arch/powerpc/kernel/rtas.c | 78 ++++- arch/powerpc/platforms/powernv/eeh-powernv.c | 27 +- arch/powerpc/platforms/pseries/eeh_pseries.c | 328 +++++++++++++++++-- drivers/vfio/vfio_iommu_spapr_tce.c | 90 +++++ 4 files changed, 484 insertions(+), 39 deletions(-)
The pSeries EEH error-injection backend currently implements a limited software-generated MMIO failure and does not use the error-injection services provided by RTAS. This series replaces that implementation with the PAPR-defined RTAS workflow based on: - ibm,open-errinjct - ibm,errinjct - ibm,close-errinjct The implementation opens an RTAS error-injection session, prepares the firmware work buffer, performs the requested injection, and closes the session on both success and failure paths. The existing EEH userspace ABI is preserved. EEH_ERR_TYPE_32 and EEH_ERR_TYPE_64 continue to represent generic 32-bit and 64-bit IOA bus-error injection requests. The pSeries backend maps these values to the corresponding RTAS error types, while the PowerNV backend explicitly maps them to the corresponding OPAL types. Additional generic EEH error types (EEH_ERR_TYPE_RECOVERED_SPECIAL_EVENT, EEH_ERR_TYPE_CORRUPTED_PAGE, and the cache/TLB corruption types) are now defined in the UAPI header and mapped explicitly to RTAS firmware encodings by the pSeries backend. Platform backends that do not support a valid generic type return -EOPNOTSUPP. No existing userspace ABI values are changed. The current injection path can be exercised for VFIO-assigned devices through VFIO_EEH_PE_INJECT_ERR. The guest or userspace VFIO application continues to use the same generic EEH type and function values, independent of whether the host platform uses RTAS or OPAL. The series also handles the unusual return format of ibm,open-errinjct: rets[0] = error-injection session token rets[1] = RTAS status rtas_call() now returns rets[1] as the status and places the session token in outputs[0], preserving the normal kernel rtas_call() convention. sys_rtas() is intentionally unchanged because it exposes the raw RTAS return cells to userspace. Userspace therefore continues to receive the session token and status in their PAPR-defined positions. The RTAS work buffer is allocated during RTAS initialization below: min(ppc64_rma_size, RTAS_INSTANTIATE_MAX) using the same accessible-memory limit used for rtas_rmo_buf. The kernel populates the buffer through its virtual mapping but passes its physical address to firmware. The complete open, inject and close sequence is serialized with a mutex. RTAS busy and extended-delay return values are handled for all three calls. A session token value of zero is accepted, and session state is tracked independently from the token value. The patches are organised as follows: Handle the special ibm,open-errinjct return format in rtas_call(). Allocate an RTAS-accessible error-injection work buffer. Add pSeries RTAS parameter validation and buffer encoding helpers. Implement RTAS-based pSeries EEH error injection. Explicitly map generic EEH error types to OPAL types on PowerNV. Testing was performed on PowerVM with firmware providing the RTAS error-injection services and with the corresponding QEMU support: https://lore.kernel.org/qemu-devel/20260520095446.64206-1-nnmlinux@linux.ibm.com/ Signed-off-by: Narayana Murty N <nnmlinux@linux.ibm.com> Narayana Murty N (5): powerpc/rtas: Handle ibm,open-errinjct return format vfio/spapr_tce: Normalize EEH IOA error injection addresses powerpc/pseries/eeh: Add RTAS error validation helpers powerpc/pseries/eeh: Implement RTAS-based EEH error injection powerpc/powernv/eeh: Map VFIO EEH error injection to OPAL arch/powerpc/kernel/rtas.c | 78 ++++- arch/powerpc/platforms/powernv/eeh-powernv.c | 27 +- arch/powerpc/platforms/pseries/eeh_pseries.c | 328 +++++++++++++++++-- drivers/vfio/vfio_iommu_spapr_tce.c | 90 +++++ 4 files changed, 484 insertions(+), 39 deletions(-) -- 2.51.1
Hi,
I noticed that I missed adding the changelog in the v4 cover letter.
Adding it here for reference v4 changes from v3:
On 31/08/26 12:24 PM, Narayana Murty N wrote:
> The pSeries EEH error-injection backend currently implements a limited
> software-generated MMIO failure and does not use the error-injection
> services provided by RTAS.
>
> This series replaces that implementation with the PAPR-defined RTAS
> workflow based on:
>
> - ibm,open-errinjct
> - ibm,errinjct
> - ibm,close-errinjct
>
> The implementation opens an RTAS error-injection session, prepares the
> firmware work buffer, performs the requested injection, and closes the
> session on both success and failure paths.
>
> The existing EEH userspace ABI is preserved. EEH_ERR_TYPE_32 and
> EEH_ERR_TYPE_64 continue to represent generic 32-bit and 64-bit IOA
> bus-error injection requests. The pSeries backend maps these values to
> the corresponding RTAS error types, while the PowerNV backend
> explicitly maps them to the corresponding OPAL types.
>
> Additional generic EEH error types (EEH_ERR_TYPE_RECOVERED_SPECIAL_EVENT,
> EEH_ERR_TYPE_CORRUPTED_PAGE, and the cache/TLB corruption types) are now
> defined in the UAPI header and mapped explicitly to RTAS firmware encodings
> by the pSeries backend. Platform backends that do not support a valid
> generic type return -EOPNOTSUPP.
>
> No existing userspace ABI values are changed.
>
> The current injection path can be exercised for VFIO-assigned devices
> through VFIO_EEH_PE_INJECT_ERR. The guest or userspace VFIO application
> continues to use the same generic EEH type and function values,
> independent of whether the host platform uses RTAS or OPAL.
>
> The series also handles the unusual return format of
> ibm,open-errinjct:
>
> rets[0] = error-injection session token
> rets[1] = RTAS status
>
> rtas_call() now returns rets[1] as the status and places the session
> token in outputs[0], preserving the normal kernel rtas_call()
> convention.
>
> sys_rtas() is intentionally unchanged because it exposes the raw RTAS
> return cells to userspace. Userspace therefore continues to receive
> the session token and status in their PAPR-defined positions.
>
> The RTAS work buffer is allocated during RTAS initialization below:
>
> min(ppc64_rma_size, RTAS_INSTANTIATE_MAX)
>
> using the same accessible-memory limit used for rtas_rmo_buf. The
> kernel populates the buffer through its virtual mapping but passes its
> physical address to firmware.
>
> The complete open, inject and close sequence is serialized with a
> mutex. RTAS busy and extended-delay return values are handled for all
> three calls. A session token value of zero is accepted, and session
> state is tracked independently from the token value.
>
> The patches are organised as follows:
>
> Handle the special ibm,open-errinjct return format in rtas_call().
> Allocate an RTAS-accessible error-injection work buffer.
> Add pSeries RTAS parameter validation and buffer encoding helpers.
> Implement RTAS-based pSeries EEH error injection.
> Explicitly map generic EEH error types to OPAL types on PowerNV.
>
> Testing was performed on PowerVM with firmware providing the RTAS
> error-injection services and with the corresponding QEMU support:
>
> https://lore.kernel.org/qemu-devel/20260520095446.64206-1-nnmlinux@linux.ibm.com/
>
> Signed-off-by: Narayana Murty N <nnmlinux@linux.ibm.com>
The corresponding QEMU v5 series is posted here:
https://lore.kernel.org/qemu-devel/20260901174110.45356-1-nnmlinux@linux.ibm.com/
Change Log:
V3 -> V4:
* Use the RTAS work area allocator instead of adding a dedicated
global error-injection buffer.
* Keep sys_rtas() raw return-cell semantics unchanged while handling
the special ibm,open-errinjct return format in rtas_call().
* Treat ibm,open-errinjct with fewer than two return cells as invalid
rtas_call() usage instead of interpreting rets[0] as status.
* Use normal Linux errno values in internal validation helpers instead
of RTAS status values.
* Simplify the pSeries RTAS open/inject/close flow.
* Keep close-session failure as cleanup reporting without overwriting
the primary operation status.
* Add VFIO sPAPR-side address normalization before dispatching IOA
error injection to the platform EEH backend.
* Normalize IOA addresses based on the IOA error type, not only
selected function codes.
* Keep the generic EEH ABI values unchanged and keep pSeries RTAS and
PowerNV OPAL mappings explicit.
V2 -> V3:
* Fixed ibm,open-errinjct return handling to correctly process
firmware responses.
* Allocate the error-injection buffer in RTAS-accessible memory
instead of general kernel memory.
* Pass the physical address of the error-injection buffer to firmware
(previously incorrect address type).
* Accept session token zero as a valid token (previously rejected
erroneously).
* Handle RTAS busy and extended-delay return codes for open-inject,
and close calls.
* Simplified the validation helper — reduced complexity and removed
redundant checks.
* Simplified the buffer-preparation helper for cleaner, more
maintainable code.
* Validate that all required RTAS tokens are present before attempting
to open a session.
* Added explicit generic EEH-to-OPAL error-type mapping for the
PowerNV platform.
v1 -> v2:
https://lore.kernel.org/all/20260527072433.94510-1-nnmlinux@linux.ibm.com/
* Addressed all review comments from Sourabh Jain
- Removed unnecessary empty line in rtas_call()
- Enhanced comment to explain PAPR specification requirements
- Corrected misleading comment about output handling
- Improved else block comment for better code clarity
* Fixed kernel test robot warnings
- Fixed kernel-doc warning for __maybe_unused parameter
- Confirmed sparse warnings are false positives (correct endianness
handling)
* Added PowerNV platform abstraction layer (new Patch 5)
- Maps EEH error types to OPAL-specific types
- Simplifies type handling by direct variable update
* Improved code comments and documentation throughout
* Added Reported-by tags for kernel test robot findings
* Split into logical 5-patch series for better review
RFC -> v1:
https://lore.kernel.org/all/20251205094510.4671-1-nnmlinux@linux.ibm.com/
* Initial 4-patch series
* Fixed PAPR ibm,open-errinjct output format (token,status order)
* Added pr_fmt handling for EEH subsystem compatibility
* Implemented comprehensive validation helpers
RFC:
https://lore.kernel.org/all/20251107091009.43034-1-nnmlinux@linux.ibm.com/
* Initial RFC implementation
Thanks,
Narayana
>
> Narayana Murty N (5):
> powerpc/rtas: Handle ibm,open-errinjct return format
> vfio/spapr_tce: Normalize EEH IOA error injection addresses
> powerpc/pseries/eeh: Add RTAS error validation helpers
> powerpc/pseries/eeh: Implement RTAS-based EEH error injection
> powerpc/powernv/eeh: Map VFIO EEH error injection to OPAL
>
> arch/powerpc/kernel/rtas.c | 78 ++++-
> arch/powerpc/platforms/powernv/eeh-powernv.c | 27 +-
> arch/powerpc/platforms/pseries/eeh_pseries.c | 328 +++++++++++++++++--
> drivers/vfio/vfio_iommu_spapr_tce.c | 90 +++++
> 4 files changed, 484 insertions(+), 39 deletions(-)
>
© 2016 - 2026 Red Hat, Inc.