Linux 5.1.15
[linux/fpc-iii.git] / drivers / iommu / intel-iommu.c
blob0feb3f70da16aebf5b9a59d7b1be8c4d9c200818
1 /*
2 * Copyright © 2006-2014 Intel Corporation.
4 * This program is free software; you can redistribute it and/or modify it
5 * under the terms and conditions of the GNU General Public License,
6 * version 2, as published by the Free Software Foundation.
8 * This program is distributed in the hope it will be useful, but WITHOUT
9 * ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
10 * FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for
11 * more details.
13 * Authors: David Woodhouse <dwmw2@infradead.org>,
14 * Ashok Raj <ashok.raj@intel.com>,
15 * Shaohua Li <shaohua.li@intel.com>,
16 * Anil S Keshavamurthy <anil.s.keshavamurthy@intel.com>,
17 * Fenghua Yu <fenghua.yu@intel.com>
18 * Joerg Roedel <jroedel@suse.de>
21 #define pr_fmt(fmt) "DMAR: " fmt
22 #define dev_fmt(fmt) pr_fmt(fmt)
24 #include <linux/init.h>
25 #include <linux/bitmap.h>
26 #include <linux/debugfs.h>
27 #include <linux/export.h>
28 #include <linux/slab.h>
29 #include <linux/irq.h>
30 #include <linux/interrupt.h>
31 #include <linux/spinlock.h>
32 #include <linux/pci.h>
33 #include <linux/dmar.h>
34 #include <linux/dma-mapping.h>
35 #include <linux/mempool.h>
36 #include <linux/memory.h>
37 #include <linux/cpu.h>
38 #include <linux/timer.h>
39 #include <linux/io.h>
40 #include <linux/iova.h>
41 #include <linux/iommu.h>
42 #include <linux/intel-iommu.h>
43 #include <linux/syscore_ops.h>
44 #include <linux/tboot.h>
45 #include <linux/dmi.h>
46 #include <linux/pci-ats.h>
47 #include <linux/memblock.h>
48 #include <linux/dma-contiguous.h>
49 #include <linux/dma-direct.h>
50 #include <linux/crash_dump.h>
51 #include <linux/numa.h>
52 #include <asm/irq_remapping.h>
53 #include <asm/cacheflush.h>
54 #include <asm/iommu.h>
56 #include "irq_remapping.h"
57 #include "intel-pasid.h"
59 #define ROOT_SIZE VTD_PAGE_SIZE
60 #define CONTEXT_SIZE VTD_PAGE_SIZE
62 #define IS_GFX_DEVICE(pdev) ((pdev->class >> 16) == PCI_BASE_CLASS_DISPLAY)
63 #define IS_USB_DEVICE(pdev) ((pdev->class >> 8) == PCI_CLASS_SERIAL_USB)
64 #define IS_ISA_DEVICE(pdev) ((pdev->class >> 8) == PCI_CLASS_BRIDGE_ISA)
65 #define IS_AZALIA(pdev) ((pdev)->vendor == 0x8086 && (pdev)->device == 0x3a3e)
67 #define IOAPIC_RANGE_START (0xfee00000)
68 #define IOAPIC_RANGE_END (0xfeefffff)
69 #define IOVA_START_ADDR (0x1000)
71 #define DEFAULT_DOMAIN_ADDRESS_WIDTH 57
73 #define MAX_AGAW_WIDTH 64
74 #define MAX_AGAW_PFN_WIDTH (MAX_AGAW_WIDTH - VTD_PAGE_SHIFT)
76 #define __DOMAIN_MAX_PFN(gaw) ((((uint64_t)1) << (gaw-VTD_PAGE_SHIFT)) - 1)
77 #define __DOMAIN_MAX_ADDR(gaw) ((((uint64_t)1) << gaw) - 1)
79 /* We limit DOMAIN_MAX_PFN to fit in an unsigned long, and DOMAIN_MAX_ADDR
80 to match. That way, we can use 'unsigned long' for PFNs with impunity. */
81 #define DOMAIN_MAX_PFN(gaw) ((unsigned long) min_t(uint64_t, \
82 __DOMAIN_MAX_PFN(gaw), (unsigned long)-1))
83 #define DOMAIN_MAX_ADDR(gaw) (((uint64_t)__DOMAIN_MAX_PFN(gaw)) << VTD_PAGE_SHIFT)
85 /* IO virtual address start page frame number */
86 #define IOVA_START_PFN (1)
88 #define IOVA_PFN(addr) ((addr) >> PAGE_SHIFT)
90 /* page table handling */
91 #define LEVEL_STRIDE (9)
92 #define LEVEL_MASK (((u64)1 << LEVEL_STRIDE) - 1)
95 * This bitmap is used to advertise the page sizes our hardware support
96 * to the IOMMU core, which will then use this information to split
97 * physically contiguous memory regions it is mapping into page sizes
98 * that we support.
100 * Traditionally the IOMMU core just handed us the mappings directly,
101 * after making sure the size is an order of a 4KiB page and that the
102 * mapping has natural alignment.
104 * To retain this behavior, we currently advertise that we support
105 * all page sizes that are an order of 4KiB.
107 * If at some point we'd like to utilize the IOMMU core's new behavior,
108 * we could change this to advertise the real page sizes we support.
110 #define INTEL_IOMMU_PGSIZES (~0xFFFUL)
112 static inline int agaw_to_level(int agaw)
114 return agaw + 2;
117 static inline int agaw_to_width(int agaw)
119 return min_t(int, 30 + agaw * LEVEL_STRIDE, MAX_AGAW_WIDTH);
122 static inline int width_to_agaw(int width)
124 return DIV_ROUND_UP(width - 30, LEVEL_STRIDE);
127 static inline unsigned int level_to_offset_bits(int level)
129 return (level - 1) * LEVEL_STRIDE;
132 static inline int pfn_level_offset(unsigned long pfn, int level)
134 return (pfn >> level_to_offset_bits(level)) & LEVEL_MASK;
137 static inline unsigned long level_mask(int level)
139 return -1UL << level_to_offset_bits(level);
142 static inline unsigned long level_size(int level)
144 return 1UL << level_to_offset_bits(level);
147 static inline unsigned long align_to_level(unsigned long pfn, int level)
149 return (pfn + level_size(level) - 1) & level_mask(level);
152 static inline unsigned long lvl_to_nr_pages(unsigned int lvl)
154 return 1 << min_t(int, (lvl - 1) * LEVEL_STRIDE, MAX_AGAW_PFN_WIDTH);
157 /* VT-d pages must always be _smaller_ than MM pages. Otherwise things
158 are never going to work. */
159 static inline unsigned long dma_to_mm_pfn(unsigned long dma_pfn)
161 return dma_pfn >> (PAGE_SHIFT - VTD_PAGE_SHIFT);
164 static inline unsigned long mm_to_dma_pfn(unsigned long mm_pfn)
166 return mm_pfn << (PAGE_SHIFT - VTD_PAGE_SHIFT);
168 static inline unsigned long page_to_dma_pfn(struct page *pg)
170 return mm_to_dma_pfn(page_to_pfn(pg));
172 static inline unsigned long virt_to_dma_pfn(void *p)
174 return page_to_dma_pfn(virt_to_page(p));
177 /* global iommu list, set NULL for ignored DMAR units */
178 static struct intel_iommu **g_iommus;
180 static void __init check_tylersburg_isoch(void);
181 static int rwbf_quirk;
184 * set to 1 to panic kernel if can't successfully enable VT-d
185 * (used when kernel is launched w/ TXT)
187 static int force_on = 0;
188 int intel_iommu_tboot_noforce;
189 static int no_platform_optin;
191 #define ROOT_ENTRY_NR (VTD_PAGE_SIZE/sizeof(struct root_entry))
194 * Take a root_entry and return the Lower Context Table Pointer (LCTP)
195 * if marked present.
197 static phys_addr_t root_entry_lctp(struct root_entry *re)
199 if (!(re->lo & 1))
200 return 0;
202 return re->lo & VTD_PAGE_MASK;
206 * Take a root_entry and return the Upper Context Table Pointer (UCTP)
207 * if marked present.
209 static phys_addr_t root_entry_uctp(struct root_entry *re)
211 if (!(re->hi & 1))
212 return 0;
214 return re->hi & VTD_PAGE_MASK;
217 static inline void context_clear_pasid_enable(struct context_entry *context)
219 context->lo &= ~(1ULL << 11);
222 static inline bool context_pasid_enabled(struct context_entry *context)
224 return !!(context->lo & (1ULL << 11));
227 static inline void context_set_copied(struct context_entry *context)
229 context->hi |= (1ull << 3);
232 static inline bool context_copied(struct context_entry *context)
234 return !!(context->hi & (1ULL << 3));
237 static inline bool __context_present(struct context_entry *context)
239 return (context->lo & 1);
242 bool context_present(struct context_entry *context)
244 return context_pasid_enabled(context) ?
245 __context_present(context) :
246 __context_present(context) && !context_copied(context);
249 static inline void context_set_present(struct context_entry *context)
251 context->lo |= 1;
254 static inline void context_set_fault_enable(struct context_entry *context)
256 context->lo &= (((u64)-1) << 2) | 1;
259 static inline void context_set_translation_type(struct context_entry *context,
260 unsigned long value)
262 context->lo &= (((u64)-1) << 4) | 3;
263 context->lo |= (value & 3) << 2;
266 static inline void context_set_address_root(struct context_entry *context,
267 unsigned long value)
269 context->lo &= ~VTD_PAGE_MASK;
270 context->lo |= value & VTD_PAGE_MASK;
273 static inline void context_set_address_width(struct context_entry *context,
274 unsigned long value)
276 context->hi |= value & 7;
279 static inline void context_set_domain_id(struct context_entry *context,
280 unsigned long value)
282 context->hi |= (value & ((1 << 16) - 1)) << 8;
285 static inline int context_domain_id(struct context_entry *c)
287 return((c->hi >> 8) & 0xffff);
290 static inline void context_clear_entry(struct context_entry *context)
292 context->lo = 0;
293 context->hi = 0;
297 * This domain is a statically identity mapping domain.
298 * 1. This domain creats a static 1:1 mapping to all usable memory.
299 * 2. It maps to each iommu if successful.
300 * 3. Each iommu mapps to this domain if successful.
302 static struct dmar_domain *si_domain;
303 static int hw_pass_through = 1;
306 * Domain represents a virtual machine, more than one devices
307 * across iommus may be owned in one domain, e.g. kvm guest.
309 #define DOMAIN_FLAG_VIRTUAL_MACHINE (1 << 0)
311 /* si_domain contains mulitple devices */
312 #define DOMAIN_FLAG_STATIC_IDENTITY (1 << 1)
314 #define for_each_domain_iommu(idx, domain) \
315 for (idx = 0; idx < g_num_of_iommus; idx++) \
316 if (domain->iommu_refcnt[idx])
318 struct dmar_rmrr_unit {
319 struct list_head list; /* list of rmrr units */
320 struct acpi_dmar_header *hdr; /* ACPI header */
321 u64 base_address; /* reserved base address*/
322 u64 end_address; /* reserved end address */
323 struct dmar_dev_scope *devices; /* target devices */
324 int devices_cnt; /* target device count */
325 struct iommu_resv_region *resv; /* reserved region handle */
328 struct dmar_atsr_unit {
329 struct list_head list; /* list of ATSR units */
330 struct acpi_dmar_header *hdr; /* ACPI header */
331 struct dmar_dev_scope *devices; /* target devices */
332 int devices_cnt; /* target device count */
333 u8 include_all:1; /* include all ports */
336 static LIST_HEAD(dmar_atsr_units);
337 static LIST_HEAD(dmar_rmrr_units);
339 #define for_each_rmrr_units(rmrr) \
340 list_for_each_entry(rmrr, &dmar_rmrr_units, list)
342 /* bitmap for indexing intel_iommus */
343 static int g_num_of_iommus;
345 static void domain_exit(struct dmar_domain *domain);
346 static void domain_remove_dev_info(struct dmar_domain *domain);
347 static void dmar_remove_one_dev_info(struct device *dev);
348 static void __dmar_remove_one_dev_info(struct device_domain_info *info);
349 static void domain_context_clear(struct intel_iommu *iommu,
350 struct device *dev);
351 static int domain_detach_iommu(struct dmar_domain *domain,
352 struct intel_iommu *iommu);
354 #ifdef CONFIG_INTEL_IOMMU_DEFAULT_ON
355 int dmar_disabled = 0;
356 #else
357 int dmar_disabled = 1;
358 #endif /*CONFIG_INTEL_IOMMU_DEFAULT_ON*/
360 int intel_iommu_enabled = 0;
361 EXPORT_SYMBOL_GPL(intel_iommu_enabled);
363 static int dmar_map_gfx = 1;
364 static int dmar_forcedac;
365 static int intel_iommu_strict;
366 static int intel_iommu_superpage = 1;
367 static int intel_iommu_sm;
368 static int iommu_identity_mapping;
370 #define IDENTMAP_ALL 1
371 #define IDENTMAP_GFX 2
372 #define IDENTMAP_AZALIA 4
374 #define sm_supported(iommu) (intel_iommu_sm && ecap_smts((iommu)->ecap))
375 #define pasid_supported(iommu) (sm_supported(iommu) && \
376 ecap_pasid((iommu)->ecap))
378 int intel_iommu_gfx_mapped;
379 EXPORT_SYMBOL_GPL(intel_iommu_gfx_mapped);
381 #define DUMMY_DEVICE_DOMAIN_INFO ((struct device_domain_info *)(-1))
382 static DEFINE_SPINLOCK(device_domain_lock);
383 static LIST_HEAD(device_domain_list);
386 * Iterate over elements in device_domain_list and call the specified
387 * callback @fn against each element.
389 int for_each_device_domain(int (*fn)(struct device_domain_info *info,
390 void *data), void *data)
392 int ret = 0;
393 unsigned long flags;
394 struct device_domain_info *info;
396 spin_lock_irqsave(&device_domain_lock, flags);
397 list_for_each_entry(info, &device_domain_list, global) {
398 ret = fn(info, data);
399 if (ret) {
400 spin_unlock_irqrestore(&device_domain_lock, flags);
401 return ret;
404 spin_unlock_irqrestore(&device_domain_lock, flags);
406 return 0;
409 const struct iommu_ops intel_iommu_ops;
411 static bool translation_pre_enabled(struct intel_iommu *iommu)
413 return (iommu->flags & VTD_FLAG_TRANS_PRE_ENABLED);
416 static void clear_translation_pre_enabled(struct intel_iommu *iommu)
418 iommu->flags &= ~VTD_FLAG_TRANS_PRE_ENABLED;
421 static void init_translation_status(struct intel_iommu *iommu)
423 u32 gsts;
425 gsts = readl(iommu->reg + DMAR_GSTS_REG);
426 if (gsts & DMA_GSTS_TES)
427 iommu->flags |= VTD_FLAG_TRANS_PRE_ENABLED;
430 /* Convert generic 'struct iommu_domain to private struct dmar_domain */
431 static struct dmar_domain *to_dmar_domain(struct iommu_domain *dom)
433 return container_of(dom, struct dmar_domain, domain);
436 static int __init intel_iommu_setup(char *str)
438 if (!str)
439 return -EINVAL;
440 while (*str) {
441 if (!strncmp(str, "on", 2)) {
442 dmar_disabled = 0;
443 pr_info("IOMMU enabled\n");
444 } else if (!strncmp(str, "off", 3)) {
445 dmar_disabled = 1;
446 no_platform_optin = 1;
447 pr_info("IOMMU disabled\n");
448 } else if (!strncmp(str, "igfx_off", 8)) {
449 dmar_map_gfx = 0;
450 pr_info("Disable GFX device mapping\n");
451 } else if (!strncmp(str, "forcedac", 8)) {
452 pr_info("Forcing DAC for PCI devices\n");
453 dmar_forcedac = 1;
454 } else if (!strncmp(str, "strict", 6)) {
455 pr_info("Disable batched IOTLB flush\n");
456 intel_iommu_strict = 1;
457 } else if (!strncmp(str, "sp_off", 6)) {
458 pr_info("Disable supported super page\n");
459 intel_iommu_superpage = 0;
460 } else if (!strncmp(str, "sm_on", 5)) {
461 pr_info("Intel-IOMMU: scalable mode supported\n");
462 intel_iommu_sm = 1;
463 } else if (!strncmp(str, "tboot_noforce", 13)) {
464 printk(KERN_INFO
465 "Intel-IOMMU: not forcing on after tboot. This could expose security risk for tboot\n");
466 intel_iommu_tboot_noforce = 1;
469 str += strcspn(str, ",");
470 while (*str == ',')
471 str++;
473 return 0;
475 __setup("intel_iommu=", intel_iommu_setup);
477 static struct kmem_cache *iommu_domain_cache;
478 static struct kmem_cache *iommu_devinfo_cache;
480 static struct dmar_domain* get_iommu_domain(struct intel_iommu *iommu, u16 did)
482 struct dmar_domain **domains;
483 int idx = did >> 8;
485 domains = iommu->domains[idx];
486 if (!domains)
487 return NULL;
489 return domains[did & 0xff];
492 static void set_iommu_domain(struct intel_iommu *iommu, u16 did,
493 struct dmar_domain *domain)
495 struct dmar_domain **domains;
496 int idx = did >> 8;
498 if (!iommu->domains[idx]) {
499 size_t size = 256 * sizeof(struct dmar_domain *);
500 iommu->domains[idx] = kzalloc(size, GFP_ATOMIC);
503 domains = iommu->domains[idx];
504 if (WARN_ON(!domains))
505 return;
506 else
507 domains[did & 0xff] = domain;
510 void *alloc_pgtable_page(int node)
512 struct page *page;
513 void *vaddr = NULL;
515 page = alloc_pages_node(node, GFP_ATOMIC | __GFP_ZERO, 0);
516 if (page)
517 vaddr = page_address(page);
518 return vaddr;
521 void free_pgtable_page(void *vaddr)
523 free_page((unsigned long)vaddr);
526 static inline void *alloc_domain_mem(void)
528 return kmem_cache_alloc(iommu_domain_cache, GFP_ATOMIC);
531 static void free_domain_mem(void *vaddr)
533 kmem_cache_free(iommu_domain_cache, vaddr);
536 static inline void * alloc_devinfo_mem(void)
538 return kmem_cache_alloc(iommu_devinfo_cache, GFP_ATOMIC);
541 static inline void free_devinfo_mem(void *vaddr)
543 kmem_cache_free(iommu_devinfo_cache, vaddr);
546 static inline int domain_type_is_vm(struct dmar_domain *domain)
548 return domain->flags & DOMAIN_FLAG_VIRTUAL_MACHINE;
551 static inline int domain_type_is_si(struct dmar_domain *domain)
553 return domain->flags & DOMAIN_FLAG_STATIC_IDENTITY;
556 static inline int domain_type_is_vm_or_si(struct dmar_domain *domain)
558 return domain->flags & (DOMAIN_FLAG_VIRTUAL_MACHINE |
559 DOMAIN_FLAG_STATIC_IDENTITY);
562 static inline int domain_pfn_supported(struct dmar_domain *domain,
563 unsigned long pfn)
565 int addr_width = agaw_to_width(domain->agaw) - VTD_PAGE_SHIFT;
567 return !(addr_width < BITS_PER_LONG && pfn >> addr_width);
570 static int __iommu_calculate_agaw(struct intel_iommu *iommu, int max_gaw)
572 unsigned long sagaw;
573 int agaw = -1;
575 sagaw = cap_sagaw(iommu->cap);
576 for (agaw = width_to_agaw(max_gaw);
577 agaw >= 0; agaw--) {
578 if (test_bit(agaw, &sagaw))
579 break;
582 return agaw;
586 * Calculate max SAGAW for each iommu.
588 int iommu_calculate_max_sagaw(struct intel_iommu *iommu)
590 return __iommu_calculate_agaw(iommu, MAX_AGAW_WIDTH);
594 * calculate agaw for each iommu.
595 * "SAGAW" may be different across iommus, use a default agaw, and
596 * get a supported less agaw for iommus that don't support the default agaw.
598 int iommu_calculate_agaw(struct intel_iommu *iommu)
600 return __iommu_calculate_agaw(iommu, DEFAULT_DOMAIN_ADDRESS_WIDTH);
603 /* This functionin only returns single iommu in a domain */
604 struct intel_iommu *domain_get_iommu(struct dmar_domain *domain)
606 int iommu_id;
608 /* si_domain and vm domain should not get here. */
609 BUG_ON(domain_type_is_vm_or_si(domain));
610 for_each_domain_iommu(iommu_id, domain)
611 break;
613 if (iommu_id < 0 || iommu_id >= g_num_of_iommus)
614 return NULL;
616 return g_iommus[iommu_id];
619 static void domain_update_iommu_coherency(struct dmar_domain *domain)
621 struct dmar_drhd_unit *drhd;
622 struct intel_iommu *iommu;
623 bool found = false;
624 int i;
626 domain->iommu_coherency = 1;
628 for_each_domain_iommu(i, domain) {
629 found = true;
630 if (!ecap_coherent(g_iommus[i]->ecap)) {
631 domain->iommu_coherency = 0;
632 break;
635 if (found)
636 return;
638 /* No hardware attached; use lowest common denominator */
639 rcu_read_lock();
640 for_each_active_iommu(iommu, drhd) {
641 if (!ecap_coherent(iommu->ecap)) {
642 domain->iommu_coherency = 0;
643 break;
646 rcu_read_unlock();
649 static int domain_update_iommu_snooping(struct intel_iommu *skip)
651 struct dmar_drhd_unit *drhd;
652 struct intel_iommu *iommu;
653 int ret = 1;
655 rcu_read_lock();
656 for_each_active_iommu(iommu, drhd) {
657 if (iommu != skip) {
658 if (!ecap_sc_support(iommu->ecap)) {
659 ret = 0;
660 break;
664 rcu_read_unlock();
666 return ret;
669 static int domain_update_iommu_superpage(struct intel_iommu *skip)
671 struct dmar_drhd_unit *drhd;
672 struct intel_iommu *iommu;
673 int mask = 0xf;
675 if (!intel_iommu_superpage) {
676 return 0;
679 /* set iommu_superpage to the smallest common denominator */
680 rcu_read_lock();
681 for_each_active_iommu(iommu, drhd) {
682 if (iommu != skip) {
683 mask &= cap_super_page_val(iommu->cap);
684 if (!mask)
685 break;
688 rcu_read_unlock();
690 return fls(mask);
693 /* Some capabilities may be different across iommus */
694 static void domain_update_iommu_cap(struct dmar_domain *domain)
696 domain_update_iommu_coherency(domain);
697 domain->iommu_snooping = domain_update_iommu_snooping(NULL);
698 domain->iommu_superpage = domain_update_iommu_superpage(NULL);
701 struct context_entry *iommu_context_addr(struct intel_iommu *iommu, u8 bus,
702 u8 devfn, int alloc)
704 struct root_entry *root = &iommu->root_entry[bus];
705 struct context_entry *context;
706 u64 *entry;
708 entry = &root->lo;
709 if (sm_supported(iommu)) {
710 if (devfn >= 0x80) {
711 devfn -= 0x80;
712 entry = &root->hi;
714 devfn *= 2;
716 if (*entry & 1)
717 context = phys_to_virt(*entry & VTD_PAGE_MASK);
718 else {
719 unsigned long phy_addr;
720 if (!alloc)
721 return NULL;
723 context = alloc_pgtable_page(iommu->node);
724 if (!context)
725 return NULL;
727 __iommu_flush_cache(iommu, (void *)context, CONTEXT_SIZE);
728 phy_addr = virt_to_phys((void *)context);
729 *entry = phy_addr | 1;
730 __iommu_flush_cache(iommu, entry, sizeof(*entry));
732 return &context[devfn];
735 static int iommu_dummy(struct device *dev)
737 return dev->archdata.iommu == DUMMY_DEVICE_DOMAIN_INFO;
740 static struct intel_iommu *device_to_iommu(struct device *dev, u8 *bus, u8 *devfn)
742 struct dmar_drhd_unit *drhd = NULL;
743 struct intel_iommu *iommu;
744 struct device *tmp;
745 struct pci_dev *ptmp, *pdev = NULL;
746 u16 segment = 0;
747 int i;
749 if (iommu_dummy(dev))
750 return NULL;
752 if (dev_is_pci(dev)) {
753 struct pci_dev *pf_pdev;
755 pdev = to_pci_dev(dev);
757 #ifdef CONFIG_X86
758 /* VMD child devices currently cannot be handled individually */
759 if (is_vmd(pdev->bus))
760 return NULL;
761 #endif
763 /* VFs aren't listed in scope tables; we need to look up
764 * the PF instead to find the IOMMU. */
765 pf_pdev = pci_physfn(pdev);
766 dev = &pf_pdev->dev;
767 segment = pci_domain_nr(pdev->bus);
768 } else if (has_acpi_companion(dev))
769 dev = &ACPI_COMPANION(dev)->dev;
771 rcu_read_lock();
772 for_each_active_iommu(iommu, drhd) {
773 if (pdev && segment != drhd->segment)
774 continue;
776 for_each_active_dev_scope(drhd->devices,
777 drhd->devices_cnt, i, tmp) {
778 if (tmp == dev) {
779 /* For a VF use its original BDF# not that of the PF
780 * which we used for the IOMMU lookup. Strictly speaking
781 * we could do this for all PCI devices; we only need to
782 * get the BDF# from the scope table for ACPI matches. */
783 if (pdev && pdev->is_virtfn)
784 goto got_pdev;
786 *bus = drhd->devices[i].bus;
787 *devfn = drhd->devices[i].devfn;
788 goto out;
791 if (!pdev || !dev_is_pci(tmp))
792 continue;
794 ptmp = to_pci_dev(tmp);
795 if (ptmp->subordinate &&
796 ptmp->subordinate->number <= pdev->bus->number &&
797 ptmp->subordinate->busn_res.end >= pdev->bus->number)
798 goto got_pdev;
801 if (pdev && drhd->include_all) {
802 got_pdev:
803 *bus = pdev->bus->number;
804 *devfn = pdev->devfn;
805 goto out;
808 iommu = NULL;
809 out:
810 rcu_read_unlock();
812 return iommu;
815 static void domain_flush_cache(struct dmar_domain *domain,
816 void *addr, int size)
818 if (!domain->iommu_coherency)
819 clflush_cache_range(addr, size);
822 static int device_context_mapped(struct intel_iommu *iommu, u8 bus, u8 devfn)
824 struct context_entry *context;
825 int ret = 0;
826 unsigned long flags;
828 spin_lock_irqsave(&iommu->lock, flags);
829 context = iommu_context_addr(iommu, bus, devfn, 0);
830 if (context)
831 ret = context_present(context);
832 spin_unlock_irqrestore(&iommu->lock, flags);
833 return ret;
836 static void free_context_table(struct intel_iommu *iommu)
838 int i;
839 unsigned long flags;
840 struct context_entry *context;
842 spin_lock_irqsave(&iommu->lock, flags);
843 if (!iommu->root_entry) {
844 goto out;
846 for (i = 0; i < ROOT_ENTRY_NR; i++) {
847 context = iommu_context_addr(iommu, i, 0, 0);
848 if (context)
849 free_pgtable_page(context);
851 if (!sm_supported(iommu))
852 continue;
854 context = iommu_context_addr(iommu, i, 0x80, 0);
855 if (context)
856 free_pgtable_page(context);
859 free_pgtable_page(iommu->root_entry);
860 iommu->root_entry = NULL;
861 out:
862 spin_unlock_irqrestore(&iommu->lock, flags);
865 static struct dma_pte *pfn_to_dma_pte(struct dmar_domain *domain,
866 unsigned long pfn, int *target_level)
868 struct dma_pte *parent, *pte;
869 int level = agaw_to_level(domain->agaw);
870 int offset;
872 BUG_ON(!domain->pgd);
874 if (!domain_pfn_supported(domain, pfn))
875 /* Address beyond IOMMU's addressing capabilities. */
876 return NULL;
878 parent = domain->pgd;
880 while (1) {
881 void *tmp_page;
883 offset = pfn_level_offset(pfn, level);
884 pte = &parent[offset];
885 if (!*target_level && (dma_pte_superpage(pte) || !dma_pte_present(pte)))
886 break;
887 if (level == *target_level)
888 break;
890 if (!dma_pte_present(pte)) {
891 uint64_t pteval;
893 tmp_page = alloc_pgtable_page(domain->nid);
895 if (!tmp_page)
896 return NULL;
898 domain_flush_cache(domain, tmp_page, VTD_PAGE_SIZE);
899 pteval = ((uint64_t)virt_to_dma_pfn(tmp_page) << VTD_PAGE_SHIFT) | DMA_PTE_READ | DMA_PTE_WRITE;
900 if (cmpxchg64(&pte->val, 0ULL, pteval))
901 /* Someone else set it while we were thinking; use theirs. */
902 free_pgtable_page(tmp_page);
903 else
904 domain_flush_cache(domain, pte, sizeof(*pte));
906 if (level == 1)
907 break;
909 parent = phys_to_virt(dma_pte_addr(pte));
910 level--;
913 if (!*target_level)
914 *target_level = level;
916 return pte;
920 /* return address's pte at specific level */
921 static struct dma_pte *dma_pfn_level_pte(struct dmar_domain *domain,
922 unsigned long pfn,
923 int level, int *large_page)
925 struct dma_pte *parent, *pte;
926 int total = agaw_to_level(domain->agaw);
927 int offset;
929 parent = domain->pgd;
930 while (level <= total) {
931 offset = pfn_level_offset(pfn, total);
932 pte = &parent[offset];
933 if (level == total)
934 return pte;
936 if (!dma_pte_present(pte)) {
937 *large_page = total;
938 break;
941 if (dma_pte_superpage(pte)) {
942 *large_page = total;
943 return pte;
946 parent = phys_to_virt(dma_pte_addr(pte));
947 total--;
949 return NULL;
952 /* clear last level pte, a tlb flush should be followed */
953 static void dma_pte_clear_range(struct dmar_domain *domain,
954 unsigned long start_pfn,
955 unsigned long last_pfn)
957 unsigned int large_page;
958 struct dma_pte *first_pte, *pte;
960 BUG_ON(!domain_pfn_supported(domain, start_pfn));
961 BUG_ON(!domain_pfn_supported(domain, last_pfn));
962 BUG_ON(start_pfn > last_pfn);
964 /* we don't need lock here; nobody else touches the iova range */
965 do {
966 large_page = 1;
967 first_pte = pte = dma_pfn_level_pte(domain, start_pfn, 1, &large_page);
968 if (!pte) {
969 start_pfn = align_to_level(start_pfn + 1, large_page + 1);
970 continue;
972 do {
973 dma_clear_pte(pte);
974 start_pfn += lvl_to_nr_pages(large_page);
975 pte++;
976 } while (start_pfn <= last_pfn && !first_pte_in_page(pte));
978 domain_flush_cache(domain, first_pte,
979 (void *)pte - (void *)first_pte);
981 } while (start_pfn && start_pfn <= last_pfn);
984 static void dma_pte_free_level(struct dmar_domain *domain, int level,
985 int retain_level, struct dma_pte *pte,
986 unsigned long pfn, unsigned long start_pfn,
987 unsigned long last_pfn)
989 pfn = max(start_pfn, pfn);
990 pte = &pte[pfn_level_offset(pfn, level)];
992 do {
993 unsigned long level_pfn;
994 struct dma_pte *level_pte;
996 if (!dma_pte_present(pte) || dma_pte_superpage(pte))
997 goto next;
999 level_pfn = pfn & level_mask(level);
1000 level_pte = phys_to_virt(dma_pte_addr(pte));
1002 if (level > 2) {
1003 dma_pte_free_level(domain, level - 1, retain_level,
1004 level_pte, level_pfn, start_pfn,
1005 last_pfn);
1009 * Free the page table if we're below the level we want to
1010 * retain and the range covers the entire table.
1012 if (level < retain_level && !(start_pfn > level_pfn ||
1013 last_pfn < level_pfn + level_size(level) - 1)) {
1014 dma_clear_pte(pte);
1015 domain_flush_cache(domain, pte, sizeof(*pte));
1016 free_pgtable_page(level_pte);
1018 next:
1019 pfn += level_size(level);
1020 } while (!first_pte_in_page(++pte) && pfn <= last_pfn);
1024 * clear last level (leaf) ptes and free page table pages below the
1025 * level we wish to keep intact.
1027 static void dma_pte_free_pagetable(struct dmar_domain *domain,
1028 unsigned long start_pfn,
1029 unsigned long last_pfn,
1030 int retain_level)
1032 BUG_ON(!domain_pfn_supported(domain, start_pfn));
1033 BUG_ON(!domain_pfn_supported(domain, last_pfn));
1034 BUG_ON(start_pfn > last_pfn);
1036 dma_pte_clear_range(domain, start_pfn, last_pfn);
1038 /* We don't need lock here; nobody else touches the iova range */
1039 dma_pte_free_level(domain, agaw_to_level(domain->agaw), retain_level,
1040 domain->pgd, 0, start_pfn, last_pfn);
1042 /* free pgd */
1043 if (start_pfn == 0 && last_pfn == DOMAIN_MAX_PFN(domain->gaw)) {
1044 free_pgtable_page(domain->pgd);
1045 domain->pgd = NULL;
1049 /* When a page at a given level is being unlinked from its parent, we don't
1050 need to *modify* it at all. All we need to do is make a list of all the
1051 pages which can be freed just as soon as we've flushed the IOTLB and we
1052 know the hardware page-walk will no longer touch them.
1053 The 'pte' argument is the *parent* PTE, pointing to the page that is to
1054 be freed. */
1055 static struct page *dma_pte_list_pagetables(struct dmar_domain *domain,
1056 int level, struct dma_pte *pte,
1057 struct page *freelist)
1059 struct page *pg;
1061 pg = pfn_to_page(dma_pte_addr(pte) >> PAGE_SHIFT);
1062 pg->freelist = freelist;
1063 freelist = pg;
1065 if (level == 1)
1066 return freelist;
1068 pte = page_address(pg);
1069 do {
1070 if (dma_pte_present(pte) && !dma_pte_superpage(pte))
1071 freelist = dma_pte_list_pagetables(domain, level - 1,
1072 pte, freelist);
1073 pte++;
1074 } while (!first_pte_in_page(pte));
1076 return freelist;
1079 static struct page *dma_pte_clear_level(struct dmar_domain *domain, int level,
1080 struct dma_pte *pte, unsigned long pfn,
1081 unsigned long start_pfn,
1082 unsigned long last_pfn,
1083 struct page *freelist)
1085 struct dma_pte *first_pte = NULL, *last_pte = NULL;
1087 pfn = max(start_pfn, pfn);
1088 pte = &pte[pfn_level_offset(pfn, level)];
1090 do {
1091 unsigned long level_pfn;
1093 if (!dma_pte_present(pte))
1094 goto next;
1096 level_pfn = pfn & level_mask(level);
1098 /* If range covers entire pagetable, free it */
1099 if (start_pfn <= level_pfn &&
1100 last_pfn >= level_pfn + level_size(level) - 1) {
1101 /* These suborbinate page tables are going away entirely. Don't
1102 bother to clear them; we're just going to *free* them. */
1103 if (level > 1 && !dma_pte_superpage(pte))
1104 freelist = dma_pte_list_pagetables(domain, level - 1, pte, freelist);
1106 dma_clear_pte(pte);
1107 if (!first_pte)
1108 first_pte = pte;
1109 last_pte = pte;
1110 } else if (level > 1) {
1111 /* Recurse down into a level that isn't *entirely* obsolete */
1112 freelist = dma_pte_clear_level(domain, level - 1,
1113 phys_to_virt(dma_pte_addr(pte)),
1114 level_pfn, start_pfn, last_pfn,
1115 freelist);
1117 next:
1118 pfn += level_size(level);
1119 } while (!first_pte_in_page(++pte) && pfn <= last_pfn);
1121 if (first_pte)
1122 domain_flush_cache(domain, first_pte,
1123 (void *)++last_pte - (void *)first_pte);
1125 return freelist;
1128 /* We can't just free the pages because the IOMMU may still be walking
1129 the page tables, and may have cached the intermediate levels. The
1130 pages can only be freed after the IOTLB flush has been done. */
1131 static struct page *domain_unmap(struct dmar_domain *domain,
1132 unsigned long start_pfn,
1133 unsigned long last_pfn)
1135 struct page *freelist;
1137 BUG_ON(!domain_pfn_supported(domain, start_pfn));
1138 BUG_ON(!domain_pfn_supported(domain, last_pfn));
1139 BUG_ON(start_pfn > last_pfn);
1141 /* we don't need lock here; nobody else touches the iova range */
1142 freelist = dma_pte_clear_level(domain, agaw_to_level(domain->agaw),
1143 domain->pgd, 0, start_pfn, last_pfn, NULL);
1145 /* free pgd */
1146 if (start_pfn == 0 && last_pfn == DOMAIN_MAX_PFN(domain->gaw)) {
1147 struct page *pgd_page = virt_to_page(domain->pgd);
1148 pgd_page->freelist = freelist;
1149 freelist = pgd_page;
1151 domain->pgd = NULL;
1154 return freelist;
1157 static void dma_free_pagelist(struct page *freelist)
1159 struct page *pg;
1161 while ((pg = freelist)) {
1162 freelist = pg->freelist;
1163 free_pgtable_page(page_address(pg));
1167 static void iova_entry_free(unsigned long data)
1169 struct page *freelist = (struct page *)data;
1171 dma_free_pagelist(freelist);
1174 /* iommu handling */
1175 static int iommu_alloc_root_entry(struct intel_iommu *iommu)
1177 struct root_entry *root;
1178 unsigned long flags;
1180 root = (struct root_entry *)alloc_pgtable_page(iommu->node);
1181 if (!root) {
1182 pr_err("Allocating root entry for %s failed\n",
1183 iommu->name);
1184 return -ENOMEM;
1187 __iommu_flush_cache(iommu, root, ROOT_SIZE);
1189 spin_lock_irqsave(&iommu->lock, flags);
1190 iommu->root_entry = root;
1191 spin_unlock_irqrestore(&iommu->lock, flags);
1193 return 0;
1196 static void iommu_set_root_entry(struct intel_iommu *iommu)
1198 u64 addr;
1199 u32 sts;
1200 unsigned long flag;
1202 addr = virt_to_phys(iommu->root_entry);
1203 if (sm_supported(iommu))
1204 addr |= DMA_RTADDR_SMT;
1206 raw_spin_lock_irqsave(&iommu->register_lock, flag);
1207 dmar_writeq(iommu->reg + DMAR_RTADDR_REG, addr);
1209 writel(iommu->gcmd | DMA_GCMD_SRTP, iommu->reg + DMAR_GCMD_REG);
1211 /* Make sure hardware complete it */
1212 IOMMU_WAIT_OP(iommu, DMAR_GSTS_REG,
1213 readl, (sts & DMA_GSTS_RTPS), sts);
1215 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
1218 void iommu_flush_write_buffer(struct intel_iommu *iommu)
1220 u32 val;
1221 unsigned long flag;
1223 if (!rwbf_quirk && !cap_rwbf(iommu->cap))
1224 return;
1226 raw_spin_lock_irqsave(&iommu->register_lock, flag);
1227 writel(iommu->gcmd | DMA_GCMD_WBF, iommu->reg + DMAR_GCMD_REG);
1229 /* Make sure hardware complete it */
1230 IOMMU_WAIT_OP(iommu, DMAR_GSTS_REG,
1231 readl, (!(val & DMA_GSTS_WBFS)), val);
1233 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
1236 /* return value determine if we need a write buffer flush */
1237 static void __iommu_flush_context(struct intel_iommu *iommu,
1238 u16 did, u16 source_id, u8 function_mask,
1239 u64 type)
1241 u64 val = 0;
1242 unsigned long flag;
1244 switch (type) {
1245 case DMA_CCMD_GLOBAL_INVL:
1246 val = DMA_CCMD_GLOBAL_INVL;
1247 break;
1248 case DMA_CCMD_DOMAIN_INVL:
1249 val = DMA_CCMD_DOMAIN_INVL|DMA_CCMD_DID(did);
1250 break;
1251 case DMA_CCMD_DEVICE_INVL:
1252 val = DMA_CCMD_DEVICE_INVL|DMA_CCMD_DID(did)
1253 | DMA_CCMD_SID(source_id) | DMA_CCMD_FM(function_mask);
1254 break;
1255 default:
1256 BUG();
1258 val |= DMA_CCMD_ICC;
1260 raw_spin_lock_irqsave(&iommu->register_lock, flag);
1261 dmar_writeq(iommu->reg + DMAR_CCMD_REG, val);
1263 /* Make sure hardware complete it */
1264 IOMMU_WAIT_OP(iommu, DMAR_CCMD_REG,
1265 dmar_readq, (!(val & DMA_CCMD_ICC)), val);
1267 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
1270 /* return value determine if we need a write buffer flush */
1271 static void __iommu_flush_iotlb(struct intel_iommu *iommu, u16 did,
1272 u64 addr, unsigned int size_order, u64 type)
1274 int tlb_offset = ecap_iotlb_offset(iommu->ecap);
1275 u64 val = 0, val_iva = 0;
1276 unsigned long flag;
1278 switch (type) {
1279 case DMA_TLB_GLOBAL_FLUSH:
1280 /* global flush doesn't need set IVA_REG */
1281 val = DMA_TLB_GLOBAL_FLUSH|DMA_TLB_IVT;
1282 break;
1283 case DMA_TLB_DSI_FLUSH:
1284 val = DMA_TLB_DSI_FLUSH|DMA_TLB_IVT|DMA_TLB_DID(did);
1285 break;
1286 case DMA_TLB_PSI_FLUSH:
1287 val = DMA_TLB_PSI_FLUSH|DMA_TLB_IVT|DMA_TLB_DID(did);
1288 /* IH bit is passed in as part of address */
1289 val_iva = size_order | addr;
1290 break;
1291 default:
1292 BUG();
1294 /* Note: set drain read/write */
1295 #if 0
1297 * This is probably to be super secure.. Looks like we can
1298 * ignore it without any impact.
1300 if (cap_read_drain(iommu->cap))
1301 val |= DMA_TLB_READ_DRAIN;
1302 #endif
1303 if (cap_write_drain(iommu->cap))
1304 val |= DMA_TLB_WRITE_DRAIN;
1306 raw_spin_lock_irqsave(&iommu->register_lock, flag);
1307 /* Note: Only uses first TLB reg currently */
1308 if (val_iva)
1309 dmar_writeq(iommu->reg + tlb_offset, val_iva);
1310 dmar_writeq(iommu->reg + tlb_offset + 8, val);
1312 /* Make sure hardware complete it */
1313 IOMMU_WAIT_OP(iommu, tlb_offset + 8,
1314 dmar_readq, (!(val & DMA_TLB_IVT)), val);
1316 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
1318 /* check IOTLB invalidation granularity */
1319 if (DMA_TLB_IAIG(val) == 0)
1320 pr_err("Flush IOTLB failed\n");
1321 if (DMA_TLB_IAIG(val) != DMA_TLB_IIRG(type))
1322 pr_debug("TLB flush request %Lx, actual %Lx\n",
1323 (unsigned long long)DMA_TLB_IIRG(type),
1324 (unsigned long long)DMA_TLB_IAIG(val));
1327 static struct device_domain_info *
1328 iommu_support_dev_iotlb (struct dmar_domain *domain, struct intel_iommu *iommu,
1329 u8 bus, u8 devfn)
1331 struct device_domain_info *info;
1333 assert_spin_locked(&device_domain_lock);
1335 if (!iommu->qi)
1336 return NULL;
1338 list_for_each_entry(info, &domain->devices, link)
1339 if (info->iommu == iommu && info->bus == bus &&
1340 info->devfn == devfn) {
1341 if (info->ats_supported && info->dev)
1342 return info;
1343 break;
1346 return NULL;
1349 static void domain_update_iotlb(struct dmar_domain *domain)
1351 struct device_domain_info *info;
1352 bool has_iotlb_device = false;
1354 assert_spin_locked(&device_domain_lock);
1356 list_for_each_entry(info, &domain->devices, link) {
1357 struct pci_dev *pdev;
1359 if (!info->dev || !dev_is_pci(info->dev))
1360 continue;
1362 pdev = to_pci_dev(info->dev);
1363 if (pdev->ats_enabled) {
1364 has_iotlb_device = true;
1365 break;
1369 domain->has_iotlb_device = has_iotlb_device;
1372 static void iommu_enable_dev_iotlb(struct device_domain_info *info)
1374 struct pci_dev *pdev;
1376 assert_spin_locked(&device_domain_lock);
1378 if (!info || !dev_is_pci(info->dev))
1379 return;
1381 pdev = to_pci_dev(info->dev);
1382 /* For IOMMU that supports device IOTLB throttling (DIT), we assign
1383 * PFSID to the invalidation desc of a VF such that IOMMU HW can gauge
1384 * queue depth at PF level. If DIT is not set, PFSID will be treated as
1385 * reserved, which should be set to 0.
1387 if (!ecap_dit(info->iommu->ecap))
1388 info->pfsid = 0;
1389 else {
1390 struct pci_dev *pf_pdev;
1392 /* pdev will be returned if device is not a vf */
1393 pf_pdev = pci_physfn(pdev);
1394 info->pfsid = PCI_DEVID(pf_pdev->bus->number, pf_pdev->devfn);
1397 #ifdef CONFIG_INTEL_IOMMU_SVM
1398 /* The PCIe spec, in its wisdom, declares that the behaviour of
1399 the device if you enable PASID support after ATS support is
1400 undefined. So always enable PASID support on devices which
1401 have it, even if we can't yet know if we're ever going to
1402 use it. */
1403 if (info->pasid_supported && !pci_enable_pasid(pdev, info->pasid_supported & ~1))
1404 info->pasid_enabled = 1;
1406 if (info->pri_supported &&
1407 (info->pasid_enabled ? pci_prg_resp_pasid_required(pdev) : 1) &&
1408 !pci_reset_pri(pdev) && !pci_enable_pri(pdev, 32))
1409 info->pri_enabled = 1;
1410 #endif
1411 if (!pdev->untrusted && info->ats_supported &&
1412 pci_ats_page_aligned(pdev) &&
1413 !pci_enable_ats(pdev, VTD_PAGE_SHIFT)) {
1414 info->ats_enabled = 1;
1415 domain_update_iotlb(info->domain);
1416 info->ats_qdep = pci_ats_queue_depth(pdev);
1420 static void iommu_disable_dev_iotlb(struct device_domain_info *info)
1422 struct pci_dev *pdev;
1424 assert_spin_locked(&device_domain_lock);
1426 if (!dev_is_pci(info->dev))
1427 return;
1429 pdev = to_pci_dev(info->dev);
1431 if (info->ats_enabled) {
1432 pci_disable_ats(pdev);
1433 info->ats_enabled = 0;
1434 domain_update_iotlb(info->domain);
1436 #ifdef CONFIG_INTEL_IOMMU_SVM
1437 if (info->pri_enabled) {
1438 pci_disable_pri(pdev);
1439 info->pri_enabled = 0;
1441 if (info->pasid_enabled) {
1442 pci_disable_pasid(pdev);
1443 info->pasid_enabled = 0;
1445 #endif
1448 static void iommu_flush_dev_iotlb(struct dmar_domain *domain,
1449 u64 addr, unsigned mask)
1451 u16 sid, qdep;
1452 unsigned long flags;
1453 struct device_domain_info *info;
1455 if (!domain->has_iotlb_device)
1456 return;
1458 spin_lock_irqsave(&device_domain_lock, flags);
1459 list_for_each_entry(info, &domain->devices, link) {
1460 if (!info->ats_enabled)
1461 continue;
1463 sid = info->bus << 8 | info->devfn;
1464 qdep = info->ats_qdep;
1465 qi_flush_dev_iotlb(info->iommu, sid, info->pfsid,
1466 qdep, addr, mask);
1468 spin_unlock_irqrestore(&device_domain_lock, flags);
1471 static void iommu_flush_iotlb_psi(struct intel_iommu *iommu,
1472 struct dmar_domain *domain,
1473 unsigned long pfn, unsigned int pages,
1474 int ih, int map)
1476 unsigned int mask = ilog2(__roundup_pow_of_two(pages));
1477 uint64_t addr = (uint64_t)pfn << VTD_PAGE_SHIFT;
1478 u16 did = domain->iommu_did[iommu->seq_id];
1480 BUG_ON(pages == 0);
1482 if (ih)
1483 ih = 1 << 6;
1485 * Fallback to domain selective flush if no PSI support or the size is
1486 * too big.
1487 * PSI requires page size to be 2 ^ x, and the base address is naturally
1488 * aligned to the size
1490 if (!cap_pgsel_inv(iommu->cap) || mask > cap_max_amask_val(iommu->cap))
1491 iommu->flush.flush_iotlb(iommu, did, 0, 0,
1492 DMA_TLB_DSI_FLUSH);
1493 else
1494 iommu->flush.flush_iotlb(iommu, did, addr | ih, mask,
1495 DMA_TLB_PSI_FLUSH);
1498 * In caching mode, changes of pages from non-present to present require
1499 * flush. However, device IOTLB doesn't need to be flushed in this case.
1501 if (!cap_caching_mode(iommu->cap) || !map)
1502 iommu_flush_dev_iotlb(domain, addr, mask);
1505 /* Notification for newly created mappings */
1506 static inline void __mapping_notify_one(struct intel_iommu *iommu,
1507 struct dmar_domain *domain,
1508 unsigned long pfn, unsigned int pages)
1510 /* It's a non-present to present mapping. Only flush if caching mode */
1511 if (cap_caching_mode(iommu->cap))
1512 iommu_flush_iotlb_psi(iommu, domain, pfn, pages, 0, 1);
1513 else
1514 iommu_flush_write_buffer(iommu);
1517 static void iommu_flush_iova(struct iova_domain *iovad)
1519 struct dmar_domain *domain;
1520 int idx;
1522 domain = container_of(iovad, struct dmar_domain, iovad);
1524 for_each_domain_iommu(idx, domain) {
1525 struct intel_iommu *iommu = g_iommus[idx];
1526 u16 did = domain->iommu_did[iommu->seq_id];
1528 iommu->flush.flush_iotlb(iommu, did, 0, 0, DMA_TLB_DSI_FLUSH);
1530 if (!cap_caching_mode(iommu->cap))
1531 iommu_flush_dev_iotlb(get_iommu_domain(iommu, did),
1532 0, MAX_AGAW_PFN_WIDTH);
1536 static void iommu_disable_protect_mem_regions(struct intel_iommu *iommu)
1538 u32 pmen;
1539 unsigned long flags;
1541 if (!cap_plmr(iommu->cap) && !cap_phmr(iommu->cap))
1542 return;
1544 raw_spin_lock_irqsave(&iommu->register_lock, flags);
1545 pmen = readl(iommu->reg + DMAR_PMEN_REG);
1546 pmen &= ~DMA_PMEN_EPM;
1547 writel(pmen, iommu->reg + DMAR_PMEN_REG);
1549 /* wait for the protected region status bit to clear */
1550 IOMMU_WAIT_OP(iommu, DMAR_PMEN_REG,
1551 readl, !(pmen & DMA_PMEN_PRS), pmen);
1553 raw_spin_unlock_irqrestore(&iommu->register_lock, flags);
1556 static void iommu_enable_translation(struct intel_iommu *iommu)
1558 u32 sts;
1559 unsigned long flags;
1561 raw_spin_lock_irqsave(&iommu->register_lock, flags);
1562 iommu->gcmd |= DMA_GCMD_TE;
1563 writel(iommu->gcmd, iommu->reg + DMAR_GCMD_REG);
1565 /* Make sure hardware complete it */
1566 IOMMU_WAIT_OP(iommu, DMAR_GSTS_REG,
1567 readl, (sts & DMA_GSTS_TES), sts);
1569 raw_spin_unlock_irqrestore(&iommu->register_lock, flags);
1572 static void iommu_disable_translation(struct intel_iommu *iommu)
1574 u32 sts;
1575 unsigned long flag;
1577 raw_spin_lock_irqsave(&iommu->register_lock, flag);
1578 iommu->gcmd &= ~DMA_GCMD_TE;
1579 writel(iommu->gcmd, iommu->reg + DMAR_GCMD_REG);
1581 /* Make sure hardware complete it */
1582 IOMMU_WAIT_OP(iommu, DMAR_GSTS_REG,
1583 readl, (!(sts & DMA_GSTS_TES)), sts);
1585 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
1589 static int iommu_init_domains(struct intel_iommu *iommu)
1591 u32 ndomains, nlongs;
1592 size_t size;
1594 ndomains = cap_ndoms(iommu->cap);
1595 pr_debug("%s: Number of Domains supported <%d>\n",
1596 iommu->name, ndomains);
1597 nlongs = BITS_TO_LONGS(ndomains);
1599 spin_lock_init(&iommu->lock);
1601 iommu->domain_ids = kcalloc(nlongs, sizeof(unsigned long), GFP_KERNEL);
1602 if (!iommu->domain_ids) {
1603 pr_err("%s: Allocating domain id array failed\n",
1604 iommu->name);
1605 return -ENOMEM;
1608 size = (ALIGN(ndomains, 256) >> 8) * sizeof(struct dmar_domain **);
1609 iommu->domains = kzalloc(size, GFP_KERNEL);
1611 if (iommu->domains) {
1612 size = 256 * sizeof(struct dmar_domain *);
1613 iommu->domains[0] = kzalloc(size, GFP_KERNEL);
1616 if (!iommu->domains || !iommu->domains[0]) {
1617 pr_err("%s: Allocating domain array failed\n",
1618 iommu->name);
1619 kfree(iommu->domain_ids);
1620 kfree(iommu->domains);
1621 iommu->domain_ids = NULL;
1622 iommu->domains = NULL;
1623 return -ENOMEM;
1629 * If Caching mode is set, then invalid translations are tagged
1630 * with domain-id 0, hence we need to pre-allocate it. We also
1631 * use domain-id 0 as a marker for non-allocated domain-id, so
1632 * make sure it is not used for a real domain.
1634 set_bit(0, iommu->domain_ids);
1637 * Vt-d spec rev3.0 (section 6.2.3.1) requires that each pasid
1638 * entry for first-level or pass-through translation modes should
1639 * be programmed with a domain id different from those used for
1640 * second-level or nested translation. We reserve a domain id for
1641 * this purpose.
1643 if (sm_supported(iommu))
1644 set_bit(FLPT_DEFAULT_DID, iommu->domain_ids);
1646 return 0;
1649 static void disable_dmar_iommu(struct intel_iommu *iommu)
1651 struct device_domain_info *info, *tmp;
1652 unsigned long flags;
1654 if (!iommu->domains || !iommu->domain_ids)
1655 return;
1657 again:
1658 spin_lock_irqsave(&device_domain_lock, flags);
1659 list_for_each_entry_safe(info, tmp, &device_domain_list, global) {
1660 struct dmar_domain *domain;
1662 if (info->iommu != iommu)
1663 continue;
1665 if (!info->dev || !info->domain)
1666 continue;
1668 domain = info->domain;
1670 __dmar_remove_one_dev_info(info);
1672 if (!domain_type_is_vm_or_si(domain)) {
1674 * The domain_exit() function can't be called under
1675 * device_domain_lock, as it takes this lock itself.
1676 * So release the lock here and re-run the loop
1677 * afterwards.
1679 spin_unlock_irqrestore(&device_domain_lock, flags);
1680 domain_exit(domain);
1681 goto again;
1684 spin_unlock_irqrestore(&device_domain_lock, flags);
1686 if (iommu->gcmd & DMA_GCMD_TE)
1687 iommu_disable_translation(iommu);
1690 static void free_dmar_iommu(struct intel_iommu *iommu)
1692 if ((iommu->domains) && (iommu->domain_ids)) {
1693 int elems = ALIGN(cap_ndoms(iommu->cap), 256) >> 8;
1694 int i;
1696 for (i = 0; i < elems; i++)
1697 kfree(iommu->domains[i]);
1698 kfree(iommu->domains);
1699 kfree(iommu->domain_ids);
1700 iommu->domains = NULL;
1701 iommu->domain_ids = NULL;
1704 g_iommus[iommu->seq_id] = NULL;
1706 /* free context mapping */
1707 free_context_table(iommu);
1709 #ifdef CONFIG_INTEL_IOMMU_SVM
1710 if (pasid_supported(iommu)) {
1711 if (ecap_prs(iommu->ecap))
1712 intel_svm_finish_prq(iommu);
1714 #endif
1717 static struct dmar_domain *alloc_domain(int flags)
1719 struct dmar_domain *domain;
1721 domain = alloc_domain_mem();
1722 if (!domain)
1723 return NULL;
1725 memset(domain, 0, sizeof(*domain));
1726 domain->nid = NUMA_NO_NODE;
1727 domain->flags = flags;
1728 domain->has_iotlb_device = false;
1729 INIT_LIST_HEAD(&domain->devices);
1731 return domain;
1734 /* Must be called with iommu->lock */
1735 static int domain_attach_iommu(struct dmar_domain *domain,
1736 struct intel_iommu *iommu)
1738 unsigned long ndomains;
1739 int num;
1741 assert_spin_locked(&device_domain_lock);
1742 assert_spin_locked(&iommu->lock);
1744 domain->iommu_refcnt[iommu->seq_id] += 1;
1745 domain->iommu_count += 1;
1746 if (domain->iommu_refcnt[iommu->seq_id] == 1) {
1747 ndomains = cap_ndoms(iommu->cap);
1748 num = find_first_zero_bit(iommu->domain_ids, ndomains);
1750 if (num >= ndomains) {
1751 pr_err("%s: No free domain ids\n", iommu->name);
1752 domain->iommu_refcnt[iommu->seq_id] -= 1;
1753 domain->iommu_count -= 1;
1754 return -ENOSPC;
1757 set_bit(num, iommu->domain_ids);
1758 set_iommu_domain(iommu, num, domain);
1760 domain->iommu_did[iommu->seq_id] = num;
1761 domain->nid = iommu->node;
1763 domain_update_iommu_cap(domain);
1766 return 0;
1769 static int domain_detach_iommu(struct dmar_domain *domain,
1770 struct intel_iommu *iommu)
1772 int num, count;
1774 assert_spin_locked(&device_domain_lock);
1775 assert_spin_locked(&iommu->lock);
1777 domain->iommu_refcnt[iommu->seq_id] -= 1;
1778 count = --domain->iommu_count;
1779 if (domain->iommu_refcnt[iommu->seq_id] == 0) {
1780 num = domain->iommu_did[iommu->seq_id];
1781 clear_bit(num, iommu->domain_ids);
1782 set_iommu_domain(iommu, num, NULL);
1784 domain_update_iommu_cap(domain);
1785 domain->iommu_did[iommu->seq_id] = 0;
1788 return count;
1791 static struct iova_domain reserved_iova_list;
1792 static struct lock_class_key reserved_rbtree_key;
1794 static int dmar_init_reserved_ranges(void)
1796 struct pci_dev *pdev = NULL;
1797 struct iova *iova;
1798 int i;
1800 init_iova_domain(&reserved_iova_list, VTD_PAGE_SIZE, IOVA_START_PFN);
1802 lockdep_set_class(&reserved_iova_list.iova_rbtree_lock,
1803 &reserved_rbtree_key);
1805 /* IOAPIC ranges shouldn't be accessed by DMA */
1806 iova = reserve_iova(&reserved_iova_list, IOVA_PFN(IOAPIC_RANGE_START),
1807 IOVA_PFN(IOAPIC_RANGE_END));
1808 if (!iova) {
1809 pr_err("Reserve IOAPIC range failed\n");
1810 return -ENODEV;
1813 /* Reserve all PCI MMIO to avoid peer-to-peer access */
1814 for_each_pci_dev(pdev) {
1815 struct resource *r;
1817 for (i = 0; i < PCI_NUM_RESOURCES; i++) {
1818 r = &pdev->resource[i];
1819 if (!r->flags || !(r->flags & IORESOURCE_MEM))
1820 continue;
1821 iova = reserve_iova(&reserved_iova_list,
1822 IOVA_PFN(r->start),
1823 IOVA_PFN(r->end));
1824 if (!iova) {
1825 pci_err(pdev, "Reserve iova for %pR failed\n", r);
1826 return -ENODEV;
1830 return 0;
1833 static void domain_reserve_special_ranges(struct dmar_domain *domain)
1835 copy_reserved_iova(&reserved_iova_list, &domain->iovad);
1838 static inline int guestwidth_to_adjustwidth(int gaw)
1840 int agaw;
1841 int r = (gaw - 12) % 9;
1843 if (r == 0)
1844 agaw = gaw;
1845 else
1846 agaw = gaw + 9 - r;
1847 if (agaw > 64)
1848 agaw = 64;
1849 return agaw;
1852 static int domain_init(struct dmar_domain *domain, struct intel_iommu *iommu,
1853 int guest_width)
1855 int adjust_width, agaw;
1856 unsigned long sagaw;
1857 int err;
1859 init_iova_domain(&domain->iovad, VTD_PAGE_SIZE, IOVA_START_PFN);
1861 err = init_iova_flush_queue(&domain->iovad,
1862 iommu_flush_iova, iova_entry_free);
1863 if (err)
1864 return err;
1866 domain_reserve_special_ranges(domain);
1868 /* calculate AGAW */
1869 if (guest_width > cap_mgaw(iommu->cap))
1870 guest_width = cap_mgaw(iommu->cap);
1871 domain->gaw = guest_width;
1872 adjust_width = guestwidth_to_adjustwidth(guest_width);
1873 agaw = width_to_agaw(adjust_width);
1874 sagaw = cap_sagaw(iommu->cap);
1875 if (!test_bit(agaw, &sagaw)) {
1876 /* hardware doesn't support it, choose a bigger one */
1877 pr_debug("Hardware doesn't support agaw %d\n", agaw);
1878 agaw = find_next_bit(&sagaw, 5, agaw);
1879 if (agaw >= 5)
1880 return -ENODEV;
1882 domain->agaw = agaw;
1884 if (ecap_coherent(iommu->ecap))
1885 domain->iommu_coherency = 1;
1886 else
1887 domain->iommu_coherency = 0;
1889 if (ecap_sc_support(iommu->ecap))
1890 domain->iommu_snooping = 1;
1891 else
1892 domain->iommu_snooping = 0;
1894 if (intel_iommu_superpage)
1895 domain->iommu_superpage = fls(cap_super_page_val(iommu->cap));
1896 else
1897 domain->iommu_superpage = 0;
1899 domain->nid = iommu->node;
1901 /* always allocate the top pgd */
1902 domain->pgd = (struct dma_pte *)alloc_pgtable_page(domain->nid);
1903 if (!domain->pgd)
1904 return -ENOMEM;
1905 __iommu_flush_cache(iommu, domain->pgd, PAGE_SIZE);
1906 return 0;
1909 static void domain_exit(struct dmar_domain *domain)
1911 struct page *freelist;
1913 /* Remove associated devices and clear attached or cached domains */
1914 rcu_read_lock();
1915 domain_remove_dev_info(domain);
1916 rcu_read_unlock();
1918 /* destroy iovas */
1919 put_iova_domain(&domain->iovad);
1921 freelist = domain_unmap(domain, 0, DOMAIN_MAX_PFN(domain->gaw));
1923 dma_free_pagelist(freelist);
1925 free_domain_mem(domain);
1929 * Get the PASID directory size for scalable mode context entry.
1930 * Value of X in the PDTS field of a scalable mode context entry
1931 * indicates PASID directory with 2^(X + 7) entries.
1933 static inline unsigned long context_get_sm_pds(struct pasid_table *table)
1935 int pds, max_pde;
1937 max_pde = table->max_pasid >> PASID_PDE_SHIFT;
1938 pds = find_first_bit((unsigned long *)&max_pde, MAX_NR_PASID_BITS);
1939 if (pds < 7)
1940 return 0;
1942 return pds - 7;
1946 * Set the RID_PASID field of a scalable mode context entry. The
1947 * IOMMU hardware will use the PASID value set in this field for
1948 * DMA translations of DMA requests without PASID.
1950 static inline void
1951 context_set_sm_rid2pasid(struct context_entry *context, unsigned long pasid)
1953 context->hi |= pasid & ((1 << 20) - 1);
1954 context->hi |= (1 << 20);
1958 * Set the DTE(Device-TLB Enable) field of a scalable mode context
1959 * entry.
1961 static inline void context_set_sm_dte(struct context_entry *context)
1963 context->lo |= (1 << 2);
1967 * Set the PRE(Page Request Enable) field of a scalable mode context
1968 * entry.
1970 static inline void context_set_sm_pre(struct context_entry *context)
1972 context->lo |= (1 << 4);
1975 /* Convert value to context PASID directory size field coding. */
1976 #define context_pdts(pds) (((pds) & 0x7) << 9)
1978 static int domain_context_mapping_one(struct dmar_domain *domain,
1979 struct intel_iommu *iommu,
1980 struct pasid_table *table,
1981 u8 bus, u8 devfn)
1983 u16 did = domain->iommu_did[iommu->seq_id];
1984 int translation = CONTEXT_TT_MULTI_LEVEL;
1985 struct device_domain_info *info = NULL;
1986 struct context_entry *context;
1987 unsigned long flags;
1988 int ret;
1990 WARN_ON(did == 0);
1992 if (hw_pass_through && domain_type_is_si(domain))
1993 translation = CONTEXT_TT_PASS_THROUGH;
1995 pr_debug("Set context mapping for %02x:%02x.%d\n",
1996 bus, PCI_SLOT(devfn), PCI_FUNC(devfn));
1998 BUG_ON(!domain->pgd);
2000 spin_lock_irqsave(&device_domain_lock, flags);
2001 spin_lock(&iommu->lock);
2003 ret = -ENOMEM;
2004 context = iommu_context_addr(iommu, bus, devfn, 1);
2005 if (!context)
2006 goto out_unlock;
2008 ret = 0;
2009 if (context_present(context))
2010 goto out_unlock;
2013 * For kdump cases, old valid entries may be cached due to the
2014 * in-flight DMA and copied pgtable, but there is no unmapping
2015 * behaviour for them, thus we need an explicit cache flush for
2016 * the newly-mapped device. For kdump, at this point, the device
2017 * is supposed to finish reset at its driver probe stage, so no
2018 * in-flight DMA will exist, and we don't need to worry anymore
2019 * hereafter.
2021 if (context_copied(context)) {
2022 u16 did_old = context_domain_id(context);
2024 if (did_old < cap_ndoms(iommu->cap)) {
2025 iommu->flush.flush_context(iommu, did_old,
2026 (((u16)bus) << 8) | devfn,
2027 DMA_CCMD_MASK_NOBIT,
2028 DMA_CCMD_DEVICE_INVL);
2029 iommu->flush.flush_iotlb(iommu, did_old, 0, 0,
2030 DMA_TLB_DSI_FLUSH);
2034 context_clear_entry(context);
2036 if (sm_supported(iommu)) {
2037 unsigned long pds;
2039 WARN_ON(!table);
2041 /* Setup the PASID DIR pointer: */
2042 pds = context_get_sm_pds(table);
2043 context->lo = (u64)virt_to_phys(table->table) |
2044 context_pdts(pds);
2046 /* Setup the RID_PASID field: */
2047 context_set_sm_rid2pasid(context, PASID_RID2PASID);
2050 * Setup the Device-TLB enable bit and Page request
2051 * Enable bit:
2053 info = iommu_support_dev_iotlb(domain, iommu, bus, devfn);
2054 if (info && info->ats_supported)
2055 context_set_sm_dte(context);
2056 if (info && info->pri_supported)
2057 context_set_sm_pre(context);
2058 } else {
2059 struct dma_pte *pgd = domain->pgd;
2060 int agaw;
2062 context_set_domain_id(context, did);
2064 if (translation != CONTEXT_TT_PASS_THROUGH) {
2066 * Skip top levels of page tables for iommu which has
2067 * less agaw than default. Unnecessary for PT mode.
2069 for (agaw = domain->agaw; agaw > iommu->agaw; agaw--) {
2070 ret = -ENOMEM;
2071 pgd = phys_to_virt(dma_pte_addr(pgd));
2072 if (!dma_pte_present(pgd))
2073 goto out_unlock;
2076 info = iommu_support_dev_iotlb(domain, iommu, bus, devfn);
2077 if (info && info->ats_supported)
2078 translation = CONTEXT_TT_DEV_IOTLB;
2079 else
2080 translation = CONTEXT_TT_MULTI_LEVEL;
2082 context_set_address_root(context, virt_to_phys(pgd));
2083 context_set_address_width(context, agaw);
2084 } else {
2086 * In pass through mode, AW must be programmed to
2087 * indicate the largest AGAW value supported by
2088 * hardware. And ASR is ignored by hardware.
2090 context_set_address_width(context, iommu->msagaw);
2093 context_set_translation_type(context, translation);
2096 context_set_fault_enable(context);
2097 context_set_present(context);
2098 domain_flush_cache(domain, context, sizeof(*context));
2101 * It's a non-present to present mapping. If hardware doesn't cache
2102 * non-present entry we only need to flush the write-buffer. If the
2103 * _does_ cache non-present entries, then it does so in the special
2104 * domain #0, which we have to flush:
2106 if (cap_caching_mode(iommu->cap)) {
2107 iommu->flush.flush_context(iommu, 0,
2108 (((u16)bus) << 8) | devfn,
2109 DMA_CCMD_MASK_NOBIT,
2110 DMA_CCMD_DEVICE_INVL);
2111 iommu->flush.flush_iotlb(iommu, did, 0, 0, DMA_TLB_DSI_FLUSH);
2112 } else {
2113 iommu_flush_write_buffer(iommu);
2115 iommu_enable_dev_iotlb(info);
2117 ret = 0;
2119 out_unlock:
2120 spin_unlock(&iommu->lock);
2121 spin_unlock_irqrestore(&device_domain_lock, flags);
2123 return ret;
2126 struct domain_context_mapping_data {
2127 struct dmar_domain *domain;
2128 struct intel_iommu *iommu;
2129 struct pasid_table *table;
2132 static int domain_context_mapping_cb(struct pci_dev *pdev,
2133 u16 alias, void *opaque)
2135 struct domain_context_mapping_data *data = opaque;
2137 return domain_context_mapping_one(data->domain, data->iommu,
2138 data->table, PCI_BUS_NUM(alias),
2139 alias & 0xff);
2142 static int
2143 domain_context_mapping(struct dmar_domain *domain, struct device *dev)
2145 struct domain_context_mapping_data data;
2146 struct pasid_table *table;
2147 struct intel_iommu *iommu;
2148 u8 bus, devfn;
2150 iommu = device_to_iommu(dev, &bus, &devfn);
2151 if (!iommu)
2152 return -ENODEV;
2154 table = intel_pasid_get_table(dev);
2156 if (!dev_is_pci(dev))
2157 return domain_context_mapping_one(domain, iommu, table,
2158 bus, devfn);
2160 data.domain = domain;
2161 data.iommu = iommu;
2162 data.table = table;
2164 return pci_for_each_dma_alias(to_pci_dev(dev),
2165 &domain_context_mapping_cb, &data);
2168 static int domain_context_mapped_cb(struct pci_dev *pdev,
2169 u16 alias, void *opaque)
2171 struct intel_iommu *iommu = opaque;
2173 return !device_context_mapped(iommu, PCI_BUS_NUM(alias), alias & 0xff);
2176 static int domain_context_mapped(struct device *dev)
2178 struct intel_iommu *iommu;
2179 u8 bus, devfn;
2181 iommu = device_to_iommu(dev, &bus, &devfn);
2182 if (!iommu)
2183 return -ENODEV;
2185 if (!dev_is_pci(dev))
2186 return device_context_mapped(iommu, bus, devfn);
2188 return !pci_for_each_dma_alias(to_pci_dev(dev),
2189 domain_context_mapped_cb, iommu);
2192 /* Returns a number of VTD pages, but aligned to MM page size */
2193 static inline unsigned long aligned_nrpages(unsigned long host_addr,
2194 size_t size)
2196 host_addr &= ~PAGE_MASK;
2197 return PAGE_ALIGN(host_addr + size) >> VTD_PAGE_SHIFT;
2200 /* Return largest possible superpage level for a given mapping */
2201 static inline int hardware_largepage_caps(struct dmar_domain *domain,
2202 unsigned long iov_pfn,
2203 unsigned long phy_pfn,
2204 unsigned long pages)
2206 int support, level = 1;
2207 unsigned long pfnmerge;
2209 support = domain->iommu_superpage;
2211 /* To use a large page, the virtual *and* physical addresses
2212 must be aligned to 2MiB/1GiB/etc. Lower bits set in either
2213 of them will mean we have to use smaller pages. So just
2214 merge them and check both at once. */
2215 pfnmerge = iov_pfn | phy_pfn;
2217 while (support && !(pfnmerge & ~VTD_STRIDE_MASK)) {
2218 pages >>= VTD_STRIDE_SHIFT;
2219 if (!pages)
2220 break;
2221 pfnmerge >>= VTD_STRIDE_SHIFT;
2222 level++;
2223 support--;
2225 return level;
2228 static int __domain_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
2229 struct scatterlist *sg, unsigned long phys_pfn,
2230 unsigned long nr_pages, int prot)
2232 struct dma_pte *first_pte = NULL, *pte = NULL;
2233 phys_addr_t uninitialized_var(pteval);
2234 unsigned long sg_res = 0;
2235 unsigned int largepage_lvl = 0;
2236 unsigned long lvl_pages = 0;
2238 BUG_ON(!domain_pfn_supported(domain, iov_pfn + nr_pages - 1));
2240 if ((prot & (DMA_PTE_READ|DMA_PTE_WRITE)) == 0)
2241 return -EINVAL;
2243 prot &= DMA_PTE_READ | DMA_PTE_WRITE | DMA_PTE_SNP;
2245 if (!sg) {
2246 sg_res = nr_pages;
2247 pteval = ((phys_addr_t)phys_pfn << VTD_PAGE_SHIFT) | prot;
2250 while (nr_pages > 0) {
2251 uint64_t tmp;
2253 if (!sg_res) {
2254 unsigned int pgoff = sg->offset & ~PAGE_MASK;
2256 sg_res = aligned_nrpages(sg->offset, sg->length);
2257 sg->dma_address = ((dma_addr_t)iov_pfn << VTD_PAGE_SHIFT) + pgoff;
2258 sg->dma_length = sg->length;
2259 pteval = (sg_phys(sg) - pgoff) | prot;
2260 phys_pfn = pteval >> VTD_PAGE_SHIFT;
2263 if (!pte) {
2264 largepage_lvl = hardware_largepage_caps(domain, iov_pfn, phys_pfn, sg_res);
2266 first_pte = pte = pfn_to_dma_pte(domain, iov_pfn, &largepage_lvl);
2267 if (!pte)
2268 return -ENOMEM;
2269 /* It is large page*/
2270 if (largepage_lvl > 1) {
2271 unsigned long nr_superpages, end_pfn;
2273 pteval |= DMA_PTE_LARGE_PAGE;
2274 lvl_pages = lvl_to_nr_pages(largepage_lvl);
2276 nr_superpages = sg_res / lvl_pages;
2277 end_pfn = iov_pfn + nr_superpages * lvl_pages - 1;
2280 * Ensure that old small page tables are
2281 * removed to make room for superpage(s).
2282 * We're adding new large pages, so make sure
2283 * we don't remove their parent tables.
2285 dma_pte_free_pagetable(domain, iov_pfn, end_pfn,
2286 largepage_lvl + 1);
2287 } else {
2288 pteval &= ~(uint64_t)DMA_PTE_LARGE_PAGE;
2292 /* We don't need lock here, nobody else
2293 * touches the iova range
2295 tmp = cmpxchg64_local(&pte->val, 0ULL, pteval);
2296 if (tmp) {
2297 static int dumps = 5;
2298 pr_crit("ERROR: DMA PTE for vPFN 0x%lx already set (to %llx not %llx)\n",
2299 iov_pfn, tmp, (unsigned long long)pteval);
2300 if (dumps) {
2301 dumps--;
2302 debug_dma_dump_mappings(NULL);
2304 WARN_ON(1);
2307 lvl_pages = lvl_to_nr_pages(largepage_lvl);
2309 BUG_ON(nr_pages < lvl_pages);
2310 BUG_ON(sg_res < lvl_pages);
2312 nr_pages -= lvl_pages;
2313 iov_pfn += lvl_pages;
2314 phys_pfn += lvl_pages;
2315 pteval += lvl_pages * VTD_PAGE_SIZE;
2316 sg_res -= lvl_pages;
2318 /* If the next PTE would be the first in a new page, then we
2319 need to flush the cache on the entries we've just written.
2320 And then we'll need to recalculate 'pte', so clear it and
2321 let it get set again in the if (!pte) block above.
2323 If we're done (!nr_pages) we need to flush the cache too.
2325 Also if we've been setting superpages, we may need to
2326 recalculate 'pte' and switch back to smaller pages for the
2327 end of the mapping, if the trailing size is not enough to
2328 use another superpage (i.e. sg_res < lvl_pages). */
2329 pte++;
2330 if (!nr_pages || first_pte_in_page(pte) ||
2331 (largepage_lvl > 1 && sg_res < lvl_pages)) {
2332 domain_flush_cache(domain, first_pte,
2333 (void *)pte - (void *)first_pte);
2334 pte = NULL;
2337 if (!sg_res && nr_pages)
2338 sg = sg_next(sg);
2340 return 0;
2343 static int domain_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
2344 struct scatterlist *sg, unsigned long phys_pfn,
2345 unsigned long nr_pages, int prot)
2347 int ret;
2348 struct intel_iommu *iommu;
2350 /* Do the real mapping first */
2351 ret = __domain_mapping(domain, iov_pfn, sg, phys_pfn, nr_pages, prot);
2352 if (ret)
2353 return ret;
2355 /* Notify about the new mapping */
2356 if (domain_type_is_vm(domain)) {
2357 /* VM typed domains can have more than one IOMMUs */
2358 int iommu_id;
2359 for_each_domain_iommu(iommu_id, domain) {
2360 iommu = g_iommus[iommu_id];
2361 __mapping_notify_one(iommu, domain, iov_pfn, nr_pages);
2363 } else {
2364 /* General domains only have one IOMMU */
2365 iommu = domain_get_iommu(domain);
2366 __mapping_notify_one(iommu, domain, iov_pfn, nr_pages);
2369 return 0;
2372 static inline int domain_sg_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
2373 struct scatterlist *sg, unsigned long nr_pages,
2374 int prot)
2376 return domain_mapping(domain, iov_pfn, sg, 0, nr_pages, prot);
2379 static inline int domain_pfn_mapping(struct dmar_domain *domain, unsigned long iov_pfn,
2380 unsigned long phys_pfn, unsigned long nr_pages,
2381 int prot)
2383 return domain_mapping(domain, iov_pfn, NULL, phys_pfn, nr_pages, prot);
2386 static void domain_context_clear_one(struct intel_iommu *iommu, u8 bus, u8 devfn)
2388 unsigned long flags;
2389 struct context_entry *context;
2390 u16 did_old;
2392 if (!iommu)
2393 return;
2395 spin_lock_irqsave(&iommu->lock, flags);
2396 context = iommu_context_addr(iommu, bus, devfn, 0);
2397 if (!context) {
2398 spin_unlock_irqrestore(&iommu->lock, flags);
2399 return;
2401 did_old = context_domain_id(context);
2402 context_clear_entry(context);
2403 __iommu_flush_cache(iommu, context, sizeof(*context));
2404 spin_unlock_irqrestore(&iommu->lock, flags);
2405 iommu->flush.flush_context(iommu,
2406 did_old,
2407 (((u16)bus) << 8) | devfn,
2408 DMA_CCMD_MASK_NOBIT,
2409 DMA_CCMD_DEVICE_INVL);
2410 iommu->flush.flush_iotlb(iommu,
2411 did_old,
2414 DMA_TLB_DSI_FLUSH);
2417 static inline void unlink_domain_info(struct device_domain_info *info)
2419 assert_spin_locked(&device_domain_lock);
2420 list_del(&info->link);
2421 list_del(&info->global);
2422 if (info->dev)
2423 info->dev->archdata.iommu = NULL;
2426 static void domain_remove_dev_info(struct dmar_domain *domain)
2428 struct device_domain_info *info, *tmp;
2429 unsigned long flags;
2431 spin_lock_irqsave(&device_domain_lock, flags);
2432 list_for_each_entry_safe(info, tmp, &domain->devices, link)
2433 __dmar_remove_one_dev_info(info);
2434 spin_unlock_irqrestore(&device_domain_lock, flags);
2438 * find_domain
2439 * Note: we use struct device->archdata.iommu stores the info
2441 static struct dmar_domain *find_domain(struct device *dev)
2443 struct device_domain_info *info;
2445 /* No lock here, assumes no domain exit in normal case */
2446 info = dev->archdata.iommu;
2447 if (likely(info))
2448 return info->domain;
2449 return NULL;
2452 static inline struct device_domain_info *
2453 dmar_search_domain_by_dev_info(int segment, int bus, int devfn)
2455 struct device_domain_info *info;
2457 list_for_each_entry(info, &device_domain_list, global)
2458 if (info->iommu->segment == segment && info->bus == bus &&
2459 info->devfn == devfn)
2460 return info;
2462 return NULL;
2465 static struct dmar_domain *dmar_insert_one_dev_info(struct intel_iommu *iommu,
2466 int bus, int devfn,
2467 struct device *dev,
2468 struct dmar_domain *domain)
2470 struct dmar_domain *found = NULL;
2471 struct device_domain_info *info;
2472 unsigned long flags;
2473 int ret;
2475 info = alloc_devinfo_mem();
2476 if (!info)
2477 return NULL;
2479 info->bus = bus;
2480 info->devfn = devfn;
2481 info->ats_supported = info->pasid_supported = info->pri_supported = 0;
2482 info->ats_enabled = info->pasid_enabled = info->pri_enabled = 0;
2483 info->ats_qdep = 0;
2484 info->dev = dev;
2485 info->domain = domain;
2486 info->iommu = iommu;
2487 info->pasid_table = NULL;
2489 if (dev && dev_is_pci(dev)) {
2490 struct pci_dev *pdev = to_pci_dev(info->dev);
2492 if (!pdev->untrusted &&
2493 !pci_ats_disabled() &&
2494 ecap_dev_iotlb_support(iommu->ecap) &&
2495 pci_find_ext_capability(pdev, PCI_EXT_CAP_ID_ATS) &&
2496 dmar_find_matched_atsr_unit(pdev))
2497 info->ats_supported = 1;
2499 if (sm_supported(iommu)) {
2500 if (pasid_supported(iommu)) {
2501 int features = pci_pasid_features(pdev);
2502 if (features >= 0)
2503 info->pasid_supported = features | 1;
2506 if (info->ats_supported && ecap_prs(iommu->ecap) &&
2507 pci_find_ext_capability(pdev, PCI_EXT_CAP_ID_PRI))
2508 info->pri_supported = 1;
2512 spin_lock_irqsave(&device_domain_lock, flags);
2513 if (dev)
2514 found = find_domain(dev);
2516 if (!found) {
2517 struct device_domain_info *info2;
2518 info2 = dmar_search_domain_by_dev_info(iommu->segment, bus, devfn);
2519 if (info2) {
2520 found = info2->domain;
2521 info2->dev = dev;
2525 if (found) {
2526 spin_unlock_irqrestore(&device_domain_lock, flags);
2527 free_devinfo_mem(info);
2528 /* Caller must free the original domain */
2529 return found;
2532 spin_lock(&iommu->lock);
2533 ret = domain_attach_iommu(domain, iommu);
2534 spin_unlock(&iommu->lock);
2536 if (ret) {
2537 spin_unlock_irqrestore(&device_domain_lock, flags);
2538 free_devinfo_mem(info);
2539 return NULL;
2542 list_add(&info->link, &domain->devices);
2543 list_add(&info->global, &device_domain_list);
2544 if (dev)
2545 dev->archdata.iommu = info;
2546 spin_unlock_irqrestore(&device_domain_lock, flags);
2548 /* PASID table is mandatory for a PCI device in scalable mode. */
2549 if (dev && dev_is_pci(dev) && sm_supported(iommu)) {
2550 ret = intel_pasid_alloc_table(dev);
2551 if (ret) {
2552 dev_err(dev, "PASID table allocation failed\n");
2553 dmar_remove_one_dev_info(dev);
2554 return NULL;
2557 /* Setup the PASID entry for requests without PASID: */
2558 spin_lock(&iommu->lock);
2559 if (hw_pass_through && domain_type_is_si(domain))
2560 ret = intel_pasid_setup_pass_through(iommu, domain,
2561 dev, PASID_RID2PASID);
2562 else
2563 ret = intel_pasid_setup_second_level(iommu, domain,
2564 dev, PASID_RID2PASID);
2565 spin_unlock(&iommu->lock);
2566 if (ret) {
2567 dev_err(dev, "Setup RID2PASID failed\n");
2568 dmar_remove_one_dev_info(dev);
2569 return NULL;
2573 if (dev && domain_context_mapping(domain, dev)) {
2574 dev_err(dev, "Domain context map failed\n");
2575 dmar_remove_one_dev_info(dev);
2576 return NULL;
2579 return domain;
2582 static int get_last_alias(struct pci_dev *pdev, u16 alias, void *opaque)
2584 *(u16 *)opaque = alias;
2585 return 0;
2588 static struct dmar_domain *find_or_alloc_domain(struct device *dev, int gaw)
2590 struct device_domain_info *info;
2591 struct dmar_domain *domain = NULL;
2592 struct intel_iommu *iommu;
2593 u16 dma_alias;
2594 unsigned long flags;
2595 u8 bus, devfn;
2597 iommu = device_to_iommu(dev, &bus, &devfn);
2598 if (!iommu)
2599 return NULL;
2601 if (dev_is_pci(dev)) {
2602 struct pci_dev *pdev = to_pci_dev(dev);
2604 pci_for_each_dma_alias(pdev, get_last_alias, &dma_alias);
2606 spin_lock_irqsave(&device_domain_lock, flags);
2607 info = dmar_search_domain_by_dev_info(pci_domain_nr(pdev->bus),
2608 PCI_BUS_NUM(dma_alias),
2609 dma_alias & 0xff);
2610 if (info) {
2611 iommu = info->iommu;
2612 domain = info->domain;
2614 spin_unlock_irqrestore(&device_domain_lock, flags);
2616 /* DMA alias already has a domain, use it */
2617 if (info)
2618 goto out;
2621 /* Allocate and initialize new domain for the device */
2622 domain = alloc_domain(0);
2623 if (!domain)
2624 return NULL;
2625 if (domain_init(domain, iommu, gaw)) {
2626 domain_exit(domain);
2627 return NULL;
2630 out:
2632 return domain;
2635 static struct dmar_domain *set_domain_for_dev(struct device *dev,
2636 struct dmar_domain *domain)
2638 struct intel_iommu *iommu;
2639 struct dmar_domain *tmp;
2640 u16 req_id, dma_alias;
2641 u8 bus, devfn;
2643 iommu = device_to_iommu(dev, &bus, &devfn);
2644 if (!iommu)
2645 return NULL;
2647 req_id = ((u16)bus << 8) | devfn;
2649 if (dev_is_pci(dev)) {
2650 struct pci_dev *pdev = to_pci_dev(dev);
2652 pci_for_each_dma_alias(pdev, get_last_alias, &dma_alias);
2654 /* register PCI DMA alias device */
2655 if (req_id != dma_alias) {
2656 tmp = dmar_insert_one_dev_info(iommu, PCI_BUS_NUM(dma_alias),
2657 dma_alias & 0xff, NULL, domain);
2659 if (!tmp || tmp != domain)
2660 return tmp;
2664 tmp = dmar_insert_one_dev_info(iommu, bus, devfn, dev, domain);
2665 if (!tmp || tmp != domain)
2666 return tmp;
2668 return domain;
2671 static struct dmar_domain *get_domain_for_dev(struct device *dev, int gaw)
2673 struct dmar_domain *domain, *tmp;
2675 domain = find_domain(dev);
2676 if (domain)
2677 goto out;
2679 domain = find_or_alloc_domain(dev, gaw);
2680 if (!domain)
2681 goto out;
2683 tmp = set_domain_for_dev(dev, domain);
2684 if (!tmp || domain != tmp) {
2685 domain_exit(domain);
2686 domain = tmp;
2689 out:
2691 return domain;
2694 static int iommu_domain_identity_map(struct dmar_domain *domain,
2695 unsigned long long start,
2696 unsigned long long end)
2698 unsigned long first_vpfn = start >> VTD_PAGE_SHIFT;
2699 unsigned long last_vpfn = end >> VTD_PAGE_SHIFT;
2701 if (!reserve_iova(&domain->iovad, dma_to_mm_pfn(first_vpfn),
2702 dma_to_mm_pfn(last_vpfn))) {
2703 pr_err("Reserving iova failed\n");
2704 return -ENOMEM;
2707 pr_debug("Mapping reserved region %llx-%llx\n", start, end);
2709 * RMRR range might have overlap with physical memory range,
2710 * clear it first
2712 dma_pte_clear_range(domain, first_vpfn, last_vpfn);
2714 return __domain_mapping(domain, first_vpfn, NULL,
2715 first_vpfn, last_vpfn - first_vpfn + 1,
2716 DMA_PTE_READ|DMA_PTE_WRITE);
2719 static int domain_prepare_identity_map(struct device *dev,
2720 struct dmar_domain *domain,
2721 unsigned long long start,
2722 unsigned long long end)
2724 /* For _hardware_ passthrough, don't bother. But for software
2725 passthrough, we do it anyway -- it may indicate a memory
2726 range which is reserved in E820, so which didn't get set
2727 up to start with in si_domain */
2728 if (domain == si_domain && hw_pass_through) {
2729 dev_warn(dev, "Ignoring identity map for HW passthrough [0x%Lx - 0x%Lx]\n",
2730 start, end);
2731 return 0;
2734 dev_info(dev, "Setting identity map [0x%Lx - 0x%Lx]\n", start, end);
2736 if (end < start) {
2737 WARN(1, "Your BIOS is broken; RMRR ends before it starts!\n"
2738 "BIOS vendor: %s; Ver: %s; Product Version: %s\n",
2739 dmi_get_system_info(DMI_BIOS_VENDOR),
2740 dmi_get_system_info(DMI_BIOS_VERSION),
2741 dmi_get_system_info(DMI_PRODUCT_VERSION));
2742 return -EIO;
2745 if (end >> agaw_to_width(domain->agaw)) {
2746 WARN(1, "Your BIOS is broken; RMRR exceeds permitted address width (%d bits)\n"
2747 "BIOS vendor: %s; Ver: %s; Product Version: %s\n",
2748 agaw_to_width(domain->agaw),
2749 dmi_get_system_info(DMI_BIOS_VENDOR),
2750 dmi_get_system_info(DMI_BIOS_VERSION),
2751 dmi_get_system_info(DMI_PRODUCT_VERSION));
2752 return -EIO;
2755 return iommu_domain_identity_map(domain, start, end);
2758 static int iommu_prepare_identity_map(struct device *dev,
2759 unsigned long long start,
2760 unsigned long long end)
2762 struct dmar_domain *domain;
2763 int ret;
2765 domain = get_domain_for_dev(dev, DEFAULT_DOMAIN_ADDRESS_WIDTH);
2766 if (!domain)
2767 return -ENOMEM;
2769 ret = domain_prepare_identity_map(dev, domain, start, end);
2770 if (ret)
2771 domain_exit(domain);
2773 return ret;
2776 static inline int iommu_prepare_rmrr_dev(struct dmar_rmrr_unit *rmrr,
2777 struct device *dev)
2779 if (dev->archdata.iommu == DUMMY_DEVICE_DOMAIN_INFO)
2780 return 0;
2781 return iommu_prepare_identity_map(dev, rmrr->base_address,
2782 rmrr->end_address);
2785 #ifdef CONFIG_INTEL_IOMMU_FLOPPY_WA
2786 static inline void iommu_prepare_isa(void)
2788 struct pci_dev *pdev;
2789 int ret;
2791 pdev = pci_get_class(PCI_CLASS_BRIDGE_ISA << 8, NULL);
2792 if (!pdev)
2793 return;
2795 pr_info("Prepare 0-16MiB unity mapping for LPC\n");
2796 ret = iommu_prepare_identity_map(&pdev->dev, 0, 16*1024*1024 - 1);
2798 if (ret)
2799 pr_err("Failed to create 0-16MiB identity map - floppy might not work\n");
2801 pci_dev_put(pdev);
2803 #else
2804 static inline void iommu_prepare_isa(void)
2806 return;
2808 #endif /* !CONFIG_INTEL_IOMMU_FLPY_WA */
2810 static int md_domain_init(struct dmar_domain *domain, int guest_width);
2812 static int __init si_domain_init(int hw)
2814 int nid, ret;
2816 si_domain = alloc_domain(DOMAIN_FLAG_STATIC_IDENTITY);
2817 if (!si_domain)
2818 return -EFAULT;
2820 if (md_domain_init(si_domain, DEFAULT_DOMAIN_ADDRESS_WIDTH)) {
2821 domain_exit(si_domain);
2822 return -EFAULT;
2825 pr_debug("Identity mapping domain allocated\n");
2827 if (hw)
2828 return 0;
2830 for_each_online_node(nid) {
2831 unsigned long start_pfn, end_pfn;
2832 int i;
2834 for_each_mem_pfn_range(i, nid, &start_pfn, &end_pfn, NULL) {
2835 ret = iommu_domain_identity_map(si_domain,
2836 PFN_PHYS(start_pfn), PFN_PHYS(end_pfn));
2837 if (ret)
2838 return ret;
2842 return 0;
2845 static int identity_mapping(struct device *dev)
2847 struct device_domain_info *info;
2849 if (likely(!iommu_identity_mapping))
2850 return 0;
2852 info = dev->archdata.iommu;
2853 if (info && info != DUMMY_DEVICE_DOMAIN_INFO)
2854 return (info->domain == si_domain);
2856 return 0;
2859 static int domain_add_dev_info(struct dmar_domain *domain, struct device *dev)
2861 struct dmar_domain *ndomain;
2862 struct intel_iommu *iommu;
2863 u8 bus, devfn;
2865 iommu = device_to_iommu(dev, &bus, &devfn);
2866 if (!iommu)
2867 return -ENODEV;
2869 ndomain = dmar_insert_one_dev_info(iommu, bus, devfn, dev, domain);
2870 if (ndomain != domain)
2871 return -EBUSY;
2873 return 0;
2876 static bool device_has_rmrr(struct device *dev)
2878 struct dmar_rmrr_unit *rmrr;
2879 struct device *tmp;
2880 int i;
2882 rcu_read_lock();
2883 for_each_rmrr_units(rmrr) {
2885 * Return TRUE if this RMRR contains the device that
2886 * is passed in.
2888 for_each_active_dev_scope(rmrr->devices,
2889 rmrr->devices_cnt, i, tmp)
2890 if (tmp == dev) {
2891 rcu_read_unlock();
2892 return true;
2895 rcu_read_unlock();
2896 return false;
2900 * There are a couple cases where we need to restrict the functionality of
2901 * devices associated with RMRRs. The first is when evaluating a device for
2902 * identity mapping because problems exist when devices are moved in and out
2903 * of domains and their respective RMRR information is lost. This means that
2904 * a device with associated RMRRs will never be in a "passthrough" domain.
2905 * The second is use of the device through the IOMMU API. This interface
2906 * expects to have full control of the IOVA space for the device. We cannot
2907 * satisfy both the requirement that RMRR access is maintained and have an
2908 * unencumbered IOVA space. We also have no ability to quiesce the device's
2909 * use of the RMRR space or even inform the IOMMU API user of the restriction.
2910 * We therefore prevent devices associated with an RMRR from participating in
2911 * the IOMMU API, which eliminates them from device assignment.
2913 * In both cases we assume that PCI USB devices with RMRRs have them largely
2914 * for historical reasons and that the RMRR space is not actively used post
2915 * boot. This exclusion may change if vendors begin to abuse it.
2917 * The same exception is made for graphics devices, with the requirement that
2918 * any use of the RMRR regions will be torn down before assigning the device
2919 * to a guest.
2921 static bool device_is_rmrr_locked(struct device *dev)
2923 if (!device_has_rmrr(dev))
2924 return false;
2926 if (dev_is_pci(dev)) {
2927 struct pci_dev *pdev = to_pci_dev(dev);
2929 if (IS_USB_DEVICE(pdev) || IS_GFX_DEVICE(pdev))
2930 return false;
2933 return true;
2936 static int iommu_should_identity_map(struct device *dev, int startup)
2938 if (dev_is_pci(dev)) {
2939 struct pci_dev *pdev = to_pci_dev(dev);
2941 if (device_is_rmrr_locked(dev))
2942 return 0;
2945 * Prevent any device marked as untrusted from getting
2946 * placed into the statically identity mapping domain.
2948 if (pdev->untrusted)
2949 return 0;
2951 if ((iommu_identity_mapping & IDENTMAP_AZALIA) && IS_AZALIA(pdev))
2952 return 1;
2954 if ((iommu_identity_mapping & IDENTMAP_GFX) && IS_GFX_DEVICE(pdev))
2955 return 1;
2957 if (!(iommu_identity_mapping & IDENTMAP_ALL))
2958 return 0;
2961 * We want to start off with all devices in the 1:1 domain, and
2962 * take them out later if we find they can't access all of memory.
2964 * However, we can't do this for PCI devices behind bridges,
2965 * because all PCI devices behind the same bridge will end up
2966 * with the same source-id on their transactions.
2968 * Practically speaking, we can't change things around for these
2969 * devices at run-time, because we can't be sure there'll be no
2970 * DMA transactions in flight for any of their siblings.
2972 * So PCI devices (unless they're on the root bus) as well as
2973 * their parent PCI-PCI or PCIe-PCI bridges must be left _out_ of
2974 * the 1:1 domain, just in _case_ one of their siblings turns out
2975 * not to be able to map all of memory.
2977 if (!pci_is_pcie(pdev)) {
2978 if (!pci_is_root_bus(pdev->bus))
2979 return 0;
2980 if (pdev->class >> 8 == PCI_CLASS_BRIDGE_PCI)
2981 return 0;
2982 } else if (pci_pcie_type(pdev) == PCI_EXP_TYPE_PCI_BRIDGE)
2983 return 0;
2984 } else {
2985 if (device_has_rmrr(dev))
2986 return 0;
2990 * At boot time, we don't yet know if devices will be 64-bit capable.
2991 * Assume that they will — if they turn out not to be, then we can
2992 * take them out of the 1:1 domain later.
2994 if (!startup) {
2996 * If the device's dma_mask is less than the system's memory
2997 * size then this is not a candidate for identity mapping.
2999 u64 dma_mask = *dev->dma_mask;
3001 if (dev->coherent_dma_mask &&
3002 dev->coherent_dma_mask < dma_mask)
3003 dma_mask = dev->coherent_dma_mask;
3005 return dma_mask >= dma_get_required_mask(dev);
3008 return 1;
3011 static int __init dev_prepare_static_identity_mapping(struct device *dev, int hw)
3013 int ret;
3015 if (!iommu_should_identity_map(dev, 1))
3016 return 0;
3018 ret = domain_add_dev_info(si_domain, dev);
3019 if (!ret)
3020 dev_info(dev, "%s identity mapping\n",
3021 hw ? "Hardware" : "Software");
3022 else if (ret == -ENODEV)
3023 /* device not associated with an iommu */
3024 ret = 0;
3026 return ret;
3030 static int __init iommu_prepare_static_identity_mapping(int hw)
3032 struct pci_dev *pdev = NULL;
3033 struct dmar_drhd_unit *drhd;
3034 struct intel_iommu *iommu;
3035 struct device *dev;
3036 int i;
3037 int ret = 0;
3039 for_each_pci_dev(pdev) {
3040 ret = dev_prepare_static_identity_mapping(&pdev->dev, hw);
3041 if (ret)
3042 return ret;
3045 for_each_active_iommu(iommu, drhd)
3046 for_each_active_dev_scope(drhd->devices, drhd->devices_cnt, i, dev) {
3047 struct acpi_device_physical_node *pn;
3048 struct acpi_device *adev;
3050 if (dev->bus != &acpi_bus_type)
3051 continue;
3053 adev= to_acpi_device(dev);
3054 mutex_lock(&adev->physical_node_lock);
3055 list_for_each_entry(pn, &adev->physical_node_list, node) {
3056 ret = dev_prepare_static_identity_mapping(pn->dev, hw);
3057 if (ret)
3058 break;
3060 mutex_unlock(&adev->physical_node_lock);
3061 if (ret)
3062 return ret;
3065 return 0;
3068 static void intel_iommu_init_qi(struct intel_iommu *iommu)
3071 * Start from the sane iommu hardware state.
3072 * If the queued invalidation is already initialized by us
3073 * (for example, while enabling interrupt-remapping) then
3074 * we got the things already rolling from a sane state.
3076 if (!iommu->qi) {
3078 * Clear any previous faults.
3080 dmar_fault(-1, iommu);
3082 * Disable queued invalidation if supported and already enabled
3083 * before OS handover.
3085 dmar_disable_qi(iommu);
3088 if (dmar_enable_qi(iommu)) {
3090 * Queued Invalidate not enabled, use Register Based Invalidate
3092 iommu->flush.flush_context = __iommu_flush_context;
3093 iommu->flush.flush_iotlb = __iommu_flush_iotlb;
3094 pr_info("%s: Using Register based invalidation\n",
3095 iommu->name);
3096 } else {
3097 iommu->flush.flush_context = qi_flush_context;
3098 iommu->flush.flush_iotlb = qi_flush_iotlb;
3099 pr_info("%s: Using Queued invalidation\n", iommu->name);
3103 static int copy_context_table(struct intel_iommu *iommu,
3104 struct root_entry *old_re,
3105 struct context_entry **tbl,
3106 int bus, bool ext)
3108 int tbl_idx, pos = 0, idx, devfn, ret = 0, did;
3109 struct context_entry *new_ce = NULL, ce;
3110 struct context_entry *old_ce = NULL;
3111 struct root_entry re;
3112 phys_addr_t old_ce_phys;
3114 tbl_idx = ext ? bus * 2 : bus;
3115 memcpy(&re, old_re, sizeof(re));
3117 for (devfn = 0; devfn < 256; devfn++) {
3118 /* First calculate the correct index */
3119 idx = (ext ? devfn * 2 : devfn) % 256;
3121 if (idx == 0) {
3122 /* First save what we may have and clean up */
3123 if (new_ce) {
3124 tbl[tbl_idx] = new_ce;
3125 __iommu_flush_cache(iommu, new_ce,
3126 VTD_PAGE_SIZE);
3127 pos = 1;
3130 if (old_ce)
3131 memunmap(old_ce);
3133 ret = 0;
3134 if (devfn < 0x80)
3135 old_ce_phys = root_entry_lctp(&re);
3136 else
3137 old_ce_phys = root_entry_uctp(&re);
3139 if (!old_ce_phys) {
3140 if (ext && devfn == 0) {
3141 /* No LCTP, try UCTP */
3142 devfn = 0x7f;
3143 continue;
3144 } else {
3145 goto out;
3149 ret = -ENOMEM;
3150 old_ce = memremap(old_ce_phys, PAGE_SIZE,
3151 MEMREMAP_WB);
3152 if (!old_ce)
3153 goto out;
3155 new_ce = alloc_pgtable_page(iommu->node);
3156 if (!new_ce)
3157 goto out_unmap;
3159 ret = 0;
3162 /* Now copy the context entry */
3163 memcpy(&ce, old_ce + idx, sizeof(ce));
3165 if (!__context_present(&ce))
3166 continue;
3168 did = context_domain_id(&ce);
3169 if (did >= 0 && did < cap_ndoms(iommu->cap))
3170 set_bit(did, iommu->domain_ids);
3173 * We need a marker for copied context entries. This
3174 * marker needs to work for the old format as well as
3175 * for extended context entries.
3177 * Bit 67 of the context entry is used. In the old
3178 * format this bit is available to software, in the
3179 * extended format it is the PGE bit, but PGE is ignored
3180 * by HW if PASIDs are disabled (and thus still
3181 * available).
3183 * So disable PASIDs first and then mark the entry
3184 * copied. This means that we don't copy PASID
3185 * translations from the old kernel, but this is fine as
3186 * faults there are not fatal.
3188 context_clear_pasid_enable(&ce);
3189 context_set_copied(&ce);
3191 new_ce[idx] = ce;
3194 tbl[tbl_idx + pos] = new_ce;
3196 __iommu_flush_cache(iommu, new_ce, VTD_PAGE_SIZE);
3198 out_unmap:
3199 memunmap(old_ce);
3201 out:
3202 return ret;
3205 static int copy_translation_tables(struct intel_iommu *iommu)
3207 struct context_entry **ctxt_tbls;
3208 struct root_entry *old_rt;
3209 phys_addr_t old_rt_phys;
3210 int ctxt_table_entries;
3211 unsigned long flags;
3212 u64 rtaddr_reg;
3213 int bus, ret;
3214 bool new_ext, ext;
3216 rtaddr_reg = dmar_readq(iommu->reg + DMAR_RTADDR_REG);
3217 ext = !!(rtaddr_reg & DMA_RTADDR_RTT);
3218 new_ext = !!ecap_ecs(iommu->ecap);
3221 * The RTT bit can only be changed when translation is disabled,
3222 * but disabling translation means to open a window for data
3223 * corruption. So bail out and don't copy anything if we would
3224 * have to change the bit.
3226 if (new_ext != ext)
3227 return -EINVAL;
3229 old_rt_phys = rtaddr_reg & VTD_PAGE_MASK;
3230 if (!old_rt_phys)
3231 return -EINVAL;
3233 old_rt = memremap(old_rt_phys, PAGE_SIZE, MEMREMAP_WB);
3234 if (!old_rt)
3235 return -ENOMEM;
3237 /* This is too big for the stack - allocate it from slab */
3238 ctxt_table_entries = ext ? 512 : 256;
3239 ret = -ENOMEM;
3240 ctxt_tbls = kcalloc(ctxt_table_entries, sizeof(void *), GFP_KERNEL);
3241 if (!ctxt_tbls)
3242 goto out_unmap;
3244 for (bus = 0; bus < 256; bus++) {
3245 ret = copy_context_table(iommu, &old_rt[bus],
3246 ctxt_tbls, bus, ext);
3247 if (ret) {
3248 pr_err("%s: Failed to copy context table for bus %d\n",
3249 iommu->name, bus);
3250 continue;
3254 spin_lock_irqsave(&iommu->lock, flags);
3256 /* Context tables are copied, now write them to the root_entry table */
3257 for (bus = 0; bus < 256; bus++) {
3258 int idx = ext ? bus * 2 : bus;
3259 u64 val;
3261 if (ctxt_tbls[idx]) {
3262 val = virt_to_phys(ctxt_tbls[idx]) | 1;
3263 iommu->root_entry[bus].lo = val;
3266 if (!ext || !ctxt_tbls[idx + 1])
3267 continue;
3269 val = virt_to_phys(ctxt_tbls[idx + 1]) | 1;
3270 iommu->root_entry[bus].hi = val;
3273 spin_unlock_irqrestore(&iommu->lock, flags);
3275 kfree(ctxt_tbls);
3277 __iommu_flush_cache(iommu, iommu->root_entry, PAGE_SIZE);
3279 ret = 0;
3281 out_unmap:
3282 memunmap(old_rt);
3284 return ret;
3287 static int __init init_dmars(void)
3289 struct dmar_drhd_unit *drhd;
3290 struct dmar_rmrr_unit *rmrr;
3291 bool copied_tables = false;
3292 struct device *dev;
3293 struct intel_iommu *iommu;
3294 int i, ret;
3297 * for each drhd
3298 * allocate root
3299 * initialize and program root entry to not present
3300 * endfor
3302 for_each_drhd_unit(drhd) {
3304 * lock not needed as this is only incremented in the single
3305 * threaded kernel __init code path all other access are read
3306 * only
3308 if (g_num_of_iommus < DMAR_UNITS_SUPPORTED) {
3309 g_num_of_iommus++;
3310 continue;
3312 pr_err_once("Exceeded %d IOMMUs\n", DMAR_UNITS_SUPPORTED);
3315 /* Preallocate enough resources for IOMMU hot-addition */
3316 if (g_num_of_iommus < DMAR_UNITS_SUPPORTED)
3317 g_num_of_iommus = DMAR_UNITS_SUPPORTED;
3319 g_iommus = kcalloc(g_num_of_iommus, sizeof(struct intel_iommu *),
3320 GFP_KERNEL);
3321 if (!g_iommus) {
3322 pr_err("Allocating global iommu array failed\n");
3323 ret = -ENOMEM;
3324 goto error;
3327 for_each_active_iommu(iommu, drhd) {
3329 * Find the max pasid size of all IOMMU's in the system.
3330 * We need to ensure the system pasid table is no bigger
3331 * than the smallest supported.
3333 if (pasid_supported(iommu)) {
3334 u32 temp = 2 << ecap_pss(iommu->ecap);
3336 intel_pasid_max_id = min_t(u32, temp,
3337 intel_pasid_max_id);
3340 g_iommus[iommu->seq_id] = iommu;
3342 intel_iommu_init_qi(iommu);
3344 ret = iommu_init_domains(iommu);
3345 if (ret)
3346 goto free_iommu;
3348 init_translation_status(iommu);
3350 if (translation_pre_enabled(iommu) && !is_kdump_kernel()) {
3351 iommu_disable_translation(iommu);
3352 clear_translation_pre_enabled(iommu);
3353 pr_warn("Translation was enabled for %s but we are not in kdump mode\n",
3354 iommu->name);
3358 * TBD:
3359 * we could share the same root & context tables
3360 * among all IOMMU's. Need to Split it later.
3362 ret = iommu_alloc_root_entry(iommu);
3363 if (ret)
3364 goto free_iommu;
3366 if (translation_pre_enabled(iommu)) {
3367 pr_info("Translation already enabled - trying to copy translation structures\n");
3369 ret = copy_translation_tables(iommu);
3370 if (ret) {
3372 * We found the IOMMU with translation
3373 * enabled - but failed to copy over the
3374 * old root-entry table. Try to proceed
3375 * by disabling translation now and
3376 * allocating a clean root-entry table.
3377 * This might cause DMAR faults, but
3378 * probably the dump will still succeed.
3380 pr_err("Failed to copy translation tables from previous kernel for %s\n",
3381 iommu->name);
3382 iommu_disable_translation(iommu);
3383 clear_translation_pre_enabled(iommu);
3384 } else {
3385 pr_info("Copied translation tables from previous kernel for %s\n",
3386 iommu->name);
3387 copied_tables = true;
3391 if (!ecap_pass_through(iommu->ecap))
3392 hw_pass_through = 0;
3393 #ifdef CONFIG_INTEL_IOMMU_SVM
3394 if (pasid_supported(iommu))
3395 intel_svm_init(iommu);
3396 #endif
3400 * Now that qi is enabled on all iommus, set the root entry and flush
3401 * caches. This is required on some Intel X58 chipsets, otherwise the
3402 * flush_context function will loop forever and the boot hangs.
3404 for_each_active_iommu(iommu, drhd) {
3405 iommu_flush_write_buffer(iommu);
3406 iommu_set_root_entry(iommu);
3407 iommu->flush.flush_context(iommu, 0, 0, 0, DMA_CCMD_GLOBAL_INVL);
3408 iommu->flush.flush_iotlb(iommu, 0, 0, 0, DMA_TLB_GLOBAL_FLUSH);
3411 if (iommu_pass_through)
3412 iommu_identity_mapping |= IDENTMAP_ALL;
3414 #ifdef CONFIG_INTEL_IOMMU_BROKEN_GFX_WA
3415 iommu_identity_mapping |= IDENTMAP_GFX;
3416 #endif
3418 check_tylersburg_isoch();
3420 if (iommu_identity_mapping) {
3421 ret = si_domain_init(hw_pass_through);
3422 if (ret)
3423 goto free_iommu;
3428 * If we copied translations from a previous kernel in the kdump
3429 * case, we can not assign the devices to domains now, as that
3430 * would eliminate the old mappings. So skip this part and defer
3431 * the assignment to device driver initialization time.
3433 if (copied_tables)
3434 goto domains_done;
3437 * If pass through is not set or not enabled, setup context entries for
3438 * identity mappings for rmrr, gfx, and isa and may fall back to static
3439 * identity mapping if iommu_identity_mapping is set.
3441 if (iommu_identity_mapping) {
3442 ret = iommu_prepare_static_identity_mapping(hw_pass_through);
3443 if (ret) {
3444 pr_crit("Failed to setup IOMMU pass-through\n");
3445 goto free_iommu;
3449 * For each rmrr
3450 * for each dev attached to rmrr
3451 * do
3452 * locate drhd for dev, alloc domain for dev
3453 * allocate free domain
3454 * allocate page table entries for rmrr
3455 * if context not allocated for bus
3456 * allocate and init context
3457 * set present in root table for this bus
3458 * init context with domain, translation etc
3459 * endfor
3460 * endfor
3462 pr_info("Setting RMRR:\n");
3463 for_each_rmrr_units(rmrr) {
3464 /* some BIOS lists non-exist devices in DMAR table. */
3465 for_each_active_dev_scope(rmrr->devices, rmrr->devices_cnt,
3466 i, dev) {
3467 ret = iommu_prepare_rmrr_dev(rmrr, dev);
3468 if (ret)
3469 pr_err("Mapping reserved region failed\n");
3473 iommu_prepare_isa();
3475 domains_done:
3478 * for each drhd
3479 * enable fault log
3480 * global invalidate context cache
3481 * global invalidate iotlb
3482 * enable translation
3484 for_each_iommu(iommu, drhd) {
3485 if (drhd->ignored) {
3487 * we always have to disable PMRs or DMA may fail on
3488 * this device
3490 if (force_on)
3491 iommu_disable_protect_mem_regions(iommu);
3492 continue;
3495 iommu_flush_write_buffer(iommu);
3497 #ifdef CONFIG_INTEL_IOMMU_SVM
3498 if (pasid_supported(iommu) && ecap_prs(iommu->ecap)) {
3500 * Call dmar_alloc_hwirq() with dmar_global_lock held,
3501 * could cause possible lock race condition.
3503 up_write(&dmar_global_lock);
3504 ret = intel_svm_enable_prq(iommu);
3505 down_write(&dmar_global_lock);
3506 if (ret)
3507 goto free_iommu;
3509 #endif
3510 ret = dmar_set_interrupt(iommu);
3511 if (ret)
3512 goto free_iommu;
3514 if (!translation_pre_enabled(iommu))
3515 iommu_enable_translation(iommu);
3517 iommu_disable_protect_mem_regions(iommu);
3520 return 0;
3522 free_iommu:
3523 for_each_active_iommu(iommu, drhd) {
3524 disable_dmar_iommu(iommu);
3525 free_dmar_iommu(iommu);
3528 kfree(g_iommus);
3530 error:
3531 return ret;
3534 /* This takes a number of _MM_ pages, not VTD pages */
3535 static unsigned long intel_alloc_iova(struct device *dev,
3536 struct dmar_domain *domain,
3537 unsigned long nrpages, uint64_t dma_mask)
3539 unsigned long iova_pfn;
3541 /* Restrict dma_mask to the width that the iommu can handle */
3542 dma_mask = min_t(uint64_t, DOMAIN_MAX_ADDR(domain->gaw), dma_mask);
3543 /* Ensure we reserve the whole size-aligned region */
3544 nrpages = __roundup_pow_of_two(nrpages);
3546 if (!dmar_forcedac && dma_mask > DMA_BIT_MASK(32)) {
3548 * First try to allocate an io virtual address in
3549 * DMA_BIT_MASK(32) and if that fails then try allocating
3550 * from higher range
3552 iova_pfn = alloc_iova_fast(&domain->iovad, nrpages,
3553 IOVA_PFN(DMA_BIT_MASK(32)), false);
3554 if (iova_pfn)
3555 return iova_pfn;
3557 iova_pfn = alloc_iova_fast(&domain->iovad, nrpages,
3558 IOVA_PFN(dma_mask), true);
3559 if (unlikely(!iova_pfn)) {
3560 dev_err(dev, "Allocating %ld-page iova failed", nrpages);
3561 return 0;
3564 return iova_pfn;
3567 struct dmar_domain *get_valid_domain_for_dev(struct device *dev)
3569 struct dmar_domain *domain, *tmp;
3570 struct dmar_rmrr_unit *rmrr;
3571 struct device *i_dev;
3572 int i, ret;
3574 domain = find_domain(dev);
3575 if (domain)
3576 goto out;
3578 domain = find_or_alloc_domain(dev, DEFAULT_DOMAIN_ADDRESS_WIDTH);
3579 if (!domain)
3580 goto out;
3582 /* We have a new domain - setup possible RMRRs for the device */
3583 rcu_read_lock();
3584 for_each_rmrr_units(rmrr) {
3585 for_each_active_dev_scope(rmrr->devices, rmrr->devices_cnt,
3586 i, i_dev) {
3587 if (i_dev != dev)
3588 continue;
3590 ret = domain_prepare_identity_map(dev, domain,
3591 rmrr->base_address,
3592 rmrr->end_address);
3593 if (ret)
3594 dev_err(dev, "Mapping reserved region failed\n");
3597 rcu_read_unlock();
3599 tmp = set_domain_for_dev(dev, domain);
3600 if (!tmp || domain != tmp) {
3601 domain_exit(domain);
3602 domain = tmp;
3605 out:
3607 if (!domain)
3608 dev_err(dev, "Allocating domain failed\n");
3611 return domain;
3614 /* Check if the dev needs to go through non-identity map and unmap process.*/
3615 static int iommu_no_mapping(struct device *dev)
3617 int found;
3619 if (iommu_dummy(dev))
3620 return 1;
3622 if (!iommu_identity_mapping)
3623 return 0;
3625 found = identity_mapping(dev);
3626 if (found) {
3627 if (iommu_should_identity_map(dev, 0))
3628 return 1;
3629 else {
3631 * 32 bit DMA is removed from si_domain and fall back
3632 * to non-identity mapping.
3634 dmar_remove_one_dev_info(dev);
3635 dev_info(dev, "32bit DMA uses non-identity mapping\n");
3636 return 0;
3638 } else {
3640 * In case of a detached 64 bit DMA device from vm, the device
3641 * is put into si_domain for identity mapping.
3643 if (iommu_should_identity_map(dev, 0)) {
3644 int ret;
3645 ret = domain_add_dev_info(si_domain, dev);
3646 if (!ret) {
3647 dev_info(dev, "64bit DMA uses identity mapping\n");
3648 return 1;
3653 return 0;
3656 static dma_addr_t __intel_map_single(struct device *dev, phys_addr_t paddr,
3657 size_t size, int dir, u64 dma_mask)
3659 struct dmar_domain *domain;
3660 phys_addr_t start_paddr;
3661 unsigned long iova_pfn;
3662 int prot = 0;
3663 int ret;
3664 struct intel_iommu *iommu;
3665 unsigned long paddr_pfn = paddr >> PAGE_SHIFT;
3667 BUG_ON(dir == DMA_NONE);
3669 if (iommu_no_mapping(dev))
3670 return paddr;
3672 domain = get_valid_domain_for_dev(dev);
3673 if (!domain)
3674 return DMA_MAPPING_ERROR;
3676 iommu = domain_get_iommu(domain);
3677 size = aligned_nrpages(paddr, size);
3679 iova_pfn = intel_alloc_iova(dev, domain, dma_to_mm_pfn(size), dma_mask);
3680 if (!iova_pfn)
3681 goto error;
3684 * Check if DMAR supports zero-length reads on write only
3685 * mappings..
3687 if (dir == DMA_TO_DEVICE || dir == DMA_BIDIRECTIONAL || \
3688 !cap_zlr(iommu->cap))
3689 prot |= DMA_PTE_READ;
3690 if (dir == DMA_FROM_DEVICE || dir == DMA_BIDIRECTIONAL)
3691 prot |= DMA_PTE_WRITE;
3693 * paddr - (paddr + size) might be partial page, we should map the whole
3694 * page. Note: if two part of one page are separately mapped, we
3695 * might have two guest_addr mapping to the same host paddr, but this
3696 * is not a big problem
3698 ret = domain_pfn_mapping(domain, mm_to_dma_pfn(iova_pfn),
3699 mm_to_dma_pfn(paddr_pfn), size, prot);
3700 if (ret)
3701 goto error;
3703 start_paddr = (phys_addr_t)iova_pfn << PAGE_SHIFT;
3704 start_paddr += paddr & ~PAGE_MASK;
3705 return start_paddr;
3707 error:
3708 if (iova_pfn)
3709 free_iova_fast(&domain->iovad, iova_pfn, dma_to_mm_pfn(size));
3710 dev_err(dev, "Device request: %zx@%llx dir %d --- failed\n",
3711 size, (unsigned long long)paddr, dir);
3712 return DMA_MAPPING_ERROR;
3715 static dma_addr_t intel_map_page(struct device *dev, struct page *page,
3716 unsigned long offset, size_t size,
3717 enum dma_data_direction dir,
3718 unsigned long attrs)
3720 return __intel_map_single(dev, page_to_phys(page) + offset, size,
3721 dir, *dev->dma_mask);
3724 static dma_addr_t intel_map_resource(struct device *dev, phys_addr_t phys_addr,
3725 size_t size, enum dma_data_direction dir,
3726 unsigned long attrs)
3728 return __intel_map_single(dev, phys_addr, size, dir, *dev->dma_mask);
3731 static void intel_unmap(struct device *dev, dma_addr_t dev_addr, size_t size)
3733 struct dmar_domain *domain;
3734 unsigned long start_pfn, last_pfn;
3735 unsigned long nrpages;
3736 unsigned long iova_pfn;
3737 struct intel_iommu *iommu;
3738 struct page *freelist;
3739 struct pci_dev *pdev = NULL;
3741 if (iommu_no_mapping(dev))
3742 return;
3744 domain = find_domain(dev);
3745 BUG_ON(!domain);
3747 iommu = domain_get_iommu(domain);
3749 iova_pfn = IOVA_PFN(dev_addr);
3751 nrpages = aligned_nrpages(dev_addr, size);
3752 start_pfn = mm_to_dma_pfn(iova_pfn);
3753 last_pfn = start_pfn + nrpages - 1;
3755 if (dev_is_pci(dev))
3756 pdev = to_pci_dev(dev);
3758 dev_dbg(dev, "Device unmapping: pfn %lx-%lx\n", start_pfn, last_pfn);
3760 freelist = domain_unmap(domain, start_pfn, last_pfn);
3762 if (intel_iommu_strict || (pdev && pdev->untrusted)) {
3763 iommu_flush_iotlb_psi(iommu, domain, start_pfn,
3764 nrpages, !freelist, 0);
3765 /* free iova */
3766 free_iova_fast(&domain->iovad, iova_pfn, dma_to_mm_pfn(nrpages));
3767 dma_free_pagelist(freelist);
3768 } else {
3769 queue_iova(&domain->iovad, iova_pfn, nrpages,
3770 (unsigned long)freelist);
3772 * queue up the release of the unmap to save the 1/6th of the
3773 * cpu used up by the iotlb flush operation...
3778 static void intel_unmap_page(struct device *dev, dma_addr_t dev_addr,
3779 size_t size, enum dma_data_direction dir,
3780 unsigned long attrs)
3782 intel_unmap(dev, dev_addr, size);
3785 static void *intel_alloc_coherent(struct device *dev, size_t size,
3786 dma_addr_t *dma_handle, gfp_t flags,
3787 unsigned long attrs)
3789 struct page *page = NULL;
3790 int order;
3792 size = PAGE_ALIGN(size);
3793 order = get_order(size);
3795 if (!iommu_no_mapping(dev))
3796 flags &= ~(GFP_DMA | GFP_DMA32);
3797 else if (dev->coherent_dma_mask < dma_get_required_mask(dev)) {
3798 if (dev->coherent_dma_mask < DMA_BIT_MASK(32))
3799 flags |= GFP_DMA;
3800 else
3801 flags |= GFP_DMA32;
3804 if (gfpflags_allow_blocking(flags)) {
3805 unsigned int count = size >> PAGE_SHIFT;
3807 page = dma_alloc_from_contiguous(dev, count, order,
3808 flags & __GFP_NOWARN);
3809 if (page && iommu_no_mapping(dev) &&
3810 page_to_phys(page) + size > dev->coherent_dma_mask) {
3811 dma_release_from_contiguous(dev, page, count);
3812 page = NULL;
3816 if (!page)
3817 page = alloc_pages(flags, order);
3818 if (!page)
3819 return NULL;
3820 memset(page_address(page), 0, size);
3822 *dma_handle = __intel_map_single(dev, page_to_phys(page), size,
3823 DMA_BIDIRECTIONAL,
3824 dev->coherent_dma_mask);
3825 if (*dma_handle != DMA_MAPPING_ERROR)
3826 return page_address(page);
3827 if (!dma_release_from_contiguous(dev, page, size >> PAGE_SHIFT))
3828 __free_pages(page, order);
3830 return NULL;
3833 static void intel_free_coherent(struct device *dev, size_t size, void *vaddr,
3834 dma_addr_t dma_handle, unsigned long attrs)
3836 int order;
3837 struct page *page = virt_to_page(vaddr);
3839 size = PAGE_ALIGN(size);
3840 order = get_order(size);
3842 intel_unmap(dev, dma_handle, size);
3843 if (!dma_release_from_contiguous(dev, page, size >> PAGE_SHIFT))
3844 __free_pages(page, order);
3847 static void intel_unmap_sg(struct device *dev, struct scatterlist *sglist,
3848 int nelems, enum dma_data_direction dir,
3849 unsigned long attrs)
3851 dma_addr_t startaddr = sg_dma_address(sglist) & PAGE_MASK;
3852 unsigned long nrpages = 0;
3853 struct scatterlist *sg;
3854 int i;
3856 for_each_sg(sglist, sg, nelems, i) {
3857 nrpages += aligned_nrpages(sg_dma_address(sg), sg_dma_len(sg));
3860 intel_unmap(dev, startaddr, nrpages << VTD_PAGE_SHIFT);
3863 static int intel_nontranslate_map_sg(struct device *hddev,
3864 struct scatterlist *sglist, int nelems, int dir)
3866 int i;
3867 struct scatterlist *sg;
3869 for_each_sg(sglist, sg, nelems, i) {
3870 BUG_ON(!sg_page(sg));
3871 sg->dma_address = sg_phys(sg);
3872 sg->dma_length = sg->length;
3874 return nelems;
3877 static int intel_map_sg(struct device *dev, struct scatterlist *sglist, int nelems,
3878 enum dma_data_direction dir, unsigned long attrs)
3880 int i;
3881 struct dmar_domain *domain;
3882 size_t size = 0;
3883 int prot = 0;
3884 unsigned long iova_pfn;
3885 int ret;
3886 struct scatterlist *sg;
3887 unsigned long start_vpfn;
3888 struct intel_iommu *iommu;
3890 BUG_ON(dir == DMA_NONE);
3891 if (iommu_no_mapping(dev))
3892 return intel_nontranslate_map_sg(dev, sglist, nelems, dir);
3894 domain = get_valid_domain_for_dev(dev);
3895 if (!domain)
3896 return 0;
3898 iommu = domain_get_iommu(domain);
3900 for_each_sg(sglist, sg, nelems, i)
3901 size += aligned_nrpages(sg->offset, sg->length);
3903 iova_pfn = intel_alloc_iova(dev, domain, dma_to_mm_pfn(size),
3904 *dev->dma_mask);
3905 if (!iova_pfn) {
3906 sglist->dma_length = 0;
3907 return 0;
3911 * Check if DMAR supports zero-length reads on write only
3912 * mappings..
3914 if (dir == DMA_TO_DEVICE || dir == DMA_BIDIRECTIONAL || \
3915 !cap_zlr(iommu->cap))
3916 prot |= DMA_PTE_READ;
3917 if (dir == DMA_FROM_DEVICE || dir == DMA_BIDIRECTIONAL)
3918 prot |= DMA_PTE_WRITE;
3920 start_vpfn = mm_to_dma_pfn(iova_pfn);
3922 ret = domain_sg_mapping(domain, start_vpfn, sglist, size, prot);
3923 if (unlikely(ret)) {
3924 dma_pte_free_pagetable(domain, start_vpfn,
3925 start_vpfn + size - 1,
3926 agaw_to_level(domain->agaw) + 1);
3927 free_iova_fast(&domain->iovad, iova_pfn, dma_to_mm_pfn(size));
3928 return 0;
3931 return nelems;
3934 static const struct dma_map_ops intel_dma_ops = {
3935 .alloc = intel_alloc_coherent,
3936 .free = intel_free_coherent,
3937 .map_sg = intel_map_sg,
3938 .unmap_sg = intel_unmap_sg,
3939 .map_page = intel_map_page,
3940 .unmap_page = intel_unmap_page,
3941 .map_resource = intel_map_resource,
3942 .unmap_resource = intel_unmap_page,
3943 .dma_supported = dma_direct_supported,
3946 static inline int iommu_domain_cache_init(void)
3948 int ret = 0;
3950 iommu_domain_cache = kmem_cache_create("iommu_domain",
3951 sizeof(struct dmar_domain),
3953 SLAB_HWCACHE_ALIGN,
3955 NULL);
3956 if (!iommu_domain_cache) {
3957 pr_err("Couldn't create iommu_domain cache\n");
3958 ret = -ENOMEM;
3961 return ret;
3964 static inline int iommu_devinfo_cache_init(void)
3966 int ret = 0;
3968 iommu_devinfo_cache = kmem_cache_create("iommu_devinfo",
3969 sizeof(struct device_domain_info),
3971 SLAB_HWCACHE_ALIGN,
3972 NULL);
3973 if (!iommu_devinfo_cache) {
3974 pr_err("Couldn't create devinfo cache\n");
3975 ret = -ENOMEM;
3978 return ret;
3981 static int __init iommu_init_mempool(void)
3983 int ret;
3984 ret = iova_cache_get();
3985 if (ret)
3986 return ret;
3988 ret = iommu_domain_cache_init();
3989 if (ret)
3990 goto domain_error;
3992 ret = iommu_devinfo_cache_init();
3993 if (!ret)
3994 return ret;
3996 kmem_cache_destroy(iommu_domain_cache);
3997 domain_error:
3998 iova_cache_put();
4000 return -ENOMEM;
4003 static void __init iommu_exit_mempool(void)
4005 kmem_cache_destroy(iommu_devinfo_cache);
4006 kmem_cache_destroy(iommu_domain_cache);
4007 iova_cache_put();
4010 static void quirk_ioat_snb_local_iommu(struct pci_dev *pdev)
4012 struct dmar_drhd_unit *drhd;
4013 u32 vtbar;
4014 int rc;
4016 /* We know that this device on this chipset has its own IOMMU.
4017 * If we find it under a different IOMMU, then the BIOS is lying
4018 * to us. Hope that the IOMMU for this device is actually
4019 * disabled, and it needs no translation...
4021 rc = pci_bus_read_config_dword(pdev->bus, PCI_DEVFN(0, 0), 0xb0, &vtbar);
4022 if (rc) {
4023 /* "can't" happen */
4024 dev_info(&pdev->dev, "failed to run vt-d quirk\n");
4025 return;
4027 vtbar &= 0xffff0000;
4029 /* we know that the this iommu should be at offset 0xa000 from vtbar */
4030 drhd = dmar_find_matched_drhd_unit(pdev);
4031 if (WARN_TAINT_ONCE(!drhd || drhd->reg_base_addr - vtbar != 0xa000,
4032 TAINT_FIRMWARE_WORKAROUND,
4033 "BIOS assigned incorrect VT-d unit for Intel(R) QuickData Technology device\n"))
4034 pdev->dev.archdata.iommu = DUMMY_DEVICE_DOMAIN_INFO;
4036 DECLARE_PCI_FIXUP_ENABLE(PCI_VENDOR_ID_INTEL, PCI_DEVICE_ID_INTEL_IOAT_SNB, quirk_ioat_snb_local_iommu);
4038 static void __init init_no_remapping_devices(void)
4040 struct dmar_drhd_unit *drhd;
4041 struct device *dev;
4042 int i;
4044 for_each_drhd_unit(drhd) {
4045 if (!drhd->include_all) {
4046 for_each_active_dev_scope(drhd->devices,
4047 drhd->devices_cnt, i, dev)
4048 break;
4049 /* ignore DMAR unit if no devices exist */
4050 if (i == drhd->devices_cnt)
4051 drhd->ignored = 1;
4055 for_each_active_drhd_unit(drhd) {
4056 if (drhd->include_all)
4057 continue;
4059 for_each_active_dev_scope(drhd->devices,
4060 drhd->devices_cnt, i, dev)
4061 if (!dev_is_pci(dev) || !IS_GFX_DEVICE(to_pci_dev(dev)))
4062 break;
4063 if (i < drhd->devices_cnt)
4064 continue;
4066 /* This IOMMU has *only* gfx devices. Either bypass it or
4067 set the gfx_mapped flag, as appropriate */
4068 if (!dmar_map_gfx) {
4069 drhd->ignored = 1;
4070 for_each_active_dev_scope(drhd->devices,
4071 drhd->devices_cnt, i, dev)
4072 dev->archdata.iommu = DUMMY_DEVICE_DOMAIN_INFO;
4077 #ifdef CONFIG_SUSPEND
4078 static int init_iommu_hw(void)
4080 struct dmar_drhd_unit *drhd;
4081 struct intel_iommu *iommu = NULL;
4083 for_each_active_iommu(iommu, drhd)
4084 if (iommu->qi)
4085 dmar_reenable_qi(iommu);
4087 for_each_iommu(iommu, drhd) {
4088 if (drhd->ignored) {
4090 * we always have to disable PMRs or DMA may fail on
4091 * this device
4093 if (force_on)
4094 iommu_disable_protect_mem_regions(iommu);
4095 continue;
4098 iommu_flush_write_buffer(iommu);
4100 iommu_set_root_entry(iommu);
4102 iommu->flush.flush_context(iommu, 0, 0, 0,
4103 DMA_CCMD_GLOBAL_INVL);
4104 iommu->flush.flush_iotlb(iommu, 0, 0, 0, DMA_TLB_GLOBAL_FLUSH);
4105 iommu_enable_translation(iommu);
4106 iommu_disable_protect_mem_regions(iommu);
4109 return 0;
4112 static void iommu_flush_all(void)
4114 struct dmar_drhd_unit *drhd;
4115 struct intel_iommu *iommu;
4117 for_each_active_iommu(iommu, drhd) {
4118 iommu->flush.flush_context(iommu, 0, 0, 0,
4119 DMA_CCMD_GLOBAL_INVL);
4120 iommu->flush.flush_iotlb(iommu, 0, 0, 0,
4121 DMA_TLB_GLOBAL_FLUSH);
4125 static int iommu_suspend(void)
4127 struct dmar_drhd_unit *drhd;
4128 struct intel_iommu *iommu = NULL;
4129 unsigned long flag;
4131 for_each_active_iommu(iommu, drhd) {
4132 iommu->iommu_state = kcalloc(MAX_SR_DMAR_REGS, sizeof(u32),
4133 GFP_ATOMIC);
4134 if (!iommu->iommu_state)
4135 goto nomem;
4138 iommu_flush_all();
4140 for_each_active_iommu(iommu, drhd) {
4141 iommu_disable_translation(iommu);
4143 raw_spin_lock_irqsave(&iommu->register_lock, flag);
4145 iommu->iommu_state[SR_DMAR_FECTL_REG] =
4146 readl(iommu->reg + DMAR_FECTL_REG);
4147 iommu->iommu_state[SR_DMAR_FEDATA_REG] =
4148 readl(iommu->reg + DMAR_FEDATA_REG);
4149 iommu->iommu_state[SR_DMAR_FEADDR_REG] =
4150 readl(iommu->reg + DMAR_FEADDR_REG);
4151 iommu->iommu_state[SR_DMAR_FEUADDR_REG] =
4152 readl(iommu->reg + DMAR_FEUADDR_REG);
4154 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
4156 return 0;
4158 nomem:
4159 for_each_active_iommu(iommu, drhd)
4160 kfree(iommu->iommu_state);
4162 return -ENOMEM;
4165 static void iommu_resume(void)
4167 struct dmar_drhd_unit *drhd;
4168 struct intel_iommu *iommu = NULL;
4169 unsigned long flag;
4171 if (init_iommu_hw()) {
4172 if (force_on)
4173 panic("tboot: IOMMU setup failed, DMAR can not resume!\n");
4174 else
4175 WARN(1, "IOMMU setup failed, DMAR can not resume!\n");
4176 return;
4179 for_each_active_iommu(iommu, drhd) {
4181 raw_spin_lock_irqsave(&iommu->register_lock, flag);
4183 writel(iommu->iommu_state[SR_DMAR_FECTL_REG],
4184 iommu->reg + DMAR_FECTL_REG);
4185 writel(iommu->iommu_state[SR_DMAR_FEDATA_REG],
4186 iommu->reg + DMAR_FEDATA_REG);
4187 writel(iommu->iommu_state[SR_DMAR_FEADDR_REG],
4188 iommu->reg + DMAR_FEADDR_REG);
4189 writel(iommu->iommu_state[SR_DMAR_FEUADDR_REG],
4190 iommu->reg + DMAR_FEUADDR_REG);
4192 raw_spin_unlock_irqrestore(&iommu->register_lock, flag);
4195 for_each_active_iommu(iommu, drhd)
4196 kfree(iommu->iommu_state);
4199 static struct syscore_ops iommu_syscore_ops = {
4200 .resume = iommu_resume,
4201 .suspend = iommu_suspend,
4204 static void __init init_iommu_pm_ops(void)
4206 register_syscore_ops(&iommu_syscore_ops);
4209 #else
4210 static inline void init_iommu_pm_ops(void) {}
4211 #endif /* CONFIG_PM */
4214 int __init dmar_parse_one_rmrr(struct acpi_dmar_header *header, void *arg)
4216 struct acpi_dmar_reserved_memory *rmrr;
4217 int prot = DMA_PTE_READ|DMA_PTE_WRITE;
4218 struct dmar_rmrr_unit *rmrru;
4219 size_t length;
4221 rmrru = kzalloc(sizeof(*rmrru), GFP_KERNEL);
4222 if (!rmrru)
4223 goto out;
4225 rmrru->hdr = header;
4226 rmrr = (struct acpi_dmar_reserved_memory *)header;
4227 rmrru->base_address = rmrr->base_address;
4228 rmrru->end_address = rmrr->end_address;
4230 length = rmrr->end_address - rmrr->base_address + 1;
4231 rmrru->resv = iommu_alloc_resv_region(rmrr->base_address, length, prot,
4232 IOMMU_RESV_DIRECT);
4233 if (!rmrru->resv)
4234 goto free_rmrru;
4236 rmrru->devices = dmar_alloc_dev_scope((void *)(rmrr + 1),
4237 ((void *)rmrr) + rmrr->header.length,
4238 &rmrru->devices_cnt);
4239 if (rmrru->devices_cnt && rmrru->devices == NULL)
4240 goto free_all;
4242 list_add(&rmrru->list, &dmar_rmrr_units);
4244 return 0;
4245 free_all:
4246 kfree(rmrru->resv);
4247 free_rmrru:
4248 kfree(rmrru);
4249 out:
4250 return -ENOMEM;
4253 static struct dmar_atsr_unit *dmar_find_atsr(struct acpi_dmar_atsr *atsr)
4255 struct dmar_atsr_unit *atsru;
4256 struct acpi_dmar_atsr *tmp;
4258 list_for_each_entry_rcu(atsru, &dmar_atsr_units, list) {
4259 tmp = (struct acpi_dmar_atsr *)atsru->hdr;
4260 if (atsr->segment != tmp->segment)
4261 continue;
4262 if (atsr->header.length != tmp->header.length)
4263 continue;
4264 if (memcmp(atsr, tmp, atsr->header.length) == 0)
4265 return atsru;
4268 return NULL;
4271 int dmar_parse_one_atsr(struct acpi_dmar_header *hdr, void *arg)
4273 struct acpi_dmar_atsr *atsr;
4274 struct dmar_atsr_unit *atsru;
4276 if (system_state >= SYSTEM_RUNNING && !intel_iommu_enabled)
4277 return 0;
4279 atsr = container_of(hdr, struct acpi_dmar_atsr, header);
4280 atsru = dmar_find_atsr(atsr);
4281 if (atsru)
4282 return 0;
4284 atsru = kzalloc(sizeof(*atsru) + hdr->length, GFP_KERNEL);
4285 if (!atsru)
4286 return -ENOMEM;
4289 * If memory is allocated from slab by ACPI _DSM method, we need to
4290 * copy the memory content because the memory buffer will be freed
4291 * on return.
4293 atsru->hdr = (void *)(atsru + 1);
4294 memcpy(atsru->hdr, hdr, hdr->length);
4295 atsru->include_all = atsr->flags & 0x1;
4296 if (!atsru->include_all) {
4297 atsru->devices = dmar_alloc_dev_scope((void *)(atsr + 1),
4298 (void *)atsr + atsr->header.length,
4299 &atsru->devices_cnt);
4300 if (atsru->devices_cnt && atsru->devices == NULL) {
4301 kfree(atsru);
4302 return -ENOMEM;
4306 list_add_rcu(&atsru->list, &dmar_atsr_units);
4308 return 0;
4311 static void intel_iommu_free_atsr(struct dmar_atsr_unit *atsru)
4313 dmar_free_dev_scope(&atsru->devices, &atsru->devices_cnt);
4314 kfree(atsru);
4317 int dmar_release_one_atsr(struct acpi_dmar_header *hdr, void *arg)
4319 struct acpi_dmar_atsr *atsr;
4320 struct dmar_atsr_unit *atsru;
4322 atsr = container_of(hdr, struct acpi_dmar_atsr, header);
4323 atsru = dmar_find_atsr(atsr);
4324 if (atsru) {
4325 list_del_rcu(&atsru->list);
4326 synchronize_rcu();
4327 intel_iommu_free_atsr(atsru);
4330 return 0;
4333 int dmar_check_one_atsr(struct acpi_dmar_header *hdr, void *arg)
4335 int i;
4336 struct device *dev;
4337 struct acpi_dmar_atsr *atsr;
4338 struct dmar_atsr_unit *atsru;
4340 atsr = container_of(hdr, struct acpi_dmar_atsr, header);
4341 atsru = dmar_find_atsr(atsr);
4342 if (!atsru)
4343 return 0;
4345 if (!atsru->include_all && atsru->devices && atsru->devices_cnt) {
4346 for_each_active_dev_scope(atsru->devices, atsru->devices_cnt,
4347 i, dev)
4348 return -EBUSY;
4351 return 0;
4354 static int intel_iommu_add(struct dmar_drhd_unit *dmaru)
4356 int sp, ret;
4357 struct intel_iommu *iommu = dmaru->iommu;
4359 if (g_iommus[iommu->seq_id])
4360 return 0;
4362 if (hw_pass_through && !ecap_pass_through(iommu->ecap)) {
4363 pr_warn("%s: Doesn't support hardware pass through.\n",
4364 iommu->name);
4365 return -ENXIO;
4367 if (!ecap_sc_support(iommu->ecap) &&
4368 domain_update_iommu_snooping(iommu)) {
4369 pr_warn("%s: Doesn't support snooping.\n",
4370 iommu->name);
4371 return -ENXIO;
4373 sp = domain_update_iommu_superpage(iommu) - 1;
4374 if (sp >= 0 && !(cap_super_page_val(iommu->cap) & (1 << sp))) {
4375 pr_warn("%s: Doesn't support large page.\n",
4376 iommu->name);
4377 return -ENXIO;
4381 * Disable translation if already enabled prior to OS handover.
4383 if (iommu->gcmd & DMA_GCMD_TE)
4384 iommu_disable_translation(iommu);
4386 g_iommus[iommu->seq_id] = iommu;
4387 ret = iommu_init_domains(iommu);
4388 if (ret == 0)
4389 ret = iommu_alloc_root_entry(iommu);
4390 if (ret)
4391 goto out;
4393 #ifdef CONFIG_INTEL_IOMMU_SVM
4394 if (pasid_supported(iommu))
4395 intel_svm_init(iommu);
4396 #endif
4398 if (dmaru->ignored) {
4400 * we always have to disable PMRs or DMA may fail on this device
4402 if (force_on)
4403 iommu_disable_protect_mem_regions(iommu);
4404 return 0;
4407 intel_iommu_init_qi(iommu);
4408 iommu_flush_write_buffer(iommu);
4410 #ifdef CONFIG_INTEL_IOMMU_SVM
4411 if (pasid_supported(iommu) && ecap_prs(iommu->ecap)) {
4412 ret = intel_svm_enable_prq(iommu);
4413 if (ret)
4414 goto disable_iommu;
4416 #endif
4417 ret = dmar_set_interrupt(iommu);
4418 if (ret)
4419 goto disable_iommu;
4421 iommu_set_root_entry(iommu);
4422 iommu->flush.flush_context(iommu, 0, 0, 0, DMA_CCMD_GLOBAL_INVL);
4423 iommu->flush.flush_iotlb(iommu, 0, 0, 0, DMA_TLB_GLOBAL_FLUSH);
4424 iommu_enable_translation(iommu);
4426 iommu_disable_protect_mem_regions(iommu);
4427 return 0;
4429 disable_iommu:
4430 disable_dmar_iommu(iommu);
4431 out:
4432 free_dmar_iommu(iommu);
4433 return ret;
4436 int dmar_iommu_hotplug(struct dmar_drhd_unit *dmaru, bool insert)
4438 int ret = 0;
4439 struct intel_iommu *iommu = dmaru->iommu;
4441 if (!intel_iommu_enabled)
4442 return 0;
4443 if (iommu == NULL)
4444 return -EINVAL;
4446 if (insert) {
4447 ret = intel_iommu_add(dmaru);
4448 } else {
4449 disable_dmar_iommu(iommu);
4450 free_dmar_iommu(iommu);
4453 return ret;
4456 static void intel_iommu_free_dmars(void)
4458 struct dmar_rmrr_unit *rmrru, *rmrr_n;
4459 struct dmar_atsr_unit *atsru, *atsr_n;
4461 list_for_each_entry_safe(rmrru, rmrr_n, &dmar_rmrr_units, list) {
4462 list_del(&rmrru->list);
4463 dmar_free_dev_scope(&rmrru->devices, &rmrru->devices_cnt);
4464 kfree(rmrru->resv);
4465 kfree(rmrru);
4468 list_for_each_entry_safe(atsru, atsr_n, &dmar_atsr_units, list) {
4469 list_del(&atsru->list);
4470 intel_iommu_free_atsr(atsru);
4474 int dmar_find_matched_atsr_unit(struct pci_dev *dev)
4476 int i, ret = 1;
4477 struct pci_bus *bus;
4478 struct pci_dev *bridge = NULL;
4479 struct device *tmp;
4480 struct acpi_dmar_atsr *atsr;
4481 struct dmar_atsr_unit *atsru;
4483 dev = pci_physfn(dev);
4484 for (bus = dev->bus; bus; bus = bus->parent) {
4485 bridge = bus->self;
4486 /* If it's an integrated device, allow ATS */
4487 if (!bridge)
4488 return 1;
4489 /* Connected via non-PCIe: no ATS */
4490 if (!pci_is_pcie(bridge) ||
4491 pci_pcie_type(bridge) == PCI_EXP_TYPE_PCI_BRIDGE)
4492 return 0;
4493 /* If we found the root port, look it up in the ATSR */
4494 if (pci_pcie_type(bridge) == PCI_EXP_TYPE_ROOT_PORT)
4495 break;
4498 rcu_read_lock();
4499 list_for_each_entry_rcu(atsru, &dmar_atsr_units, list) {
4500 atsr = container_of(atsru->hdr, struct acpi_dmar_atsr, header);
4501 if (atsr->segment != pci_domain_nr(dev->bus))
4502 continue;
4504 for_each_dev_scope(atsru->devices, atsru->devices_cnt, i, tmp)
4505 if (tmp == &bridge->dev)
4506 goto out;
4508 if (atsru->include_all)
4509 goto out;
4511 ret = 0;
4512 out:
4513 rcu_read_unlock();
4515 return ret;
4518 int dmar_iommu_notify_scope_dev(struct dmar_pci_notify_info *info)
4520 int ret;
4521 struct dmar_rmrr_unit *rmrru;
4522 struct dmar_atsr_unit *atsru;
4523 struct acpi_dmar_atsr *atsr;
4524 struct acpi_dmar_reserved_memory *rmrr;
4526 if (!intel_iommu_enabled && system_state >= SYSTEM_RUNNING)
4527 return 0;
4529 list_for_each_entry(rmrru, &dmar_rmrr_units, list) {
4530 rmrr = container_of(rmrru->hdr,
4531 struct acpi_dmar_reserved_memory, header);
4532 if (info->event == BUS_NOTIFY_ADD_DEVICE) {
4533 ret = dmar_insert_dev_scope(info, (void *)(rmrr + 1),
4534 ((void *)rmrr) + rmrr->header.length,
4535 rmrr->segment, rmrru->devices,
4536 rmrru->devices_cnt);
4537 if (ret < 0)
4538 return ret;
4539 } else if (info->event == BUS_NOTIFY_REMOVED_DEVICE) {
4540 dmar_remove_dev_scope(info, rmrr->segment,
4541 rmrru->devices, rmrru->devices_cnt);
4545 list_for_each_entry(atsru, &dmar_atsr_units, list) {
4546 if (atsru->include_all)
4547 continue;
4549 atsr = container_of(atsru->hdr, struct acpi_dmar_atsr, header);
4550 if (info->event == BUS_NOTIFY_ADD_DEVICE) {
4551 ret = dmar_insert_dev_scope(info, (void *)(atsr + 1),
4552 (void *)atsr + atsr->header.length,
4553 atsr->segment, atsru->devices,
4554 atsru->devices_cnt);
4555 if (ret > 0)
4556 break;
4557 else if (ret < 0)
4558 return ret;
4559 } else if (info->event == BUS_NOTIFY_REMOVED_DEVICE) {
4560 if (dmar_remove_dev_scope(info, atsr->segment,
4561 atsru->devices, atsru->devices_cnt))
4562 break;
4566 return 0;
4570 * Here we only respond to action of unbound device from driver.
4572 * Added device is not attached to its DMAR domain here yet. That will happen
4573 * when mapping the device to iova.
4575 static int device_notifier(struct notifier_block *nb,
4576 unsigned long action, void *data)
4578 struct device *dev = data;
4579 struct dmar_domain *domain;
4581 if (iommu_dummy(dev))
4582 return 0;
4584 if (action == BUS_NOTIFY_REMOVED_DEVICE) {
4585 domain = find_domain(dev);
4586 if (!domain)
4587 return 0;
4589 dmar_remove_one_dev_info(dev);
4590 if (!domain_type_is_vm_or_si(domain) &&
4591 list_empty(&domain->devices))
4592 domain_exit(domain);
4593 } else if (action == BUS_NOTIFY_ADD_DEVICE) {
4594 if (iommu_should_identity_map(dev, 1))
4595 domain_add_dev_info(si_domain, dev);
4598 return 0;
4601 static struct notifier_block device_nb = {
4602 .notifier_call = device_notifier,
4605 static int intel_iommu_memory_notifier(struct notifier_block *nb,
4606 unsigned long val, void *v)
4608 struct memory_notify *mhp = v;
4609 unsigned long long start, end;
4610 unsigned long start_vpfn, last_vpfn;
4612 switch (val) {
4613 case MEM_GOING_ONLINE:
4614 start = mhp->start_pfn << PAGE_SHIFT;
4615 end = ((mhp->start_pfn + mhp->nr_pages) << PAGE_SHIFT) - 1;
4616 if (iommu_domain_identity_map(si_domain, start, end)) {
4617 pr_warn("Failed to build identity map for [%llx-%llx]\n",
4618 start, end);
4619 return NOTIFY_BAD;
4621 break;
4623 case MEM_OFFLINE:
4624 case MEM_CANCEL_ONLINE:
4625 start_vpfn = mm_to_dma_pfn(mhp->start_pfn);
4626 last_vpfn = mm_to_dma_pfn(mhp->start_pfn + mhp->nr_pages - 1);
4627 while (start_vpfn <= last_vpfn) {
4628 struct iova *iova;
4629 struct dmar_drhd_unit *drhd;
4630 struct intel_iommu *iommu;
4631 struct page *freelist;
4633 iova = find_iova(&si_domain->iovad, start_vpfn);
4634 if (iova == NULL) {
4635 pr_debug("Failed get IOVA for PFN %lx\n",
4636 start_vpfn);
4637 break;
4640 iova = split_and_remove_iova(&si_domain->iovad, iova,
4641 start_vpfn, last_vpfn);
4642 if (iova == NULL) {
4643 pr_warn("Failed to split IOVA PFN [%lx-%lx]\n",
4644 start_vpfn, last_vpfn);
4645 return NOTIFY_BAD;
4648 freelist = domain_unmap(si_domain, iova->pfn_lo,
4649 iova->pfn_hi);
4651 rcu_read_lock();
4652 for_each_active_iommu(iommu, drhd)
4653 iommu_flush_iotlb_psi(iommu, si_domain,
4654 iova->pfn_lo, iova_size(iova),
4655 !freelist, 0);
4656 rcu_read_unlock();
4657 dma_free_pagelist(freelist);
4659 start_vpfn = iova->pfn_hi + 1;
4660 free_iova_mem(iova);
4662 break;
4665 return NOTIFY_OK;
4668 static struct notifier_block intel_iommu_memory_nb = {
4669 .notifier_call = intel_iommu_memory_notifier,
4670 .priority = 0
4673 static void free_all_cpu_cached_iovas(unsigned int cpu)
4675 int i;
4677 for (i = 0; i < g_num_of_iommus; i++) {
4678 struct intel_iommu *iommu = g_iommus[i];
4679 struct dmar_domain *domain;
4680 int did;
4682 if (!iommu)
4683 continue;
4685 for (did = 0; did < cap_ndoms(iommu->cap); did++) {
4686 domain = get_iommu_domain(iommu, (u16)did);
4688 if (!domain)
4689 continue;
4690 free_cpu_cached_iovas(cpu, &domain->iovad);
4695 static int intel_iommu_cpu_dead(unsigned int cpu)
4697 free_all_cpu_cached_iovas(cpu);
4698 return 0;
4701 static void intel_disable_iommus(void)
4703 struct intel_iommu *iommu = NULL;
4704 struct dmar_drhd_unit *drhd;
4706 for_each_iommu(iommu, drhd)
4707 iommu_disable_translation(iommu);
4710 static inline struct intel_iommu *dev_to_intel_iommu(struct device *dev)
4712 struct iommu_device *iommu_dev = dev_to_iommu_device(dev);
4714 return container_of(iommu_dev, struct intel_iommu, iommu);
4717 static ssize_t intel_iommu_show_version(struct device *dev,
4718 struct device_attribute *attr,
4719 char *buf)
4721 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4722 u32 ver = readl(iommu->reg + DMAR_VER_REG);
4723 return sprintf(buf, "%d:%d\n",
4724 DMAR_VER_MAJOR(ver), DMAR_VER_MINOR(ver));
4726 static DEVICE_ATTR(version, S_IRUGO, intel_iommu_show_version, NULL);
4728 static ssize_t intel_iommu_show_address(struct device *dev,
4729 struct device_attribute *attr,
4730 char *buf)
4732 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4733 return sprintf(buf, "%llx\n", iommu->reg_phys);
4735 static DEVICE_ATTR(address, S_IRUGO, intel_iommu_show_address, NULL);
4737 static ssize_t intel_iommu_show_cap(struct device *dev,
4738 struct device_attribute *attr,
4739 char *buf)
4741 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4742 return sprintf(buf, "%llx\n", iommu->cap);
4744 static DEVICE_ATTR(cap, S_IRUGO, intel_iommu_show_cap, NULL);
4746 static ssize_t intel_iommu_show_ecap(struct device *dev,
4747 struct device_attribute *attr,
4748 char *buf)
4750 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4751 return sprintf(buf, "%llx\n", iommu->ecap);
4753 static DEVICE_ATTR(ecap, S_IRUGO, intel_iommu_show_ecap, NULL);
4755 static ssize_t intel_iommu_show_ndoms(struct device *dev,
4756 struct device_attribute *attr,
4757 char *buf)
4759 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4760 return sprintf(buf, "%ld\n", cap_ndoms(iommu->cap));
4762 static DEVICE_ATTR(domains_supported, S_IRUGO, intel_iommu_show_ndoms, NULL);
4764 static ssize_t intel_iommu_show_ndoms_used(struct device *dev,
4765 struct device_attribute *attr,
4766 char *buf)
4768 struct intel_iommu *iommu = dev_to_intel_iommu(dev);
4769 return sprintf(buf, "%d\n", bitmap_weight(iommu->domain_ids,
4770 cap_ndoms(iommu->cap)));
4772 static DEVICE_ATTR(domains_used, S_IRUGO, intel_iommu_show_ndoms_used, NULL);
4774 static struct attribute *intel_iommu_attrs[] = {
4775 &dev_attr_version.attr,
4776 &dev_attr_address.attr,
4777 &dev_attr_cap.attr,
4778 &dev_attr_ecap.attr,
4779 &dev_attr_domains_supported.attr,
4780 &dev_attr_domains_used.attr,
4781 NULL,
4784 static struct attribute_group intel_iommu_group = {
4785 .name = "intel-iommu",
4786 .attrs = intel_iommu_attrs,
4789 const struct attribute_group *intel_iommu_groups[] = {
4790 &intel_iommu_group,
4791 NULL,
4794 static int __init platform_optin_force_iommu(void)
4796 struct pci_dev *pdev = NULL;
4797 bool has_untrusted_dev = false;
4799 if (!dmar_platform_optin() || no_platform_optin)
4800 return 0;
4802 for_each_pci_dev(pdev) {
4803 if (pdev->untrusted) {
4804 has_untrusted_dev = true;
4805 break;
4809 if (!has_untrusted_dev)
4810 return 0;
4812 if (no_iommu || dmar_disabled)
4813 pr_info("Intel-IOMMU force enabled due to platform opt in\n");
4816 * If Intel-IOMMU is disabled by default, we will apply identity
4817 * map for all devices except those marked as being untrusted.
4819 if (dmar_disabled)
4820 iommu_identity_mapping |= IDENTMAP_ALL;
4822 dmar_disabled = 0;
4823 #if defined(CONFIG_X86) && defined(CONFIG_SWIOTLB)
4824 swiotlb = 0;
4825 #endif
4826 no_iommu = 0;
4828 return 1;
4831 int __init intel_iommu_init(void)
4833 int ret = -ENODEV;
4834 struct dmar_drhd_unit *drhd;
4835 struct intel_iommu *iommu;
4838 * Intel IOMMU is required for a TXT/tboot launch or platform
4839 * opt in, so enforce that.
4841 force_on = tboot_force_iommu() || platform_optin_force_iommu();
4843 if (iommu_init_mempool()) {
4844 if (force_on)
4845 panic("tboot: Failed to initialize iommu memory\n");
4846 return -ENOMEM;
4849 down_write(&dmar_global_lock);
4850 if (dmar_table_init()) {
4851 if (force_on)
4852 panic("tboot: Failed to initialize DMAR table\n");
4853 goto out_free_dmar;
4856 if (dmar_dev_scope_init() < 0) {
4857 if (force_on)
4858 panic("tboot: Failed to initialize DMAR device scope\n");
4859 goto out_free_dmar;
4862 up_write(&dmar_global_lock);
4865 * The bus notifier takes the dmar_global_lock, so lockdep will
4866 * complain later when we register it under the lock.
4868 dmar_register_bus_notifier();
4870 down_write(&dmar_global_lock);
4872 if (no_iommu || dmar_disabled) {
4874 * We exit the function here to ensure IOMMU's remapping and
4875 * mempool aren't setup, which means that the IOMMU's PMRs
4876 * won't be disabled via the call to init_dmars(). So disable
4877 * it explicitly here. The PMRs were setup by tboot prior to
4878 * calling SENTER, but the kernel is expected to reset/tear
4879 * down the PMRs.
4881 if (intel_iommu_tboot_noforce) {
4882 for_each_iommu(iommu, drhd)
4883 iommu_disable_protect_mem_regions(iommu);
4887 * Make sure the IOMMUs are switched off, even when we
4888 * boot into a kexec kernel and the previous kernel left
4889 * them enabled
4891 intel_disable_iommus();
4892 goto out_free_dmar;
4895 if (list_empty(&dmar_rmrr_units))
4896 pr_info("No RMRR found\n");
4898 if (list_empty(&dmar_atsr_units))
4899 pr_info("No ATSR found\n");
4901 if (dmar_init_reserved_ranges()) {
4902 if (force_on)
4903 panic("tboot: Failed to reserve iommu ranges\n");
4904 goto out_free_reserved_range;
4907 if (dmar_map_gfx)
4908 intel_iommu_gfx_mapped = 1;
4910 init_no_remapping_devices();
4912 ret = init_dmars();
4913 if (ret) {
4914 if (force_on)
4915 panic("tboot: Failed to initialize DMARs\n");
4916 pr_err("Initialization failed\n");
4917 goto out_free_reserved_range;
4919 up_write(&dmar_global_lock);
4920 pr_info("Intel(R) Virtualization Technology for Directed I/O\n");
4922 #if defined(CONFIG_X86) && defined(CONFIG_SWIOTLB)
4923 swiotlb = 0;
4924 #endif
4925 dma_ops = &intel_dma_ops;
4927 init_iommu_pm_ops();
4929 for_each_active_iommu(iommu, drhd) {
4930 iommu_device_sysfs_add(&iommu->iommu, NULL,
4931 intel_iommu_groups,
4932 "%s", iommu->name);
4933 iommu_device_set_ops(&iommu->iommu, &intel_iommu_ops);
4934 iommu_device_register(&iommu->iommu);
4937 bus_set_iommu(&pci_bus_type, &intel_iommu_ops);
4938 bus_register_notifier(&pci_bus_type, &device_nb);
4939 if (si_domain && !hw_pass_through)
4940 register_memory_notifier(&intel_iommu_memory_nb);
4941 cpuhp_setup_state(CPUHP_IOMMU_INTEL_DEAD, "iommu/intel:dead", NULL,
4942 intel_iommu_cpu_dead);
4943 intel_iommu_enabled = 1;
4944 intel_iommu_debugfs_init();
4946 return 0;
4948 out_free_reserved_range:
4949 put_iova_domain(&reserved_iova_list);
4950 out_free_dmar:
4951 intel_iommu_free_dmars();
4952 up_write(&dmar_global_lock);
4953 iommu_exit_mempool();
4954 return ret;
4957 static int domain_context_clear_one_cb(struct pci_dev *pdev, u16 alias, void *opaque)
4959 struct intel_iommu *iommu = opaque;
4961 domain_context_clear_one(iommu, PCI_BUS_NUM(alias), alias & 0xff);
4962 return 0;
4966 * NB - intel-iommu lacks any sort of reference counting for the users of
4967 * dependent devices. If multiple endpoints have intersecting dependent
4968 * devices, unbinding the driver from any one of them will possibly leave
4969 * the others unable to operate.
4971 static void domain_context_clear(struct intel_iommu *iommu, struct device *dev)
4973 if (!iommu || !dev || !dev_is_pci(dev))
4974 return;
4976 pci_for_each_dma_alias(to_pci_dev(dev), &domain_context_clear_one_cb, iommu);
4979 static void __dmar_remove_one_dev_info(struct device_domain_info *info)
4981 struct intel_iommu *iommu;
4982 unsigned long flags;
4984 assert_spin_locked(&device_domain_lock);
4986 if (WARN_ON(!info))
4987 return;
4989 iommu = info->iommu;
4991 if (info->dev) {
4992 if (dev_is_pci(info->dev) && sm_supported(iommu))
4993 intel_pasid_tear_down_entry(iommu, info->dev,
4994 PASID_RID2PASID);
4996 iommu_disable_dev_iotlb(info);
4997 domain_context_clear(iommu, info->dev);
4998 intel_pasid_free_table(info->dev);
5001 unlink_domain_info(info);
5003 spin_lock_irqsave(&iommu->lock, flags);
5004 domain_detach_iommu(info->domain, iommu);
5005 spin_unlock_irqrestore(&iommu->lock, flags);
5007 free_devinfo_mem(info);
5010 static void dmar_remove_one_dev_info(struct device *dev)
5012 struct device_domain_info *info;
5013 unsigned long flags;
5015 spin_lock_irqsave(&device_domain_lock, flags);
5016 info = dev->archdata.iommu;
5017 __dmar_remove_one_dev_info(info);
5018 spin_unlock_irqrestore(&device_domain_lock, flags);
5021 static int md_domain_init(struct dmar_domain *domain, int guest_width)
5023 int adjust_width;
5025 init_iova_domain(&domain->iovad, VTD_PAGE_SIZE, IOVA_START_PFN);
5026 domain_reserve_special_ranges(domain);
5028 /* calculate AGAW */
5029 domain->gaw = guest_width;
5030 adjust_width = guestwidth_to_adjustwidth(guest_width);
5031 domain->agaw = width_to_agaw(adjust_width);
5033 domain->iommu_coherency = 0;
5034 domain->iommu_snooping = 0;
5035 domain->iommu_superpage = 0;
5036 domain->max_addr = 0;
5038 /* always allocate the top pgd */
5039 domain->pgd = (struct dma_pte *)alloc_pgtable_page(domain->nid);
5040 if (!domain->pgd)
5041 return -ENOMEM;
5042 domain_flush_cache(domain, domain->pgd, PAGE_SIZE);
5043 return 0;
5046 static struct iommu_domain *intel_iommu_domain_alloc(unsigned type)
5048 struct dmar_domain *dmar_domain;
5049 struct iommu_domain *domain;
5051 if (type != IOMMU_DOMAIN_UNMANAGED)
5052 return NULL;
5054 dmar_domain = alloc_domain(DOMAIN_FLAG_VIRTUAL_MACHINE);
5055 if (!dmar_domain) {
5056 pr_err("Can't allocate dmar_domain\n");
5057 return NULL;
5059 if (md_domain_init(dmar_domain, DEFAULT_DOMAIN_ADDRESS_WIDTH)) {
5060 pr_err("Domain initialization failed\n");
5061 domain_exit(dmar_domain);
5062 return NULL;
5064 domain_update_iommu_cap(dmar_domain);
5066 domain = &dmar_domain->domain;
5067 domain->geometry.aperture_start = 0;
5068 domain->geometry.aperture_end = __DOMAIN_MAX_ADDR(dmar_domain->gaw);
5069 domain->geometry.force_aperture = true;
5071 return domain;
5074 static void intel_iommu_domain_free(struct iommu_domain *domain)
5076 domain_exit(to_dmar_domain(domain));
5079 static int intel_iommu_attach_device(struct iommu_domain *domain,
5080 struct device *dev)
5082 struct dmar_domain *dmar_domain = to_dmar_domain(domain);
5083 struct intel_iommu *iommu;
5084 int addr_width;
5085 u8 bus, devfn;
5087 if (device_is_rmrr_locked(dev)) {
5088 dev_warn(dev, "Device is ineligible for IOMMU domain attach due to platform RMRR requirement. Contact your platform vendor.\n");
5089 return -EPERM;
5092 /* normally dev is not mapped */
5093 if (unlikely(domain_context_mapped(dev))) {
5094 struct dmar_domain *old_domain;
5096 old_domain = find_domain(dev);
5097 if (old_domain) {
5098 rcu_read_lock();
5099 dmar_remove_one_dev_info(dev);
5100 rcu_read_unlock();
5102 if (!domain_type_is_vm_or_si(old_domain) &&
5103 list_empty(&old_domain->devices))
5104 domain_exit(old_domain);
5108 iommu = device_to_iommu(dev, &bus, &devfn);
5109 if (!iommu)
5110 return -ENODEV;
5112 /* check if this iommu agaw is sufficient for max mapped address */
5113 addr_width = agaw_to_width(iommu->agaw);
5114 if (addr_width > cap_mgaw(iommu->cap))
5115 addr_width = cap_mgaw(iommu->cap);
5117 if (dmar_domain->max_addr > (1LL << addr_width)) {
5118 dev_err(dev, "%s: iommu width (%d) is not "
5119 "sufficient for the mapped address (%llx)\n",
5120 __func__, addr_width, dmar_domain->max_addr);
5121 return -EFAULT;
5123 dmar_domain->gaw = addr_width;
5126 * Knock out extra levels of page tables if necessary
5128 while (iommu->agaw < dmar_domain->agaw) {
5129 struct dma_pte *pte;
5131 pte = dmar_domain->pgd;
5132 if (dma_pte_present(pte)) {
5133 dmar_domain->pgd = (struct dma_pte *)
5134 phys_to_virt(dma_pte_addr(pte));
5135 free_pgtable_page(pte);
5137 dmar_domain->agaw--;
5140 return domain_add_dev_info(dmar_domain, dev);
5143 static void intel_iommu_detach_device(struct iommu_domain *domain,
5144 struct device *dev)
5146 dmar_remove_one_dev_info(dev);
5149 static int intel_iommu_map(struct iommu_domain *domain,
5150 unsigned long iova, phys_addr_t hpa,
5151 size_t size, int iommu_prot)
5153 struct dmar_domain *dmar_domain = to_dmar_domain(domain);
5154 u64 max_addr;
5155 int prot = 0;
5156 int ret;
5158 if (iommu_prot & IOMMU_READ)
5159 prot |= DMA_PTE_READ;
5160 if (iommu_prot & IOMMU_WRITE)
5161 prot |= DMA_PTE_WRITE;
5162 if ((iommu_prot & IOMMU_CACHE) && dmar_domain->iommu_snooping)
5163 prot |= DMA_PTE_SNP;
5165 max_addr = iova + size;
5166 if (dmar_domain->max_addr < max_addr) {
5167 u64 end;
5169 /* check if minimum agaw is sufficient for mapped address */
5170 end = __DOMAIN_MAX_ADDR(dmar_domain->gaw) + 1;
5171 if (end < max_addr) {
5172 pr_err("%s: iommu width (%d) is not "
5173 "sufficient for the mapped address (%llx)\n",
5174 __func__, dmar_domain->gaw, max_addr);
5175 return -EFAULT;
5177 dmar_domain->max_addr = max_addr;
5179 /* Round up size to next multiple of PAGE_SIZE, if it and
5180 the low bits of hpa would take us onto the next page */
5181 size = aligned_nrpages(hpa, size);
5182 ret = domain_pfn_mapping(dmar_domain, iova >> VTD_PAGE_SHIFT,
5183 hpa >> VTD_PAGE_SHIFT, size, prot);
5184 return ret;
5187 static size_t intel_iommu_unmap(struct iommu_domain *domain,
5188 unsigned long iova, size_t size)
5190 struct dmar_domain *dmar_domain = to_dmar_domain(domain);
5191 struct page *freelist = NULL;
5192 unsigned long start_pfn, last_pfn;
5193 unsigned int npages;
5194 int iommu_id, level = 0;
5196 /* Cope with horrid API which requires us to unmap more than the
5197 size argument if it happens to be a large-page mapping. */
5198 BUG_ON(!pfn_to_dma_pte(dmar_domain, iova >> VTD_PAGE_SHIFT, &level));
5200 if (size < VTD_PAGE_SIZE << level_to_offset_bits(level))
5201 size = VTD_PAGE_SIZE << level_to_offset_bits(level);
5203 start_pfn = iova >> VTD_PAGE_SHIFT;
5204 last_pfn = (iova + size - 1) >> VTD_PAGE_SHIFT;
5206 freelist = domain_unmap(dmar_domain, start_pfn, last_pfn);
5208 npages = last_pfn - start_pfn + 1;
5210 for_each_domain_iommu(iommu_id, dmar_domain)
5211 iommu_flush_iotlb_psi(g_iommus[iommu_id], dmar_domain,
5212 start_pfn, npages, !freelist, 0);
5214 dma_free_pagelist(freelist);
5216 if (dmar_domain->max_addr == iova + size)
5217 dmar_domain->max_addr = iova;
5219 return size;
5222 static phys_addr_t intel_iommu_iova_to_phys(struct iommu_domain *domain,
5223 dma_addr_t iova)
5225 struct dmar_domain *dmar_domain = to_dmar_domain(domain);
5226 struct dma_pte *pte;
5227 int level = 0;
5228 u64 phys = 0;
5230 pte = pfn_to_dma_pte(dmar_domain, iova >> VTD_PAGE_SHIFT, &level);
5231 if (pte)
5232 phys = dma_pte_addr(pte);
5234 return phys;
5237 static bool intel_iommu_capable(enum iommu_cap cap)
5239 if (cap == IOMMU_CAP_CACHE_COHERENCY)
5240 return domain_update_iommu_snooping(NULL) == 1;
5241 if (cap == IOMMU_CAP_INTR_REMAP)
5242 return irq_remapping_enabled == 1;
5244 return false;
5247 static int intel_iommu_add_device(struct device *dev)
5249 struct intel_iommu *iommu;
5250 struct iommu_group *group;
5251 u8 bus, devfn;
5253 iommu = device_to_iommu(dev, &bus, &devfn);
5254 if (!iommu)
5255 return -ENODEV;
5257 iommu_device_link(&iommu->iommu, dev);
5259 group = iommu_group_get_for_dev(dev);
5261 if (IS_ERR(group))
5262 return PTR_ERR(group);
5264 iommu_group_put(group);
5265 return 0;
5268 static void intel_iommu_remove_device(struct device *dev)
5270 struct intel_iommu *iommu;
5271 u8 bus, devfn;
5273 iommu = device_to_iommu(dev, &bus, &devfn);
5274 if (!iommu)
5275 return;
5277 iommu_group_remove_device(dev);
5279 iommu_device_unlink(&iommu->iommu, dev);
5282 static void intel_iommu_get_resv_regions(struct device *device,
5283 struct list_head *head)
5285 struct iommu_resv_region *reg;
5286 struct dmar_rmrr_unit *rmrr;
5287 struct device *i_dev;
5288 int i;
5290 rcu_read_lock();
5291 for_each_rmrr_units(rmrr) {
5292 for_each_active_dev_scope(rmrr->devices, rmrr->devices_cnt,
5293 i, i_dev) {
5294 if (i_dev != device)
5295 continue;
5297 list_add_tail(&rmrr->resv->list, head);
5300 rcu_read_unlock();
5302 reg = iommu_alloc_resv_region(IOAPIC_RANGE_START,
5303 IOAPIC_RANGE_END - IOAPIC_RANGE_START + 1,
5304 0, IOMMU_RESV_MSI);
5305 if (!reg)
5306 return;
5307 list_add_tail(&reg->list, head);
5310 static void intel_iommu_put_resv_regions(struct device *dev,
5311 struct list_head *head)
5313 struct iommu_resv_region *entry, *next;
5315 list_for_each_entry_safe(entry, next, head, list) {
5316 if (entry->type == IOMMU_RESV_MSI)
5317 kfree(entry);
5321 #ifdef CONFIG_INTEL_IOMMU_SVM
5322 int intel_iommu_enable_pasid(struct intel_iommu *iommu, struct intel_svm_dev *sdev)
5324 struct device_domain_info *info;
5325 struct context_entry *context;
5326 struct dmar_domain *domain;
5327 unsigned long flags;
5328 u64 ctx_lo;
5329 int ret;
5331 domain = get_valid_domain_for_dev(sdev->dev);
5332 if (!domain)
5333 return -EINVAL;
5335 spin_lock_irqsave(&device_domain_lock, flags);
5336 spin_lock(&iommu->lock);
5338 ret = -EINVAL;
5339 info = sdev->dev->archdata.iommu;
5340 if (!info || !info->pasid_supported)
5341 goto out;
5343 context = iommu_context_addr(iommu, info->bus, info->devfn, 0);
5344 if (WARN_ON(!context))
5345 goto out;
5347 ctx_lo = context[0].lo;
5349 sdev->did = FLPT_DEFAULT_DID;
5350 sdev->sid = PCI_DEVID(info->bus, info->devfn);
5352 if (!(ctx_lo & CONTEXT_PASIDE)) {
5353 ctx_lo |= CONTEXT_PASIDE;
5354 context[0].lo = ctx_lo;
5355 wmb();
5356 iommu->flush.flush_context(iommu, sdev->did, sdev->sid,
5357 DMA_CCMD_MASK_NOBIT,
5358 DMA_CCMD_DEVICE_INVL);
5361 /* Enable PASID support in the device, if it wasn't already */
5362 if (!info->pasid_enabled)
5363 iommu_enable_dev_iotlb(info);
5365 if (info->ats_enabled) {
5366 sdev->dev_iotlb = 1;
5367 sdev->qdep = info->ats_qdep;
5368 if (sdev->qdep >= QI_DEV_EIOTLB_MAX_INVS)
5369 sdev->qdep = 0;
5371 ret = 0;
5373 out:
5374 spin_unlock(&iommu->lock);
5375 spin_unlock_irqrestore(&device_domain_lock, flags);
5377 return ret;
5380 struct intel_iommu *intel_svm_device_to_iommu(struct device *dev)
5382 struct intel_iommu *iommu;
5383 u8 bus, devfn;
5385 if (iommu_dummy(dev)) {
5386 dev_warn(dev,
5387 "No IOMMU translation for device; cannot enable SVM\n");
5388 return NULL;
5391 iommu = device_to_iommu(dev, &bus, &devfn);
5392 if ((!iommu)) {
5393 dev_err(dev, "No IOMMU for device; cannot enable SVM\n");
5394 return NULL;
5397 return iommu;
5399 #endif /* CONFIG_INTEL_IOMMU_SVM */
5401 const struct iommu_ops intel_iommu_ops = {
5402 .capable = intel_iommu_capable,
5403 .domain_alloc = intel_iommu_domain_alloc,
5404 .domain_free = intel_iommu_domain_free,
5405 .attach_dev = intel_iommu_attach_device,
5406 .detach_dev = intel_iommu_detach_device,
5407 .map = intel_iommu_map,
5408 .unmap = intel_iommu_unmap,
5409 .iova_to_phys = intel_iommu_iova_to_phys,
5410 .add_device = intel_iommu_add_device,
5411 .remove_device = intel_iommu_remove_device,
5412 .get_resv_regions = intel_iommu_get_resv_regions,
5413 .put_resv_regions = intel_iommu_put_resv_regions,
5414 .device_group = pci_device_group,
5415 .pgsize_bitmap = INTEL_IOMMU_PGSIZES,
5418 static void quirk_iommu_g4x_gfx(struct pci_dev *dev)
5420 /* G4x/GM45 integrated gfx dmar support is totally busted. */
5421 pci_info(dev, "Disabling IOMMU for graphics on this chipset\n");
5422 dmar_map_gfx = 0;
5425 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2a40, quirk_iommu_g4x_gfx);
5426 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e00, quirk_iommu_g4x_gfx);
5427 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e10, quirk_iommu_g4x_gfx);
5428 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e20, quirk_iommu_g4x_gfx);
5429 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e30, quirk_iommu_g4x_gfx);
5430 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e40, quirk_iommu_g4x_gfx);
5431 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e90, quirk_iommu_g4x_gfx);
5433 static void quirk_iommu_rwbf(struct pci_dev *dev)
5436 * Mobile 4 Series Chipset neglects to set RWBF capability,
5437 * but needs it. Same seems to hold for the desktop versions.
5439 pci_info(dev, "Forcing write-buffer flush capability\n");
5440 rwbf_quirk = 1;
5443 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2a40, quirk_iommu_rwbf);
5444 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e00, quirk_iommu_rwbf);
5445 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e10, quirk_iommu_rwbf);
5446 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e20, quirk_iommu_rwbf);
5447 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e30, quirk_iommu_rwbf);
5448 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e40, quirk_iommu_rwbf);
5449 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x2e90, quirk_iommu_rwbf);
5451 #define GGC 0x52
5452 #define GGC_MEMORY_SIZE_MASK (0xf << 8)
5453 #define GGC_MEMORY_SIZE_NONE (0x0 << 8)
5454 #define GGC_MEMORY_SIZE_1M (0x1 << 8)
5455 #define GGC_MEMORY_SIZE_2M (0x3 << 8)
5456 #define GGC_MEMORY_VT_ENABLED (0x8 << 8)
5457 #define GGC_MEMORY_SIZE_2M_VT (0x9 << 8)
5458 #define GGC_MEMORY_SIZE_3M_VT (0xa << 8)
5459 #define GGC_MEMORY_SIZE_4M_VT (0xb << 8)
5461 static void quirk_calpella_no_shadow_gtt(struct pci_dev *dev)
5463 unsigned short ggc;
5465 if (pci_read_config_word(dev, GGC, &ggc))
5466 return;
5468 if (!(ggc & GGC_MEMORY_VT_ENABLED)) {
5469 pci_info(dev, "BIOS has allocated no shadow GTT; disabling IOMMU for graphics\n");
5470 dmar_map_gfx = 0;
5471 } else if (dmar_map_gfx) {
5472 /* we have to ensure the gfx device is idle before we flush */
5473 pci_info(dev, "Disabling batched IOTLB flush on Ironlake\n");
5474 intel_iommu_strict = 1;
5477 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x0040, quirk_calpella_no_shadow_gtt);
5478 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x0044, quirk_calpella_no_shadow_gtt);
5479 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x0062, quirk_calpella_no_shadow_gtt);
5480 DECLARE_PCI_FIXUP_HEADER(PCI_VENDOR_ID_INTEL, 0x006a, quirk_calpella_no_shadow_gtt);
5482 /* On Tylersburg chipsets, some BIOSes have been known to enable the
5483 ISOCH DMAR unit for the Azalia sound device, but not give it any
5484 TLB entries, which causes it to deadlock. Check for that. We do
5485 this in a function called from init_dmars(), instead of in a PCI
5486 quirk, because we don't want to print the obnoxious "BIOS broken"
5487 message if VT-d is actually disabled.
5489 static void __init check_tylersburg_isoch(void)
5491 struct pci_dev *pdev;
5492 uint32_t vtisochctrl;
5494 /* If there's no Azalia in the system anyway, forget it. */
5495 pdev = pci_get_device(PCI_VENDOR_ID_INTEL, 0x3a3e, NULL);
5496 if (!pdev)
5497 return;
5498 pci_dev_put(pdev);
5500 /* System Management Registers. Might be hidden, in which case
5501 we can't do the sanity check. But that's OK, because the
5502 known-broken BIOSes _don't_ actually hide it, so far. */
5503 pdev = pci_get_device(PCI_VENDOR_ID_INTEL, 0x342e, NULL);
5504 if (!pdev)
5505 return;
5507 if (pci_read_config_dword(pdev, 0x188, &vtisochctrl)) {
5508 pci_dev_put(pdev);
5509 return;
5512 pci_dev_put(pdev);
5514 /* If Azalia DMA is routed to the non-isoch DMAR unit, fine. */
5515 if (vtisochctrl & 1)
5516 return;
5518 /* Drop all bits other than the number of TLB entries */
5519 vtisochctrl &= 0x1c;
5521 /* If we have the recommended number of TLB entries (16), fine. */
5522 if (vtisochctrl == 0x10)
5523 return;
5525 /* Zero TLB entries? You get to ride the short bus to school. */
5526 if (!vtisochctrl) {
5527 WARN(1, "Your BIOS is broken; DMA routed to ISOCH DMAR unit but no TLB space.\n"
5528 "BIOS vendor: %s; Ver: %s; Product Version: %s\n",
5529 dmi_get_system_info(DMI_BIOS_VENDOR),
5530 dmi_get_system_info(DMI_BIOS_VERSION),
5531 dmi_get_system_info(DMI_PRODUCT_VERSION));
5532 iommu_identity_mapping |= IDENTMAP_AZALIA;
5533 return;
5536 pr_warn("Recommended TLB entries for ISOCH unit is 16; your BIOS set %d\n",
5537 vtisochctrl);