via_dmablit.c 21.3 KB
Newer Older
1
/* via_dmablit.c -- PCI DMA BitBlt support for the VIA Unichrome/Pro
D
Dave Airlie 已提交
2
 *
3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18
 * Copyright (C) 2005 Thomas Hellstrom, All Rights Reserved.
 *
 * Permission is hereby granted, free of charge, to any person obtaining a
 * copy of this software and associated documentation files (the "Software"),
 * to deal in the Software without restriction, including without limitation
 * the rights to use, copy, modify, merge, publish, distribute, sub license,
 * and/or sell copies of the Software, and to permit persons to whom the
 * Software is furnished to do so, subject to the following conditions:
 *
 * The above copyright notice and this permission notice (including the
 * next paragraph) shall be included in all copies or substantial portions
 * of the Software.
 *
 * THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
 * IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
 * FITNESS FOR A PARTICULAR PURPOSE AND NON-INFRINGEMENT. IN NO EVENT SHALL
D
Dave Airlie 已提交
19 20 21
 * THE COPYRIGHT HOLDERS, AUTHORS AND/OR ITS SUPPLIERS BE LIABLE FOR ANY CLAIM,
 * DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR
 * OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE
22 23
 * USE OR OTHER DEALINGS IN THE SOFTWARE.
 *
D
Dave Airlie 已提交
24
 * Authors:
25 26 27 28 29 30
 *    Thomas Hellstrom.
 *    Partially based on code obtained from Digeo Inc.
 */


/*
D
Dave Airlie 已提交
31 32 33 34
 * Unmaps the DMA mappings.
 * FIXME: Is this a NoOp on x86? Also
 * FIXME: What happens if this one is called and a pending blit has previously done
 * the same DMA mappings?
35 36
 */

37 38
#include <drm/drmP.h>
#include <drm/via_drm.h>
39 40 41 42
#include "via_drv.h"
#include "via_dmablit.h"

#include <linux/pagemap.h>
43
#include <linux/slab.h>
44

45 46 47
#define VIA_PGDN(x)	     (((unsigned long)(x)) & PAGE_MASK)
#define VIA_PGOFF(x)	    (((unsigned long)(x)) & ~PAGE_MASK)
#define VIA_PFN(x)	      ((unsigned long)(x) >> PAGE_SHIFT)
48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68

typedef struct _drm_via_descriptor {
	uint32_t mem_addr;
	uint32_t dev_addr;
	uint32_t size;
	uint32_t next;
} drm_via_descriptor_t;


/*
 * Unmap a DMA mapping.
 */



static void
via_unmap_blit_from_device(struct pci_dev *pdev, drm_via_sg_info_t *vsg)
{
	int num_desc = vsg->num_desc;
	unsigned cur_descriptor_page = num_desc / vsg->descriptors_per_page;
	unsigned descriptor_this_page = num_desc % vsg->descriptors_per_page;
D
Dave Airlie 已提交
69
	drm_via_descriptor_t *desc_ptr = vsg->desc_pages[cur_descriptor_page] +
70 71 72
		descriptor_this_page;
	dma_addr_t next = vsg->chain_start;

73
	while (num_desc--) {
74 75 76
		if (descriptor_this_page-- == 0) {
			cur_descriptor_page--;
			descriptor_this_page = vsg->descriptors_per_page - 1;
D
Dave Airlie 已提交
77
			desc_ptr = vsg->desc_pages[cur_descriptor_page] +
78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96
				descriptor_this_page;
		}
		dma_unmap_single(&pdev->dev, next, sizeof(*desc_ptr), DMA_TO_DEVICE);
		dma_unmap_page(&pdev->dev, desc_ptr->mem_addr, desc_ptr->size, vsg->direction);
		next = (dma_addr_t) desc_ptr->next;
		desc_ptr--;
	}
}

/*
 * If mode = 0, count how many descriptors are needed.
 * If mode = 1, Map the DMA pages for the device, put together and map also the descriptors.
 * Descriptors are run in reverse order by the hardware because we are not allowed to update the
 * 'next' field without syncing calls when the descriptor is already mapped.
 */

static void
via_map_blit_for_device(struct pci_dev *pdev,
		   const drm_via_dmablit_t *xfer,
D
Dave Airlie 已提交
97
		   drm_via_sg_info_t *vsg,
98 99 100 101 102 103 104 105 106 107 108 109 110 111
		   int mode)
{
	unsigned cur_descriptor_page = 0;
	unsigned num_descriptors_this_page = 0;
	unsigned char *mem_addr = xfer->mem_addr;
	unsigned char *cur_mem;
	unsigned char *first_addr = (unsigned char *)VIA_PGDN(mem_addr);
	uint32_t fb_addr = xfer->fb_addr;
	uint32_t cur_fb;
	unsigned long line_len;
	unsigned remaining_len;
	int num_desc = 0;
	int cur_line;
	dma_addr_t next = 0 | VIA_DMA_DPR_EC;
112
	drm_via_descriptor_t *desc_ptr = NULL;
113

D
Dave Airlie 已提交
114
	if (mode == 1)
115 116 117 118 119 120 121
		desc_ptr = vsg->desc_pages[cur_descriptor_page];

	for (cur_line = 0; cur_line < xfer->num_lines; ++cur_line) {

		line_len = xfer->line_length;
		cur_fb = fb_addr;
		cur_mem = mem_addr;
D
Dave Airlie 已提交
122

123 124
		while (line_len > 0) {

125
			remaining_len = min(PAGE_SIZE-VIA_PGOFF(cur_mem), line_len);
126 127 128
			line_len -= remaining_len;

			if (mode == 1) {
D
Dave Airlie 已提交
129 130 131
				desc_ptr->mem_addr =
					dma_map_page(&pdev->dev,
						     vsg->pages[VIA_PFN(cur_mem) -
132
								VIA_PFN(first_addr)],
D
Dave Airlie 已提交
133
						     VIA_PGOFF(cur_mem), remaining_len,
134
						     vsg->direction);
135
				desc_ptr->dev_addr = cur_fb;
D
Dave Airlie 已提交
136

137
				desc_ptr->size = remaining_len;
138
				desc_ptr->next = (uint32_t) next;
D
Dave Airlie 已提交
139
				next = dma_map_single(&pdev->dev, desc_ptr, sizeof(*desc_ptr),
140 141 142 143 144 145 146
						      DMA_TO_DEVICE);
				desc_ptr++;
				if (++num_descriptors_this_page >= vsg->descriptors_per_page) {
					num_descriptors_this_page = 0;
					desc_ptr = vsg->desc_pages[++cur_descriptor_page];
				}
			}
D
Dave Airlie 已提交
147

148 149 150 151
			num_desc++;
			cur_mem += remaining_len;
			cur_fb += remaining_len;
		}
D
Dave Airlie 已提交
152

153 154 155 156 157 158 159 160 161 162 163 164
		mem_addr += xfer->mem_stride;
		fb_addr += xfer->fb_stride;
	}

	if (mode == 1) {
		vsg->chain_start = next;
		vsg->state = dr_via_device_mapped;
	}
	vsg->num_desc = num_desc;
}

/*
D
Dave Airlie 已提交
165
 * Function that frees up all resources for a blit. It is usable even if the
166
 * blit info has only been partially built as long as the status enum is consistent
167 168 169 170
 * with the actual status of the used resources.
 */


171
static void
D
Dave Airlie 已提交
172
via_free_sg_info(struct pci_dev *pdev, drm_via_sg_info_t *vsg)
173 174 175 176
{
	struct page *page;
	int i;

177
	switch (vsg->state) {
178 179 180
	case dr_via_device_mapped:
		via_unmap_blit_from_device(pdev, vsg);
	case dr_via_desc_pages_alloc:
181
		for (i = 0; i < vsg->num_desc_pages; ++i) {
182
			if (vsg->desc_pages[i] != NULL)
183
				free_page((unsigned long)vsg->desc_pages[i]);
184 185 186
		}
		kfree(vsg->desc_pages);
	case dr_via_pages_locked:
187 188 189
		for (i = 0; i < vsg->num_pages; ++i) {
			if (NULL != (page = vsg->pages[i])) {
				if (!PageReserved(page) && (DMA_FROM_DEVICE == vsg->direction))
190 191 192 193 194 195 196 197 198
					SetPageDirty(page);
				page_cache_release(page);
			}
		}
	case dr_via_pages_alloc:
		vfree(vsg->pages);
	default:
		vsg->state = dr_via_sg_init;
	}
199 200
	vfree(vsg->bounce_buffer);
	vsg->bounce_buffer = NULL;
201
	vsg->free_on_sequence = 0;
D
Dave Airlie 已提交
202
}
203 204 205 206 207 208

/*
 * Fire a blit engine.
 */

static void
209
via_fire_dmablit(struct drm_device *dev, drm_via_sg_info_t *vsg, int engine)
210 211 212 213 214
{
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;

	VIA_WRITE(VIA_PCI_DMA_MAR0 + engine*0x10, 0);
	VIA_WRITE(VIA_PCI_DMA_DAR0 + engine*0x10, 0);
D
Dave Airlie 已提交
215
	VIA_WRITE(VIA_PCI_DMA_CSR0 + engine*0x04, VIA_DMA_CSR_DD | VIA_DMA_CSR_TD |
216 217 218 219
		  VIA_DMA_CSR_DE);
	VIA_WRITE(VIA_PCI_DMA_MR0  + engine*0x04, VIA_DMA_MR_CM | VIA_DMA_MR_TDIE);
	VIA_WRITE(VIA_PCI_DMA_BCR0 + engine*0x10, 0);
	VIA_WRITE(VIA_PCI_DMA_DPR0 + engine*0x10, vsg->chain_start);
D
Daniel Vetter 已提交
220
	wmb();
221
	VIA_WRITE(VIA_PCI_DMA_CSR0 + engine*0x04, VIA_DMA_CSR_DE | VIA_DMA_CSR_TS);
T
Thomas Hellstrom 已提交
222
	VIA_READ(VIA_PCI_DMA_CSR0 + engine*0x04);
223 224 225 226 227 228 229 230 231 232 233 234
}

/*
 * Obtain a page pointer array and lock all pages into system memory. A segmentation violation will
 * occur here if the calling user does not have access to the submitted address.
 */

static int
via_lock_all_dma_pages(drm_via_sg_info_t *vsg,  drm_via_dmablit_t *xfer)
{
	int ret;
	unsigned long first_pfn = VIA_PFN(xfer->mem_addr);
235
	vsg->num_pages = VIA_PFN(xfer->mem_addr + (xfer->num_lines * xfer->mem_stride - 1)) -
236
		first_pfn + 1;
D
Dave Airlie 已提交
237

J
Joe Perches 已提交
238 239
	vsg->pages = vzalloc(sizeof(struct page *) * vsg->num_pages);
	if (NULL == vsg->pages)
E
Eric Anholt 已提交
240
		return -ENOMEM;
241
	down_read(&current->mm->mmap_sem);
242 243 244 245 246
	ret = get_user_pages(current, current->mm,
			     (unsigned long)xfer->mem_addr,
			     vsg->num_pages,
			     (vsg->direction == DMA_FROM_DEVICE),
			     0, vsg->pages, NULL);
247 248 249

	up_read(&current->mm->mmap_sem);
	if (ret != vsg->num_pages) {
D
Dave Airlie 已提交
250
		if (ret < 0)
251 252
			return ret;
		vsg->state = dr_via_pages_locked;
E
Eric Anholt 已提交
253
		return -EINVAL;
254 255 256 257 258 259 260 261 262 263 264 265
	}
	vsg->state = dr_via_pages_locked;
	DRM_DEBUG("DMA pages locked\n");
	return 0;
}

/*
 * Allocate DMA capable memory for the blit descriptor chain, and an array that keeps track of the
 * pages we allocate. We don't want to use kmalloc for the descriptor chain because it may be
 * quite large for some blits, and pages don't need to be contingous.
 */

D
Dave Airlie 已提交
266
static int
267 268 269
via_alloc_desc_pages(drm_via_sg_info_t *vsg)
{
	int i;
D
Dave Airlie 已提交
270

271
	vsg->descriptors_per_page = PAGE_SIZE / sizeof(drm_via_descriptor_t);
D
Dave Airlie 已提交
272
	vsg->num_desc_pages = (vsg->num_desc + vsg->descriptors_per_page - 1) /
273 274
		vsg->descriptors_per_page;

275
	if (NULL ==  (vsg->desc_pages = kcalloc(vsg->num_desc_pages, sizeof(void *), GFP_KERNEL)))
E
Eric Anholt 已提交
276
		return -ENOMEM;
D
Dave Airlie 已提交
277

278
	vsg->state = dr_via_desc_pages_alloc;
279
	for (i = 0; i < vsg->num_desc_pages; ++i) {
D
Dave Airlie 已提交
280
		if (NULL == (vsg->desc_pages[i] =
281
			     (drm_via_descriptor_t *) __get_free_page(GFP_KERNEL)))
E
Eric Anholt 已提交
282
			return -ENOMEM;
283 284 285 286 287
	}
	DRM_DEBUG("Allocated %d pages for %d descriptors.\n", vsg->num_desc_pages,
		  vsg->num_desc);
	return 0;
}
D
Dave Airlie 已提交
288

289
static void
290
via_abort_dmablit(struct drm_device *dev, int engine)
291 292 293 294 295 296 297
{
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;

	VIA_WRITE(VIA_PCI_DMA_CSR0 + engine*0x04, VIA_DMA_CSR_TA);
}

static void
298
via_dmablit_engine_off(struct drm_device *dev, int engine)
299 300 301
{
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;

D
Dave Airlie 已提交
302
	VIA_WRITE(VIA_PCI_DMA_CSR0 + engine*0x04, VIA_DMA_CSR_TD | VIA_DMA_CSR_DD);
303 304 305 306 307 308 309 310 311 312
}



/*
 * The dmablit part of the IRQ handler. Trying to do only reasonably fast things here.
 * The rest, like unmapping and freeing memory for done blits is done in a separate workqueue
 * task. Basically the task of the interrupt handler is to submit a new blit to the engine, while
 * the workqueue task takes care of processing associated with the old blit.
 */
D
Dave Airlie 已提交
313

314
void
315
via_dmablit_handler(struct drm_device *dev, int engine, int from_irq)
316 317 318 319 320
{
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;
	drm_via_blitq_t *blitq = dev_priv->blit_queues + engine;
	int cur;
	int done_transfer;
321
	unsigned long irqsave = 0;
322 323 324 325 326
	uint32_t status = 0;

	DRM_DEBUG("DMA blit handler called. engine = %d, from_irq = %d, blitq = 0x%lx\n",
		  engine, from_irq, (unsigned long) blitq);

327
	if (from_irq)
328
		spin_lock(&blitq->blit_lock);
329
	else
330 331
		spin_lock_irqsave(&blitq->blit_lock, irqsave);

D
Dave Airlie 已提交
332
	done_transfer = blitq->is_active &&
333 334
	  ((status = VIA_READ(VIA_PCI_DMA_CSR0 + engine*0x04)) & VIA_DMA_CSR_TD);
	done_transfer = done_transfer || (blitq->aborting && !(status & VIA_DMA_CSR_DE));
335 336 337 338 339 340

	cur = blitq->cur;
	if (done_transfer) {

		blitq->blits[cur]->aborted = blitq->aborting;
		blitq->done_blit_handle++;
341
		wake_up(blitq->blit_queue + cur);
342 343

		cur++;
D
Dave Airlie 已提交
344
		if (cur >= VIA_NUM_BLIT_SLOTS)
345 346 347 348 349 350 351 352 353 354 355
			cur = 0;
		blitq->cur = cur;

		/*
		 * Clear transfer done flag.
		 */

		VIA_WRITE(VIA_PCI_DMA_CSR0 + engine*0x04,  VIA_DMA_CSR_TD);

		blitq->is_active = 0;
		blitq->aborting = 0;
D
Dave Airlie 已提交
356
		schedule_work(&blitq->wq);
357 358 359 360 361 362 363 364 365

	} else if (blitq->is_active && time_after_eq(jiffies, blitq->end)) {

		/*
		 * Abort transfer after one second.
		 */

		via_abort_dmablit(dev, engine);
		blitq->aborting = 1;
D
Daniel Vetter 已提交
366
		blitq->end = jiffies + HZ;
367
	}
D
Dave Airlie 已提交
368

369 370 371 372 373 374
	if (!blitq->is_active) {
		if (blitq->num_outstanding) {
			via_fire_dmablit(dev, blitq->blits[cur], engine);
			blitq->is_active = 1;
			blitq->cur = cur;
			blitq->num_outstanding--;
D
Daniel Vetter 已提交
375
			blitq->end = jiffies + HZ;
J
Jiri Slaby 已提交
376 377
			if (!timer_pending(&blitq->poll_timer))
				mod_timer(&blitq->poll_timer, jiffies + 1);
378
		} else {
379
			if (timer_pending(&blitq->poll_timer))
380 381 382
				del_timer(&blitq->poll_timer);
			via_dmablit_engine_off(dev, engine);
		}
D
Dave Airlie 已提交
383
	}
384

385
	if (from_irq)
386
		spin_unlock(&blitq->blit_lock);
387
	else
388
		spin_unlock_irqrestore(&blitq->blit_lock, irqsave);
D
Dave Airlie 已提交
389
}
390 391 392 393 394 395 396 397 398 399 400 401 402 403 404 405 406 407 408 409 410 411 412 413



/*
 * Check whether this blit is still active, performing necessary locking.
 */

static int
via_dmablit_active(drm_via_blitq_t *blitq, int engine, uint32_t handle, wait_queue_head_t **queue)
{
	unsigned long irqsave;
	uint32_t slot;
	int active;

	spin_lock_irqsave(&blitq->blit_lock, irqsave);

	/*
	 * Allow for handle wraparounds.
	 */

	active = ((blitq->done_blit_handle - handle) > (1 << 23)) &&
		((blitq->cur_blit_handle - handle) <= (1 << 23));

	if (queue && active) {
414 415
		slot = handle - blitq->done_blit_handle + blitq->cur - 1;
		if (slot >= VIA_NUM_BLIT_SLOTS)
416 417 418 419 420 421 422 423
			slot -= VIA_NUM_BLIT_SLOTS;
		*queue = blitq->blit_queue + slot;
	}

	spin_unlock_irqrestore(&blitq->blit_lock, irqsave);

	return active;
}
D
Dave Airlie 已提交
424

425 426 427 428 429
/*
 * Sync. Wait for at least three seconds for the blit to be performed.
 */

static int
D
Dave Airlie 已提交
430
via_dmablit_sync(struct drm_device *dev, uint32_t handle, int engine)
431 432 433 434 435 436 437 438
{

	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;
	drm_via_blitq_t *blitq = dev_priv->blit_queues + engine;
	wait_queue_head_t *queue;
	int ret = 0;

	if (via_dmablit_active(blitq, engine, handle, &queue)) {
D
Daniel Vetter 已提交
439
		DRM_WAIT_ON(ret, *queue, 3 * HZ,
440 441 442 443
			    !via_dmablit_active(blitq, engine, handle, NULL));
	}
	DRM_DEBUG("DMA blit sync handle 0x%x engine %d returned %d\n",
		  handle, engine, ret);
D
Dave Airlie 已提交
444

445 446 447 448 449 450 451 452 453 454 455 456 457 458 459 460 461 462
	return ret;
}


/*
 * A timer that regularly polls the blit engine in cases where we don't have interrupts:
 * a) Broken hardware (typically those that don't have any video capture facility).
 * b) Blit abort. The hardware doesn't send an interrupt when a blit is aborted.
 * The timer and hardware IRQ's can and do work in parallel. If the hardware has
 * irqs, it will shorten the latency somewhat.
 */



static void
via_dmablit_timer(unsigned long data)
{
	drm_via_blitq_t *blitq = (drm_via_blitq_t *) data;
463
	struct drm_device *dev = blitq->dev;
464 465
	int engine = (int)
		(blitq - ((drm_via_private_t *)dev->dev_private)->blit_queues);
D
Dave Airlie 已提交
466 467

	DRM_DEBUG("Polling timer called for engine %d, jiffies %lu\n", engine,
468 469 470
		  (unsigned long) jiffies);

	via_dmablit_handler(dev, engine, 0);
D
Dave Airlie 已提交
471

472
	if (!timer_pending(&blitq->poll_timer)) {
J
Jiri Slaby 已提交
473
		mod_timer(&blitq->poll_timer, jiffies + 1);
474

475 476 477 478 479 480 481 482
	       /*
		* Rerun handler to delete timer if engines are off, and
		* to shorten abort latency. This is a little nasty.
		*/

	       via_dmablit_handler(dev, engine, 0);

	}
483 484 485 486 487 488 489 490 491 492 493 494
}




/*
 * Workqueue task that frees data and mappings associated with a blit.
 * Also wakes up waiting processes. Each of these tasks handles one
 * blit engine only and may not be called on each interrupt.
 */


D
Dave Airlie 已提交
495
static void
D
David Howells 已提交
496
via_dmablit_workqueue(struct work_struct *work)
497
{
D
David Howells 已提交
498
	drm_via_blitq_t *blitq = container_of(work, drm_via_blitq_t, wq);
499
	struct drm_device *dev = blitq->dev;
500 501 502
	unsigned long irqsave;
	drm_via_sg_info_t *cur_sg;
	int cur_released;
D
Dave Airlie 已提交
503 504


505
	DRM_DEBUG("Workqueue task called for blit engine %ld\n", (unsigned long)
506 507 508
		  (blitq - ((drm_via_private_t *)dev->dev_private)->blit_queues));

	spin_lock_irqsave(&blitq->blit_lock, irqsave);
D
Dave Airlie 已提交
509

510
	while (blitq->serviced != blitq->cur) {
511 512 513 514 515

		cur_released = blitq->serviced++;

		DRM_DEBUG("Releasing blit slot %d\n", cur_released);

D
Dave Airlie 已提交
516
		if (blitq->serviced >= VIA_NUM_BLIT_SLOTS)
517
			blitq->serviced = 0;
D
Dave Airlie 已提交
518

519 520
		cur_sg = blitq->blits[cur_released];
		blitq->num_free++;
D
Dave Airlie 已提交
521

522
		spin_unlock_irqrestore(&blitq->blit_lock, irqsave);
D
Dave Airlie 已提交
523

524
		wake_up(&blitq->busy_queue);
D
Dave Airlie 已提交
525

526 527
		via_free_sg_info(dev->pdev, cur_sg);
		kfree(cur_sg);
D
Dave Airlie 已提交
528

529 530 531 532 533
		spin_lock_irqsave(&blitq->blit_lock, irqsave);
	}

	spin_unlock_irqrestore(&blitq->blit_lock, irqsave);
}
D
Dave Airlie 已提交
534

535 536 537 538 539 540 541

/*
 * Init all blit engines. Currently we use two, but some hardware have 4.
 */


void
542
via_init_dmablit(struct drm_device *dev)
543
{
544
	int i, j;
545 546 547
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;
	drm_via_blitq_t *blitq;

D
Dave Airlie 已提交
548 549
	pci_set_master(dev->pdev);

550
	for (i = 0; i < VIA_NUM_BLIT_ENGINES; ++i) {
551 552 553 554 555 556 557
		blitq = dev_priv->blit_queues + i;
		blitq->dev = dev;
		blitq->cur_blit_handle = 0;
		blitq->done_blit_handle = 0;
		blitq->head = 0;
		blitq->cur = 0;
		blitq->serviced = 0;
558
		blitq->num_free = VIA_NUM_BLIT_SLOTS - 1;
559 560 561
		blitq->num_outstanding = 0;
		blitq->is_active = 0;
		blitq->aborting = 0;
I
Ingo Molnar 已提交
562
		spin_lock_init(&blitq->blit_lock);
563
		for (j = 0; j < VIA_NUM_BLIT_SLOTS; ++j)
564 565
			init_waitqueue_head(blitq->blit_queue + j);
		init_waitqueue_head(&blitq->busy_queue);
D
David Howells 已提交
566
		INIT_WORK(&blitq->wq, via_dmablit_workqueue);
J
Jiri Slaby 已提交
567 568
		setup_timer(&blitq->poll_timer, via_dmablit_timer,
				(unsigned long)blitq);
D
Dave Airlie 已提交
569
	}
570 571 572 573 574
}

/*
 * Build all info and do all mappings required for a blit.
 */
D
Dave Airlie 已提交
575

576 577

static int
578
via_build_sg_info(struct drm_device *dev, drm_via_sg_info_t *vsg, drm_via_dmablit_t *xfer)
579 580 581
{
	int draw = xfer->to_fb;
	int ret = 0;
D
Dave Airlie 已提交
582

583
	vsg->direction = (draw) ? DMA_TO_DEVICE : DMA_FROM_DEVICE;
584
	vsg->bounce_buffer = NULL;
585 586 587 588 589

	vsg->state = dr_via_sg_init;

	if (xfer->num_lines <= 0 || xfer->line_length <= 0) {
		DRM_ERROR("Zero size bitblt.\n");
E
Eric Anholt 已提交
590
		return -EINVAL;
591 592 593 594 595
	}

	/*
	 * Below check is a driver limitation, not a hardware one. We
	 * don't want to lock unused pages, and don't want to incoporate the
D
Dave Airlie 已提交
596
	 * extra logic of avoiding them. Make sure there are no.
597 598 599
	 * (Not a big limitation anyway.)
	 */

600
	if ((xfer->mem_stride - xfer->line_length) > 2*PAGE_SIZE) {
601 602
		DRM_ERROR("Too large system memory stride. Stride: %d, "
			  "Length: %d\n", xfer->mem_stride, xfer->line_length);
E
Eric Anholt 已提交
603
		return -EINVAL;
604 605
	}

606 607 608 609 610 611 612 613 614 615 616 617 618 619 620
	if ((xfer->mem_stride == xfer->line_length) &&
	   (xfer->fb_stride == xfer->line_length)) {
		xfer->mem_stride *= xfer->num_lines;
		xfer->line_length = xfer->mem_stride;
		xfer->fb_stride = xfer->mem_stride;
		xfer->num_lines = 1;
	}

	/*
	 * Don't lock an arbitrary large number of pages, since that causes a
	 * DOS security hole.
	 */

	if (xfer->num_lines > 2048 || (xfer->num_lines*xfer->mem_stride > (2048*2048*4))) {
		DRM_ERROR("Too large PCI DMA bitblt.\n");
E
Eric Anholt 已提交
621
		return -EINVAL;
D
Dave Airlie 已提交
622
	}
623

D
Dave Airlie 已提交
624
	/*
625
	 * we allow a negative fb stride to allow flipping of images in
D
Dave Airlie 已提交
626
	 * transfer.
627 628 629 630 631
	 */

	if (xfer->mem_stride < xfer->line_length ||
		abs(xfer->fb_stride) < xfer->line_length) {
		DRM_ERROR("Invalid frame-buffer / memory stride.\n");
E
Eric Anholt 已提交
632
		return -EINVAL;
633 634 635 636 637 638 639 640 641 642
	}

	/*
	 * A hardware bug seems to be worked around if system memory addresses start on
	 * 16 byte boundaries. This seems a bit restrictive however. VIA is contacted
	 * about this. Meanwhile, impose the following restrictions:
	 */

#ifdef VIA_BUGFREE
	if ((((unsigned long)xfer->mem_addr & 3) != ((unsigned long)xfer->fb_addr & 3)) ||
643
	    ((xfer->num_lines > 1) && ((xfer->mem_stride & 3) != (xfer->fb_stride & 3)))) {
644
		DRM_ERROR("Invalid DRM bitblt alignment.\n");
E
Eric Anholt 已提交
645
		return -EINVAL;
646 647 648
	}
#else
	if ((((unsigned long)xfer->mem_addr & 15) ||
649
	      ((unsigned long)xfer->fb_addr & 3)) ||
D
Dave Airlie 已提交
650
	   ((xfer->num_lines > 1) &&
651
	   ((xfer->mem_stride & 15) || (xfer->fb_stride & 3)))) {
652
		DRM_ERROR("Invalid DRM bitblt alignment.\n");
E
Eric Anholt 已提交
653
		return -EINVAL;
D
Dave Airlie 已提交
654
	}
655 656 657 658 659 660 661 662 663 664 665 666 667 668 669
#endif

	if (0 != (ret = via_lock_all_dma_pages(vsg, xfer))) {
		DRM_ERROR("Could not lock DMA pages.\n");
		via_free_sg_info(dev->pdev, vsg);
		return ret;
	}

	via_map_blit_for_device(dev->pdev, xfer, vsg, 0);
	if (0 != (ret = via_alloc_desc_pages(vsg))) {
		DRM_ERROR("Could not allocate DMA descriptor pages.\n");
		via_free_sg_info(dev->pdev, vsg);
		return ret;
	}
	via_map_blit_for_device(dev->pdev, xfer, vsg, 1);
D
Dave Airlie 已提交
670

671 672
	return 0;
}
D
Dave Airlie 已提交
673

674 675 676 677 678 679

/*
 * Reserve one free slot in the blit queue. Will wait for one second for one
 * to become available. Otherwise -EBUSY is returned.
 */

D
Dave Airlie 已提交
680
static int
681 682
via_dmablit_grab_slot(drm_via_blitq_t *blitq, int engine)
{
683
	int ret = 0;
684 685 686 687
	unsigned long irqsave;

	DRM_DEBUG("Num free is %d\n", blitq->num_free);
	spin_lock_irqsave(&blitq->blit_lock, irqsave);
688
	while (blitq->num_free == 0) {
689 690
		spin_unlock_irqrestore(&blitq->blit_lock, irqsave);

D
Daniel Vetter 已提交
691
		DRM_WAIT_ON(ret, blitq->busy_queue, HZ, blitq->num_free > 0);
692
		if (ret)
E
Eric Anholt 已提交
693
			return (-EINTR == ret) ? -EAGAIN : ret;
D
Dave Airlie 已提交
694

695 696
		spin_lock_irqsave(&blitq->blit_lock, irqsave);
	}
D
Dave Airlie 已提交
697

698 699 700 701 702 703 704 705 706 707
	blitq->num_free--;
	spin_unlock_irqrestore(&blitq->blit_lock, irqsave);

	return 0;
}

/*
 * Hand back a free slot if we changed our mind.
 */

D
Dave Airlie 已提交
708
static void
709 710 711 712 713 714 715
via_dmablit_release_slot(drm_via_blitq_t *blitq)
{
	unsigned long irqsave;

	spin_lock_irqsave(&blitq->blit_lock, irqsave);
	blitq->num_free++;
	spin_unlock_irqrestore(&blitq->blit_lock, irqsave);
716
	wake_up(&blitq->busy_queue);
717 718 719 720 721 722 723
}

/*
 * Grab a free slot. Build blit info and queue a blit.
 */


D
Dave Airlie 已提交
724 725
static int
via_dmablit(struct drm_device *dev, drm_via_dmablit_t *xfer)
726 727 728 729
{
	drm_via_private_t *dev_priv = (drm_via_private_t *)dev->dev_private;
	drm_via_sg_info_t *vsg;
	drm_via_blitq_t *blitq;
730
	int ret;
731 732 733 734 735
	int engine;
	unsigned long irqsave;

	if (dev_priv == NULL) {
		DRM_ERROR("Called without initialization.\n");
E
Eric Anholt 已提交
736
		return -EINVAL;
737 738 739 740
	}

	engine = (xfer->to_fb) ? 0 : 1;
	blitq = dev_priv->blit_queues + engine;
741
	if (0 != (ret = via_dmablit_grab_slot(blitq, engine)))
742 743 744
		return ret;
	if (NULL == (vsg = kmalloc(sizeof(*vsg), GFP_KERNEL))) {
		via_dmablit_release_slot(blitq);
E
Eric Anholt 已提交
745
		return -ENOMEM;
746 747 748 749 750 751 752 753 754
	}
	if (0 != (ret = via_build_sg_info(dev, vsg, xfer))) {
		via_dmablit_release_slot(blitq);
		kfree(vsg);
		return ret;
	}
	spin_lock_irqsave(&blitq->blit_lock, irqsave);

	blitq->blits[blitq->head++] = vsg;
D
Dave Airlie 已提交
755
	if (blitq->head >= VIA_NUM_BLIT_SLOTS)
756 757
		blitq->head = 0;
	blitq->num_outstanding++;
D
Dave Airlie 已提交
758
	xfer->sync.sync_handle = ++blitq->cur_blit_handle;
759 760 761 762

	spin_unlock_irqrestore(&blitq->blit_lock, irqsave);
	xfer->sync.engine = engine;

D
Dave Airlie 已提交
763
	via_dmablit_handler(dev, engine, 0);
764 765 766 767 768 769

	return 0;
}

/*
 * Sync on a previously submitted blit. Note that the X server use signals extensively, and
770
 * that there is a very big probability that this IOCTL will be interrupted by a signal. In that
D
Dave Airlie 已提交
771
 * case it returns with -EAGAIN for the signal to be delivered.
772 773 774 775
 * The caller should then reissue the IOCTL. This is similar to what is being done for drmGetLock().
 */

int
776
via_dma_blit_sync(struct drm_device *dev, void *data, struct drm_file *file_priv)
777
{
778
	drm_via_blitsync_t *sync = data;
779 780
	int err;

D
Dave Airlie 已提交
781
	if (sync->engine >= VIA_NUM_BLIT_ENGINES)
E
Eric Anholt 已提交
782
		return -EINVAL;
783

784
	err = via_dmablit_sync(dev, sync->sync_handle, sync->engine);
785

E
Eric Anholt 已提交
786 787
	if (-EINTR == err)
		err = -EAGAIN;
788 789 790

	return err;
}
D
Dave Airlie 已提交
791

792 793 794

/*
 * Queue a blit and hand back a handle to be used for sync. This IOCTL may be interrupted by a signal
D
Dave Airlie 已提交
795
 * while waiting for a free slot in the blit queue. In that case it returns with -EAGAIN and should
796 797 798
 * be reissued. See the above IOCTL code.
 */

D
Dave Airlie 已提交
799
int
800
via_dma_blit(struct drm_device *dev, void *data, struct drm_file *file_priv)
801
{
802
	drm_via_dmablit_t *xfer = data;
803 804
	int err;

805
	err = via_dmablit(dev, xfer);
806 807 808

	return err;
}