From nobody Sat Jul 25 18:53:13 2026 Received: from CY3PR05CU001.outbound.protection.outlook.com (mail-westcentralusazon11013046.outbound.protection.outlook.com [40.93.201.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1EF01331A61 for ; Tue, 14 Jul 2026 18:49:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.93.201.46 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054998; cv=fail; b=QlpgOd7+JN+ONWkCOFdW19G3qwpHjfKTloqGh7eDGIQzKOOJfqHD5BnphFYKGoIarnUl8j8ihMFa2Sc1q7UjPJ2EvK8Eaie7RGnIbUc7R7scHB86wr4BtZ8L0ctI1Ud7QfvIBu2LYCEdFcC36fm616Tlp5aNn7Mai1LDmeq0Juw= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054998; c=relaxed/simple; bh=i+P9XLsIOh8wCVLf07uG+PZS0iIXP0oryuzy8FgUL8E=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=W92ihATcxNBRf61ZXbuYt20TDzxJeyH9C8Vhze5cfm720fPzYECN9qwuitgVygEfjWbh2o1TTo5d00iSnBOEeJmcp2FLbMt3aHypvoZ3CJonv1xEUEjfK+cFKJPI7EI/WZ6XBGyFEqY4hIkBfwnnh5HQSqhrukJBHIUWBEAaCb8= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=S+rnUpNk; arc=fail smtp.client-ip=40.93.201.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="S+rnUpNk" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=AMXtSlWJCkKcXC1P0UnMylPb8vf08mhv1cgHtJD5NquJlULcIty7s07SSePaq0GjRqRc0ME35YrmgqtuhaUFk03+Y0/1hVIFsXEG9tZfUlMHHb74w/cihZ9KFB15893qmnpzDAteoT+DWm5U4BWZkAmzpzHostHEkNuQResBL7APLdVn9TwLYPKy36OTQUOpBYKU6HmiQ+XIeZSskVbsQgVHux0dFfEGBck6x9qjIJvGka833TW4rkUlHfQgL4yFfaZdXQFPD5Z6dpUMZX6nZLpfPqKZf+ILEuxYiwuFnVvPLkmVueT6Bpaj3cCSk46sUGhGYePfJd8Z+nBioxjRWw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=98BDFr3zlSyECb/NtbVTJ8DkF0WsXCzkfxVfEXstVFU=; b=nglI1ldZanvitlB/4QAgZKOhK81Ue/MzKYrojd1w+FLZRPOlUyiFQGD01ZtnDJAOQJNQQrU3jp4VXBsa16BS7bX011fimqDuxg9JdiJOm8S7JVuj++HpXcx2DOcIU3j0FhMd9bucmz7V+PR9TwzVuV+sEspur1W0cAkcaTZzzTosyTYGsMiGMg9pEDiJ6cIm6Q2/nzQ29gRTM75zY7gx/IGSHiXON9gUrraXifL5Dn14+PuOmPcTxMzzIXp47fFfGp9rfisL0QBTaAK4BcbrjdLwSar5DiRmSSD84hKmnwxcLU9khzj2U6trIFPqJSb5ieMElOZDoCTwIcMQxvF7ZQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.160) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=98BDFr3zlSyECb/NtbVTJ8DkF0WsXCzkfxVfEXstVFU=; b=S+rnUpNkaS7DUH+aC46a6vykT33Cc0M/92OkgdJ4rOtxB2D1Y95y+idwiX/P8CQzbHzA2AwkItw48zuXAoJZSObzW/1bI1tr5u8hUK18DcAsq30+mW22fgIsEBM3ETWCy/O7nErjmRSjmX+bmysHiklGa+skD38h6ZEJRABDgAZkR6amcb/GA1MZ+FMrZLujpJHThy9myFsjccTvtIthQy8anWriTvtYNnJgKVnyXE8+HwF8lIiOb/klzuwAjjzkkxek3DmhGYU3oKV9NKM0i70ADLFOaLXsvd2DpuIFUGW9MAecvUFjrF1jnSiQfZQbFPBIz7draHj2bstrKFR1hQ== Received: from BL1PR13CA0193.namprd13.prod.outlook.com (2603:10b6:208:2be::18) by CH8PR12MB9837.namprd12.prod.outlook.com (2603:10b6:610:2b4::21) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.202.18; Tue, 14 Jul 2026 18:49:42 +0000 Received: from BN3PEPF0000B370.namprd21.prod.outlook.com (2603:10b6:208:2be:cafe::78) by BL1PR13CA0193.outlook.office365.com (2603:10b6:208:2be::18) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.11 via Frontend Transport; Tue, 14 Jul 2026 18:49:42 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.160) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.160 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.160; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.160) by BN3PEPF0000B370.mail.protection.outlook.com (10.167.243.167) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.3 via Frontend Transport; Tue, 14 Jul 2026 18:49:42 +0000 Received: from rnnvmail203.nvidia.com (10.129.68.9) by mail.nvidia.com (10.129.200.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:16 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail203.nvidia.com (10.129.68.9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:15 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:15 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 1/6] iommu/arm-smmu-v3: Support IDR5.DS and widen the TLBI SCALE field Date: Tue, 14 Jul 2026 11:48:47 -0700 Message-ID: <3f0c3e7b7e9177586d7e545d8089ead4ef7890f0.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B370:EE_|CH8PR12MB9837:EE_ X-MS-Office365-Filtering-Correlation-Id: 66802d18-ce4a-44ad-e91e-08dee1d8aa82 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|376014|7416014|82310400026|36860700016|1800799024|3023799007|6133799003|56012099006|22082099003|18002099003|5023799004|11063799006; X-Microsoft-Antispam-Message-Info: o++UKg5d//AB9ovgEzZcpkbb3X28q2xbEozNLoR2fIyTF0YLDLeV5vdxOXeaHehVvOoDqvxNlqfZgOL2duvQrQIvqw/gqkl+M4JrNd/TTvADiME8Ua8Dzt2FTCZ6GmgljVbuVbsP00cLbdrTNFwgv2gjFoxrLmlNdzAa6J9o82H57dyUoQ6Und9Oc3J7IcN9oKBWb986v0IM0GFq25TBpqjxDPFBlYptH2gyJA9dc5KheDd8zM5lgPlgUEwKh5TG8an5TeX4SR7iGWEcrODpHvKsoCWXfMJ6qCWIkMr7mcdRZ7+hO0dI9WEQVEAg4P6GM7WC9MyTtF0nLvUyhX3l/E/SwVq7WYHvo2umgOswmfHY+uWK02byi8yBOGmi1T7FeLOKchmigKSqhSuCVre0/QQhjKQy10OhiGw8WJ88TddVA4wJ8EJtZu+tyTNeqmbFfx7kWKzji88n9zwPvD3YCsXVNL4K6QY4YPqLfBeLqforfI1/bRdKFJT/bZWSzNx358byYwkRoO3w+7SyGWtA+Q6GDFHOcNoEPgGL/r2gTnV7cHAQyw4hd7N6VS5YlBPM6QOhfBXh5jTZf3wtlBpg23StHucGLDo8B6UmW1Gj6rps10KkWtUdTAoGr//v6MNMWHH8I9xEvpwkE1iTmWmd3/NFTGbpcBoaIL7zIBfVklE53JU0JiGqSasGuASsE/Fy8gxgY7j3sY1U/ae3jEWVIg== X-Forefront-Antispam-Report: CIP:216.228.117.160;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge1.nvidia.com;CAT:NONE;SFS:(13230040)(23010399003)(376014)(7416014)(82310400026)(36860700016)(1800799024)(3023799007)(6133799003)(56012099006)(22082099003)(18002099003)(5023799004)(11063799006);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: c1IRGH1eiDI+yfoRkM5YnuxDhKT7wHRlpAzSd2/98w2Gz0DNVebHo+jzUOOOTQPqEPyDiC4uomkCDFU96J1qbWX1GTwrEpIkOI0Jt8ovC2rkNns5E+ggyTwUE8qoHFVp4J7sMpF6D52C0gWzY9GwN4TNWoEWfIlFAIdgNk0trM7/v4TA8M2HtAozaTNOkQlYVOyyrVmAxxOwsZRHKsK3KdpZ5OrCja8HyEsxWBfYIfS468I60ygqXhX87FR87xWFTD0oY/OjgxZk8Tw9XXcu5TeA2vb+sGk27/pNGpvDmUgKC4Nwsacd3PecHyQnppixPi7Ag+MZ9l1oBxz/nC+Qz0gVpArrCwLpDoTZ8Eu699Upp+1aef0/3cfSEDNxaV08MKtTL0Yc1NcTtYfDflGrt/Ii+9vTYKaYFHHOoG1/IRdYf+WX41UolWYpNlvhq4xw X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:42.1108 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 66802d18-ce4a-44ad-e91e-08dee1d8aa82 X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.160];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B370.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH8PR12MB9837 Content-Type: text/plain; charset="utf-8" An SMMU implementing SMMU_IDR5.DS extends the range invalidation commands: the SCALE field grows a 6th bit, raising its maximum value from 31 to 39, and TTL =3D=3D 0b01 becomes a valid level hint for a 16KB translation granu= le. Add a new ARM_SMMU_FEAT_DS feature detecting the DS bit, and widen the CMDQ_TLBI_0_SCALE field to its architectural 6 bits. Mask the scale value explicitly in arm_smmu_cmdq_batch_add_range(), so the range invalidation path emits the same commands as before, keeping the pre-existing 5-bit truncation of a scale above 31. Also list DS as a valid IDR5 field in the iommu_hw_info_arm_smmuv3 kdoc: iommufd has always reported the raw IDR5 register, so a VMM may conclude from that bit alone that it can expose DS to its guest. Suggested-by: Jason Gunthorpe Fixes: d68beb276ba2 ("iommu/arm-smmu-v3: Support IOMMU_HWPT_INVALIDATE usin= g a VIOMMU object") Cc: stable@vger.kernel.org # needed by the subsequent fix Assisted-by: Claude:claude-fable-5 Signed-off-by: Nicolin Chen Reviewed-by: Jason Gunthorpe Reviewed-by: Pranjal Shrivastava --- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h | 4 +++- include/uapi/linux/iommufd.h | 4 ++-- drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 6 +++++- 3 files changed, 10 insertions(+), 4 deletions(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h b/drivers/iommu/ar= m/arm-smmu-v3/arm-smmu-v3.h index c909c9a88538b..3c59e62978a13 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h @@ -64,6 +64,7 @@ struct arm_vsmmu; =20 #define ARM_SMMU_IDR5 0x14 #define IDR5_STALL_MAX GENMASK(31, 16) +#define IDR5_DS (1 << 7) #define IDR5_GRAN64K (1 << 6) #define IDR5_GRAN16K (1 << 5) #define IDR5_GRAN4K (1 << 4) @@ -415,7 +416,7 @@ struct arm_smmu_cmd { =20 #define CMDQ_TLBI_0_NUM GENMASK_ULL(16, 12) #define CMDQ_TLBI_RANGE_NUM_MAX 31 -#define CMDQ_TLBI_0_SCALE GENMASK_ULL(24, 20) +#define CMDQ_TLBI_0_SCALE GENMASK_ULL(25, 20) #define CMDQ_TLBI_0_VMID GENMASK_ULL(47, 32) #define CMDQ_TLBI_0_ASID GENMASK_ULL(63, 48) #define CMDQ_TLBI_1_LEAF (1UL << 0) @@ -921,6 +922,7 @@ struct arm_smmu_device { #define ARM_SMMU_FEAT_HD (1 << 22) #define ARM_SMMU_FEAT_S2FWB (1 << 23) #define ARM_SMMU_FEAT_BBML2 (1 << 24) +#define ARM_SMMU_FEAT_DS (1 << 25) u32 features; =20 #define ARM_SMMU_OPT_SKIP_PREFETCH (1 << 0) diff --git a/include/uapi/linux/iommufd.h b/include/uapi/linux/iommufd.h index 0425d452d41ed..72bb0e47dc272 100644 --- a/include/uapi/linux/iommufd.h +++ b/include/uapi/linux/iommufd.h @@ -594,7 +594,7 @@ struct iommu_hw_info_vtd { * idr[0]: ST_LEVEL, TERM_MODEL, STALL_MODEL, TTENDIAN , CD2L, ASID16, TTF * idr[1]: SIDSIZE, SSIDSIZE * idr[3]: BBML, RIL - * idr[5]: VAX, GRAN64K, GRAN16K, GRAN4K + * idr[5]: VAX, GRAN64K, GRAN16K, GRAN4K, DS * * - S1P should be assumed to be true if a NESTED HWPT can be created * - VFIO/iommufd only support platforms with COHACC, it should be assumed= to be @@ -602,7 +602,7 @@ struct iommu_hw_info_vtd { * - ATS is a per-device property. If the VMM describes any devices as ATS * capable in ACPI/DT it should set the corresponding idr. * - * This list may expand in future (eg E0PD, AIE, PBHA, D128, DS etc). It is + * This list may expand in future (eg E0PD, AIE, PBHA, D128 etc). It is * important that VMMs do not read bits outside the list to allow for * compatibility with future kernels. Several features in the SMMUv3 * architecture are not currently supported by the kernel for nesting: HTT= U, diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/ar= m/arm-smmu-v3/arm-smmu-v3.c index a10affb483a4f..9f121f9f404ea 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c @@ -2446,9 +2446,10 @@ static void arm_smmu_cmdq_batch_add_range(struct arm= _smmu_device *smmu, /* Determine how many chunks of 2^scale size we have */ num =3D (num_pages >> scale) & CMDQ_TLBI_RANGE_NUM_MAX; =20 + /* Keep the pre-DS 5-bit truncation when scale > 31 */ cmd->data[0] =3D orig_data0 | FIELD_PREP(CMDQ_TLBI_0_NUM, num - 1) | - FIELD_PREP(CMDQ_TLBI_0_SCALE, scale); + FIELD_PREP(CMDQ_TLBI_0_SCALE, scale & 0x1f); =20 /* range is num * 2^scale * pgsize */ inv_range =3D num << (scale + tg); @@ -5098,6 +5099,9 @@ static int arm_smmu_device_hw_probe(struct arm_smmu_d= evice *smmu) /* Maximum number of outstanding stalls */ smmu->evtq.max_stalls =3D FIELD_GET(IDR5_STALL_MAX, reg); =20 + if (reg & IDR5_DS) + smmu->features |=3D ARM_SMMU_FEAT_DS; + /* Page sizes */ if (reg & IDR5_GRAN64K) smmu->pgsize_bitmap |=3D SZ_64K | SZ_512M; --=20 2.43.0 From nobody Sat Jul 25 18:53:13 2026 Received: from DM5PR21CU001.outbound.protection.outlook.com (mail-centralusazon11011036.outbound.protection.outlook.com [52.101.62.36]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 117E0377A87 for ; Tue, 14 Jul 2026 18:49:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.62.36 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054994; cv=fail; b=T+h0P/a36rFDE8lj0anBxuLkibIZIe/CI2TP+5eshZv/WNj6hdYI9HzN6XjM+5uWUuvqrNgYoz0X2iQ44BAtZQ2RfZKoc8OdefsAvQYM/JBWACqeyDq+Trp4s62n72B1IuA0ilpv39jTGrEhPimjHKGTYaXtZCXhprTNM5Xno1o= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054994; c=relaxed/simple; bh=T7mGxgRXriK+P2Ae96alHs5k+OQJIWgRFWPmiiahHDU=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=reuM1El1d4SRGPgLettaRytczwTokSeVgze5gnbhUWsA2DmwhnEuOiCHppJOZitB9up80tiNgui2fJM2JuoRlRPPfyugQ5afXKmTxxYrPiYrhLfDTQbh1feHGZhtnu2dlf6hhuykVs3ywcUKkn3AtRWCy/RKaJ2giMTFXVari14= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=jM+cM5P3; arc=fail smtp.client-ip=52.101.62.36 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="jM+cM5P3" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=XeEgWJ8nidzwpiDBytNjoRGLyhr+1B/Rn4RjFGAn6VX3IVypFtzXlP6em3yYrPUBt4Ob58ky2XNrWx5Gjszp+bUiRJF4X3hgIJY8N1sRmc5N3MPbO9WpkEuIwi5o4pCRrGKdE68/0oj0WOkmPiFIrNGBkUHxmmCxDKMuBsKNJ5MnoXerftGkxCWfZ5x21hVh0yNjR8/5ZcdLV43jOoFAZgNYHPCtwqQCoW64hwj6l5u33KGcchva0t3dQti0Py/K4Xspjl45zvrtPtxVB6XvLmhmd1nxr43m5pzIK3ASumV7/Tl572t0ZCvSj8rEIhy1xqkML9eNf8Lt6EyBY5oorA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=F/ZZMDQQ1u88VuGmdO/wJo7bXpfNK1/FkBn2XGeJyyo=; b=KP9Fm1XpupG2jeeKib9X9vN5cFNk08NGBfzMgTT4ImLAZq/YlOps1PCrqhXr0xj3StcM/TYaWIv4GNIq+a5HYkEt8Qx1oawE6A6Hi8z93i3FgIfbNkMLcLJCBGcXt5TYac5vA1PvS1yEPa4lPtJZIuyzk2QvQDGsOE7kYb7ow7GlfPtansQ5eTJCh4dkoDoOEOVCCl/Y2CUXRjayhBvjOrIjJXQvs0g3RaM1vCskuipD/A/NWlhpJIJQkk7pPNDIyYyjHtb+n4rmnF308Ad9j76hqwrquACoVJIC1AoIJZIICYaSNcCEjfprzs1E5Pf1yy990ewpKCBBfVStaIS+8Q== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.160) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=F/ZZMDQQ1u88VuGmdO/wJo7bXpfNK1/FkBn2XGeJyyo=; b=jM+cM5P3r6oJW/AH9y0+3Txeqa+pkXGUPnhWfnU3ApYv3Hj1oAfM1nKzmoHrtM2XBwkE0WBqejVvpxQBlxaoAFynl6yNPj55UOrTfJnyTaadoe5dPJAofgXd326EHmhelxVLES6F+j8tk01mQBSb630S54IioqhkBD6Rfh6vF0XbtnsvlTlRCtCNPPKD5Tbo55v5Sq84HaI3m5KG1sn+YREivQYNHvCtIATIwAyusFzBADVaLVYjoq3+vHVFaZZe2Q2jmMuO6QkdZfIsvf06GVzTikkl5V9/16Oa5STx0jXn6pVpCdrUtPBlOo/79zqmkJjpdcX5t7+kGoO89Lc1VQ== Received: from BL1PR13CA0193.namprd13.prod.outlook.com (2603:10b6:208:2be::18) by DS0PR12MB8453.namprd12.prod.outlook.com (2603:10b6:8:157::16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.10; Tue, 14 Jul 2026 18:49:44 +0000 Received: from BN3PEPF0000B370.namprd21.prod.outlook.com (2603:10b6:208:2be:cafe::a1) by BL1PR13CA0193.outlook.office365.com (2603:10b6:208:2be::18) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.11 via Frontend Transport; Tue, 14 Jul 2026 18:49:43 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.160) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.160 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.160; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.160) by BN3PEPF0000B370.mail.protection.outlook.com (10.167.243.167) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.3 via Frontend Transport; Tue, 14 Jul 2026 18:49:43 +0000 Received: from rnnvmail205.nvidia.com (10.129.68.10) by mail.nvidia.com (10.129.200.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:17 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail205.nvidia.com (10.129.68.10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:17 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:16 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 2/6] iommu/arm-smmu-v3-iommufd: Reject unsupported bits in invalidation commands Date: Tue, 14 Jul 2026 11:48:48 -0700 Message-ID: <5c70a336821e3cea176356470d94ff18329ff867.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B370:EE_|DS0PR12MB8453:EE_ X-MS-Office365-Filtering-Correlation-Id: b6b105e7-ddbf-4da4-4866-08dee1d8ab6a X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|7416014|23010399003|376014|1800799024|82310400026|36860700016|3023799007|11063799006|56012099006|22082099003|18002099003; X-Microsoft-Antispam-Message-Info: gipmp9u+Y7gLHfxnsttYXBlhZt1WDT+ZuVNqr7jnuODHPDIFonaFcDwwyzXMekCkqmyUQGVF5lsI3j3QTtKX2lJsM38yhuDaqUe5D5Mne+oPJSMkEWNiOVQW25/LCezwPb947S0UXPeap6dvhV7unlPasymZ1pMpMt+8nBFInnh6ti1nDm5iEeNKZ83dg2XtKl3npWV5z7gr53nP8EekNn3FSo7mQYbyWREWWoB5pwB1vaHgf/dfDJ58XdVdisAnFfByoXdSlZL/m1XBx90QsSCdoF0TbYjgqUotEoqHI/PmaK9DTzHntG1bZtmcK98bGwQBgE1tzV05nYYdJC1qCHqnT6fQgjVptCap3DHMpb43TyOdcy2Kard3hSeEKFavBvtwqm09n5Ul2u2BL/mcAtoWbc5TSP3u4+1x0x9Kb105v7oo7jImfnUd6pW+Uw/Yb6lfh6AGlHlHCCIFwQXHDNhWOrVV3JZa2kcOj15puZSOQuZ27HitFhvLfQ0GmTmr9c7GZJKviG6vLztQ0tj4Js2FHuMlAez4Sy/WxALQ2+aWRnKk1ho+/GH/PU0xgcYaWtbH+NkuivVRvrOXCKceFwlRL3x5/Jq0qXvG8fbETqBpVQI6dLwpvxoc9/kEX8o0Y3NcrIGtsR+tjxMu4e/L07UBAFpRxlEiPSzlNg4ST8yhyosMD3jDQuhYOXiRjeol982Bpyp7a+vFVapUh/7VGQ== X-Forefront-Antispam-Report: CIP:216.228.117.160;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge1.nvidia.com;CAT:NONE;SFS:(13230040)(7416014)(23010399003)(376014)(1800799024)(82310400026)(36860700016)(3023799007)(11063799006)(56012099006)(22082099003)(18002099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: MrAbkCLhDPcPYjom/uVPR1O4puxUDmHCBbEdqu1cBq9cjggpe+WvfUMBHTjCs24onDlzKUkRQmcfQYsJicsIME0KRlg5Vo7T4r3oiGAzekkDrKIjEQjt3U8urvqNKNhwJijD0ZCdBGZnuTqrgGrUKZ8t3wFQrpuouIhLZL47sLOK4xXG7/9I8nxDb/iPvzYGd6kIeR/OhN8AqgXBU19t4EO6ocKxsNNCY1L3YGaD9lmF2Xc8tDYeXdZHGY3Yk+p1tE1m+fhfCvbtdlM3Qg5IPMISYRCK+OwP2movv2DJtLtVKE+FKiuDx7JQlSn5CU3oU5rFhcQsbPN/UrOR06YnVwJBum31yLqnjjMvDvfuMHBK1d/NH01mzpwB3xySVqnt0tvF9VN/fdLxksEfa6mwNRBOoYSbWzlMXD7Vl/6coZH178vjScB7XAmJ2uXphvSh X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:43.6352 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: b6b105e7-ddbf-4da4-4866-08dee1d8ab6a X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.160];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B370.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: DS0PR12MB8453 Content-Type: text/plain; charset="utf-8" The arm_vsmmu_cache_invalidate() op hands a guest's invalidation commands to the trusted main command queue after enforcing only the VMID or the SID, and passes the rest of the command through to the queue unchanged. That lets a guest set bits the host never meant to forward: a reserved or undefined bit makes a command malformed; per the Arm SMMUv3 specification, in its section 4.1.3 "Command errors", a CERROR_ILL is raised, among other cases, when: A valid command opcode is used and a Reserved or undefined field is optionally detected as non-zero, which results in the command being treated as malformed. Restrict each opcode to the fields that the driver supports and reject the command with -EIO if it sets any other bit, before the command reaches the queue. This stops the host from forwarding any bit whose meaning it does not control. Document this contract in the uAPI header, so user space must take the responsibility to forward valid commands only. Some fields and whole opcodes are legal only on an SMMU that implements the matching feature, so accept them conditionally: - NUM, SCALE, TG and TTL need FEAT_RANGE_INV. - SCALE bit 25, for values above 31, and TTL =3D=3D 0b01 with a 16KB TG need SMMU_IDR5.DS, gated on ARM_SMMU_FEAT_DS so that a VMM exposing DS from the reported IDR5 register keeps working. - ASID is limited to asid_bits, since its upper 8 bits are RES0 on an SMMU that only supports 8-bit ASIDs. - ATC_INV needs FEAT_ATS. Per the specification's section 4.5 "ATS and PRI", CMD_ATC_INV is ILLEGAL when: SMMU_IDR0.ATS =3D=3D 0 and this command is issued on a Non-secure or Secure Command queue. - SSV, SSID and Global need a non-zero ssid_bits. Without it, setting them is not illegal but CONSTRAINED UNPREDICTABLE, which a guest should not be able to provoke. Global also takes effect only when SSV =3D=3D 1, broadening the invalidation from the one SSID to all the PASIDs of the single device that the SID field addresses. Some values inside the accepted fields are Reserved too: - NUM =3D=3D 0, SCALE =3D=3D 0 and TTL =3D=3D 0 together are a Reserved co= mbination and cause a CERROR_ILL. - NUM, SCALE and TTL turn RES0 when TG =3D=3D 0. - An ATC_INV Size above 52, the invalidate-all span, is permitted to raise a CERROR_ILL. Reject these Reserved values the same way. In contrast, an out-of-range address or ID value is defined as CONSTRAINED UNPREDICTABLE that would be scoped to the guest itself, so it does not deserve a check. Fixes: d68beb276ba2 ("iommu/arm-smmu-v3: Support IOMMU_HWPT_INVALIDATE usin= g a VIOMMU object") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Nicolin Chen Reviewed-by: Jason Gunthorpe Reviewed-by: Pranjal Shrivastava --- include/uapi/linux/iommufd.h | 4 +- .../arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 125 ++++++++++++++++-- 2 files changed, 117 insertions(+), 12 deletions(-) diff --git a/include/uapi/linux/iommufd.h b/include/uapi/linux/iommufd.h index 72bb0e47dc272..6686a121cc950 100644 --- a/include/uapi/linux/iommufd.h +++ b/include/uapi/linux/iommufd.h @@ -909,7 +909,9 @@ struct iommu_hwpt_vtd_s1_invalidate { * CMDQ_OP_CFGI_CD * CMDQ_OP_CFGI_CD_ALL * - * -EIO will be returned if the command is not supported. + * User space must forward only valid commands: the kernel rejects, with + * -EIO, any command carrying an unsupported opcode, an unsupported field, + * or a field value that the underlying SMMU hardware does not implement. */ struct iommu_viommu_arm_smmuv3_invalidate { __aligned_le64 cmd[2]; diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c b/drivers/= iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c index 1e9f7d2de3441..07e502879dffc 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c @@ -305,6 +305,102 @@ struct arm_vsmmu_invalidation_cmd { }; }; =20 +/* Reject the range field values that the spec defines as Reserved */ +static int arm_vsmmu_validate_range(struct arm_smmu_device *smmu, u64 data= [2]) +{ + bool range =3D !!(data[0] & (CMDQ_TLBI_0_NUM | CMDQ_TLBI_0_SCALE)); + u8 ttl =3D FIELD_GET(CMDQ_TLBI_1_TTL, data[1]); + u8 tg =3D FIELD_GET(CMDQ_TLBI_1_TG, data[1]); + + /* NUM, SCALE and TTL are RES0 when TG =3D=3D 0 */ + if (!tg) + return (range || ttl) ? -EIO : 0; + /* TTL =3D=3D 0b01 with a 16KB TG requires SMMU_IDR5.DS */ + if (tg =3D=3D 2 && ttl =3D=3D 1 && !(smmu->features & ARM_SMMU_FEAT_DS)) + return -EIO; + /* NUM =3D=3D 0, SCALE =3D=3D 0 with TTL =3D=3D 0 is a reserved combinati= on */ + if (!range && !ttl) + return -EIO; + return 0; +} + +static int arm_vsmmu_validate_user_cmd(struct arm_vsmmu *vsmmu, u64 data[2= ]) +{ + struct arm_smmu_device *smmu =3D vsmmu->smmu; + u64 allowed[2] =3D { CMDQ_0_OP }; + + /* Collect the fields userspace is allowed to set for each opcode */ + switch (data[0] & CMDQ_0_OP) { + case CMDQ_OP_TLBI_NH_VA: + /* An SMMU with 8-bit ASIDs treats the upper 8 bits as RES0 */ + allowed[0] |=3D FIELD_PREP(CMDQ_TLBI_0_ASID, + GENMASK(smmu->asid_bits - 1, 0)); + fallthrough; + case CMDQ_OP_TLBI_NH_VAA: + /* NUM/SCALE/TG/TTL are range fields gated on FEAT_RANGE_INV */ + if (smmu->features & ARM_SMMU_FEAT_RANGE_INV) { + if (arm_vsmmu_validate_range(smmu, data)) + return -EIO; + allowed[0] |=3D CMDQ_TLBI_0_NUM | CMDQ_TLBI_0_SCALE; + allowed[1] |=3D CMDQ_TLBI_1_TG | CMDQ_TLBI_1_TTL; + /* SCALE bit 25 (values above 31) is RES0 without DS */ + if (!(smmu->features & ARM_SMMU_FEAT_DS)) + allowed[0] &=3D ~FIELD_PREP(CMDQ_TLBI_0_SCALE, + BIT(5)); + } + allowed[0] |=3D CMDQ_TLBI_0_VMID; + allowed[1] |=3D CMDQ_TLBI_1_LEAF | CMDQ_TLBI_1_VA_MASK; + break; + case CMDQ_OP_TLBI_NH_ASID: + /* An SMMU with 8-bit ASIDs treats the upper 8 bits as RES0 */ + allowed[0] |=3D FIELD_PREP(CMDQ_TLBI_0_ASID, + GENMASK(smmu->asid_bits - 1, 0)); + fallthrough; + case CMDQ_OP_TLBI_NH_ALL: + allowed[0] |=3D CMDQ_TLBI_0_VMID; + break; + case CMDQ_OP_ATC_INV: + /* ATC_INV is illegal unless the SMMU implements ATS */ + if (!(smmu->features & ARM_SMMU_FEAT_ATS)) + return -EIO; + /* A Size above 52 (invalidate-all) may raise a CERROR_ILL */ + if (FIELD_GET(CMDQ_ATC_1_SIZE, data[1]) > ATC_INV_SIZE_ALL) + return -EIO; + /* + * SSV/SSID/Global need substream support. SSID and Global are + * IGNORED (not RES0) when SSV =3D=3D 0, so they need no SSV check. + */ + if (smmu->ssid_bits) + allowed[0] |=3D CMDQ_0_SSV | CMDQ_ATC_0_SSID | + CMDQ_ATC_0_GLOBAL; + allowed[0] |=3D CMDQ_ATC_0_SID; + allowed[1] |=3D CMDQ_ATC_1_SIZE | CMDQ_ATC_1_ADDR_MASK; + break; + case CMDQ_OP_CFGI_CD: + /* No SSV for CFGI_CD; SSID requires substream support */ + if (smmu->ssid_bits) + allowed[0] |=3D CMDQ_CFGI_0_SSID; + allowed[1] |=3D CMDQ_CFGI_1_LEAF; + fallthrough; + case CMDQ_OP_CFGI_CD_ALL: + allowed[0] |=3D CMDQ_CFGI_0_SID; + break; + } + + /* + * Reject any other bit, e.g. a RES0 bit or a Secure bit, before the + * command reaches the trusted main cmdq, so a guest cannot wedge the + * shared queue for every device with a CERROR_ILL. + * + * By contrast, an out-of-range address or ID value does not need a + * check: the spec defines it as CONSTRAINED UNPREDICTABLE, which is + * scoped to the guest itself and does not raise a CERROR_ILL. + */ + if ((data[0] & ~allowed[0]) || (data[1] & ~allowed[1])) + return -EIO; + return 0; +} + /* * Convert, in place, the raw invalidation command into an internal format= that * can be passed to arm_smmu_cmdq_issue_cmdlist(). Internally commands are @@ -315,33 +411,40 @@ struct arm_vsmmu_invalidation_cmd { static int arm_vsmmu_convert_user_cmd(struct arm_vsmmu *vsmmu, struct arm_vsmmu_invalidation_cmd *cmd) { + u64 *data =3D cmd->cmd.data; + int ret; + /* Commands are le64 stored in u64 */ - cmd->cmd.data[0] =3D le64_to_cpu(cmd->ucmd.cmd[0]); - cmd->cmd.data[1] =3D le64_to_cpu(cmd->ucmd.cmd[1]); + data[0] =3D le64_to_cpu(cmd->ucmd.cmd[0]); + data[1] =3D le64_to_cpu(cmd->ucmd.cmd[1]); + + ret =3D arm_vsmmu_validate_user_cmd(vsmmu, data); + if (ret) + return ret; =20 - switch (cmd->cmd.data[0] & CMDQ_0_OP) { + switch (data[0] & CMDQ_0_OP) { case CMDQ_OP_TLBI_NSNH_ALL: /* Convert to NH_ALL */ - cmd->cmd.data[0] =3D CMDQ_OP_TLBI_NH_ALL | - FIELD_PREP(CMDQ_TLBI_0_VMID, vsmmu->vmid); - cmd->cmd.data[1] =3D 0; + data[0] =3D CMDQ_OP_TLBI_NH_ALL | + FIELD_PREP(CMDQ_TLBI_0_VMID, vsmmu->vmid); + data[1] =3D 0; break; case CMDQ_OP_TLBI_NH_VA: case CMDQ_OP_TLBI_NH_VAA: case CMDQ_OP_TLBI_NH_ALL: case CMDQ_OP_TLBI_NH_ASID: - cmd->cmd.data[0] &=3D ~CMDQ_TLBI_0_VMID; - cmd->cmd.data[0] |=3D FIELD_PREP(CMDQ_TLBI_0_VMID, vsmmu->vmid); + data[0] &=3D ~CMDQ_TLBI_0_VMID; + data[0] |=3D FIELD_PREP(CMDQ_TLBI_0_VMID, vsmmu->vmid); break; case CMDQ_OP_ATC_INV: case CMDQ_OP_CFGI_CD: case CMDQ_OP_CFGI_CD_ALL: { - u32 sid, vsid =3D FIELD_GET(CMDQ_CFGI_0_SID, cmd->cmd.data[0]); + u32 sid, vsid =3D FIELD_GET(CMDQ_CFGI_0_SID, data[0]); =20 if (arm_vsmmu_vsid_to_sid(vsmmu, vsid, &sid)) return -EIO; - cmd->cmd.data[0] &=3D ~CMDQ_CFGI_0_SID; - cmd->cmd.data[0] |=3D FIELD_PREP(CMDQ_CFGI_0_SID, sid); + data[0] &=3D ~CMDQ_CFGI_0_SID; + data[0] |=3D FIELD_PREP(CMDQ_CFGI_0_SID, sid); break; } default: --=20 2.43.0 From nobody Sat Jul 25 18:53:13 2026 Received: from BN8PR05CU002.outbound.protection.outlook.com (mail-eastus2azon11011060.outbound.protection.outlook.com [52.101.57.60]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 12D993A5430 for ; Tue, 14 Jul 2026 18:49:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.57.60 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054994; cv=fail; b=cinh5upCqvuxTeOStDujGRSb/0PH06CxXts+EB0vkzmBv8xY28sdcRouXdsqhSW2m65mj1nDkhkucraKHUm8l8Rhj+QJxeEZ1vg0zGfrrDXae8joOJF/VXvV+NZwek8pZJuNkUUMegSp9ZRB826ktYHhljijZx0vfYmDYX8oppg= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054994; c=relaxed/simple; bh=fA4GBagE0Hgl3PTpEi4GCJ5CIH6TC8NPcWTOuGm827U=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=KOEDwlj1tcXk5TPkhknQDTHu2MYdWiyIdnsOoaIyzbq4dC1diKKqThV4VZ9M3BMy1zUJuHlqjlXqTwySqUxlKrjW9BmzpFM+ixXeUuABbUbnhYu/xpeB+38vxP4BkXyPrr+kArrT/VIuuyfOzL+V4/VcuGbwgJ8mZ+frhy/f74k= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=igtyEauS; arc=fail smtp.client-ip=52.101.57.60 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="igtyEauS" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=I8xRAlSupCNElN0e9DomvqLQNydq77UsWVDZIQdKwC85oh0feVGq/05Z47yE53kLX1y1e7WcWHX3zRFeOZEip0vCwY0VGhjYLs8WEBQLfTgz/9C7/HCt7KsP4uNsNUJvopeIkEpIMJlEO6XqtL5JVZA6bnCS8KkHgjXs7Nsd443iurNzzccnQf0L94wa39AUJ+gVDu5tmPmluVdU1aFNz13GKWL0a4R7iC/OInNJN9/WAOBOUQsQkq7GxH5KCAAcLoAU/3TC3T9MXmP0EXIbmfrVeIVP3iZ9PdMqXVUFvS4uuZXnT7MoYaoGuUg1o5oXF7UhJYgGvRgRFui9zFoVEA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=gqFpwz9zKyNZPGIeIRh6+wXm14o1BuoGQbs/Iw0QgiU=; b=feST5TIHr7upHFUTEB9cgKsvbHBnIDq9GavnMlbafqmGEoqP5szYMKbbMDwtjgv2n5GhEh6b4bUeM20G4xxcImQAbk5znYGpWS8fwdBdDzBbcsjPsyYUqAWkcrWHmsR/gwE9uxSVjlmTdZM/GEsgaNE23VWdmJFAKrwczKZ6U+Jx6eXuwpQ8iijzgCSutAOFdu+MDShqAwUV95YqxXWWUfnxp96RQTUfMCUmqFfBvVWeJOOZw+30a31MEmu2P7V9X3IBs2C/QWZT/9QCGhJSJepilhVRIfyZ8kYd5YCFtnkZxous9K6Xmv2qHLJQfFTtiOeSGLW3Hto153ocTfJwHw== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.160) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=gqFpwz9zKyNZPGIeIRh6+wXm14o1BuoGQbs/Iw0QgiU=; b=igtyEauS0wZYPavrj9NrFFY0atgbZvcUosVHnVJTo+IA34COCEgydCk16Ac/KjBLcgAOwqoMsUVWuCWy5FvxNmN6RIsukm3dxv9mWDfcNPeCd6dwb9HCsFpj4DDEXu57keY+W8UvWin2ktF+QGbx32DHos2dQj5iLdXaYb8aD9rQwCClmiOTLQ/nJ82Pfwm9rnmPn9PjgsdGAzm4q13F1OCH8BSUo6Gij44/3VzyzEJezCIuu/x1NcyLq7Lq6WJ7kKrqvlAheKUF+TzHTHwGaWRFlgXYiHe1imNfb8807x82NArMkgD2pHXjdhVrW0e/QMI2yphwV6dZU3N3lxM26Q== Received: from CH2PR02CA0017.namprd02.prod.outlook.com (2603:10b6:610:4e::27) by SJ1PR12MB6028.namprd12.prod.outlook.com (2603:10b6:a03:489::8) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.202.18; Tue, 14 Jul 2026 18:49:45 +0000 Received: from BN3PEPF0000B36D.namprd21.prod.outlook.com (2603:10b6:610:4e:cafe::9b) by CH2PR02CA0017.outlook.office365.com (2603:10b6:610:4e::27) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.9 via Frontend Transport; Tue, 14 Jul 2026 18:49:45 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.160) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.160 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.160; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.160) by BN3PEPF0000B36D.mail.protection.outlook.com (10.167.243.164) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.3 via Frontend Transport; Tue, 14 Jul 2026 18:49:44 +0000 Received: from rnnvmail205.nvidia.com (10.129.68.10) by mail.nvidia.com (10.129.200.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:18 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail205.nvidia.com (10.129.68.10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:18 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:17 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 3/6] iommufd: Iterate the cache invalidation array in the core Date: Tue, 14 Jul 2026 11:48:49 -0700 Message-ID: <10d92026fce6d6f3e74e1d41edbd03da8bec7e3f.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B36D:EE_|SJ1PR12MB6028:EE_ X-MS-Office365-Filtering-Correlation-Id: 771dde1b-018e-4cdb-0772-08dee1d8ac19 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|1800799024|7416014|36860700016|82310400026|23010399003|18002099003|22082099003|6133799003|3023799007|11063799006|5023799004|56012099006; X-Microsoft-Antispam-Message-Info: Nn9JkyvI2e+lutPatp0OEcxIGePDQ+AUFvmHXk6cbeIYZ2UQM/T8UEFfpRupqoKJDacSA2CHw7E8n0aMpaevYyRfUjCDK8+mzxLKWPQHuifTZdWiHCMTENlW/jFwOkg+lD0BEqbahatsXlwz61qNjuaCXonTvquFN92385+5qNz3KOkMXRU0MaDLbBrPTQVoHJMcNAVmBAMNM6Ztw2BLBkLwfInllqAsph2k7loErNn5y2WhuvavZFK75G0rlEzpt9vgeBLFSUS/pkcwygZbok7NJkH30LizTjlJYKttqI3JTiQCm1vq4cU4tWQZqBSEERXvP5iNbuUVuM7EQMs/P2UZMxLJs3bwmaOKbFeNQslzQbKr8skDuPH80YB5e+OAEpZJ0EDF3HPG8n4dnPj2fSBr/QNKGrMrYFhboURgNYv+Hpif7vwE8CPaQYXJ3hmUmCxc3xK0qROlpyjofKej647awoFLrYIewrK2k0IqtSVMhKRESIG86fgh4xu8mpTsZhS2ovJ3EBPebbdB5TBQlCFIpEQ916mgvC628y3IMcjor9bZgzsulM8jcPEsJ26S8uOsMmUXj0Cdmoa+szUPUkJzVPcXvazWg8mGnlRgg4k99D4SjM6oOufej26lsN7jfufd1R8tatx+tLaCNxzLpQHg1VS2e4a2W3pE/mAfxZsrtZ9bfhFfQvbCSoi8TmTOYW0AsdQp09kSSJylCrV3rA== X-Forefront-Antispam-Report: CIP:216.228.117.160;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge1.nvidia.com;CAT:NONE;SFS:(13230040)(376014)(1800799024)(7416014)(36860700016)(82310400026)(23010399003)(18002099003)(22082099003)(6133799003)(3023799007)(11063799006)(5023799004)(56012099006);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: OE2MK0MQf5UuVxSOrf3R0bP7oirZsWAvbdlo3OqcUObkLQJB+RTqkSMtrtBhg4m3UYnOqpDVAofonmSCSC8tTVSM8txgIgPKJUbiiO12y+SzyjDGSfDwjmWUY/xcJ4gE9nllPPXSpTkfzDxlRg5dhKCNZmEnizL7s3vSZxM3gwRIUH5dXx7/X0Hwk6+vHeORpaB6pE/YFdOhO+XoeVUb6Ef4Xw0oA9fTVYdtklIMRVqTgF9p2P0DtlA1oEjL4QK1SCq3VU7GFZQmlc+hq0eUzNE8nOeeJzP252IUL6XELft/AHdBxi8wmGGW0ZmGHXNoqTZOfMUmDjb6m6+zKiZQQSREVpcv6UCb+uGCfmC63rYqV+ibrnQic5gtN1cqfiEZ4k1dwjgXGFFQr1yvjReQS5W+ASseMAymo4ENqeLtU/tK6kFnTQW/PdxKXHt/+vQX X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:44.7875 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 771dde1b-018e-4cdb-0772-08dee1d8ac19 X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.160];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B36D.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ1PR12MB6028 Content-Type: text/plain; charset="utf-8" The cache invalidation ops, cache_invalidate_user() for a nested HWPT and the cache_invalidate() for a vIOMMU, are each handed the full user request array and report how many of the array entries they handled by setting the array->entry_num. Every driver therefore implements its own loop over the array, and a driver wanting to process that array in fixed-size chunks (e.g. to issue commands out of a fixed-size on-stack buffer) has to carry the loop and its sub-array bookkeeping all on its own. Move the iteration into the iommufd core instead. Invoke the op with a sub-array that starts at the first not-yet-handled entry, let it handle a prefix of that sub-array and report the count via array->entry_num, then advance the base pointer and re-invoke the op until the entire array has been consumed or until the op returns an error along the way. A driver that handles the entire window in one single call, as all of the current drivers happen to do, finishes the loop in just one pass, so this does not change any of the existing behavior. It instead lets each of the drivers convert to bounded chunk processing on its own, done by each of the subsequent changes. Suggested-by: Jason Gunthorpe Reviewed-by: Kevin Tian Reviewed-by: Lu Baolu Reviewed-by: Pranjal Shrivastava Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Nicolin Chen Reviewed-by: Jason Gunthorpe --- include/linux/iommu.h | 6 ++++-- include/linux/iommufd.h | 2 ++ drivers/iommu/iommufd/hw_pagetable.c | 25 +++++++++++++++---------- 3 files changed, 21 insertions(+), 12 deletions(-) diff --git a/include/linux/iommu.h b/include/linux/iommu.h index d20aa6f6863ab..969758f87e445 100644 --- a/include/linux/iommu.h +++ b/include/linux/iommu.h @@ -773,8 +773,10 @@ struct iommu_ops { * passes in the cache invalidation requests, in f= orm * of a driver data structure. The driver must upd= ate * array->entry_num to report the number of handled - * invalidation requests. The driver data structure - * must be defined in include/uapi/linux/iommufd.h + * invalidation requests. A driver may handle fewe= r than + * the requested, in which case the core re-invoke= s the + * op for the remainder. The driver data structure= must + * be defined in include/uapi/linux/iommufd.h * @iova_to_phys: translate iova to physical address * @enforce_cache_coherency: Prevent any kind of DMA from bypassing IOMMU_= CACHE, * including no-snoop TLPs on PCIe or other plat= form diff --git a/include/linux/iommufd.h b/include/linux/iommufd.h index 6e7efe83bc5d8..3087f5b2def84 100644 --- a/include/linux/iommufd.h +++ b/include/linux/iommufd.h @@ -154,6 +154,8 @@ struct iommufd_hw_queue { * The @array passes in the cache invalidation requests= , in * form of a driver data structure. A driver must updat= e the * array->entry_num to report the number of handled req= uests. + * A driver may handle fewer than the requested entry_n= um, in + * which case the core re-invokes the op for the remain= der. * The data structure of the array entry must be define= d in * include/uapi/linux/iommufd.h * @vdevice_size: Size of the driver-defined vDEVICE structure per this vI= OMMU diff --git a/drivers/iommu/iommufd/hw_pagetable.c b/drivers/iommu/iommufd/h= w_pagetable.c index 623cc608ca0cd..644daf18849f4 100644 --- a/drivers/iommu/iommufd/hw_pagetable.c +++ b/drivers/iommu/iommufd/hw_pagetable.c @@ -501,6 +501,8 @@ int iommufd_hwpt_invalidate(struct iommufd_ucmd *ucmd) .entry_len =3D cmd->entry_len, .entry_num =3D cmd->entry_num, }; + struct iommufd_hw_pagetable *hwpt =3D NULL; + struct iommufd_viommu *viommu =3D NULL; struct iommufd_object *pt_obj; u32 done_num =3D 0; int rc; @@ -527,31 +529,34 @@ int iommufd_hwpt_invalidate(struct iommufd_ucmd *ucmd) goto out; } if (pt_obj->type =3D=3D IOMMUFD_OBJ_HWPT_NESTED) { - struct iommufd_hw_pagetable *hwpt =3D - container_of(pt_obj, struct iommufd_hw_pagetable, obj); - + hwpt =3D container_of(pt_obj, struct iommufd_hw_pagetable, obj); if (!hwpt->domain->ops || !hwpt->domain->ops->cache_invalidate_user) { rc =3D -EOPNOTSUPP; goto out_put_pt; } - rc =3D hwpt->domain->ops->cache_invalidate_user(hwpt->domain, - &data_array); } else if (pt_obj->type =3D=3D IOMMUFD_OBJ_VIOMMU) { - struct iommufd_viommu *viommu =3D - container_of(pt_obj, struct iommufd_viommu, obj); - + viommu =3D container_of(pt_obj, struct iommufd_viommu, obj); if (!viommu->ops || !viommu->ops->cache_invalidate) { rc =3D -EOPNOTSUPP; goto out_put_pt; } - rc =3D viommu->ops->cache_invalidate(viommu, &data_array); } else { rc =3D -EINVAL; goto out_put_pt; } =20 - done_num =3D data_array.entry_num; + do { + if (viommu) + rc =3D viommu->ops->cache_invalidate(viommu, &data_array); + else + rc =3D hwpt->domain->ops->cache_invalidate_user( + hwpt->domain, &data_array); + + done_num +=3D data_array.entry_num; + data_array.uptr +=3D data_array.entry_num * data_array.entry_len; + data_array.entry_num =3D cmd->entry_num - done_num; + } while (!rc && done_num !=3D cmd->entry_num); =20 out_put_pt: iommufd_put_object(ucmd->ictx, pt_obj); --=20 2.43.0 From nobody Sat Jul 25 18:53:13 2026 Received: from MW6PR02CU001.outbound.protection.outlook.com (mail-westus2azon11012063.outbound.protection.outlook.com [52.101.48.63]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DBF4C377ABA for ; Tue, 14 Jul 2026 18:49:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.48.63 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784055000; cv=fail; b=VqyZpnPNa5scBkdCW6wAHrT3FOqONLkYb9+Q76iUt+RdISli5Jmv/P/+7oE7yZWjQtoMH9578vncq7NFPBqYX0kDgZt3aCVWd05c9d5kBgO7kXH5teozZopj56xZsrPzIb779c9qGWpUuGwPF9uc/XO6kcZ4LP0YID8IwiZYDL4= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784055000; c=relaxed/simple; bh=kDqCU4drDD/34cz1Qcz1hI5chixYCXueKsm6yKKc/M4=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=a+UPpsPtB+7knjk7EkC1OpWaD6lmV/QpGH8t1DkjYdTsFz+QHazCufNYe5bNTCfwW0+keLIYU+qgPSDxR1W2PSteI0Z3Yz5a4B0kg0S1+1jzjZPbjyFhW3PPjXQGRA9j96JhPbhZaIrHAnhY/KKpgYPvJw0yP4Oo6HRPfXBgEBs= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=svmX0FBF; arc=fail smtp.client-ip=52.101.48.63 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="svmX0FBF" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=XZXtKceVSbD5KkeZXs66Pu8N7frIjet/UWjXn3mY3CA8qy7bPjNl6+r0FaCf8/jtZbglxX4XlA1qRrO0EY3Wtdu+JmX1EwcG3kLgaMh8F1AIojKKnFvZkU7FsWf+fF207PtUlUISDjDH0e+yev81oS1uI04K7RQUGQjtvhf0RSU8NIYMkmrzZhMROXRtkzPNW7znDsnkVFKGeqd8QhsSXC5Z6BS0O7HQWdeyBfspfzHvZTo86ECQL/FhcRrVurKeS1HYy4k8FDYO1KgyaPP4yiJklflRS6dfmP5bKHqFY6tF9zOLYspBWkYj7R/ZSdeRJ5iFFPuYcKvGuinLrQ6b7A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=bssftA5XRFlAN1N8d939rzfrgVyf+942s/j0hVlMLBE=; b=li/yfcR07PZmRjpPtrSxwyX2jEduGVhzw46mQclI50o00H4uGbhk7rB/NOXQ5kBfTkjJ7vVpjoOYydwIcF7ROtiOA7E/rZNBOEdd1+1bbRFqajn78af4vENARxYYxBkTvHSHb/5QE9WFEiBRcZSrKLWabc5463XTpqvMTlfRM5Pq8M8sTqIg0pMOFplqPwKJeuEDnJvrzi+A0STIrDSjEbhsD5by3lVu0ysJn/y+Cp3UOrYdX3C7Qar5BIgOoxe2RdIIiRFca3CezsW4pMY3LrapxIdnpfxaLuzFcfZEHbva0xUYw3h05k72Q9rP8g80UyvjBUeeQGm243VO0s5l1w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.160) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=bssftA5XRFlAN1N8d939rzfrgVyf+942s/j0hVlMLBE=; b=svmX0FBF78jLz2MX3BLq1NTCBYgVdjLkLg/ztepfn0yvLePeyII++yE7y4UXh0ioX0sw5KdyZ2HrWV0+SxbbH8t5laz/SqQd/ACMJLXoqlkHjV1RK8A01hgknmWXSxSTxF9KQWCRjUhs8lO/36emsaCWQ1A/fWDQiKo9ZcyZEZR5qo/ZfgChevzmapTl1DCqWQ7nTbNwTkHD6v351AxrdxdQ8Wqixri6d526RCAjdx1EhLTAYv70O/jSwuXPT3UN+V8kro17skuQ8BrVZxGKJWCfmMyHupYWIRdPZhesi2YC02H8ixurkbkG71UdkSEosDPdZQI/XfQuXKOplZXisw== Received: from CH2PR02CA0018.namprd02.prod.outlook.com (2603:10b6:610:4e::28) by CY8PR12MB8241.namprd12.prod.outlook.com (2603:10b6:930:76::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.9; Tue, 14 Jul 2026 18:49:46 +0000 Received: from BN3PEPF0000B36D.namprd21.prod.outlook.com (2603:10b6:610:4e:cafe::97) by CH2PR02CA0018.outlook.office365.com (2603:10b6:610:4e::28) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.10 via Frontend Transport; Tue, 14 Jul 2026 18:49:45 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.160) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.160 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.160; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.160) by BN3PEPF0000B36D.mail.protection.outlook.com (10.167.243.164) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.3 via Frontend Transport; Tue, 14 Jul 2026 18:49:45 +0000 Received: from rnnvmail205.nvidia.com (10.129.68.10) by mail.nvidia.com (10.129.200.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:20 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail205.nvidia.com (10.129.68.10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:19 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:18 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 4/6] iommufd/selftest: Convert cache invalidation mocks to the core array loop Date: Tue, 14 Jul 2026 11:48:50 -0700 Message-ID: <96168e6523d81dec0b69e1ae3b22ed5cc51afe97.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B36D:EE_|CY8PR12MB8241:EE_ X-MS-Office365-Filtering-Correlation-Id: 5df66313-9ca3-48ef-d138-08dee1d8aca2 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|376014|7416014|23010399003|1800799024|36860700016|82310400026|11063799006|5023799004|22082099003|18002099003|56012099006|6133799003; X-Microsoft-Antispam-Message-Info: /2oImZNk9icsU6fIXyFt/Vd9MSH2P/xXZY9iJcRTrK9G9/dnZZZ8ejLPzCWZFJ346v8mSIuOiGOZHAmBOTyZIpqU1XRme+1+eU9Cvi+ZIbddTmOX21sa61IcWzB3sSZPmXEj3pLEX0aYzL9Ahl1x3oTf1Yg8Vjb3yFBcSYGBCZCnd9W4qEyTu2KYrPWwXUHxLS2L2I18MkTfmt4N5IodROt3nbjg2OlirPGMPTyNiu0+bYYHVvo2ujT3MA4np+f3aGR1Pjh+eVo7x7+kMzM0zClLyR29id528KxtofYWkE2/JT15rrMA8qgLsFeGt3sLGzVC709LU8aM9IxxV+fqCn1uV1fj57Za14/86q/zTr8UIR2TNoLLXnrmv0/u8N1lkqBb57cJdJEUgMbPlQzzZlp3+RnFf8wRQul7j8SVtPJSyA1VMm8V3RWpDOvSDlQXCWpid3kDMMMjnqYwlgfpZ+/ZGECVM1Kj/Gk/OVQ00u4/SZp3220ZI2aqO2OK0ijIr7B/2rrGD8LSLPvzwTWbiXuB6L/ZtfjlEtLhEasfQQhKjkr532Kn7XqJbMTcmgGGi3TVQf0FphGOp2+yVZ5Aw2SgSavWZZZuz8fBglP4IbYhAjA8GP2+znmso0mGttMQlCAvj/CJz0BmeyXKudbgrXipd9FSdnRw8xa1vPpIvJQewQytyd8W/xYaw1wH5jNTjCrSj8ZDhegNES4rs3t6jQ== X-Forefront-Antispam-Report: CIP:216.228.117.160;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge1.nvidia.com;CAT:NONE;SFS:(13230040)(376014)(7416014)(23010399003)(1800799024)(36860700016)(82310400026)(11063799006)(5023799004)(22082099003)(18002099003)(56012099006)(6133799003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: mJegaz4fVbOz1cwD7yWDpVK+E5VxHL/zMwQ53luVB/0RtSmqZ1/+TSL+iomeQCFERb8oJCSinDxIlR6zUqSxBbjqDmZC4857ObqPM39D2blOLOdqqEIR0nONbNRggSvrUJ8igTfFV1rSMker/8PkHqXupXTNud9YIAN7aogunGGMolqluJWpXsDr21ha1fYY2P/gnLvPxX0yge0O0+L8Rfml07g29Hv/LTW/r/fYxdjfx0UMuW55cM1Frj/88mZpiEzfrSUZq9xRG8A4g8+/2YvbrxjRcC5acMRG/tiWnyh76hZjX4Pe0JTDU/vHIdKiP4CnYVgHYxQTwIc1sWlJkq8AAO84shVAG6bRi+OAjOO4jpYDy9no4o28SAQ8pvdYUHTXSXT1s9D4EEj++5of+XuodnV5flM5Q+brw9TW2D3ZYI6oA/DKwXKngfdXqbuJ X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:45.6893 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 5df66313-9ca3-48ef-d138-08dee1d8aca2 X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.160];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B36D.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY8PR12MB8241 Content-Type: text/plain; charset="utf-8" The vIOMMU and the nested-domain selftest invalidation mocks each used to walk the whole request array on their own, with the vIOMMU mock even allocating a buffer sized to the entire array in order to do so first. The iommufd core now iterates the request array itself and re-invokes the op with the not-yet-handled sub-array, so handle just a single request per call out of the front of that sub-array and report one handled entry via the array->entry_num. Drop both of the loops and the kzalloc_objs() in the viommu callback function, and keep returning a success for an empty array as a probe of the selftest data type. Reviewed-by: Kevin Tian Reviewed-by: Pranjal Shrivastava Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Nicolin Chen --- drivers/iommu/iommufd/selftest.c | 147 +++++++++++++++---------------- 1 file changed, 72 insertions(+), 75 deletions(-) diff --git a/drivers/iommu/iommufd/selftest.c b/drivers/iommu/iommufd/selft= est.c index af07c642a5260..75846cf1f9c44 100644 --- a/drivers/iommu/iommufd/selftest.c +++ b/drivers/iommu/iommufd/selftest.c @@ -631,70 +631,63 @@ mock_viommu_alloc_domain_nested(struct iommufd_viommu= *viommu, u32 flags, static int mock_viommu_cache_invalidate(struct iommufd_viommu *viommu, struct iommu_user_data_array *array) { - struct iommu_viommu_invalidate_selftest *cmds; - struct iommu_viommu_invalidate_selftest *cur; - struct iommu_viommu_invalidate_selftest *end; - int rc; + struct iommu_viommu_invalidate_selftest cmd; + struct mock_dev *mdev; + struct device *dev; + u32 processed =3D 0; + int rc =3D 0; + int i; =20 - /* A zero-length array is allowed to validate the array type */ - if (array->entry_num =3D=3D 0 && - array->type =3D=3D IOMMU_VIOMMU_INVALIDATE_DATA_SELFTEST) { - array->entry_num =3D 0; - return 0; + if (array->type !=3D IOMMU_VIOMMU_INVALIDATE_DATA_SELFTEST) { + rc =3D -EINVAL; + goto out; } =20 - cmds =3D kzalloc_objs(*cmds, array->entry_num); - if (!cmds) - return -ENOMEM; - cur =3D cmds; - end =3D cmds + array->entry_num; + /* + * The core re-invokes this op for the remaining requests, so handle one + * request per call. A zero-length array only probes the type, validated + * above. + */ + if (!array->entry_num) + return 0; =20 - static_assert(sizeof(*cmds) =3D=3D 3 * sizeof(u32)); - rc =3D iommu_copy_struct_from_full_user_array( - cmds, sizeof(*cmds), array, - IOMMU_VIOMMU_INVALIDATE_DATA_SELFTEST); + rc =3D iommu_copy_struct_from_user_array( + &cmd, array, IOMMU_VIOMMU_INVALIDATE_DATA_SELFTEST, 0, + cache_id); if (rc) goto out; =20 - while (cur !=3D end) { - struct mock_dev *mdev; - struct device *dev; - int i; - - if (cur->flags & ~IOMMU_TEST_INVALIDATE_FLAG_ALL) { - rc =3D -EOPNOTSUPP; - goto out; - } - - if (cur->cache_id > MOCK_DEV_CACHE_ID_MAX) { - rc =3D -EINVAL; - goto out; - } + if (cmd.flags & ~IOMMU_TEST_INVALIDATE_FLAG_ALL) { + rc =3D -EOPNOTSUPP; + goto out; + } =20 - xa_lock(&viommu->vdevs); - dev =3D iommufd_viommu_find_dev(viommu, - (unsigned long)cur->vdev_id); - if (!dev) { - xa_unlock(&viommu->vdevs); - rc =3D -EINVAL; - goto out; - } - mdev =3D container_of(dev, struct mock_dev, dev); + if (cmd.cache_id > MOCK_DEV_CACHE_ID_MAX) { + rc =3D -EINVAL; + goto out; + } =20 - if (cur->flags & IOMMU_TEST_INVALIDATE_FLAG_ALL) { - /* Invalidate all cache entries and ignore cache_id */ - for (i =3D 0; i < MOCK_DEV_CACHE_NUM; i++) - mdev->cache[i] =3D 0; - } else { - mdev->cache[cur->cache_id] =3D 0; - } + xa_lock(&viommu->vdevs); + dev =3D iommufd_viommu_find_dev(viommu, (unsigned long)cmd.vdev_id); + if (!dev) { xa_unlock(&viommu->vdevs); - - cur++; + rc =3D -EINVAL; + goto out; + } + mdev =3D container_of(dev, struct mock_dev, dev); + + if (cmd.flags & IOMMU_TEST_INVALIDATE_FLAG_ALL) { + /* Invalidate all cache entries and ignore cache_id */ + for (i =3D 0; i < MOCK_DEV_CACHE_NUM; i++) + mdev->cache[i] =3D 0; + } else { + mdev->cache[cmd.cache_id] =3D 0; } + xa_unlock(&viommu->vdevs); + + processed =3D 1; out: - array->entry_num =3D cur - cmds; - kfree(cmds); + array->entry_num =3D processed; return rc; } =20 @@ -875,42 +868,46 @@ mock_domain_cache_invalidate_user(struct iommu_domain= *domain, struct mock_iommu_domain_nested *mock_nested =3D to_mock_nested(domain); struct iommu_hwpt_invalidate_selftest inv; u32 processed =3D 0; - int i =3D 0, j; int rc =3D 0; + int i; =20 if (array->type !=3D IOMMU_HWPT_INVALIDATE_DATA_SELFTEST) { rc =3D -EINVAL; goto out; } =20 - for ( ; i < array->entry_num; i++) { - rc =3D iommu_copy_struct_from_user_array(&inv, array, - IOMMU_HWPT_INVALIDATE_DATA_SELFTEST, - i, iotlb_id); - if (rc) - break; + /* + * The core re-invokes this op for the remaining requests, so handle one + * request per call. A zero-length array only probes the type, validated + * above. + */ + if (!array->entry_num) + return 0; =20 - if (inv.flags & ~IOMMU_TEST_INVALIDATE_FLAG_ALL) { - rc =3D -EOPNOTSUPP; - break; - } + rc =3D iommu_copy_struct_from_user_array( + &inv, array, IOMMU_HWPT_INVALIDATE_DATA_SELFTEST, 0, iotlb_id); + if (rc) + goto out; =20 - if (inv.iotlb_id > MOCK_NESTED_DOMAIN_IOTLB_ID_MAX) { - rc =3D -EINVAL; - break; - } + if (inv.flags & ~IOMMU_TEST_INVALIDATE_FLAG_ALL) { + rc =3D -EOPNOTSUPP; + goto out; + } =20 - if (inv.flags & IOMMU_TEST_INVALIDATE_FLAG_ALL) { - /* Invalidate all mock iotlb entries and ignore iotlb_id */ - for (j =3D 0; j < MOCK_NESTED_DOMAIN_IOTLB_NUM; j++) - mock_nested->iotlb[j] =3D 0; - } else { - mock_nested->iotlb[inv.iotlb_id] =3D 0; - } + if (inv.iotlb_id > MOCK_NESTED_DOMAIN_IOTLB_ID_MAX) { + rc =3D -EINVAL; + goto out; + } =20 - processed++; + if (inv.flags & IOMMU_TEST_INVALIDATE_FLAG_ALL) { + /* Invalidate all mock iotlb entries and ignore iotlb_id */ + for (i =3D 0; i < MOCK_NESTED_DOMAIN_IOTLB_NUM; i++) + mock_nested->iotlb[i] =3D 0; + } else { + mock_nested->iotlb[inv.iotlb_id] =3D 0; } =20 + processed =3D 1; out: array->entry_num =3D processed; return rc; --=20 2.43.0 From nobody Sat Jul 25 18:53:13 2026 Received: from DM1PR04CU001.outbound.protection.outlook.com (mail-centralusazon11010012.outbound.protection.outlook.com [52.101.61.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 53D6A3CF660 for ; Tue, 14 Jul 2026 18:49:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=52.101.61.12 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784055004; cv=fail; b=IjBdYhauVS8Hl7LPRH8edMp4U5xxFIXDpsQsaVA86HD4ycauY3TTNjZffA0NSqW4ztT504m5YOX3ykqHmURTG63uHlt6ePLNX/GdodYAdlw9SJQYqCEYcRDaKyi7v1pZ5wyJVFEjphkCmXg3C7jryjthHHqN23f+B+ZiUsn3eT0= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784055004; c=relaxed/simple; bh=cBjNTS5koAe6CN8cv2RkXif1EYixwbXYUCAeomXoUM0=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=WS03XTqfaDnUDgvNlZU7k0ZLtgXqbIca5oLX+qreWBnBJYzNeW35V2npbDLrAQjxIH2Q6M9Jn6+yMvI9c5gfMlVDQvnjrzx+J45EPfNarySvtSPa2FmUy6WlzxDpd9TkmOvBGZxRTZTf/4G7JSHn3uqXfh9bFijXXL0OLYdGzbw= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=nXIyteNU; arc=fail smtp.client-ip=52.101.61.12 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="nXIyteNU" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mwyV3AwuzBp6ocJZIujh4IgeLLrGungDUCsHWNWzMCdIE9lHSvXmcxXaKx9pjmHtMvw/HHZ4qf5sk2/2eW0dxIwGAJD7Ot9CZ96lCCeSypVKhwjEyXqQsCkYKbBjUkcZ0wcEMSqHLIwuiKYuhfigRaMclivaLH23vXGkvDQs1EI2+emu3trsstIVZgfDYIDrZEr11tHL1+gn2A7oBGYIjbBxjOmluuKc2FUCrPw76I5lijyZFg0ES2ZxpuWdgsgnfkcaiQ6X/YGAA/tZZjcNdlrBooNno1HrO0ej4dqh5QncUuVk5HRDL/J2xxtv1ROCPstajrT1/UXs/ll7flQE7Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=+txxj+KWXXmT6H2jQ01XkaPRn0lJYJLwceJWiWnCf5s=; b=zCpImNU3ahEP3v8/APvdbmZW4u3WnlPmlVRKOEZP6qtVo3gyLyibvYeHxvCXa4wqS4idsqL77VT93VjFK3D7+NqdBgKip0K7en1UkoF2IWGF0tPfMgOBMkjgVxmLsmF09/KJBy39VVtWjHXZyQrUzhSRV3sVpBHbbodEgFlfVUpIr1Mag4aqzfGs9zaZraVKMpobqwY7pHuO5lshhEMQhrDGldkFlpVvjfjRRU4IG6VGABIIb8dSX7ISR0WrXqlNsKsVK7jYhSaBk7z/36YshKLkABNh0B8qYjqLmTm4Qmy2ug/72Rr63bwKjiF1e/ERHgj9a1iu2c1eZy01v25x7w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.160) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+txxj+KWXXmT6H2jQ01XkaPRn0lJYJLwceJWiWnCf5s=; b=nXIyteNUUham8BDLlSvX+oOqzb0A80q6k+D33mpEVVkWNNMId08duABxP/ZtEZXTjJTEKgM8OeSLC4Qm11Vwu2F5YtedjkKerBWDjAjcALvER7fpJgoYBK9E3460rTVxDJ2CXUXMGTt3kM52xSA7Kb7FkMTkynV4qamMv8dFuHqKXd0O4auaYdC6UfOqn74OHrOc63/GHIEjWEr3Smp4KLLiXMedGx6N8Vj58Wx2ruDY9cfZHphCdllMlhIYibn0CLRZSeQpZv8ZG+5ikMG0nxgGtKXWlx/UYVz2xtCG6aiP0Acf4em4T6tgLbWeXL4JnkrJMWfsJxbM3nFVd48AgA== Received: from CH0PR07CA0017.namprd07.prod.outlook.com (2603:10b6:610:32::22) by SJ2PR12MB8807.namprd12.prod.outlook.com (2603:10b6:a03:4d0::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.9; Tue, 14 Jul 2026 18:49:48 +0000 Received: from BN3PEPF0000B372.namprd21.prod.outlook.com (2603:10b6:610:32:cafe::a0) by CH0PR07CA0017.outlook.office365.com (2603:10b6:610:32::22) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.10 via Frontend Transport; Tue, 14 Jul 2026 18:49:48 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.160) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.160 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.160; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.160) by BN3PEPF0000B372.mail.protection.outlook.com (10.167.243.169) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.245.3 via Frontend Transport; Tue, 14 Jul 2026 18:49:48 +0000 Received: from rnnvmail204.nvidia.com (10.129.68.6) by mail.nvidia.com (10.129.200.66) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:21 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail204.nvidia.com (10.129.68.6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:20 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:20 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 5/6] iommu/arm-smmu-v3-iommufd: Convert cache invalidation to the core array loop Date: Tue, 14 Jul 2026 11:48:51 -0700 Message-ID: <4c85d0d43e9871b8dc8ea8e393210bd62654c0b5.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: BN3PEPF0000B372:EE_|SJ2PR12MB8807:EE_ X-MS-Office365-Filtering-Correlation-Id: bf0ce9c5-ab9c-4b8a-76d8-08dee1d8ae32 X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|7416014|376014|23010399003|36860700016|1800799024|82310400026|3023799007|18002099003|22082099003|5023799004|56012099006|11063799006|6133799003; X-Microsoft-Antispam-Message-Info: 4ASyleA9Et1lt7YVKw7230cn4Gw6DoPm6mS3ANE5T6B5hnbg8QGSeBL9ZPZO0Fd7jgQI59ItO3nth3OLgu6ZImd06eONrsLKKNObGmualjaOEB9wvmFsP2zkeZUVFDdqzDpoo50VriEHmgN8Q3So90tU3c26vyhICq4lBvh35+IgKaBQA9qPLI6un39BjWl6ksXzV0PJR9MJo8nM14GNWkMN84XdWRJiRWVcnOOyXZmfKMyUB5CMsytvLCr56ZxbWWjIRGHLva4sZSJW7oMucHAndWDZ5OuGoUP79tf4/6b+KLO9J+VH/QPnmItKMH7Xxy3SY0NQpK0T/y51XEGWnes7phByb6JUDCi1IoGUbYo2ILWOYvgRxHppfAFbLqzoGFqX+/3zZqU1UhTgb+uk2oG6O75maYRZaA6JwGk8W/Tvkho7/wD/tXAlXCL7YZte1E89gOyeQgdsUgkSv/B97WpDdvV9RZqfkflIsmAPMkKuU8BQ/uN6EJPaDPj/8AsJc+ubD9blOlyDA/WrarPQ+jYr1AzP0kfYOdnOhNWTlZK9NpQdGcO3erfQbjqC0zfSlXbWTjroIJN+6JW9N9JmMVCXjRKvT959vB+65ffNBHZzMcxUTom88EnpIH9/zgO4I2LKk3yB5mVpFsnVfmJUgL1V5eoUMrFE7ozUqWFu97SOUXVJVzLP+tdP0/kdEvgufEj17Hwmki9PQQW+fIEUCw== X-Forefront-Antispam-Report: CIP:216.228.117.160;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge1.nvidia.com;CAT:NONE;SFS:(13230040)(7416014)(376014)(23010399003)(36860700016)(1800799024)(82310400026)(3023799007)(18002099003)(22082099003)(5023799004)(56012099006)(11063799006)(6133799003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: /vXIoGjS/Ebhy286vfcPOCaoxLh4raAQHeGQwtXMeL8AghO7zHaJalGIPCGdvCah+8quNPm1rIbQtJzMVCPwdQrLrZy7xQ507W0soZKqmwVvd0UKsFYQCxe5BZ3U9u8ujPMKY89rIQV6Vb05EU9De3N/T0JyBukts/cZI1f7KqIJiOZB5e5WBvCWoh9OfZ+vzDPYd39LYXxyjw0KgT5Y3f4k6JWCRuvONToW/I3LMPHSsNONTcfCnVGjkS4tfOBrfxD8/Bqm4H07LFDUeB/dwYEIm/R9wkReYUCvtIaVktUBWzwQtOsbxejUYt+jAGsO7dZBi2L+2+1tTYUSMHdmrxtWKaqhAqImAFG+EZW7FopmpjcG0dqfiJTVSgwb1I6h3WJIetV+AZGze1WrwAaxWDuVrim2fLETigDwDsPG1TsrVpc2lHoLZZYPeYZTd4co X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:48.3110 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: bf0ce9c5-ab9c-4b8a-76d8-08dee1d8ae32 X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.160];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: BN3PEPF0000B372.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2PR12MB8807 Content-Type: text/plain; charset="utf-8" arm_vsmmu_cache_invalidate() allocated a buffer for the entire user request array, walked the array converting each of the commands, and issued those converted commands to the cmdq in CMDQ_BATCH_ENTRIES sized chunks, carrying the sub-array bookkeeping all on its own. The iommufd core now iterates the invalidation array and re-invokes the op with the not-yet-handled sub-array, so the driver only has to proceed with a single chunk per call. Instead of a per-array allocation, use a fixed on-stack batch to copy from the userspace array. If the copy fails due to nonzero padding (VMM violates the ABI), fail the entire batch. Convert the whole batch before issuing any of it: a malformed command is a userspace bug, so the first illegal command fails the batch as a unit, issuing nothing and leaving array->entry_num at zero, the same way the copy above bails on nonzero padding. A batch that converts cleanly is issued in full, so the op returns either a handled count with no error or zero with an error. A zero-length array now returns success once the data type gets validated, matching the documented probe behavior, rather than the -EINVAL that the full-array copy helper would previously return. This also fixes two long-standing bugs: 1) On a conversion failure the old code reported commands that it had converted but not yet issued, so user space advanced its consumer index past invalidations that never reached the cmdq. 2) A zero-length array was rejected with -EINVAL, although the uAPI documents it as a valid request that only probes the data type. Reviewed-by: Kevin Tian Reviewed-by: Pranjal Shrivastava Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Nicolin Chen Reviewed-by: Jason Gunthorpe --- .../arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 68 +++++++++++-------- 1 file changed, 38 insertions(+), 30 deletions(-) diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c b/drivers/= iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c index 07e502879dffc..42a3f30b9f3be 100644 --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-iommufd.c @@ -457,49 +457,57 @@ int arm_vsmmu_cache_invalidate(struct iommufd_viommu = *viommu, struct iommu_user_data_array *array) { struct arm_vsmmu *vsmmu =3D container_of(viommu, struct arm_vsmmu, core); + struct arm_vsmmu_invalidation_cmd cmds[CMDQ_BATCH_ENTRIES - 1]; struct arm_smmu_device *smmu =3D vsmmu->smmu; - struct arm_vsmmu_invalidation_cmd *last; - struct arm_vsmmu_invalidation_cmd *cmds; - struct arm_vsmmu_invalidation_cmd *cur; - struct arm_vsmmu_invalidation_cmd *end; + struct iommu_user_data_array batch =3D { + .type =3D array->type, + .uptr =3D array->uptr, + .entry_len =3D array->entry_len, + }; + u32 processed =3D 0; int ret; - - cmds =3D kzalloc_objs(*cmds, array->entry_num); - if (!cmds) - return -ENOMEM; - cur =3D cmds; - end =3D cmds + array->entry_num; + u32 i; =20 static_assert(sizeof(*cmds) =3D=3D 2 * sizeof(u64)); + + if (array->type !=3D IOMMU_VIOMMU_INVALIDATE_DATA_ARM_SMMUV3) { + ret =3D -EINVAL; + goto out; + } + + /* A zero-length array only probes the type, validated above */ + if (!array->entry_num) + return 0; + + /* + * The core re-invokes this op for the remaining requests, so copy one + * cmdq batch worth of commands into a fixed on-stack buffer rather than + * allocating for the whole array. + */ + batch.entry_num =3D min_t(u32, array->entry_num, ARRAY_SIZE(cmds)); ret =3D iommu_copy_struct_from_full_user_array( - cmds, sizeof(*cmds), array, + cmds, sizeof(*cmds), &batch, IOMMU_VIOMMU_INVALIDATE_DATA_ARM_SMMUV3); if (ret) goto out; =20 - last =3D cmds; - while (cur !=3D end) { - ret =3D arm_vsmmu_convert_user_cmd(vsmmu, cur); + /* + * Convert the whole batch. Sending an illegal command is a VMM bug, so + * a single one fails the entire batch, issuing nothing. + */ + for (i =3D 0; i < batch.entry_num; i++) { + ret =3D arm_vsmmu_convert_user_cmd(vsmmu, &cmds[i]); if (ret) goto out; - - /* FIXME work in blocks of CMDQ_BATCH_ENTRIES and copy each block? */ - cur++; - if (cur !=3D end && (cur - last) !=3D CMDQ_BATCH_ENTRIES - 1) - continue; - - /* FIXME always uses the main cmdq rather than trying to group by type */ - ret =3D arm_smmu_cmdq_issue_cmdlist(smmu, &smmu->cmdq, &last->cmd, - cur - last, true); - if (ret) { - cur--; - goto out; - } - last =3D cur; } + + /* FIXME always uses the main cmdq rather than trying to group by type */ + ret =3D arm_smmu_cmdq_issue_cmdlist(smmu, &smmu->cmdq, &cmds->cmd, + batch.entry_num, true); + if (!ret) + processed =3D batch.entry_num; out: - array->entry_num =3D cur - cmds; - kfree(cmds); + array->entry_num =3D processed; return ret; } =20 --=20 2.43.0 From nobody Sat Jul 25 18:53:13 2026 Received: from CY3PR05CU001.outbound.protection.outlook.com (mail-westcentralusazon11013059.outbound.protection.outlook.com [40.93.201.59]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 86277377A8F for ; Tue, 14 Jul 2026 18:49:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=fail smtp.client-ip=40.93.201.59 ARC-Seal: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054990; cv=fail; b=E+u0kXyrsMn2aiitNEXhDWMSmqyPvrFrDQOzils2zQ4vE5KEJWuJe0NT1sqpNQnoakpH4htikwqbP/buNj2helTpb8fEtrfd3lUu+8cFufabFzmZezqLzSynKtAt36aU4yo3He+7P9sfP0gYGn2kFSRhHIoEGTkUs4+i6tmsIYU= ARC-Message-Signature: i=2; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784054990; c=relaxed/simple; bh=3z5FiJYOBlG3bp3h1+HfREzWU2GuY8wqYCOePyFLfpc=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=POW5XzbDXURr1jPuP9LzCkevTAaBQC/xrqfC+A+LQFCjQHRWvr5n+tOjWmGNt7D446ewa40E/r0BN8rRrb8sL/ubnfaKZObwOQxEJFl1TGu0CTGrwssDoP2tw6noFEE8UxMXSAyt4+jyjsE3sYCnQQulmF4Ny8EVDVIlY27HFgY= ARC-Authentication-Results: i=2; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com; spf=fail smtp.mailfrom=nvidia.com; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b=QFIBvWqF; arc=fail smtp.client-ip=40.93.201.59 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=nvidia.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=nvidia.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=Nvidia.com header.i=@Nvidia.com header.b="QFIBvWqF" ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=FGrJVm1SN1j6K1E87p411J1aqtLNvPdbYGfJpnzzCDPxIkQK9WT02jdsYXMt72Fhz+imo/pfjC0BgwneW61+eij9yIeKRI4TOWz4/cT3OWMCuG9TsAKO36tTksrel2ZnxM6Npwv0hLkhdo3SSYSSTZqZd0nP0+UGkIjh7woh+so76KBWeEHjHom/ZBgfAteWG4T1Mla73Fnm2F8Xnb2/qN2yrZTfPkt4zPogGax39iq54HHenwM8wGkDwVilaP6dgpa//YyopTbrdXEQ6Hd+weydnsWrpW+ut/OMw+i8OtG8CS8akMzfUw0f+Z9zZGLfd2IIrzF7WTFXsEayIHtb8w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=2kHouXK6Nt6M9Rsk/xWF8aeIpWHaFYDAPur/bFB/sdI=; b=jHpfe2ek3FLC6bToTnb9VoZ7WHAbEECF4v4zcdag0sSK5Rap9P81OYbah/xOcCvce3bOmrNASzHX0WYydf/fVk9kCDfabGajPczdXMbHAWvzMtXepuK9oMxS5aGU6MFaZoWmdgFLcg1m3GRDTN1r74decA2nD5RAfRx/rnwSvVC1SPOvWgaq3mJqNo+EYdP7RfFe2NKEWq+pvW0Ct8dTuGT3XFWsRwY/bbvIMmUGEVup40auujbx60p9yeTxtIBedQ3hqt+Az7JO6EAt/HCC9f6bihktTUFv9/BIHvqGvbh8s850Rpe1kcHs2sE9ZtUTds3sisMQE7uBYiq9sMu/mQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 216.228.117.161) smtp.rcpttodomain=kernel.org smtp.mailfrom=nvidia.com; dmarc=pass (p=reject sp=reject pct=100) action=none header.from=nvidia.com; dkim=none (message not signed); arc=none (0) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2kHouXK6Nt6M9Rsk/xWF8aeIpWHaFYDAPur/bFB/sdI=; b=QFIBvWqFg9f/X7XFRb/hVkM8fSyISRMdg/FNK5EAbHopgoqSy3/NTqlBX64iqJCAwjcR3I5XRqt2lXiI85hcPdpdhWkoQUiDBA+CsYa99fnO+/ctQsuRGzj6VxvtIRhQ5DKnbdwXY4NKjR7ChlePt19nOJPvTPY0HdmpBiSN3sRx7Awt7Xw1U9ml/nC6PHkcZGzvrqfbjqs65J8mvYfbfj7Gq3grXXiBJKOIerczwef7SD9hMX4Qqrj9UJsTmk7DCvntVyCAZq8M/vcu88t58IqN+4N0A6KSMUG8WwrChJh7YGRSfRoGJGicznI2l42/YMps7sq2bZfP2slPio80/A== Received: from SJ0PR13CA0093.namprd13.prod.outlook.com (2603:10b6:a03:2c5::8) by SA3PR12MB7998.namprd12.prod.outlook.com (2603:10b6:806:320::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.9; Tue, 14 Jul 2026 18:49:41 +0000 Received: from CO1PEPF000075F0.namprd03.prod.outlook.com (2603:10b6:a03:2c5:cafe::5c) by SJ0PR13CA0093.outlook.office365.com (2603:10b6:a03:2c5::8) with Microsoft SMTP Server (version=TLS1_3, cipher=TLS_AES_256_GCM_SHA384) id 15.21.223.10 via Frontend Transport; Tue, 14 Jul 2026 18:49:40 +0000 X-MS-Exchange-Authentication-Results: spf=pass (sender IP is 216.228.117.161) smtp.mailfrom=nvidia.com; dkim=none (message not signed) header.d=none;dmarc=pass action=none header.from=nvidia.com; Received-SPF: Pass (protection.outlook.com: domain of nvidia.com designates 216.228.117.161 as permitted sender) receiver=protection.outlook.com; client-ip=216.228.117.161; helo=mail.nvidia.com; pr=C Received: from mail.nvidia.com (216.228.117.161) by CO1PEPF000075F0.mail.protection.outlook.com (10.167.249.39) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.223.9 via Frontend Transport; Tue, 14 Jul 2026 18:49:40 +0000 Received: from rnnvmail204.nvidia.com (10.129.68.6) by mail.nvidia.com (10.129.200.67) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:22 -0700 Received: from rnnvmail204.nvidia.com (10.129.68.6) by rnnvmail204.nvidia.com (10.129.68.6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.2562.20; Tue, 14 Jul 2026 11:49:22 -0700 Received: from Asurada-Nvidia.nvidia.com (10.127.8.11) by mail.nvidia.com (10.129.68.6) with Microsoft SMTP Server id 15.2.2562.20 via Frontend Transport; Tue, 14 Jul 2026 11:49:21 -0700 From: Nicolin Chen To: Will Deacon , Jason Gunthorpe , "Kevin Tian" CC: Robin Murphy , , David Woodhouse , Lu Baolu , , , , Pranjal Shrivastava Subject: [PATCH v4 6/6] iommu/vt-d: Convert nested cache invalidation to the core array loop Date: Tue, 14 Jul 2026 11:48:52 -0700 Message-ID: <6fc43e814362d65d4c2b7d22c6fcc50ff56378c4.1784054606.git.nicolinc@nvidia.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-NV-OnPremToCloud: ExternallySecured X-EOPAttributedMessage: 0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CO1PEPF000075F0:EE_|SA3PR12MB7998:EE_ X-MS-Office365-Filtering-Correlation-Id: 3b55edda-b6cd-4fed-29cc-08dee1d8a9ab X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|36860700016|82310400026|1800799024|7416014|376014|23010399003|6133799003|18002099003|56012099006|11063799006|5023799004|22082099003; X-Microsoft-Antispam-Message-Info: +0bfizfZ++x6OfvOzDmSUcyzWH41LnRfhALkb2obHrf0OcYzSaRZR4OMLru88sNdq43pb72pVJUKrmk9rOmK+698j3z6MuUQK7nk2ODP3KM5lBr5GCRgxIRusd/2AHOtdaZ5ptuLZ5wctzrK7fro9XgnlNaGcTFcHKxew08PPdr5aDiEkKcuaYHL9SN3lxZhaRN/YOL5YxJGfWhWbqzirsZcdLTgxtM8nfy2dN6GtMwt7gCqmxkgVNGerxyF7nsLOsRI7o/wUPkn/Xtl6KGaMOmS0Pbm2OHJNr8XE6T4Upe8JXbeKyyZ2NXL/umeADlTonHakXXTcuBw7lKNv9OCjzelyjdy5qrBEjgkNwF0mPbL70fdJJiTJ5LeSv6vWdM7szEcdEAhrTvmwPeONLWak5422KwsaGCTFMgdCN+aHZxA4StC/Ukllek5W9pWj0dy9hyYJsJDm98O8G05HMEeVe3JSJ2r6oY3DGzwbNZQUUkVuuVM/6pYQCslfTOIl6zHdojp1tLeD5Y3bZtiD3aZu8WmKncEGYvtrYhzLTSt1Y+V6SJ3EDiu3+0rJIzAfqZ4tPHZoU5dV26keN0fNgSWqBgLQcYtejfZ9TgZMhGDok169im7XYK5WR2Xo297kbHi1qyo0SRqEN9cS+DMzHGvW4XmnsI9gPH5vIWvxIyR4YNU1sN83xe7LBo8ED7Bpp2s8N+Uw/BDa4CwxmydNnFSOA== X-Forefront-Antispam-Report: CIP:216.228.117.161;CTRY:US;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:mail.nvidia.com;PTR:dc6edge2.nvidia.com;CAT:NONE;SFS:(13230040)(36860700016)(82310400026)(1800799024)(7416014)(376014)(23010399003)(6133799003)(18002099003)(56012099006)(11063799006)(5023799004)(22082099003);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: sfSSziw5H7xH340qd7hDFfu7vutgHsl6B5xqygCpp/8QlL+jbY5lEI9CU3NV1Eba5ershPrHAabysJyVO/YAk7LVMCl694+7DcVTh2I+SZGfvrlESl+Dme+6YrGDTb/BEkSrEgZW2Ni75JMZAftCHW/612BQGG77ii4LA46Ac2LKnogwpXJ0nogykj6RzzAn47QKu/fqCodvLmwvW/P8yGnEY10/Z7J5pgwNkbB3LT2e+0AG1dM1OLYJL3eXkKtC4yNLxqjaeJjy7/Any1LjpgGGxRByMSE4XeuvabRBoPLhal5S9JRRtU6qBF3WCIENwkOXPQ+vhTcinHOeuEIZ8+zkOUY7rJw/NWt+AdtkbufhC0wyhFdsAe3UTOcZP1ExyhjCihhVtQLe2hDMatXc9BYRPzjxZgaY4L4rbRXyOCceFpqlxiDM5ttT89JO3W41 X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-OriginalArrivalTime: 14 Jul 2026 18:49:40.7999 (UTC) X-MS-Exchange-CrossTenant-Network-Message-Id: 3b55edda-b6cd-4fed-29cc-08dee1d8a9ab X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=43083d15-7273-40c1-b7db-39efd9ccc17a;Ip=[216.228.117.161];Helo=[mail.nvidia.com] X-MS-Exchange-CrossTenant-AuthSource: CO1PEPF000075F0.namprd03.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Anonymous X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA3PR12MB7998 Content-Type: text/plain; charset="utf-8" intel_nested_cache_invalidate_user() used to walk the whole request array on its own, copying and then flushing one single entry at a time. The iommufd core now iterates the request array itself and re-invokes the op with the not-yet-handled sub-array, so handle just a single request per call out of the front of that sub-array and report one handled entry via the array->entry_num. An empty array keeps returning a success, used as a probe of IOMMU_HWPT_INVALIDATE_DATA_VTD_S1 support. Reviewed-by: Kevin Tian Reviewed-by: Lu Baolu Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Nicolin Chen --- drivers/iommu/intel/nested.c | 54 ++++++++++++++++++++---------------- 1 file changed, 30 insertions(+), 24 deletions(-) diff --git a/drivers/iommu/intel/nested.c b/drivers/iommu/intel/nested.c index 2b979bec56cef..36e0e8e85c065 100644 --- a/drivers/iommu/intel/nested.c +++ b/drivers/iommu/intel/nested.c @@ -93,7 +93,7 @@ static int intel_nested_cache_invalidate_user(struct iomm= u_domain *domain, { struct dmar_domain *dmar_domain =3D to_dmar_domain(domain); struct iommu_hwpt_vtd_s1_invalidate inv_entry; - u32 index, processed =3D 0; + u32 processed =3D 0; int ret =3D 0; =20 if (array->type !=3D IOMMU_HWPT_INVALIDATE_DATA_VTD_S1) { @@ -101,31 +101,37 @@ static int intel_nested_cache_invalidate_user(struct = iommu_domain *domain, goto out; } =20 - for (index =3D 0; index < array->entry_num; index++) { - ret =3D iommu_copy_struct_from_user_array(&inv_entry, array, - IOMMU_HWPT_INVALIDATE_DATA_VTD_S1, - index, __reserved); - if (ret) - break; - - if ((inv_entry.flags & ~IOMMU_VTD_INV_FLAGS_LEAF) || - inv_entry.__reserved) { - ret =3D -EOPNOTSUPP; - break; - } - - if (!IS_ALIGNED(inv_entry.addr, VTD_PAGE_SIZE) || - ((inv_entry.npages =3D=3D U64_MAX) && inv_entry.addr)) { - ret =3D -EINVAL; - break; - } - - cache_tag_flush_range(dmar_domain, inv_entry.addr, - inv_entry.addr + nrpages_to_size(inv_entry.npages) - 1, - inv_entry.flags & IOMMU_VTD_INV_FLAGS_LEAF); - processed++; + /* + * The core re-invokes this op for the remaining requests, so handle one + * request per call. A zero-length array only probes the type, validated + * above. + */ + if (!array->entry_num) + return 0; + + ret =3D iommu_copy_struct_from_user_array( + &inv_entry, array, IOMMU_HWPT_INVALIDATE_DATA_VTD_S1, 0, + __reserved); + if (ret) + goto out; + + if ((inv_entry.flags & ~IOMMU_VTD_INV_FLAGS_LEAF) || + inv_entry.__reserved) { + ret =3D -EOPNOTSUPP; + goto out; + } + + if (!IS_ALIGNED(inv_entry.addr, VTD_PAGE_SIZE) || + (inv_entry.npages =3D=3D U64_MAX && inv_entry.addr)) { + ret =3D -EINVAL; + goto out; } =20 + cache_tag_flush_range(dmar_domain, inv_entry.addr, + inv_entry.addr + + nrpages_to_size(inv_entry.npages) - 1, + inv_entry.flags & IOMMU_VTD_INV_FLAGS_LEAF); + processed =3D 1; out: array->entry_num =3D processed; return ret; --=20 2.43.0