Right now, when a transport uses a shared bounce region for virtqueue memory, that region is global: multiple devices share one region at the same time. That causes two concrete problems. First, all of those devices contend over a single small region, so one busy device can starve the others. Second, there is no clean way to isolate or tear down one device's emulation on its own, because its state is tangled up in memory that everyone else is also using.
I want to fix both by giving each device its own dedicated shared memory region. Once a device owns its region, its emulation can live in a separate host process and be implemented independently of every other device, and there is no shared region left for devices to fight over, so the cross-device starvation goes away. A useful side effect is confinement: since the driver only ever places addresses inside that one region, the device can only touch the memory the driver put there.
I prpopse a new feature bit, VIRTIO_F_DMB, that adds a Device Memory Buffer: one device-owned shared memory region per device that holds that device's virtqueues (the Descriptor, Driver and Device Areas) along with the buffers the descriptors reference. When it is negotiated, every address the driver writes into a virtqueue is an offset into that region rather than a physical or bus address, so by construction the device never dereferences anything outside it. The device bounds-checks every offset and sets DEVICE_NEEDS_RESET if one is out of range. It reuses the existing Shared Memory Regions facility, refines VIRTIO_F_ACCESS_PLATFORM, and is only ever negotiated together with VIRTIO_F_ACCESS_PLATFORM.
Full draft and discussion on the list: https://lore.kernel.org/virtio-comment/20260702040006.65669-1-graf@amazon.com/T/#u
Right now, when a transport uses a shared bounce region for virtqueue memory, that region is global: multiple devices share one region at the same time. That causes two concrete problems. First, all of those devices contend over a single small region, so one busy device can starve the others. Second, there is no clean way to isolate or tear down one device's emulation on its own, because its state is tangled up in memory that everyone else is also using.
I want to fix both by giving each device its own dedicated shared memory region. Once a device owns its region, its emulation can live in a separate host process and be implemented independently of every other device, and there is no shared region left for devices to fight over, so the cross-device starvation goes away. A useful side effect is confinement: since the driver only ever places addresses inside that one region, the device can only touch the memory the driver put there.
I prpopse a new feature bit, VIRTIO_F_DMB, that adds a Device Memory Buffer: one device-owned shared memory region per device that holds that device's virtqueues (the Descriptor, Driver and Device Areas) along with the buffers the descriptors reference. When it is negotiated, every address the driver writes into a virtqueue is an offset into that region rather than a physical or bus address, so by construction the device never dereferences anything outside it. The device bounds-checks every offset and sets DEVICE_NEEDS_RESET if one is out of range. It reuses the existing Shared Memory Regions facility, refines VIRTIO_F_ACCESS_PLATFORM, and is only ever negotiated together with VIRTIO_F_ACCESS_PLATFORM.
Full draft and discussion on the list: https://lore.kernel.org/virtio-comment/20260702040006.65669-1-graf@amazon.com/T/#u