Intel-XE Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Matthew Brost" <matthew.brost@intel.com>
Cc: intel-xe@lists.freedesktop.org
Subject: Re: [PATCH v7 19/24] drm/xe: Add ULLS migration job support to migration layer
Date: Fri, 25 Sep 2026 06:34:11 +0000	[thread overview]
Message-ID: <20260925063412.61D2D1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260925045320.1325860-20-matthew.brost@intel.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/xe: Missing ULLS_EXIT in teardown leaves hardware parked on freed memory
--

commit 81f7dc64bc0d604133ac8c3a1f3ec0fd0a9dd8a1
Author: Matthew Brost <matthew.brost@intel.com>

drm/xe: Add ULLS migration job support to migration layer

Add function to enter ULLS mode for migration job and delayed worker to
exit (power saving). ULLS mode expected to entered upon page fault or
SVM prefetch. ULLS mode exit delay is currently set to 5ms.

> diff --git a/drivers/gpu/drm/xe/xe_migrate.c b/drivers/gpu/drm/xe/xe_migrate.c
> index 471ae5741836e..d7d13a25cdb91 100644
> --- a/drivers/gpu/drm/xe/xe_migrate.c
> +++ b/drivers/gpu/drm/xe/xe_migrate.c
[ ... ]
> @@ -95,9 +105,30 @@ struct xe_migrate {
>   */
>  #define MAX_PTE_PER_SDI 0x1FEU
>  
> +static bool xe_migrate_ulls_enabled(struct xe_migrate *m)
> +{
> +	lockdep_assert_held(&m->job_mutex);
> +	return m->ulls.enabled;
> +}
> +
> +static void xe_migrate_ulls_toggle_enable(struct xe_migrate *m, bool enabled)
> +{
> +	lockdep_assert_held(&m->job_mutex);
> +	m->ulls.enabled = enabled;
> +}
> +
>  static void xe_migrate_fini(void *arg)
>  {
>  	struct xe_migrate *m = arg;
> +	struct xe_device *xe = tile_to_xe(m->tile);
> +
> +	disable_delayed_work_sync(&m->ulls.exit_work);
> +	scoped_guard(mutex, &m->job_mutex) {
> +		if (xe_migrate_ulls_enabled(m)) {
> +			xe_pm_runtime_put(xe);
> +			xe_migrate_ulls_toggle_enable(m, false);

[Severity: High]
Does this missing ULLS_EXIT in the teardown sequence leave the hardware
parked on freed memory?

During driver unbind or probe failure in xe_migrate_fini(), if ULLS mode is
currently active (for example, within 5ms of a recent migration job), the
reserved hardware engine is actively spinning in a MI_SEMAPHORE_WAIT loop.

This teardown path cancels exit_work and clears the ULLS enabled flag, but
fails to push the ULLS_EXIT job or explicitly kill the queue. It then
proceeds to call xe_exec_queue_put() and free the page tables. Because
xe_exec_queue_kill() is never called, GuC is never instructed to preempt
and deregister the context.

Can this regression leave the hardware engine actively executing from the
ring buffer memory while the host frees it, potentially leading to IOMMU CAT
faults, GPU hangs, or host memory corruption?

> +		}
> +	}
>  
>  	xe_vm_lock(m->q->vm, false);
>  	xe_bo_unpin(m->pt_bo);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260925045320.1325860-1-matthew.brost@intel.com?part=19

  reply	other threads:[~2026-09-25  6:34 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-25  4:52 [PATCH v7 00/24] CPU binds and ULLS on migration queue Matthew Brost
2026-09-25  4:52 ` [PATCH v7 01/24] drm/xe: reference VM from PT BOs Matthew Brost
2026-09-25 12:00   ` Francois Dugast
2026-09-25 16:10     ` Matthew Brost
2026-09-25  4:52 ` [PATCH v7 02/24] drm/xe: Drop struct xe_migrate_pt_update argument from populate/clear vfuns Matthew Brost
2026-09-25  4:52 ` [PATCH v7 03/24] drm/xe: Add xe_migrate_update_pgtables_cpu_execute helper Matthew Brost
2026-09-25  4:53 ` [PATCH v7 04/24] drm/xe: Decouple exec queue idle check from LRC Matthew Brost
2026-09-25  4:53 ` [PATCH v7 05/24] drm/xe: Add job count to GuC exec queue snapshot Matthew Brost
2026-09-25  4:53 ` [PATCH v7 06/24] drm/xe: Update xe_bo_put_deferred arguments to include writeback flag Matthew Brost
2026-09-25  4:53 ` [PATCH v7 07/24] drm/xe: Update scheduler job layer to support PT jobs Matthew Brost
2026-09-25 11:23   ` Francois Dugast
2026-09-25  4:53 ` [PATCH v7 08/24] drm/xe: Add helpers to access PT ops Matthew Brost
2026-09-25  4:53 ` [PATCH v7 09/24] drm/xe: Add struct xe_pt_job_ops Matthew Brost
2026-09-25  4:53 ` [PATCH v7 10/24] drm/xe: Update GuC submission backend to run PT jobs Matthew Brost
2026-09-25  5:39   ` sashiko-bot
2026-09-25  5:58     ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 11/24] drm/xe: Store level in struct xe_vm_pgtable_update Matthew Brost
2026-09-25  4:53 ` [PATCH v7 12/24] drm/xe: Don't use migrate exec queue for page fault binds Matthew Brost
2026-09-25  4:53 ` [PATCH v7 13/24] drm/xe: Enable CPU binds for jobs Matthew Brost
2026-09-25  6:03   ` sashiko-bot
2026-09-25  6:54     ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 14/24] drm/xe: Remove unused arguments from xe_migrate_pt_update_ops Matthew Brost
2026-09-25  4:53 ` [PATCH v7 15/24] drm/xe: Make bind queues operate cross-tile Matthew Brost
2026-09-25  4:53 ` [PATCH v7 16/24] drm/xe: Add CPU bind layer Matthew Brost
2026-09-25  4:53 ` [PATCH v7 17/24] drm/xe: Add device flag to enable PT mirroring across tiles Matthew Brost
2026-09-25  6:25   ` sashiko-bot
2026-09-25  7:21     ` Matthew Brost
2026-09-25  9:51   ` Francois Dugast
2026-09-25  4:53 ` [PATCH v7 18/24] drm/xe: Add ULLS support to LRC Matthew Brost
2026-09-25  4:53 ` [PATCH v7 19/24] drm/xe: Add ULLS migration job support to migration layer Matthew Brost
2026-09-25  6:34   ` sashiko-bot [this message]
2026-09-25  7:17     ` Matthew Brost
2026-09-25 20:10       ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 20/24] drm/xe: Add ULLS migration job support to ring ops Matthew Brost
2026-09-25  6:38   ` sashiko-bot
2026-09-25  7:02     ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 21/24] drm/xe: Add ULLS migration job support to GuC submission Matthew Brost
2026-09-25  6:48   ` sashiko-bot
2026-09-25  7:08     ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 22/24] drm/xe: Enter ULLS for migration jobs upon page fault or SVM prefetch Matthew Brost
2026-09-25 17:49   ` Maarten Lankhorst
2026-09-25 18:17     ` Matthew Brost
2026-09-25 18:26       ` Maarten Lankhorst
2026-09-25 19:38         ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 23/24] drm/xe: add migrate ULLS period configfs attribute Matthew Brost
2026-09-25  6:51   ` sashiko-bot
2026-09-25  7:08     ` Matthew Brost
2026-09-25  4:53 ` [PATCH v7 24/24] drm/xe: Document ULLS for migration jobs Matthew Brost
2026-09-25  5:02 ` ✗ CI.checkpatch: warning for CPU binds and ULLS on migration queue (rev9) Patchwork
2026-09-25  5:04 ` ✓ CI.KUnit: success " Patchwork
2026-09-25  5:47 ` ✓ Xe.CI.BAT: " Patchwork
2026-09-25 15:05 ` ✗ Xe.CI.FULL: failure " Patchwork
2026-09-25 16:01   ` Matthew Brost
2026-09-25 18:08 ` [PATCH v7 00/24] CPU binds and ULLS on migration queue Maarten Lankhorst

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260925063412.61D2D1F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=intel-xe@lists.freedesktop.org \
    --cc=matthew.brost@intel.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox