From: sashiko-bot@kernel.org
To: "Shameer Kolothum" <skolothumtho@nvidia.com>
Cc: linux-pci@vger.kernel.org, kvm@vger.kernel.org
Subject: Re: [RFC PATCH v2 12/16] vfio/pci: Restore device state from slot_reset()
Date: Tue, 29 Sep 2026 17:50:25 +0000 [thread overview]
Message-ID: <20260929175026.3494C1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929173305.204856-13-skolothumtho@nvidia.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] pci: rwsem ABBA/starvation deadlock in AER slot reset via pci_set_power_state
--
commit 6afd5feca9e35f2a1b59b9d3719fa0d9dbdec2ca
Author: Shameer Kolothum <skolothumtho@nvidia.com>
vfio/pci: Restore device state from slot_reset()
A host reset clears device configuration. Add slot_reset() to restore
the state saved at open before tearing down interrupts. MSI-X shutdown
requires the restored BARs to access its table.
> diff --git a/drivers/vfio/pci/vfio_pci_core.c b/drivers/vfio/pci/vfio_pci_core.c
> index 667c5813f6c7c..a7b7499e071c1 100644
> --- a/drivers/vfio/pci/vfio_pci_core.c
> +++ b/drivers/vfio/pci/vfio_pci_core.c
[ ... ]
> +/* Caller holds memory_lock. Discard the pre-reset PM snapshot. */
> +static int vfio_pci_recovery_restore_state(struct vfio_pci_core_device *vdev)
> +{
> + struct pci_dev *pdev = vdev->pdev;
> + int ret;
> +
> + if (!vdev->pci_saved_state)
> + return -ENODATA;
> + ret = pci_load_saved_state(pdev, vdev->pci_saved_state);
> + if (ret)
> + return ret;
> +
> + kfree(vdev->pm_save);
> + vdev->pm_save = NULL;
> + ret = pci_set_power_state(pdev, PCI_D0);
[Severity: High]
Can this introduce an ABBA starvation deadlock with pci_bus_sem?
During an AER slot reset, pcie_do_recovery() already holds a read lock on
pci_bus_sem via pci_walk_bus(). The AER framework then calls
vfio_pci_core_aer_slot_reset(), which calls into this function and
attempts to restore the device to D0 by calling pci_set_power_state().
Internally, this transitions ASPM via pcie_aspm_pm_state_change(), which
unconditionally executes a nested down_read(&pci_bus_sem) because the
locked parameter is passed as false:
drivers/pci/pcie/aspm.c:pcie_aspm_pm_state_change() {
...
if (!locked)
down_read(&pci_bus_sem);
...
}
If a concurrent thread, such as PCI hotplug or another subsystem, attempts
to acquire down_write(&pci_bus_sem) between these two read lock
acquisitions, the fair rwsem implementation will queue the writer. The
nested down_read() will then block waiting for the writer, creating an
unresolvable starvation ABBA deadlock.
As noted in the commit message, the final patches in this series do not
appear to address or resolve this bug. Are there plans to address this
deadlock before merging?
> + if (ret)
> + return ret;
> +
> + vfio_pci_recovery_mask_saved_intx(vdev);
> + pci_restore_state(pdev);
> + return 0;
> +}
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929173305.204856-1-skolothumtho@nvidia.com?part=12
next prev parent reply other threads:[~2026-09-29 17:50 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 17:32 [RFC PATCH v2 00/16] vfio/pci: Handle PCI error recovery and report state to userspace Shameer Kolothum
2026-09-29 17:32 ` [RFC PATCH v2 01/16] vfio/pci: Add a device access gate Shameer Kolothum
2026-09-29 17:48 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 02/16] vfio/pci: Gate config space access Shameer Kolothum
2026-09-29 17:52 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 03/16] vfio/pci: Buffer ROM reads before copying to userspace Shameer Kolothum
2026-09-29 17:49 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 04/16] vfio/pci: Gate BAR and ROM access Shameer Kolothum
2026-09-29 17:41 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 05/16] vfio/pci: Fail BAR faults while access is blocked Shameer Kolothum
2026-09-29 17:45 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 06/16] vfio/pci: Gate interrupt configuration Shameer Kolothum
2026-09-29 17:43 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 07/16] vfio/pci: Gate function reset and runtime power management Shameer Kolothum
2026-09-29 17:48 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 08/16] vfio/pci: Gate device information queries and DMA-BUF export Shameer Kolothum
2026-09-29 17:44 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 09/16] vfio/pci: Add PCI error recovery state Shameer Kolothum
2026-09-29 17:44 ` sashiko-bot
2026-09-29 17:32 ` [RFC PATCH v2 10/16] vfio/pci: Quiesce INTx while access is blocked Shameer Kolothum
2026-09-29 17:45 ` sashiko-bot
2026-09-29 17:33 ` [RFC PATCH v2 11/16] vfio/pci: Add INTx recovery start and finish helpers Shameer Kolothum
2026-09-29 17:44 ` sashiko-bot
2026-09-29 17:33 ` [RFC PATCH v2 12/16] vfio/pci: Restore device state from slot_reset() Shameer Kolothum
2026-09-29 17:50 ` sashiko-bot [this message]
2026-09-29 17:33 ` [RFC PATCH v2 13/16] vfio/pci: Complete recovery in resume() Shameer Kolothum
2026-09-29 17:51 ` sashiko-bot
2026-09-29 17:33 ` [RFC PATCH v2 14/16] vfio/pci: Block device access during host recovery Shameer Kolothum
2026-09-29 17:51 ` sashiko-bot
2026-09-29 17:33 ` [RFC PATCH v2 15/16] vfio/pci: Add VFIO_DEVICE_FEATURE_PCI_ERROR_RECOVERY Shameer Kolothum
2026-09-29 17:48 ` sashiko-bot
2026-09-29 17:33 ` [RFC PATCH v2 16/16] vfio/pci: Enable host PCI error recovery for vfio-pci Shameer Kolothum
2026-09-29 17:49 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929175026.3494C1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=kvm@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=skolothumtho@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox