On 8/12/2026 Wed 13:56, Lizhi Hou wrote:
aie2_populate_range() incorrectly failed jobs for BOs with multiple
mmaps: if the unmapped entry appeared first in umap_list, the loop would
pick it up, call hmm_range_fault() on a gone VMA, and return -EFAULT
without ever trying the remaining valid mapps.

Fix it by skipping unmapped entries. After the loop, if the map list is
empty or all maps are valid, map_invalid can be cleared normally.

Fixes: e486147c912f ("accel/amdxdna: Add BO import and export")
Signed-off-by: Lizhi Hou <[email protected]>
Reviewed-by: Max Zhen <[email protected]>
---
  drivers/accel/amdxdna/aie2_ctx.c | 16 ++++++++++++++++
  1 file changed, 16 insertions(+)

diff --git a/drivers/accel/amdxdna/aie2_ctx.c b/drivers/accel/amdxdna/aie2_ctx.c
index 4b3a62aa8798..8d9c283f606a 100644
--- a/drivers/accel/amdxdna/aie2_ctx.c
+++ b/drivers/accel/amdxdna/aie2_ctx.c
@@ -1052,6 +1052,16 @@ static int aie2_populate_range(struct amdxdna_gem_obj 
*abo)
        found = false;
        down_write(&xdna->notifier_lock);
        list_for_each_entry(mapp, &abo->mem.umap_list, node) {
+               /*
+                * Skip entries that have already been unmapped.
+                *
+                * If userspace unmaps the address and later submits I/O using
+                * it, the IOMMU will reject the access and report a fault.
+                * Ignore such entries here.
+                */
+               if (mapp->unmapped)
+                       continue;
+
                if (mapp->invalid && kref_get_unless_zero(&mapp->refcnt)) {
                        found = true;
                        break;
@@ -1059,6 +1069,12 @@ static int aie2_populate_range(struct amdxdna_gem_obj 
*abo)
        }
if (!found) {
+               /*
+                * This also covers the case where all mappings have been
+                * removed. There are no invalid mappings left to process.
+                * Any subsequent I/O using the unmapped address will be
+                * rejected by the IOMMU.
+                */
                abo->mem.map_invalid = false;
                up_write(&xdna->notifier_lock);
                return 0;

Reply via email to