dri-devel.lists.freedesktop.org archive mirror
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Eliot Courtney" <ecourtney@nvidia.com>
Cc: "Alexandre Courbot" <acourbot@nvidia.com>,
	dri-devel@lists.freedesktop.org,
	"Danilo Krummrich" <dakr@kernel.org>
Subject: Re: [PATCH 07/16] gpu: nova-core: mm: Add MMU v2 page table types
Date: Wed, 09 Sep 2026 04:12:46 +0000	[thread overview]
Message-ID: <20260909041246.7A9751F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260909-mmrebase-v1-7-8dd5d4225d2e@nvidia.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] PdeOps::invalid in MMU v2 creates a valid large page PTE instead of an invalid PDE.
- [Medium] Commit message claims MMU v2 is for Hopper, contradicting the code implementation.
--

commit 123f278dccc75525e59331c1fb9bc862c6096243
Author: Joel Fernandes <joelagnelf@nvidia.com>

gpu: nova-core: mm: Add MMU v2 page table types

Add page table entry and directory structures for MMU version 2. The Pte,
Pde, and DualPde types each implement traits for the version-agnostic API
used by the forthcoming page-table walker and mapper.

>     Add page table entry and directory structures for MMU version 2 used by
>     Hopper and later GPUs.

[Severity: Medium]
Does the commit message have a typo regarding the supported architectures?

The commit message states MMU version 2 is used by Hopper and later GPUs,
but the module documentation in drivers/gpu/nova-core/mm/pagetable/ver2.rs
specifies it is for Turing, Ampere, and Ada GPUs. Hopper uses MMU v3.

> diff --git a/drivers/gpu/nova-core/mm/pagetable/ver2.rs b/drivers/gpu/nova-core/mm/pagetable/ver2.rs
> new file mode 100644
> index 0000000000000..089e5cc2bfc30
> --- /dev/null
> +++ b/drivers/gpu/nova-core/mm/pagetable/ver2.rs

[ ... ]

> +impl PdeOps for Pde {
> +    fn from_raw(val: u64) -> Self {
> +        Self::from_raw(val)
> +    }

[ ... ]

> +    fn invalid() -> Self {
> +        Self::zeroed()
> +            .with_valid_inverted(true)
> +            .with_aperture(AperturePde::Invalid)
> +    }

[Severity: High]
Does PdeOps::invalid() in MMU v2 create a valid large page PTE in hardware
instead of an invalid PDE?

By setting valid_inverted to true (bit 0 = 1), this constructs a raw value
where bit 0 is set. In NVIDIA MMU hardware, bit 0 at the PDE level acts as
the IS_PTE bit (0 = PDE, 1 = large page PTE).

The hardware will interpret this as a valid large page mapped to VRAM
physical address 0. If this is accessed, could it cause severe memory
corruption? 

While currently unreachable by untrusted input because install_mappings()
only uses AperturePde::VideoMemory, this breaks the page table abstraction
for any future code that uses invalid() to clear a PDE slot.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260909-mmrebase-v1-0-8dd5d4225d2e@nvidia.com?part=7

  reply	other threads:[~2026-09-09  4:12 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-09  3:59 [PATCH 00/16] gpu: nova-core: GPU page table, vmm, and bar1 mapping Eliot Courtney
2026-09-09  3:59 ` [PATCH 01/16] gpu: nova-core: mm: Add common types for virtual memory management Eliot Courtney
2026-09-09  3:59 ` [PATCH 02/16] gpu: nova-core: mm: Add buddy allocator and TLB to GpuMm Eliot Courtney
2026-09-09  4:09   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 03/16] gpu: nova-core: mm: Add common types for all page table formats Eliot Courtney
2026-09-09  3:59 ` [PATCH 04/16] gpu: nova-core: mm: pagetable: Add PteOps trait Eliot Courtney
2026-09-09  4:07   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 05/16] gpu: nova-core: mm: pagetable: Add PdeOps trait Eliot Courtney
2026-09-09  4:08   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 06/16] gpu: nova-core: mm: pagetable: Add DualPdeOps trait Eliot Courtney
2026-09-09  3:59 ` [PATCH 07/16] gpu: nova-core: mm: Add MMU v2 page table types Eliot Courtney
2026-09-09  4:12   ` sashiko-bot [this message]
2026-09-09 18:43   ` Danilo Krummrich
2026-09-09  3:59 ` [PATCH 08/16] gpu: nova-core: mm: Add MMU v3 " Eliot Courtney
2026-09-09  3:59 ` [PATCH 09/16] gpu: nova-core: mm: pagetable: Add MmuConfig trait Eliot Courtney
2026-09-09  4:12   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 10/16] gpu: nova-core: mm: Add page table walker for MMU v2/v3 Eliot Courtney
2026-09-09  4:07   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 11/16] gpu: nova-core: mm: Add Virtual Memory Manager Eliot Courtney
2026-09-09  3:59 ` [PATCH 12/16] gpu: nova-core: mm: Add virtual address range tracking to VMM Eliot Courtney
2026-09-09  4:18   ` sashiko-bot
2026-09-09 19:32   ` Danilo Krummrich
2026-09-09  3:59 ` [PATCH 13/16] gpu: nova-core: mm: Add multi-page mapping API " Eliot Courtney
2026-09-09  4:17   ` sashiko-bot
2026-09-09 19:58   ` Danilo Krummrich
2026-09-10  0:47   ` Alistair Popple
2026-09-09  3:59 ` [PATCH 14/16] gpu: nova-core: Add BAR1 aperture type and size constant Eliot Courtney
2026-09-09  4:14   ` sashiko-bot
2026-09-09  3:59 ` [PATCH 15/16] gpu: nova-core: mm: Add BAR1 user interface Eliot Courtney
2026-09-09  4:16   ` sashiko-bot
2026-09-09 20:13   ` Danilo Krummrich
2026-09-09  3:59 ` [PATCH 16/16] gpu: nova-core: mm: Add BAR1 memory management self-tests Eliot Courtney
2026-09-09  4:18   ` sashiko-bot
2026-09-09 21:11 ` [PATCH 00/16] gpu: nova-core: GPU page table, vmm, and bar1 mapping Danilo Krummrich
2026-09-11 15:02 ` Alexandre Courbot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260909041246.7A9751F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=acourbot@nvidia.com \
    --cc=dakr@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=ecourtney@nvidia.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).