Page MenuHomeFreeBSD

linuxkpi: track cache-attribute lifetimes for overlapping vmap mappings
Needs ReviewPublic

Authored by oleglelchuk_gmail.com on Tue, Sep 29, 3:05 PM.

Details

Reviewers
ashafer
jhb
Group Reviewers
linuxkpi
Summary

This is a proposed follow-up to Austin Shafer's D59436, responding to the discussion about cache-attribute ownership and overlapping mappings. It carries forward the correction to honor vmap()'s requested cache policy and adds per-page bookkeeping for compatible vmap aliases. I would like review of the ownership contract and the limits described below before this is considered for merging.

The displayed diff is a complete patch against FreeBSD main d2018cedb414ef17e77b7fc2fa19fd81328da46b. It replaces the original D59436 implementation; do not apply both complete patches. A separate comparison delta against that base plus exact D59436 diff 185902 is attached for reviewing only the additional changes.

Observed behavior

The LLM copied the exact D59436 vmap()/vunmap() bodies into an isolated native amd64 test module, renamed the entry points, and kept a private page allocated and wired throughout:

a = vmap(&page, 1, 0, pgprot_writecombine(PAGE_KERNEL));
b = vmap(&page, 1, 0, pgprot_writecombine(PAGE_KERNEL));
vunmap(a);
/* b is still mapped here. */

After vunmap(a), the surviving b mapping was WC while the direct map was WB. pmap_page_set_memattr() updates the direct map and page attribute, but does not rewrite the surviving pmap_qenter() alias. pmap_page_is_mapped() was false for these kernel aliases. The proposed implementation kept both aliases WC until the last unmap. A separate check showed D59436 replacing an original UC attribute with WB; the proposed implementation restored UC.

These tests demonstrate the mapping behavior. They did not reproduce a GPU hang or establish that normal i915 activity reaches this overlap. The caller/API guarantees that permit or rule out this sequence remain a review question. D59436's intended firmware-initialization fix is useful independently of this question.

Implementation and contract

  • Track vmap references per vm_page_t in a separate table, bucketed by physical page number. This assumes a stable, unique page descriptor; it does not coalesce separate fictitious descriptors for one physical address.
  • Share compatible mappings and reject conflicting explicit requests or reference overflow. As in the original proposal, a default request retains the page's existing attribute; it is not a strict request to force WB.
  • Remove the departing mapping's PTEs before dropping its attribute references. At the last reference, restore the saved attribute only if the tracked attribute is still present and pmap_page_is_mapped() is false.
  • Roll back partial acquisition on allocation failure. Reject an attribute change for kernel_object pages or pages already reported mapped.

The caller still owns the page lifetime and must coordinate other mappings/attribute changes. This is bookkeeping for vmap(), not global tracking of all native mappings. The mapped-page checks do not serialize unrelated pmap operations; if a managed mapping survives the final unmap, restoration is left to its owner. linuxkpi_vmap_pfn(), ioremap(), fictitious aliases and arbitrary native pmap_qenter() aliases are not enrolled. Review of that boundary, default-request semantics and the need for tracking versus a stricter caller contract is especially welcome.

The general diff contains no D59481 PFN ownership changes. A separate optional coordination patch lets that local PFN implementation defer its attribute restoration until tracked kernel aliases are gone. It is supplied for reproducing my tested combination, not as a dependency of this general review.

Related DRM work is in https://github.com/freebsd/drm-kmod/pull/496. It addresses a distinct Meteor Lake BAR2/GGTT physical-mapping problem, framebuffer handling and capture correctness. The ownership/reclamation problem discussed in D59481/D59883 is also separate.

Complete standalone patch:


Comparison delta after exact D59436 diff 185902:
Optional coordination with D59481 diff 188003:
Reproducer and model-test bundle:

Reproducibility guide with pinned revisions, patch order, matching module-build instructions and testing limits:


Companion complete DRM patch:

Full-file review context

The displayed diff now includes complete before/after file contents (git diff -U9999); the source changes are identical. Full-context copies: general patch

; comparison after D59436 ; optional PFN coordination ; companion DRM patch . The smaller application downloads above are retained for the documented patch sequence.

Test Plan

Completed checks:

  • Applied and reversed the standalone patch against pristine main d2018cedb414; verified exact resulting trees. The D59436-plus-comparison-delta route produces the identical general implementation.
  • Applied D59481 diff 188003, the general patch and the separate PFN-coordination patch. The resulting entire linux_page.c matches the currently running combined implementation byte for byte.
  • Compiled the separated LinuxKPI module and the native overlap fixture on amd64 with the d2018cedb414 source headers and the existing GENERIC generated configuration. Neither candidate module was installed or loaded during publication preparation.
  • Re-ran source-extracted C tests under AddressSanitizer and UndefinedBehaviorSanitizer for both the general and PFN-coordinated implementations: all six three-alias release orders, repeated pages, conflicting requests, preservation of original attributes, partial allocation failures/rollback, and 160,000 concurrent map/unmap operations per suite. The PFN variant additionally tests deferred restoration. All passed. These use a modeled VM, not native pmap.
  • The attached native comparison results were collected on 2026-09-28 using private wired RAM and native amd64 pmap on the locally patched f492ef8318f5 kernel. Its relevant native pmap/page-allocation routines were unchanged from that base. Exact D59436 produced WC/WB disagreement after one overlapping alias was removed; the expanded implementation did not. The test inspected PTEs without accessing data through mismatched aliases; all temporary mappings/pages and the module were released.

The expanded implementation has also been built and booted as part of my larger local kernel/DRM combination, most recently on d2018cedb414 on 2026-09-29 with INVARIANTS/WITNESS. Live graphics mapping and healthy-capture checks passed. This is integration evidence, not a boot test of a kernel containing only this standalone patch, and does not isolate the effect of this change from the companion DRM/PFN changes.

Still needed before treating this as an upstream-ready fix: agreement on the LinuxKPI page-owner/mapping contract; review of interactions with untracked mappings; tests on other supported architectures; and identification of a real driver path requiring overlapping vmap lifetimes. No claim is made that this patch alone fixes the observed GPU hang.

Test sources, build instructions and original native output:

Full-context publication check: reconstructed every complete before/after file from the uploaded diff, verified byte-for-byte equality with the original source versions, and checked the identical resulting tree and exact reverse application. No source code changed and no new runtime test is claimed for this formatting update.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

oleglelchuk_gmail.com created this object with visibility "Public (No Login Required)".
oleglelchuk_gmail.com edited the summary of this revision. (Show Details)
oleglelchuk_gmail.com edited the test plan for this revision. (Show Details)

I have replaced the uploaded diff with a git diff -U9999 version so the complete contents of every changed file are available, as requested. The LLM verified that the full-context diff produces exactly the same source tree as the previous upload and reverses to the same base. This update changes context only; it makes no code changes.

Full-context patch download:

.
The comparison delta, PFN coordination and DRM downloads also have full-context review copies. The updated guide explains their relationship to the existing application patches: .