From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f180.google.com (mail-qk1-f180.google.com [209.85.222.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D00B61B4234 for ; Wed, 5 Mar 2025 19:28:44 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.180 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1741202926; cv=none; b=jMlxoZqzXXC7hUma2XjUjBHWPfExx0XMKRLL9/rxcV/8ASxNObyE26U3hbiRVYGTkQo1hP1OsHgT6SwZSgZAfrCPp1P8gi1yLL9qhq2Tg95ku+7QL3BqKJpRXUvgnolQqBFZt7kxF2I2AmVgOz3mxrK0lqfCgs2eA8YBAzBr+w0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1741202926; c=relaxed/simple; bh=yags00HimzcK4ADiEl0X3eL1vhGMGirpJlRolnATCxg=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=n8wZe6WO9THhvmXKl16qDfY5gF+r2Vd2nkE5I2jaHYqDowWLb8qqH1EVLM4tY8E26FpKrRmqJIq3dzk+d/XTCkYJieYOgwYDAGRaXknTONObbiurDxEvm7lGaro9CLm5MUycL/AC4RAmb/9SnbNChMTmiKHEA2eXnD64IJWu7zg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca; spf=pass smtp.mailfrom=ziepe.ca; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b=OzyS60LM; arc=none smtp.client-ip=209.85.222.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=ziepe.ca Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=ziepe.ca header.i=@ziepe.ca header.b="OzyS60LM" Received: by mail-qk1-f180.google.com with SMTP id af79cd13be357-7c089b2e239so109666985a.0 for ; Wed, 05 Mar 2025 11:28:44 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ziepe.ca; s=google; t=1741202924; x=1741807724; darn=lists.linux.dev; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=tTrOJMautZJ74CE8chK1zIyRNkTfUPScJmXz0FQll+Y=; b=OzyS60LMucaIVAbE2Hoqgq/YUT5Xvl1Tevud41XU46v87t5Fl+o2s87AhWZ6uI7cF3 zK7eMOBR4GScmv4ILwcwIU9tCp6mStLSigzeAst74ePfI3l9nN8S/WlD/H1k5D0YKVIt BKLoD+svFC62cqSokNFQhUXofPqEB7k9tSuF7f4Fh0OYYTiIBFdyoRX+HnE7CxFmnZxQ L7DZwsSRLKNL0nUitGajoH6vndQhat0RWZtgmIWbkWiVRLXEcbpvlMwnSePw0hMs+eIU yyP+9ETw+fbYQlhAcLG41D5/gahMDnbhGkfUu4QuUGRSckN45Dhg5gFXyvIVDV8UZP17 PKxw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1741202924; x=1741807724; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=tTrOJMautZJ74CE8chK1zIyRNkTfUPScJmXz0FQll+Y=; b=lhWX49yiKpyLT9MxiFTXF0sX7b1826xpdrJWhFgf7S9Unhq6Qaxl4cjgCHqduTKfGt Lj1e6NwsQ9meQlMZWCkN+8Bt44iB2HHaFoiXn0AiLUt7LSzwWc9PCFNOM+BTN87eFTrA mINDZtunDDV4CU8MTEiNNlmg5FAB8lVzUOczZ4ANH3SgxSaGnbz4EfhCK0Vhl9PLaIS4 v4Pb5tgvi41sdkzQiLxHkrcXC2LkBTODOBJsyxhx3BLYhgq+tg5RV2otxgC8jxp9bWcR 2ehv6F1ii3MLza07HTbKtmzY9WtAKV6wy7W0Hk5SPMP3UaGsvBpBoLK6nPQZwcNexBxf 8oLQ== X-Forwarded-Encrypted: i=1; AJvYcCWdvQaFAtgWzEzJVDVzQcNpOcG+QHmphWH8tMMJLwQOAs/n6z9uwzEuKxh/qNEdxW1r+b0Cjg==@lists.linux.dev X-Gm-Message-State: AOJu0YwYA3oLu5cLZOPFF5imYo4Ix37lvbfC3xiE4bopU7VPiQssDpfS FyXSHaJebHyy8I9r7uYEzPJZ/k42s3h+AdKYKbCylL4FIxQdEfyVYFoKfdJgpIk= X-Gm-Gg: ASbGncuVxL2jjApFEd8hWvY5Rjg3K9LEStQ0VNzUk/JNbc+s8e0Fa6y1px3CloqlG1p O5V0T7Eg4bO4MFjqGxv61pz7G4dS5SLwy/R6hw35SddoZdyzv7s1MO7clxrO24eDXyEU9mf1LI0 CHoXFsL6+QG3IKFFxo91jr9t/gZswJQ4LWb6/rrPTTRsiU+PXPiAtP0oD1ovOBoxJeqaMRDiSwB y9RCus0ZR0XXHv2pBvfLQM0DfCznSFqFu85UEfjaZzI8BWf7oEpWraikAOjOFXG6TQf3jKFl0dX gjRaDQ8fgn8MkMgfUS0/au/p+pVJzRkXNZlAw6HBl0tuldEwiSzP1knxQqO65znrUxiBiFo+DbZ C+hGPNqq4cZryIeJp1g== X-Google-Smtp-Source: AGHT+IEHx2UVGeNJCjdCHNzkys/fqlsDci1nQ/1m9GKN7AMZGI83uk7z1IQe+K7jbrNiF4r725P/BQ== X-Received: by 2002:a05:620a:6285:b0:7c0:b350:820 with SMTP id af79cd13be357-7c3e39b1392mr81853985a.5.1741202923780; Wed, 05 Mar 2025 11:28:43 -0800 (PST) Received: from ziepe.ca (hlfxns017vw-142-68-128-5.dhcp-dynamic.fibreop.ns.bellaliant.net. [142.68.128.5]) by smtp.gmail.com with ESMTPSA id af79cd13be357-7c3c9f640cbsm324838085a.108.2025.03.05.11.28.43 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 05 Mar 2025 11:28:43 -0800 (PST) Received: from jgg by wakko with local (Exim 4.97) (envelope-from ) id 1tpuQ6-00000001VBp-37wk; Wed, 05 Mar 2025 15:28:42 -0400 Date: Wed, 5 Mar 2025 15:28:42 -0400 From: Jason Gunthorpe To: Xu Yilun Cc: Alexey Kardashevskiy , x86@kernel.org, kvm@vger.kernel.org, linux-crypto@vger.kernel.org, linux-pci@vger.kernel.org, linux-arch@vger.kernel.org, Sean Christopherson , Paolo Bonzini , Tom Lendacky , Ashish Kalra , Joerg Roedel , Suravee Suthikulpanit , Robin Murphy , Kevin Tian , Bjorn Helgaas , Dan Williams , Christoph Hellwig , Nikunj A Dadhania , Michael Roth , Vasant Hegde , Joao Martins , Nicolin Chen , Lu Baolu , Steve Sistare , Lukas Wunner , Jonathan Cameron , Suzuki K Poulose , Dionna Glaze , Yi Liu , iommu@lists.linux.dev, linux-coco@lists.linux.dev, Zhi Wang , "Aneesh Kumar K . V" Subject: Re: [RFC PATCH v2 14/22] iommufd: Add TIO calls Message-ID: <20250305192842.GE354403@ziepe.ca> References: <20250218111017.491719-1-aik@amd.com> <20250218111017.491719-15-aik@amd.com> <2fe6b3c6-3eed-424d-87f0-34c4e7e1c906@amd.com> <20250226131202.GH5011@ziepe.ca> <20250301003711.GR5011@ziepe.ca> Precedence: bulk X-Mailing-List: iommu@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: On Mon, Mar 03, 2025 at 01:32:47PM +0800, Xu Yilun wrote: > All these settings cannot really take function until guest verifies them > and does TDISP start. Guest verification does not (should not) need host > awareness. > > Our solution is, separate the secure DMA setting and secure device setting > in different components, iommufd & vfio. > > Guest require bind: > - ioctl(iommufd, IOMMU_VIOMMU_ALLOC, {.type = IOMMU_VIOMMU_TYPE_KVM_VALID, > .kvm_fd = kvm_fd, > .out_viommu_id = &viommu_id}); > - ioctl(iommufd, IOMMU_HWPT_ALLOC, {.flag = IOMMU_HWPT_ALLOC_TRUSTED, > .pt_id = viommu_id, > .out_hwpt_id = &hwpt_id}); > - ioctl(vfio_fd, VFIO_DEVICE_ATTACH_IOMMUFD_PT, {.pt_id = hwpt_id}) > - do secure DMA setting in Intel iommu driver. > > - ioctl(vfio_fd, VFIO_DEVICE_TSM_BIND, ...) > - do bind in Intel TSM driver. Except what do command do you issue to the secure world for TSM_BIND and what are it's argument? Again you can't include the vBDF or vIOMMU ID here. vfio also can't validate that the hwpt is in the right state when it executes this function. You could also issue the TSM bind against the idev on the iommufd side.. Part of my problem here is I don't see anyone who seems to have read all three specs and is trying to mush them together. Everyone is focused on their own spec. I know there are subtle differences :\ Jason