From nobody Mon Sep 28 18:37:14 2026 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7DA493BB673 for ; Tue, 18 Aug 2026 15:13:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787066037; cv=none; b=Rh2eeqH2YHI8bvBizMTXtkeCNUsIiebq4kUQNPQyrYJ1OBDOezQI3zAKwfk0zYedMTje3GU/UXpTEAhWvQBXC29ALNrQVsc07da16GLCljbT1UjhPws9O06M2CIGZOk2orLktUf6zCndZxH3BD4nkORqiBZO1UOW5J9tRhgWD6o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787066037; c=relaxed/simple; bh=1PTf8YbOWl7UXgO0zqjYib+M54r/rySJkiqiwmt3PHc=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=u3z9pQkoLgDwqPw1kySp0UC5qHNv7dH7GUZ01DyI0drHbT6S9d+oLvFcpZnqnhEPayFt6SxLu87Yp6LT90k2YK7DLZGlO3cAAZXU+CE/7ltBwsbHqkIIkmSjxoFWGfsvveEbOlulOjlahaU1O9PyyCDfCr6zORKs2qej7tCoNl0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Q1Zk5hXb; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=QBs9hLk0; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Q1Zk5hXb"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="QBs9hLk0" Received: from pps.filterd (m0279873.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67IE0naD1427494 for ; Tue, 18 Aug 2026 15:13:53 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= g1TN/DduOHEbBn09XbvXQheB2KNdAXxnnAWHRO8PiL0=; b=Q1Zk5hXbl//CR2jl gtt0QM3i0Wg0+sS7S2lyzozDbyQ/QH949I9pg/Te0UCFhx0+u0opQUNtOQSaGwsI LKSaFQ20OBMVi3Utfp+bsTwNp4d2EajOlBVWXEGxacdXT438uKmaTGEt5KgkZZAi 51InoeTR8NX32GEKs31v2mPqaUk8csJrU0jf4NNnyPyFpksXyIBcsMlNjI3082dK yCkPN0bSIwUZ0aRexDrbWnboCgXlr7nzQ+lwMQx6MF9o1ISzSrqogdr6FXGmh1qF xTRGSM8pZzNubflAaYM48Sh1WVACDgHrhw/j+A51aqzT1ERsSO0xTwuiCvpLbY4H /fmo5g== Received: from mail-qk1-f199.google.com (mail-qk1-f199.google.com [209.85.222.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g4nb199dx-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 18 Aug 2026 15:13:53 +0000 (GMT) Received: by mail-qk1-f199.google.com with SMTP id af79cd13be357-936d067836eso437385a.0 for ; Tue, 18 Aug 2026 08:13:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1787066033; x=1787670833; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=g1TN/DduOHEbBn09XbvXQheB2KNdAXxnnAWHRO8PiL0=; b=QBs9hLk0Rz/x4n4vasWFU23+W0ow07kBCgnnrxk7i+6t0AnM9UKjt7kUeP/x6SBVuo NwPCvTUk1/lorB6dGj179sioDOiIeCf6YjMgZNNIO/TiALa/pcVJ0ScCkx0j7Su7LPy0 1p/pTcyHuJHsgBGvbM++YN9SeyGIRa3zOLuyMXkzSovpAMS/AFPKCNTH4rclLM+rqzvV HUklJEkzrzCSo5LnDYd+Q3UxJbkkY1JLub9KfsaurvzXupR2r/BkMF1hDSzXNYusiPN6 jsHe/i4cz50neMyQba1grMjmqu9MXZDYe73Gj9aF4qovapzcouAhmM/reEaWs9pg90cv CP2w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787066033; x=1787670833; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=g1TN/DduOHEbBn09XbvXQheB2KNdAXxnnAWHRO8PiL0=; b=iYwuayd1f0dEM/K/rYtFOXn3DucWcVNmMq6aI6muGNhQ85u78uUEnd5eM3koVjgqJ/ TrjDN7Rwg9WRZrN/vVM9HyvRXC6lJBxovST7w4oP8Xqhgtu11qnz/zo3GvtNxRXZQmqA q2usFy7Ag1f+Q3ua8usnRnm3SN2uoK42eVvLE2D6sv63a7NYhnDqZikiRieaJeE7PKJ1 drqos+X7Zgx7a6CGoFD2mA6L6YU7z7oTKet4Gt5Z//PiEmD1ahWArDRGOTyoEOrCiXrq aSJCAQkCV0agaS45f/jLiy6QOaol8j2AAHI2nyd5TRh/BvOYHotzUHq5oG3ZRHBRAh8u yADg== X-Forwarded-Encrypted: i=1; AHgh+RqdfAGvA511uqbHRmTLnpjMKw9JjOYxSJLfoHngTajwKEMwoSj/Nsu/WcTvnpL6I+0RyApLV/z9A8H5Y5M=@vger.kernel.org X-Gm-Message-State: AOJu0YwW3NjfldQ91FZ4XVxT5CsFoKSANi5vAcss8DfPDNC1qNYEfaUZ 0s7uG85MLYpgPG7AMa8jxXJXU0XZmY5apLl1dUzS7iZtZW1xkxODCxGlmfE5XvvQC8ndeB2+iu5 vh+k5y9T35/ZJzs8hEsVBov8FqYQTIGay3RHioQ6BOW4LqSKnNdBBw9m5aNKy4bnp5WE= X-Gm-Gg: AR+sD12FuVUdBKYuY3ICeHDyIHFYz7cOfSVN0BBLyX3OvFyXS2eOCdF8oFVYzGoJEHF VzJffWofMMmPtMnCJIbSIzl/SzjuRTj+QL3loksvqgm0gFhfQYmHjNO445PUFoEVOEnsKww1dDj q0+fr4wuMyTkQ1OhucGRDyWTKHo5m3dU5H9g1CbJMjVHn2saciJm8oarnkdvXFKH2CPwEnSv0gr zZqG3u4SHaVhZuLlX+rrZyoEDaonPBjs0wUy8kLggc7oDUL8UlX//x093q8mkqcN+3zSC0U2VMm UlPm/U83LO7VYWtyuVcGbCrSMbSUHINFQ8PRpFIYdmk/l+BIjhK+Msx1M51pFi/4uTvdqFbrvxO zhnRk7VVxl07dezjOwUaiB46CGZ9IPIoWTQ== X-Received: by 2002:a05:620a:4014:b0:936:cda2:bd4a with SMTP id af79cd13be357-936d234d86amr3442270685a.27.1787066032215; Tue, 18 Aug 2026 08:13:52 -0700 (PDT) X-Received: by 2002:a05:620a:4014:b0:936:cda2:bd4a with SMTP id af79cd13be357-936d234d86amr3442259785a.27.1787066031704; Tue, 18 Aug 2026 08:13:51 -0700 (PDT) Received: from hu-bvisredd-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482a5a3158asm13111105f8f.7.2026.08.18.08.13.44 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 08:13:50 -0700 (PDT) From: Vishnu Reddy Date: Tue, 18 Aug 2026 20:43:22 +0530 Subject: [PATCH v2 1/2] media: iris: Fix iova allocation from restrict region Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-reserve_iova_in_driver-v2-1-5005a1154408@oss.qualcomm.com> References: <20260818-reserve_iova_in_driver-v2-0-5005a1154408@oss.qualcomm.com> In-Reply-To: <20260818-reserve_iova_in_driver-v2-0-5005a1154408@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Stanimir Varbanov Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Vishnu Reddy , stable@vger.kernel.org, Dmitry Baryshkov X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787066016; l=6296; i=busanna.reddy@oss.qualcomm.com; s=20260216; h=from:subject:message-id; bh=1PTf8YbOWl7UXgO0zqjYib+M54r/rySJkiqiwmt3PHc=; b=NqHVvSjCuArsqoSpdCEB/YOCBZlPQuP/4Em+Ep5pR7c5Lmeiz99oOo75TQNrfNICTnKyAwFcU DbpLUJ+WDeKDSqr3yYpcohY4XKqJ7dIJrw4+BbgrqC/XlUjk3K35up/ X-Developer-Key: i=busanna.reddy@oss.qualcomm.com; a=ed25519; pk=9vmy9HahBKVAa+GBFj1yHVbz0ey/ucIs1hrlfx+qtok= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE4MDExMiBTYWx0ZWRfX44vXjmyoTXQ+ 7tPon6ui28+RUOLqRZCLcEYhxEb3yLnAz4Y2vLE1RX4hTTmPhhxmqF9OUYjq9FjFSu2S2J9cf9z l+iT3iOt4cQS0eO/hC0fF1lmh87H5+QxJYfJpGLkBBE2BK+KxRD54vv1kyM6AkYTmSBExpYgBat 38HgwARcCHBSYfv59RIr+VVYPWBfVH56T+Vft6muup7UnnBNVI23ZR8c/uoSUDqjaLKJ1eL0s0P 2oon7FhTsUlw55P2JumFoBEZB1zjhMD+HP6923t8nPfCDxb//mrYkhLI8JZ+d0J6Wzf+Xq82+Qk vwupoT3u15NTsXTbGy7rq+ru8jvrHeEHf5fMx4xMgn9gXSl7SUWSD6Twx03UGV3R86VQDDUw3eA Pt1mhrZHkjQxLFO7/eFrJe1CyBj8ovT8/uBM4ZKDCDXkLy3OPeApzPvujkRnge4oTkcTbk+Ucr1 b7LCfemgnLRgexMFKEQ== X-Proofpoint-GUID: LjFrSzzN3PIhtyisRGfgL9eRACg9Vu1Y X-Authority-Analysis: v=2.4 cv=Ze4t8MVA c=1 sm=1 tr=0 ts=6a8476b1 cx=c_pps a=HLyN3IcIa5EE8TELMZ618Q==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=rJkE3RaqiGZ5pbrm-msn:22 a=e5mUnYsNAAAA:8 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=qCMCQjtVS-vTbDhzrxIA:9 a=QEXdDO2ut3YA:10 a=bTQJ7kPSJx9SKPbeHEYW:22 a=Vxmtnl_E_bksehYqCbjh:22 X-Proofpoint-ORIG-GUID: LjFrSzzN3PIhtyisRGfgL9eRACg9Vu1Y X-Proofpoint-Spam-Info: AW1haW4tMjYwODE4MDExMiBTYWx0ZWRfX9xZfCI7iGEzF R2iT/Xn9Jf0OVqm9eapTOhMTsen5bF+IfClMCLvLJQJSpJB7Qu890FQ071en0Q1QdrDjIa1c6Ky Oc3qOu6fQ04ZoeDFuSwv4gCRdw0OcfY= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-18_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 priorityscore=1501 bulkscore=0 clxscore=1015 phishscore=0 impostorscore=0 adultscore=0 suspectscore=0 malwarescore=0 lowpriorityscore=0 spamscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608180112 The VPU issues DMA through several SMMU streams, and the hardware does not give every stream the same addressable range. The non-pixel stream cannot address the low 600MB of IOVA space, while the pixel stream can address the full range: +-----------------------------------------------------------+ | non-pixel stream addressable range (600 MB - 3.5 GB) | | 0x25800000 - 0xe0000000 | +-----------------------------------------------------------+ | pixel stream addressable range (0 - 3.5 GB) | | 0x00000000 - 0xe0000000 | +-----------------------------------------------------------+ A single "iommus" property on the video-codec node puts every stream in one IOMMU domain sharing one IOVA space, so nothing stops a non-pixel buffer from landing below 600MB. Once an allocation lands below that boundary the hardware faults, which shows up as unhandled SMMU page faults and spontaneous reboots. https://gitlab.freedesktop.org/drm/msm/-/work_items/100 Fix this by reserving the 0-600MB range, below the boundary the non-pixel stream cannot address, using dma_iova_try_alloc() so the IOMMU-DMA core never hands that range out to a real DMA mapping. This reserves only IOVA space, it does not allocate any physical memory. Since sub-nodes for non-pixel, pixel, and secure streams do not exist yet and only a single device is available, the restriction is applied to both non-pixel and pixel stream IDs. Fixes: d7378f84e94e ("media: iris: introduce iris core state management wit= h shared queues") Cc: stable@vger.kernel.org Reviewed-by: Vikash Garodia Reviewed-by: Dmitry Baryshkov Signed-off-by: Vishnu Reddy --- drivers/media/platform/qcom/iris/iris_core.h | 6 +++ drivers/media/platform/qcom/iris/iris_probe.c | 62 +++++++++++++++++++++++= +++- 2 files changed, 67 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/qcom/iris/iris_core.h b/drivers/media/p= latform/qcom/iris/iris_core.h index 24da60448cf2..3e4cf652bf39 100644 --- a/drivers/media/platform/qcom/iris/iris_core.h +++ b/drivers/media/platform/qcom/iris/iris_core.h @@ -7,6 +7,7 @@ #define __IRIS_CORE_H__ =20 #include +#include #include #include =20 @@ -25,6 +26,9 @@ struct icc_info { #define IRIS_FW_VERSION_LENGTH 128 #define IFACEQ_CORE_PKT_SIZE (1024 * 4) =20 +#define IRIS_NP_RESERVE_IOVA_START 0x0 +#define IRIS_NP_RESERVE_IOVA_SIZE 0x25800000 + enum domain_type { ENCODER =3D BIT(0), DECODER =3D BIT(1), @@ -77,6 +81,7 @@ struct qcom_ubwc_cfg_data; * @instances: a list_head of all instances * @inst_fw_caps_dec: an array of supported instance capabilities by decod= er * @inst_fw_caps_enc: an array of supported instance capabilities by encod= er + * @iova_state: a pointer to an array of dma_iova_state entries reserved f= or restricted IOVA region */ =20 struct iris_core { @@ -123,6 +128,7 @@ struct iris_core { /* encoder and decoder have overlapping caps, so two different arrays are= required */ struct platform_inst_fw_cap inst_fw_caps_dec[INST_FW_CAP_MAX]; struct platform_inst_fw_cap inst_fw_caps_enc[INST_FW_CAP_MAX]; + struct dma_iova_state *iova_state; }; =20 int iris_core_init(struct iris_core *core); diff --git a/drivers/media/platform/qcom/iris/iris_probe.c b/drivers/media/= platform/qcom/iris/iris_probe.c index e4acf4a74f94..6581a969fe3f 100644 --- a/drivers/media/platform/qcom/iris/iris_probe.c +++ b/drivers/media/platform/qcom/iris/iris_probe.c @@ -150,6 +150,57 @@ static int iris_init_resources(struct iris_core *core) return iris_init_resets(core); } =20 +static void iris_unreserve_iova_region(struct device *dev, struct dma_iova= _state *iova_state) +{ + unsigned int i; + + for (i =3D 0; dma_iova_size(&iova_state[i]); i++) + dma_iova_free(dev, &iova_state[i]); +} + +static int iris_reserve_iova_region(struct device *dev, struct dma_iova_st= ate **iova_state, + unsigned long start, unsigned long size) +{ + unsigned long dma_limit =3D dev->bus_dma_limit; + unsigned long end, rem, chunk; + struct dma_iova_state *state; + unsigned int count =3D 0; + int ret =3D -ENOMEM; + + state =3D devm_kcalloc(dev, BITS_PER_TYPE(dma_addr_t) + 1, sizeof(*state)= , GFP_KERNEL); + if (!state) + return ret; + + end =3D start + size; + rem =3D end - max(start, PAGE_SIZE); + dev->bus_dma_limit =3D end - 1; + + while (rem) { + chunk =3D min(end & -end, (u64)1 << (fls64(rem) - 1)); + + if (!dma_iova_try_alloc(dev, &state[count], 0, chunk)) + goto err_free_iova; + + if (state[count].addr !=3D end - chunk || state[count].__size !=3D chunk) + goto err_free_iova; + + rem -=3D chunk; + end -=3D chunk; + count++; + } + + *iova_state =3D state; + dev->bus_dma_limit =3D dma_limit; + + return 0; + +err_free_iova: + iris_unreserve_iova_region(dev, state); + dev->bus_dma_limit =3D dma_limit; + + return ret; +} + static int iris_register_video_device(struct iris_core *core, enum domain_= type type) { struct video_device *vdev; @@ -207,6 +258,8 @@ static void iris_remove(struct platform_device *pdev) =20 v4l2_device_unregister(&core->v4l2_dev); =20 + iris_unreserve_iova_region(core->dev, core->iova_state); + mutex_destroy(&core->lock); } =20 @@ -269,10 +322,15 @@ static int iris_probe(struct platform_device *pdev) if (ret) return ret; =20 - ret =3D v4l2_device_register(dev, &core->v4l2_dev); + ret =3D iris_reserve_iova_region(dev, &core->iova_state, IRIS_NP_RESERVE_= IOVA_START, + IRIS_NP_RESERVE_IOVA_SIZE); if (ret) return ret; =20 + ret =3D v4l2_device_register(dev, &core->v4l2_dev); + if (ret) + goto err_unresv_iova_region; + ret =3D iris_register_video_device(core, DECODER); if (ret) goto err_v4l2_unreg; @@ -306,6 +364,8 @@ static int iris_probe(struct platform_device *pdev) video_unregister_device(core->vdev_dec); err_v4l2_unreg: v4l2_device_unregister(&core->v4l2_dev); +err_unresv_iova_region: + iris_unreserve_iova_region(dev, core->iova_state); =20 return ret; } --=20 2.34.1 From nobody Mon Sep 28 18:37:14 2026 Received: from mx0a-0031df01.pphosted.com (mx0a-0031df01.pphosted.com [205.220.168.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 50CEB445AF4 for ; Tue, 18 Aug 2026 15:14:01 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.168.131 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787066043; cv=none; b=Zl45rxN+YCRqUK+q2dKPTlfttKfhVu11AWJceCTnSVT42QtXH7r6y4GQ92hl0Obq1DTL3CnBmLuRQb9fePG6nhWyGnXR95+yH2BCHGWrR+Vt6LUv1xzKxP9MK8z9QuDzFIpy/9Qx3ZaPCmOOWeXwoPrCVgJ3ePMj1Hthyt/Zs8I= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787066043; c=relaxed/simple; bh=D2to+qdFUJIyRn0gO0bPSz/9KSto6nc1kDi6S4cQSCE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=E1jt/w9UYqXeOGUeATIu6/7Uub9GEA4g6ebVP8osqIVIzD8tnZk/NsqTxcR4fHMn7gLAf/CxhW9XvAhHIvYdrZVViw3fgZyljmguYT9nGgJhf5+SOPy3GP5eH59JLtxH32DmZGE8I6GnWeWX4T/ZXZA72ICf9/hngmE7tyvPH4E= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Z3fiog3g; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=AzPOQn1v; arc=none smtp.client-ip=205.220.168.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Z3fiog3g"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="AzPOQn1v" Received: from pps.filterd (m0279867.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 67IE0ZKF2564176 for ; Tue, 18 Aug 2026 15:14:00 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= wCtpXxUQCEA8WhSXbgymO2TVAaU6id4xxMyC/S5YYf4=; b=Z3fiog3gpR5J63/e 7CCWAel77dlY9WkrBJ+wpdtWVpbQEyxFPQBS7AlcOKqsQnzrb0VTKpVQRCOXx6Ja K0BiGsqhouF5lBpY1Vq84i5y9xfjf73D6YirN3nMwgXEsb47IBhj5J0PU1uOImQ/ S+ic7msXJsBNo/4F4aGJvMc2LHNKMVx8phj5zTXIgCzv0js9KNuS2DGSJwUVkPsQ 6BhrOqQJEvoMJfIjYJc4pcn4OTV2Op3KgJfX3uKzw7ziIWf5nnTJD092lhFw/V5j 8/JXzjk82bl28WYDIep2rXpg5mUeB+J6YhxUABqC7KWwG8GxzDA88F7ZN9yPukVx huKIZg== Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com [209.85.222.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4g4frmtwx3-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 18 Aug 2026 15:14:00 +0000 (GMT) Received: by mail-qk1-f198.google.com with SMTP id af79cd13be357-930a098ea19so663929585a.1 for ; Tue, 18 Aug 2026 08:14:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1787066040; x=1787670840; darn=vger.kernel.org; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=wCtpXxUQCEA8WhSXbgymO2TVAaU6id4xxMyC/S5YYf4=; b=AzPOQn1vTFOXbRMP6TtpCryH+J5H9zfBbb9Tg8ZlEldSEPNbe+G8WcDi2Zlq4AjMNM zH3CU8/nH07keRFAFRxDp6TTss9H01EKIt5kvZrp71wv8W/YUMI4sN7r4UTbQ1jdBhSm KPAg4oXU0wCEhOarHPRv1CQ/OXcAjR8/kDuzdpXH5oxXoLo5jSVEGq6rHCCPUDu5Xbmo C0V1iJA8qfOIORiOb6Gf8RrMWqbb97QiNIIdK3lPFhNsvZAfc+gNZoffgvCRgCANq/Qx NufQy6cz6KzmTbkpDnBrXN9fzOK13giuJgvZ1wWQOjvO/SamzIo4ASemYhxmawS7L9PU y4FA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787066040; x=1787670840; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :content-type:mime-version:subject:date:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=wCtpXxUQCEA8WhSXbgymO2TVAaU6id4xxMyC/S5YYf4=; b=oVSrJmSvTNrKikVnlcFREii6D+U8iy6mLVQE1Im+8H3ULqI53HtyqDUuuXNeRreyiD ZPB4GQKhXGHy8kzbAFDrXUVXumgJuRdq7JuNGRfDLBtu5ClDid0DbP6gq6sbHU0Fbqc9 kJsi4sSq5JQlLT7lc9Ei9KQYvMG2EazoAVE3R76wY/sNFUGK0PRsTFiNyKOYW9Z4f99Z zrmOnbBqZKuwC2t6BAzRMPpeNzHecRtGEvIQ2AM1SRt0W/V+eAVuzS5Evti+3c54uDmU 4gxW943W0SK34EXEe9CIpFj360XLTH26VtlEVWPwCoFxh8eXYEC1TcZurds0PquuRrky mOVg== X-Forwarded-Encrypted: i=1; AHgh+RpeAgQLEXTK72jR6AyADdgKHxnXilD0nRs+AaQwZvCNW6R4Lq6dJeZLOoDmZrPl75leiD0Qdne1clkDxII=@vger.kernel.org X-Gm-Message-State: AOJu0Yx5jR/EV6/wgO9peMUT/0UcwOmJRp9J+dgBRGIMhdJ52AzG4quD a4nCH71SW4cgTb2N0E55Xb2qY3twh0LknlFDh8cbSWkWxIs8AGjfEGzv5bWaqBgLNYOHYn/iRYx wSs3s9VwuS9WKQDuukd1vDgGraMf4yV17NZlc6Z8oHfJgZL9H8RwZBJWkabf1YIXriU8= X-Gm-Gg: AR+sD10AvzhdGlzXMsEqqhe3LJNa4ztX3z7CMqeG3R5WIMsvVGLjN4Ii/8fl47nZgpM 059JuE/z56buamp69oplMfJwlB0kyBaP+oVIy93kLX2Il3RqUoe6FXE4mW41CILCaQ12dpRG/N+ rilYmjWfKtGNW0uYonarLEXP7ZAKT6v4KJZfCiTvcbiMYz0gKaHwJSNZp0gvMk6vE67lukZGJ75 TVHTZOKYL2auXJhEYvUYE1gn60NrxyCZJWyESYID1gsS4iBpe0fyCuXsjAVhXMC7B3fWoqk120Z rO1wHo3aPEcE2Jx41KErlXB692lgVb3ZxT0dsv5Q1HYaj8mV+aIjJCSM8yZ5W4hr1XPHy4FmUUb vw2WOEnclWc7wtDjinqE8SMABUOfuRZulrg== X-Received: by 2002:a05:620a:72b4:b0:936:cae6:5869 with SMTP id af79cd13be357-936d23607b3mr2667722185a.46.1787066039411; Tue, 18 Aug 2026 08:13:59 -0700 (PDT) X-Received: by 2002:a05:620a:72b4:b0:936:cae6:5869 with SMTP id af79cd13be357-936d23607b3mr2667716085a.46.1787066038938; Tue, 18 Aug 2026 08:13:58 -0700 (PDT) Received: from hu-bvisredd-hyd.qualcomm.com ([202.46.22.19]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-482a5a3158asm13111105f8f.7.2026.08.18.08.13.52 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 08:13:58 -0700 (PDT) From: Vishnu Reddy Date: Tue, 18 Aug 2026 20:43:23 +0530 Subject: [PATCH v2 2/2] media: venus: Fix iova allocation from restrict region Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260818-reserve_iova_in_driver-v2-2-5005a1154408@oss.qualcomm.com> References: <20260818-reserve_iova_in_driver-v2-0-5005a1154408@oss.qualcomm.com> In-Reply-To: <20260818-reserve_iova_in_driver-v2-0-5005a1154408@oss.qualcomm.com> To: Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Bryan O'Donoghue , Mauro Carvalho Chehab , Hans Verkuil , Stefan Schmidt , Stanimir Varbanov Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org, Vishnu Reddy , stable@vger.kernel.org, Dmitry Baryshkov X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1787066016; l=6186; i=busanna.reddy@oss.qualcomm.com; s=20260216; h=from:subject:message-id; bh=D2to+qdFUJIyRn0gO0bPSz/9KSto6nc1kDi6S4cQSCE=; b=cyF1gI48/ejxw8jwVxPUy8tI2Ux5AK3JwWjAy26p2TYMCW0mMm9/FvQMBKK8/xEypMGQL5emd 12WCyoQ1hpzCOtGk6jBKOWbDfOiq49P2gCIEThD+m9GwEPN7No7nqNc X-Developer-Key: i=busanna.reddy@oss.qualcomm.com; a=ed25519; pk=9vmy9HahBKVAa+GBFj1yHVbz0ey/ucIs1hrlfx+qtok= X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwODE4MDExMiBTYWx0ZWRfX/4r7UKibXs1i Tz5PQZpMQXVnsMQuxZbRIuM9XTxcBIMXjiWsu+n4OUdoIN9bCxPWCshZ9JeFRfqXTvTdVWkcDVL rEzyrQk+XrUDKZftMKyiFzWDymRMTCVEUnAYAXqygfH33SMenyFsUdD7R/ZQ8yj1AQxZakF6K/i igbrCGYmRCKnpxQB9MQlYskOSU9h0PDXdMdaEZpbyMLBkSpPd7qHDCRi8ucY0bc/bCfLtMgd2fi oKsJe4+EOx6h61IOAmDoV9yz6oGOiiMLTFZmZNSZGqINyO2enYhMt6ka8umg16FOkePXAX1XI4O vF04aDED/3jhWu3fwhWCULhfym7W5/2j/DxNk1nNvAqJMS7HHvN1oSrTc4G2YAb1iKbTO1DxkJJ fkxKoaqRTeYu3DL6in3yhAODFidj01i8EzqKyTP2hYw6HodRBcIK/XDpM87lKdb1gBoGrgcO/T4 H4p79ZfuelGQoCgm5Cw== X-Proofpoint-GUID: jWaeAa473wPSC0iU1xJP8eCfA88KqaTp X-Proofpoint-ORIG-GUID: jWaeAa473wPSC0iU1xJP8eCfA88KqaTp X-Authority-Analysis: v=2.4 cv=GtlyPE1C c=1 sm=1 tr=0 ts=6a8476b8 cx=c_pps a=qKBjSQ1v91RyAK45QCPf5w==:117 a=fChuTYTh2wq5r3m49p7fHw==:17 a=IkcTkHD0fZMA:10 a=Sv0fKeRqtYgA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=eoimf2acIAo5FJnRuUoq:22 a=e5mUnYsNAAAA:8 a=VwQbUJbxAAAA:8 a=EUspDBNiAAAA:8 a=qCMCQjtVS-vTbDhzrxIA:9 a=QEXdDO2ut3YA:10 a=NFOGd7dJGGMPyQGDc5-O:22 a=Vxmtnl_E_bksehYqCbjh:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwODE4MDExMiBTYWx0ZWRfX0horU9fEvDlp B7PhCUIVOK/aZj8eLM2K5MWXKn9wzeotpN90+2jlJYtkTDZkUZea7oTQWh4xaqCRqEg7/K42cfs iUWWRZhEePyvwPV8xegsS194Hop9f9k= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-08-18_02,2026-08-18_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 suspectscore=0 malwarescore=0 impostorscore=0 lowpriorityscore=0 phishscore=0 adultscore=0 bulkscore=0 clxscore=1015 spamscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2606150000 definitions=main-2608180112 The VPU issues DMA through several SMMU streams, and the hardware does not give every stream the same addressable range. The non-pixel stream cannot address the low 600MB of IOVA space, while the pixel stream can address the full range: +-----------------------------------------------------------+ | non-pixel stream addressable range (600 MB - 3.5 GB) | | 0x25800000 - 0xe0000000 | +-----------------------------------------------------------+ | pixel stream addressable range (0 - 3.5 GB) | | 0x00000000 - 0xe0000000 | +-----------------------------------------------------------+ A single "iommus" property on the video-codec node puts every stream in one IOMMU domain sharing one IOVA space, so nothing stops a non-pixel buffer from landing below 600MB. Once an allocation lands below that boundary the hardware faults, which shows up as unhandled SMMU page faults and spontaneous reboots. https://gitlab.freedesktop.org/drm/msm/-/work_items/100 Fix this by reserving the 0-600MB range, below the boundary the non-pixel stream cannot address, using dma_iova_try_alloc() so the IOMMU-DMA core never hands that range out to a real DMA mapping. This reserves only IOVA space, it does not allocate any physical memory. Since sub-nodes for non-pixel, pixel, and secure streams do not exist yet and only a single device is available, the restriction is applied to both non-pixel and pixel stream IDs. Fixes: af2c3834c8ca ("[media] media: venus: adding core part and helper fun= ctions") Cc: stable@vger.kernel.org Reviewed-by: Vikash Garodia Reviewed-by: Dmitry Baryshkov Signed-off-by: Vishnu Reddy --- drivers/media/platform/qcom/venus/core.c | 66 ++++++++++++++++++++++++++++= ++-- drivers/media/platform/qcom/venus/core.h | 5 +++ 2 files changed, 68 insertions(+), 3 deletions(-) diff --git a/drivers/media/platform/qcom/venus/core.c b/drivers/media/platf= orm/qcom/venus/core.c index 243e342b0ae7..2a0ab553c451 100644 --- a/drivers/media/platform/qcom/venus/core.c +++ b/drivers/media/platform/qcom/venus/core.c @@ -377,6 +377,57 @@ static int venus_add_dynamic_nodes(struct venus_core *= core) static void venus_remove_dynamic_nodes(struct venus_core *core) {} #endif =20 +static void venus_unreserve_iova_region(struct device *dev, struct dma_iov= a_state *state) +{ + unsigned int i; + + for (i =3D 0; dma_iova_size(&state[i]); i++) + dma_iova_free(dev, &state[i]); +} + +static int venus_reserve_iova_region(struct device *dev, struct dma_iova_s= tate **iova_state, + unsigned long start, unsigned long size) +{ + unsigned long dma_limit =3D dev->bus_dma_limit; + unsigned long end, rem, chunk; + struct dma_iova_state *state; + unsigned int count =3D 0; + int ret =3D -ENOMEM; + + state =3D devm_kcalloc(dev, BITS_PER_TYPE(dma_addr_t) + 1, sizeof(*state)= , GFP_KERNEL); + if (!state) + return ret; + + end =3D start + size; + rem =3D end - max(start, PAGE_SIZE); + dev->bus_dma_limit =3D end - 1; + + while (rem) { + chunk =3D min(end & -end, (u64)1 << (fls64(rem) - 1)); + + if (!dma_iova_try_alloc(dev, &state[count], 0, chunk)) + goto err_free_iova; + + if (state[count].addr !=3D end - chunk || state[count].__size !=3D chunk) + goto err_free_iova; + + rem -=3D chunk; + end -=3D chunk; + count++; + } + + *iova_state =3D state; + dev->bus_dma_limit =3D dma_limit; + + return 0; + +err_free_iova: + venus_unreserve_iova_region(dev, state); + dev->bus_dma_limit =3D dma_limit; + + return ret; +} + static int venus_probe(struct platform_device *pdev) { struct device *dev =3D &pdev->dev; @@ -421,10 +472,15 @@ static int venus_probe(struct platform_device *pdev) return ret; } =20 - ret =3D dma_set_mask_and_coherent(dev, core->res->dma_mask); + ret =3D venus_reserve_iova_region(dev, &core->iova_state, VENUS_NP_RESERV= E_IOVA_START, + VENUS_NP_RESERVE_IOVA_SIZE); if (ret) goto err_core_put; =20 + ret =3D dma_set_mask_and_coherent(dev, core->res->dma_mask); + if (ret) + goto err_unresv_iova_region; + dma_set_max_seg_size(dev, UINT_MAX); =20 INIT_LIST_HEAD(&core->instances); @@ -434,13 +490,13 @@ static int venus_probe(struct platform_device *pdev) =20 ret =3D hfi_create(core, &venus_core_ops); if (ret) - goto err_core_put; + goto err_unresv_iova_region; =20 ret =3D devm_request_threaded_irq(dev, core->irq, hfi_isr, venus_isr_thre= ad, IRQF_TRIGGER_HIGH | IRQF_ONESHOT, "venus", core); if (ret) - goto err_core_put; + goto err_unresv_iova_region; =20 venus_assign_register_offsets(core); =20 @@ -525,6 +581,8 @@ static int venus_probe(struct platform_device *pdev) v4l2_device_unregister(&core->v4l2_dev); err_hfi_destroy: hfi_destroy(core); +err_unresv_iova_region: + venus_unreserve_iova_region(dev, core->iova_state); err_core_put: if (core->pm_ops->core_put) core->pm_ops->core_put(core); @@ -562,6 +620,8 @@ static void venus_remove(struct platform_device *pdev) =20 hfi_destroy(core); =20 + venus_unreserve_iova_region(dev, core->iova_state); + mutex_destroy(&core->pm_lock); mutex_destroy(&core->lock); venus_dbgfs_deinit(core); diff --git a/drivers/media/platform/qcom/venus/core.h b/drivers/media/platf= orm/qcom/venus/core.h index 46705a666776..30b8cababe86 100644 --- a/drivers/media/platform/qcom/venus/core.h +++ b/drivers/media/platform/qcom/venus/core.h @@ -8,6 +8,7 @@ #define __VENUS_CORE_H_ =20 #include +#include #include #include #include @@ -30,6 +31,9 @@ =20 #define VENUS_MAX_FPS 240 =20 +#define VENUS_NP_RESERVE_IOVA_START 0x0 +#define VENUS_NP_RESERVE_IOVA_SIZE 0x25800000 + extern int venus_fw_debug; =20 struct freq_tbl { @@ -250,6 +254,7 @@ struct venus_core { unsigned long dump_core; struct of_changeset *ocs; bool hwmode_dev; + struct dma_iova_state *iova_state; }; =20 struct vdec_controls { --=20 2.34.1