[PATCH v8 09/25] KVM: arm64: iommu: Support DABT for IOMMU

From: Mostafa Saleh

Date: Tue Sep 22 2026 - 11:14:27 EST


The pKVM SMMUv3 driver needs to trap and emulate access to the MMIO
space of the SMMUv3 to provide emulation for the kernel driver.

Add a handler for DABTs for IOMMU drivers to be able to do so.
In case the host causes a data abort, check if it's part of IOMMU
emulation first.

Signed-off-by: Mostafa Saleh <smostafa@xxxxxxxxxx>
---
arch/arm64/kvm/hyp/include/nvhe/iommu.h | 2 ++
arch/arm64/kvm/hyp/nvhe/iommu.c | 14 ++++++++++++++
arch/arm64/kvm/hyp/nvhe/mem_protect.c | 15 +++++++++++++++
3 files changed, 31 insertions(+)

diff --git a/arch/arm64/kvm/hyp/include/nvhe/iommu.h b/arch/arm64/kvm/hyp/include/nvhe/iommu.h
index 1fa728ab47d4..3f16879b5fa7 100644
--- a/arch/arm64/kvm/hyp/include/nvhe/iommu.h
+++ b/arch/arm64/kvm/hyp/include/nvhe/iommu.h
@@ -7,6 +7,7 @@
struct pkvm_iommu_ops {
int (*init)(void);
int (*host_stage2_idmap)(phys_addr_t start, phys_addr_t end, int prot);
+ bool (*dabt_handler)(struct user_pt_regs *regs, u64 esr, u64 addr);
};

int pkvm_iommu_init(void *pool_base, unsigned int nr_pages);
@@ -18,5 +19,6 @@ int pkvm_iommu_host_stage2_idmap(phys_addr_t start, phys_addr_t end,
void *pkvm_iommu_alloc_pages(u8 order);
/* Free pages from pkvm_iommu_alloc_pages(). */
void pkvm_iommu_free_pages(void *ptr);
+bool pkvm_iommu_host_dabt_handler(struct user_pt_regs *regs, u64 esr, u64 addr);

#endif /* __ARM64_KVM_NVHE_IOMMU_H__ */
diff --git a/arch/arm64/kvm/hyp/nvhe/iommu.c b/arch/arm64/kvm/hyp/nvhe/iommu.c
index cacab0dc462a..b7b11f6616cd 100644
--- a/arch/arm64/kvm/hyp/nvhe/iommu.c
+++ b/arch/arm64/kvm/hyp/nvhe/iommu.c
@@ -5,8 +5,11 @@
* Copyright (C) 2022 Linaro Ltd.
*/
#include <linux/iommu.h>
+#include <asm/kvm_hyp.h>
#include <asm/kvm_pkvm.h>

+#include <hyp/adjust_pc.h>
+
#include <nvhe/iommu.h>
#include <nvhe/mem_protect.h>
#include <nvhe/spinlock.h>
@@ -158,3 +161,14 @@ void pkvm_iommu_free_pages(void *ptr)
{
hyp_put_page(&iommu_pages_pool, ptr);
}
+
+bool pkvm_iommu_host_dabt_handler(struct user_pt_regs *regs, u64 esr, u64 addr)
+{
+ if (pkvm_iommu_ops && pkvm_iommu_ops->dabt_handler &&
+ pkvm_iommu_ops->dabt_handler(regs, esr, addr)) {
+ /* DABT handled by the driver, skip to next instruction. */
+ kvm_skip_host_instr();
+ return true;
+ }
+ return false;
+}
diff --git a/arch/arm64/kvm/hyp/nvhe/mem_protect.c b/arch/arm64/kvm/hyp/nvhe/mem_protect.c
index da5014e4e96b..863c571e47e4 100644
--- a/arch/arm64/kvm/hyp/nvhe/mem_protect.c
+++ b/arch/arm64/kvm/hyp/nvhe/mem_protect.c
@@ -758,6 +758,12 @@ static void host_inject_mem_abort(struct kvm_cpu_context *host_ctxt)
inject_host_exception(esr);
}

+static bool is_dabt_with_isv(u64 esr)
+{
+ return (ESR_ELx_EC(esr) == ESR_ELx_EC_DABT_LOW) &&
+ (esr & ESR_ELx_ISV);
+}
+
void handle_host_mem_abort(struct kvm_cpu_context *host_ctxt)
{
struct kvm_vcpu_fault_info fault;
@@ -780,6 +786,15 @@ void handle_host_mem_abort(struct kvm_cpu_context *host_ctxt)
BUG_ON(!(fault.hpfar_el2 & HPFAR_EL2_NS));
addr = FIELD_GET(HPFAR_EL2_FIPA, fault.hpfar_el2) << 12;

+ /*
+ * Emulate data aborts for IOMMU drivers, other access will be denied
+ * by host_stage2_adjust_range()
+ */
+ if (is_dabt_with_isv(esr) && !addr_is_memory(addr) &&
+ pkvm_iommu_host_dabt_handler(&host_ctxt->regs,
+ esr, addr | FAR_TO_FIPA_OFFSET(fault.far_el2)))
+ return;
+
switch (host_stage2_idmap(addr)) {
case -EPERM:
host_inject_mem_abort(host_ctxt);
--
2.55.0.1082.g2b9226bbc0-goog