[PATCH v7 00/16] iommufd: vIOMMUs and TSM guest requests for confidential guests

From: Aneesh Kumar K.V (Arm)

Date: Thu Oct 08 2026 - 02:00:22 EST


This series adds IOMMUFD and PCI/TSM infrastructure for assigning PCI
devices to confidential guests. It includes the IOMMU_VDEVICE_TSM_REQ
ioctl. The Arm CCA host backend is supplied in a separate series; this
series provides the interfaces it uses.

Physical IOMMU drivers and PCI TSM backends now provide vIOMMU ops before
IOMMUFD validates the parent HWPT. These ops provide callbacks for
determining the allocation size and initializing the vIOMMU, along with
flags specifying whether a parent HWPT is required. A nesting parent is
required by default. When the selected ops set IOMMUFD_VIOMMU_NO_HWPT,
userspace must supply a zero hwpt_id, and IOMMUFD passes NULL as the parent
domain to the initialization callback. Nested HWPT and hardware queue
allocation are rejected for a vIOMMU without a parent.

IOMMUFD first queries the TSM attached to the selected PCI device. Lookup
pins the backend module before using its vIOMMU ops, and that
reference is released after the backend's vIOMMU destruction callback.
The backend must keep its TSM registered while the module is pinned.
When no TSM provides ops for the requested type, IOMMUFD falls back
to the physical IOMMU driver. An error from TSM lookup or querying its ops is
returned without falling back.

Vdevice contexts replace the legacy PCI/TSM bind and unbind interface.
Context acquisition verifies that the device's current TSM matches the
vIOMMU's TSM. An explicit sysfs disconnect returns EBUSY while contexts
remain active. Guest requests are dispatched through the vIOMMU ops.

IOMMU_VDEVICE_TSM_REQ checks the guest architecture and the vdevice's
supported-operation mask before forwarding userspace buffers to the
backend. Request and response lengths are limited to INT_MAX so a
successful residue fits in the ioctl return value. The backend supplies
the architecture-specific request handling and TSM result code.

Notes:
* Codex was used to assist with commit message formatting and code
rearrangement.
* This series also includes patches from the following series to provide
the dependencies needed for Sashiko to review the combined changes:
https://lore.kernel.org/all/20260928-vfio-v4-0-e32e226d5932@xxxxxxxxxxxxx

Changes from v6:
https://lore.kernel.org/all/20260917140159.1163281-1-aneesh.kumar@xxxxxxxxxx
* Replace the IOMMUFD provider registry with per-device TSM operation lookup.
* Move vIOMMU allocation size and initialization into the selected vIOMMU ops.
* Select parent HWPT policy from the vIOMMU ops flags.
* Pin a vIOMMU's TSM backend module through vIOMMU destruction.

Changes from v5:
https://lore.kernel.org/all/20260525154816.1029642-1-aneesh.kumar@xxxxxxxxxx
* Replace the TSM bind/unbind interface with reference-counted contexts.
* Add the IOMMUFD vIOMMU provider abstraction.
* Route TSM guest requests through vIOMMU ops.

Changes from v4:
https://lore.kernel.org/all/20260427061005.901854-1-aneesh.kumar@xxxxxxxxxx
* Switch VFIO/iommufd to use struct file *kvm_file instead of relying on
kvm->users_count references.
* Define TSM request scope values globally in iommufd.
* Rename the ioctl to IOMMU_VDEVICE_TSM_REQ.
* Address other review feedback.

Changes from v2:
https://lore.kernel.org/all/20260309111704.2330479-1-aneesh.kumar@xxxxxxxxxx
* Bump the series revision to v4 to keep it in sync with the dependent CCA DA
patchsets. There was no v3 posting.
* Drop [PATCH v2 1/3] iommufd/viommu: Allow associating a KVM VM fd with a
vIOMMU
* Add two new patches to associate a struct kvm * with iommufd objects:
iommufd/device: Associate a kvm pointer to iommufd_device
iommufd/viommu: Associate a kvm pointer to iommufd_viommu
* Address review feedback

Changes from v1:
https://lore.kernel.org/all/20250728135216.48084-8-aneesh.kumar@xxxxxxxxxx
* Rebase onto the latest kernel
* Address review feedback
* Drop the TSM map ioctl; the KVM prefault patch will be used instead to
ensure that private memory is preallocated

Cc: Alex Williamson <alex@xxxxxxxxxxx>
Cc: Alexey Kardashevskiy <aik@xxxxxxx>
Cc: Bjorn Helgaas <bhelgaas@xxxxxxxxxx>
Cc: Catalin Marinas <catalin.marinas@xxxxxxx>
CC: Jacob Pan <jacob.pan@xxxxxxxxxxxxxxxxxxx>
Cc: Jason Gunthorpe <jgg@xxxxxxxx>
Cc: Joerg Roedel <joro@xxxxxxxxxx>
Cc: Jonathan Cameron <jic23@xxxxxxxxxx>
Cc: Jonathan Hunter <jonathanh@xxxxxxxxxx>
Cc: Kevin Tian <kevin.tian@xxxxxxxxx>
Cc: Krishna Reddy <vdumpa@xxxxxxxxxx>
Cc: Lukas Wunner <lukas@xxxxxxxxx>
Cc: Nicolin Chen <nicolinc@xxxxxxxxxx>
Cc: Robin Murphy <robin.murphy@xxxxxxx>
Cc: Samuel Ortiz <sameo@xxxxxxxxxxxx>
Cc: Shameer Kolothum <shameerali.kolothum.thodi@xxxxxxxxxx>
Cc: Steven Price <steven.price@xxxxxxx>
Cc: Suravee Suthikulpanit <suravee.suthikulpanit@xxxxxxx>
Cc: Suzuki K Poulose <suzuki.poulose@xxxxxxx>
Cc: Thierry Reding <thierry.reding@xxxxxxxxxx>
Cc: Vasant Hegde <vasant.hegde@xxxxxxx>
Cc: Will Deacon <will@xxxxxxxxxx>
Cc: Xu Yilun <yilun.xu@xxxxxxxxxxxxxxx>
Cc: kvm@xxxxxxxxxxxxxxx
Cc: linux-arm-kernel@xxxxxxxxxxxxxxxxxxx
Cc: linux-coco@xxxxxxxxxxxxxxx
Cc: linux-kernel@xxxxxxxxxxxxxxx
Cc: linux-pci@xxxxxxxxxxxxxxx
Cc: linux-tegra@xxxxxxxxxxxxxxx

Aneesh Kumar K.V (Arm) (8):
tsm: Remove the device from lookup before PCI teardown
iommufd: Add the vdevice TSM request ioctl
PCI/TSM: Remove the legacy guest request interface
PCI/TSM: Add vIOMMU-bound contexts for vdevices
iommufd/viommu: Select vIOMMU operations before allocation
iommufd/viommu: Allow PCI TSM backends to provide vIOMMU operations
iommufd: Allow vIOMMUs without a parent HWPT
PCI/TSM: wait for vdevice contexts before removing a DSM

Nicolin Chen (1):
iommufd/viommu: Keep a reference to the KVM file

Shameer Kolothum (1):
iommufd/device: Associate KVM file pointer with iommufd_device

Steffen Eiden (6):
KVM: Introduce file_to_kvm_<arch>() infrastructure
KVM: Add file back-pointer to struct kvm
KVM: x86: Use file_to_kvm_x86() in SEV
KVM/vfio: Use file-based reference counting for KVM
KVM: Restrict kvm_get_kvm/kvm_put_kvm export to internal KVM modules
KVM: Remove unused file_is_kvm

Documentation/ABI/testing/sysfs-bus-pci | 17 +-
Documentation/userspace-api/iommufd.rst | 44 ++-
arch/s390/include/asm/kvm_host_s390.h | 4 +-
arch/s390/kvm/s390/pci.c | 9 +-
arch/x86/include/asm/kvm_host.h | 2 +
arch/x86/include/asm/kvm_page_track.h | 10 +-
arch/x86/kvm/Makefile | 4 +-
arch/x86/kvm/mmu/page_track.c | 22 +-
arch/x86/kvm/svm/sev.c | 8 +-
drivers/iommu/amd/iommu.c | 3 +-
drivers/iommu/amd/iommufd.c | 18 +-
drivers/iommu/amd/iommufd.h | 11 +-
drivers/iommu/amd/nested.c | 4 +-
.../arm/arm-smmu-v3/arm-smmu-v3-iommufd.c | 37 +-
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c | 7 +-
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h | 16 +-
.../iommu/arm/arm-smmu-v3/tegra241-cmdqv.c | 24 +-
drivers/iommu/iommufd/Makefile | 2 +
drivers/iommu/iommufd/device.c | 7 +-
drivers/iommu/iommufd/hw_pagetable.c | 14 +-
drivers/iommu/iommufd/iommufd_private.h | 10 +
drivers/iommu/iommufd/main.c | 3 +
drivers/iommu/iommufd/selftest.c | 33 +-
drivers/iommu/iommufd/tsm.c | 80 ++++
drivers/iommu/iommufd/viommu.c | 117 ++++--
drivers/pci/tsm.c | 362 ++++++++----------
drivers/s390/crypto/vfio_ap_ops.c | 20 +-
drivers/vfio/group.c | 11 +-
drivers/vfio/iommufd.c | 3 +-
drivers/vfio/vfio.h | 12 +-
drivers/vfio/vfio_main.c | 57 +--
drivers/virt/coco/tsm-core.c | 55 ++-
include/linux/iommu.h | 20 +-
include/linux/iommufd.h | 35 +-
include/linux/kvm_host.h | 19 +-
include/linux/pci-tsm.h | 153 ++++----
include/linux/tsm.h | 46 +++
include/linux/vfio.h | 5 +-
include/uapi/linux/iommufd.h | 85 +++-
virt/kvm/kvm_main.c | 21 +-
virt/kvm/vfio.c | 13 +-
41 files changed, 893 insertions(+), 530 deletions(-)
create mode 100644 drivers/iommu/iommufd/tsm.c


base-commit: 551c722f40809618230001baccf219193e22fc5a
--
2.43.0