* [PATCH] slimbus: messaging: fix leaked PM vote on tid allocation failure
@ 2026-08-27 2:14 Zongmin Zhou
2026-09-17 22:10 ` Srinivas Kandagatla
0 siblings, 1 reply; 5+ messages in thread
From: Zongmin Zhou @ 2026-08-27 2:14 UTC (permalink / raw)
To: srini, gregkh; +Cc: linux-sound, linux-kernel, Zongmin Zhou
From: Zongmin Zhou <zhouzongmin@kylinos.cn>
In slim_do_transfer(), when a transaction needs a tid and
slim_alloc_txn_tid() fails, the function returns directly instead of
jumping to slim_xfer_err. The runtime PM vote taken earlier with
pm_runtime_get_sync() is then never released, leaving the controller
permanently powered up.
As txn->tid is still 0 at that point, jumping to slim_xfer_err drops
the vote exactly like it is done for other failed transactions.
Fixes: d3062a2109309 ("slimbus: messaging: add slim_alloc/free_txn_tid()")
Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn>
---
drivers/slimbus/messaging.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/slimbus/messaging.c b/drivers/slimbus/messaging.c
index e2dbe4a..ee127ef 100644
--- a/drivers/slimbus/messaging.c
+++ b/drivers/slimbus/messaging.c
@@ -139,7 +139,7 @@ int slim_do_transfer(struct slim_controller *ctrl, struct slim_msg_txn *txn)
if (need_tid) {
ret = slim_alloc_txn_tid(ctrl, txn);
if (ret)
- return ret;
+ goto slim_xfer_err;
if (!txn->msg->comp)
txn->comp = &done;
--
2.34.1
No virus found
Checked by Hillstone Network AntiVirus
^ permalink raw reply related [flat|nested] 5+ messages in thread* Re: [PATCH] slimbus: messaging: fix leaked PM vote on tid allocation failure 2026-08-27 2:14 [PATCH] slimbus: messaging: fix leaked PM vote on tid allocation failure Zongmin Zhou @ 2026-09-17 22:10 ` Srinivas Kandagatla 2026-09-22 7:32 ` Zongmin Zhou 0 siblings, 1 reply; 5+ messages in thread From: Srinivas Kandagatla @ 2026-09-17 22:10 UTC (permalink / raw) To: Zongmin Zhou, srini, gregkh; +Cc: linux-sound, linux-kernel, Zongmin Zhou On 8/27/26 3:14 AM, Zongmin Zhou wrote: > From: Zongmin Zhou <zhouzongmin@kylinos.cn> > > In slim_do_transfer(), when a transaction needs a tid and > slim_alloc_txn_tid() fails, the function returns directly instead of > jumping to slim_xfer_err. The runtime PM vote taken earlier with > pm_runtime_get_sync() is then never released, leaving the controller > permanently powered up. > > As txn->tid is still 0 at that point, jumping to slim_xfer_err drops > the vote exactly like it is done for other failed transactions. > Patch itself looks fine, was this bug hit on real hardware or is this generated from some AI. How are you testing this patch? > Fixes: d3062a2109309 ("slimbus: messaging: add slim_alloc/free_txn_tid()") Missing CC stable > Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn> > --- > drivers/slimbus/messaging.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/slimbus/messaging.c b/drivers/slimbus/messaging.c > index e2dbe4a..ee127ef 100644 > --- a/drivers/slimbus/messaging.c > +++ b/drivers/slimbus/messaging.c > @@ -139,7 +139,7 @@ int slim_do_transfer(struct slim_controller *ctrl, struct slim_msg_txn *txn) > if (need_tid) { > ret = slim_alloc_txn_tid(ctrl, txn); > if (ret) > - return ret; > + goto slim_xfer_err; > > if (!txn->msg->comp) > txn->comp = &done; ^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH] slimbus: messaging: fix leaked PM vote on tid allocation failure 2026-09-17 22:10 ` Srinivas Kandagatla @ 2026-09-22 7:32 ` Zongmin Zhou 2026-09-24 6:28 ` [PATCH v2] " Zongmin Zhou 0 siblings, 1 reply; 5+ messages in thread From: Zongmin Zhou @ 2026-09-22 7:32 UTC (permalink / raw) To: Srinivas Kandagatla, gregkh; +Cc: linux-sound, linux-kernel, Zongmin Zhou 在 2026/9/18 06:10, Srinivas Kandagatla 写道: > > On 8/27/26 3:14 AM, Zongmin Zhou wrote: >> From: Zongmin Zhou <zhouzongmin@kylinos.cn> >> >> In slim_do_transfer(), when a transaction needs a tid and >> slim_alloc_txn_tid() fails, the function returns directly instead of >> jumping to slim_xfer_err. The runtime PM vote taken earlier with >> pm_runtime_get_sync() is then never released, leaving the controller >> permanently powered up. >> >> As txn->tid is still 0 at that point, jumping to slim_xfer_err drops >> the vote exactly like it is done for other failed transactions. >> Hi Srinivas, Thanks for the review. > Patch itself looks fine, was this bug hit on real hardware or is this > generated from some AI. Found during code review while porting patches, not on real hardware. The trigger requires an exhausted tid space, which is unlikely to occur naturally. > > How are you testing this patch? Tested in a VM with a stub controller that exhausts the tid space (255 allocations, SLIM_MAX_TIDS is 256) and then issues a need_tid transfer, so slim_alloc_txn_tid() fails with -ENOSPC inside slim_do_transfer(): unpatched: slim_do_transfer() returns -ENOSPC, usage_count stays 1, device never suspends patched: same return value, usage_count 0, device autosuspends > >> Fixes: d3062a2109309 ("slimbus: messaging: add slim_alloc/free_txn_tid()") > Missing CC stable Will add in v2, thanks. >> Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn> >> --- >> drivers/slimbus/messaging.c | 2 +- >> 1 file changed, 1 insertion(+), 1 deletion(-) >> >> diff --git a/drivers/slimbus/messaging.c b/drivers/slimbus/messaging.c >> index e2dbe4a..ee127ef 100644 >> --- a/drivers/slimbus/messaging.c >> +++ b/drivers/slimbus/messaging.c >> @@ -139,7 +139,7 @@ int slim_do_transfer(struct slim_controller *ctrl, struct slim_msg_txn *txn) >> if (need_tid) { >> ret = slim_alloc_txn_tid(ctrl, txn); >> if (ret) >> - return ret; >> + goto slim_xfer_err; >> >> if (!txn->msg->comp) >> txn->comp = &done; ^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH v2] slimbus: messaging: fix leaked PM vote on tid allocation failure 2026-09-22 7:32 ` Zongmin Zhou @ 2026-09-24 6:28 ` Zongmin Zhou 2026-09-25 8:32 ` Srinivas Kandagatla 0 siblings, 1 reply; 5+ messages in thread From: Zongmin Zhou @ 2026-09-24 6:28 UTC (permalink / raw) To: srini, gregkh; +Cc: linux-kernel, linux-sound, Zongmin Zhou, stable From: Zongmin Zhou <zhouzongmin@kylinos.cn> In slim_do_transfer(), when a transaction needs a tid and slim_alloc_txn_tid() fails, the function returns directly instead of jumping to slim_xfer_err. The runtime PM vote taken earlier with pm_runtime_get_sync() is then never released, leaving the controller permanently powered up. As txn->tid is still 0 at that point, jumping to slim_xfer_err drops the vote exactly like it is done for other failed transactions. Fixes: d3062a2109309 ("slimbus: messaging: add slim_alloc/free_txn_tid()") Cc: stable@vger.kernel.org Signed-off-by: Zongmin Zhou <zhouzongmin@kylinos.cn> --- Changes in v2: - Add Cc: stable@vger.kernel.org as suggested by Srinivas. drivers/slimbus/messaging.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/slimbus/messaging.c b/drivers/slimbus/messaging.c index e2dbe4a66b70..ee127ef42046 100644 --- a/drivers/slimbus/messaging.c +++ b/drivers/slimbus/messaging.c @@ -139,7 +139,7 @@ int slim_do_transfer(struct slim_controller *ctrl, struct slim_msg_txn *txn) if (need_tid) { ret = slim_alloc_txn_tid(ctrl, txn); if (ret) - return ret; + goto slim_xfer_err; if (!txn->msg->comp) txn->comp = &done; -- 2.34.1 No virus found Checked by Hillstone Network AntiVirus ^ permalink raw reply related [flat|nested] 5+ messages in thread
* Re: [PATCH v2] slimbus: messaging: fix leaked PM vote on tid allocation failure 2026-09-24 6:28 ` [PATCH v2] " Zongmin Zhou @ 2026-09-25 8:32 ` Srinivas Kandagatla 0 siblings, 0 replies; 5+ messages in thread From: Srinivas Kandagatla @ 2026-09-25 8:32 UTC (permalink / raw) To: gregkh, Zongmin Zhou; +Cc: linux-kernel, linux-sound, Zongmin Zhou, stable On Thu, 24 Sep 2026 14:28:56 +0800, Zongmin Zhou wrote: > In slim_do_transfer(), when a transaction needs a tid and > slim_alloc_txn_tid() fails, the function returns directly instead of > jumping to slim_xfer_err. The runtime PM vote taken earlier with > pm_runtime_get_sync() is then never released, leaving the controller > permanently powered up. > > As txn->tid is still 0 at that point, jumping to slim_xfer_err drops > the vote exactly like it is done for other failed transactions. > > [...] Applied, thanks! [1/1] slimbus: messaging: fix leaked PM vote on tid allocation failure commit: d4af0dab1a6ffc5bc3688a34358be68ee93561c1 Best regards, -- Srinivas Kandagatla <srini@kernel.org> ^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-09-25 8:32 UTC | newest] Thread overview: 5+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-08-27 2:14 [PATCH] slimbus: messaging: fix leaked PM vote on tid allocation failure Zongmin Zhou 2026-09-17 22:10 ` Srinivas Kandagatla 2026-09-22 7:32 ` Zongmin Zhou 2026-09-24 6:28 ` [PATCH v2] " Zongmin Zhou 2026-09-25 8:32 ` Srinivas Kandagatla
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox