* [PATCH] accel/ivpu: Abort pending jobs on file close
@ 2026-09-14 8:29 Karol Wachowski
2026-09-14 8:48 ` sashiko-bot
2026-10-02 16:52 ` Jeff Hugo
0 siblings, 2 replies; 3+ messages in thread
From: Karol Wachowski @ 2026-09-14 8:29 UTC (permalink / raw)
To: dri-devel
Cc: oded.gabbay, jeff.hugo, lizhi.hou, andrzej.kacprowski,
dawid.osuchowski, Karol Wachowski
Closing a file only dropped ivpu_postclose()'s own reference on
file_priv; the context and command queue teardown happened later in
file_priv_release(), once every in-flight job completed and dropped
its own reference. Since nothing explicitly canceled a context's
command queues or jobs on close, any job still in flight kept running
in the background after its owning process exited, until it completed
on its own or the device's own TDR intervened. Make ivpu_postclose()
explicitly abort the context's command queues and signal and destroy
all of its pending jobs via the new ivpu_context_abort_all_jobs().
Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
---
drivers/accel/ivpu/ivpu_drv.c | 11 +++++++++++
drivers/accel/ivpu/ivpu_job.c | 11 +++++++++++
drivers/accel/ivpu/ivpu_job.h | 1 +
3 files changed, 23 insertions(+)
diff --git a/drivers/accel/ivpu/ivpu_drv.c b/drivers/accel/ivpu/ivpu_drv.c
index 647684219e9d..d7faabe0f676 100644
--- a/drivers/accel/ivpu/ivpu_drv.c
+++ b/drivers/accel/ivpu/ivpu_drv.c
@@ -393,6 +393,17 @@ static void ivpu_postclose(struct drm_device *dev, struct drm_file *file)
ivpu_dbg(vdev, FILE, "file_priv close: ctx %u process %s pid %d\n",
file_priv->ctx.id, current->comm, task_pid_nr(current));
+ if (pm_runtime_get_if_active(vdev->drm.dev) > 0) {
+ mutex_lock(&file_priv->lock);
+ if (file_priv->bound && !file_priv->aborted)
+ ivpu_context_abort_locked(file_priv);
+ mutex_unlock(&file_priv->lock);
+
+ ivpu_context_abort_all_jobs(vdev, file_priv->ctx.id);
+
+ ivpu_rpm_put(vdev);
+ }
+
ivpu_ms_cleanup(file_priv);
ivpu_file_priv_put(&file_priv);
}
diff --git a/drivers/accel/ivpu/ivpu_job.c b/drivers/accel/ivpu/ivpu_job.c
index 084d825f744d..fa04f79e8f7b 100644
--- a/drivers/accel/ivpu/ivpu_job.c
+++ b/drivers/accel/ivpu/ivpu_job.c
@@ -725,6 +725,17 @@ void ivpu_cmdq_abort_all_jobs(struct ivpu_device *vdev, u32 ctx_id, u32 cmdq_id)
mutex_unlock(&vdev->submitted_jobs_lock);
}
+void ivpu_context_abort_all_jobs(struct ivpu_device *vdev, u32 ctx_id)
+{
+ struct ivpu_job *job;
+ unsigned long id;
+
+ guard(mutex)(&vdev->submitted_jobs_lock);
+ xa_for_each(&vdev->submitted_jobs_xa, id, job)
+ if (job->file_priv->ctx.id == ctx_id)
+ ivpu_job_signal_and_destroy(vdev, id, DRM_IVPU_JOB_STATUS_ABORTED);
+}
+
static int ivpu_job_submit(struct ivpu_job *job, u8 priority, u32 cmdq_id)
{
struct ivpu_file_priv *file_priv = job->file_priv;
diff --git a/drivers/accel/ivpu/ivpu_job.h b/drivers/accel/ivpu/ivpu_job.h
index 6e32fea1eb62..f8b27e9a803f 100644
--- a/drivers/accel/ivpu/ivpu_job.h
+++ b/drivers/accel/ivpu/ivpu_job.h
@@ -89,6 +89,7 @@ void ivpu_context_abort_locked(struct ivpu_file_priv *file_priv);
void ivpu_cmdq_release_all_locked(struct ivpu_file_priv *file_priv);
void ivpu_cmdq_reset_all_contexts(struct ivpu_device *vdev);
void ivpu_cmdq_abort_all_jobs(struct ivpu_device *vdev, u32 ctx_id, u32 cmdq_id);
+void ivpu_context_abort_all_jobs(struct ivpu_device *vdev, u32 ctx_id);
void ivpu_job_done_consumer_init(struct ivpu_device *vdev);
void ivpu_job_done_consumer_fini(struct ivpu_device *vdev);
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] accel/ivpu: Abort pending jobs on file close
2026-09-14 8:29 [PATCH] accel/ivpu: Abort pending jobs on file close Karol Wachowski
@ 2026-09-14 8:48 ` sashiko-bot
2026-10-02 16:52 ` Jeff Hugo
1 sibling, 0 replies; 3+ messages in thread
From: sashiko-bot @ 2026-09-14 8:48 UTC (permalink / raw)
To: Karol Wachowski; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] Context and job cleanup is skipped when CONFIG_PM is disabled, defeating the purpose of the patch.
--
commit e999c7cb2698f3a8d3e0b1deb6b6b334895bbf3e
Author: Karol Wachowski <karol.wachowski@linux.intel.com>
accel/ivpu: Abort pending jobs on file close
This commit modifies ivpu_postclose() to explicitly abort a context's command
queues and signal all pending jobs. This ensures that any in-flight jobs do
not keep running in the background after the owning process exits.
> diff --git a/drivers/accel/ivpu/ivpu_drv.c b/drivers/accel/ivpu/ivpu_drv.c
> index 0f215392d42de..4c73dc8b3aafe 100644
> --- a/drivers/accel/ivpu/ivpu_drv.c
> +++ b/drivers/accel/ivpu/ivpu_drv.c
> @@ -393,6 +393,17 @@ static void ivpu_postclose(struct drm_device *dev, struct drm_file *file)
> ivpu_dbg(vdev, FILE, "file_priv close: ctx %u process %s pid %d\n",
> file_priv->ctx.id, current->comm, task_pid_nr(current));
>
> + if (pm_runtime_get_if_active(vdev->drm.dev) > 0) {
[Severity: High]
Does this skip the newly added job abort logic entirely when the kernel is
built without CONFIG_PM?
When CONFIG_PM is disabled, pm_runtime_get_if_active() returns -EINVAL.
This causes the condition to evaluate to false, completely bypassing the
context abort and job cleanup steps.
If an application submits jobs and closes the DRM file descriptor on a system
with CONFIG_PM=n, the driver silently skips this cleanup. This appears to
defeat the purpose of the patch on those systems, as in-flight jobs will
continue running in the background.
Could this be exploited by untrusted or unprivileged userspace to launch
long-running jobs and detach from them, causing resource exhaustion on the
NPU?
> + mutex_lock(&file_priv->lock);
> + if (file_priv->bound && !file_priv->aborted)
> + ivpu_context_abort_locked(file_priv);
> + mutex_unlock(&file_priv->lock);
> +
> + ivpu_context_abort_all_jobs(vdev, file_priv->ctx.id);
> +
> + ivpu_rpm_put(vdev);
> + }
> +
> ivpu_ms_cleanup(file_priv);
> ivpu_file_priv_put(&file_priv);
> }
[ ... ]
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260914082929.892437-1-karol.wachowski@linux.intel.com?part=1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] accel/ivpu: Abort pending jobs on file close
2026-09-14 8:29 [PATCH] accel/ivpu: Abort pending jobs on file close Karol Wachowski
2026-09-14 8:48 ` sashiko-bot
@ 2026-10-02 16:52 ` Jeff Hugo
1 sibling, 0 replies; 3+ messages in thread
From: Jeff Hugo @ 2026-10-02 16:52 UTC (permalink / raw)
To: Karol Wachowski, dri-devel
Cc: oded.gabbay, lizhi.hou, andrzej.kacprowski, dawid.osuchowski
On 9/14/2026 2:29 AM, Karol Wachowski wrote:
> Closing a file only dropped ivpu_postclose()'s own reference on
> file_priv; the context and command queue teardown happened later in
> file_priv_release(), once every in-flight job completed and dropped
> its own reference. Since nothing explicitly canceled a context's
> command queues or jobs on close, any job still in flight kept running
> in the background after its owning process exited, until it completed
> on its own or the device's own TDR intervened. Make ivpu_postclose()
> explicitly abort the context's command queues and signal and destroy
> all of its pending jobs via the new ivpu_context_abort_all_jobs().
>
> Signed-off-by: Karol Wachowski <karol.wachowski@linux.intel.com>
Reviewed-by: Jeff Hugo <jeff.hugo@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-02 16:52 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-14 8:29 [PATCH] accel/ivpu: Abort pending jobs on file close Karol Wachowski
2026-09-14 8:48 ` sashiko-bot
2026-10-02 16:52 ` Jeff Hugo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox