[PATCH v2] eal/linux: skip vfio for non-privileged container

Moses Young mosesyyoung at gmail.com
Sat May 17 09:55:28 CEST 2025


On 5/16/2025 9:30 PM, Burakov, Anatoly wrote:

> On 3/27/2025 8:57 AM, Yang Ming wrote:
>> DPDK detect vfio container according the existence of vfio
>> module. But for container with non-privileged mode, there is
>> possibility that no VFIO_DIR(/dev/vfio) mapping from host to
>> container when host have both Intel NIC and Mellanox NIC but
>> this conntainer only allocate VFs from Mellanox NIC.
>> In this case, vfio kernel module has already been loaded from
>> the host.
>> This scenario will cause the error log occurs in DPDK primary
>> process as below:
>> 'EAL:   cannot open VFIO container, error 2 (No such file or
>> directory)'
>> 'EAL: VFIO support could not be initialized'
>> Because `rte_vfio_enable()` call `rte_vfio_get_container_fd()`
>> to execute `vfio_container_fd = open(VFIO_CONTAINER_PATH,
>> O_RDWR);` but VFIO_CONTAINER_PATH(/dev/vfio/vfio) doesn't exist
>> in this container.
>> This scenario will also lead to the delay of DPDK secondary
>> process because `default_vfio_cfg->vfio_enabled = 0` and
>> `default_vfio_cfg->vfio_container_fd = -1`, socket error will
>> be set in DPDK primary process when it sync this info to
>> the secondary process.
>> This patch use to skip this kind of useless detection for this
>> scenario.
>>
>> Signed-off-by: Yang Ming <ming.1.yang at nokia-sbell.com>
>
> With a few code grammar fixes below,
>
> Acked-by: Anatoly Burakov <anatoly.burakov at intel.com>
>
>> ---
>>   lib/eal/linux/eal_vfio.c | 11 +++++++++++
>>   1 file changed, 11 insertions(+)
>>
>> diff --git a/lib/eal/linux/eal_vfio.c b/lib/eal/linux/eal_vfio.c
>> index 7132e24cba..1679d29263 100644
>> --- a/lib/eal/linux/eal_vfio.c
>> +++ b/lib/eal/linux/eal_vfio.c
>> @@ -7,6 +7,7 @@
>>   #include <fcntl.h>
>>   #include <unistd.h>
>>   #include <sys/ioctl.h>
>> +#include <dirent.h>
>>     #include <rte_errno.h>
>>   #include <rte_log.h>
>> @@ -1083,6 +1084,7 @@ rte_vfio_enable(const char *modname)
>>       /* initialize group list */
>>       int i, j;
>>       int vfio_available;
>> +    DIR *dir;
>>       const struct internal_config *internal_conf =
>>           eal_get_internal_configuration();
>>   @@ -1119,6 +1121,15 @@ rte_vfio_enable(const char *modname)
>>           return 0;
>>       }
>>   +    /* return 0 if VFIO directory not exist for container with 
>> non-privileged mode */
>
> /* VFIO directory might not exist (e.g. unprivileged containers) */
>
>> +    dir = opendir(VFIO_DIR);
>> +    if (dir == NULL) {
>> +        EAL_LOG(DEBUG,
>
> "VFIO directory does not exist, skipping VFIO support..."
>
>> +            "VFIO directory not exist, skipping VFIO support...");
>> +        return 0;
>> +    }
>> +    closedir(dir);
>> +
>>       if (internal_conf->process_type == RTE_PROC_PRIMARY) {
>>           if (vfio_mp_sync_setup() == -1) {
>>               default_vfio_cfg->vfio_container_fd = -1;
>
>
Hi Anatoly,

Thank you for your review and the suggested improvements.

I will apply the code grammar fixes you mentioned soon in next version:

1. Updated the comment to:
/* VFIO directory might not exist (e.g., unprivileged containers) */

2. Modified the log message to:
"VFIO directory does not exist, skipping VFIO support..."

These changes enhance clarity and align with the coding standards. I 
appreciate your attention to detail.

Best regards,
Yang Ming




More information about the dev mailing list