dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Adrián Larumbe" <adrian.larumbe@collabora.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v7 09/17] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove
Date: Fri, 28 Aug 2026 21:09:13 +0000	[thread overview]
Message-ID: <20260828210913.82E6A1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260828-claude-fixes-v7-9-72a13b2c125d@collabora.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [High] Dropping the PM usage counter before disabling runtime PM in the init error path creates a window for unintended device suspend, leading to a potential crash.

Pre-existing issues:
- [High] panfrost_device_fini() unconditionally accesses hardware registers even if pm_runtime_get_sync() fails, leading to a potential crash.
--

commit 2b42dddf42e663beb9d859051cf7ae5891d997e4
Author: Adrián Larumbe <adrian.larumbe@collabora.com>

drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove

This commit addresses power management reference count and autosuspend
issues during device probe and removal. It manually adjusts the PM refcount
and calls the autosuspend or noidle functions at the appropriate times to
prevent the device from remaining powered on forever or increasing its
usage count monotonically on module reloads.

> diff --git a/drivers/gpu/drm/panfrost/panfrost_device.c b/drivers/gpu/drm/panfrost/panfrost_device.c
> index 99f7da2180f92..70c8109ea6987 100644
> --- a/drivers/gpu/drm/panfrost/panfrost_device.c
> +++ b/drivers/gpu/drm/panfrost/panfrost_device.c
[ ... ]
> @@ -334,9 +335,13 @@ int panfrost_device_init(struct panfrost_device *pfdev)
>  	if (err < 0)
>  		goto out_devreg;
>  
> +	pm_runtime_put_autosuspend(pfdev->base.dev);
> +
>  	return 0;
>  
>  out_devreg:
> +	pm_runtime_dont_use_autosuspend(pfdev->base.dev);
> +	pm_runtime_put_noidle(pfdev->base.dev);
>  	pm_runtime_disable(pfdev->base.dev);

[Severity: High]
Does dropping the PM usage counter before disabling runtime PM create a race
window here? 

If `pm_runtime_put_noidle()` drops the PM usage count to 0 while PM runtime
is still active, a concurrent thread (e.g., userspace modifying sysfs power
controls) could trigger an asynchronous device suspend. This would turn off
clocks and power domains right before the error path proceeds to call
`panfrost_device_disable_hw()`, attempting to write to memory-mapped hardware
registers that are now powered off, which can cause a Synchronous External
Abort.

Should `pm_runtime_disable()` be called before `pm_runtime_put_noidle()` to
guarantee the device remains active during teardown?

>  	panfrost_device_disable_hw(pfdev);
>  	panfrost_gem_fini(pfdev);
[ ... ]
> @@ -363,7 +368,9 @@ int panfrost_device_init(struct panfrost_device *pfdev)
>  void panfrost_device_fini(struct panfrost_device *pfdev)
>  {
>  	pm_runtime_get_sync(pfdev->base.dev);
> +	pm_runtime_dont_use_autosuspend(pfdev->base.dev);
>  	pm_runtime_disable(pfdev->base.dev);
> +	pm_runtime_put_noidle(pfdev->base.dev);
>  
>  	panfrost_jm_stop_sched_jobs(pfdev);
>  	panfrost_device_disable_hw(pfdev);

[Severity: High]
This is a pre-existing issue, but panfrost_device_fini() unconditionally
accesses hardware registers even if pm_runtime_get_sync() fails.

If `pm_runtime_get_sync()` returns `< 0` (e.g., due to a hardware fault,
regulator issue, or clock failure), the function continues unconditionally
to `panfrost_device_disable_hw()`. This attempts to write to GPU/MMU
registers without power/clocks, which will result in a system crash
(Synchronous External Abort).

Can we add a check to handle the `pm_runtime_get_sync()` failure and avoid
accessing the powered-down hardware?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260828-claude-fixes-v7-0-72a13b2c125d@collabora.com?part=9

  reply	other threads:[~2026-08-28 21:09 UTC|newest]

Thread overview: 58+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-28 20:56 [PATCH v7 00/17] Collection of fixes for Panfrost: Perfcnt, RPM, refactorings Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 01/17] drm/panfrost: Move shrinker initialization and unplug one level down Adrián Larumbe
2026-09-01 11:28   ` Boris Brezillon
2026-09-02 15:36     ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 02/17] drm/panfrost: Move all DRM device initialisation into device_init() Adrián Larumbe
2026-09-01 11:49   ` Boris Brezillon
2026-09-02 15:38     ` Adrián Larumbe
2026-09-02 15:50       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 03/17] drm/panfrost: Move lock and modparam initialisations into their subsystems Adrián Larumbe
2026-08-28 21:14   ` sashiko-bot
2026-09-01 12:10   ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 04/17] drm/panfrost: Move debugfs initialisation to relevant subsystems Adrián Larumbe
2026-09-01 12:30   ` Boris Brezillon
2026-09-02 15:40     ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 05/17] drm/panfrost: Skip NULL checks for clock enable/disabling Adrián Larumbe
2026-09-01 12:31   ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 06/17] drm/panfrost: Consolidate device clock management and reset Adrián Larumbe
2026-09-01 12:38   ` Boris Brezillon
2026-09-02 15:41     ` Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 07/17] drm/panfrost: Stop all jobs before commencing device teardown Adrián Larumbe
2026-08-28 21:16   ` sashiko-bot
2026-09-01 12:58   ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 08/17] drm/panfrost: Split subsystem init/reset from interrupt enablement Adrián Larumbe
2026-08-28 21:11   ` sashiko-bot
2026-09-01 13:08   ` Boris Brezillon
2026-09-02 15:41     ` Adrián Larumbe
2026-09-02 16:05       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 09/17] drm/panfrost: Fix PM refcnt and autosuspend issues at device probe/remove Adrián Larumbe
2026-08-28 21:09   ` sashiko-bot [this message]
2026-09-01 13:18   ` Boris Brezillon
2026-09-02 15:42     ` Adrián Larumbe
2026-09-02 16:14       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 10/17] drm/panfrost: Add warning messages to fatal error conditions Adrián Larumbe
2026-08-28 21:10   ` sashiko-bot
2026-09-01 13:20   ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 11/17] drm/panfrost: Add debugfs knob for manually triggering a GPU reset Adrián Larumbe
2026-08-28 21:12   ` sashiko-bot
2026-09-01 13:27   ` Boris Brezillon
2026-09-02 15:42     ` Adrián Larumbe
2026-09-02 16:23       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 12/17] drm/panfrost: Move perfcnt GPU disable sequence into a helper Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 13/17] drm/panfrost: Skip cache flush/invalidate when enabling perfcnt Adrián Larumbe
2026-09-01 13:32   ` Boris Brezillon
2026-09-02 15:43     ` Adrián Larumbe
2026-09-02 16:29       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 14/17] drm/panfrost: Avoid cache flush after perfcnt sample in fully coherent systems Adrián Larumbe
2026-08-28 21:14   ` sashiko-bot
2026-09-01 13:37   ` Boris Brezillon
2026-09-02 15:44     ` Adrián Larumbe
2026-09-02 16:33       ` Boris Brezillon
2026-09-02 16:34   ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 15/17] drm/panfrost: Introduce a reset lock Adrián Larumbe
2026-08-28 20:56 ` [PATCH v7 16/17] drm/panfrost: Fix races between perfcnt and reset sequence Adrián Larumbe
2026-08-28 21:17   ` sashiko-bot
2026-09-01 14:03   ` Boris Brezillon
2026-09-02 15:45     ` Adrián Larumbe
2026-09-02 16:51       ` Boris Brezillon
2026-08-28 20:56 ` [PATCH v7 17/17] drm/panfrost: Bump driver minor to reflect new DUMP IOCTL req field Adrián Larumbe

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260828210913.82E6A1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=adrian.larumbe@collabora.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox