public inbox for intel-xe@lists.freedesktop.org
 help / color / mirror / Atom feed
From: "Christian König" <christian.koenig@amd.com>
To: Jason Gunthorpe <jgg@nvidia.com>
Cc: Dongwon Kim <dongwon.kim@intel.com>,
	dri-devel@lists.freedesktop.org, intel-xe@lists.freedesktop.org,
	iommu@lists.linux.dev, Kevin Tian <kevin.tian@intel.com>,
	Leon Romanovsky <leonro@nvidia.com>,
	linaro-mm-sig@lists.linaro.org, linux-media@vger.kernel.org,
	Matthew Brost <matthew.brost@intel.com>,
	Simona Vetter <simona.vetter@ffwll.ch>,
	Sumit Semwal <sumit.semwal@linaro.org>,
	Thomas Hellstrom <thomas.hellstrom@linux.intel.com>,
	Vivek Kasireddy <vivek.kasireddy@intel.com>
Subject: Re: [PATCH RFC 21/26] dma-buf: Add the Physical Address List DMA mapping type
Date: Mon, 13 Apr 2026 10:58:20 +0200	[thread overview]
Message-ID: <c413710b-4c28-4ed8-88ec-aeb8c4482011@amd.com> (raw)
In-Reply-To: <21-v1-b5cab63049c0+191af-dmabuf_map_type_jgg@nvidia.com>

On 2/18/26 01:11, Jason Gunthorpe wrote:
> This type is required by iommufd and kvm as dmabuf importers.
> 
> Due to sensitivity about abusing physical addresses, restrict importers by
> using EXPORT_SYMBOL_FOR_MODULES(). Only iommufd can implement an importer,
> the kernel module loader will enforce this.
> 
> Allow anything to implement an exporter as there are use cases in
> DPDK/SPDK to connect GPU memory into VFIO/iommufd and it is hard to abuse
> the API as an exporter.
> 
> The physical address list exporter returns a physical address list in a
> simple kvalloc'd array of struct phys_vec.

As far as I can see that is still a pretty big NO-GO.

We have seen so many problems with direct physical address access by the importer that I clear don't want to repeat that performance.

My main question is why does IOMMUFD need the physical address in the first place?

If that is really strictly necessary then I strongly suggest to not touch drivers/dma-buf in any way, but only do this is private interface between iommufd and KVM.

Regards,
Christian.

> 
> For now all entries are assumed to be MMIO and iommufd will map into
> the IOMMU using the IOMMU_MMIO flag.
> 
> Signed-off-by: Jason Gunthorpe <jgg@nvidia.com>
> ---
>  drivers/dma-buf/dma-buf-mapping.c | 63 +++++++++++++++++++++++++++++++
>  include/linux/dma-buf-mapping.h   | 42 +++++++++++++++++++++
>  2 files changed, 105 insertions(+)
> 
> diff --git a/drivers/dma-buf/dma-buf-mapping.c b/drivers/dma-buf/dma-buf-mapping.c
> index baa96b37e2c6bd..d9d6b9b5bf05c6 100644
> --- a/drivers/dma-buf/dma-buf-mapping.c
> +++ b/drivers/dma-buf/dma-buf-mapping.c
> @@ -349,3 +349,66 @@ struct dma_buf_mapping_type dma_buf_mapping_sgt_type = {
>  	.debugfs_dump = dma_buf_sgt_debugfs_dump,
>  };
>  EXPORT_SYMBOL_NS_GPL(dma_buf_mapping_sgt_type, "DMA_BUF");
> +
> +static const struct dma_buf_mapping_pal_exp_ops *
> +to_pal_exp_ops(struct dma_buf_attachment *attach)
> +{
> +	return container_of(attach->map_type.exp_ops,
> +			    struct dma_buf_mapping_pal_exp_ops, ops);
> +}
> +
> +/**
> + * dma_buf_pal_map_phys - Obtain the physical address list for a PAL attachment
> + * @attach: The DMA-buf attachment
> + *
> + * Calls the exporter's map_phys() callback to retrieve the physical address
> + * list for the buffer. The caller must hold the dma-buf's reservation lock.
> + *
> + * This symbol is restricted to iommufd to prevent misuse.
> + *
> + * Returns the physical address list on success, or an ERR_PTR on failure.
> + * The returned list must be freed with dma_buf_pal_unmap_phys().
> + */
> +struct dma_buf_phys_list *
> +dma_buf_pal_map_phys(struct dma_buf_attachment *attach)
> +{
> +	dma_resv_assert_held(attach->dmabuf->resv);
> +	return to_pal_exp_ops(attach)->map_phys(attach);
> +}
> +/*
> + * Restricted, iommufd is the only importer allowed to prevent misuse of this
> + * API.
> + */
> +EXPORT_SYMBOL_FOR_MODULES(dma_buf_pal_map_phys, "iommufd");
> +
> +/**
> + * dma_buf_pal_unmap_phys - Unmap a physical address list
> + * @attach: The DMA-buf attachment
> + * @phys: The physical address list returned by dma_buf_pal_map_phys()
> + *
> + * Returns the mapping back to the exporter. After this point the importer may
> + * not touch any of the addresses in any way.
> + */
> +void dma_buf_pal_unmap_phys(struct dma_buf_attachment *attach,
> +			    struct dma_buf_phys_list *phys)
> +{
> +	to_pal_exp_ops(attach)->unmap_phys(attach, phys);
> +}
> +EXPORT_SYMBOL_NS_GPL(dma_buf_pal_unmap_phys, "DMA_BUF");
> +
> +static inline void
> +dma_buf_pal_finish_match(struct dma_buf_match_args *args,
> +			 const struct dma_buf_mapping_match *exp,
> +			 const struct dma_buf_mapping_match *imp)
> +{
> +	args->attach->map_type = (struct dma_buf_mapping_match){
> +		.type = &dma_buf_mapping_pal_type,
> +		.exp_ops = exp->exp_ops,
> +	};
> +}
> +
> +struct dma_buf_mapping_type dma_buf_mapping_pal_type = {
> +	.name = "Physical Address List",
> +	.finish_match = dma_buf_pal_finish_match,
> +};
> +EXPORT_SYMBOL_NS_GPL(dma_buf_mapping_pal_type, "DMA_BUF");
> diff --git a/include/linux/dma-buf-mapping.h b/include/linux/dma-buf-mapping.h
> index ac859b8913edcd..10831ce2e72851 100644
> --- a/include/linux/dma-buf-mapping.h
> +++ b/include/linux/dma-buf-mapping.h
> @@ -269,4 +269,46 @@ DMA_BUF_EMAPPING_SGT_P2P(const struct dma_buf_mapping_sgt_exp_ops *exp_ops,
>  			.exporter_requires_p2p = DMA_SGT_NO_P2P,         \
>  		} })
>  
> +/*
> + * Physical Address List mapping type
> + *
> + * Use of the Physical Address List type is restricted to prevent abuse of the
> + * physical addresses API. Please check with the DMA BUF maintainers before
> + * trying to use it.
> + */
> +struct dma_buf_phys_list {
> +	size_t length;
> +	struct dma_buf_phys_vec phys[] __counted_by(length);
> +};
> +
> +extern struct dma_buf_mapping_type dma_buf_mapping_pal_type;
> +
> +struct dma_buf_mapping_pal_exp_ops {
> +	struct dma_buf_mapping_exp_ops ops;
> +	struct dma_buf_phys_list *(*map_phys)(struct dma_buf_attachment *attach);
> +	void (*unmap_phys)(struct dma_buf_attachment *attach,
> +			   struct dma_buf_phys_list *phys);
> +};
> +
> +struct dma_buf_phys_list *
> +dma_buf_pal_map_phys(struct dma_buf_attachment *attach);
> +void dma_buf_pal_unmap_phys(struct dma_buf_attachment *attach,
> +			    struct dma_buf_phys_list *phys);
> +
> +static inline struct dma_buf_mapping_match DMA_BUF_IMAPPING_PAL(void)
> +{
> +	return (struct dma_buf_mapping_match){
> +		.type = &dma_buf_mapping_pal_type,
> +	};
> +}
> +
> +static inline struct dma_buf_mapping_match
> +DMA_BUF_EMAPPING_PAL(const struct dma_buf_mapping_pal_exp_ops *exp_ops)
> +{
> +	return (struct dma_buf_mapping_match){
> +		.type = &dma_buf_mapping_pal_type,
> +		.exp_ops = &exp_ops->ops,
> +	};
> +}
> +
>  #endif


  reply	other threads:[~2026-04-13  8:58 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-02-18  0:11 [PATCH RFC 00/26] Add DMA-buf mapping types and convert vfio/iommufd to use them Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 01/26] dma-buf: Introduce DMA-buf mapping types Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 02/26] dma-buf: Add the SGT DMA mapping type Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 03/26] dma-buf: Add dma_buf_mapping_attach() Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 04/26] dma-buf: Route SGT related actions through attach->map_type Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 05/26] dma-buf: Allow single exporter drivers to avoid the match_mapping function Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 06/26] drm: Check the SGT ops for drm_gem_map_dma_buf() Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 07/26] dma-buf: Convert all the simple exporters to use SGT mapping type Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 08/26] drm/vmwgfx: Use match_mapping instead of dummy calls Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 09/26] accel/habanalabs: Use the SGT mapping type Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 10/26] drm/xe/dma-buf: " Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 11/26] drm/amdgpu: " Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 12/26] vfio/pci: Change the DMA-buf exporter to use mapping_type Jason Gunthorpe
2026-04-13  8:29   ` Baolu Lu
2026-04-13 13:01     ` Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 13/26] dma-buf: Update dma_buf_phys_vec_to_sgt() to use the SGT mapping type Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 14/26] iio: buffer: convert " Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 15/26] functionfs: " Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 16/26] dma-buf: Remove unused SGT stuff from the common structures Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 17/26] treewide: Rename dma_buf_map_attachment(_unlocked) to dma_buf_sgt_ Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 18/26] treewide: Rename dma_buf_unmap_attachment(_unlocked) to dma_buf_sgt_* Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 19/26] treewide: Rename dma_buf_attach() to dma_buf_sgt_attach() Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 20/26] treewide: Rename dma_buf_dynamic_attach() to dma_buf_sgt_dynamic_attach() Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 21/26] dma-buf: Add the Physical Address List DMA mapping type Jason Gunthorpe
2026-04-13  8:58   ` Christian König [this message]
2026-04-13 12:16     ` Jason Gunthorpe
2026-04-22  8:17       ` Christian König
2026-04-22 11:53         ` Jason Gunthorpe
2026-04-22 12:39           ` Christian König
2026-04-22 13:13             ` Jason Gunthorpe
2026-04-22 14:04               ` Christian König
2026-04-22 15:00                 ` Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 22/26] vfio/pci: Add physical address list support to DMABUF Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 23/26] iommufd: Use the PAL mapping type instead of a vfio function Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 24/26] iommufd: Support DMA-bufs with multiple physical ranges Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 25/26] iommufd/selftest: Check multi-phys DMA-buf scenarios Jason Gunthorpe
2026-02-18  0:11 ` [PATCH RFC 26/26] dma-buf: Add kunit tests for mapping type Jason Gunthorpe
2026-03-01 19:05 ` [PATCH RFC 00/26] Add DMA-buf mapping types and convert vfio/iommufd to use them Jason Gunthorpe
2026-03-03  7:07   ` Kasireddy, Vivek

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=c413710b-4c28-4ed8-88ec-aeb8c4482011@amd.com \
    --to=christian.koenig@amd.com \
    --cc=dongwon.kim@intel.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=iommu@lists.linux.dev \
    --cc=jgg@nvidia.com \
    --cc=kevin.tian@intel.com \
    --cc=leonro@nvidia.com \
    --cc=linaro-mm-sig@lists.linaro.org \
    --cc=linux-media@vger.kernel.org \
    --cc=matthew.brost@intel.com \
    --cc=simona.vetter@ffwll.ch \
    --cc=sumit.semwal@linaro.org \
    --cc=thomas.hellstrom@linux.intel.com \
    --cc=vivek.kasireddy@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox