From nobody Thu Sep 24 12:53:19 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B3B154756B9 for ; Thu, 24 Sep 2026 11:04:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247894; cv=none; b=SY8eZWxZ0OQ7R8HvlXuTr01SD6ZIZB7MoYGHCtabp4op2jP8N2HWo8CufzJCic8IohIzFvvz12W+2WVQv6Om1JFlr9wIBiGxhRHDR+rV/JJ0ZhEBrdMTvsHaN4JQ8SvVW1lM5CdRfaGw+c/qOEDVR76UPxz6s2NUshI7ZjkmkFs= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247894; c=relaxed/simple; bh=RWRAgqcZvTlrK4MF3qHx3XFr+HEwUZDkIslQuz9Qlg8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=PvZYF8JCq2EyCfysVXoMkSNCxyxwY92dypPVXuTPw6PXsa/vd+h1wYG0c0u6xvEyKWsBQK+pk69JD4GG0L3AqelGp9YaQ0j65DbK7iRbDVJalE53RXj1z1N+GM8fmj1FB3/iDsTkn04ZmMXOAo7wPd+XZmZoiL6fcFn6Xi7t5Wk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=B8n5c237; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="B8n5c237" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1790247887; bh=RWRAgqcZvTlrK4MF3qHx3XFr+HEwUZDkIslQuz9Qlg8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=B8n5c2373DgF95Ch8id6LmuRhRMms9kCwImL+CMWmVTm1TGgjloOmxAQdDy1GG4QT mfUExrk4vHViZHBFWgDXU5Knb5B8ljXjiM6Ksk6JyqKtrPgFv3rxZS8zIX4gFUPmlU j7j90+PjIRxZkvtvB5RShnK+S4Rh7Vqh72DojFhe3mmrFtbDOTq9ZM7rTawhpgkJTj 9N22loDN7VOTd+guqSajVYyaGyYSqarFZHnsdUprxUl3qMbHMBf7VyHjRgj7A/jczw CL65b63cqnZbSyBNeKvu8xVAFqeRf1EbqKTi9MgatsH9+2lUF0f9jPrDR3mHOdZc6V ytALqyFkIeiuQ== Received: from fedora-32.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id DD59717E01D1; Thu, 24 Sep 2026 13:04:46 +0200 (CEST) From: Boris Brezillon Date: Thu, 24 Sep 2026 13:04:38 +0200 Subject: [PATCH v2 1/5] drm/panthor: Avoid false positives in iova_mapped_as_huge_page() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-panthor-fix-partial-unmap-v2-1-59a68a1f9e14@collabora.com> References: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> In-Reply-To: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> To: Steven Price , Liviu Dudau , =?utf-8?q?Adri=C3=A1n_Larumbe?= , Akash Goel Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790247886; l=3632; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=RWRAgqcZvTlrK4MF3qHx3XFr+HEwUZDkIslQuz9Qlg8=; b=5zWK0jgFjRNP103VQCHWK0VdP4mIvApPtSIptMSX3bH7QUr1Gor03hxfYghzoGuYziZ4kF8Mk OgDYOS3gi3KDAEl442baR9J1LmeTmoyGai28AklsgkVU5U4RGPARVXy X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= The check on the folio size is actually moot if the BO offset matching the VA we're checking huge-mapping for is not 2M aligned as well. This means that we are sometimes returning true when we shouldn't, which forces an extra unmap+map to deal with block-mapping splits. It's not a functional bug per-se, because the unmap+map sequence will restore things in the state we expect them to be, but it's better to properly optimize those cases. Note that we now align the VA on 2M address below it otherwise we can't check the bo_offset alignment (both physical and virtual address need to be aligned, in addition to the physically contiguous size being 2M, which the folio size check ensures). These changes force us to pass the drm_gpuva that's being unmapped instead of the new mappings that will be created to cover the left/right sections we remap. This changes makes the logic a lot easier to reason about, because it doesn't make sense to how things were mapped by passing the new mappings that are not yet in place. Fixes: 8e7460eac786 ("drm/panthor: Support partial unmaps of huge pages") Reviewed-by: Liviu Dudau Reviewed-by: Akash Goel Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 24 +++++++++++++++++++----- 1 file changed, 19 insertions(+), 5 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 9f63a048df61..b0a7033480e6 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -2295,15 +2295,29 @@ static int panthor_gpuva_sm_step_map(struct drm_gpu= va_op *op, void *priv) } =20 static bool -iova_mapped_as_huge_page(struct drm_gpuva_op_map *op, u64 addr) +iova_mapped_as_huge_page(struct drm_gpuva *mapping, u64 va) { - struct panthor_gem_object *bo =3D to_panthor_bo(op->gem.obj); + struct panthor_gem_object *bo =3D to_panthor_bo(mapping->gem.obj); + u64 aligned_va =3D ALIGN_DOWN(va, SZ_2M); const struct page *pg; pgoff_t bo_offset; =20 - bo_offset =3D addr - op->va.addr + op->gem.offset; + /* If the 2M-aligned VA is outside the mapping being tested, we know + * it's not a huge map. + */ + if (aligned_va < mapping->va.addr) + return false; + + bo_offset =3D aligned_va - mapping->va.addr + mapping->gem.offset; pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; =20 + /* In case of shmem backing, we know we can only have a huge mapping + * if the bo_offset is 2M aligned, meaning we can skip the folio size + * check if it's not the case. + */ + if (!IS_ALIGNED(bo_offset, SZ_2M)) + return false; + return folio_size(page_folio(pg)) >=3D SZ_2M; } =20 @@ -2328,7 +2342,7 @@ unmap_hugepage_align(const struct drm_gpuva_op_remap = *op, */ if (op->prev && aligned_unmap_start < *unmap_start && op->prev->va.addr <=3D aligned_unmap_start && - (is_sparse || iova_mapped_as_huge_page(op->prev, *unmap_start))) { + (is_sparse || iova_mapped_as_huge_page(op->unmap->va, *unmap_start)))= { *unmap_range +=3D *unmap_start - aligned_unmap_start; *unmap_start =3D aligned_unmap_start; } @@ -2338,7 +2352,7 @@ unmap_hugepage_align(const struct drm_gpuva_op_remap = *op, */ if (op->next && aligned_unmap_end > unmap_end && op->next->va.addr + op->next->va.range >=3D aligned_unmap_end && - (is_sparse || iova_mapped_as_huge_page(op->next, unmap_end - 1))) { + (is_sparse || iova_mapped_as_huge_page(op->unmap->va, unmap_end - 1))= ) { *unmap_range +=3D aligned_unmap_end - unmap_end; } } --=20 2.55.0 From nobody Thu Sep 24 12:53:19 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 227F81A6814 for ; Thu, 24 Sep 2026 11:04:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247896; cv=none; b=DMF/KisRWoz1/TAInXY5oyjRvAfMyPetXkLB+Uswur+bvMKyY/bnwB6ib0E8q4mgj8KkSruQGGiF8908dVe70y/0WlIYtfKpiFuv6ekAvTeWZU4htQyNEvGonPg6lcJjZujfgk7DPAZOvKsmzl+CH+5GcoVCLT3R6pJIVLGvGEk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247896; c=relaxed/simple; bh=0qelJpYQzmfhybMuaPs5+rDwKz2Lxlo9Q93rfcncJ/U=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=oCzfBmVFe+QZ/64GonqvUAiE1LkKb3E1esrS0F7SUsMMNWIRIPoK7A89re+zFnktHlkFPefq8+6uAafcap8K+SiG4t5BDFiwZHaZ43OUnlnC3MkRaPbYZWpTgUu6n2hQM5kifqrIdCXhVH70J4i91DGN+a1MWYWgjI3qt1QZHCE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=Gp4UzP8L; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="Gp4UzP8L" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1790247887; bh=0qelJpYQzmfhybMuaPs5+rDwKz2Lxlo9Q93rfcncJ/U=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=Gp4UzP8LjQBqTLv+3WHrPEI1TQrt8UFzQRoL9Izf8OTGtrZZuKW6u+S8sWjJ7maa3 MavSgyle/JiKz+oq2lB9MBcoxSFUFEVxlM1r3gTbRQEfZ73urId4QrZv7lIAvW0iP/ aCj5I0I/vpaKs/gjSsVmtNIt0quSW/gbLVWwa+CmFhnAuq2NjQouA443sybLqQOs61 0kl7hY98o6CFnDl67PzOsbsnNUk44B9/IalXbdxrOCdTEVvhMXr+5C6ArpMFEStBBB ODI18GK2/0Q5pZNhXy9ZgiWgzl4yPChiQMO10Keliud/yetlOIrPa7LIK3ZOqY3S+e umuCg2qVYJXQg== Received: from fedora-32.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 75E0517E0A68; Thu, 24 Sep 2026 13:04:47 +0200 (CEST) From: Boris Brezillon Date: Thu, 24 Sep 2026 13:04:39 +0200 Subject: [PATCH v2 2/5] drm/panthor: Fix iova_mapped_as_huge_page() for imported BOs Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-panthor-fix-partial-unmap-v2-2-59a68a1f9e14@collabora.com> References: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> In-Reply-To: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> To: Steven Price , Liviu Dudau , =?utf-8?q?Adri=C3=A1n_Larumbe?= , Akash Goel Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790247886; l=3046; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=0qelJpYQzmfhybMuaPs5+rDwKz2Lxlo9Q93rfcncJ/U=; b=ZPRN5/e+EFTIVRXxWfY9ll3+430PqKUnuP8iPpFwnkDAIYAupHI8RL4KA+kIELc9DTWiQm1vF Nou2rogH5S4DSxo+tw6raw2zAAosUTkJiSSQ/ypb0L0JaWVzpfg1cdw X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Imported BOs have no backing.pages array allocated, leading to a NULL deref when iova_mapped_as_huge_page() gets called on them. Implement this check through and sgt walk to reach the position of the sgt targeted by a VA, and check that the DMA address is properly aligned and the size remaining in the SG entry is bigger than a huge page. This is basically matching the logic in vm_map_pages(), with get_pgsize() being replaced by a simpler test, because we don't care about the pgcount info. Reported-by: Akash Goel Fixes: 8e7460eac786 ("drm/panthor: Support partial unmaps of huge pages") Reviewed-by: Liviu Dudau Reviewed-by: Akash Goel Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 44 ++++++++++++++++++++++++++++---= ---- 1 file changed, 36 insertions(+), 8 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index b0a7033480e6..6cef954e2cba 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -2299,7 +2299,6 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping, u= 64 va) { struct panthor_gem_object *bo =3D to_panthor_bo(mapping->gem.obj); u64 aligned_va =3D ALIGN_DOWN(va, SZ_2M); - const struct page *pg; pgoff_t bo_offset; =20 /* If the 2M-aligned VA is outside the mapping being tested, we know @@ -2309,16 +2308,45 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping,= u64 va) return false; =20 bo_offset =3D aligned_va - mapping->va.addr + mapping->gem.offset; - pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; =20 - /* In case of shmem backing, we know we can only have a huge mapping - * if the bo_offset is 2M aligned, meaning we can skip the folio size - * check if it's not the case. - */ - if (!IS_ALIGNED(bo_offset, SZ_2M)) + if (drm_gem_is_imported(&bo->base)) { + struct sg_table *sgt =3D bo->dmap.sgt; + struct scatterlist *sgl; + unsigned int count; + + /* If this is an imported BO, we have to walk the SGT and + * check the dma address/size alignment to determine if it's + * a huge map or not. + */ + for_each_sgtable_dma_sg(sgt, sgl, count) { + size_t len =3D sg_dma_len(sgl); + dma_addr_t daddr; + + if (len <=3D bo_offset) { + bo_offset -=3D len; + continue; + } + + len -=3D bo_offset; + daddr =3D sg_dma_address(sgl) + bo_offset; + + return IS_ALIGNED(daddr, SZ_2M) && + len >=3D SZ_2M; + } + return false; + } else { + const struct page *pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; =20 - return folio_size(page_folio(pg)) >=3D SZ_2M; + /* In case of shmem backing, we know we can only have a huge mapping + * if the bo_offset is 2M aligned, meaning we can skip the folio size + * check if it's not the case. + */ + if (!IS_ALIGNED(bo_offset, SZ_2M)) + return false; + + return folio_size(page_folio(pg)) >=3D SZ_2M; + } } =20 static void --=20 2.55.0 From nobody Thu Sep 24 12:53:19 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0B14147533A for ; Thu, 24 Sep 2026 11:04:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247897; cv=none; b=cBMlrMgiTA1Y4V95pVYB3UTAotXOoUJS9YJGiBbX7FdioJVMS8efOQYvqqDw3Oy/cMuWG+CHqQf8LDNRXIwnmR37uUFcnEWUQqRxzC69sEWjG3dvZJvpasWLycFuXUFm/nul4cGQ1VJCv0kdCZX9OLQtPMRM3EYo0FmsmqQwIhM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247897; c=relaxed/simple; bh=l2etIP9PJMxsk7nG61TrL6ErHOuKhljTLXWBNvH5UPk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=FDXgD02T6WyLHYoYpu1A0C0HUsF6gyVO2z2gE5AKFEiTPkrde27BmtDVrYkY0PrDeiD3lXe7mECIhxYcyKYddUiNE7OTB+i8xXOHTR+9vl84mGjYd5b5XgHRrhuRDflKyt3y7/7fsIIWwuZnrwFT9krSsJBweSierq/gx6gVFNY= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=ZCTa7Aq6; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="ZCTa7Aq6" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1790247888; bh=l2etIP9PJMxsk7nG61TrL6ErHOuKhljTLXWBNvH5UPk=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=ZCTa7Aq6H2jP1dkJ/XI1/9q0UJr2WoX+sGCafCjPqvd9bwLe1LVWhVdVA2gYKe/TD OdS4rOGeLWmoT31hlD3lKKzN1RbgsQif9Vam45DojuYhRzaJQW8vvZiX3HoRk8d7Dm GsVIcqq1j2Q4uJdYSZ+2wwzb55OXG+iGww2i/84A2CdskONma/scHbhrb3ulK/DH2M jO673t9L32Q/GQxzYJVsPiALLWE1BZTioPYZNz85/dU/0+luEPMQlMXrP9KVTLyn1J MxuIhfUicz1sPuYIj1vY/+WgDOEGoMjpYZ3CF9J2ESAv7Cb6i0tVPRtIT6/dITjHwE VDERBtBB+PSIg== Received: from fedora-32.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 0FD1217E0A6A; Thu, 24 Sep 2026 13:04:48 +0200 (CEST) From: Boris Brezillon Date: Thu, 24 Sep 2026 13:04:40 +0200 Subject: [PATCH v2 3/5] drm/panthor: Consolidate the is-huge-page-mapping test Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-panthor-fix-partial-unmap-v2-3-59a68a1f9e14@collabora.com> References: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> In-Reply-To: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> To: Steven Price , Liviu Dudau , =?utf-8?q?Adri=C3=A1n_Larumbe?= , Akash Goel Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790247886; l=4986; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=l2etIP9PJMxsk7nG61TrL6ErHOuKhljTLXWBNvH5UPk=; b=8YK0ozC0y5iOpu9YZCXXGjwDW+e9Hjsx+mwGJ09WL+b8y5KT2WA1gQBOK17KhJe3nn6xxt70T hVBrACu56frBgx+n9ZQxbwklcrWN+kuzvekRce5wCTUKN8Vs/xkRNro X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= Right now the logic to determine whether a given VA in the drm_gpuva being unmapped is a huge page mapping or not is scattered in two functions: unmap_hugepage_align() and iova_mapped_as_huge_page(). This makes it harder to reason about the logic being implemented for very little gain (some simple checks being done twice), so let's consolidate all the checks related to huge page mapping testing in iova_mapped_as_huge_page() and leave unmap_hugepage_align() as a simple user of this helper that aligns the area to unmap based on the return of iova_mapped_as_huge_page(). Reviewed-by: Liviu Dudau Reviewed-by: Akash Goel Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 57 +++++++++++++++++--------------= ---- 1 file changed, 28 insertions(+), 29 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 6cef954e2cba..d2897099763e 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -2301,10 +2301,11 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping,= u64 va) u64 aligned_va =3D ALIGN_DOWN(va, SZ_2M); pgoff_t bo_offset; =20 - /* If the 2M-aligned VA is outside the mapping being tested, we know - * it's not a huge map. + /* If the 2M section being tested is crossing the mapping boundary + * we know it's not a huge map. */ - if (aligned_va < mapping->va.addr) + if (aligned_va < mapping->va.addr || + aligned_va + SZ_2M > mapping->va.addr + mapping->va.range) return false; =20 bo_offset =3D aligned_va - mapping->va.addr + mapping->gem.offset; @@ -2337,10 +2338,21 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping,= u64 va) return false; } else { const struct page *pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; + struct panthor_vma *vma =3D container_of(mapping, struct panthor_vma, ba= se); + bool is_sparse =3D vma->flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE; =20 - /* In case of shmem backing, we know we can only have a huge mapping - * if the bo_offset is 2M aligned, meaning we can skip the folio size - * check if it's not the case. + /* If the unmapped VMA stands for a sparse mapping, always + * assume the backing storage is a THP, since the overhead of + * unmapping 2MiB worth of 4KiB pages and remapping some of + * them is offset by the logic of working out whether it's + * the opposite case right below. + */ + if (is_sparse) + return true; + + /* In case of shmem backing, we know we can only have a huge + * mapping if the bo_offset is 2M aligned, meaning we can skip + * the folio size check if it's not the case. */ if (!IS_ALIGNED(bo_offset, SZ_2M)) return false; @@ -2353,36 +2365,23 @@ static void unmap_hugepage_align(const struct drm_gpuva_op_remap *op, u64 *unmap_start, u64 *unmap_range) { - struct panthor_vma *unmap_vma =3D container_of(op->unmap->va, struct pant= hor_vma, base); - bool is_sparse =3D unmap_vma->flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE; - u64 aligned_unmap_start, aligned_unmap_end, unmap_end; - - unmap_end =3D *unmap_start + *unmap_range; - aligned_unmap_start =3D ALIGN_DOWN(*unmap_start, SZ_2M); - aligned_unmap_end =3D ALIGN(unmap_end, SZ_2M); + u64 unmap_end =3D *unmap_start + *unmap_range; =20 /* If we're dealing with a huge page, make sure the unmap region is - * aligned on the start of the page. If the unmapped VMA stands for - * a sparse mapping, always assume the backing storage is a THP, since - * the overhead of unmapping 2MiB worth of 4KiB pages and remapping - * some of them is offset by the logic of working out whether it's - * the opposite case right below. This also holds true for op->next. + * aligned on the start of the page. */ - if (op->prev && aligned_unmap_start < *unmap_start && - op->prev->va.addr <=3D aligned_unmap_start && - (is_sparse || iova_mapped_as_huge_page(op->unmap->va, *unmap_start)))= { - *unmap_range +=3D *unmap_start - aligned_unmap_start; - *unmap_start =3D aligned_unmap_start; - } + if (op->prev && !IS_ALIGNED(*unmap_start, SZ_2M) && + iova_mapped_as_huge_page(op->unmap->va, *unmap_start)) + *unmap_start =3D ALIGN_DOWN(*unmap_start, SZ_2M); =20 /* If we're dealing with a huge page, make sure the unmap region is * aligned on the end of the page. */ - if (op->next && aligned_unmap_end > unmap_end && - op->next->va.addr + op->next->va.range >=3D aligned_unmap_end && - (is_sparse || iova_mapped_as_huge_page(op->unmap->va, unmap_end - 1))= ) { - *unmap_range +=3D aligned_unmap_end - unmap_end; - } + if (op->next && !IS_ALIGNED(unmap_end, SZ_2M) && + iova_mapped_as_huge_page(op->unmap->va, unmap_end - 1)) + unmap_end =3D ALIGN(unmap_end, SZ_2M); + + *unmap_range =3D unmap_end - *unmap_start; } =20 static int panthor_gpuva_sm_step_remap(struct drm_gpuva_op *op, --=20 2.55.0 From nobody Thu Sep 24 12:53:19 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0A5FB472F9F for ; Thu, 24 Sep 2026 11:04:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247896; cv=none; b=EwWoKmqrpIiEf27Lh6mtVkVvQpzBXBKh+WPW5jQM4Fj67AmswP9gmaKfaG8tPKv7o3n7BnsehXW5EUzoyBcr6n5hbNvGQls31doGQbI8u5UjvkcmMMvEU+0zaeRyWNbwaFklSfRLrZCf7MP4wDS4n40lIuacRbp0BRbyp/phamY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247896; c=relaxed/simple; bh=XXFQmfxbeg12M2OgKN8dJ9l8UIV4ldaUbZSuiynE7b4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=kqANcM5izBMkc4Fz9EMfqlTux4DvCPNVl8AX4j9YQDa8pu2hX6e4cBZchWs2qPG/S8o0av6dnd6ubJR5xEWkM0yBAhQkGUCg36Rx7HehfxxKwx20GQuMPGz/GJFYjm4liJ+61BGmRKQunohCA4CDV+nbnqS1BbI6bc5WixXMkAo= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=oPEz3aWT; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="oPEz3aWT" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1790247889; bh=XXFQmfxbeg12M2OgKN8dJ9l8UIV4ldaUbZSuiynE7b4=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=oPEz3aWTOD7BORoXvzIu8ZcdFFTYDR65DWxRg6vPai1wDhU70fz7IgiTAI/n2VvcF AI/sDLpbXbEgWG4QZ2+tmah/F7SgFxptiITV887SDZG9ciMHQbdePrn9DtmWwDoACG 7uQNuNQid/AsK3XQbXaWmV1qyGzFvngvTrdkijVPxwhq4If7aDi5uPXKfsT5iEOk3X /KrkNEYeJob2TT6zzTH4Yo0ab3Qj1o79BV1FL3meTVbnYLA0PxOLvI09uL0QVZaByX qm84l1crTV9aWsPIbBJRAkm5gqT7AChFcaM4SnA6RWRs6Tksw6Jjfi8qdA97IP8a9P TnPNHuqPprXug== Received: from fedora-32.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 9DD9117E0B0F; Thu, 24 Sep 2026 13:04:48 +0200 (CEST) From: Boris Brezillon Date: Thu, 24 Sep 2026 13:04:41 +0200 Subject: [PATCH v2 4/5] drm/panthor: Actually check huge-page mapping on sparse regions Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-panthor-fix-partial-unmap-v2-4-59a68a1f9e14@collabora.com> References: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> In-Reply-To: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> To: Steven Price , Liviu Dudau , =?utf-8?q?Adri=C3=A1n_Larumbe?= , Akash Goel Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790247886; l=2529; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=XXFQmfxbeg12M2OgKN8dJ9l8UIV4ldaUbZSuiynE7b4=; b=l/2yTWBNMeOJtPU6XlpqndFiYPPeycUcG7eZjtPC93NZDKhi11vFCOgO9xHR4iERb/9oXymjD Hcq/8fsUb4/C1JTK92i1i/K6v53+WNIjkB7qYNx9lkrI/NVzvWkvgah X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= With the recent changes to iova_mapped_as_huge_page(), the check for huge-page mapping of sparse BOs is actually simple: - for a sparse mapping, we know the BO offset any VA in this regions is va & (SZ_2M - 1) - the VA we're searching the BO offset for is the 2M-aligned aligned_va value This guarantees that the BO offset to check is always zero in that case. This is simple enough to let the code check if page 0 is a huge page and save the unmap+map dance when the dummy BO is not backed by a a huge page. So let's do that and kill the comment that says it's too complicated. Reviewed-by: Liviu Dudau Reviewed-by: Akash Goel Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 15 ++++++++------- 1 file changed, 8 insertions(+), 7 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index d2897099763e..01564d250adf 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -2337,18 +2337,18 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping,= u64 va) =20 return false; } else { - const struct page *pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; struct panthor_vma *vma =3D container_of(mapping, struct panthor_vma, ba= se); bool is_sparse =3D vma->flags & DRM_PANTHOR_VM_BIND_OP_MAP_SPARSE; + const struct page *pg; =20 - /* If the unmapped VMA stands for a sparse mapping, always - * assume the backing storage is a THP, since the overhead of - * unmapping 2MiB worth of 4KiB pages and remapping some of - * them is offset by the logic of working out whether it's - * the opposite case right below. + /* BO offset on a sparse mapping is chosen so that 2M-aligned + * VAs point to the start of the BO. Since aligned_va (the + * address we check huge-page against) is 2M-aligned, the BO + * offset is guaranteed to be zero. + * Check panthor_fix_sparse_map_offset() for more details. */ if (is_sparse) - return true; + bo_offset =3D 0; =20 /* In case of shmem backing, we know we can only have a huge * mapping if the bo_offset is 2M aligned, meaning we can skip @@ -2357,6 +2357,7 @@ iova_mapped_as_huge_page(struct drm_gpuva *mapping, u= 64 va) if (!IS_ALIGNED(bo_offset, SZ_2M)) return false; =20 + pg =3D bo->backing.pages[bo_offset >> PAGE_SHIFT]; return folio_size(page_folio(pg)) >=3D SZ_2M; } } --=20 2.55.0 From nobody Thu Sep 24 12:53:19 2026 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 040604756B1 for ; Thu, 24 Sep 2026 11:04:56 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247898; cv=none; b=iG2c0B/R9HWtJ/ETorlnzy0i+ZBmmp48IVUkHRymW3GwXshv9k0dc5fwfS8UKE4fwwrNhqBdvWaZ6GoAYHA3wt3QdwDclD3d2oC+GYTvX9sHVWQMIkbE8PrGhj8+4MLE57X5B4ESAPWedsR5v1Z9DuvCuEDAftcSAK7H4kG2im4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790247898; c=relaxed/simple; bh=haNaa1vTgpxyTcCfqXXR41IYwfwITsSUh39XMWGczo8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=q5gXDuLA+5ThVJXYRxkTMRbZgSNsJTLIKdBuuyHeUIcxc0BHIbOlMoYRrii2QfWWz44L+61yjobxAW9no0m8mWv256bZ1tmvUBe+f/nOLj2vGGtYmPZqNM1LZ/yxDbeGddGsA5FbG+P7rKfB1duWTMN1J+WwR+OVDq1QNn1GbmU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=lRSHosIY; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="lRSHosIY" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1790247889; bh=haNaa1vTgpxyTcCfqXXR41IYwfwITsSUh39XMWGczo8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=lRSHosIYzYj774CP8Xo/cJWcvQQCN9W8iBZfJ+6qK3+o1sv5yC7ENLvUWsEf3fQ4r Y6WWNga0wFquCVbyhCqMkh+QghMtTItG8EsXVdteIrQms8yp+KmPqsiOsmUUxzmqQD 6bcQs5vAjYf/LaPugns9OOuq8/znZjn7kTnQpVJofGo75KStzcQzJkUzoNk10BfwJ3 2AnvYygGH/2PqxdaZvkWIQeHTR4rwZnuHrLZAv3R1u/GQDOrjxViJwvij26p/Zdejc 5wWjW+sJM+hW/istAGR6mXj7jVSBb/TqZNLmrwVi87aY8tfMj5W8XSPK+zYv9pVOVG ve092JP/d35tg== Received: from fedora-32.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 36FF017E0D5D; Thu, 24 Sep 2026 13:04:49 +0200 (CEST) From: Boris Brezillon Date: Thu, 24 Sep 2026 13:04:42 +0200 Subject: [PATCH v2 5/5] drm/panthor: Remove redundant panthor_fix_sparse_map_offset() call Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260924-panthor-fix-partial-unmap-v2-5-59a68a1f9e14@collabora.com> References: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> In-Reply-To: <20260924-panthor-fix-partial-unmap-v2-0-59a68a1f9e14@collabora.com> To: Steven Price , Liviu Dudau , =?utf-8?q?Adri=C3=A1n_Larumbe?= , Akash Goel Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1790247886; l=2164; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=haNaa1vTgpxyTcCfqXXR41IYwfwITsSUh39XMWGczo8=; b=eMMbyP6t2Qzi8/4M0Ex9oQq2+t4AYFS4pSN1SCSJTLJweJK7ouqPPlzH05Y4iH9GUFntsKJVW yiE9zh6eurPAA0Hlhw6t4JbsHFxE4vT5BaGRvgr1ijjRKuqXAjGIPIa X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= op->remap.next->gem.offset is adjusted twice in panthor_gpuva_sm_step_remap() (once on the remap.next object, and once on the local map_op). Let's do it only once, and move this adjusment closer to the place it matters. Reported-by: Akash Goel Closes: https://lore.kernel.org/dri-devel/b85679e3-5ca2-4d36-8675-2b968d97c= b5b@arm.com/ Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/pantho= r/panthor_mmu.c index 01564d250adf..d8fb29ace5c4 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -2397,11 +2397,6 @@ static int panthor_gpuva_sm_step_remap(struct drm_gp= uva_op *op, =20 drm_gpuva_op_remap_to_unmap_range(&op->remap, &unmap_start, &unmap_range); =20 - /* op->remap.prev's BO offset is always the same as the unmap va's, but - * that of op->remap.next must be adjusted so as to remain < SZ_2M - */ - panthor_fix_sparse_map_offset(op->remap.next, unmap_vma->flags); - if (!unmap_vma->evicted) { /* * ARM IOMMU page table management code disallows partial unmaps of huge= pages, @@ -2447,6 +2442,12 @@ static int panthor_gpuva_sm_step_remap(struct drm_gp= uva_op *op, u64 addr =3D op->remap.next->va.addr; u64 size =3D unmap_start + unmap_range - op->remap.next->va.addr; =20 + /* op->remap.prev's BO offset is always the same as the unmap + * va's, but that of op->remap.next must be adjusted so as to + * remain < SZ_2M + */ + panthor_fix_sparse_map_offset(op->remap.next, unmap_vma->flags); + if (!unmap_vma->evicted && size > 0) { struct drm_gpuva_op_map map_op =3D { .va.addr =3D addr, @@ -2454,7 +2455,6 @@ static int panthor_gpuva_sm_step_remap(struct drm_gpu= va_op *op, .gem.obj =3D op->remap.next->gem.obj, .gem.offset =3D op->remap.next->gem.offset, }; - panthor_fix_sparse_map_offset(&map_op, unmap_vma->flags); =20 ret =3D panthor_vm_exec_map_op(vm, unmap_vma->flags, &map_op); if (ret) --=20 2.55.0