# Commit 92b8bc03bd4b582cb524db51494d0dba7607e7ac # Date 2013-03-25 16:55:22 +0100 # Author Jan Beulich # Committer Jan Beulich AMD IOMMU: allow disabling only interrupt remapping when certain IVRS consistency checks fail After some more thought on the XSA-36 and specifically the comments we got regarding disabling the IOMMU in this situation altogether making things worse instead of better, I came to the conclusion that we can actually restrict the action in affected cases to just disabling interrupt remapping. That doesn't make the situation worse than prior to the XSA-36 fixes (where interrupt remapping didn't really protect domains from one another), but allows at least DMA isolation to still be utilized. To do so, disabling of interrupt remapping must be explicitly requested on the command line - respective checks will then be skipped. Signed-off-by: Jan Beulich Acked-by: Suravee Suthikulanit --- a/xen/drivers/passthrough/amd/iommu_acpi.c +++ b/xen/drivers/passthrough/amd/iommu_acpi.c @@ -664,6 +664,9 @@ static u16 __init parse_ivhd_device_spec return dev_length; } + if ( !iommu_intremap ) + return dev_length; + /* * Some BIOSes have IOAPIC broken entries so we check for IVRS * consistency here --- whether entry's IOAPIC ID is valid and @@ -902,7 +905,7 @@ static int __init parse_ivrs_table(struc } /* Each IO-APIC must have been mentioned in the table. */ - for ( apic = 0; !error && apic < nr_ioapics; ++apic ) + for ( apic = 0; !error && iommu_intremap && apic < nr_ioapics; ++apic ) { if ( !nr_ioapic_entries[apic] || ioapic_sbdf[IO_APIC_ID(apic)].pin_setup ) --- a/xen/drivers/passthrough/amd/iommu_init.c +++ b/xen/drivers/passthrough/amd/iommu_init.c @@ -1192,7 +1192,8 @@ int __init amd_iommu_init(void) BUG_ON( !iommu_found() ); - if ( amd_iommu_perdev_intremap && amd_sp5100_erratum28() ) + if ( iommu_intremap && amd_iommu_perdev_intremap && + amd_sp5100_erratum28() ) goto error_out; ivrs_bdf_entries = amd_iommu_get_ivrs_dev_entries(); @@ -1209,7 +1210,7 @@ int __init amd_iommu_init(void) goto error_out; /* initialize io-apic interrupt remapping entries */ - if ( amd_iommu_setup_ioapic_remapping() != 0 ) + if ( iommu_intremap && amd_iommu_setup_ioapic_remapping() != 0 ) goto error_out; /* allocate and initialize a global device table shared by all iommus */