dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH v2] gpu: host1x: fix runtime PM reference leak on remove
@ 2026-09-21  8:22 Guangshuo Li
  2026-09-21  8:41 ` sashiko-bot
  0 siblings, 1 reply; 2+ messages in thread
From: Guangshuo Li @ 2026-09-21  8:22 UTC (permalink / raw)
  To: Thierry Reding, Mikko Perttunen, David Airlie, Simona Vetter,
	Ulf Hansson, Dmitry Osipenko, dri-devel, linux-tegra,
	linux-kernel
  Cc: Guangshuo Li, stable

host1x_probe() calls pm_runtime_resume_and_get() and intentionally keeps
the runtime PM usage reference for the lifetime of the driver because
host1x is not yet ready for dynamic runtime PM.

The probe error path drops this reference with
pm_runtime_put_sync_suspend(), but the remove path only calls
pm_runtime_force_suspend().

pm_runtime_force_suspend() disables runtime PM and invokes the runtime
suspend callback when necessary, but it does not decrement the runtime
PM usage counter. As a result, the reference acquired by
pm_runtime_resume_and_get() remains held after the driver is unbound.
Repeated bind and unbind cycles can therefore leave the runtime PM
usage counter increasingly unbalanced.

Drop the usage reference with pm_runtime_put_sync_suspend() before
forcing the device into suspend during removal.

This issue was found by manual code inspection.

Fixes: 6b6776e2ab8a ("gpu: host1x: Add initial runtime PM and OPP support")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
---
v2:
  - Replace pm_runtime_force_suspend() with pm_runtime_disable() after
    dropping the runtime PM usage reference, as suggested by Mikko Perttunen.

 drivers/gpu/host1x/dev.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/host1x/dev.c b/drivers/gpu/host1x/dev.c
index d2c64728f804..123143b2836b 100644
--- a/drivers/gpu/host1x/dev.c
+++ b/drivers/gpu/host1x/dev.c
@@ -729,7 +729,8 @@ static void host1x_remove(struct platform_device *pdev)
 	host1x_unregister(host);
 	host1x_debug_deinit(host);
 
-	pm_runtime_force_suspend(&pdev->dev);
+	pm_runtime_put_sync_suspend(&pdev->dev);
+	pm_runtime_disable(&pdev->dev);
 
 	host1x_intr_deinit(host);
 	host1x_syncpt_deinit(host);
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] gpu: host1x: fix runtime PM reference leak on remove
  2026-09-21  8:22 [PATCH v2] gpu: host1x: fix runtime PM reference leak on remove Guangshuo Li
@ 2026-09-21  8:41 ` sashiko-bot
  0 siblings, 0 replies; 2+ messages in thread
From: sashiko-bot @ 2026-09-21  8:41 UTC (permalink / raw)
  To: Guangshuo Li; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pm: host1x leaves hardware active and leaks resources on driver remove
--

commit 91e37111242ff2cea238fc242091a8f04f7f935f
Author: Guangshuo Li <lgs201920130244@gmail.com>
gpu: host1x: fix runtime PM reference leak on remove

This commit attempts to fix a runtime PM reference leak in host1x_remove() by
replacing pm_runtime_force_suspend() with pm_runtime_put_sync_suspend() and
pm_runtime_disable(). It drops the usage reference acquired in the probe
path before disabling runtime PM.

> diff --git a/drivers/gpu/host1x/dev.c b/drivers/gpu/host1x/dev.c
> index 7b1d091f3c090..df483ef6419d0 100644
> --- a/drivers/gpu/host1x/dev.c
> +++ b/drivers/gpu/host1x/dev.c
> @@ -677,7 +677,8 @@ static void host1x_remove(struct platform_device *pdev)
>  	host1x_unregister(host);
>  	host1x_debug_deinit(host);
>  
> -	pm_runtime_force_suspend(&pdev->dev);
> +	pm_runtime_put_sync_suspend(&pdev->dev);
> +	pm_runtime_disable(&pdev->dev);

[Severity: High]
Will this conditional suspend leave the hardware active while the driver is
torn down?

Unlike pm_runtime_force_suspend(), pm_runtime_put_sync_suspend() can silently
abort if the PM usage counter is greater than zero or if child devices are
still active. This might happen if userspace sets the device's power control
to "on", or if child devices populated by devm_of_platform_populate() are
still active, since devres cleans up children after host1x_remove() finishes.

If the suspend aborts, the device remains active with clocks enabled, reset
lines unasserted, and hardware interrupts enabled. Since host1x_remove()
continues and subsequently calls host1x_intr_deinit() and host1x_iommu_exit(),
could any active hardware DMA or interrupts result in IOMMU faults, memory
corruption, or an unhandled IRQ storm?

To ensure the hardware is forcefully quiesced while still fixing the usage
counter leak, should this instead drop the reference without triggering a
conditional idle, and then force the suspend? For example:

pm_runtime_put_noidle(&pdev->dev);
pm_runtime_force_suspend(&pdev->dev);

>  
>  	host1x_intr_deinit(host);
>  	host1x_syncpt_deinit(host);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921082206.234421-1-lgs201920130244@gmail.com?part=1

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-21  8:41 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-21  8:22 [PATCH v2] gpu: host1x: fix runtime PM reference leak on remove Guangshuo Li
2026-09-21  8:41 ` sashiko-bot

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox