From: Suzuki K Poulose <suzuki.poulose@arm.com>
To: sashiko-reviews@lists.linux.dev
Cc: Marc Zyngier <maz@kernel.org>,
kvm@vger.kernel.org, Oliver Upton <oupton@kernel.org>,
kvmarm@lists.linux.dev
Subject: Re: [PATCH v19 4/7] firmware: arm_rmm: Add support for SRO
Date: Fri, 25 Sep 2026 00:18:49 +0100 [thread overview]
Message-ID: <6a6eef51-a2c0-47cf-98d8-526ab8ebf963@arm.com> (raw)
In-Reply-To: <20260924140847.AFA411F000FF@smtp.kernel.org>
On 24/09/2026 15:08, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] arm_rmm: SRO cancellation loop prematurely exits, leaving operations suspended
> --
>
> commit 95084224252b24a8efc8b9db3fa71d3058e8d228
> Author: Steven Price <steven.price@arm.com>
>
> firmware: arm_rmm: Add support for SRO
>
> RMM v2.0 introduces the concept of "Stateful RMI Operations" (SRO). This
> commit adds support for executing SROs, including donating and reclaiming
> memory dynamically as requested by the RMM. It also implements cancellation
> support for these operations.
>
>> diff --git a/drivers/firmware/arm_rmm/rmi.c b/drivers/firmware/arm_rmm/rmi.c
>> index c9ea964fd9081..035f21d3f26b6 100644
>> --- a/drivers/firmware/arm_rmm/rmi.c
>> +++ b/drivers/firmware/arm_rmm/rmi.c
>
> [ ... ]
>
>> + if (ret) {
>> + /*
>> + * All memory donating SROs must be cancellable. So a
>> + * failure in memory allocation shouldn't be an issue.
>> + * However, if we encounter a random failure (e.g.,
>> + * buggy RMM), don't loop forever, just give up.
>> + */
>> + if (WARN_ON_ONCE(!can_cancel))
>> + return ret;
>> + /*
>> + * If we have already cancelled, and came back here due
>> + * to an error in MEMREQ, then there is no point
>> + * in going in loops.
>> + */
>> + if (WARN_ON_ONCE(cancelled))
>> + break;
>> + rmi_op_cancel(sro_handle, regs);
>> + cancelled = true;
>> +
>> + if (WARN_ON_ONCE(RMI_RESULT_STATUS(regs->a0) != RMI_INCOMPLETE))
>> + return ret;
>
> [Severity: High]
> Does this error path permanently leave the SRO suspended in the RMM?
>
> The commit message notes that after requesting cancellation, the host must
> still "continue the operation until it has completed (otherwise the incomplete
> operation may cause future RMM operations to fail)".
>
> However, when rmi_op_cancel() issues SMC_RMI_OP_CANCEL, it returns RMI_SUCCESS
This is wrong. RMI_OP_CANCEL returns RMI_INCOMPLETE. It doesn't return
RMI_SUCCESS. See Section B4.3.2.5 Cancelling an SRO (DEN0137 Beta3)
Rules RVLNV and GGSTJ covers both cases (with or without memory
reclamation). Both cases end up in RMI_INCOMPLETE, and the
RMI_OP_CONTINUE must be invoked to drive the SRO handle to inactive.
> to acknowledge the cancel request, overwriting regs->a0. As a result,
> RMI_RESULT_STATUS(regs->a0) != RMI_INCOMPLETE evaluates to true, triggering
> this WARN_ON_ONCE and causing an immediate return. The host fails to issue the
> required SMC_RMI_OP_CONTINUE calls to drive the cancellation to completion.
>
>> + }
>> + }
>> +
>> + if (cancelled)
>> + return -ECANCELED;
>> +
>> + return regs->a0;
>> +}
>> +EXPORT_SYMBOL_GPL(rmi_sro_memxfer_execute);
>
> [ ... ]
>
>> +long rmi_sro_execute(struct arm_smccc_1_2_regs *regs)
>> +{
>> + bool cancelled = false;
>> + unsigned long sro_handle = regs->a1;
>> +
>> + rmi_smccc_invoke(regs);
>> +
>> + sro_handle = regs->a1;
>> + while (RMI_RESULT_STATUS(regs->a0) == RMI_INCOMPLETE) {
>> + bool can_cancel = RMI_RESULT_CAN_CANCEL(regs->a0) == RMI_OP_CAN_CANCEL;
>> +
>> + switch (RMI_RESULT_MEMREQ(regs->a0)) {
>> + case RMI_OP_MEM_REQ_NONE:
>> + rmi_op_continue(sro_handle, RMI_CONTINUE_KEEP_GOING,
>> + regs);
>> + break;
>> + default:
>> + WARN_ON_ONCE(1);
>> + if (!can_cancel)
>> + return regs->a0;
>> + /*
>> + * We can't get here normally, but handle this anyway
>> + * for a buggy RMM implementation.
>> + */
>> + if (cancelled)
>> + return -ECANCELED;
>> + rmi_op_cancel(sro_handle, regs);
>> + cancelled = true;
>> + }
>> + }
>
> [Severity: High]
> Does this loop terminate prematurely without continuing the cancelled SRO?
>
> Similar to rmi_sro_memxfer_execute() above, after rmi_op_cancel() updates
> regs->a0 to RMI_SUCCESS, the while loop condition
> (RMI_RESULT_STATUS(regs->a0) == RMI_INCOMPLETE) evaluates to false. The
> function exits immediately without calling SMC_RMI_OP_CONTINUE to complete
> the cancellation.
As above, this is incorrect.
Cheers
Suzuki
next prev parent reply other threads:[~2026-09-24 23:18 UTC|newest]
Thread overview: 64+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-24 13:51 [PATCH v19 0/7] firmware: arm_rmm: Add RMM v2.0 base RMI support Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 1/7] firmware: arm_rmm: Add SMC definitions for calling the RMM Suzuki K Poulose
2026-09-24 16:57 ` Jonathan Cameron
2026-09-24 22:15 ` Suzuki K Poulose
2026-09-24 17:05 ` Ackerley Tng
2026-09-24 22:49 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 2/7] firmware: arm_rmm: Check for RMI support at init Suzuki K Poulose
2026-09-24 14:00 ` sashiko-bot
2026-09-24 16:58 ` Jonathan Cameron
2026-09-25 0:00 ` Gavin Shan
2026-09-25 8:51 ` Suzuki K Poulose
2026-09-25 5:43 ` Gavin Shan
2026-09-25 8:50 ` Suzuki K Poulose
2026-09-25 10:42 ` Catalin Marinas
2026-09-25 15:23 ` Suzuki K Poulose
2026-09-27 9:29 ` Marc Zyngier
2026-09-28 8:05 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 3/7] firmware: arm_rmm: Configure the RMM with the host's page size Suzuki K Poulose
2026-09-24 17:03 ` Jonathan Cameron
[not found] ` <d4b768e5-c942-43cf-aea2-c266a8bab353@oss.qualcomm.com>
2026-09-25 14:56 ` Suzuki K Poulose
2026-09-26 13:38 ` Venkata Rao Kakani
2026-09-25 0:03 ` Gavin Shan
2026-09-24 13:51 ` [PATCH v19 4/7] firmware: arm_rmm: Add support for SRO Suzuki K Poulose
2026-09-24 14:08 ` sashiko-bot
2026-09-24 23:18 ` Suzuki K Poulose [this message]
2026-09-24 19:13 ` Jonathan Cameron
2026-09-24 23:10 ` Suzuki K Poulose
2026-09-25 5:24 ` Gavin Shan
2026-09-29 12:52 ` Suzuki K Poulose
2026-09-25 11:50 ` Catalin Marinas
2026-09-25 15:11 ` Suzuki K Poulose
2026-09-28 9:28 ` Catalin Marinas
2026-09-28 10:13 ` Suzuki K Poulose
2026-09-28 17:28 ` Catalin Marinas
2026-09-28 20:45 ` Suzuki K Poulose
2026-09-24 13:51 ` [PATCH v19 5/7] firmware: arm_rmm: Activate the RMM Suzuki K Poulose
2026-09-25 12:17 ` Catalin Marinas
2026-09-25 15:02 ` Suzuki K Poulose
2026-09-25 15:34 ` Alper Gun
2026-09-25 16:42 ` Catalin Marinas
2026-09-25 17:50 ` Suzuki K Poulose
2026-09-28 9:08 ` Suzuki K Poulose
2026-09-28 13:55 ` Suzuki K Poulose
2026-09-28 18:01 ` Catalin Marinas
2026-09-28 18:28 ` Suzuki K Poulose
2026-09-29 11:15 ` Catalin Marinas
2026-09-24 13:52 ` [PATCH v19 6/7] firmware: arm_rmm: Ensure the RMM has GPT entries for memory Suzuki K Poulose
2026-09-24 21:38 ` Jonathan Cameron
2026-09-24 23:30 ` Suzuki K Poulose
2026-09-25 15:30 ` Jonathan Cameron
2026-09-25 0:07 ` Gavin Shan
2026-09-29 11:01 ` Catalin Marinas
2026-09-29 12:15 ` Suzuki K Poulose
2026-09-29 22:17 ` Shanker Donthineni
2026-09-29 22:25 ` Suzuki K Poulose
2026-09-29 22:29 ` Shanker Donthineni
2026-09-30 8:17 ` Suzuki K Poulose
2026-09-24 13:52 ` [PATCH v19 7/7] firmware: arm_rmm: Add wrappers for Realm related RMI commands Suzuki K Poulose
2026-09-25 11:56 ` Catalin Marinas
2026-09-29 12:15 ` Suzuki K Poulose
2026-09-25 6:29 ` [PATCH v19 0/7] firmware: arm_rmm: Add RMM v2.0 base RMI support Gavin Shan
2026-09-25 9:03 ` Suzuki K Poulose
2026-09-29 10:50 ` Catalin Marinas
2026-09-29 12:14 ` Suzuki K Poulose
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a6eef51-a2c0-47cf-98d8-526ab8ebf963@arm.com \
--to=suzuki.poulose@arm.com \
--cc=kvm@vger.kernel.org \
--cc=kvmarm@lists.linux.dev \
--cc=maz@kernel.org \
--cc=oupton@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox