From: sashiko-bot@kernel.org
To: "Jiaxing Hu" <gahing@gahingwoo.com>
Cc: devicetree@vger.kernel.org, dri-devel@lists.freedesktop.org,
robh@kernel.org, conor+dt@kernel.org
Subject: Re: [PATCH v13 03/14] accel/rocket: wait for a running IRQ handler before resetting a core
Date: Tue, 15 Sep 2026 10:59:15 +0000 [thread overview]
Message-ID: <20260915105915.96DAA1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260915104328.45901-4-gahing@gahingwoo.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] rocket: interrupt masking bypassed when PM is disabled or suspending
--
commit 514c825015ef4be7a517e9ee1eca6f94eae37e6d
Author: Jiaxing Hu <gahing@gahingwoo.com>
Subject: accel/rocket: wait for a running IRQ handler before resetting a core
This commit introduces a mechanism to wait for a threaded IRQ handler that
might already be running when rocket_reset() is called. It masks the
interrupt block, clears the raw status, and calls synchronize_irq() to
prevent a concurrent handler from running. It uses
pm_runtime_get_if_active() to avoid writing to registers while the power
domain is down, preventing an SError.
Link: https://lore.kernel.org/all/20260819073530.6087-1-royalnet026@gmail.com/
Link: https://lore.kernel.org/all/CAEWPSH5mxTbUkNouxm6yecMZYvDowquhvYvhaXQ8HoMtHD5U1g@mail.gmail.com/
Link: https://lore.kernel.org/all/20260912113717.6819-1-royalnet026@gmail.com/
> diff --git a/drivers/accel/rocket/rocket_job.c b/drivers/accel/rocket/rocket_job.c
> index 575945015ca3b..dfe9135d86af5 100644
> --- a/drivers/accel/rocket/rocket_job.c
> +++ b/drivers/accel/rocket/rocket_job.c
[ ... ]
> @@ -377,9 +377,68 @@ rocket_reset(struct rocket_core *core, struct drm_sched_job *bad)
[ ... ]
> + * pm_runtime_get_if_active() does not invoke a callback -- it only
> + * takes a reference on an already-active device -- and
> + * pm_runtime_put_autosuspend() is asynchronous, so neither can re-enter
> + * this driver's runtime PM callbacks while the lock is held.
> + */
> + scoped_guard(mutex, &core->job_lock) {
> + if (pm_runtime_get_if_active(core->dev) > 0) {
> + rocket_pc_writel(core, INTERRUPT_MASK, 0x0);
> + rocket_pc_writel(core, INTERRUPT_CLEAR, 0x1ffff);
> + pm_runtime_put_autosuspend(core->dev);
> + }
> + }
> +
> + /*
> + * drm_sched_stop() returns without waiting for a threaded handler that
> + * is already running, so wait for one here. This has to stay outside
> + * job_lock: the handler takes that lock, so waiting for it while
> + * holding it would deadlock instead of fencing anything.
> + */
> + synchronize_irq(core->irq);
[Severity: High]
Does this logic bypass interrupt masking when PM is disabled or during system
suspend?
If CONFIG_PM is disabled, pm_runtime_get_if_active() unconditionally returns
-EINVAL, which evaluates to <= 0.
Additionally, during system suspend, the driver uses
pm_runtime_force_suspend(). This increments the PM disable_depth before
invoking the runtime suspend callback to turn off the clocks. Because
disable_depth is non-zero, pm_runtime_get_if_active() returns -EINVAL even
though the device is still fully active at that point.
In both of these scenarios, the condition evaluates to false and the crucial
interrupt masking is skipped.
Since the hardware remains active and the interrupt is unmasked, can the
handler fire concurrently with or immediately after synchronize_irq(),
recreating the exact race condition this code aims to close?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260915104328.45901-1-gahing@gahingwoo.com?part=3
next prev parent reply other threads:[~2026-09-15 10:59 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-15 10:43 [PATCH v13 00/14] accel/rocket: RK3576 NPU (RKNN) enablement Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 01/14] accel/rocket: request the core clocks by name Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 02/14] accel/rocket: take the completion register writes under job_lock Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 03/14] accel/rocket: wait for a running IRQ handler before resetting a core Jiaxing Hu
2026-09-15 10:59 ` sashiko-bot [this message]
2026-09-16 13:28 ` Igor Paunovic
2026-09-19 9:17 ` Jiaxing Hu
2026-09-19 10:34 ` Igor Paunovic
2026-09-15 10:43 ` [PATCH v13 04/14] accel/rocket: let the core suspend after a reset Jiaxing Hu
2026-09-15 10:58 ` sashiko-bot
2026-09-15 10:43 ` [PATCH v13 05/14] accel/rocket: factor the completion tail out of the IRQ handler Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 06/14] dt-bindings: npu: rockchip: add rockchip, rk3576-rknn-core Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 07/14] dt-bindings: power: rockchip: allow resets in a power domain node Jiaxing Hu
2026-09-21 21:52 ` Heiko Stuebner
2026-09-15 10:43 ` [PATCH v13 08/14] dt-bindings: iommu: rockchip: describe the RK3576 NPU MMU Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 09/14] pmdomain: rockchip: add optional per-domain power-on settle delay Jiaxing Hu
2026-09-21 12:41 ` Ulf Hansson
2026-09-21 22:06 ` Heiko Stuebner
2026-09-22 1:28 ` Chaoyi Chen
2026-09-15 10:43 ` [PATCH v13 10/14] pmdomain: rockchip: cycle optional power-domain resets on power-on Jiaxing Hu
2026-09-15 10:56 ` sashiko-bot
2026-09-21 12:43 ` Ulf Hansson
2026-09-23 9:38 ` Philipp Zabel
2026-09-15 10:43 ` [PATCH v13 11/14] accel/rocket: select the per-core clock and reset counts from match data Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 12/14] accel/rocket: add RK3576 NPU (RKNN) support Jiaxing Hu
2026-09-15 10:43 ` [PATCH v13 13/14] arm64: dts: rockchip: add NPU (RKNN) nodes to rk3576 Jiaxing Hu
2026-09-21 21:51 ` Heiko Stuebner
2026-09-15 10:43 ` [PATCH v13 14/14] arm64: dts: rockchip: enable the NPU on rk3576-rock-4d Jiaxing Hu
2026-09-19 7:32 ` [PATCH v13 00/14] accel/rocket: RK3576 NPU (RKNN) enablement Sidong Yang
2026-09-19 9:17 ` Jiaxing Hu
2026-09-21 12:46 ` Ulf Hansson
2026-09-24 9:08 ` Jiaxing Hu
2026-09-24 13:48 ` Ulf Hansson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260915105915.96DAA1F00893@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=conor+dt@kernel.org \
--cc=devicetree@vger.kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=gahing@gahingwoo.com \
--cc=robh@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox