[PATCH v2 0/9] iommu/vt-d: Support a new DMAR flag

From: Kevin Tian

Date: Thu Jul 02 2026 - 02:01:53 EST


VT-d spec v5.2 introduces a new DMA_REMAP_OPT_OUT flag in the DMAR
table, adding another knob to affect whether the DMA remapping
capability should be turned on or off.

While at it, first clean up the existing on/off policy messed with
user opts and various force_on conditions in the first 8 patches.

On top of the improved framework, the last patch introduces the
support of the new bit.

Some cleanups will be done after this series:
- Cache dmar->flags instead of reading ACPI table multiple times
- Check intel_iommu_enabled at runtime instead of using dmar_policy
- Clean up existing warning messages (e.g. force_on panic message
always has the "tboot:" prefix)

v2:
- Rebase to 7.2-rc1
- Policy-oriented renaming to avoid confusion with runtime state (Baolu)
- Warning message/comment improvements (Baolu)
- Always return error for unsupported force_on type
- No need to do platform optin if tboot already forces on (old behavior)

v1:
https://lore.kernel.org/linux-iommu/20260604051540.592925-1-kevin.tian@xxxxxxxxx/

Kevin Tian (9):
iommu/vt-d: Fix no_iommu to disable platform optin
iommu/vt-d: Force requesting ACS when tboot is enabled
iommu/vt-d: Remove dead code when CONFIG_INTEL_IOMMU is not set
iommu/vt-d: Consolidate dmar policy management and force_on logic
iommu/vt-d: Use dmar_can_force_on() for platform optin
iommu/vt-d: Call dmar_can_force_on() for tboot optin
iommu/vt-d: Remove the 'force_on' variable
iommu/vt-d: Remove dmar_disabled
iommu/vt-d: Support the new DMA_REMAP_OPT_OUT flag bit

drivers/iommu/intel/dmar.c | 95 +++++++++++++++++++++++++++++++++----
drivers/iommu/intel/iommu.c | 78 +++++++++++++++---------------
drivers/iommu/intel/iommu.h | 64 ++++++++++++++++++++-----
drivers/iommu/intel/svm.c | 2 +-
include/linux/dmar.h | 1 +
5 files changed, 180 insertions(+), 60 deletions(-)


base-commit: dc59e4fea9d83f03bad6bddf3fa2e52491777482
--
2.43.0