Re: [RFT 3/5] drm/msm: Extract out map/unmap helpers
From: Karl Mehltretter
Date: Wed Oct 07 2026 - 01:20:13 EST
> Does this error path miss an IOTLB flush?
Yes. msm_iommu_pagetable_unmap() called iommu_flush_iotlb_all() after
rollback. __do_map() now calls __do_unmap() directly and loses that
flush.
An arm64 QEMU/SMMUv3 test:
- mapped one 4 KiB page,
- hit -EEXIST on the second page, and
- verified that rollback removed the first PTE.
No stale translation was observed because the device had not accessed
the mapping. This tested the low-level IOMMU sequence, not the MSM driver
or Qualcomm hardware.
Restoring iommu_flush_iotlb_all() on this error path preserves the old
behavior.
Karl