From nobody Wed Sep 30 05:45:47 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DE41842DA55 for ; Wed, 12 Aug 2026 10:57:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532249; cv=none; b=GGHfElhoR2s0TIfjlJ5AacJ/jnzKw3IzANV/VZubKE5FNMDd+umk1tx1fn9RfNLyG4W8aF3LIGV8ECGor4tYAWE7CVwBPMUxGFw+subRgrtAvpKuox9Bqw3IXNxs4SWeXe6CCVzKXBEaJw8Os515l8X2UYJwzZLggOaahrEYoA0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532249; c=relaxed/simple; bh=kezCxwKujVFnkMUk4rC08TaL66oxCbXBQxapiV1nUK8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=hLxBOv5ncdzQMz6hQV5uKFPG7J902mGk5Ml+vxvxVFzyuuH5oKfvRrRRmX1MU7bB9P3g+PZ8k1btA3AUHHWjqzr1xjSkw1GdYCMHcXOD2i5QA23gL+IftitWzx/8l8t7LskTY1vyBzOeFxhM+iMyEGPpqI1rwyz20T1xjyhYi+E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=pMDa+KCe; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=LPVCDLnc; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="pMDa+KCe"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="LPVCDLnc" Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67C9fhjY3082708 for ; Wed, 12 Aug 2026 10:57:27 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= x02gBLy0VRXgfeuvUNzOZdb8suVquv+njmaVZIUVEBk=; b=pMDa+KCefXMLzbhd yJj+VaDtiItYShwaSIqX2u7/+NW4UzlzLpId9MBpZSQHX7ngKP2V+nMKpFWevjmw KkfiMSN9vDX81ree5UPCC3SL+z9PWa+tCYekZJnIse6CcAUvohUdkyHtx63iPLl6 MZrtQvrju5bPv6iskP/rRQmzv75IYLW+9HSwRU17kb1RuJDXzcQrZanaG7Z39JrQ Ggf1THBQUkXKvXtB+F3GqNNDFWapIGAVZ6tfAESQRhssnpGs5i97CGbDu5ul2MDa fBNATV+OsqXO0YKWP5IY01nGesyW4Ouzs71A3zTFgWLHAO+RvrPlyc9Q0BrlcKK8 IxKODw== Received: from mail-pf1-f198.google.com (mail-pf1-f198.google.com [209.85.210.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g08jrkfn4-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 10:57:26 +0000 (GMT) Received: by mail-pf1-f198.google.com with SMTP id d2e1a72fcca58-8484b9fb055so2057157b3a.0 for ; Wed, 12 Aug 2026 03:57:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786532246; x=1787137046; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=x02gBLy0VRXgfeuvUNzOZdb8suVquv+njmaVZIUVEBk=; b=LPVCDLnc4qWtAPicGIdFC4oBc+tNz85dK1EUcuvVFbtV/Sz0VduHbHhWWQMhz/P3Rn nhnJSjNw0sYdsNgV2h4xJNX2A1WUGH07YBrAZJOLAfrteg4eSq81VXp0eYRU/giHDiSQ 8xEXaMzpmDs7HGVoo8udcJH0/aqYNgZ1USYqFEvkdx4fBpWISAQY5O09dH6rY/homhfQ Fob6kXM5YdD1Cv7kcSTVdEr1Lu6At77sjPbZmPva9+1WCK7Q/ikm+3+Nw1GsOR0vPlcQ CmqvTNi7E3WybojCr7fqakb4UUPDgi24ouIs45gE5YxvJsrEfo19mwL7A9oPiR246b/n P7ig== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532246; x=1787137046; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=x02gBLy0VRXgfeuvUNzOZdb8suVquv+njmaVZIUVEBk=; b=n1gGEmiMK5WBA0fjU+rz821u1hhVzdfeM8QMu/yLGth7XndmYDHIOGxziNK0Q2uVoN WLDIxXfwMg+CwyH6ttIHfcjyzYT3XZbLGEJ7pYozX58E0/UzmV0vvnc8D98lZ9GEYQ9f BqjDZsDmDzSwVCKZ5MJtnIU1dRWas33qzI+EtvfqJ525UR+v58vVlhu+DgVUhmon+3mM 0CZLNuTcQqNZzSoxxFvclpw06HeH34ApobMJFX/5axHniCdQ3IkOesIddD0rV2FPbZVa OLgYfflxazA7hCJsL+NspMJLiarrGOJILOFSV9wK33tICP/E2vUBK5ORekZt/sLCiQao pn1A== X-Forwarded-Encrypted: i=1; AHgh+Rq3P1Fog9fBttL5w0W08pCaUs7Cswz7gwBs3of7lri/JGLTxN4jUKqIVrkyrhaLpCvEBmTn8HFIqqx1XXE=@vger.kernel.org X-Gm-Message-State: AOJu0YyEN7bqz/2Xs7pxMtSpdR1olI81+59IoaZ1QYf2geeeh66+qksI 7gx1vXxOba1+x7we1a7iOvYYMn9UzwqphT/LR91u61yGUcyvx1bduXH2Fb84A00Mr4jjcninWdN RxnpaJ/T/mEoHZQtgPvLzrjVV5xOWsGIhiVPKaClBuq6T7wrs44an6RmWJI7vNLmlbew= X-Gm-Gg: AR+sD10VlkY5eYR/0iGSWZ79tYPsIen0bLfnD3jKEeyG9ooga4+A0wBPkB4/hC9qtZ9 vFW8/zg2Dzs7Imsk/xVQ9ZKp0kaIcr9kWHvnNtZLZWcqWa0UnMjkTqJ7nKKFJUAX3Kc3+50IQvK dHTtlp1i08s6KFomNePV3ZuvPsgrYtU3yOAC7DnFSDagSpuMk5UizLNX5SqaWFO81AmUCcdE25F epoGSaWZ7dMU6JHt2lCZIKOf71XbYSOyL+AnDVwSmsl4uLsUOGKU9mae95rJULYKB+Xqk70EE9r 7geaYGU2tAtJcIripa1XSnFt3vFqN5wDGObmeCY9df5dx1c8LObcqGOFtZmv/T88hDmMo0Quee8 RwAq8T0Cbj0mASVoIkVWHFd/9lKaRPdB/NQ== X-Received: by 2002:a05:6a00:1910:b0:848:56d4:3288 with SMTP id d2e1a72fcca58-84fb53c1f77mr4459333b3a.4.1786532246161; Wed, 12 Aug 2026 03:57:26 -0700 (PDT) X-Received: by 2002:a05:6a00:1910:b0:848:56d4:3288 with SMTP id d2e1a72fcca58-84fb53c1f77mr4459291b3a.4.1786532245714; Wed, 12 Aug 2026 03:57:25 -0700 (PDT) Received: from hu-bvisredd-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84fb1d22247sm884301b3a.15.2026.08.12.03.57.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:57:25 -0700 (PDT) From: Vishnu Reddy Date: Wed, 12 Aug 2026 16:25:58 +0530 Subject: [PATCH 1/2] media: iris: Fix iova allocation from restrict region Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-reserve_iova_in_driver-v1-1-ed62f801275c@oss.qualcomm.com> References: <20260812-reserve_iova_in_driver-v1-0-ed62f801275c@oss.qualcomm.com> In-Reply-To: <20260812-reserve_iova_in_driver-v1-0-ed62f801275c@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Stanimir Varbanov Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Vishnu Reddy , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786532236; l=6825; i=busanna.reddy@oss.qualcomm.com; s=20260216; h=from:subject:message-id; bh=kezCxwKujVFnkMUk4rC08TaL66oxCbXBQxapiV1nUK8=; b=oijVYccHHkemEt1Pmc9kwYcAW9mO/AQLofcMdPpxa+xzwCOOK69KK/yTJsizc2DiDOx04ATOW bNp3i/Y/O8xD8CkZZfyWVfOnIbm2zd8UM9R1Yuc2zqLr62bAI5B6lI1 X-Developer-Key: i=busanna.reddy@oss.qualcomm.com; a=ed25519; pk=9vmy9HahBKVAa+GBFj1yHVbz0ey/ucIs1hrlfx+qtok= X-Proofpoint-GUID: zDzhXgXrL4UCvDvAfcdq8qQMLw3SIX_8 X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDA4OCBTYWx0ZWRfX43NJ9KLgYe1Q 4erI9w35Uu7xmob2i3+3AbfbmMq7PYo0FSkjXmu3R7AwZn/ggdSN+zuSWdxb9VHht7gpqiwphsA tSC/07MpMRm9JuTrkq2U/J8Dch0d+6Y= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDA4OCBTYWx0ZWRfX3G0PSQD5BaDK 2BfuJh9O3A3Ha1gGlbA9bjKCrKIUpasEnhL2N65Ok/Iazze9DCqGvEw6uM/ymbCZefIP8wl3lqp IGb3hZL1d6ZT1t8piMVHOPrDJa6L0u00Hf/dsKEmjLiA0lJMNjSOUpOl8C1oY8mAKyvagnDq3sD kplbPI/IwGUpna0MYJzFiwWDfCWbD6co3g+F/fg+3xUTreR3BxJCj/5YO22q78lnCosHMYdyKgH 0PM9hqmD+YmL6TSjIfQAWVtyTwSsE8v4RLk/DFGyc5cpRmpCjqNANQmDONu1+8Gvkcs4h+EkyMH TJfTIVKwLkTYuBw/lIgdCkbTg2VkD1QIDrPhNx4u23DDGkM5wJ0YcFIq4uWcoWJHVMTrq97kohQ dUeCddFW9ERQDcmYLmb/3iZYWNwrfEyb7+kWVnYsTZYyPX2J1JRepez+/nyE/7v9DOvcIeqSoYE TecY8UJFhYDWwtvBGUw== X-Authority-Analysis: v=2.4 cv=Z7Dc2nRA c=1 sm=1 tr=0 ts=6a7c5196 cx=c_pps a=m5Vt/hrsBiPMCU0y4gIsQw==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=e5mUnYsNAAAA:8 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=dm53AvHgw1VIgxztvNkA:9 a=QEXdDO2ut3YA:10 a=IoOABgeZipijB_acs4fv:22 a=Vxmtnl_E_bksehYqCbjh:22 X-Proofpoint-ORIG-GUID: zDzhXgXrL4UCvDvAfcdq8qQMLw3SIX_8 X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_03,2026-08-10_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 lowpriorityscore=0 adultscore=0 clxscore=1015 impostorscore=0 spamscore=0 priorityscore=1501 bulkscore=0 phishscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120088 The VPU issues DMA through several SMMU streams, and the hardware does not give every stream the same addressable range. The non-pixel stream cannot address the low 600MB of IOVA space, while the pixel stream can address the full range: +-----------------------------------------------------------+ | non-pixel stream addressable range (600 MB - 3.5 GB) | | 0x25800000 - 0xe0000000 | +-----------------------------------------------------------+ | pixel stream addressable range (0 - 3.5 GB) | | 0x00000000 - 0xe0000000 | +-----------------------------------------------------------+ A single "iommus" property on the video-codec node puts every stream in one IOMMU domain sharing one IOVA allocator, so nothing restricts a non-pixel buffer to avoid 0 to 600MB. Once an allocation lands below that boundary the hardware faults, which shows up as unhandled SMMU page faults and spontaneous reboots. https://gitlab.freedesktop.org/drm/msm/-/work_items/100 A series to reserve the 0-600MB IOVA range via "iommu-addresses" was already posted here: https://lore.kernel.org/all/20260807-iris_iova_600mb_fix-v1-0-3996f67e33f9@= oss.qualcomm.com Those changes involve DT binding and DT node changes, and discussion is still ongoing on how to handle those for stable and for the upcoming sub-node design, with no conclusion reached yet. Thereby a critical reset issue is still open. This is an alternate solution to fix the unhandled SMMU page fault by restricting the IOVA range in the video driver, which also makes it easier and faster to land on mainline and stable kernels. At the same time the patch only reserves in the IOVA space without allocating any physical memory. Currently sub-nodes are not yet present, and only a single device is available, so the restriction is applied to both non-pixel and pixel stream IDs. This makes the solution unoptimal while fixing the issue considering all scenarios. Once sub-nodes for non-pixel, pixel, and secure streams become available, the restriction can be made stream specific. Fixes: d7378f84e94e ("media: iris: introduce iris core state management wit= h shared queues") Cc: stable@vger.kernel.org Signed-off-by: Vishnu Reddy Reviewed-by: Dmitry Baryshkov Reviewed-by: Vikash Garodia --- drivers/media/platform/qcom/iris/iris_core.h | 6 +++ drivers/media/platform/qcom/iris/iris_probe.c | 69 +++++++++++++++++++++++= +++- 2 files changed, 74 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/iris/iris_core.h b/drivers/media/p= latform/qcom/iris/iris_core.h index 24da60448cf2..79bc342a25a2 100644 --- a/drivers/media/platform/qcom/iris/iris_core.h +++ b/drivers/media/platform/qcom/iris/iris_core.h @@ -7,6 +7,7 @@ #define __IRIS_CORE_H__ =20 #include +#include #include #include =20 @@ -25,6 +26,9 @@ struct icc_info { #define IRIS_FW_VERSION_LENGTH 128 #define IFACEQ_CORE_PKT_SIZE (1024 * 4) =20 +#define IRIS_NP_RESERVE_IOVA_START 0x0 +#define IRIS_NP_RESERVE_IOVA_SIZE 0x25800000 + enum domain_type { ENCODER =3D BIT(0), DECODER =3D BIT(1), @@ -77,6 +81,7 @@ struct qcom_ubwc_cfg_data; * @instances: a list_head of all instances * @inst_fw_caps_dec: an array of supported instance capabilities by decod= er * @inst_fw_caps_enc: an array of supported instance capabilities by encod= er + * @iova_state: an array of dma_iova_state entries reserved for the restri= cted IOVA region */ =20 struct iris_core { @@ -123,6 +128,7 @@ struct iris_core { /* encoder and decoder have overlapping caps, so two different arrays are= required */ struct platform_inst_fw_cap inst_fw_caps_dec[INST_FW_CAP_MAX]; struct platform_inst_fw_cap inst_fw_caps_enc[INST_FW_CAP_MAX]; + struct dma_iova_state *iova_state; }; =20 int iris_core_init(struct iris_core *core); diff --git a/drivers/media/platform/qcom/iris/iris_probe.c b/drivers/media/= platform/qcom/iris/iris_probe.c index e4acf4a74f94..f44305ee81b6 100644 --- a/drivers/media/platform/qcom/iris/iris_probe.c +++ b/drivers/media/platform/qcom/iris/iris_probe.c @@ -150,6 +150,64 @@ static int iris_init_resources(struct iris_core *core) return iris_init_resets(core); } =20 +static int iris_reserve_iova_region(struct device *dev, struct dma_iova_st= ate **iova_state, + unsigned long start, unsigned long size) +{ + unsigned long mask =3D dma_get_mask(dev); + unsigned long end, rem, chunk; + struct dma_iova_state *state; + unsigned int count =3D 0; + int ret; + + state =3D kcalloc(BITS_PER_TYPE(dma_addr_t) + 1, sizeof(*state), GFP_KERN= EL); + if (!state) + return -ENOMEM; + + end =3D start + size; + rem =3D end - max(start, PAGE_SIZE); + + ret =3D dma_set_mask_and_coherent(dev, end - 1); + if (ret) + goto err_free_mem; + + while (rem) { + chunk =3D min(end & -end, (u64)1 << (fls64(rem) - 1)); + + if (!dma_iova_try_alloc(dev, &state[count], 0, chunk)) { + ret =3D -ENOMEM; + goto err_free_iova; + } + + rem -=3D chunk; + end -=3D chunk; + count++; + } + + *iova_state =3D state; + dma_set_mask_and_coherent(dev, mask); + + return 0; + +err_free_iova: + while (count--) + dma_iova_free(dev, &state[count]); + dma_set_mask_and_coherent(dev, mask); +err_free_mem: + kfree(state); + + return ret; +} + +static void iris_unreserve_iova_region(struct device *dev, struct dma_iova= _state *iova_state) +{ + unsigned int i; + + for (i =3D 0; dma_iova_size(&iova_state[i]); i++) + dma_iova_free(dev, &iova_state[i]); + + kfree(iova_state); +} + static int iris_register_video_device(struct iris_core *core, enum domain_= type type) { struct video_device *vdev; @@ -207,6 +265,8 @@ static void iris_remove(struct platform_device *pdev) =20 v4l2_device_unregister(&core->v4l2_dev); =20 + iris_unreserve_iova_region(core->dev, core->iova_state); + mutex_destroy(&core->lock); } =20 @@ -292,14 +352,21 @@ static int iris_probe(struct platform_device *pdev) dma_set_max_seg_size(&pdev->dev, DMA_BIT_MASK(32)); dma_set_seg_boundary(&pdev->dev, DMA_BIT_MASK(32)); =20 + ret =3D iris_reserve_iova_region(dev, &core->iova_state, IRIS_NP_RESERVE_= IOVA_START, + IRIS_NP_RESERVE_IOVA_SIZE); + if (ret) + goto err_vdev_unreg_enc; + pm_runtime_set_autosuspend_delay(core->dev, AUTOSUSPEND_DELAY_VALUE); pm_runtime_use_autosuspend(core->dev); ret =3D devm_pm_runtime_enable(core->dev); if (ret) - goto err_vdev_unreg_enc; + goto err_unresv_iova_region; =20 return 0; =20 +err_unresv_iova_region: + iris_unreserve_iova_region(dev, core->iova_state); err_vdev_unreg_enc: video_unregister_device(core->vdev_enc); err_vdev_unreg_dec: --=20 2.34.1 From nobody Wed Sep 30 05:45:47 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B374F42FCDE for ; Wed, 12 Aug 2026 10:57:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532255; cv=none; b=ZcYpXrgce2FjFfymRKkfHOyLqYNfU9MVY7JDuH9XxdRSEjvQ1pMbod66jxK0RpgZFkV1vbCjDcHa5fZUFUjQKsBSHl5q1C6S/B7Z58J4mdo3wuheJ2VIrSJJIY/JHRri4LrQkvaqj6F1TAyIVHYbkIBHNdlBBZZWqzeFUfw31sA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786532255; c=relaxed/simple; bh=8ZB9oC0BYPYr0KW4jSRGQUpa8L9wo72omlw1zjhy3Kc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=nHeLYxmJi3dhK4W9gRKft+EvHzKe6kJe9ujuysQqVbqPxjcNKuK6c7BGcq6fEU6qau3HepYPlZXEqYa2kw9rQJB2NVQFaXs8hQGwAutWoDY8vH9O9ULjx7DY2eAZGj10My2igUkSxHN9nFjeuqQcMlIrze4llM5HAHmA5B7U+Xo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=mjU2jtsD; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=iTkCT23x; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="mjU2jtsD"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="iTkCT23x" Received: from pps.filterd (m0279865.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67C9fnGd3997154 for ; Wed, 12 Aug 2026 10:57:32 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= RtUEIMWHjJys3xVIM8NtzsQlE2aU/YyF8MJBv+cSiR0=; b=mjU2jtsDChKxemqR lmetKjLKehXufJyb75N3PqRoQ1jToHyfkiQ9DeM9HRQ5aztmTEi3Iqjbb0DOAfYq B3g3EHgfgy5CUnFZmBcOFEUbK8M1Mac7NMn57lF+pFBvDU3It3A2lbREiSOMorRK Rr+BlKAX6O/HmCXzaeFXG7jbgCzKAgzLAGZjFYqwon1IaAu2VKC0nhZg5sd81ov5 WbnrIbtEaJrwsK1BDCbKqX07v7EJduHEIX9VII00Kc+xlxPjIJiy4qJmFN3M2+Yx m2yFMem7bHPdWH0BV2YiDe5YJfy5YVwlnBtAfI6QXRxQ9L/k4zD9YapDfT8eMgMG MytXdw== Received: from mail-pf1-f200.google.com (mail-pf1-f200.google.com [209.85.210.200]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g08j5kg3s-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Wed, 12 Aug 2026 10:57:32 +0000 (GMT) Received: by mail-pf1-f200.google.com with SMTP id d2e1a72fcca58-8485b7e18b4so1541602b3a.1 for ; Wed, 12 Aug 2026 03:57:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1786532251; x=1787137051; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=RtUEIMWHjJys3xVIM8NtzsQlE2aU/YyF8MJBv+cSiR0=; b=iTkCT23xbqtXcPV5Z9zExR2vUHWPNzpU6jiqoo37ytWPvWu8h5WtD6FLJZ2YIgIHs5 sEMux4bL5zbqqTWje+teydoHrDEd/2GYTCCyR+Fw327UbyTfoCpPyvvzxzHnS1h5TX1l Gt49quGrvUg3Ycq6rHAgOTRCNLZ6SkhS6Dq0/Z05/Be+nFHQvhUisWsFQBGw2LjacLm3 O8OI5xkEiI36VuZcIbShOt8wUY8j4HAhGYUQL+1oBdXyMhAy+TrXivJnKHUnd4DgFGv6 lUssfNHELUed7pL/y6oksnPc4w09uWW2+Bk6yLdiYY5on0VXBW34kPOHs4Zi0f5Urd4n oFAw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786532251; x=1787137051; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=RtUEIMWHjJys3xVIM8NtzsQlE2aU/YyF8MJBv+cSiR0=; b=QghHw1XYZjDA+AVqyjLLIOgZY/1kdtRxaCGzsH3RiJMA8HeP7HcLE/B6QEq7frGLB4 +iSBZWB1XIVWqF96aOku91Rav2ONHWvhQTNS/SdIJzI/sJybXvwjLJIHEBTxXIfdCvbn JMWM1gRxUMf23mCVYN2pWP5u13uRBEJ/yLRsVSN6PW6/TC4WbVKKMQVylobXdCI4xgcF eRgk2b8bDg/yJ65PBI2L6Yceccy5fRWuZiuay8amPTiEPiUnaNnGlRoAiZzZ+DPex+VB izSIo1Lpco6Apc0OCy+o4bW1RgsvR9IjhjcHsMjRVSZH2Z567N0H+YhfiRnkC/nROuUs f/fQ== X-Forwarded-Encrypted: i=1; AHgh+RokoqaJc1U7rnpeqWMp0HiiCqac/OPi2FfzWUwsfcJiZwplG4qAgc8U9v/MdPBW7GLhaYLnIsAZQ5R/CfQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yy+YT7a6+o8kqMRCwGFkZFLjkX0bYceY/eOSS76m5C2bWQ6cL80 VDOYnKxFNzlHPAZUAvEXsmy9NQEFZ0luidJmV2ml6bNlypZBRbv0jEe92My3pSfg1l3jCUfwt+E eUASgav1a2mCbplO36/NYPT4bYOpGKwxioov9i/3bvnWDTl+93GTbbFGeo4tCI4d9MM0= X-Gm-Gg: AR+sD10lJU29fYm8/je4PsOON1uFDbky2zZrfWOcWno8i9bIg094zu9Vqb8t3x7oqEm jme7iTsu/gMt1iX+kpJmcWVzJjf38PU+qYHVkVf+M28uNu8qzZbIC3qqIGuRT8pCHbPBOEdFbdR Qfi6MgHJOvN1+5KI7qIZOImPXGZWbj7E6k5wsKYvQv0oOp+lNaYkZnqEzAXwQQ0o9YxQZMEltb+ aqSQ0mHqS9mFXXNUSBlddP1nc5VQqEUrAXSH0RHZzQi6jiSrCVbI9TXVobHBTZfnE2mxg2YwmfQ P/8Y3619ZHZawhKBzYDWZkMechHELKxZ2VORojxZBf7OZKKMHm1+zMyAqc9mOlnv5MTJKqr26p4 LqYFpGAPd1KhpeGg2e9Z4NSvzbLYY9gGnGg== X-Received: by 2002:a05:6a00:2994:b0:848:75a1:a0fe with SMTP id d2e1a72fcca58-84fb54e1b6bmr4568446b3a.18.1786532251339; Wed, 12 Aug 2026 03:57:31 -0700 (PDT) X-Received: by 2002:a05:6a00:2994:b0:848:75a1:a0fe with SMTP id d2e1a72fcca58-84fb54e1b6bmr4568404b3a.18.1786532250868; Wed, 12 Aug 2026 03:57:30 -0700 (PDT) Received: from hu-bvisredd-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84fb1d22247sm884301b3a.15.2026.08.12.03.57.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 03:57:29 -0700 (PDT) From: Vishnu Reddy Date: Wed, 12 Aug 2026 16:25:59 +0530 Subject: [PATCH 2/2] media: venus: Fix iova allocation from restrict region Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-reserve_iova_in_driver-v1-2-ed62f801275c@oss.qualcomm.com> References: <20260812-reserve_iova_in_driver-v1-0-ed62f801275c@oss.qualcomm.com> In-Reply-To: <20260812-reserve_iova_in_driver-v1-0-ed62f801275c@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Stanimir Varbanov Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Vishnu Reddy , stable@vger.kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786532236; l=6620; i=busanna.reddy@oss.qualcomm.com; s=20260216; h=from:subject:message-id; bh=8ZB9oC0BYPYr0KW4jSRGQUpa8L9wo72omlw1zjhy3Kc=; b=e9+nzr30bUPUEH095WBn5jUl/U+gLamanqQ4ZLhfQcYtMR/6EPEyLTOmCZqbHrpgTMAhNWfya zs8kZpuQ4tFDsmnSX5L8Oppe22lPItk6sFaK6jxQYjp6dUFmDw1aaMR X-Developer-Key: i=busanna.reddy@oss.qualcomm.com; a=ed25519; pk=9vmy9HahBKVAa+GBFj1yHVbz0ey/ucIs1hrlfx+qtok= X-Proofpoint-Spam-Info: AW1haW4tMjYwODEyMDA4OCBTYWx0ZWRfX/bq9+CtV0Zrl mVCdE1Gf6PLQ8w7CwK/iNULy3L1I8LQ8f3blPkvS2wRFHw2KQ2nsvgv1pEw11X2fxV1/x9VFY7z zEOuDKTqVk+kxMQSVazJdGzjMAwbiRQ= X-Authority-Analysis: v=2.4 cv=evHvCIpX c=1 sm=1 tr=0 ts=6a7c519c cx=c_pps a=mDZGXZTwRPZaeRUbqKGCBw==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=Um2Pa8k9VHT-vaBCBUpS:22 a=e5mUnYsNAAAA:8 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=dm53AvHgw1VIgxztvNkA:9 a=QEXdDO2ut3YA:10 a=zc0IvFSfCIW2DFIPzwfm:22 a=Vxmtnl_E_bksehYqCbjh:22 X-Proofpoint-GUID: ya3TZvkm1TTwofHNFOplI8j6NPDmuADt X-Proofpoint-ORIG-GUID: ya3TZvkm1TTwofHNFOplI8j6NPDmuADt X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODEyMDA4OCBTYWx0ZWRfX8MazpIIcx+tL WKOWOasWy2KaXWEPpfwnF/KWPBXk3JC0v90Sg03bxgpgDsQr2gDO65nLI6jLubSR9VI7zk/BfU3 UeI7FVgoEdwysg/wMg349MWoKsitZHoBpQkKs4wVzITFW8nW0G1msxkm548puo9hT6Dh8xAC89G eYSLVqbbiR8lS7EYfuViSXSqxhv+XhB35wMLXOmxR+S289DJHmeqVLn8na4ZGFwMUHteW5LhFlv s+Itvn5aVsuNGaQky5FFlg6RN/M7+GT3hstEHkkMUR7058yS+s9G4b5DHPnTi95GN6jDRYwSuLM Vta2LuVEP06Woe7B2Tjnhbl7IfLFI2x3r6mw/6oqu3l8jw3q9028H953cUJSgg5mBY8x9jzLt4N 7ETr6WqZXPQ22I+DqGbYoON8Oa9mvna2BaPKKQOKE2IF20XBXy7Ayo5wC88LOXoiPDbqN7pNxY/ S5BOV6AMII5kpuFV+ow== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-12_03,2026-08-10_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 impostorscore=0 lowpriorityscore=0 adultscore=0 priorityscore=1501 bulkscore=0 suspectscore=0 clxscore=1015 phishscore=0 spamscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608120088 The VPU issues DMA through several SMMU streams, and the hardware does not give every stream the same addressable range. The non-pixel stream cannot address the low 600MB of IOVA space, while the pixel stream can address the full range: +-----------------------------------------------------------+ | non-pixel stream addressable range (600 MB - 3.5 GB) | | 0x25800000 - 0xe0000000 | +-----------------------------------------------------------+ | pixel stream addressable range (0 - 3.5 GB) | | 0x00000000 - 0xe0000000 | +-----------------------------------------------------------+ A single "iommus" property on the video-codec node puts every stream in one IOMMU domain sharing one IOVA allocator, so nothing restricts a non-pixel buffer to avoid 0 to 600MB. Once an allocation lands below that boundary the hardware faults, which shows up as unhandled SMMU page faults and spontaneous reboots. https://gitlab.freedesktop.org/drm/msm/-/work_items/100 A series to reserve the 0-600MB IOVA range via "iommu-addresses" was already posted here: https://lore.kernel.org/all/20260807-iris_iova_600mb_fix-v1-0-3996f67e33f9@= oss.qualcomm.com Those changes involve DT binding and DT node changes, and discussion is still ongoing on how to handle those for stable and for the upcoming sub-node design, with no conclusion reached yet. Thereby a critical reset issue is still open. This is an alternate solution to fix the unhandled SMMU page fault by restricting the IOVA range in the video driver, which also makes it easier and faster to land on mainline and stable kernels. At the same time the patch only reserves in the IOVA space without allocating any physical memory. Currently sub-nodes are not yet present, and only a single device is available, so the restriction is applied to both non-pixel and pixel stream IDs. This makes the solution unoptimal while fixing the issue considering all scenarios. Once sub-nodes for non-pixel, pixel, and secure streams become available, the restriction can be made stream specific. Fixes: af2c3834c8ca ("[media] media: venus: adding core part and helper fun= ctions") Cc: stable@vger.kernel.org Signed-off-by: Vishnu Reddy Reviewed-by: Dmitry Baryshkov Reviewed-by: Vikash Garodia --- drivers/media/platform/qcom/venus/core.c | 71 ++++++++++++++++++++++++++++= +++- drivers/media/platform/qcom/venus/core.h | 5 +++ 2 files changed, 74 insertions(+), 2 deletions(-) diff --git a/drivers/media/platform/qcom/venus/core.c b/drivers/media/platf= orm/qcom/venus/core.c index 243e342b0ae7..d70f7c3325b4 100644 --- a/drivers/media/platform/qcom/venus/core.c +++ b/drivers/media/platform/qcom/venus/core.c @@ -377,6 +377,64 @@ static int venus_add_dynamic_nodes(struct venus_core *= core) static void venus_remove_dynamic_nodes(struct venus_core *core) {} #endif =20 +static int venus_reserve_iova_region(struct device *dev, struct dma_iova_s= tate **iova_state, + unsigned long start, unsigned long size) +{ + struct dma_iova_state *state; + unsigned long mask =3D dma_get_mask(dev); + unsigned long end, rem, chunk; + unsigned int count =3D 0; + int ret; + + state =3D kcalloc(BITS_PER_TYPE(dma_addr_t) + 1, sizeof(*state), GFP_KERN= EL); + if (!state) + return -ENOMEM; + + end =3D start + size; + rem =3D end - max(start, PAGE_SIZE); + + ret =3D dma_set_mask_and_coherent(dev, end - 1); + if (ret) + goto err_free_mem; + + while (rem) { + chunk =3D min(end & -end, (u64)1 << (fls64(rem) - 1)); + + if (!dma_iova_try_alloc(dev, &state[count], 0, chunk)) { + ret =3D -ENOMEM; + goto err_free_iova; + } + + rem -=3D chunk; + end -=3D chunk; + count++; + } + + *iova_state =3D state; + dma_set_mask_and_coherent(dev, mask); + + return 0; + +err_free_iova: + while (count--) + dma_iova_free(dev, &state[count]); + dma_set_mask_and_coherent(dev, mask); +err_free_mem: + kfree(state); + + return ret; +} + +static void venus_unreserve_iova_region(struct device *dev, struct dma_iov= a_state *state) +{ + unsigned int i; + + for (i =3D 0; dma_iova_size(&state[i]); i++) + dma_iova_free(dev, &state[i]); + + kfree(state); +} + static int venus_probe(struct platform_device *pdev) { struct device *dev =3D &pdev->dev; @@ -427,6 +485,11 @@ static int venus_probe(struct platform_device *pdev) =20 dma_set_max_seg_size(dev, UINT_MAX); =20 + ret =3D venus_reserve_iova_region(dev, &core->iova_state, VENUS_NP_RESERV= E_IOVA_START, + VENUS_NP_RESERVE_IOVA_SIZE); + if (ret) + goto err_core_put; + INIT_LIST_HEAD(&core->instances); mutex_init(&core->lock); INIT_DELAYED_WORK(&core->work, venus_sys_error_handler); @@ -434,13 +497,13 @@ static int venus_probe(struct platform_device *pdev) =20 ret =3D hfi_create(core, &venus_core_ops); if (ret) - goto err_core_put; + goto err_unresv_iova_region; =20 ret =3D devm_request_threaded_irq(dev, core->irq, hfi_isr, venus_isr_thre= ad, IRQF_TRIGGER_HIGH | IRQF_ONESHOT, "venus", core); if (ret) - goto err_core_put; + goto err_unresv_iova_region; =20 venus_assign_register_offsets(core); =20 @@ -525,6 +588,8 @@ static int venus_probe(struct platform_device *pdev) v4l2_device_unregister(&core->v4l2_dev); err_hfi_destroy: hfi_destroy(core); +err_unresv_iova_region: + venus_unreserve_iova_region(dev, core->iova_state); err_core_put: if (core->pm_ops->core_put) core->pm_ops->core_put(core); @@ -562,6 +627,8 @@ static void venus_remove(struct platform_device *pdev) =20 hfi_destroy(core); =20 + venus_unreserve_iova_region(dev, core->iova_state); + mutex_destroy(&core->pm_lock); mutex_destroy(&core->lock); venus_dbgfs_deinit(core); diff --git a/drivers/media/platform/qcom/venus/core.h b/drivers/media/platf= orm/qcom/venus/core.h index 46705a666776..30b8cababe86 100644 --- a/drivers/media/platform/qcom/venus/core.h +++ b/drivers/media/platform/qcom/venus/core.h @@ -8,6 +8,7 @@ #define __VENUS_CORE_H_ =20 #include +#include #include #include #include @@ -30,6 +31,9 @@ =20 #define VENUS_MAX_FPS 240 =20 +#define VENUS_NP_RESERVE_IOVA_START 0x0 +#define VENUS_NP_RESERVE_IOVA_SIZE 0x25800000 + extern int venus_fw_debug; =20 struct freq_tbl { @@ -250,6 +254,7 @@ struct venus_core { unsigned long dump_core; struct of_changeset *ocs; bool hwmode_dev; + struct dma_iova_state *iova_state; }; =20 struct vdec_controls { --=20 2.34.1