From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A724B51FCC0; Wed, 30 Sep 2026 17:31:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789510; cv=none; b=bG0PzY8L+PXZasxzlD6oJjPm+72XEK7CdvDczXcBo7LCOsH2wI7oz8FtlGDuiswKEh3CW8Atpw4d6K3TyRh9S/i957szXK+XPjrBtttRUwCEmRNvMUcLSAJPSTd4NsFVR8WqsSHrczWYxDPGPEY8xvo1UjV2vK3myIqyPgS4REo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789510; c=relaxed/simple; bh=hv9v47WBpf85BJ+tWq8jKxncXLBnPeLVWhRvX3qishw=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=KTKJeZrfCOdHcnrYx2jYIBMrFxXL03Ot6ch/S324d6SoZpQMfpqdxczwQ7wn5dEEhq6TqHoQq4N+eP1cCESyjEFdNdsQKLcYC/d+zTYJTZm3NiEWfCbjFqhTfZIHVcQ+ROteBcyI9VzAWGIk19npbsJXzg6bdEa2rtILMd0JXgc= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=mi/NRhsj; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="mi/NRhsj" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 03DC31F000FF; Wed, 30 Sep 2026 17:31:46 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789507; bh=ep3sZjAXmgGEZ/ftgL9AQf6TqW5UFrLkBsKuyt0F/ys=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=mi/NRhsj6h7uSQhf/uzgIrjln1avBKUVFOE/1EymTRcuR7DWOU87aVjFlW3cazjwd fFjmxztCsotB1gOMf20EtM3Id3Cmpq8U7uYtbuQVu3wgTxOLH744UFfIg7J4CKHR5f jx3EwhwKVzuLtSiaN7ZbxHVL2SlIa/kOnuK1+UYY= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, =?UTF-8?q?Marek=20Marczykowski-G=C3=B3recki?= , Christoph Hellwig , Robert Beckett , =?UTF-8?q?Szymon=20Aceda=C5=84ski?= , =?UTF-8?q?Thomas=20Hellstr=C3=B6m?= , Rodrigo Vivi Subject: [PATCH 6.12 495/877] drm/xe: Limit sg segment size to PAGE_SIZE on Xen PV Date: Wed, 30 Sep 2026 17:23:26 +0200 Message-ID: <20260930152425.343305459@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Szymon Acedański commit 141008dec73521ccf64878517460cec8b3297251 upstream. Fix display corruption on Xen PV dom0, where DMA buffers are not guaranteed machine-contiguous, in which case bounce buffering kicks in, breaking xe's memory coherency assumptions. Apply the same workaround i915 carries in i915_sg_segment_size() since commit 78a07fe777c4 ("drm/i915: stop abusing swiotlb_max_segment"). Fixes: dd08ebf6c352 ("drm/xe: Introduce a new DRM driver for Intel GPUs") Reported-by: Marek Marczykowski-Górecki Closes: https://gitlab.freedesktop.org/drm/xe/kernel/-/work_items/8382 Link: https://lore.kernel.org/xen-devel/aYtznP_tT6xNPwf-@mail-itl/ Link: https://lore.kernel.org/all/20221020110308.1582518-1-hch@lst.de/ # i915 counterpart Cc: Christoph Hellwig Cc: Robert Beckett Cc: stable@vger.kernel.org # v6.8+ Signed-off-by: Szymon Acedański Reviewed-by: Thomas Hellström Signed-off-by: Thomas Hellström Link: https://patch.msgid.link/20260916173030.3223833-1-accek@invisiblethingslab.com (cherry picked from commit 77f704158f099b952681f207478a22d5b8218edb) Signed-off-by: Rodrigo Vivi Signed-off-by: Greg Kroah-Hartman --- drivers/gpu/drm/xe/xe_bo.h | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) --- a/drivers/gpu/drm/xe/xe_bo.h +++ b/drivers/gpu/drm/xe/xe_bo.h @@ -8,6 +8,8 @@ #include +#include + #include "xe_bo_types.h" #include "xe_macros.h" #include "xe_vm_types.h" @@ -328,6 +330,23 @@ static inline unsigned int xe_sg_segment struct scatterlist __maybe_unused sg; size_t max = BIT_ULL(sizeof(sg.length) * 8) - 1; + /* + * For Xen PV guests pages aren't contiguous in DMA (machine) address + * space. The DMA API takes care of that both in dma_alloc_* (by + * calling into the hypervisor to make the pages contiguous) and in + * dma_map_* (by bounce buffering). But xe (like i915, see commit + * 78a07fe777c4) ignores the coherency aspects of the DMA API and thus + * can't cope with bounce buffering actually happening, so add a hack + * here to force small allocations and mappings when running in PV + * mode on Xen. + * + * Note this will still break if bounce buffering is required for other + * reasons, like confidential computing hypervisors or PCIe root ports + * with addressing limitations. + */ + if (xen_pv_domain()) + return PAGE_SIZE; + max = min_t(size_t, max, dma_max_mapping_size(dev)); /*