dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] accel/ivpu: Use separate flag for job timeout
@ 2026-09-14  8:28 Karol Wachowski
  2026-09-14  8:41 ` sashiko-bot
  2026-10-02 16:53 ` Jeff Hugo
  0 siblings, 2 replies; 3+ messages in thread
From: Karol Wachowski @ 2026-09-14  8:28 UTC (permalink / raw)
  To: dri-devel
  Cc: oded.gabbay, jeff.hugo, lizhi.hou, andrzej.kacprowski,
	dawid.osuchowski, Jakub Pawlak, Karol Wachowski

From: Jakub Pawlak <jakub.pawlak@intel.com>

Use separate flag to mark a job timeout as a reason
of starting context_abort_work. This allows to distinguish
engine reset reason and clearly adjust reset procedure flow.

The flag is cleared in ivpu_prepare_for_reset(), which every
recovery and suspend path already funnels through, so that the
state is clean after recovery.

Fixes: ade00a6c903f ("accel/ivpu: Perform engine reset instead of device recovery on TDR")
Signed-off-by: Jakub Pawlak <jakub.pawlak@intel.com>
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
---
 drivers/accel/ivpu/ivpu_drv.c | 3 ++-
 drivers/accel/ivpu/ivpu_drv.h | 2 +-
 drivers/accel/ivpu/ivpu_job.c | 7 +++----
 drivers/accel/ivpu/ivpu_mmu.c | 1 -
 drivers/accel/ivpu/ivpu_pm.c  | 1 +
 5 files changed, 7 insertions(+), 7 deletions(-)

diff --git a/drivers/accel/ivpu/ivpu_drv.c b/drivers/accel/ivpu/ivpu_drv.c
index 0f215392d42d..647684219e9d 100644
--- a/drivers/accel/ivpu/ivpu_drv.c
+++ b/drivers/accel/ivpu/ivpu_drv.c
@@ -528,6 +528,7 @@ void ivpu_prepare_for_reset(struct ivpu_device *vdev)
 {
 	ivpu_hw_irq_disable(vdev);
 	disable_irq(vdev->irq);
+	atomic_set(&vdev->job_timeout_detected, 0);
 	flush_work(&vdev->irq_dct_work);
 	flush_work(&vdev->context_abort_work);
 	flush_work(&vdev->job_destroy_work);
@@ -723,7 +724,7 @@ static int ivpu_dev_init(struct ivpu_device *vdev)
 	vdev->context_xa_limit.max = IVPU_USER_CONTEXT_MAX_SSID;
 	atomic64_set(&vdev->unique_id_counter, 0);
 	atomic_set(&vdev->job_timeout_counter, 0);
-	atomic_set(&vdev->faults_detected, 0);
+	atomic_set(&vdev->job_timeout_detected, 0);
 	xa_init_flags(&vdev->context_xa, XA_FLAGS_ALLOC | XA_FLAGS_LOCK_IRQ);
 	xa_init_flags(&vdev->submitted_jobs_xa, XA_FLAGS_ALLOC1);
 	xa_init_flags(&vdev->db_xa, XA_FLAGS_ALLOC1);
diff --git a/drivers/accel/ivpu/ivpu_drv.h b/drivers/accel/ivpu/ivpu_drv.h
index 8f29f1dc52b9..37d5a6ac55f8 100644
--- a/drivers/accel/ivpu/ivpu_drv.h
+++ b/drivers/accel/ivpu/ivpu_drv.h
@@ -171,7 +171,7 @@ struct ivpu_device {
 	struct xarray submitted_jobs_xa;
 	struct ivpu_ipc_consumer job_done_consumer;
 	atomic_t job_timeout_counter;
-	atomic_t faults_detected;
+	atomic_t job_timeout_detected;
 
 	atomic64_t unique_id_counter;
 
diff --git a/drivers/accel/ivpu/ivpu_job.c b/drivers/accel/ivpu/ivpu_job.c
index b3de5dd29d1e..084d825f744d 100644
--- a/drivers/accel/ivpu/ivpu_job.c
+++ b/drivers/accel/ivpu/ivpu_job.c
@@ -626,7 +626,6 @@ bool ivpu_job_handle_engine_error(struct ivpu_device *vdev, u32 job_id, u32 job_
 		 * status and ensure both are handled in the same way
 		 */
 		job->file_priv->has_mmu_faults = true;
-		atomic_set(&vdev->faults_detected, 1);
 		queue_work(system_percpu_wq, &vdev->context_abort_work);
 		return true;
 	}
@@ -1260,10 +1259,10 @@ static int reset_engine_and_mark_faulty_contexts(struct ivpu_device *vdev)
 		return ret;
 
 	/*
-	 * If faults are detected, ignore guilty contexts from engine reset as NPU may not be stuck
-	 * and could return currently running good context and faulty contexts are already marked
+	 * If job timeout is detected, read guilty context from engine reset, for other reasons
+	 * faulty context is already known
 	 */
-	if (atomic_cmpxchg(&vdev->faults_detected, 1, 0) == 1)
+	if (atomic_cmpxchg(&vdev->job_timeout_detected, 1, 0) == 0)
 		return 0;
 
 	num_impacted_contexts = resp.payload.engine_reset_done.num_impacted_contexts;
diff --git a/drivers/accel/ivpu/ivpu_mmu.c b/drivers/accel/ivpu/ivpu_mmu.c
index 41efd8985fa6..b2025274f91d 100644
--- a/drivers/accel/ivpu/ivpu_mmu.c
+++ b/drivers/accel/ivpu/ivpu_mmu.c
@@ -964,7 +964,6 @@ void ivpu_mmu_irq_evtq_handler(struct ivpu_device *vdev)
 		file_priv = xa_load(&vdev->context_xa, ssid);
 		if (file_priv) {
 			if (!READ_ONCE(file_priv->has_mmu_faults)) {
-				atomic_set(&vdev->faults_detected, 1);
 				ivpu_mmu_dump_event(vdev, event);
 				WRITE_ONCE(file_priv->has_mmu_faults, true);
 			}
diff --git a/drivers/accel/ivpu/ivpu_pm.c b/drivers/accel/ivpu/ivpu_pm.c
index c1ce8329790e..de0becbfdffb 100644
--- a/drivers/accel/ivpu/ivpu_pm.c
+++ b/drivers/accel/ivpu/ivpu_pm.c
@@ -229,6 +229,7 @@ static void ivpu_job_timeout_work(struct work_struct *work)
 
 	ivpu_jsm_state_dump(vdev);
 	ivpu_dev_coredump(vdev);
+	atomic_set(&vdev->job_timeout_detected, 1);
 	queue_work(system_percpu_wq, &vdev->context_abort_work);
 }
 
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] accel/ivpu: Use separate flag for job timeout
  2026-09-14  8:28 [PATCH] accel/ivpu: Use separate flag for job timeout Karol Wachowski
@ 2026-09-14  8:41 ` sashiko-bot
  2026-10-02 16:53 ` Jeff Hugo
  1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-14  8:41 UTC (permalink / raw)
  To: Karol Wachowski; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:

New issues:
- [High] Premature clearing of `job_timeout_detected` flag before flushing `context_abort_work` silently drops the ban on the guilty context during a job timeout (TDR).

Pre-existing issues:
- [High] Lockless `xa_load` of `file_priv` in the MMU event queue IRQ handler leads to a Use-After-Free.
--

commit b8245a180aec634640c11be76ef2b20b2a900039
Author: Jakub Pawlak <jakub.pawlak@intel.com>

accel/ivpu: Use separate flag for job timeout

This patch introduces a separate flag, job_timeout_detected, to distinguish
engine resets caused by job timeouts from other reasons. The flag is
cleared in ivpu_prepare_for_reset() to ensure a clean state after recovery.

> diff --git a/drivers/accel/ivpu/ivpu_drv.c b/drivers/accel/ivpu/ivpu_drv.c
> index 0f215392d42de..647684219e9d3 100644
> --- a/drivers/accel/ivpu/ivpu_drv.c
> +++ b/drivers/accel/ivpu/ivpu_drv.c
> @@ -528,6 +528,7 @@ void ivpu_prepare_for_reset(struct ivpu_device *vdev)
>  {
>  	ivpu_hw_irq_disable(vdev);
>  	disable_irq(vdev->irq);
> +	atomic_set(&vdev->job_timeout_detected, 0);
>  	flush_work(&vdev->irq_dct_work);
>  	flush_work(&vdev->context_abort_work);

[Severity: High]
Is it safe to clear the job_timeout_detected flag before flushing
context_abort_work?

If a concurrent recovery calls ivpu_prepare_for_reset() and sets the flag
to 0, and context_abort_work runs simultaneously, could it reach the
atomic_cmpxchg() in reset_engine_and_mark_faulty_contexts(), see a 0, and
silently skip banning the guilty context? 

Should this flag be cleared after flushing the work queues instead?

[ ... ]

> diff --git a/drivers/accel/ivpu/ivpu_job.c b/drivers/accel/ivpu/ivpu_job.c
> index b3de5dd29d1e8..084d825f744dd 100644
> --- a/drivers/accel/ivpu/ivpu_job.c
> +++ b/drivers/accel/ivpu/ivpu_job.c
[ ... ]
> @@ -1260,10 +1259,10 @@ static int reset_engine_and_mark_faulty_contexts(struct ivpu_device *vdev)
>  		return ret;
>  
>  	/*
> -	 * If faults are detected, ignore guilty contexts from engine reset as NPU may not be stuck
> -	 * and could return currently running good context and faulty contexts are already marked
> +	 * If job timeout is detected, read guilty context from engine reset, for other reasons
> +	 * faulty context is already known
>  	 */
> -	if (atomic_cmpxchg(&vdev->faults_detected, 1, 0) == 1)
> +	if (atomic_cmpxchg(&vdev->job_timeout_detected, 1, 0) == 0)
>  		return 0;
>  
>  	num_impacted_contexts = resp.payload.engine_reset_done.num_impacted_contexts;

[ ... ]

> diff --git a/drivers/accel/ivpu/ivpu_mmu.c b/drivers/accel/ivpu/ivpu_mmu.c
> index 41efd8985fa67..b2025274f91de 100644
> --- a/drivers/accel/ivpu/ivpu_mmu.c
> +++ b/drivers/accel/ivpu/ivpu_mmu.c
> @@ -964,7 +964,6 @@ void ivpu_mmu_irq_evtq_handler(struct ivpu_device *vdev)
>  		file_priv = xa_load(&vdev->context_xa, ssid);
>  		if (file_priv) {
>  			if (!READ_ONCE(file_priv->has_mmu_faults)) {
> -				atomic_set(&vdev->faults_detected, 1);
>  				ivpu_mmu_dump_event(vdev, event);
>  				WRITE_ONCE(file_priv->has_mmu_faults, true);
>  			}

[Severity: High]
This is a pre-existing issue, but does the lockless xa_load() here risk a
use-after-free?

Looking at file_priv_release() in drivers/accel/ivpu/ivpu_drv.c, file_priv
is freed immediately via kfree() without waiting for an RCU grace period
after being removed from the xarray:

drivers/accel/ivpu/ivpu_drv.c:file_priv_release() {
    ...
    ivpu_user_limits_put(vdev, file_priv->user_limits);
    mutex_destroy(&file_priv->ms_lock);
    mutex_destroy(&file_priv->lock);
    kfree(file_priv);
}

If a user closes the file descriptor concurrently with this IRQ handler,
could file_priv be freed while we are still accessing
file_priv->has_mmu_faults via READ_ONCE() or WRITE_ONCE()?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260914082800.892044-1-karol.wachowski@linux.intel.com?part=1

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] accel/ivpu: Use separate flag for job timeout
  2026-09-14  8:28 [PATCH] accel/ivpu: Use separate flag for job timeout Karol Wachowski
  2026-09-14  8:41 ` sashiko-bot
@ 2026-10-02 16:53 ` Jeff Hugo
  1 sibling, 0 replies; 3+ messages in thread
From: Jeff Hugo @ 2026-10-02 16:53 UTC (permalink / raw)
  To: Karol Wachowski, dri-devel
  Cc: oded.gabbay, lizhi.hou, andrzej.kacprowski, dawid.osuchowski,
	Jakub Pawlak

On 9/14/2026 2:28 AM, Karol Wachowski wrote:
> From: Jakub Pawlak <jakub.pawlak@intel.com>
> 
> Use separate flag to mark a job timeout as a reason
> of starting context_abort_work. This allows to distinguish
> engine reset reason and clearly adjust reset procedure flow.
> 
> The flag is cleared in ivpu_prepare_for_reset(), which every
> recovery and suspend path already funnels through, so that the
> state is clean after recovery.
> 
> Fixes: ade00a6c903f ("accel/ivpu: Perform engine reset instead of device recovery on TDR")
> Signed-off-by: Jakub Pawlak <jakub.pawlak@intel.com>
> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>

Reviewed-by: Jeff Hugo <jeff.hugo@oss.qualcomm.com>

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-02 16:53 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14  8:28 [PATCH] accel/ivpu: Use separate flag for job timeout Karol Wachowski
2026-09-14  8:41 ` sashiko-bot
2026-10-02 16:53 ` Jeff Hugo

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox