From nobody Tue Sep 29 05:35:25 2026 Received: from out-183.mta0.migadu.com (out-183.mta0.migadu.com [91.218.175.183]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B4321406818 for ; Tue, 11 Aug 2026 20:46:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.183 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481210; cv=none; b=obf6Brr3Gy2lfjpg1EifDqMT4AI/y1JlL5jUd/LxMaSEWqU3GaAou0jR8T8NwFXXdqs4I96/SPH8JI1KYOaE7W009ZK/R6StNEf1Qgy3cL75pSVW8huAqirGgTePgJ8xKIOg1GT7o1fk0csImywhFAU17EvpBtP27XpSfkqeMTw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481210; c=relaxed/simple; bh=cwk9bNwBWVL+AmXZmNT0dHFKF9mJOaQCKyrhf/EqdqI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fsTL3Ac+Zu2E20QPdujZPI0CyjHvMw28GfdgNKB3XVsPTw9dzuvfRfLmlN3uJJ8Tv2csZXHZaqQkPyjmLssRq7Hlg6jGEHNV+2qQIotAB/ptox4xaCnuHEuJ795KfrRVgklWkrNkMjJrwZ0LkwHsjWWWOcvYZ8YJH4ryjoK1Yms= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com; spf=pass smtp.mailfrom=kaitmazov.com; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b=bBkmNYWG; arc=none smtp.client-ip=91.218.175.183 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b="bBkmNYWG" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kaitmazov.com; s=key1; t=1786481206; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2ntw0VuP3EeY8k4KPnQJ84+od73prlFVgKVcC4psjLY=; b=bBkmNYWGoLopsn087f7L9jlJ5Q3Jwv+PHzJG/NCbk4WbingkQcZg6nlTsInWx/xTcQb0Ci jOK3erqfLnKDZjvL6nMhT6flxnTQkb1SbYBu7/uK226/WbBTwuGbPnobGvMioKRQSYl453 ItP7G/NO/gUuWmWDEUimQS42y9V06/a8yEOkx+2wReYk43lRv6G0wDJei6yLlI5lHnUghl 6TqOS11EF1Vomx/wtBns0p4m2LtGZV4tZBqOIAkXC+jQpYL5U0q8LXx1eAHd+cKnFAak3+ WyCPM75veqfcbuziJoTo4Y7g135RAXzRSZzzfsPtBwh+a//+phzrUmH8nhDXUw== From: Taimuraz Kaitmazov To: mamin506@gmail.com, lizhi.hou@amd.com, ogabbay@kernel.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, sumit.semwal@linaro.org, christian.koenig@amd.com, linux-media@vger.kernel.org, linaro-mm-sig@lists.linaro.org, Taimuraz Kaitmazov Subject: [PATCH 1/3] accel/amdxdna: refuse an I/O memory mapping of an imported BO Date: Tue, 11 Aug 2026 23:45:54 +0300 Message-ID: <20260811204556.875037-2-taimuraz@kaitmazov.com> In-Reply-To: <20260811204556.875037-1-taimuraz@kaitmazov.com> References: <20260811204556.875037-1-taimuraz@kaitmazov.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" amdxdna_gem_obj_vmap() accepts whatever dma_buf_vmap() returns and only rejects a NULL vaddr. struct iosys_map is a union discriminated by is_iomem, so an exporter that answers with an I/O mapping leaves a void __iomem pointer in map->vaddr, and amdxdna_gem_vmap() stores it in abo->mem.kva, which callers use as an ordinary kernel address: amdxdna_cmd_set_error() memsets and memcpys through it. amdxdna_drm_va_tbl takes a dmabuf_fd, so a BO of type AMDXDNA_BO_SHARE or AMDXDNA_BO_CMD can be any exporter's buffer. Whether such a buffer is still in a bus aperture when it is mapped depends on the exporter. amdxdna attaches without importer ops, so an exporter that implements .pin has it called before the mapping, and amdgpu's removes VRAM from the allowed domains as soon as one attachment cannot do peer to peer, which this driver's cannot; an amdgpu buffer is therefore in GTT before any of this runs. An exporter using drm_gem_prime_dmabuf_ops has no .pin at all, nothing moves the buffer, and drm_gem_ttm_vmap() answers with iosys_map_set_vaddr_iomem() for a VRAM resident object. nouveau and radeon are in that group, so an NPU paired with one of those GPUs reaches this. Refuse the mapping, so it never reaches a caller that cannot use it. vmw_gem_vmap() does the same for the same reason. Unlike that one, this path is reachable from an unprivileged ioctl, so it does not warn; -EOPNOTSUPP is what drm_gem_vmap_locked() already returns here for an exporter with no vmap op. Signed-off-by: Taimuraz Kaitmazov --- drivers/accel/amdxdna/amdxdna_gem.c | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/am= dxdna_gem.c index 1f190b319..b66ec9e48 100644 --- a/drivers/accel/amdxdna/amdxdna_gem.c +++ b/drivers/accel/amdxdna/amdxdna_gem.c @@ -683,10 +683,16 @@ static int amdxdna_gem_obj_vmap(struct drm_gem_object= *obj, struct iosys_map *ma =20 dma_resv_assert_held(obj->resv); =20 - if (is_import_bo(abo)) + if (is_import_bo(abo)) { ret =3D dma_buf_vmap(abo->dma_buf, map); - else + /* Callers use mem.kva as an ordinary kernel address. */ + if (!ret && map->is_iomem) { + dma_buf_vunmap(abo->dma_buf, map); + return -EOPNOTSUPP; + } + } else { ret =3D drm_gem_shmem_object_vmap(obj, map); + } if (ret) return ret; if (!map->vaddr) --=20 2.55.0 From nobody Tue Sep 29 05:35:25 2026 Received: from out-172.mta0.migadu.com (out-172.mta0.migadu.com [91.218.175.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 46B16416844 for ; Tue, 11 Aug 2026 20:46:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481214; cv=none; b=t8fV04qBh9b3audjJsZk3322pCDD6fdcKK7EpDp3+QFBYIlwoeRm56bqbBJKvA1zOmjjmGuijOgPIQNprCAANqIbOh571QhC4E8tt43LxtsYPrakAm87T51Dy5cDjnhNWA8DfD9FXhmBrbW55nFa8IR50GGowoC6gT5OlC/qRXM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481214; c=relaxed/simple; bh=l6/81gtxbZ60/Hvdpw288NKu5EBB5kJc2RhGV7Ufscc=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=MUnRC6x5/+Wi7vxMAaUOM4LoWu/aV37dovrfmFmxL5DQkfWhcpHGpk7ok73nzHWNtIsytvmd2reXbScbqaWfKr8jzgsrbNyx54/g91NJGXtQniTa/2Lb2FSbbuV8I46BIf+iZX/ODn0hbZq9749+jDVQDdUFyo5jDBS5cS5iyTc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com; spf=pass smtp.mailfrom=kaitmazov.com; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b=bNewAhB1; arc=none smtp.client-ip=91.218.175.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b="bNewAhB1" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kaitmazov.com; s=key1; t=1786481210; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RVMLOnuxl7jMrjiQSGAnMsEYe1sxvBWDZDUQnH2kIwI=; b=bNewAhB1g3t4EHoKZ1aX+FJxAwyV9z6B3WMHC5i8bqglyM61XcVR2+Zkbcm/DfRY66lSCm YpeYkYKtiSuAPfwf/FANhWOO8uIU/L5rPYPUswuE95cq1bL5HbqLRlwcnY7TnIYTj7LvFi 5tSv6oaKWIdrgSrO5WET+94mT5LYRWiExSSPSVVvbhcBfAmkwaz1Q0eqsFIaR3bYAs5jzr ipbrvAzQPZC5lMYXeqe1PQUyCEHDdA5AjU3dFeJStnoxJPg4IYfAhJLa3huwnC4UWQzHuZ Ll6su59EujFucEiX7fafZmqOKB2spAEV6WgbswXVtpeblSUf7iDs84vK88cv+A== From: Taimuraz Kaitmazov To: mamin506@gmail.com, lizhi.hou@amd.com, ogabbay@kernel.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, sumit.semwal@linaro.org, christian.koenig@amd.com, linux-media@vger.kernel.org, linaro-mm-sig@lists.linaro.org, Taimuraz Kaitmazov Subject: [PATCH 2/3] accel/amdxdna: add a quiet variant of amdxdna_gem_vmap() Date: Tue, 11 Aug 2026 23:45:55 +0300 Message-ID: <20260811204556.875037-3-taimuraz@kaitmazov.com> In-Reply-To: <20260811204556.875037-1-taimuraz@kaitmazov.com> References: <20260811204556.875037-1-taimuraz@kaitmazov.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" amdxdna_gem_vmap() logs an error whenever the mapping fails, which suits its callers: each of them treats a failure as fatal to the operation it is performing. The next patch adds one that does not, and an exporter that implements no vmap op fails every call without anything caching that, so a logging probe would print on every ioctl. Split the mapping out into __amdxdna_gem_vmap(), which returns the error, and leave amdxdna_gem_vmap() as that plus the log. No caller changes: it still returns the address, or NULL after logging. Signed-off-by: Taimuraz Kaitmazov --- drivers/accel/amdxdna/amdxdna_gem.c | 29 ++++++++++++++++++++--------- 1 file changed, 20 insertions(+), 9 deletions(-) diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/am= dxdna_gem.c index b66ec9e48..d0c846b02 100644 --- a/drivers/accel/amdxdna/amdxdna_gem.c +++ b/drivers/accel/amdxdna/amdxdna_gem.c @@ -191,12 +191,8 @@ amdxdna_gem_destroy_obj(struct amdxdna_gem_obj *abo) kfree(abo); } =20 -/* - * Obtains a kernel virtual address on the BO (usually of small size). - * The mapping is established on the first call and stays valid until - * amdxdna_gem_vunmap() is called. - */ -void *amdxdna_gem_vmap(struct amdxdna_gem_obj *abo) +/* Returns the error instead of logging it. */ +static void *__amdxdna_gem_vmap(struct amdxdna_gem_obj *abo) { struct iosys_map map =3D IOSYS_MAP_INIT_VADDR(NULL); int ret; @@ -210,13 +206,28 @@ void *amdxdna_gem_vmap(struct amdxdna_gem_obj *abo) if (!abo->mem.kva) { ret =3D drm_gem_vmap(to_gobj(abo), &map); if (ret) - XDNA_ERR(abo->client->xdna, "Vmap bo failed, ret %d", ret); - else - abo->mem.kva =3D map.vaddr; + return ERR_PTR(ret); + abo->mem.kva =3D map.vaddr; } return abo->mem.kva; } =20 +/* + * Obtains a kernel virtual address on the BO (usually of small size). + * The mapping is established on the first call and stays valid until + * amdxdna_gem_vunmap() is called. + */ +void *amdxdna_gem_vmap(struct amdxdna_gem_obj *abo) +{ + void *kva =3D __amdxdna_gem_vmap(abo); + + if (IS_ERR(kva)) { + XDNA_ERR(abo->client->xdna, "Vmap bo failed, ret %ld", PTR_ERR(kva)); + return NULL; + } + return kva; +} + /* * Free mapping established through amdxdna_gem_vmap() */ --=20 2.55.0 From nobody Tue Sep 29 05:35:25 2026 Received: from out-171.mta0.migadu.com (out-171.mta0.migadu.com [91.218.175.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 57D6A4746D1 for ; Tue, 11 Aug 2026 20:46:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=91.218.175.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481217; cv=none; b=WoKqeFXNk/hWkzuzDgx1v3DqQeQBWzMFEXyvTi/sJcQmKuMkpld/9M3OaCY+YiSZhC5Lza0uX6F43gMEcNLUStQAISiam+EM6Vbdk07Az51ziedSOsoTz3CxH6QQFkk6JCumHXqzKhLa7o9XkLxtJORUr7oirX7eD22RZMie5Q4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786481217; c=relaxed/simple; bh=bjMYmIJoVJo6+Dzitc3op82ESQXEOC4QEjP/9707Ak4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=AjEvUlneji3l9fmAlZyvT6XgA7MtjjQ1IGVTlZtPrOd2sHhV9Hif4iqHcbrAPY8vNjxzcxFy+4utLTIzxuovNOxDXd2018QhkmAGLWPsuSsPpU/sFfWQvjHsIrlhXlwoie5WsGs8Wa/TpQweiq5ltK3XjFxXHmHswhBvICYsZt8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com; spf=pass smtp.mailfrom=kaitmazov.com; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b=LA0Vpkb9; arc=none smtp.client-ip=91.218.175.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kaitmazov.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kaitmazov.com header.i=@kaitmazov.com header.b="LA0Vpkb9" X-Report-Abuse: Please report any abuse attempt to abuse@migadu.com and include these headers. DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kaitmazov.com; s=key1; t=1786481213; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=zeACl+zbzOI1sHRsKncuRKubCD4eo5wsZ8YrzMDnp54=; b=LA0Vpkb9V6BwKppQAe5Vf043kHI9nBnd4pj3H3ewgL+LfQLRDFf1j4sOAG8y+TiDeDTIof hiLvsz6ovnK55FHDi4mPA2n2ziD5dqUc5zM19Cqp7jpuUKsQysiT6uUDWys2SmrYm9tiGc 7asHcSnrLdrN88L1+V+rVNZ4ZoSalxn/w6djTW4y5j0rqELhitkTxHzP8lbDuBk2RF+heu P0QR7ES0grZs9jPpSztXIcKrBR74Lv5TWSYuf9gjtaDEMEH+SQJrCHw3CtiOYGpM/O7eUi vKSgSnPSSGkV7kF6giWHCuMhWk0w3LL+AtdFOKx5ywTOjD865lXXSFqckGBG+A== From: Taimuraz Kaitmazov To: mamin506@gmail.com, lizhi.hou@amd.com, ogabbay@kernel.org Cc: dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, sumit.semwal@linaro.org, christian.koenig@amd.com, linux-media@vger.kernel.org, linaro-mm-sig@lists.linaro.org, Taimuraz Kaitmazov Subject: [PATCH 3/3] accel/amdxdna: flush only the requested range in amdxdna_flush_bo Date: Tue, 11 Aug 2026 23:45:56 +0300 Message-ID: <20260811204556.875037-4-taimuraz@kaitmazov.com> In-Reply-To: <20260811204556.875037-1-taimuraz@kaitmazov.com> References: <20260811204556.875037-1-taimuraz@kaitmazov.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Migadu-Flow: FLOW_OUT Content-Type: text/plain; charset="utf-8" SYNC_BO carries an offset and a size, but amdxdna_flush_bo() honours them only on the vmap path: an imported BO is tested for first and flushes its whole scatterlist, and the page-array fallback flushes every page of the BO. A sync costs what the BO is worth rather than what the caller asked to maintain. amdxdna_gem_obj_vmap() maps an imported BO through dma_buf_vmap(), so try the vmap path first and leave drm_clflush_sg() as the fallback for an exporter that cannot serve one. Index the page-array fallback from the requested offset. An imported BO now holds a kernel mapping from its first sync until it is freed, as a shmem BO already does. Measured on npu4, 64 MiB BO, pinned, minimum of 50 runs: an imported BO cost 1056 us to sync at every size from 4 KiB up, and now tracks the driver-owned BO at 0.7 us for 4 KiB, 17 us for 1 MiB and 1056 us for the whole BO. The driver-owned column does not move. An earlier version walked the scatterlist a page at a time instead. It fixed the range case but cost about 179 ns per page of barrier and call overhead, taking the whole-BO sync from 1056 to 3989 us, so this one reuses the mapping instead. This does not bracket the flush with dma_buf_begin_cpu_access() and dma_buf_end_cpu_access(). The driver has never called them, here or anywhere else, so the omission predates this change; what changes is that the vmap path now serves an imported BO by default, which is where the exporter's own coherency hook would matter most. Adding the bracket is follow-up work rather than part of this one: the calls carry a direction but no range, so pairing them with a ranged flush wants its own reasoning and its own measurement. Signed-off-by: Taimuraz Kaitmazov --- drivers/accel/amdxdna/amdxdna_gem.c | 14 ++++++++++---- 1 file changed, 10 insertions(+), 4 deletions(-) diff --git a/drivers/accel/amdxdna/amdxdna_gem.c b/drivers/accel/amdxdna/am= dxdna_gem.c index d0c846b02..4886f7c08 100644 --- a/drivers/accel/amdxdna/amdxdna_gem.c +++ b/drivers/accel/amdxdna/amdxdna_gem.c @@ -1234,6 +1234,8 @@ int amdxdna_drm_get_bo_info_ioctl(struct drm_device *= dev, void *data, struct drm =20 static int amdxdna_flush_bo(struct amdxdna_gem_obj *abo, u64 offset, u64 s= ize) { + unsigned long first, nr_pages; + void *kva; u64 end; =20 if (offset >=3D abo->mem.size) @@ -1243,12 +1245,16 @@ static int amdxdna_flush_bo(struct amdxdna_gem_obj = *abo, u64 offset, u64 size) return -EINVAL; =20 size =3D min(abo->mem.size, end) - offset; - if (is_import_bo(abo)) + first =3D offset >> PAGE_SHIFT; + nr_pages =3D (PAGE_ALIGN(offset + size) >> PAGE_SHIFT) - first; + + kva =3D __amdxdna_gem_vmap(abo); + if (!IS_ERR(kva)) + drm_clflush_virt_range(kva + offset, size); + else if (is_import_bo(abo)) drm_clflush_sg(abo->base.sgt); - else if (amdxdna_gem_vmap(abo)) - drm_clflush_virt_range(amdxdna_gem_vmap(abo) + offset, size); else if (abo->base.pages) - drm_clflush_pages(abo->base.pages, abo->mem.size >> PAGE_SHIFT); + drm_clflush_pages(&abo->base.pages[first], nr_pages); else return -EINVAL; =20 --=20 2.55.0