On 9/26/26 04:20, Jianfeng Liu wrote:
That commit fixed a dangling reference in the DMABUF_DEBUG default and thereby enabled the option - and with it the page-stripping sg_table wrapper that dma_buf_map_attachment() hands to importers - on every kernel with DEBUG_KERNEL=y, i.e. virtually every distro kernel.
drm/msm is broken by the wrapper. Both of msm's map paths consume sg->length and sg_phys() of the attachment sg_table: msm_iommu_pagetable_map() for the per-process GPU pagetables, and iommu_map_sg() (via iommu_map_sgtable()) for scanout. The wrapper zeroes sg->length and strips the page pointers, so mappings of imported dma-bufs silently map nothing, and userspace observes arm-smmu translation faults from UCHE, e.g. during hardware video decode (clapper, chromium) on Adreno systems:
gpu fault: ttbr0=000000088a889000 iova=000000010741c000 dir=READ type=TRANSLATION source=UCHE
Bisected on a Snapdragon X1E78100 laptop as v7.3-rc3 good, v7.3-rc4 bad, culprit 143755bdabaa9.
Switching msm to sg_dma_address()/sg_dma_len() is not a trivial fix either: those fields are only valid for sg_tables that msm has dma-mapped itself, which native non-MSM_BO_WC objects' sg_tables are not, so the conversion needs more work. The msm maintainer has therefore requested restoring the previous default for v7.3, to be revisited once msm no longer consumes struct page and sg->length of imported sg_tables.
Yeah as I said before the problematic part is MSM here. We have enforced correct driver behavior for over 5 years now when that option is enabled.
What we can do is to mark MSM as broken and/or give a warning in MSM when DMABUF_DEBUG is enabled and you try to import a DMA-buf.
But making the check not default to enable on debug kernels is not an option. This check here is exactly to point out broken drivers and you can manually disable it.
Regards, Christian.
Link: https://lore.kernel.org/linux-arm-msm/20260923074256.9357-1-liujianfeng1994@... Suggested-by: Rob Clark robin.clark@oss.qualcomm.com Cc: Christian König christian.koenig@amd.com Cc: Sumit Semwal sumit.semwal@linaro.org Cc: Karl Mehltretter kmehltretter@gmail.com
Signed-off-by: Jianfeng Liu liujianfeng1994@gmail.com
drivers/dma-buf/Kconfig | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/dma-buf/Kconfig b/drivers/dma-buf/Kconfig index e4f078a326a41..7efc0f0d07126 100644 --- a/drivers/dma-buf/Kconfig +++ b/drivers/dma-buf/Kconfig @@ -43,7 +43,7 @@ config UDMABUF config DMABUF_DEBUG bool "DMA-BUF debug checks" depends on DMA_SHARED_BUFFER
- default y if DEBUG_KERNEL
- default y if DEBUG help This option enables additional checks for DMA-BUF importers and exporters. Specifically it validates that importers do not peek at the
base-commit: 93f51579e7df248780214094418f205253383cc5 branch: revert-dmabuf-debug-for-7.3