[RFC PATCH v6 00/11] iommufd: Infrastructure for vIOMMU creation for confidential guests and guest TSM requests

From: Aneesh Kumar K.V (Arm)

Date: Thu Sep 17 2026 - 11:38:41 EST


This series adds the IOMMUFD and PCI/TSM infrastructure required for device
assignment. It introduces an IOMMUFD-owned vIOMMU provider registry and the
IOMMU_VDEVICE_TSM_REQ ioctl.

The series adds a vIOMMU provider abstraction that allows a subsystem
other than the physical IOMMU driver to implement a vIOMMU type. It groups
the vIOMMU operations with their module owner and private data, and makes
that implementation discoverable during vIOMMU allocation.

External providers are selected by exact vIOMMU type. When no provider
matches, vIOMMU creation falls back to the physical IOMMU driver. Once a
provider matches, its result is authoritative and failures do not trigger
fallback.

Guest TSM requests are dispatched through the vdevice. PCI/TSM uses
reference-counted contexts to retain the resources needed by providers,
without introducing separate IOMMUFD TSM bind or unbind ioctls.

Note: Codex was used to assist with commit message formatting and code
rearrangement.

Changes from v5:
https://lore.kernel.org/all/20260525154816.1029642-1-aneesh.kumar@xxxxxxxxxx
* Replace the TSM bind/unbind interface with reference-counted contexts.
* Add the IOMMUFD vIOMMU provider abstraction.
* Route TSM guest requests through viommu operations.

Changes from v4:
https://lore.kernel.org/all/20260427061005.901854-1-aneesh.kumar@xxxxxxxxxx
* Switch VFIO/iommufd to use struct file *kvm_file instead of relying on
kvm->users_count references.
* Define TSM request scope values globally in iommufd.
* Rename the ioctl to IOMMU_VDEVICE_TSM_REQ.
* Address other review feedback.

Changes from v2:
https://lore.kernel.org/all/20260309111704.2330479-1-aneesh.kumar@xxxxxxxxxx
* Bump the series revision to v4 to keep it in sync with the dependent CCA DA
patchsets. There was no v3 posting.
* Drop [PATCH v2 1/3] iommufd/viommu: Allow associating a KVM VM fd with a
vIOMMU
* Add two new patches to associate a struct kvm * with iommufd objects:
iommufd/device: Associate a kvm pointer to iommufd_device
iommufd/viommu: Associate a kvm pointer to iommufd_viommu
* Address review feedback

Changes from v1:
https://lore.kernel.org/all/20250728135216.48084-8-aneesh.kumar@xxxxxxxxxx
* Rebase onto the latest kernel
* Address review feedback
* Drop the TSM map ioctl; the KVM prefault patch will be used instead to
ensure that private memory is preallocated

Cc: Jason Gunthorpe <jgg@xxxxxxxx>
Cc: Alexey Kardashevskiy <aik@xxxxxxx>
Cc: Bjorn Helgaas <helgaas@xxxxxxxxxx>
Cc: Joerg Roedel <joro@xxxxxxxxxx>
Cc: Jonathan Cameron <jic23@xxxxxxxxxx>
Cc: Kevin Tian <kevin.tian@xxxxxxxxx>
Cc: Nicolin Chen <nicolinc@xxxxxxxxxx>
Cc: Samuel Ortiz <sameo@xxxxxxxxxxxx>
Cc: Steven Price <steven.price@xxxxxxx>
Cc: Suzuki K Poulose <Suzuki.Poulose@xxxxxxx>
Cc: Will Deacon <will@xxxxxxxxxx>
Cc: Xu Yilun <yilun.xu@xxxxxxxxxxxxxxx>
Cc: Shameer Kolothum <shameerali.kolothum.thodi@xxxxxxxxxx>
Cc: Paolo Bonzini <pbonzini@xxxxxxxxxx>

Aneesh Kumar K.V (Arm) (9):
vfio: cache KVM VM file references instead of raw struct kvm pointers
vfio: cdev: Reject duplicate bind before updating KVM file
iommu: Add a helper to validate a vIOMMU parent
iommu: Add a helper to query vIOMMU hardware parameters
coco: tsm: Expose active-user lifetime references
iommufd: Add vIOMMU provider support
iommufd: Add the vdevice TSM request ioctl
PCI/TSM: Remove the legacy guest request interface
PCI/TSM: Add reference-counted contexts for vdevice providers

Nicolin Chen (1):
iommufd/viommu: Keep a reference to the KVM file

Shameer Kolothum (1):
iommufd/device: Associate KVM file pointer with iommufd_device

Documentation/ABI/testing/sysfs-bus-pci | 29 ++-
drivers/iommu/iommu.c | 22 ++
drivers/iommu/iommufd/Makefile | 5 +-
drivers/iommu/iommufd/device.c | 7 +-
drivers/iommu/iommufd/iommufd_private.h | 32 +++
drivers/iommu/iommufd/main.c | 3 +
drivers/iommu/iommufd/selftest.c | 2 +-
drivers/iommu/iommufd/tsm.c | 98 ++++++++
drivers/iommu/iommufd/viommu.c | 36 ++-
drivers/iommu/iommufd/viommu_provider.c | 160 ++++++++++++
drivers/pci/tsm/core.c | 312 ++++++++++--------------
drivers/s390/crypto/vfio_ap_ops.c | 5 +-
drivers/vfio/device_cdev.c | 14 +-
drivers/vfio/group.c | 14 +-
drivers/vfio/iommufd.c | 3 +-
drivers/vfio/pci/vfio_pci_zdev.c | 7 +-
drivers/vfio/vfio.h | 16 +-
drivers/vfio/vfio_main.c | 81 +++---
drivers/virt/coco/tsm-core.c | 55 ++++-
include/linux/iommu.h | 15 ++
include/linux/iommufd.h | 42 +++-
include/linux/kvm_host.h | 3 +
include/linux/pci-tsm.h | 140 ++++-------
include/linux/tsm.h | 38 +++
include/linux/vfio.h | 17 +-
include/uapi/linux/iommufd.h | 73 ++++++
samples/devsec/link_tsm.c | 146 -----------
tools/testing/devsec/devsec.sh | 27 +-
virt/kvm/kvm_main.c | 2 +
29 files changed, 866 insertions(+), 538 deletions(-)
create mode 100644 drivers/iommu/iommufd/tsm.c
create mode 100644 drivers/iommu/iommufd/viommu_provider.c

--
2.43.0