1 /*
2  * videobuf2-dma-sg.c - dma scatter/gather memory allocator for videobuf2
3  *
4  * Copyright (C) 2010 Samsung Electronics
5  *
6  * Author: Andrzej Pietrasiewicz <andrzejtp2010@gmail.com>
7  *
8  * This program is free software; you can redistribute it and/or modify
9  * it under the terms of the GNU General Public License as published by
10  * the Free Software Foundation.
11  */
12 
13 #include <linux/module.h>
14 #include <linux/mm.h>
15 #include <linux/refcount.h>
16 #include <linux/scatterlist.h>
17 #include <linux/sched.h>
18 #include <linux/slab.h>
19 #include <linux/vmalloc.h>
20 
21 #include <media/videobuf2-v4l2.h>
22 #include <media/videobuf2-memops.h>
23 #include <media/videobuf2-dma-sg.h>
24 
25 static int debug;
26 module_param(debug, int, 0644);
27 
28 #define dprintk(level, fmt, arg...)					\
29 	do {								\
30 		if (debug >= level)					\
31 			printk(KERN_DEBUG "vb2-dma-sg: " fmt, ## arg);	\
32 	} while (0)
33 
34 struct vb2_dma_sg_buf {
35 	struct device			*dev;
36 	void				*vaddr;
37 	struct page			**pages;
38 	struct frame_vector		*vec;
39 	int				offset;
40 	enum dma_data_direction		dma_dir;
41 	struct sg_table			sg_table;
42 	/*
43 	 * This will point to sg_table when used with the MMAP or USERPTR
44 	 * memory model, and to the dma_buf sglist when used with the
45 	 * DMABUF memory model.
46 	 */
47 	struct sg_table			*dma_sgt;
48 	size_t				size;
49 	unsigned int			num_pages;
50 	refcount_t			refcount;
51 	struct vb2_vmarea_handler	handler;
52 
53 	struct dma_buf_attachment	*db_attach;
54 };
55 
56 static void vb2_dma_sg_put(void *buf_priv);
57 
58 static int vb2_dma_sg_alloc_compacted(struct vb2_dma_sg_buf *buf,
59 		gfp_t gfp_flags)
60 {
61 	unsigned int last_page = 0;
62 	unsigned long size = buf->size;
63 
64 	while (size > 0) {
65 		struct page *pages;
66 		int order;
67 		int i;
68 
69 		order = get_order(size);
70 		/* Don't over allocate*/
71 		if ((PAGE_SIZE << order) > size)
72 			order--;
73 
74 		pages = NULL;
75 		while (!pages) {
76 			pages = alloc_pages(GFP_KERNEL | __GFP_ZERO |
77 					__GFP_NOWARN | gfp_flags, order);
78 			if (pages)
79 				break;
80 
81 			if (order == 0) {
82 				while (last_page--)
83 					__free_page(buf->pages[last_page]);
84 				return -ENOMEM;
85 			}
86 			order--;
87 		}
88 
89 		split_page(pages, order);
90 		for (i = 0; i < (1 << order); i++)
91 			buf->pages[last_page++] = &pages[i];
92 
93 		size -= PAGE_SIZE << order;
94 	}
95 
96 	return 0;
97 }
98 
99 static void *vb2_dma_sg_alloc(struct device *dev, unsigned long dma_attrs,
100 			      unsigned long size, enum dma_data_direction dma_dir,
101 			      gfp_t gfp_flags)
102 {
103 	struct vb2_dma_sg_buf *buf;
104 	struct sg_table *sgt;
105 	int ret;
106 	int num_pages;
107 
108 	if (WARN_ON(!dev))
109 		return ERR_PTR(-EINVAL);
110 
111 	buf = kzalloc(sizeof *buf, GFP_KERNEL);
112 	if (!buf)
113 		return ERR_PTR(-ENOMEM);
114 
115 	buf->vaddr = NULL;
116 	buf->dma_dir = dma_dir;
117 	buf->offset = 0;
118 	buf->size = size;
119 	/* size is already page aligned */
120 	buf->num_pages = size >> PAGE_SHIFT;
121 	buf->dma_sgt = &buf->sg_table;
122 
123 	buf->pages = kvmalloc_array(buf->num_pages, sizeof(struct page *),
124 				    GFP_KERNEL | __GFP_ZERO);
125 	if (!buf->pages)
126 		goto fail_pages_array_alloc;
127 
128 	ret = vb2_dma_sg_alloc_compacted(buf, gfp_flags);
129 	if (ret)
130 		goto fail_pages_alloc;
131 
132 	ret = sg_alloc_table_from_pages(buf->dma_sgt, buf->pages,
133 			buf->num_pages, 0, size, GFP_KERNEL);
134 	if (ret)
135 		goto fail_table_alloc;
136 
137 	/* Prevent the device from being released while the buffer is used */
138 	buf->dev = get_device(dev);
139 
140 	sgt = &buf->sg_table;
141 	/*
142 	 * No need to sync to the device, this will happen later when the
143 	 * prepare() memop is called.
144 	 */
145 	sgt->nents = dma_map_sg_attrs(buf->dev, sgt->sgl, sgt->orig_nents,
146 				      buf->dma_dir, DMA_ATTR_SKIP_CPU_SYNC);
147 	if (!sgt->nents)
148 		goto fail_map;
149 
150 	buf->handler.refcount = &buf->refcount;
151 	buf->handler.put = vb2_dma_sg_put;
152 	buf->handler.arg = buf;
153 
154 	refcount_set(&buf->refcount, 1);
155 
156 	dprintk(1, "%s: Allocated buffer of %d pages\n",
157 		__func__, buf->num_pages);
158 	return buf;
159 
160 fail_map:
161 	put_device(buf->dev);
162 	sg_free_table(buf->dma_sgt);
163 fail_table_alloc:
164 	num_pages = buf->num_pages;
165 	while (num_pages--)
166 		__free_page(buf->pages[num_pages]);
167 fail_pages_alloc:
168 	kvfree(buf->pages);
169 fail_pages_array_alloc:
170 	kfree(buf);
171 	return ERR_PTR(-ENOMEM);
172 }
173 
174 static void vb2_dma_sg_put(void *buf_priv)
175 {
176 	struct vb2_dma_sg_buf *buf = buf_priv;
177 	struct sg_table *sgt = &buf->sg_table;
178 	int i = buf->num_pages;
179 
180 	if (refcount_dec_and_test(&buf->refcount)) {
181 		dprintk(1, "%s: Freeing buffer of %d pages\n", __func__,
182 			buf->num_pages);
183 		dma_unmap_sg_attrs(buf->dev, sgt->sgl, sgt->orig_nents,
184 				   buf->dma_dir, DMA_ATTR_SKIP_CPU_SYNC);
185 		if (buf->vaddr)
186 			vm_unmap_ram(buf->vaddr, buf->num_pages);
187 		sg_free_table(buf->dma_sgt);
188 		while (--i >= 0)
189 			__free_page(buf->pages[i]);
190 		kvfree(buf->pages);
191 		put_device(buf->dev);
192 		kfree(buf);
193 	}
194 }
195 
196 static void vb2_dma_sg_prepare(void *buf_priv)
197 {
198 	struct vb2_dma_sg_buf *buf = buf_priv;
199 	struct sg_table *sgt = buf->dma_sgt;
200 
201 	/* DMABUF exporter will flush the cache for us */
202 	if (buf->db_attach)
203 		return;
204 
205 	dma_sync_sg_for_device(buf->dev, sgt->sgl, sgt->orig_nents,
206 			       buf->dma_dir);
207 }
208 
209 static void vb2_dma_sg_finish(void *buf_priv)
210 {
211 	struct vb2_dma_sg_buf *buf = buf_priv;
212 	struct sg_table *sgt = buf->dma_sgt;
213 
214 	/* DMABUF exporter will flush the cache for us */
215 	if (buf->db_attach)
216 		return;
217 
218 	dma_sync_sg_for_cpu(buf->dev, sgt->sgl, sgt->orig_nents, buf->dma_dir);
219 }
220 
221 static void *vb2_dma_sg_get_userptr(struct device *dev, unsigned long vaddr,
222 				    unsigned long size,
223 				    enum dma_data_direction dma_dir)
224 {
225 	struct vb2_dma_sg_buf *buf;
226 	struct sg_table *sgt;
227 	struct frame_vector *vec;
228 
229 	if (WARN_ON(!dev))
230 		return ERR_PTR(-EINVAL);
231 
232 	buf = kzalloc(sizeof *buf, GFP_KERNEL);
233 	if (!buf)
234 		return ERR_PTR(-ENOMEM);
235 
236 	buf->vaddr = NULL;
237 	buf->dev = dev;
238 	buf->dma_dir = dma_dir;
239 	buf->offset = vaddr & ~PAGE_MASK;
240 	buf->size = size;
241 	buf->dma_sgt = &buf->sg_table;
242 	vec = vb2_create_framevec(vaddr, size);
243 	if (IS_ERR(vec))
244 		goto userptr_fail_pfnvec;
245 	buf->vec = vec;
246 
247 	buf->pages = frame_vector_pages(vec);
248 	if (IS_ERR(buf->pages))
249 		goto userptr_fail_sgtable;
250 	buf->num_pages = frame_vector_count(vec);
251 
252 	if (sg_alloc_table_from_pages(buf->dma_sgt, buf->pages,
253 			buf->num_pages, buf->offset, size, 0))
254 		goto userptr_fail_sgtable;
255 
256 	sgt = &buf->sg_table;
257 	/*
258 	 * No need to sync to the device, this will happen later when the
259 	 * prepare() memop is called.
260 	 */
261 	sgt->nents = dma_map_sg_attrs(buf->dev, sgt->sgl, sgt->orig_nents,
262 				      buf->dma_dir, DMA_ATTR_SKIP_CPU_SYNC);
263 	if (!sgt->nents)
264 		goto userptr_fail_map;
265 
266 	return buf;
267 
268 userptr_fail_map:
269 	sg_free_table(&buf->sg_table);
270 userptr_fail_sgtable:
271 	vb2_destroy_framevec(vec);
272 userptr_fail_pfnvec:
273 	kfree(buf);
274 	return ERR_PTR(-ENOMEM);
275 }
276 
277 /*
278  * @put_userptr: inform the allocator that a USERPTR buffer will no longer
279  *		 be used
280  */
281 static void vb2_dma_sg_put_userptr(void *buf_priv)
282 {
283 	struct vb2_dma_sg_buf *buf = buf_priv;
284 	struct sg_table *sgt = &buf->sg_table;
285 	int i = buf->num_pages;
286 
287 	dprintk(1, "%s: Releasing userspace buffer of %d pages\n",
288 	       __func__, buf->num_pages);
289 	dma_unmap_sg_attrs(buf->dev, sgt->sgl, sgt->orig_nents, buf->dma_dir,
290 			   DMA_ATTR_SKIP_CPU_SYNC);
291 	if (buf->vaddr)
292 		vm_unmap_ram(buf->vaddr, buf->num_pages);
293 	sg_free_table(buf->dma_sgt);
294 	if (buf->dma_dir == DMA_FROM_DEVICE ||
295 	    buf->dma_dir == DMA_BIDIRECTIONAL)
296 		while (--i >= 0)
297 			set_page_dirty_lock(buf->pages[i]);
298 	vb2_destroy_framevec(buf->vec);
299 	kfree(buf);
300 }
301 
302 static void *vb2_dma_sg_vaddr(void *buf_priv)
303 {
304 	struct vb2_dma_sg_buf *buf = buf_priv;
305 
306 	BUG_ON(!buf);
307 
308 	if (!buf->vaddr) {
309 		if (buf->db_attach)
310 			buf->vaddr = dma_buf_vmap(buf->db_attach->dmabuf);
311 		else
312 			buf->vaddr = vm_map_ram(buf->pages, buf->num_pages, -1);
313 	}
314 
315 	/* add offset in case userptr is not page-aligned */
316 	return buf->vaddr ? buf->vaddr + buf->offset : NULL;
317 }
318 
319 static unsigned int vb2_dma_sg_num_users(void *buf_priv)
320 {
321 	struct vb2_dma_sg_buf *buf = buf_priv;
322 
323 	return refcount_read(&buf->refcount);
324 }
325 
326 static int vb2_dma_sg_mmap(void *buf_priv, struct vm_area_struct *vma)
327 {
328 	struct vb2_dma_sg_buf *buf = buf_priv;
329 	int err;
330 
331 	if (!buf) {
332 		printk(KERN_ERR "No memory to map\n");
333 		return -EINVAL;
334 	}
335 
336 	err = vm_map_pages(vma, buf->pages, buf->num_pages);
337 	if (err) {
338 		printk(KERN_ERR "Remapping memory, error: %d\n", err);
339 		return err;
340 	}
341 
342 	/*
343 	 * Use common vm_area operations to track buffer refcount.
344 	 */
345 	vma->vm_private_data	= &buf->handler;
346 	vma->vm_ops		= &vb2_common_vm_ops;
347 
348 	vma->vm_ops->open(vma);
349 
350 	return 0;
351 }
352 
353 /*********************************************/
354 /*         DMABUF ops for exporters          */
355 /*********************************************/
356 
357 struct vb2_dma_sg_attachment {
358 	struct sg_table sgt;
359 	enum dma_data_direction dma_dir;
360 };
361 
362 static int vb2_dma_sg_dmabuf_ops_attach(struct dma_buf *dbuf,
363 	struct dma_buf_attachment *dbuf_attach)
364 {
365 	struct vb2_dma_sg_attachment *attach;
366 	unsigned int i;
367 	struct scatterlist *rd, *wr;
368 	struct sg_table *sgt;
369 	struct vb2_dma_sg_buf *buf = dbuf->priv;
370 	int ret;
371 
372 	attach = kzalloc(sizeof(*attach), GFP_KERNEL);
373 	if (!attach)
374 		return -ENOMEM;
375 
376 	sgt = &attach->sgt;
377 	/* Copy the buf->base_sgt scatter list to the attachment, as we can't
378 	 * map the same scatter list to multiple attachments at the same time.
379 	 */
380 	ret = sg_alloc_table(sgt, buf->dma_sgt->orig_nents, GFP_KERNEL);
381 	if (ret) {
382 		kfree(attach);
383 		return -ENOMEM;
384 	}
385 
386 	rd = buf->dma_sgt->sgl;
387 	wr = sgt->sgl;
388 	for (i = 0; i < sgt->orig_nents; ++i) {
389 		sg_set_page(wr, sg_page(rd), rd->length, rd->offset);
390 		rd = sg_next(rd);
391 		wr = sg_next(wr);
392 	}
393 
394 	attach->dma_dir = DMA_NONE;
395 	dbuf_attach->priv = attach;
396 
397 	return 0;
398 }
399 
400 static void vb2_dma_sg_dmabuf_ops_detach(struct dma_buf *dbuf,
401 	struct dma_buf_attachment *db_attach)
402 {
403 	struct vb2_dma_sg_attachment *attach = db_attach->priv;
404 	struct sg_table *sgt;
405 
406 	if (!attach)
407 		return;
408 
409 	sgt = &attach->sgt;
410 
411 	/* release the scatterlist cache */
412 	if (attach->dma_dir != DMA_NONE)
413 		dma_unmap_sg(db_attach->dev, sgt->sgl, sgt->orig_nents,
414 			attach->dma_dir);
415 	sg_free_table(sgt);
416 	kfree(attach);
417 	db_attach->priv = NULL;
418 }
419 
420 static struct sg_table *vb2_dma_sg_dmabuf_ops_map(
421 	struct dma_buf_attachment *db_attach, enum dma_data_direction dma_dir)
422 {
423 	struct vb2_dma_sg_attachment *attach = db_attach->priv;
424 	/* stealing dmabuf mutex to serialize map/unmap operations */
425 	struct mutex *lock = &db_attach->dmabuf->lock;
426 	struct sg_table *sgt;
427 
428 	mutex_lock(lock);
429 
430 	sgt = &attach->sgt;
431 	/* return previously mapped sg table */
432 	if (attach->dma_dir == dma_dir) {
433 		mutex_unlock(lock);
434 		return sgt;
435 	}
436 
437 	/* release any previous cache */
438 	if (attach->dma_dir != DMA_NONE) {
439 		dma_unmap_sg(db_attach->dev, sgt->sgl, sgt->orig_nents,
440 			attach->dma_dir);
441 		attach->dma_dir = DMA_NONE;
442 	}
443 
444 	/* mapping to the client with new direction */
445 	sgt->nents = dma_map_sg(db_attach->dev, sgt->sgl, sgt->orig_nents,
446 				dma_dir);
447 	if (!sgt->nents) {
448 		pr_err("failed to map scatterlist\n");
449 		mutex_unlock(lock);
450 		return ERR_PTR(-EIO);
451 	}
452 
453 	attach->dma_dir = dma_dir;
454 
455 	mutex_unlock(lock);
456 
457 	return sgt;
458 }
459 
460 static void vb2_dma_sg_dmabuf_ops_unmap(struct dma_buf_attachment *db_attach,
461 	struct sg_table *sgt, enum dma_data_direction dma_dir)
462 {
463 	/* nothing to be done here */
464 }
465 
466 static void vb2_dma_sg_dmabuf_ops_release(struct dma_buf *dbuf)
467 {
468 	/* drop reference obtained in vb2_dma_sg_get_dmabuf */
469 	vb2_dma_sg_put(dbuf->priv);
470 }
471 
472 static void *vb2_dma_sg_dmabuf_ops_vmap(struct dma_buf *dbuf)
473 {
474 	struct vb2_dma_sg_buf *buf = dbuf->priv;
475 
476 	return vb2_dma_sg_vaddr(buf);
477 }
478 
479 static int vb2_dma_sg_dmabuf_ops_mmap(struct dma_buf *dbuf,
480 	struct vm_area_struct *vma)
481 {
482 	return vb2_dma_sg_mmap(dbuf->priv, vma);
483 }
484 
485 static const struct dma_buf_ops vb2_dma_sg_dmabuf_ops = {
486 	.attach = vb2_dma_sg_dmabuf_ops_attach,
487 	.detach = vb2_dma_sg_dmabuf_ops_detach,
488 	.map_dma_buf = vb2_dma_sg_dmabuf_ops_map,
489 	.unmap_dma_buf = vb2_dma_sg_dmabuf_ops_unmap,
490 	.vmap = vb2_dma_sg_dmabuf_ops_vmap,
491 	.mmap = vb2_dma_sg_dmabuf_ops_mmap,
492 	.release = vb2_dma_sg_dmabuf_ops_release,
493 };
494 
495 static struct dma_buf *vb2_dma_sg_get_dmabuf(void *buf_priv, unsigned long flags)
496 {
497 	struct vb2_dma_sg_buf *buf = buf_priv;
498 	struct dma_buf *dbuf;
499 	DEFINE_DMA_BUF_EXPORT_INFO(exp_info);
500 
501 	exp_info.ops = &vb2_dma_sg_dmabuf_ops;
502 	exp_info.size = buf->size;
503 	exp_info.flags = flags;
504 	exp_info.priv = buf;
505 
506 	if (WARN_ON(!buf->dma_sgt))
507 		return NULL;
508 
509 	dbuf = dma_buf_export(&exp_info);
510 	if (IS_ERR(dbuf))
511 		return NULL;
512 
513 	/* dmabuf keeps reference to vb2 buffer */
514 	refcount_inc(&buf->refcount);
515 
516 	return dbuf;
517 }
518 
519 /*********************************************/
520 /*       callbacks for DMABUF buffers        */
521 /*********************************************/
522 
523 static int vb2_dma_sg_map_dmabuf(void *mem_priv)
524 {
525 	struct vb2_dma_sg_buf *buf = mem_priv;
526 	struct sg_table *sgt;
527 
528 	if (WARN_ON(!buf->db_attach)) {
529 		pr_err("trying to pin a non attached buffer\n");
530 		return -EINVAL;
531 	}
532 
533 	if (WARN_ON(buf->dma_sgt)) {
534 		pr_err("dmabuf buffer is already pinned\n");
535 		return 0;
536 	}
537 
538 	/* get the associated scatterlist for this buffer */
539 	sgt = dma_buf_map_attachment(buf->db_attach, buf->dma_dir);
540 	if (IS_ERR(sgt)) {
541 		pr_err("Error getting dmabuf scatterlist\n");
542 		return -EINVAL;
543 	}
544 
545 	buf->dma_sgt = sgt;
546 	buf->vaddr = NULL;
547 
548 	return 0;
549 }
550 
551 static void vb2_dma_sg_unmap_dmabuf(void *mem_priv)
552 {
553 	struct vb2_dma_sg_buf *buf = mem_priv;
554 	struct sg_table *sgt = buf->dma_sgt;
555 
556 	if (WARN_ON(!buf->db_attach)) {
557 		pr_err("trying to unpin a not attached buffer\n");
558 		return;
559 	}
560 
561 	if (WARN_ON(!sgt)) {
562 		pr_err("dmabuf buffer is already unpinned\n");
563 		return;
564 	}
565 
566 	if (buf->vaddr) {
567 		dma_buf_vunmap(buf->db_attach->dmabuf, buf->vaddr);
568 		buf->vaddr = NULL;
569 	}
570 	dma_buf_unmap_attachment(buf->db_attach, sgt, buf->dma_dir);
571 
572 	buf->dma_sgt = NULL;
573 }
574 
575 static void vb2_dma_sg_detach_dmabuf(void *mem_priv)
576 {
577 	struct vb2_dma_sg_buf *buf = mem_priv;
578 
579 	/* if vb2 works correctly you should never detach mapped buffer */
580 	if (WARN_ON(buf->dma_sgt))
581 		vb2_dma_sg_unmap_dmabuf(buf);
582 
583 	/* detach this attachment */
584 	dma_buf_detach(buf->db_attach->dmabuf, buf->db_attach);
585 	kfree(buf);
586 }
587 
588 static void *vb2_dma_sg_attach_dmabuf(struct device *dev, struct dma_buf *dbuf,
589 	unsigned long size, enum dma_data_direction dma_dir)
590 {
591 	struct vb2_dma_sg_buf *buf;
592 	struct dma_buf_attachment *dba;
593 
594 	if (WARN_ON(!dev))
595 		return ERR_PTR(-EINVAL);
596 
597 	if (dbuf->size < size)
598 		return ERR_PTR(-EFAULT);
599 
600 	buf = kzalloc(sizeof(*buf), GFP_KERNEL);
601 	if (!buf)
602 		return ERR_PTR(-ENOMEM);
603 
604 	buf->dev = dev;
605 	/* create attachment for the dmabuf with the user device */
606 	dba = dma_buf_attach(dbuf, buf->dev);
607 	if (IS_ERR(dba)) {
608 		pr_err("failed to attach dmabuf\n");
609 		kfree(buf);
610 		return dba;
611 	}
612 
613 	buf->dma_dir = dma_dir;
614 	buf->size = size;
615 	buf->db_attach = dba;
616 
617 	return buf;
618 }
619 
620 static void *vb2_dma_sg_cookie(void *buf_priv)
621 {
622 	struct vb2_dma_sg_buf *buf = buf_priv;
623 
624 	return buf->dma_sgt;
625 }
626 
627 const struct vb2_mem_ops vb2_dma_sg_memops = {
628 	.alloc		= vb2_dma_sg_alloc,
629 	.put		= vb2_dma_sg_put,
630 	.get_userptr	= vb2_dma_sg_get_userptr,
631 	.put_userptr	= vb2_dma_sg_put_userptr,
632 	.prepare	= vb2_dma_sg_prepare,
633 	.finish		= vb2_dma_sg_finish,
634 	.vaddr		= vb2_dma_sg_vaddr,
635 	.mmap		= vb2_dma_sg_mmap,
636 	.num_users	= vb2_dma_sg_num_users,
637 	.get_dmabuf	= vb2_dma_sg_get_dmabuf,
638 	.map_dmabuf	= vb2_dma_sg_map_dmabuf,
639 	.unmap_dmabuf	= vb2_dma_sg_unmap_dmabuf,
640 	.attach_dmabuf	= vb2_dma_sg_attach_dmabuf,
641 	.detach_dmabuf	= vb2_dma_sg_detach_dmabuf,
642 	.cookie		= vb2_dma_sg_cookie,
643 };
644 EXPORT_SYMBOL_GPL(vb2_dma_sg_memops);
645 
646 MODULE_DESCRIPTION("dma scatter/gather memory handling routines for videobuf2");
647 MODULE_AUTHOR("Andrzej Pietrasiewicz");
648 MODULE_LICENSE("GPL");
649