Linux PCI subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Pranjal Shrivastava" <praan@google.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access
Date: Tue, 29 Sep 2026 06:41:52 +0000	[thread overview]
Message-ID: <20260929064152.C5E451F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929034510.2023173-16-praan@google.com>

Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pm: power domain leak in arm_smmu_disable_action()
- [High] irq: CPU livelock in threaded queues due to uncleared events
--

commit 13dd005a8c8b5e0160d4c5b2b42bd2a26eae301e
Author: Pranjal Shrivastava <praan@google.com>

iommu/arm-smmu-v3: Invoke pm_runtime before hw access

This commit introduces pm_runtime helpers before accessing hardware across
the driver to avoid sleeping and deadlocking during transient power states.
It uses lockless checks and non-sleeping runtime PM gets in threaded
interrupts, and explicitly manages PM state around device disable paths.

> diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> index 2a1b5ce6ff1cf..89ffa83464780 100644
> --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
[ ... ]
> @@ -2460,6 +2478,40 @@ static irqreturn_t arm_smmu_evtq_thread(int irq, void *dev)
[ ... ]
> +	if (!arm_smmu_rpm_get_if_active(smmu)) {
> +		dev_warn_ratelimited(smmu->dev, "client device is suspended, dropping event\n");
> +		return IRQ_HANDLED;
> +	}

[Severity: High]
Can this cause an interrupt livelock?

If arm_smmu_rpm_get_if_active() observes the RPM_SUSPENDING state, it returns
false, which means this returns IRQ_HANDLED without dequeueing the event or
updating the hardware CONS pointer. 

Because the event is left in the queue, won't the SMMU hardware continue to
assert the level-triggered wired interrupt line, resulting in an infinite CPU
loop that deadlocks the suspend sequence?

>  	do {
>  		while (!queue_remove_raw(q, evt)) {
[ ... ]
> @@ -2518,6 +2571,18 @@ static irqreturn_t arm_smmu_priq_thread(int irq, void *dev)
[ ... ]
> +	if (!arm_smmu_rpm_get_if_active(smmu)) {
> +		dev_warn_ratelimited(smmu->dev, "client device is suspended, dropping page request\n");
> +		return IRQ_HANDLED;
> +	}

[Severity: High]
Similar to the evtq thread above, does returning IRQ_HANDLED here without
consuming the hardware queue entries leave the interrupt line asserted?
Could this lead to a CPU livelock during transient power states?

>  	do {
>  		while (!queue_remove_raw(q, evt))
[ ... ]
> @@ -5116,14 +5227,37 @@ static int arm_smmu_device_disable(struct arm_smmu_device *smmu)
>  static void arm_smmu_disable_action(void *data)
>  {
>  	struct arm_smmu_device *smmu = data;
> +	int ret;
>  
>  	/* If the SMMU is already suspended, nothing to do */
>  	if (!pm_runtime_suspended(smmu->dev)) {
[ ... ]
>  		arm_smmu_device_disable(smmu);
> +
> +		/*
> +		 * A PM ref was only acquired via arm_smmu_rpm_get() to
> +		 * guarantee power for the MMIO register writes in
> +		 * arm_smmu_device_disable().
> +		 *
> +		 * Drop the PM ref, we intentionally do NOT invoke a
> +		 * synchronous put/suspend here since the HW was already
> +		 * disabled above. Calling put_sync would invoke
> +		 * arm_smmu_runtime_suspend(), redundantly attempting to
> +		 * do the same. Any pending autosuspend timer is cleanly
> +		 * cancelled by pm_runtime_disable() immediately below.
> +		 * The core code ensures the power management here.
> +		 */
> +		arm_smmu_rpm_put(smmu);
>  	}
>  
> +disable_pm:
>  	if (pm_runtime_enabled(smmu->dev)) {
>  		pm_runtime_dont_use_autosuspend(smmu->dev);
>  		pm_runtime_disable(smmu->dev);
>  	}

[Severity: High]
Does this sequence strand the attached PM domain in the ON state?

The code calls an asynchronous put (arm_smmu_rpm_put() invokes
pm_runtime_put_autosuspend()) immediately before calling
pm_runtime_disable(). Disabling runtime PM while a device is active cancels
any pending autosuspend work and freezes the power state as RPM_ACTIVE.

Subsequent driver core calls to pm_runtime_put_sync() would then see
disable_depth > 0 and fail with -EACCES without suspending the device,
resulting in a permanent PM domain power leak preventing deep SOC idle states.

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260929034510.2023173-1-praan@google.com?part=15

  reply	other threads:[~2026-09-29  6:41 UTC|newest]

Thread overview: 55+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-29  3:44 [PATCH v11 00/16] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-09-29  3:44 ` [PATCH v11 01/16] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-09-29  3:59   ` sashiko-bot
2026-10-07 14:06   ` Will Deacon
2026-09-29  3:44 ` [PATCH v11 02/16] iommu/arm-smmu-v3: Add Q_POS() macro Pranjal Shrivastava
2026-09-29  4:01   ` sashiko-bot
2026-09-29  3:44 ` [PATCH v11 03/16] iommu/arm-smmu-v3: Add arm_smmu_drain_queue() helper Pranjal Shrivastava
2026-09-29  4:11   ` sashiko-bot
2026-09-30 18:24   ` Nicolin Chen
2026-09-30 20:17     ` Pranjal Shrivastava
2026-09-29  3:44 ` [PATCH v11 04/16] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-09-29  4:24   ` sashiko-bot
2026-09-29  3:44 ` [PATCH v11 05/16] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-09-29  4:31   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 06/16] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-09-29  4:42   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg() Pranjal Shrivastava
2026-09-29  5:07   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs() Pranjal Shrivastava
2026-09-29  5:22   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 09/16] iommu/arm-smmu-v3: Restore MSI config on resume Pranjal Shrivastava
2026-09-29  5:31   ` sashiko-bot
2026-10-07 14:07   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 10/16] iommu/arm-smmu-v3: Factor out arm_smmu_handle_gerror() Pranjal Shrivastava
2026-09-29  5:37   ` sashiko-bot
2026-09-30 18:34   ` Nicolin Chen
2026-09-30 20:00     ` Pranjal Shrivastava
2026-09-30 20:12       ` Nicolin Chen
2026-09-30 20:03     ` Pranjal Shrivastava
2026-10-07 14:07   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-09-29  5:55   ` sashiko-bot
2026-09-30 20:33   ` Nicolin Chen
2026-10-01  5:40     ` Pranjal Shrivastava
2026-10-01 18:03       ` Nicolin Chen
2026-10-02 16:47         ` Jason Gunthorpe
2026-10-02 21:11           ` Pranjal Shrivastava
2026-10-06 17:26             ` Nicolin Chen
2026-10-07 14:08   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 12/16] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-09-29  6:05   ` sashiko-bot
2026-09-30 19:02   ` Nicolin Chen
2026-09-30 19:57     ` Pranjal Shrivastava
2026-09-30 20:03       ` Nicolin Chen
2026-09-29  3:45 ` [PATCH v11 13/16] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-09-29  6:17   ` sashiko-bot
2026-10-01 20:22   ` Nicolin Chen
2026-10-07 14:08   ` Will Deacon
2026-09-29  3:45 ` [PATCH v11 14/16] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-09-29  6:32   ` sashiko-bot
2026-09-29  3:45 ` [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-09-29  6:41   ` sashiko-bot [this message]
2026-09-29  3:45 ` [PATCH v11 16/16] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-09-29  6:48   ` sashiko-bot
2026-10-01 19:12   ` Nicolin Chen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260929064152.C5E451F000FF@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=praan@google.com \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox