| From 607432b2618b61df81134be0ef2562b8300c1216 Mon Sep 17 00:00:00 2001 |
| From: Kevin Tian <kevin.tian@intel.com> |
| Date: Wed, 5 Aug 2026 07:43:00 +0800 |
| Subject: iommu/vt-d: Force requesting ACS when tboot is enabled |
| |
| From: Kevin Tian <kevin.tian@intel.com> |
| |
| commit 607432b2618b61df81134be0ef2562b8300c1216 upstream. |
| |
| Currently the conditions of requesting ACS in detect_intel_iommu() |
| don't include tboot, leading to a possible misconfiguration with ACS |
| disabled (e.g. due to user opts) while iommu is later forced on by |
| tboot_force_iommu(). |
| |
| Fix it by checking tboot in detect_intel_iommu(). |
| |
| Fixes: 5d990b627537 ("PCI: add pci_request_acs") |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Kevin Tian <kevin.tian@intel.com> |
| Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com> |
| Signed-off-by: Joerg Roedel <joerg.roedel@amd.com> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/iommu/intel/dmar.c | 15 +++++++++++++-- |
| drivers/iommu/intel/iommu.c | 2 +- |
| drivers/iommu/intel/iommu.h | 2 ++ |
| 3 files changed, 16 insertions(+), 3 deletions(-) |
| |
| --- a/drivers/iommu/intel/dmar.c |
| +++ b/drivers/iommu/intel/dmar.c |
| @@ -914,6 +914,18 @@ dmar_validate_one_drhd(struct acpi_dmar_ |
| return 0; |
| } |
| |
| +static bool dmar_required(void) |
| +{ |
| + /* tboot supersedes any user/platform opt */ |
| + if (!intel_iommu_tboot_noforce && tboot_enabled()) |
| + return true; |
| + |
| + if (!no_iommu && (!dmar_disabled || dmar_platform_optin())) |
| + return true; |
| + |
| + return false; |
| +} |
| + |
| void __init detect_intel_iommu(void) |
| { |
| int ret; |
| @@ -927,8 +939,7 @@ void __init detect_intel_iommu(void) |
| if (!ret) |
| ret = dmar_walk_dmar_table((struct acpi_table_dmar *)dmar_tbl, |
| &validate_drhd_cb); |
| - if (!ret && !no_iommu && !iommu_detected && |
| - (!dmar_disabled || dmar_platform_optin())) { |
| + if (!ret && !iommu_detected && dmar_required()) { |
| iommu_detected = 1; |
| /* Make sure ACS will be enabled */ |
| pci_request_acs(); |
| --- a/drivers/iommu/intel/iommu.c |
| +++ b/drivers/iommu/intel/iommu.c |
| @@ -139,7 +139,7 @@ static int rwbf_quirk; |
| * (used when kernel is launched w/ TXT) |
| */ |
| static int force_on = 0; |
| -static int intel_iommu_tboot_noforce; |
| +int intel_iommu_tboot_noforce; |
| static int no_platform_optin; |
| |
| #define ROOT_ENTRY_NR (VTD_PAGE_SIZE/sizeof(struct root_entry)) |
| --- a/drivers/iommu/intel/iommu.h |
| +++ b/drivers/iommu/intel/iommu.h |
| @@ -910,6 +910,7 @@ static inline bool ecmd_has_pmu_essentia |
| |
| extern int dmar_disabled; |
| extern int intel_iommu_enabled; |
| +extern int intel_iommu_tboot_noforce; |
| #else |
| static inline int iommu_calculate_agaw(struct intel_iommu *iommu) |
| { |
| @@ -922,6 +923,7 @@ static inline int iommu_calculate_max_sa |
| #define dmar_disabled (1) |
| #define intel_iommu_enabled (0) |
| #define intel_iommu_sm (0) |
| +#define intel_iommu_tboot_noforce (0) |
| #endif |
| |
| static inline const char *decode_prq_descriptor(char *str, size_t size, |