From: Nicolin Chen <nicolinc@nvidia.com>
To: <will@kernel.org>, <robin.murphy@arm.com>, <jgg@nvidia.com>
Cc: <joro@8bytes.org>, <praan@google.com>, <kevin.tian@intel.com>,
<smostafa@google.com>, <linux-arm-kernel@lists.infradead.org>,
<iommu@lists.linux.dev>, <linux-kernel@vger.kernel.org>,
<jamien@nvidia.com>, <kas@kernel.org>
Subject: [PATCH v10 07/13] iommu/arm-smmu-v3-kexec: Add a CD table parse helper
Date: Sun, 30 Aug 2026 16:18:08 -0700 [thread overview]
Message-ID: <ade622c5c82913442d090aec251b5662b021b129.1788130528.git.nicolinc@nvidia.com> (raw)
In-Reply-To: <cover.1788130528.git.nicolinc@nvidia.com>
An S1 STE points to a CD table that both of the kexec flavors decode: the
kdump adoption scans the CD table to reserve all the in-use ASIDs, and the
live-update restoration claims the CD table via the KHO restore API.
Add another read-only helper to the arm-smmu-v3-kexec.c:
- arm_smmu_kexec_check_ste_cdtab()
It validates the CD table geometry in an S1 STE against this kernel's own
ssid_bits and the 2-level HW capability. And it accepts a linear CD table
on the 2-level capable HW too, since a previous kernel might have used one,
like the linear stream table.
The CD table base gets validated against the table size as well, since the
spec aligns a CD table to its own size, where an unaligned base would be a
CONSTRAINED UNPREDICTABLE case: HW may zero its low bits or may fetch any
CD in the table, so a scan reading such a base could miss the CDs in use.
Reviewed-by: Jason Gunthorpe <jgg@nvidia.com>
Assisted-by: Claude:claude-fable-5
Signed-off-by: Nicolin Chen <nicolinc@nvidia.com>
---
drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h | 3 +
.../iommu/arm/arm-smmu-v3/arm-smmu-v3-kexec.c | 57 +++++++++++++++++++
2 files changed, 60 insertions(+)
diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h
index 41d7a907b9ba2..1bcf6cb2ebb3c 100644
--- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h
+++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.h
@@ -1261,6 +1261,9 @@ int arm_smmu_kexec_parse_strtab_linear(struct arm_smmu_device *smmu,
int arm_smmu_kexec_check_strtab_l1_desc(struct arm_smmu_device *smmu,
u64 l1_desc, u32 idx,
phys_addr_t *l2_base);
+int arm_smmu_kexec_check_ste_cdtab(struct arm_smmu_device *smmu, u64 ste0,
+ phys_addr_t *cdtab, u32 *s1fmt,
+ u32 *max_contexts);
#endif /* CONFIG_ARM_SMMU_V3_KEXEC */
#ifdef CONFIG_CRASH_DUMP
diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-kexec.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-kexec.c
index b15e23df11b6d..700f63c7972e9 100644
--- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-kexec.c
+++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3-kexec.c
@@ -164,3 +164,60 @@ int arm_smmu_kexec_check_strtab_l1_desc(struct arm_smmu_device *smmu,
*l2_base = base;
return 0;
}
+
+/**
+ * arm_smmu_kexec_check_ste_cdtab() - Decode the CD table geometry of an STE
+ * @smmu: SMMU device of this kernel
+ * @ste0: first 64 bits of the previous kernel's S1 STE
+ * @cdtab: pointer to return the CD table's physical address
+ * @s1fmt: pointer to return the CD table format
+ * @max_contexts: pointer to return the number of CDs
+ *
+ * Note that a linear CD table on the 2-level capable hardware is accepted, as a
+ * previous kernel might have used one, like the linear stream table.
+ *
+ * Note that the spec requires a CD table to be aligned to its own size, so an
+ * unaligned @cdtab gets rejected here: HW may then zero the low bits or fetch
+ * any CD in the table, leaving the live ASIDs unknowable to this scan.
+ *
+ * Return: 0 on success with the three outputs set, or -EINVAL on a bad geometry
+ */
+int arm_smmu_kexec_check_ste_cdtab(struct arm_smmu_device *smmu, u64 ste0,
+ phys_addr_t *cdtab, u32 *s1fmt,
+ u32 *max_contexts)
+{
+ phys_addr_t base = ste0 & STRTAB_STE_0_S1CTXPTR_MASK;
+ u32 s1cdmax = FIELD_GET(STRTAB_STE_0_S1CDMAX, ste0);
+ u32 fmt = FIELD_GET(STRTAB_STE_0_S1FMT, ste0);
+ size_t size;
+
+ if (!base || s1cdmax > smmu->ssid_bits)
+ return -EINVAL;
+
+ if (fmt != STRTAB_STE_0_S1FMT_LINEAR &&
+ fmt != STRTAB_STE_0_S1FMT_64K_L2)
+ return -EINVAL;
+
+ /* Both kernels run on the same HW, so a genuine STE never has this */
+ if (fmt == STRTAB_STE_0_S1FMT_64K_L2 &&
+ !(smmu->features & ARM_SMMU_FEAT_2_LVL_CDTAB))
+ return -EINVAL;
+
+ if (fmt == STRTAB_STE_0_S1FMT_LINEAR)
+ size = (1UL << s1cdmax) * sizeof(struct arm_smmu_cd);
+ else
+ size = DIV_ROUND_UP(1UL << s1cdmax, CTXDESC_L2_ENTRIES) *
+ sizeof(struct arm_smmu_cdtab_l1);
+
+ /*
+ * An unaligned base is CONSTRAINED UNPREDICTABLE: HW may zero the low
+ * bits or fetch any CD in the table, so live ASIDs become unknowable.
+ */
+ if (!IS_ALIGNED(base, size))
+ return -EINVAL;
+
+ *cdtab = base;
+ *s1fmt = fmt;
+ *max_contexts = 1U << s1cdmax;
+ return 0;
+}
--
2.43.0
next prev parent reply other threads:[~2026-08-30 23:18 UTC|newest]
Thread overview: 36+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-30 23:18 [PATCH v10 00/13] iommu/arm-smmu-v3: Adopt the crashed kernel's stream table for kdump Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 01/13] iommu/arm-smmu-v3: Init the vmid_map ida before the stream table setup Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 02/13] iommu/arm-smmu-v3: Make the ASID space per SMMU instance Nicolin Chen
2026-09-23 16:39 ` Jason Gunthorpe
2026-10-04 13:23 ` Will Deacon
2026-10-04 16:22 ` Jason Gunthorpe
2026-08-30 23:18 ` [PATCH v10 03/13] iommu/arm-smmu-v3: Add ARM_SMMU_FEAT_EVTQ for the event queue Nicolin Chen
2026-09-02 11:21 ` Kiryl Shutsemau
2026-09-23 16:39 ` Jason Gunthorpe
2026-10-04 13:24 ` Will Deacon
2026-10-04 20:20 ` Nicolin Chen
2026-10-05 4:37 ` Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 04/13] iommu/arm-smmu-v3: Disable the EVTQ and the PRIQ in a kdump kernel Nicolin Chen
2026-09-02 11:22 ` Kiryl Shutsemau
2026-09-23 16:39 ` Jason Gunthorpe
2026-08-30 23:18 ` [PATCH v10 05/13] iommu/arm-smmu-v3: Add strtab parse helpers to a new arm-smmu-v3-kexec.c Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 06/13] iommu/arm-smmu-v3: Add ARM_SMMU_OPT_KDUMP_ADOPT for kdump kernel Nicolin Chen
2026-10-04 13:25 ` Will Deacon
2026-10-04 16:35 ` Jason Gunthorpe
2026-10-04 20:59 ` Nicolin Chen
2026-10-05 6:34 ` Will Deacon
2026-10-05 8:04 ` Nicolin Chen
2026-10-04 20:47 ` Nicolin Chen
2026-10-05 6:32 ` Will Deacon
2026-10-05 7:56 ` Nicolin Chen
2026-10-05 8:10 ` Will Deacon
2026-08-30 23:18 ` Nicolin Chen [this message]
2026-08-30 23:18 ` [PATCH v10 08/13] iommu/arm-smmu-v3-kexec: Add ASID/VMID reservation helpers Nicolin Chen
2026-09-23 16:39 ` Jason Gunthorpe
2026-08-30 23:18 ` [PATCH v10 09/13] iommu/arm-smmu-v3-kdump: Reserve crashed kernel's ASIDs and VMIDs Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 10/13] iommu/arm-smmu-v3-kdump: Implement is_attach_deferred() Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 11/13] iommu/arm-smmu-v3: Retain CR0_SMMUEN during kdump device reset Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 12/13] iommu/arm-smmu-v3: Skip RMR bypass for kdump adoption Nicolin Chen
2026-08-30 23:18 ` [PATCH v10 13/13] iommu/arm-smmu-v3: Detect ARM_SMMU_OPT_KDUMP_ADOPT in probe() Nicolin Chen
2026-09-14 10:41 ` [PATCH v10 00/13] iommu/arm-smmu-v3: Adopt the crashed kernel's stream table for kdump Breno Leitao
2026-09-28 15:23 ` Cristian Prundeanu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ade622c5c82913442d090aec251b5662b021b129.1788130528.git.nicolinc@nvidia.com \
--to=nicolinc@nvidia.com \
--cc=iommu@lists.linux.dev \
--cc=jamien@nvidia.com \
--cc=jgg@nvidia.com \
--cc=joro@8bytes.org \
--cc=kas@kernel.org \
--cc=kevin.tian@intel.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=praan@google.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®