From: Ilia Levi <ilia.levi@intel.com>
To: intel-xe@lists.freedesktop.org
Cc: ilia.levi@intel.com, koby.elbaz@intel.com,
meny.yossefi@intel.com, shuicheng.lin@intel.com,
thomas.hellstrom@intel.com, matthew.auld@intel.com,
matthew.brost@intel.com
Subject: [PATCH v3 0/7] drm/xe/mmio_gem: fix fault handler and destroy path
Date: Thu, 23 Jul 2026 19:18:25 +0300 [thread overview]
Message-ID: <20260723161832.137153-1-ilia.levi@intel.com> (raw)
This series fixes several issues in xe_mmio_gem, introduced by
1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions"):
split VMA handling, WB/UC aliasing of the dummy page, a rb-tree
leak on destroy, dummy page accumulation, and use-after-free / MMIO
access after destroy. It also converts the existing PCI barrier mmap
to build on xe_mmio_gem now that the infrastructure is in place.
v3: (Matt Auld)
- New patch using the xe_mmio_gem infra for PCI barrier mmap
- New patch for rejecting VMA split
- Using dma_resv lock for synchronization
- SIGBUS instead of dummy page on access after destroy
- Some changes in patch splitting (e.g. the vm_pgoff handling now lives
in the destroy-flow patch alongside the zap that needs it)
v2:
- New patch 1/5: fix dummy page WB/UC aliasing (Sashiko)
- Patch 2/5: no longer modifies xe_mmio_gem_vm_fault_dummy_page() (handled by 1/5)
- Patch 3/5: unchanged
- Patch 4/5: compute pfn inside scoped_guard
- Patch 5/5: adapt to xe_mmio_gem_vm_fault_dummy_page() signature change, fix "objecthas" typo
Ilia Levi (5):
drm/xe/mmio_gem: forbid VMA split
drm/xe/mmio_gem: use write-back mapping for dummy page
drm/xe/mmio_gem: simplify fault handler loop
drm/xe/mmio_gem: cache the dummy page per object
drm/xe/mmio_gem: fix destroy flow
Matthew Auld (1):
drm/xe: convert PCI barrier mmap to use xe_mmio_gem
Shuicheng Lin (1):
drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy
drivers/gpu/drm/xe/xe_bo.c | 24 ++++--
drivers/gpu/drm/xe/xe_bo.h | 1 -
drivers/gpu/drm/xe/xe_device.c | 102 ++-----------------------
drivers/gpu/drm/xe/xe_device_types.h | 12 +++
drivers/gpu/drm/xe/xe_mmio_gem.c | 108 ++++++++++++++++++---------
drivers/gpu/drm/xe/xe_mmio_gem.h | 2 +-
6 files changed, 112 insertions(+), 137 deletions(-)
--
2.49.1
next reply other threads:[~2026-07-23 16:18 UTC|newest]
Thread overview: 19+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 16:18 Ilia Levi [this message]
2026-07-23 16:18 ` [PATCH v3 1/7] drm/xe/mmio_gem: forbid VMA split Ilia Levi
2026-07-23 16:25 ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 2/7] drm/xe/mmio_gem: use write-back mapping for dummy page Ilia Levi
2026-07-23 17:16 ` Matthew Auld
2026-07-24 9:49 ` Levi, Ilia
2026-07-28 16:37 ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 3/7] drm/xe/mmio_gem: simplify fault handler loop Ilia Levi
2026-07-23 17:22 ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 4/7] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Ilia Levi
2026-07-23 16:18 ` [PATCH v3 5/7] drm/xe/mmio_gem: cache the dummy page per object Ilia Levi
2026-07-28 16:33 ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 6/7] drm/xe/mmio_gem: fix destroy flow Ilia Levi
2026-07-24 12:50 ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 7/7] drm/xe: convert PCI barrier mmap to use xe_mmio_gem Ilia Levi
2026-08-04 14:00 ` Levi, Ilia
2026-07-23 16:59 ` ✓ CI.KUnit: success for drm/xe/mmio_gem: fix fault handler and destroy path (rev3) Patchwork
2026-07-23 17:34 ` ✓ Xe.CI.BAT: " Patchwork
2026-07-24 17:14 ` ✓ Xe.CI.FULL: " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260723161832.137153-1-ilia.levi@intel.com \
--to=ilia.levi@intel.com \
--cc=intel-xe@lists.freedesktop.org \
--cc=koby.elbaz@intel.com \
--cc=matthew.auld@intel.com \
--cc=matthew.brost@intel.com \
--cc=meny.yossefi@intel.com \
--cc=shuicheng.lin@intel.com \
--cc=thomas.hellstrom@intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox