From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 212EB2DFA4A for ; Mon, 21 Sep 2026 00:48:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951734; cv=none; b=Iqe+tys6c6TvI6NRV1aAkMm863b2kqmmRwmXOndqWBafHKus2ay1C5x9WlJyFp5sjAdPlS17IGbb/Tb2+fUOSQ+zQFGwFIFGZrm0u8qRZZfmlxIGNL1any8SkZ/wTSBWmfk6HgvwrFJz2oDfpQAyMiYWpf+H4NU+k5hDbIzjbXI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951734; c=relaxed/simple; bh=nPezMDYp5xpL65qddw2WVC7a5eW4PH+MLRIAj/7Q7y8=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=D9YWyeeFb2UIwLtLNlPLgo9QVaG/NuMclcduJ+Y/r+f7WVUwjYKcd3Bw/QXz2Vt1wvlrd1UxUxeU7M91HHUwCVOS51jabFlfaDZOyOKqd8yD6vnDsw7SvQ5eDU2hRuqXyAr2wKtL+Z94mtiYyA58wgRqR3UYccq82jWTb6Xo6K4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=EQnUPG68; arc=none smtp.client-ip=209.85.215.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="EQnUPG68" Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cc1cade6b71so2376149a12.0 for ; Sun, 20 Sep 2026 17:48:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789951726; x=1790556526; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=UKH4Gc6Z+bMWga98+CS78z+EWlxfzC75QI3yKAEUybQ=; b=EQnUPG68SwnLY+W7u779YyeTdXSDqsUXqmw/oWzRoN+e3R0kW8fEfC0PR7wdWw4nDP 99iVPCcjOxBX23kmVM66r1LzIProL3lkVzJ9eaMdVk4zvvT0Lv/oOFYxBPdseYLswOvK 9A1YpB5QhC44CAHyj6o2yam9FiF1rTNE8veYb0KTLv58Ebq3I+CIRkC/jkEr3BnCjEmi xQhuCpLAalFoKjY3hOzk2bRp8p/ym6bnToDoHXVlI9LQSOea6NUbZYDc79UP7/s3Y0UL BnJxLbVg9qhcS15B6WZTggkF46er2PZgEDbTtZ99WBK2Z6JWBcNNqBicZEnWavaLCcVr 9gpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789951726; x=1790556526; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UKH4Gc6Z+bMWga98+CS78z+EWlxfzC75QI3yKAEUybQ=; b=eDTtDttVStOShyIYEW5at5Z7BTLoL4GgihHTOUyReqhqR5jeV9lEUr71GX3zZGmYEK EVgesLqllUcuhmIZT3oe7cs5lJx839kY5bTNe0Ejut7k4r/16rH7mC0EJLBG1KKjS9La /JdAEXemxv7VOtXSRiOvkO4CvnchihlwdOcv8PTorXLDdFstwE3IHt77FvN+3sgiVbAx 8KPW0ioyHTr0BMcyJa+lVPPT+bIYSX2HrziljGVQkAF/+S2Brkjs5wFXaCh4H46Z85LL bv351H43IiIg7KZ4lJ4+P5NeQk5c6AqvFv0U9D6Xar0weZJ8pv0fKyHGJQy9usy1A+xD NAGA== X-Forwarded-Encrypted: i=1; AKwUvBwAUi7jMX8NZ4Y4fr/b4XCR/g1TOZB977tSp22wOxLwnFRx2C6T8YeI1zhNm9dONCRlzUI=@vger.kernel.org X-Gm-Message-State: AFuF++n8buGp5jQpwnbnHjXNXBerit4pnE0xVCVBhuOxJ0z127JaJ0AV Y8pkxILjBAj+1NXacKwxjmsuhgQ1SYgrXMcREYxXAMH71NnSu8cKAsWLRYXFNn5MOuwjiIYRpxq Otni1OIcsV1JvPg== X-Received: from plao7.prod.google.com ([2002:a17:903:3007:b0:2df:4e63:c417]) (user=skhawaja job=prod-delivery.src-stubby-dispatcher) by 2002:a17:903:3b86:b0:2dd:c100:251d with SMTP id d9443c01a7336-2ddc10025a3mr60411435ad.38.1789951725377; Sun, 20 Sep 2026 17:48:45 -0700 (PDT) Date: Mon, 21 Sep 2026 00:48:21 +0000 In-Reply-To: <20260921004834.2601285-1-skhawaja@google.com> Precedence: bulk X-Mailing-List: kvm@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921004834.2601285-1-skhawaja@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921004834.2601285-6-skhawaja@google.com> Subject: [PATCH v5 05/18] iommu: Implement IOMMU domain preservation From: Samiullah Khawaja To: David Woodhouse , Lu Baolu , Joerg Roedel , Will Deacon , Jason Gunthorpe Cc: Samiullah Khawaja , Pranjal Shrivastava , Robin Murphy , Kevin Tian , Alex Williamson , Shuah Khan , iommu@lists.linux.dev, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Pratyush Yadav , Pasha Tatashin , David Matlack , Andrew Morton , Vipin Sharma Content-Type: text/plain; charset="UTF-8" Add IOMMU domain ops that can be implemented by the IOMMU drivers if they support IOMMU domain preservation across liveupdate. The new IOMMU domain preserve, unpreserve and restore APIs call these ops to perform respective live update operations. Reviewed-by: Pranjal Shrivastava Signed-off-by: Samiullah Khawaja --- drivers/iommu/liveupdate.c | 128 +++++++++++++++++++++++++++++++ include/linux/iommu-liveupdate.h | 11 +++ include/linux/iommu.h | 5 ++ 3 files changed, 144 insertions(+) diff --git a/drivers/iommu/liveupdate.c b/drivers/iommu/liveupdate.c index b644f4792532..be542efbb023 100644 --- a/drivers/iommu/liveupdate.c +++ b/drivers/iommu/liveupdate.c @@ -37,11 +37,15 @@ #define pr_fmt(fmt) "iommu: liveupdate: " fmt #include +#include #include #include #include #include +#define iommu_max_objs_per_page(_array) \ + ((PAGE_SIZE - sizeof(struct iommu_array_hdr_ser)) / sizeof((_array)->objects[0])) + struct iommu_flb_obj { struct mutex lock; struct iommu_flb_ser *ser; @@ -251,3 +255,127 @@ void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler) liveupdate_unregister_flb(handler, &iommu_flb); } EXPORT_SYMBOL(iommu_liveupdate_unregister_flb); + +static int alloc_object_ser(void **curr_array_ptr, u64 max_objs) +{ + struct iommu_array_hdr_ser *curr_array = *curr_array_ptr; + struct iommu_array_hdr_ser *next_array; + + /* + * The objects marked as deleted are not reused to avoid traversal of + * linked-list and arrays. + */ + if (curr_array->nr_objects >= max_objs) { + next_array = kho_alloc_preserve(PAGE_SIZE); + if (IS_ERR(next_array)) + return PTR_ERR(next_array); + + curr_array->next_array_phys = virt_to_phys(next_array); + *curr_array_ptr = next_array; + curr_array = next_array; + } + + return curr_array->nr_objects++; +} + +static struct iommu_domain_ser *alloc_iommu_domain_ser(struct iommu_flb_obj *flb) +{ + int idx; + + idx = alloc_object_ser((void **) &flb->curr_domain_array, + iommu_max_objs_per_page(flb->curr_domain_array)); + if (idx < 0) + return ERR_PTR(idx); + + flb->curr_domain_array->objects[idx].hdr.ref_count = 1; + return &flb->curr_domain_array->objects[idx]; +} + +/** + * iommu_preserve_domain() - Preserve an IOMMU domain across live update + * @domain: Domain to preserve + * @ser: Pointer to receive the virtual serialized domain state handle + * + * Return: 0 on success, or negative error code. + */ +int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser) +{ + struct pt_iommu *pt = iommupt_from_domain(domain); + struct iommu_domain_ser *domain_ser; + struct iommu_flb_obj *flb_obj; + int ret; + + if (!pt || !pt->ops->preserve || !pt->ops->unpreserve) + return -EOPNOTSUPP; + + ret = liveupdate_flb_get_outgoing(&iommu_flb, (void **)&flb_obj); + if (ret) + return ret; + + mutex_lock(&flb_obj->lock); + if (domain->preserved_state) { + ret = -EBUSY; + goto out_unlock; + } + + domain_ser = alloc_iommu_domain_ser(flb_obj); + if (IS_ERR(domain_ser)) { + ret = PTR_ERR(domain_ser); + goto out_unlock; + } + + ret = pt->ops->preserve(pt, domain_ser); + if (ret) { + domain_ser->hdr.flags |= IOMMU_SER_FLAG_DELETED; + goto out_unlock; + } + + domain->preserved_state = domain_ser; + *ser = domain_ser; + ret = 0; +out_unlock: + mutex_unlock(&flb_obj->lock); + liveupdate_flb_put_outgoing(&iommu_flb); + return ret; +} +EXPORT_SYMBOL_GPL(iommu_preserve_domain); + +/** + * iommu_unpreserve_domain() - Unpreserve a preserved IOMMU domain + * @domain: Domain to unpreserve + */ +void iommu_unpreserve_domain(struct iommu_domain *domain) +{ + struct pt_iommu *pt = iommupt_from_domain(domain); + struct iommu_domain_ser *domain_ser; + struct iommu_flb_obj *flb_obj; + int ret; + + if (WARN_ON(!pt || !pt->ops->unpreserve)) + return; + + ret = liveupdate_flb_get_outgoing(&iommu_flb, (void **)&flb_obj); + if (WARN_ON(ret)) + return; + + mutex_lock(&flb_obj->lock); + if (!domain->preserved_state) + goto out_unlock; + + /* + * There is no check for attached devices here. The correctness relies + * on the Live Update Orchestrator's session lifecycle. All resources + * (iommufd, vfio devices) are preserved within a single session. If the + * session is torn down, the .unpreserve callbacks for all files will be + * invoked, ensuring a consistent cleanup without needing explicit + * refcounting for the serialized objects here. + */ + domain_ser = domain->preserved_state; + pt->ops->unpreserve(pt, domain_ser); + domain_ser->hdr.flags |= IOMMU_SER_FLAG_DELETED; + domain->preserved_state = NULL; +out_unlock: + mutex_unlock(&flb_obj->lock); + liveupdate_flb_put_outgoing(&iommu_flb); +} +EXPORT_SYMBOL_GPL(iommu_unpreserve_domain); diff --git a/include/linux/iommu-liveupdate.h b/include/linux/iommu-liveupdate.h index 4755ab3cd67a..caa9778eee2d 100644 --- a/include/linux/iommu-liveupdate.h +++ b/include/linux/iommu-liveupdate.h @@ -15,6 +15,8 @@ #ifdef CONFIG_IOMMU_LIVEUPDATE int iommu_liveupdate_register_flb(struct liveupdate_file_handler *handler); void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler); +int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser); +void iommu_unpreserve_domain(struct iommu_domain *domain); #else static inline int iommu_liveupdate_register_flb(struct liveupdate_file_handler *handler) { @@ -24,5 +26,14 @@ static inline int iommu_liveupdate_register_flb(struct liveupdate_file_handler * static inline void iommu_liveupdate_unregister_flb(struct liveupdate_file_handler *handler) { } + +static inline int iommu_preserve_domain(struct iommu_domain *domain, struct iommu_domain_ser **ser) +{ + return -EOPNOTSUPP; +} + +static inline void iommu_unpreserve_domain(struct iommu_domain *domain) +{ +} #endif #endif /* _LINUX_IOMMU_LIVEUPDATE_H */ diff --git a/include/linux/iommu.h b/include/linux/iommu.h index ac43b8b93f14..26de40d5a98e 100644 --- a/include/linux/iommu.h +++ b/include/linux/iommu.h @@ -14,6 +14,7 @@ #include #include #include +#include #include #define IOMMU_READ (1 << 0) @@ -249,6 +250,10 @@ struct iommu_domain { struct list_head next; }; }; + +#ifdef CONFIG_IOMMU_LIVEUPDATE + struct iommu_domain_ser *preserved_state; +#endif }; static inline bool iommu_is_dma_domain(struct iommu_domain *domain) -- 2.55.0.1082.g2b9226bbc0-goog