From: sashiko-bot@kernel.org
To: "Michael J. Ruhl" <michael.j.ruhl@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v3 09/10] drm/xe/vsec: Support late bind fw information
Date: Mon, 24 Aug 2026 16:36:56 +0000 [thread overview]
Message-ID: <20260824163656.75BAC1F00A3A@smtp.kernel.org> (raw)
In-Reply-To: <20260824162317.2450380-21-michael.j.ruhl@intel.com>
Thank you for your contribution! Sashiko AI review found 3 potential issue(s) to consider:
New issues:
- [High] Registering devm resources from a delayed work that is cancelled via a devm action causes the devm resources to be leaked and outlive the driver binding, leading to a Use-After-Free.
- [High] Holding the DRM SRCU read lock while sleeping for up to 20 seconds blocks device hot-unplug and causes userspace tasks to hang unresponsively.
Pre-existing issues:
- [High] The PMT VSEC initialization does not restrict execution on Virtual Functions (VFs), violating the restriction on VF access to physical SOC controllers.
--
--- Patch [9]: [PATCH v3 09/10] drm/xe/vsec: Support late bind fw information ---
commit baf7715ba5240a405fca0471519228b0c43828df
Author: Michael J. Ruhl <michael.j.ruhl@intel.com>
drm/xe/vsec: Support late bind fw information
This commit updates the XE PMT probe to support late bind devices by
waiting for the appropriate firmware state before proceeding with
initialization. It introduces a delayed work queue to retry the probe
and pauses telemetry reads until the firmware is ready.
> diff --git a/drivers/gpu/drm/xe/xe_vsec.c b/drivers/gpu/drm/xe/xe_vsec.c
> index 578d59048b39c..edc20c24137ed 100644
> --- a/drivers/gpu/drm/xe/xe_vsec.c
> +++ b/drivers/gpu/drm/xe/xe_vsec.c
[ ... ]
> @@ -272,6 +282,56 @@ static int xe_guid_decode(u32 guid, int *index, u32 *offset)
[ ... ]
> +static bool wait_for_fw(struct xe_device *xe)
> +{
> + int retries = VSEC_LATE_BIND_RETRY; /* wait up to 20 secs */
> +
> + if (xe->info.platform != XE_CRESCENTISLAND)
> + return true;
> +
> + while (retries--) {
> + if (xe_is_oobmsm_fw_ready(xe))
> + return true;
> +
> + msleep(VSEC_LATE_BIND_DELAY_MSEC);
> + }
> +
> + drm_warn(&xe->drm, "Late Binding failed to complete\n");
> +
> + return false;
> +}
[ ... ]
> @@ -318,6 +378,11 @@ int xe_pmt_telem_read(struct device *dev, u32 guid, u64 *data, loff_t user_offse
[ ... ]
> if (!drm_dev_enter(&xe->drm, &idx))
> return -ENODEV;
[ ... ]
> + if (!wait_for_fw(xe)) {
> + ret = -ENODATA;
> + goto runtime_exit;
> + }
[Severity: High]
Does holding the DRM SRCU read lock while sleeping block device hot-unplug?
Earlier in xe_pmt_telem_read(), drm_dev_enter() is called, which acquires
the SRCU read lock. Inside this critical section, wait_for_fw() can sleep
for up to 20 seconds using msleep().
Could this uninterruptible sleep under SRCU prevent synchronize_srcu() from
completing during drm_dev_unplug(), causing a 20-second stall and leaving
user processes unkillable?
[ ... ]
> @@ -454,12 +532,44 @@ static enum xe_vsec get_platform_info(struct xe_device *xe)
[ ... ]
> +static void cri_late_bind_probe(struct xe_device *xe)
> +{
[ ... ]
> + info->priv_data = &xe_cri_pmt_cb;
> + xe->soc_remapper.set_telem_region(xe, CRI_IDX_TELEM_DISCOVERY);
> +
> + intel_vsec_register(dev, info);
> +}
> +
> +static void vsec_disable_late_bind_work(void *arg)
> +{
> + struct xe_device *xe = arg;
> +
> + /*
> + * If was work was cancelled while it was still pending, we need to
> + * take care of releasing the runtime reference
> + */
> + if (disable_delayed_work_sync(&xe->pmt.work))
> + xe_pm_runtime_put(xe);
> +}
[Severity: High]
Can this sequence leak devres resources and cause a use-after-free?
When the driver unbinds, devres_release_all() detaches existing resources
to a local list and executes them. vsec_disable_late_bind_work() is
registered as a devm action and runs during this process.
If vsec_disable_late_bind_work() blocks in disable_delayed_work_sync() while
the work queue is actively executing cri_late_bind_probe(), the work thread
will call intel_vsec_register(), which allocates and attaches new devm
resources.
Since devres_release_all() only processes its detached list, will these
newly added devres nodes be added to the empty devres head, leaving them
behind to outlive the driver?
[ ... ]
> @@ -467,30 +577,44 @@ void xe_vsec_init(struct xe_device *xe)
> {
> struct intel_vsec_platform_info *info;
> struct device *dev = xe->drm.dev;
> enum xe_vsec platform;
>
> platform = get_platform_info(xe);
> if (platform == XE_VSEC_UNKNOWN)
> - return;
> + return 0;
>
> info = &xe_vsec_info[platform];
> if (!info->headers)
> - return;
> + return 0;
[Severity: High]
This is a pre-existing issue, but does this initialization path lack an
IS_SRIOV_VF() guard before accessing physical SOC controllers?
If xe_vsec_init() is called during Virtual Function (VF) initialization, it
proceeds to access the SOC remapper and register the VSEC PMT auxiliary
device.
Since these are PF-only hardware resources, will accessing them from a VF
context result in hardware faults or MMIO timeouts?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260824162317.2450380-12-michael.j.ruhl@intel.com?part=9
next prev parent reply other threads:[~2026-08-24 16:36 UTC|newest]
Thread overview: 41+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 16:23 [PATCH v3 00/10] Crescent Island PMT support Michael J. Ruhl
2026-08-24 16:23 ` [PATCH v3 01/10] platform/x86/intel/pmt: complete pcidev to device update Michael J. Ruhl
2026-08-24 18:56 ` Rodrigo Vivi
2026-08-25 9:40 ` Ilpo Järvinen
2026-08-25 9:25 ` Ilpo Järvinen
2026-08-24 16:23 ` [PATCH v3 02/10] platform/x86/intel/pmt: Add register access callbacks Michael J. Ruhl
2026-08-24 16:36 ` sashiko-bot
2026-08-24 18:39 ` Ruhl, Michael J
2026-08-25 9:34 ` Ilpo Järvinen
2026-08-26 16:13 ` Ruhl, Michael J
2026-08-26 18:30 ` Ilpo Järvinen
2026-08-27 17:05 ` Ruhl, Michael J
2026-08-24 16:23 ` [PATCH v3 03/10] drm/xe/vsec: Protect against missing config Michael J. Ruhl
2026-08-24 16:36 ` sashiko-bot
2026-08-24 18:43 ` Ruhl, Michael J
2026-08-24 19:01 ` Rodrigo Vivi
2026-08-24 16:23 ` [PATCH v3 04/10] drm/xe/vsec: Use correct pm state get Michael J. Ruhl
2026-08-24 19:04 ` Rodrigo Vivi
2026-08-24 16:23 ` [PATCH v3 05/10] drm/xe/vsec: Support possible hotplug exit Michael J. Ruhl
2026-08-24 19:07 ` Rodrigo Vivi
2026-08-24 16:23 ` [PATCH v3 06/10] drm/xe/vsec: Support Crescent Island PMT Michael J. Ruhl
2026-08-24 16:33 ` sashiko-bot
2026-08-24 19:10 ` Rodrigo Vivi
2026-08-25 10:19 ` Ilpo Järvinen
2026-08-24 16:23 ` [PATCH v3 07/10] drm/xe/vsec: Crescent Island PMT decode Michael J. Ruhl
2026-08-24 16:35 ` sashiko-bot
2026-08-25 10:24 ` Ilpo Järvinen
2026-08-24 16:23 ` [PATCH v3 08/10] drm/xe/vsec: Crescent Island PMT callbacks Michael J. Ruhl
2026-08-24 16:37 ` sashiko-bot
2026-08-24 18:47 ` Ruhl, Michael J
2026-08-24 16:23 ` [PATCH v3 09/10] drm/xe/vsec: Support late bind fw information Michael J. Ruhl
2026-08-24 16:36 ` sashiko-bot [this message]
2026-08-24 19:15 ` Rodrigo Vivi
2026-08-26 13:45 ` Ruhl, Michael J
2026-08-25 10:01 ` Ilpo Järvinen
2026-08-24 16:23 ` [PATCH v3 10/10] drm/xe/vsec: Update PMT internal access for CRI Michael J. Ruhl
2026-08-24 19:18 ` Rodrigo Vivi
2026-08-25 10:16 ` Ilpo Järvinen
2026-08-25 6:44 ` ✓ CI.KUnit: success for Crescent Island PMT support (rev5) Patchwork
2026-08-25 7:29 ` ✓ Xe.CI.BAT: " Patchwork
2026-08-25 10:56 ` ✗ Xe.CI.FULL: failure " Patchwork
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260824163656.75BAC1F00A3A@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=michael.j.ruhl@intel.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox