From: Davidlohr Bueso <dave@stgolabs.net>
To: sashiko-reviews@lists.linux.dev, dave.jiang@intel.com
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v9 02/10] cxl/pci: Add BI topology enable/disable
Date: Wed, 23 Sep 2026 10:00:26 -0700 [thread overview]
Message-ID: <20260923170026.6tpxbrgsbqa2zplr@offworld> (raw)
In-Reply-To: <20260923011241.4B9451F000FF@smtp.kernel.org>
On Wed, 23 Sep 2026, sashiko-bot@kernel.org wrote:
>Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>- [Medium] cxl/pci: TOCTOU race in BI setup against concurrent AER reset
False positive, see below.
>--
>
>commit 1daa4037cbac0ebc16630c3d4f45c358bd7890f9
>Author: Davidlohr Bueso <dave@stgolabs.net>
>
>cxl/pci: Add BI topology enable/disable
>
>This patch implements setup and teardown of the Back-Invalidate (BI) topology
>on CXL endpoints and upstream components. It also adds a reset detection
>mechanism to verify whether a reset cleared the hardware BI Enable state.
>
>> diff --git a/drivers/cxl/core/pci.c b/drivers/cxl/core/pci.c
>> index b8676a3d6ec90..f3ca9861a7ba1 100644
>> --- a/drivers/cxl/core/pci.c
>> +++ b/drivers/cxl/core/pci.c
>[ ... ]
>> +static int __cxl_bi_ctrl_endpoint(struct cxl_dev_state *cxlds, bool enable)
>> +{
>[ ... ]
>> + FIELD_MODIFY(CXL_BI_DECODER_CTRL_BI_ENABLE, &ctrl, enable);
>> + writel(ctrl, bi + CXL_BI_DECODER_CTRL_OFFSET);
>> + cxlds->bi = enable;
>
>[Severity: Medium]
>Could this lockless update of cxlds->bi race with a concurrent AER reset
>handled by cxl_bi_reset_detected()?
>
>If a user manually binds the cxl_port driver via sysfs concurrently with a
>PCI AER reset (SBR), the manual sysfs bind takes the endpoint->dev lock,
>while the AER recovery (cxl_reset_done()) takes the cxlmd->dev lock, allowing
>them to execute concurrently.
The endpoint port cannot be bound on its own. Unbinding it from cxl_port
tears it down through cxl_detach_ep() and a subsequent sysfs bind fails
with -ENODEV. The only path that reaches __cxl_bi_ctrl_endpoint(enable) is
the endpoint port probe, and that runs synchronously from
devm_cxl_add_endpoint().
The driver core holds device_lock(&cxlmd->dev) across cxl_mem_probe(), and
cxl_reset_done() takes that same lock before calling
cxl_bi_reset_detected(). The reset side therefore cannot observe the
window between the writel() and the cxlds->bi store; it waits for the
probe to return and only then compares the flag against the hardware bit.
>
>There is a window between the writel() that sets the hardware bit and the
>assignment of cxlds->bi. If the AER SBR wipes the hardware bit in this window,
>could cxl_bi_reset_detected() check the still-false cxlds->bi and ignore the
>reset?
I widened the window with a 4s msleep() between the writel() and the store,
rebinded mem0 and issued an SBR through sysfs while the probe was sleeping
in that window:
[16.846] cxl_pci 0000:0d:00.0: reset via cxl_bus
[19.290] cxl_pci 0000:0d:00.0: BI requests enabled
[19.335] cxl_mem mem0: probe: 0
[19.337] cxl_pci 0000:0d:00.0: BI disabled by reset
The SBR itself lands in the window and clears BI Enable, but the reset
write blocks on the memdev lock until the probe completes. .reset_done then
runs, sees cxlds->bi set with the hardware bit clear, and clears the flag.
A subsequent HDM-DB attach is refused with "BI not enabled on device". The
software state does not desynchronize.
Independently of this, patch 4 re-reads BI Enable after committing each
endpoint decoder, so a stale flag could not commit a decoder with BI on a
device whose BI Enable is clear.
Thanks,
Davidlohr
next prev parent reply other threads:[~2026-09-23 17:00 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-22 23:38 [PATCH v9 0/10] cxl: Support Back-Invalidate Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 01/10] cxl: Add BI register probing and port initialization Davidlohr Bueso
2026-09-29 4:06 ` Richard Cheng
2026-09-22 23:38 ` [PATCH v9 02/10] cxl/pci: Add BI topology enable/disable Davidlohr Bueso
2026-09-23 1:12 ` sashiko-bot
2026-09-23 17:00 ` Davidlohr Bueso [this message]
2026-09-23 5:41 ` Li Ming
2026-09-25 23:32 ` Jonathan Cameron
2026-09-29 8:52 ` Richard Cheng
2026-09-30 23:01 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 03/10] cxl/hdm: Add BI coherency support for endpoint decoders Davidlohr Bueso
2026-09-23 6:06 ` Li Ming
2026-09-30 23:11 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 04/10] cxl: Add HDM-DB region creation Davidlohr Bueso
2026-10-01 3:28 ` Alison Schofield
2026-10-01 8:57 ` Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 05/10] cxl/hdm: Rename decoder coherency flags Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-22 23:38 ` [PATCH v9 06/10] cxl/region: Log the coherency model at region creation Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-30 23:10 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 07/10] cxl/pci: Split BI capability probe from setup Davidlohr Bueso
2026-09-24 0:49 ` Li Ming
2026-09-30 23:09 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 08/10] cxl: Allow auto-committed BI hdm decoders Davidlohr Bueso
2026-10-01 3:49 ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 09/10] cxl/test: Add mock BI topology support Davidlohr Bueso
2026-09-23 1:11 ` sashiko-bot
2026-09-23 20:57 ` Davidlohr Bueso
2026-09-23 0:43 ` [PATCH v9 10/10] cxl/doc: Update maturity map with BI support Davidlohr Bueso
2026-09-24 0:50 ` Li Ming
2026-09-30 23:08 ` Alison Schofield
2026-09-30 16:47 ` [PATCH v9 0/10] cxl: Support Back-Invalidate Alison Schofield
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260923170026.6tpxbrgsbqa2zplr@offworld \
--to=dave@stgolabs.net \
--cc=dave.jiang@intel.com \
--cc=linux-cxl@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).