* [PATCH] udmabuf: Disable the list length limit by default
@ 2026-10-06 0:48 Val Packett
2026-10-06 7:34 ` Christian König
0 siblings, 1 reply; 2+ messages in thread
From: Val Packett @ 2026-10-06 0:48 UTC (permalink / raw)
To: Gerd Hoffmann, Vivek Kasireddy, Sumit Semwal,
Christian König, Philipp Stanner
Cc: Val Packett, dri-devel, linux-media, linaro-mm-sig, linux-kernel
Shared memory buffers for software-rendered GUI applications are often
large and highly fragmented in memory. To get a shareable handle to such
a buffer from a guest VM, a virtio-gpu device backend can use the
UDMABUF_CREATE_LIST ioctl with the memfds backing guest RAM and the list
of guest physical pages sent by the guest driver. That list reaches 80K
entries for a maximized window on a 4K display!
Like 44e9eb5a7621 ("dma-buf/udmabuf: Disable the size limit by default")
did for the size limit, change the default to INT_MAX since the amount
of protection provided by this limit seems dubious.
Signed-off-by: Val Packett <val@invisiblethingslab.com>
---
drivers/dma-buf/udmabuf.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/dma-buf/udmabuf.c b/drivers/dma-buf/udmabuf.c
index df6dd0046242..589031133588 100644
--- a/drivers/dma-buf/udmabuf.c
+++ b/drivers/dma-buf/udmabuf.c
@@ -16,9 +16,9 @@
#include <linux/vmalloc.h>
#include <linux/iosys-map.h>
-static int list_limit = 1024;
+static int list_limit = INT_MAX;
module_param(list_limit, int, 0644);
-MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is 1024.");
+MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is INT_MAX.");
static int size_limit_mb = INT_MAX;
module_param(size_limit_mb, int, 0644);
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] udmabuf: Disable the list length limit by default
2026-10-06 0:48 [PATCH] udmabuf: Disable the list length limit by default Val Packett
@ 2026-10-06 7:34 ` Christian König
0 siblings, 0 replies; 2+ messages in thread
From: Christian König @ 2026-10-06 7:34 UTC (permalink / raw)
To: Val Packett, Gerd Hoffmann, Vivek Kasireddy, Sumit Semwal,
Philipp Stanner
Cc: dri-devel, linux-media, linaro-mm-sig, linux-kernel
On 10/6/26 02:48, Val Packett wrote:
> Shared memory buffers for software-rendered GUI applications are often
> large and highly fragmented in memory. To get a shareable handle to such
> a buffer from a guest VM, a virtio-gpu device backend can use the
> UDMABUF_CREATE_LIST ioctl with the memfds backing guest RAM and the list
> of guest physical pages sent by the guest driver. That list reaches 80K
> entries for a maximized window on a 4K display!
>
> Like 44e9eb5a7621 ("dma-buf/udmabuf: Disable the size limit by default")
> did for the size limit, change the default to INT_MAX since the amount
> of protection provided by this limit seems dubious.
>
> Signed-off-by: Val Packett <val@invisiblethingslab.com>
> ---
> drivers/dma-buf/udmabuf.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma-buf/udmabuf.c b/drivers/dma-buf/udmabuf.c
> index df6dd0046242..589031133588 100644
> --- a/drivers/dma-buf/udmabuf.c
> +++ b/drivers/dma-buf/udmabuf.c
> @@ -16,9 +16,9 @@
> #include <linux/vmalloc.h>
> #include <linux/iosys-map.h>
>
> -static int list_limit = 1024;
> +static int list_limit = INT_MAX;
> module_param(list_limit, int, 0644);
> -MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is 1024.");
> +MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is INT_MAX.");
This will completely overflow the size calculation in udmabuf_ioctl_create_list().
Please fix udmabuf_ioctl_create_list() to use memdup_array_user() and use a reasonable limit here. Something like 128k should probably do.
Apart from that I think we need to start using huge and giant pages for virtio-gpu on the client side, we already had it multiple times that we hit limits with that in multiple places.
Sharing 80k individual 4k pointers is really not very efficient.
Regards,
Christian.
>
> static int size_limit_mb = INT_MAX;
> module_param(size_limit_mb, int, 0644);
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-06 7:34 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-06 0:48 [PATCH] udmabuf: Disable the list length limit by default Val Packett
2026-10-06 7:34 ` Christian König
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®