Re: [RFC PATCH v6 05/11] iommu: Add a helper to validate a vIOMMU parent

From: Jason Gunthorpe

Date: Mon Sep 28 2026 - 08:25:10 EST


On Mon, Sep 28, 2026 at 04:06:42PM +0530, Aneesh Kumar K.V wrote:
> Jason Gunthorpe <jgg@xxxxxxxxxx> writes:
>
> > On Fri, Sep 25, 2026 at 11:18:44AM +0530, Aneesh Kumar K.V wrote:
> >> > The TSM viommu should use a NULL parent domain, it doesn't have an
> >> > iommufd managed S2.
> >>
> >> How would we assign an untrusted device? I currently follow these steps:
> >
> >> 1. Create an HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT.
> >> 2. Allocate a vIOMMU with viommu.hwpt_id set to that hwpt_id.
> >> 3. Allocate a vdevice with alloc_vdev.viommu_id set to that viommu_id.
> >> 4. Use VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id.
> >
> > The vmiommu.hwpt_id should be 0.
> >
> > 1. Create a a HWPT with IOMMU_HWPT_ALLOC_NEST_PARENT
> > 2. VFIO_DEVICE_ATTACH_IOMMUFD_PT with the hwpt_id to establish the T=0
> > identity S2, no T=0 vSMMU
> > 3. Create a VIOMMU with no hwpt_id and the RMM's type. This triggers
> > RMM to create the the T=1 vSMMU inside the realm
> > 4. Allocate a vdevice on the viommu_id. This triggers RMM to create
> > the VDEV inside the realm
> > 5. Setup guest ACPI tables/etc to point at the RMM's T=1 vsmmu.
> >
> > Now both the T=1 VSUMM and T=0 fixed translation are setup.
> >
>
> ok so iommufd_viommu_alloc_ioctl() will do this based on type.
>
> + if (iommufd_viommu_type_requires_hwpt(cmd->type)) {
> + hwpt_paging = iommufd_get_hwpt_paging(ucmd, cmd->hwpt_id);
> + if (IS_ERR(hwpt_paging)) {

The core code should not decode type, that's always a hack..

The ideal thing is to order things so we get a viommu_ops before
trying to get the hwpt, then use a flag in the ops

Jason