From: Jason Gunthorpe <jgg@nvidia.com>
To: Robin Murphy <robin.murphy@arm.com>,
Ankit Agrawal <ankita@nvidia.com>, Jiri Pirko <jiri@nvidia.com>,
Leon Romanovsky <leon@kernel.org>
Cc: Mostafa Saleh <smostafa@google.com>,
"Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
Marek Szyprowski <m.szyprowski@samsung.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Steven Price <steven.price@arm.com>,
Suzuki K Poulose <Suzuki.Poulose@arm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Jiri Pirko <jiri@resnulli.us>, Petr Tesarik <ptesarik@suse.com>,
Alexey Kardashevskiy <aik@amd.com>,
Dan Williams <dan.j.williams@intel.com>,
Xu Yilun <yilun.xu@linux.intel.com>,
linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>,
Nicholas Piggin <npiggin@gmail.com>,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Sven Schnelle <svens@linux.ibm.com>,
x86@kernel.org, Michael Kelley <mhklinux@outlook.com>
Subject: Re: [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference
Date: Mon, 10 Aug 2026 12:08:32 -0300 [thread overview]
Message-ID: <20260810150832.GB291736@nvidia.com> (raw)
In-Reply-To: <21813ccf-96e5-4a7e-a3b3-aaaec7e0d23c@arm.com>
On Mon, Aug 10, 2026 at 03:18:03PM +0100, Robin Murphy wrote:
> Cool. So in fact that puts us in an interesting position for now where
> non-CoCo "untrusted" (i.e. external) devices should have IOMMU translation
> forced on by default, while CoCo "unaccepted" devices (i.e. those which do
> have a mechanism to transition into a T=1 or equivalent state) should *not*
> try to use an associated IOMMU, on the assumption that it may only work for
> T=1 traffic. All the more reason to sort these abstractions out so we can
> make the right distinctions clearly :)
I think the guest flow works out fairly logically:
1) At boot the IOMMU core always setups blocking translation. No more
auto-attaching paging or identity domains at probe time [optional,
but default on for CC guest]
* This means devices that can have their DMA disabled do
* Additionally T=1 capable devices have their T=1 DMA blocked by
the CC platform itself. eg RMM is to leave the T=1 STE set to
blocking at VM boot until commanded otherwise.
Aside from CC this also goes hand in hand with DRTM support in the
kernel where we do want to carry over the DMA access block from the
secure launch until the system, ideally via userspace policy, has
approved the device.
2) Before probing a driver we synchronize the TDISP state, IOMMU
and configure the DMA API:
a. If no iommu, then DMA API is in physical
b. If both device and IOMMU same-T then DMA API follows IOMMU configuration:
- DMA API is physical if IOMMU configuration is identity
- DMA API is dma-iomu if paging
- IOMMU sets the proper domain for the DMA API, removes the
blocking
c. If device and iommu have different T state then assume no iommu
and DMA API is physical
2b) For T=1 capable devices this is the moment we tell the CC platform
to permit DMA
3) The DMA API configuration follows per-device flags:
- Using IOMMU: Use dma-iommu not physical
- Using T=0/1: Replaces 'force dma unencrypted'. Ie T=0 uses
swiotlb to get CC shared memory.
- adversarial: Replaces pdev->trusted/etc. Causes IOMMU and
SWIOTLB to bounce buffer partial pages.
Causes iommu to prefer paging not identity.
4) After removing a driver we restore the IOMMU back to blocking. The
CC platform is told to block DMA again, if it can.
If we ever do decide to support dual iommu then #2 would be the point
we swap the iommu control between the T=0/1 iommu.
> (And while untrusted vIOMMUs for purely-untrusted devices in CoCo
> environments would be pretty straightforward as well, I guess we might need
> some sort of acceptance status for trusted vIOMMU devices themselves?
> Hmm...)
That should fall into the overall plan for device acceptance. We want
the kernel to have a small policy of devices it would accept prior to
the initrd. Untrusted versions of iommu (and others) should not auto
probe.
The initrd can then decide if it wants to probe the untrusted
iommu. Probably it does not right now since we haven't done any
security analysis on the SMMUv3 being operated by a hostile
hypervisor. ARM should be OK here, a modular SMMUv3 will achieve this
trivially. x86 will have a harder time.
Userspace will run its acceptance flow and figure out what drivers to
bind. Along the way userspace will record what it is accepting in a
measurement log.
So, lots of little steps along the path. I imagine various series
something like:
- Basic version of #1 and #2 to generally defer opening DMA till
probe
- TSM APIs to support setting T=1 and doing the evidence suff
- T=1 flag for devices supported by IOMMU and DMA API, replacing force
dma unencrypted
- Userspace driven policy control over device binding
- General trust level concept, including an "adversarial" trust level
which will trigger various auto configuration and mitigations
- tsm_mr improvmements
- adversarial T=1 devices, eg SWIOTLB still bounce buffers but has to
support a private pool
Regards,
Jason
next prev parent reply other threads:[~2026-08-10 15:08 UTC|newest]
Thread overview: 96+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-17 18:04 [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 01/23] dma-direct: return struct page from dma_direct_alloc_from_pool() Aneesh Kumar K.V (Arm)
2026-07-21 11:54 ` Leon Romanovsky
2026-07-21 14:20 ` Aneesh Kumar K.V
2026-07-21 14:29 ` Leon Romanovsky
2026-07-21 15:10 ` Aneesh Kumar K.V
2026-07-21 15:33 ` Leon Romanovsky
2026-07-22 19:59 ` Jason Gunthorpe
2026-07-23 7:57 ` Leon Romanovsky
2026-07-25 14:34 ` Jason Gunthorpe
2026-07-26 8:17 ` Leon Romanovsky
2026-07-27 4:23 ` Jason Gunthorpe
2026-07-27 11:40 ` Leon Romanovsky
2026-07-28 12:31 ` Aneesh Kumar K.V
2026-07-28 14:24 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 02/23] dma-pool: fix page leak in atomic_pool_expand() cleanup Aneesh Kumar K.V (Arm)
2026-07-21 12:31 ` Leon Romanovsky
2026-07-21 14:41 ` Aneesh Kumar K.V
2026-07-21 15:34 ` Leon Romanovsky
2026-07-17 18:04 ` [PATCH v8 03/23] iommu/dma: Check atomic pool allocation result directly Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 04/23] dma: free atomic pool pages by physical address Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 05/23] swiotlb: Preserve allocation virtual address for dynamic pools Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 06/23] s390: Expose protected virtualization through cc_platform_has() Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 07/23] dma-direct: swiotlb: handle swiotlb alloc/free outside __dma_direct_alloc_pages Aneesh Kumar K.V (Arm)
2026-07-28 14:26 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 08/23] coco: arm64: s390: powerpc: Mark secure guests with CC_ATTR_GUEST_MEM_ENCRYPT Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 09/23] dma-mapping: Add internal shared allocation attribute Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 10/23] dma-direct: use __DMA_ATTR_ALLOC_CC_SHARED in alloc/free paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 11/23] dma-pool: track decrypted atomic pools and select them via attrs Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference Aneesh Kumar K.V (Arm)
2026-07-28 14:41 ` Mostafa Saleh
2026-07-29 9:05 ` Aneesh Kumar K.V
2026-07-29 10:08 ` Mostafa Saleh
2026-07-29 12:42 ` Aneesh Kumar K.V
2026-08-04 14:20 ` Jason Gunthorpe
2026-08-05 9:10 ` Mostafa Saleh
2026-08-05 12:30 ` Jason Gunthorpe
2026-08-07 11:03 ` Robin Murphy
2026-08-07 11:55 ` Jason Gunthorpe
2026-08-07 15:54 ` Robin Murphy
2026-08-07 17:01 ` Jason Gunthorpe
2026-08-10 14:18 ` Robin Murphy
2026-08-10 15:08 ` Jason Gunthorpe [this message]
2026-07-17 18:04 ` [PATCH v8 13/23] dma: swiotlb: track pool encryption state and honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 14/23] dma-mapping: make dma_pgprot() honor __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 15/23] dma-direct: pass attrs to dma_capable() for DMA_ATTR_CC_SHARED checks Aneesh Kumar K.V (Arm)
2026-07-28 14:30 ` Mostafa Saleh
2026-07-29 9:09 ` Aneesh Kumar K.V
2026-07-30 21:05 ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 16/23] dma-direct: Move dma_direct_map_phys() to dma/direct.c Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 17/23] dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-08-07 9:26 ` [PATCH] arm64: swiotlb: Keep the default size for protected guests Aneesh Kumar K.V (Arm)
2026-08-07 11:58 ` Will Deacon
2026-08-07 13:03 ` Aneesh Kumar K.V
2026-08-07 13:18 ` Will Deacon
2026-08-07 13:58 ` Jason Gunthorpe
2026-08-07 15:34 ` Mostafa Saleh
2026-08-07 16:47 ` Jason Gunthorpe
2026-08-07 18:13 ` Mostafa Saleh
2026-08-07 18:20 ` Jason Gunthorpe
2026-08-10 9:13 ` Marek Szyprowski
2026-08-10 9:29 ` Aneesh Kumar K.V
2026-08-10 10:20 ` Will Deacon
2026-08-10 11:37 ` Marek Szyprowski
2026-08-10 11:46 ` Will Deacon
2026-08-10 13:08 ` Jason Gunthorpe
2026-08-10 14:08 ` Robin Murphy
2026-08-10 14:14 ` Will Deacon
2026-08-10 15:44 ` Catalin Marinas
2026-08-10 15:58 ` Will Deacon
2026-08-10 16:21 ` Catalin Marinas
2026-08-10 14:33 ` Aneesh Kumar K.V
2026-08-07 18:00 ` Aneesh Kumar K.V
2026-08-10 5:00 ` Michael Kelley
2026-08-10 13:15 ` Robin Murphy
2026-08-07 17:59 ` Aneesh Kumar K.V
2026-07-17 18:04 ` [PATCH v8 18/23] dma-direct: set decrypted flag for remapped DMA allocations Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 19/23] dma-direct: select DMA address encoding from __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-28 14:31 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 20/23] dma-direct: rename ret to cpu_addr in alloc helpers Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 21/23] dma: swiotlb: free dynamic pools from process context Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 22/23] dma: swiotlb: handle set_memory_decrypted() failures Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 23/23] swiotlb: remove unused SWIOTLB_FORCE flag Aneesh Kumar K.V (Arm)
2026-07-21 12:40 ` [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Leon Romanovsky
2026-07-22 19:57 ` Jason Gunthorpe
2026-07-23 7:51 ` Leon Romanovsky
2026-07-25 14:32 ` Jason Gunthorpe
2026-07-25 7:09 ` Aneesh Kumar K.V
2026-07-31 7:33 ` Marek Szyprowski
2026-08-07 9:21 ` Aneesh Kumar K.V
2026-08-07 9:51 ` Mostafa Saleh
2026-08-07 10:04 ` Marek Szyprowski
2026-07-28 14:22 ` Mostafa Saleh
2026-07-29 9:12 ` Aneesh Kumar K.V
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260810150832.GB291736@nvidia.com \
--to=jgg@nvidia.com \
--cc=Suzuki.Poulose@arm.com \
--cc=agordeev@linux.ibm.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=ankita@nvidia.com \
--cc=borntraeger@linux.ibm.com \
--cc=catalin.marinas@arm.com \
--cc=chleroy@kernel.org \
--cc=dan.j.williams@intel.com \
--cc=gerald.schaefer@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=iommu@lists.linux.dev \
--cc=jiri@nvidia.com \
--cc=jiri@resnulli.us \
--cc=leon@kernel.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=m.szyprowski@samsung.com \
--cc=maddy@linux.ibm.com \
--cc=maz@kernel.org \
--cc=mhklinux@outlook.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=ptesarik@suse.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=steven.price@arm.com \
--cc=svens@linux.ibm.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox