1 // SPDX-License-Identifier: GPL-2.0 OR MIT
2 /**************************************************************************
3 *
4 * Copyright (c) 2009-2024 Broadcom. All Rights Reserved. The term
5 * “Broadcom” refers to Broadcom Inc. and/or its subsidiaries.
6 *
7 * Permission is hereby granted, free of charge, to any person obtaining a
8 * copy of this software and associated documentation files (the
9 * "Software"), to deal in the Software without restriction, including
10 * without limitation the rights to use, copy, modify, merge, publish,
11 * distribute, sub license, and/or sell copies of the Software, and to
12 * permit persons to whom the Software is furnished to do so, subject to
13 * the following conditions:
14 *
15 * The above copyright notice and this permission notice (including the
16 * next paragraph) shall be included in all copies or substantial portions
17 * of the Software.
18 *
19 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
20 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
21 * FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. IN NO EVENT SHALL
22 * THE COPYRIGHT HOLDERS, AUTHORS AND/OR ITS SUPPLIERS BE LIABLE FOR ANY CLAIM,
23 * DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
24 * OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
25 * USE OR OTHER DEALINGS IN THE SOFTWARE.
26 *
27 **************************************************************************/
28
29 #include "vmwgfx_bo.h"
30 #include "vmwgfx_drv.h"
31 #include "vmwgfx_resource_priv.h"
32 #include "vmwgfx_so.h"
33 #include "vmwgfx_binding.h"
34 #include "vmw_surface_cache.h"
35 #include "device_include/svga3d_surfacedefs.h"
36
37 #include <drm/ttm/ttm_placement.h>
38
39 #define SVGA3D_FLAGS_64(upper32, lower32) (((uint64_t)upper32 << 32) | lower32)
40
41 /**
42 * struct vmw_user_surface - User-space visible surface resource
43 *
44 * @prime: The TTM prime object.
45 * @srf: The surface metadata.
46 * @master: Master of the creating client. Used for security check.
47 */
48 struct vmw_user_surface {
49 struct ttm_prime_object prime;
50 struct vmw_surface srf;
51 struct drm_master *master;
52 };
53
54 /**
55 * struct vmw_surface_offset - Backing store mip level offset info
56 *
57 * @face: Surface face.
58 * @mip: Mip level.
59 * @bo_offset: Offset into backing store of this mip level.
60 *
61 */
62 struct vmw_surface_offset {
63 uint32_t face;
64 uint32_t mip;
65 uint32_t bo_offset;
66 };
67
68 /**
69 * struct vmw_surface_dirty - Surface dirty-tracker
70 * @cache: Cached layout information of the surface.
71 * @num_subres: Number of subresources.
72 * @boxes: Array of SVGA3dBoxes indicating dirty regions. One per subresource.
73 */
74 struct vmw_surface_dirty {
75 struct vmw_surface_cache cache;
76 u32 num_subres;
77 SVGA3dBox boxes[] __counted_by(num_subres);
78 };
79
80 static void vmw_user_surface_free(struct vmw_resource *res);
81 static struct vmw_resource *
82 vmw_user_surface_base_to_res(struct ttm_base_object *base);
83 static int vmw_legacy_srf_bind(struct vmw_resource *res,
84 struct ttm_validate_buffer *val_buf);
85 static int vmw_legacy_srf_unbind(struct vmw_resource *res,
86 bool readback,
87 struct ttm_validate_buffer *val_buf);
88 static int vmw_legacy_srf_create(struct vmw_resource *res);
89 static int vmw_legacy_srf_destroy(struct vmw_resource *res);
90 static int vmw_gb_surface_create(struct vmw_resource *res);
91 static int vmw_gb_surface_bind(struct vmw_resource *res,
92 struct ttm_validate_buffer *val_buf);
93 static int vmw_gb_surface_unbind(struct vmw_resource *res,
94 bool readback,
95 struct ttm_validate_buffer *val_buf);
96 static int vmw_gb_surface_destroy(struct vmw_resource *res);
97 static int
98 vmw_gb_surface_define_internal(struct drm_device *dev,
99 struct drm_vmw_gb_surface_create_ext_req *req,
100 struct drm_vmw_gb_surface_create_rep *rep,
101 struct drm_file *file_priv);
102 static int
103 vmw_gb_surface_reference_internal(struct drm_device *dev,
104 struct drm_vmw_surface_arg *req,
105 struct drm_vmw_gb_surface_ref_ext_rep *rep,
106 struct drm_file *file_priv);
107
108 static void vmw_surface_dirty_free(struct vmw_resource *res);
109 static int vmw_surface_dirty_alloc(struct vmw_resource *res);
110 static int vmw_surface_dirty_sync(struct vmw_resource *res);
111 static void vmw_surface_dirty_range_add(struct vmw_resource *res, size_t start,
112 size_t end);
113 static int vmw_surface_clean(struct vmw_resource *res);
114
115 static const struct vmw_user_resource_conv user_surface_conv = {
116 .object_type = VMW_RES_SURFACE,
117 .base_obj_to_res = vmw_user_surface_base_to_res,
118 .res_free = vmw_user_surface_free
119 };
120
121 const struct vmw_user_resource_conv *user_surface_converter =
122 &user_surface_conv;
123
124 static const struct vmw_res_func vmw_legacy_surface_func = {
125 .res_type = vmw_res_surface,
126 .needs_guest_memory = false,
127 .may_evict = true,
128 .prio = 1,
129 .dirty_prio = 1,
130 .type_name = "legacy surfaces",
131 .domain = VMW_BO_DOMAIN_GMR,
132 .busy_domain = VMW_BO_DOMAIN_GMR | VMW_BO_DOMAIN_VRAM,
133 .create = &vmw_legacy_srf_create,
134 .destroy = &vmw_legacy_srf_destroy,
135 .bind = &vmw_legacy_srf_bind,
136 .unbind = &vmw_legacy_srf_unbind
137 };
138
139 static const struct vmw_res_func vmw_gb_surface_func = {
140 .res_type = vmw_res_surface,
141 .needs_guest_memory = true,
142 .may_evict = true,
143 .prio = 1,
144 .dirty_prio = 2,
145 .type_name = "guest backed surfaces",
146 .domain = VMW_BO_DOMAIN_MOB,
147 .busy_domain = VMW_BO_DOMAIN_MOB,
148 .create = vmw_gb_surface_create,
149 .destroy = vmw_gb_surface_destroy,
150 .bind = vmw_gb_surface_bind,
151 .unbind = vmw_gb_surface_unbind,
152 .dirty_alloc = vmw_surface_dirty_alloc,
153 .dirty_free = vmw_surface_dirty_free,
154 .dirty_sync = vmw_surface_dirty_sync,
155 .dirty_range_add = vmw_surface_dirty_range_add,
156 .clean = vmw_surface_clean,
157 };
158
159 /*
160 * struct vmw_surface_dma - SVGA3D DMA command
161 */
162 struct vmw_surface_dma {
163 SVGA3dCmdHeader header;
164 SVGA3dCmdSurfaceDMA body;
165 SVGA3dCopyBox cb;
166 SVGA3dCmdSurfaceDMASuffix suffix;
167 };
168
169 /*
170 * struct vmw_surface_define - SVGA3D Surface Define command
171 */
172 struct vmw_surface_define {
173 SVGA3dCmdHeader header;
174 SVGA3dCmdDefineSurface body;
175 };
176
177 /*
178 * struct vmw_surface_destroy - SVGA3D Surface Destroy command
179 */
180 struct vmw_surface_destroy {
181 SVGA3dCmdHeader header;
182 SVGA3dCmdDestroySurface body;
183 };
184
185
186 /**
187 * vmw_surface_dma_size - Compute fifo size for a dma command.
188 *
189 * @srf: Pointer to a struct vmw_surface
190 *
191 * Computes the required size for a surface dma command for backup or
192 * restoration of the surface represented by @srf.
193 */
vmw_surface_dma_size(const struct vmw_surface * srf)194 static inline uint32_t vmw_surface_dma_size(const struct vmw_surface *srf)
195 {
196 return srf->metadata.num_sizes * sizeof(struct vmw_surface_dma);
197 }
198
199
200 /**
201 * vmw_surface_define_size - Compute fifo size for a surface define command.
202 *
203 * @srf: Pointer to a struct vmw_surface
204 *
205 * Computes the required size for a surface define command for the definition
206 * of the surface represented by @srf.
207 */
vmw_surface_define_size(const struct vmw_surface * srf)208 static inline uint32_t vmw_surface_define_size(const struct vmw_surface *srf)
209 {
210 return sizeof(struct vmw_surface_define) + srf->metadata.num_sizes *
211 sizeof(SVGA3dSize);
212 }
213
214
215 /**
216 * vmw_surface_destroy_size - Compute fifo size for a surface destroy command.
217 *
218 * Computes the required size for a surface destroy command for the destruction
219 * of a hw surface.
220 */
vmw_surface_destroy_size(void)221 static inline uint32_t vmw_surface_destroy_size(void)
222 {
223 return sizeof(struct vmw_surface_destroy);
224 }
225
226 /**
227 * vmw_surface_destroy_encode - Encode a surface_destroy command.
228 *
229 * @id: The surface id
230 * @cmd_space: Pointer to memory area in which the commands should be encoded.
231 */
vmw_surface_destroy_encode(uint32_t id,void * cmd_space)232 static void vmw_surface_destroy_encode(uint32_t id,
233 void *cmd_space)
234 {
235 struct vmw_surface_destroy *cmd = (struct vmw_surface_destroy *)
236 cmd_space;
237
238 cmd->header.id = SVGA_3D_CMD_SURFACE_DESTROY;
239 cmd->header.size = sizeof(cmd->body);
240 cmd->body.sid = id;
241 }
242
243 /**
244 * vmw_surface_define_encode - Encode a surface_define command.
245 *
246 * @srf: Pointer to a struct vmw_surface object.
247 * @cmd_space: Pointer to memory area in which the commands should be encoded.
248 */
vmw_surface_define_encode(const struct vmw_surface * srf,void * cmd_space)249 static void vmw_surface_define_encode(const struct vmw_surface *srf,
250 void *cmd_space)
251 {
252 struct vmw_surface_define *cmd = (struct vmw_surface_define *)
253 cmd_space;
254 struct drm_vmw_size *src_size;
255 SVGA3dSize *cmd_size;
256 uint32_t cmd_len;
257 int i;
258
259 cmd_len = sizeof(cmd->body) + srf->metadata.num_sizes *
260 sizeof(SVGA3dSize);
261
262 cmd->header.id = SVGA_3D_CMD_SURFACE_DEFINE;
263 cmd->header.size = cmd_len;
264 cmd->body.sid = srf->res.id;
265 /*
266 * Downcast of surfaceFlags, was upcasted when received from user-space,
267 * since driver internally stores as 64 bit.
268 * For legacy surface define only 32 bit flag is supported.
269 */
270 cmd->body.surfaceFlags = (SVGA3dSurface1Flags)srf->metadata.flags;
271 cmd->body.format = srf->metadata.format;
272 for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i)
273 cmd->body.face[i].numMipLevels = srf->metadata.mip_levels[i];
274
275 cmd += 1;
276 cmd_size = (SVGA3dSize *) cmd;
277 src_size = srf->metadata.sizes;
278
279 for (i = 0; i < srf->metadata.num_sizes; ++i, cmd_size++, src_size++) {
280 cmd_size->width = src_size->width;
281 cmd_size->height = src_size->height;
282 cmd_size->depth = src_size->depth;
283 }
284 }
285
286 /**
287 * vmw_surface_dma_encode - Encode a surface_dma command.
288 *
289 * @srf: Pointer to a struct vmw_surface object.
290 * @cmd_space: Pointer to memory area in which the commands should be encoded.
291 * @ptr: Pointer to an SVGAGuestPtr indicating where the surface contents
292 * should be placed or read from.
293 * @to_surface: Boolean whether to DMA to the surface or from the surface.
294 */
vmw_surface_dma_encode(struct vmw_surface * srf,void * cmd_space,const SVGAGuestPtr * ptr,bool to_surface)295 static void vmw_surface_dma_encode(struct vmw_surface *srf,
296 void *cmd_space,
297 const SVGAGuestPtr *ptr,
298 bool to_surface)
299 {
300 uint32_t i;
301 struct vmw_surface_dma *cmd = (struct vmw_surface_dma *)cmd_space;
302 const struct SVGA3dSurfaceDesc *desc =
303 vmw_surface_get_desc(srf->metadata.format);
304
305 for (i = 0; i < srf->metadata.num_sizes; ++i) {
306 SVGA3dCmdHeader *header = &cmd->header;
307 SVGA3dCmdSurfaceDMA *body = &cmd->body;
308 SVGA3dCopyBox *cb = &cmd->cb;
309 SVGA3dCmdSurfaceDMASuffix *suffix = &cmd->suffix;
310 const struct vmw_surface_offset *cur_offset = &srf->offsets[i];
311 const struct drm_vmw_size *cur_size = &srf->metadata.sizes[i];
312
313 header->id = SVGA_3D_CMD_SURFACE_DMA;
314 header->size = sizeof(*body) + sizeof(*cb) + sizeof(*suffix);
315
316 body->guest.ptr = *ptr;
317 body->guest.ptr.offset += cur_offset->bo_offset;
318 body->guest.pitch = vmw_surface_calculate_pitch(desc, cur_size);
319 body->host.sid = srf->res.id;
320 body->host.face = cur_offset->face;
321 body->host.mipmap = cur_offset->mip;
322 body->transfer = ((to_surface) ? SVGA3D_WRITE_HOST_VRAM :
323 SVGA3D_READ_HOST_VRAM);
324 cb->x = 0;
325 cb->y = 0;
326 cb->z = 0;
327 cb->srcx = 0;
328 cb->srcy = 0;
329 cb->srcz = 0;
330 cb->w = cur_size->width;
331 cb->h = cur_size->height;
332 cb->d = cur_size->depth;
333
334 suffix->suffixSize = sizeof(*suffix);
335 suffix->maximumOffset =
336 vmw_surface_get_image_buffer_size(desc, cur_size,
337 body->guest.pitch);
338 suffix->flags.discard = 0;
339 suffix->flags.unsynchronized = 0;
340 suffix->flags.reserved = 0;
341 ++cmd;
342 }
343 };
344
345
346 /**
347 * vmw_hw_surface_destroy - destroy a Device surface
348 *
349 * @res: Pointer to a struct vmw_resource embedded in a struct
350 * vmw_surface.
351 *
352 * Destroys a the device surface associated with a struct vmw_surface if
353 * any, and adjusts resource count accordingly.
354 */
vmw_hw_surface_destroy(struct vmw_resource * res)355 static void vmw_hw_surface_destroy(struct vmw_resource *res)
356 {
357
358 struct vmw_private *dev_priv = res->dev_priv;
359 void *cmd;
360
361 if (res->func->destroy == vmw_gb_surface_destroy) {
362 (void) vmw_gb_surface_destroy(res);
363 return;
364 }
365
366 if (res->id != -1) {
367
368 cmd = VMW_CMD_RESERVE(dev_priv, vmw_surface_destroy_size());
369 if (unlikely(!cmd))
370 return;
371
372 vmw_surface_destroy_encode(res->id, cmd);
373 vmw_cmd_commit(dev_priv, vmw_surface_destroy_size());
374
375 /*
376 * used_memory_size_atomic, or separate lock
377 * to avoid taking dev_priv::cmdbuf_mutex in
378 * the destroy path.
379 */
380
381 mutex_lock(&dev_priv->cmdbuf_mutex);
382 dev_priv->used_memory_size -= res->guest_memory_size;
383 mutex_unlock(&dev_priv->cmdbuf_mutex);
384 }
385 }
386
387 /**
388 * vmw_legacy_srf_create - Create a device surface as part of the
389 * resource validation process.
390 *
391 * @res: Pointer to a struct vmw_surface.
392 *
393 * If the surface doesn't have a hw id.
394 *
395 * Returns -EBUSY if there wasn't sufficient device resources to
396 * complete the validation. Retry after freeing up resources.
397 *
398 * May return other errors if the kernel is out of guest resources.
399 */
vmw_legacy_srf_create(struct vmw_resource * res)400 static int vmw_legacy_srf_create(struct vmw_resource *res)
401 {
402 struct vmw_private *dev_priv = res->dev_priv;
403 struct vmw_surface *srf;
404 uint32_t submit_size;
405 uint8_t *cmd;
406 int ret;
407
408 if (likely(res->id != -1))
409 return 0;
410
411 srf = vmw_res_to_srf(res);
412 if (unlikely(dev_priv->used_memory_size + res->guest_memory_size >=
413 dev_priv->memory_size))
414 return -EBUSY;
415
416 /*
417 * Alloc id for the resource.
418 */
419
420 ret = vmw_resource_alloc_id(res);
421 if (unlikely(ret != 0)) {
422 DRM_ERROR("Failed to allocate a surface id.\n");
423 goto out_no_id;
424 }
425
426 if (unlikely(res->id >= SVGA3D_HB_MAX_SURFACE_IDS)) {
427 ret = -EBUSY;
428 goto out_no_fifo;
429 }
430
431 /*
432 * Encode surface define- commands.
433 */
434
435 submit_size = vmw_surface_define_size(srf);
436 cmd = VMW_CMD_RESERVE(dev_priv, submit_size);
437 if (unlikely(!cmd)) {
438 ret = -ENOMEM;
439 goto out_no_fifo;
440 }
441
442 vmw_surface_define_encode(srf, cmd);
443 vmw_cmd_commit(dev_priv, submit_size);
444 vmw_fifo_resource_inc(dev_priv);
445
446 /*
447 * Surface memory usage accounting.
448 */
449
450 dev_priv->used_memory_size += res->guest_memory_size;
451 return 0;
452
453 out_no_fifo:
454 vmw_resource_release_id(res);
455 out_no_id:
456 return ret;
457 }
458
459 /**
460 * vmw_legacy_srf_dma - Copy backup data to or from a legacy surface.
461 *
462 * @res: Pointer to a struct vmw_res embedded in a struct
463 * vmw_surface.
464 * @val_buf: Pointer to a struct ttm_validate_buffer containing
465 * information about the backup buffer.
466 * @bind: Boolean wether to DMA to the surface.
467 *
468 * Transfer backup data to or from a legacy surface as part of the
469 * validation process.
470 * May return other errors if the kernel is out of guest resources.
471 * The backup buffer will be fenced or idle upon successful completion,
472 * and if the surface needs persistent backup storage, the backup buffer
473 * will also be returned reserved iff @bind is true.
474 */
vmw_legacy_srf_dma(struct vmw_resource * res,struct ttm_validate_buffer * val_buf,bool bind)475 static int vmw_legacy_srf_dma(struct vmw_resource *res,
476 struct ttm_validate_buffer *val_buf,
477 bool bind)
478 {
479 SVGAGuestPtr ptr;
480 struct vmw_fence_obj *fence;
481 uint32_t submit_size;
482 struct vmw_surface *srf = vmw_res_to_srf(res);
483 uint8_t *cmd;
484 struct vmw_private *dev_priv = res->dev_priv;
485
486 BUG_ON(!val_buf->bo);
487 submit_size = vmw_surface_dma_size(srf);
488 cmd = VMW_CMD_RESERVE(dev_priv, submit_size);
489 if (unlikely(!cmd))
490 return -ENOMEM;
491
492 vmw_bo_get_guest_ptr(val_buf->bo, &ptr);
493 vmw_surface_dma_encode(srf, cmd, &ptr, bind);
494
495 vmw_cmd_commit(dev_priv, submit_size);
496
497 /*
498 * Create a fence object and fence the backup buffer.
499 */
500
501 (void) vmw_execbuf_fence_commands(NULL, dev_priv,
502 &fence, NULL);
503
504 vmw_bo_fence_single(val_buf->bo, fence);
505
506 if (likely(fence != NULL))
507 vmw_fence_obj_unreference(&fence);
508
509 return 0;
510 }
511
512 /**
513 * vmw_legacy_srf_bind - Perform a legacy surface bind as part of the
514 * surface validation process.
515 *
516 * @res: Pointer to a struct vmw_res embedded in a struct
517 * vmw_surface.
518 * @val_buf: Pointer to a struct ttm_validate_buffer containing
519 * information about the backup buffer.
520 *
521 * This function will copy backup data to the surface if the
522 * backup buffer is dirty.
523 */
vmw_legacy_srf_bind(struct vmw_resource * res,struct ttm_validate_buffer * val_buf)524 static int vmw_legacy_srf_bind(struct vmw_resource *res,
525 struct ttm_validate_buffer *val_buf)
526 {
527 if (!res->guest_memory_dirty)
528 return 0;
529
530 return vmw_legacy_srf_dma(res, val_buf, true);
531 }
532
533
534 /**
535 * vmw_legacy_srf_unbind - Perform a legacy surface unbind as part of the
536 * surface eviction process.
537 *
538 * @res: Pointer to a struct vmw_res embedded in a struct
539 * vmw_surface.
540 * @readback: Readback - only true if dirty
541 * @val_buf: Pointer to a struct ttm_validate_buffer containing
542 * information about the backup buffer.
543 *
544 * This function will copy backup data from the surface.
545 */
vmw_legacy_srf_unbind(struct vmw_resource * res,bool readback,struct ttm_validate_buffer * val_buf)546 static int vmw_legacy_srf_unbind(struct vmw_resource *res,
547 bool readback,
548 struct ttm_validate_buffer *val_buf)
549 {
550 if (unlikely(readback))
551 return vmw_legacy_srf_dma(res, val_buf, false);
552 return 0;
553 }
554
555 /**
556 * vmw_legacy_srf_destroy - Destroy a device surface as part of a
557 * resource eviction process.
558 *
559 * @res: Pointer to a struct vmw_res embedded in a struct
560 * vmw_surface.
561 */
vmw_legacy_srf_destroy(struct vmw_resource * res)562 static int vmw_legacy_srf_destroy(struct vmw_resource *res)
563 {
564 struct vmw_private *dev_priv = res->dev_priv;
565 uint32_t submit_size;
566 uint8_t *cmd;
567
568 BUG_ON(res->id == -1);
569
570 /*
571 * Encode the dma- and surface destroy commands.
572 */
573
574 submit_size = vmw_surface_destroy_size();
575 cmd = VMW_CMD_RESERVE(dev_priv, submit_size);
576 if (unlikely(!cmd))
577 return -ENOMEM;
578
579 vmw_surface_destroy_encode(res->id, cmd);
580 vmw_cmd_commit(dev_priv, submit_size);
581
582 /*
583 * Surface memory usage accounting.
584 */
585
586 dev_priv->used_memory_size -= res->guest_memory_size;
587
588 /*
589 * Release the surface ID.
590 */
591
592 vmw_resource_release_id(res);
593 vmw_fifo_resource_dec(dev_priv);
594
595 return 0;
596 }
597
598
599 /**
600 * vmw_surface_init - initialize a struct vmw_surface
601 *
602 * @dev_priv: Pointer to a device private struct.
603 * @srf: Pointer to the struct vmw_surface to initialize.
604 * @res_free: Pointer to a resource destructor used to free
605 * the object.
606 */
vmw_surface_init(struct vmw_private * dev_priv,struct vmw_surface * srf,void (* res_free)(struct vmw_resource * res))607 static int vmw_surface_init(struct vmw_private *dev_priv,
608 struct vmw_surface *srf,
609 void (*res_free) (struct vmw_resource *res))
610 {
611 int ret;
612 struct vmw_resource *res = &srf->res;
613
614 BUG_ON(!res_free);
615 ret = vmw_resource_init(dev_priv, res, true, res_free,
616 (dev_priv->has_mob) ? &vmw_gb_surface_func :
617 &vmw_legacy_surface_func);
618
619 if (unlikely(ret != 0)) {
620 res_free(res);
621 return ret;
622 }
623
624 /*
625 * The surface won't be visible to hardware until a
626 * surface validate.
627 */
628
629 INIT_LIST_HEAD(&srf->view_list);
630 res->hw_destroy = vmw_hw_surface_destroy;
631 return ret;
632 }
633
634 /**
635 * vmw_user_surface_base_to_res - TTM base object to resource converter for
636 * user visible surfaces
637 *
638 * @base: Pointer to a TTM base object
639 *
640 * Returns the struct vmw_resource embedded in a struct vmw_surface
641 * for the user-visible object identified by the TTM base object @base.
642 */
643 static struct vmw_resource *
vmw_user_surface_base_to_res(struct ttm_base_object * base)644 vmw_user_surface_base_to_res(struct ttm_base_object *base)
645 {
646 return &(container_of(base, struct vmw_user_surface,
647 prime.base)->srf.res);
648 }
649
650 /**
651 * vmw_user_surface_free - User visible surface resource destructor
652 *
653 * @res: A struct vmw_resource embedded in a struct vmw_surface.
654 */
vmw_user_surface_free(struct vmw_resource * res)655 static void vmw_user_surface_free(struct vmw_resource *res)
656 {
657 struct vmw_surface *srf = vmw_res_to_srf(res);
658 struct vmw_user_surface *user_srf =
659 container_of(srf, struct vmw_user_surface, srf);
660
661 WARN_ON(res->dirty);
662 if (user_srf->master)
663 drm_master_put(&user_srf->master);
664 kfree(srf->offsets);
665 kfree(srf->metadata.sizes);
666 kfree(srf->snooper.image);
667 ttm_prime_object_kfree(user_srf, prime);
668 }
669
670 /**
671 * vmw_user_surface_base_release - User visible surface TTM base object destructor
672 *
673 * @p_base: Pointer to a pointer to a TTM base object
674 * embedded in a struct vmw_user_surface.
675 *
676 * Drops the base object's reference on its resource, and the
677 * pointer pointed to by *p_base is set to NULL.
678 */
vmw_user_surface_base_release(struct ttm_base_object ** p_base)679 static void vmw_user_surface_base_release(struct ttm_base_object **p_base)
680 {
681 struct ttm_base_object *base = *p_base;
682 struct vmw_user_surface *user_srf =
683 container_of(base, struct vmw_user_surface, prime.base);
684 struct vmw_resource *res = &user_srf->srf.res;
685
686 *p_base = NULL;
687
688 /*
689 * Dumb buffers own the resource and they'll unref the
690 * resource themselves
691 */
692 WARN_ON(res && res->guest_memory_bo && res->guest_memory_bo->is_dumb);
693
694 vmw_resource_unreference(&res);
695 }
696
697 /**
698 * vmw_surface_destroy_ioctl - Ioctl function implementing
699 * the user surface destroy functionality.
700 *
701 * @dev: Pointer to a struct drm_device.
702 * @data: Pointer to data copied from / to user-space.
703 * @file_priv: Pointer to a drm file private structure.
704 */
vmw_surface_destroy_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)705 int vmw_surface_destroy_ioctl(struct drm_device *dev, void *data,
706 struct drm_file *file_priv)
707 {
708 struct drm_vmw_surface_arg *arg = (struct drm_vmw_surface_arg *)data;
709 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
710
711 return ttm_ref_object_base_unref(tfile, arg->sid);
712 }
713
714 /**
715 * vmw_surface_define_ioctl - Ioctl function implementing
716 * the user surface define functionality.
717 *
718 * @dev: Pointer to a struct drm_device.
719 * @data: Pointer to data copied from / to user-space.
720 * @file_priv: Pointer to a drm file private structure.
721 */
vmw_surface_define_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)722 int vmw_surface_define_ioctl(struct drm_device *dev, void *data,
723 struct drm_file *file_priv)
724 {
725 struct vmw_private *dev_priv = vmw_priv(dev);
726 struct vmw_user_surface *user_srf;
727 struct vmw_surface *srf;
728 struct vmw_surface_metadata *metadata;
729 struct vmw_resource *res;
730 struct vmw_resource *tmp;
731 union drm_vmw_surface_create_arg *arg =
732 (union drm_vmw_surface_create_arg *)data;
733 struct drm_vmw_surface_create_req *req = &arg->req;
734 struct drm_vmw_surface_arg *rep = &arg->rep;
735 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
736 int ret;
737 int i, j;
738 uint32_t cur_bo_offset;
739 struct drm_vmw_size *cur_size;
740 struct vmw_surface_offset *cur_offset;
741 uint32_t num_sizes;
742 const SVGA3dSurfaceDesc *desc;
743
744 num_sizes = 0;
745 for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i) {
746 if (req->mip_levels[i] > DRM_VMW_MAX_MIP_LEVELS)
747 return -EINVAL;
748 num_sizes += req->mip_levels[i];
749 }
750
751 if (num_sizes > DRM_VMW_MAX_SURFACE_FACES * DRM_VMW_MAX_MIP_LEVELS ||
752 num_sizes == 0)
753 return -EINVAL;
754
755 desc = vmw_surface_get_desc(req->format);
756 if (unlikely(desc->blockDesc == SVGA3DBLOCKDESC_NONE)) {
757 VMW_DEBUG_USER("Invalid format %d for surface creation.\n",
758 req->format);
759 return -EINVAL;
760 }
761
762 user_srf = kzalloc(sizeof(*user_srf), GFP_KERNEL);
763 if (unlikely(!user_srf)) {
764 ret = -ENOMEM;
765 goto out_unlock;
766 }
767
768 srf = &user_srf->srf;
769 metadata = &srf->metadata;
770 res = &srf->res;
771
772 /* Driver internally stores as 64-bit flags */
773 metadata->flags = (SVGA3dSurfaceAllFlags)req->flags;
774 metadata->format = req->format;
775 metadata->scanout = req->scanout;
776
777 memcpy(metadata->mip_levels, req->mip_levels,
778 sizeof(metadata->mip_levels));
779 metadata->num_sizes = num_sizes;
780 metadata->sizes =
781 memdup_array_user((struct drm_vmw_size __user *)(unsigned long)
782 req->size_addr,
783 metadata->num_sizes, sizeof(*metadata->sizes));
784 if (IS_ERR(metadata->sizes)) {
785 ret = PTR_ERR(metadata->sizes);
786 goto out_no_sizes;
787 }
788 srf->offsets = kmalloc_array(metadata->num_sizes, sizeof(*srf->offsets),
789 GFP_KERNEL);
790 if (unlikely(!srf->offsets)) {
791 ret = -ENOMEM;
792 goto out_no_offsets;
793 }
794
795 metadata->base_size = *srf->metadata.sizes;
796 metadata->autogen_filter = SVGA3D_TEX_FILTER_NONE;
797 metadata->multisample_count = 0;
798 metadata->multisample_pattern = SVGA3D_MS_PATTERN_NONE;
799 metadata->quality_level = SVGA3D_MS_QUALITY_NONE;
800
801 cur_bo_offset = 0;
802 cur_offset = srf->offsets;
803 cur_size = metadata->sizes;
804
805 for (i = 0; i < DRM_VMW_MAX_SURFACE_FACES; ++i) {
806 for (j = 0; j < metadata->mip_levels[i]; ++j) {
807 uint32_t stride = vmw_surface_calculate_pitch(
808 desc, cur_size);
809
810 cur_offset->face = i;
811 cur_offset->mip = j;
812 cur_offset->bo_offset = cur_bo_offset;
813 cur_bo_offset += vmw_surface_get_image_buffer_size
814 (desc, cur_size, stride);
815 ++cur_offset;
816 ++cur_size;
817 }
818 }
819 res->guest_memory_size = cur_bo_offset;
820 if (!file_priv->atomic &&
821 metadata->scanout &&
822 metadata->num_sizes == 1 &&
823 metadata->sizes[0].width == VMW_CURSOR_SNOOP_WIDTH &&
824 metadata->sizes[0].height == VMW_CURSOR_SNOOP_HEIGHT &&
825 metadata->format == VMW_CURSOR_SNOOP_FORMAT) {
826 const struct SVGA3dSurfaceDesc *desc =
827 vmw_surface_get_desc(VMW_CURSOR_SNOOP_FORMAT);
828 const u32 cursor_size_bytes = VMW_CURSOR_SNOOP_WIDTH *
829 VMW_CURSOR_SNOOP_HEIGHT *
830 desc->pitchBytesPerBlock;
831 srf->snooper.image = kzalloc(cursor_size_bytes, GFP_KERNEL);
832 if (!srf->snooper.image) {
833 DRM_ERROR("Failed to allocate cursor_image\n");
834 ret = -ENOMEM;
835 goto out_no_copy;
836 }
837 } else {
838 srf->snooper.image = NULL;
839 }
840
841 if (drm_is_primary_client(file_priv))
842 user_srf->master = drm_file_get_master(file_priv);
843
844 /**
845 * From this point, the generic resource management functions
846 * destroy the object on failure.
847 */
848
849 ret = vmw_surface_init(dev_priv, srf, vmw_user_surface_free);
850 if (unlikely(ret != 0))
851 goto out_unlock;
852
853 /*
854 * A gb-aware client referencing a surface will expect a backup
855 * buffer to be present.
856 */
857 if (dev_priv->has_mob) {
858 struct vmw_bo_params params = {
859 .domain = VMW_BO_DOMAIN_SYS,
860 .busy_domain = VMW_BO_DOMAIN_SYS,
861 .bo_type = ttm_bo_type_device,
862 .size = res->guest_memory_size,
863 .pin = false
864 };
865
866 ret = vmw_gem_object_create(dev_priv,
867 ¶ms,
868 &res->guest_memory_bo);
869 if (unlikely(ret != 0)) {
870 vmw_resource_unreference(&res);
871 goto out_unlock;
872 }
873
874 ret = vmw_bo_add_detached_resource(res->guest_memory_bo, res);
875 if (unlikely(ret != 0)) {
876 vmw_resource_unreference(&res);
877 goto out_unlock;
878 }
879 }
880
881 tmp = vmw_resource_reference(&srf->res);
882 ret = ttm_prime_object_init(tfile, res->guest_memory_size,
883 &user_srf->prime,
884 VMW_RES_SURFACE,
885 &vmw_user_surface_base_release);
886
887 if (unlikely(ret != 0)) {
888 vmw_resource_unreference(&tmp);
889 vmw_resource_unreference(&res);
890 goto out_unlock;
891 }
892
893 rep->sid = user_srf->prime.base.handle;
894 vmw_resource_unreference(&res);
895
896 return 0;
897 out_no_copy:
898 kfree(srf->offsets);
899 out_no_offsets:
900 kfree(metadata->sizes);
901 out_no_sizes:
902 ttm_prime_object_kfree(user_srf, prime);
903 out_unlock:
904 return ret;
905 }
906
907 static struct vmw_user_surface *
vmw_lookup_user_surface_for_buffer(struct vmw_private * vmw,struct vmw_bo * bo,u32 handle)908 vmw_lookup_user_surface_for_buffer(struct vmw_private *vmw, struct vmw_bo *bo,
909 u32 handle)
910 {
911 struct vmw_user_surface *user_srf = NULL;
912 struct vmw_surface *surf;
913 struct ttm_base_object *base;
914
915 surf = vmw_bo_surface(bo);
916 if (surf) {
917 rcu_read_lock();
918 user_srf = container_of(surf, struct vmw_user_surface, srf);
919 base = &user_srf->prime.base;
920 if (base && !kref_get_unless_zero(&base->refcount)) {
921 drm_dbg_driver(&vmw->drm,
922 "%s: referencing a stale surface handle %d\n",
923 __func__, handle);
924 base = NULL;
925 user_srf = NULL;
926 }
927 rcu_read_unlock();
928 }
929
930 return user_srf;
931 }
932
vmw_lookup_surface_for_buffer(struct vmw_private * vmw,struct vmw_bo * bo,u32 handle)933 struct vmw_surface *vmw_lookup_surface_for_buffer(struct vmw_private *vmw,
934 struct vmw_bo *bo,
935 u32 handle)
936 {
937 struct vmw_user_surface *user_srf =
938 vmw_lookup_user_surface_for_buffer(vmw, bo, handle);
939 struct vmw_surface *surf = NULL;
940 struct ttm_base_object *base;
941
942 if (user_srf) {
943 surf = vmw_surface_reference(&user_srf->srf);
944 base = &user_srf->prime.base;
945 ttm_base_object_unref(&base);
946 }
947 return surf;
948 }
949
vmw_lookup_surface_handle_for_buffer(struct vmw_private * vmw,struct vmw_bo * bo,u32 handle)950 u32 vmw_lookup_surface_handle_for_buffer(struct vmw_private *vmw,
951 struct vmw_bo *bo,
952 u32 handle)
953 {
954 struct vmw_user_surface *user_srf =
955 vmw_lookup_user_surface_for_buffer(vmw, bo, handle);
956 int surf_handle = 0;
957 struct ttm_base_object *base;
958
959 if (user_srf) {
960 base = &user_srf->prime.base;
961 surf_handle = (u32)base->handle;
962 ttm_base_object_unref(&base);
963 }
964 return surf_handle;
965 }
966
vmw_buffer_prime_to_surface_base(struct vmw_private * dev_priv,struct drm_file * file_priv,u32 fd,u32 * handle,struct ttm_base_object ** base_p)967 static int vmw_buffer_prime_to_surface_base(struct vmw_private *dev_priv,
968 struct drm_file *file_priv,
969 u32 fd, u32 *handle,
970 struct ttm_base_object **base_p)
971 {
972 struct ttm_base_object *base;
973 struct vmw_bo *bo;
974 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
975 struct vmw_user_surface *user_srf;
976 int ret;
977
978 ret = drm_gem_prime_fd_to_handle(&dev_priv->drm, file_priv, fd, handle);
979 if (ret) {
980 drm_warn(&dev_priv->drm,
981 "Wasn't able to find user buffer for fd = %u.\n", fd);
982 return ret;
983 }
984
985 ret = vmw_user_bo_lookup(file_priv, *handle, &bo);
986 if (ret) {
987 drm_warn(&dev_priv->drm,
988 "Wasn't able to lookup user buffer for handle = %u.\n", *handle);
989 return ret;
990 }
991
992 user_srf = vmw_lookup_user_surface_for_buffer(dev_priv, bo, *handle);
993 if (WARN_ON(!user_srf)) {
994 drm_warn(&dev_priv->drm,
995 "User surface fd %d (handle %d) is null.\n", fd, *handle);
996 ret = -EINVAL;
997 goto out;
998 }
999
1000 base = &user_srf->prime.base;
1001 ret = ttm_ref_object_add(tfile, base, NULL, false);
1002 if (ret) {
1003 drm_warn(&dev_priv->drm,
1004 "Couldn't add an object ref for the buffer (%d).\n", *handle);
1005 goto out;
1006 }
1007
1008 *base_p = base;
1009 out:
1010 vmw_user_bo_unref(&bo);
1011
1012 return ret;
1013 }
1014
1015 static int
vmw_surface_handle_reference(struct vmw_private * dev_priv,struct drm_file * file_priv,uint32_t u_handle,enum drm_vmw_handle_type handle_type,struct ttm_base_object ** base_p)1016 vmw_surface_handle_reference(struct vmw_private *dev_priv,
1017 struct drm_file *file_priv,
1018 uint32_t u_handle,
1019 enum drm_vmw_handle_type handle_type,
1020 struct ttm_base_object **base_p)
1021 {
1022 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
1023 struct vmw_user_surface *user_srf = NULL;
1024 uint32_t handle;
1025 struct ttm_base_object *base;
1026 int ret;
1027
1028 if (handle_type == DRM_VMW_HANDLE_PRIME) {
1029 ret = ttm_prime_fd_to_handle(tfile, u_handle, &handle);
1030 if (ret)
1031 return vmw_buffer_prime_to_surface_base(dev_priv,
1032 file_priv,
1033 u_handle,
1034 &handle,
1035 base_p);
1036 } else {
1037 handle = u_handle;
1038 }
1039
1040 ret = -EINVAL;
1041 base = ttm_base_object_lookup_for_ref(dev_priv->tdev, handle);
1042 if (unlikely(!base)) {
1043 VMW_DEBUG_USER("Could not find surface to reference.\n");
1044 goto out_no_lookup;
1045 }
1046
1047 if (unlikely(ttm_base_object_type(base) != VMW_RES_SURFACE)) {
1048 VMW_DEBUG_USER("Referenced object is not a surface.\n");
1049 goto out_bad_resource;
1050 }
1051 if (handle_type != DRM_VMW_HANDLE_PRIME) {
1052 bool require_exist = false;
1053
1054 user_srf = container_of(base, struct vmw_user_surface,
1055 prime.base);
1056
1057 /* Error out if we are unauthenticated primary */
1058 if (drm_is_primary_client(file_priv) &&
1059 !file_priv->authenticated) {
1060 ret = -EACCES;
1061 goto out_bad_resource;
1062 }
1063
1064 /*
1065 * Make sure the surface creator has the same
1066 * authenticating master, or is already registered with us.
1067 */
1068 if (drm_is_primary_client(file_priv) &&
1069 user_srf->master != file_priv->master)
1070 require_exist = true;
1071
1072 if (unlikely(drm_is_render_client(file_priv)))
1073 require_exist = true;
1074
1075 ret = ttm_ref_object_add(tfile, base, NULL, require_exist);
1076 if (unlikely(ret != 0)) {
1077 DRM_ERROR("Could not add a reference to a surface.\n");
1078 goto out_bad_resource;
1079 }
1080 }
1081
1082 *base_p = base;
1083 return 0;
1084
1085 out_bad_resource:
1086 ttm_base_object_unref(&base);
1087 out_no_lookup:
1088 if (handle_type == DRM_VMW_HANDLE_PRIME)
1089 (void) ttm_ref_object_base_unref(tfile, handle);
1090
1091 return ret;
1092 }
1093
1094 /**
1095 * vmw_surface_reference_ioctl - Ioctl function implementing
1096 * the user surface reference functionality.
1097 *
1098 * @dev: Pointer to a struct drm_device.
1099 * @data: Pointer to data copied from / to user-space.
1100 * @file_priv: Pointer to a drm file private structure.
1101 */
vmw_surface_reference_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)1102 int vmw_surface_reference_ioctl(struct drm_device *dev, void *data,
1103 struct drm_file *file_priv)
1104 {
1105 struct vmw_private *dev_priv = vmw_priv(dev);
1106 union drm_vmw_surface_reference_arg *arg =
1107 (union drm_vmw_surface_reference_arg *)data;
1108 struct drm_vmw_surface_arg *req = &arg->req;
1109 struct drm_vmw_surface_create_req *rep = &arg->rep;
1110 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
1111 struct vmw_surface *srf;
1112 struct vmw_user_surface *user_srf;
1113 struct drm_vmw_size __user *user_sizes;
1114 struct ttm_base_object *base;
1115 int ret;
1116
1117 ret = vmw_surface_handle_reference(dev_priv, file_priv, req->sid,
1118 req->handle_type, &base);
1119 if (unlikely(ret != 0))
1120 return ret;
1121
1122 user_srf = container_of(base, struct vmw_user_surface, prime.base);
1123 srf = &user_srf->srf;
1124
1125 /* Downcast of flags when sending back to user space */
1126 rep->flags = (uint32_t)srf->metadata.flags;
1127 rep->format = srf->metadata.format;
1128 memcpy(rep->mip_levels, srf->metadata.mip_levels,
1129 sizeof(srf->metadata.mip_levels));
1130 user_sizes = (struct drm_vmw_size __user *)(unsigned long)
1131 rep->size_addr;
1132
1133 if (user_sizes)
1134 ret = copy_to_user(user_sizes, &srf->metadata.base_size,
1135 sizeof(srf->metadata.base_size));
1136 if (unlikely(ret != 0)) {
1137 VMW_DEBUG_USER("copy_to_user failed %p %u\n", user_sizes,
1138 srf->metadata.num_sizes);
1139 ttm_ref_object_base_unref(tfile, base->handle);
1140 ret = -EFAULT;
1141 }
1142
1143 ttm_base_object_unref(&base);
1144
1145 return ret;
1146 }
1147
1148 /**
1149 * vmw_gb_surface_create - Encode a surface_define command.
1150 *
1151 * @res: Pointer to a struct vmw_resource embedded in a struct
1152 * vmw_surface.
1153 */
vmw_gb_surface_create(struct vmw_resource * res)1154 static int vmw_gb_surface_create(struct vmw_resource *res)
1155 {
1156 struct vmw_private *dev_priv = res->dev_priv;
1157 struct vmw_surface *srf = vmw_res_to_srf(res);
1158 struct vmw_surface_metadata *metadata = &srf->metadata;
1159 uint32_t cmd_len, cmd_id, submit_len;
1160 int ret;
1161 struct {
1162 SVGA3dCmdHeader header;
1163 SVGA3dCmdDefineGBSurface body;
1164 } *cmd;
1165 struct {
1166 SVGA3dCmdHeader header;
1167 SVGA3dCmdDefineGBSurface_v2 body;
1168 } *cmd2;
1169 struct {
1170 SVGA3dCmdHeader header;
1171 SVGA3dCmdDefineGBSurface_v3 body;
1172 } *cmd3;
1173 struct {
1174 SVGA3dCmdHeader header;
1175 SVGA3dCmdDefineGBSurface_v4 body;
1176 } *cmd4;
1177
1178 if (likely(res->id != -1))
1179 return 0;
1180
1181 vmw_fifo_resource_inc(dev_priv);
1182 ret = vmw_resource_alloc_id(res);
1183 if (unlikely(ret != 0)) {
1184 DRM_ERROR("Failed to allocate a surface id.\n");
1185 goto out_no_id;
1186 }
1187
1188 if (unlikely(res->id >= VMWGFX_NUM_GB_SURFACE)) {
1189 ret = -EBUSY;
1190 goto out_no_fifo;
1191 }
1192
1193 if (has_sm5_context(dev_priv) && metadata->array_size > 0) {
1194 cmd_id = SVGA_3D_CMD_DEFINE_GB_SURFACE_V4;
1195 cmd_len = sizeof(cmd4->body);
1196 submit_len = sizeof(*cmd4);
1197 } else if (has_sm4_1_context(dev_priv) && metadata->array_size > 0) {
1198 cmd_id = SVGA_3D_CMD_DEFINE_GB_SURFACE_V3;
1199 cmd_len = sizeof(cmd3->body);
1200 submit_len = sizeof(*cmd3);
1201 } else if (metadata->array_size > 0) {
1202 /* VMW_SM_4 support verified at creation time. */
1203 cmd_id = SVGA_3D_CMD_DEFINE_GB_SURFACE_V2;
1204 cmd_len = sizeof(cmd2->body);
1205 submit_len = sizeof(*cmd2);
1206 } else {
1207 cmd_id = SVGA_3D_CMD_DEFINE_GB_SURFACE;
1208 cmd_len = sizeof(cmd->body);
1209 submit_len = sizeof(*cmd);
1210 }
1211
1212 cmd = VMW_CMD_RESERVE(dev_priv, submit_len);
1213 cmd2 = (typeof(cmd2))cmd;
1214 cmd3 = (typeof(cmd3))cmd;
1215 cmd4 = (typeof(cmd4))cmd;
1216 if (unlikely(!cmd)) {
1217 ret = -ENOMEM;
1218 goto out_no_fifo;
1219 }
1220
1221 if (has_sm5_context(dev_priv) && metadata->array_size > 0) {
1222 cmd4->header.id = cmd_id;
1223 cmd4->header.size = cmd_len;
1224 cmd4->body.sid = srf->res.id;
1225 cmd4->body.surfaceFlags = metadata->flags;
1226 cmd4->body.format = metadata->format;
1227 cmd4->body.numMipLevels = metadata->mip_levels[0];
1228 cmd4->body.multisampleCount = metadata->multisample_count;
1229 cmd4->body.multisamplePattern = metadata->multisample_pattern;
1230 cmd4->body.qualityLevel = metadata->quality_level;
1231 cmd4->body.autogenFilter = metadata->autogen_filter;
1232 cmd4->body.size.width = metadata->base_size.width;
1233 cmd4->body.size.height = metadata->base_size.height;
1234 cmd4->body.size.depth = metadata->base_size.depth;
1235 cmd4->body.arraySize = metadata->array_size;
1236 cmd4->body.bufferByteStride = metadata->buffer_byte_stride;
1237 } else if (has_sm4_1_context(dev_priv) && metadata->array_size > 0) {
1238 cmd3->header.id = cmd_id;
1239 cmd3->header.size = cmd_len;
1240 cmd3->body.sid = srf->res.id;
1241 cmd3->body.surfaceFlags = metadata->flags;
1242 cmd3->body.format = metadata->format;
1243 cmd3->body.numMipLevels = metadata->mip_levels[0];
1244 cmd3->body.multisampleCount = metadata->multisample_count;
1245 cmd3->body.multisamplePattern = metadata->multisample_pattern;
1246 cmd3->body.qualityLevel = metadata->quality_level;
1247 cmd3->body.autogenFilter = metadata->autogen_filter;
1248 cmd3->body.size.width = metadata->base_size.width;
1249 cmd3->body.size.height = metadata->base_size.height;
1250 cmd3->body.size.depth = metadata->base_size.depth;
1251 cmd3->body.arraySize = metadata->array_size;
1252 } else if (metadata->array_size > 0) {
1253 cmd2->header.id = cmd_id;
1254 cmd2->header.size = cmd_len;
1255 cmd2->body.sid = srf->res.id;
1256 cmd2->body.surfaceFlags = metadata->flags;
1257 cmd2->body.format = metadata->format;
1258 cmd2->body.numMipLevels = metadata->mip_levels[0];
1259 cmd2->body.multisampleCount = metadata->multisample_count;
1260 cmd2->body.autogenFilter = metadata->autogen_filter;
1261 cmd2->body.size.width = metadata->base_size.width;
1262 cmd2->body.size.height = metadata->base_size.height;
1263 cmd2->body.size.depth = metadata->base_size.depth;
1264 cmd2->body.arraySize = metadata->array_size;
1265 } else {
1266 cmd->header.id = cmd_id;
1267 cmd->header.size = cmd_len;
1268 cmd->body.sid = srf->res.id;
1269 cmd->body.surfaceFlags = metadata->flags;
1270 cmd->body.format = metadata->format;
1271 cmd->body.numMipLevels = metadata->mip_levels[0];
1272 cmd->body.multisampleCount = metadata->multisample_count;
1273 cmd->body.autogenFilter = metadata->autogen_filter;
1274 cmd->body.size.width = metadata->base_size.width;
1275 cmd->body.size.height = metadata->base_size.height;
1276 cmd->body.size.depth = metadata->base_size.depth;
1277 }
1278
1279 vmw_cmd_commit(dev_priv, submit_len);
1280
1281 return 0;
1282
1283 out_no_fifo:
1284 vmw_resource_release_id(res);
1285 out_no_id:
1286 vmw_fifo_resource_dec(dev_priv);
1287 return ret;
1288 }
1289
1290
vmw_gb_surface_bind(struct vmw_resource * res,struct ttm_validate_buffer * val_buf)1291 static int vmw_gb_surface_bind(struct vmw_resource *res,
1292 struct ttm_validate_buffer *val_buf)
1293 {
1294 struct vmw_private *dev_priv = res->dev_priv;
1295 struct {
1296 SVGA3dCmdHeader header;
1297 SVGA3dCmdBindGBSurface body;
1298 } *cmd1;
1299 struct {
1300 SVGA3dCmdHeader header;
1301 SVGA3dCmdUpdateGBSurface body;
1302 } *cmd2;
1303 uint32_t submit_size;
1304 struct ttm_buffer_object *bo = val_buf->bo;
1305
1306 BUG_ON(bo->resource->mem_type != VMW_PL_MOB);
1307
1308 submit_size = sizeof(*cmd1) + (res->guest_memory_dirty ? sizeof(*cmd2) : 0);
1309
1310 cmd1 = VMW_CMD_RESERVE(dev_priv, submit_size);
1311 if (unlikely(!cmd1))
1312 return -ENOMEM;
1313
1314 cmd1->header.id = SVGA_3D_CMD_BIND_GB_SURFACE;
1315 cmd1->header.size = sizeof(cmd1->body);
1316 cmd1->body.sid = res->id;
1317 cmd1->body.mobid = bo->resource->start;
1318 if (res->guest_memory_dirty) {
1319 cmd2 = (void *) &cmd1[1];
1320 cmd2->header.id = SVGA_3D_CMD_UPDATE_GB_SURFACE;
1321 cmd2->header.size = sizeof(cmd2->body);
1322 cmd2->body.sid = res->id;
1323 }
1324 vmw_cmd_commit(dev_priv, submit_size);
1325
1326 if (res->guest_memory_bo->dirty && res->guest_memory_dirty) {
1327 /* We've just made a full upload. Cear dirty regions. */
1328 vmw_bo_dirty_clear_res(res);
1329 }
1330
1331 res->guest_memory_dirty = false;
1332
1333 return 0;
1334 }
1335
vmw_gb_surface_unbind(struct vmw_resource * res,bool readback,struct ttm_validate_buffer * val_buf)1336 static int vmw_gb_surface_unbind(struct vmw_resource *res,
1337 bool readback,
1338 struct ttm_validate_buffer *val_buf)
1339 {
1340 struct vmw_private *dev_priv = res->dev_priv;
1341 struct ttm_buffer_object *bo = val_buf->bo;
1342 struct vmw_fence_obj *fence;
1343
1344 struct {
1345 SVGA3dCmdHeader header;
1346 SVGA3dCmdReadbackGBSurface body;
1347 } *cmd1;
1348 struct {
1349 SVGA3dCmdHeader header;
1350 SVGA3dCmdInvalidateGBSurface body;
1351 } *cmd2;
1352 struct {
1353 SVGA3dCmdHeader header;
1354 SVGA3dCmdBindGBSurface body;
1355 } *cmd3;
1356 uint32_t submit_size;
1357 uint8_t *cmd;
1358
1359
1360 BUG_ON(bo->resource->mem_type != VMW_PL_MOB);
1361
1362 submit_size = sizeof(*cmd3) + (readback ? sizeof(*cmd1) : sizeof(*cmd2));
1363 cmd = VMW_CMD_RESERVE(dev_priv, submit_size);
1364 if (unlikely(!cmd))
1365 return -ENOMEM;
1366
1367 if (readback) {
1368 cmd1 = (void *) cmd;
1369 cmd1->header.id = SVGA_3D_CMD_READBACK_GB_SURFACE;
1370 cmd1->header.size = sizeof(cmd1->body);
1371 cmd1->body.sid = res->id;
1372 cmd3 = (void *) &cmd1[1];
1373 } else {
1374 cmd2 = (void *) cmd;
1375 cmd2->header.id = SVGA_3D_CMD_INVALIDATE_GB_SURFACE;
1376 cmd2->header.size = sizeof(cmd2->body);
1377 cmd2->body.sid = res->id;
1378 cmd3 = (void *) &cmd2[1];
1379 }
1380
1381 cmd3->header.id = SVGA_3D_CMD_BIND_GB_SURFACE;
1382 cmd3->header.size = sizeof(cmd3->body);
1383 cmd3->body.sid = res->id;
1384 cmd3->body.mobid = SVGA3D_INVALID_ID;
1385
1386 vmw_cmd_commit(dev_priv, submit_size);
1387
1388 /*
1389 * Create a fence object and fence the backup buffer.
1390 */
1391
1392 (void) vmw_execbuf_fence_commands(NULL, dev_priv,
1393 &fence, NULL);
1394
1395 vmw_bo_fence_single(val_buf->bo, fence);
1396
1397 if (likely(fence != NULL))
1398 vmw_fence_obj_unreference(&fence);
1399
1400 return 0;
1401 }
1402
vmw_gb_surface_destroy(struct vmw_resource * res)1403 static int vmw_gb_surface_destroy(struct vmw_resource *res)
1404 {
1405 struct vmw_private *dev_priv = res->dev_priv;
1406 struct vmw_surface *srf = vmw_res_to_srf(res);
1407 struct {
1408 SVGA3dCmdHeader header;
1409 SVGA3dCmdDestroyGBSurface body;
1410 } *cmd;
1411
1412 if (likely(res->id == -1))
1413 return 0;
1414
1415 mutex_lock(&dev_priv->binding_mutex);
1416 vmw_view_surface_list_destroy(dev_priv, &srf->view_list);
1417 vmw_binding_res_list_scrub(&res->binding_head);
1418
1419 cmd = VMW_CMD_RESERVE(dev_priv, sizeof(*cmd));
1420 if (unlikely(!cmd)) {
1421 mutex_unlock(&dev_priv->binding_mutex);
1422 return -ENOMEM;
1423 }
1424
1425 cmd->header.id = SVGA_3D_CMD_DESTROY_GB_SURFACE;
1426 cmd->header.size = sizeof(cmd->body);
1427 cmd->body.sid = res->id;
1428 vmw_cmd_commit(dev_priv, sizeof(*cmd));
1429 mutex_unlock(&dev_priv->binding_mutex);
1430 vmw_resource_release_id(res);
1431 vmw_fifo_resource_dec(dev_priv);
1432
1433 return 0;
1434 }
1435
1436 /**
1437 * vmw_gb_surface_define_ioctl - Ioctl function implementing
1438 * the user surface define functionality.
1439 *
1440 * @dev: Pointer to a struct drm_device.
1441 * @data: Pointer to data copied from / to user-space.
1442 * @file_priv: Pointer to a drm file private structure.
1443 */
vmw_gb_surface_define_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)1444 int vmw_gb_surface_define_ioctl(struct drm_device *dev, void *data,
1445 struct drm_file *file_priv)
1446 {
1447 union drm_vmw_gb_surface_create_arg *arg =
1448 (union drm_vmw_gb_surface_create_arg *)data;
1449 struct drm_vmw_gb_surface_create_rep *rep = &arg->rep;
1450 struct drm_vmw_gb_surface_create_ext_req req_ext;
1451
1452 req_ext.base = arg->req;
1453 req_ext.version = drm_vmw_gb_surface_v1;
1454 req_ext.svga3d_flags_upper_32_bits = 0;
1455 req_ext.multisample_pattern = SVGA3D_MS_PATTERN_NONE;
1456 req_ext.quality_level = SVGA3D_MS_QUALITY_NONE;
1457 req_ext.buffer_byte_stride = 0;
1458 req_ext.must_be_zero = 0;
1459
1460 return vmw_gb_surface_define_internal(dev, &req_ext, rep, file_priv);
1461 }
1462
1463 /**
1464 * vmw_gb_surface_reference_ioctl - Ioctl function implementing
1465 * the user surface reference functionality.
1466 *
1467 * @dev: Pointer to a struct drm_device.
1468 * @data: Pointer to data copied from / to user-space.
1469 * @file_priv: Pointer to a drm file private structure.
1470 */
vmw_gb_surface_reference_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)1471 int vmw_gb_surface_reference_ioctl(struct drm_device *dev, void *data,
1472 struct drm_file *file_priv)
1473 {
1474 union drm_vmw_gb_surface_reference_arg *arg =
1475 (union drm_vmw_gb_surface_reference_arg *)data;
1476 struct drm_vmw_surface_arg *req = &arg->req;
1477 struct drm_vmw_gb_surface_ref_rep *rep = &arg->rep;
1478 struct drm_vmw_gb_surface_ref_ext_rep rep_ext;
1479 int ret;
1480
1481 ret = vmw_gb_surface_reference_internal(dev, req, &rep_ext, file_priv);
1482
1483 if (unlikely(ret != 0))
1484 return ret;
1485
1486 rep->creq = rep_ext.creq.base;
1487 rep->crep = rep_ext.crep;
1488
1489 return ret;
1490 }
1491
1492 /**
1493 * vmw_gb_surface_define_ext_ioctl - Ioctl function implementing
1494 * the user surface define functionality.
1495 *
1496 * @dev: Pointer to a struct drm_device.
1497 * @data: Pointer to data copied from / to user-space.
1498 * @file_priv: Pointer to a drm file private structure.
1499 */
vmw_gb_surface_define_ext_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)1500 int vmw_gb_surface_define_ext_ioctl(struct drm_device *dev, void *data,
1501 struct drm_file *file_priv)
1502 {
1503 union drm_vmw_gb_surface_create_ext_arg *arg =
1504 (union drm_vmw_gb_surface_create_ext_arg *)data;
1505 struct drm_vmw_gb_surface_create_ext_req *req = &arg->req;
1506 struct drm_vmw_gb_surface_create_rep *rep = &arg->rep;
1507
1508 return vmw_gb_surface_define_internal(dev, req, rep, file_priv);
1509 }
1510
1511 /**
1512 * vmw_gb_surface_reference_ext_ioctl - Ioctl function implementing
1513 * the user surface reference functionality.
1514 *
1515 * @dev: Pointer to a struct drm_device.
1516 * @data: Pointer to data copied from / to user-space.
1517 * @file_priv: Pointer to a drm file private structure.
1518 */
vmw_gb_surface_reference_ext_ioctl(struct drm_device * dev,void * data,struct drm_file * file_priv)1519 int vmw_gb_surface_reference_ext_ioctl(struct drm_device *dev, void *data,
1520 struct drm_file *file_priv)
1521 {
1522 union drm_vmw_gb_surface_reference_ext_arg *arg =
1523 (union drm_vmw_gb_surface_reference_ext_arg *)data;
1524 struct drm_vmw_surface_arg *req = &arg->req;
1525 struct drm_vmw_gb_surface_ref_ext_rep *rep = &arg->rep;
1526
1527 return vmw_gb_surface_reference_internal(dev, req, rep, file_priv);
1528 }
1529
1530 /**
1531 * vmw_gb_surface_define_internal - Ioctl function implementing
1532 * the user surface define functionality.
1533 *
1534 * @dev: Pointer to a struct drm_device.
1535 * @req: Request argument from user-space.
1536 * @rep: Response argument to user-space.
1537 * @file_priv: Pointer to a drm file private structure.
1538 */
1539 static int
vmw_gb_surface_define_internal(struct drm_device * dev,struct drm_vmw_gb_surface_create_ext_req * req,struct drm_vmw_gb_surface_create_rep * rep,struct drm_file * file_priv)1540 vmw_gb_surface_define_internal(struct drm_device *dev,
1541 struct drm_vmw_gb_surface_create_ext_req *req,
1542 struct drm_vmw_gb_surface_create_rep *rep,
1543 struct drm_file *file_priv)
1544 {
1545 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
1546 struct vmw_private *dev_priv = vmw_priv(dev);
1547 struct vmw_user_surface *user_srf;
1548 struct vmw_surface_metadata metadata = {0};
1549 struct vmw_surface *srf;
1550 struct vmw_resource *res;
1551 struct vmw_resource *tmp;
1552 int ret = 0;
1553 uint32_t backup_handle = 0;
1554 SVGA3dSurfaceAllFlags svga3d_flags_64 =
1555 SVGA3D_FLAGS_64(req->svga3d_flags_upper_32_bits,
1556 req->base.svga3d_flags);
1557
1558 /* array_size must be null for non-GL3 host. */
1559 if (req->base.array_size > 0 && !has_sm4_context(dev_priv)) {
1560 VMW_DEBUG_USER("SM4 surface not supported.\n");
1561 return -EINVAL;
1562 }
1563
1564 if (!has_sm4_1_context(dev_priv)) {
1565 if (req->svga3d_flags_upper_32_bits != 0)
1566 ret = -EINVAL;
1567
1568 if (req->base.multisample_count != 0)
1569 ret = -EINVAL;
1570
1571 if (req->multisample_pattern != SVGA3D_MS_PATTERN_NONE)
1572 ret = -EINVAL;
1573
1574 if (req->quality_level != SVGA3D_MS_QUALITY_NONE)
1575 ret = -EINVAL;
1576
1577 if (ret) {
1578 VMW_DEBUG_USER("SM4.1 surface not supported.\n");
1579 return ret;
1580 }
1581 }
1582
1583 if (req->buffer_byte_stride > 0 && !has_sm5_context(dev_priv)) {
1584 VMW_DEBUG_USER("SM5 surface not supported.\n");
1585 return -EINVAL;
1586 }
1587
1588 if ((svga3d_flags_64 & SVGA3D_SURFACE_MULTISAMPLE) &&
1589 req->base.multisample_count == 0) {
1590 VMW_DEBUG_USER("Invalid sample count.\n");
1591 return -EINVAL;
1592 }
1593
1594 if (req->base.mip_levels > DRM_VMW_MAX_MIP_LEVELS) {
1595 VMW_DEBUG_USER("Invalid mip level.\n");
1596 return -EINVAL;
1597 }
1598
1599 metadata.flags = svga3d_flags_64;
1600 metadata.format = req->base.format;
1601 metadata.mip_levels[0] = req->base.mip_levels;
1602 metadata.multisample_count = req->base.multisample_count;
1603 metadata.multisample_pattern = req->multisample_pattern;
1604 metadata.quality_level = req->quality_level;
1605 metadata.array_size = req->base.array_size;
1606 metadata.buffer_byte_stride = req->buffer_byte_stride;
1607 metadata.num_sizes = 1;
1608 metadata.base_size = req->base.base_size;
1609 metadata.scanout = req->base.drm_surface_flags &
1610 drm_vmw_surface_flag_scanout;
1611
1612 /* Define a surface based on the parameters. */
1613 ret = vmw_gb_surface_define(dev_priv, &metadata, &srf);
1614 if (ret != 0) {
1615 VMW_DEBUG_USER("Failed to define surface.\n");
1616 return ret;
1617 }
1618
1619 user_srf = container_of(srf, struct vmw_user_surface, srf);
1620 if (drm_is_primary_client(file_priv))
1621 user_srf->master = drm_file_get_master(file_priv);
1622
1623 res = &user_srf->srf.res;
1624
1625 if (req->base.buffer_handle != SVGA3D_INVALID_ID) {
1626 ret = vmw_user_bo_lookup(file_priv, req->base.buffer_handle,
1627 &res->guest_memory_bo);
1628 if (ret == 0) {
1629 if (res->guest_memory_bo->is_dumb) {
1630 VMW_DEBUG_USER("Can't backup surface with a dumb buffer.\n");
1631 vmw_user_bo_unref(&res->guest_memory_bo);
1632 ret = -EINVAL;
1633 goto out_unlock;
1634 } else if (res->guest_memory_bo->tbo.base.size < res->guest_memory_size) {
1635 VMW_DEBUG_USER("Surface backup buffer too small.\n");
1636 vmw_user_bo_unref(&res->guest_memory_bo);
1637 ret = -EINVAL;
1638 goto out_unlock;
1639 } else {
1640 backup_handle = req->base.buffer_handle;
1641 }
1642 }
1643 } else if (req->base.drm_surface_flags &
1644 (drm_vmw_surface_flag_create_buffer |
1645 drm_vmw_surface_flag_coherent)) {
1646 ret = vmw_gem_object_create_with_handle(dev_priv, file_priv,
1647 res->guest_memory_size,
1648 &backup_handle,
1649 &res->guest_memory_bo);
1650 }
1651
1652 if (unlikely(ret != 0)) {
1653 vmw_resource_unreference(&res);
1654 goto out_unlock;
1655 }
1656
1657 if (req->base.drm_surface_flags & drm_vmw_surface_flag_coherent) {
1658 struct vmw_bo *backup = res->guest_memory_bo;
1659
1660 ttm_bo_reserve(&backup->tbo, false, false, NULL);
1661 if (!res->func->dirty_alloc)
1662 ret = -EINVAL;
1663 if (!ret)
1664 ret = vmw_bo_dirty_add(backup);
1665 if (!ret) {
1666 res->coherent = true;
1667 ret = res->func->dirty_alloc(res);
1668 }
1669 ttm_bo_unreserve(&backup->tbo);
1670 if (ret) {
1671 vmw_resource_unreference(&res);
1672 goto out_unlock;
1673 }
1674
1675 }
1676
1677 if (res->guest_memory_bo) {
1678 ret = vmw_bo_add_detached_resource(res->guest_memory_bo, res);
1679 if (unlikely(ret != 0)) {
1680 vmw_resource_unreference(&res);
1681 goto out_unlock;
1682 }
1683 }
1684
1685 tmp = vmw_resource_reference(res);
1686 ret = ttm_prime_object_init(tfile, res->guest_memory_size, &user_srf->prime,
1687 VMW_RES_SURFACE,
1688 &vmw_user_surface_base_release);
1689
1690 if (unlikely(ret != 0)) {
1691 vmw_resource_unreference(&tmp);
1692 vmw_resource_unreference(&res);
1693 goto out_unlock;
1694 }
1695
1696 rep->handle = user_srf->prime.base.handle;
1697 rep->backup_size = res->guest_memory_size;
1698 if (res->guest_memory_bo) {
1699 rep->buffer_map_handle =
1700 drm_vma_node_offset_addr(&res->guest_memory_bo->tbo.base.vma_node);
1701 rep->buffer_size = res->guest_memory_bo->tbo.base.size;
1702 rep->buffer_handle = backup_handle;
1703 } else {
1704 rep->buffer_map_handle = 0;
1705 rep->buffer_size = 0;
1706 rep->buffer_handle = SVGA3D_INVALID_ID;
1707 }
1708 vmw_resource_unreference(&res);
1709
1710 out_unlock:
1711 return ret;
1712 }
1713
1714 /**
1715 * vmw_gb_surface_reference_internal - Ioctl function implementing
1716 * the user surface reference functionality.
1717 *
1718 * @dev: Pointer to a struct drm_device.
1719 * @req: Pointer to user-space request surface arg.
1720 * @rep: Pointer to response to user-space.
1721 * @file_priv: Pointer to a drm file private structure.
1722 */
1723 static int
vmw_gb_surface_reference_internal(struct drm_device * dev,struct drm_vmw_surface_arg * req,struct drm_vmw_gb_surface_ref_ext_rep * rep,struct drm_file * file_priv)1724 vmw_gb_surface_reference_internal(struct drm_device *dev,
1725 struct drm_vmw_surface_arg *req,
1726 struct drm_vmw_gb_surface_ref_ext_rep *rep,
1727 struct drm_file *file_priv)
1728 {
1729 struct vmw_private *dev_priv = vmw_priv(dev);
1730 struct vmw_surface *srf;
1731 struct vmw_user_surface *user_srf;
1732 struct vmw_surface_metadata *metadata;
1733 struct ttm_base_object *base;
1734 u32 backup_handle;
1735 int ret;
1736
1737 ret = vmw_surface_handle_reference(dev_priv, file_priv, req->sid,
1738 req->handle_type, &base);
1739 if (unlikely(ret != 0))
1740 return ret;
1741
1742 user_srf = container_of(base, struct vmw_user_surface, prime.base);
1743 srf = &user_srf->srf;
1744 if (!srf->res.guest_memory_bo) {
1745 DRM_ERROR("Shared GB surface is missing a backup buffer.\n");
1746 goto out_bad_resource;
1747 }
1748 metadata = &srf->metadata;
1749
1750 mutex_lock(&dev_priv->cmdbuf_mutex); /* Protect res->backup */
1751 ret = drm_gem_handle_create(file_priv, &srf->res.guest_memory_bo->tbo.base,
1752 &backup_handle);
1753 mutex_unlock(&dev_priv->cmdbuf_mutex);
1754 if (ret != 0) {
1755 drm_err(dev, "Wasn't able to create a backing handle for surface sid = %u.\n",
1756 req->sid);
1757 goto out_bad_resource;
1758 }
1759
1760 rep->creq.base.svga3d_flags = SVGA3D_FLAGS_LOWER_32(metadata->flags);
1761 rep->creq.base.format = metadata->format;
1762 rep->creq.base.mip_levels = metadata->mip_levels[0];
1763 rep->creq.base.drm_surface_flags = 0;
1764 rep->creq.base.multisample_count = metadata->multisample_count;
1765 rep->creq.base.autogen_filter = metadata->autogen_filter;
1766 rep->creq.base.array_size = metadata->array_size;
1767 rep->creq.base.buffer_handle = backup_handle;
1768 rep->creq.base.base_size = metadata->base_size;
1769 rep->crep.handle = user_srf->prime.base.handle;
1770 rep->crep.backup_size = srf->res.guest_memory_size;
1771 rep->crep.buffer_handle = backup_handle;
1772 rep->crep.buffer_map_handle =
1773 drm_vma_node_offset_addr(&srf->res.guest_memory_bo->tbo.base.vma_node);
1774 rep->crep.buffer_size = srf->res.guest_memory_bo->tbo.base.size;
1775
1776 rep->creq.version = drm_vmw_gb_surface_v1;
1777 rep->creq.svga3d_flags_upper_32_bits =
1778 SVGA3D_FLAGS_UPPER_32(metadata->flags);
1779 rep->creq.multisample_pattern = metadata->multisample_pattern;
1780 rep->creq.quality_level = metadata->quality_level;
1781 rep->creq.must_be_zero = 0;
1782
1783 out_bad_resource:
1784 ttm_base_object_unref(&base);
1785
1786 return ret;
1787 }
1788
1789 /**
1790 * vmw_subres_dirty_add - Add a dirty region to a subresource
1791 * @dirty: The surfaces's dirty tracker.
1792 * @loc_start: The location corresponding to the start of the region.
1793 * @loc_end: The location corresponding to the end of the region.
1794 *
1795 * As we are assuming that @loc_start and @loc_end represent a sequential
1796 * range of backing store memory, if the region spans multiple lines then
1797 * regardless of the x coordinate, the full lines are dirtied.
1798 * Correspondingly if the region spans multiple z slices, then full rather
1799 * than partial z slices are dirtied.
1800 */
vmw_subres_dirty_add(struct vmw_surface_dirty * dirty,const struct vmw_surface_loc * loc_start,const struct vmw_surface_loc * loc_end)1801 static void vmw_subres_dirty_add(struct vmw_surface_dirty *dirty,
1802 const struct vmw_surface_loc *loc_start,
1803 const struct vmw_surface_loc *loc_end)
1804 {
1805 const struct vmw_surface_cache *cache = &dirty->cache;
1806 SVGA3dBox *box = &dirty->boxes[loc_start->sub_resource];
1807 u32 mip = loc_start->sub_resource % cache->num_mip_levels;
1808 const struct drm_vmw_size *size = &cache->mip[mip].size;
1809 u32 box_c2 = box->z + box->d;
1810
1811 if (WARN_ON(loc_start->sub_resource >= dirty->num_subres))
1812 return;
1813
1814 if (box->d == 0 || box->z > loc_start->z)
1815 box->z = loc_start->z;
1816 if (box_c2 < loc_end->z)
1817 box->d = loc_end->z - box->z;
1818
1819 if (loc_start->z + 1 == loc_end->z) {
1820 box_c2 = box->y + box->h;
1821 if (box->h == 0 || box->y > loc_start->y)
1822 box->y = loc_start->y;
1823 if (box_c2 < loc_end->y)
1824 box->h = loc_end->y - box->y;
1825
1826 if (loc_start->y + 1 == loc_end->y) {
1827 box_c2 = box->x + box->w;
1828 if (box->w == 0 || box->x > loc_start->x)
1829 box->x = loc_start->x;
1830 if (box_c2 < loc_end->x)
1831 box->w = loc_end->x - box->x;
1832 } else {
1833 box->x = 0;
1834 box->w = size->width;
1835 }
1836 } else {
1837 box->y = 0;
1838 box->h = size->height;
1839 box->x = 0;
1840 box->w = size->width;
1841 }
1842 }
1843
1844 /**
1845 * vmw_subres_dirty_full - Mark a full subresource as dirty
1846 * @dirty: The surface's dirty tracker.
1847 * @subres: The subresource
1848 */
vmw_subres_dirty_full(struct vmw_surface_dirty * dirty,u32 subres)1849 static void vmw_subres_dirty_full(struct vmw_surface_dirty *dirty, u32 subres)
1850 {
1851 const struct vmw_surface_cache *cache = &dirty->cache;
1852 u32 mip = subres % cache->num_mip_levels;
1853 const struct drm_vmw_size *size = &cache->mip[mip].size;
1854 SVGA3dBox *box = &dirty->boxes[subres];
1855
1856 box->x = 0;
1857 box->y = 0;
1858 box->z = 0;
1859 box->w = size->width;
1860 box->h = size->height;
1861 box->d = size->depth;
1862 }
1863
1864 /*
1865 * vmw_surface_tex_dirty_add_range - The dirty_add_range callback for texture
1866 * surfaces.
1867 */
vmw_surface_tex_dirty_range_add(struct vmw_resource * res,size_t start,size_t end)1868 static void vmw_surface_tex_dirty_range_add(struct vmw_resource *res,
1869 size_t start, size_t end)
1870 {
1871 struct vmw_surface_dirty *dirty =
1872 (struct vmw_surface_dirty *) res->dirty;
1873 size_t backup_end = res->guest_memory_offset + res->guest_memory_size;
1874 struct vmw_surface_loc loc1, loc2;
1875 const struct vmw_surface_cache *cache;
1876
1877 start = max_t(size_t, start, res->guest_memory_offset) - res->guest_memory_offset;
1878 end = min(end, backup_end) - res->guest_memory_offset;
1879 cache = &dirty->cache;
1880 vmw_surface_get_loc(cache, &loc1, start);
1881 vmw_surface_get_loc(cache, &loc2, end - 1);
1882 vmw_surface_inc_loc(cache, &loc2);
1883
1884 if (loc1.sheet != loc2.sheet) {
1885 u32 sub_res;
1886
1887 /*
1888 * Multiple multisample sheets. To do this in an optimized
1889 * fashion, compute the dirty region for each sheet and the
1890 * resulting union. Since this is not a common case, just dirty
1891 * the whole surface.
1892 */
1893 for (sub_res = 0; sub_res < dirty->num_subres; ++sub_res)
1894 vmw_subres_dirty_full(dirty, sub_res);
1895 return;
1896 }
1897 if (loc1.sub_resource + 1 == loc2.sub_resource) {
1898 /* Dirty range covers a single sub-resource */
1899 vmw_subres_dirty_add(dirty, &loc1, &loc2);
1900 } else {
1901 /* Dirty range covers multiple sub-resources */
1902 struct vmw_surface_loc loc_min, loc_max;
1903 u32 sub_res;
1904
1905 vmw_surface_max_loc(cache, loc1.sub_resource, &loc_max);
1906 vmw_subres_dirty_add(dirty, &loc1, &loc_max);
1907 vmw_surface_min_loc(cache, loc2.sub_resource - 1, &loc_min);
1908 vmw_subres_dirty_add(dirty, &loc_min, &loc2);
1909 for (sub_res = loc1.sub_resource + 1;
1910 sub_res < loc2.sub_resource - 1; ++sub_res)
1911 vmw_subres_dirty_full(dirty, sub_res);
1912 }
1913 }
1914
1915 /*
1916 * vmw_surface_tex_dirty_add_range - The dirty_add_range callback for buffer
1917 * surfaces.
1918 */
vmw_surface_buf_dirty_range_add(struct vmw_resource * res,size_t start,size_t end)1919 static void vmw_surface_buf_dirty_range_add(struct vmw_resource *res,
1920 size_t start, size_t end)
1921 {
1922 struct vmw_surface_dirty *dirty =
1923 (struct vmw_surface_dirty *) res->dirty;
1924 const struct vmw_surface_cache *cache = &dirty->cache;
1925 size_t backup_end = res->guest_memory_offset + cache->mip_chain_bytes;
1926 SVGA3dBox *box = &dirty->boxes[0];
1927 u32 box_c2;
1928
1929 box->h = box->d = 1;
1930 start = max_t(size_t, start, res->guest_memory_offset) - res->guest_memory_offset;
1931 end = min(end, backup_end) - res->guest_memory_offset;
1932 box_c2 = box->x + box->w;
1933 if (box->w == 0 || box->x > start)
1934 box->x = start;
1935 if (box_c2 < end)
1936 box->w = end - box->x;
1937 }
1938
1939 /*
1940 * vmw_surface_tex_dirty_add_range - The dirty_add_range callback for surfaces
1941 */
vmw_surface_dirty_range_add(struct vmw_resource * res,size_t start,size_t end)1942 static void vmw_surface_dirty_range_add(struct vmw_resource *res, size_t start,
1943 size_t end)
1944 {
1945 struct vmw_surface *srf = vmw_res_to_srf(res);
1946
1947 if (WARN_ON(end <= res->guest_memory_offset ||
1948 start >= res->guest_memory_offset + res->guest_memory_size))
1949 return;
1950
1951 if (srf->metadata.format == SVGA3D_BUFFER)
1952 vmw_surface_buf_dirty_range_add(res, start, end);
1953 else
1954 vmw_surface_tex_dirty_range_add(res, start, end);
1955 }
1956
1957 /*
1958 * vmw_surface_dirty_sync - The surface's dirty_sync callback.
1959 */
vmw_surface_dirty_sync(struct vmw_resource * res)1960 static int vmw_surface_dirty_sync(struct vmw_resource *res)
1961 {
1962 struct vmw_private *dev_priv = res->dev_priv;
1963 u32 i, num_dirty;
1964 struct vmw_surface_dirty *dirty =
1965 (struct vmw_surface_dirty *) res->dirty;
1966 size_t alloc_size;
1967 const struct vmw_surface_cache *cache = &dirty->cache;
1968 struct {
1969 SVGA3dCmdHeader header;
1970 SVGA3dCmdDXUpdateSubResource body;
1971 } *cmd1;
1972 struct {
1973 SVGA3dCmdHeader header;
1974 SVGA3dCmdUpdateGBImage body;
1975 } *cmd2;
1976 void *cmd;
1977
1978 num_dirty = 0;
1979 for (i = 0; i < dirty->num_subres; ++i) {
1980 const SVGA3dBox *box = &dirty->boxes[i];
1981
1982 if (box->d)
1983 num_dirty++;
1984 }
1985
1986 if (!num_dirty)
1987 goto out;
1988
1989 alloc_size = num_dirty * ((has_sm4_context(dev_priv)) ? sizeof(*cmd1) : sizeof(*cmd2));
1990 cmd = VMW_CMD_RESERVE(dev_priv, alloc_size);
1991 if (!cmd)
1992 return -ENOMEM;
1993
1994 cmd1 = cmd;
1995 cmd2 = cmd;
1996
1997 for (i = 0; i < dirty->num_subres; ++i) {
1998 const SVGA3dBox *box = &dirty->boxes[i];
1999
2000 if (!box->d)
2001 continue;
2002
2003 /*
2004 * DX_UPDATE_SUBRESOURCE is aware of array surfaces.
2005 * UPDATE_GB_IMAGE is not.
2006 */
2007 if (has_sm4_context(dev_priv)) {
2008 cmd1->header.id = SVGA_3D_CMD_DX_UPDATE_SUBRESOURCE;
2009 cmd1->header.size = sizeof(cmd1->body);
2010 cmd1->body.sid = res->id;
2011 cmd1->body.subResource = i;
2012 cmd1->body.box = *box;
2013 cmd1++;
2014 } else {
2015 cmd2->header.id = SVGA_3D_CMD_UPDATE_GB_IMAGE;
2016 cmd2->header.size = sizeof(cmd2->body);
2017 cmd2->body.image.sid = res->id;
2018 cmd2->body.image.face = i / cache->num_mip_levels;
2019 cmd2->body.image.mipmap = i -
2020 (cache->num_mip_levels * cmd2->body.image.face);
2021 cmd2->body.box = *box;
2022 cmd2++;
2023 }
2024
2025 }
2026 vmw_cmd_commit(dev_priv, alloc_size);
2027 out:
2028 memset(&dirty->boxes[0], 0, sizeof(dirty->boxes[0]) *
2029 dirty->num_subres);
2030
2031 return 0;
2032 }
2033
2034 /*
2035 * vmw_surface_dirty_alloc - The surface's dirty_alloc callback.
2036 */
vmw_surface_dirty_alloc(struct vmw_resource * res)2037 static int vmw_surface_dirty_alloc(struct vmw_resource *res)
2038 {
2039 struct vmw_surface *srf = vmw_res_to_srf(res);
2040 const struct vmw_surface_metadata *metadata = &srf->metadata;
2041 struct vmw_surface_dirty *dirty;
2042 u32 num_layers = 1;
2043 u32 num_mip;
2044 u32 num_subres;
2045 u32 num_samples;
2046 size_t dirty_size;
2047 int ret;
2048
2049 if (metadata->array_size)
2050 num_layers = metadata->array_size;
2051 else if (metadata->flags & SVGA3D_SURFACE_CUBEMAP)
2052 num_layers *= SVGA3D_MAX_SURFACE_FACES;
2053
2054 num_mip = metadata->mip_levels[0];
2055 if (!num_mip)
2056 num_mip = 1;
2057
2058 num_subres = num_layers * num_mip;
2059 dirty_size = struct_size(dirty, boxes, num_subres);
2060
2061 dirty = kvzalloc(dirty_size, GFP_KERNEL);
2062 if (!dirty) {
2063 ret = -ENOMEM;
2064 goto out_no_dirty;
2065 }
2066
2067 num_samples = max_t(u32, 1, metadata->multisample_count);
2068 ret = vmw_surface_setup_cache(&metadata->base_size, metadata->format,
2069 num_mip, num_layers, num_samples,
2070 &dirty->cache);
2071 if (ret)
2072 goto out_no_cache;
2073
2074 dirty->num_subres = num_subres;
2075 res->dirty = (struct vmw_resource_dirty *) dirty;
2076
2077 return 0;
2078
2079 out_no_cache:
2080 kvfree(dirty);
2081 out_no_dirty:
2082 return ret;
2083 }
2084
2085 /*
2086 * vmw_surface_dirty_free - The surface's dirty_free callback
2087 */
vmw_surface_dirty_free(struct vmw_resource * res)2088 static void vmw_surface_dirty_free(struct vmw_resource *res)
2089 {
2090 struct vmw_surface_dirty *dirty =
2091 (struct vmw_surface_dirty *) res->dirty;
2092
2093 kvfree(dirty);
2094 res->dirty = NULL;
2095 }
2096
2097 /*
2098 * vmw_surface_clean - The surface's clean callback
2099 */
vmw_surface_clean(struct vmw_resource * res)2100 static int vmw_surface_clean(struct vmw_resource *res)
2101 {
2102 struct vmw_private *dev_priv = res->dev_priv;
2103 size_t alloc_size;
2104 struct {
2105 SVGA3dCmdHeader header;
2106 SVGA3dCmdReadbackGBSurface body;
2107 } *cmd;
2108
2109 alloc_size = sizeof(*cmd);
2110 cmd = VMW_CMD_RESERVE(dev_priv, alloc_size);
2111 if (!cmd)
2112 return -ENOMEM;
2113
2114 cmd->header.id = SVGA_3D_CMD_READBACK_GB_SURFACE;
2115 cmd->header.size = sizeof(cmd->body);
2116 cmd->body.sid = res->id;
2117 vmw_cmd_commit(dev_priv, alloc_size);
2118
2119 return 0;
2120 }
2121
2122 /*
2123 * vmw_gb_surface_define - Define a private GB surface
2124 *
2125 * @dev_priv: Pointer to a device private.
2126 * @metadata: Metadata representing the surface to create.
2127 * @user_srf_out: allocated user_srf. Set to NULL on failure.
2128 *
2129 * GB surfaces allocated by this function will not have a user mode handle, and
2130 * thus will only be visible to vmwgfx. For optimization reasons the
2131 * surface may later be given a user mode handle by another function to make
2132 * it available to user mode drivers.
2133 */
vmw_gb_surface_define(struct vmw_private * dev_priv,const struct vmw_surface_metadata * req,struct vmw_surface ** srf_out)2134 int vmw_gb_surface_define(struct vmw_private *dev_priv,
2135 const struct vmw_surface_metadata *req,
2136 struct vmw_surface **srf_out)
2137 {
2138 struct vmw_surface_metadata *metadata;
2139 struct vmw_user_surface *user_srf;
2140 struct vmw_surface *srf;
2141 u32 sample_count = 1;
2142 u32 num_layers = 1;
2143 int ret;
2144
2145 *srf_out = NULL;
2146
2147 if (req->scanout) {
2148 if (!vmw_surface_is_screen_target_format(req->format)) {
2149 VMW_DEBUG_USER("Invalid Screen Target surface format.");
2150 return -EINVAL;
2151 }
2152
2153 if (req->base_size.width > dev_priv->texture_max_width ||
2154 req->base_size.height > dev_priv->texture_max_height) {
2155 VMW_DEBUG_USER("%ux%u\n, exceed max surface size %ux%u",
2156 req->base_size.width,
2157 req->base_size.height,
2158 dev_priv->texture_max_width,
2159 dev_priv->texture_max_height);
2160 return -EINVAL;
2161 }
2162 } else {
2163 const SVGA3dSurfaceDesc *desc =
2164 vmw_surface_get_desc(req->format);
2165
2166 if (desc->blockDesc == SVGA3DBLOCKDESC_NONE) {
2167 VMW_DEBUG_USER("Invalid surface format.\n");
2168 return -EINVAL;
2169 }
2170 }
2171
2172 if (req->autogen_filter != SVGA3D_TEX_FILTER_NONE)
2173 return -EINVAL;
2174
2175 if (req->num_sizes != 1)
2176 return -EINVAL;
2177
2178 if (req->sizes != NULL)
2179 return -EINVAL;
2180
2181 user_srf = kzalloc(sizeof(*user_srf), GFP_KERNEL);
2182 if (unlikely(!user_srf)) {
2183 ret = -ENOMEM;
2184 goto out_unlock;
2185 }
2186
2187 *srf_out = &user_srf->srf;
2188
2189 srf = &user_srf->srf;
2190 srf->metadata = *req;
2191 srf->offsets = NULL;
2192
2193 metadata = &srf->metadata;
2194
2195 if (metadata->array_size)
2196 num_layers = req->array_size;
2197 else if (metadata->flags & SVGA3D_SURFACE_CUBEMAP)
2198 num_layers = SVGA3D_MAX_SURFACE_FACES;
2199
2200 if (metadata->flags & SVGA3D_SURFACE_MULTISAMPLE)
2201 sample_count = metadata->multisample_count;
2202
2203 srf->res.guest_memory_size =
2204 vmw_surface_get_serialized_size_extended(
2205 metadata->format,
2206 metadata->base_size,
2207 metadata->mip_levels[0],
2208 num_layers,
2209 sample_count);
2210
2211 if (metadata->flags & SVGA3D_SURFACE_BIND_STREAM_OUTPUT)
2212 srf->res.guest_memory_size += sizeof(SVGA3dDXSOState);
2213
2214 /*
2215 * Don't set SVGA3D_SURFACE_SCREENTARGET flag for a scanout surface with
2216 * size greater than STDU max width/height. This is really a workaround
2217 * to support creation of big framebuffer requested by some user-space
2218 * for whole topology. That big framebuffer won't really be used for
2219 * binding with screen target as during prepare_fb a separate surface is
2220 * created so it's safe to ignore SVGA3D_SURFACE_SCREENTARGET flag.
2221 */
2222 if (dev_priv->active_display_unit == vmw_du_screen_target &&
2223 metadata->scanout &&
2224 metadata->base_size.width <= dev_priv->stdu_max_width &&
2225 metadata->base_size.height <= dev_priv->stdu_max_height)
2226 metadata->flags |= SVGA3D_SURFACE_SCREENTARGET;
2227
2228 /*
2229 * From this point, the generic resource management functions
2230 * destroy the object on failure.
2231 */
2232 ret = vmw_surface_init(dev_priv, srf, vmw_user_surface_free);
2233
2234 return ret;
2235
2236 out_unlock:
2237 return ret;
2238 }
2239
vmw_format_bpp_to_svga(struct vmw_private * vmw,int bpp)2240 static SVGA3dSurfaceFormat vmw_format_bpp_to_svga(struct vmw_private *vmw,
2241 int bpp)
2242 {
2243 switch (bpp) {
2244 case 8: /* DRM_FORMAT_C8 */
2245 return SVGA3D_P8;
2246 case 16: /* DRM_FORMAT_RGB565 */
2247 return SVGA3D_R5G6B5;
2248 case 32: /* DRM_FORMAT_XRGB8888 */
2249 if (has_sm4_context(vmw))
2250 return SVGA3D_B8G8R8X8_UNORM;
2251 return SVGA3D_X8R8G8B8;
2252 default:
2253 drm_warn(&vmw->drm, "Unsupported format bpp: %d\n", bpp);
2254 return SVGA3D_X8R8G8B8;
2255 }
2256 }
2257
2258 /**
2259 * vmw_dumb_create - Create a dumb kms buffer
2260 *
2261 * @file_priv: Pointer to a struct drm_file identifying the caller.
2262 * @dev: Pointer to the drm device.
2263 * @args: Pointer to a struct drm_mode_create_dumb structure
2264 * Return: Zero on success, negative error code on failure.
2265 *
2266 * This is a driver callback for the core drm create_dumb functionality.
2267 * Note that this is very similar to the vmw_bo_alloc ioctl, except
2268 * that the arguments have a different format.
2269 */
vmw_dumb_create(struct drm_file * file_priv,struct drm_device * dev,struct drm_mode_create_dumb * args)2270 int vmw_dumb_create(struct drm_file *file_priv,
2271 struct drm_device *dev,
2272 struct drm_mode_create_dumb *args)
2273 {
2274 struct vmw_private *dev_priv = vmw_priv(dev);
2275 struct ttm_object_file *tfile = vmw_fpriv(file_priv)->tfile;
2276 struct vmw_bo *vbo = NULL;
2277 struct vmw_resource *res = NULL;
2278 union drm_vmw_gb_surface_create_ext_arg arg = { 0 };
2279 struct drm_vmw_gb_surface_create_ext_req *req = &arg.req;
2280 int ret;
2281 struct drm_vmw_size drm_size = {
2282 .width = args->width,
2283 .height = args->height,
2284 .depth = 1,
2285 };
2286 SVGA3dSurfaceFormat format = vmw_format_bpp_to_svga(dev_priv, args->bpp);
2287 const struct SVGA3dSurfaceDesc *desc = vmw_surface_get_desc(format);
2288 SVGA3dSurfaceAllFlags flags = SVGA3D_SURFACE_HINT_TEXTURE |
2289 SVGA3D_SURFACE_HINT_RENDERTARGET |
2290 SVGA3D_SURFACE_SCREENTARGET;
2291
2292 if (vmw_surface_is_dx_screen_target_format(format)) {
2293 flags |= SVGA3D_SURFACE_BIND_SHADER_RESOURCE |
2294 SVGA3D_SURFACE_BIND_RENDER_TARGET;
2295 }
2296
2297 /*
2298 * Without mob support we're just going to use raw memory buffer
2299 * because we wouldn't be able to support full surface coherency
2300 * without mobs. There also no reason to support surface coherency
2301 * without 3d (i.e. gpu usage on the host) because then all the
2302 * contents is going to be rendered guest side.
2303 */
2304 if (!dev_priv->has_mob || !vmw_supports_3d(dev_priv)) {
2305 int cpp = DIV_ROUND_UP(args->bpp, 8);
2306
2307 switch (cpp) {
2308 case 1: /* DRM_FORMAT_C8 */
2309 case 2: /* DRM_FORMAT_RGB565 */
2310 case 4: /* DRM_FORMAT_XRGB8888 */
2311 break;
2312 default:
2313 /*
2314 * Dumb buffers don't allow anything else.
2315 * This is tested via IGT's dumb_buffers
2316 */
2317 return -EINVAL;
2318 }
2319
2320 args->pitch = args->width * cpp;
2321 args->size = ALIGN(args->pitch * args->height, PAGE_SIZE);
2322
2323 ret = vmw_gem_object_create_with_handle(dev_priv, file_priv,
2324 args->size, &args->handle,
2325 &vbo);
2326 /* drop reference from allocate - handle holds it now */
2327 drm_gem_object_put(&vbo->tbo.base);
2328 return ret;
2329 }
2330
2331 req->version = drm_vmw_gb_surface_v1;
2332 req->multisample_pattern = SVGA3D_MS_PATTERN_NONE;
2333 req->quality_level = SVGA3D_MS_QUALITY_NONE;
2334 req->buffer_byte_stride = 0;
2335 req->must_be_zero = 0;
2336 req->base.svga3d_flags = SVGA3D_FLAGS_LOWER_32(flags);
2337 req->svga3d_flags_upper_32_bits = SVGA3D_FLAGS_UPPER_32(flags);
2338 req->base.format = (uint32_t)format;
2339 req->base.drm_surface_flags = drm_vmw_surface_flag_scanout;
2340 req->base.drm_surface_flags |= drm_vmw_surface_flag_shareable;
2341 req->base.drm_surface_flags |= drm_vmw_surface_flag_create_buffer;
2342 req->base.drm_surface_flags |= drm_vmw_surface_flag_coherent;
2343 req->base.base_size.width = args->width;
2344 req->base.base_size.height = args->height;
2345 req->base.base_size.depth = 1;
2346 req->base.array_size = 0;
2347 req->base.mip_levels = 1;
2348 req->base.multisample_count = 0;
2349 req->base.buffer_handle = SVGA3D_INVALID_ID;
2350 req->base.autogen_filter = SVGA3D_TEX_FILTER_NONE;
2351 ret = vmw_gb_surface_define_ext_ioctl(dev, &arg, file_priv);
2352 if (ret) {
2353 drm_warn(dev, "Unable to create a dumb buffer\n");
2354 return ret;
2355 }
2356
2357 args->handle = arg.rep.buffer_handle;
2358 args->size = arg.rep.buffer_size;
2359 args->pitch = vmw_surface_calculate_pitch(desc, &drm_size);
2360
2361 ret = vmw_user_resource_lookup_handle(dev_priv, tfile, arg.rep.handle,
2362 user_surface_converter,
2363 &res);
2364 if (ret) {
2365 drm_err(dev, "Created resource handle doesn't exist!\n");
2366 goto err;
2367 }
2368
2369 vbo = res->guest_memory_bo;
2370 vbo->is_dumb = true;
2371 vbo->dumb_surface = vmw_res_to_srf(res);
2372 drm_gem_object_put(&vbo->tbo.base);
2373 /*
2374 * Unset the user surface dtor since this in not actually exposed
2375 * to userspace. The suface is owned via the dumb_buffer's GEM handle
2376 */
2377 struct vmw_user_surface *usurf = container_of(vbo->dumb_surface,
2378 struct vmw_user_surface, srf);
2379 usurf->prime.base.refcount_release = NULL;
2380 err:
2381 if (res)
2382 vmw_resource_unreference(&res);
2383
2384 ttm_ref_object_base_unref(tfile, arg.rep.handle);
2385
2386 return ret;
2387 }
2388