* [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
@ 2026-09-23 12:26 Aldo Ariel Panzardo
2026-09-23 14:37 ` Zack Rusin
0 siblings, 1 reply; 8+ messages in thread
From: Aldo Ariel Panzardo @ 2026-09-23 12:26 UTC (permalink / raw)
To: Zack Rusin
Cc: bcm-kernel-feedback-list, dri-devel, Christian König,
linux-kernel, Aldo Ariel Panzardo, stable
vmw_gem_object_get_sg_table() returns vmw_tt->vsgt.sgt when the buffer
object has already been DMA mapped. vmw_ttm_map_dma() sets that field
to &vmw_tt->sgt, which is a member embedded inside the struct
vmw_ttm_tt allocation and not a table of its own.
The core owns whatever .get_sg_table returns. drm_gem_map_dma_buf()
takes the table and drm_gem_unmap_dma_buf() destroys it in full:
dma_unmap_sgtable(attach->dev, sgt, dir, DMA_ATTR_SKIP_CPU_SYNC);
sg_free_table(sgt);
kfree(sgt);
Both are ops of drm_gem_prime_dmabuf_ops, so the core ends up calling
kfree() on &vmw_tt->sgt, which is not the start of an allocation. The
preceding sg_free_table() also destroys a scatterlist that vmwgfx still
considers its own and frees again from vmw_ttm_unmap_dma().
drm_gem_unmap_dma_buf() runs from dma_buf_detach(), including the
importer's error path, so a failed import is enough to reach it:
exporting a bound buffer with DRM_IOCTL_PRIME_HANDLE_TO_FD and
importing it on a second DRM device with DRM_IOCTL_PRIME_FD_TO_HANDLE
is sufficient. Both ioctls are DRM_RENDER_ALLOW.
Observed on 6.12.101 with KASAN, as uid 65534:
BUG: KASAN: invalid-free in drm_gem_unmap_dma_buf+0xb3/0xf0
Free of addr ffff888008290450 by task poc_mm04_sgtabl/321
CPU: 1 UID: 65534 PID: 321 Comm: poc_mm04_sgtabl Not tainted 6.12.101 #4
kasan_report_invalid_free+0x94/0xc0
check_slab_allocation+0x116/0x120
kfree+0x103/0x360
drm_gem_unmap_dma_buf+0xb3/0xf0
dma_buf_detach+0x165/0x510
drm_gem_prime_import_dev+0x33e/0x430
which belongs to the cache kmalloc-192 of size 192
The buggy address is located 80 bytes inside of
144-byte region [ffff888008290400, ffff888008290490)
80 is offsetof(struct vmw_ttm_tt, sgt) and 144 is sizeof(struct
vmw_ttm_tt), which identifies the freed pointer as the embedded member.
Always return a table the core can own, as the other drivers do.
Reusing the cached representation would require copying it into a
freshly allocated sg_table, never returning the alias.
Fixes: 8afa13a0583f ("drm/vmwgfx: Implement DRIVER_GEM")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
---
drivers/gpu/drm/vmwgfx/vmwgfx_gem.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
index 39f8c4655..a0233729b 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
@@ -73,10 +73,13 @@ static struct sg_table *vmw_gem_object_get_sg_table(struct drm_gem_object *obj)
struct vmw_ttm_tt *vmw_tt =
container_of(bo->ttm, struct vmw_ttm_tt, dma_ttm);
- if (vmw_tt->vsgt.sgt)
- return vmw_tt->vsgt.sgt;
-
- return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages, vmw_tt->dma_ttm.num_pages);
+ /*
+ * Do not return &vmw_tt->sgt: the core owns what this returns and
+ * drm_gem_unmap_dma_buf() sg_free_table()s and kfree()s it, but that
+ * sg_table is embedded in the vmw_ttm_tt allocation.
+ */
+ return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages,
+ vmw_tt->dma_ttm.num_pages);
}
static int vmw_gem_vmap(struct drm_gem_object *obj, struct iosys_map *map)
--
2.43.0
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
2026-09-23 12:26 [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core Aldo Ariel Panzardo
@ 2026-09-23 14:37 ` Zack Rusin
[not found] ` <CAP48HfviFZXacVY9Lj4Hv7+brObhmxWLYAM8MNiTUkJNchnp1Q@mail.gmail.com>
0 siblings, 1 reply; 8+ messages in thread
From: Zack Rusin @ 2026-09-23 14:37 UTC (permalink / raw)
To: Aldo Ariel Panzardo
Cc: bcm-kernel-feedback-list, dri-devel, Christian König,
linux-kernel, stable
[-- Attachment #1: Type: text/plain, Size: 3946 bytes --]
On Wed, Sep 23, 2026 at 8:26 AM Aldo Ariel Panzardo <qwe.aldo@gmail.com> wrote:
>
> vmw_gem_object_get_sg_table() returns vmw_tt->vsgt.sgt when the buffer
> object has already been DMA mapped. vmw_ttm_map_dma() sets that field
> to &vmw_tt->sgt, which is a member embedded inside the struct
> vmw_ttm_tt allocation and not a table of its own.
>
> The core owns whatever .get_sg_table returns. drm_gem_map_dma_buf()
> takes the table and drm_gem_unmap_dma_buf() destroys it in full:
>
> dma_unmap_sgtable(attach->dev, sgt, dir, DMA_ATTR_SKIP_CPU_SYNC);
> sg_free_table(sgt);
> kfree(sgt);
>
> Both are ops of drm_gem_prime_dmabuf_ops, so the core ends up calling
> kfree() on &vmw_tt->sgt, which is not the start of an allocation. The
> preceding sg_free_table() also destroys a scatterlist that vmwgfx still
> considers its own and frees again from vmw_ttm_unmap_dma().
>
> drm_gem_unmap_dma_buf() runs from dma_buf_detach(), including the
> importer's error path, so a failed import is enough to reach it:
> exporting a bound buffer with DRM_IOCTL_PRIME_HANDLE_TO_FD and
> importing it on a second DRM device with DRM_IOCTL_PRIME_FD_TO_HANDLE
> is sufficient. Both ioctls are DRM_RENDER_ALLOW.
>
> Observed on 6.12.101 with KASAN, as uid 65534:
>
> BUG: KASAN: invalid-free in drm_gem_unmap_dma_buf+0xb3/0xf0
> Free of addr ffff888008290450 by task poc_mm04_sgtabl/321
> CPU: 1 UID: 65534 PID: 321 Comm: poc_mm04_sgtabl Not tainted 6.12.101 #4
> kasan_report_invalid_free+0x94/0xc0
> check_slab_allocation+0x116/0x120
> kfree+0x103/0x360
> drm_gem_unmap_dma_buf+0xb3/0xf0
> dma_buf_detach+0x165/0x510
> drm_gem_prime_import_dev+0x33e/0x430
> which belongs to the cache kmalloc-192 of size 192
> The buggy address is located 80 bytes inside of
> 144-byte region [ffff888008290400, ffff888008290490)
>
> 80 is offsetof(struct vmw_ttm_tt, sgt) and 144 is sizeof(struct
> vmw_ttm_tt), which identifies the freed pointer as the embedded member.
>
> Always return a table the core can own, as the other drivers do.
> Reusing the cached representation would require copying it into a
> freshly allocated sg_table, never returning the alias.
>
> Fixes: 8afa13a0583f ("drm/vmwgfx: Implement DRIVER_GEM")
> Cc: stable@vger.kernel.org
> Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
> ---
> drivers/gpu/drm/vmwgfx/vmwgfx_gem.c | 11 +++++++----
> 1 file changed, 7 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
> index 39f8c4655..a0233729b 100644
> --- a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
> +++ b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
> @@ -73,10 +73,13 @@ static struct sg_table *vmw_gem_object_get_sg_table(struct drm_gem_object *obj)
> struct vmw_ttm_tt *vmw_tt =
> container_of(bo->ttm, struct vmw_ttm_tt, dma_ttm);
>
> - if (vmw_tt->vsgt.sgt)
> - return vmw_tt->vsgt.sgt;
> -
> - return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages, vmw_tt->dma_ttm.num_pages);
> + /*
> + * Do not return &vmw_tt->sgt: the core owns what this returns and
> + * drm_gem_unmap_dma_buf() sg_free_table()s and kfree()s it, but that
> + * sg_table is embedded in the vmw_ttm_tt allocation.
> + */
> + return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages,
> + vmw_tt->dma_ttm.num_pages);
> }
>
> static int vmw_gem_vmap(struct drm_gem_object *obj, struct iosys_map *map)
> --
> 2.43.0
>
Thank you. Because of the influx of llm patches it's very hard to
reason about what's valid and what's not if it comes without a
reproducible testcase. Could you please add an igt testcase for this
and then include the full igt results for vmwgfx before and after this
change? Same for your other change.
z
[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 5414 bytes --]
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
[not found] ` <CAP48HfviFZXacVY9Lj4Hv7+brObhmxWLYAM8MNiTUkJNchnp1Q@mail.gmail.com>
@ 2026-10-03 0:34 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-03 16:38 ` Aldo Ariel Panzardo
0 siblings, 1 reply; 8+ messages in thread
From: Maaz Mombasawala <maaz.mombasawala@broadcom.com> @ 2026-10-03 0:34 UTC (permalink / raw)
To: Aldo Ariel, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
Hi Aldo,
Using your POC, I am not able to recreate this bug you described in your commit.
This is on a top of tree drm-misc-fixes kernel with kasan enabled.
Are you sure the bug you describe is not fixed on drm-misc-fixes already?
--
Maaz Mombasawala <maaz.mombasawala@broadcom.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
2026-10-03 0:34 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
@ 2026-10-03 16:38 ` Aldo Ariel Panzardo
2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
0 siblings, 1 reply; 8+ messages in thread
From: Aldo Ariel Panzardo @ 2026-10-03 16:38 UTC (permalink / raw)
To: maaz.mombasawala, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
Hi Maaz,
Thanks for testing.
I think the reason you could not reproduce is that the original PoC
opens two fds to the same vmwgfx render node. When the importer
and exporter are the same device, drm_gem_prime_import_dev() hits
the drm_gem_is_prime_exported_dma_buf() check (drm_prime.c:976):
it sees dma_buf->ops == drm_gem_prime_dmabuf_ops && obj->dev == dev,
and returns dma_buf->priv directly without attaching or mapping —
so drm_gem_unmap_dma_buf() is never reached and the kfree never fires.
To hit the invalid-free, the PRIME import must go through a
different DRM device (e.g. virtio-gpu) so the full attachment
map/unmap path is taken. In addition, the BO must be bound to a GB
surface before the import, so that vmw_ttm_map_dma() runs and
caches vsgt.sgt = &vmw_tt->sgt (the embedded member). Without the
bind, the TTM is not DMA-mapped and get_sg_table falls through to
drm_prime_pages_to_sg(), which allocates a fresh table — no bug.
With an updated PoC that uses a second GPU for import and binds the
BO first, I was able to reproduce on mainline 7.3-rc4 (6edd14dd67d7):
BUG: KASAN: invalid-free in drm_gem_unmap_dma_buf+0x6b/0x80
Free of addr ffff888103c34e60 by task poc_mm04_attack/242
CPU: 2 UID: 65534 PID: 242 Comm: poc_mm04_attack Not tainted
7.3.0-rc4-g6edd14dd67d7-dirty #8 PREEMPT(lazy)
Call Trace:
<TASK>
kasan_report_invalid_free+0xb8/0xe0
check_slab_allocation+0xf5/0x100
kfree+0x163/0x510
drm_gem_unmap_dma_buf+0x6b/0x80
dma_buf_unmap_attachment_unlocked+0x72/0xc0
drm_gem_prime_import_dev+0x1f5/0x260
virtgpu_gem_prime_import+0x328/0x580
drm_gem_prime_fd_to_handle+0x116/0x370
drm_ioctl+0x3d4/0x790
Allocated by task 242:
vmw_ttm_tt_create+0x4c/0x130
ttm_tt_create+0xca/0x190
ttm_bo_handle_move_mem+0xea/0x270
vmw_bo_create+0x248/0x3c0
vmw_gem_object_create_ioctl+0xa1/0x1a0
The buggy address belongs to the cache kmalloc-192 of size 192
The buggy address is located 96 bytes inside of
160-byte region [ffff888103c34e00, ffff888103c34ea0)
Setup:
- QEMU with -device vmware-svga -device virtio-gpu-pci
- Kernel: 7.3-rc4, KASAN, CONFIG_DRM_VMWGFX=y
- Three local-only changes to make vmwgfx probe on QEMU:
1. pitchlock error return bypassed (hardware capability
check, not security-relevant — VMware real passes it)
2. SVGA_CAP_GBOBJECTS forced (QEMU does not advertise it;
VMware real does)
3. max_mob_pages/max_mob_size forced to 256 MB (QEMU
returns 0; VMware real provides real values)
None of these touch the PRIME export/import path or the
sg_table ownership code.
- DMA map mode: vmw_dma_map_populate (line in boot log:
"DMA map mode: Caching DMA mappings")
Steps (runs as uid 65534):
1. DRM_VMW_ALLOC_DMABUF(262144) on vmwgfx renderD128
2. DRM_IOCTL_PRIME_HANDLE_TO_FD
3. DRM_VMW_GB_SURFACE_CREATE 256x256
4. EXECBUF BIND_GB_SURFACE(sid, mobid=handle)
-> vmw_ttm_bind -> vmw_ttm_map_dma
-> sets vsgt.sgt = &vmw_tt->sgt (embedded, vmw_dma_map_populate)
5. DRM_IOCTL_PRIME_FD_TO_HANDLE on virtio-gpu renderD129
-> dma_buf_map_attachment -> drm_gem_map_dma_buf
-> vmw_gem_object_get_sg_table returns &vmw_tt->sgt
-> virtgpu_gem_prime_import_sg_table fails with -ENODEV
(no blob resource support in this QEMU config)
-> error cleanup: dma_buf_unmap_attachment_unlocked
-> drm_gem_unmap_dma_buf: sg_free_table + kfree(&vmw_tt->sgt)
=> KASAN: invalid-free (interior pointer of vmw_ttm_tt)
I also found a second, related bug in the same function. When
testing without the GBOBJECTS/MOB patches (i.e. vanilla QEMU where
BOs go to VRAM only), vmw_gem_object_get_sg_table() does
container_of(bo->ttm, ...) without checking that bo->ttm is
non-NULL. Without MOB, the BO stays in VRAM and no TTM TT is
ever allocated, so bo->ttm is NULL and the dereference faults:
BUG: KASAN: null-ptr-deref in vmw_gem_object_get_sg_table+0x2f/0xa0
Read of size 8 at addr 0000000000000088 by task poc_sgtable/330
CPU: 0 UID: 0 PID: 330 Comm: poc_sgtable Not tainted
7.3.0-rc4-g6edd14dd67d7-dirty #7 PREEMPT(lazy)
Call Trace:
vmw_gem_object_get_sg_table+0x2f/0xa0
drm_gem_map_dma_buf+0x79/0x120
dma_buf_map_attachment+0xc1/0x4f0
drm_gem_prime_import_dev+0xe0/0x260
virtgpu_gem_prime_import+0x328/0x580
drm_gem_prime_fd_to_handle+0x116/0x370
Steps:
1. DRM_IOCTL_MODE_CREATE_DUMB on vmwgfx (64x64x32)
2. DRM_IOCTL_PRIME_HANDLE_TO_FD
3. DRM_IOCTL_PRIME_FD_TO_HANDLE on virtio-gpu
-> NULL pointer dereference at offset 0x88
I have both PoC sources and the full KASAN/dmesg logs ready.
Regarding Zack's request for igt tests: I have not written those
yet but plan to include them with v2.
Would you like me to send v2 as two patches (1/2 NULL-check,
2/2 embedded sg_table fix) in this same thread, or do you prefer
the NULL-deref fix as a separate submission?
thanks,
Aldo
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
2026-10-03 16:38 ` Aldo Ariel Panzardo
@ 2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-07 4:43 ` Aldo Ariel Panzardo
` (2 more replies)
0 siblings, 3 replies; 8+ messages in thread
From: Maaz Mombasawala <maaz.mombasawala@broadcom.com> @ 2026-10-05 20:16 UTC (permalink / raw)
To: Aldo Ariel Panzardo, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
Hi,
I see you are using qemu for virtualization. That is not something we test and
support, can you recreate this bug and do the fix on vmware workstation
instead?
Also please do an igt run to make sure there are no regressions with your fix.
--
Maaz Mombasawala <maaz.mombasawala@broadcom.com>
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core
2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
@ 2026-10-07 4:43 ` Aldo Ariel Panzardo
2026-10-07 4:46 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - UNFIXED vmwgfx] Aldo Ariel Panzardo
2026-10-07 4:47 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - FIXED vmwgfx] Aldo Ariel Panzardo
2 siblings, 0 replies; 8+ messages in thread
From: Aldo Ariel Panzardo @ 2026-10-07 4:43 UTC (permalink / raw)
To: maaz.mombasawala, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
Hi Maaz,
I reproduced the bug on VMware Workstation with a kernel based on
mainline (commit 6edd14dd67d7, v7.3-rc4), with the vgem test
modification described below. Below is the setup, the KASAN splat,
and notes on reproducing.
Regarding your October 3 question about drm-misc-fixes: as of
2026-10-06, I searched for "vmw_gem_object_get_sg_table drm-misc-fixes"
and found no indexed commit fixing this function's embedded sg_table
ownership issue. The published drm-misc-fixes-2026-10-01 pull request
lists vmwgfx input validation and blend-mode changes, not this fix [1].
I could not access the branch's live file history, so I cannot confirm
that no commit touching vmw_gem_object_get_sg_table exists at its current
tip. The vgem import-path change described below can prevent the test
from reaching the affected callback without fixing that callback.
[1] https://www.mail-archive.com/dri-devel%40lists.freedesktop.org/msg641567.html
Setup:
- VMware Workstation 26.0.0 (build 25388281) on Ubuntu 24.04 host
- Guest: Debian 12 (bookworm), CONFIG_KASAN=y
- Kernel: commit 6edd14dd67d76d39a518ad3bf1a98363690a5a62 (v7.3-rc4)
- vmwgfx loaded as module (out-of-tree rebuild from same tree)
- Second DRM device: vgem (with gem_prime_import_sg_table enabled,
see note below)
- PoC runs as UID 65534 (nobody), no capabilities
KASAN splat (the v7.3-rc4 commit above, VMware Workstation):
The runtime release string in the unedited trace below is 7.3.0-rc4+.
BUG: KASAN: invalid-free in dma_buf_unmap_attachment+0xaa/0x1d0
Free of addr ffff888104489960 by task poc_sgtable/354
CPU: 0 UID: 65534 PID: 354 Comm: poc_sgtable Tainted: G OE 7.3.0-rc4+ #16
Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 02/17/2026
Call Trace:
<TASK>
dump_stack_lvl+0x60/0x80
print_report+0xd0/0x630
kasan_report_invalid_free+0x9e/0xc0
check_slab_allocation+0xf5/0x100
kfree+0x166/0x420
dma_buf_unmap_attachment+0xaa/0x1d0
dma_buf_unmap_attachment_unlocked+0x80/0x100
drm_prime_gem_destroy+0x42/0x90 [drm]
drm_gem_shmem_release+0x71/0x800 [drm_shmem_helper]
drm_gem_shmem_object_free+0x9/0x20 [drm_shmem_helper]
drm_gem_object_release_handle+0xaf/0x220 [drm]
drm_gem_handle_delete+0x59/0xa0 [drm]
drm_ioctl_kernel+0x163/0x2d0 [drm]
drm_ioctl+0x4ce/0xb10 [drm]
__x64_sys_ioctl+0x135/0x1c0
do_syscall_64+0xc1/0x560
entry_SYSCALL_64_after_hwframe+0x76/0x7e
Steps to reproduce:
1. DRM_VMW_ALLOC_DMABUF(262144) on vmwgfx renderD128
2. DRM_IOCTL_PRIME_HANDLE_TO_FD
3. DRM_VMW_GB_SURFACE_CREATE_EXT 64x64 (BO size 262144 bytes)
4. EXECBUF BIND_GB_SURFACE(sid, mobid=handle)
-> vmw_ttm_bind -> vmw_ttm_map_dma
-> caches vsgt.sgt = &vmw_tt->sgt (embedded member)
5. DRM_IOCTL_PRIME_FD_TO_HANDLE on a second DRM device (vgem)
-> dma_buf_map_attachment -> drm_gem_map_dma_buf
-> vmw_gem_object_get_sg_table returns &vmw_tt->sgt
6. Close the importing GEM handle (DRM_IOCTL_GEM_CLOSE or fd close)
-> drm_prime_gem_destroy -> dma_buf_unmap_attachment
-> drm_gem_unmap_dma_buf: sg_free_table + kfree(&vmw_tt->sgt)
(drm_gem_unmap_dma_buf elided in trace by tail-call optimization)
=> KASAN: invalid-free (interior pointer of vmw_ttm_tt object)
Note on the importing device:
The bug is in vmwgfx's vmw_gem_object_get_sg_table() which returns
an interior pointer (&vmw_tt->sgt) that the DRM core later kfree()s.
Any importing driver that calls dma_buf_map_attachment() triggers it,
provided the BO has been DMA-mapped (vsgt.sgt cached by a prior
surface bind), as demonstrated with vgem configured with
gem_prime_import_sg_table. This was tested with vgem; the statement
about other importing drivers is an inference from the shared PRIME
map/unmap path.
On mainline, vgem recently switched to drm_gem_shmem_prime_import_no_map
(commit 660cd44659a0, "drm/shmem-helper: Import dmabuf without mapping
its sg_table") which skips the map/unmap cycle entirely. This means
vgem no longer exercises the buggy path by default. For this reproduction,
I set .gem_prime_import_sg_table = drm_gem_shmem_prime_import_sg_table
in vgem_drv.c to use the mapping import path (one-line change, no
modification to vmwgfx).
The vgem change avoids the affected path for vgem specifically, but
the underlying vmwgfx defect is unresolved: vmw_gem_object_get_sg_table()
still returns an interior pointer when vsgt.sgt is cached on the
tested kernel. The invalid kfree was demonstrated with vgem configured
with gem_prime_import_sg_table; other importing drivers were not tested.
I also confirmed the invalid-free on kernel 6.12.0 running on
VMware Workstation, where vgem still uses the mapping import path
and no vgem modification is needed:
BUG: KASAN: invalid-free in dma_buf_detach+0x147/0x4e0
Free of addr ffff88811813e250 by task poc_sgtable/521
CPU: 3 UID: 65534 PID: 521 Comm: poc_sgtable Tainted: G OE 6.12.0 #3
Hardware name: VMware, Inc. VMware Virtual Platform
Call Trace:
kasan_report_invalid_free+0x90/0xb0
check_slab_allocation+0xf5/0x100
kfree+0xd3/0x400
dma_buf_detach+0x147/0x4e0
drm_prime_gem_destroy+0x67/0x90 [drm]
drm_gem_shmem_free+0x71/0x520 [drm_shmem_helper]
drm_gem_handle_delete+0xd9/0x140 [drm]
Patch used for the comparison:
UNFIXED means vmwgfx built from commit
6edd14dd67d76d39a518ad3bf1a98363690a5a62 (v7.3-rc4). FIXED means the
same commit with the change below applied to vmw_gem_object_get_sg_table().
This patch contains two changes:
(a) Add a NULL-check for bo->ttm before dereferencing it via
container_of, returning -ENODEV if the TTM backend is absent.
(b) Always return a freshly allocated sg_table via
drm_prime_pages_to_sg() instead of returning the cached
vsgt.sgt interior pointer, which is the root cause of the
invalid kfree.
diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
index 39f8c46550c2..98c5e42cc762 100644
--- a/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
+++ b/drivers/gpu/drm/vmwgfx/vmwgfx_gem.c
@@ -70,13 +70,15 @@ static void vmw_gem_object_unpin(struct drm_gem_object *obj)
static struct sg_table *vmw_gem_object_get_sg_table(struct drm_gem_object *obj)
{
struct ttm_buffer_object *bo = drm_gem_ttm_of_gem(obj);
- struct vmw_ttm_tt *vmw_tt =
- container_of(bo->ttm, struct vmw_ttm_tt, dma_ttm);
+ struct vmw_ttm_tt *vmw_tt;
- if (vmw_tt->vsgt.sgt)
- return vmw_tt->vsgt.sgt;
+ if (!bo->ttm)
+ return ERR_PTR(-ENODEV);
- return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages, vmw_tt->dma_ttm.num_pages);
+ vmw_tt = container_of(bo->ttm, struct vmw_ttm_tt, dma_ttm);
+
+ return drm_prime_pages_to_sg(obj->dev, vmw_tt->dma_ttm.pages,
+ vmw_tt->dma_ttm.num_pages);
}
static int vmw_gem_vmap(struct drm_gem_object *obj, struct iosys_map *map)
IGT regression test (existing suite):
I ran the igt-gpu-tools vmwgfx test suite on the same kernel
(6edd14dd67d76d39a518ad3bf1a98363690a5a62, v7.3-rc4,
VMware Workstation, Debian 12), swapping vmwgfx.ko built without and
with the fix described above at runtime via rmmod/insmod. Results
are identical -- no additional failures:
IGT version: 2.6-NO-GIT (source from commit 5e43e9d, built from tarball)
Invocations:
sudo /usr/local/igt/vmwgfx/vmw_execution_buffer
sudo /usr/local/igt/vmwgfx/vmw_mob_stress
sudo /usr/local/igt/vmwgfx/vmw_ref_count
sudo /usr/local/igt/vmwgfx/vmw_surface_copy
sudo /usr/local/igt/vmwgfx/vmw_tri
sudo /usr/local/igt/vmwgfx/vmw_prime
UNFIXED FIXED
vmw_execution_buffer:
mob-create-map: SUCCESS SUCCESS
buffer-create: SUCCESS SUCCESS
execution-buffer-submit-sync: SUCCESS SUCCESS
vmw_mob_stress:
max_mob_mem_stress: FAIL FAIL (pre-existing)
vmw_ref_count:
surface_prime_transfer_explicit_mob: SUCCESS SUCCESS
surface_prime_transfer_implicit_mob: SUCCESS SUCCESS
surface_prime_transfer_fd_dup: SUCCESS SUCCESS
surface_prime_transfer_two_surfaces: SUCCESS SUCCESS
surface_prime_transfer_single_surface_multiple_handle: SUCCESS SUCCESS
mob_repeated_unref: SUCCESS SUCCESS
surface_repeated_unref: SUCCESS SUCCESS
surface_alloc_ref_unref: SUCCESS SUCCESS
surface_buffer_ref: SUCCESS SUCCESS
surface_prime_refs: SUCCESS SUCCESS
surface_buffer_prime_refs: SUCCESS SUCCESS
vmw_surface_copy:
test_invalid_copies: SUCCESS SUCCESS
test_invalid_copies_3d: SUCCESS SUCCESS
vmw_tri:
tri: FAIL FAIL (pre-existing)
tri-no-sync-coherent: FAIL FAIL (pre-existing)
tri-2d: SUCCESS SUCCESS
vmw_prime:
basic-vgem: SUCCESS SUCCESS
tri-map-gem: FAIL FAIL (pre-existing)
tri-map-dmabuf: FAIL FAIL (pre-existing)
draw-dumb-buffer: FAIL FAIL (pre-existing)
buffer-surface-fb-sharing-sync-readback: FAIL FAIL (pre-existing)
buffer-surface-fb-sharing-sync: FAIL FAIL (pre-existing)
buffer-surface-fb-sharing: FAIL FAIL (pre-existing)
18 SUCCESS, 9 FAIL (all pre-existing, identical in both runs).
Every subtest listed individually. No additional failures from
the fix.
IGT regression test (new sgtable-invalid-free subtest):
I also wrote and compiled a dedicated IGT subtest
(vmw_prime_sgtable) that exercises the same PRIME
export/import/close flow from the standalone reproducer. It was
compiled against the igt-gpu-tools tree and executed on the same
kernel (v7.3-rc4, VMware Workstation, CONFIG_KASAN=y), with the
same vgem mapping-import configuration described above. Results:
- UNFIXED vmwgfx: subtest sgtable-invalid-free SUCCESS.
Immediately afterward, a TTM cleanup worker Oopsed in
dma_direct_unmap_sg, with vmw_ttm_unmap_dma in the call
trace. This is consistent with corruption of the sg_table
used during cleanup.
- FIXED vmwgfx: subtest sgtable-invalid-free SUCCESS.
dmesg after the test shows no Oops, no KASAN reports,
no BUG. A separate WARNING from vmw_cmdbuf_ctx_process
(command buffer error during EXECBUF) appears in dmesg;
it is distinct from the sg_table invalid-free reported
here.
Full IGT logs follow in two replies to this message (unfixed and
fixed runs).
Standalone reproducer results:
The standalone reproducer (vmw_sgtable_test.c) was compiled and
executed on VMware Workstation 26.0.0, kernel commit
6edd14dd67d76d39a518ad3bf1a98363690a5a62 (v7.3-rc4), without and
with the fix described above:
- UNFIXED vmwgfx: BUG: KASAN: invalid-free in dma_buf_unmap_attachment
- FIXED vmwgfx: clean (no KASAN)
Both the standalone reproducer and the IGT testcase were compiled and
executed as described above. The standalone reproducer
(vmw_sgtable_test.c) and IGT testcase source
(vmw_prime_sgtable.c) are included below.
Full IGT logs follow in two replies to this message (unfixed
and fixed runs).
Requires vgem with gem_prime_import_sg_table (one-line override in
vgem_drv.c, see note above) to exercise the mapping import path.
Let me know if you can reproduce with this setup, or if you need
anything else from my side. I am happy to send v2 patches whenever
you are ready.
thanks,
Aldo
---8<--- vmw_sgtable_test.c ---8<---
/*
* vmw_prime_sgtable_test: Reproduce embedded sg_table invalid-free in vmwgfx.
* Without fix: KASAN reports invalid-free. With fix: clean.
*/
#include <stdio.h>
#include <string.h>
#include <stdlib.h>
#include <fcntl.h>
#include <unistd.h>
#include <sys/ioctl.h>
#include <sys/mman.h>
#include <errno.h>
#include <stdint.h>
/* DRM core */
#define DRM_COMMAND_BASE 0x40
#define DRM_IOCTL_BASE 'd'
#define DRM_IOWR(nr, type) _IOWR(DRM_IOCTL_BASE, nr, type)
#define DRM_IOW(nr, type) _IOW(DRM_IOCTL_BASE, nr, type)
struct drm_prime_handle { uint32_t handle; uint32_t flags; int32_t fd; };
struct drm_gem_close { uint32_t handle; uint32_t pad; };
#define DRM_IOCTL_PRIME_HANDLE_TO_FD _IOWR(DRM_IOCTL_BASE, 0x2d, struct drm_prime_handle)
#define DRM_IOCTL_PRIME_FD_TO_HANDLE _IOWR(DRM_IOCTL_BASE, 0x2e, struct drm_prime_handle)
#define DRM_IOCTL_GEM_CLOSE _IOW(DRM_IOCTL_BASE, 0x09, struct drm_gem_close)
/* vmwgfx */
#define DRM_VMW_ALLOC_DMABUF 1
#define DRM_VMW_GB_SURFACE_CREATE 23
#define DRM_VMW_GB_SURFACE_CREATE_EXT 27
#define DRM_VMW_EXECBUF 12
#define DRM_VMW_EXECBUF_VERSION 2
#define SVGA_3D_CMD_BIND_GB_SURFACE 1099
struct drm_vmw_alloc_bo_req { uint32_t size, pad64; };
struct drm_vmw_bo_rep { uint64_t map_handle; uint32_t handle, cur_gmr_id, cur_gmr_offset, pad64; };
union drm_vmw_alloc_bo_arg { struct drm_vmw_alloc_bo_req req; struct drm_vmw_bo_rep rep; };
struct drm_vmw_size { uint32_t width, height, depth, pad64; };
struct drm_vmw_gb_surface_create_req {
uint32_t svga3d_flags; uint32_t format; uint32_t mip_levels;
uint32_t drm_surface_flags; uint32_t multisample_count;
uint32_t autogen_filter; uint32_t array_size;
uint32_t buffer_handle; struct drm_vmw_size base_size;
};
struct drm_vmw_gb_surface_create_rep {
uint32_t handle; uint32_t backup_size; uint32_t buffer_handle;
uint32_t buffer_size; uint64_t buffer_map_handle;
};
union drm_vmw_gb_surface_create_arg {
struct drm_vmw_gb_surface_create_rep rep;
struct drm_vmw_gb_surface_create_req req;
};
struct drm_vmw_gb_surface_create_ext_req {
struct drm_vmw_gb_surface_create_req base;
uint32_t version;
uint32_t svga3d_flags_upper_32_bits;
uint32_t multisample_pattern;
uint32_t quality_level;
uint32_t buffer_byte_stride;
uint32_t must_be_zero;
};
union drm_vmw_gb_surface_create_ext_arg {
struct drm_vmw_gb_surface_create_ext_req req;
struct drm_vmw_gb_surface_create_rep rep;
};
struct drm_vmw_execbuf_arg {
uint64_t commands; uint32_t command_size; uint32_t throttle_us;
uint64_t fence_rep; uint32_t version; uint32_t flags;
uint32_t context_handle; int32_t imported_fence_fd;
};
#pragma pack(push, 1)
typedef struct { uint32_t id; uint32_t size; } SVGA3dCmdHeader;
typedef struct { uint32_t sid; uint32_t mobid; } SVGA3dCmdBindGBSurface;
#pragma pack(pop)
#define IOCTL_ALLOC DRM_IOWR(DRM_COMMAND_BASE + DRM_VMW_ALLOC_DMABUF, union drm_vmw_alloc_bo_arg)
#define IOCTL_SURFACE_EXT DRM_IOWR(DRM_COMMAND_BASE + DRM_VMW_GB_SURFACE_CREATE_EXT, union drm_vmw_gb_surface_create_ext_arg)
#define IOCTL_EXECBUF DRM_IOW(DRM_COMMAND_BASE + DRM_VMW_EXECBUF, struct drm_vmw_execbuf_arg)
int main(void) {
int vmw_fd, vgem_fd, prime_fd, ret;
union drm_vmw_alloc_bo_arg alloc;
union drm_vmw_gb_surface_create_ext_arg surf;
struct drm_vmw_execbuf_arg exec;
struct { SVGA3dCmdHeader hdr; SVGA3dCmdBindGBSurface body; } cmd;
struct drm_prime_handle ph, ph2;
struct drm_gem_close cl;
void *map;
vmw_fd = open("/dev/dri/renderD128", O_RDWR);
vgem_fd = open("/dev/dri/renderD129", O_RDWR);
if (vmw_fd < 0 || vgem_fd < 0) { perror("open"); return 77; }
/* 1. Alloc BO */
memset(&alloc, 0, sizeof(alloc));
alloc.req.size = 256 * 256 * 4;
ret = ioctl(vmw_fd, IOCTL_ALLOC, &alloc);
if (ret < 0) { perror("alloc"); return 1; }
printf("[+] BO handle=%u\n", alloc.rep.handle);
/* 2. Populate */
map = mmap(NULL, 256*256*4, PROT_READ|PROT_WRITE, MAP_SHARED, vmw_fd, alloc.rep.map_handle);
if (map != MAP_FAILED) { memset(map, 0x41, 256*256*4); munmap(map, 256*256*4); }
/* 3. PRIME export the MOB handle */
memset(&ph, 0, sizeof(ph));
ph.handle = alloc.rep.handle;
ph.flags = O_CLOEXEC | O_RDWR;
ret = ioctl(vmw_fd, DRM_IOCTL_PRIME_HANDLE_TO_FD, &ph);
if (ret < 0) { perror("export"); return 1; }
prime_fd = ph.fd;
printf("[+] PRIME exported fd=%d\n", prime_fd);
/* 4. Create GB surface + bind (triggers vmw_ttm_map_dma -> vsgt.sgt cache) */
memset(&surf, 0, sizeof(surf));
surf.req.base.svga3d_flags = (1 << 6); /* SVGA3D_SURFACE_HINT_RENDERTARGET */
surf.req.base.format = 37; /* SVGA3D_BUFFER */
surf.req.base.mip_levels = 1;
surf.req.base.autogen_filter = 1;
surf.req.base.array_size = 1;
surf.req.base.drm_surface_flags = 1; /* drm_vmw_surface_flag_shareable */
surf.req.base.buffer_handle = alloc.rep.handle; /* backup = our MOB */
surf.req.base.base_size.width = 64;
surf.req.base.base_size.height = 64;
surf.req.base.base_size.depth = 1;
surf.req.version = 1; /* drm_vmw_surface_version_v1 */
ret = ioctl(vmw_fd, IOCTL_SURFACE_EXT, &surf);
if (ret < 0) { printf("[-] surface create: %s (non-fatal)\n", strerror(errno)); }
else {
printf("[+] surface sid=%u backup_size=%u\n", surf.rep.handle, surf.rep.backup_size);
/* EXECBUF bind */
cmd.hdr.id = SVGA_3D_CMD_BIND_GB_SURFACE;
cmd.hdr.size = sizeof(cmd.body);
cmd.body.sid = surf.rep.handle;
cmd.body.mobid = alloc.rep.handle;
memset(&exec, 0, sizeof(exec));
exec.commands = (uint64_t)(uintptr_t)&cmd;
exec.command_size = sizeof(cmd);
exec.version = DRM_VMW_EXECBUF_VERSION;
exec.context_handle = 0xFFFFFFFF; /* SVGA3D_INVALID_ID = no DX context */
ret = ioctl(vmw_fd, IOCTL_EXECBUF, &exec);
if (ret < 0) printf("[-] execbuf bind: %s\n", strerror(errno));
else printf("[+] BIND_GB_SURFACE OK\n");
}
/* 5. Cross-device PRIME import */
memset(&ph2, 0, sizeof(ph2));
ph2.fd = prime_fd;
ret = ioctl(vgem_fd, DRM_IOCTL_PRIME_FD_TO_HANDLE, &ph2);
if (ret < 0) {
printf("[-] PRIME import failed: errno=%d\n", errno);
close(prime_fd); close(vmw_fd); close(vgem_fd);
return 1;
}
printf("[+] PRIME imported handle=%u\n", ph2.handle);
/* 6. Close import -> kfree(sgt) */
memset(&cl, 0, sizeof(cl));
cl.handle = ph2.handle;
ioctl(vgem_fd, DRM_IOCTL_GEM_CLOSE, &cl);
close(prime_fd);
printf("[+] DONE. Check: sudo dmesg | grep KASAN\n");
close(vmw_fd); close(vgem_fd);
return 0;
}
---8<--- vmw_prime_sgtable.c (IGT testcase) ---8<---
// SPDX-License-Identifier: GPL-2.0 OR MIT
/*
* Test: vmw_prime_sgtable
*
* Validates that vmwgfx correctly handles embedded sg_table lifetime
* during cross-device PRIME import/close sequences. On unfixed kernels,
* closing the imported GEM handle triggers kfree() on the embedded
* (non-heap-allocated) sg_table inside struct vmw_ttm_tt, producing a
* KASAN invalid-free splat.
*/
#include "igt_kms.h"
#include "igt_vmwgfx.h"
#include <fcntl.h>
#include <string.h>
#include <sys/ioctl.h>
IGT_TEST_DESCRIPTION("Test sg_table lifetime in vmwgfx PRIME export/import paths.");
/*
* Full ioctl number for DRM_VMW_EXECBUF — vmwgfx_drm.h provides the
* command offset but not the composed ioctl macro.
*/
#define IOCTL_VMW_EXECBUF \
DRM_IOW(DRM_COMMAND_BASE + DRM_VMW_EXECBUF, struct drm_vmw_execbuf_arg)
static void test_sgtable_invalid_free(int vmw_fd, int import_fd)
{
struct vmw_mob *mob;
struct vmw_surface *surf;
int prime_fd, ret;
void *map;
const uint32_t bo_size = 64 * 64 * 4;
SVGA3dSize surf_size = { .width = 64, .height = 64, .depth = 1 };
/* 1. Create and populate a MOB */
mob = vmw_ioctl_mob_create(vmw_fd, bo_size);
igt_require(mob);
igt_require(mob->handle != 0);
map = vmw_ioctl_mob_map(vmw_fd, mob);
igt_require(map);
memset(map, 0x41, bo_size);
vmw_ioctl_mob_unmap(mob);
/* 2. PRIME export the MOB handle */
prime_fd = prime_handle_to_fd(vmw_fd, mob->handle);
igt_assert(prime_fd >= 0);
/* 3. Create a GB surface backed by this MOB */
surf = vmw_ioctl_create_surface_full(vmw_fd,
SVGA3D_SURFACE_HINT_RENDERTARGET, /* flags */
SVGA3D_BUFFER, /* format */
0, /* multisample_count */
SVGA3D_MS_PATTERN_NONE,
SVGA3D_MS_QUALITY_NONE,
SVGA3D_TEX_FILTER_NEAREST, /* autogen_filter */
1, /* num_mip_levels */
1, /* array_size */
surf_size,
mob->handle, /* buffer_handle (backup) */
drm_vmw_surface_flag_shareable);
/* Surface creation + bind trigger DMA mapping of the BO. */
if (surf) {
/* 4. Bind surface to MOB via raw EXECBUF */
struct {
SVGA3dCmdHeader hdr;
SVGA3dCmdBindGBSurface body;
} cmd;
struct drm_vmw_execbuf_arg exec;
cmd.hdr.id = SVGA_3D_CMD_BIND_GB_SURFACE;
cmd.hdr.size = sizeof(cmd.body);
cmd.body.sid = surf->base.handle;
cmd.body.mobid = mob->handle;
memset(&exec, 0, sizeof(exec));
exec.commands = (uint64_t)(uintptr_t)&cmd;
exec.command_size = sizeof(cmd);
exec.version = DRM_VMW_EXECBUF_VERSION;
exec.context_handle = 0xFFFFFFFF;
ret = ioctl(vmw_fd, IOCTL_VMW_EXECBUF, &exec);
if (ret < 0)
igt_debug("execbuf bind: %s (non-fatal)\n",
strerror(errno));
else
igt_debug("BIND_GB_SURFACE OK (sid=%u, mobid=%u)\n",
surf->base.handle, mob->handle);
}
/*
* 5. Cross-device PRIME import using raw ioctl.
*
* Do NOT use prime_fd_to_handle() — it returns ENOSYS on
* some vmwgfx setups. Raw DRM_IOCTL_PRIME_FD_TO_HANDLE works.
*/
{
struct drm_prime_handle import_args;
struct drm_gem_close close_args;
memset(&import_args, 0, sizeof(import_args));
import_args.fd = prime_fd;
ret = ioctl(import_fd, DRM_IOCTL_PRIME_FD_TO_HANDLE,
&import_args);
igt_assert_eq(ret, 0);
igt_assert(import_args.handle != 0);
igt_debug("PRIME imported handle=%u\n", import_args.handle);
/*
* 6. Close the imported handle.
*
* On unfixed kernels this triggers kfree() on the
* embedded sg_table that was never separately allocated,
* causing KASAN invalid-free. On fixed kernels this
* completes cleanly.
*/
memset(&close_args, 0, sizeof(close_args));
close_args.handle = import_args.handle;
ret = ioctl(import_fd, DRM_IOCTL_GEM_CLOSE, &close_args);
igt_assert_eq(ret, 0);
}
/* 7. Cleanup */
close(prime_fd);
if (surf)
vmw_ioctl_surface_unref(vmw_fd, surf);
vmw_ioctl_mob_close_handle(vmw_fd, mob);
}
int igt_main()
{
int vmw_fd = -1;
int import_fd = -1;
igt_fixture() {
vmw_fd = open("/dev/dri/renderD128", O_RDWR);
igt_require(vmw_fd >= 0);
/*
* Need a second DRM device for cross-device PRIME import.
* Try renderD129 (typically VGEM or another GPU node).
*/
import_fd = open("/dev/dri/renderD129", O_RDWR);
if (import_fd < 0)
import_fd = open("/dev/dri/card1", O_RDWR);
igt_require_f(import_fd >= 0,
"Need a second DRM device for PRIME import\n");
}
igt_describe("Validates sg_table lifetime during PRIME"
" export/import/close. On unfixed kernels, closing the"
" imported handle triggers an invalid kfree of the"
" embedded sg_table.");
igt_subtest("sgtable-invalid-free") {
test_sgtable_invalid_free(vmw_fd, import_fd);
}
igt_fixture() {
if (import_fd >= 0)
close(import_fd);
if (vmw_fd >= 0)
close(vmw_fd);
}
}
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - UNFIXED vmwgfx]
2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-07 4:43 ` Aldo Ariel Panzardo
@ 2026-10-07 4:46 ` Aldo Ariel Panzardo
2026-10-07 4:47 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - FIXED vmwgfx] Aldo Ariel Panzardo
2 siblings, 0 replies; 8+ messages in thread
From: Aldo Ariel Panzardo @ 2026-10-07 4:46 UTC (permalink / raw)
To: maaz.mombasawala, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
=== IGT FULL LOG - UNFIXED vmwgfx (kernel 7.3.0-rc4+) ===
=== Kernel commit: 6edd14dd67d76d39a518ad3bf1a98363690a5a62 ===
===== vmw_execution_buffer =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: mob-create-map
Subtest mob-create-map: SUCCESS (0.000s)
Starting subtest: buffer-create
Subtest buffer-create: SUCCESS (0.000s)
Starting subtest: execution-buffer-submit-sync
Subtest execution-buffer-submit-sync: SUCCESS (0.043s)
===== vmw_mob_stress =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: max_mob_mem_stress
[1800.110260] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.110277] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.110281] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1800.110282] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_mob_stress.c:44 __igt_unique____real_main48()
#3 ../tests/vmwgfx/vmw_mob_stress.c:48 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest max_mob_mem_stress failed.
**** DEBUG ****
[1800.102037] (vmw_mob_stress:507) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.102095] (vmw_mob_stress:507) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.103017] (vmw_mob_stress:507) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.110260] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.110277] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.110281] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1800.110282] (vmw_mob_stress:507) igt_vmwgfx-CRITICAL: error: 128 != 127
[1800.110679] (vmw_mob_stress:507) igt_core-INFO: Stack trace:
[1800.112293] (vmw_mob_stress:507) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.112541] (vmw_mob_stress:507) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1800.112658] (vmw_mob_stress:507) igt_core-INFO: #2 ../tests/vmwgfx/vmw_mob_stress.c:44 __igt_unique____real_main48()
[1800.112666] (vmw_mob_stress:507) igt_core-INFO: #3 ../tests/vmwgfx/vmw_mob_stress.c:48 main()
[1800.114232] (vmw_mob_stress:507) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1800.114588] (vmw_mob_stress:507) igt_core-INFO: #5 [__libc_start_main+0x85]
[1800.114710] (vmw_mob_stress:507) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest max_mob_mem_stress: FAIL (0.013s)
===== vmw_ref_count =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: surface_prime_transfer_explicit_mob
Subtest surface_prime_transfer_explicit_mob: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_implicit_mob
Subtest surface_prime_transfer_implicit_mob: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_fd_dup
Subtest surface_prime_transfer_fd_dup: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_two_surfaces
Subtest surface_prime_transfer_two_surfaces: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_single_surface_multiple_handle
Subtest surface_prime_transfer_single_surface_multiple_handle: SUCCESS (0.000s)
Starting subtest: mob_repeated_unref
Subtest mob_repeated_unref: SUCCESS (0.000s)
Starting subtest: surface_repeated_unref
Subtest surface_repeated_unref: SUCCESS (0.000s)
Starting subtest: surface_alloc_ref_unref
Subtest surface_alloc_ref_unref: SUCCESS (0.000s)
Starting subtest: surface_buffer_ref
Subtest surface_buffer_ref: SUCCESS (0.001s)
Starting subtest: surface_prime_refs
Subtest surface_prime_refs: SUCCESS (0.001s)
Starting subtest: surface_buffer_prime_refs
Subtest surface_buffer_prime_refs: SUCCESS (0.002s)
===== vmw_surface_copy =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: test_invalid_copies
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
Subtest test_invalid_copies: SUCCESS (0.044s)
Starting subtest: test_invalid_copies_3d
Subtest test_invalid_copies_3d: SUCCESS (0.002s)
===== vmw_tri =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: tri
[1800.277574] (vmw_tri:518) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.277594] (vmw_tri:518) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.277600] (vmw_tri:518) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1800.277602] (vmw_tri:518) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_tri.c:51 __igt_unique____real_main183()
#3 ../tests/vmwgfx/vmw_tri.c:183 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest tri failed.
**** DEBUG ****
[1800.267736] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1800.267853] (vmw_tri:518) DEBUG: Test requirement passed: cid != SVGA3D_INVALID_ID
[1800.267866] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.268076] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.268947] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.277574] (vmw_tri:518) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.277594] (vmw_tri:518) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.277600] (vmw_tri:518) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1800.277602] (vmw_tri:518) igt_vmwgfx-CRITICAL: error: 128 != 127
[1800.278185] (vmw_tri:518) igt_core-INFO: Stack trace:
[1800.279302] (vmw_tri:518) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.280572] (vmw_tri:518) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1800.280931] (vmw_tri:518) igt_core-INFO: #2 ../tests/vmwgfx/vmw_tri.c:51 __igt_unique____real_main183()
[1800.280954] (vmw_tri:518) igt_core-INFO: #3 ../tests/vmwgfx/vmw_tri.c:183 main()
[1800.282657] (vmw_tri:518) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1800.283135] (vmw_tri:518) igt_core-INFO: #5 [__libc_start_main+0x85]
[1800.283402] (vmw_tri:518) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest tri: FAIL (0.016s)
Starting subtest: tri-no-sync-coherent
[1800.289286] (vmw_tri:518) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.289302] (vmw_tri:518) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.289305] (vmw_tri:518) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_tri.c:172 __igt_unique____real_main183()
#3 ../tests/vmwgfx/vmw_tri.c:183 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest tri-no-sync-coherent failed.
**** DEBUG ****
[1800.284354] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1800.284451] (vmw_tri:518) DEBUG: Test requirement passed: cid != SVGA3D_INVALID_ID
[1800.284455] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.284564] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.285413] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.285515] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.285813] (vmw_tri:518) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.289286] (vmw_tri:518) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1800.289302] (vmw_tri:518) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1800.289305] (vmw_tri:518) igt_vmwgfx-CRITICAL: error: 128 != 127
[1800.289723] (vmw_tri:518) igt_core-INFO: Stack trace:
[1800.290521] (vmw_tri:518) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.290812] (vmw_tri:518) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1800.291011] (vmw_tri:518) igt_core-INFO: #2 ../tests/vmwgfx/vmw_tri.c:172 __igt_unique____real_main183()
[1800.291034] (vmw_tri:518) igt_core-INFO: #3 ../tests/vmwgfx/vmw_tri.c:183 main()
[1800.291750] (vmw_tri:518) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1800.292262] (vmw_tri:518) igt_core-INFO: #5 [__libc_start_main+0x85]
[1800.292468] (vmw_tri:518) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest tri-no-sync-coherent: FAIL (0.008s)
Starting subtest: tri-2d
Subtest tri-2d: SUCCESS (0.003s)
===== vmw_prime =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339031 for randomisation
Opened device: /dev/dri/card0
Opened device: /dev/dri/renderD128
Starting subtest: tri-map-gem
vmw_ioctl_surface_ref Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_mob_map: Map failed.
[1800.369142] (vmw_prime:522) CRITICAL: Test assertion failure function draw_triangle_map_gem, file ../tests/vmwgfx/vmw_prime.c:123:
[1800.369155] (vmw_prime:522) CRITICAL: Failed assertion: save_status
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:500 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest tri-map-gem failed.
**** DEBUG ****
[1800.332062] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.332112] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.368843] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.368884] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.368936] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.369032] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.369142] (vmw_prime:522) CRITICAL: Test assertion failure function draw_triangle_map_gem, file ../tests/vmwgfx/vmw_prime.c:123:
[1800.369155] (vmw_prime:522) CRITICAL: Failed assertion: save_status
[1800.369553] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.370663] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.370823] (vmw_prime:522) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:500 __igt_unique____real_main508()
[1800.370850] (vmw_prime:522) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.372483] (vmw_prime:522) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1800.372843] (vmw_prime:522) igt_core-INFO: #4 [__libc_start_main+0x85]
[1800.372951] (vmw_prime:522) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest tri-map-gem: FAIL (0.041s)
Starting subtest: tri-map-dmabuf
vmw_ioctl_surface_ref Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_mob_map: Map failed.
[1800.411443] (vmw_prime:522) CRITICAL: Test assertion failure function draw_triangle_map_dmabuf, file ../tests/vmwgfx/vmw_prime.c:160:
[1800.411445] (vmw_prime:522) CRITICAL: Failed assertion: save_status
[1800.411446] (vmw_prime:522) CRITICAL: Last errno: 22, Invalid argument
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:520 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest tri-map-dmabuf failed.
**** DEBUG ****
[1800.373580] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.373616] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.411278] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.411306] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1800.411353] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.411397] (vmw_prime:522) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1800.411443] (vmw_prime:522) CRITICAL: Test assertion failure function draw_triangle_map_dmabuf, file ../tests/vmwgfx/vmw_prime.c:160:
[1800.411445] (vmw_prime:522) CRITICAL: Failed assertion: save_status
[1800.411446] (vmw_prime:522) CRITICAL: Last errno: 22, Invalid argument
[1800.411830] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.412547] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.412779] (vmw_prime:522) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:520 __igt_unique____real_main508()
[1800.412861] (vmw_prime:522) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.413482] (vmw_prime:522) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1800.413798] (vmw_prime:522) igt_core-INFO: #4 [__libc_start_main+0x85]
[1800.413953] (vmw_prime:522) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest tri-map-dmabuf: FAIL (0.041s)
Starting subtest: draw-dumb-buffer
vmw_ioctl_surface_ref Failed
[1800.448784] (vmw_prime:522) CRITICAL: Test assertion failure function prepare_crtc_surface, file ../tests/vmwgfx/vmw_prime.c:250:
[1800.448787] (vmw_prime:522) CRITICAL: Failed assertion: (__kms_addfb(gpu->fb.fd, gpu->fb_surface->base.handle, gpu->fb.width, gpu->fb.height, gpu->fb.drm_format, gpu->fb.modifier, gpu->fb.strides, gpu->fb.offsets, gpu->fb.num_planes, 0, &gpu->fb.fb_id)) == 0
[1800.448789] (vmw_prime:522) CRITICAL: Last errno: 22, Invalid argument
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:242 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest draw-dumb-buffer failed.
**** DEBUG ****
[1800.414404] (vmw_prime:522) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1800.414451] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1800.414506] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1800.414524] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1800.414611] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=2, pitch=5120)
[1800.414615] (vmw_prime:522) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1800.414661] (vmw_prime:522) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1800.448784] (vmw_prime:522) CRITICAL: Test assertion failure function prepare_crtc_surface, file ../tests/vmwgfx/vmw_prime.c:250:
[1800.448787] (vmw_prime:522) CRITICAL: Failed assertion: (__kms_addfb(gpu->fb.fd, gpu->fb_surface->base.handle, gpu->fb.width, gpu->fb.height, gpu->fb.drm_format, gpu->fb.modifier, gpu->fb.strides, gpu->fb.offsets, gpu->fb.num_planes, 0, &gpu->fb.fb_id)) == 0
[1800.448789] (vmw_prime:522) CRITICAL: Last errno: 22, Invalid argument
[1800.449070] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.449652] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.449777] (vmw_prime:522) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:242 __igt_unique____real_main508()
[1800.449784] (vmw_prime:522) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.450320] (vmw_prime:522) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1800.450639] (vmw_prime:522) igt_core-INFO: #4 [__libc_start_main+0x85]
[1800.450758] (vmw_prime:522) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest draw-dumb-buffer: FAIL (0.037s)
Starting subtest: buffer-surface-fb-sharing-sync-readback
[1800.455256] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.455270] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.455272] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.455273] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:545 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing-sync-readback failed.
**** DEBUG ****
[1800.451402] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1800.451462] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1800.451475] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1800.451619] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=3, pitch=5120)
[1800.451622] (vmw_prime:522) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1800.451645] (vmw_prime:522) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1800.454258] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454259] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454261] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_fb(113)
[1800.454263] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1800.454264] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1800.454265] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1800.454268] (vmw_prime:522) igt_kms-DEBUG: display: commit {
[1800.454305] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454306] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454306] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 113, src (0, 0), mode 1280x800
[1800.454546] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454548] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454548] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe A, disabling
[1800.454579] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe A, (0, 0)
[1800.454622] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454623] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454623] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe B, disabling
[1800.454653] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454653] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454654] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe B, disabling
[1800.454671] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe B, (0, 0)
[1800.454704] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454705] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454705] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe C, disabling
[1800.454730] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454731] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454731] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe C, disabling
[1800.454747] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe C, (0, 0)
[1800.454779] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454780] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454780] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe D, disabling
[1800.454807] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454807] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454808] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe D, disabling
[1800.454825] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe D, (0, 0)
[1800.454857] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454858] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454858] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe E, disabling
[1800.454881] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454882] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454882] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe E, disabling
[1800.454898] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe E, (0, 0)
[1800.454930] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454931] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454931] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe F, disabling
[1800.454954] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.454954] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.454955] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe F, disabling
[1800.454970] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe F, (0, 0)
[1800.455004] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.455004] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.455005] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe G, disabling
[1800.455026] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.455027] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.455027] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe G, disabling
[1800.455042] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe G, (0, 0)
[1800.455074] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.455074] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.455075] (vmw_prime:522) igt_kms-DEBUG: display: SetCrtc pipe H, disabling
[1800.455099] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.455100] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.455100] (vmw_prime:522) igt_kms-DEBUG: display: SetCursor pipe H, disabling
[1800.455118] (vmw_prime:522) igt_kms-DEBUG: display: MoveCursor pipe H, (0, 0)
[1800.455134] (vmw_prime:522) igt_kms-DEBUG: display: }
[1800.455256] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.455270] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.455272] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.455273] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
[1800.455557] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.456377] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.456490] (vmw_prime:522) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1800.456556] (vmw_prime:522) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1800.456738] (vmw_prime:522) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1800.456757] (vmw_prime:522) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:545 __igt_unique____real_main508()
[1800.456762] (vmw_prime:522) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.457374] (vmw_prime:522) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1800.457744] (vmw_prime:522) igt_core-INFO: #7 [__libc_start_main+0x85]
[1800.457884] (vmw_prime:522) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing-sync-readback: FAIL (0.007s)
Starting subtest: buffer-surface-fb-sharing-sync
[1800.461596] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.461608] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.461611] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.461612] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:552 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing-sync failed.
**** DEBUG ****
[1800.458295] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1800.458353] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1800.458365] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1800.458474] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=4, pitch=5120)
[1800.458477] (vmw_prime:522) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1800.458509] (vmw_prime:522) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1800.461286] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461287] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461288] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_fb(114)
[1800.461289] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1800.461290] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1800.461291] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1800.461292] (vmw_prime:522) igt_kms-DEBUG: display: commit {
[1800.461292] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461293] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461294] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 114, src (0, 0), mode 1280x800
[1800.461498] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461499] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461500] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461501] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461502] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461502] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461503] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461503] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461505] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461505] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461506] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461506] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461507] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461507] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461508] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461508] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461509] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461509] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461510] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461510] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461511] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461512] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461512] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461513] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461513] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461514] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461514] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461515] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461515] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.461516] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.461516] (vmw_prime:522) igt_kms-DEBUG: display: }
[1800.461596] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.461608] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.461611] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.461612] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
[1800.461902] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.462479] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.462588] (vmw_prime:522) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1800.462652] (vmw_prime:522) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1800.462811] (vmw_prime:522) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1800.462827] (vmw_prime:522) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:552 __igt_unique____real_main508()
[1800.462833] (vmw_prime:522) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.463376] (vmw_prime:522) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1800.463875] (vmw_prime:522) igt_core-INFO: #7 [__libc_start_main+0x85]
[1800.464036] (vmw_prime:522) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing-sync: FAIL (0.006s)
Starting subtest: buffer-surface-fb-sharing
[1800.467715] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.467727] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.467729] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.467730] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:557 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing failed.
**** DEBUG ****
[1800.464501] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1800.464547] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1800.464558] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1800.464654] (vmw_prime:522) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=5, pitch=5120)
[1800.464657] (vmw_prime:522) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1800.464680] (vmw_prime:522) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1800.467412] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467414] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467414] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_fb(115)
[1800.467415] (vmw_prime:522) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1800.467416] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1800.467417] (vmw_prime:522) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1800.467418] (vmw_prime:522) igt_kms-DEBUG: display: commit {
[1800.467419] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467420] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467420] (vmw_prime:522) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 115, src (0, 0), mode 1280x800
[1800.467617] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467619] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467620] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467620] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467621] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467621] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467623] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467623] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467624] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467624] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467625] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467625] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467626] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467627] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467627] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467628] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467628] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467629] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467630] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467630] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467631] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467632] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467632] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467633] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467634] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467634] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467635] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467635] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467636] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1800.467636] (vmw_prime:522) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1800.467637] (vmw_prime:522) igt_kms-DEBUG: display: }
[1800.467715] (vmw_prime:522) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1800.467727] (vmw_prime:522) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1800.467729] (vmw_prime:522) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1800.467730] (vmw_prime:522) igt_pipe_crc-CRITICAL: error: -1 != 4
[1800.467980] (vmw_prime:522) igt_core-INFO: Stack trace:
[1800.468502] (vmw_prime:522) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1800.468585] (vmw_prime:522) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1800.468631] (vmw_prime:522) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1800.468749] (vmw_prime:522) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1800.468753] (vmw_prime:522) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:557 __igt_unique____real_main508()
[1800.468759] (vmw_prime:522) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1800.469291] (vmw_prime:522) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1800.469635] (vmw_prime:522) igt_core-INFO: #7 [__libc_start_main+0x85]
[1800.469772] (vmw_prime:522) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing: FAIL (0.006s)
Opened device: /dev/dri/card1
Starting subtest: basic-vgem
Subtest basic-vgem: SUCCESS (0.001s)
=== New IGT subtest (vmw_prime_sgtable) with dmesg ===
Rebooting with UNFIXED...
alive
VM up
=== IGT TESTCASE: UNFIXED vmwgfx ===
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791343583 for randomisation
Starting subtest: sgtable-invalid-free
Subtest sgtable-invalid-free: SUCCESS (0.001s)
=== FULL DMESG AFTER TEST ===
[ 6355.323263] Console: switching to colour dummy device 80x25
[ 6355.323331] [IGT] vmw_prime_sgtable: executing
[ 6355.327240] [IGT] vmw_prime_sgtable: starting subtest sgtable-invalid-free
[ 6355.328534] [IGT] vmw_prime_sgtable: finished subtest sgtable-invalid-free, SUCCESS
[ 6355.329152] [IGT] vmw_prime_sgtable: exiting, ret=0
[ 6355.329600] Console: switching to colour frame buffer device 160x50
[ 6355.331267] Oops: general protection fault, probably for non-canonical address 0xdffffc0000000003: 0000 [#4] SMP KASAN NOPTI
[ 6355.332337] KASAN: null-ptr-deref in range [0x0000000000000018-0x000000000000001f]
[ 6355.333074] CPU: 1 UID: 0 PID: 812 Comm: kworker/u23:1 Tainted: G B D W OE 7.3.0-rc4+ #17 PREEMPT(lazy)
[ 6355.334054] Tainted: [B]=BAD_PAGE, [D]=DIE, [W]=WARN, [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
[ 6355.334824] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 02/17/2026
[ 6355.335839] Workqueue: ttm ttm_bo_delayed_delete [ttm]
[ 6355.336350] RIP: 0010:dma_direct_unmap_sg+0xb9/0x870
[ 6355.336838] Code: 85 ca 04 00 00 48 8b 43 20 48 89 c3 48 83 e3 fc a8 01 48 0f 44 dd 45 39 ef 0f 84 48 02 00 00 48 8d 7b 1c 48 89 f8 48 c1 e8 03 <42> 0f b6 14 20 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85
[ 6355.338548] RSP: 0018:ffff8881060d7b38 EFLAGS: 00010207
[ 6355.339053] RAX: 0000000000000003 RBX: 0000000000000000 RCX: ffffed102071c469
[ 6355.339733] RDX: 1ffff1102071c469 RSI: ffff8881038e2348 RDI: 000000000000001c
[ 6355.340415] RBP: ffff88810c9f436c R08: 0000000000000000 R09: ffffed102071c47b
[ 6355.341096] R10: ffff8881038e20d0 R11: 00000000cc4dc460 R12: dffffc0000000000
[ 6355.341780] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000001
[ 6355.342455] FS: 0000000000000000(0000) GS:ffff88826ac8a000(0000) knlGS:0000000000000000
[ 6355.343212] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 6355.343737] CR2: 00005583d8efb1c8 CR3: 0000000120cdb006 CR4: 0000000000770ef0
[ 6355.344396] PKRU: 55555554
[ 6355.344663] Call Trace:
[ 6355.344904] <TASK>
[ 6355.345118] ? kasan_save_track+0x10/0x30
[ 6355.345504] ? dma_unmap_sg_attrs+0x73/0x2c0
[ 6355.345905] vmw_ttm_unmap_dma+0x164/0x290 [vmwgfx]
[ 6355.346373] vmw_ttm_unpopulate+0xcd/0x120 [vmwgfx]
[ 6355.347169] ttm_tt_unpopulate+0xa0/0x2a0 [ttm]
[ 6355.347943] ? _raw_spin_lock_irqsave+0x92/0xf0
[ 6355.348699] ttm_bo_cleanup_memtype_use+0xe5/0x1e0 [ttm]
[ 6355.349519] ttm_bo_delayed_delete+0x68/0xf0 [ttm]
[ 6355.350305] process_one_work+0x738/0x11a0
[ 6355.351017] ? move_linked_works+0x12c/0x2a0
[ 6355.351761] ? __pfx_process_one_work+0x10/0x10
[ 6355.352517] ? _raw_spin_lock_irq+0x87/0xf0
[ 6355.353218] ? __pfx_ttm_bo_delayed_delete+0x10/0x10 [ttm]
[ 6355.354051] ? assign_work+0x122/0x3e0
[ 6355.354732] worker_thread+0x53a/0xf50
[ 6355.355432] ? __pfx_worker_thread+0x10/0x10
[ 6355.356153] kthread+0x325/0x420
[ 6355.356788] ? recalc_sigpending+0x15d/0x1e0
[ 6355.357517] ? __pfx_kthread+0x10/0x10
[ 6355.358185] ret_from_fork+0x3de/0x770
[ 6355.358855] ? __pfx_ret_from_fork+0x10/0x10
[ 6355.359580] ? __switch_to+0x3ad/0xd80
[ 6355.360238] ? __pfx_kthread+0x10/0x10
[ 6355.360894] ret_from_fork_asm+0x1a/0x30
[ 6355.361569] </TASK>
[ 6355.362087] Modules linked in: vmwgfx(OE) drm_client_lib(OE) drm_ttm_helper(OE) ttm(OE) vgem(OE) drm_shmem_helper(OE) drm_kms_helper(OE) e1000(E) [last unloaded: ttm(OE)]
[ 6355.364125] ---[ end trace 0000000000000000 ]---
[ 6355.368262] RIP: 0010:dma_direct_unmap_sg+0xb9/0x870
[ 6355.368662] Code: 85 ca 04 00 00 48 8b 43 20 48 89 c3 48 83 e3 fc a8 01 48 0f 44 dd 45 39 ef 0f 84 48 02 00 00 48 8d 7b 1c 48 89 f8 48 c1 e8 03 <42> 0f b6 14 20 48 89 f8 83 e0 07 83 c0 03 38 d0 7c 08 84 d2 0f 85
[ 6355.369377] RSP: 0018:ffff88810ac77b38 EFLAGS: 00010207
[ 6355.370112] RAX: 0000000000000003 RBX: 0000000000000000 RCX: ffffed102071c469
[ 6355.370452] RDX: 1ffff1102071c469 RSI: ffff8881038e2348 RDI: 000000000000001c
[ 6355.370757] RBP: ffff88810af3996c R08: 0000000000000000 R09: ffffed102071c47b
[ 6355.371124] R10: ffff8881038e20d0 R11: 00000000cc4dc460 R12: dffffc0000000000
[ 6355.371467] R13: 0000000000000000 R14: 0000000000000000 R15: 0000000000000001
[ 6355.371800] FS: 0000000000000000(0000) GS:ffff88826ad8a000(0000) knlGS:0000000000000000
[ 6355.372092] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 6355.372412] CR2: 00007f84493510a0 CR3: 0000000174c50006 CR4: 0000000000770ef0
[ 6355.372709] PKRU: 55555554
^ permalink raw reply [flat|nested] 8+ messages in thread
* Re: [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - FIXED vmwgfx]
2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-07 4:43 ` Aldo Ariel Panzardo
2026-10-07 4:46 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - UNFIXED vmwgfx] Aldo Ariel Panzardo
@ 2026-10-07 4:47 ` Aldo Ariel Panzardo
2 siblings, 0 replies; 8+ messages in thread
From: Aldo Ariel Panzardo @ 2026-10-07 4:47 UTC (permalink / raw)
To: maaz.mombasawala, zack.rusin
Cc: bcm-kernel-feedback-list, dri-devel, christian.koenig,
linux-kernel, stable
=== IGT FULL LOG - FIXED vmwgfx (kernel 7.3.0-rc4+) ===
=== Kernel commit: 6edd14dd67d76d39a518ad3bf1a98363690a5a62 ===
===== vmw_execution_buffer =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: mob-create-map
Subtest mob-create-map: SUCCESS (0.000s)
Starting subtest: buffer-create
Subtest buffer-create: SUCCESS (0.000s)
Starting subtest: execution-buffer-submit-sync
Subtest execution-buffer-submit-sync: SUCCESS (0.032s)
===== vmw_mob_stress =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: max_mob_mem_stress
[1812.758600] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.758617] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.758621] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1812.758623] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_mob_stress.c:44 __igt_unique____real_main48()
#3 ../tests/vmwgfx/vmw_mob_stress.c:48 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest max_mob_mem_stress failed.
**** DEBUG ****
[1812.754433] (vmw_mob_stress:579) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.754493] (vmw_mob_stress:579) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.755365] (vmw_mob_stress:579) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.758600] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.758617] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.758621] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1812.758623] (vmw_mob_stress:579) igt_vmwgfx-CRITICAL: error: 128 != 127
[1812.759007] (vmw_mob_stress:579) igt_core-INFO: Stack trace:
[1812.760091] (vmw_mob_stress:579) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1812.760277] (vmw_mob_stress:579) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1812.760409] (vmw_mob_stress:579) igt_core-INFO: #2 ../tests/vmwgfx/vmw_mob_stress.c:44 __igt_unique____real_main48()
[1812.760416] (vmw_mob_stress:579) igt_core-INFO: #3 ../tests/vmwgfx/vmw_mob_stress.c:48 main()
[1812.761941] (vmw_mob_stress:579) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1812.762251] (vmw_mob_stress:579) igt_core-INFO: #5 [__libc_start_main+0x85]
[1812.762389] (vmw_mob_stress:579) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest max_mob_mem_stress: FAIL (0.008s)
===== vmw_ref_count =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: surface_prime_transfer_explicit_mob
Subtest surface_prime_transfer_explicit_mob: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_implicit_mob
Subtest surface_prime_transfer_implicit_mob: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_fd_dup
Subtest surface_prime_transfer_fd_dup: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_two_surfaces
Subtest surface_prime_transfer_two_surfaces: SUCCESS (0.000s)
Starting subtest: surface_prime_transfer_single_surface_multiple_handle
Subtest surface_prime_transfer_single_surface_multiple_handle: SUCCESS (0.000s)
Starting subtest: mob_repeated_unref
Subtest mob_repeated_unref: SUCCESS (0.000s)
Starting subtest: surface_repeated_unref
Subtest surface_repeated_unref: SUCCESS (0.000s)
Starting subtest: surface_alloc_ref_unref
Subtest surface_alloc_ref_unref: SUCCESS (0.000s)
Starting subtest: surface_buffer_ref
Subtest surface_buffer_ref: SUCCESS (0.001s)
Starting subtest: surface_prime_refs
Subtest surface_prime_refs: SUCCESS (0.001s)
Starting subtest: surface_buffer_prime_refs
Subtest surface_buffer_prime_refs: SUCCESS (0.001s)
===== vmw_surface_copy =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: test_invalid_copies
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
Subtest test_invalid_copies: SUCCESS (0.049s)
Starting subtest: test_invalid_copies_3d
Subtest test_invalid_copies_3d: SUCCESS (0.001s)
===== vmw_tri =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/renderD128
Starting subtest: tri
[1812.916602] (vmw_tri:588) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.916625] (vmw_tri:588) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.916629] (vmw_tri:588) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1812.916631] (vmw_tri:588) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_tri.c:51 __igt_unique____real_main183()
#3 ../tests/vmwgfx/vmw_tri.c:183 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest tri failed.
**** DEBUG ****
[1812.907494] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1812.907562] (vmw_tri:588) DEBUG: Test requirement passed: cid != SVGA3D_INVALID_ID
[1812.907571] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.907669] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.908847] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.916602] (vmw_tri:588) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.916625] (vmw_tri:588) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.916629] (vmw_tri:588) igt_vmwgfx-CRITICAL: Last errno: 2, No such file or directory
[1812.916631] (vmw_tri:588) igt_vmwgfx-CRITICAL: error: 128 != 127
[1812.917125] (vmw_tri:588) igt_core-INFO: Stack trace:
[1812.918079] (vmw_tri:588) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1812.918265] (vmw_tri:588) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1812.918410] (vmw_tri:588) igt_core-INFO: #2 ../tests/vmwgfx/vmw_tri.c:51 __igt_unique____real_main183()
[1812.918442] (vmw_tri:588) igt_core-INFO: #3 ../tests/vmwgfx/vmw_tri.c:183 main()
[1812.919944] (vmw_tri:588) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1812.920259] (vmw_tri:588) igt_core-INFO: #5 [__libc_start_main+0x85]
[1812.920399] (vmw_tri:588) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest tri: FAIL (0.013s)
Starting subtest: tri-no-sync-coherent
[1812.925114] (vmw_tri:588) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.925129] (vmw_tri:588) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.925132] (vmw_tri:588) igt_vmwgfx-CRITICAL: error: 128 != 127
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
#2 ../tests/vmwgfx/vmw_tri.c:172 __igt_unique____real_main183()
#3 ../tests/vmwgfx/vmw_tri.c:183 main()
#4 [__libc_init_first+0x8a]
#5 [__libc_start_main+0x85]
#6 [_start+0x21]
Subtest tri-no-sync-coherent failed.
**** DEBUG ****
[1812.920885] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1812.920936] (vmw_tri:588) DEBUG: Test requirement passed: cid != SVGA3D_INVALID_ID
[1812.920937] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.920991] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.921887] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.921947] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.922284] (vmw_tri:588) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.925114] (vmw_tri:588) igt_vmwgfx-CRITICAL: Test assertion failure function vmw_triangle_assert_values, file ../lib/igt_vmwgfx.c:1309:
[1812.925129] (vmw_tri:588) igt_vmwgfx-CRITICAL: Failed assertion: out_pixel[0] == 127
[1812.925132] (vmw_tri:588) igt_vmwgfx-CRITICAL: error: 128 != 127
[1812.925466] (vmw_tri:588) igt_core-INFO: Stack trace:
[1812.926399] (vmw_tri:588) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1812.926832] (vmw_tri:588) igt_core-INFO: #1 ../lib/igt_vmwgfx.c:1331 vmw_triangle_assert_values()
[1812.926938] (vmw_tri:588) igt_core-INFO: #2 ../tests/vmwgfx/vmw_tri.c:172 __igt_unique____real_main183()
[1812.926964] (vmw_tri:588) igt_core-INFO: #3 ../tests/vmwgfx/vmw_tri.c:183 main()
[1812.927527] (vmw_tri:588) igt_core-INFO: #4 [__libc_init_first+0x8a]
[1812.929069] (vmw_tri:588) igt_core-INFO: #5 [__libc_start_main+0x85]
[1812.929202] (vmw_tri:588) igt_core-INFO: #6 [_start+0x21]
**** END ****
Subtest tri-no-sync-coherent: FAIL (0.009s)
Starting subtest: tri-2d
Subtest tri-2d: SUCCESS (0.005s)
===== vmw_prime =====
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791339044 for randomisation
Opened device: /dev/dri/card0
Opened device: /dev/dri/renderD128
Starting subtest: tri-map-gem
vmw_ioctl_surface_ref Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_mob_map: Map failed.
[1813.009742] (vmw_prime:593) CRITICAL: Test assertion failure function draw_triangle_map_gem, file ../tests/vmwgfx/vmw_prime.c:123:
[1813.009744] (vmw_prime:593) CRITICAL: Failed assertion: save_status
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:500 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest tri-map-gem failed.
**** DEBUG ****
[1812.968183] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1812.968228] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1813.009532] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.009576] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1813.009612] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.009659] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.009742] (vmw_prime:593) CRITICAL: Test assertion failure function draw_triangle_map_gem, file ../tests/vmwgfx/vmw_prime.c:123:
[1813.009744] (vmw_prime:593) CRITICAL: Failed assertion: save_status
[1813.010076] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.011065] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.011213] (vmw_prime:593) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:500 __igt_unique____real_main508()
[1813.011231] (vmw_prime:593) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.012855] (vmw_prime:593) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1813.013162] (vmw_prime:593) igt_core-INFO: #4 [__libc_start_main+0x85]
[1813.013308] (vmw_prime:593) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest tri-map-gem: FAIL (0.046s)
Starting subtest: tri-map-dmabuf
vmw_ioctl_surface_ref Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_command error Invalid argument.
vmw_ioctl_fence_finish Failed
vmw_ioctl_mob_map: Map failed.
[1813.052296] (vmw_prime:593) CRITICAL: Test assertion failure function draw_triangle_map_dmabuf, file ../tests/vmwgfx/vmw_prime.c:160:
[1813.052298] (vmw_prime:593) CRITICAL: Failed assertion: save_status
[1813.052300] (vmw_prime:593) CRITICAL: Last errno: 22, Invalid argument
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:520 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest tri-map-dmabuf failed.
**** DEBUG ****
[1813.014001] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1813.014040] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1813.052087] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.052111] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(fd)
[1813.052200] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.052245] (vmw_prime:593) igt_vmwgfx-INFO: vmw_ioctl_command error Invalid argument.
[1813.052296] (vmw_prime:593) CRITICAL: Test assertion failure function draw_triangle_map_dmabuf, file ../tests/vmwgfx/vmw_prime.c:160:
[1813.052298] (vmw_prime:593) CRITICAL: Failed assertion: save_status
[1813.052300] (vmw_prime:593) CRITICAL: Last errno: 22, Invalid argument
[1813.052581] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.053203] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.053343] (vmw_prime:593) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:520 __igt_unique____real_main508()
[1813.053361] (vmw_prime:593) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.053911] (vmw_prime:593) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1813.054225] (vmw_prime:593) igt_core-INFO: #4 [__libc_start_main+0x85]
[1813.054351] (vmw_prime:593) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest tri-map-dmabuf: FAIL (0.041s)
Starting subtest: draw-dumb-buffer
vmw_ioctl_surface_ref Failed
[1813.093153] (vmw_prime:593) CRITICAL: Test assertion failure function prepare_crtc_surface, file ../tests/vmwgfx/vmw_prime.c:250:
[1813.093156] (vmw_prime:593) CRITICAL: Failed assertion: (__kms_addfb(gpu->fb.fd, gpu->fb_surface->base.handle, gpu->fb.width, gpu->fb.height, gpu->fb.drm_format, gpu->fb.modifier, gpu->fb.strides, gpu->fb.offsets, gpu->fb.num_planes, 0, &gpu->fb.fb_id)) == 0
[1813.093158] (vmw_prime:593) CRITICAL: Last errno: 22, Invalid argument
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../tests/vmwgfx/vmw_prime.c:242 __igt_unique____real_main508()
#2 ../tests/vmwgfx/vmw_prime.c:508 main()
#3 [__libc_init_first+0x8a]
#4 [__libc_start_main+0x85]
#5 [_start+0x21]
Subtest draw-dumb-buffer failed.
**** DEBUG ****
[1813.054730] (vmw_prime:593) igt_vmwgfx-DEBUG: Test requirement passed: vmw_supports_3d(drm_fd)
[1813.054777] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1813.054837] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1813.054850] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1813.054914] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=2, pitch=5120)
[1813.054917] (vmw_prime:593) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1813.054959] (vmw_prime:593) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1813.093153] (vmw_prime:593) CRITICAL: Test assertion failure function prepare_crtc_surface, file ../tests/vmwgfx/vmw_prime.c:250:
[1813.093156] (vmw_prime:593) CRITICAL: Failed assertion: (__kms_addfb(gpu->fb.fd, gpu->fb_surface->base.handle, gpu->fb.width, gpu->fb.height, gpu->fb.drm_format, gpu->fb.modifier, gpu->fb.strides, gpu->fb.offsets, gpu->fb.num_planes, 0, &gpu->fb.fb_id)) == 0
[1813.093158] (vmw_prime:593) CRITICAL: Last errno: 22, Invalid argument
[1813.093417] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.094067] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.094204] (vmw_prime:593) igt_core-INFO: #1 ../tests/vmwgfx/vmw_prime.c:242 __igt_unique____real_main508()
[1813.094222] (vmw_prime:593) igt_core-INFO: #2 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.094804] (vmw_prime:593) igt_core-INFO: #3 [__libc_init_first+0x8a]
[1813.095127] (vmw_prime:593) igt_core-INFO: #4 [__libc_start_main+0x85]
[1813.095286] (vmw_prime:593) igt_core-INFO: #5 [_start+0x21]
**** END ****
Subtest draw-dumb-buffer: FAIL (0.041s)
Starting subtest: buffer-surface-fb-sharing-sync-readback
[1813.100669] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.100685] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.100687] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.100689] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:545 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing-sync-readback failed.
**** DEBUG ****
[1813.096322] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1813.096375] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1813.096389] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1813.096550] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=3, pitch=5120)
[1813.096553] (vmw_prime:593) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1813.096576] (vmw_prime:593) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1813.099306] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099307] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099309] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_fb(113)
[1813.099311] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1813.099312] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1813.099313] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1813.099316] (vmw_prime:593) igt_kms-DEBUG: display: commit {
[1813.099351] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099352] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099354] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 113, src (0, 0), mode 1280x800
[1813.099665] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099668] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099669] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe A, disabling
[1813.099712] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe A, (0, 0)
[1813.099762] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099763] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099765] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe B, disabling
[1813.099796] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099797] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099797] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe B, disabling
[1813.099814] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe B, (0, 0)
[1813.099848] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099849] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099850] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe C, disabling
[1813.099875] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099876] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099876] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe C, disabling
[1813.099896] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe C, (0, 0)
[1813.099929] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099929] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099930] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe D, disabling
[1813.099954] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.099955] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.099955] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe D, disabling
[1813.100141] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe D, (0, 0)
[1813.100175] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100175] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100176] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe E, disabling
[1813.100199] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100200] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100201] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe E, disabling
[1813.100216] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe E, (0, 0)
[1813.100252] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100252] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100253] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe F, disabling
[1813.100277] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100278] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100278] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe F, disabling
[1813.100299] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe F, (0, 0)
[1813.100333] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100334] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100335] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe G, disabling
[1813.100359] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100360] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100360] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe G, disabling
[1813.100376] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe G, (0, 0)
[1813.100409] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100409] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100410] (vmw_prime:593) igt_kms-DEBUG: display: SetCrtc pipe H, disabling
[1813.100457] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.100458] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.100459] (vmw_prime:593) igt_kms-DEBUG: display: SetCursor pipe H, disabling
[1813.100478] (vmw_prime:593) igt_kms-DEBUG: display: MoveCursor pipe H, (0, 0)
[1813.100497] (vmw_prime:593) igt_kms-DEBUG: display: }
[1813.100669] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.100685] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.100687] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.100689] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
[1813.100982] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.101587] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.101705] (vmw_prime:593) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1813.101768] (vmw_prime:593) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1813.101901] (vmw_prime:593) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1813.101917] (vmw_prime:593) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:545 __igt_unique____real_main508()
[1813.101921] (vmw_prime:593) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.102482] (vmw_prime:593) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1813.102807] (vmw_prime:593) igt_core-INFO: #7 [__libc_start_main+0x85]
[1813.102930] (vmw_prime:593) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing-sync-readback: FAIL (0.007s)
Starting subtest: buffer-surface-fb-sharing-sync
[1813.106531] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.106544] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.106547] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.106549] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:552 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing-sync failed.
**** DEBUG ****
[1813.103307] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1813.103351] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1813.103361] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1813.103455] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=4, pitch=5120)
[1813.103457] (vmw_prime:593) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1813.103481] (vmw_prime:593) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1813.106221] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106222] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106223] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_fb(114)
[1813.106224] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1813.106224] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1813.106225] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1813.106227] (vmw_prime:593) igt_kms-DEBUG: display: commit {
[1813.106228] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106228] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106229] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 114, src (0, 0), mode 1280x800
[1813.106399] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106400] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106401] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106401] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106402] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106403] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106404] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106404] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106405] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106405] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106406] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106406] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106407] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106407] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106408] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106409] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106409] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106410] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106411] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106412] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106413] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106413] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106414] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106414] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106415] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106415] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106416] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106416] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106418] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.106418] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.106419] (vmw_prime:593) igt_kms-DEBUG: display: }
[1813.106531] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.106544] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.106547] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.106549] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
[1813.106808] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.107348] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.107488] (vmw_prime:593) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1813.107546] (vmw_prime:593) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1813.107896] (vmw_prime:593) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1813.107933] (vmw_prime:593) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:552 __igt_unique____real_main508()
[1813.107946] (vmw_prime:593) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.108807] (vmw_prime:593) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1813.109133] (vmw_prime:593) igt_core-INFO: #7 [__libc_start_main+0x85]
[1813.109257] (vmw_prime:593) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing-sync: FAIL (0.006s)
Starting subtest: buffer-surface-fb-sharing
[1813.117148] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.117160] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.117163] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.117164] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
Stack trace:
#0 ../lib/igt_core.c:2146 __igt_fail_assert()
#1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
#2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
#3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
#4 ../tests/vmwgfx/vmw_prime.c:557 __igt_unique____real_main508()
#5 ../tests/vmwgfx/vmw_prime.c:508 main()
#6 [__libc_init_first+0x8a]
#7 [__libc_start_main+0x85]
#8 [_start+0x21]
Subtest buffer-surface-fb-sharing failed.
**** DEBUG ****
[1813.109649] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: set_crtc(A)
[1813.109692] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: Selecting CRTC A
[1813.109702] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(width=1280, height=800, format=XR24(0x34325258), modifier=0x0, size=0)
[1813.109822] (vmw_prime:593) igt_fb-DEBUG: igt_create_fb_with_bo_size(handle=5, pitch=5120)
[1813.109824] (vmw_prime:593) ioctl_wrappers-DEBUG: Test requirement passed: igt_has_fb_modifiers(fd)
[1813.109846] (vmw_prime:593) igt_fb-DEBUG: Test requirement passed: cairo_surface_status(fb->cairo_surface) == CAIRO_STATUS_SUCCESS
[1813.116870] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.116872] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.116872] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_fb(115)
[1813.116873] (vmw_prime:593) igt_kms-DEBUG: display: A.0: plane_set_size (1280x800)
[1813.116875] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_position(0,0)
[1813.116875] (vmw_prime:593) igt_kms-DEBUG: display: A.0: fb_set_size(1280x800)
[1813.116876] (vmw_prime:593) igt_kms-DEBUG: display: commit {
[1813.116877] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.116878] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.116878] (vmw_prime:593) igt_kms-DEBUG: display: Virtual-1: SetCrtc pipe A, fb 115, src (0, 0), mode 1280x800
[1813.117048] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117049] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117050] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117051] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117051] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117052] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117053] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117053] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117054] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117055] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117055] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117056] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117057] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117057] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117058] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117058] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117059] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117059] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117060] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117060] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117062] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117062] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117063] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117063] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117063] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117064] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117065] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117065] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117066] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: plane_idx >= 0 && plane_idx < crtc->n_planes
[1813.117066] (vmw_prime:593) igt_kms-DEBUG: Test requirement passed: crtc->planes[plane_idx].type == plane_type
[1813.117067] (vmw_prime:593) igt_kms-DEBUG: display: }
[1813.117148] (vmw_prime:593) igt_pipe_crc-CRITICAL: Test assertion failure function igt_pipe_crc_start, file ../lib/igt_pipe_crc.c:416:
[1813.117160] (vmw_prime:593) igt_pipe_crc-CRITICAL: Failed assertion: write(pipe_crc->ctl_fd, src, strlen(src)) == strlen(src)
[1813.117163] (vmw_prime:593) igt_pipe_crc-CRITICAL: Last errno: 22, Invalid argument
[1813.117164] (vmw_prime:593) igt_pipe_crc-CRITICAL: error: -1 != 4
[1813.117417] (vmw_prime:593) igt_core-INFO: Stack trace:
[1813.117947] (vmw_prime:593) igt_core-INFO: #0 ../lib/igt_core.c:2146 __igt_fail_assert()
[1813.118041] (vmw_prime:593) igt_core-INFO: #1 ../lib/igt_pipe_crc.c:422 igt_pipe_crc_start()
[1813.118085] (vmw_prime:593) igt_core-INFO: #2 ../lib/igt_pipe_crc.c:627 igt_pipe_crc_collect_crc()
[1813.118199] (vmw_prime:593) igt_core-INFO: #3 ../tests/vmwgfx/vmw_prime.c:307 draw_triangle_3d()
[1813.118203] (vmw_prime:593) igt_core-INFO: #4 ../tests/vmwgfx/vmw_prime.c:557 __igt_unique____real_main508()
[1813.118209] (vmw_prime:593) igt_core-INFO: #5 ../tests/vmwgfx/vmw_prime.c:508 main()
[1813.118737] (vmw_prime:593) igt_core-INFO: #6 [__libc_init_first+0x8a]
[1813.119016] (vmw_prime:593) igt_core-INFO: #7 [__libc_start_main+0x85]
[1813.119146] (vmw_prime:593) igt_core-INFO: #8 [_start+0x21]
**** END ****
Subtest buffer-surface-fb-sharing: FAIL (0.010s)
Opened device: /dev/dri/card1
Starting subtest: basic-vgem
Subtest basic-vgem: SUCCESS (0.001s)
=== New IGT subtest (vmw_prime_sgtable) with dmesg ===
IGT-Version: 2.6-NO-GIT (x86_64) (Linux: 7.3.0-rc4+ x86_64)
Using IGT_SRANDOM=1791345857 for randomisation
Starting subtest: sgtable-invalid-free
Subtest sgtable-invalid-free: SUCCESS (0.001s)
=== DMESG AFTER FIXED TEST (cleared before) ===
[ 34.274292] Console: switching to colour dummy device 80x25
[ 34.274341] [IGT] vmw_prime_sgtable: executing
[ 34.284281] [IGT] vmw_prime_sgtable: starting subtest sgtable-invalid-free
[ 34.284814] ------------[ cut here ]------------
[ 34.284821] Command buffer error.
[ 34.284824] WARNING: vmwgfx_cmdbuf.c:403 at vmw_cmdbuf_ctx_process+0x1bb/0x7a0 [vmwgfx], CPU#0: irq/16-vmwgfx/328
[ 34.284884] [IGT] vmw_prime_sgtable: finished subtest sgtable-invalid-free, SUCCESS
[ 34.288247] Modules linked in: vgem(OE) drm_shmem_helper(OE) vmwgfx(OE) drm_client_lib(OE) drm_ttm_helper(OE) ttm(OE) drm_kms_helper(OE) e1000(E)
[ 34.289491] CPU: 0 UID: 0 PID: 328 Comm: irq/16-vmwgfx Tainted: G OE 7.3.0-rc4+ #17 PREEMPT(lazy)
[ 34.290495] Tainted: [O]=OOT_MODULE, [E]=UNSIGNED_MODULE
[ 34.291008] Hardware name: VMware, Inc. VMware Virtual Platform/440BX Desktop Reference Platform, BIOS 6.00 02/17/2026
[ 34.292043] RIP: 0010:vmw_cmdbuf_ctx_process+0x1bb/0x7a0 [vmwgfx]
[ 34.292663] Code: 30 01 83 fd 04 0f 84 56 03 00 00 0f 87 3d 02 00 00 83 fd 01 0f 84 27 02 00 00 83 fd 03 0f 85 12 02 00 00 48 8d 3d 55 65 e3 ff <67> 48 0f b9 3a 4c 89 f0 48 c1 e8 03 80 3c 18 00 0f 85 91 04 00 00
[ 34.294411] RSP: 0018:ffff8881025efbd8 EFLAGS: 00010246
[ 34.294894] RAX: ffff888119b73870 RBX: dffffc0000000000 RCX: 0000000000000000
[ 34.295562] RDX: 1ffff1102336e748 RSI: 0000000000000246 RDI: ffffffffc0150a60
[ 34.296246] RBP: 0000000000000003 R08: 0000000000000000 R09: ffffed10204bdf69
[ 34.296891] R10: 0000000000000003 R11: ffff8881f7243858 R12: ffff8881077cfe00
[ 34.297548] R13: ffff8881077cfc00 R14: ffff8881077cfe08 R15: ffff8881077cfe18
[ 34.298198] FS: 0000000000000000(0000) GS:ffff888253a0a000(0000) knlGS:0000000000000000
[ 34.298923] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 34.299475] CR2: 00005570bddc1690 CR3: 0000000105e8c006 CR4: 0000000000770ef0
[ 34.300174] PKRU: 55555554
[ 34.300454] Call Trace:
[ 34.300699] <TASK>
[ 34.300915] vmw_cmdbuf_man_process+0xe1/0x2b0 [vmwgfx]
[ 34.301417] ? __pfx_vmw_cmdbuf_man_process+0x10/0x10 [vmwgfx]
[ 34.301970] ? _raw_spin_lock+0x81/0xe0
[ 34.302340] ? __pfx__raw_spin_lock+0x10/0x10
[ 34.302750] ? __pfx___schedule+0x10/0x10
[ 34.303126] vmw_cmdbuf_irqthread+0x21/0x30 [vmwgfx]
[ 34.303628] vmw_thread_fn+0xcb/0xf0 [vmwgfx]
[ 34.304075] ? __pfx_vmw_thread_fn+0x10/0x10 [vmwgfx]
[ 34.304565] irq_thread_fn+0x87/0x150
[ 34.304916] irq_thread+0x394/0x600
[ 34.305262] ? __pfx_irq_thread_fn+0x10/0x10
[ 34.305673] ? __pfx_irq_thread+0x10/0x10
[ 34.306057] ? __pfx_irq_thread_dtor+0x10/0x10
[ 34.306484] ? __kthread_parkme+0x8d/0x170
[ 34.306868] ? __pfx_irq_thread+0x10/0x10
[ 34.307248] ? __pfx_irq_thread+0x10/0x10
[ 34.307658] kthread+0x325/0x420
[ 34.307980] ? recalc_sigpending+0x15d/0x1e0
[ 34.308399] ? __pfx_kthread+0x10/0x10
[ 34.308753] ret_from_fork+0x3de/0x770
[ 34.309110] ? __pfx_ret_from_fork+0x10/0x10
[ 34.309530] ? __switch_to+0x3ad/0xd80
[ 34.309894] ? __pfx_kthread+0x10/0x10
[ 34.310264] ret_from_fork_asm+0x1a/0x30
[ 34.310653] </TASK>
[ 34.310876] ---[ end trace 0000000000000000 ]---
[ 34.311666] [IGT] vmw_prime_sgtable: exiting, ret=0
[ 34.312097] Console: switching to colour frame buffer device 160x50
=== END ===
^ permalink raw reply [flat|nested] 8+ messages in thread
end of thread, other threads:[~2026-10-07 4:47 UTC | newest]
Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23 12:26 [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core Aldo Ariel Panzardo
2026-09-23 14:37 ` Zack Rusin
[not found] ` <CAP48HfviFZXacVY9Lj4Hv7+brObhmxWLYAM8MNiTUkJNchnp1Q@mail.gmail.com>
2026-10-03 0:34 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-03 16:38 ` Aldo Ariel Panzardo
2026-10-05 20:16 ` Maaz Mombasawala <maaz.mombasawala@broadcom.com>
2026-10-07 4:43 ` Aldo Ariel Panzardo
2026-10-07 4:46 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - UNFIXED vmwgfx] Aldo Ariel Panzardo
2026-10-07 4:47 ` [PATCH] drm/vmwgfx: do not hand the embedded sg_table to the PRIME core [IGT full log - FIXED vmwgfx] Aldo Ariel Panzardo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®