Re: [PATCH v3 2/5] iommu/amd: Fix DTE clearing and rename iommu_ignore_device()

From: Vasant Hegde

Date: Fri Sep 04 2026 - 06:14:42 EST


Jason,


On 8/28/2026 5:23 PM, Jason Gunthorpe wrote:
> On Fri, Aug 28, 2026 at 10:46:48AM +0530, Vasant Hegde wrote:
>>> Having the driver boot up with all DTEs programmed to identity (eg
>>> 0'd) and then try to fix them to blocking after the iommu probes
>>> devices is security backwards.
>>
>> During boot, it only sets dte.v bit.
>
> First it clears it to fully 0, what does 0 do in HW?

IF DTE is fully zero, then all requests are blocked for that devid.

>
> It doesn't make sense that you'd pass over the DTEs after
> probing if the original 0'd DTE was actually blocking?

During boot, it sets certain default values includ dte.v. It doesn't clear
everything. In probe path, if probe fails then its clearing it entirely.

May be we should just remove ignore_device() completely? as
- normal boot, its not yet configured, so no DMA is allowed
- kdump boot, old DTE is still valid and let it continue?


-Vasant