From: "Alexandre Courbot" <acourbot@nvidia.com>
To: "Gary Guo" <gary@garyguo.net>
Cc: "Danilo Krummrich" <dakr@kernel.org>,
"Matteo Kloiber" <kernel@matt3o12.de>, <aliceryhl@google.com>,
<ojeda@kernel.org>, <airlied@gmail.com>, <simona@ffwll.ch>,
<abdiel.janulgue@gmail.com>, <daniel.almeida@collabora.com>,
<robin.murphy@arm.com>, <a.hindborg@kernel.org>,
<nova-gpu@lists.linux.dev>, <dri-devel@lists.freedesktop.org>,
<driver-core@lists.linux.dev>, <rust-for-linux@vger.kernel.org>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH 2/2] rust: scatterlist: honor the device's maximum segment size
Date: Tue, 15 Sep 2026 13:44:33 +0900 [thread overview]
Message-ID: <DLFM6SJH6L3P.9YG5DXQPR3TX@nvidia.com> (raw)
In-Reply-To: <DLEYQNUGTQYU.34AISCMMZXG8B@garyguo.net>
On Mon Sep 14, 2026 at 7:22 PM JST, Gary Guo wrote:
> On Mon Sep 14, 2026 at 10:58 AM BST, Danilo Krummrich wrote:
>> On Mon Sep 14, 2026 at 2:45 AM CEST, Alexandre Courbot wrote:
>>> On Mon Sep 14, 2026 at 6:08 AM JST, Matteo Kloiber wrote:
>>>> On Mon Sep 7, 2026 at 11:43 AM JST, Alexandre Courbot wrote:
>>>>> It also means that without patch 1, nova-core would split the firmware
>>>>> into hundreds of 64KB SG entries, which is not breaking but still
>>>>> something we want to avoid. The correct fix is to make sure that
>>>>> `dma_set_max_seg_size` is called by the driver, and while we are at it
>>>>> we also want every driver to call `dma_set_mask_and_coherent`. Ideally
>>>>> we would use the type system to make sure that both functions are called
>>>>> before any DMA operation can take place (using a safe interface), but
>>>>> I'm not quite sure yet how we can do this.
>>>>
>>>> This sounds sensible indeed. Should I open a thread regarding that on Zulip?
>>>
>>> Probably not necessary, the mailing-list has a larger audience and is
>>> the right place for this. I expect people will jump in here with their
>>> thoughts.
>>
>> The problem with those is not that they must strictly be called before
>> allocating DMA memory, but they must not be called concurrently with other DMA
>> operations, such as allocating DMA memory, as it would technically be a data
>> race.
>
> Do they really have to be called *before* allocating DMA memory, not do they
> just need not be called *concurrent* to DMA memory allocation?
>
> If it's the former, we can require these to require mutable reference instead,
> so the probe takes `Pin<&'bound mut Device<Core<'_>>>` which still derefs to
> `&'bound Device<Bound>`, but Rust will require the shared reference to not
> co-exist with the mutable reference.
As Danilo pointed out [1] from a strict safety perspective they must not
be called concurrently to DMA allocations. So there is not a hard need
to call them before.
But my point is different: until patch 1 of this series, nova-core
didn't do anything particularly wrong but was operating with an
inaccurate DMA segment size. Which is currently inconsequential as long
as you don't set `CONFIG_DMA_API_DEBUG`, but will become sub-optimal if
patch 2 gets merged (which it should be, otherwise more DMA-limited
devices could start misbehaving).
The thing is that every driver *really* should set their DMA mask and
max segment size ASAP, but at the moment this is done through two unsafe
functions that are very easy to overlook.
And practically speaking, is there a reason *not* to do that setup
before allocating objects?
So I am thinking that maybe we could have a kind of `DeviceDma` type
which construction involves setting the core DMA parameters (or
acknowledging the defaults), and to which all allocations would be tied.
IOW, Danilo's DMA allocations rework [2] would tie to that `DeviceDma`
object (which itself would be tied to the bound device) instead of the
device itself.
[1] https://lore.kernel.org/DLEY8AHWZFCQ.QUHP2NHJW1QX@kernel.org
[2] https://lore.kernel.org/20260830193824.471089-1-dakr@kernel.org
next prev parent reply other threads:[~2026-09-15 4:44 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 23:32 [PATCH 0/2] rust: honor the maximum DMA " Matteo Kloiber
2026-08-31 23:32 ` [PATCH 1/2] gpu: nova-core: declare unlimited DMA max " Matteo Kloiber
2026-09-07 2:10 ` Alexandre Courbot
2026-09-13 21:07 ` Matteo Kloiber
2026-08-31 23:32 ` [PATCH 2/2] rust: scatterlist: honor the device's maximum " Matteo Kloiber
2026-09-07 2:43 ` Alexandre Courbot
2026-09-13 21:08 ` Matteo Kloiber
2026-09-14 0:45 ` Alexandre Courbot
2026-09-14 9:58 ` Danilo Krummrich
2026-09-14 10:22 ` Gary Guo
2026-09-14 12:17 ` Robin Murphy
2026-09-14 13:17 ` Gary Guo
2026-09-14 13:57 ` Danilo Krummrich
2026-09-15 4:44 ` Alexandre Courbot [this message]
2026-09-15 4:52 ` Alexandre Courbot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLFM6SJH6L3P.9YG5DXQPR3TX@nvidia.com \
--to=acourbot@nvidia.com \
--cc=a.hindborg@kernel.org \
--cc=abdiel.janulgue@gmail.com \
--cc=airlied@gmail.com \
--cc=aliceryhl@google.com \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=driver-core@lists.linux.dev \
--cc=gary@garyguo.net \
--cc=kernel@matt3o12.de \
--cc=linux-kernel@vger.kernel.org \
--cc=nova-gpu@lists.linux.dev \
--cc=ojeda@kernel.org \
--cc=robin.murphy@arm.com \
--cc=rust-for-linux@vger.kernel.org \
--cc=simona@ffwll.ch \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®