is configured to work in secure ATS mode, but the ATS
>> is not actually secure here, right? AMD's secure ATS relies on checking
>> GPA to SPA translation; however, GPA is always equal to SPA in the SVA
>> case.
>>
>> Am I understanding this correctly?
>>
> 
> Looks so.
> 
> To support secure ATS, the IOMMU needs a structure to manage the
> permission per the translated address (TA).
> 
> For #2 it reuses the S2 page table for permission track hence requires
> nesting and TA = S2 IOVA. It cannot support bare metal SVA given
> S2 is absent.
> 
> AMD is clearly this flavor. also supported by ARM.
> 
> For #3 it reuses the full translation (s1, s2, or nested) with TA =
> untranslated IOVA. This supposes to work with all existing ATS
> scenarios. Probably good for prototype development but no
> real value given it loses all perf benefit from ATS or even worse
> perf compared to no ats due to double walking.
> 
> Both #2/#3 have PCI topology restrictions e.g. CXL.
> 
> ARM probably supports #3 as a special case of #2.
> 
> For #4, it introduces a separate permission structure per real
> physical address, hence TA = physical address. It's supposed
> to work for all ATS scenarios and CXL, with some burden e.g.
> sync with IO page table plus more invalidations, etc.

Nice Summary. #2 / #4 is practically useful scenario's.

-Vasant




  reply	other threads:[~2025-02-28  8:53 UTC|newest]

Thread overview: 68+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-02-25 10:58 [PATCH] iommu/amd: Add Secure ATS support Vasant Hegde
2025-02-25 12:30 ` Yi Liu
2025-02-25 13:18   ` Robin Murphy
2025-02-25 13:57     ` Yi Liu
2025-02-25 14:55     ` Jason Gunthorpe
2025-02-26  1:09       ` Yi Liu
2025-02-26  1:13         ` Jason Gunthorpe
2025-02-26  1:27           ` Yi Liu
2025-02-26  2:52           ` Tian, Kevin
2025-02-26  1:12       ` Tian, Kevin
2025-02-26  1:17         ` Jason Gunthorpe
2025-02-26  2:50           ` Tian, Kevin
2025-02-26 12:57             ` Jason Gunthorpe
2025-02-26  7:05           ` Tian, Kevin
2025-02-26 12:58             ` Jason Gunthorpe
2025-02-27 15:27             ` Vasant Hegde
2025-02-28  6:32               ` Tian, Kevin
2025-02-28  7:43                 ` Yi Liu
2025-02-28  8:30                   ` Vasant Hegde
2025-02-28  8:47                     ` Yi Liu
2025-02-28  8:47                       ` Vasant Hegde
2025-03-02  8:10                         ` Yi Liu
2025-03-03  3:00                           ` Tian, Kevin
2025-03-04  6:58                             ` Yi Liu
2025-03-03 11:42                           ` Vasant Hegde
2025-03-05  3:24                             ` Tian, Kevin
2025-03-10 17:07                               ` Vasant Hegde
2025-03-12  7:15                                 ` Tian, Kevin
2025-03-17  8:56                                   ` Vasant Hegde
2025-04-07  5:28                                     ` Tian, Kevin
2025-03-03 18:38                           ` Jason Gunthorpe
2025-03-04  2:16                             ` Baolu Lu
2025-03-04 14:18                               ` Jason Gunthorpe
2025-03-05  2:45                                 ` Baolu Lu
2025-03-05  2:46                                 ` Tian, Kevin
2025-03-04  6:50                             ` Yi Liu
2025-03-04 10:46                               ` Vasant Hegde
2025-03-04 14:20                               ` Jason Gunthorpe
2025-03-05  2:50                                 ` Tian, Kevin
2025-03-05 17:22                                   ` Jason Gunthorpe
2025-03-06  2:41                                     ` Tian, Kevin
2025-03-14 12:54                                 ` Yi Liu
2025-03-04 10:15                             ` Vasant Hegde
2025-03-04 14:24                               ` Jason Gunthorpe
2025-03-10 16:35                                 ` Vasant Hegde
2025-03-14 12:09                                 ` Yi Liu
2025-03-19 19:52                                   ` Jason Gunthorpe
2025-03-14 12:22                               ` Yi Liu
2025-02-28  8:26                 ` Vasant Hegde
2025-02-28 14:56               ` Jason Gunthorpe
2025-03-03  2:55                 ` Tian, Kevin
2025-03-10 14:13                   ` Vasant Hegde
2025-03-12  6:55                     ` Tian, Kevin
2025-03-03 11:56                 ` Vasant Hegde
2025-02-26  4:47       ` Vasant Hegde
2025-02-26  7:10         ` Tian, Kevin
2025-02-26 13:01           ` Jason Gunthorpe
2025-02-26 22:42           ` Jerry Snitselaar
2025-02-27 16:04           ` Vasant Hegde
2025-02-28  0:04             ` Jason Gunthorpe
2025-02-28  6:18               ` Tian, Kevin
2025-02-28  1:47             ` Baolu Lu
2025-02-28  6:15               ` Tian, Kevin
2025-02-28  8:53                 ` Vasant Hegde [this message]
2025-02-28 14:53                 ` Jason Gunthorpe
2025-03-03  2:43                   ` Tian, Kevin
2025-02-28  8:38               ` Vasant Hegde
2025-02-26  4:33   ` Vasant Hegde

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bb359e20-2d96-4277-b341-c8fe9c16dad6@amd.com \
    --to=vasant.hegde@amd.com \
    --cc=baolu.lu@linux.intel.com \
    --cc=iommu@lists.linux.dev \
    --cc=jgg@ziepe.ca \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=robin.murphy@arm.com \
    --cc=suravee.suthikulpanit@amd.com \
    --cc=will@kernel.org \
    --cc=yi.l.liu@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.