dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v6 01/16] drm/panfrost: Move shrinker initialization and unplug one level down
Date: Wed, 26 Aug 2026 21:34:17 +0000	[thread overview]
Message-ID: <20260826213417.E72891F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260826-claude-fixes-v6-1-78119af409e7@collabora.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Closing a GEM object or MMU context during/after device unbind causes a kernel panic due to unclocked MMU register access.
--

commit 78f80dbfd319f079f4898f5d8b2af5e44a1877d5
Author: Adrián Larumbe <adrian.larumbe@collabora.com>

drm/panfrost: Move shrinker initialization and unplug one level down

This commit moves the initialization and cleanup of the GEM shrinker into
the core GEM init and fini paths. It mimics the behavior seen in Panthor
and removes an unnecessary config feature check.

> diff --git a/drivers/gpu/drm/panfrost/panfrost_drv.c b/drivers/gpu/drm/panfrost/panfrost_drv.c
> --- a/drivers/gpu/drm/panfrost/panfrost_drv.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_drv.c
[ ... ]
> @@ -1024,7 +1019,6 @@ static void panfrost_remove(struct platform_device *pdev)
>  	struct panfrost_device *pfdev = platform_get_drvdata(pdev);
>  
>  	drm_dev_unregister(&pfdev->base);
> -	panfrost_gem_shrinker_cleanup(&pfdev->base);
>  
>  	pm_runtime_get_sync(pfdev->base.dev);
>  	pm_runtime_disable(pfdev->base.dev);
[Severity: High]
This is a pre-existing issue, but closing a GEM object or MMU context during
or after device unbind can cause a kernel panic due to unclocked MMU register
access.

When a userspace process closes a DRM file descriptor concurrently with
device unbind, it triggers panfrost_mmu_flush_range().

During unbind, pm_runtime_disable() is called here while the device is in
the RPM_ACTIVE state. The status remains RPM_ACTIVE even after
panfrost_clk_fini() turns off the hardware clocks.

Because the status remains active, concurrent execution of
panfrost_mmu_flush_range() evaluates to true:

drivers/gpu/drm/panfrost/panfrost_mmu.c:panfrost_mmu_flush_range() {
    ...
    if (pm_runtime_active(pfdev->base.dev))
        mmu_hw_do_operation(pfdev, mmu, iova, size, AS_COMMAND_FLUSH_PT);
    ...
}

The same vulnerability exists in context destruction during teardown:

drivers/gpu/drm/panfrost/panfrost_mmu.c:panfrost_mmu_release_ctx() {
    ...
    if (pm_runtime_active(pfdev->base.dev))
        panfrost_mmu_disable(pfdev, mmu->as);
    ...
}

Could this pm_runtime_disable() sequence leave the device vulnerable to a
synchronous external abort on ARM when those powered-down registers are
concurrently accessed?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260826-claude-fixes-v6-0-78119af409e7@collabora.com?part=1

  reply	other threads:[~2026-08-26 21:34 UTC|newest]

Thread overview: 25+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-26 21:18 [PATCH v6 00/16] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 01/16] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-08-26 21:34   ` sashiko-bot [this message]
2026-08-26 21:18 ` [PATCH v6 02/16] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 03/16] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 04/16] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 05/16] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 06/16] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 07/16] drm/panfrost: Split subsystem init/reset from interrupt enablement Adrián Larumbe
2026-08-26 21:34   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 08/16] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-08-26 21:31   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 09/16] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-08-26 21:27   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 10/16] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-08-26 21:34   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 11/16] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 12/16] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 13/16] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-08-26 21:36   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 14/16] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-08-26 21:18 ` [PATCH v6 15/16] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-08-26 21:35   ` sashiko-bot
2026-08-26 21:18 ` [PATCH v6 16/16] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe
2026-08-26 21:37   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260826213417.E72891F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=adrian.larumbe@collabora.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox