From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from bombadil.infradead.org (bombadil.infradead.org [198.137.202.133]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 12C55C982E6 for ; Fri, 18 Sep 2026 20:07:10 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Type:Cc:To:From: Subject:Message-ID:References:Mime-Version:In-Reply-To:Date:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=YSbW92ll6VraodQnupXl7opG78OubPyViHFwv8TLCbk=; b=Yr05GVY73ZZjC7sZZorur3bMqA DffpymsJSqtzG9B1IPqiwhnZAQ/PHTXPTqOKoFsiZ7is/keXHKdquPjS9xtwK1hy4/hB4xKURBibA tIKjzvb06bHPOOtPxWrk61qS/ns/da3V2uF32GzZReu0G+wcRROET/Vw2ZjN6WS1NeJfPoIp4S86c ZrlXY4YYpvaxlg7IaPfJOCfVRw+Y8LRTQ6N29drtn2+sGBYbqGdO1Ochy2B9aAKutAL42Q0MI7/Xq gPC+48oydDxlmdkjFEa/gfaVpNSaXHHSBVlJCwkr/dfm7UpVlog8VciB/hulxKWO48Zofcak9q6ic GsDBOgXA==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1x7erV-0000000FTTG-3ucD; Fri, 18 Sep 2026 20:07:09 +0000 Received: from mail-pl1-x648.google.com ([2607:f8b0:4864:20::648]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1x7erN-0000000FTKz-3CBi for kexec@lists.infradead.org; Fri, 18 Sep 2026 20:07:03 +0000 Received: by mail-pl1-x648.google.com with SMTP id d9443c01a7336-2db3d832827so14515865ad.2 for ; Fri, 18 Sep 2026 13:06:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789762018; x=1790366818; darn=lists.infradead.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=YSbW92ll6VraodQnupXl7opG78OubPyViHFwv8TLCbk=; b=g9z9SAUv+8I/NVUCOBbOhVO0NJCPvRnFDylv2+aSlV8Rfi1S7RtWjVbaeZQVz5JY23 cWsXLK9j1cU5Bf+J+Zi5KaUEYfACLEFehz6pzdjzFziNqZinhZ6HjXYyScJbfJDi9yPf YGDXIW9XXEo61QKvnMBBo2w0t1Cdc+GtYqtR+QaDucZEM0x0a8mILTSJh1RA8w+2JdSM FUrmQnt5bEn+2DtncDuIqgU9h7nGzoeWms59hEqZFDBP9qCTzb+TfpPcC8fGhgCJHaoi 1mYBgRAK5WNIMbWBPBumk2zAIm/wZiovkc9rBosaaVmtrD6DitICFhzOSuYX/kcls6jD ysjg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789762018; x=1790366818; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=YSbW92ll6VraodQnupXl7opG78OubPyViHFwv8TLCbk=; b=JU9E1xWI2LdQ7Bu5rtd0okSDOgiePbzDyVguI2G19zga6k3chYRmPr37Yrq+7n779x hE5ai9Qkp4hoIFRg8iUCw9uB0N+bzhq4Jxg3V7x3x6L31OT2hwykeoORUKk2UgJEU3u8 tO1OCtCpsOQJ45xubFzFPiJguh+iA44V/toLR3qrsrXfRR68zG894+BEsxxblg9epjJ/ N6QBs3hIwB9/bNbvnGS2SzQHHlWGMsgEVbNQhh5Ru+GIU9/Yeew2BW1wKxwQj7pMxtYS 8BtH+ejMUcdra+FBZ+sRyq8AoEYjmJa4hwMiTtPmq23BFO2qGxQhw+9suLIF6TexY01c rsbQ== X-Gm-Message-State: AFuF++kQm+D4SsCC5pL6RtDc/NKl1NJRkOii/JFjzKPkwh2FO+OWqhXQ kBrNCb/O6Fr7WTBJ2N2G486fzWTJlcDe34YZTAZ07KTAD+/QlQFKahRMMzIxT2ZexlqCrq9YjeV 9ATl+uKYNZ+e/jDMcCB0m0nOaGJQp5G3eYD9POo0Po+bwgIr0b+mSbgMhJveFu2CXTnXERgTRLk 3ZtByVvvp+z33o3S+z7EvOHikREyg3WkRiEVzBu5n8C1wkxz3tmCA= X-Received: from pgbcn9.prod.google.com ([2002:a05:6a02:a89:b0:cc1:be9e:35ef]) (user=dmatlack job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:4b28:b0:2dd:c100:a5e7 with SMTP id d9443c01a7336-2ddc100a6e5mr8872815ad.59.1789762018048; Fri, 18 Sep 2026 13:06:58 -0700 (PDT) Date: Fri, 18 Sep 2026 20:06:31 +0000 In-Reply-To: <20260918200640.887030-1-dmatlack@google.com> Mime-Version: 1.0 References: <20260918200640.887030-1-dmatlack@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260918200640.887030-6-dmatlack@google.com> Subject: [PATCH v9 05/13] PCI: liveupdate: Auto-preserve upstream bridges across Live Update From: David Matlack To: kexec@lists.infradead.org, linux-doc@vger.kernel.org, linux-kernel@vger.kernel.org, linux-mm@kvack.org, linux-pci@vger.kernel.org Cc: Adithya Jayachandran , Alexander Graf , Alex Williamson , Bjorn Helgaas , Chris Li , David Matlack , David Rientjes , Jacob Pan , Jason Gunthorpe , Jonathan Corbet , Josh Hilke , Leon Romanovsky , Lukas Wunner , Mike Rapoport , Parav Pandit , Pasha Tatashin , Pranjal Shrivastava , Pratyush Yadav , Randy Dunlap , Saeed Mahameed , Samiullah Khawaja , Shuah Khan , Vipin Sharma , William Tu , Yi Liu Content-Type: text/plain; charset="UTF-8" X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260918_130701_894063_FDF1EEFE X-CRM114-Status: GOOD ( 28.57 ) X-BeenThere: kexec@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "kexec" Errors-To: kexec-bounces+kexec=archiver.kernel.org@lists.infradead.org When a PCI device is preserved across a Live Update, all of its upstream bridges up to the root port must also be preserved. This enables the PCI core and any drivers bound to the bridges to manage bridges correctly across a Live Update. Notably, this will be used in subsequent commits to ensure that preserved devices can continue performing memory transactions without a disruption or change in routing. To preserve bridges, the PCI core tracks the number of downstream devices preserved under each bridge using a reference count in struct pci_dev_ser. This allows a bridge to remain preserved until all its downstream preserved devices are unpreserved or finish their participation in the Live Update. Reviewed-by: Pasha Tatashin Reviewed-by: Pranjal Shrivastava Signed-off-by: David Matlack --- drivers/pci/liveupdate.c | 125 +++++++++++++++++++++++++++--------- include/linux/kho/abi/pci.h | 5 +- include/linux/pci.h | 3 + 3 files changed, 99 insertions(+), 34 deletions(-) diff --git a/drivers/pci/liveupdate.c b/drivers/pci/liveupdate.c index ec8db86ed66d..825df024eec4 100644 --- a/drivers/pci/liveupdate.c +++ b/drivers/pci/liveupdate.c @@ -122,7 +122,6 @@ * preserved. These may be relaxed in the future: * * * The device cannot be a Virtual Function (VF). - * * The device cannot be behind a PCI-to-PCI bridge. * * Driver Binding * ============== @@ -137,6 +136,18 @@ * bound to the correct driver. The PCI core does not protect against a device * getting preserved by driver A in the outgoing kernel and then getting bound * to driver B in the incoming kernel. + * + * PCI-to-PCI Bridges + * ================== + * + * Any PCI-to-PCI bridges upstream of a preserved device are automatically + * preserved when the device is preserved. The PCI core keeps track of the + * number of downstream devices that are preserved under a bridge so that the + * bridge is only unpreserved once all downstream devices are unpreserved. + * + * This enables the PCI core and any drivers bound to the bridge to participate + * in the Live Update so that preserved endpoints can continue issuing memory + * transactions during the Live Update. */ #define pr_fmt(fmt) "PCI: liveupdate: " fmt @@ -407,55 +418,84 @@ static struct pci_dev_ser *pci_flb_alloc_dev_ser(struct pci_flb_outgoing *outgoi return dev_ser; } -static void pci_liveupdate_unpreserve_device(struct pci_flb_outgoing *outgoing, - struct pci_dev *dev) +static int pci_liveupdate_unpreserve_device(struct pci_flb_outgoing *outgoing, + struct pci_dev *dev) { struct pci_dev_ser *dev_ser = dev->liveupdate.outgoing; if (!dev_ser) { pci_warn(dev, "Cannot unpreserve device that is not preserved\n"); - return; + return -EINVAL; } + if (!dev_ser->refcount) { + pci_WARN(dev, 1, "Preserved device has a 0 refcount!\n"); + return -EINVAL; + } + + if (--dev_ser->refcount) + return 0; + pci_info(dev, "Device will no longer be preserved across next Live Update\n"); outgoing->ser->nr_devices--; memset(dev_ser, 0, sizeof(*dev_ser)); dev->liveupdate.outgoing = NULL; + return 0; +} + +static void pci_liveupdate_unpreserve_path(struct pci_flb_outgoing *outgoing, + struct pci_dev *dev, + struct pci_dev *end) +{ + for_each_pci_dev_in_path(dev) { + if (dev == end) + break; + + if (pci_liveupdate_unpreserve_device(outgoing, dev)) + return; + } } static int pci_liveupdate_preserve_device(struct pci_flb_outgoing *outgoing, struct pci_dev *dev) { - struct pci_dev_ser *dev_ser; - if (dev->is_virtfn) { pci_warn(dev, "Cannot preserve Virtual Functions\n"); return -EINVAL; } - if (dev->liveupdate.outgoing) { + /* + * Endpoint devices should not be preserved more than once. + * Bridges are preserved once for every downstream device that + * is preserved. + */ + if (dev->liveupdate.outgoing && !dev->subordinate) { pci_warn(dev, "Device is already preserved\n"); return -EBUSY; } - if (!pci_is_root_bus(dev->bus)) { - pci_warn(dev, "Cannot preserve devices behind bridges\n"); + if (dev->liveupdate.outgoing && !dev->liveupdate.outgoing->refcount) { + pci_WARN(dev, 1, "Preserved device with 0 refcount!\n"); return -EINVAL; } - dev_ser = pci_flb_alloc_dev_ser(outgoing); - if (IS_ERR(dev_ser)) - return PTR_ERR(dev_ser); + if (!dev->liveupdate.outgoing) { + struct pci_dev_ser *dev_ser; - pci_info(dev, "Device will be preserved across next Live Update\n"); - outgoing->ser->nr_devices++; - outgoing->ser->devices = kho_block_set_head_pa(&outgoing->block_set); + dev_ser = pci_flb_alloc_dev_ser(outgoing); + if (IS_ERR(dev_ser)) + return PTR_ERR(dev_ser); - dev_ser->domain = pci_domain_nr(dev->bus); - dev_ser->bdf = pci_dev_id(dev); - dev_ser->refcount++; + pci_info(dev, "Device will be preserved across next Live Update\n"); + outgoing->ser->nr_devices++; + outgoing->ser->devices = kho_block_set_head_pa(&outgoing->block_set); + + dev_ser->domain = pci_domain_nr(dev->bus); + dev_ser->bdf = pci_dev_id(dev); + dev->liveupdate.outgoing = dev_ser; + } - dev->liveupdate.outgoing = dev_ser; + dev->liveupdate.outgoing->refcount++; return 0; } @@ -468,12 +508,16 @@ static int pci_liveupdate_preserve_device(struct pci_flb_outgoing *outgoing, * pci_liveupdate_preserve() from their struct liveupdate_file_handler * preserve() callback to ensure the outgoing struct pci_ser is already set up. * + * pci_liveupdate_preserve() automatically preserves all bridges upstream of + * @dev. + * * Returns: 0 on success, <0 on failure. */ int pci_liveupdate_preserve(struct pci_dev *dev) { struct pci_flb_outgoing *outgoing = NULL; - int ret; + struct pci_dev *start = dev; + int ret = -ENODEV; guard(rwsem_write)(&pci_liveupdate.rwsem); @@ -481,7 +525,13 @@ int pci_liveupdate_preserve(struct pci_dev *dev) if (IS_ERR(outgoing)) return PTR_ERR(outgoing); - ret = pci_liveupdate_preserve_device(outgoing, dev); + for_each_pci_dev_in_path(dev) { + ret = pci_liveupdate_preserve_device(outgoing, dev); + if (ret) { + pci_liveupdate_unpreserve_path(outgoing, start, dev); + break; + } + } pci_liveupdate_flb_put_outgoing(); return ret; @@ -497,6 +547,9 @@ EXPORT_SYMBOL_GPL(pci_liveupdate_preserve); * pci_liveupdate_unpreserve() from their struct liveupdate_file_handler * unpreserve() callback to ensure the outgoing struct pci_ser is already set * up. + * + * pci_liveupdate_unpreserve() automatically unpreserves all bridges upstream of + * @dev. */ void pci_liveupdate_unpreserve(struct pci_dev *dev) { @@ -510,7 +563,7 @@ void pci_liveupdate_unpreserve(struct pci_dev *dev) return; } - pci_liveupdate_unpreserve_device(outgoing, dev); + pci_liveupdate_unpreserve_path(outgoing, dev, /*end=*/NULL); pci_liveupdate_flb_put_outgoing(); } EXPORT_SYMBOL_GPL(pci_liveupdate_unpreserve); @@ -600,28 +653,30 @@ void pci_liveupdate_cleanup_device(struct pci_dev *dev) pci_WARN(dev, 1, "Destroying incoming-preserved device!\n"); } -static void pci_liveupdate_finish_device(struct pci_ser *ser, struct pci_dev *dev) +static int pci_liveupdate_finish_device(struct pci_ser *ser, struct pci_dev *dev) { if (!dev->liveupdate.incoming) { pci_warn(dev, "Cannot finish preserving an unpreserved device\n"); - return; + return -EINVAL; } - if (dev->liveupdate.incoming->refcount != 1) { - pci_WARN(dev, 1, "Preserved device has a corrupted refcount!\n"); - return; + if (!dev->liveupdate.incoming->refcount) { + pci_WARN(dev, 1, "Preserved device has a 0 refcount!\n"); + return -EINVAL; } /* - * Drop the refcount so this device does not get treated as an incoming - * device again, e.g. in case pci_liveupdate_setup_device() gets called - * again because the device is hot-plugged. + * Decrement the refcount so this device does not get treated as an + * incoming device again, e.g. in case pci_liveupdate_setup_device() + * gets called again because the device is hot-plugged. */ - dev->liveupdate.incoming->refcount = 0; + if (--dev->liveupdate.incoming->refcount) + return 0; pci_info(dev, "Device is finished participating in Live Update\n"); dev->liveupdate.incoming = NULL; ser->nr_devices--; + return 0; } /** @@ -633,6 +688,8 @@ static void pci_liveupdate_finish_device(struct pci_ser *ser, struct pci_dev *de * Update. Drivers must call pci_liveupdate_finish() from their struct * liveupdate_file_handler finish() callback to ensure the incoming struct * pci_ser is allocated. + * + * pci_liveupdate_finish() automatically finishes all bridges upstream of @dev. */ void pci_liveupdate_finish(struct pci_dev *dev) { @@ -646,7 +703,11 @@ void pci_liveupdate_finish(struct pci_dev *dev) return; } - pci_liveupdate_finish_device(incoming->ser, dev); + for_each_pci_dev_in_path(dev) { + if (pci_liveupdate_finish_device(incoming->ser, dev)) + break; + } + pci_liveupdate_flb_put_incoming(); } EXPORT_SYMBOL_GPL(pci_liveupdate_finish); diff --git a/include/linux/kho/abi/pci.h b/include/linux/kho/abi/pci.h index 4096e3cd3324..9485ed73c351 100644 --- a/include/linux/kho/abi/pci.h +++ b/include/linux/kho/abi/pci.h @@ -24,7 +24,7 @@ */ #define PCI_LUO_FLB_COMPATIBLE "pci" -#define PCI_LUO_FLB_VERSION 1 +#define PCI_LUO_FLB_VERSION 2 /** * struct pci_dev_ser - Serialized state about a single PCI device. @@ -33,7 +33,8 @@ * @bdf: The device's PCI bus, device, and function number. * @refcount: Reference count used by the PCI core to keep track of whether it * is done using a device's struct pci_dev_ser. The value of the - * refcount is equal to 1 when the struct pci_dev_ser is in use, and + * refcount is equal to the number of preserved devices at or below + * it in the PCI hierarchy when the struct pci_dev_ser is in use, and * 0 otherwise. */ struct pci_dev_ser { diff --git a/include/linux/pci.h b/include/linux/pci.h index 76abe884e3dc..b35ac263c451 100644 --- a/include/linux/pci.h +++ b/include/linux/pci.h @@ -836,6 +836,9 @@ static inline struct pci_dev *pci_upstream_bridge(struct pci_dev *dev) return dev->bus->self; } +#define for_each_pci_dev_in_path(dev) \ + for (; dev; dev = pci_upstream_bridge(dev)) + #ifdef CONFIG_PCI_MSI static inline bool pci_dev_msi_enabled(struct pci_dev *pci_dev) { -- 2.55.0.1082.g2b9226bbc0-goog