Re: [PATCH v4] iommu/amd: Make PerfOpt compulsory

From: Jason Gunthorpe

Date: Fri Oct 02 2026 - 07:46:46 EST


On Thu, Oct 01, 2026 at 10:57:17PM -0500, Mario Limonciello wrote:
> > On 10/1/2026 11:54 PM, Mario Limonciello (AMD) wrote:
> > > PerfOpt is only a feature usable by integrated GPUs and only in identity
> > > mode. Instead of leaving a policy knob in amdgpu, just turn it on when
> > > an integrated GPU is in identity.
> > >
> > > PerfOpt locks the GPU into identity mode where the DTE is ignored, so mark
> > > it require_direct (blocks VFIO/iommufd claims) and disable PASID (no GCR3
> > > table in the fast path).
> > >
> > > This drops quite a bit of compatibility glue. There was a refcounting
> > > system, exported symbols, and device attach/detach logic. By just setting
> > > it immediately it's a lot more straightforward.
> > >
> > > Suggested-by: Jason Gunthorpe <jgg@xxxxxxxx>
> > > Signed-off-by: Mario Limonciello (AMD) <superm1@xxxxxxxxxx>
> > > ---
> > > v4:
> > > * Disable PASID for PerfOpt devices
> > > * Don't allow attaching a blocked domain
> >
> > This will block attaching device to guest via vfio-pci. Is that fine?
>
> Right - The thing is from that experiment on v3, putting it in blocked
> domain does nothing while PerfOpt is enabled.
>
> I figured the user should be aware; so I was between blocking attaching a
> blocked domain or showing a warning.

Ideally you'd fix it by making the perfopt bit only set when an
identity domain is attached.

Though I'm not especially happy to see a driver that can't support at
least blocking, that's pretty broken in our model...

Definately don't show a warning, this is security stuff if the driver
can't do an operation then it must fail.

Jason