From: Alex Williamson <alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
To: benh-XVmvHMARGAS8U2dJNN8I7kB+6BGkLq7r@public.gmane.org,
aik-sLpHqDYs0B2HXe+LvDLADg@public.gmane.org,
david-xT8FGy+AXnRB3Ne2BGzF6laj5H9X9Tb+@public.gmane.org,
joerg.roedel-5C7GfCeVMHo@public.gmane.org,
dwmw2-wEGCiKHe2LqWVfeAwA7xHQ@public.gmane.org
Cc: kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
B07421-KZfg59tc24xl57MIdRCFDg@public.gmane.org,
linux-pci-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
agraf-l3A5Bk7waGM@public.gmane.org,
qemu-devel-qX2TKyscuCcdnm+yROfE0A@public.gmane.org,
chrisw-69jw2NvuJkxg9hUCZPvPmw@public.gmane.org,
B08248-KZfg59tc24xl57MIdRCFDg@public.gmane.org,
iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org,
avi-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org,
gregkh-hQyY1W1yCW8ekmWlsbkhG0B+6BGkLq7r@public.gmane.org,
bhelgaas-hpIqsD4AKlfQT0dZR+AlfA@public.gmane.org,
linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org,
benve-FYB4Gu1CFyUAvxtiuMwx3w@public.gmane.org
Subject: [PATCH v2 06/13] iommu: Make use of DMA quirking and ACS enabled check for groups
Date: Mon, 21 May 2012 23:05:15 -0600 [thread overview]
Message-ID: <20120522050515.5871.92344.stgit@bling.home> (raw)
In-Reply-To: <20120522043607.5871.11340.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
Incorporate DMA quirking and ACS checking into amd_iommu and
intel-iommu. Note that IOMMU groups are not yet used for
streaming DMA, so this doesn't immediately solve the problems
with broken Ricoh devices. This a very strict implementation of
ACS checking, which will often result in multifunction devices
being grouped together. This is actually a good thing as we
generally have no reason to trust isolation between functions,
but I won't be surprised if we later add a boot option to relax
this if a user wants to opt-in to a less secure grouping.
Signed-off-by: Alex Williamson <alex.williamson-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
---
drivers/iommu/amd_iommu.c | 18 ++++++++++++++++++
drivers/iommu/intel-iommu.c | 18 ++++++++++++++++++
2 files changed, 36 insertions(+), 0 deletions(-)
diff --git a/drivers/iommu/amd_iommu.c b/drivers/iommu/amd_iommu.c
index b7e5ddf..be72d6d 100644
--- a/drivers/iommu/amd_iommu.c
+++ b/drivers/iommu/amd_iommu.c
@@ -254,6 +254,8 @@ static bool check_device(struct device *dev)
return true;
}
+#define PCI_ACS_ENABLED (PCI_ACS_SV | PCI_ACS_RR | PCI_ACS_CR | PCI_ACS_UF)
+
static int iommu_init_device(struct device *dev)
{
struct pci_dev *dma_pdev, *pdev = to_pci_dev(dev);
@@ -291,6 +293,22 @@ static int iommu_init_device(struct device *dev)
dma_pdev = pci_get_slot(pdev->bus,
PCI_DEVFN(PCI_SLOT(pdev->devfn), 0));
+ dma_pdev = pci_dma_source(dma_pdev);
+
+ if (dma_pdev->multifunction &&
+ !pci_acs_enabled(dma_pdev, PCI_ACS_ENABLED))
+ dma_pdev = pci_get_slot(dma_pdev->bus,
+ PCI_DEVFN(PCI_SLOT(dma_pdev->devfn),
+ 0));
+
+ while (!pci_is_root_bus(dma_pdev->bus)) {
+ if (pci_acs_path_enabled(dma_pdev->bus->self,
+ NULL, PCI_ACS_ENABLED))
+ break;
+
+ dma_pdev = dma_pdev->bus->self;
+ }
+
group = iommu_group_get(&dma_pdev->dev);
if (!group) {
group = iommu_group_alloc();
diff --git a/drivers/iommu/intel-iommu.c b/drivers/iommu/intel-iommu.c
index e63b33b..cf2a650 100644
--- a/drivers/iommu/intel-iommu.c
+++ b/drivers/iommu/intel-iommu.c
@@ -4087,6 +4087,8 @@ static int intel_iommu_domain_has_cap(struct iommu_domain *domain,
return 0;
}
+#define PCI_ACS_ENABLED (PCI_ACS_SV | PCI_ACS_RR | PCI_ACS_CR | PCI_ACS_UF)
+
static int intel_iommu_add_device(struct device *dev)
{
struct pci_dev *pdev = to_pci_dev(dev);
@@ -4113,6 +4115,22 @@ static int intel_iommu_add_device(struct device *dev)
dma_pdev = pci_get_slot(pdev->bus,
PCI_DEVFN(PCI_SLOT(pdev->devfn), 0));
+ dma_pdev = pci_dma_source(dma_pdev);
+
+ if (dma_pdev->multifunction &&
+ !pci_acs_enabled(dma_pdev, PCI_ACS_ENABLED))
+ dma_pdev = pci_get_slot(dma_pdev->bus,
+ PCI_DEVFN(PCI_SLOT(dma_pdev->devfn),
+ 0));
+
+ while (!pci_is_root_bus(dma_pdev->bus)) {
+ if (pci_acs_path_enabled(dma_pdev->bus->self,
+ NULL, PCI_ACS_ENABLED))
+ break;
+
+ dma_pdev = dma_pdev->bus->self;
+ }
+
group = iommu_group_get(&dma_pdev->dev);
if (!group) {
group = iommu_group_alloc();
next prev parent reply other threads:[~2012-05-22 5:05 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2012-05-22 5:04 [PATCH v2 00/13] IOMMU Groups + VFIO Alex Williamson
[not found] ` <20120522043607.5871.11340.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
2012-05-22 5:04 ` [PATCH v2 01/13] driver core: Add iommu_group tracking to struct device Alex Williamson
2012-05-22 5:04 ` [PATCH v2 02/13] iommu: IOMMU Groups Alex Williamson
2012-05-22 5:04 ` [PATCH v2 03/13] iommu: IOMMU groups for VT-d and AMD-Vi Alex Williamson
[not found] ` <20120522050454.5871.67086.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
2012-05-24 21:01 ` Don Dutile
[not found] ` <4FBEA18F.1040607-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-05-24 21:49 ` Alex Williamson
2012-05-22 5:05 ` [PATCH v2 04/13] pci: Add PCI DMA source ID quirk Alex Williamson
2012-05-22 5:05 ` [PATCH v2 05/13] pci: Add ACS validation utility Alex Williamson
[not found] ` <20120522050508.5871.96269.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
2012-05-24 21:30 ` Don Dutile
[not found] ` <4FBEA887.6010908-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-05-24 22:35 ` Alex Williamson
2012-05-22 5:05 ` Alex Williamson [this message]
2012-05-22 5:05 ` [PATCH v2 07/13] vfio: VFIO core Alex Williamson
2012-05-22 5:05 ` [PATCH v2 08/13] vfio: Add documentation Alex Williamson
2012-05-22 5:05 ` [PATCH v2 09/13] vfio: x86 IOMMU implementation Alex Williamson
[not found] ` <20120522050536.5871.65171.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
2012-05-24 21:38 ` Don Dutile
[not found] ` <4FBEAA5C.4060105-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-05-24 22:46 ` Alex Williamson
2012-05-25 15:22 ` Don Dutile
2012-05-22 5:05 ` [PATCH v2 10/13] pci: export pci_user functions for use by other drivers Alex Williamson
2012-05-22 5:05 ` [PATCH v2 11/13] pci: Create common pcibios_err_to_errno Alex Williamson
2012-05-22 5:05 ` [PATCH v2 12/13] pci: Misc pci_reg additions Alex Williamson
[not found] ` <20120522050557.5871.15364.stgit-xdHQ/5r00wBBDLzU/O5InQ@public.gmane.org>
2012-05-24 21:49 ` Don Dutile
[not found] ` <4FBEACE2.1050701-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org>
2012-05-24 22:17 ` Alex Williamson
2012-05-22 5:06 ` [PATCH v2 13/13] vfio: Add PCI device driver Alex Williamson
2012-05-24 21:56 ` [PATCH v2 00/13] IOMMU Groups + VFIO Don Dutile
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20120522050515.5871.92344.stgit@bling.home \
--to=alex.williamson-h+wxahxf7alqt0dzr+alfa@public.gmane.org \
--cc=B07421-KZfg59tc24xl57MIdRCFDg@public.gmane.org \
--cc=B08248-KZfg59tc24xl57MIdRCFDg@public.gmane.org \
--cc=agraf-l3A5Bk7waGM@public.gmane.org \
--cc=aik-sLpHqDYs0B2HXe+LvDLADg@public.gmane.org \
--cc=avi-H+wXaHxf7aLQT0dZR+AlfA@public.gmane.org \
--cc=benh-XVmvHMARGAS8U2dJNN8I7kB+6BGkLq7r@public.gmane.org \
--cc=benve-FYB4Gu1CFyUAvxtiuMwx3w@public.gmane.org \
--cc=bhelgaas-hpIqsD4AKlfQT0dZR+AlfA@public.gmane.org \
--cc=chrisw-69jw2NvuJkxg9hUCZPvPmw@public.gmane.org \
--cc=david-xT8FGy+AXnRB3Ne2BGzF6laj5H9X9Tb+@public.gmane.org \
--cc=dwmw2-wEGCiKHe2LqWVfeAwA7xHQ@public.gmane.org \
--cc=gregkh-hQyY1W1yCW8ekmWlsbkhG0B+6BGkLq7r@public.gmane.org \
--cc=iommu-cunTk1MwBs9QetFLy7KEm3xJsTq8ys+cHZ5vskTnxNA@public.gmane.org \
--cc=joerg.roedel-5C7GfCeVMHo@public.gmane.org \
--cc=kvm-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=linux-kernel-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=linux-pci-u79uwXL29TY76Z2rM5mHXA@public.gmane.org \
--cc=qemu-devel-qX2TKyscuCcdnm+yROfE0A@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).