From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E798238E8B4 for ; Sat, 15 Aug 2026 19:54:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.47 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786823668; cv=none; b=GPAbcubVkeKPKM8qlfPbT1Zk+RI4Yzkz3gwQxHgFJjbWGgzVbPONtXLWNPT3NQM8ivMMVOalKGspiR+DVE7+LOV4HFS4Gjld8R4KfBRt4AF3dDsucDq5bnREGdfP8/QbJZFksMC8a0m6u9fUksVu/s/aHl04YGxYEq7cumalXlQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786823668; c=relaxed/simple; bh=4x7JDN/4fjdUnaajMlXq9PBSudKMF7Q9PTrqPVDNpXQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: Content-Type:MIME-Version; b=Eyx4XvHSeO+iiElxmK1qGTchvpZ4QlojA5+rRf+xcnHpMst74nsGyzDMUdTKaICuKqgVfbMs2HCNppGduriHqDxImWBWZOib8Ef585gSqDlHhieUXMnfypAGg/hI+oYRgDcS0PQpBtGUbko5+1tt5fC65YHoNpH7khJ9JSdqREk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=NmzTaDSE; arc=none smtp.client-ip=209.85.128.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="NmzTaDSE" Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-4956d1d9fb2so2950575e9.0 for ; Sat, 15 Aug 2026 12:54:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786823665; x=1787428465; darn=vger.kernel.org; h=mime-version:content-transfer-encoding:content-type:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=FxobjEeJRawVMzSAB2ltdXyzVXZZsToR6chxQbXYXeo=; b=NmzTaDSE/C72knDc8i1vN355vJFVj25YZLko4DQOrxdWyjpPAei53HjhU9492Csyko Di2Hw+O5A9FaErK4yc1I70BBWmk2ehEkkEb/YNmmINmG6gAuq0TUifKvYL2KETQ2IabA bWDljEcd9BD2YJcR02BT8LSp7+exY3qiAIE2hoQ/GSgeWMc6uSiFAnP7xR9Bty838dZt vAuGP2aEd/+RhKrqIUKJuh/P7Fhd1hZDYJKys11MNnCe6/BcymWntiZpMEEsFEXooVyj talXRKxOySikvhMan0bxfqqks1Y3JKU0FtShgEAlOP5E7znMetjbRp8lV4bpstyn6e63 8tKQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786823665; x=1787428465; h=mime-version:content-transfer-encoding:content-type:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=FxobjEeJRawVMzSAB2ltdXyzVXZZsToR6chxQbXYXeo=; b=d96O7aUpHviNlrZUu+2/BRjBgdwqahbCFr30qQ5w3nL8d33dQq5GxdReAaNKJm4ECU VKghcFnyxTHufMRr+fDAvaayrCYalYMS3h7jBFmREP5OrUwRZj8SJ8jzcsbj0w7rahl5 yIWMYR8LVKUpsZTId5jXzVfzoP1E2Yqzkr+cjbVLUTxXDf3apmSYSDPjHk4Tclxo0cJ5 K0FU67POvB308Ocax/gt2lvH/BM8aG13fYxZiJtVTp6sB4rw5HpVCAYWU7FAZ2WYiuHE WWjaUFN5MguQIwTUgWfmwYL1BAzSgRwEm7BQJjsm2hM9EJFyMseR0cfh9KJ0aooqnT6s z7ng== X-Gm-Message-State: AOJu0YzSToCDNehssEVoteRS4XQmA/xbchP2qYGGwUofSEnqgy33RUed BsAn5fsu7McC5wuFPVgfm85uatpAgOSMZMNhSPxL4wrqECaoAJbbin6P X-Gm-Gg: AR+sD11lwfnQcvl/AuOXaduFH00ByhMa93EyZb43dU61kRFPd6ERZdZNeYiGo3qQQia vlynSd+6F8O4ZnppIZjiNasQjpFUvSuT0weaO9Lhih6Ft2kNNf4cnUDiTNJM03RKxe7GelG7+iJ 4guIsO+m0bUMEcNVAqQWSXVZ8JEzPLqHgPlFx+DEOeiqTp96iaIQYtHRUl6wnudjw5gLG2jxPpk CUnNGCt9fgnoB8q32gwhnNU1Mr/or+QNQCtnmTE/+bDZ7caWLUBtIaKdg1cWPB1olPjOTdgXDOn lY7DnTaidNB1h6cEYQQJqmrFbq6L2PDCj9A+BogZtgAQ11npdXqeBKdxl0JQF769zcVeVTp9LNJ sH0meY6aXRU4JuYFYoJHDY4bwVxIYnxkCT9zdTzQZQVGXRsn9CAxg98MTcDTWMuaaDGs7I9a24S 02mZVXDgZR4X8W7gc6HB7ZJwMzRa8sUyCvaJZXdq1UT+Nb2+VIcA4yQvb7VDjg8vWJk6kTDL16X Xm1X1rNxEyN8cnHY4Rd1I635JzFHTr6hJ3VN9T73Q== X-Received: by 2002:a05:600c:a47:b0:496:bbce:ef with SMTP id 5b1f17b1804b1-4998796ca48mr110524505e9.3.1786823665137; Sat, 15 Aug 2026 12:54:25 -0700 (PDT) Received: from [127.0.0.1] (ip-109-193-028-127.um39.pools.vodafone-ip.de. [109.193.28.127]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499899bff2csm133743775e9.7.2026.08.15.12.54.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 15 Aug 2026 12:54:24 -0700 (PDT) From: Marek Czernohous To: nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org Cc: linux-kernel@vger.kernel.org, Danilo Krummrich , Lyude Paul , David Airlie , Simona Vetter Subject: [PATCH 1/3] drm/nouveau: destroy the fence event before cancelling its work Date: Sat, 15 Aug 2026 21:54:20 +0200 Message-ID: <178682366002.3748010.12779628082366287968@gmail.com> X-Mailer: python-smtplib In-Reply-To: <178682366001.3748010.7798811159846779765@gmail.com> References: <178682366001.3748010.7798811159846779765@gmail.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 From: Marek Czernohous nouveau_fence_context_del() cancels the uevent work first and only tears the event down afterwards: cancel_work_sync(&fctx->uevent_work); nouveau_fence_context_kill(fctx, 0); nvif_event_dtor(&fctx->event); Between the cancel and the dtor the event is still armed, and nouveau_fence_wait_uevent_handler() queues the work unconditionally: schedule_work(&fctx->uevent_work); return NVIF_EVENT_KEEP; So a non-stall interrupt arriving in that window re-arms the work that was just cancelled. The callers free the context immediately afterwards, for example nv84_fence_context_del(): nouveau_fence_context_del(&fctx->base); chan->fence = NULL; nouveau_fence_context_free(&fctx->base); nouveau_fence_uevent_work() then runs against freed memory, taking fctx->lock and walking fctx->pending. Only chips from G84 on can reach this at all: nouveau_fence_context_new() returns before nvif_event_ctor() when priv->uevent is clear, and nv84_fence_create() is the only place that sets it. nv84_fence_context_del() is the context_del for all of those, because nvc0_fence_create() and gv100_fence_create() build on nv84_fence_create() and override only context_new. Drop the event first, so no further work can be queued, and only then drain what is already queued. nouveau_fence_context_kill() keeps its place after the drain. It can still touch the event: nouveau_fence_signal() returns true when a fence that had enable_signaling() called on it is signalled and fctx->notify_ref drops to zero, and the loop then calls nvif_event_block() once. That call runs in the same thread just after the dtor, where nvif_event_constructed() is false and it is a no-op. Blocking an event that no longer exists would be pointless anyway. The reordering does open one window, so it is worth saying what closes it. A fence holder that reaches nouveau_fence_enable_signaling() between the dtor and the kill gets a silent no-op from nvif_event_allow(), so that fence will not be woken by a non-stall interrupt any more. It does not have to be: the kill runs immediately afterwards, signals every fence on fctx->pending under fctx->lock and sets fctx->killed, after which nouveau_fence_emit() refuses further work with -ENODEV. Reported-by: sashiko-bot Link: https://sashiko.dev/#/patchset/20260812231330.705425-1-mczernohous@gmail.com?part=1 Fixes: 39126abc5e20 ("nouveau: offload fence uevents work to workqueue") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Marek Czernohous --- drivers/gpu/drm/nouveau/nouveau_fence.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_fence.c b/drivers/gpu/drm/nouveau/nouveau_fence.c index edbe9e08ba0f..4a3698dc2cd1 100644 --- a/drivers/gpu/drm/nouveau/nouveau_fence.c +++ b/drivers/gpu/drm/nouveau/nouveau_fence.c @@ -96,9 +96,9 @@ nouveau_fence_context_kill(struct nouveau_fence_chan *fctx, int error) void nouveau_fence_context_del(struct nouveau_fence_chan *fctx) { + nvif_event_dtor(&fctx->event); cancel_work_sync(&fctx->uevent_work); nouveau_fence_context_kill(fctx, 0); - nvif_event_dtor(&fctx->event); fctx->dead = 1; /* -- 2.54.0