208 lines · c
1// SPDX-License-Identifier: GPL-2.02/*3 * Copyright (C) 2015-2018 Etnaviv Project4 */5 6#include <linux/kernel.h>7 8#include "etnaviv_gem.h"9#include "etnaviv_gpu.h"10 11#include "cmdstream.xml.h"12 13#define EXTRACT(val, field) (((val) & field##__MASK) >> field##__SHIFT)14 15struct etna_validation_state {16 struct etnaviv_gpu *gpu;17 const struct drm_etnaviv_gem_submit_reloc *relocs;18 unsigned int num_relocs;19 u32 *start;20};21 22static const struct {23 u16 offset;24 u16 size;25} etnaviv_sensitive_states[] __initconst = {26#define ST(start, num) { (start) >> 2, (num) }27 /* 2D */28 ST(0x1200, 1),29 ST(0x1228, 1),30 ST(0x1238, 1),31 ST(0x1284, 1),32 ST(0x128c, 1),33 ST(0x1304, 1),34 ST(0x1310, 1),35 ST(0x1318, 1),36 ST(0x12800, 4),37 ST(0x128a0, 4),38 ST(0x128c0, 4),39 ST(0x12970, 4),40 ST(0x12a00, 8),41 ST(0x12b40, 8),42 ST(0x12b80, 8),43 ST(0x12ce0, 8),44 /* 3D */45 ST(0x0644, 1),46 ST(0x064c, 1),47 ST(0x0680, 8),48 ST(0x086c, 1),49 ST(0x1028, 1),50 ST(0x1410, 1),51 ST(0x1430, 1),52 ST(0x1458, 1),53 ST(0x1460, 8),54 ST(0x1480, 8),55 ST(0x1500, 8),56 ST(0x1520, 8),57 ST(0x1540, 8),58 ST(0x1608, 1),59 ST(0x1610, 1),60 ST(0x1658, 1),61 ST(0x165c, 1),62 ST(0x1664, 1),63 ST(0x1668, 1),64 ST(0x16a4, 1),65 ST(0x16c0, 8),66 ST(0x16e0, 8),67 ST(0x1740, 8),68 ST(0x17c0, 8),69 ST(0x17e0, 8),70 ST(0x2400, 14 * 16),71 ST(0x3824, 1),72 ST(0x10800, 32 * 16),73 ST(0x14600, 16),74 ST(0x14800, 8 * 8),75#undef ST76};77 78#define ETNAVIV_STATES_SIZE (VIV_FE_LOAD_STATE_HEADER_OFFSET__MASK + 1u)79static DECLARE_BITMAP(etnaviv_states, ETNAVIV_STATES_SIZE);80 81void __init etnaviv_validate_init(void)82{83 unsigned int i;84 85 for (i = 0; i < ARRAY_SIZE(etnaviv_sensitive_states); i++)86 bitmap_set(etnaviv_states, etnaviv_sensitive_states[i].offset,87 etnaviv_sensitive_states[i].size);88}89 90static void etnaviv_warn_if_non_sensitive(struct etna_validation_state *state,91 unsigned int buf_offset, unsigned int state_addr)92{93 if (state->num_relocs && state->relocs->submit_offset < buf_offset) {94 dev_warn_once(state->gpu->dev,95 "%s: relocation for non-sensitive state 0x%x at offset %u\n",96 __func__, state_addr,97 state->relocs->submit_offset);98 while (state->num_relocs &&99 state->relocs->submit_offset < buf_offset) {100 state->relocs++;101 state->num_relocs--;102 }103 }104}105 106static bool etnaviv_validate_load_state(struct etna_validation_state *state,107 u32 *ptr, unsigned int state_offset, unsigned int num)108{109 unsigned int size = min(ETNAVIV_STATES_SIZE, state_offset + num);110 unsigned int st_offset = state_offset, buf_offset;111 112 for_each_set_bit_from(st_offset, etnaviv_states, size) {113 buf_offset = (ptr - state->start +114 st_offset - state_offset) * 4;115 116 etnaviv_warn_if_non_sensitive(state, buf_offset, st_offset * 4);117 if (state->num_relocs &&118 state->relocs->submit_offset == buf_offset) {119 state->relocs++;120 state->num_relocs--;121 continue;122 }123 124 dev_warn_ratelimited(state->gpu->dev,125 "%s: load state touches restricted state 0x%x at offset %u\n",126 __func__, st_offset * 4, buf_offset);127 return false;128 }129 130 if (state->num_relocs) {131 buf_offset = (ptr - state->start + num) * 4;132 etnaviv_warn_if_non_sensitive(state, buf_offset, st_offset * 4 +133 state->relocs->submit_offset -134 buf_offset);135 }136 137 return true;138}139 140static uint8_t cmd_length[32] = {141 [FE_OPCODE_DRAW_PRIMITIVES] = 4,142 [FE_OPCODE_DRAW_INDEXED_PRIMITIVES] = 6,143 [FE_OPCODE_DRAW_INSTANCED] = 4,144 [FE_OPCODE_NOP] = 2,145 [FE_OPCODE_STALL] = 2,146};147 148bool etnaviv_cmd_validate_one(struct etnaviv_gpu *gpu, u32 *stream,149 unsigned int size,150 struct drm_etnaviv_gem_submit_reloc *relocs,151 unsigned int reloc_size)152{153 struct etna_validation_state state;154 u32 *buf = stream;155 u32 *end = buf + size;156 157 state.gpu = gpu;158 state.relocs = relocs;159 state.num_relocs = reloc_size;160 state.start = stream;161 162 while (buf < end) {163 u32 cmd = *buf;164 unsigned int len, n, off;165 unsigned int op = cmd >> 27;166 167 switch (op) {168 case FE_OPCODE_LOAD_STATE:169 n = EXTRACT(cmd, VIV_FE_LOAD_STATE_HEADER_COUNT);170 len = ALIGN(1 + n, 2);171 if (buf + len > end)172 break;173 174 off = EXTRACT(cmd, VIV_FE_LOAD_STATE_HEADER_OFFSET);175 if (!etnaviv_validate_load_state(&state, buf + 1,176 off, n))177 return false;178 break;179 180 case FE_OPCODE_DRAW_2D:181 n = EXTRACT(cmd, VIV_FE_DRAW_2D_HEADER_COUNT);182 if (n == 0)183 n = 256;184 len = 2 + n * 2;185 break;186 187 default:188 len = cmd_length[op];189 if (len == 0) {190 dev_err(gpu->dev, "%s: op %u not permitted at offset %tu\n",191 __func__, op, buf - state.start);192 return false;193 }194 break;195 }196 197 buf += len;198 }199 200 if (buf > end) {201 dev_err(gpu->dev, "%s: commands overflow end of buffer: %tu > %u\n",202 __func__, buf - state.start, size);203 return false;204 }205 206 return true;207}208