From: Pranjal Shrivastava <praan@google.com>
To: Jason Gunthorpe <jgg@nvidia.com>
Cc: iommu@lists.linux.dev, Will Deacon <will@kernel.org>,
Joerg Roedel <joro@8bytes.org>,
Robin Murphy <robin.murphy@arm.com>,
Jason Gunthorpe <jgg@ziepe.ca>,
Mostafa Saleh <smostafa@google.com>,
Nicolin Chen <nicolinc@nvidia.com>,
Daniel Mentz <danielmentz@google.com>,
linux-arm-kernel@lists.infradead.org
Subject: Re: [PATCH v9 07/12] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions
Date: Tue, 25 Aug 2026 18:38:35 +0000 [thread overview]
Message-ID: <ao3hK8tdOPLvbpfK@google.com> (raw)
In-Reply-To: <178767577113.3356902.16348370784507904981.b4-review@b4>
On Tue, Aug 25, 2026 at 01:36:11PM -0300, Jason Gunthorpe wrote:
> > [ ... 52 lines skipped ... ]
> > while (!queue_has_space(&llq, n + sync)) {
> > local_irq_restore(flags);
> > +
> > + /* Avoid waiting for space if the SMMU is suspending */
> > + if (Q_STOP(READ_ONCE(cmdq->q.llq.prod)))
> > + return 0;
> > +
> > if (arm_smmu_cmdq_poll_until_not_full(smmu, cmdq, &llq))
> > dev_err_ratelimited(smmu->dev, "CMDQ timeout\n");
> > local_irq_save(flags);
>
> [Severity: Critical]
> Can this loop bypass the Q_STOP check if a suspend happens concurrently?
>
> If a thread enters the while loop because there's no space, and a concurrent
> task sets the CMDQ_PROD_STOP_FLAG while space becomes available:
>
> 1. arm_smmu_cmdq_poll_until_not_full() updates llq.val with the latest global
> state, which now includes the newly set STOP_FLAG in llq.prod.
> 2. The loop condition !queue_has_space(&llq, n + sync) now evaluates to false,
> causing the thread to exit the inner loop.
> 3. This bypasses the Q_STOP(READ_ONCE(cmdq->q.llq.prod)) check inside the
> loop, as well as the Q_STOP(llq.prod) check at the top of the do-while loop.
>
> The thread would then successfully cmpxchg the new producer index with the
> STOP_FLAG set.
>
> Make sense to me, having arm_smmu_cmdq_poll_until_not_full() reload
> the llq and then not loop again from the top skips the Q_STOP
> flag.
>
Right. I guess we should check the condition again after exiting the
loop or add the point of commitment to this space loop somehow. I'll
take care of this.
Thanks,
Praan
next prev parent reply other threads:[~2026-08-25 18:38 UTC|newest]
Thread overview: 39+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-28 21:09 [PATCH v9 00/12] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 01/12] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 17:35 ` Pranjal Shrivastava
2026-08-25 18:47 ` Nicolin Chen
2026-08-25 19:01 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 02/12] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 17:37 ` Pranjal Shrivastava
2026-08-25 18:20 ` Nicolin Chen
2026-08-25 18:57 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 03/12] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 04/12] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 05/12] iommu/arm-smmu-v3: Cache and restore MSI config Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:01 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 06/12] iommu/arm-smmu-v3: Handle gerror during suspend Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:06 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 07/12] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:38 ` Pranjal Shrivastava [this message]
2026-07-28 21:09 ` [PATCH v9 08/12] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:46 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 09/12] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-08-25 16:36 ` Jason Gunthorpe
2026-08-25 18:53 ` Pranjal Shrivastava
2026-08-25 20:17 ` Jason Gunthorpe
2026-08-26 11:51 ` Pranjal Shrivastava
2026-08-26 13:47 ` Jason Gunthorpe
2026-08-26 14:17 ` Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 10/12] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 11/12] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-07-28 21:09 ` [PATCH v9 12/12] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-08-25 13:33 ` [PATCH v9 00/12] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Jason Gunthorpe
2026-08-25 18:50 ` Pranjal Shrivastava
2026-08-25 20:14 ` Jason Gunthorpe
2026-08-26 11:55 ` Pranjal Shrivastava
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ao3hK8tdOPLvbpfK@google.com \
--to=praan@google.com \
--cc=danielmentz@google.com \
--cc=iommu@lists.linux.dev \
--cc=jgg@nvidia.com \
--cc=jgg@ziepe.ca \
--cc=joro@8bytes.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=nicolinc@nvidia.com \
--cc=robin.murphy@arm.com \
--cc=smostafa@google.com \
--cc=will@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox