From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
To: bhelgaas@google.com, alex@shazbot.org, jjohnson@kernel.org
Cc: johannes@sipsolutions.net, mani@kernel.org, jgg@ziepe.ca,
yishaih@nvidia.com, skolothumtho@nvidia.com,
kevin.tian@intel.com, linux-pci@vger.kernel.org,
kvm@vger.kernel.org, linux-wireless@vger.kernel.org,
ath11k@lists.infradead.org, ath12k@lists.infradead.org,
linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org,
Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
Subject: [PATCH 2/7] vfio: Add qcom_vfio.h header for MSI cache protocol
Date: Wed, 30 Sep 2026 16:08:28 +0200 [thread overview]
Message-ID: <20260930140833.576941-3-jtornosm@redhat.com> (raw)
In-Reply-To: <20260930140833.576941-1-jtornosm@redhat.com>
Add shared header defining the communication protocol between
qcom-vfio-pci variant driver and Qualcomm device drivers (ath11k,
ath12k) for passing physical host MSI addresses to VMs.
Qualcomm device firmware requires physical host MSI addresses rather
than guest IOVA addresses. The qcom-vfio-pci driver caches host MSI
values in extended PCI config space with a magic signature "QMSI" for
VM discovery.
Protocol:
1. Host: qcom-vfio-pci finds free space in extended config (0x100-0xFFF)
2. Host: Writes magic signature "QMSI" (0x49534D51) followed by MSI data
3. VM: Device driver searches for "QMSI" signature to locate cached MSI
4. VM: Reads MSI values and programs device firmware
This avoids offset mismatch when QEMU filters certain capabilities,
causing host and VM to see different extended capability chains.
Signed-off-by: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
---
include/linux/qcom_vfio.h | 88 +++++++++++++++++++++++++++++++++++++++
1 file changed, 88 insertions(+)
create mode 100644 include/linux/qcom_vfio.h
diff --git a/include/linux/qcom_vfio.h b/include/linux/qcom_vfio.h
new file mode 100644
index 000000000000..c59c81936e84
--- /dev/null
+++ b/include/linux/qcom_vfio.h
@@ -0,0 +1,88 @@
+/* SPDX-License-Identifier: GPL-2.0-only */
+/* SPDX-FileCopyrightText: Copyright Red Hat */
+
+#ifndef _QCOM_VFIO_H_
+#define _QCOM_VFIO_H_
+
+#include <linux/pci.h>
+
+/*
+ * MSI Address Passthrough Quirk
+ *
+ * Qualcomm device firmware requires physical host MSI addresses rather than
+ * guest IOVA addresses. The qcom-vfio-pci variant driver caches host MSI
+ * values in extended PCI config space with a magic signature for VM
+ * discovery.
+ *
+ * Protocol:
+ * 1. Host: qcom-vfio-pci finds free space in extended config (0x100-0xFFF)
+ * 2. Host: Writes magic signature "QMSI" (0x49534D51) followed by MSI data
+ * 3. VM: Device driver searches for "QMSI" signature to locate cached MSI
+ * 4. VM: Reads MSI values and programs device firmware
+ *
+ * This avoids offset mismatch when QEMU filters certain capabilities, causing
+ * host and VM to see different extended capability chains.
+ *
+ * Layout in extended config space:
+ * +0x00: Magic signature "QMSI" (0x49534D51)
+ * +0x04: MSI address low 32 bits
+ * +0x08: MSI address high 32 bits
+ * +0x0C: MSI data (16 bits)
+ *
+ * Applicable to:
+ * - ath11k WiFi (PCI ID 0x17cb:0x1103)
+ * - ath12k WiFi (PCI ID 0x17cb:0x1107)
+ */
+
+/* Magic signature "QMSI" to identify cached MSI data */
+#define QCOM_VFIO_MSI_MAGIC 0x49534D51
+
+/* Space needed for magic + MSI passthrough data */
+#define QCOM_VFIO_MSI_SPACE_SIZE 16
+
+/* Relative offsets from base discovered by qcom_vfio_find_msi_offset() */
+#define QCOM_VFIO_MSI_MAGIC_OFFSET 0x00 /* Magic signature "QMSI" */
+#define QCOM_VFIO_MSI_ADDR_LO_OFFSET 0x04 /* Host MSI address low 32 bits */
+#define QCOM_VFIO_MSI_ADDR_HI_OFFSET 0x08 /* Host MSI address high 32 bits */
+#define QCOM_VFIO_MSI_DATA_OFFSET 0x0C /* Host MSI data (16 bits) */
+
+/**
+ * qcom_vfio_find_msi_offset - Find free space for host to cache MSI
+ * @pdev: PCI device
+ *
+ * Host-side function: Finds free space in extended config to write MSI cache.
+ * Uses PCI core utility to scan capability chain.
+ *
+ * Returns: Offset in extended config space (>= 0x100), or 0 if no space found
+ */
+static inline int qcom_vfio_find_msi_offset(struct pci_dev *pdev)
+{
+ return pci_find_free_ext_cap_offset(pdev, QCOM_VFIO_MSI_SPACE_SIZE);
+}
+
+/**
+ * qcom_vfio_find_msi_cache - Locate cached MSI data by magic signature
+ * @pdev: PCI device
+ *
+ * VM-side function: Searches extended config space for "QMSI" magic signature
+ * to locate host-cached MSI values. This avoids offset mismatch when QEMU
+ * filters certain capabilities.
+ *
+ * Returns: Offset of MSI data (after magic), or 0 if not found
+ */
+static inline int qcom_vfio_find_msi_cache(struct pci_dev *pdev)
+{
+ u32 magic;
+ int offset;
+
+ for (offset = 0x100; offset <= 0xf00; offset += 4) {
+ if (pci_read_config_dword(pdev, offset, &magic))
+ continue;
+ if (magic == QCOM_VFIO_MSI_MAGIC)
+ return offset;
+ }
+
+ return 0;
+}
+
+#endif /* _QCOM_VFIO_H_ */
--
2.53.0
next prev parent reply other threads:[~2026-09-30 14:09 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 14:08 [PATCH 0/7] Enable Qualcomm WiFi PCIe passthrough to VMs Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` [PATCH 1/7] PCI: Add pci_find_free_ext_cap_offset() helper Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` Jose Ignacio Tornos Martinez [this message]
2026-09-30 14:08 ` [PATCH 3/7] vfio/pci: Add qcom-vfio-pci variant driver Jose Ignacio Tornos Martinez
2026-09-30 15:12 ` Jason Gunthorpe
2026-10-01 7:19 ` Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` [PATCH 4/7] ath11k: add PCIe link recovery retry Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` [PATCH 5/7] ath11k: Use VFIO MSI cache when available Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` [PATCH 6/7] ath12k: add PCIe link recovery retry Jose Ignacio Tornos Martinez
2026-09-30 14:08 ` [PATCH 7/7] ath12k: Use VFIO MSI cache when available Jose Ignacio Tornos Martinez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930140833.576941-3-jtornosm@redhat.com \
--to=jtornosm@redhat.com \
--cc=alex@shazbot.org \
--cc=ath11k@lists.infradead.org \
--cc=ath12k@lists.infradead.org \
--cc=bhelgaas@google.com \
--cc=jgg@ziepe.ca \
--cc=jjohnson@kernel.org \
--cc=johannes@sipsolutions.net \
--cc=kevin.tian@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=mani@kernel.org \
--cc=skolothumtho@nvidia.com \
--cc=yishaih@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®