[PATCH v2 6/9] gpu: nova-core: gsp: cmdq: split the transport part of the receive path

From: Alexandre Courbot

Date: Sun Sep 27 2026 - 09:48:36 EST


`wait_for_msg` mixes two layers: the transport layer which polls the
queue, extracts the element header and validates the checksum, and the
RPC layer which reads the RPC header and trims the payload slices to the
length advertised by the RPC header.

Move the transport layer into `wait_for_element`, and introduce
`consume_element`, a transport-level method which runs a closure on the
next element before advancing the CPU read pointer past it, and
`parse_rpc_message`, which validates the RPC layer. This sets things up
for moving the RPC code into its own module, leaving the transport
agnostic of the message type.

Signed-off-by: Alexandre Courbot <acourbot@xxxxxxxxxx>
---
drivers/gpu/nova-core/gsp/cmdq.rs | 91 ++++++++++++++++++++++++++++-----------
1 file changed, 65 insertions(+), 26 deletions(-)

diff --git a/drivers/gpu/nova-core/gsp/cmdq.rs b/drivers/gpu/nova-core/gsp/cmdq.rs
index 640afe2e29cb..169ef0865339 100644
--- a/drivers/gpu/nova-core/gsp/cmdq.rs
+++ b/drivers/gpu/nova-core/gsp/cmdq.rs
@@ -411,7 +411,7 @@ struct GspCommand<'a> {

/// A message ready to be processed from the message queue.
///
-/// This is the type returned by [`CmdqInner::wait_for_msg`].
+/// This is the type returned by [`CmdqInner::wait_for_element`].
struct GspMessage<'a> {
// Reference to the header of the message.
header: &'a GspMsgElement,
@@ -566,7 +566,7 @@ fn send_command_element(
Ok(())
}

- /// Wait for a message to become available on the message queue.
+ /// Wait for the next element to become available on the message queue.
///
/// This works purely at the transport layer and does not interpret or validate the message
/// beyond the advertised length in its [`GspMsgElement`].
@@ -584,7 +584,7 @@ fn send_command_element(
/// message queue.
///
/// Error codes returned by the message constructor are propagated as-is.
- fn wait_for_msg(&self, timeout: Delta) -> Result<GspMessage<'_>> {
+ fn wait_for_element(&self, timeout: Delta) -> Result<GspMessage<'_>> {
// Wait for a message to arrive from the GSP.
let (slice_1, slice_2) = read_poll_timeout(
|| Ok(self.gsp_mem.driver_read_area()),
@@ -606,18 +606,65 @@ fn wait_for_msg(&self, timeout: Delta) -> Result<GspMessage<'_>> {
return Err(EIO);
}

+ Ok(GspMessage {
+ header,
+ contents: (slice_1, slice_2),
+ })
+ }
+
+ /// Wait for the next element on the message queue, pass it to `process_element`, and advances
+ /// the read pointer past it.
+ ///
+ /// The read pointer advances regardless of whether `process_element` succeeds or not.
+ ///
+ /// # Errors
+ ///
+ /// Errors from [`Self::wait_for_element`] and from `process_element` are propagated as-is.
+ fn consume_element<R>(
+ &mut self,
+ timeout: Delta,
+ process_element: impl FnOnce(GspMessage<'_>) -> Result<R>,
+ ) -> Result<R> {
+ let (elem_count, result) = {
+ let message = self.wait_for_element(timeout)?;
+
+ (
+ u32::try_from(message.header.length().div_ceil(GSP_PAGE_SIZE))?,
+ process_element(message),
+ )
+ };
+
+ self.gsp_mem.advance_cpu_read_ptr(elem_count);
+
+ result
+ }
+
+ /// Validate the RPC layer of `element` and trim its contents down to the RPC payload.
+ ///
+ /// # Errors
+ ///
+ /// - `EIO` if the element is shorter than the payload length advertised by the RPC header.
+ fn parse_rpc_message<'a>(
+ dev: &device::Device,
+ element: GspMessage<'a>,
+ ) -> Result<GspMessage<'a>> {
+ let GspMessage {
+ header,
+ contents: (slice_1, slice_2),
+ } = element;
+
let rpc_header = header.rpc_header();
let payload_length = rpc_header.length();

dev_dbg!(
- &self.dev,
+ dev,
"GSP RPC: receive: seq# {}, function={:?}, length=0x{:x}\n",
rpc_header.sequence(),
rpc_header.function(),
payload_length,
);

- // Check that the driver read area is large enough for the message.
+ // Check that the element is large enough for the message.
if slice_1.len() + slice_2.len() < payload_length {
return Err(EIO);
}
@@ -646,7 +693,8 @@ fn wait_for_msg(&self, timeout: Delta) -> Result<GspMessage<'_>> {
/// The expected message type is specified using the `M` generic parameter. If the pending
/// message has a different function code, `ERANGE` is returned and the message is consumed.
///
- /// The read pointer is always advanced past the message, regardless of whether it matched.
+ /// The read pointer is always advanced past the message, regardless of whether it matched or
+ /// could be parsed.
///
/// # Errors
///
@@ -662,12 +710,16 @@ fn receive_msg<M: MessageFromGsp>(&mut self, timeout: Delta) -> Result<M>
// This allows all error types, including `Infallible`, to be used for `M::InitError`.
Error: From<M::InitError>,
{
- let message = self.wait_for_msg(timeout)?;
- let function = message.header.rpc_header().function().map_err(|_| EINVAL)?;
+ let dev = self.dev;
+
+ self.consume_element(timeout, |element| {
+ let message = Self::parse_rpc_message(dev, element)?;
+ let function = message.header.rpc_header().function().map_err(|_| EINVAL)?;
+
+ if function != M::FUNCTION {
+ return Err(ERANGE);
+ }

- // Extract the message. Store the result as we want to advance the read pointer even in
- // case of failure.
- let result = if function == M::FUNCTION {
let (cmd, contents_1) = M::Message::from_bytes_prefix(message.contents.0).ok_or(EIO)?;
let mut sbuffer = SBufferIter::new_reader([contents_1, message.contents.1]);

@@ -675,22 +727,9 @@ fn receive_msg<M: MessageFromGsp>(&mut self, timeout: Delta) -> Result<M>
.map_err(|e| e.into())
.inspect(|_| {
if !sbuffer.is_empty() {
- dev_warn!(
- &self.dev,
- "GSP message {:?} has unprocessed data\n",
- function
- );
+ dev_warn!(dev, "GSP message {:?} has unprocessed data\n", function);
}
})
- } else {
- Err(ERANGE)
- };
-
- // Advance the read pointer past this message.
- self.gsp_mem.advance_cpu_read_ptr(u32::try_from(
- message.header.length().div_ceil(GSP_PAGE_SIZE),
- )?);
-
- result
+ })
}
}

--
2.55.0