pub struct IommufdCtx { /* private fields */ }Expand description
An open iommufd file descriptor (/dev/iommu).
Wraps the fd and provides safe methods for the iommufd ioctls needed to allocate an IOAS and map/unmap host memory into it.
Implementations§
Source§impl IommufdCtx
impl IommufdCtx
Sourcepub fn ioas_alloc(&self) -> Result<u32>
pub fn ioas_alloc(&self) -> Result<u32>
Allocate a new IO Address Space (IOAS).
Returns the kernel-assigned IOAS object ID.
Sourcepub unsafe fn ioas_map(
&self,
ioas_id: u32,
iova: u64,
user_va: u64,
length: u64,
writable: bool,
) -> Result<()>
pub unsafe fn ioas_map( &self, ioas_id: u32, iova: u64, user_va: u64, length: u64, writable: bool, ) -> Result<()>
Map a user VA range into an IOAS at a fixed IOVA.
ioas_id is the IOAS to map into. iova is the fixed IO virtual
address. user_va is the host virtual address of the backing memory.
length is the size in bytes (must be page-aligned).
§Safety
user_va must point to valid, backed memory for length bytes.
The memory must remain mapped for the lifetime of this IOAS mapping.
Sourcepub fn ioas_map_file(
&self,
ioas_id: u32,
iova: u64,
fd: RawFd,
start: u64,
length: u64,
writable: bool,
) -> Result<()>
pub fn ioas_map_file( &self, ioas_id: u32, iova: u64, fd: RawFd, start: u64, length: u64, writable: bool, ) -> Result<()>
Map a file/memfd range into an IOAS at a fixed IOVA via
IOMMU_IOAS_MAP_FILE.
Unlike Self::ioas_map, the kernel pins the backing folios directly
from fd, so no host VA is required. start is the byte offset within
the file; like Self::ioas_map, both start and length must be
page-aligned. Requires a kernel with IOMMU_IOAS_MAP_FILE (Linux
6.13+).
Sourcepub fn ioas_unmap(&self, ioas_id: u32, iova: u64, length: u64) -> Result<u64>
pub fn ioas_unmap(&self, ioas_id: u32, iova: u64, length: u64) -> Result<u64>
Unmap an IOVA range from an IOAS.
Returns the number of bytes actually unmapped.
Sourcepub fn hwpt_alloc(
&self,
flags: u32,
dev_id: u32,
pt_id: u32,
data_type: u32,
data: Option<&IommuHwptArmSmmuv3>,
) -> Result<u32>
pub fn hwpt_alloc( &self, flags: u32, dev_id: u32, pt_id: u32, data_type: u32, data: Option<&IommuHwptArmSmmuv3>, ) -> Result<u32>
Allocate a hardware page table (HWPT).
For a nesting parent (S2): set flags = IOMMU_HWPT_ALLOC_NEST_PARENT,
pt_id = IOAS ID, data_type = IOMMU_HWPT_DATA_NONE.
For a nested child (S1): set flags = 0, pt_id = parent HWPT ID
or vIOMMU ID, data_type = IOMMU_HWPT_DATA_ARM_SMMUV3, and pass the
STE data via data.
Returns the kernel-assigned HWPT object ID.
Sourcepub fn get_hw_info(
&self,
dev_id: u32,
out_info: &mut IommuHwInfoArmSmmuv3,
) -> Result<(u32, u64)>
pub fn get_hw_info( &self, dev_id: u32, out_info: &mut IommuHwInfoArmSmmuv3, ) -> Result<(u32, u64)>
Query hardware information for a device’s IOMMU.
Returns (out_data_type, out_capabilities). The type-specific data is
written into out_info.
Sourcepub fn hwpt_invalidate(
&self,
hwpt_id: u32,
data_type: u32,
entries: &[[u64; 2]],
) -> Result<u32, HwptInvalidateError>
pub fn hwpt_invalidate( &self, hwpt_id: u32, data_type: u32, entries: &[[u64; 2]], ) -> Result<u32, HwptInvalidateError>
Invalidate IOMMU caches via a nested HWPT or vIOMMU.
hwpt_id is a nested HWPT ID or vIOMMU ID. Each entry in entries is a
raw 128-bit invalidation command as a [qw0, qw1] quadword pair; the
kernel parses the opcode and operands per data_type.
On full success returns the number of entries handled (always
entries.len()). On failure returns a HwptInvalidateError carrying
the kernel’s in/out entry_num — the count of leading entries it
reports as handled before the failure — so the caller can locate the
offending entry. The kernel writes entry_num back even on error.
Caveat: entry_num is only meaningful when the kernel reached its
per-entry processing loop. For an early failure (notably -ENOMEM
allocating the kernel-side scratch array) the field is left at the
input count, so HwptInvalidateError::handled can equal
entries.len() despite nothing being handled. Callers must treat
handled >= entries.len() on the error path as “position unknown”.
Sourcepub fn viommu_alloc(
&self,
viommu_type: u32,
dev_id: u32,
hwpt_id: u32,
) -> Result<ViommuAlloc>
pub fn viommu_alloc( &self, viommu_type: u32, dev_id: u32, hwpt_id: u32, ) -> Result<ViommuAlloc>
Allocate a virtual IOMMU (vIOMMU).
viommu_type should be IOMMU_VIOMMU_TYPE_ARM_SMMUV3 for SMMUv3.
dev_id is a device bound to the physical IOMMU backing this vIOMMU.
hwpt_id is the nesting parent HWPT to associate with.
Returns ViommuAlloc::Incompatible when the nesting parent and device
belong to different physical SMMUs. For this wrapper all generic fields
are fixed to valid Arm SMMUv3 values and hwpt_id is supplied by
IommufdCtx::hwpt_alloc with IOMMU_HWPT_ALLOC_NEST_PARENT; after
those core checks, the Arm driver returns EINVAL only when the parent
domain’s SMMU differs from the device’s SMMU.
Sourcepub fn vdevice_alloc(
&self,
viommu_id: u32,
dev_id: u32,
virt_id: u64,
) -> Result<u32>
pub fn vdevice_alloc( &self, viommu_id: u32, dev_id: u32, virt_id: u64, ) -> Result<u32>
Allocate a virtual device (vDevice) on a vIOMMU.
virt_id is the virtual stream ID (e.g., guest BDF for SMMUv3).
Returns the kernel-assigned vDevice object ID.
Sourcepub fn veventq_alloc(
&self,
viommu_id: u32,
veventq_type: u32,
depth: u32,
) -> Result<(u32, File)>
pub fn veventq_alloc( &self, viommu_id: u32, veventq_type: u32, depth: u32, ) -> Result<(u32, File)>
Allocate a virtual event queue (vEVENTQ) on a vIOMMU.
veventq_type should be IOMMU_VEVENTQ_TYPE_ARM_SMMUV3 for SMMUv3.
depth is the maximum number of events in the queue.
Returns (veventq_id, veventq_fd). The fd is an eventfd-style file
descriptor that can be polled for fault events.