All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Danilo Krummrich" <dakr@kernel.org>,
	"Alexandre Courbot" <acourbot@nvidia.com>,
	"John Hubbard" <jhubbard@nvidia.com>
Cc: "Will Pierce" <wpierce@nvidia.com>,
	"Alex Gaynor" <alex.gaynor@gmail.com>,
	"Bjorn Helgaas" <bhelgaas@google.com>,
	"Boqun Feng" <boqun.feng@gmail.com>, "Zhi Wang" <zhiw@nvidia.com>,
	"Alexandre Courbot" <acourbot@nvidia.com>,
	"Simona Vetter" <simona@ffwll.ch>, "Gary Guo" <gary@garyguo.net>,
	"Joel Fernandes" <joelagnelf@nvidia.com>,
	"Timur Tabi" <ttabi@nvidia.com>,
	"Andreas Hindborg" <a.hindborg@kernel.org>,
	"Danilo Krummrich" <dakr@kernel.org>,
	"Alice Ryhl" <aliceryhl@google.com>,
	"Trevor Gross" <tmgross@umich.edu>,
	"David Airlie" <airlied@gmail.com>,
	LKML <linux-kernel@vger.kernel.org>,
	"Miguel Ojeda" <ojeda@kernel.org>,
	"Alistair Popple" <apopple@nvidia.com>,
	nova-gpu@lists.linux.dev,
	"Björn Roy Baron" <bjorn3_gh@protonmail.com>,
	"Benno Lossin" <lossin@kernel.org>,
	"Eliot Courtney" <ecourtney@nvidia.com>
Subject: Re: [PATCH v3 07/14] gpu: nova-core: add an interrupt delivery self-test
Date: Thu, 03 Sep 2026 03:29:41 +0000	[thread overview]
Message-ID: <20260903032942.2DA621F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260903031514.1515905-8-jhubbard@nvidia.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] The `vectors_ref` field introduces a self-referential struct using a reference derived from a short-lived macro-local `&mut` binding. `try_pin_init!` provides access to previously initialized fields via local variable bindings, which expire at the end of the initialization closure. Taking a reference from this local variable and artificially extending its lifetime to `'gpu` via `unsafe { &*... }` violates strict aliasing rules (Stacked Borrows / Tree Borrows). When the closure returns, the local variable goes out of scope, its provenance tag is popped, and `vectors_ref` becomes a dangling pointer under the Rust memory model. Furthermore, the `pin-init` crate explicitly documents: "IMPORTANT: You are not allowed to create references to fields of the struct inside of the initializer."
--

commit 9bb2c0e6b8faa56d9fead3fb4f99c60340b45be0
Author: John Hubbard <jhubbard@nvidia.com>

gpu: nova-core: add an interrupt delivery self-test

Add an optional probe-time self-test that injects the CPU doorbell
through the GIN software trigger. It confirms the interrupt reaches
the driver's handler to validate the PCI interrupt path without GSP firmware.

> diff --git a/drivers/gpu/nova-core/gpu.rs b/drivers/gpu/nova-core/gpu.rs
> index e1ac8ee9ba4db..8a9bc4baf9ac0 100644
> --- a/drivers/gpu/nova-core/gpu.rs
> +++ b/drivers/gpu/nova-core/gpu.rs

[ ... ]

> @@ -330,6 +337,12 @@ pub(crate) fn new<'a>(
>          let dev = pdev.as_ref();
>  
>          try_pin_init!(Self {
> +            vectors: crate::irq::alloc_vectors(pdev, crate::irq::SERVICED_SUBTREE.into())?,
> +
> +            // SAFETY: `vectors` is initialized above, lives at a pinned stable address, and is
> +            // dropped after every field that uses `vectors_ref` (struct field drop order).
> +            vectors_ref: unsafe { &*core::ptr::from_ref(vectors.as_ref().get_ref()) },

[Severity: High]
Does this create a dangling pointer under the Rust memory model?

`try_pin_init!` provides access to previously initialized fields via local
variable bindings, which expire at the end of the initialization closure.
Taking a reference from this local variable and artificially extending its
lifetime to `'gpu` via `unsafe { &*... }` violates strict aliasing rules
(Stacked Borrows / Tree Borrows).

When the closure returns, the local variable goes out of scope, its
provenance tag is popped, and `vectors_ref` becomes a dangling pointer.
The `pin-init` crate also explicitly documents that creating references to
fields of the struct inside the initializer is not allowed.

> +
>              spec: Spec::new(dev, bar).inspect(|spec| {
>                  dev_info!(dev,"NVIDIA ({})\n", spec);
>              })?,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260903031514.1515905-1-jhubbard@nvidia.com?part=7

  reply	other threads:[~2026-09-03  3:29 UTC|newest]

Thread overview: 35+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  3:14 [PATCH v3 00/14] nova-core: GPU interrupt support and GSP event delivery John Hubbard
2026-09-03  3:15 ` [PATCH v3 01/14] rust: pci: declare IrqType and IrqTypes with impl_flags John Hubbard
2026-09-03  3:15 ` [PATCH v3 02/14] rust: sync: completion: add wait_for_completion_timeout() John Hubbard
2026-09-03  3:15 ` [PATCH v3 03/14] gpu: nova-core: add the GIN vector and subtree newtypes John Hubbard
2026-09-05  1:39   ` Alexandre Courbot
2026-09-03  3:15 ` [PATCH v3 04/14] gpu: nova-core: add the GIN CPU interrupt tree and MSI EOI registers John Hubbard
2026-09-03  3:15 ` [PATCH v3 05/14] gpu: nova-core: add the per-architecture GIN CPU interrupt HAL John Hubbard
2026-09-05  6:11   ` Alexandre Courbot
2026-09-03  3:15 ` [PATCH v3 06/14] gpu: nova-core: add the GIN interrupt tree and allocate its vectors John Hubbard
2026-09-05 13:55   ` Alexandre Courbot
2026-09-06 23:10     ` John Hubbard
2026-09-07  0:24       ` Alexandre Courbot
2026-09-03  3:15 ` [PATCH v3 07/14] gpu: nova-core: add an interrupt delivery self-test John Hubbard
2026-09-03  3:29   ` sashiko-bot [this message]
2026-09-03  3:57     ` John Hubbard
2026-09-07  5:26   ` Alexandre Courbot
2026-09-03  3:15 ` [PATCH v3 08/14] gpu: nova-core: log GSP events instead of discarding them John Hubbard
2026-09-03  3:15 ` [PATCH v3 09/14] gpu: nova-core: recover the GSP receive path from corrupt framing John Hubbard
2026-09-04 10:53   ` Alexandre Courbot
2026-09-04 11:17     ` Gary Guo
2026-09-04 13:45       ` Alexandre Courbot
2026-09-03  3:15 ` [PATCH v3 10/14] gpu: nova-core: bound a GSP wait by a single deadline John Hubbard
2026-09-04 11:13   ` Alexandre Courbot
2026-09-04 11:26     ` Gary Guo
2026-09-04 13:32       ` Alexandre Courbot
2026-09-04 13:41         ` Gary Guo
2026-09-03  3:15 ` [PATCH v3 11/14] gpu: nova-core: add the falcon interrupt status and routing registers John Hubbard
2026-09-03  3:15 ` [PATCH v3 12/14] gpu: nova-core: drive GSP events with the SWGEN0 interrupt John Hubbard
2026-09-03  3:28   ` sashiko-bot
2026-09-03  3:55     ` John Hubbard
2026-09-04  1:53       ` John Hubbard
2026-09-07  6:59   ` Alexandre Courbot
2026-09-07 18:17     ` John Hubbard
2026-09-03  3:15 ` [PATCH v3 13/14] gpu: nova-core: add KUnit tests for the interrupt tree and HALs John Hubbard
2026-09-03  3:15 ` [PATCH v3 14/14] gpu: nova-core: document the GIN interrupt controller and GSP events John Hubbard

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260903032942.2DA621F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=a.hindborg@kernel.org \
    --cc=acourbot@nvidia.com \
    --cc=airlied@gmail.com \
    --cc=alex.gaynor@gmail.com \
    --cc=aliceryhl@google.com \
    --cc=apopple@nvidia.com \
    --cc=bhelgaas@google.com \
    --cc=bjorn3_gh@protonmail.com \
    --cc=boqun.feng@gmail.com \
    --cc=dakr@kernel.org \
    --cc=ecourtney@nvidia.com \
    --cc=gary@garyguo.net \
    --cc=jhubbard@nvidia.com \
    --cc=joelagnelf@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=lossin@kernel.org \
    --cc=nova-gpu@lists.linux.dev \
    --cc=ojeda@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    --cc=simona@ffwll.ch \
    --cc=tmgross@umich.edu \
    --cc=ttabi@nvidia.com \
    --cc=wpierce@nvidia.com \
    --cc=zhiw@nvidia.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.