From: Jason Gunthorpe <jgg@nvidia.com>
To: Mostafa Saleh <smostafa@google.com>
Cc: "Aneesh Kumar K.V" <aneesh.kumar@kernel.org>,
iommu@lists.linux.dev, linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, linux-coco@lists.linux.dev,
Robin Murphy <robin.murphy@arm.com>,
Marek Szyprowski <m.szyprowski@samsung.com>,
Will Deacon <will@kernel.org>, Marc Zyngier <maz@kernel.org>,
Steven Price <steven.price@arm.com>,
Suzuki K Poulose <Suzuki.Poulose@arm.com>,
Catalin Marinas <catalin.marinas@arm.com>,
Jiri Pirko <jiri@resnulli.us>, Petr Tesarik <ptesarik@suse.com>,
Alexey Kardashevskiy <aik@amd.com>,
Dan Williams <dan.j.williams@intel.com>,
Xu Yilun <yilun.xu@linux.intel.com>,
linuxppc-dev@lists.ozlabs.org, linux-s390@vger.kernel.org,
Madhavan Srinivasan <maddy@linux.ibm.com>,
Michael Ellerman <mpe@ellerman.id.au>,
Nicholas Piggin <npiggin@gmail.com>,
"Christophe Leroy (CS GROUP)" <chleroy@kernel.org>,
Alexander Gordeev <agordeev@linux.ibm.com>,
Gerald Schaefer <gerald.schaefer@linux.ibm.com>,
Heiko Carstens <hca@linux.ibm.com>,
Vasily Gorbik <gor@linux.ibm.com>,
Christian Borntraeger <borntraeger@linux.ibm.com>,
Sven Schnelle <svens@linux.ibm.com>,
x86@kernel.org, Michael Kelley <mhklinux@outlook.com>
Subject: Re: [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference
Date: Wed, 5 Aug 2026 09:30:23 -0300 [thread overview]
Message-ID: <20260805123023.GO27883@nvidia.com> (raw)
In-Reply-To: <anL9-OrDGqYQAWNV@google.com>
On Wed, Aug 05, 2026 at 09:10:16AM +0000, Mostafa Saleh wrote:
> On Tue, Aug 04, 2026 at 11:20:32AM -0300, Jason Gunthorpe wrote:
> > On Wed, Jul 29, 2026 at 06:12:38PM +0530, Aneesh Kumar K.V wrote:
> > > There is a possibility that we may support io_tlb_mem with cc_shared =
> > > false in the future. As a result, only swiotlb_map() knows which type of
> > > bounce buffer was used, making it the only place where the attributes
> > > can be updated correctly.
> >
> > Yeah, +1, the attribute should be changed at the same effective place
> > the source memory is changed away from what the DMA API user
> > provided. Only the thing providing the new memory (eg swiotlb) should
> > know its properties.
>
> I will keep the conversation here instead of 2 threads.
>
> That seems like a big leap, I'd be worried about devices that operate
> on confidential data that should not be shared/decrypted.
That seems like something very differnt.
> One example for this which exists in pKVM (this part is not
> upstream yet) is non coherent devices that require bouncing but they
> still want to keep the data private. In that case ideally they get
> an encrypted SWIOTLB pool, but it's always better to fail than to use
> a decrypted pool behind it's back.
We don't have any API for a DMA API caller to signal 'must be
confidential'. If we want to add one it would be a flag to check
before changing the physical address in swiotlb.
As defined today the DMA API expressly copies from private to shared
memory, that is baked into it's design and not a bug.
My expectation is all these cases have to be solved by setting up the
swiotlb properly so it provides suitable bounce buffers. Yes, this
means we will eventually need both private and shared swiotlb pools.
> I have not been following the work on T=1/T=0 devices, but IIRC, they
> required some complexity to handle their stage-2 as these modes will
> be emulated differently (for CCA, RMM vs untrusted host).
> I was thinking that it might be easier to represent those to the
> guest kernel as 2 separate devices (bounded to different groups...)
> where one is trusted and the other is not, and that way the DMA-API
> can have strict rules about memory sharing.
No way! That's would be a giant disaster for the driver model.
Each struct device will have a flag that shows if it is in T=1 or T=0
state. The flag can only change while a driver is not bound, and
changing the flag will update the DMA API configuration.
A T=1 device should have the same issue as you point out for pkvm, it
really needs to have a private SWIOTLB pool.
> Otherwise, SWIOTLB does not seem like the right place to me, as it
> does not understand the context the device is operating in, and the
> DMA-API should deduce that from the flags passed.
It is exactly the right place because it is the one supplying the new
memory. Context is irrelevant, the flag only describes what the new
memory actually *IS*, and swiotlb knows 100% if the new memory is
shared or private.
For your issue it would be appropriate to add a debugging check that
the new memory is not incompatible with the expected policy. eg a T=1
device getting decrypted swiotlb memory is a bug in swiotlb setup that
should be caught. But that's a debugging check, we expect the swiotlb
to have selected the right kind of memory by construction. This isn't
done yet since this series doesn't even yet support a T=1 device..
Jason
next prev parent reply other threads:[~2026-08-05 12:30 UTC|newest]
Thread overview: 62+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-17 18:04 [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 01/23] dma-direct: return struct page from dma_direct_alloc_from_pool() Aneesh Kumar K.V (Arm)
2026-07-21 11:54 ` Leon Romanovsky
2026-07-21 14:20 ` Aneesh Kumar K.V
2026-07-21 14:29 ` Leon Romanovsky
2026-07-21 15:10 ` Aneesh Kumar K.V
2026-07-21 15:33 ` Leon Romanovsky
2026-07-22 19:59 ` Jason Gunthorpe
2026-07-23 7:57 ` Leon Romanovsky
2026-07-25 14:34 ` Jason Gunthorpe
2026-07-26 8:17 ` Leon Romanovsky
2026-07-27 4:23 ` Jason Gunthorpe
2026-07-27 11:40 ` Leon Romanovsky
2026-07-28 12:31 ` Aneesh Kumar K.V
2026-07-28 14:24 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 02/23] dma-pool: fix page leak in atomic_pool_expand() cleanup Aneesh Kumar K.V (Arm)
2026-07-21 12:31 ` Leon Romanovsky
2026-07-21 14:41 ` Aneesh Kumar K.V
2026-07-21 15:34 ` Leon Romanovsky
2026-07-17 18:04 ` [PATCH v8 03/23] iommu/dma: Check atomic pool allocation result directly Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 04/23] dma: free atomic pool pages by physical address Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 05/23] swiotlb: Preserve allocation virtual address for dynamic pools Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 06/23] s390: Expose protected virtualization through cc_platform_has() Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 07/23] dma-direct: swiotlb: handle swiotlb alloc/free outside __dma_direct_alloc_pages Aneesh Kumar K.V (Arm)
2026-07-28 14:26 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 08/23] coco: arm64: s390: powerpc: Mark secure guests with CC_ATTR_GUEST_MEM_ENCRYPT Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 09/23] dma-mapping: Add internal shared allocation attribute Aneesh Kumar K.V (Arm)
2026-07-28 14:25 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 10/23] dma-direct: use __DMA_ATTR_ALLOC_CC_SHARED in alloc/free paths Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 11/23] dma-pool: track decrypted atomic pools and select them via attrs Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 12/23] dma: swiotlb: pass mapping attributes by reference Aneesh Kumar K.V (Arm)
2026-07-28 14:41 ` Mostafa Saleh
2026-07-29 9:05 ` Aneesh Kumar K.V
2026-07-29 10:08 ` Mostafa Saleh
2026-07-29 12:42 ` Aneesh Kumar K.V
2026-08-04 14:20 ` Jason Gunthorpe
2026-08-05 9:10 ` Mostafa Saleh
2026-08-05 12:30 ` Jason Gunthorpe [this message]
2026-07-17 18:04 ` [PATCH v8 13/23] dma: swiotlb: track pool encryption state and honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 14/23] dma-mapping: make dma_pgprot() honor __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 15/23] dma-direct: pass attrs to dma_capable() for DMA_ATTR_CC_SHARED checks Aneesh Kumar K.V (Arm)
2026-07-28 14:30 ` Mostafa Saleh
2026-07-29 9:09 ` Aneesh Kumar K.V
2026-07-30 21:05 ` Jason Gunthorpe
2026-07-17 18:04 ` [PATCH v8 16/23] dma-direct: Move dma_direct_map_phys() to dma/direct.c Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 17/23] dma-direct: make dma_direct_map_phys() honor DMA_ATTR_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 18/23] dma-direct: set decrypted flag for remapped DMA allocations Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 19/23] dma-direct: select DMA address encoding from __DMA_ATTR_ALLOC_CC_SHARED Aneesh Kumar K.V (Arm)
2026-07-28 14:31 ` Mostafa Saleh
2026-07-17 18:04 ` [PATCH v8 20/23] dma-direct: rename ret to cpu_addr in alloc helpers Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 21/23] dma: swiotlb: free dynamic pools from process context Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 22/23] dma: swiotlb: handle set_memory_decrypted() failures Aneesh Kumar K.V (Arm)
2026-07-17 18:04 ` [PATCH v8 23/23] swiotlb: remove unused SWIOTLB_FORCE flag Aneesh Kumar K.V (Arm)
2026-07-21 12:40 ` [PATCH v8 00/23] dma-mapping: Track shared DMA state through direct, pool and swiotlb paths Leon Romanovsky
2026-07-22 19:57 ` Jason Gunthorpe
2026-07-23 7:51 ` Leon Romanovsky
2026-07-25 14:32 ` Jason Gunthorpe
2026-07-25 7:09 ` Aneesh Kumar K.V
2026-07-31 7:33 ` Marek Szyprowski
2026-07-28 14:22 ` Mostafa Saleh
2026-07-29 9:12 ` Aneesh Kumar K.V
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805123023.GO27883@nvidia.com \
--to=jgg@nvidia.com \
--cc=Suzuki.Poulose@arm.com \
--cc=agordeev@linux.ibm.com \
--cc=aik@amd.com \
--cc=aneesh.kumar@kernel.org \
--cc=borntraeger@linux.ibm.com \
--cc=catalin.marinas@arm.com \
--cc=chleroy@kernel.org \
--cc=dan.j.williams@intel.com \
--cc=gerald.schaefer@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=iommu@lists.linux.dev \
--cc=jiri@resnulli.us \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=linuxppc-dev@lists.ozlabs.org \
--cc=m.szyprowski@samsung.com \
--cc=maddy@linux.ibm.com \
--cc=maz@kernel.org \
--cc=mhklinux@outlook.com \
--cc=mpe@ellerman.id.au \
--cc=npiggin@gmail.com \
--cc=ptesarik@suse.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=steven.price@arm.com \
--cc=svens@linux.ibm.com \
--cc=will@kernel.org \
--cc=x86@kernel.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome