accel/amdxdna: Skip unmapped range in aie2_populate_range()

aie2_populate_range() incorrectly failed jobs for BOs with multiple
mmaps: if the unmapped entry appeared first in umap_list, the loop would
pick it up, call hmm_range_fault() on a gone VMA, and return -EFAULT
without ever trying the remaining valid mapps.

Fix it by skipping unmapped entries. After the loop, if the map list is
empty or all maps are valid, map_invalid can be cleared normally.

Fixes: e486147c91 ("accel/amdxdna: Add BO import and export")
Reviewed-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260812205628.810816-1-lizhi.hou@amd.com
This commit is contained in:
Lizhi Hou
2026-08-12 13:56:28 -07:00
parent 9a11db6887
commit 6c916e301f

View File

@@ -1053,6 +1053,16 @@ static int aie2_populate_range(struct amdxdna_gem_obj *abo)
found = false;
down_write(&xdna->notifier_lock);
list_for_each_entry(mapp, &abo->mem.umap_list, node) {
/*
* Skip entries that have already been unmapped.
*
* If userspace unmaps the address and later submits I/O using
* it, the IOMMU will reject the access and report a fault.
* Ignore such entries here.
*/
if (mapp->unmapped)
continue;
if (mapp->invalid && kref_get_unless_zero(&mapp->refcnt)) {
found = true;
break;
@@ -1060,6 +1070,12 @@ static int aie2_populate_range(struct amdxdna_gem_obj *abo)
}
if (!found) {
/*
* This also covers the case where all mappings have been
* removed. There are no invalid mappings left to process.
* Any subsequent I/O using the unmapped address will be
* rejected by the IOMMU.
*/
abo->mem.map_invalid = false;
up_write(&xdna->notifier_lock);
return 0;