Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Ilia Levi <ilia.levi@intel.com>
To: intel-xe@lists.freedesktop.org
Cc: ilia.levi@intel.com, koby.elbaz@intel.com,
	meny.yossefi@intel.com, shuicheng.lin@intel.com,
	thomas.hellstrom@intel.com, matthew.auld@intel.com,
	matthew.brost@intel.com
Subject: [PATCH v3 0/7] drm/xe/mmio_gem: fix fault handler and destroy path
Date: Thu, 23 Jul 2026 19:18:25 +0300	[thread overview]
Message-ID: <20260723161832.137153-1-ilia.levi@intel.com> (raw)

This series fixes several issues in xe_mmio_gem, introduced by
1ffcf8b8ae8a ("drm/xe: Support for mmap-ing mmio regions"):
split VMA handling, WB/UC aliasing of the dummy page, a rb-tree
leak on destroy, dummy page accumulation, and use-after-free / MMIO
access after destroy. It also converts the existing PCI barrier mmap
to build on xe_mmio_gem now that the infrastructure is in place.

v3: (Matt Auld)
- New patch using the xe_mmio_gem infra for PCI barrier mmap
- New patch for rejecting VMA split
- Using dma_resv lock for synchronization
- SIGBUS instead of dummy page on access after destroy
- Some changes in patch splitting (e.g. the vm_pgoff handling now lives
  in the destroy-flow patch alongside the zap that needs it)

v2:
- New patch 1/5: fix dummy page WB/UC aliasing (Sashiko)
- Patch 2/5: no longer modifies xe_mmio_gem_vm_fault_dummy_page() (handled by 1/5)
- Patch 3/5: unchanged
- Patch 4/5: compute pfn inside scoped_guard
- Patch 5/5: adapt to xe_mmio_gem_vm_fault_dummy_page() signature change, fix "objecthas" typo

Ilia Levi (5):
  drm/xe/mmio_gem: forbid VMA split
  drm/xe/mmio_gem: use write-back mapping for dummy page
  drm/xe/mmio_gem: simplify fault handler loop
  drm/xe/mmio_gem: cache the dummy page per object
  drm/xe/mmio_gem: fix destroy flow

Matthew Auld (1):
  drm/xe: convert PCI barrier mmap to use xe_mmio_gem

Shuicheng Lin (1):
  drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy

 drivers/gpu/drm/xe/xe_bo.c           |  24 ++++--
 drivers/gpu/drm/xe/xe_bo.h           |   1 -
 drivers/gpu/drm/xe/xe_device.c       | 102 ++-----------------------
 drivers/gpu/drm/xe/xe_device_types.h |  12 +++
 drivers/gpu/drm/xe/xe_mmio_gem.c     | 108 ++++++++++++++++++---------
 drivers/gpu/drm/xe/xe_mmio_gem.h     |   2 +-
 6 files changed, 112 insertions(+), 137 deletions(-)

-- 
2.49.1


             reply	other threads:[~2026-07-23 16:18 UTC|newest]

Thread overview: 19+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 16:18 Ilia Levi [this message]
2026-07-23 16:18 ` [PATCH v3 1/7] drm/xe/mmio_gem: forbid VMA split Ilia Levi
2026-07-23 16:25   ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 2/7] drm/xe/mmio_gem: use write-back mapping for dummy page Ilia Levi
2026-07-23 17:16   ` Matthew Auld
2026-07-24  9:49     ` Levi, Ilia
2026-07-28 16:37       ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 3/7] drm/xe/mmio_gem: simplify fault handler loop Ilia Levi
2026-07-23 17:22   ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 4/7] drm/xe/mmio_gem: Revoke drm_vma_node on xe_mmio_gem destroy Ilia Levi
2026-07-23 16:18 ` [PATCH v3 5/7] drm/xe/mmio_gem: cache the dummy page per object Ilia Levi
2026-07-28 16:33   ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 6/7] drm/xe/mmio_gem: fix destroy flow Ilia Levi
2026-07-24 12:50   ` Matthew Auld
2026-07-23 16:18 ` [PATCH v3 7/7] drm/xe: convert PCI barrier mmap to use xe_mmio_gem Ilia Levi
2026-08-04 14:00   ` Levi, Ilia
2026-07-23 16:59 ` ✓ CI.KUnit: success for drm/xe/mmio_gem: fix fault handler and destroy path (rev3) Patchwork
2026-07-23 17:34 ` ✓ Xe.CI.BAT: " Patchwork
2026-07-24 17:14 ` ✓ Xe.CI.FULL: " Patchwork

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723161832.137153-1-ilia.levi@intel.com \
    --to=ilia.levi@intel.com \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=koby.elbaz@intel.com \
    --cc=matthew.auld@intel.com \
    --cc=matthew.brost@intel.com \
    --cc=meny.yossefi@intel.com \
    --cc=shuicheng.lin@intel.com \
    --cc=thomas.hellstrom@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox