From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 11/17] drm/panfrost: Add debugfs knob for manually triggering a GPU reset
Date: Fri, 28 Aug 2026 21:12:25 +0000 [thread overview]
Message-ID: <20260828211225.E292F1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260828-claude-fixes-v7-11-72a13b2c125d@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
New issues:
- [Medium] Incorrect handling of pm_runtime_get_if_in_use() return value in reset_set() leading to usage count underflow.
Pre-existing issues:
- [High] Incorrect handling of pm_runtime_get_if_in_use() return value in panfrost_gpu_get_latest_flush_id() causing unsafe MMIO reads and PM underflow.
--
commit 6c0954bdc79e7702d546ce41292da37dbd1a90e1
Author: Adrián Larumbe <adrian.larumbe@collabora.com>
drm/panfrost: Add debugfs knob for manually triggering a GPU reset
This patch adds a debugfs file for manually triggering a GPU reset to aid
in testing potential races between the reset sequence and hardware register
access.
> diff --git a/drivers/gpu/drm/panfrost/panfrost_device.c b/drivers/gpu/drm/panfrost/panfrost_device.c
> index d8acae9b8cfac..b6a48ae0d3a61 100644
> --- a/drivers/gpu/drm/panfrost/panfrost_device.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_device.c
[ ... ]
> @@ -600,9 +601,43 @@ EXPORT_GPL_DEV_PM_OPS(panfrost_pm_ops) = {
> };
>
> #ifdef CONFIG_DEBUG_FS
[ ... ]
> +static int reset_set(void *data, u64 val)
> +{
> + struct panfrost_device *pfdev =
> + container_of(data, struct panfrost_device, base);
> +
> + if (pm_runtime_get_if_in_use(pfdev->base.dev)) {
[Severity: Medium]
When pm_runtime_get_if_in_use() is called while runtime PM is disabled
(such as during driver unbind or system suspend), it returns -EINVAL.
Since -EINVAL evaluates to true in this condition, does this cause the
block to execute without a successful get?
If so, could this regression lead to an unbalanced pm_runtime_put() call
at the end of the block and a PM usage counter underflow?
> + panfrost_device_schedule_reset(pfdev);
> + flush_work(&pfdev->reset.work);
> + pm_runtime_put(pfdev->base.dev);
> + }
> +
> + return 0;
> +}
[ ... ]
[Severity: High]
This isn't a bug introduced by this patch, but looking at a similar
pre-existing pattern in drivers/gpu/drm/panfrost/panfrost_gpu.c:
panfrost_gpu_get_latest_flush_id() {
if (panfrost_has_hw_feature(pfdev, HW_FEATURE_FLUSH_REDUCTION)) {
if (pm_runtime_get_if_in_use(pfdev->base.dev)) {
flush_id = gpu_read(pfdev, GPU_LATEST_FLUSH_ID);
pm_runtime_put(pfdev->base.dev);
return flush_id;
}
}
...
}
If pm_runtime_get_if_in_use() returns -EINVAL during system suspend or
teardown when disable_depth > 0, does this condition also evaluate to true?
Could this result in an unsafe MMIO read on potentially powered-off
hardware, followed by another unbalanced usage count decrement?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260828-claude-fixes-v7-0-72a13b2c125d@collabora.com?part=11
next prev parent reply other threads:[~2026-08-28 21:12 UTC|newest]
Thread overview: 58+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 20:56 [PATCH v7 00/17] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 01/17] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-09-01 11:28 ` Boris Brezillon
2026-09-02 15:36 ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 02/17] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-09-01 11:49 ` Boris Brezillon
2026-09-02 15:38 ` Adrián Larumbe
2026-09-02 15:50 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 03/17] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-08-28 21:14 ` sashiko-bot
2026-09-01 12:10 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 04/17] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-09-01 12:30 ` Boris Brezillon
2026-09-02 15:40 ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 05/17] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-09-01 12:31 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 06/17] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-09-01 12:38 ` Boris Brezillon
2026-09-02 15:41 ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 07/17] drm/panfrost: Stop all jobs before commencing device teardown Adrián Larumbe
2026-08-28 21:16 ` sashiko-bot
2026-09-01 12:58 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 08/17] drm/panfrost: Split subsystem init/reset from interrupt enablement Adrián Larumbe
2026-08-28 21:11 ` sashiko-bot
2026-09-01 13:08 ` Boris Brezillon
2026-09-02 15:41 ` Adrián Larumbe
2026-09-02 16:05 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 09/17] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-08-28 21:09 ` sashiko-bot
2026-09-01 13:18 ` Boris Brezillon
2026-09-02 15:42 ` Adrián Larumbe
2026-09-02 16:14 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 10/17] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-08-28 21:10 ` sashiko-bot
2026-09-01 13:20 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 11/17] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-08-28 21:12 ` sashiko-bot [this message]
2026-09-01 13:27 ` Boris Brezillon
2026-09-02 15:42 ` Adrián Larumbe
2026-09-02 16:23 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 12/17] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 13/17] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-09-01 13:32 ` Boris Brezillon
2026-09-02 15:43 ` Adrián Larumbe
2026-09-02 16:29 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 14/17] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-08-28 21:14 ` sashiko-bot
2026-09-01 13:37 ` Boris Brezillon
2026-09-02 15:44 ` Adrián Larumbe
2026-09-02 16:33 ` Boris Brezillon
2026-09-02 16:34 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 15/17] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 16/17] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-08-28 21:17 ` sashiko-bot
2026-09-01 14:03 ` Boris Brezillon
2026-09-02 15:45 ` Adrián Larumbe
2026-09-02 16:51 ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 17/17] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828211225.E292F1F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=adrian.larumbe@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.