All of lore.kernel.org
 help / color / mirror / Atom feed
From: Aneesh Kumar K.V <aneesh.kumar@kernel.org>
To: Jason Gunthorpe <jgg@nvidia.com>
Cc: linux-coco@lists.linux.dev, iommu@lists.linux.dev,
	linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
	Alexey Kardashevskiy <aik@amd.com>,
	Bjorn Helgaas <helgaas@kernel.org>,
	Joerg Roedel <joro@8bytes.org>,
	Jonathan Cameron <jic23@kernel.org>,
	Kevin Tian <kevin.tian@intel.com>,
	Nicolin Chen <nicolinc@nvidia.com>,
	Samuel Ortiz <sameo@rivosinc.com>,
	Steven Price <steven.price@arm.com>,
	Suzuki K Poulose <Suzuki.Poulose@arm.com>,
	Will Deacon <will@kernel.org>,
	Xu Yilun <yilun.xu@linux.intel.com>,
	Shameer Kolothum <shameerali.kolothum.thodi@huawei.com>,
	Paolo Bonzini <pbonzini@redhat.com>
Subject: Re: [RFC PATCH v6 05/11] iommu: Add a helper to validate a vIOMMU parent
Date: Mon, 28 Sep 2026 21:09:06 +0530	[thread overview]
Message-ID: <yq5azex1peqt.fsf@kernel.org> (raw)
In-Reply-To: <20260928121147.GP9354@nvidia.com>

Jason Gunthorpe <jgg@nvidia.com> writes:

> On Mon, Sep 28, 2026 at 04:06:42PM +0530, Aneesh Kumar K.V wrote:
>> Jason Gunthorpe <jgg@nvidia.com> writes:
>> 
>> > On Fri, Sep 25, 2026 at 11:18:44AM +0530, Aneesh Kumar K.V wrote:
>> >> > The TSM viommu should use a NULL parent domain, it doesn't have an
>> >> > iommufd managed S2.
>> >> 
>> >> How would we assign an untrusted device? I currently follow these steps:
>> >
>> >> 1. Create an HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT.
>> >> 2. Allocate a vIOMMU with viommu.hwpt_id set to that hwpt_id.
>> >> 3. Allocate a vdevice with alloc_vdev.viommu_id set to that viommu_id.
>> >> 4. Use VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id.
>> >
>> > The vmiommu.hwpt_id should be 0.
>> >
>> > 1. Create a a HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT
>> > 2. VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id to establish the T=0
>> >    identity S2, no T=0 vSMMU
>> > 3. Create a VIOMMU with no hwpt_id and the RMM's type. This triggers
>> >    RMM to create the the T=1 vSMMU inside the realm
>> > 4. Allocate a vdevice on the viommu_id. This triggers RMM to create
>> >    the VDEV inside the realm
>> > 5. Setup guest ACPI tables/etc to point at the RMM's T=1 vsmmu.
>> >
>> > Now both the T=1 VSUMM and T=0 fixed translation are setup.
>> >
>> 
>> ok so iommufd_viommu_alloc_ioctl() will do this based on type.
>> 
>> +	if (iommufd_viommu_type_requires_hwpt(cmd->type)) {
>> +		hwpt_paging = iommufd_get_hwpt_paging(ucmd, cmd->hwpt_id);
>> +		if (IS_ERR(hwpt_paging)) {
>
> The core code should not decode type, that's always a hack..
>
> The ideal thing is to order things so we get a viommu_ops before
> trying to get the hwpt, then use a flag in the ops
>

Does that mean the SMMU driver will return viommu_ops before
iommu_ops->viommu_init() is called? If so, should viommu_init() be moved
into viommu_ops?

Would the core then only need to do something like:

	rc = tsm_viommu_get_info(idev->dev, cmd->type, &info);
	if (not_using_tsm) // All smmu driver will now support get_viommu_info.
		rc = iommu_ops->get_viommu_info(idev->dev, cmd->type, &info);

and then call info->ops->viommu_init()?

-aneesh

  reply	other threads:[~2026-09-28 15:39 UTC|newest]

Thread overview: 72+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-17 14:01 [RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 01/11] vfio: cache KVM VM file references instead of raw struct kvm pointers Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-30  7:19     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 02/11] vfio: cdev: Reject duplicate bind before updating KVM file Aneesh Kumar K.V (Arm)
2026-09-24  7:53   ` Tian, Kevin
2026-09-25  5:49     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 03/11] iommufd/device: Associate KVM file pointer with iommufd_device Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 04/11] iommufd/viommu: Keep a reference to the KVM file Aneesh Kumar K.V (Arm)
2026-09-30 13:28   ` Vasant Hegde
2026-10-02  5:26     ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 05/11] iommu: Add a helper to validate a vIOMMU parent Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  5:48     ` Aneesh Kumar K.V
2026-09-25 12:23       ` Jason Gunthorpe
2026-09-28 10:36         ` Aneesh Kumar K.V
2026-09-28 12:11           ` Jason Gunthorpe
2026-09-28 15:39             ` Aneesh Kumar K.V [this message]
2026-09-28 16:17               ` Jason Gunthorpe
2026-09-28 18:08                 ` Jacob Pan
2026-09-28 18:20                   ` Jason Gunthorpe
2026-09-28 22:24                     ` Jacob Pan
2026-09-28 23:03                       ` Jason Gunthorpe
2026-09-29  5:55                         ` Jacob Pan
2026-09-29 12:30                           ` Jason Gunthorpe
2026-09-29 23:15                             ` Jacob Pan
2026-09-29 23:30                               ` Jason Gunthorpe
2026-09-17 14:01 ` [RFC PATCH v6 06/11] iommu: Add a helper to query vIOMMU hardware parameters Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  5:59     ` Aneesh Kumar K.V
2026-09-25 12:29       ` Jason Gunthorpe
2026-09-17 14:01 ` [RFC PATCH v6 07/11] coco: tsm: Expose active-user lifetime references Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 08/11] iommufd: Add vIOMMU provider support Aneesh Kumar K.V (Arm)
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  6:08     ` Aneesh Kumar K.V
2026-09-25 12:39       ` Jason Gunthorpe
2026-09-28  3:41         ` Tian, Kevin
2026-09-29  6:14           ` Aneesh Kumar K.V
2026-09-29 12:17             ` Jason Gunthorpe
2026-09-29 12:45               ` Aneesh Kumar K.V
2026-09-29 13:06                 ` Jason Gunthorpe
2026-09-29 15:58                   ` Aneesh Kumar K.V
2026-09-29 19:10                     ` Jason Gunthorpe
2026-09-28 10:51         ` Aneesh Kumar K.V
2026-09-17 14:01 ` [RFC PATCH v6 09/11] iommufd: Add the vdevice TSM request ioctl Aneesh Kumar K.V (Arm)
2026-09-18 13:09   ` Alexey Kardashevskiy
2026-09-18 13:13     ` Jason Gunthorpe
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-30  8:03     ` Aneesh Kumar K.V
2026-09-30 13:26       ` Vasant Hegde
2026-09-30 14:03         ` Jason Gunthorpe
2026-09-30 14:08       ` Jason Gunthorpe
2026-09-17 14:01 ` [RFC PATCH v6 10/11] PCI/TSM: Remove the legacy guest request interface Aneesh Kumar K.V (Arm)
2026-09-17 14:01 ` [RFC PATCH v6 11/11] PCI/TSM: Add reference-counted contexts for vdevice providers Aneesh Kumar K.V (Arm)
2026-09-24  8:17   ` Tian, Kevin
2026-09-24 19:41   ` Jason Gunthorpe
2026-09-25  8:15     ` Aneesh Kumar K.V
2026-09-28 18:47   ` Sonang Patel
2026-09-28 23:08     ` Jason Gunthorpe
2026-10-02  6:14       ` Aneesh Kumar K.V
2026-10-02 13:06         ` Jason Gunthorpe
2026-09-17 14:17 ` [RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests Aneesh Kumar K.V
2026-09-24  7:48 ` Tian, Kevin
2026-09-24 19:20   ` Jason Gunthorpe
2026-09-28  3:35     ` Tian, Kevin
2026-09-28 13:08       ` Jason Gunthorpe
2026-09-25  8:29   ` Aneesh Kumar K.V
2026-09-28  3:41     ` Tian, Kevin
2026-09-28  3:55       ` Tian, Kevin
2026-09-24 19:09 ` Jason Gunthorpe
2026-09-25  6:46   ` Aneesh Kumar K.V
2026-09-25 12:45     ` Jason Gunthorpe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=yq5azex1peqt.fsf@kernel.org \
    --to=aneesh.kumar@kernel.org \
    --cc=Suzuki.Poulose@arm.com \
    --cc=aik@amd.com \
    --cc=helgaas@kernel.org \
    --cc=iommu@lists.linux.dev \
    --cc=jgg@nvidia.com \
    --cc=jic23@kernel.org \
    --cc=joro@8bytes.org \
    --cc=kevin.tian@intel.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nicolinc@nvidia.com \
    --cc=pbonzini@redhat.com \
    --cc=sameo@rivosinc.com \
    --cc=shameerali.kolothum.thodi@huawei.com \
    --cc=steven.price@arm.com \
    --cc=will@kernel.org \
    --cc=yilun.xu@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.