From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00B792F0C7E for ; Mon, 21 Sep 2026 00:48:53 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951736; cv=none; b=W0XlYCaqfYT3udT/GthYN6ej40ClLDmKRiWjvK3hf/mudL7zyLB0bXajJkmnfuBOb0SL5zHvHQum4VesVhiG62lZHAAytQVs74wb78lLdTB+R5vyhKD/CYDzzm2PY9CNcti89gh0JFOlsepkjU7ez+na/HxGrhI0VvWA+DAhdsU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789951736; c=relaxed/simple; bh=avPZ16PAm2KRLLs3zFSBl7jOowUvnuNq+fuMqUotd3A=; h=Date:In-Reply-To:Mime-Version:References:Message-ID:Subject:From: To:Cc:Content-Type; b=bAtiItiyn3Fo0BFgLA+Zy3GL3/DoO6zJW3Gk/U1+Jgq00e9HVTeBdS1KTjmvDbsaJMYPuyiToJFUsIrvv8n65O2TZ37TWT+jBnyFSvwNgOS2hrPe/XOsBavcaJ9XpKwE6oJgUDuT9mNIPY1949Zvo+W8h7MFpt+nuxa12yopBmI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b=BRfbpAcZ; arc=none smtp.client-ip=209.85.210.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=google.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=flex--skhawaja.bounces.google.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=google.com header.i=@google.com header.b="BRfbpAcZ" Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-86a2639398cso5295365b3a.3 for ; Sun, 20 Sep 2026 17:48:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20251104; t=1789951733; x=1790556533; darn=vger.kernel.org; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:from:to:cc:subject:date:message-id:reply-to :content-type; bh=/sjf1DDcqeGOiFnNg/3dW38k0O9F/mHXt9LSFR/mRoI=; b=BRfbpAcZmOmJDGP4osSCg3PLLoHDJDWTaenp35KhmHipsl2mvDqOW0HJNs/Mz3dnm8 OuTGTXf7g0RDlyfXBs4N0Ojr8OQ5z4LQvslxytFh+xppBK75Hv2VdGPLY35vlU6HBHZJ ghCm3nYmcbctH6qIbfW413jxO9y1e1TtlNssbcpBXYrnLCPYOYmuK4DVLZoOMbmXmrRZ gZK4rwZbbbb3oI/Kl5nCLbIToLF6PBen8ll7VNflqmu0ASesIf6gEd26jbIyUrF1jPs2 xAyY+UNCQUM/RTXWMQimMTY4D/AwWHKdD7rID4c9C06Fj68Xvsze9Q5amlR/kMpMjQoM z2IA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789951733; x=1790556533; h=content-type:cc:to:from:subject:message-id:references:mime-version :in-reply-to:date:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/sjf1DDcqeGOiFnNg/3dW38k0O9F/mHXt9LSFR/mRoI=; b=f8t0V/ADkRD4zHzvdymwAF3vBy6HQhewhZXY53e24O4o2YlLu+OgXTaOwDCpHKS7Tx gxj4xICv4bhBcbPaTUxwgnVqZkAZbgGotDj+YhiMbuOGc5rLiY77WH0gLdYr7oHzfcjl MFJxTnD4bHAWtOfiUiN3u3vpS+Rr2ZPM7eey6aF2yu+X8snzNqoh188wORC4Otfuadlm GCesPoW59LL4N3qoK4E0WkMHcd91YoA1oeupQT7txd70EK+5a2otD4bdXbEF7KSrrftN Kpa2MMHdpYD+81O0dRk9082sTYQv0N/EjvOph3rLh16k3ApLdSUnEuqIQzuS+9jamb8A tN4g== X-Forwarded-Encrypted: i=1; AKwUvBympj6EPe5IDe5gZ4+VjDWdpXFrzISQx/sOiw1zp1lUASrRwZPUT8FcyHsUK3Ryfsewl3D8u43DgCrIf2Y=@vger.kernel.org X-Gm-Message-State: AFuF++mlXf0ExuhBb4abjv2DhZ0QAfwYDZS/y7sG56zA2oGV6OMEmuMp LGoRTl7pHzErcrXSqYDbyVXKgj+XQOZxYpYlViQq2/sPLEq/Ek5NEktc70nOM5XI8mG9mXUqDwb x/sn5bkI1MT5NVg== X-Received: from pgtk20.prod.google.com ([2002:a65:68d4:0:b0:cc5:1024:105e]) (user=skhawaja job=prod-delivery.src-stubby-dispatcher) by 2002:a05:6a00:1804:b0:852:131f:b9d2 with SMTP id d2e1a72fcca58-874db8eab76mr12887659b3a.2.1789951732364; Sun, 20 Sep 2026 17:48:52 -0700 (PDT) Date: Mon, 21 Sep 2026 00:48:30 +0000 In-Reply-To: <20260921004834.2601285-1-skhawaja@google.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 References: <20260921004834.2601285-1-skhawaja@google.com> X-Mailer: git-send-email 2.55.0.1082.g2b9226bbc0-goog Message-ID: <20260921004834.2601285-15-skhawaja@google.com> Subject: [PATCH v5 14/18] iommufd: Implement ioctl to mark HWPT for preservation From: Samiullah Khawaja To: David Woodhouse , Lu Baolu , Joerg Roedel , Will Deacon , Jason Gunthorpe Cc: YiFei Zhu , Pranjal Shrivastava , Samiullah Khawaja , Robin Murphy , Kevin Tian , Alex Williamson , Shuah Khan , iommu@lists.linux.dev, linux-kernel@vger.kernel.org, kvm@vger.kernel.org, Pratyush Yadav , Pasha Tatashin , David Matlack , Andrew Morton , Vipin Sharma Content-Type: text/plain; charset="UTF-8" From: YiFei Zhu Userspace provides a token to mark the HWPT for preservation. Note that this token is not the LUO token that is used to preserve the iommufd. Once all the required HWPT are marked for preservation, the user can preserve the iommufd into LUO. The iommufd will preserve the HWPTs that are marked for preservation. The marked HWPTs are tracked using a new XArray mark protected by a new liveupdate mutex. This mutex will also be used during iommufd preservation to protect against any race with the mark preserve ioctl. The HWPT token will be used during restore to identify this HWPT. The restoration logic is not implemented and will be added later. Reviewed-by: Pranjal Shrivastava Signed-off-by: YiFei Zhu Signed-off-by: Samiullah Khawaja --- MAINTAINERS | 1 + drivers/iommu/iommufd/Makefile | 1 + drivers/iommu/iommufd/iommufd_private.h | 17 ++++++ drivers/iommu/iommufd/liveupdate.c | 71 +++++++++++++++++++++++++ drivers/iommu/iommufd/main.c | 9 ++++ include/uapi/linux/iommufd.h | 27 ++++++++++ 6 files changed, 126 insertions(+) create mode 100644 drivers/iommu/iommufd/liveupdate.c diff --git a/MAINTAINERS b/MAINTAINERS index ae6df95dc398..d4848ec3a9d6 100644 --- a/MAINTAINERS +++ b/MAINTAINERS @@ -13728,6 +13728,7 @@ M: Samiullah Khawaja R: Pranjal Shrivastava L: iommu@lists.linux.dev S: Maintained +F: drivers/iommu/iommufd/liveupdate.c F: drivers/iommu/liveupdate.c F: include/linux/iommu-liveupdate.h F: include/linux/kho/abi/iommu.h diff --git a/drivers/iommu/iommufd/Makefile b/drivers/iommu/iommufd/Makefile index 67207914bb6e..cfd5b4b14ccb 100644 --- a/drivers/iommu/iommufd/Makefile +++ b/drivers/iommu/iommufd/Makefile @@ -12,6 +12,7 @@ iommufd-y := \ iommufd-$(CONFIG_IOMMUFD_NOIOMMU) += hwpt_noiommu.o iommufd-$(CONFIG_IOMMUFD_TEST) += selftest.o +iommufd-$(CONFIG_IOMMU_LIVEUPDATE) += liveupdate.o obj-$(CONFIG_IOMMUFD) += iommufd.o obj-$(CONFIG_IOMMUFD_DRIVER) += iova_bitmap.o diff --git a/drivers/iommu/iommufd/iommufd_private.h b/drivers/iommu/iommufd/iommufd_private.h index eb2e85b27e42..a33b32708afa 100644 --- a/drivers/iommu/iommufd/iommufd_private.h +++ b/drivers/iommu/iommufd/iommufd_private.h @@ -44,6 +44,11 @@ struct iommufd_ctx { struct file *file; struct xarray objects; struct xarray groups; +#ifdef CONFIG_IOMMU_LIVEUPDATE +#define IOMMUFD_OBJ_LIVEUPDATE_MARK XA_MARK_1 + /* @liveupdate_mutex: Protects the preservation of HWPTs. */ + struct mutex liveupdate_mutex; +#endif wait_queue_head_t destroy_wait; struct rw_semaphore ioas_creation_lock; struct maple_tree mt_mmap; @@ -392,6 +397,9 @@ struct iommufd_hwpt_paging { bool auto_domain : 1; bool enforce_cache_coherency : 1; bool nest_parent : 1; +#ifdef CONFIG_IOMMU_LIVEUPDATE + u64 liveupdate_token; +#endif /* Head at iommufd_ioas::hwpt_list */ struct list_head hwpt_item; struct iommufd_sw_msi_maps present_sw_msi; @@ -729,6 +737,15 @@ void iommufd_vdevice_abort(struct iommufd_object *obj); int iommufd_hw_queue_alloc_ioctl(struct iommufd_ucmd *ucmd); void iommufd_hw_queue_destroy(struct iommufd_object *obj); +#ifdef CONFIG_IOMMU_LIVEUPDATE +int iommufd_hwpt_liveupdate_mark_preserve(struct iommufd_ucmd *ucmd); +#else +static inline int iommufd_hwpt_liveupdate_mark_preserve(struct iommufd_ucmd *ucmd) +{ + return -ENOTTY; +} +#endif + #ifdef CONFIG_IOMMUFD_TEST int iommufd_test(struct iommufd_ucmd *ucmd); void iommufd_selftest_destroy(struct iommufd_object *obj); diff --git a/drivers/iommu/iommufd/liveupdate.c b/drivers/iommu/iommufd/liveupdate.c new file mode 100644 index 000000000000..96f01ee5a1e8 --- /dev/null +++ b/drivers/iommu/iommufd/liveupdate.c @@ -0,0 +1,71 @@ +// SPDX-License-Identifier: GPL-2.0-only + +/* + * Copyright (C) 2026, Google LLC + * Author: Samiullah Khawaja + */ + +#define pr_fmt(fmt) "iommufd: " fmt + +#include +#include +#include + +#include "iommufd_private.h" + +int iommufd_hwpt_liveupdate_mark_preserve(struct iommufd_ucmd *ucmd) +{ + struct iommu_hwpt_liveupdate_mark_preserve *cmd = ucmd->cmd; + struct iommufd_hwpt_paging *hwpt_target; + struct iommufd_hwpt_paging *hwpt_paging; + struct iommufd_ctx *ictx = ucmd->ictx; + struct iommufd_object *obj; + unsigned long index; + bool marked = false; + int rc = 0; + + hwpt_target = iommufd_get_hwpt_paging(ucmd, cmd->hwpt_id); + if (IS_ERR(hwpt_target)) + return PTR_ERR(hwpt_target); + + mutex_lock(&ictx->liveupdate_mutex); + + xa_lock(&ictx->objects); + + /* PRI use cases are not supported. */ + if (hwpt_target->common.fault) { + rc = -EOPNOTSUPP; + goto out_unlock; + } + + xa_for_each_marked(&ictx->objects, index, obj, IOMMUFD_OBJ_LIVEUPDATE_MARK) { + if (WARN_ON_ONCE(obj->type != IOMMUFD_OBJ_HWPT_PAGING)) + continue; + + hwpt_paging = to_hwpt_paging(container_of(obj, struct iommufd_hw_pagetable, obj)); + + if (hwpt_paging == hwpt_target) + marked = true; + + if (hwpt_paging->liveupdate_token == cmd->hwpt_token) { + if (hwpt_paging == hwpt_target) + goto out_unlock; + + rc = -EADDRINUSE; + goto out_unlock; + } + } + + __xa_set_mark(&ictx->objects, hwpt_target->common.obj.id, IOMMUFD_OBJ_LIVEUPDATE_MARK); + + if (marked) + pr_warn_ratelimited("Overwriting HWPT liveupdate token from: %llu to %llu\n", + hwpt_target->liveupdate_token, cmd->hwpt_token); + hwpt_target->liveupdate_token = cmd->hwpt_token; + +out_unlock: + xa_unlock(&ictx->objects); + mutex_unlock(&ictx->liveupdate_mutex); + iommufd_put_object(ictx, &hwpt_target->common.obj); + return rc; +} diff --git a/drivers/iommu/iommufd/main.c b/drivers/iommu/iommufd/main.c index 9a921b153162..fe8610fd58e3 100644 --- a/drivers/iommu/iommufd/main.c +++ b/drivers/iommu/iommufd/main.c @@ -333,6 +333,9 @@ static int iommufd_fops_open(struct inode *inode, struct file *filp) init_rwsem(&ictx->ioas_creation_lock); xa_init_flags(&ictx->objects, XA_FLAGS_ALLOC1 | XA_FLAGS_ACCOUNT); xa_init(&ictx->groups); +#ifdef CONFIG_IOMMU_LIVEUPDATE + mutex_init(&ictx->liveupdate_mutex); +#endif ictx->file = filp; mt_init_flags(&ictx->mt_mmap, MT_FLAGS_ALLOC_RANGE); init_waitqueue_head(&ictx->destroy_wait); @@ -395,6 +398,9 @@ static int iommufd_fops_release(struct inode *inode, struct file *filp) * iommufd_object_tombstone_user() */ xa_destroy(&ictx->objects); +#ifdef CONFIG_IOMMU_LIVEUPDATE + mutex_destroy(&ictx->liveupdate_mutex); +#endif WARN_ON(!xa_empty(&ictx->groups)); @@ -440,6 +446,7 @@ union ucmd_buffer { struct iommu_hwpt_alloc hwpt; struct iommu_hwpt_get_dirty_bitmap get_dirty_bitmap; struct iommu_hwpt_invalidate cache; + struct iommu_hwpt_liveupdate_mark_preserve mark_preserve; struct iommu_hwpt_set_dirty_tracking set_dirty_tracking; struct iommu_ioas_alloc alloc; struct iommu_ioas_allow_iovas allow_iovas; @@ -516,6 +523,8 @@ static const struct iommufd_ioctl_op iommufd_ioctl_ops[] = { __reserved), IOCTL_OP(IOMMU_VIOMMU_ALLOC, iommufd_viommu_alloc_ioctl, struct iommu_viommu_alloc, out_viommu_id), + IOCTL_OP(IOMMU_HWPT_LIVEUPDATE_MARK_PRESERVE, iommufd_hwpt_liveupdate_mark_preserve, + struct iommu_hwpt_liveupdate_mark_preserve, hwpt_token), #ifdef CONFIG_IOMMUFD_TEST IOCTL_OP(IOMMU_TEST_CMD, iommufd_test, struct iommu_test_cmd, last), #endif diff --git a/include/uapi/linux/iommufd.h b/include/uapi/linux/iommufd.h index 206fa667c782..34637712c873 100644 --- a/include/uapi/linux/iommufd.h +++ b/include/uapi/linux/iommufd.h @@ -58,6 +58,7 @@ enum { IOMMUFD_CMD_VEVENTQ_ALLOC = 0x93, IOMMUFD_CMD_HW_QUEUE_ALLOC = 0x94, IOMMUFD_CMD_IOAS_NOIOMMU_GET_PA = 0x95, + IOMMUFD_CMD_HWPT_LIVEUPDATE_MARK_PRESERVE = 0x96, }; /** @@ -1390,4 +1391,30 @@ struct iommu_hw_queue_alloc { __aligned_u64 length; }; #define IOMMU_HW_QUEUE_ALLOC _IO(IOMMUFD_TYPE, IOMMUFD_CMD_HW_QUEUE_ALLOC) + +/** + * struct iommu_hwpt_liveupdate_mark_preserve - ioctl(IOMMU_HWPT_LIVEUPDATE_MARK_PRESERVE) + * @size: sizeof(struct iommu_hwpt_liveupdate_mark_preserve) + * @hwpt_id: Iommufd object ID of the target HWPT + * @hwpt_token: Token to identify this hwpt upon restore + * + * The target HWPT will be preserved during iommufd preservation. + * Only file-based memory mappings (e.g. memfd) are supported for HWPTs marked + * for preservation. Mapping anonymous memory into a preserved HWPT will result + * in a failure during the preservation phase. + * + * The hwpt_token is provided by userspace. If userspace enters a token + * already in use within this iommufd, -EADDRINUSE is returned from this ioctl. + * + * Note: There is no 'unmark' operation, so any HWPTs pooled in userspace that + * are marked for preservation must be destroyed after use. + */ +struct iommu_hwpt_liveupdate_mark_preserve { + __u32 size; + __u32 hwpt_id; + __aligned_u64 hwpt_token; +}; +#define IOMMU_HWPT_LIVEUPDATE_MARK_PRESERVE \ + _IO(IOMMUFD_TYPE, IOMMUFD_CMD_HWPT_LIVEUPDATE_MARK_PRESERVE) + #endif -- 2.55.0.1082.g2b9226bbc0-goog