diff mbox series

[v6,03/11] xen/arm: Allow device-passthrough even the IOMMU is off

Message ID 20220214031956.3726764-4-penny.zheng@arm.com (mailing list archive)
State New, archived
Headers show
Series direct-map memory map | expand

Commit Message

Penny Zheng Feb. 14, 2022, 3:19 a.m. UTC
From: Stefano Stabellini <sstabellini@kernel.org>

At the moment, we are only supporting device-passthrough when Xen has
enabled the IOMMU. There are some use cases where it is not possible to
use the IOMMU (e.g. doesn't exist, hardware limitation, performance) yet
it would be OK to assign a device to trusted domain so long they are
direct-mapped or the device doesn't do DMA.

Note that when the IOMMU is disabled, it will be necessary to add
xen,force-assign-without-iommu for every device that needs to be assigned.

Signed-off-by: Stefano Stabellini <stefano.stabellini@xilinx.com>
Signed-off-by: Penny Zheng <penny.zheng@arm.com>
Tested-by: Stefano Stabellini <sstabellini@kernel.org>
---
v3 changes:
- new commit, split from the original "[PATCH v2 2/6] xen/arm: introduce
direct-map for domUs"
---
v4 changes:
- explain briefly in the commit message why we want to do device assignment
without IOMMU.
---
v5 changes:
- nothing changed
---
v6 changes
- commit message refinement
---
 xen/arch/arm/domain_build.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

Comments

Julien Grall Feb. 15, 2022, 8:26 p.m. UTC | #1
Hi,

On 14/02/2022 03:19, Penny Zheng wrote:
> From: Stefano Stabellini <sstabellini@kernel.org>
> 
> At the moment, we are only supporting device-passthrough when Xen has
> enabled the IOMMU. There are some use cases where it is not possible to
> use the IOMMU (e.g. doesn't exist, hardware limitation, performance) yet
> it would be OK to assign a device to trusted domain so long they are
> direct-mapped or the device doesn't do DMA.
> 
> Note that when the IOMMU is disabled, it will be necessary to add
> xen,force-assign-without-iommu for every device that needs to be assigned.
> 
> Signed-off-by: Stefano Stabellini <stefano.stabellini@xilinx.com>
> Signed-off-by: Penny Zheng <penny.zheng@arm.com>
> Tested-by: Stefano Stabellini <sstabellini@kernel.org>

Acked-by: Julien Grall <jgrall@amazon.com>

Cheers,
diff mbox series

Patch

diff --git a/xen/arch/arm/domain_build.c b/xen/arch/arm/domain_build.c
index 6467e8ee32..c1e8c99f64 100644
--- a/xen/arch/arm/domain_build.c
+++ b/xen/arch/arm/domain_build.c
@@ -3047,7 +3047,8 @@  void __init create_domUs(void)
             panic("Missing property 'cpus' for domain %s\n",
                   dt_node_name(node));
 
-        if ( dt_find_compatible_node(node, NULL, "multiboot,device-tree") )
+        if ( dt_find_compatible_node(node, NULL, "multiboot,device-tree") &&
+             iommu_enabled )
             d_cfg.flags |= XEN_DOMCTL_CDF_iommu;
 
         if ( !dt_property_read_u32(node, "nr_spis", &d_cfg.arch.nr_spis) )