iommu: assert directly that a confinement moves with its device
reassign was added at D4 to fix a regression and has been proven only indirectly since — three IOMMU+USB cases going green. That covered the visible symptom (a driver's DMA rings unbound) and neither of the latent ones: the confinement still naming the giver, so the giver's death would tear down a domain a live driver was using, and the receiver's death would leave one behind. Those are now asserted. confinementOwner exposes the record's owner so the suite can see it. The sequence is the delegation in miniature: unconfined, confine as this task, reassign to another, confirm the new holder owns it and the old one does not, then kill the new holder and confirm the domain goes with it. Two attempts at this test could not have failed. The first found no PCI function to confine — pciAddressOf needs a pci_device entry and this case runs no pci-bus — so every assertion skipped silently while the case stayed green. It now synthesizes a function the way pci-bus does, a 4 KiB config window inside the bridge's ECAM, and asserts that precondition explicitly so a skip is a failure. Verified to discriminate: making reassign a no-op flips three assertions, including the domain surviving its holder's death. Suite 118/118.
This commit is contained in:
@@ -51,10 +51,13 @@ that cannot safely run in user space.**
|
||||
| D8 | **`maximum_children_per_parent` deleted** — the authorisation it stood in for exists | **blocked on D6**, and now ordered after D9 |
|
||||
| D9 | The device table becomes dynamic; **`maximum_devices` deleted**; per-holder quota declared | **done** — one of the two invented numbers is gone |
|
||||
|
||||
**Run 2 resumes at D0.** D1, D2, D4, D5 (`pci-bus` only) and D9 landed; `maximum_devices`
|
||||
no longer exists and the suite is 118/118. Questions 6 and 7 dissolved, so the order is
|
||||
now **D0 → D5 → D6 → D8**, which deletes `maximum_children_per_parent`. Only D7 is still
|
||||
blocked, on question 8, and it is needed for neither ceiling. D10 is optional.
|
||||
**Run 2 stops, blocked.** Landed: D0, D1, D2, D4, D9, and D5 for three of five
|
||||
claimants (`usb-xhci-bus`, `pci-bus`, `virtio-gpu`). `maximum_devices` no longer exists,
|
||||
delegation is atomic with the spawn, and the suite is 118/118.
|
||||
|
||||
Blocked: **D6 and D8 on question 9** (`ps2-bus` needs two devices and ignores its
|
||||
assignment; discovery needs a node nobody assigns), and **D7 on question 8**. So
|
||||
`maximum_children_per_parent` — the second invented number — is one answer away.
|
||||
|
||||
Ordering is load-bearing. D1–D2 built and proved the mechanism with nothing depending on
|
||||
it. D4–D5 move each claimant across one at a time, so the suite stays green throughout
|
||||
|
||||
Reference in New Issue
Block a user