[PATCH v3 09/10] rust: pci: add SR-IOV enable and disable callbacks

From: Zhi Wang

Date: Wed Sep 30 2026 - 06:33:53 EST


From: Peter Colberg <peter@xxxxxxxxxxx>

Allow Rust PCI drivers to configure SR-IOV through sriov_numvfs.
Split the C configure callback into sriov_enable() and sriov_disable(),
passing pinned driver data and a token for the requested operation.
Require drivers to implement both callbacks together.

Return the enabled guard's VF count on success and disarm its rollback.
On a disable request, verify that the driver has removed all VFs before
reporting success. VfRegistration handles VF removal during PF teardown;
these callbacks only handle explicit configuration requests.

Suggested-by: Danilo Krummrich <dakr@xxxxxxxxxx>
Signed-off-by: Peter Colberg <peter@xxxxxxxxxxx>
Signed-off-by: Zhi Wang <zhiw@xxxxxxxxxx>
---
rust/kernel/pci.rs | 83 ++++++++++++++++++++++++++++++++++++++++++
rust/kernel/pci/iov.rs | 62 +++++++++++++++++++++++++++----
2 files changed, 137 insertions(+), 8 deletions(-)

diff --git a/rust/kernel/pci.rs b/rust/kernel/pci.rs
index 8a87e2202a2c..87d2e637d902 100644
--- a/rust/kernel/pci.rs
+++ b/rust/kernel/pci.rs
@@ -87,12 +87,22 @@ unsafe fn register(
name: &'static CStr,
module: &'static ThisModule,
) -> Result {
+ #[cfg(CONFIG_PCI_IOV)]
+ build_assert!(
+ T::HAS_SRIOV_ENABLE == T::HAS_SRIOV_DISABLE,
+ "PCI drivers must implement both sriov_enable and sriov_disable"
+ );
+
// SAFETY: It's safe to set the fields of `struct pci_driver` on initialization.
unsafe {
(*pdrv.get()).name = name.as_char_ptr();
(*pdrv.get()).probe = Some(Self::probe_callback);
(*pdrv.get()).remove = Some(Self::remove_callback);
(*pdrv.get()).id_table = T::ID_TABLE.as_ptr();
+ #[cfg(CONFIG_PCI_IOV)]
+ if T::HAS_SRIOV_ENABLE {
+ (*pdrv.get()).sriov_configure = Some(Self::sriov_configure_callback);
+ }
}

// SAFETY: `pdrv` is guaranteed to be a valid `DriverType`.
@@ -344,6 +354,79 @@ fn probe<'bound>(
fn unbind<'bound>(dev: &'bound Device<device::Core<'_>>, this: Pin<&Self::Data<'bound>>) {
let _ = (dev, this);
}
+
+ /// Enables Single Root I/O Virtualization (SR-IOV) for a PF.
+ ///
+ /// Called when userspace writes a nonzero VF count to `sriov_numvfs`. The token carries the
+ /// requested count and permission to enable VFs on this PF. Return the guard obtained from
+ /// [`SriovEnable::enable()`] after completing setup; dropping it rolls back the enable.
+ ///
+ /// The PF must own a [`VfRegistration`] before enabling VFs. That registration disables
+ /// SR-IOV when the driver data is destroyed, while resources needed by VF drivers remain live.
+ /// Implement this callback and [`Self::sriov_disable()`] together, or implement neither.
+ ///
+ /// See [PCI Express I/O Virtualization].
+ ///
+ /// [PCI Express I/O Virtualization]: https://docs.kernel.org/PCI/pci-iov-howto.html
+ ///
+ /// # Examples
+ ///
+ /// ```
+ /// # use kernel::{device::Core, pci, prelude::*};
+ /// # struct Data;
+ /// fn sriov_enable<'callback>(
+ /// _dev: &pci::Device<Core<'_>>,
+ /// _this: Pin<&Data>,
+ /// token: pci::SriovEnable<'callback>,
+ /// ) -> Result<pci::SriovEnabled<'callback>> {
+ /// let num_vfs = token.num_vfs();
+ /// let enabled = token.enable(num_vfs)?;
+ /// // Complete any additional setup before returning the guard.
+ /// Ok(enabled)
+ /// }
+ /// ```
+ #[cfg(CONFIG_PCI_IOV)]
+ fn sriov_enable<'bound, 'callback>(
+ dev: &'bound Device<device::Core<'_>>,
+ this: Pin<&Self::Data<'bound>>,
+ token: SriovEnable<'callback>,
+ ) -> Result<SriovEnabled<'callback>> {
+ let _ = (dev, this, token);
+ build_error!(crate::error::VTABLE_DEFAULT_ERROR)
+ }
+
+ /// Disables all VFs of a PF in response to a userspace request.
+ ///
+ /// Called when userspace writes zero to `sriov_numvfs`. Call [`SriovDisable::disable()`]
+ /// while resources used by VF drivers are still available. Returning an error before calling
+ /// it leaves the VFs enabled. Returning success requires that all VFs have been disabled.
+ ///
+ /// This callback is not invoked during PF unbind; [`VfRegistration`] owns that teardown.
+ /// Implement this callback and [`Self::sriov_enable()`] together, or implement neither.
+ ///
+ /// # Examples
+ ///
+ /// ```
+ /// # use kernel::{device::Core, pci, prelude::*};
+ /// # struct Data;
+ /// fn sriov_disable(
+ /// _dev: &pci::Device<Core<'_>>,
+ /// _this: Pin<&Data>,
+ /// token: pci::SriovDisable<'_>,
+ /// ) -> Result {
+ /// token.disable();
+ /// Ok(())
+ /// }
+ /// ```
+ #[cfg(CONFIG_PCI_IOV)]
+ fn sriov_disable<'bound>(
+ dev: &'bound Device<device::Core<'_>>,
+ this: Pin<&Self::Data<'bound>>,
+ token: SriovDisable<'_>,
+ ) -> Result {
+ let _ = (dev, this, token);
+ build_error!(crate::error::VTABLE_DEFAULT_ERROR)
+ }
}

/// The PCI device representation.
diff --git a/rust/kernel/pci/iov.rs b/rust/kernel/pci/iov.rs
index e608b2f1e70c..9d9bd3ac7025 100644
--- a/rust/kernel/pci/iov.rs
+++ b/rust/kernel/pci/iov.rs
@@ -2,12 +2,19 @@

//! Abstractions for PCI Single Root I/O Virtualization (SR-IOV) drivers.

-use super::Device;
+use super::{
+ Adapter,
+ Device,
+ Driver, //
+};

use crate::{
bindings,
device,
- error::to_result,
+ error::{
+ from_result,
+ to_result, //
+ },
prelude::*,
types::{
CovariantForLt,
@@ -22,7 +29,6 @@
impl Device {
/// Returns `true` if this device is a Physical Function (PF).
#[inline]
- #[expect(dead_code)]
pub(crate) fn is_physfn(&self) -> bool {
// SAFETY: `self.as_raw` is a valid pointer to a `struct pci_dev`.
unsafe { (*self.as_raw()).is_physfn() != 0 }
@@ -76,7 +82,7 @@ pub(crate) fn disable_sriov(&self) {
}
}

-/// Permission to enable VFs during a driver's `sriov_enable()` callback.
+/// Permission to enable VFs during a driver's [`Driver::sriov_enable()`] callback.
///
/// The PCI adapter creates this token for the PF being configured. It cannot be cloned or sent
/// to another thread, and its lifetime is restricted to the callback. Enabling VFs consumes it.
@@ -105,7 +111,7 @@ pub fn num_vfs(&self) -> u32 {
///
/// VF drivers can probe before this method returns, so the PF resources they access must
/// already be initialized. The returned guard disables the VFs if subsequent setup fails.
- /// Return it from `sriov_enable()` to leave the VFs enabled on callback success.
+ /// Return it from [`Driver::sriov_enable()`] to leave the VFs enabled on callback success.
pub fn enable(self, num_vfs: u32) -> Result<SriovEnabled<'callback>> {
if num_vfs == 0 || num_vfs > self.num_vfs {
return Err(EINVAL);
@@ -126,14 +132,13 @@ pub fn enable(self, num_vfs: u32) -> Result<SriovEnabled<'callback>> {
}
}

-/// Enabled VFs awaiting successful completion of `sriov_enable()`.
+/// Enabled VFs awaiting successful completion of [`Driver::sriov_enable()`].
pub struct SriovEnabled<'callback> {
pdev: Option<&'callback Device<device::CoreInternal<'callback>>>,
num_vfs: c_int,
}

impl SriovEnabled<'_> {
- #[expect(dead_code)]
fn disarm(mut self) -> c_int {
self.pdev = None;
self.num_vfs
@@ -148,7 +153,7 @@ fn drop(&mut self) {
}
}

-/// Permission to disable VFs during a driver's `sriov_disable()` callback.
+/// Permission to disable VFs during a driver's [`Driver::sriov_disable()`] callback.
///
/// The PCI adapter creates this token for the PF being configured. It cannot be cloned or sent
/// to another thread, and its lifetime is restricted to the callback. Dropping the token does
@@ -166,6 +171,47 @@ pub fn disable(self) {
}
}

+impl<T: Driver> Adapter<T> {
+ pub(super) extern "C" fn sriov_configure_callback(
+ pdev: *mut bindings::pci_dev,
+ nr_virtfn: c_int,
+ ) -> c_int {
+ // SAFETY: The PCI bus only ever calls the sriov_configure callback with a valid pointer to
+ // a `struct pci_dev`.
+ //
+ // INVARIANT: `pdev` is valid for the duration of `sriov_configure_callback()`.
+ let pdev = unsafe { &*pdev.cast::<Device<device::CoreInternal<'_>>>() };
+
+ // SAFETY: `sriov_configure` is called only after a successful probe and before unbind, so
+ // the stored pointer has type `T::Data<'_>` and remains valid throughout this callback.
+ let data = unsafe { pdev.as_ref().drvdata_borrow::<T::Data<'_>>() };
+
+ from_result(|| {
+ if !pdev.is_physfn() {
+ return Err(ENODEV);
+ }
+ if nr_virtfn == 0 {
+ T::sriov_disable(pdev, data, SriovDisable { pdev })?;
+ if pdev.num_vf() != 0 {
+ return Err(EBUSY);
+ }
+ Ok(0)
+ } else {
+ let num_vfs = u16::try_from(nr_virtfn).map_err(|_| EINVAL)?;
+ let enabled = T::sriov_enable(
+ pdev,
+ data,
+ SriovEnable {
+ pdev,
+ num_vfs: u32::from(num_vfs),
+ },
+ )?;
+ Ok(enabled.disarm())
+ }
+ })
+ }
+}
+
/// Wrapper for VF registration data stored inside a [`VfRegistration`].
///
/// Stores a [`TypeId`] header (derived from `F`) followed by the pinned data,
--
2.53.0