dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Karunika Choo" <karunika.choo@arm.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH v1 13/27] drm/panthor: Add AM_PARTITION_CONTROL support
Date: Tue, 22 Sep 2026 20:57:56 +0000	[thread overview]
Message-ID: <20260922205756.6934D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260922204535.2850094-14-karunika.choo@arm.com>

Thank you for your contribution! Sashiko AI review found 7 potential issue(s) to consider:
- [High] pm: Unsafe shared IRQ handling without Runtime PM validation
- [High] drm/panthor: CPU soft lockup risk in partition_state_wait()
- [Medium] pm: Hardware power leak due to pm_runtime_put_noidle() on teardown paths
- [Medium] drm/panthor: OPEN_WINDOW command issued without waiting for hardware reset
- [Medium] drm/panthor: TOCTOU race in window_open() and window_close()
- [Medium] drm/panthor: Type mismatch passing resource_size_t to %llx format specifier
- [Low] drm/panthor: Missing NULL check for devm_kasprintf() string allocation
--

commit aae06968ea5bf0c6d7a668bdeb14d91ee2943a9e
Author: Karunika Choo <karunika.choo@arm.com>

drm/panthor: Add AM_PARTITION_CONTROL support

Mali v15 AM GPUs expose AM_PARTITION_CONTROL blocks to manage partition
access windows. Add a panthor arbitration platform driver and wire it into
Kconfig and the panthor build.

> diff --git a/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c
> new file mode 100644
> index 0000000000000..09342245a47d1
> --- /dev/null
> +++ b/drivers/gpu/drm/panthor/arbitration/panthor_arbitration_drv.c

[ ... ]

> +int panthor_arbitration_parse_resource(struct device *dev,
> +				       const struct fwnode_handle *child,
> +				       struct panthor_arbitration_resource *res)
> +{

[ ... ]

> +	if (!fwnode_property_present(child, DT_ID)) {
> +		dev_warn(dev, "Missing '%s' property in %s@%llx", DT_ID, name,
> +			 res->res.start);
> +		return -ENODEV;
> +	}
> +
> +	ret = fwnode_property_read_u32(child, DT_ID, &res->id);
> +	if (ret) {
> +		dev_warn(dev, "Malformed '%s' property in %s@%llx", DT_ID, name,
> +			 res->res.start);

[Severity: Medium]
Will passing res->res.start (a resource_size_t) to a %llx format specifier
corrupt the variadic stack arguments on 32-bit builds?

[ ... ]

> +static int panthor_arbitration_probe(struct platform_device *pdev)
> +{

[ ... ]

> +	ret = panthor_partition_control_init(adev);
> +	if (ret)
> +		goto err_term_pc;
> +
> +	ret = of_platform_populate(dev->of_node, NULL, NULL, dev);
> +	if (ret)
> +		goto err_depopulate;
> +
> +	pm_runtime_set_autosuspend_delay(dev, PANTHOR_PM_AUTOSUSPEND_DELAY_MS);
> +	pm_runtime_use_autosuspend(dev);
> +
> +	pm_runtime_put_autosuspend(dev);
> +
> +	return 0;
> +
> +err_depopulate:
> +	of_platform_depopulate(dev);
> +
> +err_term_pc:
> +	panthor_partition_control_term(adev);
> +	pm_runtime_put_noidle(dev);
> +	return ret;

[Severity: Medium]
Does using pm_runtime_put_noidle() here leave the hardware permanently
powered on during a probe failure?

Since devres cleanup will invoke pm_runtime_disable() and cancel any pending
PM operations, using put_noidle instead of put_sync_suspend() drops the usage
count but doesn't schedule an idle check.

[ ... ]

> diff --git a/drivers/gpu/drm/panthor/arbitration/panthor_partition_control.c b/drivers/gpu/drm/panthor/arbitration/panthor_partition_control.c
> new file mode 100644
> index 0000000000000..e6fbf5e58b51a
> --- /dev/null
> +++ b/drivers/gpu/drm/panthor/arbitration/panthor_partition_control.c

[ ... ]

> +static int partition_state_wait(struct panthor_partition_control *pc, u32 state)
> +{
> +	u32 partition_state;
> +
> +	return read_poll_timeout_atomic(partition_state_get, partition_state,
> +					partition_state == state,
> +					PART_REG_POLL_SLEEP_US,
> +					PART_STATE_TRANSITION_TIMEOUT_US,
> +					false, pc);
> +}

[Severity: High]
Can read_poll_timeout_atomic() trigger CPU soft lockups if it busy-waits for
up to 5 seconds?

The PART_STATE_TRANSITION_TIMEOUT_US macro is set to 5,000,000 (5 seconds).
The atomic variant disables preemption and uses udelay(). Since callers run
in a sleepable context, should this use read_poll_timeout() instead?

[ ... ]

> +static int window_close(struct panthor_partition_control *pc)
> +{
> +	/* Partition already closed. */
> +	if (partition_state_get(pc) == PART_STATE_RESET)
> +		return 1;
> +
> +	guard(spinlock_irqsave)(&pc->lock);

[Severity: Medium]
Is there a time-of-check to time-of-use (TOCTOU) race here since the
hardware state is checked before the pc->lock is acquired?

[ ... ]

> +static int window_open(struct panthor_partition_control *pc, u8 aw_id)
> +{
> +	if (aw_id >= AM_ARB_MAX_AW_COUNT)
> +		return -EINVAL;
> +
> +	if (partition_state_get(pc) == PART_STATE_WINDOW_OPEN) {
> +		u8 cur_aw = partition_aw_get(pc);
> +
> +		if (cur_aw == aw_id)
> +			return 0;
> +
> +		dev_warn(pc->dev,
> +			 "%s: OPEN_WINDOW(%u): Already opened for aw=%u, state=%u. Closing...",
> +			 pc->name, aw_id, cur_aw, partition_state_get(pc));
> +
> +		window_close(pc);
> +	}
> +
> +	guard(spinlock_irqsave)(&pc->lock);

[Severity: Medium]
Similar to window_close(), we check the hardware state locklessly before
acquiring pc->lock. Can concurrent calls observe the state incorrectly?

> +
> +	gpu_write(pc->iomem, AM_PART_COMMAND,
> +		  AM_PART_SET_COMMAND(PART_CMD_OPEN_WINDOW) | AM_PART_SET_WINDOW(aw_id));

[Severity: Medium]
Does window_close() ensure the hardware has reached PART_STATE_RESET before
we issue the OPEN_WINDOW command here?

If window_close() asynchronously processes the close command, sending an open
command immediately to the exact same register might create a race condition,
potentially causing a PART_INVALID_COMMAND fault.

[ ... ]

> +static irqreturn_t partition_irq_raw_handler(int irq, void *data)
> +{
> +	struct panthor_partition_control *pc = data;
> +	u32 status;
> +
> +	status = gpu_read(pc->iomem, AM_PART_IRQ_STATUS);
> +	if (!status)
> +		return IRQ_NONE;

[Severity: High]
Since this handler is registered with IRQF_SHARED, could reading from the
hardware register without Runtime PM validation cause issues?

Other devices on the same interrupt line can trigger this handler. If the
device is runtime-suspended, this unconditional read could result in a bus
fault or return garbage data. Should this use pm_runtime_get_if_active()
first?

[ ... ]

> +static int partition_control_init(struct panthor_arbitration *adev,
> +				   const struct fwnode_handle *child)
> +{

[ ... ]

> +	pc = devm_kzalloc(dev, sizeof(*pc), GFP_KERNEL);
> +	if (!pc)
> +		return -ENOMEM;
> +
> +	name = devm_kasprintf(dev, GFP_KERNEL, "pc%d", res.id);
> +
> +	iomem = devm_ioremap_resource(dev, &res.res);

[Severity: Low]
Is there a missing NULL check for the name allocation here?

If devm_kasprintf() fails, name will be NULL, which is later passed to
another devm_kasprintf() for the IRQ name.

[ ... ]

> +	irqdata = irq_get_irq_data(irq);
> +	if (irqdata)
> +		irq_flags = irqd_get_trigger_type(irqdata);
> +
> +	ret = devm_request_irq(
> +		dev, irq, partition_irq_raw_handler, irq_flags | IRQF_SHARED,
> +		devm_kasprintf(dev, GFP_KERNEL, "panthor-%s-irq", name), pc);
> +	if (ret)
> +		return ret;

[Severity: High]
The irq is requested here, but it doesn't seem to be saved into pc->irq.

Without storing it, panthor_partition_control_suspend() cannot call
synchronize_irq() during power down, which risks suspending the hardware
while an interrupt is mid-flight.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260922204535.2850094-1-karunika.choo@arm.com?part=13

  reply	other threads:[~2026-09-22 20:57 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 20:44 [PATCH v1 00/27] drm/panthor: Add Mali v15 virtualization support Karunika Choo
2026-09-22 20:44 ` [PATCH v1 01/27] drm/panthor: Ignore -EOPNOTSUPP for shader-present nvmem lookup Karunika Choo
2026-09-22 20:44 ` [PATCH v1 02/27] drm/panthor: Move register access helpers out of panthor_device.h Karunika Choo
2026-09-22 20:54   ` sashiko-bot
2026-09-22 20:44 ` [PATCH v1 03/27] drm/panthor: Parse and store GPU_ID fields Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-22 20:44 ` [PATCH v1 04/27] drm/panthor: Add 64-bit GPU_ID decoding for v15 GPUs Karunika Choo
2026-09-22 21:01   ` sashiko-bot
2026-09-22 23:23   ` Deborah Brouwer
2026-09-22 20:44 ` [PATCH v1 05/27] drm/panthor: Move register base offsets to the HW description Karunika Choo
2026-09-22 20:45 ` [PATCH v1 06/27] drm/panthor: Derive MMU AS register addresses from base and stride Karunika Choo
2026-09-22 21:00   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 07/27] dt-bindings: gpu: mali-valhall-csf: Add Mali Gen5 AM compatible Karunika Choo
2026-09-28 10:02   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 08/27] drm/panthor: Add Mali v15 hardware support Karunika Choo
2026-09-22 20:58   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 09/27] drm/panthor: Skip devfreq when no OPP table is present Karunika Choo
2026-09-22 20:45 ` [PATCH v1 10/27] dt-bindings: gpu: panthor: Document panthor-system bindings Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-28 10:05   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 11/27] drm/panthor: Add AM_SYSTEM platform driver Karunika Choo
2026-09-22 20:59   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 12/27] dt-bindings: gpu: panthor: Document panthor-arbitration bindings Karunika Choo
2026-09-22 20:59   ` sashiko-bot
2026-09-28 10:06   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 13/27] drm/panthor: Add AM_PARTITION_CONTROL support Karunika Choo
2026-09-22 20:57   ` sashiko-bot [this message]
2026-09-22 20:45 ` [PATCH v1 14/27] drm/panthor: Add AM message helpers Karunika Choo
2026-09-22 20:58   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 15/27] drm/panthor: Add AM_RESOURCE_GROUP support Karunika Choo
2026-09-22 20:56   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 16/27] drm/panthor: Add arbitration scheduler Karunika Choo
2026-09-22 21:00   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 17/27] drm/panthor: Route arbitration events Karunika Choo
2026-09-22 21:04   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 18/27] dt-bindings: gpu: panthor: Document AW assignment DT property Karunika Choo
2026-09-22 20:57   ` sashiko-bot
2026-09-28 10:06   ` Krzysztof Kozlowski
2026-09-22 20:45 ` [PATCH v1 19/27] drm/panthor: Add AW assignment tracking Karunika Choo
2026-09-22 20:45 ` [PATCH v1 20/27] drm/panthor: Handle partition control INVALID_COMMAND interrupt Karunika Choo
2026-09-22 21:04   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 21/27] drm/panthor: Request AW to yield GPU access on idle Karunika Choo
2026-09-22 21:07   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 22/27] drm/panthor: Add access-window support Karunika Choo
2026-09-22 21:05   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 23/27] drm/panthor: Synchronize HW component PM transitions Karunika Choo
2026-09-22 20:45 ` [PATCH v1 24/27] drm/panthor: Route HW component PM through access windows Karunika Choo
2026-09-22 21:06   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 25/27] drm/panthor: Tolerate access-window loss during HW waits Karunika Choo
2026-09-22 21:14   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 26/27] drm/panthor: Prevent missed post-yield cleanup due to reset Karunika Choo
2026-09-22 21:12   ` sashiko-bot
2026-09-22 20:45 ` [PATCH v1 27/27] drm/panthor: Release GPU access immediately for out-of-band grants Karunika Choo
2026-09-22 21:06   ` sashiko-bot

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922205756.6934D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=karunika.choo@arm.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox