Re: [PATCH] s390: protvirt: virtio: Refuse device without IOMMU

From: Halil Pasic
Date: Mon Jun 15 2020 - 06:37:38 EST


On Mon, 15 Jun 2020 11:01:55 +0800
Jason Wang <jasowang@xxxxxxxxxx> wrote:

> > hum, in between I found another way which seems to me much better:
> >
> > We already have the force_dma_unencrypted() function available which
> > AFAIU is what we want for encrypted memory protection and is already
> > used by power and x86 SEV/SME in a way that seems AFAIU compatible
> > with our problem.
> >
> > Even DMA and IOMMU are different things, I think they should be used
> > together in our case.
> >
> > What do you think?
> >
> > The patch would then be something like:
> >
> > diff --git a/drivers/virtio/virtio.c b/drivers/virtio/virtio.c
> > index a977e32a88f2..53476d5bbe35 100644
> > --- a/drivers/virtio/virtio.c
> > +++ b/drivers/virtio/virtio.c
> > @@ -4,6 +4,7 @@
> > Â#include <linux/virtio_config.h>
> > Â#include <linux/module.h>
> > Â#include <linux/idr.h>
> > +#include <linux/dma-direct.h>
> > Â#include <uapi/linux/virtio_ids.h>
> >
> > Â/* Unique numbering for virtio devices. */
> > @@ -179,6 +180,10 @@ int virtio_finalize_features(struct virtio_device
> > *dev)
> > ÂÂÂÂÂÂÂ if (!virtio_has_feature(dev, VIRTIO_F_VERSION_1))
> > ÂÂÂÂÂÂÂÂÂÂÂÂÂÂÂ return 0;
> >
> > +ÂÂÂÂÂÂ if (force_dma_unencrypted(&dev->dev) &&
> > +ÂÂÂÂÂÂÂÂÂÂ !virtio_has_feature(dev, VIRTIO_F_IOMMU_PLATFORM))
> > +ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ return -EIO;
> > +
> > ÂÂÂÂÂÂÂ virtio_add_status(dev, VIRTIO_CONFIG_S_FEATURES_OK);
> > ÂÂÂÂÂÂÂ status = dev->config->get_status(dev);
> > ÂÂÂÂÂÂÂ if (!(status & VIRTIO_CONFIG_S_FEATURES_OK)) {
>
>
> I think this can work but need to listen from Michael

I don't think Christoph Hellwig will like force_dma_unencrypted()
in virtio code:
https://lkml.org/lkml/2020/2/20/630

Regards,
Halil