Re: [RFC PATCH v6 09/11] iommufd: Add the vdevice TSM request ioctl

From: Jason Gunthorpe

Date: Wed Sep 30 2026 - 10:16:59 EST


On Wed, Sep 30, 2026 at 06:56:03PM +0530, Vasant Hegde wrote:
> >>> [ ... 34 lines skipped ... ]
> >>> +/**
> >>> + * enum iommu_vdevice_tsm_guest_req_op - operation for guest TSM requests
> >>> + * @TSM_REQ_VALIDATE_MMIO: Validate MMIO for the TDI
> >>> + * @TSM_REQ_SET_TDI_STATE: Set TDI state
> >>> + * @TSM_REQ_SEV_ENABLE_DMA: Enable SEV DMA
> >>
> >> That seems wrong.. The hypervisor should not have control over T=1
> >> DMA.
> >>
>
> (Still catching up with entire thread)
>
> In case of AMD IOMMU, before allowing DMA from secure guest, we have to update
> IOMMU host (nested) page table entry size to match the RMP table.

Okay, but that is not "Enable SEV DMA" that is "something something
RMP"

I do not like these obfuscated names that are still architecture
specific behaviors but obscure what the actual spec defined underlying
action is.

If AMD needs some RMP maintinance then have a clearly named RMP
maintainence op that links back to the specification documentation.

I've never liked this approach since I saw the first iommufd patches.

iommufd, philisophically, is about providing truely general APIs that
can work for everyone, and very device specific APIs that directly
work the device's interface in the natural device specific way
according to their specs.

So I would hope to see some general APIs for the SPDM related stuff, I
think everyone has that and it should work in exactly the same way? Or
not?

Everything else should point down to arch specific stuff. Like if we
need to do some RMI_VDEV_XX then it should be called that here, not
obfuscated.

Jason