Skip to content

openrknn: document vendor multi-core submit from decompile - #92

Merged
widgetii merged 1 commit into
masterfrom
openrknn/multicore-investigation
Apr 13, 2026
Merged

widgetii merged 1 commit into
masterfrom
openrknn/multicore-investigation

Conversation

@widgetii

Copy link
Copy Markdown
Owner

Summary

Documents findings from decompiling the vendor's submit path in librknnrt.so:

  • Vendor fills rknpu_submit with core_mask from ctx+2428, subcore_task[] all zeroed
  • rknn_set_core_mask (sub_E1260) just stores the mask value — no kernel ioctl
  • Vendor submits task_number = N*3 with core_mask=0 (AUTO) for 3-core execution
  • CRITICAL: core_mask=0 with tripled tasks causes kernel panic without vendor's context setup

Disabled the vendor-3core submit path to prevent panics.

Key decompile references

Function Address Role
sub_3075F0 0x3075F0 Submit dispatcher — fills rknpu_submit struct
sub_2E9948 0x2E9948 ioctl wrapper — calls 0xC0686441
sub_E1260 0x0E1260 rknn_set_core_mask — stores mask at ctx+2428
0x40086414 — Allocate context handle (likely needed for core_mask=0)

Next step

Reproduce the vendor's kernel init sequence:

  1. Call ioctl 0x40086414 to allocate a context handle
  2. Call ioctl 0x40106410 to configure NPU cores
  3. Then submit with core_mask=0 and tripled task count

🤖 Generated with Claude Code

From decompiling librknnrt.so's submit path and ioctl tracing:
- Vendor sends 10 ACTION ioctls during init (POWER_ON, GET_IOMMU_EN, etc.)
- Vendor submit: core_mask=0 (AUTO), subcore_task all zeroed, task_number=N*3
- Kernel auto-distributes tasks across all 3 NPU cores
- core_mask=0 with tripled tasks crashes kernel without vendor's context setup
- Single-core tasks only cover ~512/1024 spatial positions (by design)
- Tripled tasks on single core: kernel rejects (task_start+count exceeds BO)

The 50% spatial coverage is a fundamental architectural feature: the RKNN
compiler generates single-core tasks for half the spatial dimension, with
multi-core replicas for the other half. Full coverage requires kernel-level
multi-core dispatch that openrknn's OWN mode doesn't implement yet.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@widgetii
widgetii force-pushed the openrknn/multicore-investigation branch from 021f948 to b43ee21 Compare April 13, 2026 10:22
@widgetii
widgetii merged commit 2972cff into master Apr 13, 2026
7 checks passed
@widgetii
widgetii deleted the openrknn/multicore-investigation branch April 13, 2026 10:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant