From: Bjorn Helgaas <helgaas@kernel.org>
To: David Matlack <dmatlack@google.com>
Cc: kexec@lists.infradead.org, linux-doc@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-mm@kvack.org,
linux-pci@vger.kernel.org,
Adithya Jayachandran <ajayachandra@nvidia.com>,
Alexander Graf <graf@amazon.com>,
Alex Williamson <alex@shazbot.org>,
Bjorn Helgaas <bhelgaas@google.com>, Chris Li <chrisl@kernel.org>,
David Rientjes <rientjes@google.com>,
Jacob Pan <jacob.pan@linux.microsoft.com>,
Jason Gunthorpe <jgg@nvidia.com>,
Jonathan Corbet <corbet@lwn.net>, Josh Hilke <jrhilke@google.com>,
Leon Romanovsky <leonro@nvidia.com>,
Lukas Wunner <lukas@wunner.de>, Mike Rapoport <rppt@kernel.org>,
Parav Pandit <parav@nvidia.com>,
Pasha Tatashin <pasha.tatashin@soleen.com>,
Pranjal Shrivastava <praan@google.com>,
Pratyush Yadav <pratyush@kernel.org>,
Saeed Mahameed <saeedm@nvidia.com>,
Samiullah Khawaja <skhawaja@google.com>,
Shuah Khan <skhan@linuxfoundation.org>,
Vipin Sharma <vipinsh@google.com>, William Tu <witu@nvidia.com>,
Yi Liu <yi.l.liu@intel.com>
Subject: Re: [PATCH v7 08/12] PCI: liveupdate: Inherit ACS flags in incoming preserved devices
Date: Mon, 27 Jul 2026 17:54:00 -0500 [thread overview]
Message-ID: <20260727225400.GA1268182@bhelgaas> (raw)
In-Reply-To: <20260710212616.1351130-9-dmatlack@google.com>
On Fri, Jul 10, 2026 at 09:26:11PM +0000, David Matlack wrote:
> Inherit Access Control Services (ACS) flags on all incoming preserved
> devices (endpoints and upstream bridges) during a Live Update.
>
> Inheriting ACS flags avoids changing routing rules while memory
> transactions are in flight from preserved devices. This is also strictly
> necessary to ensure that IOMMU group assignments do not change across
> a Live Update for preserved devices, as changing ACS configurations can
> split or merge IOMMU groups.
>
> Cache the inherited ACS controls established by the previous kernel in
> struct pci_dev so that ACS controls do not change after a reset
> (pci_restore_state() calls pci_enable_acs()).
>
> To simplify ACS inheritance, reject preserving any devices that require
> quirks to enable ACS as those quirks would also have to take Live Update
> into account.
>
> Signed-off-by: David Matlack <dmatlack@google.com>
> ---
> drivers/pci/liveupdate.c | 68 ++++++++++++++++++++++++++++++++++
> drivers/pci/liveupdate.h | 11 ++++++
> drivers/pci/pci.c | 6 +++
> drivers/pci/pci.h | 5 +++
> drivers/pci/quirks.c | 7 ++++
> include/linux/pci_liveupdate.h | 6 +++
> 6 files changed, 103 insertions(+)
>
> diff --git a/drivers/pci/liveupdate.c b/drivers/pci/liveupdate.c
> index 7f7710cb1da0..a95bfe5eff77 100644
> --- a/drivers/pci/liveupdate.c
> +++ b/drivers/pci/liveupdate.c
> @@ -71,6 +71,9 @@
> *
> * * The device cannot be a Virtual Function (VF).
> *
> + * * The device cannot require device-specific quirks to enable Access
> + * Control Services (ACS).
> + *
> * Driver Binding
> * ==============
> *
> @@ -113,6 +116,18 @@
> * This enables the PCI core and any drivers bound to the bridge to participate
> * in the Live Update so that preserved endpoints can continue issuing memory
> * transactions during the Live Update.
> + *
> + * Handling Preserved Devices
> + * ==========================
> + *
> + * The PCI core treats preserved devices differently than non-preserved devices.
> + * This section enumerates those differences.
> + *
> + * * The PCI core inherits all ACS flags enabled on incoming preserved devices
> + * rather than assigning new ones. This ensures that TLPs are routed the same
> + * way after Live Update and ensures that IOMMU groups do not change. Note
> + * that a device will use its inherited ACS flags for the lifetime of its
> + * struct pci_dev (i.e. even after pci_liveupdate_finish()).
> */
>
> #define pr_fmt(fmt) "PCI: " KBUILD_BASENAME ": " fmt
> @@ -128,6 +143,7 @@
> #include <linux/slab.h>
>
> #include "liveupdate.h"
> +#include "pci.h"
>
> /**
> * struct pci_liveupdate_global - Global state for PCI Live Update support
> @@ -374,6 +390,16 @@ static int __pci_liveupdate_preserve_device(struct pci_flb_outgoing *outgoing, s
> {
> struct pci_dev_ser *dev_ser;
>
> + /*
> + * Do not preserve devices that rely on device-specific ACS equivalents
> + * (for now) since that would complicate keeping ACS constant across
> + * Live Update.
> + */
> + if (pci_need_dev_specific_enable_acs(dev)) {
> + pci_warn(dev, "Refusing to preserve device that relies on ACS quirks\n");
> + return -EINVAL;
> + }
> +
> dev_ser = pci_get_empty_or_append(outgoing);
> if (IS_ERR(dev_ser))
> return PTR_ERR(dev_ser);
> @@ -655,6 +681,7 @@ void pci_liveupdate_setup_device(struct pci_dev *dev)
>
> pci_info(dev, "Device was preserved by previous kernel across Live Update\n");
> dev->liveupdate.incoming = dev_ser;
> + dev->liveupdate.was_preserved = true;
>
> /*
> * Hold the ref on the incoming FLB until pci_liveupdate_finish() so
> @@ -748,6 +775,47 @@ void pci_liveupdate_finish(struct pci_dev *dev)
> }
> EXPORT_SYMBOL_GPL(pci_liveupdate_finish);
>
> +void pci_liveupdate_init_acs(struct pci_dev *dev)
> +{
> + guard(rwsem_read)(&pci_liveupdate.rwsem);
> +
> + if (!dev->acs_cap || !dev->liveupdate.incoming)
> + return;
> +
> + pci_read_config_word(dev, dev->acs_cap + PCI_ACS_CTRL, &dev->liveupdate.acs_ctrl);
This is called from pci_acs_init(), which is called from
pci_init_capabilities() when we first enumerate a device, so it
captures PCI_ACS_CTRL at boot-time, which is before any
pci_enable_acs() calls. I don't think it will include the effect of
pci_std_enable_acs() (if an IOMMU driver called pci_request_acs() and
there was no device-specific quirk) or any command-line parameters
("pci=config_acs=").
I thought you would want to save the
PCI_ACS_CTRL value at the time of the liveupdate?
I'm having a hard time parsing pci_enable_acs(), so I'm sure I'm
missing something here.
> +}
> +
> +int pci_liveupdate_enable_acs(struct pci_dev *dev)
> +{
> + u16 acs_ctrl = dev->liveupdate.acs_ctrl;
> + u16 acs_cap = dev->acs_cap;
> +
> + /*
> + * Use liveupdate.was_preserved instead of liveupdate.incoming since the
> + * device's ACS controls should not change even after the device is
> + * finished participating in the Live Update.
> + */
> + if (!dev->liveupdate.was_preserved)
> + return -EINVAL;
I don't quite understand what's going on here.
Partly it's because the function name and return values don't seem
obvious to me. I guess returning 0 means "this device was preserved
across a liveupdate and we restored its previous ACS CTRL value, so
pci_enable_acs() doesn't need to do anything else."
Anything else means "device has not been preserved across a liveupdate
(or it was preserved but the new kernel added a device-specific ACS
quirk for it)."
But more fundamentally, after a liveupdate has completed, why does
pci_enable_acs() need to work differently than it would if there had
never been a liveupdate?
Maybe it's the comment that's confusing me. Returning -EINVAL means
pci_enable_acs() will continue on and potentially update ACS CTRL.
The comment suggests "ACS controls shouldn't change even after
liveupdate completes", but if we don't want pci_enable_acs() to do
anything, wouldn't we return 0 here?
I guess this part will be exercised by pci_restore_state(), e.g.,
during resume after suspend. I can't remember why we use
pci_enable_acs() there instead of saving ACS state in pci_save_state()
and then restoring it.
> + /*
> + * The previous kernel should not have preserved any devices that
> + * require device-specific quirks to enable ACS, but if such a device is
> + * detected (e.g. new device-specific ACS quirk in the current kernel),
> + * log a big warning and fall back to the normal enable ACS path.
> + */
> + if (pci_need_dev_specific_enable_acs(dev)) {
> + pci_warn(dev, "Device-specific quirk required to enable ACS!\n");
> + WARN_ON_ONCE(true);
> + return -EINVAL;
> + }
> +
> + if (acs_cap)
> + pci_write_config_word(dev, acs_cap + PCI_ACS_CTRL, acs_ctrl);
> +
> + return 0;
> +}
> +
> /**
> * pci_liveupdate_is_incoming() - Check if a device is incoming-preserved
> * @dev: The PCI device to check
> diff --git a/drivers/pci/liveupdate.h b/drivers/pci/liveupdate.h
> index c763255a8de4..4e8a01bcb4bb 100644
> --- a/drivers/pci/liveupdate.h
> +++ b/drivers/pci/liveupdate.h
> @@ -16,6 +16,8 @@ void pci_liveupdate_cleanup_device(struct pci_dev *dev);
> bool pci_liveupdate_scan_bridge_begin(struct pci_bus *bus, struct pci_dev *dev,
> int pass);
> void pci_liveupdate_scan_bridge_end(struct pci_dev *dev, int pass);
> +void pci_liveupdate_init_acs(struct pci_dev *dev);
> +int pci_liveupdate_enable_acs(struct pci_dev *dev);
> #else
> static inline void pci_liveupdate_setup_device(struct pci_dev *dev)
> {
> @@ -35,6 +37,15 @@ static inline bool pci_liveupdate_scan_bridge_begin(struct pci_bus *bus,
> static inline void pci_liveupdate_scan_bridge_end(struct pci_dev *dev, int pass)
> {
> }
> +
> +static inline void pci_liveupdate_init_acs(struct pci_dev *dev)
> +{
> +}
> +
> +static inline int pci_liveupdate_enable_acs(struct pci_dev *dev)
> +{
> + return -EINVAL;
> +}
> #endif
>
> #endif /* DRIVERS_PCI_LIVEUPDATE_H */
> diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c
> index 77b17b13ee61..739ecaab2e76 100644
> --- a/drivers/pci/pci.c
> +++ b/drivers/pci/pci.c
> @@ -34,6 +34,8 @@
> #include <linux/aer.h>
> #include <linux/bitfield.h>
> #include <linux/suspend.h>
> +
> +#include "liveupdate.h"
> #include "pci.h"
>
> DEFINE_MUTEX(pci_slot_mutex);
> @@ -1008,6 +1010,9 @@ void pci_enable_acs(struct pci_dev *dev)
> bool enable_acs = false;
> int pos;
>
> + if (!pci_liveupdate_enable_acs(dev))
> + return;
> +
> /* If an iommu is present we start with kernel default caps */
> if (pci_acs_enable) {
> if (pci_dev_specific_enable_acs(dev))
> @@ -3689,6 +3694,7 @@ void pci_acs_init(struct pci_dev *dev)
>
> pci_read_config_word(dev, pos + PCI_ACS_CAP, &dev->acs_capabilities);
> pci_disable_broken_acs_cap(dev);
> + pci_liveupdate_init_acs(dev);
> }
>
> /**
> diff --git a/drivers/pci/pci.h b/drivers/pci/pci.h
> index 4469e1a77f3c..988a18b3204a 100644
> --- a/drivers/pci/pci.h
> +++ b/drivers/pci/pci.h
> @@ -1047,6 +1047,7 @@ void pci_acs_init(struct pci_dev *dev);
> void pci_enable_acs(struct pci_dev *dev);
> #ifdef CONFIG_PCI_QUIRKS
> int pci_dev_specific_acs_enabled(struct pci_dev *dev, u16 acs_flags);
> +bool pci_need_dev_specific_enable_acs(struct pci_dev *dev);
> int pci_dev_specific_enable_acs(struct pci_dev *dev);
> int pci_dev_specific_disable_acs_redir(struct pci_dev *dev);
> void pci_disable_broken_acs_cap(struct pci_dev *pdev);
> @@ -1057,6 +1058,10 @@ static inline int pci_dev_specific_acs_enabled(struct pci_dev *dev,
> {
> return -ENOTTY;
> }
> +static inline bool pci_need_dev_specific_enable_acs(struct pci_dev *dev)
> +{
> + return false;
> +}
> static inline int pci_dev_specific_enable_acs(struct pci_dev *dev)
> {
> return -ENOTTY;
> diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
> index 7ac39ec2843e..99b819f38e49 100644
> --- a/drivers/pci/quirks.c
> +++ b/drivers/pci/quirks.c
> @@ -5473,6 +5473,13 @@ static const struct pci_dev_acs_ops *pci_dev_acs_ops_get(struct pci_dev *dev)
> return NULL;
> }
>
> +bool pci_need_dev_specific_enable_acs(struct pci_dev *dev)
> +{
> + const struct pci_dev_acs_ops *p = pci_dev_acs_ops_get(dev);
> +
> + return p && p->enable_acs;
> +}
> +
> int pci_dev_specific_enable_acs(struct pci_dev *dev)
> {
> const struct pci_dev_acs_ops *p = pci_dev_acs_ops_get(dev);
> diff --git a/include/linux/pci_liveupdate.h b/include/linux/pci_liveupdate.h
> index 2be98819e313..2446c6d237ca 100644
> --- a/include/linux/pci_liveupdate.h
> +++ b/include/linux/pci_liveupdate.h
> @@ -17,14 +17,20 @@
> * struct pci_liveupdate - PCI Live Update state for a struct pci_dev
> * @outgoing: State preserved for the next kernel.
> * @incoming: State preserved by the previous kernel.
> + * @acs_ctrl: ACS features established by the previous kernel.
> * @inherit_buses: True if the PCI core should inherit the secondary and
> * subordinate bus numbers assigned to this device due to
> * an ongoing Live Update.
> + * @was_preserved: True if this struct pci_dev was preserved by the previous
> + * kernel. Unlike @incoming, this field is not cleared after
> + * the device is finished participating in Live Update.
> */
> struct pci_liveupdate {
> struct pci_dev_ser *outgoing;
> struct pci_dev_ser *incoming;
> + u16 acs_ctrl;
> bool inherit_buses;
> + bool was_preserved;
> };
>
> struct pci_dev;
> --
> 2.55.0.795.g602f6c329a-goog
>
next prev parent reply other threads:[~2026-07-27 22:54 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-10 21:26 [PATCH v7 00/12] PCI: liveupdate: PCI core support for Live Update David Matlack
2026-07-10 21:26 ` [PATCH v7 01/12] PCI: liveupdate: Set up FLB handler for the PCI core David Matlack
2026-07-17 19:28 ` Pasha Tatashin
2026-07-17 19:30 ` Jason Gunthorpe
2026-07-17 19:40 ` Pasha Tatashin
2026-07-17 19:42 ` Pasha Tatashin
2026-07-23 22:21 ` Bjorn Helgaas
2026-07-27 17:40 ` David Matlack
2026-07-27 19:27 ` Bjorn Helgaas
2026-07-27 20:06 ` David Matlack
2026-07-10 21:26 ` [PATCH v7 02/12] PCI: liveupdate: Track outgoing preserved PCI devices David Matlack
2026-07-17 19:38 ` Pasha Tatashin
2026-07-23 22:29 ` Bjorn Helgaas
2026-07-24 20:32 ` Bjorn Helgaas
2026-07-10 21:26 ` [PATCH v7 03/12] PCI: liveupdate: Track incoming " David Matlack
2026-07-17 21:46 ` Pasha Tatashin
2026-07-20 21:54 ` David Matlack
2026-07-20 22:44 ` Pasha Tatashin
2026-07-20 23:07 ` David Matlack
2026-07-21 17:55 ` Pasha Tatashin
2026-07-21 20:25 ` David Matlack
2026-07-21 21:35 ` Pasha Tatashin
2026-07-21 23:02 ` Samiullah Khawaja
2026-07-21 23:16 ` David Matlack
2026-07-21 23:18 ` David Matlack
2026-07-21 23:46 ` Pasha Tatashin
2026-07-22 17:00 ` David Matlack
2026-07-17 22:38 ` Alex Williamson
2026-07-20 22:00 ` David Matlack
2026-07-22 16:10 ` David Matlack
2026-07-10 21:26 ` [PATCH v7 04/12] PCI: liveupdate: Document driver binding responsibilities David Matlack
2026-07-10 21:26 ` [PATCH v7 05/12] PCI: liveupdate: Keep bus numbers constant during Live Update David Matlack
2026-07-17 21:48 ` Pasha Tatashin
2026-07-23 23:01 ` Bjorn Helgaas
2026-07-10 21:26 ` [PATCH v7 06/12] PCI: liveupdate: Auto-preserve upstream bridges across " David Matlack
2026-07-17 22:00 ` Pasha Tatashin
2026-07-24 20:55 ` Bjorn Helgaas
2026-07-24 21:54 ` David Matlack
2026-07-10 21:26 ` [PATCH v7 07/12] PCI: Refactor matching logic for pci_dev_acs_ops David Matlack
2026-07-17 22:02 ` Pasha Tatashin
2026-07-24 21:03 ` Bjorn Helgaas
2026-07-10 21:26 ` [PATCH v7 08/12] PCI: liveupdate: Inherit ACS flags in incoming preserved devices David Matlack
2026-07-17 22:08 ` Pasha Tatashin
2026-07-27 22:54 ` Bjorn Helgaas [this message]
2026-07-27 23:11 ` David Matlack
2026-07-10 21:26 ` [PATCH v7 09/12] PCI: liveupdate: Inherit ARI Forwarding Enable on preserved bridges David Matlack
2026-07-17 23:29 ` Pasha Tatashin
2026-07-20 23:19 ` David Matlack
2026-07-21 18:17 ` Pasha Tatashin
2026-07-21 20:26 ` David Matlack
2026-07-27 23:07 ` Bjorn Helgaas
2026-07-27 23:22 ` David Matlack
2026-07-10 21:26 ` [PATCH v7 10/12] PCI: liveupdate: Freeze preservation status during shutdown David Matlack
2026-07-17 23:30 ` Pasha Tatashin
2026-07-10 21:26 ` [PATCH v7 11/12] PCI: liveupdate: Do not disable bus mastering on preserved devices during kexec David Matlack
2026-07-17 23:32 ` Pasha Tatashin
2026-07-10 21:26 ` [PATCH v7 12/12] Documentation: PCI: Add documentation for Live Update David Matlack
2026-07-17 23:38 ` Pasha Tatashin
2026-07-27 17:52 ` [PATCH v7 00/12] PCI: liveupdate: PCI core support " David Matlack
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260727225400.GA1268182@bhelgaas \
--to=helgaas@kernel.org \
--cc=ajayachandra@nvidia.com \
--cc=alex@shazbot.org \
--cc=bhelgaas@google.com \
--cc=chrisl@kernel.org \
--cc=corbet@lwn.net \
--cc=dmatlack@google.com \
--cc=graf@amazon.com \
--cc=jacob.pan@linux.microsoft.com \
--cc=jgg@nvidia.com \
--cc=jrhilke@google.com \
--cc=kexec@lists.infradead.org \
--cc=leonro@nvidia.com \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-pci@vger.kernel.org \
--cc=lukas@wunner.de \
--cc=parav@nvidia.com \
--cc=pasha.tatashin@soleen.com \
--cc=praan@google.com \
--cc=pratyush@kernel.org \
--cc=rientjes@google.com \
--cc=rppt@kernel.org \
--cc=saeedm@nvidia.com \
--cc=skhan@linuxfoundation.org \
--cc=skhawaja@google.com \
--cc=vipinsh@google.com \
--cc=witu@nvidia.com \
--cc=yi.l.liu@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox