Re: [PATCH 6.18 0019/1611] iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19

Usama Arif <[email protected]>
Newsgroups dev.linux.lists.patches,org.kernel.vger.stable
Message-ID <[email protected]>
On Tue, 21 Jul 2026 17:02:15 +0200 Greg Kroah-Hartman <[email protected]> wrote:

> 6.18-stable review patch.  If anyone has any objections, please let me know.
> 
> ------------------
> 
> From: Vasant Hegde <[email protected]>
> 
> [ Upstream commit 1f44aab79bac31f459422dfb213e907bb386509c ]
> 
> Due to CVE-2023-20585, the PPR log buffer must use the maximum supported
> size (512K) on Genoa (Family 0x19, model >= 0x10) systems when SNP is
> enabled, to mitigate a potential security vulnerability. Note that Family
> 0x19 models below 0x10 (Milan) do not support PPR when SNP is enabled.
> Hence the PPR log size increase is only applied for model >= 0x10.
> All other systems continue to use the default PPR log buffer size (8K).
> 
> Apply the errata fix by making the following changes:
> 
> - Introduce global new variable (amd_iommu_pprlog_size) to have PPR log buffer
>   size. Adjust variable size for Genoa family.
> 
> - Extend 'amd_iommu_apply_erratum_snp()' to also set the PPR log buffer
>   size to maximum for Family 0x19 model >= 0x10 when SNP is enabled.
> 
> - Rename PPR_* macros to make it more readable.
> 
> Link: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3016.html
> Cc: Borislav Petkov <[email protected]>
> Cc: Suravee Suthikulpanit <[email protected]>
> Cc: Joerg Roedel <[email protected]>
> Signed-off-by: Vasant Hegde <[email protected]>
> Tested-by: Dheeraj Kumar Srivastava <[email protected]>
> Signed-off-by: Joerg Roedel <[email protected]>
> Signed-off-by: Sasha Levin <[email protected]>
> ---
>  drivers/iommu/amd/amd_iommu.h       |  1 +
>  drivers/iommu/amd/amd_iommu_types.h | 11 ++++++-----
>  drivers/iommu/amd/init.c            | 13 ++++++++++++-
>  drivers/iommu/amd/ppr.c             |  8 +++++---
>  4 files changed, 24 insertions(+), 9 deletions(-)
> 

Hi,

I have raised this in [1] but also raising it here, this series seems to break
kexec on Milan hosts.

kexec starts working on SNP hosts once we do:
Revert "iommu/amd: Use maximum PPR log buffer size when SNP is enabled on Family 0x19"
Revert "iommu/amd: Use maximum Event log buffer size when SNP is enabled on Family 0x19"

on top 6.18.43 release.

[1] https://lore.kernel.org/all/[email protected]/


> diff --git a/drivers/iommu/amd/amd_iommu.h b/drivers/iommu/amd/amd_iommu.h
> index 57d7f3faa98c6e..ef397c5a2c4ab2 100644
> --- a/drivers/iommu/amd/amd_iommu.h
> +++ b/drivers/iommu/amd/amd_iommu.h
> @@ -12,6 +12,7 @@
>  #include "amd_iommu_types.h"
>  
>  extern int amd_iommu_evtlog_size;
> +extern int amd_iommu_pprlog_size;
>  
>  irqreturn_t amd_iommu_int_thread(int irq, void *data);
>  irqreturn_t amd_iommu_int_thread_evtlog(int irq, void *data);
> diff --git a/drivers/iommu/amd/amd_iommu_types.h b/drivers/iommu/amd/amd_iommu_types.h
> index bdd6c38ddfec9b..2494b1958117b2 100644
> --- a/drivers/iommu/amd/amd_iommu_types.h
> +++ b/drivers/iommu/amd/amd_iommu_types.h
> @@ -257,11 +257,12 @@
>  #define EVTLOG_LEN_MASK_MAX	(0xFULL << EVTLOG_SIZE_SHIFT)
>  
>  /* Constants for PPR Log handling */
> -#define PPR_LOG_ENTRIES		512
> -#define PPR_LOG_SIZE_SHIFT	56
> -#define PPR_LOG_SIZE_512	(0x9ULL << PPR_LOG_SIZE_SHIFT)
> -#define PPR_ENTRY_SIZE		16
> -#define PPR_LOG_SIZE		(PPR_ENTRY_SIZE * PPR_LOG_ENTRIES)
> +#define PPRLOG_ENTRY_SIZE	0x10
> +#define PPRLOG_SIZE_SHIFT	56
> +#define PPRLOG_SIZE_DEF		SZ_8K	/* 512 entries */
> +#define PPRLOG_LEN_MASK_DEF	(0x9ULL << PPRLOG_SIZE_SHIFT)
> +#define PPRLOG_SIZE_MAX		SZ_512K	/* 32K entries */
> +#define PPRLOG_LEN_MASK_MAX	(0xFULL << PPRLOG_SIZE_SHIFT)
>  
>  /* PAGE_SERVICE_REQUEST PPR Log Buffer Entry flags */
>  #define PPR_FLAG_EXEC		0x002	/* Execute permission requested */
> diff --git a/drivers/iommu/amd/init.c b/drivers/iommu/amd/init.c
> index 64964bb5ce0d36..6e5efc340c83e4 100644
> --- a/drivers/iommu/amd/init.c
> +++ b/drivers/iommu/amd/init.c
> @@ -133,6 +133,7 @@ struct ivhd_entry {
>  } __attribute__((packed));
>  
>  int amd_iommu_evtlog_size = EVTLOG_SIZE_DEF;
> +int amd_iommu_pprlog_size = PPRLOG_SIZE_DEF;
>  
>  /*
>   * An AMD IOMMU memory definition structure. It defines things like exclusion
> @@ -3411,6 +3412,16 @@ static void amd_iommu_apply_erratum_snp(void)
>  	amd_iommu_evtlog_size = EVTLOG_SIZE_MAX;
>  	pr_info("Applying erratum: Increase Event log size to 0x%x\n",
>  		amd_iommu_evtlog_size);
> +
> +	/*
> +	 * Set PPR log buffer size to max.
> +	 * (Family 0x19, model < 0x10 doesn't support PPR when SNP is enabled).
> +	 */
> +	if (boot_cpu_data.x86_model >= 0x10) {
> +		amd_iommu_pprlog_size = PPRLOG_SIZE_MAX;
> +		pr_info("Applying erratum: Increase PPR log size to 0x%x\n",
> +			amd_iommu_pprlog_size);
> +	}
>  #endif
>  }
>  
> @@ -4071,7 +4082,7 @@ int amd_iommu_snp_disable(void)
>  		if (ret)
>  			return ret;
>  
> -		ret = iommu_make_shared(iommu->ppr_log, PPR_LOG_SIZE);
> +		ret = iommu_make_shared(iommu->ppr_log, amd_iommu_pprlog_size);
>  		if (ret)
>  			return ret;
>  
> diff --git a/drivers/iommu/amd/ppr.c b/drivers/iommu/amd/ppr.c
> index e6767c057d01fa..1f8d2823bea42c 100644
> --- a/drivers/iommu/amd/ppr.c
> +++ b/drivers/iommu/amd/ppr.c
> @@ -20,7 +20,7 @@
>  int __init amd_iommu_alloc_ppr_log(struct amd_iommu *iommu)
>  {
>  	iommu->ppr_log = iommu_alloc_4k_pages(iommu, GFP_KERNEL | __GFP_ZERO,
> -					      PPR_LOG_SIZE);
> +					      amd_iommu_pprlog_size);
>  	return iommu->ppr_log ? 0 : -ENOMEM;
>  }
>  
> @@ -33,7 +33,9 @@ void amd_iommu_enable_ppr_log(struct amd_iommu *iommu)
>  
>  	iommu_feature_enable(iommu, CONTROL_PPR_EN);
>  
> -	entry = iommu_virt_to_phys(iommu->ppr_log) | PPR_LOG_SIZE_512;
> +	entry = iommu_virt_to_phys(iommu->ppr_log);
> +	entry |= (amd_iommu_pprlog_size == PPRLOG_SIZE_DEF) ?
> +			PPRLOG_LEN_MASK_DEF : PPRLOG_LEN_MASK_MAX;
>  
>  	memcpy_toio(iommu->mmio_base + MMIO_PPR_LOG_OFFSET,
>  		    &entry, sizeof(entry));
> @@ -201,7 +203,7 @@ void amd_iommu_poll_ppr_log(struct amd_iommu *iommu)
>  			raw[0] = raw[1] = 0UL;
>  
>  		/* Update head pointer of hardware ring-buffer */
> -		head = (head + PPR_ENTRY_SIZE) % PPR_LOG_SIZE;
> +		head = (head + PPRLOG_ENTRY_SIZE) % amd_iommu_pprlog_size;
>  		writel(head, iommu->mmio_base + MMIO_PPR_HEAD_OFFSET);
>  
>  		/* Handle PPR entry */
> -- 
> 2.53.0
> 
> 
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.