From: Mostafa Saleh <smostafa@google.com>
To: linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, kvmarm@lists.linux.dev,
iommu@lists.linux.dev
Cc: catalin.marinas@arm.com, will@kernel.org, maz@kernel.org,
oliver.upton@linux.dev, joey.gouly@arm.com,
suzuki.poulose@arm.com, yuzenghui@huawei.com, joro@8bytes.org,
jgg@ziepe.ca, mark.rutland@arm.com, qperret@google.com,
tabba@google.com, vdonnefort@google.com,
sebastianene@google.com, keirf@google.com,
Mostafa Saleh <smostafa@google.com>
Subject: [PATCH v8 08/25] KVM: arm64: iommu: Add memory pool
Date: Tue, 22 Sep 2026 13:12:41 +0000 [thread overview]
Message-ID: <20260922131259.2975334-9-smostafa@google.com> (raw)
In-Reply-To: <20260922131259.2975334-1-smostafa@google.com>
IOMMU drivers need to allocate memory for the shadow page table.
Similar to the host stage-2 CPU page table, the IOMMU pool
is allocated early from the carveout and its memory is added to
a pool which the IOMMU driver can allocate from and reclaim to at
run time.
As this is too early for drivers to use initcalls, the number of
pages allocated is set from command line "kvm-arm.iommu_pgt_mem".
Later when the driver registers, it will pass how many pages it
needs, and if it was more than what was allocated, it will fail
to register.
Signed-off-by: Mostafa Saleh <smostafa@google.com>
---
.../admin-guide/kernel-parameters.txt | 5 +++
arch/arm64/include/asm/kvm_host.h | 3 +-
arch/arm64/kvm/hyp/include/nvhe/iommu.h | 8 +++-
arch/arm64/kvm/hyp/nvhe/iommu.c | 21 +++++++++-
arch/arm64/kvm/hyp/nvhe/setup.c | 11 ++++-
arch/arm64/kvm/iommu.c | 41 ++++++++++++++++++-
arch/arm64/kvm/pkvm.c | 1 +
7 files changed, 85 insertions(+), 5 deletions(-)
diff --git a/Documentation/admin-guide/kernel-parameters.txt b/Documentation/admin-guide/kernel-parameters.txt
index 33cd30996e47..408a1f431782 100644
--- a/Documentation/admin-guide/kernel-parameters.txt
+++ b/Documentation/admin-guide/kernel-parameters.txt
@@ -3240,6 +3240,11 @@ Kernel parameters
max_snp_asid == min_sev_asid-1, will effectively make
SEV-ES unusable.
+ kvm-arm.iommu_pgt_mem=nn[KMG]
+ [KVM,ARM,EARLY]
+ Memory allocated for the IOMMU pool from the KVM carveout
+ when running in protected mode (See kvm-arm.mode=).
+
kvm-arm.mode=
[KVM,ARM,EARLY] Select one of KVM/arm64's modes of
operation.
diff --git a/arch/arm64/include/asm/kvm_host.h b/arch/arm64/include/asm/kvm_host.h
index 7ba7d384889e..743d812e8ee0 100644
--- a/arch/arm64/include/asm/kvm_host.h
+++ b/arch/arm64/include/asm/kvm_host.h
@@ -1719,7 +1719,8 @@ long kvm_get_cap_for_kvm_ioctl(unsigned int ioctl, long *ext);
#ifndef __KVM_NVHE_HYPERVISOR__
struct pkvm_iommu_ops;
-int pkvm_iommu_register_driver(struct pkvm_iommu_ops *hyp_ops);
+int pkvm_iommu_register_driver(struct pkvm_iommu_ops *hyp_ops, unsigned int nr_pages);
+unsigned int pkvm_iommu_pages(void);
#endif
#endif /* __ARM64_KVM_HOST_H__ */
diff --git a/arch/arm64/kvm/hyp/include/nvhe/iommu.h b/arch/arm64/kvm/hyp/include/nvhe/iommu.h
index 2e35ec01c75d..1fa728ab47d4 100644
--- a/arch/arm64/kvm/hyp/include/nvhe/iommu.h
+++ b/arch/arm64/kvm/hyp/include/nvhe/iommu.h
@@ -9,8 +9,14 @@ struct pkvm_iommu_ops {
int (*host_stage2_idmap)(phys_addr_t start, phys_addr_t end, int prot);
};
-int pkvm_iommu_init(void);
+int pkvm_iommu_init(void *pool_base, unsigned int nr_pages);
int pkvm_iommu_host_stage2_idmap(phys_addr_t start, phys_addr_t end,
enum kvm_pgtable_prot prot);
+
+/* Allocate pages from the IOMMU carveout, returns zeroed memory. */
+void *pkvm_iommu_alloc_pages(u8 order);
+/* Free pages from pkvm_iommu_alloc_pages(). */
+void pkvm_iommu_free_pages(void *ptr);
+
#endif /* __ARM64_KVM_NVHE_IOMMU_H__ */
diff --git a/arch/arm64/kvm/hyp/nvhe/iommu.c b/arch/arm64/kvm/hyp/nvhe/iommu.c
index 3637b0327d9e..cacab0dc462a 100644
--- a/arch/arm64/kvm/hyp/nvhe/iommu.c
+++ b/arch/arm64/kvm/hyp/nvhe/iommu.c
@@ -16,6 +16,7 @@ struct pkvm_iommu_ops *pkvm_iommu_ops;
/* Protected by host_mmu.lock */
static bool pkvm_idmap_initialized;
+static struct hyp_pool iommu_pages_pool;
static inline int pkvm_to_iommu_prot(enum kvm_pgtable_prot prot)
{
@@ -113,7 +114,7 @@ static int pkvm_iommu_snapshot_host_stage2(void)
return ret;
}
-int pkvm_iommu_init(void)
+int pkvm_iommu_init(void *pool_base, unsigned int nr_pages)
{
int ret;
@@ -122,6 +123,14 @@ int pkvm_iommu_init(void)
!pkvm_iommu_ops->host_stage2_idmap)
return 0;
+ if (!nr_pages)
+ return -ENOMEM;
+
+ ret = hyp_pool_init(&iommu_pages_pool, hyp_virt_to_pfn(pool_base),
+ nr_pages, 0);
+ if (ret)
+ return ret;
+
ret = pkvm_iommu_ops->init();
if (ret)
return ret;
@@ -139,3 +148,13 @@ int pkvm_iommu_host_stage2_idmap(phys_addr_t start, phys_addr_t end,
return pkvm_iommu_ops->host_stage2_idmap(start, end, pkvm_to_iommu_prot(prot));
}
+
+void *pkvm_iommu_alloc_pages(u8 order)
+{
+ return hyp_alloc_pages(&iommu_pages_pool, order);
+}
+
+void pkvm_iommu_free_pages(void *ptr)
+{
+ hyp_put_page(&iommu_pages_pool, ptr);
+}
diff --git a/arch/arm64/kvm/hyp/nvhe/setup.c b/arch/arm64/kvm/hyp/nvhe/setup.c
index 9607d1b18a88..7ce1fc2232da 100644
--- a/arch/arm64/kvm/hyp/nvhe/setup.c
+++ b/arch/arm64/kvm/hyp/nvhe/setup.c
@@ -22,6 +22,8 @@
unsigned long hyp_nr_cpus;
+unsigned int hyp_kvm_iommu_pages;
+
#define hyp_percpu_size ((unsigned long)__per_cpu_end - \
(unsigned long)__per_cpu_start)
@@ -33,6 +35,7 @@ static void *selftest_base;
static void *ffa_proxy_pages;
static struct kvm_pgtable_mm_ops pkvm_pgtable_mm_ops;
static struct hyp_pool hpool;
+static void *iommu_base;
static int divide_memory_pool(void *virt, unsigned long size)
{
@@ -70,6 +73,12 @@ static int divide_memory_pool(void *virt, unsigned long size)
if (!ffa_proxy_pages)
return -ENOMEM;
+ if (hyp_kvm_iommu_pages) {
+ iommu_base = hyp_early_alloc_contig(hyp_kvm_iommu_pages);
+ if (!iommu_base)
+ return -ENOMEM;
+ }
+
return 0;
}
@@ -334,7 +343,7 @@ void __noreturn __pkvm_init_finalise(void)
* resources that would be leaked if the hypervisor fails after as there
* is no remove_iommu_driver() at the moment.
*/
- ret = pkvm_iommu_init();
+ ret = pkvm_iommu_init(iommu_base, hyp_kvm_iommu_pages);
if (ret)
goto out;
diff --git a/arch/arm64/kvm/iommu.c b/arch/arm64/kvm/iommu.c
index 30a3862e93d7..f008f68eee40 100644
--- a/arch/arm64/kvm/iommu.c
+++ b/arch/arm64/kvm/iommu.c
@@ -7,10 +7,11 @@
#include <linux/kvm_host.h>
extern struct pkvm_iommu_ops *kvm_nvhe_sym(pkvm_iommu_ops);
+extern unsigned int kvm_nvhe_sym(hyp_kvm_iommu_pages);
static DEFINE_MUTEX(pkvm_iommu_reg_lock);
-int pkvm_iommu_register_driver(struct pkvm_iommu_ops *hyp_ops)
+int pkvm_iommu_register_driver(struct pkvm_iommu_ops *hyp_ops, unsigned int nr_pages)
{
guard(mutex)(&pkvm_iommu_reg_lock);
@@ -20,6 +21,44 @@ int pkvm_iommu_register_driver(struct pkvm_iommu_ops *hyp_ops)
if (kvm_nvhe_sym(pkvm_iommu_ops))
return -EBUSY;
+ /* See pkvm_iommu_pages() */
+ if (nr_pages > kvm_nvhe_sym(hyp_kvm_iommu_pages)) {
+ kvm_err("IOMMU pool needs 0x%x pages, check kvm-arm.iommu_pgt_mem\n", nr_pages);
+ return -ENOMEM;
+ }
+
kvm_nvhe_sym(pkvm_iommu_ops) = hyp_ops;
return 0;
}
+
+unsigned int pkvm_iommu_pages(void)
+{
+ /*
+ * This is used very early during setup_arch() before any initcalls
+ * or any drivers are registered.
+ * This value is set by a command line option.
+ * Later, when the driver is registered, it will pass the number
+ * pages needed for it's page tables, if it was more than what
+ * the system has already allocated, it will fail registration.
+ */
+ return kvm_nvhe_sym(hyp_kvm_iommu_pages);
+}
+
+static int __init early_iommu_pgt_mem(char *arg)
+{
+ unsigned long long requested_size;
+
+ if (!arg)
+ return -EINVAL;
+
+ requested_size = memparse(arg, NULL);
+
+ if (requested_size > UINT_MAX) {
+ kvm_err("kvm-arm.iommu_pgt_mem is too large\n");
+ return -EINVAL;
+ }
+
+ kvm_nvhe_sym(hyp_kvm_iommu_pages) = DIV_ROUND_UP(requested_size, PAGE_SIZE);
+ return 0;
+}
+early_param("kvm-arm.iommu_pgt_mem", early_iommu_pgt_mem);
diff --git a/arch/arm64/kvm/pkvm.c b/arch/arm64/kvm/pkvm.c
index 8e4c6e4bec12..b6cf01e00f6b 100644
--- a/arch/arm64/kvm/pkvm.c
+++ b/arch/arm64/kvm/pkvm.c
@@ -63,6 +63,7 @@ void __init kvm_hyp_reserve(void)
hyp_mem_pages += hyp_vmemmap_pages(STRUCT_HYP_PAGE_SIZE);
hyp_mem_pages += pkvm_selftest_pages();
hyp_mem_pages += hyp_ffa_proxy_pages();
+ hyp_mem_pages += pkvm_iommu_pages();
/*
* Try to allocate a PMD-aligned region to reduce TLB pressure once
--
2.55.0.1082.g2b9226bbc0-goog
next prev parent reply other threads:[~2026-09-22 13:13 UTC|newest]
Thread overview: 31+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 13:12 [PATCH v8 00/25] KVM: arm64: SMMUv3 driver for pKVM (trap and emulate) Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 01/25] KVM: arm64: Donate MMIO to the hypervisor Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 02/25] iommu/arm-smmu-v3: Move Queue and STE functions to header Mostafa Saleh
2026-09-22 18:23 ` Nicolin Chen
2026-09-22 13:12 ` [PATCH v8 03/25] iommu/arm-smmu-v3: Introduce RangeInval encoding helpers Mostafa Saleh
2026-09-22 18:45 ` Nicolin Chen
2026-09-22 13:12 ` [PATCH v8 04/25] iommu/arm-smmu-v3: Move IDR parsing to common functions Mostafa Saleh
2026-09-22 19:45 ` Nicolin Chen
2026-09-22 13:12 ` [PATCH v8 05/25] iommu/arm-smmu-v3: Move hitless machinery to common code Mostafa Saleh
2026-09-22 19:59 ` Nicolin Chen
2026-09-22 13:12 ` [PATCH v8 06/25] KVM: arm64: iommu: Introduce IOMMU driver infrastructure Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 07/25] KVM: arm64: iommu: Shadow host stage-2 page table Mostafa Saleh
2026-09-22 13:12 ` Mostafa Saleh [this message]
2026-09-22 13:12 ` [PATCH v8 09/25] KVM: arm64: iommu: Support DABT for IOMMU Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 10/25] iommu/arm-smmu-v3-kvm: Add SMMUv3 driver Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 11/25] iommu/arm-smmu-v3-kvm: Add the kernel driver Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 12/25] iommu/arm-smmu-v3-kvm: Probe SMMU HW Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 13/25] iommu/arm-smmu-v3-kvm: Add MMIO emulation Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 14/25] iommu/arm-smmu-v3-kvm: Shadow the command queue Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 15/25] iommu/arm-smmu-v3-kvm: Add CMDQ functions Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 16/25] iommu/arm-smmu-v3-kvm: Emulate CMDQ for host Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 17/25] iommu/arm-smmu-v3-kvm: Shadow stream table Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 18/25] iommu/arm-smmu-v3-kvm: Shadow STEs Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 19/25] iommu/arm-smmu-v3-kvm: Share other queues Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 20/25] iommu/arm-smmu-v3-kvm: Emulate GBPA Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 21/25] iommu/io-pgtable-arm: Support io-pgtable-arm in the hypervisor Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 22/25] iommu/arm-smmu-v3-kvm: Shadow the CPU stage-2 page table Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 23/25] iommu/arm-smmu-v3-kvm: Invalidate the SMMU TLBs Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 24/25] iommu/arm-smmu-v3-kvm: Enable nesting Mostafa Saleh
2026-09-22 13:12 ` [PATCH v8 25/25] KVM: arm64: Add documentation for pKVM DMA isolation Mostafa Saleh
2026-09-22 18:07 ` [PATCH v8 00/25] KVM: arm64: SMMUv3 driver for pKVM (trap and emulate) Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922131259.2975334-9-smostafa@google.com \
--to=smostafa@google.com \
--cc=catalin.marinas@arm.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@ziepe.ca \
--cc=joey.gouly@arm.com \
--cc=joro@8bytes.org \
--cc=keirf@google.com \
--cc=kvmarm@lists.linux.dev \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=mark.rutland@arm.com \
--cc=maz@kernel.org \
--cc=oliver.upton@linux.dev \
--cc=qperret@google.com \
--cc=sebastianene@google.com \
--cc=suzuki.poulose@arm.com \
--cc=tabba@google.com \
--cc=vdonnefort@google.com \
--cc=will@kernel.org \
--cc=yuzenghui@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®