linux-cxl.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
From: Davidlohr Bueso <dave@stgolabs.net>
To: sashiko-reviews@lists.linux.dev, dave.jiang@intel.com
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v9 02/10] cxl/pci: Add BI topology enable/disable
Date: Wed, 23 Sep 2026 10:00:26 -0700	[thread overview]
Message-ID: <20260923170026.6tpxbrgsbqa2zplr@offworld> (raw)
In-Reply-To: <20260923011241.4B9451F000FF@smtp.kernel.org>

On Wed, 23 Sep 2026, sashiko-bot@kernel.org wrote:

>Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
>- [Medium] cxl/pci: TOCTOU race in BI setup against concurrent AER reset

False positive, see below.

>--
>
>commit 1daa4037cbac0ebc16630c3d4f45c358bd7890f9
>Author: Davidlohr Bueso <dave@stgolabs.net>
>
>cxl/pci: Add BI topology enable/disable
>
>This patch implements setup and teardown of the Back-Invalidate (BI) topology
>on CXL endpoints and upstream components. It also adds a reset detection
>mechanism to verify whether a reset cleared the hardware BI Enable state.
>
>> diff --git a/drivers/cxl/core/pci.c b/drivers/cxl/core/pci.c
>> index b8676a3d6ec90..f3ca9861a7ba1 100644
>> --- a/drivers/cxl/core/pci.c
>> +++ b/drivers/cxl/core/pci.c
>[ ... ]
>> +static int __cxl_bi_ctrl_endpoint(struct cxl_dev_state *cxlds, bool enable)
>> +{
>[ ... ]
>> +	FIELD_MODIFY(CXL_BI_DECODER_CTRL_BI_ENABLE, &ctrl, enable);
>> +	writel(ctrl, bi + CXL_BI_DECODER_CTRL_OFFSET);
>> +	cxlds->bi = enable;
>
>[Severity: Medium]
>Could this lockless update of cxlds->bi race with a concurrent AER reset
>handled by cxl_bi_reset_detected()?
>
>If a user manually binds the cxl_port driver via sysfs concurrently with a
>PCI AER reset (SBR), the manual sysfs bind takes the endpoint->dev lock,
>while the AER recovery (cxl_reset_done()) takes the cxlmd->dev lock, allowing
>them to execute concurrently.

The endpoint port cannot be bound on its own. Unbinding it from cxl_port
tears it down through cxl_detach_ep() and a subsequent sysfs bind fails
with -ENODEV. The only path that reaches __cxl_bi_ctrl_endpoint(enable) is
the endpoint port probe, and that runs synchronously from
devm_cxl_add_endpoint().

The driver core holds device_lock(&cxlmd->dev) across cxl_mem_probe(), and
cxl_reset_done() takes that same lock before calling
cxl_bi_reset_detected(). The reset side therefore cannot observe the
window between the writel() and the cxlds->bi store; it waits for the
probe to return and only then compares the flag against the hardware bit.

>
>There is a window between the writel() that sets the hardware bit and the
>assignment of cxlds->bi. If the AER SBR wipes the hardware bit in this window,
>could cxl_bi_reset_detected() check the still-false cxlds->bi and ignore the
>reset?

I widened the window with a 4s msleep() between the writel() and the store,
rebinded mem0 and issued an SBR through sysfs while the probe was sleeping
in that window:

   [16.846] cxl_pci 0000:0d:00.0: reset via cxl_bus
   [19.290] cxl_pci 0000:0d:00.0: BI requests enabled
   [19.335] cxl_mem mem0: probe: 0
   [19.337] cxl_pci 0000:0d:00.0: BI disabled by reset

The SBR itself lands in the window and clears BI Enable, but the reset
write blocks on the memdev lock until the probe completes. .reset_done then
runs, sees cxlds->bi set with the hardware bit clear, and clears the flag.
A subsequent HDM-DB attach is refused with "BI not enabled on device". The
software state does not desynchronize.

Independently of this, patch 4 re-reads BI Enable after committing each
endpoint decoder, so a stale flag could not commit a decoder with BI on a
device whose BI Enable is clear.

Thanks,
Davidlohr

  reply	other threads:[~2026-09-23 17:00 UTC|newest]

Thread overview: 33+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-22 23:38 [PATCH v9 0/10] cxl: Support Back-Invalidate Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 01/10] cxl: Add BI register probing and port initialization Davidlohr Bueso
2026-09-29  4:06   ` Richard Cheng
2026-09-22 23:38 ` [PATCH v9 02/10] cxl/pci: Add BI topology enable/disable Davidlohr Bueso
2026-09-23  1:12   ` sashiko-bot
2026-09-23 17:00     ` Davidlohr Bueso [this message]
2026-09-23  5:41   ` Li Ming
2026-09-25 23:32   ` Jonathan Cameron
2026-09-29  8:52   ` Richard Cheng
2026-09-30 23:01   ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 03/10] cxl/hdm: Add BI coherency support for endpoint decoders Davidlohr Bueso
2026-09-23  6:06   ` Li Ming
2026-09-30 23:11   ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 04/10] cxl: Add HDM-DB region creation Davidlohr Bueso
2026-10-01  3:28   ` Alison Schofield
2026-10-01  8:57     ` Davidlohr Bueso
2026-09-22 23:38 ` [PATCH v9 05/10] cxl/hdm: Rename decoder coherency flags Davidlohr Bueso
2026-09-24  0:49   ` Li Ming
2026-09-22 23:38 ` [PATCH v9 06/10] cxl/region: Log the coherency model at region creation Davidlohr Bueso
2026-09-24  0:49   ` Li Ming
2026-09-30 23:10   ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 07/10] cxl/pci: Split BI capability probe from setup Davidlohr Bueso
2026-09-24  0:49   ` Li Ming
2026-09-30 23:09   ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 08/10] cxl: Allow auto-committed BI hdm decoders Davidlohr Bueso
2026-10-01  3:49   ` Alison Schofield
2026-09-22 23:38 ` [PATCH v9 09/10] cxl/test: Add mock BI topology support Davidlohr Bueso
2026-09-23  1:11   ` sashiko-bot
2026-09-23 20:57     ` Davidlohr Bueso
2026-09-23  0:43 ` [PATCH v9 10/10] cxl/doc: Update maturity map with BI support Davidlohr Bueso
2026-09-24  0:50   ` Li Ming
2026-09-30 23:08   ` Alison Schofield
2026-09-30 16:47 ` [PATCH v9 0/10] cxl: Support Back-Invalidate Alison Schofield

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260923170026.6tpxbrgsbqa2zplr@offworld \
    --to=dave@stgolabs.net \
    --cc=dave.jiang@intel.com \
    --cc=linux-cxl@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).