From: "Alexandre Courbot" <acourbot@nvidia.com>
To: "Gary Guo" <gary@garyguo.net>
Cc: "Danilo Krummrich" <dakr@kernel.org>,
"Matteo Kloiber" <kernel@matt3o12.de>, <aliceryhl@google.com>,
<ojeda@kernel.org>, <airlied@gmail.com>, <simona@ffwll.ch>,
<abdiel.janulgue@gmail.com>, <daniel.almeida@collabora.com>,
<robin.murphy@arm.com>, <a.hindborg@kernel.org>,
<nova-gpu@lists.linux.dev>, <dri-devel@lists.freedesktop.org>,
<driver-core@lists.linux.dev>, <rust-for-linux@vger.kernel.org>,
<linux-kernel@vger.kernel.org>
Subject: Re: [PATCH 2/2] rust: scatterlist: honor the device's maximum segment size
Date: Tue, 15 Sep 2026 13:52:32 +0900 [thread overview]
Message-ID: <DLFMCWWIALSU.2RHGOMHHCOJS@nvidia.com> (raw)
In-Reply-To: <DLFM6SJH6L3P.9YG5DXQPR3TX@nvidia.com>
On Tue Sep 15, 2026 at 1:44 PM JST, Alexandre Courbot wrote:
> On Mon Sep 14, 2026 at 7:22 PM JST, Gary Guo wrote:
>> On Mon Sep 14, 2026 at 10:58 AM BST, Danilo Krummrich wrote:
>>> On Mon Sep 14, 2026 at 2:45 AM CEST, Alexandre Courbot wrote:
>>>> On Mon Sep 14, 2026 at 6:08 AM JST, Matteo Kloiber wrote:
>>>>> On Mon Sep 7, 2026 at 11:43 AM JST, Alexandre Courbot wrote:
>>>>>> It also means that without patch 1, nova-core would split the firmware
>>>>>> into hundreds of 64KB SG entries, which is not breaking but still
>>>>>> something we want to avoid. The correct fix is to make sure that
>>>>>> `dma_set_max_seg_size` is called by the driver, and while we are at it
>>>>>> we also want every driver to call `dma_set_mask_and_coherent`. Ideally
>>>>>> we would use the type system to make sure that both functions are called
>>>>>> before any DMA operation can take place (using a safe interface), but
>>>>>> I'm not quite sure yet how we can do this.
>>>>>
>>>>> This sounds sensible indeed. Should I open a thread regarding that on Zulip?
>>>>
>>>> Probably not necessary, the mailing-list has a larger audience and is
>>>> the right place for this. I expect people will jump in here with their
>>>> thoughts.
>>>
>>> The problem with those is not that they must strictly be called before
>>> allocating DMA memory, but they must not be called concurrently with other DMA
>>> operations, such as allocating DMA memory, as it would technically be a data
>>> race.
>>
>> Do they really have to be called *before* allocating DMA memory, not do they
>> just need not be called *concurrent* to DMA memory allocation?
>>
>> If it's the former, we can require these to require mutable reference instead,
>> so the probe takes `Pin<&'bound mut Device<Core<'_>>>` which still derefs to
>> `&'bound Device<Bound>`, but Rust will require the shared reference to not
>> co-exist with the mutable reference.
>
> As Danilo pointed out [1] from a strict safety perspective they must not
> be called concurrently to DMA allocations. So there is not a hard need
> to call them before.
>
> But my point is different: until patch 1 of this series, nova-core
> didn't do anything particularly wrong but was operating with an
> inaccurate DMA segment size. Which is currently inconsequential as long
> as you don't set `CONFIG_DMA_API_DEBUG`, but will become sub-optimal if
> patch 2 gets merged (which it should be, otherwise more DMA-limited
> devices could start misbehaving).
>
> The thing is that every driver *really* should set their DMA mask and
> max segment size ASAP, but at the moment this is done through two unsafe
> functions that are very easy to overlook.
>
> And practically speaking, is there a reason *not* to do that setup
> before allocating objects?
>
> So I am thinking that maybe we could have a kind of `DeviceDma` type
> which construction involves setting the core DMA parameters (or
> acknowledging the defaults), and to which all allocations would be tied.
> IOW, Danilo's DMA allocations rework [2] would tie to that `DeviceDma`
> object (which itself would be tied to the bound device) instead of the
> device itself.
>
> [1] https://lore.kernel.org/DLEY8AHWZFCQ.QUHP2NHJW1QX@kernel.org
> [2] https://lore.kernel.org/20260830193824.471089-1-dakr@kernel.org
Sorry, I typed this message while travelling (and offline) and sent it
before noticing there has been new replies that make most of it
irrelevant.
prev parent reply other threads:[~2026-09-15 4:52 UTC|newest]
Thread overview: 15+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-31 23:32 [PATCH 0/2] rust: honor the maximum DMA " Matteo Kloiber
2026-08-31 23:32 ` [PATCH 1/2] gpu: nova-core: declare unlimited DMA max " Matteo Kloiber
2026-09-07 2:10 ` Alexandre Courbot
2026-09-13 21:07 ` Matteo Kloiber
2026-08-31 23:32 ` [PATCH 2/2] rust: scatterlist: honor the device's maximum " Matteo Kloiber
2026-09-07 2:43 ` Alexandre Courbot
2026-09-13 21:08 ` Matteo Kloiber
2026-09-14 0:45 ` Alexandre Courbot
2026-09-14 9:58 ` Danilo Krummrich
2026-09-14 10:22 ` Gary Guo
2026-09-14 12:17 ` Robin Murphy
2026-09-14 13:17 ` Gary Guo
2026-09-14 13:57 ` Danilo Krummrich
2026-09-15 4:44 ` Alexandre Courbot
2026-09-15 4:52 ` Alexandre Courbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=DLFMCWWIALSU.2RHGOMHHCOJS@nvidia.com \
--to=acourbot@nvidia.com \
--cc=a.hindborg@kernel.org \
--cc=abdiel.janulgue@gmail.com \
--cc=airlied@gmail.com \
--cc=aliceryhl@google.com \
--cc=dakr@kernel.org \
--cc=daniel.almeida@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=driver-core@lists.linux.dev \
--cc=gary@garyguo.net \
--cc=kernel@matt3o12.de \
--cc=linux-kernel@vger.kernel.org \
--cc=nova-gpu@lists.linux.dev \
--cc=ojeda@kernel.org \
--cc=robin.murphy@arm.com \
--cc=rust-for-linux@vger.kernel.org \
--cc=simona@ffwll.ch \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®