All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v8 13/16] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems
Date: Mon, 07 Sep 2026 20:35:23 +0000	[thread overview]
Message-ID: <20260907203524.367401F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260907-claude-fixes-v8-13-c2bcb5e82184@collabora.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Use-After-Free in IRQ handler during device teardown due to shared interrupt firing after subsystem deinitialization.
--

commit 4af8baef18e17c6d5fb401654ac07ca6918a16ae
Author: Adrián Larumbe <adrian.larumbe@collabora.com>

drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems

This commit skips flushing the GPU caches after a performance counter sample
is made available if the GPU and CPU are fully coherent. It directly signals
the completion instead.

> diff --git a/drivers/gpu/drm/panfrost/panfrost_perfcnt.c b/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> index ffc77121070e2..b3f71d7fd82a9 100644
> --- a/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> @@ -52,7 +52,10 @@ void panfrost_perfcnt_clean_cache_done(struct panfrost_device *pfdev)
>  
>  void panfrost_perfcnt_sample_done(struct panfrost_device *pfdev)
>  {
> -	gpu_write(pfdev, GPU_CMD, GPU_CMD_CLEAN_CACHES);
> +	if (pfdev->features.selected_coherency != COHERENCY_ACE)
> +		gpu_write(pfdev, GPU_CMD, GPU_CMD_CLEAN_CACHES);
> +	else
> +		complete(&pfdev->perfcnt->dump_comp);

[Severity: High]
This is a pre-existing issue, but can this dereference of pfdev->perfcnt lead
to a use-after-free during device teardown?

Looking at panfrost_gpu_init() in drivers/gpu/drm/panfrost/panfrost_gpu.c,
the shared GPU IRQ is requested before panfrost_perfcnt_init() allocates
pfdev->perfcnt. During driver teardown (panfrost_device_fini()), devres
cleans up allocations in reverse order. This means pfdev->perfcnt is freed
while the shared IRQ remains registered.

If an external interrupt fires on the shared IRQ line during this window,
panfrost_gpu_irq_handler() could see the GPU_IRQ_PERFCNT_SAMPLE_COMPLETED
bit set (e.g., if reading GPU_INT_STAT from unclocked hardware returns
0xFFFFFFFF).

The handler would then call panfrost_perfcnt_sample_done(), which accesses
the already freed pfdev->perfcnt pointer here.

Should the GPU IRQ be explicitly disabled or unregistered before perfcnt is
deinitialized?

>  }
>  
>  static int panfrost_perfcnt_dump_locked(struct panfrost_device *pfdev)

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260907-claude-fixes-v8-0-c2bcb5e82184@collabora.com?part=13

  reply	other threads:[~2026-09-07 20:35 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-07 20:16 [PATCH v8 00/16] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 01/16] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 02/16] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 03/16] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-09-07 20:28   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 04/16] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 05/16] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-09-07 20:31   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 06/16] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-09-07 20:29   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 07/16] drm/panfrost: Explicitly enable MMU interrupts at device init Adrián Larumbe
2026-09-07 20:31   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 08/16] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 09/16] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 10/16] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-09-07 20:28   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 11/16] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 12/16] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-09-07 20:16 ` [PATCH v8 13/16] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-09-07 20:35   ` sashiko-bot [this message]
2026-09-07 20:16 ` [PATCH v8 14/16] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-09-07 20:38   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 15/16] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-09-07 20:36   ` sashiko-bot
2026-09-07 20:16 ` [PATCH v8 16/16] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe
2026-09-07 20:33   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260907203524.367401F00A3A@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=adrian.larumbe@collabora.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.