All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions
@ 2026-09-13 20:12 Risto Pajula
  2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
  2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
  0 siblings, 2 replies; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
  To: Lyude Paul, Danilo Krummrich
  Cc: nouveau, dri-devel, linux-kernel, Risto Pajula

Hi,

This series fixes two independent Nouveau regressions affecting VDPAU
hardware video decoding on NVIDIA GK107 (Kepler).

Patch 1 fixes engine context mappings for the legacy MSVLD, MSPDEC and
MSPPP video engines. Since commit 8ab849d6dd4c
("drm/nouveau/fifo: add new engine context handling"), privileged engine
context mappings cause FIFO PRIV_VIOLATION faults and kill the channel
during VDPAU decoding on GK107.

Patch 2 fixes a fence/progress hang introduced by commit 55e1a5996085
("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling").
Legacy FIFO implementations use a single global nonstall event at
index 0, while channel event registration was changed to use runl->id
unconditionally. This can leave fence completion waiting for an event
that is never signalled.


Tested on NVIDIA GK107 with a Linux 7.3-rc2 based drm-misc tree,
Mesa 25.0.7 and mpv using VDPAU_DRIVER=nouveau and vdpau-copy.

With both patches applied:

  H.264 1920x1080:        PASS
  MPEG-2 1920x1080:      PASS
  VC-1 Advanced Profile: PASS

All three tests completed using VDPAU hardware decoding. No Nouveau
faults were reported in dmesg.


Thanks,
Risto

Risto Pajula (2):
  drm/nouveau/fifo/gk104: fix legacy video engine context mappings
  drm/nouveau/fifo: use global nonstall event on legacy FIFO

 drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++
 drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c |  3 ++-
 2 files changed, 16 insertions(+), 1 deletion(-)

-- 
2.47.3


^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings
  2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
@ 2026-09-13 20:12 ` Risto Pajula
  2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
  1 sibling, 0 replies; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
  To: Lyude Paul, Danilo Krummrich
  Cc: nouveau, dri-devel, linux-kernel, Risto Pajula

Commit 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling")
made gk104_ectx_ctor() map engine contexts privileged by default.

On GK107, mapping the legacy MSVLD, MSPDEC and MSPPP video engine
contexts privileged causes FIFO PRIV_VIOLATION faults and kills the
channel during VDPAU decoding.

These engines require non-privileged engine context mappings. Keep
privileged mappings for the other engines, but clear the privileged
flag for the legacy video engines.

Fixes: 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling")
Assisted-by: LLM
Signed-off-by: Risto Pajula <or.pajula@gmail.com>
---
 drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++
 1 file changed, 14 insertions(+)

diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
index 5655eda52..bbeb33cd9 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
@@ -180,6 +180,20 @@ gk104_ectx_ctor(struct nvkm_engn *engn, struct nvkm_vctx *vctx)
 	struct gf100_vmm_map_v0 args = { .priv = 1 };
 	int ret;
 
+	/*
+	 * Legacy video engines access their engine contexts through
+	 * non-privileged MMU requests.
+	 */
+	switch (engn->engine->subdev.type) {
+	case NVKM_ENGINE_MSPDEC:
+	case NVKM_ENGINE_MSPPP:
+	case NVKM_ENGINE_MSVLD:
+		args.priv = 0;
+		break;
+	default:
+		break;
+	}
+
 	ret = nvkm_vmm_get(vctx->vmm, 12, vctx->inst->size, &vctx->vma);
 	if (ret)
 		return ret;
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO
  2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
  2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
@ 2026-09-13 20:12 ` Risto Pajula
  2026-09-13 20:23   ` sashiko-bot
  1 sibling, 1 reply; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
  To: Lyude Paul, Danilo Krummrich
  Cc: nouveau, dri-devel, linux-kernel, Risto Pajula

The per-runlist nonstall interrupt handling change made channel
nonstall event registration use the runlist ID instead of the global
event index 0.

Legacy FIFO implementations do not provide a nonstall constructor.
They have a single global nonstall event, and their interrupt handlers
signal event index 0. Registering channel events using runl->id can
therefore leave fence completion waiting for an event that is never
signalled.

Use the runlist ID when per-runlist nonstall interrupts have been
constructed, and keep using event index 0 for legacy FIFO
implementations.

Fixes: 55e1a5996085 ("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling")
Assisted-by: LLM
Signed-off-by: Risto Pajula <or.pajula@gmail.com>
---
 drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
index d6a87cec2..b96e84192 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
@@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_
 
 	switch (args->v0.type) {
 	case NVIF_CHAN_EVENT_V0_NON_STALL_INTR:
-		return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id,
+		return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event,
+				runl->fifo->func->nonstall_ctor ? runl->id : 0,
 				       NVKM_FIFO_NONSTALL_EVENT, NULL);
 	case NVIF_CHAN_EVENT_V0_KILLED:
 		return nvkm_uevent_add(uevent, &runl->chid->event, chan->id,
-- 
2.47.3


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO
  2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
@ 2026-09-13 20:23   ` sashiko-bot
  0 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-13 20:23 UTC (permalink / raw)
  To: Risto Pajula; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [Critical] If channel initialization fails early in `nvkm_chan_new_()`, the cleanup path dereferences a NULL `chan->cgrp`.
--

commit 6a368e9f19db8e6f77b9767f67dd0d51b8625cd8
Author: Risto Pajula <or.pajula@gmail.com>

drm/nouveau/fifo: use global nonstall event on legacy FIFO

This commit changes the nonstall event registration to use the runlist ID
only when per-runlist nonstall interrupts are supported, falling back to
event index 0 for legacy FIFO implementations. This fixes an issue where
fence completion waits for an event that is never signalled.

> diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> index d6a87cec21503..b96e841920320 100644
> --- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> +++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> @@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_
>  
>  	switch (args->v0.type) {
>  	case NVIF_CHAN_EVENT_V0_NON_STALL_INTR:
> -		return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id,
> +		return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event,
> +				runl->fifo->func->nonstall_ctor ? runl->id : 0,
>  				       NVKM_FIFO_NONSTALL_EVENT, NULL);
>  	case NVIF_CHAN_EVENT_V0_KILLED:
>  		return nvkm_uevent_add(uevent, &runl->chid->event, chan->id,

[Severity: Critical]
This is a pre-existing issue, but while reviewing the channel handling code, I
noticed a potential NULL pointer dereference if channel initialization fails
early.

In drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_new_():

    ret = nvkm_cgrp_new(runl, chan->name, vmm, fifo->func->cgrp.force,
                        &chan->cgrp);
    if (ret) {
        RUNL_DEBUG(runl, "cgrp %d", ret);
        return ret;
    }

If nvkm_cgrp_new() fails, chan->cgrp remains NULL but the error is returned
to the caller while leaving the partially initialized channel allocated.

The cleanup path in nvkm_chan_del() unconditionally executes the RAMFC clear
callback on the partially initialized channel object:

drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_del() {
    ...
    if (chan->func->ramfc->clear)
        chan->func->ramfc->clear(chan);
    ...
}

For hardware-specific implementations like nv04_chan_ramfc_clear() in
drivers/gpu/drm/nouveau/nvkm/engine/fifo/nv04.c, this directly dereferences
chan->cgrp:

    struct nvkm_memory *ramfc =
        chan->cgrp->runl->fifo->engine.subdev.device->imem->ramfc;

Could this lead to a kernel panic when a userspace program invokes the
NVIF_IOCTL_NEW ioctl to create a new channel and nvkm_cgrp_new() fails? This
seems reachable if a user provides an invalid channel group or during memory
pressure.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260913201225.5975-1-or.pajula@gmail.com?part=2

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-13 20:54 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
2026-09-13 20:23   ` sashiko-bot

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.