From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f178.google.com (mail-pl1-f178.google.com [209.85.214.178]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CC2C633A6EB for ; Sun, 9 Aug 2026 08:52:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.178 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786265530; cv=none; b=CZoqnGdvyCGFS/4fAlVpDbt31zyYRdnRRpex5TL4pFQfsvcgvfB0bjha3M/a4l3vnyEnuIkV0N4aQmyyIg5ksavEW3Gwz3v3YSQXpuvSFTVlqfZzs4ssxgEMPc2VkHuq9z6O/mOi1o+5AoFt1AR3cDeX/b8EftAJF2oo79Whdqw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786265530; c=relaxed/simple; bh=sxKZAH1YTVniJZgci/Dr6SqZEdTmzqVp+ZjlBNb7eqA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lDouFDwqQc/0gK0kknNBw9KOIs4SVK195YKPHMHsVy5csPzj3vNhafViOya8onUaeMjy98RvgKjhHuPUmQb/xQfvsIk9Ucg5tUTPH2hdP6/MNmm+RCIKJRZTGBgZfzln/d+8VCi0JA3SrR7ZRsGPnKUaHyP4M8q0EPvimah4+8k= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mdGwzeDB; arc=none smtp.client-ip=209.85.214.178 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mdGwzeDB" Received: by mail-pl1-f178.google.com with SMTP id d9443c01a7336-2cc73e322dbso8558775ad.1 for ; Sun, 09 Aug 2026 01:52:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786265526; x=1786870326; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=c/m4TAD904Gpx4jOO1f1keOOyQGwoQabIUB++Z17kjo=; b=mdGwzeDBg56gZrx/tLx2jO729tLS4CLg/rGLvLtgldOAbpVx7IfrxwL5qJyTiNIge2 010FHWCzQAJFT5+O5NHtMdyq4CB6mteK8gL2chScsVQ/Bz9wi69627sbRO3gL1Gu4eQu JkWGPl2NxQzY8Cd5jdwwHwJYVCka0qdVfckcTe/hz0ykR/qZz+HvRNLEryo/P4+HcOzp l+UuqpnGF2JhtwnsmX2enySR8VAeeABnoKNIfNedKoW7Z/PfDywy4Gk60whQtAvsmvfA 69km7V020B0oorqagR2YzZwxD+rFl0oF+7x223Cvq0uoCOtJ3QgE+xvVuL/IKOG89EnP W3zw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786265526; x=1786870326; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=c/m4TAD904Gpx4jOO1f1keOOyQGwoQabIUB++Z17kjo=; b=QBZmzP7ZIbYbwcyylVr3a0AyxuD+K7ONU0QIHOxGDXpLVdD4+rMxnHpItYy7Im3F2H xi0U7R/J7ZyxL3/ycy/bOSZuA1atMmOY827G7nrVvEkA/Q1kti7crpgHDC+QTq+/IJlj +U9QjWU1WI66ofF03OI1WrcN1LVyuLnBV4B2zC3DXzVNHztSyV8ph4ExV7WF+Dx/z7Nt Bb0mXnVC05aWO7v0rdPZDWtf++jzJH19RptspaCq4/+tEd3gl2JRXSbUCVss8GN9yZUJ Vy4JT0EaFFpnwgvFlZFXRYuUhxaCRZdfIJgdZpJV4NwE553B4ldpxkVmNT671Aodou7H B0NA== X-Forwarded-Encrypted: i=1; AHgh+RoaQiHiSG5FpW8KMB7KVMHn9WtPgb53oUEQs6pQCmcIgPABk3CwId+GGciFkgtn+z9bkOedpZC36WWHgzE=@vger.kernel.org X-Gm-Message-State: AOJu0YzNsWGatWwBESAKjfKAQThzZHwVH7NbJ0sQvoXH80NlGduHixdt iXDDUQZjN6fCnnpq0XKBT+TfCaUEI5fx7qvrIjS0DI20Pt3J4QqTgr0D X-Gm-Gg: AR+sD11EMzvEnQ+MXy3sx0GL5UoDVWAj3EgAhOBhSq+v6UU2Eoh+ZfDl6e9BHbgdlwP egwmQl/CQKZoz0b0h++PHpIJ1STryXL5bAdGCitCwA2f8glwV08ro+dZsEI6KchgnK0oy7LSoB3 4sh6q29BrxO5w0Y/lo/pdL7g3gUks5P1l9oaEJIM0fbMhBM5LNBPxxwzjZKEo/fxZzi+CoJJ3j0 xTDzk1uLQJCcrtJtFAjzhyHIV00BkMaVa65IdZ8nyYrtIrnPeRlDIL3JHvSi5DCj4EayuKrjGzl MLMW3IMc6Pup5Z5EC3UvHr8mJnI38rY2R80WyU3wgvbjsaYsk7ND1DZlx0JksFDCpxXJEvqznZT BUAu9UKsD5YB/apTU5PKfM6U3uWFVC3YYwFxQWZFT3UapAVlttqRRZCntkTSYzXX+vDddtfOlMg 9svohXveS7OH6YH1i5zWMWcHQFoxVK3/7Z5yCejEmYRq0IOizlGMleVjs6w6IbpmYsoc0mDbJod 8fV4GgJb6w= X-Received: by 2002:a05:6a20:a111:b0:3bf:7eb5:9459 with SMTP id adf61e73a8af0-3cb85ef9202mr36500133637.20.1786265525696; Sun, 09 Aug 2026 01:52:05 -0700 (PDT) Received: from localhost.localdomain ([103.178.205.91]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be86fc7bsm28800025eec.1.2026.08.09.01.52.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 01:52:05 -0700 (PDT) From: Sreeraj S Kurup To: alexander.deucher@amd.com, christian.koenig@amd.com Cc: amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, airlied@gmail.com, simona@ffwll.ch, Sreeraj S Kurup Subject: [PATCH v4 6/6] drm/amdgpu/ras: Fix delayed work cancellation order during teardown Date: Sun, 9 Aug 2026 08:47:35 +0000 Message-ID: <20260809084735.9743-7-sreekuttan2156239@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260809084735.9743-1-sreekuttan2156239@gmail.com> References: <20260809084735.9743-1-sreekuttan2156239@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit In amdgpu_ras_fini(), cancel_delayed_work_sync() is currently called after ACA subsystems and locks are destroyed. Similarly, in amdgpu_ras_recovery_fini(), mutex_destroy(&con->page_rsv_lock) is called before cancel_delayed_work_sync(&con->page_retirement_dwork). If delayed work runs while teardown is in progress, it can attempt to acquire destroyed mutexes, leading to locking violations and potential use-after-free conditions. Fix this by moving cancel_delayed_work_sync() and cancel_work_sync() prior to mutex destruction and subsystem teardown in both functions, ensuring all pending work is synchronously canceled while locks remain intact. Signed-off-by: Sreeraj S Kurup --- drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c index 764cd4950408..23b9844d9f1c 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_ras.c @@ -3994,15 +3994,14 @@ static int amdgpu_ras_recovery_fini(struct amdgpu_device *adev) if (con->page_retirement_thread) kthread_stop(con->page_retirement_thread); + cancel_work_sync(&con->recovery_work); + cancel_delayed_work_sync(&con->page_retirement_dwork); + atomic_set(&con->page_retirement_req_cnt, 0); atomic_set(&con->poison_creation_count, 0); mutex_destroy(&con->page_rsv_lock); - cancel_work_sync(&con->recovery_work); - - cancel_delayed_work_sync(&con->page_retirement_dwork); - amdgpu_ras_ecc_log_fini(&con->umc_ecc_log); mutex_lock(&con->recovery_lock); @@ -4751,6 +4750,8 @@ int amdgpu_ras_fini(struct amdgpu_device *adev) if (!adev->ras_enabled || !con) return 0; + cancel_delayed_work_sync(&con->ras_counte_delay_work); + amdgpu_ras_critical_region_fini(adev); mutex_destroy(&con->critical_region_lock); @@ -4785,8 +4786,6 @@ int amdgpu_ras_fini(struct amdgpu_device *adev) if (AMDGPU_RAS_GET_FEATURES(con->features)) amdgpu_ras_disable_all_features(adev, 0); - cancel_delayed_work_sync(&con->ras_counte_delay_work); - amdgpu_ras_set_context(adev, NULL); kfree(con); -- 2.54.0