From: Thomas Huth <thuth@redhat.com>
To: Mikko Perttunen <mperttunen@nvidia.com>
Cc: dri-devel@lists.freedesktop.org, linux-tegra@vger.kernel.org,
linux-kernel@vger.kernel.org, linux-crypto@vger.kernel.org,
Thierry Reding <thierry.reding@gmail.com>,
David Airlie <airlied@gmail.com>,
Jonathan Hunter <jonathanh@nvidia.com>,
Aaron Kling <webgeek1234@gmail.com>,
"David S. Miller" <davem@davemloft.net>,
Simona Vetter <simona@ffwll.ch>,
Herbert Xu <herbert@gondor.apana.org.au>,
Akhil R <akhilrajeev@nvidia.com>
Subject: Re: [PATCH 1/2] gpu: host1x: Allow entries in BO caches to be freed
Date: Wed, 16 Sep 2026 13:06:37 +0200 [thread overview]
Message-ID: <4fb988c5-3dc7-49b2-aca8-45f23e71bad3@redhat.com> (raw)
In-Reply-To: <20260515-host1x-bocache-leak-v1-1-a0375f68aeab@nvidia.com>
On 15/05/2026 04.34, Mikko Perttunen wrote:
> When a buffer object is pinned via host1x_bo_pin() with a cache, the
> resulting mapping is kept in the cache so it can be reused on subsequent
> pins. Each mapping held a reference to the underlying host1x_bo (taken
> in tegra_bo_pin / gather_bo_pin), so as long as a mapping was cached,
> the bo itself could not be freed.
>
> However, the only way to remove the cached mapping was through the free
> path of the buffer object. This meant that if a bo got cached, it could
> never get freed again.
>
> Resolve the circularity by holding a weak reference to the bo from the
> cache side. This is done by having the .pin callbacks not bump the bo's
> refcount -- instead the common Host1x bo code does so, except for the
> cache reference.
>
> Also move the remove-cache-mapping-on-free code into a common function
> inside Host1x code. This is only called from the TegraDRM GEM buffers
> since those are the only ones that can be cached at the moment.
>
> Reported-by: Aaron Kling <webgeek1234@gmail.com>
> Fixes: 1f39b1dfa53c ("drm/tegra: Implement buffer object cache")
> Signed-off-by: Mikko Perttunen <mperttunen@nvidia.com>
> ---
...
> diff --git a/include/linux/host1x.h b/include/linux/host1x.h
> index 5e7a63143a4a..d8f052a85b75 100644
> --- a/include/linux/host1x.h
> +++ b/include/linux/host1x.h
> @@ -143,6 +143,12 @@ static inline struct host1x_bo_mapping *to_host1x_bo_mapping(struct kref *ref)
> return container_of(ref, struct host1x_bo_mapping, ref);
> }
>
> +/**
> + * struct host1x_bo_ops - operations implemented by a host1x_bo provider
> + *
> + * @pin: create a DMA mapping. Implementation must not touch the bo's refcount.
> + * @unpin: destroy a DMA mapping. Implementation must not touch the bo's refcount.
> + */
> struct host1x_bo_ops {
> struct host1x_bo *(*get)(struct host1x_bo *bo);
> void (*put)(struct host1x_bo *bo);
Hi Mikko!
FYI, this now causes some warnings during "make htmldocs":
WARNING: .../linux/include/linux/host1x.h:159 struct member 'get' not
described in 'host1x_bo_ops'
WARNING: .../linux/include/linux/host1x.h:159 struct member 'put' not
described in 'host1x_bo_ops'
WARNING: .../linux/include/linux/host1x.h:159 struct member 'mmap' not
described in 'host1x_bo_ops'
WARNING: .../linux/include/linux/host1x.h:159 struct member 'munmap' not
described in 'host1x_bo_ops'
If you've got some spare time, could you maybe send a patch to fix it?
Thanks,
Thomas
next prev parent reply other threads:[~2026-09-16 11:06 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-15 2:34 [PATCH 0/2] Fix leaking of cached Host1x buffer objects Mikko Perttunen
2026-05-15 2:34 ` [PATCH 1/2] gpu: host1x: Allow entries in BO caches to be freed Mikko Perttunen
2026-05-17 20:02 ` Aaron Kling
2026-05-18 2:12 ` Mikko Perttunen
2026-05-28 12:16 ` Thierry Reding
2026-09-16 11:06 ` Thomas Huth [this message]
2026-05-15 2:34 ` [PATCH 2/2] crypto: tegra - Don't touch bo refcount in host1x bo pin/unpin Mikko Perttunen
2026-05-22 12:32 ` Herbert Xu
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=4fb988c5-3dc7-49b2-aca8-45f23e71bad3@redhat.com \
--to=thuth@redhat.com \
--cc=airlied@gmail.com \
--cc=akhilrajeev@nvidia.com \
--cc=davem@davemloft.net \
--cc=dri-devel@lists.freedesktop.org \
--cc=herbert@gondor.apana.org.au \
--cc=jonathanh@nvidia.com \
--cc=linux-crypto@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-tegra@vger.kernel.org \
--cc=mperttunen@nvidia.com \
--cc=simona@ffwll.ch \
--cc=thierry.reding@gmail.com \
--cc=webgeek1234@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®