1 /*
2  * Copyright (C) 2008 Ben Skeggs.
3  * All Rights Reserved.
4  *
5  * Permission is hereby granted, free of charge, to any person obtaining
6  * a copy of this software and associated documentation files (the
7  * "Software"), to deal in the Software without restriction, including
8  * without limitation the rights to use, copy, modify, merge, publish,
9  * distribute, sublicense, and/or sell copies of the Software, and to
10  * permit persons to whom the Software is furnished to do so, subject to
11  * the following conditions:
12  *
13  * The above copyright notice and this permission notice (including the
14  * next paragraph) shall be included in all copies or substantial
15  * portions of the Software.
16  *
17  * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
18  * EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF
19  * MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT.
20  * IN NO EVENT SHALL THE COPYRIGHT OWNER(S) AND/OR ITS SUPPLIERS BE
21  * LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
22  * OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION
23  * WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
24  *
25  */
26 #include "drmP.h"
27 #include "drm.h"
28 
29 #include "nouveau_drv.h"
30 #include "nouveau_drm.h"
31 #include "nouveau_dma.h"
32 
33 #define nouveau_gem_pushbuf_sync(chan) 0
34 
35 int
nouveau_gem_object_new(struct drm_gem_object * gem)36 nouveau_gem_object_new(struct drm_gem_object *gem)
37 {
38 	return 0;
39 }
40 
41 void
nouveau_gem_object_del(struct drm_gem_object * gem)42 nouveau_gem_object_del(struct drm_gem_object *gem)
43 {
44 	struct nouveau_bo *nvbo = gem->driver_private;
45 	struct ttm_buffer_object *bo = &nvbo->bo;
46 
47 	if (!nvbo)
48 		return;
49 	nvbo->gem = NULL;
50 
51 	if (unlikely(nvbo->pin_refcnt)) {
52 		nvbo->pin_refcnt = 1;
53 		nouveau_bo_unpin(nvbo);
54 	}
55 
56 	ttm_bo_unref(&bo);
57 
58 	drm_gem_object_release(gem);
59 	kfree(gem);
60 }
61 
62 int
nouveau_gem_object_open(struct drm_gem_object * gem,struct drm_file * file_priv)63 nouveau_gem_object_open(struct drm_gem_object *gem, struct drm_file *file_priv)
64 {
65 	struct nouveau_fpriv *fpriv = nouveau_fpriv(file_priv);
66 	struct nouveau_bo *nvbo = nouveau_gem_object(gem);
67 	struct nouveau_vma *vma;
68 	int ret;
69 
70 	if (!fpriv->vm)
71 		return 0;
72 
73 	ret = ttm_bo_reserve(&nvbo->bo, false, false, false, 0);
74 	if (ret)
75 		return ret;
76 
77 	vma = nouveau_bo_vma_find(nvbo, fpriv->vm);
78 	if (!vma) {
79 		vma = kzalloc(sizeof(*vma), GFP_KERNEL);
80 		if (!vma) {
81 			ret = -ENOMEM;
82 			goto out;
83 		}
84 
85 		ret = nouveau_bo_vma_add(nvbo, fpriv->vm, vma);
86 		if (ret) {
87 			kfree(vma);
88 			goto out;
89 		}
90 	} else {
91 		vma->refcount++;
92 	}
93 
94 out:
95 	ttm_bo_unreserve(&nvbo->bo);
96 	return ret;
97 }
98 
99 void
nouveau_gem_object_close(struct drm_gem_object * gem,struct drm_file * file_priv)100 nouveau_gem_object_close(struct drm_gem_object *gem, struct drm_file *file_priv)
101 {
102 	struct nouveau_fpriv *fpriv = nouveau_fpriv(file_priv);
103 	struct nouveau_bo *nvbo = nouveau_gem_object(gem);
104 	struct nouveau_vma *vma;
105 	int ret;
106 
107 	if (!fpriv->vm)
108 		return;
109 
110 	ret = ttm_bo_reserve(&nvbo->bo, false, false, false, 0);
111 	if (ret)
112 		return;
113 
114 	vma = nouveau_bo_vma_find(nvbo, fpriv->vm);
115 	if (vma) {
116 		if (--vma->refcount == 0) {
117 			nouveau_bo_vma_del(nvbo, vma);
118 			kfree(vma);
119 		}
120 	}
121 	ttm_bo_unreserve(&nvbo->bo);
122 }
123 
124 int
nouveau_gem_new(struct drm_device * dev,int size,int align,uint32_t domain,uint32_t tile_mode,uint32_t tile_flags,struct nouveau_bo ** pnvbo)125 nouveau_gem_new(struct drm_device *dev, int size, int align, uint32_t domain,
126 		uint32_t tile_mode, uint32_t tile_flags,
127 		struct nouveau_bo **pnvbo)
128 {
129 	struct drm_nouveau_private *dev_priv = dev->dev_private;
130 	struct nouveau_bo *nvbo;
131 	u32 flags = 0;
132 	int ret;
133 
134 	if (domain & NOUVEAU_GEM_DOMAIN_VRAM)
135 		flags |= TTM_PL_FLAG_VRAM;
136 	if (domain & NOUVEAU_GEM_DOMAIN_GART)
137 		flags |= TTM_PL_FLAG_TT;
138 	if (!flags || domain & NOUVEAU_GEM_DOMAIN_CPU)
139 		flags |= TTM_PL_FLAG_SYSTEM;
140 
141 	ret = nouveau_bo_new(dev, size, align, flags, tile_mode,
142 			     tile_flags, pnvbo);
143 	if (ret)
144 		return ret;
145 	nvbo = *pnvbo;
146 
147 	/* we restrict allowed domains on nv50+ to only the types
148 	 * that were requested at creation time.  not possibly on
149 	 * earlier chips without busting the ABI.
150 	 */
151 	nvbo->valid_domains = NOUVEAU_GEM_DOMAIN_VRAM |
152 			      NOUVEAU_GEM_DOMAIN_GART;
153 	if (dev_priv->card_type >= NV_50)
154 		nvbo->valid_domains &= domain;
155 
156 	nvbo->gem = drm_gem_object_alloc(dev, nvbo->bo.mem.size);
157 	if (!nvbo->gem) {
158 		nouveau_bo_ref(NULL, pnvbo);
159 		return -ENOMEM;
160 	}
161 
162 	nvbo->bo.persistent_swap_storage = nvbo->gem->filp;
163 	nvbo->gem->driver_private = nvbo;
164 	return 0;
165 }
166 
167 static int
nouveau_gem_info(struct drm_file * file_priv,struct drm_gem_object * gem,struct drm_nouveau_gem_info * rep)168 nouveau_gem_info(struct drm_file *file_priv, struct drm_gem_object *gem,
169 		 struct drm_nouveau_gem_info *rep)
170 {
171 	struct nouveau_fpriv *fpriv = nouveau_fpriv(file_priv);
172 	struct nouveau_bo *nvbo = nouveau_gem_object(gem);
173 	struct nouveau_vma *vma;
174 
175 	if (nvbo->bo.mem.mem_type == TTM_PL_TT)
176 		rep->domain = NOUVEAU_GEM_DOMAIN_GART;
177 	else
178 		rep->domain = NOUVEAU_GEM_DOMAIN_VRAM;
179 
180 	rep->offset = nvbo->bo.offset;
181 	if (fpriv->vm) {
182 		vma = nouveau_bo_vma_find(nvbo, fpriv->vm);
183 		if (!vma)
184 			return -EINVAL;
185 
186 		rep->offset = vma->offset;
187 	}
188 
189 	rep->size = nvbo->bo.mem.num_pages << PAGE_SHIFT;
190 	rep->map_handle = nvbo->bo.addr_space_offset;
191 	rep->tile_mode = nvbo->tile_mode;
192 	rep->tile_flags = nvbo->tile_flags;
193 	return 0;
194 }
195 
196 int
nouveau_gem_ioctl_new(struct drm_device * dev,void * data,struct drm_file * file_priv)197 nouveau_gem_ioctl_new(struct drm_device *dev, void *data,
198 		      struct drm_file *file_priv)
199 {
200 	struct drm_nouveau_private *dev_priv = dev->dev_private;
201 	struct drm_nouveau_gem_new *req = data;
202 	struct nouveau_bo *nvbo = NULL;
203 	int ret = 0;
204 
205 	if (unlikely(dev_priv->ttm.bdev.dev_mapping == NULL))
206 		dev_priv->ttm.bdev.dev_mapping = dev_priv->dev->dev_mapping;
207 
208 	if (!dev_priv->engine.vram.flags_valid(dev, req->info.tile_flags)) {
209 		NV_ERROR(dev, "bad page flags: 0x%08x\n", req->info.tile_flags);
210 		return -EINVAL;
211 	}
212 
213 	ret = nouveau_gem_new(dev, req->info.size, req->align,
214 			      req->info.domain, req->info.tile_mode,
215 			      req->info.tile_flags, &nvbo);
216 	if (ret)
217 		return ret;
218 
219 	ret = drm_gem_handle_create(file_priv, nvbo->gem, &req->info.handle);
220 	if (ret == 0) {
221 		ret = nouveau_gem_info(file_priv, nvbo->gem, &req->info);
222 		if (ret)
223 			drm_gem_handle_delete(file_priv, req->info.handle);
224 	}
225 
226 	/* drop reference from allocate - handle holds it now */
227 	drm_gem_object_unreference_unlocked(nvbo->gem);
228 	return ret;
229 }
230 
231 static int
nouveau_gem_set_domain(struct drm_gem_object * gem,uint32_t read_domains,uint32_t write_domains,uint32_t valid_domains)232 nouveau_gem_set_domain(struct drm_gem_object *gem, uint32_t read_domains,
233 		       uint32_t write_domains, uint32_t valid_domains)
234 {
235 	struct nouveau_bo *nvbo = gem->driver_private;
236 	struct ttm_buffer_object *bo = &nvbo->bo;
237 	uint32_t domains = valid_domains & nvbo->valid_domains &
238 		(write_domains ? write_domains : read_domains);
239 	uint32_t pref_flags = 0, valid_flags = 0;
240 
241 	if (!domains)
242 		return -EINVAL;
243 
244 	if (valid_domains & NOUVEAU_GEM_DOMAIN_VRAM)
245 		valid_flags |= TTM_PL_FLAG_VRAM;
246 
247 	if (valid_domains & NOUVEAU_GEM_DOMAIN_GART)
248 		valid_flags |= TTM_PL_FLAG_TT;
249 
250 	if ((domains & NOUVEAU_GEM_DOMAIN_VRAM) &&
251 	    bo->mem.mem_type == TTM_PL_VRAM)
252 		pref_flags |= TTM_PL_FLAG_VRAM;
253 
254 	else if ((domains & NOUVEAU_GEM_DOMAIN_GART) &&
255 		 bo->mem.mem_type == TTM_PL_TT)
256 		pref_flags |= TTM_PL_FLAG_TT;
257 
258 	else if (domains & NOUVEAU_GEM_DOMAIN_VRAM)
259 		pref_flags |= TTM_PL_FLAG_VRAM;
260 
261 	else
262 		pref_flags |= TTM_PL_FLAG_TT;
263 
264 	nouveau_bo_placement_set(nvbo, pref_flags, valid_flags);
265 
266 	return 0;
267 }
268 
269 struct validate_op {
270 	struct list_head vram_list;
271 	struct list_head gart_list;
272 	struct list_head both_list;
273 };
274 
275 static void
validate_fini_list(struct list_head * list,struct nouveau_fence * fence)276 validate_fini_list(struct list_head *list, struct nouveau_fence *fence)
277 {
278 	struct list_head *entry, *tmp;
279 	struct nouveau_bo *nvbo;
280 
281 	list_for_each_safe(entry, tmp, list) {
282 		nvbo = list_entry(entry, struct nouveau_bo, entry);
283 
284 		if (likely(fence))
285 			nouveau_bo_fence(nvbo, fence);
286 
287 		if (unlikely(nvbo->validate_mapped)) {
288 			ttm_bo_kunmap(&nvbo->kmap);
289 			nvbo->validate_mapped = false;
290 		}
291 
292 		list_del(&nvbo->entry);
293 		nvbo->reserved_by = NULL;
294 		ttm_bo_unreserve(&nvbo->bo);
295 		drm_gem_object_unreference_unlocked(nvbo->gem);
296 	}
297 }
298 
299 static void
validate_fini(struct validate_op * op,struct nouveau_fence * fence)300 validate_fini(struct validate_op *op, struct nouveau_fence* fence)
301 {
302 	validate_fini_list(&op->vram_list, fence);
303 	validate_fini_list(&op->gart_list, fence);
304 	validate_fini_list(&op->both_list, fence);
305 }
306 
307 static int
validate_init(struct nouveau_channel * chan,struct drm_file * file_priv,struct drm_nouveau_gem_pushbuf_bo * pbbo,int nr_buffers,struct validate_op * op)308 validate_init(struct nouveau_channel *chan, struct drm_file *file_priv,
309 	      struct drm_nouveau_gem_pushbuf_bo *pbbo,
310 	      int nr_buffers, struct validate_op *op)
311 {
312 	struct drm_device *dev = chan->dev;
313 	struct drm_nouveau_private *dev_priv = dev->dev_private;
314 	uint32_t sequence;
315 	int trycnt = 0;
316 	int ret, i;
317 
318 	sequence = atomic_add_return(1, &dev_priv->ttm.validate_sequence);
319 retry:
320 	if (++trycnt > 100000) {
321 		NV_ERROR(dev, "%s failed and gave up.\n", __func__);
322 		return -EINVAL;
323 	}
324 
325 	for (i = 0; i < nr_buffers; i++) {
326 		struct drm_nouveau_gem_pushbuf_bo *b = &pbbo[i];
327 		struct drm_gem_object *gem;
328 		struct nouveau_bo *nvbo;
329 
330 		gem = drm_gem_object_lookup(dev, file_priv, b->handle);
331 		if (!gem) {
332 			NV_ERROR(dev, "Unknown handle 0x%08x\n", b->handle);
333 			validate_fini(op, NULL);
334 			return -ENOENT;
335 		}
336 		nvbo = gem->driver_private;
337 
338 		if (nvbo->reserved_by && nvbo->reserved_by == file_priv) {
339 			NV_ERROR(dev, "multiple instances of buffer %d on "
340 				      "validation list\n", b->handle);
341 			validate_fini(op, NULL);
342 			return -EINVAL;
343 		}
344 
345 		ret = ttm_bo_reserve(&nvbo->bo, true, false, true, sequence);
346 		if (ret) {
347 			validate_fini(op, NULL);
348 			if (unlikely(ret == -EAGAIN))
349 				ret = ttm_bo_wait_unreserved(&nvbo->bo, true);
350 			drm_gem_object_unreference_unlocked(gem);
351 			if (unlikely(ret)) {
352 				if (ret != -ERESTARTSYS)
353 					NV_ERROR(dev, "fail reserve\n");
354 				return ret;
355 			}
356 			goto retry;
357 		}
358 
359 		b->user_priv = (uint64_t)(unsigned long)nvbo;
360 		nvbo->reserved_by = file_priv;
361 		nvbo->pbbo_index = i;
362 		if ((b->valid_domains & NOUVEAU_GEM_DOMAIN_VRAM) &&
363 		    (b->valid_domains & NOUVEAU_GEM_DOMAIN_GART))
364 			list_add_tail(&nvbo->entry, &op->both_list);
365 		else
366 		if (b->valid_domains & NOUVEAU_GEM_DOMAIN_VRAM)
367 			list_add_tail(&nvbo->entry, &op->vram_list);
368 		else
369 		if (b->valid_domains & NOUVEAU_GEM_DOMAIN_GART)
370 			list_add_tail(&nvbo->entry, &op->gart_list);
371 		else {
372 			NV_ERROR(dev, "invalid valid domains: 0x%08x\n",
373 				 b->valid_domains);
374 			list_add_tail(&nvbo->entry, &op->both_list);
375 			validate_fini(op, NULL);
376 			return -EINVAL;
377 		}
378 	}
379 
380 	return 0;
381 }
382 
383 static int
validate_sync(struct nouveau_channel * chan,struct nouveau_bo * nvbo)384 validate_sync(struct nouveau_channel *chan, struct nouveau_bo *nvbo)
385 {
386 	struct nouveau_fence *fence = NULL;
387 	int ret = 0;
388 
389 	spin_lock(&nvbo->bo.bdev->fence_lock);
390 	if (nvbo->bo.sync_obj)
391 		fence = nouveau_fence_ref(nvbo->bo.sync_obj);
392 	spin_unlock(&nvbo->bo.bdev->fence_lock);
393 
394 	if (fence) {
395 		ret = nouveau_fence_sync(fence, chan);
396 		nouveau_fence_unref(&fence);
397 	}
398 
399 	return ret;
400 }
401 
402 static int
validate_list(struct nouveau_channel * chan,struct list_head * list,struct drm_nouveau_gem_pushbuf_bo * pbbo,uint64_t user_pbbo_ptr)403 validate_list(struct nouveau_channel *chan, struct list_head *list,
404 	      struct drm_nouveau_gem_pushbuf_bo *pbbo, uint64_t user_pbbo_ptr)
405 {
406 	struct drm_nouveau_private *dev_priv = chan->dev->dev_private;
407 	struct drm_nouveau_gem_pushbuf_bo __user *upbbo =
408 				(void __force __user *)(uintptr_t)user_pbbo_ptr;
409 	struct drm_device *dev = chan->dev;
410 	struct nouveau_bo *nvbo;
411 	int ret, relocs = 0;
412 
413 	list_for_each_entry(nvbo, list, entry) {
414 		struct drm_nouveau_gem_pushbuf_bo *b = &pbbo[nvbo->pbbo_index];
415 
416 		ret = validate_sync(chan, nvbo);
417 		if (unlikely(ret)) {
418 			NV_ERROR(dev, "fail pre-validate sync\n");
419 			return ret;
420 		}
421 
422 		ret = nouveau_gem_set_domain(nvbo->gem, b->read_domains,
423 					     b->write_domains,
424 					     b->valid_domains);
425 		if (unlikely(ret)) {
426 			NV_ERROR(dev, "fail set_domain\n");
427 			return ret;
428 		}
429 
430 		ret = nouveau_bo_validate(nvbo, true, false, false);
431 		if (unlikely(ret)) {
432 			if (ret != -ERESTARTSYS)
433 				NV_ERROR(dev, "fail ttm_validate\n");
434 			return ret;
435 		}
436 
437 		ret = validate_sync(chan, nvbo);
438 		if (unlikely(ret)) {
439 			NV_ERROR(dev, "fail post-validate sync\n");
440 			return ret;
441 		}
442 
443 		if (dev_priv->card_type < NV_50) {
444 			if (nvbo->bo.offset == b->presumed.offset &&
445 			    ((nvbo->bo.mem.mem_type == TTM_PL_VRAM &&
446 			      b->presumed.domain & NOUVEAU_GEM_DOMAIN_VRAM) ||
447 			     (nvbo->bo.mem.mem_type == TTM_PL_TT &&
448 			      b->presumed.domain & NOUVEAU_GEM_DOMAIN_GART)))
449 				continue;
450 
451 			if (nvbo->bo.mem.mem_type == TTM_PL_TT)
452 				b->presumed.domain = NOUVEAU_GEM_DOMAIN_GART;
453 			else
454 				b->presumed.domain = NOUVEAU_GEM_DOMAIN_VRAM;
455 			b->presumed.offset = nvbo->bo.offset;
456 			b->presumed.valid = 0;
457 			relocs++;
458 
459 			if (DRM_COPY_TO_USER(&upbbo[nvbo->pbbo_index].presumed,
460 					     &b->presumed, sizeof(b->presumed)))
461 				return -EFAULT;
462 		}
463 	}
464 
465 	return relocs;
466 }
467 
468 static int
nouveau_gem_pushbuf_validate(struct nouveau_channel * chan,struct drm_file * file_priv,struct drm_nouveau_gem_pushbuf_bo * pbbo,uint64_t user_buffers,int nr_buffers,struct validate_op * op,int * apply_relocs)469 nouveau_gem_pushbuf_validate(struct nouveau_channel *chan,
470 			     struct drm_file *file_priv,
471 			     struct drm_nouveau_gem_pushbuf_bo *pbbo,
472 			     uint64_t user_buffers, int nr_buffers,
473 			     struct validate_op *op, int *apply_relocs)
474 {
475 	struct drm_device *dev = chan->dev;
476 	int ret, relocs = 0;
477 
478 	INIT_LIST_HEAD(&op->vram_list);
479 	INIT_LIST_HEAD(&op->gart_list);
480 	INIT_LIST_HEAD(&op->both_list);
481 
482 	if (nr_buffers == 0)
483 		return 0;
484 
485 	ret = validate_init(chan, file_priv, pbbo, nr_buffers, op);
486 	if (unlikely(ret)) {
487 		if (ret != -ERESTARTSYS)
488 			NV_ERROR(dev, "validate_init\n");
489 		return ret;
490 	}
491 
492 	ret = validate_list(chan, &op->vram_list, pbbo, user_buffers);
493 	if (unlikely(ret < 0)) {
494 		if (ret != -ERESTARTSYS)
495 			NV_ERROR(dev, "validate vram_list\n");
496 		validate_fini(op, NULL);
497 		return ret;
498 	}
499 	relocs += ret;
500 
501 	ret = validate_list(chan, &op->gart_list, pbbo, user_buffers);
502 	if (unlikely(ret < 0)) {
503 		if (ret != -ERESTARTSYS)
504 			NV_ERROR(dev, "validate gart_list\n");
505 		validate_fini(op, NULL);
506 		return ret;
507 	}
508 	relocs += ret;
509 
510 	ret = validate_list(chan, &op->both_list, pbbo, user_buffers);
511 	if (unlikely(ret < 0)) {
512 		if (ret != -ERESTARTSYS)
513 			NV_ERROR(dev, "validate both_list\n");
514 		validate_fini(op, NULL);
515 		return ret;
516 	}
517 	relocs += ret;
518 
519 	*apply_relocs = relocs;
520 	return 0;
521 }
522 
523 static inline void *
u_memcpya(uint64_t user,unsigned nmemb,unsigned size)524 u_memcpya(uint64_t user, unsigned nmemb, unsigned size)
525 {
526 	void *mem;
527 	void __user *userptr = (void __force __user *)(uintptr_t)user;
528 
529 	mem = kmalloc(nmemb * size, GFP_KERNEL);
530 	if (!mem)
531 		return ERR_PTR(-ENOMEM);
532 
533 	if (DRM_COPY_FROM_USER(mem, userptr, nmemb * size)) {
534 		kfree(mem);
535 		return ERR_PTR(-EFAULT);
536 	}
537 
538 	return mem;
539 }
540 
541 static int
nouveau_gem_pushbuf_reloc_apply(struct drm_device * dev,struct drm_nouveau_gem_pushbuf * req,struct drm_nouveau_gem_pushbuf_bo * bo)542 nouveau_gem_pushbuf_reloc_apply(struct drm_device *dev,
543 				struct drm_nouveau_gem_pushbuf *req,
544 				struct drm_nouveau_gem_pushbuf_bo *bo)
545 {
546 	struct drm_nouveau_gem_pushbuf_reloc *reloc = NULL;
547 	int ret = 0;
548 	unsigned i;
549 
550 	reloc = u_memcpya(req->relocs, req->nr_relocs, sizeof(*reloc));
551 	if (IS_ERR(reloc))
552 		return PTR_ERR(reloc);
553 
554 	for (i = 0; i < req->nr_relocs; i++) {
555 		struct drm_nouveau_gem_pushbuf_reloc *r = &reloc[i];
556 		struct drm_nouveau_gem_pushbuf_bo *b;
557 		struct nouveau_bo *nvbo;
558 		uint32_t data;
559 
560 		if (unlikely(r->bo_index > req->nr_buffers)) {
561 			NV_ERROR(dev, "reloc bo index invalid\n");
562 			ret = -EINVAL;
563 			break;
564 		}
565 
566 		b = &bo[r->bo_index];
567 		if (b->presumed.valid)
568 			continue;
569 
570 		if (unlikely(r->reloc_bo_index > req->nr_buffers)) {
571 			NV_ERROR(dev, "reloc container bo index invalid\n");
572 			ret = -EINVAL;
573 			break;
574 		}
575 		nvbo = (void *)(unsigned long)bo[r->reloc_bo_index].user_priv;
576 
577 		if (unlikely(r->reloc_bo_offset + 4 >
578 			     nvbo->bo.mem.num_pages << PAGE_SHIFT)) {
579 			NV_ERROR(dev, "reloc outside of bo\n");
580 			ret = -EINVAL;
581 			break;
582 		}
583 
584 		if (!nvbo->kmap.virtual) {
585 			ret = ttm_bo_kmap(&nvbo->bo, 0, nvbo->bo.mem.num_pages,
586 					  &nvbo->kmap);
587 			if (ret) {
588 				NV_ERROR(dev, "failed kmap for reloc\n");
589 				break;
590 			}
591 			nvbo->validate_mapped = true;
592 		}
593 
594 		if (r->flags & NOUVEAU_GEM_RELOC_LOW)
595 			data = b->presumed.offset + r->data;
596 		else
597 		if (r->flags & NOUVEAU_GEM_RELOC_HIGH)
598 			data = (b->presumed.offset + r->data) >> 32;
599 		else
600 			data = r->data;
601 
602 		if (r->flags & NOUVEAU_GEM_RELOC_OR) {
603 			if (b->presumed.domain == NOUVEAU_GEM_DOMAIN_GART)
604 				data |= r->tor;
605 			else
606 				data |= r->vor;
607 		}
608 
609 		spin_lock(&nvbo->bo.bdev->fence_lock);
610 		ret = ttm_bo_wait(&nvbo->bo, false, false, false);
611 		spin_unlock(&nvbo->bo.bdev->fence_lock);
612 		if (ret) {
613 			NV_ERROR(dev, "reloc wait_idle failed: %d\n", ret);
614 			break;
615 		}
616 
617 		nouveau_bo_wr32(nvbo, r->reloc_bo_offset >> 2, data);
618 	}
619 
620 	kfree(reloc);
621 	return ret;
622 }
623 
624 int
nouveau_gem_ioctl_pushbuf(struct drm_device * dev,void * data,struct drm_file * file_priv)625 nouveau_gem_ioctl_pushbuf(struct drm_device *dev, void *data,
626 			  struct drm_file *file_priv)
627 {
628 	struct drm_nouveau_private *dev_priv = dev->dev_private;
629 	struct drm_nouveau_gem_pushbuf *req = data;
630 	struct drm_nouveau_gem_pushbuf_push *push;
631 	struct drm_nouveau_gem_pushbuf_bo *bo;
632 	struct nouveau_channel *chan;
633 	struct validate_op op;
634 	struct nouveau_fence *fence = NULL;
635 	int i, j, ret = 0, do_reloc = 0;
636 
637 	chan = nouveau_channel_get(file_priv, req->channel);
638 	if (IS_ERR(chan))
639 		return PTR_ERR(chan);
640 
641 	req->vram_available = dev_priv->fb_aper_free;
642 	req->gart_available = dev_priv->gart_info.aper_free;
643 	if (unlikely(req->nr_push == 0))
644 		goto out_next;
645 
646 	if (unlikely(req->nr_push > NOUVEAU_GEM_MAX_PUSH)) {
647 		NV_ERROR(dev, "pushbuf push count exceeds limit: %d max %d\n",
648 			 req->nr_push, NOUVEAU_GEM_MAX_PUSH);
649 		nouveau_channel_put(&chan);
650 		return -EINVAL;
651 	}
652 
653 	if (unlikely(req->nr_buffers > NOUVEAU_GEM_MAX_BUFFERS)) {
654 		NV_ERROR(dev, "pushbuf bo count exceeds limit: %d max %d\n",
655 			 req->nr_buffers, NOUVEAU_GEM_MAX_BUFFERS);
656 		nouveau_channel_put(&chan);
657 		return -EINVAL;
658 	}
659 
660 	if (unlikely(req->nr_relocs > NOUVEAU_GEM_MAX_RELOCS)) {
661 		NV_ERROR(dev, "pushbuf reloc count exceeds limit: %d max %d\n",
662 			 req->nr_relocs, NOUVEAU_GEM_MAX_RELOCS);
663 		nouveau_channel_put(&chan);
664 		return -EINVAL;
665 	}
666 
667 	push = u_memcpya(req->push, req->nr_push, sizeof(*push));
668 	if (IS_ERR(push)) {
669 		nouveau_channel_put(&chan);
670 		return PTR_ERR(push);
671 	}
672 
673 	bo = u_memcpya(req->buffers, req->nr_buffers, sizeof(*bo));
674 	if (IS_ERR(bo)) {
675 		kfree(push);
676 		nouveau_channel_put(&chan);
677 		return PTR_ERR(bo);
678 	}
679 
680 	/* Ensure all push buffers are on validate list */
681 	for (i = 0; i < req->nr_push; i++) {
682 		if (push[i].bo_index >= req->nr_buffers) {
683 			NV_ERROR(dev, "push %d buffer not in list\n", i);
684 			ret = -EINVAL;
685 			goto out_prevalid;
686 		}
687 	}
688 
689 	/* Validate buffer list */
690 	ret = nouveau_gem_pushbuf_validate(chan, file_priv, bo, req->buffers,
691 					   req->nr_buffers, &op, &do_reloc);
692 	if (ret) {
693 		if (ret != -ERESTARTSYS)
694 			NV_ERROR(dev, "validate: %d\n", ret);
695 		goto out_prevalid;
696 	}
697 
698 	/* Apply any relocations that are required */
699 	if (do_reloc) {
700 		ret = nouveau_gem_pushbuf_reloc_apply(dev, req, bo);
701 		if (ret) {
702 			NV_ERROR(dev, "reloc apply: %d\n", ret);
703 			goto out;
704 		}
705 	}
706 
707 	if (chan->dma.ib_max) {
708 		ret = nouveau_dma_wait(chan, req->nr_push + 1, 6);
709 		if (ret) {
710 			NV_INFO(dev, "nv50cal_space: %d\n", ret);
711 			goto out;
712 		}
713 
714 		for (i = 0; i < req->nr_push; i++) {
715 			struct nouveau_bo *nvbo = (void *)(unsigned long)
716 				bo[push[i].bo_index].user_priv;
717 
718 			nv50_dma_push(chan, nvbo, push[i].offset,
719 				      push[i].length);
720 		}
721 	} else
722 	if (dev_priv->chipset >= 0x25) {
723 		ret = RING_SPACE(chan, req->nr_push * 2);
724 		if (ret) {
725 			NV_ERROR(dev, "cal_space: %d\n", ret);
726 			goto out;
727 		}
728 
729 		for (i = 0; i < req->nr_push; i++) {
730 			struct nouveau_bo *nvbo = (void *)(unsigned long)
731 				bo[push[i].bo_index].user_priv;
732 			struct drm_mm_node *mem = nvbo->bo.mem.mm_node;
733 
734 			OUT_RING(chan, ((mem->start << PAGE_SHIFT) +
735 					push[i].offset) | 2);
736 			OUT_RING(chan, 0);
737 		}
738 	} else {
739 		ret = RING_SPACE(chan, req->nr_push * (2 + NOUVEAU_DMA_SKIPS));
740 		if (ret) {
741 			NV_ERROR(dev, "jmp_space: %d\n", ret);
742 			goto out;
743 		}
744 
745 		for (i = 0; i < req->nr_push; i++) {
746 			struct nouveau_bo *nvbo = (void *)(unsigned long)
747 				bo[push[i].bo_index].user_priv;
748 			struct drm_mm_node *mem = nvbo->bo.mem.mm_node;
749 			uint32_t cmd;
750 
751 			cmd = chan->pushbuf_base + ((chan->dma.cur + 2) << 2);
752 			cmd |= 0x20000000;
753 			if (unlikely(cmd != req->suffix0)) {
754 				if (!nvbo->kmap.virtual) {
755 					ret = ttm_bo_kmap(&nvbo->bo, 0,
756 							  nvbo->bo.mem.
757 							  num_pages,
758 							  &nvbo->kmap);
759 					if (ret) {
760 						WIND_RING(chan);
761 						goto out;
762 					}
763 					nvbo->validate_mapped = true;
764 				}
765 
766 				nouveau_bo_wr32(nvbo, (push[i].offset +
767 						push[i].length - 8) / 4, cmd);
768 			}
769 
770 			OUT_RING(chan, ((mem->start << PAGE_SHIFT) +
771 					push[i].offset) | 0x20000000);
772 			OUT_RING(chan, 0);
773 			for (j = 0; j < NOUVEAU_DMA_SKIPS; j++)
774 				OUT_RING(chan, 0);
775 		}
776 	}
777 
778 	ret = nouveau_fence_new(chan, &fence, true);
779 	if (ret) {
780 		NV_ERROR(dev, "error fencing pushbuf: %d\n", ret);
781 		WIND_RING(chan);
782 		goto out;
783 	}
784 
785 out:
786 	validate_fini(&op, fence);
787 	nouveau_fence_unref(&fence);
788 
789 out_prevalid:
790 	kfree(bo);
791 	kfree(push);
792 
793 out_next:
794 	if (chan->dma.ib_max) {
795 		req->suffix0 = 0x00000000;
796 		req->suffix1 = 0x00000000;
797 	} else
798 	if (dev_priv->chipset >= 0x25) {
799 		req->suffix0 = 0x00020000;
800 		req->suffix1 = 0x00000000;
801 	} else {
802 		req->suffix0 = 0x20000000 |
803 			      (chan->pushbuf_base + ((chan->dma.cur + 2) << 2));
804 		req->suffix1 = 0x00000000;
805 	}
806 
807 	nouveau_channel_put(&chan);
808 	return ret;
809 }
810 
811 static inline uint32_t
domain_to_ttm(struct nouveau_bo * nvbo,uint32_t domain)812 domain_to_ttm(struct nouveau_bo *nvbo, uint32_t domain)
813 {
814 	uint32_t flags = 0;
815 
816 	if (domain & NOUVEAU_GEM_DOMAIN_VRAM)
817 		flags |= TTM_PL_FLAG_VRAM;
818 	if (domain & NOUVEAU_GEM_DOMAIN_GART)
819 		flags |= TTM_PL_FLAG_TT;
820 
821 	return flags;
822 }
823 
824 int
nouveau_gem_ioctl_cpu_prep(struct drm_device * dev,void * data,struct drm_file * file_priv)825 nouveau_gem_ioctl_cpu_prep(struct drm_device *dev, void *data,
826 			   struct drm_file *file_priv)
827 {
828 	struct drm_nouveau_gem_cpu_prep *req = data;
829 	struct drm_gem_object *gem;
830 	struct nouveau_bo *nvbo;
831 	bool no_wait = !!(req->flags & NOUVEAU_GEM_CPU_PREP_NOWAIT);
832 	int ret = -EINVAL;
833 
834 	gem = drm_gem_object_lookup(dev, file_priv, req->handle);
835 	if (!gem)
836 		return -ENOENT;
837 	nvbo = nouveau_gem_object(gem);
838 
839 	spin_lock(&nvbo->bo.bdev->fence_lock);
840 	ret = ttm_bo_wait(&nvbo->bo, true, true, no_wait);
841 	spin_unlock(&nvbo->bo.bdev->fence_lock);
842 	drm_gem_object_unreference_unlocked(gem);
843 	return ret;
844 }
845 
846 int
nouveau_gem_ioctl_cpu_fini(struct drm_device * dev,void * data,struct drm_file * file_priv)847 nouveau_gem_ioctl_cpu_fini(struct drm_device *dev, void *data,
848 			   struct drm_file *file_priv)
849 {
850 	return 0;
851 }
852 
853 int
nouveau_gem_ioctl_info(struct drm_device * dev,void * data,struct drm_file * file_priv)854 nouveau_gem_ioctl_info(struct drm_device *dev, void *data,
855 		       struct drm_file *file_priv)
856 {
857 	struct drm_nouveau_gem_info *req = data;
858 	struct drm_gem_object *gem;
859 	int ret;
860 
861 	gem = drm_gem_object_lookup(dev, file_priv, req->handle);
862 	if (!gem)
863 		return -ENOENT;
864 
865 	ret = nouveau_gem_info(file_priv, gem, req);
866 	drm_gem_object_unreference_unlocked(gem);
867 	return ret;
868 }
869 
870