[PATCH 05/27] gpu: nova-core: zero-pad radix3 page table levels to page boundary
From: John Hubbard
Date: Tue Aug 18 2026 - 23:53:44 EST
GSP-RM allocates the whole radix3 page table region in one block and
zeroes it before writing entries. The booter reads each level a full
page at a time when it walks the table, so every byte of a level page is
firmware-visible whether or not it holds a valid entry.
The driver allocates each level separately and writes only the valid
entries, so the last page of each level is only partly written. The
booter reads the whole page regardless, and a non-zero word in the
unwritten remainder is indistinguishable from an entry.
Zero-pad each level to the next GSP_PAGE_SIZE boundary after writing
entries, and size each level buffer to that padded length so the pad
does not force a reallocation.
Assisted-by: Cursor:claude-opus-5
Signed-off-by: John Hubbard <jhubbard@xxxxxxxxxx>
---
drivers/gpu/nova-core/firmware/radix3.rs | 40 +++++++++++++++---------
1 file changed, 26 insertions(+), 14 deletions(-)
diff --git a/drivers/gpu/nova-core/firmware/radix3.rs b/drivers/gpu/nova-core/firmware/radix3.rs
index b60611c7bea0..f14ad4e82d3d 100644
--- a/drivers/gpu/nova-core/firmware/radix3.rs
+++ b/drivers/gpu/nova-core/firmware/radix3.rs
@@ -67,22 +67,18 @@ pub(crate) fn new<'a>(
Ok(try_pin_init!(Self {
data <- SGTable::new(dev, data, DataDirection::ToDevice, GFP_KERNEL),
level2 <- {
- VVec::<u8>::with_capacity(
- data.iter().count() * core::mem::size_of::<u64>(),
- GFP_KERNEL,
- )
- .map_err(|_| ENOMEM)
- .and_then(|level2| map_into_lvl(&data, level2))
- .map(|level2| SGTable::new(dev, level2, DataDirection::ToDevice, GFP_KERNEL))?
+ let level2 = VVec::<u8>::with_capacity(lvl_size(&data), GFP_KERNEL)
+ .map_err(|_| ENOMEM)
+ .and_then(|level2| map_into_lvl(&data, level2))?;
+
+ SGTable::new(dev, level2, DataDirection::ToDevice, GFP_KERNEL)
},
level1 <- {
- VVec::<u8>::with_capacity(
- level2.iter().count() * core::mem::size_of::<u64>(),
- GFP_KERNEL,
- )
- .map_err(|_| ENOMEM)
- .and_then(|level1| map_into_lvl(&level2, level1))
- .map(|level1| SGTable::new(dev, level1, DataDirection::ToDevice, GFP_KERNEL))?
+ let level1 = VVec::<u8>::with_capacity(lvl_size(&level2), GFP_KERNEL)
+ .map_err(|_| ENOMEM)
+ .and_then(|level1| map_into_lvl(&level2, level1))?;
+
+ SGTable::new(dev, level1, DataDirection::ToDevice, GFP_KERNEL)
},
level0: {
let level1_entry = level1.iter().next().ok_or(EINVAL)?;
@@ -113,6 +109,17 @@ pub(crate) fn size(&self) -> usize {
}
}
+/// Returns the size, in bytes, of the page table level that maps `sg_table`: one `u64` entry per
+/// 4KB page it spans, rounded up to the page boundary that [`map_into_lvl`] pads to.
+fn lvl_size(sg_table: &SGTable<Owned<VVec<u8>>>) -> usize {
+ let entries: usize = sg_table
+ .iter()
+ .map(|sg_entry| usize::from_safe_cast(sg_entry.dma_len()).div_ceil(GSP_PAGE_SIZE))
+ .sum();
+
+ (entries * size_of::<u64>()).next_multiple_of(GSP_PAGE_SIZE)
+}
+
/// Build a page table from a scatter-gather list.
///
/// Takes each DMA-mapped region from `sg_table` and writes page table entries
@@ -129,5 +136,10 @@ fn map_into_lvl(sg_table: &SGTable<Owned<VVec<u8>>>, mut dst: VVec<u8>) -> Resul
}
}
+ // The last page of a level is only partly filled, and the booter DMAs each level a
+ // whole page at a time, so no entry past the last valid one may hold a stale address.
+ let padded = dst.len().next_multiple_of(GSP_PAGE_SIZE);
+ dst.resize(padded, 0, GFP_KERNEL)?;
+
Ok(dst)
}
--
2.55.0