>-----Original Message-----
>From: Jason Gunthorpe <j...@nvidia.com>
>Subject: Re: [PATCH v3 00/19] Add a host IOMMU device abstraction to
>check with vIOMMU
>
>On Mon, May 06, 2024 at 02:30:47AM +0000, Duan, Zhenzhong wrote:
>
>> I'm not clear how useful multiple iommufd instances support are.
>> One possible benefit is for security? It may bring a slightly fine-grained
>> isolation in kernel.
>
>No. I don't think there is any usecase, it is only harmful.

OK, so we need to limit QEMU to only one iommufd instance.

In cdev series, we support mix of legacy and iommufd backend and multiple 
iommufd backend instances for flexibility.
We need to make a choice to have this limitation only for nesting series or 
globally(including cdev).
May I ask what harmfulness we may have?

Thanks
Zhenzhong

Reply via email to