From: James Zhu <jamesz-5C7GfCeVMHo@public.gmane.org>
To: "Christian König" <christian.koenig-5C7GfCeVMHo@public.gmane.org>,
"James Zhu" <James.Zhu-5C7GfCeVMHo@public.gmane.org>,
amd-gfx-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org
Subject: Re: [PATCH] drm/amdgpu:Added support for MV packet
Date: Tue, 3 Apr 2018 10:52:31 -0400 [thread overview]
Message-ID: <024c3ae7-e36a-8700-5bbe-ef83de2f5b1d@amd.com> (raw)
In-Reply-To: <5138ab5e-8056-93f3-a635-bec2d17c8d5c-5C7GfCeVMHo@public.gmane.org>
Hi Christian,
Thanks for correction.
Since MV dump is not normal encoding, its size is HxW/8. So the 2nd
buffer size if 1/12 of the 1st one.
Thanks and Best Regards!
James Zhu
On 2018-04-03 05:11 AM, Christian König wrote:
> Am 02.04.2018 um 22:27 schrieb James Zhu:
>>
>>
>> On 2018-03-31 01:51 PM, Christian König wrote:
>>> Am 29.03.2018 um 23:02 schrieb James Zhu:
>>>> Motion vector packet needs support in physic mode.
>>>>
>>>> Signed-off-by: James Zhu <James.Zhu@amd.com>
>>>> ---
>>>> drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c | 24
>>>> ++++++++++++++++++++++++
>>>> 1 file changed, 24 insertions(+)
>>>>
>>>> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>>> b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>>> index 4dfa868..ef6b780 100644
>>>> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>>> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>>> @@ -767,6 +767,18 @@ int amdgpu_vce_ring_parse_cs(struct
>>>> amdgpu_cs_parser *p, uint32_t ib_idx)
>>>> if (r)
>>>> goto out;
>>>> break;
>>>> +
>>>> + case 0x0500000d: /* MV buffer */
>>>> + r = amdgpu_vce_validate_bo(p, ib_idx, idx + 3,
>>>> + idx + 2, 0, 0);
>>>> + if (r)
>>>> + goto out;
>>>> +
>>>> + r = amdgpu_vce_validate_bo(p, ib_idx, idx + 8,
>>>> + idx + 7, 0, 0);
>>>> + if (r)
>>>> + goto out;
>>>> + break;
>>>
>>> You need to specify a size here or otherwise userspace could
>>> allocate only a 4kb buffer and hope that VCE write over the end of
>>> the buffer.
>>>
>>> Since the MVs are easily controllable userspace can hope to hit and
>>> fill a page table with this. That would be a security hole you can
>>> push an elephant through, taking over the whole system with that is
>>> just a typing exercise.
>>>
>>> Regards,
>>> Christian.
>>>
>> Hi Christian,
>>
>> The first buffer is for input frame, I saw encode doesn't specify the
>> size.
>
> Good point, that makes this far less problematic, but I still think
> correct size handling would be nice to have.
>
> Take a look at the second pass for the encode command, size handling
> is there:
>> case 0x03000001: /* encode */
>> r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 10,
>> idx + 9,
>> *size, 0);
>> if (r)
>> goto out;
>
> If I'm not completely mistake you just need to specify "*size" and
> "*size / 3" as parameters for your call to amdgpu_vce_cs_reloc as well.
>
>> The 2nd buffer is for mv dump buffer, the size should be fixed with
>> ALIGN(enc.width, 16) * ALIGN(enc.height, 16) / 8 which is less than
>> 4k. Since IB doesn't pass down this value. how to specify the size
>> for this case?
>
> Why do you think that ALIGN(enc.width, 16) * ALIGN(enc.height, 16) / 8
> is less than 4k? If I do the math correctly for a 1920x1088 input
> picture that should be around 255k.
>
> *size should be size of the input picture in bytes (luma+chroma), so
> something like "*ALIGN(size * 3 / 2 / 8, 256) / 8" should do it.
>
> Regards,
> Christian.
>
>>
>> Best Regards!
>> James Zhu
>>>> }
>>>> idx += len / 4;
>>>> @@ -884,6 +896,18 @@ int amdgpu_vce_ring_parse_cs(struct
>>>> amdgpu_cs_parser *p, uint32_t ib_idx)
>>>> goto out;
>>>> break;
>>>> + case 0x0500000d: /* MV buffer */
>>>> + r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 3,
>>>> + idx + 2, 0, 0);
>>>> + if (r)
>>>> + goto out;
>>>> +
>>>> + r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 8,
>>>> + idx + 7, 0, 0);
>>>> + if (r)
>>>> + goto out;
>>>> + break;
>>>> +
>>>> default:
>>>> DRM_ERROR("invalid VCE command (0x%x)!\n", cmd);
>>>> r = -EINVAL;
>>>
>>
>
_______________________________________________
amd-gfx mailing list
amd-gfx@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/amd-gfx
next prev parent reply other threads:[~2018-04-03 14:52 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-03-29 21:02 [PATCH] drm/amdgpu:Added support for MV packet James Zhu
[not found] ` <1522357350-7872-1-git-send-email-James.Zhu-5C7GfCeVMHo@public.gmane.org>
2018-03-31 17:51 ` Christian König
[not found] ` <de5a8e06-1549-2647-932a-f64a4a96b3c3-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2018-04-02 20:27 ` James Zhu
[not found] ` <ebbfe0e7-6930-c142-5ea6-13fcc7caba17-5C7GfCeVMHo@public.gmane.org>
2018-04-03 9:11 ` Christian König
[not found] ` <5138ab5e-8056-93f3-a635-bec2d17c8d5c-5C7GfCeVMHo@public.gmane.org>
2018-04-03 14:52 ` James Zhu [this message]
2018-04-03 14:49 ` [PATCH v2] " James Zhu
[not found] ` <1522766956-22431-1-git-send-email-James.Zhu-5C7GfCeVMHo@public.gmane.org>
2018-04-04 9:12 ` Christian König
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=024c3ae7-e36a-8700-5bbe-ef83de2f5b1d@amd.com \
--to=jamesz-5c7gfcevmho@public.gmane.org \
--cc=James.Zhu-5C7GfCeVMHo@public.gmane.org \
--cc=amd-gfx-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org \
--cc=christian.koenig-5C7GfCeVMHo@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox