From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4A8AC32A3DA for ; Wed, 24 Jun 2026 05:54:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782280492; cv=none; b=lDt6eJhXAG7lyCwZat8OBOUv2Ixp6lbNq0pH/dOmXcs3e1n1c7ALRH8Bb9itN9SJUxrcZT6Zun+izaO41r4+1PeNUOO879ly7whYRza7ipbUDjGQRNB3IMtDGf0NgLzX5kaVaACqKE257IXlw1P114w3O+3QlvzcYGAkFmVUHWo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1782280492; c=relaxed/simple; bh=9H2LXXH1ijxCQaeue1SG4WwhkL9LpGm+RywgeqInJ1I=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=QG4Kcf1G1x6t3Ab3rCsC1NxGsA9Gsca4RczJ5GcAWtHuX9Iz7nqR2aASZ+VKOk/pVnESb+LsICuxfDNqRD9NoDTm40/9alGYFn6mUj+/OZI5TLf1sR/n16//88OwZtm8EfGoGIWJYnv4BPHC23Tj/bLY5u98c3K/bRpTGcWUo8E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=V1KMypld; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=clFPgAXk; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="V1KMypld"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="clFPgAXk" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 65O1SxGD1386766 for ; Wed, 24 Jun 2026 05:54:50 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= vGkBHGU47ddmNPvFDOUDXBceGSA+1MmLTmUnnSnIwOQ=; b=V1KMypldk/vHXHHd FXVsNRBPu0Eb6EaTHFwrZCAaiypnrUlYdEbIYFQeeNE0lVMKRsVHr1d2ijON+x4+ wUko6Qf3INl5zd3INJo9ox8yJfmN9CZhOen1qvwYqgGYgozyQGGH6/QpTuYZoOda Ew649YvOIQPX/BySWkOI5D6wStV2MLwzLetf3StAWEeHdyYxMrHe56GY2Y/e+iDB 0wpw5ylHYfkxzJr+/mE/x5mcziVJBaOIdifumLaFXp8+2LZWwf+FpnRp0kv7A+BM 5pMjpBlFOhun8kkZ7gRTfPS0rwRzdS9uqTrJuRk3nEMLz9Jdq3Y/EnowlAozcVPI MWOR8g== Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4f00ev9m1q-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 24 Jun 2026 05:54:49 +0000 (GMT) Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-c90101fb3deso439459a12.3 for ; Tue, 23 Jun 2026 22:54:49 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1782280489; x=1782885289; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=vGkBHGU47ddmNPvFDOUDXBceGSA+1MmLTmUnnSnIwOQ=; b=clFPgAXkLh9e/3eI26weJOx9fzIQguXM0QEUmN3/MqFCBOXFCAVbJ0vF4fqfG52TsP yUeNroLedja6HH8aTWIC/Zg0wIqmvYmceIHv7f+oPwgk72Fjhg0ErvFFO43EWEiMoPTg 0dKBLXR/T43BSYTZLM3wfHGsqCBsnRqI2OJ/17+HvwpMV+hzHnLvxNDLs86Bu1gS3d4c /bpZ8Qcys5JlwWnN2jXYE/bcMui37julf5XdPjjPrjwzXOhUEAlcNdUIT1lryfF4bEd9 tX7cO3t87BVLXaTkNpng19PcJ1Wo30WKWTRMHzUWkSah7yGB43rOIU1nA9MgvWZnROFA 57CA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1782280489; x=1782885289; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=vGkBHGU47ddmNPvFDOUDXBceGSA+1MmLTmUnnSnIwOQ=; b=fLhzrsPV0oOJUasfvnXnefjbyhSj9IL1fZfqCe1B8NJ1u1F2Gs7vzGfSdm0z7koDav 0YB71aH8o5P61QNt2xfQt6DmDgGjn3XqKW+ljDtFabKBS08ZORM6j6py1q6H0oH5QCXy VFzzpXF/KGhTvWWYOhHNzO5hsXBNJ4qZCsxmmUj7wJ92OlI/vF09PUijEoeE8/4WjP8K PCKAreWHw1jBrUuFc1UT0unyQf7chGG7AVzmQs9Sqwihl9U8ONUDfquoenudR8UpEnUK oeE9iKa0VL+U6H/148ny6U4EYq1Z5pDmhfqzXpjliVyhwuGITn0ja10RCgNRDIBKtjd6 gf2Q== X-Forwarded-Encrypted: i=1; AHgh+Rp7gVpN2iG7D1btIBSHTN70Zn7YDXS4wP35WexX8jUBYj7gZ1v03c1ObO5sy9mQH1SvHMgLQfjMLWxBU28=@vger.kernel.org X-Gm-Message-State: AOJu0YzWovQhZvE43eMcBTYOM8g0smkxLF+odfwr7VSZBNvfUEMD6NoN nEobBsZEFxQM914P25MGb1antfNiSgKyg+6sHYVeFg63Cya6q269Vp5UqA/TQyKbyAz3hamRCUq 2wBg9QOVa76HSk0QlcBUjt02QSa68Im3lLYpNxDi0Tj899Bk5DQVkOMG/FtEAcZJT6y0= X-Gm-Gg: AfdE7cmCllxduf6HxLqedQWNnsltJtkLiuSkiMevHJK8mptcBTxmNHsI+oiXrCYQ3ND mL4PNYmgzMzoyaXr+UenJL2MeFPx43sutMNljyWUInNe4xONItlwweniBf9vODV/eZzObhw+0a7 mMVKQT89NBNkOu/Yzm0udt3gGXS8c7y1hjv8QC+KbrkX/O/PWvipxrjp742a22LwpX2AK0i+mEy QadNNT31F9tNV0PTOeZ4mYPjE3gxODE3oxgkdJbAbyi/Ipz6Odc34H32zGux1OEPcLxOOX/sQYJ ra0OQDhSDSU40Jak2fex0OFuSQl2Q1pcrA3s3YxPPg5UVUZWbY6KRVy/7kYEmVcFip+qbpg4HbB VvOWaFGp5cVUXj2pOz3ksit/bXoPrG2JNTnio+Zx4kiZ9Ynce3pN5j4eoo1oy8rTqdqg5WChmIb KarZiDgXtMUfRnYxPBXs8Zo7hPrOc7 X-Received: by 2002:a05:6a00:e88:b0:82f:72e6:ed4 with SMTP id d2e1a72fcca58-845a24ebe94mr2890244b3a.0.1782280488958; Tue, 23 Jun 2026 22:54:48 -0700 (PDT) X-Received: by 2002:a05:6a00:e88:b0:82f:72e6:ed4 with SMTP id d2e1a72fcca58-845a24ebe94mr2890221b3a.0.1782280488504; Tue, 23 Jun 2026 22:54:48 -0700 (PDT) Received: from [10.193.24.221] (blr-bdr-fw-01_GlobalNAT_AllZones-Outside.qualcomm.com. [103.229.18.19]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-845a3feb7b3sm1210952b3a.13.2026.06.23.22.54.43 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 23 Jun 2026 22:54:47 -0700 (PDT) Message-ID: <0e1c5b0e-9442-4fcb-936a-dedbe7b1f8a5@oss.qualcomm.com> Date: Wed, 24 Jun 2026 11:24:42 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH v3] x86/pci-dma: add a SWIOTLB_ANY flag to lift the low mem limitation To: Borislav Petkov , "Miao, Jun" Cc: "tglx@kernel.org" , "mingo@redhat.com" , "dave.hansen@linux.intel.com" , "m.szyprowski@samsung.com" , "robin.murphy@arm.com" , "x86@kernel.org" , "linux-kernel@vger.kernel.org" , "Edgecombe, Rick P" , Tom Lendacky , Michael Roth , Nikunj A Dadhania References: <20260212093701.4165275-1-jun.miao@intel.com> <20260601055431.GAah0el3Tmk824mhgb@fat_crate.local> <20260624014307.GBajs2K1mqot3ZUwng@fat_crate.local> <20260624022947.GCajtBG92H2po_GxdG@fat_crate.local> <20260624051151.GEajtnF44jZ6hlnIhi@fat_crate.local> Content-Language: en-US From: Aakarsh Jain In-Reply-To: <20260624051151.GEajtnF44jZ6hlnIhi@fat_crate.local> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Proofpoint-Spam-Info: AW1haW4tMjYwNjI0MDA0NSBTYWx0ZWRfX1e+yH/fGyLf7 DOerJD4ypssP1n1yZi5YqnR04DzyUc9Wl3wTqqvC4icBmm8yeWQurD+AUpbpdK1cw/XSFiLnoqm CEuS+3PqvVafAEwQYS46dr+vTQGB3II= X-Authority-Analysis: v=2.4 cv=JbaMa0KV c=1 sm=1 tr=0 ts=6a3b7129 cx=c_pps a=oF/VQ+ItUULfLr/lQ2/icg==:117 a=Ou0eQOY4+eZoSc0qltEV5Q==:17 a=GrlH_9Pr-laFOETL:21 a=IkcTkHD0fZMA:10 a=FelO9ux0wxsA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=lhDUGOEZoVihWeNzqYIA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=3WC7DwWrALyhR5TkjVHa:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjI0MDA0NSBTYWx0ZWRfX6qR3nQK2HTvI ksmoyGpDMi8qwU59cTwTba1M5+jFDbuU/GY1HriiMAiSIM8IzgsqaNrXbxcIzrsSJ8H/eF5HwQU UIB5JyfuXt3iZI+JRWObqmrVcXXktuzTmghle8ffuWPju4G5D6jlJTDhZLauFcQvExUAJMejkRb HfusRuyVJ2RI8w8/90G7ug8/abPh4LgZ0O1ONTlKQtQ7Dc6hfbtl1bTLB5G9XApHBJIxAUsQfgU PdKw0+kbQEmRxezigt10ie62v5fst1w5Kg+B4sJ15d6ciTtEhtqAQed990XKas9au/fVvq/h4dS uuAcaQo7SNlmS1SEksqbzNwkOm+bzeGPWq2I7woK5cNHmdLWeCSIbDHV3WhQIqIl4Tzc6A4kJn0 hMf2PCY6JYYJd6kvWhBBoozE+kMJ0Q== X-Proofpoint-ORIG-GUID: TgND2h91SpSSXBMXRU1Tend52sHDzRXO X-Proofpoint-GUID: TgND2h91SpSSXBMXRU1Tend52sHDzRXO X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-24_01,2026-06-23_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 phishscore=0 lowpriorityscore=0 spamscore=0 malwarescore=0 suspectscore=0 adultscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2606240045 Hi Borislav, On 6/24/2026 10:41 AM, Borislav Petkov wrote: > On Wed, Jun 24, 2026 at 03:23:39AM +0000, Miao, Jun wrote: >>> On Wed, Jun 24, 2026 at 01:53:39AM +0000, Miao, Jun wrote: >>>> Good suggestion and thank you for testing the ADM SEV-SNP. >>> >>> I don't think anyone tested it on SNP yet. >> >> I only know that SEV-SNP is a more advanced, third-generation feature. >> Are we using "SEV" here as a shorthand for these? > > You have SEV, SEV-ES and SEV-SNP in the order of their appearance and in the > order they have gotten additional features. SNP is the one which is has > addressed the most if not all? confidential VM attack vectors. And that's the > one I care about as the other two are just the prerequisites to the SNP thing. > In my opinion only anyway. > >> When using confidential VMs, users want to pass through both the high-speed >> network interface card (NIC) or an 8-GPUs setup into the CVMs. During data >> transfer, the SWIOTLB bounce buffer becomes a critical "hot path" acting as >> an intermediary for convertor between private and shared memory. >> consequently, the capacity requirement increases—otherwise, network or data >> transfer performance would be adversely affected. > > Yes, that makes more sense. Pls add it to the commit message. > >> What I mean to convey is that in TEE environments based on AMD SEV or Intel TDX, >> the core issue is the lack of trust in the hypervisor's VMM. > > Then say it this way. Trusted hypervisor sounds like we trust the HV. Which we > absolutely do not. > >> When using confidential VMs, users want to pass through both the high-speed >> network interface card (NIC) or an 8-GPUs setup into the CVMs. During data >> transfer, the SWIOTLB bounce buffer becomes a critical "hot path" acting as >> an intermediary for convertor between private and shared memory. >> consequently, the capacity requirement increases—otherwise, network or data >> transfer performance would be adversely affected >> >> Confidential VMs include AMD SEV and Intel TDX guests want to allocate >> a swiotlb buffer that is not restricted to low memory in TEE. > > Sounds better, yes. > > Except that we still need to test it on SNP. > > Adding some folks on Cc who can do that and take a look at your patch and vet > it for SNP - my guest is still broken. :-\ > I tested this patch on a SEV-SNP guest and it works as expected. The SWIOTLB buffer is now allocated above the 4 GB low-memory boundary, confirming that the SWIOTLB_ANY flag takes effect on SNP as well. I was also able to scale the bounce buffer size up to support larger networking workloads. From kernel dmesg logs: root@ubuntu:/home/ubuntu# dmesg | grep -i sev [ 21.191917] Memory Encryption Features active: AMD SEV SEV-ES SEV-SNP [ 21.192883] SEV: Status: SEV SEV-ES SEV-SNP [ 21.401897] SEV: APIC: wakeup_secondary_cpu() replaced with wakeup_cpu_via_vmgexit() [ 22.117267] SEV: Using SNP CPUID table, 28 entries present. [ 22.117884] SEV: SNP running at VMPL0. [ 24.164260] SEV: SNP guest platform devices initialized. [ 28.815142] systemd[1]: Detected confidential virtualization sev-snp. [ 30.063831] sev-guest sev-guest: Initialized SEV guest driver (using VMPCK0 communication key) root@ubuntu:/home/ubuntu# dmesg | grep -i "IO TLB" [ 6.743607] software IO TLB: area num 4. [ 24.164169] software IO TLB: mapped [mem 0x0000001df9c00000-0x0000001ff9c00000] (8192MB) [ 24.331266] software IO TLB: Memory encryption is active and system is using DMA bounce buffers root@ubuntu:/home/ubuntu# Thanks, Aakarsh> Thx. >