All of lore.kernel.org
 help / color / mirror / Atom feed
From: Matthew Brost <matthew.brost@intel.com>
To: <sashiko-reviews@lists.linux.dev>
Cc: <intel-xe@lists.freedesktop.org>
Subject: Re: [PATCH v4 17/25] drm/xe: Add device flag to enable PT mirroring across tiles
Date: Thu, 3 Sep 2026 18:33:56 -0700	[thread overview]
Message-ID: <apogBNby1891GbhR@gsse-cloud1.jf.intel.com> (raw)
In-Reply-To: <20260904002953.B10C41F000E9@smtp.kernel.org>

On Fri, Sep 04, 2026 at 12:29:53AM +0000, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
> - [High] Incorrect tile mask generation causes missing TLB invalidations on secondary tiles
> - [High] Shallow copy of Page Reclaim List (PRL) leads to Double Free during TLB invalidation
> - [Medium] Unnecessary allocation of unused page table roots and scratch tables
> --
> 
> commit 084f96016724c31d7bcd97e7c49979198c29fe71
> Author: Matthew Brost <matthew.brost@intel.com>
> Subject: drm/xe: Add device flag to enable PT mirroring across tiles
> 
> Some multi-tile devices may want to mirror page tables across tiles for
> memory-bandwidth reasons, while others may not. Add a device flag that
> allows enabling or disabling page-table mirroring across tiles.
> 
> Link: https://patch.msgid.link/20260228013501.106680-18-matthew.brost@intel.com
> 
> > diff --git a/drivers/gpu/drm/xe/xe_pt.c b/drivers/gpu/drm/xe/xe_pt.c
> > index 821edeaecaed9..deb33e85e6eb7 100644
> > --- a/drivers/gpu/drm/xe/xe_pt.c
> > +++ b/drivers/gpu/drm/xe/xe_pt.c
> [ ... ]
> > @@ -2542,9 +2553,20 @@ int xe_pt_update_ops_prepare(struct xe_device *xe, struct xe_vma_ops *vops)
> >  	int id, err;
> >  
> >  	for_each_tile(tile, xe, id) {
> > +		struct xe_vm_pgtable_update_ops *pt_update_ops =
> > +			&vops->pt_update_ops[id];
> > +
> >  		if (!vops->pt_update_ops[id].num_ops)
> >  			continue;
> >  
> > +		if (pt_mirroring_disabled_for_tile(vops->vm, id)) {
> > +			struct xe_page_reclaim_list *prl = &pt_update_ops->prl;
> > +
> > +			/* Transfer root PT update ops PRL to current */
> > +			*prl = vops->pt_update_ops[0].prl;
> 
> [Severity: High]
> Does this shallow copy of the Page Reclaim List (PRL) cause a double free?
> 
> By copying the structure directly without incrementing a reference count,
> multiple tiles now hold a pointer to the same page. Later, when
> xe_tlb_inval_job_create() adds this to jobs in xe_pt_update_ops_run(), both
> jobs take ownership. When the jobs finish, they will both call
> xe_page_reclaim_entries_put(), freeing the same page twice.
> 

This is correct. Will fix.

> > +			continue;
> > +		}
> > +
> >  		err = __xe_pt_update_ops_prepare(tile, vops);
> >  		if (err)
> >  			return err;
> [ ... ]
> > diff --git a/drivers/gpu/drm/xe/xe_vm.c b/drivers/gpu/drm/xe/xe_vm.c
> > index 33ef4ccc3550b..d9a9c0844c5e3 100644
> > --- a/drivers/gpu/drm/xe/xe_vm.c
> > +++ b/drivers/gpu/drm/xe/xe_vm.c
> > @@ -844,6 +844,14 @@ int xe_vm_rebind(struct xe_vm *vm, bool rebind_worker)
> >  	return err;
> >  }
> >  
> > +static u8 adjust_rebind_tile_mask(struct xe_vm *vm, u8 tile_mask)
> > +{
> > +	if (vm->xe->info.has_pt_mirror)
> > +		return tile_mask;
> > +
> > +	return (0x1 << vm->xe->info.max_gt_per_tile) - 1;
> 
> [Severity: High]
> Is max_gt_per_tile being used here incorrectly instead of the total tile count?
> 
> If a device (like PVC) has 1 GT per tile, this evaluates to 1, causing the
> generated mask to omit secondary tiles. During xe_vma_rebind(), the num_ops
> will only be incremented for tile 0.
> 
> Consequently, xe_pt_update_ops_prepare() skips preparation for the secondary
> tiles, leaving their start and last variables uninitialized (zeroed). When
> TLB invalidation jobs are created later, they use a range of [0, 0] for
> these tiles, leaving stale TLB entries that could cause memory corruption.
> 

This is correct. Will fix.

> > +}
> > +
> >  struct dma_fence *xe_vma_rebind(struct xe_vm *vm, struct xe_vma *vma, u8 tile_mask)
> >  {
> >  	struct dma_fence *fence = NULL;
> [ ... ]
> > @@ -1737,7 +1747,8 @@ struct xe_vm *xe_vm_create(struct xe_device *xe, u32 flags, struct xe_file *xef)
> >  
> >  		for_each_tile(tile, xe, id) {
> >  			if (flags & XE_VM_FLAG_MIGRATION &&
> > -			    tile->id != XE_VM_FLAG_TILE_ID(flags))
> > +			    tile->id != XE_VM_FLAG_TILE_ID(flags) &&
> > +			    (vm->xe->info.has_pt_mirror || id))
> >  				continue;
> >  
> >  			vm->pt_root[id] = xe_pt_create(vm, tile, xe->info.vm_max_level,
> >  						       &exec);
> 
> [Severity: Medium]
> For standard user VMs, does this unconditionally allocate page table roots
> and scratch tables for secondary tiles even when PT mirroring is disabled?
> 
> When has_pt_mirror is false, xe_vm_pt_root() is hardcoded to return
> vm->pt_root[0]. As a result, the allocations made here for id > 0 (and their
> associated scratch tables) are never used, wasting VRAM.
> 

Techincally, but I'm not going to worry about 4k vs functionality
required for the migrate layer.

Matt 

> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20260903235842.3401722-1-matthew.brost@intel.com?part=17

  reply	other threads:[~2026-09-04  1:34 UTC|newest]

Thread overview: 48+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03 23:58 [PATCH v4 00/25] CPU binds and ULLS on migration queue Matthew Brost
2026-09-03 23:58 ` [PATCH v4 01/25] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-03 23:58 ` [PATCH v4 02/25] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-04  0:15   ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 03/25] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-03 23:58 ` [PATCH v4 04/25] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-03 23:58 ` [PATCH v4 05/25] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-03 23:58 ` [PATCH v4 06/25] drm/xe: Add XE_BO_FLAG_PUT_VM_ASYNC Matthew Brost
2026-09-04  0:18   ` sashiko-bot
2026-09-04  0:41     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 07/25] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-04  0:25   ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 08/25] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 09/25] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 10/25] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-04  0:36   ` sashiko-bot
2026-09-04  0:57     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 11/25] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-04  0:19   ` sashiko-bot
2026-09-03 23:58 ` [PATCH v4 12/25] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-03 23:58 ` [PATCH v4 13/25] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-04  0:31   ` sashiko-bot
2026-09-04  1:04     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 14/25] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 15/25] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-03 23:58 ` [PATCH v4 16/25] drm/xe: Add CPU bind layer Matthew Brost
2026-09-04  0:31   ` sashiko-bot
2026-09-04  1:18     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 17/25] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-04  0:29   ` sashiko-bot
2026-09-04  1:33     ` Matthew Brost [this message]
2026-09-03 23:58 ` [PATCH v4 18/25] drm/xe: Add xe_hw_engine_write_ring_tail Matthew Brost
2026-09-03 23:58 ` [PATCH v4 19/25] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-03 23:58 ` [PATCH v4 20/25] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-04  0:27   ` sashiko-bot
2026-09-04  1:35     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 21/25] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-03 23:58 ` [PATCH v4 22/25] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-04  0:38   ` sashiko-bot
2026-09-04  1:41     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 23/25] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-04  0:28   ` sashiko-bot
2026-09-04  1:32     ` Matthew Brost
2026-09-03 23:58 ` [PATCH v4 24/25] drm/xe: Add modparam to enable / disable ULLS on migrate queue Matthew Brost
2026-09-03 23:58 ` [PATCH v4 25/25] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-04  0:47 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev6) Patchwork
2026-09-04  0:49 ` ✓ CI.KUnit: success " Patchwork
2026-09-04  1:33 ` ✓ Xe.CI.BAT: " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=apogBNby1891GbhR@gsse-cloud1.jf.intel.com \
    --to=matthew.brost@intel.com \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.