From nobody Sat Oct 3 03:54:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7A7D632B107; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; cv=none; b=lIsBrCIejcM2xvHeMqK7Yi4m6M7AalBUtiVWRk55lcp1P2YVpxLwCAryUutTX2VSW+J9Dnl0HEQNQRXxqpS28a7xhvVeYQ481dl/mDOzEOE9AAeOI6AnQKjxVIg172L0syPHchMLNb4UzRyiCCJGEk7gXFb89V5hhRk4Znhi/Aw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; c=relaxed/simple; bh=JTWQsMVQWpqAcgi+OJObB+Qe7+AfYuU84GSs5YSeK3o=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=upOdq/nlCw1rsIlV1rKhAYtF+18FhrI4aR+GCB63blKc5Y57GsQD+vFEYXBC6v+xk5VdSKPJGDSOkYu7iv2zi9yGpgchg8WIEE26ffB+0UDWMew5BUS8m/Dpm6BX23y81U6qgklKMKd/oREevpZ79yygJa2fv3R1K8e045Euwik= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=U/x0iTAs; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="U/x0iTAs" Received: by smtp.kernel.org (Postfix) with ESMTPS id 30F8CC2BCF5; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785991537; bh=JTWQsMVQWpqAcgi+OJObB+Qe7+AfYuU84GSs5YSeK3o=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=U/x0iTAsLGlq0H2AAeKCP5ZySWe8sNag3kBEpXV6BEh/+Hgo8dEc1OPDc7WYNYMTO sW8z6TA+LA+BkQK5M39oamWrYtiXnWZIzfWh6Tsnv5M+jvpOxd3LpttFttRvp1t2tE 2jmwtunmEtD9P4SkWoDwi/u1nIXYzyexV2gIhlu132aLwu5+EfRNbeQpbgWruIClQS OGpcM1bYKaeQQzKclukUR4z9Uutqb3dW1s5NY/RdkDvmrlE9hbMwImFapnBnqgMh9O z/WWbWr4cMBW8lB5EopamSiRGVYyecm8bDH1rPwRFILl4KtEVSxMfR9oQmtgVPuTdr qRNHjOV11TqZg== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 11665C55838; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Thu, 06 Aug 2026 12:45:24 +0800 Subject: [PATCH 1/3] drm/amdgpu: disallow multiple FENCE chunks in one submit Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260806-amdgpu-fixes-v1-1-ce247012d4da@outlook.com> References: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> In-Reply-To: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> To: Alex Deucher , =?utf-8?q?Christian_K=C3=B6nig?= , David Airlie , Simona Vetter , Jammy Zhou , Madhav Chauhan , Felix Kuehling Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1617; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=U1v7v3zFLG1cH7eOPY13uCvfCEVk89tQy4HVVMDjA30=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBLB/Ihr1ifkNpY86DomM62A6+quZw2Ll7DvtuFu3 HP70+MbCic6SlkYxLgYZMUUWY4XXPpm4btFd4vPlmSYOaxMIEMYuDgFYCJWMxgZJiQZdbx4+8gq ykxiptS8TfHehaEdndwHzsxKmS5hqXnzNMM/Zc3i+6+zV4kUs6p5yTEzOMZpa3lcW1L7lcWnbs6 5Ffu4AMMlSJ8= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo amdgpu_cs_pass1() dispatches on chunk_id once per chunk without rejecting repeated ids. p->uf_bo is a single-slot field, so a submission carrying two AMDGPU_CHUNK_ID_FENCE chunks runs amdgpu_cs_p1_user_fence() twice, and the second run overwrites p->uf_bo with a freshly referenced BO without dropping the reference taken by the first. amdgpu_cs_parser_fini() only unrefs the final p->uf_bo, so every FENCE chunk but the last leaks a BO reference. The leaked BO outlives handle close and process exit. Reject duplicate FENCE chunks the same way commit fec5f8e8c6bc ("drm/amdgpu: disallow multiple BO_HANDLES chunks in one submit") did for p->bo_list. Fixes: d38ceaf99ed0 ("drm/amdgpu: add core driver (v4)") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo Reviewed-by: Christian K=C3=B6nig --- drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c b/drivers/gpu/drm/amd/a= mdgpu/amdgpu_cs.c index 5445f75741b5..9c514cb01096 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c @@ -228,6 +228,10 @@ static int amdgpu_cs_pass1(struct amdgpu_cs_parser *p, if (size < sizeof(struct drm_amdgpu_cs_chunk_fence)) goto free_partial_kdata; =20 + /* Only a single user fence is allowed to simplify handling. */ + if (p->uf_bo) + goto free_partial_kdata; + ret =3D amdgpu_cs_p1_user_fence(p, p->chunks[i].kdata, &uf_offset); if (ret) --=20 2.51.2 From nobody Sat Oct 3 03:54:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EA873403E3; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; cv=none; b=OZWc4AAESHaps630pt31jGTedQ/56y/zpxRBo9xgp4MGHuuCioGhgWHtZZLup6aN5d6yAQCTL/H41EStJHS1QipGdrGlkDJpf7oO10IoD/l85ijM3SwggjZkqtY+appdrKZCRbFCrWaig/p0srT6JVVBIS5FI8vqr3+SJnJxxww= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; c=relaxed/simple; bh=bAaTk4jjY1AcRN0tzZgeyd0ZFfZYjo/TJnyi0hH0QLE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=XxFe060lbMGRKMzabB29CgaC4/YQi4Td3HNnNT8WIpypo8NLJ71MlQZl38+eQG4O6WYo7yVH7P8e+3yC6mPRvggRDNd9IvpysQfXz/OCNsVPQQ+IvH1jafM56yDv+lIM0D52xghQtwCKjrw911j3qpMqCbdftDRUkbuo8/MIy2o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=nf4bEjx4; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="nf4bEjx4" Received: by smtp.kernel.org (Postfix) with ESMTPS id 428D3C2BCF4; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785991537; bh=bAaTk4jjY1AcRN0tzZgeyd0ZFfZYjo/TJnyi0hH0QLE=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=nf4bEjx4nN3npxssqVgl6MWoz34O8xTALlLFbgzYyJpkix9TTHhPPlHPeLjxq5nN+ ndzTTSRe9DHMmQQLEkhQ9PSjtcZnwzLHyWZb9+NCHWKCTPRwYReYdU4nQDSp2KPgR/ 4e9YmltygW8auCH8yMsaZKfUuIkCOP+tKH0HJTOPlbzdfQ9z+2Yj8Wz456MfuXXKwm a9BQQ8a4/dg6PqtBkJJKCQJdm08AVMw+CDtIPyXjyqYsLCSCYofF4MOepzkJs85Bp/ ib7wBNon97cLBe/aeykvXBbP99UFBOrFa/MWvwtdmbtevbe92AFRg6oZt5tdDHQCnD FMja714BA/jOw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 238FDC56205; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Thu, 06 Aug 2026 12:45:25 +0800 Subject: [PATCH 2/3] drm/amdgpu: fix VM update overrun on non-4K page kernels Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260806-amdgpu-fixes-v1-2-ce247012d4da@outlook.com> References: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> In-Reply-To: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> To: Alex Deucher , =?utf-8?q?Christian_K=C3=B6nig?= , David Airlie , Simona Vetter , Jammy Zhou , Madhav Chauhan , Felix Kuehling Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang , stable@vger.kernel.org X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=2456; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=RZz+TFSeftgnMAQF9ZGjSUuynkvUNb8BqbEu73b+W2w=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBLB/OLTuwuNp3tJBO+8KlctJP3i6dLA+V+8Fh8+V tAbknUte2tHKQuDGBeDrJgiy/GCS98sfLfobvHZkgwzh5UJZAgDF6cAXESO4a94HfMmCXVP5a4H wf17MkVZ/0x6x9x3Y6bxcWujI5HiU7czMvR/Ngl4lL7UZcnehNYtrj1bGqb/W8jw/uCje8d2el6 s72MHAEbVS7g= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo The contiguity scan in amdgpu_vm_update_range() rounds num_entries up to count * AMDGPU_GPU_PAGES_IN_CPU_PAGE, but count is only constrained by the loop bound when the loop body executes. The guard num_entries > AMDGPU_GPU_PAGES_IN_CPU_PAGE proves that tmp =3D num_entries / AMDGPU_GPU_PAGES_IN_CPU_PAGE is at least 1, while the initial count of 2 needs tmp >=3D 2. Each iteration consumes a multiple of AMDGPU_GPU_PAGES_IN_CPU_PAGE, so a mapping whose GPU page count is not a multiple of it eventually reaches an iteration where num_entries is above AMDGPU_GPU_PAGES_IN_CPU_PAGE but below twice that. tmp is then 1, the loop body never runs, count keeps its initial value, and num_entries is rounded up past what the cursor holds, tripping BUG_ON(size > cur->remaining) in amdgpu_res_next(). AMDGPU_GEM_VA is DRM_RENDER_ALLOW and amdgpu_vm_verify_parameters() only requires map_size to be a multiple of AMDGPU_GPU_PAGE_SIZE, so an unprivileged caller can reach this. On 4K page hosts AMDGPU_GPU_PAGES_IN_CPU_PAGE is 1, tmp >=3D 2 always holds, and the bug is unreachable. Clamp the rounded-up value against num_entries, mirroring the min() that amdgpu_res_first() already applies to cur->size. A contiguous short tail is then mapped in full, and a non-contiguous one falls back to a single CPU page so the loop still makes forward progress. Fixes: a39f2a8d7066 ("drm/amdgpu: nuke amdgpu_vm_bo_split_mapping v2") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Junrui Luo --- Found by code inspection; not tested on hardware. I have no access to a 64K-page host with an AMD GPU, so the BUG_ON() path was not exercised at runtime. --- drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c b/drivers/gpu/drm/amd/a= mdgpu/amdgpu_vm.c index dc6a9d7dd0b2..365a1c4a4527 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c @@ -1193,8 +1193,9 @@ int amdgpu_vm_update_range(struct amdgpu_device *adev= , struct amdgpu_vm *vm, } if (!contiguous) count--; - num_entries =3D count * - AMDGPU_GPU_PAGES_IN_CPU_PAGE; + num_entries =3D min(count * + AMDGPU_GPU_PAGES_IN_CPU_PAGE, + num_entries); } =20 if (!contiguous) { --=20 2.51.2 From nobody Sat Oct 3 03:54:02 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7EB0A340A6B for ; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; cv=none; b=oqwEgSUUd9abhP/7FkILo1YuCXOzMtU4ifxEimkv8iBMGU10jKDWPPxq+LrS7Hi5iPdtTYJvaqPDLZVppFzNskBqSZ+La1983paIob8JLsHGQejlk9qLh3n+dVRemRny3wM/rUNkgIMgR/9F3p0vMhgb9CJuE1qGO2s1Gn3BXhs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785991537; c=relaxed/simple; bh=qps4WXR6Y3kW2L+YWOrgrmtd3I5PsdfE4fmyegP2GcM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=BBxa+OFV4TSns8H4P7iffUA8uECVUS6r+UWdwPxI6pjdYo6YAFMtVfDePNXPR5p55sgth5th3n0FT4e1BvzsrgUR/QPvjJ6kGlWny8fhttacVXVH2j7MzhKXG1WTrv0IQghxFyfz+kOskn/8MwA7zJq0BzAjmHqLnUP7juGqZMo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=ILDNVWJV; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="ILDNVWJV" Received: by smtp.kernel.org (Postfix) with ESMTPS id 4AB6DC2BCFA; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1785991537; bh=qps4WXR6Y3kW2L+YWOrgrmtd3I5PsdfE4fmyegP2GcM=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=ILDNVWJVxJQfuEPhFup9jfsI2OuGe3FdYZAnlYlNMqBwpr9vVfYYBjNukX2PdB+8n yfT7pnF96Xm001au9PdM9wJaRlJ+a+K4MGlP/ORn6LPkt0JIjOJ+DLnFTfFN6eFyrS TW9y4bFDET4jvR1P6TI4K7NIDOdiof8f0QvPsdkCdi9fUxoPMmPEGQk0EiHSVpXpsu iL/vxEWlL3/e3IWRPN1KjRlcNIWkef1Boc7kWCTdtLqSz3AtzphYpPhzd2z1ZUE8t7 rwlG+WqTiSJ3qzx87IYjFYF6wEkI2lS/FlwBviOXUzG4aBF/jchHkgixbx0o23bELB MRm4ILU951b/g== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 37278C56208; Thu, 6 Aug 2026 04:45:37 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Thu, 06 Aug 2026 12:45:26 +0800 Subject: [PATCH 3/3] drm/amdgpu: add the BO-va mapping offset when kmapping an IB Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260806-amdgpu-fixes-v1-3-ce247012d4da@outlook.com> References: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> In-Reply-To: <20260806-amdgpu-fixes-v1-0-ce247012d4da@outlook.com> To: Alex Deucher , =?utf-8?q?Christian_K=C3=B6nig?= , David Airlie , Simona Vetter , Jammy Zhou , Madhav Chauhan , Felix Kuehling Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1861; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=MbTPCxPC+NDqqRce7zTi4D+evqyxLQPMZapIx+qmD0Q=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBLB/DfZi47l17h7SAeu4BEMcj9s2DaB3/PUHs7Qr W735Venv+goZWEQ42KQFVNkOV5w6ZuF7xbdLT5bkmHmsDKBDGHg4hSAiSzNYfjJGLTW9nlC6BXO woRQd5XGF9N/L/TaekN2tl3t8czgJm1nRoYNy5/s/vlEadqbDVUJms8cuoTL51u9k/f/yJS309L u0B8uAHdPSUc= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo amdgpu_cs_patch_ibs() derives the CPU-side view of a UVD/VCE/VCN indirect buffer from the BO returned by amdgpu_cs_find_mapping(): r =3D amdgpu_bo_kmap(aobj, (void **)&kptr); kptr +=3D va_start - (m->start * AMDGPU_GPU_PAGE_SIZE); amdgpu_bo_kmap() returns the start of the BO, so only the displacement of va_start inside the mapping is added. The page tables, however, are programmed from mapping->offset (see amdgpu_vm_bo_update()), which records the offset_in_bo the client passed to AMDGPU_GEM_VA. The GPU therefore resolves va_start to BO byte m->offset + (va_start - m->start * AMDGPU_GPU_PAGE_SIZE) while the kernel inspects the byte m->offset lower. Whenever an IB is submitted through a mapping created with a non-zero offset_in_bo, the two views disagree. Add the missing term so the kmapped pointer describes the same bytes the page tables do. Every other CPU-side consumer of amdgpu_cs_find_mapping() omits mapping->offset in the same way. Fixes: 4802ce117786 ("drm/amdgpu: fix UVD/VCE VM emulation") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c b/drivers/gpu/drm/amd/a= mdgpu/amdgpu_cs.c index 9c514cb01096..a72cee871af3 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c @@ -1047,7 +1047,7 @@ static int amdgpu_cs_patch_ibs(struct amdgpu_cs_parse= r *p, if (r) return r; =20 - kptr +=3D va_start - (m->start * AMDGPU_GPU_PAGE_SIZE); + kptr +=3D m->offset + va_start - (m->start * AMDGPU_GPU_PAGE_SIZE); =20 if (ring->funcs->parse_cs) { memcpy(ib->ptr, kptr, ib->length_dw * 4); --=20 2.51.2