From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D91AF43B6E5 for ; Tue, 11 Aug 2026 10:17:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443482; cv=none; b=XeOzNH5wbWKNP/enpCaaQ9+iLBY/8Q5he8YyRtPmaydbFHmgPC7airYesxFvxujAh3E230HNAOCj8MIyXxpMZNubatT1Zc8bpoC/9VdvwYmaFn2ngfduv4X+sBYqtWzYMI32BVXSkFMhTE+eclXQ7hGhdBdDFAh9+OE/tI/dpfY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443482; c=relaxed/simple; bh=ycLtDUILBUNGvGA3TCZuAZrvo03VF+JiaIir96T3EKQ=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=UFF6UY2j3Uj2ZUvaBhtpifU8kBsNlUtnIWuvEbZIlh1q29vdZc+vNb/QSvnuabi/ueAF7lkOY1LSz09D5B8zZ4JXeesKZ1ojs6dPpLSC8Yp7kKwaQ9wPJ+H1eUJEVuRqN/Ys2KQ5qZ13I6qaO5xxWHYnJpnQPX5Zrw16/zQPCls= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=EuXIA5lu; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="EuXIA5lu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443468; bh=ycLtDUILBUNGvGA3TCZuAZrvo03VF+JiaIir96T3EKQ=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=EuXIA5luX54UHnD5ViwyRpm0i69gStmk6K4DIyFIiDilYjP6VV73DYCL9cG4xXvmC VJMEQbEMqmmS658YBzvs6coez1VwpE210eA7IBs0geN+9A8IIZyoM0PBgUwgd6syG1 tuI4ubPsUTkZNW+y4sqGBmLXvu822NHDBh2br7oUNzGXk2NpXYj7ZUGWEi1+YGHZK+ 3hKQW+DS+AjEeXqiZNMBkGzg7bFzSGsVSzi0Z9jOL3loV/KvT04S3YUVeQu/6lBwG0 /qSk4oArOOHe4MSMo2NJx4o3VWqg+nWCOI4ev4xeijJ/shcw3JLQfJfP495Q3Y1O1h X6Q3/48oZLslg== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 9DE0917E0778; Tue, 11 Aug 2026 12:17:47 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:35 +0200 Subject: [PATCH v2 01/17] drm/panthor: Disable reset work before unplug Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-1-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=3214; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=ycLtDUILBUNGvGA3TCZuAZrvo03VF+JiaIir96T3EKQ=; b=UaWMZzECfriH7c2mI5nVv+K1t5Pcuwy7hfBFBQQQ2zsv78tVj9wFPEij3gdcIAqYf3jWxa8Df P7RKw/ZytyOBHqnlufo3RweVTFv4a+8P/fckK/hooMqAdpZU2qP8jTE X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Unplug is supposed to be the end of the road, so we need to make sure reset works won't execute while we're cleaning up everything as part of the unplug, otherwise it would mess up the internal state. In order to be able to call disable_work_sync() in the unplug path, we need to defer the unplug triggered by the reset logic, otherwise we would deadlock. Fixes: 5fe909cae118 ("drm/panthor: Add the device logical block") Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 21 ++++++++++++++++++++- drivers/gpu/drm/panthor/panthor_device.h | 3 +++ 2 files changed, 23 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index 0b25abebb803..c41de1b61533 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -91,6 +91,16 @@ void panthor_device_unplug(struct panthor_device *ptdev) */ mutex_unlock(&ptdev->unplug.lock); =20 + /* Unplug triggered by a device removal might race with the deferred + * one queued by the reset work. The function covers this concurrent + * unplug situation, but if we can disable the work before its + * execution, that's still better. + */ + disable_work(&ptdev->unplug.work); + + /* Make sure we're not interrupted by resets while we're unplugging. */ + disable_work_sync(&ptdev->reset.work); + /* Now, try to cleanly shutdown the GPU before the device resources * get reclaimed. */ @@ -114,6 +124,13 @@ void panthor_device_unplug(struct panthor_device *ptde= v) complete_all(&ptdev->unplug.done); } =20 +static void panthor_device_unplug_work(struct work_struct *work) +{ + struct panthor_device *ptdev =3D container_of(work, struct panthor_device= , unplug.work); + + panthor_device_unplug(ptdev); +} + static void panthor_device_reset_cleanup(struct drm_device *ddev, void *da= ta) { struct panthor_device *ptdev =3D container_of(ddev, struct panthor_device= , base); @@ -148,8 +165,9 @@ static void panthor_device_reset_work(struct work_struc= t *work) drm_dev_exit(cookie); =20 if (ret) { - panthor_device_unplug(ptdev); + disable_work(&ptdev->reset.work); drm_err(&ptdev->base, "Failed to boot MCU after reset, making device unu= sable."); + queue_work(ptdev->reset.wq, &ptdev->unplug.work); } } =20 @@ -206,6 +224,7 @@ int panthor_device_init(struct panthor_device *ptdev) */ *dummy_page_virt =3D 1; =20 + INIT_WORK(&ptdev->unplug.work, panthor_device_unplug_work); INIT_WORK(&ptdev->reset.work, panthor_device_reset_work); disable_work(&ptdev->reset.work); ptdev->reset.wq =3D alloc_ordered_workqueue("panthor-reset-wq", 0); diff --git a/drivers/gpu/drm/panthor/panthor_device.h b/drivers/gpu/drm/pan= thor/panthor_device.h index 0fda64fbe5f2..ea23dde90fea 100644 --- a/drivers/gpu/drm/panthor/panthor_device.h +++ b/drivers/gpu/drm/panthor/panthor_device.h @@ -264,6 +264,9 @@ struct panthor_device { * operation is done. */ struct completion done; + + /** @work: Unplug work. */ + struct work_struct work; } unplug; =20 /** @reset: Reset related fields. */ --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B362543231B for ; Tue, 11 Aug 2026 10:17:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443492; cv=none; b=lKeo+tKBMRO94RFJHkmVzRVhXi8SkEgrptra/tpCKVaLjCiDGxNnH9GYf7Q6L/6jrBdvNGGfmJDyqu3HBDOZ7w1ET9N8g72HeCOJxYLkhbObjY1DLKpfFL6AbjCTNXGDnG7bUkDkfkqI4fPc/plCN/ppBnMlbxYwUkr4beUrAgQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443492; c=relaxed/simple; bh=fzLWUDPtqoIwG8+ccSWaLGPju4rxuXjgRSA/ZeNnC6E=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=cxVnMY06cFqEh1TAJZ1kJ5TtI7jg2UaBCvBWQM8fqLXlT5frmYrTVnA2WMSFJ5G5/Qynux6j66K44xxQ6Auma2ie9mWWrj5+G3G9p9Cp3ABvhvz5ivJ6xLnoYEnUBalC4O13f7T5zdp83SRK4SXhMBKb5Xo/2ZN89q4yK9yK14k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=g8btHzNm; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="g8btHzNm" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443468; bh=fzLWUDPtqoIwG8+ccSWaLGPju4rxuXjgRSA/ZeNnC6E=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=g8btHzNmnHcZ/N36x8L0IRMZMWbrhUFj3yteqbte6AGhUy8FuPLgRgOH62j0uYmfx lTBFatH658IgIVBM2aon7TS7NsbAK9ePQn8xVvPrGGaaVXvcciMZmL+WpO4EvJHAMT xznZPv1VXXnnghzKDnh6rMKBMeSaXUNvH2kT93GSI5duRb6/LjIlDDz3cP8Zoi0nxU EIl5OrfaCHnoHQ5Nl4JXNbFgK9ngEuqEqjY1d5+v5f9mIR8r4T8mf4AIMFu7n8EcCH /5nrmFLQ3jyEcSGlK6ueXffHxW7+UEYlkzdcun3GM3RjD4I1Ikncug74FXjHAerI8B 7aw51Sq0VOedg== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 287F317E0EF0; Tue, 11 Aug 2026 12:17:48 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:36 +0200 Subject: [PATCH v2 02/17] drm/panthor: Further delay reset work enablement Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-2-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=1731; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=fzLWUDPtqoIwG8+ccSWaLGPju4rxuXjgRSA/ZeNnC6E=; b=v4QUI2eEqCE7l0H1iOl8FYGceTetF0ckuE0U63QSdLYPeVsRHBo+njSpylXOytl3AWnZwOBuZ dkuYk/sZV8nAb9Vb+rBv5HIXPNqDFh3ikRWfqACLMayuod2fQqRR7JA X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= There's no point re-enabling the reset work before the DRM device registration succeeds, so move the enable_work() after the point where nothing can fail anymore, and in the unlikely event where a reset was pending, reschedule it. Fixes: 1b8d771fb214 ("drm/panthor: Keep the reset work disabled until every= thing is initialized") Closes: https://sashiko.dev/#/patchset/20260625-panthor-misc-fixes-v1-0-b67= ed973fea6@collabora.com?part=3D2 Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 11 ++++++++--- 1 file changed, 8 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index c41de1b61533..5355c4074f1f 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -305,9 +305,6 @@ int panthor_device_init(struct panthor_device *ptdev) =20 panthor_gem_init(ptdev); =20 - /* Now that everything is initialized, we can enable the reset work. */ - enable_work(&ptdev->reset.work); - /* ~3 frames */ pm_runtime_set_autosuspend_delay(ptdev->base.dev, 50); pm_runtime_use_autosuspend(ptdev->base.dev); @@ -316,6 +313,14 @@ int panthor_device_init(struct panthor_device *ptdev) if (ret) goto err_disable_autosuspend; =20 + /* Now that everything is initialized, we can enable the reset work. + * If there was a reset pending, clear and reschedule, otherwise the + * reset.pending bit is stuck. + */ + enable_work(&ptdev->reset.work); + if (atomic_read(&ptdev->reset.pending)) + queue_work(ptdev->reset.wq, &ptdev->reset.work); + pm_runtime_put_autosuspend(ptdev->base.dev); return 0; =20 --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8FF1943B4B3 for ; Tue, 11 Aug 2026 10:17:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443492; cv=none; b=bg05mutRPoPJlRbtfrvbhvPtDXdXYVfQL98cBcf7djk4I4DfTvzwVAEFd5/GnArgHYzVuVDqW02C1/gGvTY3RKtbHeZBeYDYkgU1glpH4vVo55C4NE3kTO7UWk7Sfsch52R4oC+RpjAzK6rMS+JAE8E3edX0TayJ6uLrk1EapR8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443492; c=relaxed/simple; bh=0OePKVAEPcE3PmS+UKX8kJpdcShf9zGywxXUPRUZm6U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=mpm7gDZRO+k3Uff41zZO9J6ea4+zYVvXkCfLZXmHzR16c9ai5arpfgBajFIyXrEHny8h5yrs6d1I4lyGI/WJuLEhy1Faamh0OH9rLjLvu+0W8rAzFl/O8EHasVfsJ9VNDExyds89GgR3NVtsjfObBODwdr31IDFLDBda5V58w9o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=iMB9nbYx; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="iMB9nbYx" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443469; bh=0OePKVAEPcE3PmS+UKX8kJpdcShf9zGywxXUPRUZm6U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=iMB9nbYxz+LKH7bR7fg/EUBLMp2ouxBkDAM/4umFfijvIQgWOFjKsCKDwM9MHdNPo Y6AETdl/ll7nnStC98yFj8hrygOARxqOmXlI0dBtfAFYNdcWP4+2kTb589+ambysji aGe204b5fU2qC/rRvoXO3zUPBRmXqegQsX7yBgEsO9575AkzcB7tb6k7MIX1H5oXoQ n/WxM5iL+3VG6RjCyBjM8xYboA9HFqjKnNpfVYxNgMnoLyMR7eZV1yQvfRpTWlXKZz coA3PqEWH5uhulnOoxKRMseUhinuFg18COX+YcnksSXQiT6zbf3ccjSxC35TWljhec RqAXgRWtP2X+A== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id A8D1317E0F35; Tue, 11 Aug 2026 12:17:48 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:37 +0200 Subject: [PATCH v2 03/17] drm/panthor: Make sure reset requests in the resume path are not lost Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-3-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon , sashiko-bot@kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=1203; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=0OePKVAEPcE3PmS+UKX8kJpdcShf9zGywxXUPRUZm6U=; b=/8vHXxwABB8nXP1nq4deTo04O3q+XmvP5i0H07rSdxcACNg8albv6BGrMMwOqp8AXlnfCRDgx YDFNjSJCP+XBGZewyC7o3MH5VDYsixXJrnYgcVOzS5P0+SH9nL9Rta0 X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= A reset might have been queued while we were resuming. Make sure it's not lost by rescheduling it. Fixes: 5fe909cae118 ("drm/panthor: Add the device logical block") Reported-by: sashiko-bot@kernel.org Closes: https://sashiko.dev/#/patchset/20260804-panthor-unplug-fixes-v1-0-a= bbbd2d41b13@collabora.com?part=3D2 Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index 5355c4074f1f..2520158adb03 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -570,6 +570,13 @@ int panthor_device_resume(struct device *dev) DRM_PANTHOR_USER_MMIO_OFFSET, 0, 1); atomic_set(&ptdev->pm.state, PANTHOR_DEVICE_PM_STATE_ACTIVE); mutex_unlock(&ptdev->pm.mmio_lock); + + /* A reset might have been queued while we were resuming. Make sure + * it's not lost by rescheduling it. + */ + if (atomic_read(&ptdev->reset.pending)) + queue_work(ptdev->reset.wq, &ptdev->reset.work); + return 0; =20 err_suspend_devfreq: --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A15C4314AB for ; Tue, 11 Aug 2026 10:17:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443498; cv=none; b=GWT6fneeXJJacWPi19kAnL5P9/SxnH2yw09TVgAN/5OAO8Eslg7mhqMmIDeO4TdnVzGTQrlt70UFZ+A+6xuEBGeJDjkNVRXYEpmIOtbqxwDvCISKizr8IMzHRkWdYDAKwRIPS4/1ig38F2cnl5wMaRdCgFyUm2ByfcEBto8PEzo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443498; c=relaxed/simple; bh=76GunOx6VjNDBXpXmvzFeO0zG5xEZwxiP+FPiy9vntU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=OFakEuzQkftMl1w6K28WwrVElRthkZww9A+rRVfQCPJmZzHoQ0j3pjwFyCk3sIZ855fCyyC6pFwIp9VPMy8GG8SwYdO2XKfo1ssZvKulsspUVSv3hVIPPWyRmYjl/z1kQmi2dKMJdl1R65TFh9rvajgJJCU2O6WKHWUVi1/TXrU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=RAcJ4tmc; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="RAcJ4tmc" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443469; bh=76GunOx6VjNDBXpXmvzFeO0zG5xEZwxiP+FPiy9vntU=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=RAcJ4tmc3tys7NE3ud9C2V69VhGvR8ML8Qxu4ffrCIPszRmUT84D8LEww3EvN5zQd nX6bhHESSiNrJEpQtlpu+wVP9UzW5swORUNczDyDQ1Lb3+BSQs+GWZ/bo46ah4dK4x g3ajoBKA4Cxrd+e2SQPsmY+zhk/eUhklbZ4PjtI74KxM6cVwgUte5Zobv1Cpmmbaa4 bPbjiNJKMo5Vz0Xoj70t+4VxFGp25IuCU1HnywDdKb2KIuNhkzh80GDixvIxbSGtb+ qnxRvz5k3fbMNE0mJxUcBgCMhFjiyeMJLv7Os8QkvMwZ9urvSGVIFLXI7KjM5pAm7f Eyuf/4uv15e0A== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 3F46E17E0F83; Tue, 11 Aug 2026 12:17:49 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:38 +0200 Subject: [PATCH v2 04/17] drm/panthor: Make sure reset requests in the post reset path are not lost Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-4-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon , sashiko-bot@kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=2210; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=76GunOx6VjNDBXpXmvzFeO0zG5xEZwxiP+FPiy9vntU=; b=AFKfwh+Qo12V30mfiD6T9zo3eMTdrDWgKWVJGiIn4iRt7+JpiX3R8gWfqHv9Re68X9iRAWZRz E2DxgmKLzOEDxTjLB12mWLuO4rwOEZhTUvN3ZVAGl/PPVADMirix6uX X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= In theory, there might be MMU/FW faults happening after the FW has successfully started, and since we clear the reset.pending bit after panthor_fw_post_reset() has returned, there's a short window during which a reset request can be ignored. The other case is a reset condition in other subcomponents that would not prevent the FW to boot, but given what's currently done in the post_reset() helpers, I don't see how this can happen. Anyway, it's probably safer to reset the pending bit just before the SOFT_RESET is issued, so there's absolutely no timeframe during which a reset event can be lost. The risk is an infinite reset loop if the reset condition doesn't prevent the FW to boot, and keeps happening in subsequent resets. Fixes: 5fe909cae118 ("drm/panthor: Add the device logical block") Reported-by: sashiko-bot@kernel.org Closes: https://sashiko.dev/#/patchset/20260804-panthor-unplug-fixes-v1-0-a= bbbd2d41b13@collabora.com?part=3D2 Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index 2520158adb03..393031ada315 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -156,11 +156,18 @@ static void panthor_device_reset_work(struct work_str= uct *work) panthor_sched_pre_reset(ptdev); panthor_fw_pre_reset(ptdev, true); panthor_mmu_pre_reset(ptdev); + + /* Reset the pending bit just before the SOFT_RESET to catch any reset + * condition happening in the post reset path. If we're in such a bad + * state we can't even resume the FW, we will bail out and unplug + * anyway, at which point the reset work is disabled, which should + * prevent an infinite reset loop. + */ + atomic_set(&ptdev->reset.pending, 0); panthor_hw_soft_reset(ptdev); panthor_hw_l2_power_on(ptdev); panthor_mmu_post_reset(ptdev); ret =3D panthor_fw_post_reset(ptdev); - atomic_set(&ptdev->reset.pending, 0); panthor_sched_post_reset(ptdev, ret !=3D 0); drm_dev_exit(cookie); =20 --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3458543B3EA for ; Tue, 11 Aug 2026 10:18:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443487; cv=none; b=W/KdiPYnVc1YWrVViGzzGSp2ChwMSck0Blecow7v9Qlod+4H3dPzIvl5PQ9EaWYJA+bSswRRIU+nDbdUGo6bsKX/lK7At1Vzr5qEUYTWtuCJGrcFSCSOvOV6MMSGGTbNFS1ht1AYxjAQ9SkXFx/IPbZ32sGroHncLO+gGjQNr4A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443487; c=relaxed/simple; bh=sS1voS0F+wgg2eh+l3RNjJaKI/tWiqmrmFsqaEonVJE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=KtFjHEY+SpzVnCnU+Ia6B5/OJOwARSq2BWobd1gPWwlD+hCanw+Wab9o0s07OI/UnROTqHy6WvzdomL17k0+zWa05A3jNcaAlr9RmaoyHZrbGlJtvTLpjrdGkODZWLsOrm17QctCUgYubXF5pQbeKsvnsW6Ne52h4ujoXSf+VBg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=BQnAqdav; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="BQnAqdav" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443470; bh=sS1voS0F+wgg2eh+l3RNjJaKI/tWiqmrmFsqaEonVJE=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=BQnAqdav5/b7Fzs6+RzAhZNNc9WcG85QTmgEZwS3BlylNzYRzePkpakIKIc870wbf dWtk6zzD0eTGNOFmtNsxlnUQUxFYjnNbPyw8k4VOQaZGotRQ1WIQyOf9+40Kiz7m3c /fkf39YU0RfH+OmaUYZC3xfw++AAgnjBJ19iykVal8mD2yH919k81UzffCBpnX8SlZ /mEVu5gYU5nmG243SaccKaAyK3ePWl9S/RBxz1mcggCegwXm+68ienBb6JZqXGccF2 DXdhSzF2WPEtIUX90xJjv2k65s1u1DM9DnSso4lSn4z3WQ2DWA2xbjJ5uT2mK5jxbF jmJtieM8e7PeA== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id C354817E0F85; Tue, 11 Aug 2026 12:17:49 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:39 +0200 Subject: [PATCH v2 05/17] drm/panthor: Flush the cleanup_wq in the unplug path Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-5-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon , sashiko-bot@kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=2279; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=sS1voS0F+wgg2eh+l3RNjJaKI/tWiqmrmFsqaEonVJE=; b=DES6GhuWFkrZ8m64B4oMJQpE30gXXiQtO8TDJSbXH0z4ErXDvhoYHm2i2gufvvTNJLvXzXvqY mt7PA/nQVFwD4DoQbLo/fblIaZj389eJ2KdIlChWRWCj1KpH0aOCu3g X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= If we don't do that, we might face various UAFs, because the resource referenced by these work items might be gone by the time they get executed. In each subcomponent making use of the panthor_cleanup_wq, we add a flush_workqueue() at the end of the _unplug() function. Note that this assumes no more work items from this subcomponent gets queued after that point. Fixes: de8548813824 ("drm/panthor: Add the scheduler logical block") Fixes: 647810ec2476 ("drm/panthor: Add the MMU/VM logical block") Reported-by: sashiko-bot@kernel.org Closes: https://sashiko.dev/#/patchset/20260625-panthor-signal-from-irq-v5-= 0-8836a74e0ef9@collabora.com?part=3D2 Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 6 ++++++ drivers/gpu/drm/panthor/panthor_sched.c | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 0182b72f1932..0b862d3c3605 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -3365,6 +3365,12 @@ void panthor_mmu_unplug(struct panthor_device *ptdev) } } mutex_unlock(&ptdev->mmu->as.slots_lock); + + /* Ensure any pending job cleanup work are executed before returning, + * otherwise those might access objects that are gone if the work is + * executed after other components are unplugged. + */ + flush_workqueue(panthor_cleanup_wq); } =20 static void panthor_mmu_release_wq(struct drm_device *ddev, void *res) diff --git a/drivers/gpu/drm/panthor/panthor_sched.c b/drivers/gpu/drm/pant= hor/panthor_sched.c index 5832dccfc093..f18b2e03f2fd 100644 --- a/drivers/gpu/drm/panthor/panthor_sched.c +++ b/drivers/gpu/drm/panthor/panthor_sched.c @@ -4074,6 +4074,12 @@ void panthor_sched_unplug(struct panthor_device *ptd= ev) sched->pm.has_ref =3D false; } mutex_unlock(&sched->lock); + + /* Ensure any pending group release work are executed before returning, + * otherwise those might access objects that are gone if the work is + * executed after other components are unplugged. + */ + flush_workqueue(panthor_cleanup_wq); } =20 static void panthor_sched_fini(struct drm_device *ddev, void *res) --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 45D2943C7C3 for ; Tue, 11 Aug 2026 10:18:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443485; cv=none; b=SVz0LRv+oxTTtbu5lwGz+3DNGcog0YofaVkMdEGcpDEjsZsT3li3QbUL3mP3f3HN3/9OheiHZXoL+TKNB2ieM1WZ8k300OPAbrgd6QkWC5Du7xB7GPH7tNx4pL7OKQE44MdRMqJ1TNOeIGAas5dcD9uH2FVo3G1BArphT2c6az8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443485; c=relaxed/simple; bh=f5zHXc9uXZcwLI3x1yehgFoxkAFjMfodJSRm8Oweu+o=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=cBFRTvmAOzcT6d8hpi8E89+C6p5u8S7zzgJy5ej9ZT1UsCWnrcsZgDmtWtc4DFgEBxLE6lffu8sT2CLeqHBXjlvuIbi9cXDnD7UZFnmmyjbAKm/hrQvJlQhCiVj5dYeyq3kxBvT8oWHzld6TeuUc6o5vLXZwVeg/u2LEWy67kyA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=OzGbDw8E; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="OzGbDw8E" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443470; bh=f5zHXc9uXZcwLI3x1yehgFoxkAFjMfodJSRm8Oweu+o=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=OzGbDw8EFWezx8eO4KXDeaIzzu0pCm4mnRLuJtXR5ak7UFhhxhst3b23Q5cR2nUez W3HAk2IyZ2X+EETQ8hCtYg0wRCj0QzpqmyIfRWGSmErQ55CGTvB9ZUswGCSKuBdtmq gGSW+QbKYhMwGhCLV4X7YEBG3pgBy+jhBvNH2II9n78zhe6KQsx+4bVGqitIriZb6B +7QeCZVO/qt91FbZuj4IfzF9AZ8ePCbGX6xt/5JAefaPXKcEyIrN8qnunGqy0d0EQQ IZhRZVGTtxHoXG5wsq1kkv6A+r8cEVc0+hiBxQFl2QBwwLl65O67U6H7Yg5ugiP3BY iv6APB3xgkhMA== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 5578A17E0FAB; Tue, 11 Aug 2026 12:17:50 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:40 +0200 Subject: [PATCH v2 06/17] drm/panthor: Drop unused vm argument passed to panthor_vm_prepare_sync_only_op_ctx() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-6-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=1147; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=f5zHXc9uXZcwLI3x1yehgFoxkAFjMfodJSRm8Oweu+o=; b=SAigtzJNZQW4wmzNQ7W2aqpetbGDJ0MU8kbCobcaec2UpsJ5uz4iRfIV9kbidNSrQOReu28Dz uKcF1VfTsclCZ7gFK4W8yw0MwApEtRJK7vv+zSmRO1BQV9+77uGY5OI X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= No need to pass a panthor_vm around if it's unused. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 0b862d3c3605..6c48e88ad17f 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -1463,8 +1463,8 @@ static int panthor_vm_prepare_unmap_op_ctx(struct pan= thor_vm_op_ctx *op_ctx, return ret; } =20 -static void panthor_vm_prepare_sync_only_op_ctx(struct panthor_vm_op_ctx *= op_ctx, - struct panthor_vm *vm) +static void +panthor_vm_prepare_sync_only_op_ctx(struct panthor_vm_op_ctx *op_ctx) { memset(op_ctx, 0, sizeof(*op_ctx)); op_ctx->flags =3D DRM_PANTHOR_VM_BIND_OP_TYPE_SYNC_ONLY; @@ -3026,7 +3026,7 @@ panthor_vm_bind_prepare_op_ctx(struct drm_file *file, if (!op->syncs.count) return -EINVAL; =20 - panthor_vm_prepare_sync_only_op_ctx(op_ctx, vm); + panthor_vm_prepare_sync_only_op_ctx(op_ctx); return 0; =20 default: --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5076C430CD3 for ; Tue, 11 Aug 2026 10:18:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443500; cv=none; b=tIPicGqGjJ7USL9zt+ttt20D2Mf/i4NbisGYtgFJKSbbslp6ZYpdZUk2dKGcH3lRqnMufjSG+DVMe+9zcLY3AA61tJjydfCh7k8H35JDt62wqJLJwM8rjRft6iskhK4MMXGi6PtVYn6oNRCNsu2y/BtJ7UsLLWxKtfgRVfyclc0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443500; c=relaxed/simple; bh=ryOmwVVB01y5hHhXlGNMY6pOLjAGiF1Kwfym+edbAZU=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=hGV2F+qGP7hpqYUcHK+QnGEie4KVEstPzOdMHqAIDI/mT95gJzR+L5Fe0U1lkh8OyL+uvcq7+LrKBikAL+QFaiA2rXUtd8x3Ca93jSKdAesJXop05m8wSVCtiQc2qPk/PbIjiUGqV1prgpJ8eY4OaX0IhVfg4R36gl3xKwUkDxI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=UqZQVJFu; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="UqZQVJFu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443471; bh=ryOmwVVB01y5hHhXlGNMY6pOLjAGiF1Kwfym+edbAZU=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=UqZQVJFuLyhwKk5gwh1DaBX4BUhJHcyWg84wlac0MVXdFp/RPlU1cDlNkUwGo+AFz 1wBJ339W+i78P8+61OUQGi3Z+LQtakIgsH+T6YZHA41NGwQO8+cm+DLqsRRhlHCr2Z HHgX7qRDxi8X1MatVIJwnJ67T7eaocX1aiRvUSWz6tAHqTf9nZpjrIR0WruNiKEi7/ WNKGTjvNMH/gzqpvByNSggeVeUpRFdowS77Aolkd7WV2SQXP+n60p+NPoDHyTsFVj1 x/zASrDe/1LPnpKkdx2tyFx9qNYo2jtweRwngopMbeegfqjxGhxx2reHpo7s+ejCLH m+md5Z8bntkzw== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id D4CBA17E0FB1; Tue, 11 Aug 2026 12:17:50 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:41 +0200 Subject: [PATCH v2 07/17] drm/panthor: Move the debugfs initialization to panthor_device.c Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-7-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=2777; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=ryOmwVVB01y5hHhXlGNMY6pOLjAGiF1Kwfym+edbAZU=; b=50qaObyjcRcVN/664J2FCwEEskACF+mQwo/7PxiBtJQHivoXbtTSBaGVnjMfkHTG0cotd7NHi Fq5p6bQb8W0AA0d8yWKx4ZjdIGlp6ieDi0kV71YgSyS8AOOtYNmAB5M X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Those are per-device debugfs-files, so it makes sense to have the initialization logic in panthor_device.c. Reviewed-by: Liviu Dudau Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 9 +++++++++ drivers/gpu/drm/panthor/panthor_device.h | 4 ++++ drivers/gpu/drm/panthor/panthor_drv.c | 10 +--------- 3 files changed, 14 insertions(+), 9 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index 393031ada315..d9eab6021145 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -13,6 +13,7 @@ #include =20 #include +#include #include #include =20 @@ -646,3 +647,11 @@ int panthor_device_suspend(struct device *dev) atomic_set(&ptdev->pm.state, PANTHOR_DEVICE_PM_STATE_SUSPENDED); return 0; } + +#ifdef CONFIG_DEBUG_FS +void panthor_device_debugfs_init(struct drm_minor *minor) +{ + panthor_mmu_debugfs_init(minor); + panthor_gem_debugfs_init(minor); +} +#endif diff --git a/drivers/gpu/drm/panthor/panthor_device.h b/drivers/gpu/drm/pan= thor/panthor_device.h index ea23dde90fea..10c96abf9cff 100644 --- a/drivers/gpu/drm/panthor/panthor_device.h +++ b/drivers/gpu/drm/panthor/panthor_device.h @@ -406,6 +406,10 @@ int panthor_device_mmap_io(struct panthor_device *ptde= v, int panthor_device_resume(struct device *dev); int panthor_device_suspend(struct device *dev); =20 +#ifdef CONFIG_DEBUG_FS +void panthor_device_debugfs_init(struct drm_minor *minor); +#endif + static inline int panthor_device_resume_and_get(struct panthor_device *ptd= ev) { int ret =3D pm_runtime_resume_and_get(ptdev->base.dev); diff --git a/drivers/gpu/drm/panthor/panthor_drv.c b/drivers/gpu/drm/pantho= r/panthor_drv.c index 46a3080b0b20..924a7ecd3733 100644 --- a/drivers/gpu/drm/panthor/panthor_drv.c +++ b/drivers/gpu/drm/panthor/panthor_drv.c @@ -1764,14 +1764,6 @@ static const struct file_operations panthor_drm_driv= er_fops =3D { .fop_flags =3D FOP_UNSIGNED_OFFSET, }; =20 -#ifdef CONFIG_DEBUG_FS -static void panthor_debugfs_init(struct drm_minor *minor) -{ - panthor_mmu_debugfs_init(minor); - panthor_gem_debugfs_init(minor); -} -#endif - /* * PanCSF driver version: * - 1.0 - initial interface @@ -1807,7 +1799,7 @@ static const struct drm_driver panthor_drm_driver =3D= { .gem_prime_import_sg_table =3D panthor_gem_prime_import_sg_table, .gem_prime_import =3D panthor_gem_prime_import, #ifdef CONFIG_DEBUG_FS - .debugfs_init =3D panthor_debugfs_init, + .debugfs_init =3D panthor_device_debugfs_init, #endif }; =20 --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C99D8439912 for ; Tue, 11 Aug 2026 10:18:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443504; cv=none; b=qUCWqJEe3B0yUTCiSa60IczyHSFRuLD8t2cVvlaZeawvsM7f3L9VxP7uG6Vlq+4vbzl0iTtl99P9Yk7wIgZd1q6MymtNynKmLvdw/odBc8Loo7nzap5v0I99tPnzuZ0sNfJ4nrPoXH5DT7KIuLaC1HeydsL/5E+D2cEcHvwjdRE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443504; c=relaxed/simple; bh=CV5hoQc2I+RwGiMTZrDPEFDKyNKUL7e2Mb6GnXdLfFA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Xs1CWV3//QGWP/zKilibsmgwCxbyor+mkyXFcc+4bHN39nIVs2RLBpaR70iwYIWXOe3l1Hc23oLn4BGRmflAWfBaBZw6PB/rClxos30nLF7N8uQT/SSE530vQMZ1PXI8JLvkkPuTVnafqHpyRszRns185BNSTeGf0dGkR962jiw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=pBcqHOBu; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="pBcqHOBu" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443471; bh=CV5hoQc2I+RwGiMTZrDPEFDKyNKUL7e2Mb6GnXdLfFA=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=pBcqHOBuJKGhBKWn8gc2DGDeHTW0Rvsy/IGpHexFCNZVHAzCPRzUQS+wCZ3l2mpky v5reN1PE5fHTaUNMTV3zmh+y4uQE4Iz3oU80dYFvoBR3IS+tMrw39/3WwpSddCAghh qqjb75JWcnnWr1pK//YwxiLbdxggpwTuQz+qvutFjFnqSiSfboZuMRPdVwHBI1z+5T y8YjXf4dPrOJ0jeSnirKhaPx3Cfolv0Tf7JrvFqYqLpumio/NtvqTloasKtcGujOsK kjN5CEioGA0s34PUmSgP9V8KHk29VrCrcPBLhNCiUu3bhwZ8Rc+TiOmWxSTHiTEXA4 eq4nqz668fS1Q== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 5EEAD17E0FE2; Tue, 11 Aug 2026 12:17:51 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:42 +0200 Subject: [PATCH v2 08/17] drm/panthor: Split panthor_vm Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-8-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=79339; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=CV5hoQc2I+RwGiMTZrDPEFDKyNKUL7e2Mb6GnXdLfFA=; b=CXlKpHUyZvD0GrN/jPY/DPt4xexBhb0maSs/yOTFYtT33wFXs4veLwgAYuJaPzuf/Ip4cb1uj VfqgQzNWKRrANdJE5rtU1/6VamKA1L79Vq+JboCt5VMoKYQv/xu6TWX X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= The way things are currently defined makes the cleanup procedure harder because the panthor_vm object cleanup happens after drm_gpuvm_fini() has been called, and sometimes we need a drm_gpuvm to undo things. This has been worked around by things like the panthor_vm_unmap_range() call in panthor_vm_destroy(), but there are still situations where this is problematic, like the show_each_vm() where we walk a list of VM and call drm_debugfs_gpuva_info() on each, with the risk of hitting an object that had drm_gpuvm_fini() called on it already. There's more of these tricky situations to come when we get to making the unplug logic more robust, so let's address the problem ahead of it and split the panthor_vm object in two: - panthor_as: this is the object embedding drm_gpuvm and more generally dealing with page table updates/residency - panthor_vm: this is the user-visible object wrapping around panthor_as. Among other things, it contains the scheduler for the bind queue and the drm_mm tree for kernel BO allocation. This object owns a drm_gpuvm ref. With this in place, we can do the cleanup steps that need a valid drm_gpuvm object in panthor_vm_release(), and the rest is cleaned up in panthor_as_free(). Note that there's a bunch of s/as[_nr]/slot/ variable/argument renames to clear the confusion between the AS slot number and the newly introduced panthor_as object. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 1051 +++++++++++++++++------------= ---- 1 file changed, 551 insertions(+), 500 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 6c48e88ad17f..041836552953 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -41,14 +41,14 @@ =20 #define MAX_AS_SLOTS 32 =20 -struct panthor_vm; +struct panthor_as; =20 /** * struct panthor_as_slot - Address space slot */ struct panthor_as_slot { - /** @vm: VM bound to this slot. NULL is no VM is bound. */ - struct panthor_vm *vm; + /** @as: AS bound to this slot. NULL if no AS is bound. */ + struct panthor_as *as; }; =20 /** @@ -77,19 +77,19 @@ struct panthor_mmu { /** @as.faulty_mask: Bitmask encoding the faulty slots. */ unsigned long faulty_mask; =20 - /** @as.slots: VMs currently bound to the AS slots. */ + /** @as.slots: AS currently bound to the AS slots. */ struct panthor_as_slot slots[MAX_AS_SLOTS]; =20 /** - * @as.lru_list: List of least recently used VMs. + * @as.lru_list: List of least recently used AS. * - * We use this list to pick a VM to evict when all slots are + * We use this list to pick an AS to evict when all slots are * used. * - * There should be no more active VMs than there are AS slots, - * so this LRU is just here to keep VMs bound until there's - * a need to release a slot, thus avoid unnecessary TLB/cache - * flushes. + * There should be no more active AS than there are AS slots, + * so this LRU is just here to keep page tables bound until + * there's a need to release a slot, thus avoiding unnecessary + * TLB/cache flushes. */ struct list_head lru_list; } as; @@ -153,9 +153,9 @@ struct panthor_vma { }; =20 /** - * struct panthor_vm_op_ctx - VM operation context + * struct panthor_as_op_ctx - AS operation context * - * With VM operations potentially taking place in a dma-signaling path, we + * With AS operations potentially taking place in a dma-signaling path, we * need to make sure everything that might require resource allocation is * pre-allocated upfront. This is what this operation context is far. * @@ -163,7 +163,7 @@ struct panthor_vma { * asynchronously, and let the VM_BIND scheduler process the next VM_BIND * request. */ -struct panthor_vm_op_ctx { +struct panthor_as_op_ctx { /** @rsvd_page_tables: Pages reserved for the MMU page table update. */ struct { /** @rsvd_page_tables.count: Number of pages reserved. */ @@ -215,13 +215,120 @@ struct panthor_vm_op_ctx { } map; }; =20 +/** + * struct panthor_as - Used to managed a GPU address space. + */ +struct panthor_as { + /** + * @base: Inherit from drm_gpuvm. + * + * We delegate all the VA management to the common drm_gpuvm framework + * and only implement hooks to update the MMU page table. + */ + struct drm_gpuvm base; + + /** @memattr: Value to program to the AS_MEMATTR register. */ + u64 memattr; + + /** @pt: Page table fields. */ + struct { + /** @pt.ops: Page table ops. */ + struct io_pgtable_ops *ops; + + /** @pt.root: Page table root. */ + void *root; + } pt; + + /** + * @op_lock: Lock used to serialize operations on the AS. + * + * The serialization of jobs queued to the VM_BIND queue is already + * taken care of by drm_sched, but we need to serialize synchronous + * and asynchronous VM_BIND request. This is what this lock is for. + */ + struct mutex op_lock; + + /** + * @op_ctx: The context attached to the currently executing operation. + * + * NULL when no operation is in progress. + */ + struct panthor_as_op_ctx *op_ctx; + + /** @active_cnt: Number of active users of this address space. */ + refcount_t active_cnt; + + /** @hw_slot: Hardware slot related fields. */ + struct { + /** + * @hw_slot.id: ID of the slot this AS is bound to. + * + * A value of -1 means the AS is inactive/not bound. + */ + int id; + + /** + * @hw_slot.lru_node: Used to insert the AS in panthor_mmu::as::lru_list. + * + * Active ASs should not be inserted in the LRU list. + */ + struct list_head lru_node; + } hw_slot; + + /** + * @unusable: True if the AS has turned unusable because something + * bad happened during an asynchronous request. + * + * We don't try to recover from such failures, because this implies + * informing userspace about the specific operation that failed, and + * hoping the userspace driver can replay things from there. This all + * sounds very complicated for little gain. + * + * Instead, we should just flag the AS as unusable, and fail any + * further request targeting this AS. + * + * We also provide a way to query an AS state, so userspace can + * destroy it and create a new one. + * + * As an analogy, this would be mapped to a VK_ERROR_DEVICE_LOST + * situation, where the logical device needs to be re-created. + */ + bool unusable; + + /** + * @unhandled_fault: Unhandled fault happened. + * + * This should be reported to the scheduler, and the queue/group be + * flagged as faulty as a result. + */ + bool unhandled_fault; + + /** @locked_region: Information about the currently locked region current= ly. */ + struct { + /** @locked_region.start: Start of the locked region. */ + u64 start; + + /** @locked_region.size: Size of the locked region. */ + u64 size; + } locked_region; + + /** @reclaim: Fields related to BO reclaim. */ + struct { + /** @reclaim.lru: LRU of BOs that are only mapped to this AS. */ + struct drm_gem_lru lru; + + /** + * @reclaim.lru_node: Node used to insert the AS in + * panthor_device::reclaim::vms. + */ + struct list_head lru_node; + } reclaim; +}; + /** * struct panthor_vm - VM object * * A VM is an object representing a GPU (or MCU) virtual address space. - * It embeds the MMU page table for this address space, a tree containing - * all the virtual mappings of GEM objects, and other things needed to man= age - * the VM. * * Except for the MCU VM, which is managed by the kernel, all other VMs are * created by userspace and mostly managed by userspace, using the @@ -233,13 +340,11 @@ struct panthor_vm_op_ctx { * by default). */ struct panthor_vm { - /** - * @base: Inherit from drm_gpuvm. - * - * We delegate all the VA management to the common drm_gpuvm framework - * and only implement hooks to update the MMU page table. - */ - struct drm_gpuvm base; + /** @refcount: VM refcount. */ + struct kref refcount; + + /** @as: VM address space. */ + struct panthor_as *as; =20 /** * @sched: Scheduler used for asynchronous VM_BIND request. @@ -256,34 +361,6 @@ struct panthor_vm { */ struct drm_sched_entity entity; =20 - /** @ptdev: Device. */ - struct panthor_device *ptdev; - - /** @memattr: Value to program to the AS_MEMATTR register. */ - u64 memattr; - - /** @pgtbl_ops: Page table operations. */ - struct io_pgtable_ops *pgtbl_ops; - - /** @root_page_table: Stores the root page table pointer. */ - void *root_page_table; - - /** - * @op_lock: Lock used to serialize operations on a VM. - * - * The serialization of jobs queued to the VM_BIND queue is already - * taken care of by drm_sched, but we need to serialize synchronous - * and asynchronous VM_BIND request. This is what this lock is for. - */ - struct mutex op_lock; - - /** - * @op_ctx: The context attached to the currently executing VM operation. - * - * NULL when no operation is in progress. - */ - struct panthor_vm_op_ctx *op_ctx; - /** * @mm: Memory management object representing the auto-VA/kernel-VA. * @@ -313,26 +390,6 @@ struct panthor_vm { /** @user_va_range: Upper boundary of VAs VM users can map objects agains= t. */ u64 user_va_range; =20 - /** @as: Address space related fields. */ - struct { - /** - * @as.id: ID of the address space this VM is bound to. - * - * A value of -1 means the VM is inactive/not bound. - */ - int id; - - /** @as.active_cnt: Number of active users of this VM. */ - refcount_t active_cnt; - - /** - * @as.lru_node: Used to instead the VM in the panthor_mmu::as::lru_list. - * - * Active VMs should not be inserted in the LRU list. - */ - struct list_head lru_node; - } as; - /** * @heaps: Tiler heap related fields. */ @@ -361,55 +418,6 @@ struct panthor_vm { */ bool destroyed; =20 - /** - * @unusable: True if the VM has turned unusable because something - * bad happened during an asynchronous request. - * - * We don't try to recover from such failures, because this implies - * informing userspace about the specific operation that failed, and - * hoping the userspace driver can replay things from there. This all - * sounds very complicated for little gain. - * - * Instead, we should just flag the VM as unusable, and fail any - * further request targeting this VM. - * - * We also provide a way to query a VM state, so userspace can destroy - * it and create a new one. - * - * As an analogy, this would be mapped to a VK_ERROR_DEVICE_LOST - * situation, where the logical device needs to be re-created. - */ - bool unusable; - - /** - * @unhandled_fault: Unhandled fault happened. - * - * This should be reported to the scheduler, and the queue/group be - * flagged as faulty as a result. - */ - bool unhandled_fault; - - /** @locked_region: Information about the currently locked region current= ly. */ - struct { - /** @locked_region.start: Start of the locked region. */ - u64 start; - - /** @locked_region.size: Size of the locked region. */ - u64 size; - } locked_region; - - /** @reclaim: Fields related to BO reclaim. */ - struct { - /** @reclaim.lru: LRU of BOs that are only mapped to this VM. */ - struct drm_gem_lru lru; - - /** - * @reclaim.lru_node: Node used to insert the VM in - * panthor_device::reclaim::vms. - */ - struct list_head lru_node; - } reclaim; - /** * @dummy: Dummy object used for sparse mappings. * @@ -437,7 +445,7 @@ struct panthor_vm_bind_job { struct panthor_vm *vm; =20 /** @ctx: Operation context. */ - struct panthor_vm_op_ctx ctx; + struct panthor_as_op_ctx ctx; }; =20 /* @@ -466,36 +474,37 @@ static struct kmem_cache *pt_cache; */ static void *alloc_pt(void *cookie, size_t size, gfp_t gfp) { - struct panthor_vm *vm =3D cookie; + struct panthor_as *as =3D cookie; + struct panthor_as_op_ctx *op_ctx =3D as->op_ctx; + struct drm_device *ddev =3D as->base.drm; void *page; =20 /* Allocation of the root page table happening during init. */ - if (unlikely(!vm->root_page_table)) { + if (unlikely(!as->pt.root)) { + struct device *dev =3D drm_dev_dma_dev(ddev); struct page *p; =20 - drm_WARN_ON(&vm->ptdev->base, vm->op_ctx); - p =3D alloc_pages_node(dev_to_node(vm->ptdev->base.dev), - gfp | __GFP_ZERO, get_order(size)); + drm_WARN_ON(ddev, op_ctx); + p =3D alloc_pages_node(dev_to_node(dev), gfp | __GFP_ZERO, get_order(siz= e)); page =3D p ? page_address(p) : NULL; - vm->root_page_table =3D page; + as->pt.root =3D page; return page; } =20 /* We're not supposed to have anything bigger than 4k here, because we pi= cked a * 4k granule size at init time. */ - if (drm_WARN_ON(&vm->ptdev->base, size !=3D SZ_4K)) + if (drm_WARN_ON(ddev, size !=3D SZ_4K)) return NULL; =20 /* We must have some op_ctx attached to the VM and it must have at least = one * free page. */ - if (drm_WARN_ON(&vm->ptdev->base, !vm->op_ctx) || - drm_WARN_ON(&vm->ptdev->base, - vm->op_ctx->rsvd_page_tables.ptr >=3D vm->op_ctx->rsvd_page_tables.coun= t)) + if (drm_WARN_ON(ddev, !op_ctx) || + drm_WARN_ON(ddev, op_ctx->rsvd_page_tables.ptr >=3D op_ctx->rsvd_page= _tables.count)) return NULL; =20 - page =3D vm->op_ctx->rsvd_page_tables.pages[vm->op_ctx->rsvd_page_tables.= ptr++]; + page =3D op_ctx->rsvd_page_tables.pages[op_ctx->rsvd_page_tables.ptr++]; memset(page, 0, SZ_4K); =20 /* Page table entries don't use virtual addresses, which trips out @@ -518,22 +527,23 @@ static void *alloc_pt(void *cookie, size_t size, gfp_= t gfp) */ static void free_pt(void *cookie, void *data, size_t size) { - struct panthor_vm *vm =3D cookie; + struct panthor_as *as =3D cookie; + struct drm_device *ddev =3D as->base.drm; =20 - if (unlikely(vm->root_page_table =3D=3D data)) { + if (unlikely(as->pt.root =3D=3D data)) { free_pages((unsigned long)data, get_order(size)); - vm->root_page_table =3D NULL; + as->pt.root =3D NULL; return; } =20 - if (drm_WARN_ON(&vm->ptdev->base, size !=3D SZ_4K)) + if (drm_WARN_ON(ddev, size !=3D SZ_4K)) return; =20 /* Return the page to the pt_cache. */ kmem_cache_free(pt_cache, data); } =20 -static int wait_ready(struct panthor_device *ptdev, u32 as_nr) +static int wait_ready(struct panthor_device *ptdev, u32 slot) { struct panthor_mmu *mmu =3D ptdev->mmu; int ret; @@ -542,7 +552,7 @@ static int wait_ready(struct panthor_device *ptdev, u32= as_nr) /* Wait for the MMU status to indicate there is no active command, in * case one is pending. */ - ret =3D gpu_read_relaxed_poll_timeout_atomic(mmu->iomem, AS_STATUS(as_nr)= , val, + ret =3D gpu_read_relaxed_poll_timeout_atomic(mmu->iomem, AS_STATUS(slot),= val, !(val & AS_STATUS_AS_ACTIVE), 10, 100000); =20 if (ret) { @@ -553,15 +563,15 @@ static int wait_ready(struct panthor_device *ptdev, u= 32 as_nr) return ret; } =20 -static int as_send_cmd_and_wait(struct panthor_device *ptdev, u32 as_nr, u= 32 cmd) +static int as_send_cmd_and_wait(struct panthor_device *ptdev, u32 slot, u3= 2 cmd) { int status; =20 /* write AS_COMMAND when MMU is ready to accept another command */ - status =3D wait_ready(ptdev, as_nr); + status =3D wait_ready(ptdev, slot); if (!status) { - gpu_write(ptdev->mmu->iomem, AS_COMMAND(as_nr), cmd); - status =3D wait_ready(ptdev, as_nr); + gpu_write(ptdev->mmu->iomem, AS_COMMAND(slot), cmd); + status =3D wait_ready(ptdev, slot); } =20 return status; @@ -596,41 +606,41 @@ static u64 pack_region_range(struct panthor_device *p= tdev, u64 *region_start, u6 return region_width | *region_start; } =20 -static u32 panthor_mmu_as_fault_mask(struct panthor_device *ptdev, u32 as) +static u32 panthor_mmu_as_fault_mask(struct panthor_device *ptdev, u32 slo= t) { - return BIT(as); + return BIT(slot); } =20 /* Forward declaration to call helpers within as_enable/disable */ static void panthor_mmu_irq_handler(struct panthor_device *ptdev, u32 stat= us); PANTHOR_IRQ_HANDLER(mmu, panthor_mmu_irq_handler); =20 -static int panthor_mmu_as_enable(struct panthor_device *ptdev, u32 as_nr, +static int panthor_mmu_as_enable(struct panthor_device *ptdev, u32 slot, u64 transtab, u64 transcfg, u64 memattr) { struct panthor_mmu *mmu =3D ptdev->mmu; =20 panthor_mmu_irq_enable_events(&ptdev->mmu->irq, - panthor_mmu_as_fault_mask(ptdev, as_nr)); + panthor_mmu_as_fault_mask(ptdev, slot)); =20 - gpu_write64(mmu->iomem, AS_TRANSTAB(as_nr), transtab); - gpu_write64(mmu->iomem, AS_MEMATTR(as_nr), memattr); - gpu_write64(mmu->iomem, AS_TRANSCFG(as_nr), transcfg); + gpu_write64(mmu->iomem, AS_TRANSTAB(slot), transtab); + gpu_write64(mmu->iomem, AS_MEMATTR(slot), memattr); + gpu_write64(mmu->iomem, AS_TRANSCFG(slot), transcfg); =20 - return as_send_cmd_and_wait(ptdev, as_nr, AS_COMMAND_UPDATE); + return as_send_cmd_and_wait(ptdev, slot, AS_COMMAND_UPDATE); } =20 -static int panthor_mmu_as_disable(struct panthor_device *ptdev, u32 as_nr, +static int panthor_mmu_as_disable(struct panthor_device *ptdev, u32 slot, bool recycle_slot) { struct panthor_mmu *mmu =3D ptdev->mmu; - struct panthor_vm *vm =3D ptdev->mmu->as.slots[as_nr].vm; + struct panthor_as *as =3D ptdev->mmu->as.slots[slot].as; int ret; =20 lockdep_assert_held(&ptdev->mmu->as.slots_lock); =20 panthor_mmu_irq_disable_events(&ptdev->mmu->irq, - panthor_mmu_as_fault_mask(ptdev, as_nr)); + panthor_mmu_as_fault_mask(ptdev, slot)); =20 /* Flush+invalidate RW caches, invalidate RO ones. */ ret =3D panthor_gpu_flush_caches(ptdev, CACHE_CLEAN | CACHE_INV, @@ -638,9 +648,9 @@ static int panthor_mmu_as_disable(struct panthor_device= *ptdev, u32 as_nr, if (ret) return ret; =20 - if (vm && vm->locked_region.size) { + if (as && as->locked_region.size) { /* Unlock the region if there's a lock pending. */ - ret =3D as_send_cmd_and_wait(ptdev, vm->as.id, AS_COMMAND_UNLOCK); + ret =3D as_send_cmd_and_wait(ptdev, slot, AS_COMMAND_UNLOCK); if (ret) return ret; } @@ -651,11 +661,11 @@ static int panthor_mmu_as_disable(struct panthor_devi= ce *ptdev, u32 as_nr, if (recycle_slot) return 0; =20 - gpu_write64(mmu->iomem, AS_TRANSTAB(as_nr), 0); - gpu_write64(mmu->iomem, AS_MEMATTR(as_nr), 0); - gpu_write64(mmu->iomem, AS_TRANSCFG(as_nr), AS_TRANSCFG_ADRMODE_UNMAPPED); + gpu_write64(mmu->iomem, AS_TRANSTAB(slot), 0); + gpu_write64(mmu->iomem, AS_MEMATTR(slot), 0); + gpu_write64(mmu->iomem, AS_TRANSCFG(slot), AS_TRANSCFG_ADRMODE_UNMAPPED); =20 - return as_send_cmd_and_wait(ptdev, as_nr, AS_COMMAND_UPDATE); + return as_send_cmd_and_wait(ptdev, slot, AS_COMMAND_UPDATE); } =20 static u32 panthor_mmu_fault_mask(struct panthor_device *ptdev, u32 value) @@ -672,7 +682,7 @@ static u32 panthor_mmu_fault_mask(struct panthor_device= *ptdev, u32 value) */ bool panthor_vm_has_unhandled_faults(struct panthor_vm *vm) { - return vm->unhandled_fault; + return vm->as->unhandled_fault; } =20 /** @@ -683,23 +693,23 @@ bool panthor_vm_has_unhandled_faults(struct panthor_v= m *vm) */ bool panthor_vm_is_unusable(struct panthor_vm *vm) { - return vm->unusable; + return vm->as->unusable; } =20 -static void panthor_vm_release_as_locked(struct panthor_vm *vm) +static void panthor_as_release_hw_slot_locked(struct panthor_as *as) { - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); =20 lockdep_assert_held(&ptdev->mmu->as.slots_lock); =20 - if (drm_WARN_ON(&ptdev->base, vm->as.id < 0)) + if (drm_WARN_ON(&ptdev->base, as->hw_slot.id < 0)) return; =20 - ptdev->mmu->as.slots[vm->as.id].vm =3D NULL; - clear_bit(vm->as.id, &ptdev->mmu->as.alloc_mask); - refcount_set(&vm->as.active_cnt, 0); - list_del_init(&vm->as.lru_node); - vm->as.id =3D -1; + ptdev->mmu->as.slots[as->hw_slot.id].as =3D NULL; + clear_bit(as->hw_slot.id, &ptdev->mmu->as.alloc_mask); + refcount_set(&as->active_cnt, 0); + list_del_init(&as->hw_slot.lru_node); + as->hw_slot.id =3D -1; } =20 /** @@ -712,17 +722,18 @@ static void panthor_vm_release_as_locked(struct panth= or_vm *vm) */ int panthor_vm_active(struct panthor_vm *vm) { - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_as *as =3D vm->as; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); u32 va_bits =3D GPU_MMU_FEATURES_VA_BITS(ptdev->gpu_info.mmu_features); - struct io_pgtable_cfg *cfg =3D &io_pgtable_ops_to_pgtable(vm->pgtbl_ops)-= >cfg; - int ret =3D 0, as, cookie; + struct io_pgtable_cfg *cfg =3D &io_pgtable_ops_to_pgtable(as->pt.ops)->cf= g; + int ret =3D 0, slot, cookie; u64 transtab, transcfg; u32 fault_mask; =20 if (!drm_dev_enter(&ptdev->base, &cookie)) return -ENODEV; =20 - if (refcount_inc_not_zero(&vm->as.active_cnt)) + if (refcount_inc_not_zero(&as->active_cnt)) goto out_dev_exit; =20 /* As soon as active is called, we place the VM at the end of the VM LRU. @@ -731,25 +742,25 @@ int panthor_vm_active(struct panthor_vm *vm) * that's an acceptable trade-off. */ mutex_lock(&ptdev->base.gem_lru_mutex); - if (vm->reclaim.lru.count) - list_move_tail(&vm->reclaim.lru_node, &ptdev->reclaim.vms); + if (as->reclaim.lru.count) + list_move_tail(&as->reclaim.lru_node, &ptdev->reclaim.vms); mutex_unlock(&ptdev->base.gem_lru_mutex); =20 /* Make sure we don't race with lock/unlock_region() calls * happening around VM bind operations. */ - mutex_lock(&vm->op_lock); + mutex_lock(&as->op_lock); mutex_lock(&ptdev->mmu->as.slots_lock); =20 - if (refcount_inc_not_zero(&vm->as.active_cnt)) + if (refcount_inc_not_zero(&as->active_cnt)) goto out_unlock; =20 - as =3D vm->as.id; - if (as >=3D 0) { + slot =3D as->hw_slot.id; + if (slot >=3D 0) { /* Unhandled pagefault on this AS, the MMU was disabled. We need to * re-enable the MMU after clearing+unmasking the AS interrupts. */ - if (ptdev->mmu->as.faulty_mask & panthor_mmu_as_fault_mask(ptdev, as)) + if (ptdev->mmu->as.faulty_mask & panthor_mmu_as_fault_mask(ptdev, slot)) goto out_enable_as; =20 goto out_make_active; @@ -758,36 +769,36 @@ int panthor_vm_active(struct panthor_vm *vm) /* Check for a free AS */ if (vm->for_mcu) { drm_WARN_ON(&ptdev->base, ptdev->mmu->as.alloc_mask & BIT(0)); - as =3D 0; + slot =3D 0; } else { - as =3D ffz(ptdev->mmu->as.alloc_mask | BIT(0)); + slot =3D ffz(ptdev->mmu->as.alloc_mask | BIT(0)); } =20 - if (!(BIT(as) & ptdev->gpu_info.as_present)) { - struct panthor_vm *lru_vm; + if (!(BIT(slot) & ptdev->gpu_info.as_present)) { + struct panthor_as *lru_as; =20 - lru_vm =3D list_first_entry_or_null(&ptdev->mmu->as.lru_list, - struct panthor_vm, - as.lru_node); - if (drm_WARN_ON(&ptdev->base, !lru_vm)) { + lru_as =3D list_first_entry_or_null(&ptdev->mmu->as.lru_list, + struct panthor_as, + hw_slot.lru_node); + if (drm_WARN_ON(&ptdev->base, !lru_as)) { ret =3D -EBUSY; goto out_unlock; } =20 - drm_WARN_ON(&ptdev->base, refcount_read(&lru_vm->as.active_cnt)); - as =3D lru_vm->as.id; + drm_WARN_ON(&ptdev->base, refcount_read(&lru_as->active_cnt)); + slot =3D lru_as->hw_slot.id; =20 - ret =3D panthor_mmu_as_disable(ptdev, as, true); + ret =3D panthor_mmu_as_disable(ptdev, slot, true); if (ret) goto out_unlock; =20 - panthor_vm_release_as_locked(lru_vm); + panthor_as_release_hw_slot_locked(lru_as); } =20 /* Assign the free or reclaimed AS to the FD */ - vm->as.id =3D as; - set_bit(as, &ptdev->mmu->as.alloc_mask); - ptdev->mmu->as.slots[as].vm =3D vm; + as->hw_slot.id =3D slot; + set_bit(slot, &ptdev->mmu->as.alloc_mask); + ptdev->mmu->as.slots[slot].as =3D as; =20 out_enable_as: transtab =3D cfg->arm_lpae_s1_cfg.ttbr; @@ -799,12 +810,12 @@ int panthor_vm_active(struct panthor_vm *vm) transcfg |=3D AS_TRANSCFG_PTW_SH_OS; =20 /* If the VM is re-activated, we clear the fault. */ - vm->unhandled_fault =3D false; + as->unhandled_fault =3D false; =20 /* Unhandled pagefault on this AS, clear the fault and enable the AS, * which re-enables interrupts. */ - fault_mask =3D panthor_mmu_as_fault_mask(ptdev, as); + fault_mask =3D panthor_mmu_as_fault_mask(ptdev, slot); if (ptdev->mmu->as.faulty_mask & fault_mask) { gpu_write(ptdev->mmu->irq.iomem, INT_CLEAR, fault_mask); ptdev->mmu->as.faulty_mask &=3D ~fault_mask; @@ -813,18 +824,18 @@ int panthor_vm_active(struct panthor_vm *vm) /* The VM update is guarded by ::op_lock, which we take at the beginning * of this function, so we don't expect any locked region here. */ - drm_WARN_ON(&vm->ptdev->base, vm->locked_region.size > 0); - ret =3D panthor_mmu_as_enable(vm->ptdev, vm->as.id, transtab, transcfg, v= m->memattr); + drm_WARN_ON(&ptdev->base, as->locked_region.size > 0); + ret =3D panthor_mmu_as_enable(ptdev, as->hw_slot.id, transtab, transcfg, = as->memattr); =20 out_make_active: if (!ret) { - refcount_set(&vm->as.active_cnt, 1); - list_del_init(&vm->as.lru_node); + refcount_set(&as->active_cnt, 1); + list_del_init(&as->hw_slot.lru_node); } =20 out_unlock: mutex_unlock(&ptdev->mmu->as.slots_lock); - mutex_unlock(&vm->op_lock); + mutex_unlock(&as->op_lock); =20 out_dev_exit: drm_dev_exit(cookie); @@ -846,21 +857,22 @@ int panthor_vm_active(struct panthor_vm *vm) */ void panthor_vm_idle(struct panthor_vm *vm) { - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_as *as =3D vm->as; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); =20 - if (!refcount_dec_and_mutex_lock(&vm->as.active_cnt, &ptdev->mmu->as.slot= s_lock)) + if (!refcount_dec_and_mutex_lock(&as->active_cnt, &ptdev->mmu->as.slots_l= ock)) return; =20 - if (!drm_WARN_ON(&ptdev->base, vm->as.id =3D=3D -1 || !list_empty(&vm->as= .lru_node))) - list_add_tail(&vm->as.lru_node, &ptdev->mmu->as.lru_list); + if (!drm_WARN_ON(&ptdev->base, as->hw_slot.id =3D=3D -1 || !list_empty(&a= s->hw_slot.lru_node))) + list_add_tail(&as->hw_slot.lru_node, &ptdev->mmu->as.lru_list); =20 - refcount_set(&vm->as.active_cnt, 0); + refcount_set(&as->active_cnt, 0); mutex_unlock(&ptdev->mmu->as.slots_lock); } =20 u32 panthor_vm_page_size(struct panthor_vm *vm) { - const struct io_pgtable *pgt =3D io_pgtable_ops_to_pgtable(vm->pgtbl_ops); + const struct io_pgtable *pgt =3D io_pgtable_ops_to_pgtable(vm->as->pt.ops= ); u32 pg_shift =3D ffs(pgt->cfg.pgsize_bitmap) - 1; =20 return 1u << pg_shift; @@ -884,7 +896,7 @@ static void panthor_vm_start(struct panthor_vm *vm) */ int panthor_vm_as(struct panthor_vm *vm) { - return vm->as.id; + return vm->as->hw_slot.id; } =20 static size_t get_pgsize(u64 addr, size_t size, size_t *count) @@ -908,43 +920,43 @@ static size_t get_pgsize(u64 addr, size_t size, size_= t *count) return SZ_2M; } =20 -static void panthor_vm_declare_unusable(struct panthor_vm *vm) +static void panthor_as_declare_unusable(struct panthor_as *as) { - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); int cookie; =20 - if (vm->unusable) + if (as->unusable) return; =20 - vm->unusable =3D true; + as->unusable =3D true; mutex_lock(&ptdev->mmu->as.slots_lock); - if (vm->as.id >=3D 0 && drm_dev_enter(&ptdev->base, &cookie)) { - panthor_mmu_as_disable(ptdev, vm->as.id, false); + if (as->hw_slot.id >=3D 0 && drm_dev_enter(&ptdev->base, &cookie)) { + panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); drm_dev_exit(cookie); } mutex_unlock(&ptdev->mmu->as.slots_lock); } =20 -static void panthor_vm_unmap_pages(struct panthor_vm *vm, u64 iova, u64 si= ze) +static void panthor_as_unmap_pages(struct panthor_as *as, u64 iova, u64 si= ze) { - struct panthor_device *ptdev =3D vm->ptdev; - struct io_pgtable_ops *ops =3D vm->pgtbl_ops; + struct drm_device *ddev =3D as->base.drm; + struct io_pgtable_ops *ops =3D as->pt.ops; u64 start_iova =3D iova; u64 offset =3D 0; =20 if (!size) return; =20 - drm_WARN_ON(&ptdev->base, - (iova < vm->locked_region.start) || - (iova + size > vm->locked_region.start + vm->locked_region.size)); + drm_WARN_ON(ddev, + (iova < as->locked_region.start) || + (iova + size > as->locked_region.start + as->locked_region.size)); =20 while (offset < size) { size_t unmapped_sz =3D 0, pgcount; size_t pgsize =3D get_pgsize(iova + offset, size - offset, &pgcount); =20 unmapped_sz =3D ops->unmap_pages(ops, iova + offset, pgsize, pgcount, NU= LL); - if (drm_WARN_ON_ONCE(&ptdev->base, unmapped_sz !=3D pgsize * pgcount)) { + if (drm_WARN_ON_ONCE(ddev, unmapped_sz !=3D pgsize * pgcount)) { /* Gracefully handle sparsely unmapped regions to avoid leaving * page table pages behind when the drm_gpuvm and VM page table * are out-of-sync. This is not supposed to happen, hence the @@ -958,33 +970,32 @@ static void panthor_vm_unmap_pages(struct panthor_vm = *vm, u64 iova, u64 size) * so flag the VM unusable to make sure it's not going * to be used anymore. */ - panthor_vm_declare_unusable(vm); + panthor_as_declare_unusable(as); =20 /* If we don't make progress, we're screwed. That also means * something else prevents us from unmapping the region, but * there's not much we can do here: time for debugging. */ - if (drm_WARN_ON_ONCE(&ptdev->base, !unmapped_sz)) + if (drm_WARN_ON_ONCE(ddev, !unmapped_sz)) return; } =20 - drm_dbg(&ptdev->base, - "unmap: as=3D%d, iova=3D0x%llx, sz=3D%llu, va=3D0x%llx, pgcnt=3D%zu, pg= sz=3D%zu", - vm->as.id, start_iova, size, iova + offset, - unmapped_sz / pgsize, pgsize); + drm_dbg(ddev, + "unmap: iova=3D0x%llx, sz=3D%llu, va=3D0x%llx, pgcnt=3D%zu, pgsz=3D%zu", + start_iova, size, iova + offset, unmapped_sz / pgsize, pgsize); =20 offset +=3D unmapped_sz; } } =20 static int -panthor_vm_map_pages(struct panthor_vm *vm, u64 iova, int prot, +panthor_as_map_pages(struct panthor_as *as, u64 iova, int prot, struct sg_table *sgt, u64 offset, u64 size) { - struct panthor_device *ptdev =3D vm->ptdev; + struct drm_device *ddev =3D as->base.drm; unsigned int count; struct scatterlist *sgl; - struct io_pgtable_ops *ops =3D vm->pgtbl_ops; + struct io_pgtable_ops *ops =3D as->pt.ops; u64 start_iova =3D iova; u64 start_size =3D size; int ret; @@ -992,9 +1003,9 @@ panthor_vm_map_pages(struct panthor_vm *vm, u64 iova, = int prot, if (!size) return 0; =20 - drm_WARN_ON(&ptdev->base, - (iova < vm->locked_region.start) || - (iova + size > vm->locked_region.start + vm->locked_region.size)); + drm_WARN_ON(ddev, + (iova < as->locked_region.start) || + (iova + size > as->locked_region.start + as->locked_region.size)); =20 for_each_sgtable_dma_sg(sgt, sgl, count) { dma_addr_t paddr =3D sg_dma_address(sgl); @@ -1017,10 +1028,9 @@ panthor_vm_map_pages(struct panthor_vm *vm, u64 iova= , int prot, ret =3D ops->map_pages(ops, iova, paddr, pgsize, pgcount, prot, GFP_KERNEL, &mapped); =20 - drm_dbg(&ptdev->base, - "map: as=3D%d, iova=3D0x%llx, sz=3D%llu, va=3D0x%llx, pa=3D%pad, pgcnt= =3D%zu, pgsz=3D%zu", - vm->as.id, start_iova, start_size, iova, &paddr, - mapped / pgsize, pgsize); + drm_dbg(ddev, + "map: iova=3D0x%llx, sz=3D%llu, va=3D0x%llx, pa=3D%pad, pgcnt=3D%zu, p= gsz=3D%zu", + start_iova, start_size, iova, &paddr, mapped / pgsize, pgsize); =20 iova +=3D mapped; paddr +=3D mapped; @@ -1031,12 +1041,12 @@ panthor_vm_map_pages(struct panthor_vm *vm, u64 iov= a, int prot, ret =3D -ENOMEM; =20 /* If something fails, we stop there, and flag the VM unusable. */ - if (drm_WARN_ON_ONCE(&ptdev->base, ret)) { + if (drm_WARN_ON_ONCE(ddev, ret)) { /* Unmap what we've already mapped to avoid leaving page * table pages behind. */ - panthor_vm_unmap_pages(vm, start_iova, iova - start_iova); - panthor_vm_declare_unusable(vm); + panthor_as_unmap_pages(as, start_iova, iova - start_iova); + panthor_as_declare_unusable(as); return ret; } } @@ -1051,8 +1061,8 @@ panthor_vm_map_pages(struct panthor_vm *vm, u64 iova,= int prot, } =20 static int -panthor_vm_map_sparse(struct panthor_vm *vm, u64 iova, int prot, - struct sg_table *sgt, u64 size) +panthor_as_map_sparse(struct panthor_as *as, u64 iova, + int prot, struct sg_table *sgt, u64 size) { u64 mapped =3D 0; int ret; @@ -1061,10 +1071,10 @@ panthor_vm_map_sparse(struct panthor_vm *vm, u64 io= va, int prot, u64 addr =3D iova + mapped; u32 chunk_size =3D min(size - mapped, SZ_2M - (addr & (SZ_2M - 1))); =20 - ret =3D panthor_vm_map_pages(vm, addr, prot, sgt, + ret =3D panthor_as_map_pages(as, addr, prot, sgt, addr % SZ_2M, chunk_size); if (ret) { - panthor_vm_unmap_pages(vm, iova, mapped); + panthor_as_unmap_pages(as, iova, mapped); return ret; } =20 @@ -1166,8 +1176,8 @@ static void panthor_vm_bo_free(struct drm_gpuvm_bo *v= m_bo) kfree(vm_bo); } =20 -static void panthor_vm_cleanup_op_ctx(struct panthor_vm_op_ctx *op_ctx, - struct panthor_vm *vm) +static void panthor_as_cleanup_op_ctx(struct panthor_as_op_ctx *op_ctx, + struct panthor_as *as) { u32 remaining_pt_count =3D op_ctx->rsvd_page_tables.count - op_ctx->rsvd_page_tables.ptr; @@ -1202,11 +1212,11 @@ static void panthor_vm_cleanup_op_ctx(struct pantho= r_vm_op_ctx *op_ctx, kfree(op_ctx->preallocated_vmas[i]); =20 if (!skip_deferred_cleanup) - drm_gpuvm_bo_deferred_cleanup(&vm->base); + drm_gpuvm_bo_deferred_cleanup(&as->base); } =20 static void -panthor_vm_op_ctx_return_vma(struct panthor_vm_op_ctx *op_ctx, +panthor_as_op_ctx_return_vma(struct panthor_as_op_ctx *op_ctx, struct panthor_vma *vma) { for (u32 i =3D 0; i < ARRAY_SIZE(op_ctx->preallocated_vmas); i++) { @@ -1220,7 +1230,7 @@ panthor_vm_op_ctx_return_vma(struct panthor_vm_op_ctx= *op_ctx, } =20 static struct panthor_vma * -panthor_vm_op_ctx_get_vma(struct panthor_vm_op_ctx *op_ctx) +panthor_as_op_ctx_get_vma(struct panthor_as_op_ctx *op_ctx) { for (u32 i =3D 0; i < ARRAY_SIZE(op_ctx->preallocated_vmas); i++) { struct panthor_vma *vma =3D op_ctx->preallocated_vmas[i]; @@ -1235,7 +1245,7 @@ panthor_vm_op_ctx_get_vma(struct panthor_vm_op_ctx *o= p_ctx) } =20 static int -panthor_vm_op_ctx_prealloc_vmas(struct panthor_vm_op_ctx *op_ctx) +panthor_as_op_ctx_prealloc_vmas(struct panthor_as_op_ctx *op_ctx) { u32 vma_count; =20 @@ -1274,7 +1284,7 @@ panthor_vm_op_ctx_prealloc_vmas(struct panthor_vm_op_= ctx *op_ctx) return 0; } =20 -static void panthor_vm_init_op_ctx(struct panthor_vm_op_ctx *op_ctx, +static void panthor_vm_init_op_ctx(struct panthor_as_op_ctx *op_ctx, u64 size, u64 va, u32 flags) { memset(op_ctx, 0, sizeof(*op_ctx)); @@ -1283,7 +1293,7 @@ static void panthor_vm_init_op_ctx(struct panthor_vm_= op_ctx *op_ctx, op_ctx->va.addr =3D va; } =20 -static int panthor_vm_op_ctx_prealloc_pts(struct panthor_vm_op_ctx *op_ctx) +static int panthor_as_op_ctx_prealloc_pts(struct panthor_as_op_ctx *op_ctx) { u64 size =3D op_ctx->va.range; u64 va =3D op_ctx->va.addr; @@ -1319,8 +1329,8 @@ static int panthor_vm_op_ctx_prealloc_pts(struct pant= hor_vm_op_ctx *op_ctx) DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE | \ DRM_PANTHOR_VM_BIND_OP_TYPE_MASK) =20 -static int panthor_vm_prepare_map_op_ctx(struct panthor_vm_op_ctx *op_ctx, - struct panthor_vm *vm, +static int panthor_as_prepare_map_op_ctx(struct panthor_as_op_ctx *op_ctx, + struct panthor_as *as, struct panthor_gem_object *bo, const struct drm_panthor_vm_bind_op *op) { @@ -1355,12 +1365,12 @@ static int panthor_vm_prepare_map_op_ctx(struct pan= thor_vm_op_ctx *op_ctx, =20 /* If the BO has an exclusive VM attached, it can't be mapped to other VM= s. */ if (bo->exclusive_vm_root_gem && - bo->exclusive_vm_root_gem !=3D panthor_vm_root_gem(vm)) + bo->exclusive_vm_root_gem !=3D as->base.r_obj) return -EINVAL; =20 panthor_vm_init_op_ctx(op_ctx, op->size, op->va, op->flags); =20 - ret =3D panthor_vm_op_ctx_prealloc_vmas(op_ctx); + ret =3D panthor_as_op_ctx_prealloc_vmas(op_ctx); if (ret) goto err_cleanup; =20 @@ -1380,7 +1390,7 @@ static int panthor_vm_prepare_map_op_ctx(struct panth= or_vm_op_ctx *op_ctx, goto err_cleanup; } =20 - preallocated_vm_bo =3D drm_gpuvm_bo_create(&vm->base, &bo->base); + preallocated_vm_bo =3D drm_gpuvm_bo_create(&as->base, &bo->base); if (!preallocated_vm_bo) { ret =3D -ENOMEM; goto err_cleanup; @@ -1389,15 +1399,15 @@ static int panthor_vm_prepare_map_op_ctx(struct pan= thor_vm_op_ctx *op_ctx, op_ctx->map.vm_bo =3D drm_gpuvm_bo_obtain_prealloc(preallocated_vm_bo); op_ctx->map.bo_offset =3D op->bo_offset; =20 - ret =3D panthor_vm_op_ctx_prealloc_pts(op_ctx); + ret =3D panthor_as_op_ctx_prealloc_pts(op_ctx); if (ret) goto err_cleanup; =20 /* Insert BO into the extobj list last, when we know nothing can fail. */ - if (bo->base.resv !=3D panthor_vm_resv(vm)) { - dma_resv_lock(panthor_vm_resv(vm), NULL); + if (bo->base.resv !=3D drm_gpuvm_resv(&as->base)) { + dma_resv_lock(drm_gpuvm_resv(&as->base), NULL); drm_gpuvm_bo_extobj_add(op_ctx->map.vm_bo); - dma_resv_unlock(panthor_vm_resv(vm)); + dma_resv_unlock(drm_gpuvm_resv(&as->base)); } =20 /* And finally update the BO state. */ @@ -1410,12 +1420,12 @@ static int panthor_vm_prepare_map_op_ctx(struct pan= thor_vm_op_ctx *op_ctx, return 0; =20 err_cleanup: - panthor_vm_cleanup_op_ctx(op_ctx, vm); + panthor_as_cleanup_op_ctx(op_ctx, as); return ret; } =20 -static int panthor_vm_prepare_unmap_op_ctx(struct panthor_vm_op_ctx *op_ct= x, - struct panthor_vm *vm, +static int panthor_as_prepare_unmap_op_ctx(struct panthor_as_op_ctx *op_ct= x, + struct panthor_as *as, u64 va, u64 size) { u32 pt_count =3D 0; @@ -1436,7 +1446,7 @@ static int panthor_vm_prepare_unmap_op_ctx(struct pan= thor_vm_op_ctx *op_ctx, ALIGN(va + size, SZ_2M) !=3D ALIGN(va, SZ_2M)) pt_count++; =20 - ret =3D panthor_vm_op_ctx_prealloc_vmas(op_ctx); + ret =3D panthor_as_op_ctx_prealloc_vmas(op_ctx); if (ret) goto err_cleanup; =20 @@ -1459,12 +1469,12 @@ static int panthor_vm_prepare_unmap_op_ctx(struct p= anthor_vm_op_ctx *op_ctx, return 0; =20 err_cleanup: - panthor_vm_cleanup_op_ctx(op_ctx, vm); + panthor_as_cleanup_op_ctx(op_ctx, as); return ret; } =20 static void -panthor_vm_prepare_sync_only_op_ctx(struct panthor_vm_op_ctx *op_ctx) +panthor_as_prepare_sync_only_op_ctx(struct panthor_as_op_ctx *op_ctx) { memset(op_ctx, 0, sizeof(*op_ctx)); op_ctx->flags =3D DRM_PANTHOR_VM_BIND_OP_TYPE_SYNC_ONLY; @@ -1492,8 +1502,8 @@ panthor_vm_get_bo_for_va(struct panthor_vm *vm, u64 v= a, u64 *bo_offset) struct panthor_vma *vma; =20 /* Take the VM lock to prevent concurrent map/unmap operations. */ - mutex_lock(&vm->op_lock); - gpuva =3D drm_gpuva_find_first(&vm->base, va, 1); + mutex_lock(&vm->as->op_lock); + gpuva =3D drm_gpuva_find_first(&vm->as->base, va, 1); vma =3D gpuva ? container_of(gpuva, struct panthor_vma, base) : NULL; if (vma && vma->base.gem.obj) { drm_gem_object_get(vma->base.gem.obj); @@ -1502,7 +1512,7 @@ panthor_vm_get_bo_for_va(struct panthor_vm *vm, u64 v= a, u64 *bo_offset) vma->base.gem.offset + (va - vma->base.va.addr) : va & (SZ_2M - 1); } - mutex_unlock(&vm->op_lock); + mutex_unlock(&vm->as->op_lock); =20 return bo; } @@ -1622,22 +1632,24 @@ int panthor_vm_pool_create_vm(struct panthor_device= *ptdev, =20 static void panthor_vm_destroy(struct panthor_vm *vm) { + struct panthor_as *as; + struct panthor_device *ptdev; + if (!vm) return; =20 + as =3D vm->as; + ptdev =3D container_of(as->base.drm, struct panthor_device, base); vm->destroyed =3D true; =20 /* Tell scheduler to stop all GPU work related to this VM */ - if (refcount_read(&vm->as.active_cnt) > 0) - panthor_sched_prepare_for_vm_destruction(vm->ptdev); + if (refcount_read(&as->active_cnt) > 0) + panthor_sched_prepare_for_vm_destruction(ptdev); =20 mutex_lock(&vm->heaps.lock); panthor_heap_pool_destroy(vm->heaps.pool); vm->heaps.pool =3D NULL; mutex_unlock(&vm->heaps.lock); - - drm_WARN_ON(&vm->ptdev->base, - panthor_vm_unmap_range(vm, vm->base.mm_start, vm->base.mm_range)); panthor_vm_put(vm); } =20 @@ -1777,17 +1789,18 @@ static const char *access_type_name(struct panthor_= device *ptdev, } } =20 -static int panthor_vm_lock_region(struct panthor_vm *vm, u64 start, u64 si= ze) +static int panthor_as_lock_region(struct panthor_as *as, u64 start, u64 si= ze) { - struct panthor_device *ptdev =3D vm->ptdev; + struct drm_device *ddev =3D as->base.drm; + struct panthor_device *ptdev =3D container_of(ddev, struct panthor_device= , base); int ret =3D 0; =20 - /* sm_step_remap() can call panthor_vm_lock_region() to account for + /* sm_step_remap() can call panthor_as_lock_region() to account for * the wider unmap needed when doing a partial huge page unamp. We * need to ignore the lock if it's already part of the locked region. */ - if (start >=3D vm->locked_region.start && - start + size <=3D vm->locked_region.start + vm->locked_region.size) + if (start >=3D as->locked_region.start && + start + size <=3D as->locked_region.start + as->locked_region.size) return 0; =20 /* sm_step_remap() may need a locked region that isn't a strict superset @@ -1798,42 +1811,42 @@ static int panthor_vm_lock_region(struct panthor_vm= *vm, u64 start, u64 size) * boundaries in a remap operation can only shift up or down respectively, * but never otherwise. */ - if (vm->locked_region.size) { - u64 end =3D max(vm->locked_region.start + vm->locked_region.size, + if (as->locked_region.size) { + u64 end =3D max(as->locked_region.start + as->locked_region.size, start + size); =20 - drm_WARN_ON_ONCE(&vm->ptdev->base, (start + size <=3D vm->locked_region.= start) || - (start >=3D vm->locked_region.start + vm->locked_region.size)); + drm_WARN_ON_ONCE(ddev, (start + size <=3D as->locked_region.start) || + (start >=3D as->locked_region.start + as->locked_region.size)); =20 - start =3D min(start, vm->locked_region.start); + start =3D min(start, as->locked_region.start); size =3D end - start; } =20 mutex_lock(&ptdev->mmu->as.slots_lock); - if (vm->as.id >=3D 0 && size) { + if (as->hw_slot.id >=3D 0 && size) { /* Lock the region that needs to be updated */ - gpu_write64(ptdev->mmu->iomem, AS_LOCKADDR(vm->as.id), + gpu_write64(ptdev->mmu->iomem, AS_LOCKADDR(as->hw_slot.id), pack_region_range(ptdev, &start, &size)); =20 /* If the lock succeeded, update the locked_region info. */ - ret =3D as_send_cmd_and_wait(ptdev, vm->as.id, AS_COMMAND_LOCK); + ret =3D as_send_cmd_and_wait(ptdev, as->hw_slot.id, AS_COMMAND_LOCK); } =20 if (!ret) { - vm->locked_region.start =3D start; - vm->locked_region.size =3D size; + as->locked_region.start =3D start; + as->locked_region.size =3D size; } mutex_unlock(&ptdev->mmu->as.slots_lock); =20 return ret; } =20 -static void panthor_vm_unlock_region(struct panthor_vm *vm) +static void panthor_as_unlock_region(struct panthor_as *as) { - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); =20 mutex_lock(&ptdev->mmu->as.slots_lock); - if (vm->as.id >=3D 0) { + if (as->hw_slot.id >=3D 0) { int ret; =20 /* flush+invalidate RW caches and invalidate RO ones. @@ -1846,7 +1859,7 @@ static void panthor_vm_unlock_region(struct panthor_v= m *vm) =20 /* Unlock the region if the flush is effective. */ if (!ret) - ret =3D as_send_cmd_and_wait(ptdev, vm->as.id, AS_COMMAND_UNLOCK); + ret =3D as_send_cmd_and_wait(ptdev, as->hw_slot.id, AS_COMMAND_UNLOCK); =20 /* If we fail to flush or unlock the region, schedule a GPU reset * to unblock the situation. @@ -1854,8 +1867,8 @@ static void panthor_vm_unlock_region(struct panthor_v= m *vm) if (ret) panthor_device_schedule_reset(ptdev); } - vm->locked_region.start =3D 0; - vm->locked_region.size =3D 0; + as->locked_region.start =3D 0; + as->locked_region.size =3D 0; mutex_unlock(&ptdev->mmu->as.slots_lock); } =20 @@ -1908,8 +1921,8 @@ static void panthor_mmu_irq_handler(struct panthor_de= vice *ptdev, u32 status) */ gpu_write(mmu->irq.iomem, INT_CLEAR, mask); =20 - if (ptdev->mmu->as.slots[as].vm) - ptdev->mmu->as.slots[as].vm->unhandled_fault =3D true; + if (ptdev->mmu->as.slots[as].as) + ptdev->mmu->as.slots[as].as->unhandled_fault =3D true; =20 /* Disable the MMU to kill jobs on this AS. */ panthor_mmu_as_disable(ptdev, as, false); @@ -1937,12 +1950,12 @@ void panthor_mmu_suspend(struct panthor_device *ptd= ev) { mutex_lock(&ptdev->mmu->as.slots_lock); for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { - struct panthor_vm *vm =3D ptdev->mmu->as.slots[i].vm; + struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; =20 - if (vm) { + if (as) { drm_WARN_ON(&ptdev->base, panthor_mmu_as_disable(ptdev, i, false)); - panthor_vm_release_as_locked(vm); + panthor_as_release_hw_slot_locked(as); } } mutex_unlock(&ptdev->mmu->as.slots_lock); @@ -2012,10 +2025,10 @@ void panthor_mmu_post_reset(struct panthor_device *= ptdev) ptdev->mmu->as.faulty_mask =3D 0; =20 for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { - struct panthor_vm *vm =3D ptdev->mmu->as.slots[i].vm; + struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; =20 - if (vm) - panthor_vm_release_as_locked(vm); + if (as) + panthor_as_release_hw_slot_locked(as); } =20 mutex_unlock(&ptdev->mmu->as.slots_lock); @@ -2031,15 +2044,23 @@ void panthor_mmu_post_reset(struct panthor_device *= ptdev) mutex_unlock(&ptdev->mmu->vm.lock); } =20 -static void panthor_vm_free(struct drm_gpuvm *gpuvm) +static void panthor_vm_release(struct kref *kref) { - struct panthor_vm *vm =3D container_of(gpuvm, struct panthor_vm, base); - struct panthor_device *ptdev =3D vm->ptdev; + struct panthor_vm *vm =3D container_of(kref, struct panthor_vm, refcount); + struct panthor_as *as =3D vm->as; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); =20 + /* Make sure the page table behind this VM doesn't participate in reclaim + * after that point, since we're about to release everything anyway. + */ mutex_lock(&ptdev->base.gem_lru_mutex); - list_del_init(&vm->reclaim.lru_node); + list_del_init(&as->reclaim.lru_node); mutex_unlock(&ptdev->base.gem_lru_mutex); =20 + /* Unmap everything in case some BOs were still mapped. */ + drm_WARN_ON(&ptdev->base, + panthor_vm_unmap_range(vm, as->base.mm_start, as->base.mm_range)); + mutex_lock(&vm->heaps.lock); if (drm_WARN_ON(&ptdev->base, vm->heaps.pool)) panthor_heap_pool_destroy(vm->heaps.pool); @@ -2060,29 +2081,26 @@ static void panthor_vm_free(struct drm_gpuvm *gpuvm) drm_sched_entity_destroy(&vm->entity); drm_sched_fini(&vm->sched); =20 - mutex_lock(&vm->op_lock); + mutex_lock(&vm->as->op_lock); mutex_lock(&ptdev->mmu->as.slots_lock); - if (vm->as.id >=3D 0) { + if (as->hw_slot.id >=3D 0) { int cookie; =20 if (drm_dev_enter(&ptdev->base, &cookie)) { - panthor_mmu_as_disable(ptdev, vm->as.id, false); + panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); drm_dev_exit(cookie); } =20 - ptdev->mmu->as.slots[vm->as.id].vm =3D NULL; - clear_bit(vm->as.id, &ptdev->mmu->as.alloc_mask); - list_del(&vm->as.lru_node); + panthor_as_release_hw_slot_locked(as); } mutex_unlock(&ptdev->mmu->as.slots_lock); - mutex_unlock(&vm->op_lock); - - free_io_pgtable_ops(vm->pgtbl_ops); + mutex_unlock(&vm->as->op_lock); =20 if (vm->dummy) drm_gem_object_put(&vm->dummy->base); =20 drm_mm_takedown(&vm->mm); + drm_gpuvm_put(&as->base); kfree(vm); } =20 @@ -2092,7 +2110,8 @@ static void panthor_vm_free(struct drm_gpuvm *gpuvm) */ void panthor_vm_put(struct panthor_vm *vm) { - drm_gpuvm_put(vm ? &vm->base : NULL); + if (vm) + kref_put(&vm->refcount, panthor_vm_release); } =20 /** @@ -2104,7 +2123,7 @@ void panthor_vm_put(struct panthor_vm *vm) struct panthor_vm *panthor_vm_get(struct panthor_vm *vm) { if (vm) - drm_gpuvm_get(&vm->base); + kref_get(&vm->refcount); =20 return vm; } @@ -2125,6 +2144,8 @@ struct panthor_vm *panthor_vm_get(struct panthor_vm *= vm) */ struct panthor_heap_pool *panthor_vm_get_heap_pool(struct panthor_vm *vm, = bool create) { + struct panthor_device *ptdev =3D container_of(vm->as->base.drm, + struct panthor_device, base); struct panthor_heap_pool *pool; =20 mutex_lock(&vm->heaps.lock); @@ -2132,7 +2153,7 @@ struct panthor_heap_pool *panthor_vm_get_heap_pool(st= ruct panthor_vm *vm, bool c if (vm->destroyed) pool =3D ERR_PTR(-EINVAL); else - pool =3D panthor_heap_pool_create(vm->ptdev, vm); + pool =3D panthor_heap_pool_create(ptdev, vm); =20 if (!IS_ERR(pool)) vm->heaps.pool =3D panthor_heap_pool_get(pool); @@ -2167,7 +2188,7 @@ void panthor_vm_heaps_sizes(struct panthor_file *pfil= e, struct drm_memory_stats xa_for_each(&pfile->vms->xa, i, vm) { size_t size =3D panthor_heap_pool_size(vm->heaps.pool); stats->resident +=3D size; - if (vm->as.id >=3D 0) + if (vm->as->hw_slot.id >=3D 0) stats->active +=3D size; } xa_unlock(&pfile->vms->xa); @@ -2215,8 +2236,7 @@ static u64 mair_to_memattr(u64 mair, bool coherent) return memattr; } =20 -static void panthor_vma_link(struct panthor_vm *vm, - struct panthor_vma *vma, +static void panthor_vma_link(struct panthor_vma *vma, struct drm_gpuvm_bo *vm_bo) { struct panthor_gem_object *bo =3D to_panthor_bo(vma->base.gem.obj); @@ -2252,25 +2272,25 @@ panthor_fix_sparse_map_offset(struct drm_gpuva_op_m= ap *op, u32 flags) } =20 static int -panthor_vm_exec_map_op(struct panthor_vm *vm, u32 flags, +panthor_as_exec_map_op(struct panthor_as *as, u32 flags, const struct drm_gpuva_op_map *op) { struct panthor_gem_object *bo =3D to_panthor_bo(op->gem.obj); int prot =3D flags_to_prot(flags); =20 if (flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE) - return panthor_vm_map_sparse(vm, op->va.addr, prot, + return panthor_as_map_sparse(as, op->va.addr, prot, bo->dmap.sgt, op->va.range); =20 - return panthor_vm_map_pages(vm, op->va.addr, prot, bo->dmap.sgt, + return panthor_as_map_pages(as, op->va.addr, prot, bo->dmap.sgt, op->gem.offset, op->va.range); } =20 static int panthor_gpuva_sm_step_map(struct drm_gpuva_op *op, void *priv) { - struct panthor_vm *vm =3D priv; - struct panthor_vm_op_ctx *op_ctx =3D vm->op_ctx; - struct panthor_vma *vma =3D panthor_vm_op_ctx_get_vma(op_ctx); + struct panthor_as *as =3D priv; + struct panthor_as_op_ctx *op_ctx =3D as->op_ctx; + struct panthor_vma *vma =3D panthor_as_op_ctx_get_vma(op_ctx); int ret; =20 if (!vma) @@ -2279,14 +2299,14 @@ static int panthor_gpuva_sm_step_map(struct drm_gpu= va_op *op, void *priv) panthor_vma_init(vma, op_ctx->flags & PANTHOR_VM_MAP_FLAGS); panthor_fix_sparse_map_offset(&op->map, vma->flags); =20 - ret =3D panthor_vm_exec_map_op(vm, vma->flags, &op->map); + ret =3D panthor_as_exec_map_op(as, vma->flags, &op->map); if (ret) { - panthor_vm_op_ctx_return_vma(op_ctx, vma); + panthor_as_op_ctx_return_vma(op_ctx, vma); return ret; } =20 - drm_gpuva_map(&vm->base, &vma->base, &op->map); - panthor_vma_link(vm, vma, op_ctx->map.vm_bo); + drm_gpuva_map(&as->base, &vma->base, &op->map); + panthor_vma_link(vma, op_ctx->map.vm_bo); =20 drm_gpuvm_bo_put_deferred(op_ctx->map.vm_bo); op_ctx->map.vm_bo =3D NULL; @@ -2347,8 +2367,8 @@ static int panthor_gpuva_sm_step_remap(struct drm_gpu= va_op *op, void *priv) { struct panthor_vma *unmap_vma =3D container_of(op->remap.unmap->va, struc= t panthor_vma, base); - struct panthor_vm *vm =3D priv; - struct panthor_vm_op_ctx *op_ctx =3D vm->op_ctx; + struct panthor_as *as =3D priv; + struct panthor_as_op_ctx *op_ctx =3D as->op_ctx; struct panthor_vma *prev_vma =3D NULL, *next_vma =3D NULL; u64 unmap_start, unmap_range; int ret; @@ -2374,8 +2394,8 @@ static int panthor_gpuva_sm_step_remap(struct drm_gpu= va_op *op, * atomicity. panthor_vm_lock_region() bails out early if the new region * is already part of the locked region, so no need to do this check her= e. */ - panthor_vm_lock_region(vm, unmap_start, unmap_range); - panthor_vm_unmap_pages(vm, unmap_start, unmap_range); + panthor_as_lock_region(as, unmap_start, unmap_range); + panthor_as_unmap_pages(as, unmap_start, unmap_range); } =20 if (op->remap.prev) { @@ -2391,12 +2411,12 @@ static int panthor_gpuva_sm_step_remap(struct drm_g= puva_op *op, }; panthor_fix_sparse_map_offset(&map_op, unmap_vma->flags); =20 - ret =3D panthor_vm_exec_map_op(vm, unmap_vma->flags, &map_op); + ret =3D panthor_as_exec_map_op(as, unmap_vma->flags, &map_op); if (ret) return ret; } =20 - prev_vma =3D panthor_vm_op_ctx_get_vma(op_ctx); + prev_vma =3D panthor_as_op_ctx_get_vma(op_ctx); panthor_vma_init(prev_vma, unmap_vma->flags); prev_vma->evicted =3D unmap_vma->evicted; } @@ -2414,12 +2434,12 @@ static int panthor_gpuva_sm_step_remap(struct drm_g= puva_op *op, }; panthor_fix_sparse_map_offset(&map_op, unmap_vma->flags); =20 - ret =3D panthor_vm_exec_map_op(vm, unmap_vma->flags, &map_op); + ret =3D panthor_as_exec_map_op(as, unmap_vma->flags, &map_op); if (ret) return ret; } =20 - next_vma =3D panthor_vm_op_ctx_get_vma(op_ctx); + next_vma =3D panthor_as_op_ctx_get_vma(op_ctx); panthor_vma_init(next_vma, unmap_vma->flags); next_vma->evicted =3D unmap_vma->evicted; } @@ -2434,11 +2454,11 @@ static int panthor_gpuva_sm_step_remap(struct drm_g= puva_op *op, * owned by the old mapping which will be released when this * mapping is destroyed, we need to grab a ref here. */ - panthor_vma_link(vm, prev_vma, op->remap.unmap->va->vm_bo); + panthor_vma_link(prev_vma, op->remap.unmap->va->vm_bo); } =20 if (next_vma) { - panthor_vma_link(vm, next_vma, op->remap.unmap->va->vm_bo); + panthor_vma_link(next_vma, op->remap.unmap->va->vm_bo); } =20 panthor_vma_unlink(unmap_vma); @@ -2449,10 +2469,10 @@ static int panthor_gpuva_sm_step_unmap(struct drm_g= puva_op *op, void *priv) { struct panthor_vma *unmap_vma =3D container_of(op->unmap.va, struct panth= or_vma, base); - struct panthor_vm *vm =3D priv; + struct panthor_as *as =3D priv; =20 if (!unmap_vma->evicted) { - panthor_vm_unmap_pages(vm, unmap_vma->base.va.addr, + panthor_as_unmap_pages(as, unmap_vma->base.va.addr, unmap_vma->base.va.range); } =20 @@ -2464,7 +2484,7 @@ static int panthor_gpuva_sm_step_unmap(struct drm_gpu= va_op *op, void panthor_vm_update_bo_reclaim_lru_locked(struct panthor_gem_object *bo) { struct panthor_device *ptdev =3D container_of(bo->base.dev, struct pantho= r_device, base); - struct panthor_vm *vm =3D NULL; + struct panthor_as *as =3D NULL; struct drm_gpuvm_bo *vm_bo; =20 dma_resv_assert_held(bo->base.resv); @@ -2477,13 +2497,13 @@ void panthor_vm_update_bo_reclaim_lru_locked(struct= panthor_gem_object *bo) /* We're only supposed to have one non-evicted vm_bo in the list if we g= et * there. */ - drm_WARN_ON(&ptdev->base, vm); - vm =3D container_of(vm_bo->vm, struct panthor_vm, base); + drm_WARN_ON(&ptdev->base, as); + as =3D container_of(vm_bo->vm, struct panthor_as, base); =20 mutex_lock(&ptdev->base.gem_lru_mutex); - drm_gem_lru_move_tail_locked(&vm->reclaim.lru, &bo->base); - if (list_empty(&vm->reclaim.lru_node)) - list_move(&vm->reclaim.lru_node, &ptdev->reclaim.vms); + drm_gem_lru_move_tail_locked(&as->reclaim.lru, &bo->base); + if (list_empty(&as->reclaim.lru_node)) + list_move(&as->reclaim.lru_node, &ptdev->reclaim.vms); mutex_unlock(&ptdev->base.gem_lru_mutex); } } @@ -2494,10 +2514,10 @@ int panthor_vm_evict_bo_mappings_locked(struct pant= hor_gem_object *bo) int ret =3D 0; =20 drm_gem_for_each_gpuvm_bo(vm_bo, &bo->base) { - struct panthor_vm *vm =3D container_of(vm_bo->vm, struct panthor_vm, bas= e); + struct panthor_as *as =3D container_of(vm_bo->vm, struct panthor_as, bas= e); struct drm_gpuva *va; =20 - if (!mutex_trylock(&vm->op_lock)) + if (!mutex_trylock(&as->op_lock)) return -EDEADLK; =20 /* It can be that the vm_bo was already evicted but a new @@ -2526,16 +2546,16 @@ int panthor_vm_evict_bo_mappings_locked(struct pant= hor_gem_object *bo) * will be validated, causing all its evicted VMAs to be repopulated * before the job runs. So no GPU fault expected. */ - ret =3D panthor_vm_lock_region(vm, va->va.addr, va->va.range); + ret =3D panthor_as_lock_region(as, va->va.addr, va->va.range); if (ret) break; =20 - panthor_vm_unmap_pages(vm, va->va.addr, va->va.range); - panthor_vm_unlock_region(vm); + panthor_as_unmap_pages(as, va->va.addr, va->va.range); + panthor_as_unlock_region(as); vma->evicted =3D true; } =20 - mutex_unlock(&vm->op_lock); + mutex_unlock(&as->op_lock); =20 if (ret) break; @@ -2545,14 +2565,14 @@ int panthor_vm_evict_bo_mappings_locked(struct pant= hor_gem_object *bo) } =20 static struct panthor_vma *select_evicted_vma(struct drm_gpuvm_bo *vm_bo, - struct panthor_vm_op_ctx *op_ctx) + struct panthor_as_op_ctx *op_ctx) { - struct panthor_vm *vm =3D container_of(vm_bo->vm, struct panthor_vm, base= ); + struct panthor_as *as =3D container_of(vm_bo->vm, struct panthor_as, base= ); struct panthor_vma *first_evicted_vma =3D NULL; struct drm_gpuva *va; =20 /* Take op_lock to protect against va insertion/removal. */ - mutex_lock(&vm->op_lock); + mutex_lock(&as->op_lock); drm_gpuvm_bo_for_each_va(va, vm_bo) { struct panthor_vma *vma =3D container_of(va, struct panthor_vma, base); =20 @@ -2563,22 +2583,22 @@ static struct panthor_vma *select_evicted_vma(struc= t drm_gpuvm_bo *vm_bo, break; } } - mutex_unlock(&vm->op_lock); + mutex_unlock(&as->op_lock); =20 return first_evicted_vma; } =20 static int remap_evicted_vma(struct drm_gpuvm_bo *vm_bo, struct panthor_vma *evicted_vma, - struct panthor_vm_op_ctx *op_ctx) + struct panthor_as_op_ctx *op_ctx) { - struct panthor_vm *vm =3D container_of(vm_bo->vm, struct panthor_vm, base= ); + struct panthor_as *as =3D container_of(vm_bo->vm, struct panthor_as, base= ); struct panthor_gem_object *bo =3D to_panthor_bo(vm_bo->obj); struct drm_gpuva *va; bool found =3D false; int ret; =20 - ret =3D panthor_vm_op_ctx_prealloc_pts(op_ctx); + ret =3D panthor_as_op_ctx_prealloc_pts(op_ctx); if (ret) goto out_cleanup; =20 @@ -2587,7 +2607,7 @@ static int remap_evicted_vma(struct drm_gpuvm_bo *vm_= bo, * to release it so we can allocate PTs, because this very same lock * is taken in a DMA-signalling path. */ - mutex_lock(&vm->op_lock); + mutex_lock(&as->op_lock); drm_gpuvm_bo_for_each_va(va, vm_bo) { struct panthor_vma *vma =3D container_of(va, struct panthor_vma, base); =20 @@ -2607,8 +2627,8 @@ static int remap_evicted_vma(struct drm_gpuvm_bo *vm_= bo, } =20 if (found) { - vm->op_ctx =3D op_ctx; - ret =3D panthor_vm_lock_region(vm, evicted_vma->base.va.addr, + as->op_ctx =3D op_ctx; + ret =3D panthor_as_lock_region(as, evicted_vma->base.va.addr, evicted_vma->base.va.range); if (!ret) { struct drm_gpuva_op_map map_op =3D { @@ -2617,34 +2637,37 @@ static int remap_evicted_vma(struct drm_gpuvm_bo *v= m_bo, .gem.obj =3D &bo->base, .gem.offset =3D evicted_vma->base.gem.offset, }; - if (evicted_vma->flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE) - drm_WARN_ON_ONCE(&vm->ptdev->base, map_op.gem.offset !=3D - (map_op.va.addr & (SZ_2M - 1))); + if (evicted_vma->flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE) { + u64 expected_offset =3D map_op.va.addr & (SZ_2M - 1); =20 - ret =3D panthor_vm_exec_map_op(vm, evicted_vma->flags, &map_op); + drm_WARN_ON_ONCE(as->base.drm, + map_op.gem.offset !=3D expected_offset); + } + + ret =3D panthor_as_exec_map_op(as, evicted_vma->flags, &map_op); if (!ret) evicted_vma->evicted =3D false; =20 - panthor_vm_unlock_region(vm); + panthor_as_unlock_region(as); } =20 - vm->op_ctx =3D NULL; + as->op_ctx =3D NULL; } =20 - mutex_unlock(&vm->op_lock); + mutex_unlock(&as->op_lock); =20 out_cleanup: - panthor_vm_cleanup_op_ctx(op_ctx, vm); + panthor_as_cleanup_op_ctx(op_ctx, as); return ret; } =20 static int panthor_vm_restore_vmas(struct drm_gpuvm_bo *vm_bo) { - struct panthor_vm *vm =3D container_of(vm_bo->vm, struct panthor_vm, base= ); + struct panthor_as *as =3D container_of(vm_bo->vm, struct panthor_as, base= ); struct panthor_gem_object *bo =3D to_panthor_bo(vm_bo->obj); - struct panthor_vm_op_ctx op_ctx; + struct panthor_as_op_ctx op_ctx; =20 - if (drm_WARN_ON_ONCE(&vm->ptdev->base, !bo->dmap.sgt)) + if (drm_WARN_ON_ONCE(as->base.drm, !bo->dmap.sgt)) return -EINVAL; =20 for (struct panthor_vma *vma =3D select_evicted_vma(vm_bo, &op_ctx); @@ -2680,8 +2703,19 @@ static int panthor_vm_bo_validate(struct drm_gpuvm_b= o *vm_bo, return 0; } =20 +static void panthor_as_free(struct drm_gpuvm *gpuvm) +{ + struct panthor_as *as =3D container_of(gpuvm, struct panthor_as, base); + + if (as->pt.ops) + free_io_pgtable_ops(as->pt.ops); + + mutex_destroy(&as->op_lock); + kfree(as); +} + static const struct drm_gpuvm_ops panthor_gpuvm_ops =3D { - .vm_free =3D panthor_vm_free, + .vm_free =3D panthor_as_free, .vm_bo_free =3D panthor_vm_bo_free, .sm_step_map =3D panthor_gpuva_sm_step_map, .sm_step_remap =3D panthor_gpuva_sm_step_remap, @@ -2697,7 +2731,7 @@ static const struct drm_gpuvm_ops panthor_gpuvm_ops = =3D { */ struct dma_resv *panthor_vm_resv(struct panthor_vm *vm) { - return drm_gpuvm_resv(&vm->base); + return drm_gpuvm_resv(&vm->as->base); } =20 struct drm_gem_object *panthor_vm_root_gem(struct panthor_vm *vm) @@ -2705,12 +2739,12 @@ struct drm_gem_object *panthor_vm_root_gem(struct p= anthor_vm *vm) if (!vm) return NULL; =20 - return vm->base.r_obj; + return vm->as->base.r_obj; } =20 -static int -panthor_vm_exec_op(struct panthor_vm *vm, struct panthor_vm_op_ctx *op, - bool flag_vm_unusable_on_failure) +static int panthor_as_exec_op(struct panthor_as *as, + struct panthor_as_op_ctx *op, + bool flag_vm_unusable_on_failure) { u32 op_type =3D op->flags & DRM_PANTHOR_VM_BIND_OP_TYPE_MASK; int ret; @@ -2718,10 +2752,10 @@ panthor_vm_exec_op(struct panthor_vm *vm, struct pa= nthor_vm_op_ctx *op, if (op_type =3D=3D DRM_PANTHOR_VM_BIND_OP_TYPE_SYNC_ONLY) return 0; =20 - mutex_lock(&vm->op_lock); - vm->op_ctx =3D op; + mutex_lock(&as->op_lock); + as->op_ctx =3D op; =20 - ret =3D panthor_vm_lock_region(vm, op->va.addr, op->va.range); + ret =3D panthor_as_lock_region(as, op->va.addr, op->va.range); if (ret) goto out; =20 @@ -2734,17 +2768,17 @@ panthor_vm_exec_op(struct panthor_vm *vm, struct pa= nthor_vm_op_ctx *op, .map.gem.offset =3D op->map.bo_offset, }; =20 - if (vm->unusable) { + if (as->unusable) { ret =3D -EINVAL; break; } =20 - ret =3D drm_gpuvm_sm_map(&vm->base, vm, &map_req); + ret =3D drm_gpuvm_sm_map(&as->base, as, &map_req); break; } =20 case DRM_PANTHOR_VM_BIND_OP_TYPE_UNMAP: - ret =3D drm_gpuvm_sm_unmap(&vm->base, vm, op->va.addr, op->va.range); + ret =3D drm_gpuvm_sm_unmap(&as->base, as, op->va.addr, op->va.range); break; =20 default: @@ -2752,14 +2786,14 @@ panthor_vm_exec_op(struct panthor_vm *vm, struct pa= nthor_vm_op_ctx *op, break; } =20 - panthor_vm_unlock_region(vm); + panthor_as_unlock_region(as); =20 out: if (ret && flag_vm_unusable_on_failure) - panthor_vm_declare_unusable(vm); + panthor_as_declare_unusable(as); =20 - vm->op_ctx =3D NULL; - mutex_unlock(&vm->op_lock); + as->op_ctx =3D NULL; + mutex_unlock(&as->op_lock); =20 return ret; } @@ -2777,7 +2811,7 @@ panthor_vm_bind_run_job(struct drm_sched_job *sched_j= ob) * to be destroyed and recreated. */ cookie =3D dma_fence_begin_signalling(); - ret =3D panthor_vm_exec_op(job->vm, &job->ctx, true); + ret =3D panthor_as_exec_op(job->vm->as, &job->ctx, true); dma_fence_end_signalling(cookie); =20 return ret ? ERR_PTR(ret) : NULL; @@ -2790,7 +2824,7 @@ static void panthor_vm_bind_job_release(struct kref *= kref) if (job->base.s_fence) drm_sched_job_cleanup(&job->base); =20 - panthor_vm_cleanup_op_ctx(&job->ctx, job->vm); + panthor_as_cleanup_op_ctx(&job->ctx, job->vm->as); panthor_vm_put(job->vm); kfree(job); } @@ -2835,6 +2869,62 @@ static const struct drm_sched_backend_ops panthor_vm= _bind_ops =3D { .timedout_job =3D panthor_vm_bind_timedout_job, }; =20 +static struct panthor_as * +panthor_as_create(struct panthor_device *ptdev, const char *name, + u64 min_va, u64 va_range) +{ + struct io_pgtable_cfg as_cfg =3D { + .pgsize_bitmap =3D ptdev->mmu_info.page_size_bitmap, + .ias =3D GPU_MMU_FEATURES_VA_BITS(ptdev->gpu_info.mmu_features), + .oas =3D GPU_MMU_FEATURES_PA_BITS(ptdev->gpu_info.mmu_features), + .coherent_walk =3D ptdev->coherent, + .tlb =3D &mmu_tlb_ops, + .iommu_dev =3D drm_dev_dma_dev(&ptdev->base), + .alloc =3D alloc_pt, + .free =3D free_pt, + }; + struct drm_gem_object *dummy_gem; + struct panthor_as *as; + u64 mair; + + /* We allocate a dummy GEM for the VM. */ + dummy_gem =3D drm_gpuvm_resv_object_alloc(&ptdev->base); + if (!dummy_gem) + return ERR_PTR(-ENOMEM); + + as =3D kzalloc_obj(*as); + if (!as) { + drm_gem_object_put(dummy_gem); + return ERR_PTR(-ENOMEM); + } + + mutex_init(&as->op_lock); + drm_gem_lru_init(&as->reclaim.lru); + INIT_LIST_HEAD(&as->reclaim.lru_node); + INIT_LIST_HEAD(&as->hw_slot.lru_node); + as->hw_slot.id =3D -1; + refcount_set(&as->active_cnt, 0); + + /* We intentionally leave the reserved range to zero, because we want ker= nel VMAs + * to be handled the same way user VMAs are. + */ + drm_gpuvm_init(&as->base, name, + DRM_GPUVM_RESV_PROTECTED | DRM_GPUVM_IMMEDIATE_MODE, + &ptdev->base, dummy_gem, min_va, va_range, 0, 0, + &panthor_gpuvm_ops); + drm_gem_object_put(dummy_gem); + + as->pt.ops =3D alloc_io_pgtable_ops(ARM_64_LPAE_S1, &as_cfg, as); + if (!as->pt.ops) { + drm_gpuvm_put(&as->base); + return ERR_PTR(-EINVAL); + } + + mair =3D io_pgtable_ops_to_pgtable(as->pt.ops)->cfg.arm_lpae_s1_cfg.mair; + as->memattr =3D mair_to_memattr(mair, ptdev->coherent); + return as; +} + /** * panthor_vm_create() - Create a VM * @ptdev: Device. @@ -2852,9 +2942,8 @@ panthor_vm_create(struct panthor_device *ptdev, bool = for_mcu, u64 auto_kernel_va_start, u64 auto_kernel_va_size) { u32 va_bits =3D GPU_MMU_FEATURES_VA_BITS(ptdev->gpu_info.mmu_features); - u32 pa_bits =3D GPU_MMU_FEATURES_PA_BITS(ptdev->gpu_info.mmu_features); + const char *name =3D for_mcu ? "panthor-MCU-VM" : "panthor-GPU-VM"; u64 full_va_range =3D 1ull << va_bits; - struct drm_gem_object *dummy_gem; struct drm_gpu_scheduler *sched; const struct drm_sched_init_args sched_args =3D { .ops =3D &panthor_vm_bind_ops, @@ -2865,27 +2954,11 @@ panthor_vm_create(struct panthor_device *ptdev, boo= l for_mcu, .name =3D "panthor-vm-bind", .dev =3D ptdev->base.dev, }; - struct io_pgtable_cfg pgtbl_cfg; - u64 mair, min_va, va_range; + struct panthor_as *as; struct panthor_vm *vm; + u64 min_va, va_range; int ret; =20 - vm =3D kzalloc_obj(*vm); - if (!vm) - return ERR_PTR(-ENOMEM); - - /* We allocate a dummy GEM for the VM. */ - dummy_gem =3D drm_gpuvm_resv_object_alloc(&ptdev->base); - if (!dummy_gem) { - ret =3D -ENOMEM; - goto err_free_vm; - } - - mutex_init(&vm->heaps.lock); - vm->for_mcu =3D for_mcu; - vm->ptdev =3D ptdev; - mutex_init(&vm->op_lock); - if (for_mcu) { /* CSF MCU is a cortex M7, and can only address 4G */ min_va =3D 0; @@ -2895,49 +2968,35 @@ panthor_vm_create(struct panthor_device *ptdev, boo= l for_mcu, va_range =3D full_va_range; } =20 + as =3D panthor_as_create(ptdev, name, min_va, va_range); + if (IS_ERR(as)) + return ERR_CAST(as); + + vm =3D kzalloc_obj(*vm); + if (!vm) { + ret =3D -ENOMEM; + goto err_put_as; + } + vm->user_va_range =3D kernel_va_start; + vm->as =3D as; + mutex_init(&vm->heaps.lock); + vm->for_mcu =3D for_mcu; =20 mutex_init(&vm->mm_lock); drm_mm_init(&vm->mm, kernel_va_start, kernel_va_size); vm->kernel_auto_va.start =3D auto_kernel_va_start; vm->kernel_auto_va.end =3D vm->kernel_auto_va.start + auto_kernel_va_size= - 1; =20 - drm_gem_lru_init(&vm->reclaim.lru); - INIT_LIST_HEAD(&vm->reclaim.lru_node); - INIT_LIST_HEAD(&vm->node); - INIT_LIST_HEAD(&vm->as.lru_node); - vm->as.id =3D -1; - refcount_set(&vm->as.active_cnt, 0); - - pgtbl_cfg =3D (struct io_pgtable_cfg) { - .pgsize_bitmap =3D ptdev->mmu_info.page_size_bitmap, - .ias =3D va_bits, - .oas =3D pa_bits, - .coherent_walk =3D ptdev->coherent, - .tlb =3D &mmu_tlb_ops, - .iommu_dev =3D ptdev->base.dev, - .alloc =3D alloc_pt, - .free =3D free_pt, - }; - - vm->pgtbl_ops =3D alloc_io_pgtable_ops(ARM_64_LPAE_S1, &pgtbl_cfg, vm); - if (!vm->pgtbl_ops) { - ret =3D -EINVAL; - goto err_mm_takedown; - } - ret =3D drm_sched_init(&vm->sched, &sched_args); if (ret) - goto err_free_io_pgtable; + goto err_free_vm; =20 sched =3D &vm->sched; ret =3D drm_sched_entity_init(&vm->entity, 0, &sched, 1, NULL); if (ret) goto err_sched_fini; =20 - mair =3D io_pgtable_ops_to_pgtable(vm->pgtbl_ops)->cfg.arm_lpae_s1_cfg.ma= ir; - vm->memattr =3D mair_to_memattr(mair, ptdev->coherent); - mutex_lock(&ptdev->mmu->vm.lock); list_add_tail(&vm->node, &ptdev->mmu->vm.list); =20 @@ -2946,28 +3005,20 @@ panthor_vm_create(struct panthor_device *ptdev, boo= l for_mcu, panthor_vm_stop(vm); mutex_unlock(&ptdev->mmu->vm.lock); =20 - /* We intentionally leave the reserved range to zero, because we want ker= nel VMAs - * to be handled the same way user VMAs are. - */ - drm_gpuvm_init(&vm->base, for_mcu ? "panthor-MCU-VM" : "panthor-GPU-VM", - DRM_GPUVM_RESV_PROTECTED | DRM_GPUVM_IMMEDIATE_MODE, - &ptdev->base, dummy_gem, min_va, va_range, 0, 0, - &panthor_gpuvm_ops); - drm_gem_object_put(dummy_gem); + kref_init(&vm->refcount); return vm; =20 err_sched_fini: drm_sched_fini(&vm->sched); =20 -err_free_io_pgtable: - free_io_pgtable_ops(vm->pgtbl_ops); - -err_mm_takedown: - drm_mm_takedown(&vm->mm); - drm_gem_object_put(dummy_gem); - err_free_vm: + drm_mm_takedown(&vm->mm); + mutex_destroy(&vm->mm_lock); + mutex_destroy(&vm->heaps.lock); kfree(vm); + +err_put_as: + drm_gpuvm_put(&as->base); return ERR_PTR(ret); } =20 @@ -2975,7 +3026,7 @@ static int panthor_vm_bind_prepare_op_ctx(struct drm_file *file, struct panthor_vm *vm, const struct drm_panthor_vm_bind_op *op, - struct panthor_vm_op_ctx *op_ctx) + struct panthor_as_op_ctx *op_ctx) { ssize_t vm_pgsz =3D panthor_vm_page_size(vm); struct drm_gem_object *gem; @@ -2998,7 +3049,7 @@ panthor_vm_bind_prepare_op_ctx(struct drm_file *file, drm_gem_object_get(&vm->dummy->base); } =20 - ret =3D panthor_vm_prepare_map_op_ctx(op_ctx, vm, + ret =3D panthor_as_prepare_map_op_ctx(op_ctx, vm->as, gem ? to_panthor_bo(gem) : NULL, op); drm_gem_object_put(gem); @@ -3011,7 +3062,7 @@ panthor_vm_bind_prepare_op_ctx(struct drm_file *file, if (op->bo_handle || op->bo_offset) return -EINVAL; =20 - return panthor_vm_prepare_unmap_op_ctx(op_ctx, vm, op->va, op->size); + return panthor_as_prepare_unmap_op_ctx(op_ctx, vm->as, op->va, op->size); =20 case DRM_PANTHOR_VM_BIND_OP_TYPE_SYNC_ONLY: if (op->flags & ~DRM_PANTHOR_VM_BIND_OP_TYPE_MASK) @@ -3026,7 +3077,7 @@ panthor_vm_bind_prepare_op_ctx(struct drm_file *file, if (!op->syncs.count) return -EINVAL; =20 - panthor_vm_prepare_sync_only_op_ctx(op_ctx); + panthor_as_prepare_sync_only_op_ctx(op_ctx); return 0; =20 default: @@ -3061,7 +3112,7 @@ panthor_vm_bind_job_create(struct drm_file *file, if (!vm) return ERR_PTR(-EINVAL); =20 - if (vm->destroyed || vm->unusable) + if (vm->destroyed || vm->as->unusable) return ERR_PTR(-EINVAL); =20 job =3D kzalloc_obj(*job); @@ -3107,7 +3158,7 @@ int panthor_vm_bind_job_prepare_resvs(struct drm_exec= *exec, int ret; =20 /* Acquire the VM lock an reserve a slot for this VM bind job. */ - ret =3D drm_gpuvm_prepare_vm(&job->vm->base, exec, 1); + ret =3D drm_gpuvm_prepare_vm(&job->vm->as->base, exec, 1); if (ret) return ret; =20 @@ -3132,7 +3183,7 @@ void panthor_vm_bind_job_update_resvs(struct drm_exec= *exec, struct panthor_vm_bind_job *job =3D container_of(sched_job, struct pantho= r_vm_bind_job, base); =20 /* Explicit sync =3D> we just register our job finished fence as bookkeep= . */ - drm_gpuvm_resv_add_fence(&job->vm->base, exec, + drm_gpuvm_resv_add_fence(&job->vm->as->base, exec, &sched_job->s_fence->finished, DMA_RESV_USAGE_BOOKKEEP, DMA_RESV_USAGE_BOOKKEEP); @@ -3143,7 +3194,7 @@ void panthor_vm_update_resvs(struct panthor_vm *vm, s= truct drm_exec *exec, enum dma_resv_usage private_usage, enum dma_resv_usage extobj_usage) { - drm_gpuvm_resv_add_fence(&vm->base, exec, fence, private_usage, extobj_us= age); + drm_gpuvm_resv_add_fence(&vm->as->base, exec, fence, private_usage, extob= j_usage); } =20 /** @@ -3158,7 +3209,7 @@ int panthor_vm_bind_exec_sync_op(struct drm_file *fil= e, struct panthor_vm *vm, struct drm_panthor_vm_bind_op *op) { - struct panthor_vm_op_ctx op_ctx; + struct panthor_as_op_ctx op_ctx; int ret; =20 /* No sync objects allowed on synchronous operations. */ @@ -3172,8 +3223,8 @@ int panthor_vm_bind_exec_sync_op(struct drm_file *fil= e, if (ret) return ret; =20 - ret =3D panthor_vm_exec_op(vm, &op_ctx, false); - panthor_vm_cleanup_op_ctx(&op_ctx, vm); + ret =3D panthor_as_exec_op(vm->as, &op_ctx, false); + panthor_as_cleanup_op_ctx(&op_ctx, vm->as); =20 return ret; } @@ -3202,18 +3253,18 @@ int panthor_vm_map_bo_range(struct panthor_vm *vm, = struct panthor_gem_object *bo .va =3D va, .flags =3D flags, }; - struct panthor_vm_op_ctx op_ctx; + struct panthor_as_op_ctx op_ctx; int ret; =20 - if (drm_WARN_ON(&vm->ptdev->base, flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPAR= SE)) + if (drm_WARN_ON(vm->as->base.drm, flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPAR= SE)) return -EINVAL; =20 - ret =3D panthor_vm_prepare_map_op_ctx(&op_ctx, vm, bo, &op); + ret =3D panthor_as_prepare_map_op_ctx(&op_ctx, vm->as, bo, &op); if (ret) return ret; =20 - ret =3D panthor_vm_exec_op(vm, &op_ctx, false); - panthor_vm_cleanup_op_ctx(&op_ctx, vm); + ret =3D panthor_as_exec_op(vm->as, &op_ctx, false); + panthor_as_cleanup_op_ctx(&op_ctx, vm->as); =20 return ret; } @@ -3231,15 +3282,15 @@ int panthor_vm_map_bo_range(struct panthor_vm *vm, = struct panthor_gem_object *bo */ int panthor_vm_unmap_range(struct panthor_vm *vm, u64 va, u64 size) { - struct panthor_vm_op_ctx op_ctx; + struct panthor_as_op_ctx op_ctx; int ret; =20 - ret =3D panthor_vm_prepare_unmap_op_ctx(&op_ctx, vm, va, size); + ret =3D panthor_as_prepare_unmap_op_ctx(&op_ctx, vm->as, va, size); if (ret) return ret; =20 - ret =3D panthor_vm_exec_op(vm, &op_ctx, false); - panthor_vm_cleanup_op_ctx(&op_ctx, vm); + ret =3D panthor_as_exec_op(vm->as, &op_ctx, false); + panthor_as_cleanup_op_ctx(&op_ctx, vm->as); =20 return ret; } @@ -3263,15 +3314,15 @@ int panthor_vm_prepare_mapped_bos_resvs(struct drm_= exec *exec, struct panthor_vm int ret; =20 /* Acquire the VM lock and reserve a slot for this GPU job. */ - ret =3D drm_gpuvm_prepare_vm(&vm->base, exec, slot_count); + ret =3D drm_gpuvm_prepare_vm(&vm->as->base, exec, slot_count); if (ret) return ret; =20 - ret =3D drm_gpuvm_prepare_objects(&vm->base, exec, slot_count); + ret =3D drm_gpuvm_prepare_objects(&vm->as->base, exec, slot_count); if (ret) return ret; =20 - return drm_gpuvm_validate(&vm->base, exec); + return drm_gpuvm_validate(&vm->as->base, exec); } =20 unsigned long @@ -3288,21 +3339,21 @@ panthor_mmu_reclaim_priv_bos(struct panthor_device = *ptdev, list_splice_init(&ptdev->reclaim.vms, &vms); =20 while (freed < nr_to_scan) { - struct panthor_vm *vm; + struct panthor_as *as; =20 - vm =3D list_first_entry_or_null(&vms, typeof(*vm), + as =3D list_first_entry_or_null(&vms, typeof(*as), reclaim.lru_node); - if (!vm) + if (!as) break; =20 - if (!kref_get_unless_zero(&vm->base.kref)) { - list_del_init(&vm->reclaim.lru_node); + if (!kref_get_unless_zero(&as->base.kref)) { + list_del_init(&as->reclaim.lru_node); continue; } =20 mutex_unlock(&ptdev->base.gem_lru_mutex); =20 - freed +=3D drm_gem_lru_scan(&ptdev->base, &vm->reclaim.lru, + freed +=3D drm_gem_lru_scan(&ptdev->base, &as->reclaim.lru, nr_to_scan - freed, remaining, shrink, NULL); =20 @@ -3311,20 +3362,20 @@ panthor_mmu_reclaim_priv_bos(struct panthor_device = *ptdev, /* If the VM is still in the temporary list, remove it so we * can proceed with the next VM. */ - if (vm =3D=3D list_first_entry_or_null(&vms, typeof(*vm), reclaim.lru_no= de)) { - list_del_init(&vm->reclaim.lru_node); + if (as =3D=3D list_first_entry_or_null(&vms, typeof(*as), reclaim.lru_no= de)) { + list_del_init(&as->reclaim.lru_node); =20 /* Keep the VM around if there are still things to * reclaim, so we can preserve the LRU order when * re-inserting in ptdev->reclaim.vms at the end. */ - if (vm->reclaim.lru.count > 0) - list_add_tail(&vm->reclaim.lru_node, &remaining_vms); + if (as->reclaim.lru.count > 0) + list_add_tail(&as->reclaim.lru_node, &remaining_vms); } =20 mutex_unlock(&ptdev->base.gem_lru_mutex); =20 - panthor_vm_put(vm); + drm_gpuvm_put(&as->base); =20 mutex_lock(&ptdev->base.gem_lru_mutex); } @@ -3356,12 +3407,12 @@ void panthor_mmu_unplug(struct panthor_device *ptde= v) =20 mutex_lock(&ptdev->mmu->as.slots_lock); for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { - struct panthor_vm *vm =3D ptdev->mmu->as.slots[i].vm; + struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; =20 - if (vm) { + if (as) { drm_WARN_ON(&ptdev->base, panthor_mmu_as_disable(ptdev, i, false)); - panthor_vm_release_as_locked(vm); + panthor_as_release_hw_slot_locked(as); } } mutex_unlock(&ptdev->mmu->as.slots_lock); @@ -3451,9 +3502,9 @@ static int show_vm_gpuvas(struct panthor_vm *vm, stru= ct seq_file *m) { int ret; =20 - mutex_lock(&vm->op_lock); - ret =3D drm_debugfs_gpuva_info(m, &vm->base); - mutex_unlock(&vm->op_lock); + mutex_lock(&vm->as->op_lock); + ret =3D drm_debugfs_gpuva_info(m, &vm->as->base); + mutex_unlock(&vm->as->op_lock); =20 return ret; } --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 239ED43A7F6 for ; Tue, 11 Aug 2026 10:18:12 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443504; cv=none; b=fOLD/VPdtrB9GritCyLutjs4Xywa/CCkFOshjcLpY4QH8Ze09bg5NeUhrZYg3gHxCDMaU24FAyKF3DCID1Glr2X0VssJYjqxgCI9/569k4sixgBAYAw4d2fFVwo4XHFL7xVE8CKnirdONUJC8R5raq0MxyXsfBsPvRR04JxhY4E= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443504; c=relaxed/simple; bh=llmvfl88D0kE2ATS1wrk/iq+rvVdEB4y6FFYtHMalPM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=pFD0nbeAM38e/cy9SvZr7X4SxjdgEeaacKFzTBOt9Y8KEuqZRSPfibskb/6LMeUY2NXSEGKuTHhwmJJoJJ1E6WtH9lCMDUBJG7xl6HkKVOjUM0zGdL+4bCHinRScXSmPw2D+RxcIpRHiErTpAeD/OVhXuAaYlrwUSRD3trY8sCA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=Lbbe61kH; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="Lbbe61kH" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443472; bh=llmvfl88D0kE2ATS1wrk/iq+rvVdEB4y6FFYtHMalPM=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=Lbbe61kHovLdL7gG/D+fn9KNJQP9snSY2+N3/4C/WUrIc5OCOn5uN/Vnp8KLlumOr pqMRmCpyiZH3D81JTyaxi/nWnpH81Xds2ujPbezdBAayQn3NmvrT2lE/ub3LAbHYLO BXDc7OqnlCxAxtMu3xSdDXDK+aHx0h6aL/degroo5PYAO7gbNusQmh9UGHSHYrwQdi nfYBbSCj5ABDEs7nUBVQwhkdx/RRxWJR3puHRT0NAF1uHnIEdlliKZrEe2DAQAKPms DCuGb8Y2CkToVXjZkyViMPHH3QsWXhXEOcqHPJYM/8/I5WBqDZ02Z89Qi3NrFaITwQ scbgBKQXLFmOw== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id EE7A417E0FEA; Tue, 11 Aug 2026 12:17:51 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:43 +0200 Subject: [PATCH v2 09/17] drm/panthor: Add fine-grained restrictions on VMs Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-9-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=10100; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=llmvfl88D0kE2ATS1wrk/iq+rvVdEB4y6FFYtHMalPM=; b=Vo9zpctxSEkPYCrj/bEH2F4tsEcC6od0OsGOQxJiV12kA4bkdAPV6IJYySvSxqzmXFHHOSaxj qrbMxEPGLTDCFt0kDVEsrRvG5F/STK0/dmcVnhfNuzDpc977CRr+lfC X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= We currently restrict what a VM is allowed to do based on two states: panthor_vm::destroyed and panthor_vm_pgtable::unusable, but we'll soon need a no-unmap restriction to fix the unplug logic. Instead of adding a third boolean that would reflect this new limitation, let's overhaul the current restriction logic by adding separate restriction flags representing the operations we want to prevent (map, unmap and use). Map and use restrictions are set everywhere we were previously calling panthor_vm_pgtable_declare_unusable() or setting ::destroyed to true, since that's what those two flags were preventing. We also add restriction checks in panthor_vm_pgtable_prepare_[un]map_op_ctx() and panthor_vm_pgtable_exec_op() and drop the ones we had in panthor_vm_bind_job_create() since they are redundant. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 134 ++++++++++++++++++++++--------= ---- 1 file changed, 88 insertions(+), 46 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 041836552953..1b401fd0d2d7 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -215,6 +215,25 @@ struct panthor_as_op_ctx { } map; }; =20 +/** + * enum panthor_as_restriction - List of restrictions that can apply to an= AS. + * + * An AS always starts unrestricted, but based on the faults or device sta= te + * changes, restrictions can be added over time. Restrictions can't be rem= oved + * though. Once a VM is restricted, a new one must be created to lift the + * restrictions. + */ +enum panthor_as_restriction { + /** @PANTHOR_AS_FORBID_MAP: The AS can't map new buffers. */ + PANTHOR_AS_FORBID_MAP =3D BIT(0), + + /** @PANTHOR_AS_FORBID_UNMAP: The AS can't remove existing mappings. */ + PANTHOR_AS_FORBID_UNMAP =3D BIT(1), + + /** @PANTHOR_AS_FORBID_USE: The AS can't become active again. */ + PANTHOR_AS_FORBID_USE =3D BIT(2), +}; + /** * struct panthor_as - Used to managed a GPU address space. */ @@ -275,25 +294,8 @@ struct panthor_as { struct list_head lru_node; } hw_slot; =20 - /** - * @unusable: True if the AS has turned unusable because something - * bad happened during an asynchronous request. - * - * We don't try to recover from such failures, because this implies - * informing userspace about the specific operation that failed, and - * hoping the userspace driver can replay things from there. This all - * sounds very complicated for little gain. - * - * Instead, we should just flag the AS as unusable, and fail any - * further request targeting this AS. - * - * We also provide a way to query an AS state, so userspace can - * destroy it and create a new one. - * - * As an analogy, this would be mapped to a VK_ERROR_DEVICE_LOST - * situation, where the logical device needs to be re-created. - */ - bool unusable; + /** @restrictions: Bitmask of panthor_as_restriction flags. */ + atomic_t restrictions; =20 /** * @unhandled_fault: Unhandled fault happened. @@ -411,13 +413,6 @@ struct panthor_vm { /** @for_mcu: True if this is the MCU VM. */ bool for_mcu; =20 - /** - * @destroyed: True if the VM was destroyed. - * - * No further bind requests should be queued to a destroyed VM. - */ - bool destroyed; - /** * @dummy: Dummy object used for sparse mappings. * @@ -693,7 +688,9 @@ bool panthor_vm_has_unhandled_faults(struct panthor_vm = *vm) */ bool panthor_vm_is_unusable(struct panthor_vm *vm) { - return vm->as->unusable; + return (atomic_read(&vm->as->restrictions) & + (PANTHOR_AS_FORBID_USE | PANTHOR_AS_FORBID_MAP | + PANTHOR_AS_FORBID_UNMAP)); } =20 static void panthor_as_release_hw_slot_locked(struct panthor_as *as) @@ -752,6 +749,11 @@ int panthor_vm_active(struct panthor_vm *vm) mutex_lock(&as->op_lock); mutex_lock(&ptdev->mmu->as.slots_lock); =20 + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_USE) { + ret =3D -EINVAL; + goto out_unlock; + } + if (refcount_inc_not_zero(&as->active_cnt)) goto out_unlock; =20 @@ -920,21 +922,29 @@ static size_t get_pgsize(u64 addr, size_t size, size_= t *count) return SZ_2M; } =20 -static void panthor_as_declare_unusable(struct panthor_as *as) +static void panthor_as_restrict_usage_locked(struct panthor_as *as, + u32 new_restrictions) { struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); int cookie; =20 - if (as->unusable) - return; + lockdep_assert_held(&as->op_lock); =20 - as->unusable =3D true; - mutex_lock(&ptdev->mmu->as.slots_lock); - if (as->hw_slot.id >=3D 0 && drm_dev_enter(&ptdev->base, &cookie)) { - panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); - drm_dev_exit(cookie); + if (new_restrictions & PANTHOR_AS_FORBID_USE) { + guard(mutex)(&ptdev->mmu->as.slots_lock); + if (as->hw_slot.id >=3D 0 && drm_dev_enter(&ptdev->base, &cookie)) { + /* Try to disable the AS. If as_disable() passed, this should cause + * a fault on the next memory access. If it failed, a reset is + * scheduled to recover from the GPU hang. + * We intentionally don't call release_as_locked() here, because + * this would mess up with the active_cnt refcount. + */ + panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); + drm_dev_exit(cookie); + } } - mutex_unlock(&ptdev->mmu->as.slots_lock); + + atomic_or(new_restrictions, &as->restrictions); } =20 static void panthor_as_unmap_pages(struct panthor_as *as, u64 iova, u64 si= ze) @@ -970,7 +980,9 @@ static void panthor_as_unmap_pages(struct panthor_as *a= s, u64 iova, u64 size) * so flag the VM unusable to make sure it's not going * to be used anymore. */ - panthor_as_declare_unusable(as); + panthor_as_restrict_usage_locked(as, + PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP); =20 /* If we don't make progress, we're screwed. That also means * something else prevents us from unmapping the region, but @@ -1046,7 +1058,9 @@ panthor_as_map_pages(struct panthor_as *as, u64 iova,= int prot, * table pages behind. */ panthor_as_unmap_pages(as, start_iova, iova - start_iova); - panthor_as_declare_unusable(as); + panthor_as_restrict_usage_locked(as, + PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP); return ret; } } @@ -1339,6 +1353,9 @@ static int panthor_as_prepare_map_op_ctx(struct panth= or_as_op_ctx *op_ctx, struct sg_table *sgt =3D NULL; int ret; =20 + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_MAP) + return -EINVAL; + if (!bo) return -EINVAL; =20 @@ -1431,6 +1448,9 @@ static int panthor_as_prepare_unmap_op_ctx(struct pan= thor_as_op_ctx *op_ctx, u32 pt_count =3D 0; int ret; =20 + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_UNMAP) + return -EINVAL; + memset(op_ctx, 0, sizeof(*op_ctx)); op_ctx->va.range =3D size; op_ctx->va.addr =3D va; @@ -1640,7 +1660,12 @@ static void panthor_vm_destroy(struct panthor_vm *vm) =20 as =3D vm->as; ptdev =3D container_of(as->base.drm, struct panthor_device, base); - vm->destroyed =3D true; + + scoped_guard(mutex, &as->op_lock) { + panthor_as_restrict_usage_locked(as, + PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP); + } =20 /* Tell scheduler to stop all GPU work related to this VM */ if (refcount_read(&as->active_cnt) > 0) @@ -2150,7 +2175,7 @@ struct panthor_heap_pool *panthor_vm_get_heap_pool(st= ruct panthor_vm *vm, bool c =20 mutex_lock(&vm->heaps.lock); if (!vm->heaps.pool && create) { - if (vm->destroyed) + if (panthor_vm_is_unusable(vm)) pool =3D ERR_PTR(-EINVAL); else pool =3D panthor_heap_pool_create(ptdev, vm); @@ -2520,6 +2545,17 @@ int panthor_vm_evict_bo_mappings_locked(struct panth= or_gem_object *bo) if (!mutex_trylock(&as->op_lock)) return -EDEADLK; =20 + /* Unmaps are forbidden when we failed to communicate with the GPU, + * meaning we can't guarantee that the GPU will see our page table + * updates which might lead to UAF situations. In that case, we + * just skip eviction on this VM. Things should go back to normal + * after a GPU reset. + */ + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_UNMAP) { + ret =3D -EBUSY; + goto unlock_op; + } + /* It can be that the vm_bo was already evicted but a new * mapping pointing to this BO got created in the meantime, * thus turning the vm_bo in partially evicted state. In that case @@ -2555,6 +2591,7 @@ int panthor_vm_evict_bo_mappings_locked(struct pantho= r_gem_object *bo) vma->evicted =3D true; } =20 +unlock_op: mutex_unlock(&as->op_lock); =20 if (ret) @@ -2768,7 +2805,7 @@ static int panthor_as_exec_op(struct panthor_as *as, .map.gem.offset =3D op->map.bo_offset, }; =20 - if (as->unusable) { + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_MAP) { ret =3D -EINVAL; break; } @@ -2778,6 +2815,11 @@ static int panthor_as_exec_op(struct panthor_as *as, } =20 case DRM_PANTHOR_VM_BIND_OP_TYPE_UNMAP: + if (atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_UNMAP) { + ret =3D -EINVAL; + break; + } + ret =3D drm_gpuvm_sm_unmap(&as->base, as, op->va.addr, op->va.range); break; =20 @@ -2789,8 +2831,11 @@ static int panthor_as_exec_op(struct panthor_as *as, panthor_as_unlock_region(as); =20 out: - if (ret && flag_vm_unusable_on_failure) - panthor_as_declare_unusable(as); + if (ret && flag_vm_unusable_on_failure) { + panthor_as_restrict_usage_locked(as, + PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP); + } =20 as->op_ctx =3D NULL; mutex_unlock(&as->op_lock); @@ -3112,9 +3157,6 @@ panthor_vm_bind_job_create(struct drm_file *file, if (!vm) return ERR_PTR(-EINVAL); =20 - if (vm->destroyed || vm->as->unusable) - return ERR_PTR(-EINVAL); - job =3D kzalloc_obj(*job); if (!job) return ERR_PTR(-ENOMEM); --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF35043B49C for ; Tue, 11 Aug 2026 10:18:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; cv=none; b=eAIPGnpAFFV6DjW9MSXVOmpZVxJAnLxPmczDwtRxyCbGx6VYCn8rOOSbOHVkzSuNq2vwkoXzc71lj5uzgxx4xuRvuPhlLHQZ9/YZcB3LJyWW/yM6Nd4g5AwzAougaRNOteC9wsYazIAMhpcOy8c5Rp7lGjz+d59/jtSbFyfAZ7U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; c=relaxed/simple; bh=tdKa3iEPlj3pDEW5mojDJ07XRew8XsVzU/fp1UTnZ+s=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=IxjdJjVJu/GUVi6ICLsZibwLy1WQ6hVMoNMYLftVLS1ngtFm4slnrxMfUDeBFQKmoIT6KyMbovP0cYig2pEEStUYCviGW1e7L4t89hd1jV9Ixccdpwg0rHqMuAMPeSA1kUXCjvpxqcgq7Yh+npYRbrnVaLdvRinoI4apZDWIYjw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=dtUQK+it; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="dtUQK+it" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443472; bh=tdKa3iEPlj3pDEW5mojDJ07XRew8XsVzU/fp1UTnZ+s=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=dtUQK+it7DhezXywi/idifHHMdch9D1kdNpnve/7HTapPAyjxs0ZuXEWkS4gqqQzS DTd5wFio21QUfg6Lqx6cpLeAdRR+vetHdohVB68jIbZx6XdgOpYHNaGc6yW/I4YkIA uc63wNR5NvtnmGeMVmeA4pYWdefXBPgwrmsQSjVdcNfQahMWZggt0FeOgOWSicl06P +kjh9N4CkAf648oPhnd3nkYdpFFo26cXexs9/ayV4XMiPIUJ1+AnXtN9m35zGhwyDA gKUXPhjxxUhQ0buLG9k+yELkM4QTWlrNZtWXdLNxufR8rnGrHUMs5NhkOmxSf5BGGY Bd9au4tXfEMqA== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 7B2BC17E107E; Tue, 11 Aug 2026 12:17:52 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:44 +0200 Subject: [PATCH v2 10/17] drm/panthor: Check AS state before disabling Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-10-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=1813; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=tdKa3iEPlj3pDEW5mojDJ07XRew8XsVzU/fp1UTnZ+s=; b=DL0wv/KpUhTY11HUkSoSQ0lr6Ag4Jnb3mHCpc/YqeDKuHesr6CS4z6SUnJr2alm65cl2LvAuz dQF3rqYQboaDeOMk+YDY5WV7DRbn+W5fGt8qr8Mle8MX7I+ka4qeTHb X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Use TRANSTAB =3D=3D 0 as a way to detect if an AS slot is idle. This allows us to make panthor_mmu_as_disable() a NOP when it's called after a SOFT_RESET, which will be needed for our unplug rework. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 16 +++++++++++++--- 1 file changed, 13 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 1b401fd0d2d7..a48466788f4d 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -634,6 +634,10 @@ static int panthor_mmu_as_disable(struct panthor_devic= e *ptdev, u32 slot, =20 lockdep_assert_held(&ptdev->mmu->as.slots_lock); =20 + /* The AS was disabled already, nothing to do. */ + if (!gpu_read64(mmu->iomem, AS_TRANSTAB(slot))) + return 0; + panthor_mmu_irq_disable_events(&ptdev->mmu->irq, panthor_mmu_as_fault_mask(ptdev, slot)); =20 @@ -656,11 +660,17 @@ static int panthor_mmu_as_disable(struct panthor_devi= ce *ptdev, u32 slot, if (recycle_slot) return 0; =20 - gpu_write64(mmu->iomem, AS_TRANSTAB(slot), 0); - gpu_write64(mmu->iomem, AS_MEMATTR(slot), 0); gpu_write64(mmu->iomem, AS_TRANSCFG(slot), AS_TRANSCFG_ADRMODE_UNMAPPED); + ret =3D as_send_cmd_and_wait(ptdev, slot, AS_COMMAND_UPDATE); + if (ret) + return ret; =20 - return as_send_cmd_and_wait(ptdev, slot, AS_COMMAND_UPDATE); + /* We reset the other fields late to ensure that, if something fails, + * the page table is considered active (TRANSTAB !=3D NULL). + */ + gpu_write64(mmu->iomem, AS_MEMATTR(slot), 0); + gpu_write64(mmu->iomem, AS_TRANSTAB(slot), 0); + return 0; } =20 static u32 panthor_mmu_fault_mask(struct panthor_device *ptdev, u32 value) --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF56743BDD6 for ; Tue, 11 Aug 2026 10:18:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443512; cv=none; b=EnhTXhE2ep/uBc8PcnZ9pTi/K4tDWTEYGgpNeJ/zmAe4rELZG90Aloil4yll3LVWZi9XxfluuFvAyVrdvL7Ogurfy3RUjw6Ojs8qoJEODFEKGksL7U3PCAatT4RzzhoFLA51w/1iwx5pmeG5/Y7e9/ScpFitjln5P2VkNNQahHU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443512; c=relaxed/simple; bh=eIGFqWwRdHzc0YJCpTSG0l4q+0hV+wtL1nhMwVIM0fw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=ahl/gcq1/DZi5xHSkzl+1CNGmzct2aQa4Vz1UtDBQybslS8jkOEcgYTCszyzT1ltqR807fIiZU9U0v9MbL8fkonpW7uGo2PHJ62cQ5UCa5WtQ8vOyb05jkGfTfzA+nT5N+5HVspRIbS/9V43y/O3CPfe39ieQP7bw3ERuYgh3qs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=WYMbkO4j; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="WYMbkO4j" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443473; bh=eIGFqWwRdHzc0YJCpTSG0l4q+0hV+wtL1nhMwVIM0fw=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=WYMbkO4j8wNvXblqz9TsTRTHpgPsqiMuMH74og3prNM60jAQ5Auf1IXADuyEXTqhk S0bbVd2gtr/7ZtQq5456K+LRs0m+/tYiEPxBZHGNu/ILfdm9nu/xR/yyF9XIB76sgH jTK2rNRtEDK0XVNQTJyRPisS4pb6IGoPRXrGpLfNgyKQBED/3DoYgSdc+1bLn5Or12 5doU/LsAZbGMN6HagF+lxNVoydyk0POO0mVUqWK9289+NVfTd8GlurisYefkc9M1OT j7Ra63Fzy+RIY64RDwc/NkPpsmvoHmzZ6F+NmwV/A/52i42MKb6OlCx8ZhdTH8Q6ye zSkqQQpEA6YOQ== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 086C817E10BE; Tue, 11 Aug 2026 12:17:53 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:45 +0200 Subject: [PATCH v2 11/17] drm/panthor: Don't pre-allocate VMAs or page tables when preparing a full VM unmap Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-11-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=1151; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=eIGFqWwRdHzc0YJCpTSG0l4q+0hV+wtL1nhMwVIM0fw=; b=z1SA76QrLdUgnR1+zNEf53fehokyNlqidR3JmCeOxIhO9FT9Hyxw8/STWywYQOUT++5VYBQ6Q LeI6D8V6YFLC6YyfibkyWxlS4SbFIJmxFuhPf28uBg9hfCPzPaCzbRt X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= In the cleanup path, we unmap the full VA range to make sure things are clean before the VM is released. I'd rather not fail on memory allocation in that path, so let's make sure panthor_vm_pgtable_prepare_unmap_op_ctx() doesn't allocate VMAs or page tables when the unmap range matches the VM virtual address range. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index a48466788f4d..acdc0dd04f8b 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -1466,6 +1466,10 @@ static int panthor_as_prepare_unmap_op_ctx(struct pa= nthor_as_op_ctx *op_ctx, op_ctx->va.addr =3D va; op_ctx->flags =3D DRM_PANTHOR_VM_BIND_OP_TYPE_UNMAP; =20 + /* Unmap on the whole VM range don't need new VMAs or page tables. */ + if (va =3D=3D as->base.mm_start && size =3D=3D as->base.mm_range) + return 0; + /* Pre-allocate L3 page tables to account for the split-2M-block * situation on unmap. */ --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5A78F43B6D2 for ; Tue, 11 Aug 2026 10:18:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; cv=none; b=nNKCPqx5UU/oVChmqm/oL6SYLTffO0XJMFfaOGItvf+J7Gk6KcP48hwVcrvR/UNI991OGCbcLwUFTj5TdDhg9x2BFdS0vIVqgo4qsfMugnIi4dASJ+p6ZOTgVe6aNGXKtsRbYBRmgD2bpldJ+sAiXHnFKb1mZRrNQ6deCRBPO8A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; c=relaxed/simple; bh=MMB3tis1Iw6TJXUg2/lV4hJQ0a/iBpumFaeH2zEhW2g=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=XvtmgGpjodPiqTL0c42RurtHwW4sCBI5rZ6Z/yXZyOl7cR6trc/VGp8wm9pZNT9yT+Lz73z/Vh0/JZPegaTcIi2sm9Iuwr3gQjK8JLHuiHLVpwnHKPaE7Mvv8L0AvtO/WEA/zcktL/1Exg6Vof9y4d0eF/relpO5Tomd4qGh34g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=m7HbmNX1; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="m7HbmNX1" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443473; bh=MMB3tis1Iw6TJXUg2/lV4hJQ0a/iBpumFaeH2zEhW2g=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=m7HbmNX1fsoEqqcpgOQIa8D5TRrYwMQSGhd++R2Z/pgjNn1uRb2/23DjkTShZkYdp HkoIVs987LWGI9hRD6L9gl8SrseR1UIR9ren3/zezNW7sHOdL+H7PHpuTZff3MNSLv fEeK25o7ALcGUite9MD2yUuoVJsey5ir1J6THAgnKbxOwkTbtrg2Z9EgK6y9HeJCXP TxcgvP/PddrNJlMCJTx0GWr338HRLg5KgeDpS6udIS6PLHuGA8m86/7P7EzYZHJ6Tf SEUGGOyhyGaWRAIElZuvbsLZWyiH6i4sCiJzqX/t/uVyDipEsAwbdGb8ebTi0/W5Q2 nhQYIV5L4hrLA== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 8835217E11F6; Tue, 11 Aug 2026 12:17:53 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:46 +0200 Subject: [PATCH v2 12/17] drm/panthor: Make the VM cleanup path more robust against UAF Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-12-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443466; l=11511; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=MMB3tis1Iw6TJXUg2/lV4hJQ0a/iBpumFaeH2zEhW2g=; b=lxPh8xX1kINRzOHMxuD66aNzu9cd9l36K0TnTM0YMNZrnPGsAylxZvyxNyJFGAm+lyHEXsp/O WEzUMF1S1hiCTWhO/di3IaQdgci8/TOtvFHSz293Wl0If2C4KG1p4Mk X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= The VM cleanup tries to gracefully evict the page table from its AS slot to make sure the HW doesn't have access to the memory anymore. But it might happen that the eviction fails because the HW hung, and in that case, we have no guarantee that the HW won't access the memory until we've properly reset the GPU. Defer the cleanup of VMs after the reset is effective when this situation happens. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 239 +++++++++++++++++++++++++-----= ---- 1 file changed, 175 insertions(+), 64 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index acdc0dd04f8b..93e9d55da783 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -92,6 +92,17 @@ struct panthor_mmu { * TLB/cache flushes. */ struct list_head lru_list; + + /** + * @cleanup_list: List containing VMs waiting for cleanup. + * + * This list is used to keep track of VMs that got released but + * couldn't be evicted from their AS slot because the HW hanged. + * In that case, we add the VM to the list, and wait for the next + * post_reset, at which point we're sure the HW is idle and the + * VM resources can go away. + */ + struct list_head cleanup_list; } as; =20 /** @vm: VMs management fields */ @@ -107,6 +118,12 @@ struct panthor_mmu { =20 /** @vm.wq: Workqueue used for the VM_BIND queues. */ struct workqueue_struct *wq; + + /** + * @vm.cleanup_work: Used to cleanup the VMs that are in + * panthor_mmu::as::cleanup_list. + */ + struct work_struct cleanup_work; } vm; }; =20 @@ -2002,6 +2019,35 @@ void panthor_mmu_suspend(struct panthor_device *ptde= v) panthor_mmu_irq_suspend(&ptdev->mmu->irq); } =20 +static void mmu_post_reset_cleanup(struct panthor_device *ptdev) +{ + guard(mutex)(&ptdev->mmu->as.slots_lock); + + /* Now that the reset is effective, we can assume that none of the + * AS slots are setup, and clear the faulty flags too. + */ + ptdev->mmu->as.alloc_mask =3D 0; + ptdev->mmu->as.faulty_mask =3D 0; + + for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { + struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; + + if (!as) + continue; + + panthor_as_release_hw_slot_locked(as); + + /* FIXME: We shouldn't drop the no-unmap restriction if + * we're in the unplug path and the device wasn't properly + * stopped with a SOFT_RESET. + */ + atomic_and(~PANTHOR_AS_FORBID_UNMAP, &as->restrictions); + } + + if (!list_empty(&ptdev->mmu->as.cleanup_list)) + queue_work(panthor_cleanup_wq, &ptdev->mmu->vm.cleanup_work); +} + /** * panthor_mmu_resume() - Resume the MMU logic * @ptdev: Device. @@ -2013,11 +2059,7 @@ void panthor_mmu_suspend(struct panthor_device *ptde= v) */ void panthor_mmu_resume(struct panthor_device *ptdev) { - mutex_lock(&ptdev->mmu->as.slots_lock); - ptdev->mmu->as.alloc_mask =3D 0; - ptdev->mmu->as.faulty_mask =3D 0; - mutex_unlock(&ptdev->mmu->as.slots_lock); - + mmu_post_reset_cleanup(ptdev); panthor_mmu_irq_resume(&ptdev->mmu->irq); } =20 @@ -2055,22 +2097,7 @@ void panthor_mmu_post_reset(struct panthor_device *p= tdev) { struct panthor_vm *vm; =20 - mutex_lock(&ptdev->mmu->as.slots_lock); - - /* Now that the reset is effective, we can assume that none of the - * AS slots are setup, and clear the faulty flags too. - */ - ptdev->mmu->as.alloc_mask =3D 0; - ptdev->mmu->as.faulty_mask =3D 0; - - for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { - struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; - - if (as) - panthor_as_release_hw_slot_locked(as); - } - - mutex_unlock(&ptdev->mmu->as.slots_lock); + mmu_post_reset_cleanup(ptdev); =20 panthor_mmu_irq_resume(&ptdev->mmu->irq); =20 @@ -2083,58 +2110,26 @@ void panthor_mmu_post_reset(struct panthor_device *= ptdev) mutex_unlock(&ptdev->mmu->vm.lock); } =20 -static void panthor_vm_release(struct kref *kref) +static void vm_cleanup(struct panthor_vm *vm) { - struct panthor_vm *vm =3D container_of(kref, struct panthor_vm, refcount); struct panthor_as *as =3D vm->as; struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); =20 - /* Make sure the page table behind this VM doesn't participate in reclaim - * after that point, since we're about to release everything anyway. - */ - mutex_lock(&ptdev->base.gem_lru_mutex); - list_del_init(&as->reclaim.lru_node); - mutex_unlock(&ptdev->base.gem_lru_mutex); + if (!(atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_UNMAP)) { + /* Unmap everything in case some BOs were still mapped. */ + drm_WARN_ON(&ptdev->base, + panthor_vm_unmap_range(vm, as->base.mm_start, as->base.mm_range)); + } =20 - /* Unmap everything in case some BOs were still mapped. */ - drm_WARN_ON(&ptdev->base, - panthor_vm_unmap_range(vm, as->base.mm_start, as->base.mm_range)); - - mutex_lock(&vm->heaps.lock); - if (drm_WARN_ON(&ptdev->base, vm->heaps.pool)) - panthor_heap_pool_destroy(vm->heaps.pool); - mutex_unlock(&vm->heaps.lock); + scoped_guard(mutex, &vm->heaps.lock) { + if (drm_WARN_ON(&ptdev->base, vm->heaps.pool)) + panthor_heap_pool_destroy(vm->heaps.pool); + } mutex_destroy(&vm->heaps.lock); =20 - mutex_lock(&ptdev->mmu->vm.lock); - list_del(&vm->node); - /* Restore the scheduler state so we can call drm_sched_entity_destroy() - * and drm_sched_fini(). If get there, that means we have no job left - * and no new jobs can be queued, so we can start the scheduler without - * risking interfering with the reset. - */ - if (ptdev->mmu->vm.reset_in_progress) - panthor_vm_start(vm); - mutex_unlock(&ptdev->mmu->vm.lock); - drm_sched_entity_destroy(&vm->entity); drm_sched_fini(&vm->sched); =20 - mutex_lock(&vm->as->op_lock); - mutex_lock(&ptdev->mmu->as.slots_lock); - if (as->hw_slot.id >=3D 0) { - int cookie; - - if (drm_dev_enter(&ptdev->base, &cookie)) { - panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); - drm_dev_exit(cookie); - } - - panthor_as_release_hw_slot_locked(as); - } - mutex_unlock(&ptdev->mmu->as.slots_lock); - mutex_unlock(&vm->as->op_lock); - if (vm->dummy) drm_gem_object_put(&vm->dummy->base); =20 @@ -2143,6 +2138,88 @@ static void panthor_vm_release(struct kref *kref) kfree(vm); } =20 +static bool vm_prep_for_cleanup(struct panthor_vm *vm) +{ + struct panthor_as *as =3D vm->as; + struct panthor_device *ptdev =3D container_of(as->base.drm, struct pantho= r_device, base); + bool ready_for_cleanup; + int cookie, ret; + + /* First we forbid any kind of use on the VM that's about to be + * released. UNMAP will be restored later if we manage to evict + * the page table from its AS slot. + */ + atomic_or(PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP | + PANTHOR_AS_FORBID_UNMAP, + &vm->as->restrictions); + + /* Make sure the page table behind this VM doesn't participate in reclaim + * after that point, since we're about to release everything anyway. + */ + scoped_guard(mutex, &ptdev->base.gem_lru_mutex) + list_del_init(&as->reclaim.lru_node); + + scoped_guard(mutex, &ptdev->mmu->vm.lock) { + /* Remove the VM from the list early, so it can't be seen by the VM list + * walkers after that point. + */ + list_del(&vm->node); + + /* Restore the scheduler state so we can call drm_sched_entity_destroy() + * and drm_sched_fini(). If get there, that means we have no job left + * and no new jobs can be queued, so we can start the scheduler without + * risking interfering with the reset. + */ + if (ptdev->mmu->vm.reset_in_progress) + panthor_vm_start(vm); + } + + if (!drm_dev_enter(&ptdev->base, &cookie)) { + guard(mutex)(&ptdev->mmu->as.slots_lock); + + /* We're in the unplug path and can't recover from + * that, so we just forcibly evict the pgtable. The + * no-unmap restriction will leak resources if + * we can't guarantee the HW stopped. + */ + if (as->hw_slot.id >=3D 0) + panthor_as_release_hw_slot_locked(as); + + return true; + } + + scoped_guard(mutex, &ptdev->mmu->as.slots_lock) { + if (as->hw_slot.id >=3D 0) { + ret =3D panthor_mmu_as_disable(ptdev, as->hw_slot.id, false); + if (!ret) { + panthor_as_release_hw_slot_locked(as); + } else { + list_add_tail(&vm->node, &ptdev->mmu->as.cleanup_list); + panthor_device_schedule_reset(ptdev); + } + } + + /* Page table is no longer resident, we can relax the no-unmap + * restriction. + */ + ready_for_cleanup =3D as->hw_slot.id < 0; + if (ready_for_cleanup) + atomic_and(~PANTHOR_AS_FORBID_UNMAP, &as->restrictions); + } + + drm_dev_exit(cookie); + return ready_for_cleanup; +} + +static void panthor_vm_release(struct kref *kref) +{ + struct panthor_vm *vm =3D container_of(kref, struct panthor_vm, refcount); + + if (vm_prep_for_cleanup(vm)) + vm_cleanup(vm); +} + /** * panthor_vm_put() - Release a reference on a VM * @vm: VM to release the reference on. Can be NULL. @@ -2758,7 +2835,11 @@ static void panthor_as_free(struct drm_gpuvm *gpuvm) { struct panthor_as *as =3D container_of(gpuvm, struct panthor_as, base); =20 - if (as->pt.ops) + /* If we get to that point and we're still not allowed to unmap, + * this means the HW is still running and has a access to the page + * table, so we just leak it to avoid UAF. + */ + if (as->pt.ops && !(atomic_read(&as->restrictions) & PANTHOR_AS_FORBID_UN= MAP)) free_io_pgtable_ops(as->pt.ops); =20 mutex_destroy(&as->op_lock); @@ -3473,6 +3554,13 @@ void panthor_mmu_unplug(struct panthor_device *ptdev) } mutex_unlock(&ptdev->mmu->as.slots_lock); =20 + /* Make sure pending VM cleanups are processed before leaving. Those + * cleanups might schedule vm_bind_job cleanups, so keep this + * flush_work() before the final flush_workqueue(panthor_cleanup_wq). + */ + flush_work(&ptdev->mmu->vm.cleanup_work); + drm_WARN_ON(&ptdev->base, !list_empty(&ptdev->mmu->as.cleanup_list)); + /* Ensure any pending job cleanup work are executed before returning, * otherwise those might access objects that are gone if the work is * executed after other components are unplugged. @@ -3490,6 +3578,27 @@ static void panthor_mmu_info_init(struct panthor_dev= ice *ptdev) ptdev->mmu_info.page_size_bitmap =3D SZ_4K | SZ_2M; } =20 +static void mmu_cleanup_vms_work(struct work_struct *work) +{ + struct panthor_mmu *mmu =3D + container_of(work, struct panthor_mmu, vm.cleanup_work); + struct panthor_vm *vm, *tmp; + LIST_HEAD(cleanup_list); + + /* Collect the VMs to cleanup first. */ + scoped_guard(mutex, &mmu->as.slots_lock) { + list_for_each_entry_safe(vm, tmp, &mmu->as.cleanup_list, node) { + if (vm->as->hw_slot.id < 0) + list_move_tail(&vm->node, &cleanup_list); + } + } + + list_for_each_entry_safe(vm, tmp, &cleanup_list, node) { + list_del(&vm->node); + vm_cleanup(vm); + } +} + /** * panthor_mmu_init() - Initialize the MMU logic. * @ptdev: Device. @@ -3508,7 +3617,9 @@ int panthor_mmu_init(struct panthor_device *ptdev) if (!mmu) return -ENOMEM; =20 + INIT_WORK(&mmu->vm.cleanup_work, mmu_cleanup_vms_work); INIT_LIST_HEAD(&mmu->as.lru_list); + INIT_LIST_HEAD(&mmu->as.cleanup_list); =20 ret =3D drmm_mutex_init(&ptdev->base, &mmu->as.slots_lock); if (ret) --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF82843BDDB for ; Tue, 11 Aug 2026 10:18:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443507; cv=none; b=u3HmIx3JiehmKzGojXDHrLbWQALKlN6Dp60FVpxYZmVMzaEErLMhVVX8lr9XuiAZkBbVktyb6zmATXh8vnTeo1K23GXFWNO9PVif0JSp6CaPhxdnesRwE+aX+5+D38k4TmH4xNfEjg90gGK16pLD/ENRwuCLOCVC7fBmZ0JGiM4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443507; c=relaxed/simple; bh=ZYp1BwFYi/2bMtugS7zfwiZcE/lz4o2JKqmO8xY3DZg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Qsu4GjbANnEKi5YasVRDRO4dZSk1uYS1oS7/N3Ny27FmV6o6BOvLgNGKESncev+VxyXH/t0jc69sdRgYpBbo1k+jIvbt4j0m5topVFJQydAk+BmuHLPBdwIF4mwWtQb+EgGGTDYSpaVZ9rv0dHqllqGqmEgA+KR6cSWfY0xfbao= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=OyN0CK2L; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="OyN0CK2L" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443474; bh=ZYp1BwFYi/2bMtugS7zfwiZcE/lz4o2JKqmO8xY3DZg=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=OyN0CK2L/BWmz56KZILZlyitqyDMV/7BudwMHU+mdbWnEGLWv7QgNKSptrjz6HYuH uIZpSpQi8YG5Gt4MgdkYPaGX80xuz+VNUPVDFMvV/1gX2gF1XXRDPiXHMr2GmyJx9Z nAjtDG5vBxw8AVP+hBt1X/k0tDjkghLZUQRu57lqW83G8VLo2eMguH8stu115Aq4lE OQykSiwqCJactx8eYLfi6UKaiJJ7r3S3r+MbfMAXc6rmlZXBN5afYpY3cvkJOwo2np 3KdRmQISEqro8fJeIBrnHamirNHJ9J2KAzUAJlu6kUU4CpRXKviiCaZFbACQN4BtCR j1ZqZ8wpG1d9Q== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 116A817E121B; Tue, 11 Aug 2026 12:17:54 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:47 +0200 Subject: [PATCH v2 13/17] drm/panthor: Track user owned VMs Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-13-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443467; l=3118; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=ZYp1BwFYi/2bMtugS7zfwiZcE/lz4o2JKqmO8xY3DZg=; b=E6X2u1SlVbfXZJFr5NcQYVPfwjUJLGgjEPktcj/6ShDfxYzGNiPzJIGQSEkQPZebr4Ue0KB0c T/jfpramj//DGOWle0q1ERIqrh2HMWh6amKS3Hd7U+RP4DrTaxuyffA X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= We will soon need this to fix the unplug logic and make sure panthor_vm objects are not left behind after an unplug. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 29 ++++++++++++++++++++++++++--- 1 file changed, 26 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 93e9d55da783..5672d437d52d 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -107,12 +107,15 @@ struct panthor_mmu { =20 /** @vm: VMs management fields */ struct { - /** @vm.lock: Lock protecting access to list. */ + /** @vm.lock: Lock protecting access to list and user_owned. */ struct mutex lock; =20 /** @vm.list: List containing all VMs. */ struct list_head list; =20 + /** @vm.list: List containing VMs with a valid handle. */ + struct list_head user_owned; + /** @vm.reset_in_progress: True if a reset is in progress. */ bool reset_in_progress; =20 @@ -427,6 +430,9 @@ struct panthor_vm { /** @node: Used to insert the VM in the panthor_mmu::vm::list. */ struct list_head node; =20 + /* @user_node: Used to insert the VM in the panthor_mmu::vm::user_owned l= ist. */ + struct list_head user_node; + /** @for_mcu: True if this is the MCU VM. */ bool for_mcu; =20 @@ -1669,10 +1675,19 @@ int panthor_vm_pool_create_vm(struct panthor_device= *ptdev, drm_gem_object_get(&pool->dummy->base); vm->dummy =3D pool->dummy; =20 + /* Insert in the list before xa_alloc() so we can't race with + * panthor_vm_pool_destroy_vm() have the VM inserted in the + * user_owned list after it's been destroyed. + */ + scoped_guard(mutex, &ptdev->mmu->vm.lock) + list_add_tail(&vm->user_node, &ptdev->mmu->vm.user_owned); + ret =3D xa_alloc(&pool->xa, &id, vm, XA_LIMIT(1, PANTHOR_MAX_VMS_PER_FILE), GFP_KERNEL); =20 if (ret) { + scoped_guard(mutex, &ptdev->mmu->vm.lock) + list_del_init(&vm->user_node); panthor_vm_put(vm); return ret; } @@ -1727,13 +1742,19 @@ static void panthor_vm_destroy(struct panthor_vm *v= m) */ int panthor_vm_pool_destroy_vm(struct panthor_vm_pool *pool, u32 handle) { + struct panthor_device *ptdev; struct panthor_vm *vm; =20 vm =3D xa_erase(&pool->xa, handle); + if (!vm) + return -EINVAL; + + ptdev =3D container_of(vm->as->base.drm, struct panthor_device, base); + scoped_guard(mutex, &ptdev->mmu->vm.lock) + list_del_init(&vm->user_node); =20 panthor_vm_destroy(vm); - - return vm ? 0 : -EINVAL; + return 0; } =20 /** @@ -3118,6 +3139,7 @@ panthor_vm_create(struct panthor_device *ptdev, bool = for_mcu, goto err_put_as; } =20 + INIT_LIST_HEAD(&vm->user_node); vm->user_va_range =3D kernel_va_start; vm->as =3D as; mutex_init(&vm->heaps.lock); @@ -3626,6 +3648,7 @@ int panthor_mmu_init(struct panthor_device *ptdev) return ret; =20 INIT_LIST_HEAD(&mmu->vm.list); + INIT_LIST_HEAD(&mmu->vm.user_owned); ret =3D drmm_mutex_init(&ptdev->base, &mmu->vm.lock); if (ret) return ret; --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B077543C061 for ; Tue, 11 Aug 2026 10:18:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; cv=none; b=UDHjfXPRaCW1BdRDRSu6c/ERAX7R/V1CwcrMVzRjoP6/yTqHFflQsG1sWFJECSK3clkRGx0pDxgaesH28cENveJfiiBGN2L7p/5OxK2A1CM67D88lgOXoUh9J40KSLDiTuLv9vMAIvRBVo3Vm2A2UlDgumS7YI95nMu9MyAOHLU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443505; c=relaxed/simple; bh=lcAAaMZkFVpvqzbW1ekUP0RAfWGLsBJ4f5VZYcVrQW8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=pSKlzhWjTYlRVLROufoqhVQYffVU3YLHhIRKaBm5QPeWKpk6aDsEfbUdMGLbq4oVKnk2KyX/Wpe+hDZtnUA5Bh772WIF59JgjElBpvSmnYbYJd0DZ8MecYSBnFUheAHV+5si0Ul/CwJKzgncm2b1VNj09aIESThAk48ArZchFms= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=ZFhNbWgG; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="ZFhNbWgG" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443474; bh=lcAAaMZkFVpvqzbW1ekUP0RAfWGLsBJ4f5VZYcVrQW8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=ZFhNbWgGJDJHNFrbiTrXMkjLvVsqm48o5wa/dmm9LDQXiKdL64xIeDqZHvDJbIkWZ Ev/r649AAgqwYCEYja2YVf4hhjuR4nDJsy8AD5vcXHwSqIVbUfQl1ODKnfCQgcvZcB T0DWLRNEOHYehR5MwYIa3/8PTP7ZHk7iSN2NUtfqy7uqAhxKOxe2rEX0B5emkxKx1W /9bV+MCoidJAJaKi9HupJEMs5wRhOEjQfnV8jVj8f4OTvZmPd7x4hwv66LkfMI0NR3 anpLL6JmE+9h3LkztoGg0sF2/YkWZDJLUHTZWpTRrJh4IvbJw89PB0E7w/EMatNQW0 mHX2IlT6colbw== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 9334F17E121D; Tue, 11 Aug 2026 12:17:54 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:48 +0200 Subject: [PATCH v2 14/17] drm/panthor: Track user owned groups Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-14-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443467; l=4878; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=lcAAaMZkFVpvqzbW1ekUP0RAfWGLsBJ4f5VZYcVrQW8=; b=A+82uoOnOw4n6wtdo3NOs2UIvJoh+JkdgkKrsXaMXK+N9qZti59ELWt5MZ7QCGv3sjyAfZSW3 T4PTbmaXuikB/tJs/eS86Lc5VhNtpDNLUnGyWvu32rvi8BDRVs6gJ2x X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= A group can outlive its user handle because of internal refs. In order to fix the unplug logic, we need to keep track of groups that have a valid user handle so we can release the references that were owned by the user processes in the unplug path. This is the prep work to keep track of user owned groups. Note that the destroyed attribute is dropped because it's equivalent to checking whether the group is inserted in the user_owned list now. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_sched.c | 39 +++++++++++++++++++++++------= ---- 1 file changed, 27 insertions(+), 12 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_sched.c b/drivers/gpu/drm/pant= hor/panthor_sched.c index f18b2e03f2fd..756c3fa7a242 100644 --- a/drivers/gpu/drm/panthor/panthor_sched.c +++ b/drivers/gpu/drm/panthor/panthor_sched.c @@ -252,6 +252,15 @@ struct panthor_scheduler { * This list is evaluated in the @sync_upd_work work. */ struct list_head waiting; + + /** + * @user_owned: List of groups that have a valid user handle. + * + * All groups are inserted in this list at creation time through their + * panthor_group;:user_node, and evicted from this list when + * panthor_group_destroy() is called. + */ + struct list_head user_owned; } groups; =20 /** @@ -587,15 +596,6 @@ struct panthor_group { */ int csg_id; =20 - /** - * @destroyed: True when the group has been destroyed. - * - * If a group is destroyed it becomes useless: no further jobs can be sub= mitted - * to its queues. We simply wait for all references to be dropped so we c= an - * release the group object. - */ - bool destroyed; - /** * @timedout: True when a timeout occurred on any of the queues owned by * this group. @@ -705,6 +705,17 @@ struct panthor_group { * panthor_group::groups::waiting list. */ struct list_head wait_node; + + /** + * @user_node: Used to insert the group in the panthor_scheduler::groups:= :user_owned list. + * + * When the group is created, it's inserted in panthor_scheduler::groups:= :user_owned, + * and when panthor_group_destroy, the group is remove from this list. + * + * When the device is unplugged, all groups that remain in this list must= have an extra + * put_group() called on them to release the reference owned by the per-f= ile group pool. + */ + struct list_head user_node; }; =20 struct panthor_job_profiling_data { @@ -967,6 +978,7 @@ static void group_release(struct kref *kref) struct panthor_device *ptdev =3D group->ptdev; =20 drm_WARN_ON(&ptdev->base, group->csg_id >=3D 0); + drm_WARN_ON(&ptdev->base, !list_empty(&group->user_node)); drm_WARN_ON(&ptdev->base, !list_empty(&group->run_node)); drm_WARN_ON(&ptdev->base, !list_empty(&group->wait_node)); =20 @@ -1082,7 +1094,7 @@ group_can_run(struct panthor_group *group) { return group->state !=3D PANTHOR_CS_GROUP_TERMINATED && group->state !=3D PANTHOR_CS_GROUP_UNKNOWN_STATE && - !group->destroyed && group->fatal_queues =3D=3D 0 && + !list_empty(&group->user_node) && group->fatal_queues =3D=3D 0 && !group->timedout; } =20 @@ -2403,7 +2415,7 @@ tick_ctx_apply(struct panthor_scheduler *sched, struc= t panthor_sched_tick_ctx *c * re-evaluate as soon as possible and get rid of * this dangling group. */ - if (group->destroyed) + if (list_empty(&group->user_node)) ctx->immediate_tick =3D true; group_put(group); } @@ -3691,6 +3703,7 @@ int panthor_group_create(struct panthor_file *pfile, group->tiler_core_mask =3D group_args->tiler_core_mask; group->priority =3D group_args->priority; =20 + INIT_LIST_HEAD(&group->user_node); INIT_LIST_HEAD(&group->wait_node); INIT_LIST_HEAD(&group->run_node); INIT_WORK(&group->term_work, group_term_work); @@ -3764,6 +3777,7 @@ int panthor_group_create(struct panthor_file *pfile, mutex_lock(&sched->lock); list_add_tail(&group->run_node, &sched->groups.idle[group->priority]); + list_add_tail(&group->user_node, &sched->groups.user_owned); mutex_unlock(&sched->lock); } mutex_unlock(&sched->reset.lock); @@ -3801,7 +3815,7 @@ int panthor_group_destroy(struct panthor_file *pfile,= u32 group_handle) =20 mutex_lock(&sched->reset.lock); mutex_lock(&sched->lock); - group->destroyed =3D true; + list_del_init(&group->user_node); if (group->csg_id >=3D 0) { sched_queue_delayed_work(sched, tick, 0); } else if (!atomic_read(&sched->reset.in_progress)) { @@ -4167,6 +4181,7 @@ int panthor_sched_init(struct panthor_device *ptdev) INIT_LIST_HEAD(&sched->groups.idle[prio]); } INIT_LIST_HEAD(&sched->groups.waiting); + INIT_LIST_HEAD(&sched->groups.user_owned); =20 ret =3D drmm_mutex_init(&ptdev->base, &sched->reset.lock); if (ret) --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF48F43B6CC for ; Tue, 11 Aug 2026 10:18:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443507; cv=none; b=QJZk19B+Q3u4YaLMiA0WJv53CFCVeMkAeNzm4DhnJtsOIhMXuK2wuvxtcTpV2KyxCMsg/86Yk4u9mKcIz83ovPkITTOaIWHw0Wg15pd8Y16qPUNQVHmluN3Sk39w9HOxi5jPbGihD74VH4ncjA7I62d5AHq4ci6DKVd5XtaGifg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443507; c=relaxed/simple; bh=TviPz1FlyvJV94lktEvYQlU3XjvzrR+5TgVN0dnYaaA=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=o+tUjlDLj+iW/2cyZXMLJxS0IttRJdY4pAABefx3gGWRUzWMkZh5jXSOJQ7aLCMvSBvg08dxJeBf2NyEBn5faq7g0y51EX4+0o9ESeQGNNgerVof4jn7UwwiFXcsuLy4GMw84iXGlOSvk1cBJYJWHYR8fnGr311P4MRfqE08k2g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=fsbyNBaw; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="fsbyNBaw" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443475; bh=TviPz1FlyvJV94lktEvYQlU3XjvzrR+5TgVN0dnYaaA=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=fsbyNBawvhx9uVRd8WyNcZ1osgZw2bNt2CehNVtH78wW/c0U5Cj6gxTpRf+kmktcK bSFwHxptzipOHLYz2GVzRnj+SHnt3PANjRAQg4d8Uk8ktqpKJ5qzkm+eLRwVL6Un8o 6UDDK25mA8TB++wC+JC8I9pml/RBl3rT5nL6SZOCoYVsiRg7xGldFXlioLUD7TRT7j t4zTS+si81aVgrTKz+oYj6RxxDO6GxWb6F3HeAVHZRHDKgLiaOrIeOZN6AGgcsBw0r 9EXR/D6rx1R8WwXofhCRgohORE63D8zYNmYbbHZyqH8KHESQ5kjS6m12jPC4OVb752 dLq6+XaAoxZWw== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 1B80D17E12A2; Tue, 11 Aug 2026 12:17:55 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:49 +0200 Subject: [PATCH v2 15/17] drm/panthor: Fix the unplug logic Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-15-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443467; l=25271; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=TviPz1FlyvJV94lktEvYQlU3XjvzrR+5TgVN0dnYaaA=; b=ib+33whB7cbiV9hSWrqP9tEX4FYjsvAVwH8+D3oniyLF1oh7G51r2abB6rJtzpL/KPCdTwD/P eFfghv+XcdtCmFDQ/ry2SGJUUCID3DUZbCCTSazcjaZEzNgOMukK5bE X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= The current unplug logic is broken in multiple subtle ways: 1. it assumes that the HW is still accessible in multiple places, which goes against the very concept of hot-unplug 2. it doesn't take into account the fact the stop is a failible operation, and that we theoretically have no guarantee that the HW is actually stopped after we've released the resources Those issues are hard to reason about because Mali GPUs are on a platform bus, which is not hot-pluggable, so they are in practice always accessible as long as we can enable their dependencies (clocks, power-domain, ...). The problem is, if the GPU is in such a bad state it can't properly reset/resume, there are various operations that can't be done properly, and the unplug logic is clearly not ready for that. And more importantly, if we can't guarantee the reset was effective, we have to assume the HW still has access to the resource we passed to it, meaning we can't return these resources to the system without risking a UAF. This patch does several things: - it resets the GPU before calling the _unplug() functions - it drops the pm_get/put that around the sub-component unplug calls (no longer needed if we assume the HW is gone and can't be accessed anymore) - it changes the _unplug() implementations to not touch the HW anymore - it let's each component know whether it should leak resources the HW might have its hands on at the time the unplug happens - it releases all resources at unplug time even if open FDs exist. This is needed otherwise we could have deferred cleanup work accessing objects that have been freed Unfortunately, I couldn't find a way to break things into multiple commits while preserving bisectability. Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 45 +++++++++--- drivers/gpu/drm/panthor/panthor_device.h | 15 ++++ drivers/gpu/drm/panthor/panthor_drv.c | 114 ++++++++++++++++++++++++---= ---- drivers/gpu/drm/panthor/panthor_fw.c | 9 +-- drivers/gpu/drm/panthor/panthor_mmu.c | 96 +++++++++++++++++++++----- drivers/gpu/drm/panthor/panthor_mmu.h | 1 + drivers/gpu/drm/panthor/panthor_sched.c | 83 +++++++++++++++++++++- 7 files changed, 301 insertions(+), 62 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index d9eab6021145..d037c89e6198 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -62,8 +62,34 @@ static int panthor_init_power(struct device *dev) return devm_pm_domain_attach_list(dev, NULL, &pd_list); } =20 +static int panthor_device_stop_before_unplug(struct panthor_device *ptdev) +{ + int ret; + + /* Make sure any further modification to the existing VMs are blocked + * before proceeding with the SOFT_RESET. + */ + panthor_mmu_freeze_before_unplug(ptdev); + + /* Core clock should be enough to issue a reset. */ + ret =3D clk_prepare_enable(ptdev->clks.core); + if (ret) + return ret; + + /* A successful soft-reset should guarantee that all components of the + * HW are off, meaning we can proceed with the rest of the unplug + * procedure. + */ + ret =3D panthor_hw_soft_reset(ptdev); + + clk_disable_unprepare(ptdev->clks.core); + return ret; +} + void panthor_device_unplug(struct panthor_device *ptdev) { + int ret; + /* This function can be called from two different path: the reset work * and the platform device remove callback. drm_dev_unplug() doesn't * deal with concurrent callers, so we have to protect drm_dev_unplug() @@ -80,8 +106,6 @@ void panthor_device_unplug(struct panthor_device *ptdev) return; } =20 - drm_WARN_ON(&ptdev->base, pm_runtime_get_sync(ptdev->base.dev) < 0); - /* Call drm_dev_unplug() so any access to HW blocks happening after * that point get rejected. */ @@ -102,6 +126,16 @@ void panthor_device_unplug(struct panthor_device *ptde= v) /* Make sure we're not interrupted by resets while we're unplugging. */ disable_work_sync(&ptdev->reset.work); =20 + /* Do anything we can to stop the HW. If we can't guarantee that the HW + * is fully stopped, we also can't guarantee the resources it had access + * to won't be touched after the device is gone (clocks and regulators + * can be shared, and the HW might still be running behind our back). + */ + ret =3D panthor_device_stop_before_unplug(ptdev); + if (drm_WARN(&ptdev->base, ret, + "Couldn't stop the device, this might lead to resource leaks")) + ptdev->unplug.leak_active_resources =3D true; + /* Now, try to cleanly shutdown the GPU before the device resources * get reclaimed. */ @@ -112,13 +146,6 @@ void panthor_device_unplug(struct panthor_device *ptde= v) panthor_gpu_unplug(ptdev); panthor_pwr_unplug(ptdev); =20 - pm_runtime_dont_use_autosuspend(ptdev->base.dev); - pm_runtime_put_sync_suspend(ptdev->base.dev); - - /* If PM is disabled, we need to call the suspend handler manually. */ - if (!IS_ENABLED(CONFIG_PM)) - panthor_device_suspend(ptdev->base.dev); - /* Report the unplug operation as done to unblock concurrent * panthor_device_unplug() callers. */ diff --git a/drivers/gpu/drm/panthor/panthor_device.h b/drivers/gpu/drm/pan= thor/panthor_device.h index 10c96abf9cff..8c9177cf5da2 100644 --- a/drivers/gpu/drm/panthor/panthor_device.h +++ b/drivers/gpu/drm/panthor/panthor_device.h @@ -267,6 +267,21 @@ struct panthor_device { =20 /** @work: Unplug work. */ struct work_struct work; + + /** + * @leak_active_resources: Sub-components should leak resources HW has + * access to. + * + * This is set to true when we can guarantee the HW has been fully stopp= ed + * in the unplug path. In that case, we'd rather leak resource than retu= rn + * them to the system with the risk that they might be accessed by the + * HW behind our back. + * + * This is particularly important for any piece of memory used by the GPU + * (MMU page tables, FW sections, group resources shared with the FW, + * any BO attached to an active VM, ...). + */ + bool leak_active_resources; } unplug; =20 /** @reset: Reset related fields. */ diff --git a/drivers/gpu/drm/panthor/panthor_drv.c b/drivers/gpu/drm/pantho= r/panthor_drv.c index 924a7ecd3733..bdbda7f5a8bd 100644 --- a/drivers/gpu/drm/panthor/panthor_drv.c +++ b/drivers/gpu/drm/panthor/panthor_drv.c @@ -1025,11 +1025,21 @@ static int panthor_ioctl_vm_destroy(struct drm_devi= ce *ddev, void *data, { struct panthor_file *pfile =3D file->driver_priv; struct drm_panthor_vm_destroy *args =3D data; + int cookie, ret; =20 - if (args->pad) - return -EINVAL; + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; =20 - return panthor_vm_pool_destroy_vm(pfile->vms, args->id); + if (args->pad) { + ret =3D -EINVAL; + goto out_dev_exit; + } + + ret =3D panthor_vm_pool_destroy_vm(pfile->vms, args->id); + +out_dev_exit: + drm_dev_exit(cookie); + return ret; } =20 #define PANTHOR_BO_FLAGS (DRM_PANTHOR_BO_NO_MMAP | \ @@ -1219,11 +1229,21 @@ static int panthor_ioctl_group_destroy(struct drm_d= evice *ddev, void *data, { struct panthor_file *pfile =3D file->driver_priv; struct drm_panthor_group_destroy *args =3D data; + int cookie, ret; =20 - if (args->pad) - return -EINVAL; + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; =20 - return panthor_group_destroy(pfile, args->group_handle); + if (args->pad) { + ret =3D -EINVAL; + goto out_dev_exit; + } + + ret =3D panthor_group_destroy(pfile, args->group_handle); + +out_dev_exit: + drm_dev_exit(cookie); + return ret; } =20 static int panthor_ioctl_group_create(struct drm_device *ddev, void *data, @@ -1232,27 +1252,36 @@ static int panthor_ioctl_group_create(struct drm_de= vice *ddev, void *data, struct panthor_file *pfile =3D file->driver_priv; struct drm_panthor_group_create *args =3D data; struct drm_panthor_queue_create *queue_args; - int ret; + int cookie, ret; =20 - if (!args->queues.count || args->queues.count > MAX_CS_PER_CSG) - return -EINVAL; + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; + + if (!args->queues.count || args->queues.count > MAX_CS_PER_CSG) { + ret =3D -EINVAL; + goto out_dev_exit; + } =20 ret =3D PANTHOR_UOBJ_GET_ARRAY(queue_args, &args->queues); if (ret) - return ret; + goto out_dev_exit; =20 ret =3D group_priority_permit(file, args->priority); if (ret) - goto out; + goto out_free_args; =20 ret =3D panthor_group_create(pfile, args, queue_args, file->client_id); if (ret < 0) - goto out; + goto out_free_args; + args->group_handle =3D ret; ret =3D 0; =20 -out: +out_free_args: kvfree(queue_args); + +out_dev_exit: + drm_dev_exit(cookie); return ret; } =20 @@ -1261,8 +1290,15 @@ static int panthor_ioctl_group_get_state(struct drm_= device *ddev, void *data, { struct panthor_file *pfile =3D file->driver_priv; struct drm_panthor_group_get_state *args =3D data; + int cookie, ret; =20 - return panthor_group_get_state(pfile, args); + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; + + ret =3D panthor_group_get_state(pfile, args); + + drm_dev_exit(cookie); + return ret; } =20 static int panthor_ioctl_tiler_heap_create(struct drm_device *ddev, void *= data, @@ -1272,11 +1308,16 @@ static int panthor_ioctl_tiler_heap_create(struct d= rm_device *ddev, void *data, struct drm_panthor_tiler_heap_create *args =3D data; struct panthor_heap_pool *pool; struct panthor_vm *vm; - int ret; + int cookie, ret; + + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; =20 vm =3D panthor_vm_pool_get_vm(pfile->vms, args->vm_id); - if (!vm) - return -EINVAL; + if (!vm) { + ret =3D -EINVAL; + goto out_dev_exit; + } =20 pool =3D panthor_vm_get_heap_pool(vm, true); if (IS_ERR(pool)) { @@ -1305,6 +1346,9 @@ static int panthor_ioctl_tiler_heap_create(struct drm= _device *ddev, void *data, =20 out_put_vm: panthor_vm_put(vm); + +out_dev_exit: + drm_dev_exit(cookie); return ret; } =20 @@ -1315,14 +1359,21 @@ static int panthor_ioctl_tiler_heap_destroy(struct = drm_device *ddev, void *data, struct drm_panthor_tiler_heap_destroy *args =3D data; struct panthor_heap_pool *pool; struct panthor_vm *vm; - int ret; + int cookie, ret; =20 - if (args->pad) - return -EINVAL; + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; + + if (args->pad) { + ret =3D -EINVAL; + goto out_dev_exit; + } =20 vm =3D panthor_vm_pool_get_vm(pfile->vms, args->handle >> 16); - if (!vm) - return -EINVAL; + if (!vm) { + ret =3D -EINVAL; + goto out_dev_exit; + } =20 pool =3D panthor_vm_get_heap_pool(vm, false); if (IS_ERR(pool)) { @@ -1335,6 +1386,9 @@ static int panthor_ioctl_tiler_heap_destroy(struct dr= m_device *ddev, void *data, =20 out_put_vm: panthor_vm_put(vm); + +out_dev_exit: + drm_dev_exit(cookie); return ret; } =20 @@ -1466,10 +1520,16 @@ static int panthor_ioctl_vm_get_state(struct drm_de= vice *ddev, void *data, struct panthor_file *pfile =3D file->driver_priv; struct drm_panthor_vm_get_state *args =3D data; struct panthor_vm *vm; + int cookie, ret; + + if (!drm_dev_enter(ddev, &cookie)) + return -ENODEV; =20 vm =3D panthor_vm_pool_get_vm(pfile->vms, args->vm_id); - if (!vm) - return -EINVAL; + if (!vm) { + ret =3D -EINVAL; + goto out_dev_exit; + } =20 if (panthor_vm_is_unusable(vm)) args->state =3D DRM_PANTHOR_VM_STATE_UNUSABLE; @@ -1477,7 +1537,11 @@ static int panthor_ioctl_vm_get_state(struct drm_dev= ice *ddev, void *data, args->state =3D DRM_PANTHOR_VM_STATE_USABLE; =20 panthor_vm_put(vm); - return 0; + ret =3D 0; + +out_dev_exit: + drm_dev_exit(cookie); + return ret; } =20 static int panthor_ioctl_bo_set_label(struct drm_device *ddev, void *data, diff --git a/drivers/gpu/drm/panthor/panthor_fw.c b/drivers/gpu/drm/panthor= /panthor_fw.c index fc1a423e48a8..8d9fdc3202a1 100644 --- a/drivers/gpu/drm/panthor/panthor_fw.c +++ b/drivers/gpu/drm/panthor/panthor_fw.c @@ -1285,11 +1285,9 @@ void panthor_fw_unplug(struct panthor_device *ptdev) =20 disable_delayed_work_sync(&ptdev->fw->watchdog.ping_work); =20 - if (!IS_ENABLED(CONFIG_PM) || pm_runtime_active(ptdev->base.dev)) { - /* Make sure the IRQ handler cannot be called after that point. */ + /* Make sure the IRQ handler cannot be called after that point. */ + if (!IS_ENABLED(CONFIG_PM) || pm_runtime_active(ptdev->base.dev)) panthor_job_irq_suspend(&ptdev->fw->irq); - panthor_fw_stop(ptdev); - } =20 list_for_each_entry(section, &ptdev->fw->sections, node) panthor_kernel_bo_destroy(section->mem); @@ -1301,9 +1299,6 @@ void panthor_fw_unplug(struct panthor_device *ptdev) */ panthor_vm_put(ptdev->fw->vm); ptdev->fw->vm =3D NULL; - - if (!IS_ENABLED(CONFIG_PM) || pm_runtime_active(ptdev->base.dev)) - panthor_hw_l2_power_off(ptdev); } =20 /** diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 5672d437d52d..56ca23580d21 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -1787,17 +1787,27 @@ panthor_vm_pool_get_vm(struct panthor_vm_pool *pool= , u32 handle) */ void panthor_vm_pool_destroy(struct panthor_file *pfile) { + struct panthor_device *ptdev =3D pfile->ptdev; struct panthor_vm *vm; unsigned long i; + int cookie; =20 if (!pfile->vms) return; =20 - xa_for_each(&pfile->vms->xa, i, vm) - panthor_vm_destroy(vm); + /* If device is gone VMs have been destroyed already, and the XArray + * contains pointers to objects that have been freed. + */ + if (drm_dev_enter(&ptdev->base, &cookie)) { + xa_for_each(&pfile->vms->xa, i, vm) + panthor_vm_destroy(vm); + + drm_dev_exit(cookie); + } =20 if (pfile->vms->dummy) drm_gem_object_put(&pfile->vms->dummy->base); + xa_destroy(&pfile->vms->xa); kfree(pfile->vms); } @@ -2040,7 +2050,7 @@ void panthor_mmu_suspend(struct panthor_device *ptdev) panthor_mmu_irq_suspend(&ptdev->mmu->irq); } =20 -static void mmu_post_reset_cleanup(struct panthor_device *ptdev) +static void mmu_post_reset_cleanup(struct panthor_device *ptdev, bool on_u= nplug) { guard(mutex)(&ptdev->mmu->as.slots_lock); =20 @@ -2058,11 +2068,12 @@ static void mmu_post_reset_cleanup(struct panthor_d= evice *ptdev) =20 panthor_as_release_hw_slot_locked(as); =20 - /* FIXME: We shouldn't drop the no-unmap restriction if - * we're in the unplug path and the device wasn't properly - * stopped with a SOFT_RESET. + /* If this is an unplug situation and leak_active_resources is + * true, we have to keep the no-unmap restriction to force a + * resource leak. */ - atomic_and(~PANTHOR_AS_FORBID_UNMAP, &as->restrictions); + if (!on_unplug || !ptdev->unplug.leak_active_resources) + atomic_and(~PANTHOR_AS_FORBID_UNMAP, &as->restrictions); } =20 if (!list_empty(&ptdev->mmu->as.cleanup_list)) @@ -2080,7 +2091,7 @@ static void mmu_post_reset_cleanup(struct panthor_dev= ice *ptdev) */ void panthor_mmu_resume(struct panthor_device *ptdev) { - mmu_post_reset_cleanup(ptdev); + mmu_post_reset_cleanup(ptdev, false); panthor_mmu_irq_resume(&ptdev->mmu->irq); } =20 @@ -2118,7 +2129,7 @@ void panthor_mmu_post_reset(struct panthor_device *pt= dev) { struct panthor_vm *vm; =20 - mmu_post_reset_cleanup(ptdev); + mmu_post_reset_cleanup(ptdev, false); =20 panthor_mmu_irq_resume(&ptdev->mmu->irq); =20 @@ -2197,8 +2208,19 @@ static bool vm_prep_for_cleanup(struct panthor_vm *v= m) } =20 if (!drm_dev_enter(&ptdev->base, &cookie)) { + /* Device is gone, take the unplug lock to make sure + * panthor_device_stop_before_unplug() has run and + * ::leak_active_resources is valid. + */ + guard(mutex)(&ptdev->unplug.lock); guard(mutex)(&ptdev->mmu->as.slots_lock); =20 + /* If we're not asked to leak resources, drop the + * no-unmap restriction. + */ + if (!ptdev->unplug.leak_active_resources) + atomic_and(~PANTHOR_AS_FORBID_UNMAP, &as->restrictions); + /* We're in the unplug path and can't recover from * that, so we just forcibly evict the pgtable. The * no-unmap restriction will leak resources if @@ -3552,6 +3574,41 @@ panthor_mmu_reclaim_priv_bos(struct panthor_device *= ptdev, return freed; } =20 +void panthor_mmu_freeze_before_unplug(struct panthor_device *ptdev) +{ + struct panthor_vm *vm; + + guard(mutex)(&ptdev->mmu->vm.lock); + guard(mutex)(&ptdev->mmu->as.slots_lock); + list_for_each_entry(vm, &ptdev->mmu->vm.list, node) { + /* We intentionally don't use panthor_vm_restrict_usage_locked() here + * because we don't want the AS eviction to happen, otherwise we + * won't be able to know which VMs were active at the time the + * unplug happened. Unmap is forbidden to make sure any modification + * to the VM is blocked after that point. This way, if the reset + * fails, we're able to flag VMs that need to leak their resources. + */ + atomic_or(PANTHOR_AS_FORBID_USE | + PANTHOR_AS_FORBID_MAP | + PANTHOR_AS_FORBID_UNMAP, + &vm->as->restrictions); + } +} + +static struct panthor_vm * +pop_user_owned_vm(struct panthor_device *ptdev) +{ + struct panthor_vm *vm; + + guard(mutex)(&ptdev->mmu->vm.lock); + vm =3D list_first_entry_or_null(&ptdev->mmu->vm.user_owned, + struct panthor_vm, user_node); + if (vm) + list_del_init(&vm->user_node); + + return vm; +} + /** * panthor_mmu_unplug() - Unplug the MMU logic * @ptdev: Device. @@ -3564,17 +3621,18 @@ void panthor_mmu_unplug(struct panthor_device *ptde= v) if (!IS_ENABLED(CONFIG_PM) || pm_runtime_active(ptdev->base.dev)) panthor_mmu_irq_suspend(&ptdev->mmu->irq); =20 - mutex_lock(&ptdev->mmu->as.slots_lock); - for (u32 i =3D 0; i < ARRAY_SIZE(ptdev->mmu->as.slots); i++) { - struct panthor_as *as =3D ptdev->mmu->as.slots[i].as; + mmu_post_reset_cleanup(ptdev, true); =20 - if (as) { - drm_WARN_ON(&ptdev->base, - panthor_mmu_as_disable(ptdev, i, false)); - panthor_as_release_hw_slot_locked(as); - } + /* Collect non-destroyed user VMs so we can return the ref owned by the + * XArray. If we don't do that, we leak all user VMs that were still + * alive at the point drm_dev_unplug() was called, because + * panthor_ioctl_vm_destroy() bails out early if the device is + * unplugged. + */ + for (struct panthor_vm *vm =3D pop_user_owned_vm(ptdev); vm; + vm =3D pop_user_owned_vm(ptdev)) { + panthor_vm_destroy(vm); } - mutex_unlock(&ptdev->mmu->as.slots_lock); =20 /* Make sure pending VM cleanups are processed before leaving. Those * cleanups might schedule vm_bind_job cleanups, so keep this @@ -3582,6 +3640,8 @@ void panthor_mmu_unplug(struct panthor_device *ptdev) */ flush_work(&ptdev->mmu->vm.cleanup_work); drm_WARN_ON(&ptdev->base, !list_empty(&ptdev->mmu->as.cleanup_list)); + drm_WARN_ON(&ptdev->base, !list_empty(&ptdev->mmu->vm.list)); + drm_WARN_ON(&ptdev->base, !list_empty(&ptdev->mmu->vm.user_owned)); =20 /* Ensure any pending job cleanup work are executed before returning, * otherwise those might access objects that are gone if the work is diff --git a/drivers/gpu/drm/panthor/panthor_mmu.h b/drivers/gpu/drm/pantho= r/panthor_mmu.h index 3522fbbce369..efe6e07936a0 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.h +++ b/drivers/gpu/drm/panthor/panthor_mmu.h @@ -18,6 +18,7 @@ struct panthor_vma; struct panthor_mmu; =20 int panthor_mmu_init(struct panthor_device *ptdev); +void panthor_mmu_freeze_before_unplug(struct panthor_device *ptdev); void panthor_mmu_unplug(struct panthor_device *ptdev); void panthor_mmu_pre_reset(struct panthor_device *ptdev); void panthor_mmu_post_reset(struct panthor_device *ptdev); diff --git a/drivers/gpu/drm/panthor/panthor_sched.c b/drivers/gpu/drm/pant= hor/panthor_sched.c index 756c3fa7a242..e834fca11070 100644 --- a/drivers/gpu/drm/panthor/panthor_sched.c +++ b/drivers/gpu/drm/panthor/panthor_sched.c @@ -3049,12 +3049,17 @@ static void update_fdinfo_stats(struct panthor_job = *job) void panthor_fdinfo_gather_group_samples(struct panthor_file *pfile) { struct panthor_group_pool *gpool =3D pfile->groups; + struct panthor_device *ptdev =3D pfile->ptdev; struct panthor_group *group; unsigned long i; + int cookie; =20 if (IS_ERR_OR_NULL(gpool)) return; =20 + if (!drm_dev_enter(&ptdev->base, &cookie)) + return; + xa_lock(&gpool->xa); xa_for_each_marked(&gpool->xa, i, group, GROUP_REGISTERED) { guard(spinlock)(&group->fdinfo.lock); @@ -3064,6 +3069,8 @@ void panthor_fdinfo_gather_group_samples(struct panth= or_file *pfile) group->fdinfo.data.time =3D 0; } xa_unlock(&gpool->xa); + + drm_dev_exit(cookie); } =20 static bool queue_check_job_completion(struct panthor_queue *queue) @@ -3893,14 +3900,23 @@ int panthor_group_pool_create(struct panthor_file *= pfile) void panthor_group_pool_destroy(struct panthor_file *pfile) { struct panthor_group_pool *gpool =3D pfile->groups; + struct panthor_device *ptdev =3D pfile->ptdev; struct panthor_group *group; unsigned long i; + int cookie; =20 if (IS_ERR_OR_NULL(gpool)) return; =20 - xa_for_each(&gpool->xa, i, group) - panthor_group_destroy(pfile, i); + /* If device is gone groups have been destroyed already, and the XArray + * contains pointers to objects that have been freed. + */ + if (drm_dev_enter(&ptdev->base, &cookie)) { + xa_for_each(&gpool->xa, i, group) + panthor_group_destroy(pfile, i); + + drm_dev_exit(cookie); + } =20 xa_destroy(&gpool->xa); kfree(gpool); @@ -3919,11 +3935,16 @@ panthor_fdinfo_gather_group_mem_info(struct panthor= _file *pfile, struct drm_memory_stats *stats) { struct panthor_group_pool *gpool =3D pfile->groups; + struct panthor_device *ptdev =3D pfile->ptdev; struct panthor_group *group; unsigned long i; + int cookie; + + if (!drm_dev_enter(&ptdev->base, &cookie)) + return; =20 if (IS_ERR_OR_NULL(gpool)) - return; + goto out_dev_exit; =20 xa_lock(&gpool->xa); xa_for_each_marked(&gpool->xa, i, group, GROUP_REGISTERED) { @@ -3932,6 +3953,9 @@ panthor_fdinfo_gather_group_mem_info(struct panthor_f= ile *pfile, stats->active +=3D group->fdinfo.kbo_sizes; } xa_unlock(&gpool->xa); + +out_dev_exit: + drm_dev_exit(cookie); } =20 static void job_release(struct kref *ref) @@ -4077,23 +4101,76 @@ void panthor_job_update_resvs(struct drm_exec *exec= , struct drm_sched_job *sched void panthor_sched_unplug(struct panthor_device *ptdev) { struct panthor_scheduler *sched =3D ptdev->scheduler; + struct panthor_group *group, *tmp_group; + LIST_HEAD(groups); =20 disable_delayed_work_sync(&sched->tick_work); disable_work_sync(&sched->fw_events_work); disable_work_sync(&sched->sync_upd_work); =20 mutex_lock(&sched->lock); + + /* Do a pass on the on-slot groups, and schedule termination. */ + for (u32 i =3D 0; i < sched->csg_slot_count; i++) { + struct panthor_csg_slot *csg_slot =3D &sched->csg_slots[i]; + struct panthor_group *group =3D csg_slot->group; + + if (!group) + continue; + + group_get(group); + group->state =3D PANTHOR_CS_GROUP_TERMINATED; + group_unbind_locked(group); + list_del_init(&group->wait_node); + group_queue_work(group, term); + + group_put(group); + } + + /* Now take care of the non-resident groups. */ + for (u32 i =3D 0; i < ARRAY_SIZE(sched->groups.runnable); i++) + list_splice_init(&sched->groups.runnable[i], &groups); + + for (u32 i =3D 0; i < ARRAY_SIZE(sched->groups.idle); i++) + list_splice_init(&sched->groups.idle[i], &groups); + + list_for_each_entry_safe(group, tmp_group, &groups, run_node) { + list_del_init(&group->run_node); + list_del_init(&group->wait_node); + group_queue_work(group, term); + } + + /* All groups that still have a user handle need a group_put() + * because after drm_dev_unplug() has been called those handles + * can't be released through the GROUP_DESTROY IOCTL anymore. + */ + list_for_each_entry_safe(group, tmp_group, &sched->groups.user_owned, use= r_node) { + list_del_init(&group->user_node); + group_put(group); + } + if (sched->pm.has_ref) { pm_runtime_put(ptdev->base.dev); sched->pm.has_ref =3D false; } mutex_unlock(&sched->lock); =20 + /* Ensure all term work are done. */ + flush_workqueue(sched->wq); + /* Ensure any pending group release work are executed before returning, * otherwise those might access objects that are gone if the work is * executed after other components are unplugged. */ flush_workqueue(panthor_cleanup_wq); + + /* After we've flushed the workqueues, all lists should be empty. */ + drm_WARN_ON(&ptdev->base, !list_empty(&sched->groups.user_owned)); + for (u32 i =3D 0; i < ARRAY_SIZE(sched->groups.runnable); i++) + drm_WARN_ON(&ptdev->base, !list_empty(&sched->groups.runnable[i])); + + for (u32 i =3D 0; i < ARRAY_SIZE(sched->groups.idle); i++) + drm_WARN_ON(&ptdev->base, !list_empty(&sched->groups.idle[i])); } =20 static void panthor_sched_fini(struct drm_device *ddev, void *res) --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AF9BE43C05F for ; Tue, 11 Aug 2026 10:18:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443508; cv=none; b=Fn0vqAqNzwYxbmr3CliKZ0Phw8Ppdx5jsA5+Lb0qlU+qPEdpJclNjm+NJDtdL+Oj/CDvkupfKzi36bHcv3EH2+XFiYON6BhLRKiaX1ESo85nDfSDGRmpdjvrizD5d9ws3K4DpFO0COQ7zL7veCTGpqVZrd40DfZb/91xC6z+3L8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443508; c=relaxed/simple; bh=7N37NOXE6t6LYdtHY0SctYLGB3NwQAvWVebTTDpQLj0=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=nlLhd8B5u4OT0tpltyaT3osJIrleZzGxmiQ7JPwsIaqWPKoA1kVhlHe+UcIM9d7r3uCbzEevQ5BjtJyZbc6whgAZYYzypHJnqKgc/x+c6Xhl47EjEbdnXIWlDbFa36yb/ABLYgEyc566Jrpe0qzfq6knxCYxwJPB4rbgDEcHmCs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=PrRsa3Bp; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="PrRsa3Bp" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443476; bh=7N37NOXE6t6LYdtHY0SctYLGB3NwQAvWVebTTDpQLj0=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=PrRsa3BpGICCHsRY14WqT0OWimJLNCQzl1BCmU9s1jIXl794EP2Lcs136evfpMI6e SndTPSTux1U0X6OAW1oxonFIZLqUeLUen0QH3Y3ZjkgbldtNX6fPyC8mV5or40abo4 PmdhQIC237R/2vgLM1AKLDxvkQAj9C7wSxBw98mg5LRJvv61WPnAmHlOKppnf3r0vO Xw2xTJFEj4xalPC9GMXVCDJeVmZWjvNWZ6PsYTJOOjrct+Fo7al7zgXojB5TxkPN9i ZelJ7LWIqJn40VgQMbGrRBd0PLo+SeQlxbnJVEeN2BdAOWweJyRmvT555WCeiQRATo Ka5UMkegPyI4w== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id A444017E12AC; Tue, 11 Aug 2026 12:17:55 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:50 +0200 Subject: [PATCH v2 16/17] drm/panthor: Add a debugfs knob to simulate unplug failures Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-16-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443467; l=3076; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=7N37NOXE6t6LYdtHY0SctYLGB3NwQAvWVebTTDpQLj0=; b=eIwFSb1TMMVWONvICcJN0HA92yitzHVt2oSWHWis4iLtsPgz1EV79nZAPD4ChAr5B91x75j+I G+IXEk2YD7WCui198R3h9sPDFhGr+rC1PvbQaJO1ngzf6LDZjvpetyR X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Unplug failures are almost impossible to reproduce in practice, so let's add a debugfs knob to simulate those. With this new knob, we can check this error case with the following sequence: # echo 1 > /sys/kernel/debug/dri/128/fake_unplug_failure # # echo fb000000.gpu > /sys/module/panthor/drivers/platform\:panthor/unbind # Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 28 ++++++++++++++++++++++++++++ drivers/gpu/drm/panthor/panthor_device.h | 8 ++++++++ 2 files changed, 36 insertions(+) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index d037c89e6198..012edf5d590c 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -4,6 +4,7 @@ /* Copyright 2023 Collabora ltd. */ /* Copyright 2025 ARM Limited. All rights reserved. */ =20 +#include #include #include #include @@ -81,6 +82,8 @@ static int panthor_device_stop_before_unplug(struct panth= or_device *ptdev) * procedure. */ ret =3D panthor_hw_soft_reset(ptdev); + if (!ret && ptdev->unplug.fake_failure) + ret =3D -EIO; =20 clk_disable_unprepare(ptdev->clks.core); return ret; @@ -676,8 +679,33 @@ int panthor_device_suspend(struct device *dev) } =20 #ifdef CONFIG_DEBUG_FS +static int panthor_device_fake_unplug_failure_get(void *data, u64 *val) +{ + struct panthor_device *ptdev =3D data; + + *val =3D ptdev->unplug.fake_failure ? 1 : 0; + return 0; +} + +static int panthor_device_fake_unplug_failure_set(void *data, u64 val) +{ + struct panthor_device *ptdev =3D data; + + ptdev->unplug.fake_failure =3D val ? true : false; + return 0; +} + +DEFINE_DEBUGFS_ATTRIBUTE(panthor_device_fake_unplug_failure_fops, + panthor_device_fake_unplug_failure_get, + panthor_device_fake_unplug_failure_set, "%llu\n"); + void panthor_device_debugfs_init(struct drm_minor *minor) { + struct panthor_device *ptdev =3D container_of(minor->dev, struct panthor_= device, base); + + debugfs_create_file("fake_unplug_failure", 0644, + minor->debugfs_root, ptdev, + &panthor_device_fake_unplug_failure_fops); panthor_mmu_debugfs_init(minor); panthor_gem_debugfs_init(minor); } diff --git a/drivers/gpu/drm/panthor/panthor_device.h b/drivers/gpu/drm/pan= thor/panthor_device.h index 8c9177cf5da2..b2788373bfa9 100644 --- a/drivers/gpu/drm/panthor/panthor_device.h +++ b/drivers/gpu/drm/panthor/panthor_device.h @@ -282,6 +282,14 @@ struct panthor_device { * any BO attached to an active VM, ...). */ bool leak_active_resources; + + /** + * @fake_failure: When true, pretend the SOFT_RESET in the unplug path f= ailed. + * + * This is important to check that we're doing the right thing in this v= ery + * unlikely case. + */ + bool fake_failure; } unplug; =20 /** @reset: Reset related fields. */ --=20 2.55.0 From nobody Tue Sep 29 06:58:49 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D2A97431A5C for ; Tue, 11 Aug 2026 10:18:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443521; cv=none; b=N763VKdIM5CQuspuTB0Yjrdr3VKaSxJC73gJCZjzxzTWODarA+0nOKf4pPMeo52NRvC97tjMugy3qYGuOiRniTLSCGCZArvRoAcwqO3EMwtqd6y8ipwXN1X/9wSzEcP0iwVhWkmHfxsCk9NrWkGS8VW+eXLqeBZUsJasTXAjUZU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786443521; c=relaxed/simple; bh=mUoAoXlDI7yZyvH60OvVhl7XJ24dV86jsycZLjHMo7U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=LH+dGxPmJZAeWPA1bwcL6uHKxn2ZLK5jQmfyaQ9YS8VZMHaGML96CkznNcBlO/PTfH/GGoSwFL0sBYgRGD6ZZf7Q+ol7Q9TCIIrsnPLjgVTzTY4GXaIbjqkNysOPoWbs6g7zeQRg4VLDNh6PoHqkizs2GLASlzJDAkwuTHQf7QQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=YbrHB5ZA; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="YbrHB5ZA" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786443476; bh=mUoAoXlDI7yZyvH60OvVhl7XJ24dV86jsycZLjHMo7U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=YbrHB5ZAe69NiObLrwREIj5xxCMmeYtXrtI/5PpwyWd8hwk2/dKP6iHpD6B1ITruW JnpsElxANrgxpucAAFqogHaScUStHa4rGJztGMJ4WdIkBDN4Jm6Gvq6EhZ0ZpwZrcE yQXnzLRE4B2x1RK4LqwjYBYp2FMkytuUqkGEVGIZYwDb2MskPhBfyECtFd8QloZPLo ZPHPsBRVQ9HtZ9IVPV+GEWPeFWS0qz3NZl+kRmWMFDELlA02wbARM3pgoO+6oZoWQw BEExpeej2zCpNBaS5sS1/2dDPmLNjQhQrH4EwpO8cJRIgoc4d8zGlzHe8bKkQwzb2X 0zIlehRXyqG9A== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 306D517E12AE; Tue, 11 Aug 2026 12:17:56 +0200 (CEST) From: Boris Brezillon Date: Tue, 11 Aug 2026 12:17:51 +0200 Subject: [PATCH v2 17/17] drm/panthor: Add a debugfs knobs to simulate reset failures Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260811-panthor-unplug-fixes-v2-17-6b583e37f9ae@collabora.com> References: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> In-Reply-To: <20260811-panthor-unplug-fixes-v2-0-6b583e37f9ae@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786443467; l=3671; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=mUoAoXlDI7yZyvH60OvVhl7XJ24dV86jsycZLjHMo7U=; b=CMqGYTbeMGpUymG0t0PK1yg0WM9B44OlTt3NMAV6ERJsy93lVaqTECzIY8ai7sVkkc5EqSDlw 4oHpHG/ZTJZDy2DqFiAvScHH5WunZCFwzYXMxoypj4lB59by8JZKnZj X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= It's almost impossible to trigger a situation where the reset doesn't work now that the driver is more mature, so let's add two knobs to exercise this error path: - a knob to trigger a reset - a knob to fake an error in the reset path Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_device.c | 45 ++++++++++++++++++++++++++++= +++- drivers/gpu/drm/panthor/panthor_device.h | 8 ++++++ 2 files changed, 52 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/panthor/panthor_device.c b/drivers/gpu/drm/pan= thor/panthor_device.c index 012edf5d590c..09c9cc922e70 100644 --- a/drivers/gpu/drm/panthor/panthor_device.c +++ b/drivers/gpu/drm/panthor/panthor_device.c @@ -198,7 +198,10 @@ static void panthor_device_reset_work(struct work_stru= ct *work) panthor_hw_soft_reset(ptdev); panthor_hw_l2_power_on(ptdev); panthor_mmu_post_reset(ptdev); - ret =3D panthor_fw_post_reset(ptdev); + if (ptdev->reset.fake_failure) + ret =3D -EIO; + else + ret =3D panthor_fw_post_reset(ptdev); panthor_sched_post_reset(ptdev, ret !=3D 0); drm_dev_exit(cookie); =20 @@ -699,6 +702,40 @@ DEFINE_DEBUGFS_ATTRIBUTE(panthor_device_fake_unplug_fa= ilure_fops, panthor_device_fake_unplug_failure_get, panthor_device_fake_unplug_failure_set, "%llu\n"); =20 +static int panthor_device_fake_fw_reset_failure_get(void *data, u64 *val) +{ + struct panthor_device *ptdev =3D data; + + *val =3D ptdev->reset.fake_failure ? 1 : 0; + return 0; +} + +static int panthor_device_fake_fw_reset_failure_set(void *data, u64 val) +{ + struct panthor_device *ptdev =3D data; + + ptdev->reset.fake_failure =3D val ? true : false; + return 0; +} + +DEFINE_DEBUGFS_ATTRIBUTE(panthor_device_fake_fw_reset_failure_fops, + panthor_device_fake_fw_reset_failure_get, + panthor_device_fake_fw_reset_failure_set, "%llu\n"); + +static ssize_t panthor_device_reset_file_write(struct file *file, + const char __user *, size_t size, + loff_t *) +{ + struct panthor_device *ptdev =3D file_inode(file)->i_private; + + panthor_device_schedule_reset(ptdev); + return size; +} + +static const struct debugfs_short_fops panthor_device_reset_fops =3D { + .write =3D panthor_device_reset_file_write, +}; + void panthor_device_debugfs_init(struct drm_minor *minor) { struct panthor_device *ptdev =3D container_of(minor->dev, struct panthor_= device, base); @@ -706,6 +743,12 @@ void panthor_device_debugfs_init(struct drm_minor *min= or) debugfs_create_file("fake_unplug_failure", 0644, minor->debugfs_root, ptdev, &panthor_device_fake_unplug_failure_fops); + debugfs_create_file("fake_fw_reset_failure", 0644, + minor->debugfs_root, ptdev, + &panthor_device_fake_fw_reset_failure_fops); + debugfs_create_file("reset", 0200, + minor->debugfs_root, ptdev, + &panthor_device_reset_fops); panthor_mmu_debugfs_init(minor); panthor_gem_debugfs_init(minor); } diff --git a/drivers/gpu/drm/panthor/panthor_device.h b/drivers/gpu/drm/pan= thor/panthor_device.h index b2788373bfa9..160593824ef2 100644 --- a/drivers/gpu/drm/panthor/panthor_device.h +++ b/drivers/gpu/drm/panthor/panthor_device.h @@ -313,6 +313,14 @@ struct panthor_device { * all FW sections to make sure we start from a fresh state. */ bool fast; + + /** + * @fake_failure: When true, pretend the FW boot in the reset path faile= d. + * + * This is important to check that we're doing the right thing in this v= ery + * unlikely case. + */ + bool fake_failure; } reset; =20 /** @pm: Power management related data. */ --=20 2.55.0