* [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions
@ 2026-09-13 20:12 Risto Pajula
2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
0 siblings, 2 replies; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
To: Lyude Paul, Danilo Krummrich
Cc: nouveau, dri-devel, linux-kernel, Risto Pajula
Hi,
This series fixes two independent Nouveau regressions affecting VDPAU
hardware video decoding on NVIDIA GK107 (Kepler).
Patch 1 fixes engine context mappings for the legacy MSVLD, MSPDEC and
MSPPP video engines. Since commit 8ab849d6dd4c
("drm/nouveau/fifo: add new engine context handling"), privileged engine
context mappings cause FIFO PRIV_VIOLATION faults and kill the channel
during VDPAU decoding on GK107.
Patch 2 fixes a fence/progress hang introduced by commit 55e1a5996085
("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling").
Legacy FIFO implementations use a single global nonstall event at
index 0, while channel event registration was changed to use runl->id
unconditionally. This can leave fence completion waiting for an event
that is never signalled.
Tested on NVIDIA GK107 with a Linux 7.3-rc2 based drm-misc tree,
Mesa 25.0.7 and mpv using VDPAU_DRIVER=nouveau and vdpau-copy.
With both patches applied:
H.264 1920x1080: PASS
MPEG-2 1920x1080: PASS
VC-1 Advanced Profile: PASS
All three tests completed using VDPAU hardware decoding. No Nouveau
faults were reported in dmesg.
Thanks,
Risto
Risto Pajula (2):
drm/nouveau/fifo/gk104: fix legacy video engine context mappings
drm/nouveau/fifo: use global nonstall event on legacy FIFO
drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++
drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c | 3 ++-
2 files changed, 16 insertions(+), 1 deletion(-)
--
2.47.3
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings
2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
@ 2026-09-13 20:12 ` Risto Pajula
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
1 sibling, 0 replies; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
To: Lyude Paul, Danilo Krummrich
Cc: nouveau, dri-devel, linux-kernel, Risto Pajula
Commit 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling")
made gk104_ectx_ctor() map engine contexts privileged by default.
On GK107, mapping the legacy MSVLD, MSPDEC and MSPPP video engine
contexts privileged causes FIFO PRIV_VIOLATION faults and kills the
channel during VDPAU decoding.
These engines require non-privileged engine context mappings. Keep
privileged mappings for the other engines, but clear the privileged
flag for the legacy video engines.
Fixes: 8ab849d6dd4c ("drm/nouveau/fifo: add new engine context handling")
Assisted-by: LLM
Signed-off-by: Risto Pajula <or.pajula@gmail.com>
---
drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
index 5655eda52..bbeb33cd9 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/gk104.c
@@ -180,6 +180,20 @@ gk104_ectx_ctor(struct nvkm_engn *engn, struct nvkm_vctx *vctx)
struct gf100_vmm_map_v0 args = { .priv = 1 };
int ret;
+ /*
+ * Legacy video engines access their engine contexts through
+ * non-privileged MMU requests.
+ */
+ switch (engn->engine->subdev.type) {
+ case NVKM_ENGINE_MSPDEC:
+ case NVKM_ENGINE_MSPPP:
+ case NVKM_ENGINE_MSVLD:
+ args.priv = 0;
+ break;
+ default:
+ break;
+ }
+
ret = nvkm_vmm_get(vctx->vmm, 12, vctx->inst->size, &vctx->vma);
if (ret)
return ret;
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO
2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
@ 2026-09-13 20:12 ` Risto Pajula
2026-09-13 20:23 ` sashiko-bot
1 sibling, 1 reply; 4+ messages in thread
From: Risto Pajula @ 2026-09-13 20:12 UTC (permalink / raw)
To: Lyude Paul, Danilo Krummrich
Cc: nouveau, dri-devel, linux-kernel, Risto Pajula
The per-runlist nonstall interrupt handling change made channel
nonstall event registration use the runlist ID instead of the global
event index 0.
Legacy FIFO implementations do not provide a nonstall constructor.
They have a single global nonstall event, and their interrupt handlers
signal event index 0. Registering channel events using runl->id can
therefore leave fence completion waiting for an event that is never
signalled.
Use the runlist ID when per-runlist nonstall interrupts have been
constructed, and keep using event index 0 for legacy FIFO
implementations.
Fixes: 55e1a5996085 ("drm/nouveau/fifo/ga100-: add per-runlist nonstall intr handling")
Assisted-by: LLM
Signed-off-by: Risto Pajula <or.pajula@gmail.com>
---
drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
index d6a87cec2..b96e84192 100644
--- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
+++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
@@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_
switch (args->v0.type) {
case NVIF_CHAN_EVENT_V0_NON_STALL_INTR:
- return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id,
+ return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event,
+ runl->fifo->func->nonstall_ctor ? runl->id : 0,
NVKM_FIFO_NONSTALL_EVENT, NULL);
case NVIF_CHAN_EVENT_V0_KILLED:
return nvkm_uevent_add(uevent, &runl->chid->event, chan->id,
--
2.47.3
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
@ 2026-09-13 20:23 ` sashiko-bot
0 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-13 20:23 UTC (permalink / raw)
To: Risto Pajula; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [Critical] If channel initialization fails early in `nvkm_chan_new_()`, the cleanup path dereferences a NULL `chan->cgrp`.
--
commit 6a368e9f19db8e6f77b9767f67dd0d51b8625cd8
Author: Risto Pajula <or.pajula@gmail.com>
drm/nouveau/fifo: use global nonstall event on legacy FIFO
This commit changes the nonstall event registration to use the runlist ID
only when per-runlist nonstall interrupts are supported, falling back to
event index 0 for legacy FIFO implementations. This fixes an issue where
fence completion waits for an event that is never signalled.
> diff --git a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> index d6a87cec21503..b96e841920320 100644
> --- a/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> +++ b/drivers/gpu/drm/nouveau/nvkm/engine/fifo/uchan.c
> @@ -52,7 +52,8 @@ nvkm_uchan_uevent(struct nvkm_object *object, void *argv, u32 argc, struct nvkm_
>
> switch (args->v0.type) {
> case NVIF_CHAN_EVENT_V0_NON_STALL_INTR:
> - return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event, runl->id,
> + return nvkm_uevent_add(uevent, &runl->fifo->nonstall.event,
> + runl->fifo->func->nonstall_ctor ? runl->id : 0,
> NVKM_FIFO_NONSTALL_EVENT, NULL);
> case NVIF_CHAN_EVENT_V0_KILLED:
> return nvkm_uevent_add(uevent, &runl->chid->event, chan->id,
[Severity: Critical]
This is a pre-existing issue, but while reviewing the channel handling code, I
noticed a potential NULL pointer dereference if channel initialization fails
early.
In drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_new_():
ret = nvkm_cgrp_new(runl, chan->name, vmm, fifo->func->cgrp.force,
&chan->cgrp);
if (ret) {
RUNL_DEBUG(runl, "cgrp %d", ret);
return ret;
}
If nvkm_cgrp_new() fails, chan->cgrp remains NULL but the error is returned
to the caller while leaving the partially initialized channel allocated.
The cleanup path in nvkm_chan_del() unconditionally executes the RAMFC clear
callback on the partially initialized channel object:
drivers/gpu/drm/nouveau/nvkm/engine/fifo/chan.c:nvkm_chan_del() {
...
if (chan->func->ramfc->clear)
chan->func->ramfc->clear(chan);
...
}
For hardware-specific implementations like nv04_chan_ramfc_clear() in
drivers/gpu/drm/nouveau/nvkm/engine/fifo/nv04.c, this directly dereferences
chan->cgrp:
struct nvkm_memory *ramfc =
chan->cgrp->runl->fifo->engine.subdev.device->imem->ramfc;
Could this lead to a kernel panic when a userspace program invokes the
NVIF_IOCTL_NEW ioctl to create a new channel and nvkm_cgrp_new() fails? This
seems reachable if a user provides an invalid channel group or during memory
pressure.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260913201225.5975-1-or.pajula@gmail.com?part=2
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-13 20:54 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-13 20:12 [PATCH 0/2] drm/nouveau: fix GK107 VDPAU regressions Risto Pajula
2026-09-13 20:12 ` [PATCH 1/2] drm/nouveau/fifo/gk104: fix legacy video engine context mappings Risto Pajula
2026-09-13 20:12 ` [PATCH 2/2] drm/nouveau/fifo: use global nonstall event on legacy FIFO Risto Pajula
2026-09-13 20:23 ` sashiko-bot
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.