* [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions
@ 2026-09-13 20:12 Risto Pajula
2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
0 siblings, 2 replies; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
To: Lyude Paul, Danilo Krummrich
Cc: nouveau, dri-devel, linux-kernel, Risto Pajula
Hi,
This series fixes two independent Nouveau regressions affecting VDPAU
hardware video decoding on NVIDIA GK107 (Kepler).
Patch 1 fixes engine context mappings for the legacy MSVLD, MSPDEC and
MSPPP video engines. Since commit 8ab849d6dd4c
("drm/nouveau/fifo: add new engine context handling"), privileged engine
context mappings cause FIFO PRIV_VIOLATION faults and kill the channel
during VDPAU decoding on GK107.
Patch 2 fixes a fence/progress hang introduced by commit 55e1a5996085
("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling").
Legacy FIFO implementations use a single global nonstall event at
index 0, while channel event registration was changed to use runl->id
unconditionally. This can leave fence completion waiting for an event
that is never signalled.
Tested on NVIDIA GK107 with a Linux 7.3-rc2 based drm-misc tree,
Mesa 25.0.7 and mpv using VDPAU_DRIVER=nouveau and vdpau-copy.
With both patches applied:
H.264 1920x1080: PASS
MPEG-2 1920x1080: PASS
VC-1 Advanced Profile: PASS
All three tests completed using VDPAU hardware decoding. No Nouveau
faults were reported in dmesg.
Thanks,
Risto
Risto Pajula (2):
drm/nouveau/fifo/gk104: fix legacy video engine context mappings
drm/nouveau/fifo: use global nonstall event on legacy FIFO
drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++
drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c | 3 ++-
2 files changed, 16 insertions(+), 1 deletion(-)
--
2.47.3
^ permalink raw reply [flat|nested] 4+ messages in thread* [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings 2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula @ 2026-09-13 20:12 ` Risto Pajula 2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula 1 sibling, 0 replies; 4+ messages in thread From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw) To: Lyude Paul, Danilo Krummrich Cc: nouveau, dri-devel, linux-kernel, Risto Pajula Commit 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling") made gk104_ectx_ctor() map engine contexts privileged by default. On GK107, mapping the legacy MSVLD, MSPDEC and MSPPP video engine contexts privileged causes FIFO PRIV_VIOLATION faults and kills the channel during VDPAU decoding. These engines require non-privileged engine context mappings. Keep privileged mappings for the other engines, but clear the privileged flag for the legacy video engines. Fixes: 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling") Assisted-by: LLM Signed-off-by: Risto Pajula <or.pajula@gmail.com> --- drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c index 5655eda52..bbeb33cd9 100644 --- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c +++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c @@ -180,6 +180,20 @@ gk104_ectx_ctor(struct nvkm_engn *engn, struct nvkm_vctx *vctx) struct gf100_vmm_map_v0 args = { .priv = 1 }; int ret; + /* + * Legacy video engines access their engine contexts through + * non-privileged MMU requests. + */ + switch (engn->engine->subdev.type) { + case NVKM_ENGINE_MSPDEC: + case NVKM_ENGINE_MSPPP: + case NVKM_ENGINE_MSVLD: + args.priv = 0; + break; + default: + break; + } + ret = nvkm_vmm_get(vctx->vmm, 12, vctx->inst->size, &vctx->vma); if (ret) return ret; -- 2.47.3 ^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO 2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula 2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula @ 2026-09-13 20:12 ` Risto Pajula 2026-09-13 20:23 ` sashiko-bot 1 sibling, 1 reply; 4+ messages in thread From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw) To: Lyude Paul, Danilo Krummrich Cc: nouveau, dri-devel, linux-kernel, Risto Pajula The per-runlist nonstall interrupt handling change made channel nonstall event registration use the runlist ID instead of the global event index 0. Legacy FIFO implementations do not provide a nonstall constructor. They have a single global nonstall event, and their interrupt handlers signal event index 0. Registering channel events using runl->id can therefore leave fence completion waiting for an event that is never signalled. Use the runlist ID when per-runlist nonstall interrupts have been constructed, and keep using event index 0 for legacy FIFO implementations. Fixes: 55e1a5996085 ("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling") Assisted-by: LLM Signed-off-by: Risto Pajula <or.pajula@gmail.com> --- drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c index d6a87cec2..b96e84192 100644 --- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c +++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c @@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_ switch (args->v0.type) { case NVIF_CHAN_EVENT_V0_NON_STALL_INTR: - return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id, + return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, + runl->fifo->func->nonstall_ctor ? runl->id : 0, NVKM_FIFO_NONSTALL_EVENT, NULL); case NVIF_CHAN_EVENT_V0_KILLED: return nvkm_uevent_add(uevent, &runl->chid->event, chan->id, -- 2.47.3 ^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO 2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula @ 2026-09-13 20:23 ` sashiko-bot 0 siblings, 0 replies; 4+ messages in thread From: sashiko-bot @ 2026-09-13 20:23 UTC (permalink / raw) To: Risto Pajula; +Cc: dri-devel Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: Pre-existing issues: - [Critical] If channel initialization fails early in `nvkm_chan_new_()`, the cleanup path dereferences a NULL `chan->cgrp`. -- commit 6a368e9f19db8e6f77b9767f67dd0d51b8625cd8 Author: Risto Pajula <or.pajula@gmail.com> drm/nouveau/fifo: use global nonstall event on legacy FIFO This commit changes the nonstall event registration to use the runlist ID only when per-runlist nonstall interrupts are supported, falling back to event index 0 for legacy FIFO implementations. This fixes an issue where fence completion waits for an event that is never signalled. > diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c > index d6a87cec21503..b96e841920320 100644 > --- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c > +++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c > @@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_ > > switch (args->v0.type) { > case NVIF_CHAN_EVENT_V0_NON_STALL_INTR: > - return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id, > + return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, > + runl->fifo->func->nonstall_ctor ? runl->id : 0, > NVKM_FIFO_NONSTALL_EVENT, NULL); > case NVIF_CHAN_EVENT_V0_KILLED: > return nvkm_uevent_add(uevent, &runl->chid->event, chan->id, [Severity: Critical] This is a pre-existing issue, but while reviewing the channel handling code, I noticed a potential NULL pointer dereference if channel initialization fails early. In drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_new_(): ret = nvkm_cgrp_new(runl, chan->name, vmm, fifo->func->cgrp.force, &chan->cgrp); if (ret) { RUNL_DEBUG(runl, "cgrp %d", ret); return ret; } If nvkm_cgrp_new() fails, chan->cgrp remains NULL but the error is returned to the caller while leaving the partially initialized channel allocated. The cleanup path in nvkm_chan_del() unconditionally executes the RAMFC clear callback on the partially initialized channel object: drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_del() { ... if (chan->func->ramfc->clear) chan->func->ramfc->clear(chan); ... } For hardware-specific implementations like nv04_chan_ramfc_clear() in drivers/gpu/drm/nouveau/nvkm/engine/fifo/nv04.c, this directly dereferences chan->cgrp: struct nvkm_memory *ramfc = chan->cgrp->runl->fifo->engine.subdev.device->imem->ramfc; Could this lead to a kernel panic when a userspace program invokes the NVIF_IOCTL_NEW ioctl to create a new channel and nvkm_cgrp_new() fails? This seems reachable if a user provides an invalid channel group or during memory pressure. -- Sashiko AI review · https://sashiko.dev/#/patchset/20260913201225.5975-1-or.pajula@gmail.com?part=2 ^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-13 20:54 UTC | newest] Thread overview: 4+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula 2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula 2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula 2026-09-13 20:23 ` sashiko-bot
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.