[PATCH v3 0/2] iommu/iommufd: Expose PCI host bridge MMIO windows for opt-in IOVA avoidance
From: Guanghui Feng
Date: Sun Oct 04 2026 - 12:28:52 EST
When a device sits behind a PCIe switch and ACS Upstream Forwarding is
not fully enabled, DMA TLPs whose IOVA happens to fall within a host
bridge MMIO window may be routed peer-to-peer to another downstream
device instead of upstream to the root complex for IOMMU translation.
This can lead to faults, data corruption, or silent misrouting.
The DMA IOVA layer already avoids this via iova_reserve_pci_windows().
However, passthrough paths that let userspace pick IOVAs (VFIO type1,
iommufd) had no mechanism to learn about these ranges. Commit
cd2c9fcf5c66 ("iommu/dma: Move PCI window region reservation back into
dma specific path.") intentionally keeps this information out of the
IOMMU reserved-region API to avoid pessimistically restricting
userspace.
Following Jason Gunthorpe's suggestion [1], this series takes an opt-in
approach: the kernel reports the information, userspace decides whether
to avoid it.
Patch 1 adds iommu_get_pci_resv_windows(), a shared helper that
enumerates a device's host bridge MMIO windows as sorted, merged
IOMMU_RESV_RESERVED regions.
Patch 2 adds the IOMMU_GET_PCI_MMIO_WINDOWS ioctl to iommufd, a
per-device query that returns these windows to userspace without
reserving or enforcing them.
[1] https://lore.kernel.org/all/20260921115513.GK11599@xxxxxxxx/
v2: https://lore.kernel.org/all/20260921103922.1113752-1-guanghuifeng@xxxxxxxxxxxxxxxxx/
v1: https://lore.kernel.org/all/20260921070234.897736-1-guanghuifeng@xxxxxxxxxxxxxxxxx/
Changes since v2:
- Complete redesign per Robin Murphy's and Jason Gunthorpe's review.
v2 forced PCI window reservation through iommu_get_group_resv_regions()
which was explicitly rejected (this was tried before and reverted by
cd2c9fcf5c66). v3 instead provides an opt-in query interface.
- Patch 1: add iommu_get_pci_resv_windows() as a standalone helper.
No longer touches dma-iommu.c (the existing direct enumeration in
iova_reserve_pci_windows() is simpler and allocation-free; refactoring
it to use the helper would add unnecessary overhead for no functional
benefit).
- Patch 2: new IOMMU_GET_PCI_MMIO_WINDOWS ioctl replaces the v2
iommufd enforce-path change. Reports windows to userspace without
reserving them.
- io_pagetable.c and dma-iommu.c are unchanged from base.
Changes since v1:
- (Superseded by v2->v3 changes above.)
Guanghui Feng (2):
iommu: Add iommu_get_pci_resv_windows() helper
iommufd: Add IOMMU_GET_PCI_MMIO_WINDOWS ioctl
drivers/iommu/iommu-priv.h | 12 +++++
drivers/iommu/iommu.c | 57 ++++++++++++++++++++++
drivers/iommu/iommufd/device.c | 64 +++++++++++++++++++++++++
drivers/iommu/iommufd/iommufd_private.h | 1 +
drivers/iommu/iommufd/main.c | 3 ++
include/uapi/linux/iommufd.h | 55 +++++++++++++++++++++
6 files changed, 192 insertions(+)
--
2.43.7