From: sashiko-bot@kernel.org
To: "Eliot Courtney" <ecourtney@nvidia.com>
Cc: "Alexandre Courbot" <acourbot@nvidia.com>,
dri-devel@lists.freedesktop.org,
"Danilo Krummrich" <dakr@kernel.org>
Subject: Re: [PATCH 07/16] gpu: nova-core: mm: Add MMU v2 page table types
Date: Wed, 09 Sep 2026 04:12:46 +0000 [thread overview]
Message-ID: <20260909041246.7A9751F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260909-mmrebase-v1-7-8dd5d4225d2e@nvidia.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] PdeOps::invalid in MMU v2 creates a valid large page PTE instead of an invalid PDE.
- [Medium] Commit message claims MMU v2 is for Hopper, contradicting the code implementation.
--
commit 123f278dccc75525e59331c1fb9bc862c6096243
Author: Joel Fernandes <joelagnelf@nvidia.com>
gpu: nova-core: mm: Add MMU v2 page table types
Add page table entry and directory structures for MMU version 2. The Pte,
Pde, and DualPde types each implement traits for the version-agnostic API
used by the forthcoming page-table walker and mapper.
> Add page table entry and directory structures for MMU version 2 used by
> Hopper and later GPUs.
[Severity: Medium]
Does the commit message have a typo regarding the supported architectures?
The commit message states MMU version 2 is used by Hopper and later GPUs,
but the module documentation in drivers/gpu/nova-core/mm/pagetable/ver2.rs
specifies it is for Turing, Ampere, and Ada GPUs. Hopper uses MMU v3.
> diff --git a/drivers/gpu/nova-core/mm/pagetable/ver2.rs b/drivers/gpu/nova-core/mm/pagetable/ver2.rs
> new file mode 100644
> index 0000000000000..089e5cc2bfc30
> --- /dev/null
> +++ b/drivers/gpu/nova-core/mm/pagetable/ver2.rs
[ ... ]
> +impl PdeOps for Pde {
> + fn from_raw(val: u64) -> Self {
> + Self::from_raw(val)
> + }
[ ... ]
> + fn invalid() -> Self {
> + Self::zeroed()
> + .with_valid_inverted(true)
> + .with_aperture(AperturePde::Invalid)
> + }
[Severity: High]
Does PdeOps::invalid() in MMU v2 create a valid large page PTE in hardware
instead of an invalid PDE?
By setting valid_inverted to true (bit 0 = 1), this constructs a raw value
where bit 0 is set. In NVIDIA MMU hardware, bit 0 at the PDE level acts as
the IS_PTE bit (0 = PDE, 1 = large page PTE).
The hardware will interpret this as a valid large page mapped to VRAM
physical address 0. If this is accessed, could it cause severe memory
corruption?
While currently unreachable by untrusted input because install_mappings()
only uses AperturePde::VideoMemory, this breaks the page table abstraction
for any future code that uses invalid() to clear a PDE slot.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-mmrebase-v1-0-8dd5d4225d2e@nvidia.com?part=7
next prev parent reply other threads:[~2026-09-09 4:12 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 3:59 [PATCH 00/16] gpu: nova-core: GPU page table, vmm, and bar1 mapping Eliot Courtney
2026-09-09 3:59 ` [PATCH 01/16] gpu: nova-core: mm: Add common types for virtual memory management Eliot Courtney
2026-09-09 3:59 ` [PATCH 02/16] gpu: nova-core: mm: Add buddy allocator and TLB to GpuMm Eliot Courtney
2026-09-09 4:09 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 03/16] gpu: nova-core: mm: Add common types for all page table formats Eliot Courtney
2026-09-09 3:59 ` [PATCH 04/16] gpu: nova-core: mm: pagetable: Add PteOps trait Eliot Courtney
2026-09-09 4:07 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 05/16] gpu: nova-core: mm: pagetable: Add PdeOps trait Eliot Courtney
2026-09-09 4:08 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 06/16] gpu: nova-core: mm: pagetable: Add DualPdeOps trait Eliot Courtney
2026-09-09 3:59 ` [PATCH 07/16] gpu: nova-core: mm: Add MMU v2 page table types Eliot Courtney
2026-09-09 4:12 ` sashiko-bot [this message]
2026-09-09 18:43 ` Danilo Krummrich
2026-09-09 3:59 ` [PATCH 08/16] gpu: nova-core: mm: Add MMU v3 " Eliot Courtney
2026-09-09 3:59 ` [PATCH 09/16] gpu: nova-core: mm: pagetable: Add MmuConfig trait Eliot Courtney
2026-09-09 4:12 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 10/16] gpu: nova-core: mm: Add page table walker for MMU v2/v3 Eliot Courtney
2026-09-09 4:07 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 11/16] gpu: nova-core: mm: Add Virtual Memory Manager Eliot Courtney
2026-09-09 3:59 ` [PATCH 12/16] gpu: nova-core: mm: Add virtual address range tracking to VMM Eliot Courtney
2026-09-09 4:18 ` sashiko-bot
2026-09-09 19:32 ` Danilo Krummrich
2026-09-09 3:59 ` [PATCH 13/16] gpu: nova-core: mm: Add multi-page mapping API " Eliot Courtney
2026-09-09 4:17 ` sashiko-bot
2026-09-09 19:58 ` Danilo Krummrich
2026-09-10 0:47 ` Alistair Popple
2026-09-09 3:59 ` [PATCH 14/16] gpu: nova-core: Add BAR1 aperture type and size constant Eliot Courtney
2026-09-09 4:14 ` sashiko-bot
2026-09-09 3:59 ` [PATCH 15/16] gpu: nova-core: mm: Add BAR1 user interface Eliot Courtney
2026-09-09 4:16 ` sashiko-bot
2026-09-09 20:13 ` Danilo Krummrich
2026-09-09 3:59 ` [PATCH 16/16] gpu: nova-core: mm: Add BAR1 memory management self-tests Eliot Courtney
2026-09-09 4:18 ` sashiko-bot
2026-09-09 21:11 ` [PATCH 00/16] gpu: nova-core: GPU page table, vmm, and bar1 mapping Danilo Krummrich
2026-09-11 15:02 ` Alexandre Courbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909041246.7A9751F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=acourbot@nvidia.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=ecourtney@nvidia.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).