From: sashiko-bot@kernel.org
To: "Rob Clark" <robin.clark@oss.qualcomm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [RFT 3/5] drm/msm: Extract out map/unmap helpers
Date: Tue, 06 Oct 2026 13:19:19 +0000 [thread overview]
Message-ID: <20261006131920.6870D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20261006131000.81501-4-robin.clark@oss.qualcomm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/msm: missing IOTLB flush on pagetable map error path
--
commit 7d5e2545b852417f316f5873d935ec2b95998bbf
Author: Rob Clark <robin.clark@oss.qualcomm.com>
drm/msm: Extract out map/unmap helpers
This commit extracts `__do_map()` and `__do_unmap()` helpers from
`msm_iommu_pagetable_map()` and `msm_iommu_pagetable_unmap()` respectively.
It aims to reuse these helpers without any functional changes.
> diff --git a/drivers/gpu/drm/msm/msm_iommu.c b/drivers/gpu/drm/msm/msm_iommu.c
> index da6782fca6bd2..a658493f80072 100644
> --- a/drivers/gpu/drm/msm/msm_iommu.c
> +++ b/drivers/gpu/drm/msm/msm_iommu.c
[ ... ]
> @@ -204,10 +169,9 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
> size_t pgsize, count, mapped = 0;
> int ret;
>
> - pgsize = calc_pgsize(pagetable, addr, phys, size, &count);
> + pgsize = calc_pgsize(pgsize_bitmap, addr, phys, size, &count);
>
> - ret = ops->map_pages(ops, addr, phys, pgsize, count,
> - prot, GFP_KERNEL, &mapped);
> + ret = map(arg, phys, addr, pgsize, count, prot, &mapped);
>
> /* map_pages could fail after mapping some of the pages,
> * so update the counters before error handling.
> @@ -218,7 +182,7 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
> len -= mapped;
>
> if (ret) {
> - msm_iommu_pagetable_unmap(mmu, iova, addr - iova);
> + __do_unmap(pgsize_bitmap, iova, addr - iova, arg, unmap);
> return -EINVAL;
> }
[Severity: High]
Does this error path miss an IOTLB flush?
Before this commit, a failure in the mapping loop would call
msm_iommu_pagetable_unmap(), which flushes the IOTLB after unmapping.
Now, the refactored __do_map() calls the new __do_unmap() helper directly.
Because __do_unmap() skips the IOTLB flush, the error rollback leaves stale
virtual-to-physical address translations for partially mapped pages in the
TLB, which can lead to rogue DMA and memory corruption (use-after-free).
[ ... ]
> @@ -227,6 +191,78 @@ static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
> return 0;
> }
>
> +static size_t
> +__unmap_pgtable(void *arg, u64 iova, size_t pgsize, size_t pgcount)
[ ... ]
> +static int msm_iommu_pagetable_map(struct msm_mmu *mmu, u64 iova,
> + struct sg_table *sgt, size_t off, size_t len,
> + int prot)
> +{
> + struct msm_iommu_pagetable *pagetable = to_pagetable(mmu);
> + struct io_pgtable_ops *ops = pagetable->pgtbl_ops;
> +
> + if (!sgt)
> + return msm_iommu_pagetable_map_prr(mmu, iova, len, prot);
> +
> + return __do_map(pagetable->pgsize_bitmap, iova, sgt, off, len, prot,
> + ops, __map_pgtable, __unmap_pgtable);
> +}
[Severity: High]
Can this propagate the error from __do_map() without flushing the IOTLB?
When __do_map() hits an error and returns, msm_iommu_pagetable_map() passes
the error up the stack without initiating a TLB flush, cementing the
missing flush bug from the __do_map() failure path.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261006131000.81501-4-robin.clark@oss.qualcomm.com?part=1
next prev parent reply other threads:[~2026-10-06 13:19 UTC|newest]
Thread overview: 14+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-06 13:09 [RFT 0/5] drm/msm: DMABUF_DEBUG fixes Rob Clark
2026-10-06 13:09 ` [RFT 1/5] drm/msm: Cleanup if pages_to_sg() fails Rob Clark
2026-10-06 13:09 ` [RFT 2/5] drm/msm/gem: dma_map/unmap_sgtable() Rob Clark
2026-10-06 13:09 ` [RFT 3/5] drm/msm: Extract out map/unmap helpers Rob Clark
2026-10-06 13:19 ` sashiko-bot [this message]
2026-10-07 5:19 ` Karl Mehltretter
2026-10-07 15:13 ` Rob Clark
2026-10-06 13:09 ` [RFT 4/5] drm/msm: Convert iommu map/unmap to helpers Rob Clark
2026-10-06 13:25 ` sashiko-bot
2026-10-07 5:23 ` Karl Mehltretter
2026-10-07 15:14 ` Rob Clark
2026-10-06 13:09 ` [RFT 5/5] drm/msm: Convert map helper to use dma-address Rob Clark
2026-10-07 13:15 ` [RFT 0/5] drm/msm: DMABUF_DEBUG fixes Jianfeng Liu
2026-10-07 15:54 ` Rob Clark
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261006131920.6870D1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=robin.clark@oss.qualcomm.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox