From: "Christian König" <christian.koenig-5C7GfCeVMHo@public.gmane.org>
To: James Zhu <jamesz-5C7GfCeVMHo@public.gmane.org>,
James Zhu <James.Zhu-5C7GfCeVMHo@public.gmane.org>,
amd-gfx-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org
Subject: Re: [PATCH] drm/amdgpu:Added support for MV packet
Date: Tue, 3 Apr 2018 11:11:08 +0200 [thread overview]
Message-ID: <5138ab5e-8056-93f3-a635-bec2d17c8d5c@amd.com> (raw)
In-Reply-To: <ebbfe0e7-6930-c142-5ea6-13fcc7caba17-5C7GfCeVMHo@public.gmane.org>
Am 02.04.2018 um 22:27 schrieb James Zhu:
>
>
> On 2018-03-31 01:51 PM, Christian König wrote:
>> Am 29.03.2018 um 23:02 schrieb James Zhu:
>>> Motion vector packet needs support in physic mode.
>>>
>>> Signed-off-by: James Zhu <James.Zhu@amd.com>
>>> ---
>>> drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c | 24 ++++++++++++++++++++++++
>>> 1 file changed, 24 insertions(+)
>>>
>>> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>> b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>> index 4dfa868..ef6b780 100644
>>> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vce.c
>>> @@ -767,6 +767,18 @@ int amdgpu_vce_ring_parse_cs(struct
>>> amdgpu_cs_parser *p, uint32_t ib_idx)
>>> if (r)
>>> goto out;
>>> break;
>>> +
>>> + case 0x0500000d: /* MV buffer */
>>> + r = amdgpu_vce_validate_bo(p, ib_idx, idx + 3,
>>> + idx + 2, 0, 0);
>>> + if (r)
>>> + goto out;
>>> +
>>> + r = amdgpu_vce_validate_bo(p, ib_idx, idx + 8,
>>> + idx + 7, 0, 0);
>>> + if (r)
>>> + goto out;
>>> + break;
>>
>> You need to specify a size here or otherwise userspace could allocate
>> only a 4kb buffer and hope that VCE write over the end of the buffer.
>>
>> Since the MVs are easily controllable userspace can hope to hit and
>> fill a page table with this. That would be a security hole you can
>> push an elephant through, taking over the whole system with that is
>> just a typing exercise.
>>
>> Regards,
>> Christian.
>>
> Hi Christian,
>
> The first buffer is for input frame, I saw encode doesn't specify the
> size.
Good point, that makes this far less problematic, but I still think
correct size handling would be nice to have.
Take a look at the second pass for the encode command, size handling is
there:
> case 0x03000001: /* encode */
> r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 10,
> idx + 9,
> *size, 0);
> if (r)
> goto out;
If I'm not completely mistake you just need to specify "*size" and
"*size / 3" as parameters for your call to amdgpu_vce_cs_reloc as well.
> The 2nd buffer is for mv dump buffer, the size should be fixed with
> ALIGN(enc.width, 16) * ALIGN(enc.height, 16) / 8 which is less than
> 4k. Since IB doesn't pass down this value. how to specify the size for
> this case?
Why do you think that ALIGN(enc.width, 16) * ALIGN(enc.height, 16) / 8
is less than 4k? If I do the math correctly for a 1920x1088 input
picture that should be around 255k.
*size should be size of the input picture in bytes (luma+chroma), so
something like "*ALIGN(size * 3 / 2 / 8, 256) / 8" should do it.
Regards,
Christian.
>
> Best Regards!
> James Zhu
>>> }
>>> idx += len / 4;
>>> @@ -884,6 +896,18 @@ int amdgpu_vce_ring_parse_cs(struct
>>> amdgpu_cs_parser *p, uint32_t ib_idx)
>>> goto out;
>>> break;
>>> + case 0x0500000d: /* MV buffer */
>>> + r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 3,
>>> + idx + 2, 0, 0);
>>> + if (r)
>>> + goto out;
>>> +
>>> + r = amdgpu_vce_cs_reloc(p, ib_idx, idx + 8,
>>> + idx + 7, 0, 0);
>>> + if (r)
>>> + goto out;
>>> + break;
>>> +
>>> default:
>>> DRM_ERROR("invalid VCE command (0x%x)!\n", cmd);
>>> r = -EINVAL;
>>
>
_______________________________________________
amd-gfx mailing list
amd-gfx@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/amd-gfx
next prev parent reply other threads:[~2018-04-03 9:11 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-03-29 21:02 [PATCH] drm/amdgpu:Added support for MV packet James Zhu
[not found] ` <1522357350-7872-1-git-send-email-James.Zhu-5C7GfCeVMHo@public.gmane.org>
2018-03-31 17:51 ` Christian König
[not found] ` <de5a8e06-1549-2647-932a-f64a4a96b3c3-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org>
2018-04-02 20:27 ` James Zhu
[not found] ` <ebbfe0e7-6930-c142-5ea6-13fcc7caba17-5C7GfCeVMHo@public.gmane.org>
2018-04-03 9:11 ` Christian König [this message]
[not found] ` <5138ab5e-8056-93f3-a635-bec2d17c8d5c-5C7GfCeVMHo@public.gmane.org>
2018-04-03 14:52 ` James Zhu
2018-04-03 14:49 ` [PATCH v2] " James Zhu
[not found] ` <1522766956-22431-1-git-send-email-James.Zhu-5C7GfCeVMHo@public.gmane.org>
2018-04-04 9:12 ` Christian König
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=5138ab5e-8056-93f3-a635-bec2d17c8d5c@amd.com \
--to=christian.koenig-5c7gfcevmho@public.gmane.org \
--cc=James.Zhu-5C7GfCeVMHo@public.gmane.org \
--cc=amd-gfx-PD4FTy7X32lNgt0PjOBp9y5qC8QIuHrW@public.gmane.org \
--cc=jamesz-5C7GfCeVMHo@public.gmane.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox