From: Alexey Kardashevskiy <aik@amd.com>
To: <x86@kernel.org>
Cc: linux-kernel@vger.kernel.org, kvm@vger.kernel.org,
linux-crypto@vger.kernel.org, linux-pci@vger.kernel.org,
"Thomas Gleixner" <tglx@kernel.org>,
"Ingo Molnar" <mingo@redhat.com>,
"Borislav Petkov" <bp@alien8.de>,
"Dave Hansen" <dave.hansen@linux.intel.com>,
"H. Peter Anvin" <hpa@zytor.com>,
"Sean Christopherson" <seanjc@google.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Andy Lutomirski" <luto@kernel.org>,
"Peter Zijlstra" <peterz@infradead.org>,
"Ashish Kalra" <ashish.kalra@amd.com>,
"Tom Lendacky" <thomas.lendacky@amd.com>,
"Herbert Xu" <herbert@gondor.apana.org.au>,
"David S. Miller" <davem@davemloft.net>,
"Bjorn Helgaas" <bhelgaas@google.com>,
"Juergen Gross" <jgross@suse.com>,
"Stefano Stabellini" <sstabellini@kernel.org>,
"Oleksandr Tyshchenko" <oleksandr_tyshchenko@epam.com>,
"Marek Szyprowski" <m.szyprowski@samsung.com>,
"Robin Murphy" <robin.murphy@arm.com>,
"Andrew Morton" <akpm@linux-foundation.org>,
"David Hildenbrand" <david@kernel.org>,
"Lorenzo Stoakes" <ljs@kernel.org>,
"Liam R. Howlett" <liam@infradead.org>,
"Vlastimil Babka" <vbabka@kernel.org>,
"Mike Rapoport" <rppt@kernel.org>,
"Suren Baghdasaryan" <surenb@google.com>,
"Michal Hocko" <mhocko@suse.com>,
"Catalin Marinas" <catalin.marinas@arm.com>,
"Jini Susan George" <jinisusan.george@amd.com>,
"Kees Cook" <kees@kernel.org>,
"Michael Ellerman" <mpe@ellerman.id.au>,
"Nikunj A Dadhania" <nikunj@amd.com>,
"Ard Biesheuvel" <ardb@kernel.org>,
"Eric Biggers" <ebiggers@kernel.org>,
"Kim Phillips" <kim.phillips@amd.com>,
"Joerg Roedel" <jroedel@suse.de>,
"Ethan Nelson-Moore" <enelsonmoore@gmail.com>,
"Tycho Andersen (AMD)" <tycho@kernel.org>,
"Liam Merwick" <liam.merwick@oracle.com>,
"Michael Kerrisk" <mtk.manpages@gmail.com>,
"Suresh Siddha" <suresh.b.siddha@intel.com>,
"Xiaotian Feng" <dfeng@redhat.com>,
"Venkatesh Pallipadi" <venkatesh.pallipadi@intel.com>,
"Andi Kleen" <ak@linux.intel.com>,
"Kiryl Shutsemau" <kas@kernel.org>,
"Tony Luck" <tony.luck@intel.com>,
"Jason Gunthorpe" <jgg@ziepe.ca>,
"Lu Baolu" <baolu.lu@linux.intel.com>,
"Xu Yilun" <yilun.xu@linux.intel.com>,
"Carlos López" <clopez@suse.de>,
"Jonathan Cameron" <jic23@kernel.org>,
"Jori Koolstra" <jkoolstra@xs4all.nl>,
"Thomas Weißschuh" <thomas.weissschuh@linutronix.de>,
"Aneesh Kumar K.V (Arm)" <aneesh.kumar@kernel.org>,
"Ian Campbell" <ian.campbell@citrix.com>,
"Jeremy Fitzhardinge" <jeremy.fitzhardinge@citrix.com>,
"Petr Tesarik" <ptesarik@suse.com>,
"David Howells" <dhowells@redhat.com>,
"Haavard Skinnemoen" <hskinnemoen@atmel.com>,
"Kenji Kaneshige" <kaneshige.kenji@jp.fujitsu.com>,
"Ilpo Järvinen" <ilpo.jarvinen@linux.intel.com>,
"Christian Marangi" <ansuelsmth@gmail.com>,
"Dave Jiang" <dave.jiang@intel.com>,
"Michael Kelley" <mhklinux@outlook.com>,
"Ilias Stamatis" <ilstam@amazon.com>,
"Sumanth Korikkar" <sumanthk@linux.ibm.com>,
"Simona Vetter" <simona.vetter@ffwll.ch>,
"Toshi Kani" <toshi.kani@hp.com>,
"Greg Kroah-Hartman" <gregkh@linuxfoundation.org>,
"Vinod Koul" <vkoul@kernel.org>,
"Jiang Liu" <jiang.liu@linux.intel.com>,
"Arnd Bergmann" <arnd@arndb.de>,
"Anshuman Khandual" <anshuman.khandual@arm.com>,
"Kefeng Wang" <wangkefeng.wang@huawei.com>,
"Palmer Dabbelt" <palmerdabbelt@google.com>,
linux-coco@lists.linux.dev, xen-devel@lists.xenproject.org,
iommu@lists.linux.dev, linux-mm@kvack.org,
"Alexey Kardashevskiy" <aik@amd.com>,
aik@ozlabs.ru, "Santosh Shukla" <santosh.shukla@amd.com>,
"Pratik R . Sampat" <prsampat@amd.com>,
"Scott Soule Cheloha" <scott.cheloha@amd.com>,
"Ackerley Tng" <ackerleytng@google.com>,
"Fuad Tabba" <tabba@google.com>
Subject: [RFC PATCH kernel 08/17] x86/dma: Add ARCH_HAS_PHYS_TO_DMA
Date: Wed, 16 Sep 2026 21:51:48 +1000 [thread overview]
Message-ID: <20260916115159.1938195-9-aik@amd.com> (raw)
In-Reply-To: <20260916115159.1938195-1-aik@amd.com>
Confidential VMs work with both trusted and legacy (untrusted devices).
The trusted devices allow DMA to/from encrypted guest memory while legacy
devices have to use SWIOTLB or share pages for DMA.
In case of P2P between trusted and legacy devices, the trusted device has
to perform DMA with T=1 (a PCIe IDE TLP bit saying "encrypt") but the target
may be shared.
One way of allowing the above on AMD SEV is using IOMMU sDTE vTOM feature
which is a bus address:
- below that address all accesses target private guest memory;
- above - shared memory.
Effectively this adds some high bit in a DMA handle to mark "shared" (on
AMD).
Copy the generic phys_to_dma / dma_to_phys helpers from
include/linux/dma-direct.h into arch/x86/include/asm/dma-direct.h and
select ARCH_HAS_PHYS_TO_DMA for x86.
The x86 implementation is the same as the generic code for
__phys_to_dma, dma_range_map handling, and SME encryption, with two
additions for confidential devices:
- cc_shared_dma_offset and cc_private_dma_offset in dev_archdata
- when TDI is accepted is true, phys_to_dma() adds the shared or
private offset (selected by DMA_ATTR_CC_SHARED), and dma_to_phys()
subtracts it on the way back
phys_to_dma() also gains an attrs argument so dma_capable() and swiotlb can
pass mapping attributes through. Update the call sites accordingly.
Signed-off-by: Alexey Kardashevskiy <aik@amd.com>
---
DMA_ATTR_CC_SHARED or __DMA_ATTR_ALLOC_CC_SHARED?
---
arch/x86/Kconfig | 1 +
arch/x86/include/asm/device.h | 2 +
arch/x86/include/asm/dma-direct.h | 77 ++++++++++++++++++++
include/linux/dma-direct.h | 2 +-
drivers/xen/swiotlb-xen.c | 2 +-
kernel/dma/swiotlb.c | 2 +-
6 files changed, 83 insertions(+), 3 deletions(-)
diff --git a/arch/x86/Kconfig b/arch/x86/Kconfig
index 15fd9ec5ecac..c4df431e74b2 100644
--- a/arch/x86/Kconfig
+++ b/arch/x86/Kconfig
@@ -112,6 +112,7 @@ config X86
select ARCH_HAS_UBSAN
select ARCH_HAS_DEBUG_WX
select ARCH_HAS_ZONE_DMA_SET if EXPERT
+ select ARCH_HAS_PHYS_TO_DMA
select ARCH_HAVE_NMI_SAFE_CMPXCHG
select ARCH_HAVE_EXTRA_ELF_NOTES
select ARCH_MEMORY_ORDER_TSO
diff --git a/arch/x86/include/asm/device.h b/arch/x86/include/asm/device.h
index 7c0a52ca2f4d..0dbc2c125522 100644
--- a/arch/x86/include/asm/device.h
+++ b/arch/x86/include/asm/device.h
@@ -3,6 +3,8 @@
#define _ASM_X86_DEVICE_H
struct dev_archdata {
+ dma_addr_t cc_shared_dma_offset;
+ dma_addr_t cc_private_dma_offset;
};
struct pdev_archdata {
diff --git a/arch/x86/include/asm/dma-direct.h b/arch/x86/include/asm/dma-direct.h
new file mode 100644
index 000000000000..37074c87bbec
--- /dev/null
+++ b/arch/x86/include/asm/dma-direct.h
@@ -0,0 +1,77 @@
+/* SPDX-License-Identifier: GPL-2.0 */
+#ifndef ASM_X86_DMA_DIRECT_H
+#define ASM_X86_DMA_DIRECT_H 1
+
+#include <linux/pci-tsm.h>
+
+static inline dma_addr_t __phys_to_dma(struct device *dev, phys_addr_t paddr)
+{
+ if (dev->dma_range_map)
+ return translate_phys_to_dma(dev, paddr);
+
+ return paddr;
+}
+
+static inline bool __device_cc_accepted(struct device *dev)
+{
+ if (!dev || !dev_is_pci(dev) || !to_pci_dev(dev)->tsm)
+ return false;
+
+ return test_bit(PCI_TSM_F_ACCEPT, &to_pci_dev(dev)->tsm->flags);
+}
+
+static inline dma_addr_t phys_to_dma(struct device *dev, phys_addr_t paddr, unsigned long attrs)
+{
+ if (__device_cc_accepted(dev)) {
+ if (attrs & DMA_ATTR_CC_SHARED)
+ return __phys_to_dma(dev, paddr) + dev->archdata.cc_shared_dma_offset;
+
+ return __phys_to_dma(dev, paddr) + dev->archdata.cc_private_dma_offset;
+ }
+
+ return dma_addr_encrypted(__phys_to_dma(dev, paddr));
+}
+
+static inline phys_addr_t dma_to_phys(struct device *dev, dma_addr_t daddr)
+{
+ phys_addr_t paddr;
+
+ if (__device_cc_accepted(dev)) {
+ if (dev->archdata.cc_shared_dma_offset &&
+ daddr >= dev->archdata.cc_shared_dma_offset)
+ return daddr - dev->archdata.cc_shared_dma_offset;
+
+ if (dev->archdata.cc_private_dma_offset &&
+ daddr >= dev->archdata.cc_private_dma_offset)
+ return daddr - dev->archdata.cc_private_dma_offset;
+ }
+
+ daddr = dma_addr_canonical(daddr);
+ if (dev->dma_range_map)
+ paddr = translate_dma_to_phys(dev, daddr);
+ else
+ paddr = daddr;
+
+ return paddr;
+}
+
+static inline dma_addr_t phys_to_dma_unencrypted(struct device *dev, phys_addr_t paddr)
+{
+ if (__device_cc_accepted(dev))
+ return __phys_to_dma(dev, paddr) + dev->archdata.cc_shared_dma_offset;
+
+ return dma_addr_unencrypted(__phys_to_dma(dev, paddr));
+}
+
+static inline dma_addr_t phys_to_dma_encrypted(struct device *dev, phys_addr_t paddr)
+{
+ if (__device_cc_accepted(dev))
+ return __phys_to_dma(dev, paddr) + dev->archdata.cc_private_dma_offset;
+
+ return dma_addr_encrypted(__phys_to_dma(dev, paddr));
+}
+
+#define phys_to_dma_unencrypted phys_to_dma_unencrypted
+#define phys_to_dma_encrypted phys_to_dma_encrypted
+
+#endif /* ASM_X86_DMA_DIRECT_H */
diff --git a/include/linux/dma-direct.h b/include/linux/dma-direct.h
index daa31a1adf7b..616b66ccf322 100644
--- a/include/linux/dma-direct.h
+++ b/include/linux/dma-direct.h
@@ -150,7 +150,7 @@ static inline bool dma_capable(struct device *dev, dma_addr_t addr, size_t size,
return false;
if (is_ram && !IS_ENABLED(CONFIG_ARCH_DMA_ADDR_T_64BIT) &&
- min(addr, end) < phys_to_dma(dev, PFN_PHYS(min_low_pfn)))
+ min(addr, end) < phys_to_dma(dev, PFN_PHYS(min_low_pfn), attrs))
return false;
return end <= min_not_zero(*dev->dma_mask, dev->bus_dma_limit);
diff --git a/drivers/xen/swiotlb-xen.c b/drivers/xen/swiotlb-xen.c
index e2538824ef52..915c174f8b56 100644
--- a/drivers/xen/swiotlb-xen.c
+++ b/drivers/xen/swiotlb-xen.c
@@ -55,7 +55,7 @@ static inline phys_addr_t xen_phys_to_bus(struct device *dev, phys_addr_t paddr)
static inline dma_addr_t xen_phys_to_dma(struct device *dev, phys_addr_t paddr)
{
- return phys_to_dma(dev, xen_phys_to_bus(dev, paddr));
+ return phys_to_dma(dev, xen_phys_to_bus(dev, paddr), 0);
}
static inline phys_addr_t xen_bus_to_phys(struct device *dev,
diff --git a/kernel/dma/swiotlb.c b/kernel/dma/swiotlb.c
index ded7016a46a7..d7c7d15740ae 100644
--- a/kernel/dma/swiotlb.c
+++ b/kernel/dma/swiotlb.c
@@ -1764,7 +1764,7 @@ dma_addr_t swiotlb_map(struct device *dev, phys_addr_t paddr, size_t size,
phys_addr_t swiotlb_addr;
dma_addr_t dma_addr;
- trace_swiotlb_bounced(dev, phys_to_dma(dev, paddr), size);
+ trace_swiotlb_bounced(dev, phys_to_dma(dev, paddr, attrs), size);
swiotlb_addr = swiotlb_tbl_map_single(dev, paddr, size, 0, dir, &attrs);
if (swiotlb_addr == (phys_addr_t)DMA_MAPPING_ERROR)
--
2.55.0
next prev parent reply other threads:[~2026-09-16 11:57 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 11:51 [RFC PATCH kernel 00/17] PCI/TSM: coco/sev-guest: Implement SEV-TIO PCIe TDISP (phase2) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 01/17] pci/dma/tsm: Call disable DMA bus hook on cleanup Alexey Kardashevskiy
2026-09-16 17:49 ` Borislav Petkov
2026-09-16 11:51 ` [RFC PATCH kernel 02/17] pci/tsm: Fix stale comment about TDI report range start Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 03/17] tsm/core: Store range_id in pci_tsm_mmio_entry Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 04/17] crypto/ccp/tsm: Use TSM API for DOE Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 05/17] tsm-core: Register nevertheless Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 06/17] x86/io/tsm: Allow mixed ioremap for shared+private BARs Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 07/17] x86/dma: Revert "x86: Remove unnecessary architecture-specific <asm/device.h>" Alexey Kardashevskiy
2026-09-16 11:51 ` Alexey Kardashevskiy [this message]
2026-09-16 11:51 ` [RFC PATCH kernel 09/17] dma/swiotlb: Force shared DMA for allocatios from SWIOTLB Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 10/17] x86, dma: Allow accepted devices to map private memory Alexey Kardashevskiy
2026-09-16 12:48 ` Jason Gunthorpe
2026-09-16 11:51 ` [RFC PATCH kernel 11/17] tsm/core: Add TDI status Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 12/17] coco/sev-guest: Allow multiple source files in the driver Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 13/17] x86/sev: Pass HV features to sev-guest device via platform data Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 14/17] x86/sev: Add GHCB calls for SEV-TIO Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 15/17] x86/sev: Implement guest TSM driver for SEV-TIO (phase2, DMA) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 16/17] x86/sev: Enable secure MMIO (phase2) Alexey Kardashevskiy
2026-09-16 11:51 ` [RFC PATCH kernel 17/17] x86/sev: Flush IOMMU TLB for trusted devices Alexey Kardashevskiy
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916115159.1938195-9-aik@amd.com \
--to=aik@amd.com \
--cc=ackerleytng@google.com \
--cc=aik@ozlabs.ru \
--cc=ak@linux.intel.com \
--cc=akpm@linux-foundation.org \
--cc=aneesh.kumar@kernel.org \
--cc=anshuman.khandual@arm.com \
--cc=ansuelsmth@gmail.com \
--cc=ardb@kernel.org \
--cc=arnd@arndb.de \
--cc=ashish.kalra@amd.com \
--cc=baolu.lu@linux.intel.com \
--cc=bhelgaas@google.com \
--cc=bp@alien8.de \
--cc=catalin.marinas@arm.com \
--cc=clopez@suse.de \
--cc=dave.hansen@linux.intel.com \
--cc=dave.jiang@intel.com \
--cc=davem@davemloft.net \
--cc=david@kernel.org \
--cc=dfeng@redhat.com \
--cc=dhowells@redhat.com \
--cc=ebiggers@kernel.org \
--cc=enelsonmoore@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=herbert@gondor.apana.org.au \
--cc=hpa@zytor.com \
--cc=hskinnemoen@atmel.com \
--cc=ian.campbell@citrix.com \
--cc=ilpo.jarvinen@linux.intel.com \
--cc=ilstam@amazon.com \
--cc=iommu@lists.linux.dev \
--cc=jeremy.fitzhardinge@citrix.com \
--cc=jgg@ziepe.ca \
--cc=jgross@suse.com \
--cc=jiang.liu@linux.intel.com \
--cc=jic23@kernel.org \
--cc=jinisusan.george@amd.com \
--cc=jkoolstra@xs4all.nl \
--cc=jroedel@suse.de \
--cc=kaneshige.kenji@jp.fujitsu.com \
--cc=kas@kernel.org \
--cc=kees@kernel.org \
--cc=kim.phillips@amd.com \
--cc=kvm@vger.kernel.org \
--cc=liam.merwick@oracle.com \
--cc=liam@infradead.org \
--cc=linux-coco@lists.linux.dev \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mm@kvack.org \
--cc=linux-pci@vger.kernel.org \
--cc=ljs@kernel.org \
--cc=luto@kernel.org \
--cc=m.szyprowski@samsung.com \
--cc=mhklinux@outlook.com \
--cc=mhocko@suse.com \
--cc=mingo@redhat.com \
--cc=mpe@ellerman.id.au \
--cc=mtk.manpages@gmail.com \
--cc=nikunj@amd.com \
--cc=oleksandr_tyshchenko@epam.com \
--cc=palmerdabbelt@google.com \
--cc=pbonzini@redhat.com \
--cc=peterz@infradead.org \
--cc=prsampat@amd.com \
--cc=ptesarik@suse.com \
--cc=robin.murphy@arm.com \
--cc=rppt@kernel.org \
--cc=santosh.shukla@amd.com \
--cc=scott.cheloha@amd.com \
--cc=seanjc@google.com \
--cc=simona.vetter@ffwll.ch \
--cc=sstabellini@kernel.org \
--cc=sumanthk@linux.ibm.com \
--cc=surenb@google.com \
--cc=suresh.b.siddha@intel.com \
--cc=tabba@google.com \
--cc=tglx@kernel.org \
--cc=thomas.lendacky@amd.com \
--cc=thomas.weissschuh@linutronix.de \
--cc=tony.luck@intel.com \
--cc=toshi.kani@hp.com \
--cc=tycho@kernel.org \
--cc=vbabka@kernel.org \
--cc=venkatesh.pallipadi@intel.com \
--cc=vkoul@kernel.org \
--cc=wangkefeng.wang@huawei.com \
--cc=x86@kernel.org \
--cc=xen-devel@lists.xenproject.org \
--cc=yilun.xu@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®