[PATCH V2 11/20] accel/amdxdna: Decouple AIE4 doorbell and MSI-X notify transport hooks
From: David Zhang
Date: Tue Oct 06 2026 - 00:24:37 EST
Separate PCI-specific doorbell and interrupt notification handling from
the transport-neutral context code.
Note that new transport functions are wired in later patches in this
series. Neither NULL dereference nor BAR boundary bypass can occur
because doorbell ringing is not invoked until full context setup and BAR
validation are established.
Co-developed-by: Wendy Liang <wendy.liang@xxxxxxx>
Signed-off-by: Wendy Liang <wendy.liang@xxxxxxx>
Signed-off-by: David Zhang <yidong.zhang@xxxxxxx>
---
drivers/accel/amdxdna/aie4_ctx.c | 29 ++++---------
drivers/accel/amdxdna/aie4_pci.c | 66 +++++++++++++++++++++++++++++
drivers/accel/amdxdna/aie4_pci.h | 14 ++++++
drivers/accel/amdxdna/amdxdna_ctx.h | 2 +
4 files changed, 90 insertions(+), 21 deletions(-)
diff --git a/drivers/accel/amdxdna/aie4_ctx.c b/drivers/accel/amdxdna/aie4_ctx.c
index 5eb918e1d58c..5a2fc19bad20 100644
--- a/drivers/accel/amdxdna/aie4_ctx.c
+++ b/drivers/accel/amdxdna/aie4_ctx.c
@@ -22,18 +22,9 @@
#include "amdxdna_mailbox_helper.h"
#include "amdxdna_pci_drv.h"
-static irqreturn_t cert_comp_isr(int irq, void *p)
-{
- struct cert_comp *cert_comp = p;
-
- wake_up_all(&cert_comp->waitq);
- return IRQ_HANDLED;
-}
-
static struct cert_comp *aie4_lookup_cert_comp(struct amdxdna_dev_hdl *ndev, u32 msix_idx)
{
struct amdxdna_dev *xdna = ndev->aie.xdna;
- struct pci_dev *pdev = to_pci_dev(xdna->ddev.dev);
struct cert_comp *cert_comp;
int ret;
@@ -51,32 +42,27 @@ static struct cert_comp *aie4_lookup_cert_comp(struct amdxdna_dev_hdl *ndev, u32
cert_comp->ndev = ndev;
cert_comp->msix_idx = msix_idx;
+ cert_comp->irq = -ENOENT;
init_waitqueue_head(&cert_comp->waitq);
kref_init(&cert_comp->kref);
- ret = pci_irq_vector(pdev, cert_comp->msix_idx);
- if (ret < 0) {
- XDNA_ERR(xdna, "MSI-X idx %u is invalid, ret:%d", msix_idx, ret);
- goto free_cert_comp;
- }
- cert_comp->irq = ret;
-
- ret = request_irq(cert_comp->irq, cert_comp_isr, 0, "xdna_hsa", cert_comp);
+ /* Transport-specific: PCI wires an MSI-X irq, platform an IPI callback. */
+ ret = aie4_request_notification(cert_comp);
if (ret) {
- XDNA_ERR(xdna, "request irq %d failed %d", cert_comp->irq, ret);
+ XDNA_ERR(xdna, "request notification for msix idx %u failed %d", msix_idx, ret);
goto free_cert_comp;
}
ret = xa_err(xa_store(&ndev->cert_comp_xa, msix_idx, cert_comp, GFP_KERNEL));
if (ret) {
- XDNA_ERR(xdna, "store cert_comp for msix idx %d failed %d", msix_idx, ret);
+ XDNA_ERR(xdna, "store cert_comp for msix idx %u failed %d", msix_idx, ret);
goto free_irq;
}
return cert_comp;
free_irq:
- free_irq(cert_comp->irq, cert_comp);
+ aie4_free_notification(cert_comp);
free_cert_comp:
kfree(cert_comp);
return NULL;
@@ -90,7 +76,7 @@ static void cert_comp_release(struct kref *kref)
drm_WARN_ON(&ndev->aie.xdna->ddev, !mutex_is_locked(&ndev->cert_comp_lock));
xa_erase(&ndev->cert_comp_xa, cert_comp->msix_idx);
- free_irq(cert_comp->irq, cert_comp);
+ aie4_free_notification(cert_comp);
kfree(cert_comp);
}
@@ -100,6 +86,7 @@ static void aie4_put_cert_comp(struct cert_comp *cert_comp)
ndev = cert_comp->ndev;
guard(mutex)(&ndev->cert_comp_lock);
+
kref_put(&cert_comp->kref, cert_comp_release);
}
diff --git a/drivers/accel/amdxdna/aie4_pci.c b/drivers/accel/amdxdna/aie4_pci.c
index 4a5f30b42743..9d970d4da435 100644
--- a/drivers/accel/amdxdna/aie4_pci.c
+++ b/drivers/accel/amdxdna/aie4_pci.c
@@ -14,6 +14,7 @@
#include "aie.h"
#include "aie4_msg_priv.h"
+#include "amdxdna_ctx.h"
#include "aie4_pci.h"
#include "amdxdna_mailbox.h"
#include "amdxdna_mailbox_helper.h"
@@ -110,6 +111,69 @@ static void aie4_mailbox_fini(struct amdxdna_dev_hdl *ndev)
ndev->mbox = NULL;
}
+static irqreturn_t cert_comp_isr(int irq, void *p)
+{
+ struct cert_comp *cert_comp = p;
+
+ wake_up_all(&cert_comp->waitq);
+ return IRQ_HANDLED;
+}
+
+/* Wire per-cert completion notification interrupt. */
+int aie4_request_notification(struct cert_comp *comp)
+{
+ struct pci_dev *pdev = to_pci_dev(comp->ndev->aie.xdna->ddev.dev);
+ int ret;
+
+ ret = pci_irq_vector(pdev, comp->msix_idx);
+ if (ret < 0)
+ return ret;
+ comp->irq = ret;
+
+ ret = request_irq(comp->irq, cert_comp_isr, 0, "xdna_hsa", comp);
+ if (ret) {
+ comp->irq = -ENOENT;
+ return ret;
+ }
+
+ return 0;
+}
+
+/* Tear down per-cert completion notification interrupt. */
+void aie4_free_notification(struct cert_comp *comp)
+{
+ if (comp->irq >= 0)
+ free_irq(comp->irq, comp);
+}
+
+/* Validate and configure hardware context doorbell target. */
+int aie4_doorbell_setup(struct amdxdna_hwctx *hwctx,
+ const struct aie4_msg_create_hw_context_resp *resp)
+{
+ struct amdxdna_dev *xdna = hwctx->client->xdna;
+ struct amdxdna_dev_hdl *ndev = xdna->dev_handle;
+ struct amdxdna_hwctx_priv *priv = hwctx->priv;
+ struct pci_dev *pdev = to_pci_dev(xdna->ddev.dev);
+ u64 db_off = (u64)ndev->priv->doorbell_off + resp->doorbell_offset;
+
+ /* Validate doorbell offset against mapped BAR bounds. */
+ if (db_off + sizeof(u32) >
+ pci_resource_len(pdev, xdna->dev_info->doorbell_bar)) {
+ XDNA_ERR(xdna, "doorbell offset 0x%llx out of BAR", db_off);
+ return -EINVAL;
+ }
+
+ priv->doorbell_addr = ndev->doorbell_base + ndev->priv->doorbell_off +
+ resp->doorbell_offset;
+ return 0;
+}
+
+/* Ring context doorbell to notify CERT. */
+void aie4_doorbell_ring(struct amdxdna_hwctx *hwctx)
+{
+ writel(0, hwctx->priv->doorbell_addr);
+}
+
static int aie4_irq_init(struct amdxdna_dev *xdna)
{
struct pci_dev *pdev = to_pci_dev(xdna->ddev.dev);
@@ -623,6 +687,7 @@ static int aie4m_pcidev_init(struct amdxdna_dev *xdna)
set_bit(SMU_REG_BAR(ndev, i), &bars);
set_bit(xdna->dev_info->mbox_bar, &bars);
set_bit(xdna->dev_info->sram_bar, &bars);
+ set_bit(xdna->dev_info->doorbell_bar, &bars);
for (i = 0; i < PCI_NUM_RESOURCES; i++) {
if (!test_bit(i, &bars))
@@ -636,6 +701,7 @@ static int aie4m_pcidev_init(struct amdxdna_dev *xdna)
ndev->mbox_base = tbl[xdna->dev_info->mbox_bar];
ndev->rbuf_base = tbl[xdna->dev_info->sram_bar];
+ ndev->doorbell_base = tbl[xdna->dev_info->doorbell_bar];
pci_set_master(pdev);
diff --git a/drivers/accel/amdxdna/aie4_pci.h b/drivers/accel/amdxdna/aie4_pci.h
index 959ef3695813..9fcdfcc5a15f 100644
--- a/drivers/accel/amdxdna/aie4_pci.h
+++ b/drivers/accel/amdxdna/aie4_pci.h
@@ -32,6 +32,8 @@ struct amdxdna_hwctx_priv {
struct cert_comp *cert_comp;
u32 hw_ctx_id;
+
+ void __iomem *doorbell_addr;
};
struct amdxdna_dev_priv {
@@ -54,6 +56,7 @@ struct amdxdna_dev_hdl {
const struct amdxdna_dev_priv *priv;
void __iomem *mbox_base;
void __iomem *rbuf_base;
+ void __iomem *doorbell_base;
struct mailbox *mbox;
u32 partition_id;
@@ -111,6 +114,17 @@ int aie4_cmd_wait(struct amdxdna_hwctx *hwctx, u64 seq, u32 timeout);
/* aie4_pci.c */
int aie4_restore_power_mode(struct amdxdna_dev_hdl *ndev);
+/*
+ * Transport hooks implemented by PCI backend. Doorbell hooks are wired during
+ * kernel queue creation and command submission in later patches in the series.
+ */
+struct aie4_msg_create_hw_context_resp;
+int aie4_doorbell_setup(struct amdxdna_hwctx *hwctx,
+ const struct aie4_msg_create_hw_context_resp *resp);
+void aie4_doorbell_ring(struct amdxdna_hwctx *hwctx);
+int aie4_request_notification(struct cert_comp *comp);
+void aie4_free_notification(struct cert_comp *comp);
+
/* aie4_sriov.c */
#if IS_ENABLED(CONFIG_PCI_IOV)
int aie4_sriov_configure(struct amdxdna_dev *xdna, int num_vfs);
diff --git a/drivers/accel/amdxdna/amdxdna_ctx.h b/drivers/accel/amdxdna/amdxdna_ctx.h
index 6e78bab8a02c..9bbc3db4ebde 100644
--- a/drivers/accel/amdxdna/amdxdna_ctx.h
+++ b/drivers/accel/amdxdna/amdxdna_ctx.h
@@ -6,6 +6,8 @@
#ifndef _AMDXDNA_CTX_H_
#define _AMDXDNA_CTX_H_
+#include <drm/amdxdna_accel.h>
+#include <drm/gpu_scheduler.h>
#include <linux/bitfield.h>
#include "amdxdna_gem.h"
--
2.34.1