From: Eric Auger <eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
To: "eric.auger.pro-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org,
eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org,
linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
kvmarm-FPEHb7Xf0XXUo1n7N8X6UoWGPAHP3yOg@public.gmane.org,
joro-zLv9SwRftAIdnm+yROfE0A@public.gmane.org,
alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
jean-philippe.brucker-5wv7dgnIgG8@public.gmane.org,
jacob.jun.pan-VuQAYsv1563Yd54FQh9/CA@public.gmane.org,
yi.l.liu"@linux.intel.com,
will.deacon-5wv7dgnIgG8@public.gmane.org,
robin.murphy-5wv7dgnIgG8@public.gmane.org
Cc: marc.zyngier-5wv7dgnIgG8@public.gmane.org,
peter.maydell-QSEj5FYQhm4dnm+yROfE0A@public.gmane.org,
christoffer.dall-5wv7dgnIgG8@public.gmane.org
Subject: [RFC 07/13] vfio: Document nested stage control
Date: Thu, 23 Aug 2018 14:17:30 +0200 [thread overview]
Message-ID: <1535026656-8450-8-git-send-email-eric.auger@redhat.com> (raw)
In-Reply-To: <1535026656-8450-1-git-send-email-eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
New iotcls were introduced to pass information about guest stage1
to the host through VFIO. Let's document the nested stage control.
Signed-off-by: Eric Auger <eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
---
fault reporting is current missing to the picture
---
Documentation/vfio.txt | 45 +++++++++++++++++++++++++++++++++++++++++++++
1 file changed, 45 insertions(+)
diff --git a/Documentation/vfio.txt b/Documentation/vfio.txt
index f1a4d3c..858a363 100644
--- a/Documentation/vfio.txt
+++ b/Documentation/vfio.txt
@@ -239,6 +239,51 @@ group and can access them as follows::
/* Gratuitous device reset and go... */
ioctl(device, VFIO_DEVICE_RESET);
+IOMMU Dual Stage Control
+------------------------
+
+Some IOMMUs support 2 stages of translation. This is useful when the
+guest is exposed with a virtual IOMMU and some devices are assigned
+to the guest through VFIO. Then the guest OS can use stage 1 (IOVA -> GPA),
+while the hypervisor uses stage 2 for VM isolation (GPA -> HPA).
+
+The guest gets ownership of the stage 1 page tables and also owns stage 1
+configuration structures. The hypervisor owns the root configuration structure
+(for security reason), including stage 2 configuration. This works as long
+configuration structures and page table format are compatible between the
+virtual IOMMU and the physical IOMMU.
+
+Assuming the HW supports it, this nested mode is selected by choosing the
+VFIO_TYPE1_NESTING_IOMMU type through:
+
+ioctl(container, VFIO_SET_IOMMU, VFIO_TYPE1_NESTING_IOMMU);
+
+This forces the hypervisor to use the stage 2, leaving stage 1 available for
+guest usage.
+
+Once groups are attached to the container, the guest stage 1 translation
+configuration data can be passed to VFIO by using
+
+ioctl(container, VFIO_IOMMU_BIND_GUEST_STAGE, &guest_stage_info);
+
+This allows to combine guest stage1 configuration structure along with hypervisor
+stage 2 configuration structure. stage 1 configuration structures are dependent
+on the IOMMU type.
+
+When the guest invalidates stage 1 entries, IOTLB invalidations must be forwarded
+to the host through
+ioctl(container, VFIO_IOMMU_TLB_INVALIDATE, &inv_data);
+Those invalidations can happen at various granularity levels, page, context, ...
+
+The ARM SMMU specification introduces another challenge: MSIs are translated by
+both the virtual SMMU and the physical SMMU. To build a nested mapping for the
+IOVA programmed into the assigned device, the guest needs to pass its IOVA/MSI
+doorbell GPA binding to the host. Then the hypervisor can build a nested stage 2
+binding eventually translating into the physical MSI doorbell.
+
+This is achieved by
+ioctl(container, VFIO_IOMMU_BIND_MSI, &guest_binding);
+
VFIO User API
-------------------------------------------------------------------------------
--
2.5.5
next prev parent reply other threads:[~2018-08-23 12:17 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-08-23 12:17 [RFC 00/13] SMMUv3 Nested Stage Setup Eric Auger
[not found] ` <1535026656-8450-1-git-send-email-eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-08-23 12:17 ` [RFC 01/13] iommu: Introduce bind_guest_stage API Eric Auger
2018-08-23 15:25 ` Auger Eric
2018-08-31 13:11 ` Jean-Philippe Brucker
[not found] ` <b7909f1b-57ce-f4db-d916-140a63283232-5wv7dgnIgG8@public.gmane.org>
2018-08-31 13:52 ` Auger Eric
2018-09-03 12:19 ` Jean-Philippe Brucker
[not found] ` <4309832b-27ed-597a-b5a1-f439fbea9843-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-04 7:57 ` Tian, Kevin
2018-09-04 8:10 ` Auger Eric
[not found] ` <220e4c2a-d31c-d8fb-2d77-d902d2f13bb2-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-04 8:34 ` Tian, Kevin
2018-09-04 8:41 ` Auger Eric
2018-09-04 8:43 ` Tian, Kevin
2018-09-04 9:53 ` Jean-Philippe Brucker
2018-09-05 0:36 ` Tian, Kevin
[not found] ` <A2975661238FB949B60364EF0F2C257439CCE9EE@SHSMSX104.ccr.corp.intel.com>
2018-08-24 13:20 ` Auger Eric
2018-08-23 12:17 ` [RFC 02/13] iommu: Introduce tlb_invalidate API Eric Auger
2018-08-31 13:17 ` Jean-Philippe Brucker
2018-08-31 14:07 ` Auger Eric
2018-09-03 12:28 ` Jean-Philippe Brucker
2018-09-03 12:41 ` Auger Eric
2018-09-03 13:41 ` Jean-Philippe Brucker
2018-08-23 12:17 ` [RFC 03/13] iommu: Introduce bind_guest_msi Eric Auger
2018-08-23 12:17 ` [RFC 04/13] vfio: VFIO_IOMMU_BIND_GUEST_STAGE Eric Auger
2018-08-23 12:17 ` [RFC 05/13] vfio: VFIO_IOMMU_TLB_INVALIDATE Eric Auger
2018-08-23 12:17 ` [RFC 06/13] vfio: VFIO_IOMMU_BIND_MSI Eric Auger
2018-08-23 12:17 ` Eric Auger [this message]
2018-08-23 12:17 ` [RFC 08/13] iommu/arm-smmu-v3: Link domains and devices Eric Auger
2018-08-23 12:17 ` [RFC 09/13] iommu/smmuv3: Get prepared for nested stage support Eric Auger
2018-08-31 13:20 ` Jean-Philippe Brucker
2018-08-31 14:11 ` Auger Eric
[not found] ` <012d4950-7a06-2d59-85a0-44d511ad893b-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2018-09-03 12:29 ` Jean-Philippe Brucker
2018-09-03 12:48 ` Auger Eric
2018-08-23 12:17 ` [RFC 10/13] iommu/smmuv3: Implement bind_guest_stage Eric Auger
2018-08-23 12:17 ` [RFC 11/13] iommu/smmuv3: Implement tlb_invalidate Eric Auger
2018-08-23 12:17 ` [RFC 12/13] dma-iommu: Implement NESTED_MSI cookie Eric Auger
2018-08-23 12:17 ` [RFC 13/13] iommu/smmuv3: Implement bind_guest_msi Eric Auger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1535026656-8450-8-git-send-email-eric.auger@redhat.com \
--to=eric.auger-h+wxahxf7alqt0dzr+alfa@public.gmane.org \
--cc="eric.auger.pro-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org, eric.auger-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org, linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org, kvmarm-FPEHb7Xf0XXUo1n7N8X6UoWGPAHP3yOg@public.gmane.org, joro-zLv9SwRftAIdnm+yROfE0A@public.gmane.org, alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org, jean-philippe.brucker-5wv7dgnIgG8@public.gmane.org, jacob.jun.pan-VuQAYsv1563Yd54FQh9/CA@public.gmane.org, yi.l.liu"@linux.intel.com \
--cc=christoffer.dall-5wv7dgnIgG8@public.gmane.org \
--cc=marc.zyngier-5wv7dgnIgG8@public.gmane.org \
--cc=peter.maydell-QSEj5FYQhm4dnm+yROfE0A@public.gmane.org \
--cc=robin.murphy-5wv7dgnIgG8@public.gmane.org \
--cc=will.deacon-5wv7dgnIgG8@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox