From nobody Sun Sep 14 06:35:40 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1CC8DC61DA3 for ; Thu, 26 Jan 2023 18:26:47 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232062AbjAZS0q (ORCPT ); Thu, 26 Jan 2023 13:26:46 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:46012 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S231995AbjAZS0i (ORCPT ); Thu, 26 Jan 2023 13:26:38 -0500 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id 5ED236A731 for ; Thu, 26 Jan 2023 10:26:35 -0800 (PST) Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 84C931424; Thu, 26 Jan 2023 10:27:17 -0800 (PST) Received: from e121345-lin.cambridge.arm.com (e121345-lin.cambridge.arm.com [10.1.196.40]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 93A133F71E; Thu, 26 Jan 2023 10:26:34 -0800 (PST) From: Robin Murphy To: joro@8bytes.org, will@kernel.org Cc: iommu@lists.linux.dev, linux-kernel@vger.kernel.org, hch@lst.de, jgg@nvidia.com, baolu.lu@linux.intel.com Subject: [PATCH v2 5/8] iommu: Switch __iommu_domain_alloc() to device ops Date: Thu, 26 Jan 2023 18:26:20 +0000 Message-Id: <23b51c84247cb36e96c242d3aef8ef555b6d05cd.1674753627.git.robin.murphy@arm.com> X-Mailer: git-send-email 2.36.1.dirty In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Type: text/plain; charset="utf-8" In all the places we allocate default domains, we have (or can easily get hold of) a device from which to resolve the right IOMMU ops; only the public iommu_domain_alloc() interface actually depends on bus ops. Reworking the public API is a big enough mission in its own right, but in the meantime we can still decouple it from bus ops internally to move forward. Signed-off-by: Robin Murphy Reviewed-by: Lu Baolu --- v2: - Explain the mitigation better in the warning message - Fix theoretical bug if alloc_dev is never assigned because the bus has no devices - Use new dev_iommu_ops_valid() since in theory VFIO noiommu makes device_iommu_mapped() -> dev_iommu_ops() an unsafe assumption [Baolu] drivers/iommu/iommu.c | 59 ++++++++++++++++++++++++++++--------------- 1 file changed, 39 insertions(+), 20 deletions(-) diff --git a/drivers/iommu/iommu.c b/drivers/iommu/iommu.c index 440bb3b7bded..bdc5fdf39d2b 100644 --- a/drivers/iommu/iommu.c +++ b/drivers/iommu/iommu.c @@ -89,7 +89,7 @@ static int iommu_bus_notifier(struct notifier_block *nb, unsigned long action, void *data); static int iommu_alloc_default_domain(struct iommu_group *group, struct device *dev); -static struct iommu_domain *__iommu_domain_alloc(struct bus_type *bus, +static struct iommu_domain *__iommu_domain_alloc(struct device *dev, unsigned type); static int __iommu_attach_device(struct iommu_domain *domain, struct device *dev); @@ -1641,15 +1641,15 @@ static int iommu_get_def_domain_type(struct device = *dev) return 0; } =20 -static int iommu_group_alloc_default_domain(struct bus_type *bus, - struct iommu_group *group, +static int iommu_group_alloc_default_domain(struct iommu_group *group, + struct device *dev, unsigned int type) { struct iommu_domain *dom; =20 - dom =3D __iommu_domain_alloc(bus, type); + dom =3D __iommu_domain_alloc(dev, type); if (!dom && type !=3D IOMMU_DOMAIN_DMA) { - dom =3D __iommu_domain_alloc(bus, IOMMU_DOMAIN_DMA); + dom =3D __iommu_domain_alloc(dev, IOMMU_DOMAIN_DMA); if (dom) pr_warn("Failed to allocate default IOMMU domain of type %u for group %= s - Falling back to IOMMU_DOMAIN_DMA", type, group->name); @@ -1674,7 +1674,7 @@ static int iommu_alloc_default_domain(struct iommu_gr= oup *group, =20 type =3D iommu_get_def_domain_type(dev) ? : iommu_def_domain_type; =20 - return iommu_group_alloc_default_domain(dev->bus, group, type); + return iommu_group_alloc_default_domain(group, dev, type); } =20 /** @@ -1787,8 +1787,7 @@ static int probe_get_default_domain_type(struct devic= e *dev, void *data) return 0; } =20 -static void probe_alloc_default_domain(struct bus_type *bus, - struct iommu_group *group) +static void probe_alloc_default_domain(struct iommu_group *group) { struct __group_domain_type gtype; =20 @@ -1798,10 +1797,12 @@ static void probe_alloc_default_domain(struct bus_t= ype *bus, __iommu_group_for_each_dev(group, >ype, probe_get_default_domain_type); =20 - if (!gtype.type) + if (!gtype.type) { gtype.type =3D iommu_def_domain_type; + gtype.dev =3D iommu_group_first_dev(group); + } =20 - iommu_group_alloc_default_domain(bus, group, gtype.type); + iommu_group_alloc_default_domain(group, gtype.dev, gtype.type); =20 } =20 @@ -1864,7 +1865,7 @@ int bus_iommu_probe(struct bus_type *bus) list_del_init(&group->entry); =20 /* Try to allocate default domain */ - probe_alloc_default_domain(bus, group); + probe_alloc_default_domain(group); =20 if (!group->default_domain) { mutex_unlock(&group->mutex); @@ -1953,15 +1954,12 @@ void iommu_set_fault_handler(struct iommu_domain *d= omain, } EXPORT_SYMBOL_GPL(iommu_set_fault_handler); =20 -static struct iommu_domain *__iommu_domain_alloc(struct bus_type *bus, +static struct iommu_domain *__iommu_domain_alloc(struct device *dev, unsigned type) { - const struct iommu_ops *ops =3D bus ? bus->iommu_ops : NULL; + const struct iommu_ops *ops =3D dev_iommu_ops(dev); struct iommu_domain *domain; =20 - if (!ops) - return NULL; - domain =3D ops->domain_alloc(type); if (!domain) return NULL; @@ -1980,9 +1978,30 @@ static struct iommu_domain *__iommu_domain_alloc(str= uct bus_type *bus, return domain; } =20 +static int __iommu_domain_alloc_dev(struct device *dev, void *data) +{ + struct device **alloc_dev =3D data; + + if (!dev_iommu_ops_valid(dev)) + return 0; + + WARN_ONCE(*alloc_dev && dev_iommu_ops(dev) !=3D dev_iommu_ops(*alloc_dev), + "Multiple IOMMU drivers present, which the public IOMMU API can't fully = support yet. You may still need to disable one or more to get the expected = result here, sorry!\n"); + + *alloc_dev =3D dev; + return 0; +} + struct iommu_domain *iommu_domain_alloc(struct bus_type *bus) { - return __iommu_domain_alloc(bus, IOMMU_DOMAIN_UNMANAGED); + struct device *dev =3D NULL; + + /* We always check the whole bus, so the return value isn't useful */ + bus_for_each_dev(bus, NULL, &dev, __iommu_domain_alloc_dev); + if (!dev) + return NULL; + + return __iommu_domain_alloc(dev, IOMMU_DOMAIN_UNMANAGED); } EXPORT_SYMBOL_GPL(iommu_domain_alloc); =20 @@ -2906,7 +2925,7 @@ static int iommu_change_dev_def_domain(struct iommu_g= roup *group, } =20 /* Sets group->default_domain to the newly allocated domain */ - ret =3D iommu_group_alloc_default_domain(dev->bus, group, type); + ret =3D iommu_group_alloc_default_domain(group, dev, type); if (ret) goto out; =20 @@ -3120,13 +3139,13 @@ static int __iommu_group_alloc_blocking_domain(stru= ct iommu_group *group) if (group->blocking_domain) return 0; =20 - group->blocking_domain =3D __iommu_domain_alloc(dev->bus, IOMMU_DOMAIN_BL= OCKED); + group->blocking_domain =3D __iommu_domain_alloc(dev, IOMMU_DOMAIN_BLOCKED= ); if (!group->blocking_domain) { /* * For drivers that do not yet understand IOMMU_DOMAIN_BLOCKED * create an empty domain instead. */ - group->blocking_domain =3D __iommu_domain_alloc(dev->bus, IOMMU_DOMAIN_U= NMANAGED); + group->blocking_domain =3D __iommu_domain_alloc(dev, IOMMU_DOMAIN_UNMANA= GED); if (!group->blocking_domain) return -EINVAL; } --=20 2.36.1.dirty