From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v9 07/16] drm/panfrost: Explicitly enable MMU interrupts at device init
Date: Fri, 11 Sep 2026 23:43:16 +0000 [thread overview]
Message-ID: <20260911234317.24C671F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260912-claude-fixes-v9-7-e588feaa61ef@collabora.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
Pre-existing issues:
- [High] This problem wasn't introduced by this patch, but the GPU reset sequence (`panfrost_reset`) synchronizes the Job Management (JM) IRQ but fails to mask or synchronize the MMU IRQ, leading to a TOCTOU data race that can corrupt the driver state for newly submitted jobs.
- [High] This problem wasn't introduced by this patch, but during driver unbind (`panfrost_remove`) or probe failure, clocks and power domains are disabled while shared IRQ handlers remain active, which can lead to kernel crashes if the shared IRQ line is asserted.
--
commit 8161749d65dccd8c767c11da6233beaf16346d71
Author: Adrián Larumbe <adrian.larumbe@collabora.com>
drm/panfrost: Explicitly enable MMU interrupts at device init
Because the device must be in a position to accept jobs between the time
drm_dev_register() is called and autosuspend first kicks in, this commit
enables MMU interrupts at device initialisation time. This avoids a narrow
window where jobs targeting the tiler buffer object could time out.
> diff --git a/drivers/gpu/drm/panfrost/panfrost_mmu.c b/drivers/gpu/drm/panfrost/panfrost_mmu.c
> index 5c393ed6e3101..faa62643caf1d 100644
> --- a/drivers/gpu/drm/panfrost/panfrost_mmu.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_mmu.c
[ ... ]
> @@ -355,8 +361,7 @@ void panfrost_mmu_reset(struct panfrost_device *pfdev)
>
> spin_unlock(&pfdev->as_lock);
>
> - mmu_write(pfdev, MMU_INT_CLEAR, ~0);
> - mmu_write(pfdev, MMU_INT_MASK, ~0);
> + panfrost_mmu_enable_interrupts(pfdev);
[Severity: High]
This isn't a bug introduced by this patch, but does the GPU reset sequence
have a data race here?
When panfrost_reset() in drivers/gpu/drm/panfrost/panfrost_job.c triggers
a reset, it synchronizes the JM IRQ but fails to mask or synchronize the
MMU IRQ:
drivers/gpu/drm/panfrost/panfrost_job.c:panfrost_reset() {
...
job_write(pfdev, JOB_INT_MASK, 0);
synchronize_irq(pfdev->js->irq);
...
}
Because the MMU IRQ isn't synchronized, panfrost_mmu_irq_handler_thread()
can execute concurrently with panfrost_device_reset() and
panfrost_mmu_reset().
Since panfrost_mmu_enable_interrupts() modifies the MMU_INT_MASK hardware
register outside of pfdev->as_lock, could this race cause pfdev->as_faulty_mask
and the hardware register to become inconsistent if a fault occurs exactly
during reset, leading to timeouts for newly submitted jobs?
> }
>
[ ... ]
> @@ -973,6 +978,8 @@ int panfrost_mmu_init(struct panfrost_device *pfdev)
> return err;
> }
>
> + panfrost_mmu_enable_interrupts(pfdev);
> +
[Severity: High]
This is a pre-existing issue, but could enabling interrupts here cause a bus
error if the probe fails or during driver unbind?
If probe fails later in panfrost_device_init() in
drivers/gpu/drm/panfrost/panfrost_device.c, or during module unload in
panfrost_remove() in drivers/gpu/drm/panfrost/panfrost_drv.c,
panfrost_mmu_fini() is called to clear the mask:
drivers/gpu/drm/panfrost/panfrost_mmu.c:panfrost_mmu_fini() {
mmu_write(pfdev, MMU_INT_MASK, 0);
}
However, this doesn't set PANFROST_COMP_BIT_MMU in pfdev->is_suspended or
call synchronize_irq(). The clocks and power domains are then disabled, but
the devm-managed shared IRQ remains registered until the probe or remove
function fully returns.
If the shared IRQ line is asserted during this teardown window, won't
panfrost_mmu_irq_handler() bypass the is_suspended check and read
MMU_INT_STAT without active clocks, resulting in a synchronous external abort?
> return 0;
> }
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260912-claude-fixes-v9-0-e588feaa61ef@collabora.com?part=7
next prev parent reply other threads:[~2026-09-11 23:43 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-11 23:28 [PATCH v9 00/16] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 01/16] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 02/16] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 03/16] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 04/16] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 05/16] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-09-11 23:36 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 06/16] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-09-11 23:49 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 07/16] drm/panfrost: Explicitly enable MMU interrupts at device init Adrián Larumbe
2026-09-11 23:43 ` sashiko-bot [this message]
2026-09-11 23:28 ` [PATCH v9 08/16] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 09/16] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 10/16] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 11/16] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-09-11 23:41 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 12/16] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-09-11 23:28 ` [PATCH v9 13/16] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-09-11 23:40 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 14/16] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-09-11 23:47 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 15/16] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-09-11 23:47 ` sashiko-bot
2026-09-11 23:28 ` [PATCH v9 16/16] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260911234317.24C671F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=adrian.larumbe@collabora.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.