From: Karl Mehltretter <kmehltretter@gmail.com>
To: iommu@lists.linux.dev, dri-devel@lists.freedesktop.org
Cc: "Karl Mehltretter" <kmehltretter@gmail.com>,
"Diederik de Haas" <diederik@cknow-tech.com>,
"Joerg Roedel" <joro@8bytes.org>, "Will Deacon" <will@kernel.org>,
"Robin Murphy" <robin.murphy@arm.com>,
"Sandy Huang" <hjc@rock-chips.com>,
"Heiko Stübner" <heiko@sntech.de>, "Andy Yan" <andyshrk@163.com>,
"Maarten Lankhorst" <maarten.lankhorst@linux.intel.com>,
"Maxime Ripard" <mripard@kernel.org>,
"Thomas Zimmermann" <tzimmermann@suse.de>,
"David Airlie" <airlied@gmail.com>,
"Simona Vetter" <simona@ffwll.ch>,
"Sumit Semwal" <sumit.semwal@linaro.org>,
"Christian König" <christian.koenig@amd.com>,
"Rob Clark" <robin.clark@oss.qualcomm.com>,
"Jason Gunthorpe" <jgg@nvidia.com>,
"Marek Szyprowski" <m.szyprowski@samsung.com>,
"Jianfeng Liu" <liujianfeng1994@gmail.com>,
linux-media@vger.kernel.org, linaro-mm-sig@lists.linaro.org,
linux-rockchip@lists.infradead.org,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org
Subject: [RFC PATCH 1/2] iommu: Add iommu_map_sgtable_dma()
Date: Fri, 9 Oct 2026 02:21:13 +0200 [thread overview]
Message-ID: <20261009002114.67851-2-kmehltretter@gmail.com> (raw)
In-Reply-To: <20261009002114.67851-1-kmehltretter@gmail.com>
DMA-BUF attachments provide DMA addresses, not CPU-side pages.
iommu_map_sgtable() needs those pages, so private-domain importers such
as Rockchip cannot use it with strict DMABUF_DEBUG.
Add an iommu-dma helper to map a live attachment into another domain by
translating through the device's default DMA domain. Roll back target
mappings on error. This still recovers physical addresses internally.
Only non-bounced iommu-dma mappings are supported. Other DMA backends,
marked bus addresses and zero translations return -EOPNOTSUPP, as does
the IOMMU_DMA=n stub. A zero lookup cannot distinguish a hole from PA0.
Reject bounce slots because a second mapping cannot keep them in sync
with writes to the original buffer.
DMABUF_DEBUG currently drops DMA flags from its copy, so the bus-address
check depends on the input retaining that mark.
Assisted-by: LLM
Signed-off-by: Karl Mehltretter <kmehltretter@gmail.com>
---
drivers/iommu/dma-iommu.c | 131 ++++++++++++++++++++++++++++++++++++++
include/linux/iommu.h | 12 ++++
2 files changed, 143 insertions(+)
diff --git a/drivers/iommu/dma-iommu.c b/drivers/iommu/dma-iommu.c
index 58c624513cd4..b9a1f91ec5db 100644
--- a/drivers/iommu/dma-iommu.c
+++ b/drivers/iommu/dma-iommu.c
@@ -38,6 +38,137 @@
#include "dma-iommu.h"
#include "iommu-pages.h"
+/**
+ * iommu_map_sgtable_dma - map the DMA side of an sg_table into a domain
+ * @domain: domain to map into
+ * @iova: IOVA of the first byte
+ * @dev: device for which @sgt is mapped
+ * @sgt: live DMA-API mapping for @dev, backed by non-bounced RAM
+ * @prot: IOMMU protection flags
+ *
+ * Translate the DMA addresses through @dev's default iommu-dma domain and
+ * map the backing memory into @domain without reading the CPU side of @sgt.
+ * Direct DMA and other DMA backends are not supported. Entries marked as
+ * PCI P2P bus addresses and SWIOTLB bounce buffers are also not supported.
+ *
+ * The caller must keep the source mapping, DMA backend and default domain
+ * unchanged until the target mapping is removed. This function may sleep.
+ * DMA addresses and lengths must be aligned to the smaller of the source
+ * and target domains' minimum page sizes. @iova and the total length must
+ * be aligned to the target domain's minimum page size.
+ *
+ * A zero reverse translation is unsupported: iommu_iova_to_phys() cannot
+ * distinguish an absent mapping from a mapping to physical address zero.
+ *
+ * Return: the number of bytes mapped, -EOPNOTSUPP for unsupported source
+ * mappings or source alignment, or another negative errno on error. Any
+ * target mappings installed by this call are removed on error.
+ */
+ssize_t iommu_map_sgtable_dma(struct iommu_domain *domain, unsigned long iova,
+ struct device *dev, struct sg_table *sgt,
+ int prot)
+{
+ struct iommu_domain *dma_domain;
+ size_t len = 0, mapped = 0, total = 0;
+ struct scatterlist *sg;
+ size_t granule, target_granule;
+ phys_addr_t start = 0;
+ unsigned long last_iova;
+ unsigned int i;
+ int ret;
+
+ if (!domain->pgsize_bitmap)
+ return -EINVAL;
+
+ target_granule = 1UL << __ffs(domain->pgsize_bitmap);
+ if (!use_dma_iommu(dev))
+ return -EOPNOTSUPP;
+ dma_domain = iommu_get_dma_domain(dev);
+ if (!dma_domain || !dma_domain->pgsize_bitmap)
+ return -EOPNOTSUPP;
+ granule = min(target_granule,
+ 1UL << __ffs(dma_domain->pgsize_bitmap));
+
+ for_each_sgtable_dma_sg(sgt, sg, i) {
+ dma_addr_t last_dma;
+ size_t dma_len = sg_dma_len(sg);
+
+ if (sg_dma_is_bus_address(sg))
+ return -EOPNOTSUPP;
+ if (!dma_len || !IS_ALIGNED(sg_dma_address(sg), granule) ||
+ !IS_ALIGNED(dma_len, granule))
+ return -EOPNOTSUPP;
+ if (check_add_overflow(sg_dma_address(sg), dma_len - 1,
+ &last_dma) ||
+ check_add_overflow(total, dma_len, &total))
+ return -EOVERFLOW;
+ }
+ if (!total)
+ return 0;
+ if (total > SSIZE_MAX || !IS_ALIGNED(iova, target_granule) ||
+ !IS_ALIGNED(total, target_granule))
+ return -EINVAL;
+ if (check_add_overflow(iova, total - 1, &last_iova))
+ return -EOVERFLOW;
+
+ for_each_sgtable_dma_sg(sgt, sg, i) {
+ dma_addr_t dma_addr = sg_dma_address(sg);
+ size_t dma_len = sg_dma_len(sg);
+
+ while (dma_len) {
+ phys_addr_t next;
+ phys_addr_t phys;
+
+ phys = iommu_iova_to_phys(dma_domain, dma_addr);
+ if (!phys || swiotlb_find_pool(dev, phys)) {
+ ret = -EOPNOTSUPP;
+ goto out_err;
+ }
+
+ if (len && check_add_overflow(start, len, &next)) {
+ ret = -EOVERFLOW;
+ goto out_err;
+ }
+ if (len && phys != next) {
+ ret = iommu_map_nosync(domain, iova + mapped,
+ start, len, prot,
+ GFP_KERNEL);
+ if (ret)
+ goto out_err;
+ mapped += len;
+ len = 0;
+ }
+ if (!len)
+ start = phys;
+ if (check_add_overflow(len, granule, &len)) {
+ ret = -EOVERFLOW;
+ goto out_err;
+ }
+ dma_addr += granule;
+ dma_len -= granule;
+ }
+ }
+
+ if (len) {
+ ret = iommu_map_nosync(domain, iova + mapped, start, len, prot,
+ GFP_KERNEL);
+ if (ret)
+ goto out_err;
+ mapped += len;
+ }
+
+ ret = iommu_sync_map(domain, iova, mapped);
+ if (ret)
+ goto out_err;
+
+ return mapped;
+
+out_err:
+ iommu_unmap(domain, iova, mapped);
+ return ret;
+}
+EXPORT_SYMBOL_GPL(iommu_map_sgtable_dma);
+
struct iommu_dma_msi_page {
struct list_head list;
dma_addr_t iova;
diff --git a/include/linux/iommu.h b/include/linux/iommu.h
index ac43b8b93f14..95d90c7f953b 100644
--- a/include/linux/iommu.h
+++ b/include/linux/iommu.h
@@ -1604,8 +1604,20 @@ static inline void iommu_debugfs_setup(void) {}
#endif
#ifdef CONFIG_IOMMU_DMA
+ssize_t iommu_map_sgtable_dma(struct iommu_domain *domain, unsigned long iova,
+ struct device *dev, struct sg_table *sgt,
+ int prot);
int iommu_get_msi_cookie(struct iommu_domain *domain, dma_addr_t base);
#else /* CONFIG_IOMMU_DMA */
+static inline ssize_t iommu_map_sgtable_dma(struct iommu_domain *domain,
+ unsigned long iova,
+ struct device *dev,
+ struct sg_table *sgt,
+ int prot)
+{
+ return -EOPNOTSUPP;
+}
+
static inline int iommu_get_msi_cookie(struct iommu_domain *domain, dma_addr_t base)
{
return -ENODEV;
--
2.53.0
next prev parent reply other threads:[~2026-10-09 0:21 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 0:21 [RFC PATCH 0/2] iommu, drm/rockchip: Map private-domain imports from DMA addresses Karl Mehltretter
2026-10-09 0:21 ` Karl Mehltretter [this message]
2026-10-09 14:43 ` [RFC PATCH 1/2] iommu: Add iommu_map_sgtable_dma() Jason Gunthorpe
2026-10-09 0:21 ` [RFC PATCH 2/2] drm/rockchip: Map imported buffers from DMA addresses Karl Mehltretter
2026-10-09 13:45 ` [RFC PATCH 0/2] iommu, drm/rockchip: Map private-domain imports " Robin Murphy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009002114.67851-2-kmehltretter@gmail.com \
--to=kmehltretter@gmail.com \
--cc=airlied@gmail.com \
--cc=andyshrk@163.com \
--cc=christian.koenig@amd.com \
--cc=diederik@cknow-tech.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=heiko@sntech.de \
--cc=hjc@rock-chips.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@nvidia.com \
--cc=joro@8bytes.org \
--cc=linaro-mm-sig@lists.linaro.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=linux-rockchip@lists.infradead.org \
--cc=liujianfeng1994@gmail.com \
--cc=m.szyprowski@samsung.com \
--cc=maarten.lankhorst@linux.intel.com \
--cc=mripard@kernel.org \
--cc=robin.clark@oss.qualcomm.com \
--cc=robin.murphy@arm.com \
--cc=simona@ffwll.ch \
--cc=sumit.semwal@linaro.org \
--cc=tzimmermann@suse.de \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox