From: Jianfeng Liu <liujianfeng1994@gmail.com>
To: dri-devel@lists.freedesktop.org, linux-media@vger.kernel.org,
linux-kernel@vger.kernel.org
Cc: linux-arm-msm@vger.kernel.org,
"Jessica Zhang" <jesszhan0024@gmail.com>,
"Sumit Semwal" <sumit.semwal@linaro.org>,
linaro-mm-sig@lists.linaro.org,
"Christian König" <christian.koenig@amd.com>,
"Rob Clark" <robin.clark@oss.qualcomm.com>,
"Sean Paul" <sean@poorly.run>, "Simona Vetter" <simona@ffwll.ch>,
freedreno@lists.freedesktop.org,
"Marijn Suijten" <marijn.suijten@somainline.org>,
"David Airlie" <airlied@gmail.com>,
"Dmitry Baryshkov" <lumag@kernel.org>,
"Abhinav Kumar" <abhinav.kumar@linux.dev>,
"Jianfeng Liu" <liujianfeng1994@gmail.com>,
"Karl Mehltretter" <kmehltretter@gmail.com>
Subject: [RFC PATCH v1 0/2] Fix the v7.3-rc4 DMABUF_DEBUG regression breaking drm/msm hardware video decode
Date: Wed, 23 Sep 2026 15:42:21 +0800 [thread overview]
Message-ID: <20260923074256.9357-1-liujianfeng1994@gmail.com> (raw)
Hardware video decode in clapper and chromium (V4L2 decoder output
buffers imported into drm/msm for rendering and scanout) breaks on
v7.3-rc4 with arm-smmu translation faults:
gpu fault: ttbr0=000000088a889000 iova=000000010741c000 dir=READ
type=TRANSLATION source=UCHE
v7.3-rc3 works fine. Bisecting between the two points at
143755bdabaa9 ("dma-buf: Make DMABUF_DEBUG default to y on
DEBUG_KERNEL kernels"), which fixed a dangling reference in the
DMABUF_DEBUG default and thereby silently enabled the option - and
with it the page-stripping sg_table wrapper that
dma_buf_map_attachment() hands to importers - on every kernel with
DEBUG_KERNEL=y, i.e. virtually every distro kernel.
drm/msm is affected in two places. It fills the page array of
imported GEM objects through the deprecated
drm_prime_sg_to_page_array(), and it maps the attachment sg_table
into the GPU's own pagetables with iommu_map_sgtable(). Both need
the struct page of the sg_table, which the debug wrapper removes
(and it zeroes sg->length, so the page iterator yields nothing while
the uninitialized page array is kept, with the helper still
returning success).
When such an import is used for rendering, the VM_BIND map job then
fails asynchronously after userspace has already enqueued GPU work
referencing the mapping, which surfaces as the UCHE translation
fault above instead of a clean error.
Patch 1 restores the DMABUF_DEBUG default to n until msm can be
converted to build its GPU mappings from the attachment's DMA
addresses. Patch 2 replaces the deprecated helper in msm with an
explicit loop that rejects page-less sg_tables at import time, so
userspace gets a clean -EINVAL and can fall back instead of
crashing the GPU.
Tested on a Snapdragon laptop with an Adreno GPU and arm-smmu
(v7.3-rc4):
- DMABUF_DEBUG off: hardware video decode works as on v7.3-rc3
- DMABUF_DEBUG on, without patch 2: GPU faults as above
- DMABUF_DEBUG on, with patch 2: imports are rejected cleanly
("import of dmabuf from 'videobuf2_dma_contig' rejected: sg_table
has no/misaligned struct page info"), no GPU faults. clapper falls
back to a working display path; chromium shows a black window as
it has no fallback for a failed zero-copy import.
A full fix for DMABUF_DEBUG=y requires msm to map imported buffers
from their DMA addresses rather than struct pages; that conversion
is left as future work.
Comments welcome.
Jianfeng Liu (2):
dma-buf: keep DMABUF_DEBUG off by default
drm/msm: reject dma-buf imports without struct page info
drivers/dma-buf/Kconfig | 9 ++++++++-
drivers/gpu/drm/msm/msm_gem.c | 31 ++++++++++++++++++++++++++++---
2 files changed, 36 insertions(+), 4 deletions(-)
---
base-commit: 93f51579e7df248780214094418f205253383cc5
branch: fix/dmabuf-debug-msm-import
--
2.47.3
next reply other threads:[~2026-09-23 7:43 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-23 7:42 Jianfeng Liu [this message]
2026-09-23 7:42 ` [RFC PATCH v1 1/2] dma-buf: keep DMABUF_DEBUG off by default Jianfeng Liu
2026-09-23 8:03 ` Christian König
2026-09-24 14:01 ` Rob Clark
2026-09-24 14:54 ` Jianfeng Liu
2026-09-24 15:23 ` Rob Clark
2026-09-25 17:18 ` Rob Clark
2026-09-24 10:28 ` Bryan O'Donoghue
2026-09-23 7:42 ` [RFC PATCH v1 2/2] drm/msm: reject dma-buf imports without struct page info Jianfeng Liu
2026-09-24 10:36 ` Bryan O'Donoghue
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923074256.9357-1-liujianfeng1994@gmail.com \
--to=liujianfeng1994@gmail.com \
--cc=abhinav.kumar@linux.dev \
--cc=airlied@gmail.com \
--cc=christian.koenig@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=freedreno@lists.freedesktop.org \
--cc=jesszhan0024@gmail.com \
--cc=kmehltretter@gmail.com \
--cc=linaro-mm-sig@lists.linaro.org \
--cc=linux-arm-msm@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=lumag@kernel.org \
--cc=marijn.suijten@somainline.org \
--cc=robin.clark@oss.qualcomm.com \
--cc=sean@poorly.run \
--cc=simona@ffwll.ch \
--cc=sumit.semwal@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.