From: Jesper Wendel Devantier <foss@defmacro.it>
To: Daniel Gomez <da.gomez@kernel.org>
Cc: qemu-devel@nongnu.org, Paolo Bonzini <pbonzini@redhat.com>,
Peter Xu <peterx@redhat.com>,
Philippe Mathieu-Daudé <philmd@mailo.com>,
Keith Busch <kbusch@kernel.org>, Klaus Jensen <its@irrelevant.dk>,
Klaus Jensen <k.jensen@samsung.com>,
qemu-block@nongnu.org, Daniel Gomez <da.gomez@samsung.com>,
GOST <gost.dev@samsung.com>
Subject: Re: [PATCH v2 7/7] hw/nvme: cap mdts for CMB/PMR-only
Date: Sat, 5 Sep 2026 00:02:22 +0200 [thread overview]
Message-ID: <20260904235915.7-foss@defmacro.it> (raw)
In-Reply-To: <20260819-align-nvme-mdts-with-linux-v2-7-351ac2dfed64@samsung.com>
On 2026-08-19T17:24:09+02:00, Daniel Gomez <da.gomez@kernel.org> wrote:
> From: Daniel Gomez <da.gomez@samsung.com>
>
> Commit 53493c1f83 ("hw/nvme: cap MDTS value for internal limitation")
> capped MDTS so the worst-case PRP count would fit in IOV_MAX, leaving
> transfers limited to 2 MiB.
>
> Now that dma_blk_cb() can batch IOs up to IOV_MAX instead of limiting
> to IOV_MAX, remove it, except for CMB/PMR-only where the limit still
> applies.
>
> In addition, fix UB when mdts >= 31 by dropping the shift and making the
> cap explicit. Fixes error with ubsan:
> ../hw/nvme/ctrl.c:8638:33: runtime error: shift exponent 32 is too
> large for 32-bit type 'int'
>
> Suggested-by: Klaus Jensen <k.jensen@samsung.com>
> Signed-off-by: Daniel Gomez <da.gomez@samsung.com>
> ---
> hw/nvme/ctrl.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/hw/nvme/ctrl.c b/hw/nvme/ctrl.c
> index 7861d8f2521..ff7e4a055b8 100644
> --- a/hw/nvme/ctrl.c
> +++ b/hw/nvme/ctrl.c
> @@ -8802,8 +8802,10 @@ static bool nvme_check_params(NvmeCtrl *n, Error **errp)
> host_memory_backend_set_mapped(n->pmr.dev, true);
> }
>
> - if (!n->params.mdts || ((1 << n->params.mdts) + 1) > IOV_MAX) {
> - error_setg(errp, "mdts exceeds IOV_MAX");
> + /* 2^mdts + 1 must fit IOV_MAX */
> + if ((n->params.cmb_size_mb || n->pmr.dev) &&
> + (!n->params.mdts || (params->mdts > 9))) {
> + error_setg(errp, "mdts=%u is incompatible with CMB/PMR", params->mdts);
> return false;
> }
>
>
> --
> 2.55.0
>
>
>
I generally agree except for a single nit-pick, if you will permit me.
(params->mdts > 9) -- it seems a bit indirect and could break if,
for some reason, IOV_MAX is different.
```c
static inline uint64_t nvme_mdts_max_iovs(uint8_t mdts)
{
return mdts >= 64 ? UINT64_MAX : (1ULL << mdts) + 1;
}
```
Then the check becomes
```c
if ((params->cmb_size_mb || n->pmr.dev) &&
(!params->mdts || nvme_mdts_max_iovs(params->mdts) > IOV_MAX)) {
error_setg(errp, "mdts=%u is incompatible with CMB/PMR", params->mdts);
return false;
}
```
?
next prev parent reply other threads:[~2026-09-04 22:03 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-19 15:24 [PATCH v2 0/7] hw/nvme: lift IOV_MAX limit in DMA path Daniel Gomez
2026-08-19 15:24 ` [PATCH v2 1/7] dma-helpers: fix unaligned discard_back Daniel Gomez
2026-09-04 21:57 ` Jesper Wendel Devantier
2026-09-09 12:17 ` Daniel Gomez
2026-08-19 15:24 ` [PATCH v2 2/7] dma-helpers: ensure IOV_MAX chunks end aligned Daniel Gomez
2026-08-19 15:24 ` [PATCH v2 3/7] dma-helpers: cap iovec allocation at IOV_MAX Daniel Gomez
2026-09-04 21:57 ` Jesper Wendel Devantier
2026-08-19 15:24 ` [PATCH v2 4/7] dma-helpers: chunk dma_blk_cb " Daniel Gomez
2026-09-04 21:58 ` Jesper Wendel Devantier
2026-08-19 15:24 ` [PATCH v2 5/7] hw/nvme: clamp mdts and zasl shifts Daniel Gomez
2026-09-04 21:58 ` Jesper Wendel Devantier
2026-08-19 15:24 ` [PATCH v2 6/7] hw/nvme: drop DMA-path IOV_MAX guard Daniel Gomez
2026-09-04 21:59 ` Jesper Wendel Devantier
2026-08-19 15:24 ` [PATCH v2 7/7] hw/nvme: cap mdts for CMB/PMR-only Daniel Gomez
2026-09-04 22:02 ` Jesper Wendel Devantier [this message]
2026-09-09 12:35 ` Daniel Gomez
2026-09-04 22:00 ` [PATCH v2 0/7] hw/nvme: lift IOV_MAX limit in DMA path Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260904235915.7-foss@defmacro.it \
--to=foss@defmacro.it \
--cc=da.gomez@kernel.org \
--cc=da.gomez@samsung.com \
--cc=gost.dev@samsung.com \
--cc=its@irrelevant.dk \
--cc=k.jensen@samsung.com \
--cc=kbusch@kernel.org \
--cc=pbonzini@redhat.com \
--cc=peterx@redhat.com \
--cc=philmd@mailo.com \
--cc=qemu-block@nongnu.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.