mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Christian König" <christian.koenig@amd.com>
To: rob.clark@oss.qualcomm.com
Cc: Jianfeng Liu <liujianfeng1994@gmail.com>,
	dri-devel@lists.freedesktop.org, linux-media@vger.kernel.org,
	linux-kernel@vger.kernel.org,
	Sumit Semwal <sumit.semwal@linaro.org>,
	Bryan O'Donoghue <bod.linux@nxsw.ie>,
	Dmitry Baryshkov <lumag@kernel.org>,
	Karl Mehltretter <kmehltretter@gmail.com>,
	linux-arm-msm@vger.kernel.org, freedreno@lists.freedesktop.org,
	linaro-mm-sig@lists.linaro.org
Subject: Re: [PATCH] Revert "dma-buf: Make DMABUF_DEBUG default to y on DEBUG_KERNEL kernels"
Date: Mon, 28 Sep 2026 12:47:52 +0200	[thread overview]
Message-ID: <50a9c1f1-6889-4bd5-b4f7-0500d30d3dd9@amd.com> (raw)
In-Reply-To: <CACSVV02WCQwQy9BpUUqziQTtKV7QyJruiM+iTiLE_SEVKtpVNQ@mail.gmail.com>

On 9/28/26 12:36, Rob Clark wrote:
> On Mon, Sep 28, 2026 at 1:19 AM Christian König
> <christian.koenig@amd.com> wrote:
>>
>> On 9/26/26 04:20, Jianfeng Liu wrote:
>>> That commit fixed a dangling reference in the DMABUF_DEBUG default
>>> and thereby enabled the option - and with it the page-stripping
>>> sg_table wrapper that dma_buf_map_attachment() hands to importers -
>>> on every kernel with DEBUG_KERNEL=y, i.e. virtually every distro
>>> kernel.
>>>
>>> drm/msm is broken by the wrapper.  Both of msm's map paths consume
>>> sg->length and sg_phys() of the attachment sg_table:
>>> msm_iommu_pagetable_map() for the per-process GPU pagetables, and
>>> iommu_map_sg() (via iommu_map_sgtable()) for scanout.  The wrapper
>>> zeroes sg->length and strips the page pointers, so mappings of
>>> imported dma-bufs silently map nothing, and userspace observes
>>> arm-smmu translation faults from UCHE, e.g. during hardware video
>>> decode (clapper, chromium) on Adreno systems:
>>>
>>>   gpu fault: ttbr0=000000088a889000 iova=000000010741c000 dir=READ
>>>   type=TRANSLATION source=UCHE
>>>
>>> Bisected on a Snapdragon X1E78100 laptop as v7.3-rc3 good,
>>> v7.3-rc4 bad, culprit 143755bdabaa9.
>>>
>>> Switching msm to sg_dma_address()/sg_dma_len() is not a trivial fix
>>> either: those fields are only valid for sg_tables that msm has
>>> dma-mapped itself, which native non-MSM_BO_WC objects' sg_tables
>>> are not, so the conversion needs more work.  The msm maintainer has
>>> therefore requested restoring the previous default for v7.3, to be
>>> revisited once msm no longer consumes struct page and sg->length of
>>> imported sg_tables.
>>
>> Yeah as I said before the problematic part is MSM here. We have enforced correct driver behavior for over 5 years now when that option is enabled.
> 
> The problem is bigger than MSM here

Well, so far I have only heard about MSM.

But yes I mean the config option is doing exactly what it is supposed to do, pointing out when driver need some work to get this fixed.

I also agree that we shouldn't have allowed driver to touch that stuff in the first place and better document how to do things but yeah I can't change the past I can only try to fix it now.

>> What we can do is to mark MSM as broken and/or give a warning in MSM when DMABUF_DEBUG is enabled and you try to import a DMA-buf.
> 
> sorry, no, we can't mark MSM as broken.. we can mark DMABUF_DEBUG as BROKEN

As I wrote the debug functionality to enforce not using struct pages has been around for over 5 years now, it was just not enabled by default.

What I can offer is to set it to default N for another few month to give you more time to fix things.

Regards,
Christian.

> 
> BR,
> -R
> 
>> But making the check not default to enable on debug kernels is not an option. This check here is exactly to point out broken drivers and you can manually disable it.
>>
>> Regards,
>> Christian.
>>
>>>
>>> Link: https://lore.kernel.org/linux-arm-msm/20260923074256.9357-1-liujianfeng1994@gmail.com/
>>> Suggested-by: Rob Clark <robin.clark@oss.qualcomm.com>
>>> Cc: Christian König <christian.koenig@amd.com>
>>> Cc: Sumit Semwal <sumit.semwal@linaro.org>
>>> Cc: Karl Mehltretter <kmehltretter@gmail.com>
>>>
>>> Signed-off-by: Jianfeng Liu <liujianfeng1994@gmail.com>
>>> ---
>>>
>>>  drivers/dma-buf/Kconfig | 2 +-
>>>  1 file changed, 1 insertion(+), 1 deletion(-)
>>>
>>> diff --git a/drivers/dma-buf/Kconfig b/drivers/dma-buf/Kconfig
>>> index e4f078a326a41..7efc0f0d07126 100644
>>> --- a/drivers/dma-buf/Kconfig
>>> +++ b/drivers/dma-buf/Kconfig
>>> @@ -43,7 +43,7 @@ config UDMABUF
>>>  config DMABUF_DEBUG
>>>       bool "DMA-BUF debug checks"
>>>       depends on DMA_SHARED_BUFFER
>>> -     default y if DEBUG_KERNEL
>>> +     default y if DEBUG
>>>       help
>>>         This option enables additional checks for DMA-BUF importers and
>>>         exporters. Specifically it validates that importers do not peek at the
>>> ---
>>> base-commit: 93f51579e7df248780214094418f205253383cc5
>>> branch: revert-dmabuf-debug-for-7.3
>>>
>>


  reply	other threads:[~2026-09-28 10:48 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26  2:20 Jianfeng Liu
2026-09-26 18:40 ` Rob Clark
2026-09-28  8:18 ` Christian König
2026-09-28 10:36   ` Rob Clark
2026-09-28 10:47     ` Christian König [this message]
2026-09-28 11:21       ` Rob Clark
2026-09-28 19:39         ` Karl Mehltretter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=50a9c1f1-6889-4bd5-b4f7-0500d30d3dd9@amd.com \
    --to=christian.koenig@amd.com \
    --cc=bod.linux@nxsw.ie \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=freedreno@lists.freedesktop.org \
    --cc=kmehltretter@gmail.com \
    --cc=linaro-mm-sig@lists.linaro.org \
    --cc=linux-arm-msm@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=liujianfeng1994@gmail.com \
    --cc=lumag@kernel.org \
    --cc=rob.clark@oss.qualcomm.com \
    --cc=sumit.semwal@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®