[vfio-users] Is there any risk when pcie brigde downstream devices are all passthrough into a single vm?

Acewind acewind at gmail.com
Sat Jul 27 09:26:31 UTC 2019


I install ubuntu 18.04 on Hewlett-Packard PC with i5-3470 CPU and
independent AMD graphics card. The indepent VGA is plugged into a
processor-base pcie root port:

00:01.0 PCI bridge [0604]: Intel Corporation Xeon E3-1200 v2/3rd Gen Core
processor PCI Express Root Port [8086:0151] (rev 09)
    Kernel driver in use: pcieport
    Kernel modules: shpchp
01:00.0 VGA compatible controller [0300]: Advanced Micro Devices, Inc.
[AMD/ATI]
Caicos XT [Radeon HD 7470/8470 / R5 235/310 OEM] [1002:6778]
    Subsystem: Micro-Star International Co., Ltd. [MSI] Caicos XT [Radeon
HD 7470/8470 / R5 235/310 OEM] [1462:212a]
    Kernel driver in use: vfio-pci
    Kernel modules: radeon
01:00.1 Audio device [0403]: Advanced Micro Devices, Inc. [AMD/ATI] Caicos
HDMI Audio [Radeon HD 6450 / 7450/8450/8490 OEM / R5 230/235/235X OEM]
[1002:a...
    Subsystem: Micro-Star International Co., Ltd. [MSI] Caicos HDMI Audio
[Radeon HD 6450 / 7450/8450/8490 OEM / R5 230/235/235X OEM] [1462:aa98]
    Kernel driver in use: vfio-pci
    Kernel modules: snd_hda_intel

According to knowledges about iommu passthrough with OVMF, an acs override
patch option downstream is enabled on kernel command line, then the PCI
bridge is splitted out of the iommu group, only vga and audio device left.
Then I passthrough both of them into a vm. My question is about the risk of
this case. Two devices under the PCI bridge are all used by a single vm,
May I confirm there's not any risk?
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://listman.redhat.com/archives/vfio-users/attachments/20190727/63f56b01/attachment.htm>


More information about the vfio-users mailing list