On 10/6/26 02:48, Val Packett wrote:
Shared memory buffers for software-rendered GUI applications are often large and highly fragmented in memory. To get a shareable handle to such a buffer from a guest VM, a virtio-gpu device backend can use the UDMABUF_CREATE_LIST ioctl with the memfds backing guest RAM and the list of guest physical pages sent by the guest driver. That list reaches 80K entries for a maximized window on a 4K display!
Like 44e9eb5a7621 ("dma-buf/udmabuf: Disable the size limit by default") did for the size limit, change the default to INT_MAX since the amount of protection provided by this limit seems dubious.
Signed-off-by: Val Packett val@invisiblethingslab.com
drivers/dma-buf/udmabuf.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/dma-buf/udmabuf.c b/drivers/dma-buf/udmabuf.c index df6dd0046242..589031133588 100644 --- a/drivers/dma-buf/udmabuf.c +++ b/drivers/dma-buf/udmabuf.c @@ -16,9 +16,9 @@ #include <linux/vmalloc.h> #include <linux/iosys-map.h> -static int list_limit = 1024; +static int list_limit = INT_MAX; module_param(list_limit, int, 0644); -MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is 1024."); +MODULE_PARM_DESC(list_limit, "udmabuf_create_list->count limit. Default is INT_MAX.");
This will completely overflow the size calculation in udmabuf_ioctl_create_list().
Please fix udmabuf_ioctl_create_list() to use memdup_array_user() and use a reasonable limit here. Something like 128k should probably do.
Apart from that I think we need to start using huge and giant pages for virtio-gpu on the client side, we already had it multiple times that we hit limits with that in multiple places.
Sharing 80k individual 4k pointers is really not very efficient.
Regards, Christian.
static int size_limit_mb = INT_MAX; module_param(size_limit_mb, int, 0644);
linaro-mm-sig@lists.linaro.org