dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Rob Clark" <robin.clark@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [RFT 3/5] drm/msm: Extract out map/unmap helpers
Date: Tue, 06 Oct 2026 13:19:19 +0000	[thread overview]
Message-ID: <20261006131920.6870D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261006131000.81501-4-robin.clark@oss.qualcomm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/msm: missing IOTLB flush on pagetable map error path
--

commit 7d5e2545b852417f316f5873d935ec2b95998bbf
Author: Rob Clark <robin.clark@oss.qualcomm.com>

drm/msm: Extract out map/unmap helpers

This commit extracts `__do_map()` and `__do_unmap()` helpers from
`msm_iommu_pagetable_map()` and `msm_iommu_pagetable_unmap()` respectively.
It aims to reuse these helpers without any functional changes.

> diff --git a/drivers/gpu/drm/msm/msm_iommu.c b/drivers/gpu/drm/msm/msm_iommu.c
> index da6782fca6bd2..a658493f80072 100644
> --- a/drivers/gpu/drm/msm/msm_iommu.c
> +++ b/drivers/gpu/drm/msm/msm_iommu.c
[ ... ]
> @@ -204,10 +169,9 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
>  			size_t pgsize, count, mapped = 0;
>  			int ret;
>  
> -			pgsize = calc_pgsize(pagetable, addr, phys, size, &count);
> +			pgsize = calc_pgsize(pgsize_bitmap, addr, phys, size, &count);
>  
> -			ret = ops->map_pages(ops, addr, phys, pgsize, count,
> -					     prot, GFP_KERNEL, &mapped);
> +			ret = map(arg, phys, addr, pgsize, count, prot, &mapped);
>  
>  			/* map_pages could fail after mapping some of the pages,
>  			 * so update the counters before error handling.
> @@ -218,7 +182,7 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
>  			len  -= mapped;
>  
>  			if (ret) {
> -				msm_iommu_pagetable_unmap(mmu, iova, addr - iova);
> +				__do_unmap(pgsize_bitmap, iova, addr - iova, arg, unmap);
>  				return -EINVAL;
>  			}

[Severity: High]
Does this error path miss an IOTLB flush?

Before this commit, a failure in the mapping loop would call
msm_iommu_pagetable_unmap(), which flushes the IOTLB after unmapping.

Now, the refactored __do_map() calls the new __do_unmap() helper directly.
Because __do_unmap() skips the IOTLB flush, the error rollback leaves stale
virtual-to-physical address translations for partially mapped pages in the
TLB, which can lead to rogue DMA and memory corruption (use-after-free).

[ ... ]
> @@ -227,6 +191,78 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
>  	return 0;
>  }
>  
> +static size_t
> +__unmap_pgtable(void *arg, u64 iova, size_t pgsize, size_t pgcount)
[ ... ]
> +static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
> +				   struct sg_table *sgt, size_t off, size_t len,
> +				   int prot)
> +{
> +	struct msm_iommu_pagetable *pagetable = to_pagetable(mmu);
> +	struct io_pgtable_ops *ops = pagetable->pgtbl_ops;
> +
> +	if (!sgt)
> +		return msm_iommu_pagetable_map_prr(mmu, iova, len, prot);
> +
> +	return __do_map(pagetable->pgsize_bitmap, iova, sgt, off, len, prot,
> +			ops, __map_pgtable, __unmap_pgtable);
> +}

[Severity: High]
Can this propagate the error from __do_map() without flushing the IOTLB?

When __do_map() hits an error and returns, msm_iommu_pagetable_map() passes
the error up the stack without initiating a TLB flush, cementing the
missing flush bug from the __do_map() failure path.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20261006131000.81501-4-robin.clark@oss.qualcomm.com?part=1

  reply	other threads:[~2026-10-06 13:19 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 13:09 [RFT 0/5] drm/msm: DMABUF_DEBUG fixes Rob Clark
2026-10-06 13:09 ` [RFT 1/5] drm/msm: Cleanup if pages_to_sg() fails Rob Clark
2026-10-06 13:09 ` [RFT 2/5] drm/msm/gem: dma_map/unmap_sgtable() Rob Clark
2026-10-06 13:09 ` [RFT 3/5] drm/msm: Extract out map/unmap helpers Rob Clark
2026-10-06 13:19   ` sashiko-bot [this message]
2026-10-07  5:19     ` Karl Mehltretter
2026-10-07 15:13       ` Rob Clark
2026-10-06 13:09 ` [RFT 4/5] drm/msm: Convert iommu map/unmap to helpers Rob Clark
2026-10-06 13:25   ` sashiko-bot
2026-10-07  5:23     ` Karl Mehltretter
2026-10-07 15:14       ` Rob Clark
2026-10-06 13:09 ` [RFT 5/5] drm/msm: Convert map helper to use dma-address Rob Clark
2026-10-07 13:15 ` [RFT 0/5] drm/msm: DMABUF_DEBUG fixes Jianfeng Liu
2026-10-07 15:54   ` Rob Clark

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006131920.6870D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=robin.clark@oss.qualcomm.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox