1 # SPDX-License-Identifier: GPL-2.0-only
3 tristate "VFIO Non-Privileged userspace driver framework"
5 depends on IOMMUFD || !IOMMUFD
7 select VFIO_CONTAINER if IOMMUFD=n
9 VFIO provides a framework for secure userspace device drivers.
10 See Documentation/driver-api/vfio.rst for more details.
12 If you don't know what to do here, say N.
16 bool "Support for the VFIO container /dev/vfio/vfio"
17 select VFIO_IOMMU_TYPE1 if MMU && (X86 || S390 || ARM || ARM64)
20 The VFIO container is the classic interface to VFIO for establishing
21 IOMMU mappings. If N is selected here then IOMMUFD must be used to
24 Unless testing IOMMUFD say Y here.
27 config VFIO_IOMMU_TYPE1
31 config VFIO_IOMMU_SPAPR_TCE
33 depends on SPAPR_TCE_IOMMU
38 bool "VFIO No-IOMMU support"
40 VFIO is built on the ability to isolate devices using the IOMMU.
41 Only with an IOMMU can userspace access to DMA capable devices be
42 considered secure. VFIO No-IOMMU mode enables IOMMU groups for
43 devices without IOMMU backing for the purpose of re-using the VFIO
44 infrastructure in a non-secure mode. Use of this mode will result
45 in an unsupportable kernel and will therefore taint the kernel.
46 Device assignment to virtual machines is also not possible with
47 this mode since there is no IOMMU to provide DMA translation.
49 If you don't know what to do here, say N.
56 source "drivers/vfio/pci/Kconfig"
57 source "drivers/vfio/platform/Kconfig"
58 source "drivers/vfio/mdev/Kconfig"
59 source "drivers/vfio/fsl-mc/Kconfig"
62 source "virt/lib/Kconfig"