[RFC PATCH v1 14/18] iommu/amd: AMD IOMMU support for memory encryption

From: Tom Lendacky
Date: Tue Apr 26 2016 - 18:58:46 EST


Add support to the AMD IOMMU driver to set the memory encryption mask if
memory encryption is enabled.

Signed-off-by: Tom Lendacky <thomas.lendacky@xxxxxxx>
---
arch/x86/include/asm/mem_encrypt.h | 2 ++
arch/x86/mm/mem_encrypt.c | 5 +++++
drivers/iommu/amd_iommu.c | 10 ++++++++++
3 files changed, 17 insertions(+)

diff --git a/arch/x86/include/asm/mem_encrypt.h b/arch/x86/include/asm/mem_encrypt.h
index d17d8cf..55163e4 100644
--- a/arch/x86/include/asm/mem_encrypt.h
+++ b/arch/x86/include/asm/mem_encrypt.h
@@ -39,6 +39,8 @@ void __init sme_early_init(void);
/* Architecture __weak replacement functions */
void __init mem_encrypt_init(void);

+unsigned long amd_iommu_get_me_mask(void);
+
unsigned long swiotlb_get_me_mask(void);
void swiotlb_set_mem_dec(void *vaddr, unsigned long size);

diff --git a/arch/x86/mm/mem_encrypt.c b/arch/x86/mm/mem_encrypt.c
index 594dc65..6efceb8 100644
--- a/arch/x86/mm/mem_encrypt.c
+++ b/arch/x86/mm/mem_encrypt.c
@@ -179,6 +179,11 @@ void __init mem_encrypt_init(void)
swiotlb_clear_encryption();
}

+unsigned long amd_iommu_get_me_mask(void)
+{
+ return sme_me_mask;
+}
+
unsigned long swiotlb_get_me_mask(void)
{
return sme_me_mask;
diff --git a/drivers/iommu/amd_iommu.c b/drivers/iommu/amd_iommu.c
index 5efadad..5dc8f52 100644
--- a/drivers/iommu/amd_iommu.c
+++ b/drivers/iommu/amd_iommu.c
@@ -156,6 +156,15 @@ struct dma_ops_domain {
struct aperture_range *aperture[APERTURE_MAX_RANGES];
};

+/*
+ * Support for memory encryption. If memory encryption is supported, then an
+ * override to this function will be provided.
+ */
+unsigned long __weak amd_iommu_get_me_mask(void)
+{
+ return 0;
+}
+
/****************************************************************************
*
* Helper functions
@@ -2612,6 +2621,7 @@ static dma_addr_t __map_single(struct device *dev,
if (address == DMA_ERROR_CODE)
goto out;

+ paddr |= amd_iommu_get_me_mask();
start = address;
for (i = 0; i < pages; ++i) {
ret = dma_ops_domain_map(dma_dom, start, paddr, dir);