ttm_bo_vm_dummy_page() allocates a page and a managed cleanup action on every call. These allocations remain until the DRM device is released, so repeated fallback faults can retain many pages.
Keep one zeroed dummy page in each Xe BO and reuse it when device I/O is blocked or the device is unplugged. Use cmpxchg() to handle concurrent faults and free the page when the BO is destroyed. Map the faulting address first and return any error from that operation. Prefault the rest of the VMA as a best-effort optimization. A per-BO page also prevents writable mappings from different BOs from sharing data. Cc: Matthew Brost <[email protected]> Cc: Thomas Hellström <[email protected]> Cc: Himal Prasad Ghimiray <[email protected]> Cc: Rodrigo Vivi <[email protected]> Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Arvind Yadav <[email protected]> --- drivers/gpu/drm/xe/xe_bo.c | 51 +++++++++++++++++++++++++++++++- drivers/gpu/drm/xe/xe_bo_types.h | 4 +++ 2 files changed, 54 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/xe/xe_bo.c b/drivers/gpu/drm/xe/xe_bo.c index b86cd6030ed6..1f6ea9f5afe6 100644 --- a/drivers/gpu/drm/xe/xe_bo.c +++ b/drivers/gpu/drm/xe/xe_bo.c @@ -1876,6 +1876,9 @@ static void xe_ttm_bo_destroy(struct ttm_buffer_object *ttm_bo) list_del(&bo->vram_userfault_link); mutex_unlock(&xe->mem_access.vram_userfault.lock); + if (bo->wedged_dummy_page) + __free_page(bo->wedged_dummy_page); + kfree(bo); } @@ -2080,6 +2083,50 @@ static vm_fault_t xe_bo_cpu_fault_fastpath(struct vm_fault *vmf, struct xe_devic return ret; } +static vm_fault_t xe_bo_vm_dummy_page(struct vm_fault *vmf, struct xe_bo *bo) +{ + struct vm_area_struct *vma = vmf->vma; + struct page *page, *old; + unsigned long address; + unsigned long pfn; + vm_fault_t ret, prefault_ret; + + page = READ_ONCE(bo->wedged_dummy_page); + if (!page) { + page = alloc_page(GFP_KERNEL | __GFP_ZERO); + if (!page) + return VM_FAULT_OOM; + + old = cmpxchg(&bo->wedged_dummy_page, NULL, page); + if (old) { + __free_page(page); + page = old; + } + } + + pfn = page_to_pfn(page); + + /* The faulting address must be mapped successfully. */ + ret = vmf_insert_pfn_prot(vma, vmf->address, pfn, + vma->vm_page_prot); + if (ret & VM_FAULT_ERROR) + return ret; + + /* Prefault the remaining VMA as a best-effort optimization. */ + for (address = vma->vm_start; address < vma->vm_end; + address += PAGE_SIZE) { + if (address == vmf->address) + continue; + + prefault_ret = vmf_insert_pfn_prot(vma, address, pfn, + vma->vm_page_prot); + if (prefault_ret & VM_FAULT_ERROR) + break; + } + + return ret; +} + static vm_fault_t xe_bo_cpu_fault(struct vm_fault *vmf) { struct ttm_buffer_object *tbo = vmf->vma->vm_private_data; @@ -2095,7 +2142,7 @@ static vm_fault_t xe_bo_cpu_fault(struct vm_fault *vmf) int idx; if (xe_device_io_blocked(xe) || !drm_dev_enter(&xe->drm, &idx)) - return ttm_bo_vm_dummy_page(vmf, vmf->vma->vm_page_prot); + return xe_bo_vm_dummy_page(vmf, bo); ret = xe_bo_cpu_fault_fastpath(vmf, xe, bo, needs_rpm); if (ret != VM_FAULT_RETRY) @@ -2385,6 +2432,8 @@ struct xe_bo *xe_bo_init_locked(struct xe_device *xe, struct xe_bo *bo, return bo; } + bo->wedged_dummy_page = NULL; + bo->ccs_cleared = false; bo->tile = tile; bo->flags = flags; diff --git a/drivers/gpu/drm/xe/xe_bo_types.h b/drivers/gpu/drm/xe/xe_bo_types.h index e45f24301050..82ee171ea6de 100644 --- a/drivers/gpu/drm/xe/xe_bo_types.h +++ b/drivers/gpu/drm/xe/xe_bo_types.h @@ -20,6 +20,7 @@ struct xe_device; struct xe_mem_pool_node; struct xe_vm; +struct page; #define XE_BO_MAX_PLACEMENTS 3 @@ -106,6 +107,9 @@ struct xe_bo { /** @vram_userfault_link: Link into @mem_access.vram_userfault.list */ struct list_head vram_userfault_link; + /** @wedged_dummy_page: Zeroed page used for faults after device wedge */ + struct page *wedged_dummy_page; + /** * @min_align: minimum alignment needed for this BO if different * from default -- 2.43.0
