On Mon Sep 28, 2026 at 5:42 PM JST, Eliot Courtney wrote:
> Add a decoder for NVKV. This is for receiving messages from GSP for
> GMCAPI calls. The NVKV format essentially encodes a sequence of function
> calls f(key, index, value). This decoder reads an encoded stream and
> invokes a type implementing the new `Schema` and `Visit` trait. The
> `Visit` trait can either consume the value or not, which is useful for
> composing schemas. If a (key, index, value) is not consumed, error out
> depending on `UnknownKeyPolicy`. Whether ignoring unknown keys is ok or
> not is per each GMCAPI call.
>
> Add kunit tests for the decoder.
>
> Signed-off-by: Eliot Courtney <[email protected]>
> ---
> drivers/gpu/nova-core/gsp/nvkv.rs | 3 +
> drivers/gpu/nova-core/gsp/nvkv/decode.rs | 487
> +++++++++++++++++++++++++++++++
> 2 files changed, 490 insertions(+)
>
> diff --git a/drivers/gpu/nova-core/gsp/nvkv.rs
> b/drivers/gpu/nova-core/gsp/nvkv.rs
> index 0957dce92f96..10f7a16ffc23 100644
> --- a/drivers/gpu/nova-core/gsp/nvkv.rs
> +++ b/drivers/gpu/nova-core/gsp/nvkv.rs
> @@ -29,6 +29,9 @@
> mod encode;
> pub(crate) use encode::*;
>
> +mod decode;
> +pub(crate) use decode::*;
> +
> /// The allocator backing [`EncodedStream`].
> type StreamAllocator = KVmalloc;
>
> diff --git a/drivers/gpu/nova-core/gsp/nvkv/decode.rs
> b/drivers/gpu/nova-core/gsp/nvkv/decode.rs
> new file mode 100644
> index 000000000000..c4c24fe1108e
> --- /dev/null
> +++ b/drivers/gpu/nova-core/gsp/nvkv/decode.rs
> @@ -0,0 +1,487 @@
> +// SPDX-License-Identifier: GPL-2.0
> +// SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION &
> AFFILIATES. All rights reserved.
> +
> +#![cfg_attr(not(CONFIG_KUNIT), expect(dead_code))]
> +
> +use kernel::prelude::*;
> +
> +use crate::{
> + gsp::nvkv::{
> + Index,
> + KeyId,
> + Op,
> + Opcode, //
> + },
> + num, //
> +};
> +
> +/// A decoded NVKV value.
> +#[derive(Copy, Clone, Debug, PartialEq, Eq)]
> +pub(crate) enum DecoderValue<'a> {
> + Scalar32(u32),
> + Scalar64(u64),
> + Array8(&'a [u8]),
> + Array32(&'a [u32]),
> + Array64(&'a [u64]),
> +}
> +
> +/// Implements `TryFrom` from the given `DecoderValue` variant to the given
> type.
> +///
> +/// `TryFrom` is used by the `Schema` implementations in this file to
> convert from the
> +/// `DecoderValue`s into the types to store. Provide the implementations for
> basic types here.
nit: proper doclinks for referenced types (recurring problem throughout
the file).
> +macro_rules! impl_try_from_decoder_value {
> + ($ty:ty, $variant:ident) => {
> + impl<'a> TryFrom<DecoderValue<'a>> for $ty {
> + type Error = Error;
> +
> + fn try_from(value: DecoderValue<'a>) -> Result<Self> {
> + if let DecoderValue::$variant(v) = value {
> + Ok(v)
> + } else {
> + Err(EINVAL)
> + }
> + }
> + }
> + };
> +}
> +
> +impl_try_from_decoder_value!(u32, Scalar32);
> +impl_try_from_decoder_value!(u64, Scalar64);
> +impl_try_from_decoder_value!(&'a [u8], Array8);
> +impl_try_from_decoder_value!(&'a [u32], Array32);
> +impl_try_from_decoder_value!(&'a [u64], Array64);
> +
> +/// A visitor that consumes decoded NVKV and produces a `Target`.
> +pub(crate) trait Schema {
> + type Target;
> +
> + /// Returns an initializer that creates an empty schema in place.
> + ///
> + /// Use [`KBox::init`] for the heap or `stack_pin_init!` for the stack
> (if sure that the value
> + /// is small enough to fit).
> + fn init() -> impl Init<Self>
> + where
> + Self: Sized;
> +
> + /// Returns an initializer that makes the decoded `Target`.
> + ///
> + /// After the returned initializer runs, the schema should be empty
> again.
> + fn finish(&mut self) -> impl Init<Self::Target, Error> + '_;
> +}
> +
> +/// A visitor that consumes decoded NVKV from a stream.
Note that `Schema` is also defined as a "visitor that consumes decoded
NVKV", which makes things a bit confusing. I guess that's because both
traits implement different aspects of what a typical visitor does, but
clarifying their relationship (and the reason for splitting) would be
helpful.
> +///
> +/// A schema that doesn't need to borrow data from the stream can implement
> this for all `'data`
> +/// lifetimes, avoiding having to carry the lifetime parameter. A schema
> that borrows from the
> +/// stream directly should implements it for its own lifetime only.
> +pub(crate) trait Visit<'data> {
Should this be named `Visitor` instead of `Visit`? Trait names should be
nouns rather than verbs, and this would make the `Decoder::visit`
method's prototype read more clearly imho. If you intended to use
`Visit` as a noun, I don't think that works either since the `visit`
method is potentially called many times (so it is not a single visit).
> + /// Visits one decoded pair. Returns `Ok(true)` if the schema consumed
> it.
> + fn visit(&mut self, key: KeyId, index: Index, value:
> DecoderValue<'data>) -> Result<bool>;
> +}
> +
> +/// A read position in an NVKV stream.
> +struct Cursor<'a> {
> + data: &'a [u64],
> +}
> +
> +impl<'a> Cursor<'a> {
> + /// Creates a cursor at the start of `data`.
> + fn new(data: &'a [u64]) -> Self {
> + Self { data }
> + }
> +
> + /// Returns `true` if no `u64` values remain.
> + fn is_empty(&self) -> bool {
> + self.data.is_empty()
> + }
> +
> + /// Takes the next `u64`.
> + fn take_u64(&mut self) -> Result<u64> {
> + // PANIC: `take_u64s(1)` returns exactly one element on success.
> + Ok(self.take_u64s(1)?[0])
> + }
> +
> + /// Takes `count` bytes. If `count` is not a multiple of 8 (`u64` size),
> bytes are discarded up
> + /// to the next multiple.
> + fn take_u8s(&mut self, count: usize) -> Result<&'a [u8]> {
> + let values = self.take_u64s(count.div_ceil(8))?;
s/8/size_of::<u64>()
> + values.as_bytes().get(..count).ok_or(EINVAL)
> + }
> +
> + /// Takes `count` 32-bit values. If `count` is not a multiple of 2
> (`u64` size), bytes are
> + /// discarded up to the next multiple.
> + fn take_u32s(&mut self, count: usize) -> Result<&'a [u32]> {
> + let values = self.take_u64s(count.div_ceil(2))?;
... and maybe `size_of::<u64>() / size_of::<u32>()` here?
> + <[u32]>::ref_from_prefix_with_elems(values.as_bytes(), count)
> + .map(|(elems, _)| elems)
> + .map_err(|_| EINVAL)
> + }
> +
> + /// Takes `count` `u64` values, or fails with `EINVAL` if fewer remain.
> + fn take_u64s(&mut self, count: usize) -> Result<&'a [u64]> {
> + let (prefix, suffix) =
> self.data.split_at_checked(count).ok_or(EINVAL)?;
> + self.data = suffix;
> + Ok(prefix)
> + }
> +}
> +
> +/// A decoder for an NVKV stream.
> +pub(crate) struct Decoder<'a> {
> + data: &'a [u64],
> + policy: UnknownKeyPolicy,
> +}
> +
> +impl<'a> Decoder<'a> {
> + /// Creates a decoder for `data` that handles unknown keys per `policy`.
> + pub(crate) fn new(data: &'a [u64], policy: UnknownKeyPolicy) -> Self {
> + Self { data, policy }
> + }
> +
> + fn visit<S: Visit<'a>>(
Although private this method would benefit from having a short documentation.
> + &self,
> + schema: &mut S,
> + key: KeyId,
> + index: Index,
> + value: DecoderValue<'a>,
> + ) -> Result {
> + let consumed = schema.visit(key, index, value)?;
> + if !consumed && self.policy == UnknownKeyPolicy::Error {
> + Err(EINVAL)
> + } else {
> + Ok(())
> + }
> + }
> +
> + fn seq_key(base: KeyId, offset: usize) -> Result<KeyId> {
Same here.
> + base.checked_add(KeyId::try_from(offset)?).ok_or(EINVAL)
> + }
> +
> + /// Decodes every pair into `schema` and returns the result of
> [`Schema::finish`].
> + pub(crate) fn decode<'s, S: Schema + Visit<'a>>(
> + &self,
> + schema: &'s mut S,
> + ) -> Result<impl Init<S::Target, Error> + 's> {
> + let mut cursor = Cursor::new(self.data);
> + while !cursor.is_empty() {
> + let op: Op = cursor.take_u64()?.into();
> +
> + let key = op.key().into();
Tip: you should be able to declare the `key` field as follows
15:0 key => KeyId
... and obtain a `KeyId` directly, making the call to `into` unnecessary.
> + let index = op.index();
> + let op_value: u32 = op.value().into();
Same here with `u32`.
> + match op.opcode()? {
> + Opcode::Imm32 => {
> + self.visit(schema, key, index,
> DecoderValue::Scalar32(op_value))?;
> + }
> + Opcode::Seq32 => {
> + let values =
> cursor.take_u32s(num::u32_as_usize(op_value))?;
nit: let's use the `IntoSafeCast` trait instead since this code does not
run in const context.
> + for (i, &value) in values.iter().enumerate() {
> + let key = Self::seq_key(key, i)?;
> + self.visit(schema, key, index,
> DecoderValue::Scalar32(value))?;
> + }
> + }
> + Opcode::Seq64 => {
> + let values =
> cursor.take_u64s(num::u32_as_usize(op_value))?;
> + for (i, &value) in values.iter().enumerate() {
> + let key = Self::seq_key(key, i)?;
> + self.visit(schema, key, index,
> DecoderValue::Scalar64(value))?;
> + }
> + }
> + Opcode::Array8 => {
> + let value =
> cursor.take_u8s(num::u32_as_usize(op_value))?;
> + self.visit(schema, key, index,
> DecoderValue::Array8(value))?;
> + }
> + Opcode::Array32 => {
> + let value =
> cursor.take_u32s(num::u32_as_usize(op_value))?;
> + self.visit(schema, key, index,
> DecoderValue::Array32(value))?;
> + }
> + Opcode::Array64 => {
> + let value =
> cursor.take_u64s(num::u32_as_usize(op_value))?;
> + self.visit(schema, key, index,
> DecoderValue::Array64(value))?;
> + }
> + };
> + }
> + Ok(schema.finish())
> + }
> +}
> +
> +/// This is defined per call.
> +#[derive(Debug, Clone, Copy, PartialEq, Eq)]
> +pub(crate) enum UnknownKeyPolicy {
> + Ignore,
> + Error,
> +}
Documentation explaining the effect of each variant would be nice.
> +
> +#[kunit_tests(nova_core_nvkv_decode)]
> +mod tests {
> + use super::*;
> +
> + use crate::gsp::nvkv::Encoder;
> +
> + // Tests that basic decoding into a manually implemented `Schema` works
> correctly.
> + #[test]
> + fn decode_raw_schema() -> Result {
> + // Decodes an IMM32 pair and a SEQ64 pair (the encoder emits a u64
> as a single-element
> + // SEQ64) with a hand written `Schema`. Keys and value constants
> chosen to distinguish e.g.
> + // saving the wrong value to the wrong location.
> + const SCALAR32_KEY: KeyId = 0x1001;
> + const SCALAR64_KEY: KeyId = 0x1002;
> + const UNKNOWN_KEY: KeyId = 0x2001;
> +
> + const SCALAR32_VALUE: u32 = 0x1111_2222;
> + const SCALAR64_VALUE: u64 = 0x3333_4444_5555_6666;
> +
> + // The output type of the hand written `Schema`. In this case, we
> can have it also implement
> + // `Schema` on itself rather than having a separate carrier type,
> since the `Schema`
> + // implementation is completely stateless.
> + #[derive(Default)]
> + struct RawSchema {
> + scalar32: u32,
> + scalar64: u64,
> + }
> +
> + impl Schema for RawSchema {
> + type Target = Self;
> +
> + fn init() -> impl Init<Self> {
> + Self::default()
> + }
> +
> + fn finish(&mut self) -> impl Init<Self::Target, Error> + '_ {
> + Ok(core::mem::take(self))
> + }
> + }
> +
> + impl<'d> Visit<'d> for RawSchema {
> + fn visit(&mut self, key: KeyId, index: Index, value:
> DecoderValue<'d>) -> Result<bool> {
> + if index != Index::new::<0>() {
> + return Err(EINVAL);
> + }
> + match key {
> + SCALAR32_KEY => self.scalar32 = value.try_into()?,
> + SCALAR64_KEY => self.scalar64 = value.try_into()?,
> + _ => return Ok(false),
> + }
> + Ok(true)
> + }
> + }
> +
> + let mut encoder = Encoder::new();
> + encoder.encode_u32(SCALAR32_KEY, Index::new::<0>(), SCALAR32_VALUE)?;
> + encoder.encode_u64(SCALAR64_KEY, Index::new::<0>(), SCALAR64_VALUE)?;
> + let serialized = encoder.finish();
> +
> + let decoder = Decoder::new(&serialized, UnknownKeyPolicy::Error);
> + let mut schema = KBox::init(RawSchema::init(), GFP_KERNEL)?;
> + let decoded = KBox::try_init(decoder.decode(&mut *schema)?,
> GFP_KERNEL)?;
> +
> + assert_eq!(decoded.scalar32, SCALAR32_VALUE);
> + assert_eq!(decoded.scalar64, SCALAR64_VALUE);
Nice test!
> +
> + // An unknown key should fail with under `UnknownKeyPolicy::Error`
> and be skipped under
> + // `UnknownKeyPolicy::Ignore`.
> + let mut encoder = Encoder::new();
> + encoder.encode_u32(UNKNOWN_KEY, Index::new::<0>(), 1)?;
> +
> + let serialized = encoder.finish();
> + let decoder = Decoder::new(&serialized, UnknownKeyPolicy::Error);
> + let mut schema = KBox::init(RawSchema::init(), GFP_KERNEL)?;
> + assert!(decoder.decode(&mut *schema).is_err());
> +
> + let decoder = Decoder::new(&serialized, UnknownKeyPolicy::Ignore);
> + let mut schema = KBox::init(RawSchema::init(), GFP_KERNEL)?;
> + let decoded = KBox::try_init(decoder.decode(&mut *schema)?,
> GFP_KERNEL)?;
> + assert_eq!(decoded.scalar32, 0);
... this part looks like it should be its own test though. That's
trivial to achieve if you declare `RawSchema` at the module-level
instead of inside the method.
(also nit: let's assert `scalar64` as well, or none of the values at all
- I'd lean towards none since that part is already covered by the
regular decoding test).
> +
> + Ok(())
> + }
> +
> + /// Records each visit as (key, index, value), for tests on hand-built
> streams.
nit: `(key, index, value)`
> + #[derive(Default)]
> + struct Recorder<'d> {
> + visits: KVVec<(KeyId, u64, DecoderValue<'d>)>,
> + }
> +
> + impl<'d> Schema for Recorder<'d> {
> + type Target = KVVec<(KeyId, u64, DecoderValue<'d>)>;
> +
> + fn init() -> impl Init<Self> {
> + Self::default()
> + }
> +
> + fn finish(&mut self) -> impl Init<Self::Target, Error> + '_ {
> + Ok(core::mem::take(&mut self.visits))
> + }
> + }
> +
> + impl<'d> Visit<'d> for Recorder<'d> {
> + fn visit(&mut self, key: KeyId, index: Index, value:
> DecoderValue<'d>) -> Result<bool> {
> + self.visits.push((key, index.get(), value), GFP_KERNEL)?;
> + Ok(true)
> + }
> + }
> +
> + // Tests the decoder on hand-built `u64` values that the encoder does
> not produce: SEQ32,
> + // multi-value SEQ64, zero counts, a non-zero index and padded arrays.
> + #[test]
> + fn decode_raw_u64s() -> Result {
> + const SEQ32_KEY: KeyId = 0x2000;
> + const SEQ64_KEY: KeyId = 0x2010;
> + const EMPTY_SEQ64_KEY: KeyId = 0x2020;
> + const EMPTY_SEQ32_KEY: KeyId = 0x2021;
> + const EMPTY_ARRAY8_KEY: KeyId = 0x2030;
> + const EMPTY_ARRAY32_KEY: KeyId = 0x2031;
> + const EMPTY_ARRAY64_KEY: KeyId = 0x2032;
> + const ARRAY8_KEY: KeyId = 0x2040;
> + const ARRAY32_KEY: KeyId = 0x2041;
> +
> + let index3 = Index::new::<3>();
nit: variable only used once, can be created inline.
I really like how testing coverage has improved in this revision!