Linux-ARM-Kernel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Aneesh Kumar K.V <aneesh.kumar@kernel.org>
To: Marek Szyprowski <m.szyprowski@samsung.com>,
	iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
	linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev
Cc: Robin Murphy <robin.murphy@arm.com>,
	Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
	Steven Price <steven.price@arm.com>,
	Suzuki K Poulose <Suzuki.Poulose@arm.com>,
	Catalin Marinas <catalin.marinas@arm.com>,
	Jiri Pirko <jiri@resnulli.us>, Jason Gunthorpe <jgg@ziepe.ca>,
	Mostafa Saleh <smostafa@google.com>,
	Petr Tesarik <ptesarik@suse.com>,
	Alexey Kardashevskiy <aik@amd.com>,
	Dan Williams <dan.j.williams@intel.com>,
	Xu Yilun <yilun.xu@linux.intel.com>,
	linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org,
	Madhavan Srinivasan <maddy@linux.ibm.com>,
	Michael Ellerman <mpe@ellerman.id.au>,
	Nicholas Piggin <npiggin@gmail.com>,
	"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
	Alexander Gordeev <agordeev@linux.ibm.com>,
	Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
	Heiko Carstens <hca@linux.ibm.com>,
	Vasily Gorbik <gor@linux.ibm.com>,
	Christian Borntraeger <borntraeger@linux.ibm.com>,
	Sven Schnelle <svens@linux.ibm.com>,
	x86@kernel.org
Subject: Re: [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths
Date: Fri, 07 Aug 2026 14:51:35 +0530	[thread overview]
Message-ID: <yq5afr0q2sm8.fsf@kernel.org> (raw)
In-Reply-To: <85be992d-9567-433e-ae2e-64ae5483964d@samsung.com>

Marek Szyprowski <m.szyprowski@samsung.com> writes:

> On 25.07.2026 09:09, Aneesh Kumar K.V wrote:
>> "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org> writes:
>>> This series tracks confidential-computing shared DMA state through the
>>> dma-direct, dma-pool, and swiotlb paths so that encrypted and decrypted
>>> DMA buffers are handled consistently.
>>>
>>> Today, the direct DMA path mostly relies on force_dma_unencrypted() for
>>> shared/decrypted buffer handling. This series consolidates the
>>> force_dma_unencrypted() checks in the top-level functions and ensures
>>> that the remaining DMA interfaces use DMA attributes to make the correct
>>> decisions.
>>>
>>> The series separates mapping and allocation state:
>>> - DMA_ATTR_CC_SHARED describes the DMA address attribute requested for a
>>>   mapping. It tells the DMA mapping path that the DMA address must target
>>>   shared/decrypted memory.
>>> - __DMA_ATTR_ALLOC_CC_SHARED is an internal DMA-mapping attribute used only
>>>   by allocation paths after the DMA core decides that the backing pages
>>>   must be allocated as shared/decrypted memory.
>>>
>>> The series:
>>> - moves swiotlb-backed allocations out of __dma_direct_alloc_pages(),
>>> - uses __DMA_ATTR_ALLOC_CC_SHARED through the dma-direct alloc/free paths
>>> - teaches the atomic DMA pools to track encrypted versus decrypted
>>>   state
>>> - tracks swiotlb pool encryption state and enforces strict pool
>>>   selection
>>> - centralizes encrypted/decrypted pgprot handling in dma_pgprot() using
>>>   DMA attributes
>>> - passes DMA attributes down to dma_capable() so capability checks can
>>>   validate whether the selected DMA address encoding matches
>>>   DMA_ATTR_CC_SHARED
>>> - makes dma_direct_map_phys() choose the DMA address encoding from
>>>   DMA_ATTR_CC_SHARED and fall back to swiotlb when a shared DMA request
>>>   cannot use the direct mapping, which lets arm64 and x86 CCA guests stop
>>>   relying on SWIOTLB_FORCE for DMA mappings
>>> - use the selected swiotlb pool state to derive the returned DMA
>>>   address
>>> - reports CC_ATTR_GUEST_MEM_ENCRYPT for arm64 Realms, powerpc secure
>>>   guests, and s390 protected virtualization guests.
>>>
>>> Dependency:
>>> This series depends on the pKVM changes posted at:
>>> https://lore.kernel.org/all/20260603110522.3331819-1-smostafa@google.com
>>>
>>> Please merge this series only after the pKVM changes above are merged.
>>> Otherwise pKVM will be broken.
>>>
>> pKVM topic branch is now available 
>>
>> https://lore.kernel.org/all/178467286876.125042.12010461715645610054.b4-ty@kernel.org/
>>
>> https://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-next/coco
> I've just got back from my holiday's and I see that there is everything ready to give
> this patchset some tests in linux-next. I hope nothing will break.
>
> I've applied this patchset to dma-mapping-for-next, on top of pKVM topic branch with
> patch "[PATCH v8 17/23] dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED"
> rebased onto latest changes in arch/arm64/mm/init.c.
>

That might need a fix.

From 5a9af89e74e9e2671ed0a572af129ebfa6fd4640 Mon Sep 17 00:00:00 2001
From: "Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>
Date: Fri, 7 Aug 2026 13:14:51 +0530
Subject: [PATCH] arm64: swiotlb: Keep the default size for protected guests

Realm guests and protected KVM guests may require swiotlb for device DMA
even when all system RAM is addressable by the DMA zones.

Do not reduce the SWIOTLB buffer to the kmalloc-bouncing size for these
guests, as the reduced number of slots can be exhausted during CCA guest
operation.

Fixes: 30c5e45ee2c5 ("dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED")
Signed-off-by: Aneesh Kumar K.V (Arm) <aneesh.kumar@kernel.org>
---
 arch/arm64/mm/init.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/arch/arm64/mm/init.c b/arch/arm64/mm/init.c
index e308a7cabd12..24caaf10e755 100644
--- a/arch/arm64/mm/init.c
+++ b/arch/arm64/mm/init.c
@@ -339,7 +339,8 @@ void __init arch_mm_preinit(void)
 {
 	unsigned int flags = SWIOTLB_VERBOSE;
 
-	if (max_pfn <= PFN_DOWN(arm64_dma_phys_limit)) {
+	if (!cc_platform_has(CC_ATTR_GUEST_MEM_ENCRYPT) &&
+	    max_pfn <= PFN_DOWN(arm64_dma_phys_limit)) {
 		/*
 		 * If no bouncing needed for ZONE_DMA, reduce the swiotlb
 		 * buffer for kmalloc() bouncing to 1MB per 1GB of RAM.
-- 
2.43.0



  reply	other threads:[~2026-08-07  9:21 UTC|newest]

Thread overview: 70+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-17 18:04 [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 01/23] dma-direct: return struct page from dma_direct_alloc_from_pool() Aneesh Kumar K.V (Arm)
2026-07-21 11:54   ` Leon Romanovsky
2026-07-21 14:20     ` Aneesh Kumar K.V
2026-07-21 14:29       ` Leon Romanovsky
2026-07-21 15:10         ` Aneesh Kumar K.V
2026-07-21 15:33           ` Leon Romanovsky
2026-07-22 19:59             ` Jason Gunthorpe
2026-07-23  7:57               ` Leon Romanovsky
2026-07-25 14:34                 ` Jason Gunthorpe
2026-07-26  8:17                   ` Leon Romanovsky
2026-07-27  4:23                     ` Jason Gunthorpe
2026-07-27 11:40                       ` Leon Romanovsky
2026-07-28 12:31                     ` Aneesh Kumar K.V
2026-07-28 14:24   ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 02/23] dma-pool: fix page leak in atomic_pool_expand() cleanup Aneesh Kumar K.V (Arm)
2026-07-21 12:31   ` Leon Romanovsky
2026-07-21 14:41     ` Aneesh Kumar K.V
2026-07-21 15:34       ` Leon Romanovsky
2026-07-17 18:04 ` [PATCH v8 03/23] iommu/dma: Check atomic pool allocation result directly Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 04/23] dma: free atomic pool pages by physical address Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 05/23] swiotlb: Preserve allocation virtual address for dynamic pools Aneesh Kumar K.V (Arm)
2026-07-28 14:25   ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 06/23] s390: Expose protected virtualization through cc_platform_has() Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 07/23] dma-direct: swiotlb: handle swiotlb alloc/free outside __dma_direct_alloc_pages Aneesh Kumar K.V (Arm)
2026-07-28 14:26   ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 08/23] coco: arm64: s390: powerpc: Mark secure guests with CC_ATTR_GUEST_MEM_ENCRYPT Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 09/23] dma-mapping: Add internal shared allocation attribute Aneesh Kumar K.V (Arm)
2026-07-28 14:25   ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 10/23] dma-direct: use __DMA_ATTR_ALLOC_CC_SHARED in alloc/free paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 11/23] dma-pool: track decrypted atomic pools and select them via attrs Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference Aneesh Kumar K.V (Arm)
2026-07-28 14:41   ` Mostafa Saleh
2026-07-29  9:05     ` Aneesh Kumar K.V
2026-07-29 10:08       ` Mostafa Saleh
2026-07-29 12:42         ` Aneesh Kumar K.V
2026-08-04 14:20           ` Jason Gunthorpe
2026-08-05  9:10             ` Mostafa Saleh
2026-08-05 12:30               ` Jason Gunthorpe
2026-08-07 11:03                 ` Robin Murphy
2026-08-07 11:55                   ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 13/23] dma: swiotlb: track pool encryption state and honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 14/23] dma-mapping: make dma_pgprot() honor __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 15/23] dma-direct: pass attrs to dma_capable() for DMA_ATTR_CC_SHARED checks Aneesh Kumar K.V (Arm)
2026-07-28 14:30   ` Mostafa Saleh
2026-07-29  9:09     ` Aneesh Kumar K.V
2026-07-30 21:05       ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 16/23] dma-direct: Move dma_direct_map_phys() to dma/direct.c Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 17/23] dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-08-07  9:26   ` [PATCH] arm64: swiotlb: Keep the default size for protected guests Aneesh Kumar K.V (Arm)
2026-08-07 11:58     ` Will Deacon
2026-08-07 13:03       ` Aneesh Kumar K.V
2026-07-17 18:04 ` [PATCH v8 18/23] dma-direct: set decrypted flag for remapped DMA allocations Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 19/23] dma-direct: select DMA address encoding from __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-28 14:31   ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 20/23] dma-direct: rename ret to cpu_addr in alloc helpers Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 21/23] dma: swiotlb: free dynamic pools from process context Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 22/23] dma: swiotlb: handle set_memory_decrypted() failures Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 23/23] swiotlb: remove unused SWIOTLB_FORCE flag Aneesh Kumar K.V (Arm)
2026-07-21 12:40 ` [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Leon Romanovsky
2026-07-22 19:57   ` Jason Gunthorpe
2026-07-23  7:51     ` Leon Romanovsky
2026-07-25 14:32       ` Jason Gunthorpe
2026-07-25  7:09 ` Aneesh Kumar K.V
2026-07-31  7:33   ` Marek Szyprowski
2026-08-07  9:21     ` Aneesh Kumar K.V [this message]
2026-08-07  9:51     ` Mostafa Saleh
2026-08-07 10:04       ` Marek Szyprowski
2026-07-28 14:22 ` Mostafa Saleh
2026-07-29  9:12   ` Aneesh Kumar K.V

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=yq5afr0q2sm8.fsf@kernel.org \
    --to=aneesh.kumar@kernel.org \
    --cc=Suzuki.Poulose@arm.com \
    --cc=agordeev@linux.ibm.com \
    --cc=aik@amd.com \
    --cc=borntraeger@linux.ibm.com \
    --cc=catalin.marinas@arm.com \
    --cc=chleroy@kernel.org \
    --cc=dan.j.williams@intel.com \
    --cc=gerald.schaefer@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=iommu@lists.linux.dev \
    --cc=jgg@ziepe.ca \
    --cc=jiri@resnulli.us \
    --cc=linux-arm-kernel@lists.infradead.org \
    --cc=linux-coco@lists.linux.dev \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=linuxppc-dev@lists.ozlabs.org \
    --cc=m.szyprowski@samsung.com \
    --cc=maddy@linux.ibm.com \
    --cc=maz@kernel.org \
    --cc=mpe@ellerman.id.au \
    --cc=npiggin@gmail.com \
    --cc=ptesarik@suse.com \
    --cc=robin.murphy@arm.com \
    --cc=smostafa@google.com \
    --cc=steven.price@arm.com \
    --cc=svens@linux.ibm.com \
    --cc=will@kernel.org \
    --cc=x86@kernel.org \
    --cc=yilun.xu@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox