2 * generic functions used by VFIO devices
4 * Copyright Red Hat, Inc. 2012
7 * Alex Williamson <alex.williamson@redhat.com>
9 * This work is licensed under the terms of the GNU GPL, version 2. See
10 * the COPYING file in the top-level directory.
12 * Based on qemu-kvm device-assignment:
13 * Adapted for KVM by Qumranet.
14 * Copyright (c) 2007, Neocleus, Alex Novik (alex@neocleus.com)
15 * Copyright (c) 2007, Neocleus, Guy Zana (guy@neocleus.com)
16 * Copyright (C) 2008, Qumranet, Amit Shah (amit.shah@qumranet.com)
17 * Copyright (C) 2008, Red Hat, Amit Shah (amit.shah@redhat.com)
18 * Copyright (C) 2008, IBM, Muli Ben-Yehuda (muli@il.ibm.com)
21 #include "qemu/osdep.h"
22 #include <sys/ioctl.h>
23 #include <linux/vfio.h>
25 #include "hw/vfio/vfio-common.h"
26 #include "exec/address-spaces.h"
27 #include "exec/memory.h"
28 #include "exec/ram_addr.h"
30 #include "qemu/error-report.h"
31 #include "qemu/range.h"
32 #include "sysemu/reset.h"
34 #include "qapi/error.h"
35 #include "migration/migration.h"
38 VFIOGroupList vfio_group_list
=
39 QLIST_HEAD_INITIALIZER(vfio_group_list
);
41 static int vfio_ram_block_discard_disable(VFIOContainer
*container
, bool state
)
43 switch (container
->iommu_type
) {
44 case VFIO_TYPE1v2_IOMMU
:
45 case VFIO_TYPE1_IOMMU
:
47 * We support coordinated discarding of RAM via the RamDiscardManager.
49 return ram_block_uncoordinated_discard_disable(state
);
52 * VFIO_SPAPR_TCE_IOMMU most probably works just fine with
53 * RamDiscardManager, however, it is completely untested.
55 * VFIO_SPAPR_TCE_v2_IOMMU with "DMA memory preregistering" does
56 * completely the opposite of managing mapping/pinning dynamically as
57 * required by RamDiscardManager. We would have to special-case sections
58 * with a RamDiscardManager.
60 return ram_block_discard_disable(state
);
64 static int vfio_dma_unmap_bitmap(const VFIOContainer
*container
,
65 hwaddr iova
, ram_addr_t size
,
68 const VFIOContainerBase
*bcontainer
= &container
->bcontainer
;
69 struct vfio_iommu_type1_dma_unmap
*unmap
;
70 struct vfio_bitmap
*bitmap
;
74 ret
= vfio_bitmap_alloc(&vbmap
, size
);
79 unmap
= g_malloc0(sizeof(*unmap
) + sizeof(*bitmap
));
81 unmap
->argsz
= sizeof(*unmap
) + sizeof(*bitmap
);
84 unmap
->flags
|= VFIO_DMA_UNMAP_FLAG_GET_DIRTY_BITMAP
;
85 bitmap
= (struct vfio_bitmap
*)&unmap
->data
;
88 * cpu_physical_memory_set_dirty_lebitmap() supports pages in bitmap of
89 * qemu_real_host_page_size to mark those dirty. Hence set bitmap_pgsize
90 * to qemu_real_host_page_size.
92 bitmap
->pgsize
= qemu_real_host_page_size();
93 bitmap
->size
= vbmap
.size
;
94 bitmap
->data
= (__u64
*)vbmap
.bitmap
;
96 if (vbmap
.size
> bcontainer
->max_dirty_bitmap_size
) {
97 error_report("UNMAP: Size of bitmap too big 0x%"PRIx64
, vbmap
.size
);
102 ret
= ioctl(container
->fd
, VFIO_IOMMU_UNMAP_DMA
, unmap
);
104 cpu_physical_memory_set_dirty_lebitmap(vbmap
.bitmap
,
105 iotlb
->translated_addr
, vbmap
.pages
);
107 error_report("VFIO_UNMAP_DMA with DIRTY_BITMAP : %m");
112 g_free(vbmap
.bitmap
);
118 * DMA - Mapping and unmapping for the "type1" IOMMU interface used on x86
120 static int vfio_legacy_dma_unmap(const VFIOContainerBase
*bcontainer
,
121 hwaddr iova
, ram_addr_t size
,
122 IOMMUTLBEntry
*iotlb
)
124 const VFIOContainer
*container
= container_of(bcontainer
, VFIOContainer
,
126 struct vfio_iommu_type1_dma_unmap unmap
= {
127 .argsz
= sizeof(unmap
),
132 bool need_dirty_sync
= false;
135 if (iotlb
&& vfio_devices_all_running_and_mig_active(bcontainer
)) {
136 if (!vfio_devices_all_device_dirty_tracking(bcontainer
) &&
137 bcontainer
->dirty_pages_supported
) {
138 return vfio_dma_unmap_bitmap(container
, iova
, size
, iotlb
);
141 need_dirty_sync
= true;
144 while (ioctl(container
->fd
, VFIO_IOMMU_UNMAP_DMA
, &unmap
)) {
146 * The type1 backend has an off-by-one bug in the kernel (71a7d3d78e3c
147 * v4.15) where an overflow in its wrap-around check prevents us from
148 * unmapping the last page of the address space. Test for the error
149 * condition and re-try the unmap excluding the last page. The
150 * expectation is that we've never mapped the last page anyway and this
151 * unmap request comes via vIOMMU support which also makes it unlikely
152 * that this page is used. This bug was introduced well after type1 v2
153 * support was introduced, so we shouldn't need to test for v1. A fix
154 * is queued for kernel v5.0 so this workaround can be removed once
155 * affected kernels are sufficiently deprecated.
157 if (errno
== EINVAL
&& unmap
.size
&& !(unmap
.iova
+ unmap
.size
) &&
158 container
->iommu_type
== VFIO_TYPE1v2_IOMMU
) {
159 trace_vfio_legacy_dma_unmap_overflow_workaround();
160 unmap
.size
-= 1ULL << ctz64(bcontainer
->pgsizes
);
163 error_report("VFIO_UNMAP_DMA failed: %s", strerror(errno
));
167 if (need_dirty_sync
) {
168 ret
= vfio_get_dirty_bitmap(bcontainer
, iova
, size
,
169 iotlb
->translated_addr
);
178 static int vfio_legacy_dma_map(const VFIOContainerBase
*bcontainer
, hwaddr iova
,
179 ram_addr_t size
, void *vaddr
, bool readonly
)
181 const VFIOContainer
*container
= container_of(bcontainer
, VFIOContainer
,
183 struct vfio_iommu_type1_dma_map map
= {
184 .argsz
= sizeof(map
),
185 .flags
= VFIO_DMA_MAP_FLAG_READ
,
186 .vaddr
= (__u64
)(uintptr_t)vaddr
,
192 map
.flags
|= VFIO_DMA_MAP_FLAG_WRITE
;
196 * Try the mapping, if it fails with EBUSY, unmap the region and try
197 * again. This shouldn't be necessary, but we sometimes see it in
200 if (ioctl(container
->fd
, VFIO_IOMMU_MAP_DMA
, &map
) == 0 ||
202 vfio_legacy_dma_unmap(bcontainer
, iova
, size
, NULL
) == 0 &&
203 ioctl(container
->fd
, VFIO_IOMMU_MAP_DMA
, &map
) == 0)) {
207 error_report("VFIO_MAP_DMA failed: %s", strerror(errno
));
212 vfio_legacy_set_dirty_page_tracking(const VFIOContainerBase
*bcontainer
,
215 const VFIOContainer
*container
= container_of(bcontainer
, VFIOContainer
,
218 struct vfio_iommu_type1_dirty_bitmap dirty
= {
219 .argsz
= sizeof(dirty
),
223 dirty
.flags
= VFIO_IOMMU_DIRTY_PAGES_FLAG_START
;
225 dirty
.flags
= VFIO_IOMMU_DIRTY_PAGES_FLAG_STOP
;
228 ret
= ioctl(container
->fd
, VFIO_IOMMU_DIRTY_PAGES
, &dirty
);
231 error_report("Failed to set dirty tracking flag 0x%x errno: %d",
238 static int vfio_legacy_query_dirty_bitmap(const VFIOContainerBase
*bcontainer
,
240 hwaddr iova
, hwaddr size
)
242 const VFIOContainer
*container
= container_of(bcontainer
, VFIOContainer
,
244 struct vfio_iommu_type1_dirty_bitmap
*dbitmap
;
245 struct vfio_iommu_type1_dirty_bitmap_get
*range
;
248 dbitmap
= g_malloc0(sizeof(*dbitmap
) + sizeof(*range
));
250 dbitmap
->argsz
= sizeof(*dbitmap
) + sizeof(*range
);
251 dbitmap
->flags
= VFIO_IOMMU_DIRTY_PAGES_FLAG_GET_BITMAP
;
252 range
= (struct vfio_iommu_type1_dirty_bitmap_get
*)&dbitmap
->data
;
257 * cpu_physical_memory_set_dirty_lebitmap() supports pages in bitmap of
258 * qemu_real_host_page_size to mark those dirty. Hence set bitmap's pgsize
259 * to qemu_real_host_page_size.
261 range
->bitmap
.pgsize
= qemu_real_host_page_size();
262 range
->bitmap
.size
= vbmap
->size
;
263 range
->bitmap
.data
= (__u64
*)vbmap
->bitmap
;
265 ret
= ioctl(container
->fd
, VFIO_IOMMU_DIRTY_PAGES
, dbitmap
);
268 error_report("Failed to get dirty bitmap for iova: 0x%"PRIx64
269 " size: 0x%"PRIx64
" err: %d", (uint64_t)range
->iova
,
270 (uint64_t)range
->size
, errno
);
278 static struct vfio_info_cap_header
*
279 vfio_get_iommu_type1_info_cap(struct vfio_iommu_type1_info
*info
, uint16_t id
)
281 if (!(info
->flags
& VFIO_IOMMU_INFO_CAPS
)) {
285 return vfio_get_cap((void *)info
, info
->cap_offset
, id
);
288 bool vfio_get_info_dma_avail(struct vfio_iommu_type1_info
*info
,
291 struct vfio_info_cap_header
*hdr
;
292 struct vfio_iommu_type1_info_dma_avail
*cap
;
294 /* If the capability cannot be found, assume no DMA limiting */
295 hdr
= vfio_get_iommu_type1_info_cap(info
,
296 VFIO_IOMMU_TYPE1_INFO_DMA_AVAIL
);
309 static bool vfio_get_info_iova_range(struct vfio_iommu_type1_info
*info
,
310 VFIOContainerBase
*bcontainer
)
312 struct vfio_info_cap_header
*hdr
;
313 struct vfio_iommu_type1_info_cap_iova_range
*cap
;
315 hdr
= vfio_get_iommu_type1_info_cap(info
,
316 VFIO_IOMMU_TYPE1_INFO_CAP_IOVA_RANGE
);
323 for (int i
= 0; i
< cap
->nr_iovas
; i
++) {
324 Range
*range
= g_new(Range
, 1);
326 range_set_bounds(range
, cap
->iova_ranges
[i
].start
,
327 cap
->iova_ranges
[i
].end
);
328 bcontainer
->iova_ranges
=
329 range_list_insert(bcontainer
->iova_ranges
, range
);
335 static void vfio_kvm_device_add_group(VFIOGroup
*group
)
339 if (vfio_kvm_device_add_fd(group
->fd
, &err
)) {
340 error_reportf_err(err
, "group ID %d: ", group
->groupid
);
344 static void vfio_kvm_device_del_group(VFIOGroup
*group
)
348 if (vfio_kvm_device_del_fd(group
->fd
, &err
)) {
349 error_reportf_err(err
, "group ID %d: ", group
->groupid
);
354 * vfio_get_iommu_type - selects the richest iommu_type (v2 first)
356 static int vfio_get_iommu_type(VFIOContainer
*container
,
359 int iommu_types
[] = { VFIO_TYPE1v2_IOMMU
, VFIO_TYPE1_IOMMU
,
360 VFIO_SPAPR_TCE_v2_IOMMU
, VFIO_SPAPR_TCE_IOMMU
};
363 for (i
= 0; i
< ARRAY_SIZE(iommu_types
); i
++) {
364 if (ioctl(container
->fd
, VFIO_CHECK_EXTENSION
, iommu_types
[i
])) {
365 return iommu_types
[i
];
368 error_setg(errp
, "No available IOMMU models");
372 static int vfio_init_container(VFIOContainer
*container
, int group_fd
,
377 iommu_type
= vfio_get_iommu_type(container
, errp
);
378 if (iommu_type
< 0) {
382 ret
= ioctl(group_fd
, VFIO_GROUP_SET_CONTAINER
, &container
->fd
);
384 error_setg_errno(errp
, errno
, "Failed to set group container");
388 while (ioctl(container
->fd
, VFIO_SET_IOMMU
, iommu_type
)) {
389 if (iommu_type
== VFIO_SPAPR_TCE_v2_IOMMU
) {
391 * On sPAPR, despite the IOMMU subdriver always advertises v1 and
392 * v2, the running platform may not support v2 and there is no
393 * way to guess it until an IOMMU group gets added to the container.
394 * So in case it fails with v2, try v1 as a fallback.
396 iommu_type
= VFIO_SPAPR_TCE_IOMMU
;
399 error_setg_errno(errp
, errno
, "Failed to set iommu for container");
403 container
->iommu_type
= iommu_type
;
407 static int vfio_get_iommu_info(VFIOContainer
*container
,
408 struct vfio_iommu_type1_info
**info
)
411 size_t argsz
= sizeof(struct vfio_iommu_type1_info
);
413 *info
= g_new0(struct vfio_iommu_type1_info
, 1);
415 (*info
)->argsz
= argsz
;
417 if (ioctl(container
->fd
, VFIO_IOMMU_GET_INFO
, *info
)) {
423 if (((*info
)->argsz
> argsz
)) {
424 argsz
= (*info
)->argsz
;
425 *info
= g_realloc(*info
, argsz
);
432 static struct vfio_info_cap_header
*
433 vfio_get_iommu_info_cap(struct vfio_iommu_type1_info
*info
, uint16_t id
)
435 struct vfio_info_cap_header
*hdr
;
438 if (!(info
->flags
& VFIO_IOMMU_INFO_CAPS
)) {
442 for (hdr
= ptr
+ info
->cap_offset
; hdr
!= ptr
; hdr
= ptr
+ hdr
->next
) {
451 static void vfio_get_iommu_info_migration(VFIOContainer
*container
,
452 struct vfio_iommu_type1_info
*info
)
454 struct vfio_info_cap_header
*hdr
;
455 struct vfio_iommu_type1_info_cap_migration
*cap_mig
;
456 VFIOContainerBase
*bcontainer
= &container
->bcontainer
;
458 hdr
= vfio_get_iommu_info_cap(info
, VFIO_IOMMU_TYPE1_INFO_CAP_MIGRATION
);
463 cap_mig
= container_of(hdr
, struct vfio_iommu_type1_info_cap_migration
,
467 * cpu_physical_memory_set_dirty_lebitmap() supports pages in bitmap of
468 * qemu_real_host_page_size to mark those dirty.
470 if (cap_mig
->pgsize_bitmap
& qemu_real_host_page_size()) {
471 bcontainer
->dirty_pages_supported
= true;
472 bcontainer
->max_dirty_bitmap_size
= cap_mig
->max_dirty_bitmap_size
;
473 bcontainer
->dirty_pgsizes
= cap_mig
->pgsize_bitmap
;
477 static int vfio_connect_container(VFIOGroup
*group
, AddressSpace
*as
,
480 VFIOContainer
*container
;
481 VFIOContainerBase
*bcontainer
;
483 VFIOAddressSpace
*space
;
485 space
= vfio_get_address_space(as
);
488 * VFIO is currently incompatible with discarding of RAM insofar as the
489 * madvise to purge (zap) the page from QEMU's address space does not
490 * interact with the memory API and therefore leaves stale virtual to
491 * physical mappings in the IOMMU if the page was previously pinned. We
492 * therefore set discarding broken for each group added to a container,
493 * whether the container is used individually or shared. This provides
494 * us with options to allow devices within a group to opt-in and allow
495 * discarding, so long as it is done consistently for a group (for instance
496 * if the device is an mdev device where it is known that the host vendor
497 * driver will never pin pages outside of the working set of the guest
498 * driver, which would thus not be discarding candidates).
500 * The first opportunity to induce pinning occurs here where we attempt to
501 * attach the group to existing containers within the AddressSpace. If any
502 * pages are already zapped from the virtual address space, such as from
503 * previous discards, new pinning will cause valid mappings to be
504 * re-established. Likewise, when the overall MemoryListener for a new
505 * container is registered, a replay of mappings within the AddressSpace
506 * will occur, re-establishing any previously zapped pages as well.
508 * Especially virtio-balloon is currently only prevented from discarding
509 * new memory, it will not yet set ram_block_discard_set_required() and
510 * therefore, neither stops us here or deals with the sudden memory
511 * consumption of inflated memory.
513 * We do support discarding of memory coordinated via the RamDiscardManager
514 * with some IOMMU types. vfio_ram_block_discard_disable() handles the
515 * details once we know which type of IOMMU we are using.
518 QLIST_FOREACH(bcontainer
, &space
->containers
, next
) {
519 container
= container_of(bcontainer
, VFIOContainer
, bcontainer
);
520 if (!ioctl(group
->fd
, VFIO_GROUP_SET_CONTAINER
, &container
->fd
)) {
521 ret
= vfio_ram_block_discard_disable(container
, true);
523 error_setg_errno(errp
, -ret
,
524 "Cannot set discarding of RAM broken");
525 if (ioctl(group
->fd
, VFIO_GROUP_UNSET_CONTAINER
,
527 error_report("vfio: error disconnecting group %d from"
528 " container", group
->groupid
);
532 group
->container
= container
;
533 QLIST_INSERT_HEAD(&container
->group_list
, group
, container_next
);
534 vfio_kvm_device_add_group(group
);
539 fd
= qemu_open_old("/dev/vfio/vfio", O_RDWR
);
541 error_setg_errno(errp
, errno
, "failed to open /dev/vfio/vfio");
546 ret
= ioctl(fd
, VFIO_GET_API_VERSION
);
547 if (ret
!= VFIO_API_VERSION
) {
548 error_setg(errp
, "supported vfio version: %d, "
549 "reported version: %d", VFIO_API_VERSION
, ret
);
554 container
= g_malloc0(sizeof(*container
));
556 bcontainer
= &container
->bcontainer
;
557 vfio_container_init(bcontainer
, space
, &vfio_legacy_ops
);
559 ret
= vfio_init_container(container
, group
->fd
, errp
);
561 goto free_container_exit
;
564 ret
= vfio_ram_block_discard_disable(container
, true);
566 error_setg_errno(errp
, -ret
, "Cannot set discarding of RAM broken");
567 goto free_container_exit
;
570 switch (container
->iommu_type
) {
571 case VFIO_TYPE1v2_IOMMU
:
572 case VFIO_TYPE1_IOMMU
:
574 struct vfio_iommu_type1_info
*info
;
576 ret
= vfio_get_iommu_info(container
, &info
);
578 error_setg_errno(errp
, -ret
, "Failed to get VFIO IOMMU info");
579 goto enable_discards_exit
;
582 if (info
->flags
& VFIO_IOMMU_INFO_PGSIZES
) {
583 bcontainer
->pgsizes
= info
->iova_pgsizes
;
585 bcontainer
->pgsizes
= qemu_real_host_page_size();
588 if (!vfio_get_info_dma_avail(info
, &bcontainer
->dma_max_mappings
)) {
589 bcontainer
->dma_max_mappings
= 65535;
592 vfio_get_info_iova_range(info
, bcontainer
);
594 vfio_get_iommu_info_migration(container
, info
);
598 case VFIO_SPAPR_TCE_v2_IOMMU
:
599 case VFIO_SPAPR_TCE_IOMMU
:
601 ret
= vfio_spapr_container_init(container
, errp
);
603 goto enable_discards_exit
;
609 vfio_kvm_device_add_group(group
);
611 QLIST_INIT(&container
->group_list
);
612 QLIST_INSERT_HEAD(&space
->containers
, bcontainer
, next
);
614 group
->container
= container
;
615 QLIST_INSERT_HEAD(&container
->group_list
, group
, container_next
);
617 bcontainer
->listener
= vfio_memory_listener
;
618 memory_listener_register(&bcontainer
->listener
, bcontainer
->space
->as
);
620 if (bcontainer
->error
) {
622 error_propagate_prepend(errp
, bcontainer
->error
,
623 "memory listener initialization failed: ");
624 goto listener_release_exit
;
627 bcontainer
->initialized
= true;
630 listener_release_exit
:
631 QLIST_REMOVE(group
, container_next
);
632 QLIST_REMOVE(bcontainer
, next
);
633 vfio_kvm_device_del_group(group
);
634 memory_listener_unregister(&bcontainer
->listener
);
635 if (container
->iommu_type
== VFIO_SPAPR_TCE_v2_IOMMU
||
636 container
->iommu_type
== VFIO_SPAPR_TCE_IOMMU
) {
637 vfio_spapr_container_deinit(container
);
640 enable_discards_exit
:
641 vfio_ram_block_discard_disable(container
, false);
650 vfio_put_address_space(space
);
655 static void vfio_disconnect_container(VFIOGroup
*group
)
657 VFIOContainer
*container
= group
->container
;
658 VFIOContainerBase
*bcontainer
= &container
->bcontainer
;
660 QLIST_REMOVE(group
, container_next
);
661 group
->container
= NULL
;
664 * Explicitly release the listener first before unset container,
665 * since unset may destroy the backend container if it's the last
668 if (QLIST_EMPTY(&container
->group_list
)) {
669 memory_listener_unregister(&bcontainer
->listener
);
670 if (container
->iommu_type
== VFIO_SPAPR_TCE_v2_IOMMU
||
671 container
->iommu_type
== VFIO_SPAPR_TCE_IOMMU
) {
672 vfio_spapr_container_deinit(container
);
676 if (ioctl(group
->fd
, VFIO_GROUP_UNSET_CONTAINER
, &container
->fd
)) {
677 error_report("vfio: error disconnecting group %d from container",
681 if (QLIST_EMPTY(&container
->group_list
)) {
682 VFIOAddressSpace
*space
= bcontainer
->space
;
684 vfio_container_destroy(bcontainer
);
686 trace_vfio_disconnect_container(container
->fd
);
687 close(container
->fd
);
690 vfio_put_address_space(space
);
694 static VFIOGroup
*vfio_get_group(int groupid
, AddressSpace
*as
, Error
**errp
)
698 struct vfio_group_status status
= { .argsz
= sizeof(status
) };
700 QLIST_FOREACH(group
, &vfio_group_list
, next
) {
701 if (group
->groupid
== groupid
) {
702 /* Found it. Now is it already in the right context? */
703 if (group
->container
->bcontainer
.space
->as
== as
) {
706 error_setg(errp
, "group %d used in multiple address spaces",
713 group
= g_malloc0(sizeof(*group
));
715 snprintf(path
, sizeof(path
), "/dev/vfio/%d", groupid
);
716 group
->fd
= qemu_open_old(path
, O_RDWR
);
718 error_setg_errno(errp
, errno
, "failed to open %s", path
);
719 goto free_group_exit
;
722 if (ioctl(group
->fd
, VFIO_GROUP_GET_STATUS
, &status
)) {
723 error_setg_errno(errp
, errno
, "failed to get group %d status", groupid
);
727 if (!(status
.flags
& VFIO_GROUP_FLAGS_VIABLE
)) {
728 error_setg(errp
, "group %d is not viable", groupid
);
729 error_append_hint(errp
,
730 "Please ensure all devices within the iommu_group "
731 "are bound to their vfio bus driver.\n");
735 group
->groupid
= groupid
;
736 QLIST_INIT(&group
->device_list
);
738 if (vfio_connect_container(group
, as
, errp
)) {
739 error_prepend(errp
, "failed to setup container for group %d: ",
744 QLIST_INSERT_HEAD(&vfio_group_list
, group
, next
);
757 static void vfio_put_group(VFIOGroup
*group
)
759 if (!group
|| !QLIST_EMPTY(&group
->device_list
)) {
763 if (!group
->ram_block_discard_allowed
) {
764 vfio_ram_block_discard_disable(group
->container
, false);
766 vfio_kvm_device_del_group(group
);
767 vfio_disconnect_container(group
);
768 QLIST_REMOVE(group
, next
);
769 trace_vfio_put_group(group
->fd
);
774 static int vfio_get_device(VFIOGroup
*group
, const char *name
,
775 VFIODevice
*vbasedev
, Error
**errp
)
777 g_autofree
struct vfio_device_info
*info
= NULL
;
780 fd
= ioctl(group
->fd
, VFIO_GROUP_GET_DEVICE_FD
, name
);
782 error_setg_errno(errp
, errno
, "error getting device from group %d",
784 error_append_hint(errp
,
785 "Verify all devices in group %d are bound to vfio-<bus> "
786 "or pci-stub and not already in use\n", group
->groupid
);
790 info
= vfio_get_device_info(fd
);
792 error_setg_errno(errp
, errno
, "error getting device info");
798 * Set discarding of RAM as not broken for this group if the driver knows
799 * the device operates compatibly with discarding. Setting must be
800 * consistent per group, but since compatibility is really only possible
801 * with mdev currently, we expect singleton groups.
803 if (vbasedev
->ram_block_discard_allowed
!=
804 group
->ram_block_discard_allowed
) {
805 if (!QLIST_EMPTY(&group
->device_list
)) {
806 error_setg(errp
, "Inconsistent setting of support for discarding "
807 "RAM (e.g., balloon) within group");
812 if (!group
->ram_block_discard_allowed
) {
813 group
->ram_block_discard_allowed
= true;
814 vfio_ram_block_discard_disable(group
->container
, false);
819 vbasedev
->group
= group
;
820 QLIST_INSERT_HEAD(&group
->device_list
, vbasedev
, next
);
822 vbasedev
->num_irqs
= info
->num_irqs
;
823 vbasedev
->num_regions
= info
->num_regions
;
824 vbasedev
->flags
= info
->flags
;
826 trace_vfio_get_device(name
, info
->flags
, info
->num_regions
, info
->num_irqs
);
828 vbasedev
->reset_works
= !!(info
->flags
& VFIO_DEVICE_FLAGS_RESET
);
833 static void vfio_put_base_device(VFIODevice
*vbasedev
)
835 if (!vbasedev
->group
) {
838 QLIST_REMOVE(vbasedev
, next
);
839 vbasedev
->group
= NULL
;
840 trace_vfio_put_base_device(vbasedev
->fd
);
844 static int vfio_device_groupid(VFIODevice
*vbasedev
, Error
**errp
)
846 char *tmp
, group_path
[PATH_MAX
], *group_name
;
850 tmp
= g_strdup_printf("%s/iommu_group", vbasedev
->sysfsdev
);
851 len
= readlink(tmp
, group_path
, sizeof(group_path
));
854 if (len
<= 0 || len
>= sizeof(group_path
)) {
855 ret
= len
< 0 ? -errno
: -ENAMETOOLONG
;
856 error_setg_errno(errp
, -ret
, "no iommu_group found");
862 group_name
= basename(group_path
);
863 if (sscanf(group_name
, "%d", &groupid
) != 1) {
864 error_setg_errno(errp
, errno
, "failed to read %s", group_path
);
871 * vfio_attach_device: attach a device to a security context
872 * @name and @vbasedev->name are likely to be different depending
873 * on the type of the device, hence the need for passing @name
875 static int vfio_legacy_attach_device(const char *name
, VFIODevice
*vbasedev
,
876 AddressSpace
*as
, Error
**errp
)
878 int groupid
= vfio_device_groupid(vbasedev
, errp
);
879 VFIODevice
*vbasedev_iter
;
881 VFIOContainerBase
*bcontainer
;
888 trace_vfio_attach_device(vbasedev
->name
, groupid
);
890 group
= vfio_get_group(groupid
, as
, errp
);
895 QLIST_FOREACH(vbasedev_iter
, &group
->device_list
, next
) {
896 if (strcmp(vbasedev_iter
->name
, vbasedev
->name
) == 0) {
897 error_setg(errp
, "device is already attached");
898 vfio_put_group(group
);
902 ret
= vfio_get_device(group
, name
, vbasedev
, errp
);
904 vfio_put_group(group
);
908 bcontainer
= &group
->container
->bcontainer
;
909 vbasedev
->bcontainer
= bcontainer
;
910 QLIST_INSERT_HEAD(&bcontainer
->device_list
, vbasedev
, container_next
);
911 QLIST_INSERT_HEAD(&vfio_device_list
, vbasedev
, global_next
);
916 static void vfio_legacy_detach_device(VFIODevice
*vbasedev
)
918 VFIOGroup
*group
= vbasedev
->group
;
920 QLIST_REMOVE(vbasedev
, global_next
);
921 QLIST_REMOVE(vbasedev
, container_next
);
922 vbasedev
->bcontainer
= NULL
;
923 trace_vfio_detach_device(vbasedev
->name
, group
->groupid
);
924 vfio_put_base_device(vbasedev
);
925 vfio_put_group(group
);
928 static int vfio_legacy_pci_hot_reset(VFIODevice
*vbasedev
, bool single
)
930 VFIOPCIDevice
*vdev
= container_of(vbasedev
, VFIOPCIDevice
, vbasedev
);
932 struct vfio_pci_hot_reset_info
*info
= NULL
;
933 struct vfio_pci_dependent_device
*devices
;
934 struct vfio_pci_hot_reset
*reset
;
939 trace_vfio_pci_hot_reset(vdev
->vbasedev
.name
, single
? "one" : "multi");
942 vfio_pci_pre_reset(vdev
);
944 vdev
->vbasedev
.needs_reset
= false;
946 ret
= vfio_pci_get_pci_hot_reset_info(vdev
, &info
);
951 devices
= &info
->devices
[0];
953 trace_vfio_pci_hot_reset_has_dep_devices(vdev
->vbasedev
.name
);
955 /* Verify that we have all the groups required */
956 for (i
= 0; i
< info
->count
; i
++) {
957 PCIHostDeviceAddress host
;
959 VFIODevice
*vbasedev_iter
;
961 host
.domain
= devices
[i
].segment
;
962 host
.bus
= devices
[i
].bus
;
963 host
.slot
= PCI_SLOT(devices
[i
].devfn
);
964 host
.function
= PCI_FUNC(devices
[i
].devfn
);
966 trace_vfio_pci_hot_reset_dep_devices(host
.domain
,
967 host
.bus
, host
.slot
, host
.function
, devices
[i
].group_id
);
969 if (vfio_pci_host_match(&host
, vdev
->vbasedev
.name
)) {
973 QLIST_FOREACH(group
, &vfio_group_list
, next
) {
974 if (group
->groupid
== devices
[i
].group_id
) {
980 if (!vdev
->has_pm_reset
) {
981 error_report("vfio: Cannot reset device %s, "
982 "depends on group %d which is not owned.",
983 vdev
->vbasedev
.name
, devices
[i
].group_id
);
989 /* Prep dependent devices for reset and clear our marker. */
990 QLIST_FOREACH(vbasedev_iter
, &group
->device_list
, next
) {
991 if (!vbasedev_iter
->dev
->realized
||
992 vbasedev_iter
->type
!= VFIO_DEVICE_TYPE_PCI
) {
995 tmp
= container_of(vbasedev_iter
, VFIOPCIDevice
, vbasedev
);
996 if (vfio_pci_host_match(&host
, tmp
->vbasedev
.name
)) {
1001 vfio_pci_pre_reset(tmp
);
1002 tmp
->vbasedev
.needs_reset
= false;
1009 if (!single
&& !multi
) {
1014 /* Determine how many group fds need to be passed */
1016 QLIST_FOREACH(group
, &vfio_group_list
, next
) {
1017 for (i
= 0; i
< info
->count
; i
++) {
1018 if (group
->groupid
== devices
[i
].group_id
) {
1025 reset
= g_malloc0(sizeof(*reset
) + (count
* sizeof(*fds
)));
1026 reset
->argsz
= sizeof(*reset
) + (count
* sizeof(*fds
));
1027 fds
= &reset
->group_fds
[0];
1029 /* Fill in group fds */
1030 QLIST_FOREACH(group
, &vfio_group_list
, next
) {
1031 for (i
= 0; i
< info
->count
; i
++) {
1032 if (group
->groupid
== devices
[i
].group_id
) {
1033 fds
[reset
->count
++] = group
->fd
;
1040 ret
= ioctl(vdev
->vbasedev
.fd
, VFIO_DEVICE_PCI_HOT_RESET
, reset
);
1046 trace_vfio_pci_hot_reset_result(vdev
->vbasedev
.name
,
1047 ret
? strerror(errno
) : "Success");
1050 /* Re-enable INTx on affected devices */
1051 for (i
= 0; i
< info
->count
; i
++) {
1052 PCIHostDeviceAddress host
;
1054 VFIODevice
*vbasedev_iter
;
1056 host
.domain
= devices
[i
].segment
;
1057 host
.bus
= devices
[i
].bus
;
1058 host
.slot
= PCI_SLOT(devices
[i
].devfn
);
1059 host
.function
= PCI_FUNC(devices
[i
].devfn
);
1061 if (vfio_pci_host_match(&host
, vdev
->vbasedev
.name
)) {
1065 QLIST_FOREACH(group
, &vfio_group_list
, next
) {
1066 if (group
->groupid
== devices
[i
].group_id
) {
1075 QLIST_FOREACH(vbasedev_iter
, &group
->device_list
, next
) {
1076 if (!vbasedev_iter
->dev
->realized
||
1077 vbasedev_iter
->type
!= VFIO_DEVICE_TYPE_PCI
) {
1080 tmp
= container_of(vbasedev_iter
, VFIOPCIDevice
, vbasedev
);
1081 if (vfio_pci_host_match(&host
, tmp
->vbasedev
.name
)) {
1082 vfio_pci_post_reset(tmp
);
1089 vfio_pci_post_reset(vdev
);
1096 const VFIOIOMMUOps vfio_legacy_ops
= {
1097 .dma_map
= vfio_legacy_dma_map
,
1098 .dma_unmap
= vfio_legacy_dma_unmap
,
1099 .attach_device
= vfio_legacy_attach_device
,
1100 .detach_device
= vfio_legacy_detach_device
,
1101 .set_dirty_page_tracking
= vfio_legacy_set_dirty_page_tracking
,
1102 .query_dirty_bitmap
= vfio_legacy_query_dirty_bitmap
,
1103 .pci_hot_reset
= vfio_legacy_pci_hot_reset
,