From: Leon Romanovsky <leon@kernel.org>
To: Bjorn Helgaas <bhelgaas@google.com>,
Logan Gunthorpe <logang@deltatee.com>,
Jonathan Corbet <corbet@lwn.net>,
Shuah Khan <skhan@linuxfoundation.org>,
Alex Williamson <alex@shazbot.org>
Cc: linux-pci@vger.kernel.org, linux-kernel@vger.kernel.org,
linux-doc@vger.kernel.org
Subject: [PATCH 06/13] PCI: Account for ACS egress control in isolation checks
Date: Sun, 2 Aug 2026 18:09:44 +0300 [thread overview]
Message-ID: <20260802-fix-p2p-acs-v1-6-a7c5eb64fff6@nvidia.com> (raw)
In-Reply-To: <20260802-fix-p2p-acs-v1-0-a7c5eb64fff6@nvidia.com>
From: Leon Romanovsky <leonro@nvidia.com>
pci_acs_enabled() treats P2P Request Redirect as effective whenever its
control bit is set. PCIe r7.0, sec 6.12.3, table 6-11 lets an enabled
Egress Control Vector override it: a clear vector bit routes the request
directly.
IOMMU grouping uses this check to prove peer requests cannot bypass the
IOMMU, but cannot know every applicable vector bit, so Request Redirect
gives no such guarantee while Egress Control is enabled.
Report Request Redirect as ineffective there, merging the devices into
one IOMMU group, and report no isolation when the register cannot be
read. Apply the same rule to the Intel SPT PCH quirk.
Signed-off-by: Leon Romanovsky <leonro@nvidia.com>
---
drivers/pci/pci.c | 12 +++++++++++-
drivers/pci/quirks.c | 10 ++++++++--
2 files changed, 19 insertions(+), 3 deletions(-)
diff --git a/drivers/pci/pci.c b/drivers/pci/pci.c
index 154eb08036ad..bc1c3b68c131 100644
--- a/drivers/pci/pci.c
+++ b/drivers/pci/pci.c
@@ -3620,7 +3620,8 @@ static bool pci_acs_flags_enabled(struct pci_dev *pdev, u16 acs_flags)
*/
acs_flags &= (pdev->acs_capabilities | PCI_ACS_EC);
- pci_read_config_word(pdev, pos + PCI_ACS_CTRL, &ctrl);
+ if (pci_read_config_word(pdev, pos + PCI_ACS_CTRL, &ctrl))
+ return false;
/*
* Direct Translated P2P routes a Translated Request to the peer
@@ -3630,6 +3631,15 @@ static bool pci_acs_flags_enabled(struct pci_dev *pdev, u16 acs_flags)
if (request_redirect && (ctrl & PCI_ACS_DT) && !(ctrl & PCI_ACS_TB))
return false;
+ /*
+ * Egress Control can override Request Redirect for peer requests.
+ * This target-independent check cannot prove that every applicable
+ * Egress Control Vector bit is set, so RR does not guarantee isolation
+ * while EC is enabled.
+ */
+ if (request_redirect && (ctrl & PCI_ACS_EC))
+ return false;
+
return (ctrl & acs_flags) == acs_flags;
}
diff --git a/drivers/pci/quirks.c b/drivers/pci/quirks.c
index bb4c09cbbd10..ebfe902b0118 100644
--- a/drivers/pci/quirks.c
+++ b/drivers/pci/quirks.c
@@ -4990,15 +4990,21 @@ static int pci_quirk_intel_spt_pch_acs(struct pci_dev *dev, u16 acs_flags)
return -ENOTTY;
/* see pci_acs_flags_enabled() */
- pci_read_config_dword(dev, pos + PCI_ACS_CAP, &cap);
+ if (pci_read_config_dword(dev, pos + PCI_ACS_CAP, &cap))
+ return 0;
acs_flags &= (cap | PCI_ACS_EC);
- pci_read_config_dword(dev, pos + INTEL_SPT_ACS_CTRL, &ctrl);
+ if (pci_read_config_dword(dev, pos + INTEL_SPT_ACS_CTRL, &ctrl))
+ return 0;
/* Direct Translated P2P may bypass Request Redirect. */
if (request_redirect && (ctrl & PCI_ACS_DT) && !(ctrl & PCI_ACS_TB))
return 0;
+ /* Egress Control may override Request Redirect for peer requests. */
+ if (request_redirect && (ctrl & PCI_ACS_EC))
+ return 0;
+
return pci_acs_ctrl_enabled(acs_flags, ctrl);
}
--
2.55.0
next prev parent reply other threads:[~2026-08-02 15:10 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-02 15:09 [PATCH 00/13] PCI/P2PDMA: Fix ACS egress control handling Leon Romanovsky
2026-08-02 15:09 ` [PATCH 01/13] PCI/P2PDMA: Safely terminate ACS redirect lists Leon Romanovsky
2026-08-04 19:49 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 02/13] PCI/P2PDMA: Report ACS ports when the paths share no upstream bridge Leon Romanovsky
2026-08-04 19:52 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 03/13] PCI/P2PDMA: Document the Address Type assumption Leon Romanovsky
2026-08-04 19:55 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 04/13] PCI: Account for Direct Translated P2P in ACS isolation checks Leon Romanovsky
2026-08-04 20:03 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 05/13] PCI: Add ACS egress control vector accessor Leon Romanovsky
2026-08-04 21:55 ` Logan Gunthorpe
2026-08-02 15:09 ` Leon Romanovsky [this message]
2026-08-04 21:55 ` [PATCH 06/13] PCI: Account for ACS egress control in isolation checks Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 07/13] PCI/P2PDMA: Derive peer-to-peer routing from ACS control bits Leon Romanovsky
2026-08-04 21:55 ` Logan Gunthorpe
2026-08-04 21:58 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 08/13] PCI/P2PDMA: Honor ACS egress control vectors Leon Romanovsky
2026-08-04 21:56 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 09/13] PCI/P2PDMA: Document ACS egress control handling Leon Romanovsky
2026-08-04 22:01 ` Logan Gunthorpe
2026-08-05 9:02 ` Leon Romanovsky
2026-08-02 15:09 ` [PATCH 10/13] PCI/P2PDMA: Extract pure ACS routing decision helpers Leon Romanovsky
2026-08-04 22:07 ` Logan Gunthorpe
2026-08-05 9:06 ` Leon Romanovsky
2026-08-02 15:09 ` [PATCH 11/13] PCI/P2PDMA: Add KUnit tests for ACS routing decisions Leon Romanovsky
2026-08-04 22:37 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 12/13] PCI/P2PDMA: Add KUnit coverage for the ACS P2P routing walk Leon Romanovsky
2026-08-04 22:37 ` Logan Gunthorpe
2026-08-02 15:09 ` [PATCH 13/13] PCI: Add KUnit coverage for ACS isolation checks Leon Romanovsky
2026-08-04 22:38 ` Logan Gunthorpe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260802-fix-p2p-acs-v1-6-a7c5eb64fff6@nvidia.com \
--to=leon@kernel.org \
--cc=alex@shazbot.org \
--cc=bhelgaas@google.com \
--cc=corbet@lwn.net \
--cc=linux-doc@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=logang@deltatee.com \
--cc=skhan@linuxfoundation.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox