From: sashiko-bot@kernel.org
To: "Pranjal Shrivastava" <praan@google.com>
Cc: linux-pci@vger.kernel.org
Subject: Re: [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access
Date: Tue, 29 Sep 2026 06:41:52 +0000 [thread overview]
Message-ID: <20260929064152.C5E451F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260929034510.2023173-16-praan@google.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] pm: power domain leak in arm_smmu_disable_action()
- [High] irq: CPU livelock in threaded queues due to uncleared events
--
commit 13dd005a8c8b5e0160d4c5b2b42bd2a26eae301e
Author: Pranjal Shrivastava <praan@google.com>
iommu/arm-smmu-v3: Invoke pm_runtime before hw access
This commit introduces pm_runtime helpers before accessing hardware across
the driver to avoid sleeping and deadlocking during transient power states.
It uses lockless checks and non-sleeping runtime PM gets in threaded
interrupts, and explicitly manages PM state around device disable paths.
> diff --git a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> index 2a1b5ce6ff1cf..89ffa83464780 100644
> --- a/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
> +++ b/drivers/iommu/arm/arm-smmu-v3/arm-smmu-v3.c
[ ... ]
> @@ -2460,6 +2478,40 @@ static irqreturn_t arm_smmu_evtq_thread(int irq, void *dev)
[ ... ]
> + if (!arm_smmu_rpm_get_if_active(smmu)) {
> + dev_warn_ratelimited(smmu->dev, "client device is suspended, dropping event\n");
> + return IRQ_HANDLED;
> + }
[Severity: High]
Can this cause an interrupt livelock?
If arm_smmu_rpm_get_if_active() observes the RPM_SUSPENDING state, it returns
false, which means this returns IRQ_HANDLED without dequeueing the event or
updating the hardware CONS pointer.
Because the event is left in the queue, won't the SMMU hardware continue to
assert the level-triggered wired interrupt line, resulting in an infinite CPU
loop that deadlocks the suspend sequence?
> do {
> while (!queue_remove_raw(q, evt)) {
[ ... ]
> @@ -2518,6 +2571,18 @@ static irqreturn_t arm_smmu_priq_thread(int irq, void *dev)
[ ... ]
> + if (!arm_smmu_rpm_get_if_active(smmu)) {
> + dev_warn_ratelimited(smmu->dev, "client device is suspended, dropping page request\n");
> + return IRQ_HANDLED;
> + }
[Severity: High]
Similar to the evtq thread above, does returning IRQ_HANDLED here without
consuming the hardware queue entries leave the interrupt line asserted?
Could this lead to a CPU livelock during transient power states?
> do {
> while (!queue_remove_raw(q, evt))
[ ... ]
> @@ -5116,14 +5227,37 @@ static int arm_smmu_device_disable(struct arm_smmu_device *smmu)
> static void arm_smmu_disable_action(void *data)
> {
> struct arm_smmu_device *smmu = data;
> + int ret;
>
> /* If the SMMU is already suspended, nothing to do */
> if (!pm_runtime_suspended(smmu->dev)) {
[ ... ]
> arm_smmu_device_disable(smmu);
> +
> + /*
> + * A PM ref was only acquired via arm_smmu_rpm_get() to
> + * guarantee power for the MMIO register writes in
> + * arm_smmu_device_disable().
> + *
> + * Drop the PM ref, we intentionally do NOT invoke a
> + * synchronous put/suspend here since the HW was already
> + * disabled above. Calling put_sync would invoke
> + * arm_smmu_runtime_suspend(), redundantly attempting to
> + * do the same. Any pending autosuspend timer is cleanly
> + * cancelled by pm_runtime_disable() immediately below.
> + * The core code ensures the power management here.
> + */
> + arm_smmu_rpm_put(smmu);
> }
>
> +disable_pm:
> if (pm_runtime_enabled(smmu->dev)) {
> pm_runtime_dont_use_autosuspend(smmu->dev);
> pm_runtime_disable(smmu->dev);
> }
[Severity: High]
Does this sequence strand the attached PM domain in the ON state?
The code calls an asynchronous put (arm_smmu_rpm_put() invokes
pm_runtime_put_autosuspend()) immediately before calling
pm_runtime_disable(). Disabling runtime PM while a device is active cancels
any pending autosuspend work and freezes the power state as RPM_ACTIVE.
Subsequent driver core calls to pm_runtime_put_sync() would then see
disable_depth > 0 and fail with -EACCES without suspending the device,
resulting in a permanent PM domain power leak preventing deep SOC idle states.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260929034510.2023173-1-praan@google.com?part=15
next prev parent reply other threads:[~2026-09-29 6:41 UTC|newest]
Thread overview: 55+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-29 3:44 [PATCH v11 00/16] iommu/arm-smmu-v3: Implement Runtime/System Sleep ops Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 01/16] iommu/arm-smmu-v3: Refactor arm_smmu_setup_irqs Pranjal Shrivastava
2026-09-29 3:59 ` sashiko-bot
2026-10-07 14:06 ` Will Deacon
2026-09-29 3:44 ` [PATCH v11 02/16] iommu/arm-smmu-v3: Add Q_POS() macro Pranjal Shrivastava
2026-09-29 4:01 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 03/16] iommu/arm-smmu-v3: Add arm_smmu_drain_queue() helper Pranjal Shrivastava
2026-09-29 4:11 ` sashiko-bot
2026-09-30 18:24 ` Nicolin Chen
2026-09-30 20:17 ` Pranjal Shrivastava
2026-09-29 3:44 ` [PATCH v11 04/16] iommu/tegra241-cmdqv: Add a helper to drain VCMDQs Pranjal Shrivastava
2026-09-29 4:24 ` sashiko-bot
2026-09-29 3:44 ` [PATCH v11 05/16] iommu/arm-smmu-v3: Add a helper to drain cmd queues Pranjal Shrivastava
2026-09-29 4:31 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 06/16] iommu/tegra241-cmdqv: Restore PROD and CONS after resume Pranjal Shrivastava
2026-09-29 4:42 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 07/16] genirq/msi: Cache MSI message in irq_chip_write_msi_msg() Pranjal Shrivastava
2026-09-29 5:07 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 08/16] genirq/msi: Provide msi_device_domain_restore_msi_msgs() Pranjal Shrivastava
2026-09-29 5:22 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 09/16] iommu/arm-smmu-v3: Restore MSI config on resume Pranjal Shrivastava
2026-09-29 5:31 ` sashiko-bot
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 10/16] iommu/arm-smmu-v3: Factor out arm_smmu_handle_gerror() Pranjal Shrivastava
2026-09-29 5:37 ` sashiko-bot
2026-09-30 18:34 ` Nicolin Chen
2026-09-30 20:00 ` Pranjal Shrivastava
2026-09-30 20:12 ` Nicolin Chen
2026-09-30 20:03 ` Pranjal Shrivastava
2026-10-07 14:07 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 11/16] iommu/arm-smmu-v3: Add CMDQ_PROD_STOP_FLAG to gate CMDQ submissions Pranjal Shrivastava
2026-09-29 5:55 ` sashiko-bot
2026-09-30 20:33 ` Nicolin Chen
2026-10-01 5:40 ` Pranjal Shrivastava
2026-10-01 18:03 ` Nicolin Chen
2026-10-02 16:47 ` Jason Gunthorpe
2026-10-02 21:11 ` Pranjal Shrivastava
2026-10-06 17:26 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 12/16] iommu/tegra241-cmdqv: Add a helper to quiesce VCMDQs Pranjal Shrivastava
2026-09-29 6:05 ` sashiko-bot
2026-09-30 19:02 ` Nicolin Chen
2026-09-30 19:57 ` Pranjal Shrivastava
2026-09-30 20:03 ` Nicolin Chen
2026-09-29 3:45 ` [PATCH v11 13/16] iommu/arm-smmu-v3: Implement pm_runtime & system sleep ops Pranjal Shrivastava
2026-09-29 6:17 ` sashiko-bot
2026-10-01 20:22 ` Nicolin Chen
2026-10-07 14:08 ` Will Deacon
2026-09-29 3:45 ` [PATCH v11 14/16] iommu/arm-smmu-v3: Enable pm_runtime and setup devlinks Pranjal Shrivastava
2026-09-29 6:32 ` sashiko-bot
2026-09-29 3:45 ` [PATCH v11 15/16] iommu/arm-smmu-v3: Invoke pm_runtime before hw access Pranjal Shrivastava
2026-09-29 6:41 ` sashiko-bot [this message]
2026-09-29 3:45 ` [PATCH v11 16/16] iommu/arm-smmu-v3: Add KUnit unit tests for Runtime PM Pranjal Shrivastava
2026-09-29 6:48 ` sashiko-bot
2026-10-01 19:12 ` Nicolin Chen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260929064152.C5E451F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=praan@google.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox