From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v9 11/16] drm/panfrost: Move perfcnt GPU disable sequence into a helper
Date: Fri, 11 Sep 2026 23:41:06 +0000 [thread overview]
Message-ID: <20260911234107.3F65B1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260912-claude-fixes-v9-11-e588feaa61ef@collabora.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Use-after-free of pfdev->perfcnt in GPU interrupt handler on device unbind due to devres cleanup order.
--
commit 62f6a919f812a1a1e64197b8f8a6a6d6f4790287
Author: Adrián Larumbe <adrian.larumbe@collabora.com>
drm/panfrost: Move perfcnt GPU disable sequence into a helper
This commit factors out the performance counter hardware disable sequence into a
new helper function panfrost_perfcnt_hw_disable() to reduce repetition.
> diff --git a/drivers/gpu/drm/panfrost/panfrost_perfcnt.c b/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> index 7020c0192e189..f71534e741b65 100644
> --- a/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_perfcnt.c
> @@ -35,6 +35,16 @@ struct panfrost_perfcnt {
> struct completion dump_comp;
> };
>
> +static void panfrost_perfcnt_hw_disable(struct panfrost_device *pfdev)
> +{
> + gpu_write(pfdev, GPU_PERFCNT_CFG,
> + GPU_PERFCNT_CFG_MODE(GPU_PERFCNT_CFG_MODE_OFF));
> + gpu_write(pfdev, GPU_PRFCNT_JM_EN, 0x0);
> + gpu_write(pfdev, GPU_PRFCNT_SHADER_EN, 0x0);
> + gpu_write(pfdev, GPU_PRFCNT_MMU_L2_EN, 0x0);
> + gpu_write(pfdev, GPU_PRFCNT_TILER_EN, 0);
> +}
> +
> void panfrost_perfcnt_clean_cache_done(struct panfrost_device *pfdev)
> {
> complete(&pfdev->perfcnt->dump_comp);
[Severity: High]
This isn't a bug introduced by this patch, but can this dereference of
pfdev->perfcnt in panfrost_perfcnt_clean_cache_done() lead to a
use-after-free during device unbind?
The allocation order in panfrost_device_init() establishes a devres LIFO free
order that could cause this:
panfrost_device.c:panfrost_device_init() {
...
err = panfrost_gpu_init(pfdev);
// Registers GPU IRQ via devm_request_irq()
...
err = panfrost_perfcnt_init(pfdev);
// Allocates pfdev->perfcnt via devm_kzalloc()
...
}
Because devres cleans up in LIFO order, on device unbind, pfdev->perfcnt is
freed before the GPU IRQ handler is unregistered.
Additionally, panfrost_device_fini() temporarily un-suspends the device, which
unmasks the hardware interrupts via panfrost_device_reset(), and then calls
panfrost_gpu_fini(). While panfrost_gpu_fini() powers off the hardware, it
does not mask the interrupts.
If the shared IRQ line fires during this window, or if reading GPU_INT_STAT
returns 0xFFFFFFFF because power domains are off, panfrost_gpu_irq_handler()
will execute, pass the state & GPU_IRQ_CLEAN_CACHES_COMPLETED check, and call
panfrost_perfcnt_clean_cache_done().
Would this result in a use-after-free when accessing
pfdev->perfcnt->dump_comp?
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260912-claude-fixes-v9-0-e588feaa61ef@collabora.com?part=11
next prev parent reply other threads:[~2026-09-11 23:41 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 23:28 [PATCH v9 00/16] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 01/16] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 02/16] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 03/16] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 04/16] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 05/16] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-09-11 23:36 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 06/16] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-09-11 23:49 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 07/16] drm/panfrost: Explicitly enable MMU interrupts at device init Adrián Larumbe
2026-09-11 23:43 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 08/16] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 09/16] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 10/16] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 11/16] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-09-11 23:41 ` sashiko-bot [this message]
2026-09-11 23:28 ` [PATCH v9 12/16] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 13/16] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-09-11 23:40 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 14/16] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-09-11 23:47 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 15/16] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-09-11 23:47 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 16/16] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911234107.3F65B1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=adrian.larumbe@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.