Re: [RFC PATCH v6 05/11] iommu: Add a helper to validate a vIOMMU parent

From: Aneesh Kumar K . V

Date: Mon Sep 28 2026 - 06:36:59 EST


Jason Gunthorpe <jgg@xxxxxxxxxx> writes:

> On Fri, Sep 25, 2026 at 11:18:44AM +0530, Aneesh Kumar K.V wrote:
>> > The TSM viommu should use a NULL parent domain, it doesn't have an
>> > iommufd managed S2.
>>
>> How would we assign an untrusted device? I currently follow these steps:
>
>> 1. Create an HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT.
>> 2. Allocate a vIOMMU with viommu.hwpt_id set to that hwpt_id.
>> 3. Allocate a vdevice with alloc_vdev.viommu_id set to that viommu_id.
>> 4. Use VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id.
>
> The vmiommu.hwpt_id should be 0.
>
> 1. Create a a HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT
> 2. VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id to establish the T=0
> identity S2, no T=0 vSMMU
> 3. Create a VIOMMU with no hwpt_id and the RMM's type. This triggers
> RMM to create the the T=1 vSMMU inside the realm
> 4. Allocate a vdevice on the viommu_id. This triggers RMM to create
> the VDEV inside the realm
> 5. Setup guest ACPI tables/etc to point at the RMM's T=1 vsmmu.
>
> Now both the T=1 VSUMM and T=0 fixed translation are setup.
>

ok so iommufd_viommu_alloc_ioctl() will do this based on type.

+ if (iommufd_viommu_type_requires_hwpt(cmd->type)) {
+ hwpt_paging = iommufd_get_hwpt_paging(ucmd, cmd->hwpt_id);
+ if (IS_ERR(hwpt_paging)) {


-aneesh