From: sashiko-bot@kernel.org
To: alucerop@amd.com
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v1 1/4] driver core: Rely on supplier driver binding at link creation
Date: Tue, 22 Sep 2026 17:56:14 +0000 [thread overview]
Message-ID: <20260922175614.AE72D1F00899@smtp.kernel.org> (raw)
In-Reply-To: <20260921191239.4249-2-alucerop@amd.com>
Thank you for your contribution! Sashiko AI review found 4 potential issue(s) to consider:
- [High] driver core: AB-BA deadlock in device_link_add and device_release_driver_internal
- [High] driver core: fw_devlink broken by rejecting unbound suppliers in device_link_add
- [Low] driver core: mixed goto cleanup and scoped_guard violates cleanup guidelines
- [Low] driver core: dead code in PM runtime check due to device_is_bound
--
commit 1f69a7873c55c75da1b5f2ed9898c41c813921cc
Author: Alejandro Lucero <alucerop@amd.com>
driver core: Rely on supplier driver binding at link creation
This commit modifies device link creation to rely on supplier driver binding.
It evaluates device_is_bound() for the supplier upfront and conditionally
checks PM initialization based on the DL_FLAG_PM_RUNTIME flag.
> diff --git a/drivers/base/core.c b/drivers/base/core.c
> index 4c0c373998a19..eb6d87e35d76c 100644
> --- a/drivers/base/core.c
> +++ b/drivers/base/core.c
> @@ -834,15 +834,26 @@ struct device_link *device_link_add(struct device *consumer,
> device_pm_lock();
>
> /*
> - * If the supplier has not been fully registered yet or there is a
> - * reverse (non-SYNC_STATE_ONLY) dependency between the consumer and
> - * the supplier already in the graph, return NULL. If the link is a
> - * SYNC_STATE_ONLY link, we don't check for reverse dependencies
> - * because it only affects sync_state() callbacks.
> + * If the supplier has not been fully registered yet with a driver
> + * return NULL.
> */
> - if (!device_pm_initialized(supplier)
> - || (!(flags & DL_FLAG_SYNC_STATE_ONLY) &&
> - device_is_dependent(consumer, supplier))) {
> + scoped_guard(device, supplier) {
[Severity: High]
Can this lead to an AB-BA deadlock between device_links_write_lock() and
the supplier device lock?
The device_link_add() function holds device_links_write_lock() before
acquiring the supplier's device lock via scoped_guard(device, supplier).
However, during device unbinding, device_release_driver_internal() takes the
device lock via __device_driver_lock() first. It then calls
__device_release_driver() which invokes device_links_driver_cleanup(),
attempting to acquire device_links_write_lock().
Could this result in a lock inversion?
> + if (!device_is_bound(supplier)) {
[Severity: High]
Does rejecting unbound suppliers break fw_devlink's dependency tracking?
The fw_devlink_create_devlink() routine actively tries to create dormant
links to supplier devices before they are probed or bound to a driver. This
ensures proper probe ordering.
Rejecting these links unconditionally because device_is_bound() requires a
driver to be attached appears to break deferred probing guarantees.
Should we permit links when the supplier is not bound yet?
> + link = NULL;
> + goto out;
[Severity: Low]
Does jumping out of a scope-based cleanup block violate the cleanup
guidelines?
The kernel subsystem cleanup guidelines state that the usage of goto and
cleanup helpers should never be mixed in the same function.
Using a goto to jump out of a scoped_guard() block to a manual cleanup label
mixes the two paradigms.
Could this be converted completely to scope-based cleanup, or would it be
better to avoid using scoped_guard() here?
> + }
> + }
> + /*
> + * If consumer asks for PM to use the link and the supplier has not
> + * PM initialized, or if there is a reverse (non-SYNC_STATE_ONLY)
> + * dependency between the consumer and the supplier already in the
> + * graph, return NULL. If the link is a SYNC_STATE_ONLY link, we
> + * don't check for reverse dependencies because it only affects
> + * sync_state() callbacks.
> + */
> + if (((flags & DL_FLAG_PM_RUNTIME) && !device_pm_initialized(supplier)) ||
[Severity: Low]
Is the !device_pm_initialized(supplier) condition reachable anymore?
The device_is_bound() check earlier in the function fundamentally
guarantees that a driver is attached. This is only possible if the
device has already been registered.
Since device_pm_initialized() directly evaluates to device_is_registered(),
!device_pm_initialized(supplier) will evaluate to false under all possible
code paths passing the new bound check.
Is this check now dead code?
> + (!(flags & DL_FLAG_SYNC_STATE_ONLY) &&
> + device_is_dependent(consumer, supplier))) {
> link = NULL;
> goto out;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260921191239.4249-1-alucerop@amd.com?part=1
next prev parent reply other threads:[~2026-09-22 17:56 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-21 19:12 [PATCH v1 0/4] Type2 multipf support alucerop
2026-09-21 19:12 ` [PATCH v1 1/4] driver core: Rely on supplier driver binding at link creation alucerop
2026-09-22 17:56 ` sashiko-bot [this message]
2026-09-22 21:39 ` Maxime Chevallier
2026-09-23 8:49 ` Lucero Palau, Alejandro
2026-09-23 9:58 ` Lucero Palau, Alejandro
2026-09-24 8:59 ` Lucero Palau, Alejandro
2026-09-21 19:12 ` [PATCH v1 2/4] cxl/region: Add region reference in memdev attach alucerop
2026-09-22 17:56 ` sashiko-bot
2026-09-21 19:12 ` [PATCH v1 3/4] cxl/memdev: Add support for multi PF devices alucerop
2026-09-21 23:07 ` Dave Jiang
2026-09-22 14:07 ` Lucero Palau, Alejandro
2026-09-22 16:39 ` Dave Jiang
2026-09-22 17:56 ` sashiko-bot
2026-09-21 19:12 ` [PATCH v1 4/4] sfc: add multipf support alucerop
2026-09-22 17:56 ` sashiko-bot
2026-09-24 1:15 ` Jonathan Cameron
2026-09-25 11:16 ` Lucero Palau, Alejandro
2026-09-25 20:24 ` Jonathan Cameron
2026-09-23 20:00 ` [syzbot ci] Re: Type2 " syzbot ci
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260922175614.AE72D1F00899@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=alucerop@amd.com \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox