DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Prashant Gupta <prashant.gupta_3@nxp.com>
To: stephen@networkplumber.org, dev@dpdk.org
Cc: Gagandeep Singh <g.singh@nxp.com>
Subject: [PATCH v7-S1 5/6] dma/dpaa2: validate FLE pool IOVA mapping at vchan setup
Date: Fri,  9 Oct 2026 16:20:18 +0530	[thread overview]
Message-ID: <20261009105019.1121083-6-prashant.gupta_3@nxp.com> (raw)
In-Reply-To: <20261009105019.1121083-1-prashant.gupta_3@nxp.com>

From: Gagandeep Singh <g.singh@nxp.com>

The enqueue path turns every FLE virtual address into an IOVA with a
single subtraction:

        fle_iova = (uint64_t)fle - qdma_vq->fle_iova2va_offset;

That offset is derived once from fle_pool->mz, which is the memzone
holding the mempool header, not the mempool object storage. The
objects are allocated from one or more mempool memory chunks, so the
offset derived from the header does not by itself guarantee that all
FLE objects share the same virtual-to-IOVA relationship.

Validate the FLE pool immediately after creation by walking all memory
chunks with rte_mempool_mem_iter(). Verify that every chunk has a valid
IOVA mapping and that all chunks share the same VA-to-IOVA offset. A
pool spanning chunks with different offsets, for example when using
IOVA-as-PA with fragmented hugepages, would result in incorrect IOVAs
being programmed into FLEs.

Reject such pools during vchan setup instead of allowing invalid IOVAs
to reach the enqueue fast path.

On failure, log the pool name, release the mempool and clear the saved
pointer so that a later vchan setup retry does not fail due to a stale
pool-name collision.

Signed-off-by: Gagandeep Singh <g.singh@nxp.com>
Signed-off-by: Prashant Gupta <prashant.gupta_3@nxp.com>
---
 drivers/dma/dpaa2/dpaa2_qdma.c | 55 +++++++++++++++++++++++++++++-----
 1 file changed, 48 insertions(+), 7 deletions(-)

diff --git a/drivers/dma/dpaa2/dpaa2_qdma.c b/drivers/dma/dpaa2/dpaa2_qdma.c
index e8ec9cddfc..8d10edfd04 100644
--- a/drivers/dma/dpaa2/dpaa2_qdma.c
+++ b/drivers/dma/dpaa2/dpaa2_qdma.c
@@ -1333,6 +1333,32 @@ dpaa2_qdma_vchan_rbp_set(struct qdma_virt_queue *vq,
 	return 0;
 }
 
+struct dpaa2_qdma_fle_pool_check {
+	uint64_t iova2va_offset;
+	bool bad;
+};
+
+static void
+dpaa2_qdma_fle_pool_iova_check(struct rte_mempool *mp __rte_unused,
+		void *opaque, struct rte_mempool_memhdr *memhdr,
+		unsigned int mem_idx)
+{
+	struct dpaa2_qdma_fle_pool_check *check = opaque;
+	uint64_t offset;
+
+	if (memhdr->iova == RTE_BAD_IOVA) {
+		check->bad = true;
+		return;
+	}
+
+	offset = (uint64_t)memhdr->addr - memhdr->iova;
+
+	if (mem_idx == 0)
+		check->iova2va_offset = offset;
+	else if (offset != check->iova2va_offset)
+		check->bad = true;
+}
+
 static int
 dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 	const struct rte_dma_vchan_conf *conf,
@@ -1340,10 +1366,10 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 {
 	struct dpaa2_dpdmai_dev *dpdmai_dev = dev->data->dev_private;
 	struct qdma_device *qdma_dev = dpdmai_dev->qdma_dev;
+	struct dpaa2_qdma_fle_pool_check fle_check = {0};
 	uint32_t pool_size;
 	char pool_name[64];
 	int ret;
-	uint64_t iova, va;
 
 	DPAA2_QDMA_FUNC_TRACE();
 
@@ -1379,9 +1405,18 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 		DPAA2_QDMA_ERR("%s create failed", pool_name);
 		return -ENOMEM;
 	}
-	iova = qdma_dev->vqs[vchan].fle_pool->mz->iova;
-	va = qdma_dev->vqs[vchan].fle_pool->mz->addr_64;
-	qdma_dev->vqs[vchan].fle_iova2va_offset = va - iova;
+	rte_mempool_mem_iter(qdma_dev->vqs[vchan].fle_pool,
+			dpaa2_qdma_fle_pool_iova_check, &fle_check);
+
+	if (fle_check.bad) {
+		DPAA2_QDMA_ERR("%s spans inconsistent IOVA offsets",
+				pool_name);
+		ret = -EINVAL;
+		goto err_pool;
+	}
+
+	qdma_dev->vqs[vchan].fle_iova2va_offset =
+		fle_check.iova2va_offset;
 
 	if (qdma_dev->is_silent) {
 		ret = rte_mempool_get_bulk(qdma_dev->vqs[vchan].fle_pool,
@@ -1390,7 +1425,7 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 		if (ret) {
 			DPAA2_QDMA_ERR("sg cntx get from %s for silent mode",
 				       pool_name);
-			return ret;
+			goto err_pool;
 		}
 		ret = rte_mempool_get_bulk(qdma_dev->vqs[vchan].fle_pool,
 				(void **)qdma_dev->vqs[vchan].cntx_fle_sdd,
@@ -1398,7 +1433,7 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 		if (ret) {
 			DPAA2_QDMA_ERR("long cntx get from %s for silent mode",
 				       pool_name);
-			return ret;
+			goto err_pool;
 		}
 	} else {
 		qdma_dev->vqs[vchan].ring_cntx_idx = rte_malloc(NULL,
@@ -1406,7 +1441,8 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 				RTE_CACHE_LINE_SIZE);
 		if (!qdma_dev->vqs[vchan].ring_cntx_idx) {
 			DPAA2_QDMA_ERR("DQ response ring alloc failed.");
-			return -ENOMEM;
+			ret = -ENOMEM;
+			goto err_pool;
 		}
 		qdma_dev->vqs[vchan].ring_cntx_idx->start = 0;
 		qdma_dev->vqs[vchan].ring_cntx_idx->tail = 0;
@@ -1422,6 +1458,11 @@ dpaa2_qdma_vchan_setup(struct rte_dma_dev *dev, uint16_t vchan,
 	qdma_dev->vqs[vchan].nb_desc = conf->nb_desc;
 
 	return 0;
+
+err_pool:
+	rte_mempool_free(qdma_dev->vqs[vchan].fle_pool);
+	qdma_dev->vqs[vchan].fle_pool = NULL;
+	return ret;
 }
 
 static int
-- 
2.43.0


  parent reply	other threads:[~2026-10-09 10:50 UTC|newest]

Thread overview: 39+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-15 11:34 [PATCH v3-S1 0/5] dpaa2: bus, DMA and mempool base fixes Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 2/5] bus/fslmc: reduce probe-time logging and MC traffic Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 3/5] dma/dpaa2: fix array-bounds warning in dequeue path Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 4/5] dma/dpaa2: validate IOVA in pre-populate helpers Prashant Gupta
2026-09-15 11:34 ` [PATCH v3-S1 5/5] mempool/dpaa2: support ops index from primary in secondary Prashant Gupta
2026-09-15 15:24 ` [PATCH v3-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-09-22  9:21 ` [PATCH v4-S1 " Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 2/5] bus/fslmc: reduce probe-time logging and MC traffic Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 3/5] dma/dpaa2: fix array-bounds warning in dequeue path Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 4/5] dma/dpaa2: validate IOVA in pre-populate helpers Prashant Gupta
2026-09-22  9:21   ` [PATCH v4-S1 5/5] mempool/dpaa2: support ops index from primary in secondary Prashant Gupta
2026-09-22 13:59   ` [PATCH v4-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-09-29 14:21   ` [PATCH v5-S1 " Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 1/5] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 2/5] bus/fslmc: reduce probe-time logging and skip ignored devices Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 3/5] dma/dpaa2: fix array-bounds warning and SG FD double-put Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 4/5] dma/dpaa2: validate FLE pool IOVA mapping at vchan setup Prashant Gupta
2026-09-29 14:21     ` [PATCH v5-S1 5/5] mempool/dpaa2: look up ops index locally in secondary Prashant Gupta
2026-09-29 15:45     ` [PATCH v5-S1 0/5] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-10-06 14:57       ` [EXT] " Prashant Gupta
2026-10-06 15:07     ` [PATCH v6-S1 0/6] " Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 1/6] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 2/6] bus/fslmc: reduce probe logging and skip ignored devices Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 3/6] dma/dpaa2: use memcpy to fill completion index ring Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 4/6] dma/dpaa2: release SG FLE on completion ring overflow Prashant Gupta
2026-10-06 15:07       ` [PATCH v6-S1 5/6] dma/dpaa2: validate FLE pool IOVA mapping at vchan setup Prashant Gupta
2026-10-08 22:41         ` Stephen Hemminger
2026-10-06 15:07       ` [PATCH v6-S1 6/6] mempool/dpaa2: look up ops index locally in secondary Prashant Gupta
2026-10-07 15:51       ` [PATCH v6-S1 0/6] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger
2026-10-09 10:50       ` [PATCH v7-S1 " Prashant Gupta
2026-10-09 10:50         ` [PATCH v7-S1 1/6] bus/fslmc: defer bus initialization to probe Prashant Gupta
2026-10-09 10:50         ` [PATCH v7-S1 2/6] bus/fslmc: reduce probe logging and skip ignored devices Prashant Gupta
2026-10-09 10:50         ` [PATCH v7-S1 3/6] dma/dpaa2: use memcpy to fill completion index ring Prashant Gupta
2026-10-09 10:50         ` [PATCH v7-S1 4/6] dma/dpaa2: release SG FLE on completion ring overflow Prashant Gupta
2026-10-09 10:50         ` Prashant Gupta [this message]
2026-10-09 10:50         ` [PATCH v7-S1 6/6] mempool/dpaa2: look up ops index locally in secondary Prashant Gupta
2026-10-09 19:08         ` [PATCH v7-S1 0/6] dpaa2: bus, DMA and mempool base fixes Stephen Hemminger

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261009105019.1121083-6-prashant.gupta_3@nxp.com \
    --to=prashant.gupta_3@nxp.com \
    --cc=dev@dpdk.org \
    --cc=g.singh@nxp.com \
    --cc=stephen@networkplumber.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox