RE: [RFC PATCH v6 08/11] iommufd: Add vIOMMU provider support
From: Aneesh Kumar K . V
Date: Tue Sep 29 2026 - 02:15:29 EST
"Tian, Kevin" <kevin.tian@xxxxxxxxx> writes:
>> From: Jason Gunthorpe <jgg@xxxxxxxxxx>
>> Sent: Friday, September 25, 2026 8:39 PM
>>
>> On Fri, Sep 25, 2026 at 11:38:15AM +0530, Aneesh Kumar K.V wrote:
>> > Jason Gunthorpe <jgg@xxxxxxxxxx> writes:
>> >
[ ... 26 lines skipped ... ]
>>
>> Just put the two new ops in:
>>
>> struct pci_tsm_ops {
>> size_t (*viommu_get_size)(struct device *dev, enum
>> iommu_viommu_type type);
>> int (*viommu_init)(struct iommufd_viommu *viommu, struct device
>> *dev,
>> struct iommu_domain *parent,
>> const struct iommu_user_data *user_data);
>> }
>>
>> And bounce them with a static inline
>>
>> static inline
>> ssize_t pci_tsm_viommu_get_size(struct device *dev, enum
>> iommu_viommu_type type)
>> {
>> const struct pci_tsm_ops *ops;
>> struct pci_dev *pdev;
>>
>> if (!dev_is_pci(dev))
>> return -EINVAL;
>>
>> pdev = to_pci_dev(dev);
>> if (!pdev->tsm)
>> return -ENODEV;
>>
>> ops = to_pci_tsm_ops(pdev->tsm);
>> if (!ops->viommu_get_size)
>> return 0;
>> return ops->viommu_get_size(dev, type);
>> }
>>
>> No module dependency.
>>
>> The iommufd side is simple, it just calls this before calling the
>> iommu driver. First one to return a size wins and creates the viommu.
>>
>> We'd want to have a reasonable lifetime model where the the pdev->tsm
>> is guarenteed stable while a driver is bound.
>>
>
> +1
I am looking into implementing this as follows:
tsm_viommu_get_ops() runs with pci_tsm_rwsem held for read and takes a
temporary reference on the backend module (the CCA module). This keeps
the selected ops callable until vIOMMU initialization completes. iommufd
then drops the reference. This does not pin a particular TSM
registration or prevent tsm_unregister().
CCA vIOMMU initialization takes a tsm_dev reference, keeping the TSM
object and its PCI/TSM resources alive until the vIOMMU is destroyed.
The initialization callback also takes a reference on the CCA module so
that the vIOMMU callbacks remain available after iommufd drops the
temporary discovery reference described above.
For a link TSM-connected device, a vdevice holds a pci_tsm_context
reference. The context holds device references and increments PF0's
context_users under the PF0 mutex. PCI/TSM disconnect checks that count
under the same mutex and returns -EBUSY while contexts remain. The
context is released during vdevice teardown. This prevents link
disconnect while a vdevice is active without blocking tsm_unregister().
A new unregistering state is added to tsm_dev. tsm_unregister() sets it,
unregisters the class device, and drops the registration reference. New
vIOMMU allocations, vdevice contexts, and PCI TSM connect/lock
operations reject the TSM once this state is set. Existing users retain
their references and can be torn down normally, so tsm_unregister() does
not need to wait for them. PCI/TSM teardown occurs when the last active
tsm_dev reference is dropped.
-aneesh