From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from kanga.kvack.org (kanga.kvack.org [205.233.56.17]) by smtp.lore.kernel.org (Postfix) with ESMTP id CB02CC3DA4A for ; Fri, 2 Aug 2024 11:22:13 +0000 (UTC) Received: by kanga.kvack.org (Postfix) id 62E5C6B0085; Fri, 2 Aug 2024 07:22:13 -0400 (EDT) Received: by kanga.kvack.org (Postfix, from userid 40) id 5DEB06B0088; Fri, 2 Aug 2024 07:22:13 -0400 (EDT) X-Delivered-To: int-list-linux-mm@kvack.org Received: by kanga.kvack.org (Postfix, from userid 63042) id 458ED6B0089; Fri, 2 Aug 2024 07:22:13 -0400 (EDT) X-Delivered-To: linux-mm@kvack.org Received: from relay.hostedemail.com (smtprelay0013.hostedemail.com [216.40.44.13]) by kanga.kvack.org (Postfix) with ESMTP id 27F1A6B0085 for ; Fri, 2 Aug 2024 07:22:13 -0400 (EDT) Received: from smtpin09.hostedemail.com (a10.router.float.18 [10.200.18.1]) by unirelay06.hostedemail.com (Postfix) with ESMTP id C5FC7A50CC for ; Fri, 2 Aug 2024 11:22:12 +0000 (UTC) X-FDA: 82407066504.09.DF48631 Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2070.outbound.protection.outlook.com [40.107.93.70]) by imf03.hostedemail.com (Postfix) with ESMTP id ECD7A2001E for ; Fri, 2 Aug 2024 11:22:09 +0000 (UTC) Authentication-Results: imf03.hostedemail.com; dkim=pass header.d=Nvidia.com header.s=selector2 header.b=Jbhet361; arc=pass ("microsoft.com:s=arcselector10001:i=1"); spf=pass (imf03.hostedemail.com: domain of jgg@nvidia.com designates 40.107.93.70 as permitted sender) smtp.mailfrom=jgg@nvidia.com; dmarc=pass (policy=reject) header.from=nvidia.com ARC-Message-Signature: i=2; a=rsa-sha256; c=relaxed/relaxed; d=hostedemail.com; s=arc-20220608; t=1722597671; h=from:from:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:content-transfer-encoding: in-reply-to:in-reply-to:references:references:dkim-signature; bh=alX4lXDEyzHuCyvrSAfdM1uFxUZy5Vn/2/bDNEMCTII=; b=ol/nR8av3kKDjVpwCFyDqfvkvjaOcfPTwQT6HXe/VNydXnzVcuyatKiqXFcCtv7ZMGlIny Zh7/t5QknbM+NirzmuHcOX+4Hm3PV8PqEh7lUtfGXtr3PQz9bYwt0EIHBzw+gmzWLG3vfx /Kl/IQpu+qm43ITUqqfIVYbGkOwqar8= ARC-Seal: i=2; s=arc-20220608; d=hostedemail.com; t=1722597671; a=rsa-sha256; cv=pass; b=fKGbQxMyNhIzD12EpLJSc5CxWV+ffHF/HwZPJ9jpie69Jwd8MwXAXGcMjthCGW3zFQRkik 7vS+N5HJumPaNnRSolb521kTfHQjOPO6ndYlyg9Y45hZ008rItMrULSkRNjWNYzbkC4vry nJaawy222S58A5zlB+1vf2p54b3YYvA= ARC-Authentication-Results: i=2; imf03.hostedemail.com; dkim=pass header.d=Nvidia.com header.s=selector2 header.b=Jbhet361; arc=pass ("microsoft.com:s=arcselector10001:i=1"); spf=pass (imf03.hostedemail.com: domain of jgg@nvidia.com designates 40.107.93.70 as permitted sender) smtp.mailfrom=jgg@nvidia.com; dmarc=pass (policy=reject) header.from=nvidia.com ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=h91MF4Rw2SMLe6bqH6MZ+qEYdDujqr1YWBFgTbRGW4TYi9Mn9mz0s4zPCXVI+per+Ul9aA8biV6h+BOcxpAy1lz0G+DRSOvJdETe+rshjPWXDpCQYnR8SUzCBMYb/iKT7Z3v+SgQvniaq6ynByOw6ufD0l/74PbXAjBtJiPCtWKQf/bywGIWbC9LkX9Zj2YTpaJuR+4N0dQ95d4Lv9jOxWhaZgvC6ZDsb0AcjgDKDbva7grwsvztv/6B3PgJDQX9/Jd197edOHlsme0OCN9fPTAfsCJvRFv0RVWRIiz0gjatHhfLC0vS6+sq3sHKKaYbvyKjKi7XTZXX1B1byQHEPw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=alX4lXDEyzHuCyvrSAfdM1uFxUZy5Vn/2/bDNEMCTII=; b=ygQJggFC7PS9ntL6DWjIBZiiCTNO2Slzb0eQSWmJC/eZ5LHmfqZ+FdV7hdUaZE5TRi/ezperxE4u2685ZGjkzctvuQbTwJemQV7H+JE9mcel735HTd/o9yP+smyx8WXTPc9v1ARA50uw6QWHUkWs/Xfi2xo7EYaae+t4o7/kULjw34igqQjsukUh9ZfGQmVLoOYeDnhp69HVnRjEBcS/4oTtb4ShVZSkZvmK2KAkHLfz9AU6YSBuq8kP1qypcG5bdYxki8Q0RnBpkXHBVSTVa//7Y7719PTjlOotuinsiwOoJTGfD2IXL1fIdCn/Y7S7L95EZ6W/bO2LuGGPy2su8w== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=nvidia.com; dmarc=pass action=none header.from=nvidia.com; dkim=pass header.d=nvidia.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=Nvidia.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=alX4lXDEyzHuCyvrSAfdM1uFxUZy5Vn/2/bDNEMCTII=; b=Jbhet361mop4mnCm+Wvu4Pxs9roEnJpDF/bWlKZ/4nWXGHLIH2Nm3wqu8/pFrkl/kSO+kyMLOAJTm1t8SVI0Q5SBJ5+RJa3DrmWYXzS/I9Bv3UvY+10bZDkmEFGFCsFUmoKjyW3WMYIioieqihwKYnnyqnO2t4gjE8+QPfio7K8Jz7ZRiNFWeIotpSeuvlmsZNInAnAz0UQRIU5qZ5yLccruywukEyHeOjmxd39gNNgGjnfTpgpS02EOoY/ZTBgbKRmGq1nmmm1dokFrtnorMePvNDSFPCaHtpoE32aQk9/my8jwDEfM92YjCsbZ8jp8q0UD/fs6SX1UPp9xfkcLzg== Received: from CH3PR12MB7763.namprd12.prod.outlook.com (2603:10b6:610:145::10) by SN7PR12MB7450.namprd12.prod.outlook.com (2603:10b6:806:29a::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7828.22; Fri, 2 Aug 2024 11:22:06 +0000 Received: from CH3PR12MB7763.namprd12.prod.outlook.com ([fe80::8b63:dd80:c182:4ce8]) by CH3PR12MB7763.namprd12.prod.outlook.com ([fe80::8b63:dd80:c182:4ce8%4]) with mapi id 15.20.7828.024; Fri, 2 Aug 2024 11:22:06 +0000 Date: Fri, 2 Aug 2024 08:22:05 -0300 From: Jason Gunthorpe To: "Tian, Kevin" Cc: David Hildenbrand , Mostafa Saleh , John Hubbard , Elliot Berman , Andrew Morton , Shuah Khan , Matthew Wilcox , "maz@kernel.org" , "kvm@vger.kernel.org" , "linux-arm-msm@vger.kernel.org" , "linux-mm@kvack.org" , "linux-kernel@vger.kernel.org" , "linux-kselftest@vger.kernel.org" , "pbonzini@redhat.com" , Fuad Tabba , "Xu, Yilun" , "Qiang, Chenyi" Subject: Re: [PATCH RFC 0/5] mm/gup: Introduce exclusive GUP pinning Message-ID: <20240802112205.GA478300@nvidia.com> References: <20240618-exclusive-gup-v1-0-30472a19c5d1@quicinc.com> <7fb8cc2c-916a-43e1-9edf-23ed35e42f51@nvidia.com> <14bd145a-039f-4fb9-8598-384d6a051737@redhat.com> <1ab73f42-9397-4fc7-8e62-2627b945f729@redhat.com> <20240620143406.GJ2494510@nvidia.com> Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-ClientProxiedBy: BLAPR03CA0015.namprd03.prod.outlook.com (2603:10b6:208:32b::20) To CH3PR12MB7763.namprd12.prod.outlook.com (2603:10b6:610:145::10) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: CH3PR12MB7763:EE_|SN7PR12MB7450:EE_ X-MS-Office365-Filtering-Correlation-Id: e59ca243-a732-4c0a-1912-08dcb2e5574d X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|7416014|376014|1800799024|366016; X-Microsoft-Antispam-Message-Info: =?us-ascii?Q?TKgnZOI60gkPYCOilhemKhKQm9XnKeFyUIyN1EyLS2Hu4wKgzVoJysg0N8V8?= =?us-ascii?Q?3s4Lu46LL2dp0sHrJ9F+nVzYlQkya3fRH3kPtxP2/3FxvpbQO5fmWqNUdM/L?= =?us-ascii?Q?ETXaQyB7r2VNDAkY3VxeBrC3zFsDSR5FzUqIzsAqOx0O+EpIu3VizQSE5KYL?= =?us-ascii?Q?9D8GtUheTNyZF48jtbwy2DO7Ilb9Iu6TbvaVnz6ySmPStZfdnvpd45sIgX89?= =?us-ascii?Q?wJgU8g3If2+eWHzeQ8RXasgAwkD839MDCicr24zIPR1OYeCjg9LgxWNyWmGO?= =?us-ascii?Q?bq4XfUgAy3sMMDh35gsALnPF6i52KsaOqdnsJlSCEd+xxtAvWyhqailHlRyg?= =?us-ascii?Q?DcBCU96OAKaX31J5mRmujgAJH8oPrNB0sDd/NGJ9+vavVTyqfddLx+xLHsyf?= =?us-ascii?Q?Q4PPdRch/TJXF+bjLFNu35qVpTNEpFD7PYLSJGVtakrpeAIEZKAADcAqgZxV?= =?us-ascii?Q?ILcO447KcwGBjJKutzHnvFGvSWW/Wm2wriuYxAV4zpMjZpJPR64N3fx8Bh51?= =?us-ascii?Q?lUJQBGydSnHe86vr48MATy0meS3ILTyMIBUQ1FsQCZ+ZXuRZy/Vorg4BwbjS?= =?us-ascii?Q?s0EeJbJgCwAa1bEzBPTdclBC3SQuWzdt7juqJEBJHRNMSTuEYucITfMDsiZw?= =?us-ascii?Q?BXldSNy1kt0KE9oLGUvxxOqK76QZHqaSdCne3Ucxd7/0or/8MDZfergY9DlV?= =?us-ascii?Q?Lbpl0sLbl+eT7YEyV1fbxUJSqnYhZhIXjR9IR1ichTuc1wJ6ooZaax8lhJz5?= =?us-ascii?Q?d/0vgqNeWy1HEEqPlXUYLmHuTUedz7luK+u6RyMVJ2lK4OcohCPN+6Z/tjHo?= =?us-ascii?Q?5A2LulyTOmJqIg2FuX8FAc6W1J1jwPZZTnrjISIN3t/KwbIDFw8BmJ95qGnJ?= =?us-ascii?Q?3oZqDuuiDjmsMsO1HFj5ngckUTbW/OOzvqy06YM9Ej3cwjGNruJHqKeU1ppp?= =?us-ascii?Q?hPC85VW9PnfnEhmurF20faOetHe5fayTH8JoZPUnFyXlKjV/5Vx/+VXNlzMR?= =?us-ascii?Q?fBkjrs+PVsNnJrb+LRiW5hGX1Qba/oy3+T2swKb7f8KetQycXQfil/QPlm/d?= =?us-ascii?Q?xpQ8p35EIuP2vE78nReAMs/9eZeVFoVcH7eFw/WWCc4pyft8KDrJHqika2Tt?= =?us-ascii?Q?CtNyRiYn5h60tBPZIturJlC+mxuQRkkmpr8kRCCKDAmM3Yuj6Y30XGff7+zT?= =?us-ascii?Q?dJyWvmasQjX0Pix1Tx9vt0FCTrX526HBKpx0IWnvwySzi966+HKY952nJUC1?= =?us-ascii?Q?0aYIC8WwhZDt6OlykZTQGF7+0oUEbP3S0hZpHMGQZqvNVuEOWcalf5kD33xD?= =?us-ascii?Q?tMx3wiqNt83ZhkXnlVTJnbQp1MVhaMgZBB50/+U0vhVbvA=3D=3D?= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:CH3PR12MB7763.namprd12.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(7416014)(376014)(1800799024)(366016);DIR:OUT;SFP:1101; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?us-ascii?Q?LIykHP4eeyP6HvfRG668LGnh95FlSzHPoXWFqnFoPVFmJZ3oxB6DlIHW2G6G?= =?us-ascii?Q?W7pS9Ix0nq4mmeGNNKoT7/XxqHe8HGhjLq/h2kbXIPuh63xYBKl9oqvR3q2Q?= =?us-ascii?Q?ZVnUtTQz+iczoLQ+MeuVUqE67wnXk/ubGzZJop5H19iB9fbUVMhHUYZ+MQQx?= =?us-ascii?Q?sOEkHVuPbb2Bw/OBGks/MyxFVxzqyU2qHcXgt1QxfKgPgqHjbvrddp1JronI?= =?us-ascii?Q?rnu4O0N9HOy4WYV8OHrOn8vkcwSwK61mOCjcBdqVP4m5mu/aoutudKg1lQqh?= =?us-ascii?Q?gNK40UbUZY9JSMqBLOGBWmG7OYgqMvqQ/yDes2NE3xNDzvaQDvTutFiysaJU?= =?us-ascii?Q?y3kbylz+bj1taWHdRzR8Qf4+LZmEuCXUGLjtn+fCo5dv4YlHD8FiuZ/x0w+a?= =?us-ascii?Q?/ALGy51LEH8wXoakxrzwc/R6k1THXg2+20yfSzqwp7aiybfgbrrlkCp3r1hP?= =?us-ascii?Q?VVIhb1CR3lFJup3dEvmfS16b5WbOHeqpzTKnAVPhhvdWS0IaIDOdAxENTCgg?= =?us-ascii?Q?uFicgl9DCcKwisfZxsq8aFnk2PRv36NjZs7lbIl7Mz5G9a7AbpJuTYkIafr3?= =?us-ascii?Q?+hOxfNCAhh18ulAXebuQD3XSDnRXSmydJ1Fn7NWXARbAiv7U8gqMak72unT0?= =?us-ascii?Q?Deil9AAO70ZIaqYUMftwaKwuIbU81pIP32IxDlrl8KLwnHVQODgN6UkTEPC2?= =?us-ascii?Q?guyjKgc9LItIp2x4NOhsLtdvwliY+ZuO8cAQICobMeNiAB+RDC0Lb4L0RAH+?= =?us-ascii?Q?EV5VB63fIY2QH7GICx5uc9KcW/B9fisUo7Z2GnUY4QqsW3DkbN7Km8Lc8h91?= =?us-ascii?Q?L00mcYM5JNY+vvTvMzUWsaaYHHJ+6zYeUIX3oD+pd+JCYsx/BTXoHIU31YjD?= =?us-ascii?Q?HVR8bDqdtcIZlX+GuX5IpY4kHb+cUwu8ffDU81cWVIQVFa1K2j82Qyc1eeRJ?= =?us-ascii?Q?6E2PfNUkkBwPw3DsJQI9tjDJvdAJ88+ufO597K/yQC01KActbM9y5586FTZ9?= =?us-ascii?Q?zq/v3AuiDOzoepLb926pGlasraIdbb9UWg0geRLgYCNa1+xUwpFybw3G4tsv?= =?us-ascii?Q?lNx3m6HLaRhblhdrLv+vZxqd+RZ9rxmJ5NqHDr2TKn7bBbT6igcPT5411GaW?= =?us-ascii?Q?uyb+gYpqNfuBYE6JoY4xm/wMjcpbdlXoXx4tuivu888DHPUTo/uTsG54v+4x?= =?us-ascii?Q?sazw8XxS1Bybkmx6feOZ9poeK3TBdrt/rfCh1la00q/7hy5tUJvp3WX5VfuZ?= =?us-ascii?Q?sM+0/Krdd10b9vYDRSyByOD7jdvT9hw1hh4Oi4Pz9Mp9kwKQCK9alS9DHUBf?= =?us-ascii?Q?iBpZ2Gws6oWgXB/l7TttnGBB+JQPr0hlIDz+bcfML0PS+LoFbUFQsDIwo7fB?= =?us-ascii?Q?vvds+NBSM18ki9ybl3/FILUPtsXhGTvGnTylYrjix6eF/14U2u+DZ6RvquUh?= =?us-ascii?Q?UMu/LgyHnD/EAJ+T2w7MZPRoXzv2EwVuLy8uISzRzhWPk2MkJnVH+QhYcBAR?= =?us-ascii?Q?n7vE26gw9mZXD1LvmCjYyElI9/SI9qvOmlUdFx1+pxO28fHo6qFdKqvK2KoM?= =?us-ascii?Q?20oyn1PO1FmwE94IIarPLdYs0BhgQqAJpRogd/OQ?= X-OriginatorOrg: Nvidia.com X-MS-Exchange-CrossTenant-Network-Message-Id: e59ca243-a732-4c0a-1912-08dcb2e5574d X-MS-Exchange-CrossTenant-AuthSource: CH3PR12MB7763.namprd12.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Aug 2024 11:22:06.3104 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 43083d15-7273-40c1-b7db-39efd9ccc17a X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: +jAlkaFG1ENblE1d7tRJaLZbeNd2sM+MIh/9nkYKtlAGhTOTmuUDSzTxeDkMEYOv X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN7PR12MB7450 X-Stat-Signature: b8aqzuiwbew4hfqnyqn6xgftdrmwn39i X-Rspamd-Queue-Id: ECD7A2001E X-Rspam-User: X-Rspamd-Server: rspam08 X-HE-Tag: 1722597729-837728 X-HE-Meta: U2FsdGVkX1+UZfeF9YpP55KqIzcSgXJ2tCCNDZNJLxKscG96JZhvzCASQzRDIS28uP20ME8rX7/wKTM6lCQxvY+kkSYiMrKDMG/cN2IBEDFHexRsl3Cb7vv9yNYNNrfuNpbD634COava5+86J1frTUqMcmuIMMwZ2/7ZcQS7MyVSw2so9t2IJq40OmbgP6ZQF+g8/hgmjO/IB1oCJOcL6KJ9dH8eiOEzyAmuYz4v+C4Hx0aXC082yqlc07WjRwbqoRKTG46KX2eVnChSTXCVIKH6J3qDZFENYZt0l53P14sIS+lkivSGJe9yABceBaqygdAa8D87CWDg1t5/HCUjt5wtEd+EWgvn76ecWaXOW82hctpL8+E88v0dwLW4VB1TSMZusyIW3f6zszZiM3jZfnI02y7J7NmTwaNlTHDq6tJravcS9FvZ/P7a/Dnh8pv+QVLwbKqqL+heSL87kJMTP7tuiHdVGEzOE3Ju+mCDnyG6jTGPV+tw33JPVyP90495PxmBe+cB1XRfxM6NojFhvmttIwvS6+jVYDIHV2vZGjyIAuRcKgXlcrlJDVwxLF7oV7xMV7mKiU3PeHZc5n2K5i6QRxq1BJE8G+EOW4G2qcSTj9j9L4D10/YqFzjsZvMacvzVJ9QddNxv9z8kwDdIpULvE25VGWLOEM/blHLK3x0XFYckNNJcGYNYLyrMpI5+Dv0qSRG4mermPn7yvuJ6uIWEbvq/slRX4qW1i1WeDTsm6tjSKjFgGyAGR0Uu5nqRHphU72gufWDtOfVwa/H+HgXf1mMlExtyMOLoD0S05kGQ26kYTGXe752yigmfXiHyNJBHQJX4YM6Cu9SL0+P/crCM0gvKp2cuA+tzZndICZ39a4nb/ruEycw1v/e9f5jmBxs/HCLUWai4Ki6IODlEoQnByd6EHGutkEUPkwgJp19zrOfXp++pvQ+K3jcs4hWIx4q7YF6BU4WGdkgNvNv HLfJGeI4 HX3TxkAjEWX2Y6oRE4J7/Nh/BLo9zhHwR7LmfDKZBmvv0p71wjfgE9YM9Sh4q5eijD722qCnCEnm8lUvDFimV3nqGXRR+XbUzbmoZ4tTm9Z1n8NvwAS5EGIvnRs3W8TA87c6E2oK0ik3GONSvflHsNa3H/jr/D1yHwKv412tDr7KrHO6PAyqYT6cHqVo1IXQwi2cf1fZ8sTKr2tSxNHEgQh4wsDbkXsVQDH5+C1afGquO+ouaeUZY4p2GxwrjjFwtRjHiO0dlxc68u0kt7rhJ7k69an67iFxEAMiTtocBWQsB+zeat5O4+q2a6i3TshIauRCoRP77UuoZ37/O2PMnhIXwWcBk3lMV/01y X-Bogosity: Ham, tests=bogofilter, spamicity=0.000000, version=1.2.4 Sender: owner-linux-mm@kvack.org Precedence: bulk X-Loop: owner-majordomo@kvack.org List-ID: List-Subscribe: List-Unsubscribe: On Fri, Aug 02, 2024 at 08:26:48AM +0000, Tian, Kevin wrote: > > From: Jason Gunthorpe > > Sent: Thursday, June 20, 2024 10:34 PM > > > > On Thu, Jun 20, 2024 at 04:14:23PM +0200, David Hildenbrand wrote: > > > > > 1) How would the device be able to grab/access "private memory", if not > > > via the user page tables? > > > > The approaches I'm aware of require the secure world to own the IOMMU > > and generate the IOMMU page tables. So we will not use a GUP approach > > with VFIO today as the kernel will not have any reason to generate a > > page table in the first place. Instead we will say "this PCI device > > translates through the secure world" and walk away. > > > > The page table population would have to be done through the KVM path. > > Sorry for noting this discussion late. Dave pointed it to me in a related > thread [1]. > > I had an impression that above approach fits some trusted IO arch (e.g. > TDX Connect which has a special secure I/O page table format and > requires sharing it between IOMMU/KVM) but not all. > > e.g. SEV-TIO spec [2] (page 8) describes to have the IOMMU walk the > existing I/O page tables to get HPA and then verify it through a new > permission table (RMP) for access control. It is not possible, you cannot have the unsecure world control the IOMMU translation and expect a secure guest. The unsecure world can attack the guest by scrambling the mappings of its private pages. A RMP does not protect against this. This is why the secure world controls the CPU's GPA translation exclusively, same reasoning for iommu. Jason