From: sashiko-bot@kernel.org
To: "Boris Brezillon" <boris.brezillon@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 8/9] drm/panthor: Don't defer FW event processing
Date: Tue, 25 Aug 2026 08:21:36 +0000 [thread overview]
Message-ID: <20260825082136.B9FA81F00A3E@smtp.kernel.org> (raw)
In-Reply-To: <20260825-panthor-signal-from-irq-v7-8-ebb5b4c891a4@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Possible Use-After-Free of firmware structures when group_process_tiler_oom() runs concurrently with or after panthor_fw_unplug(). This problem wasn't introduced by this patch, but remains unresolved as replacing fw_events_work with direct threaded IRQ processing still leaves tiler_oom_work queued to an unflushed workqueue.
--
--- Patch [8]: [PATCH v7 8/9] drm/panthor: Don't defer FW event processing ---
commit 99ae40464e2d4753b77cca3059716afd0d1bd396
Author: Boris Brezillon <boris.brezillon@collabora.com>
drm/panthor: Don't defer FW event processing
This commit avoids a workqueue roundtrip by processing firmware events
immediately from panthor_sched_report_fw_events() rather than deferring
them to the fw_events_work workqueue.
> diff --git a/drivers/gpu/drm/panthor/panthor_sched.c b/drivers/gpu/drm/panthor/panthor_sched.c
> index 64b5fc1a0984f..7f99745ff4041 100644
> --- a/drivers/gpu/drm/panthor/panthor_sched.c
> +++ b/drivers/gpu/drm/panthor/panthor_sched.c
[ ... ]
> @@ -4083,7 +4055,6 @@ void panthor_sched_unplug(struct panthor_device *ptdev)
> struct panthor_scheduler *sched = ptdev->scheduler;
>
> disable_delayed_work_sync(&sched->tick_work);
> - disable_work_sync(&sched->fw_events_work);
[Severity: High]
This is a pre-existing issue, but since we are modifying the workqueue teardown
here in panthor_sched_unplug(), is it possible for a tiler_oom_work to execute
after panthor_fw_unplug() has already run?
In panthor_device_unplug(), the sequence calls panthor_sched_unplug() which
stops the scheduler tick and disables some works, but it doesn't appear to
flush sched->heap_alloc_wq where tiler_oom_work is queued.
If panthor_fw_unplug() subsequently destroys the firmware mappings, and a
pending tiler_oom_work executes group_process_tiler_oom():
drivers/gpu/drm/panthor/panthor_sched.c:group_process_tiler_oom()
cs_iface = panthor_fw_get_cs_iface(ptdev, csg_id, cs_id);
heaps = panthor_vm_get_heap_pool(group->vm, false);
heap_address = cs_iface->output->heap_address;
Could this dereference the unmapped cs_iface->output memory and cause a
use-after-free, since the async worker doesn't seem to check drm_dev_enter()?
> disable_work_sync(&sched->sync_upd_work);
>
> mutex_lock(&sched->lock);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260825-panthor-signal-from-irq-v7-0-ebb5b4c891a4@collabora.com?part=8
next prev parent reply other threads:[~2026-08-25 8:21 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 8:01 [PATCH v7 0/9] drm/panthor: Reduce dma_fence signalling latency Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 1/9] drm/panthor: Make panthor_irq::state a non-atomic field Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 2/9] drm/panthor: Move the register accessors before the IRQ helpers Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 3/9] drm/panthor: Replace the panthor_irq macro machinery by inline helpers Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 4/9] drm/panthor: Don't update might_have_idle_groups in process_idle_event_locked() Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 5/9] drm/panthor: Get rid of panthor_group::fatal_lock Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 6/9] drm/panthor: Protect events processing with a separate spinlock Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 7/9] drm/panthor: Don't defer job completion checks Boris Brezillon
2026-08-25 8:01 ` [PATCH v7 8/9] drm/panthor: Don't defer FW event processing Boris Brezillon
2026-08-25 8:21 ` sashiko-bot [this message]
2026-08-25 8:01 ` [PATCH v7 9/9] drm/panthor: Automate CSG IRQ processing at group unbind time Boris Brezillon
2026-08-27 7:19 ` [PATCH v7 0/9] drm/panthor: Reduce dma_fence signalling latency Boris Brezillon
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825082136.B9FA81F00A3E@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=boris.brezillon@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.