From: Jan Maslak <jan.maslak@intel.com>
To: intel-xe@lists.freedesktop.org
Cc: matthew.auld@intel.com, matthew.brost@intel.com,
thomas.hellstrom@linux.intel.com, rodrigo.vivi@intel.com,
Christoph Manszewski <christoph.manszewski@intel.com>,
Jan Maslak <jan.maslak@intel.com>
Subject: [PATCH v3 1/4] drm/xe/xe_migrate: Align MEM_COPY pitch with destination address
Date: Wed, 9 Sep 2026 08:18:42 +0200 [thread overview]
Message-ID: <20260909061845.4048047-2-jan.maslak@intel.com> (raw)
In-Reply-To: <20260909061845.4048047-1-jan.maslak@intel.com>
From: Christoph Manszewski <christoph.manszewski@intel.com>
MEM_COPY_CMD can corrupt memory when MATRIX_COPY mode uses a pitch that
is not aligned to the destination address.
Fix this by incorporating the destination address into the pitch
selection so the chosen pitch is aligned to both the copy length and the
destination address.
Signed-off-by: Christoph Manszewski <christoph.manszewski@intel.com>
Signed-off-by: Jan Maslak <jan.maslak@intel.com>
Reviewed-by: Matthew Auld <matthew.auld@intel.com>
---
drivers/gpu/drm/xe/xe_migrate.c | 29 +++++++++++++++++------------
1 file changed, 17 insertions(+), 12 deletions(-)
diff --git a/drivers/gpu/drm/xe/xe_migrate.c b/drivers/gpu/drm/xe/xe_migrate.c
index ff45c24d8889..2e5827aaf99d 100644
--- a/drivers/gpu/drm/xe/xe_migrate.c
+++ b/drivers/gpu/drm/xe/xe_migrate.c
@@ -2205,17 +2205,18 @@ static bool xe_migrate_vram_use_pde(struct drm_pagemap_addr *sram_addr,
#define XE_CACHELINE_BYTES 64ull
#define XE_CACHELINE_MASK (XE_CACHELINE_BYTES - 1)
-static u32 xe_migrate_copy_pitch(struct xe_device *xe, u32 len)
+static u32 xe_migrate_copy_pitch(struct xe_device *xe, u32 len, u64 dst_addr)
{
+ u64 align_check = len | dst_addr;
u32 pitch;
- if (IS_ALIGNED(len, PAGE_SIZE))
+ if (IS_ALIGNED(align_check, PAGE_SIZE))
pitch = PAGE_SIZE;
- else if (IS_ALIGNED(len, SZ_4K))
+ else if (IS_ALIGNED(align_check, SZ_4K))
pitch = SZ_4K;
- else if (IS_ALIGNED(len, SZ_256))
+ else if (IS_ALIGNED(align_check, SZ_256))
pitch = SZ_256;
- else if (IS_ALIGNED(len, 4))
+ else if (IS_ALIGNED(align_check, 4))
pitch = 4;
else
pitch = 1;
@@ -2242,16 +2243,11 @@ static struct dma_fence *xe_migrate_vram(struct xe_migrate *m,
struct xe_bb *bb;
u32 update_idx, pt_slot = 0;
unsigned long npages = DIV_ROUND_UP(len + sram_offset, PAGE_SIZE);
- unsigned int pitch = xe_migrate_copy_pitch(xe, len);
+ unsigned int pitch;
int err;
unsigned long i, j;
bool use_pde = xe_migrate_vram_use_pde(sram_addr, len + sram_offset);
- if (!xe->info.has_mem_copy_instr &&
- drm_WARN_ON(&xe->drm,
- (!IS_ALIGNED(len, pitch)) || (sram_offset | vram_addr) & XE_CACHELINE_MASK))
- return ERR_PTR(-EOPNOTSUPP);
-
xe_assert(xe, npages * PAGE_SIZE <= MAX_PREEMPTDISABLE_TRANSFER);
batch_size += pte_update_cmd_size(npages << PAGE_SHIFT);
@@ -2303,6 +2299,13 @@ static struct dma_fence *xe_migrate_vram(struct xe_migrate *m,
dst_L0_ofs = xe_migrate_vm_addr(pt_slot, 0) + sram_offset;
}
+ pitch = xe_migrate_copy_pitch(xe, len, dst_L0_ofs);
+ if (!xe->info.has_mem_copy_instr &&
+ drm_WARN_ON(&xe->drm,
+ (!IS_ALIGNED(len, pitch)) ||
+ (sram_offset | vram_addr) & XE_CACHELINE_MASK))
+ return ERR_PTR(-EOPNOTSUPP);
+
bb->cs[bb->len++] = MI_BATCH_BUFFER_END;
update_idx = bb->len;
@@ -2555,7 +2558,9 @@ int xe_migrate_access_memory(struct xe_migrate *m, struct xe_bo *bo,
else
current_bytes = min_t(int, bytes_left, cursor.size);
- pitch = xe_migrate_copy_pitch(xe, current_bytes);
+ pitch = xe_migrate_copy_pitch(xe, current_bytes,
+ write ? vram_addr :
+ (unsigned long)buf & ~PAGE_MASK);
if (xe->info.has_mem_copy_instr)
current_bytes = min_t(int, current_bytes, U16_MAX * pitch);
else
--
2.43.0
next prev parent reply other threads:[~2026-09-09 6:19 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 6:18 [PATCH v3 0/4] drm/xe/xe_migrate: Fix memory corruption with unaligned dst in MEM_COPY Jan Maslak
2026-09-09 6:18 ` Jan Maslak [this message]
2026-09-09 6:32 ` [PATCH v3 1/4] drm/xe/xe_migrate: Align MEM_COPY pitch with destination address sashiko-bot
2026-09-09 6:18 ` [PATCH v3 2/4] drm/xe/xe_migrate: Fix page tracking in access_memory Jan Maslak
2026-09-09 6:30 ` sashiko-bot
2026-09-09 6:18 ` [PATCH v3 3/4] drm/xe/xe_migrate: Optimize unaligned access_memory copies Jan Maslak
2026-09-09 6:31 ` sashiko-bot
2026-09-09 6:18 ` [PATCH v3 4/4] drm/xe/tests: Add xe_migrate_access_memory subtest Jan Maslak
2026-09-09 6:28 ` sashiko-bot
2026-09-09 6:25 ` ✗ CI.checkpatch: warning for drm/xe/xe_migrate: Fix memory corruption with unaligned dst in MEM_COPY (rev3) Patchwork
2026-09-09 6:27 ` ✓ CI.KUnit: success " Patchwork
2026-09-09 7:04 ` ✗ Xe.CI.BAT: failure " Patchwork
2026-09-09 11:36 ` ✗ Xe.CI.FULL: " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909061845.4048047-2-jan.maslak@intel.com \
--to=jan.maslak@intel.com \
--cc=christoph.manszewski@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=matthew.auld@intel.com \
--cc=matthew.brost@intel.com \
--cc=rodrigo.vivi@intel.com \
--cc=thomas.hellstrom@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.