From: Jose Ignacio Tornos Martinez <jtornosm@redhat.com>
To: bhelgaas@google.com, alex@shazbot.org, jjohnson@kernel.org
Cc: johannes@sipsolutions.net, mani@kernel.org, jgg@ziepe.ca,
yishaih@nvidia.com, skolothumtho@nvidia.com,
kevin.tian@intel.com, linux-pci@vger.kernel.org,
kvm@vger.kernel.org, linux-wireless@vger.kernel.org,
ath11k@lists.infradead.org, ath12k@lists.infradead.org,
linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH 0/7] Enable Qualcomm WiFi PCIe passthrough to VMs
Date: Wed, 30 Sep 2026 16:10:45 +0200 [thread overview]
Message-ID: <20260930141045.577212-1-jtornosm@redhat.com> (raw)
This series enables Qualcomm ath11k/ath12k WiFi devices to work in VM
passthrough scenarios, addressing a long-standing issue where these
devices fail to initialize when passed through to VMs via VFIO.
Qualcomm ath11k/ath12k WiFi devices have been broken in VM passthrough
since they were introduced. The devices use an embedded interrupt
controller that requires physical host MSI addresses programmed to
device registers, but in VMs the driver only sees virtualized guest
addresses. This causes firmware initialization to fail with errors like
"BHI offset: 0xffffffff is out of range".
Multiple attempts have been made to solve this over the past 2 years:
March 2024: Workaround using module parameters [1]
- Required manually copying MSI values from host to VM
- Rejected by Johannes Berg as too manual, suggested VMM solution
August 2024: QEMU + kernel solution by Alex Williamson [2]
- Kernel disables MSI virtualization, QEMU intercepts config writes
- Uses brute force pattern matching to infer MSI data writes
- Stuck as RFC - no progress in 8+ months
No action from Qualcomm: Despite multiple reports, no vendor solution
The solution in this series provides a clean, kernel-only solution that
addresses the previous concerns.
Architecture:
1. qcom-vfio-pci variant driver caches physical host MSI values and
exposes them via extended config space with magic signature "QMSI"
In this way, device-specific hardware quirks belong only in kernel
drivers, not userspace, independent of the tools used.
This follows the established VFIO variant driver pattern used by
other drivers like mlx5-vfio-pci (netdev tree) and nvgrace-gpu (platform
tree).
2. VM drivers (ath11k/ath12k) automatically discover and use cached values
3. PCIe link recovery handles VM timing variations
Thoroughly tested: 3 VMs across 2 WiFi generations, all devices successfully
initialized and are ready for use.
- VM1: ath11k (WCN6855)
- VM2: ath11k (WCN6855)
- VM3: ath12k (WCN7850)
[1] https://lore.kernel.org/all/20240322104912.94811-1-jtornosm@redhat.com/
[2] https://lore.kernel.org/kvm/20240812170014.1583783-1-alex.williamson@redhat.com/
[3] Original problem report:
https://lore.kernel.org/all/fc6bd06f-d52b-4dee-ab1b-4bb845cc0b95@quicinc.com/
Jose Ignacio Tornos Martinez (7):
PCI: Add pci_find_free_ext_cap_offset() helper
vfio: Add qcom_vfio.h header for MSI cache protocol
vfio/pci: Add qcom-vfio-pci variant driver
ath11k: Add PCIe link recovery retry for VMs
ath11k: Use VFIO MSI cache when available
ath12k: Add PCIe link recovery retry for VMs
ath12k: Use VFIO MSI cache when available
--
2.53.0
next reply other threads:[~2026-09-30 14:10 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 14:10 Jose Ignacio Tornos Martinez [this message]
-- strict thread matches above, loose matches on Subject: below --
2026-09-30 14:08 Jose Ignacio Tornos Martinez
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930141045.577212-1-jtornosm@redhat.com \
--to=jtornosm@redhat.com \
--cc=alex@shazbot.org \
--cc=ath11k@lists.infradead.org \
--cc=ath12k@lists.infradead.org \
--cc=bhelgaas@google.com \
--cc=jgg@ziepe.ca \
--cc=jjohnson@kernel.org \
--cc=johannes@sipsolutions.net \
--cc=kevin.tian@intel.com \
--cc=kvm@vger.kernel.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=linux-wireless@vger.kernel.org \
--cc=mani@kernel.org \
--cc=skolothumtho@nvidia.com \
--cc=yishaih@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®