mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [RFC PATCH 0/7] iommu/amd: Implement live update state preservation
@ 2026-10-05  6:40 Ankit Soni
  2026-10-05  6:40 ` [RFC PATCH 1/7] iommu/amd: defer device attach only on a kdump boot Ankit Soni
                   ` (6 more replies)
  0 siblings, 7 replies; 8+ messages in thread
From: Ankit Soni @ 2026-10-05  6:40 UTC (permalink / raw)
  To: iommu, joro, will, jgg
  Cc: suravee.suthikulpanit, vasant.hegde, robin.murphy,
	joao.m.martins, alejandro.j.jimenez, pasha.tatashin, rppt,
	pratyush, skhawaja, praan, baolu.lu, dwmw2, kevin.tian, dmatlack,
	vipinsh, kexec, linux-kernel

This series adds AMD-Vi support for IOMMU state preservation across a
kexec-based live update, so a passed-through device keeps its translations
and keeps doing DMA while the kernel underneath is replaced.

It applies on top of the IOMMU live update core series v5 [1], currently in
review, and reuses the FLB preservation mechanism that series introduces.

This is an RFC. The reclaim path is not included; it depends on the phase 2
iommufd work and will follow.

What is preserved
=================
The Device Table, adopted by the incoming kernel rather than rebuilt, and for
each preserved device its domain ID, page-table mode, and GCR3 tree if the
device uses PASID.

What is not preserved
=====================
The command buffer, event log, PPR log, GA log, GA tail and cmd_sem, and the
interrupt remapping tables. The incoming kernel allocates all of them fresh.
Interrupts raised during the window are lost, but the data and the completion
records travel by DMA, so a driver finds the completed work when it next
reads its queues.

Disabling the PPR log also disables PPR, so a preserved device cannot
raise a page request across the window. That is safe only because an HWPT
with a fault queue cannot be marked for preservation today; if that is
relaxed for SVA, such a request would go unanswered and, with the event
log stopped, unlogged. Whoever adds PRI preservation needs to revisit
this.

Architectural overview
======================
At preserve time the driver pins the PCI segment's Device Table for KHO and
records each preserved device's domain ID, page-table mode and GCR3 tree.

At shutdown translation stays enabled on any unit carrying preserved devices,
so their DMA never stops. Everything else on that unit is made safe: DTEs of
unpreserved devices are reset to blocked, the interrupt fields of every DTE
are cleared because no DTE may point at a table the next kernel can recycle,
and the command, event, PPR and GA engines are stopped and polled until idle.
That last step matters because the incoming kernel may reuse the pages those
buffers occupied, and an engine still writing after the kexec would corrupt
them with nothing to attribute the damage to. If an engine does not go idle
the driver panics rather than complete the handover.

On the live update boot the driver finds its record by MMIO physical base,
adopts the Device Table, and reserves the domain IDs it describes so a new
domain cannot alias a preserved one. A unit handed over translating is left
translating. When the core probes the preserved devices their domain ID and
GCR3 tree are adopted on attach and verified against the live DTE; a mismatch
fails the attach. A restored domain is immutable, so a preserved device may
only attach to the domain restored for it.

One generic change
==================
Patch 2 moves the LUO handover-tree parse into start_kernel(), immediately
before late_time_init().

AMD-Vi needs this because it is the x86 interrupt remapping provider, so
amd_iommu_prepare() runs from late_time_init() via enable_IR_x2apic(). It
queries preserved state from three sites on that path. LUO parses the tree
from an early_initcall inside rest_init(), so those queries run before the
data exists and cannot tell "nothing was preserved" from "not parsed yet".
The driver then disables a unit the previous kernel left translating.

Note:
ATS and PASID state on the device itself is not adopted. For a preserved
device the attach path still runs the normal enable sequence, so an
ATS-capable device would have its ATS Control register rewritten while it
is doing DMA. Adopting that state is PCI core roadmap item #4 [2], so this
series leaves it alone rather than reprogramming the PCI side here. The
restored DTE's IOTLB bit is checked against the device's ATS state, which
catches a disagreement.

[1] Samiullah Khawaja, "iommu: Add live update state preservation" (v5)
    https://lore.kernel.org/linux-iommu/20260921004834.2601285-1-skhawaja@google.com/
[2] David Matlack, "RFC: PCI core Live Update Roadmap"
    https://lore.kernel.org/linux-pci/20261001232133.560284-1-dmatlack@google.com/

Ankit Soni (7):
  iommu/amd: defer device attach only on a kdump boot
  liveupdate: parse the incoming handover tree before late_time_init()
  iommu/kho/abi: add AMD IOMMU live-update serialisation structs
  iommu/amd: preserve IOMMU and device state for live update
  iommu/amd: clear unpreserved DTEs and quiesce logs at live-update shutdown
  iommu/amd: restore preserved state on a live-update boot
  iommu/amd: reattach preserved devices to their restored domains

 drivers/iommu/amd/Makefile          |   1 +
 drivers/iommu/amd/amd_iommu.h       |  34 ++
 drivers/iommu/amd/amd_iommu_types.h |  14 +
 drivers/iommu/amd/init.c            | 253 +++++++++++--
 drivers/iommu/amd/iommu.c           | 144 +++++++-
 drivers/iommu/amd/liveupdate.c      | 543 ++++++++++++++++++++++++++++
 drivers/iommu/amd/nested.c          |   8 +
 include/linux/kho/abi/iommu.h       |  70 ++++
 include/linux/liveupdate.h          |   4 +
 init/main.c                         |   2 +
 kernel/liveupdate/luo_core.c        |   5 +-
 11 files changed, 1039 insertions(+), 39 deletions(-)
 create mode 100644 drivers/iommu/amd/liveupdate.c


base-commit: 1d195de0e8caf627e93c0a39af1e84bb19e3cc53
-- 
2.43.0


^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2026-10-05  6:44 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-05  6:40 [RFC PATCH 0/7] iommu/amd: Implement live update state preservation Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 1/7] iommu/amd: defer device attach only on a kdump boot Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 2/7] liveupdate: parse the incoming handover tree before late_time_init() Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 3/7] iommu/kho/abi: add AMD IOMMU live-update serialisation structs Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 4/7] iommu/amd: preserve IOMMU and device state for live update Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 5/7] iommu/amd: clear unpreserved DTEs and quiesce logs at live-update shutdown Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 6/7] iommu/amd: restore preserved state on a live-update boot Ankit Soni
2026-10-05  6:40 ` [RFC PATCH 7/7] iommu/amd: reattach preserved devices to their restored domains Ankit Soni

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®