[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH v7 1/5] xen/domctl: extend XEN_DOMCTL_assign_device to handle not only iommu


  • To: "xen-devel@xxxxxxxxxxxxxxxxxxxx" <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Oleksii Moisieiev <Oleksii_Moisieiev@xxxxxxxx>
  • Date: Wed, 14 Jan 2026 18:29:48 +0000
  • Accept-language: en-US
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=epam.com; dmarc=pass action=none header.from=epam.com; dkim=pass header.d=epam.com; arc=none
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=0ZOur9hcnIrC49t2nKFG1sBkxLPTcU8vBfzNYSma4Nw=; b=v5hXRKmJTu7ls9U7cuVc8rp1UjonOz4dIc3fBpbGn4gPUh/ooBabSgQztW+NWWGCIsX+DgdgcNojRz0jmnJqCzeC+Y+gdZeojvpU0HHSNULRkNqeS76BGxOrzmTndtci1O6LpF28Yd0QCuLLpsh3V8fBpDlx/hOVQpicttoscaiv2g5X8eaiXA8B08N+goJlM7pB4IKdASK1oalbKjQXC7jcbAyK3orcSuESu82wYawy1A6MsGQQBLfxSVEfhZm76UhkBtd7OZ+hup7pd0liVQT2Pn7N2qKrLqEud8+m8eP+gTvmNY2Hg+IuXX/BL47xpooteB74m0Jxj4Irt3dO9w==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=L8fXhzxNP0d2MzduSM+KJPPnnJo6PyWv0onJd8yvQpRog2WJe76T9qKVmoCiKc95tsLzYwARUn7E+O5WOQn2l/6tZ8ffi8zUSgn7bhctMs8Nec6svTEJcg3bqrpaMMH99QEaw4aR0H0joTue+p2sJEot7+Io3GivAdTmnKcP0GOhGoeFLbWpOkPVELA1WmAI1dNiJD9xnop29rlkGlHvspkZP7e5wucxuRt9yCuXkqCIhr9cKeVAwNNuWBBMV7NklvhY0+zPmeK35J9zX4l0SaOM2Eb5CuPCVarUn7q2jVqLp7nGZ8CPMHpBNtbQXyPft1kTracL3Kew1ibhVs27dg==
  • Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=epam.com;
  • Cc: Andrew Cooper <andrew.cooper3@xxxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Bertrand Marquis <bertrand.marquis@xxxxxxx>, Jan Beulich <jbeulich@xxxxxxxx>, Juergen Gross <jgross@xxxxxxxx>, Julien Grall <julien@xxxxxxx>, Michal Orzel <michal.orzel@xxxxxxx>, Oleksii Moisieiev <Oleksii_Moisieiev@xxxxxxxx>, Roger Pau Monné <roger.pau@xxxxxxxxxx>, Stefano Stabellini <sstabellini@xxxxxxxxxx>, Volodymyr Babchuk <Volodymyr_Babchuk@xxxxxxxx>, Grygorii Strashko <grygorii_strashko@xxxxxxxx>
  • Delivery-date: Wed, 14 Jan 2026 18:29:55 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>
  • Thread-index: AQHchYPDuN/1Zdz2qUyC6pz/50rn/A==
  • Thread-topic: [PATCH v7 1/5] xen/domctl: extend XEN_DOMCTL_assign_device to handle not only iommu

From: Grygorii Strashko <grygorii_strashko@xxxxxxxx>

Add chained handling of assigned DT devices to support access-controller
functionality through SCI framework, so a DT device assign request can be
passed to firmware for processing and enabling VM access to the requested
device (for example, device power management through SCMI).

The SCI access-controller DT device processing is called before the IOMMU
path. It runs for any DT-described device (protected or not, and even when
the IOMMU is disabled). The IOMMU path remains unchanged for PCI devices;
only the DT path is relaxed to permit non-IOMMU devices.

This lets xl.cfg:"dtdev" list both IOMMU-protected and non-protected DT
devices:

dtdev = [
    "/soc/video@e6ef0000", <- IOMMU protected device
    "/soc/i2c@e6508000", <- not IOMMU protected device
]

The change is done in two parts:
1) call sci_do_domctl() in do_domctl() before IOMMU processing and propagate
its error if it fails while the IOMMU path succeeds (unhandled cases return
-ENXIO and are ignored);
2) update iommu_do_dt_domctl() to check for dt_device_is_protected() and
not fail if DT device is not protected by IOMMU. iommu_do_pci_domctl
doesn't need to be updated because iommu_do_domctl first tries
iommu_do_pci_domctl (when CONFIG_HAS_PCI) and falls back to
iommu_do_dt_domctl only if PCI returns -ENODEV.
The new dt_device_is_protected() bypass in iommu_do_dt_domctl only
applies to DT-described devices; SCI parameters are carried via DT nodes.
PCI devices handled by iommu_do_pci_domctl do not carry DT/SCI
metadata in this path, so there is no notion of “SCI parameters on a
non-IOMMU-protected PCI device” for it to interpret or to skip. The
PCI path should continue to report errors if assignment cannot be
performed by the IOMMU layer.
So we should leave iommu_do_pci_domctl unchanged; the SCI/DT-specific
relaxations belong only in the DT path.
Also SCI handling only exists when DT is present.

Signed-off-by: Grygorii Strashko <grygorii_strashko@xxxxxxxx>
Signed-off-by: Oleksii Moisieiev <oleksii_moisieiev@xxxxxxxx>
---

Changes in v7:
- update domctl to build on both Arm and x86 platforms
- move ret1 declaration to the top of the function as required by code
style

Changes in v6:
- change iommu_do_domctl and sci_do_domctl command order and
call sci_do_domctl first which will produce cleaner code path.
Also dropped changing return code when iommu was disabled in
iommu_do_domctl.

Changes in v5:
- return -EINVAL if mediator without assign_dt_device was provided
- invert return code check for iommu_do_domctl in
XEN_DOMCTL_assign_device domctl processing to make cleaner code
- change -ENOTSUPP error code to -ENXIO in sci_do_domctl
- handle -ENXIO return comde of iommu_do_domctl
- leave !dt_device_is_protected check in iommu_do_dt_domctl to make
code work the same way it's done in "handle_device" call while
creating hwdom(dom0) and "handle_passthrough_prop" call for dom0less
creation
- drop return check from sci_assign_dt_device call as not needed
- do not return EINVAL when addign_dt_device is not set. That is
because this callback is optional and not implemented in single-agent driver

 xen/arch/arm/firmware/sci.c             | 35 +++++++++++++++++++++++++
 xen/arch/arm/include/asm/firmware/sci.h | 14 ++++++++++
 xen/common/domctl.c                     | 35 ++++++++++++++++++++++++-
 xen/drivers/passthrough/device_tree.c   |  6 +++++
 4 files changed, 89 insertions(+), 1 deletion(-)

diff --git a/xen/arch/arm/firmware/sci.c b/xen/arch/arm/firmware/sci.c
index aa93cda7f0..31a7e5c28b 100644
--- a/xen/arch/arm/firmware/sci.c
+++ b/xen/arch/arm/firmware/sci.c
@@ -126,6 +126,41 @@ int sci_assign_dt_device(struct domain *d, struct 
dt_device_node *dev)
     return 0;
 }
 
+int sci_do_domctl(struct xen_domctl *domctl, struct domain *d,
+                  XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_domctl)
+{
+    struct dt_device_node *dev;
+    int ret = 0;
+
+    switch ( domctl->cmd )
+    {
+    case XEN_DOMCTL_assign_device:
+        ret = -ENXIO;
+        if ( domctl->u.assign_device.dev != XEN_DOMCTL_DEV_DT )
+            break;
+
+        if ( !cur_mediator )
+            break;
+
+        if ( !cur_mediator->assign_dt_device )
+            break;
+
+        ret = dt_find_node_by_gpath(domctl->u.assign_device.u.dt.path,
+                                    domctl->u.assign_device.u.dt.size, &dev);
+        if ( ret )
+            return ret;
+
+        ret = sci_assign_dt_device(d, dev);
+
+        break;
+    default:
+        /* do not fail here as call is chained with iommu handling */
+        break;
+    }
+
+    return ret;
+}
+
 static int __init sci_init(void)
 {
     struct dt_device_node *np;
diff --git a/xen/arch/arm/include/asm/firmware/sci.h 
b/xen/arch/arm/include/asm/firmware/sci.h
index 3500216bc2..a2d314e627 100644
--- a/xen/arch/arm/include/asm/firmware/sci.h
+++ b/xen/arch/arm/include/asm/firmware/sci.h
@@ -146,6 +146,14 @@ int sci_dt_finalize(struct domain *d, void *fdt);
  * control" functionality.
  */
 int sci_assign_dt_device(struct domain *d, struct dt_device_node *dev);
+
+/*
+ * SCI domctl handler
+ *
+ * Only XEN_DOMCTL_assign_device is handled for now.
+ */
+int sci_do_domctl(struct xen_domctl *domctl, struct domain *d,
+                  XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_domctl);
 #else
 
 static inline bool sci_domain_is_enabled(struct domain *d)
@@ -195,6 +203,12 @@ static inline int sci_assign_dt_device(struct domain *d,
     return 0;
 }
 
+static inline int sci_do_domctl(struct xen_domctl *domctl, struct domain *d,
+                                XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_domctl)
+{
+    return 0;
+}
+
 #endif /* CONFIG_ARM_SCI */
 
 #endif /* __ASM_ARM_SCI_H */
diff --git a/xen/common/domctl.c b/xen/common/domctl.c
index 954d790226..5a31cccdd7 100644
--- a/xen/common/domctl.c
+++ b/xen/common/domctl.c
@@ -29,6 +29,9 @@
 #include <xen/xvmalloc.h>
 
 #include <asm/current.h>
+#if IS_ENABLED(CONFIG_ARM)
+#include <asm/firmware/sci.h>
+#endif
 #include <asm/irq.h>
 #include <asm/page.h>
 #include <asm/p2m.h>
@@ -274,7 +277,7 @@ static bool is_stable_domctl(uint32_t cmd)
 
 long do_domctl(XEN_GUEST_HANDLE_PARAM(xen_domctl_t) u_domctl)
 {
-    long ret = 0;
+    long ret = 0, ret1 = 0;
     bool copyback = false;
     struct xen_domctl curop, *op = &curop;
     struct domain *d;
@@ -827,7 +830,37 @@ long do_domctl(XEN_GUEST_HANDLE_PARAM(xen_domctl_t) 
u_domctl)
     case XEN_DOMCTL_test_assign_device:
     case XEN_DOMCTL_deassign_device:
     case XEN_DOMCTL_get_device_group:
+        if ( IS_ENABLED(CONFIG_ARM) )
+        {
+            /*
+             * Add chained handling of assigned DT devices to support
+             * access-controller functionality through SCI framework, so
+             * DT device assign request can be passed to FW for processing and
+             * enabling VM access to requested device.
+             * The access-controller DT device processing is called before 
IOMMU
+             * processing preserving return code and expected to be executed 
for
+             * any DT device regardless if DT device is protected by IOMMU or
+             * not (or IOMMU is disabled).
+             */
+            ret1 = sci_do_domctl(op, d, u_domctl);
+            if ( ret1 < 0 )
+                return ret1;
+        }
+        else
+            ret1 = -ENXIO;
+
         ret = iommu_do_domctl(op, d, u_domctl);
+        if ( ret < 0 )
+            return ret;
+
+        /*
+         * If IOMMU processing was successful, check for SCI processing return
+         * code and if it was failed then overwrite the return code to 
propagate
+         * SCI failure back to caller.
+         */
+        if ( ret1 != -ENXIO )
+            ret = ret1;
+
         break;
 
     case XEN_DOMCTL_get_paging_mempool_size:
diff --git a/xen/drivers/passthrough/device_tree.c 
b/xen/drivers/passthrough/device_tree.c
index f5850a2607..29a44dc773 100644
--- a/xen/drivers/passthrough/device_tree.c
+++ b/xen/drivers/passthrough/device_tree.c
@@ -379,6 +379,12 @@ int iommu_do_dt_domctl(struct xen_domctl *domctl, struct 
domain *d,
             break;
         }
 
+        if ( !dt_device_is_protected(dev) )
+        {
+            ret = 0;
+            break;
+        }
+
         ret = iommu_assign_dt_device(d, dev);
 
         if ( ret )
-- 
2.34.1

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.