From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-lf1-f53.google.com (mail-lf1-f53.google.com [209.85.167.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 28FED3DB30C for ; Thu, 23 Jul 2026 07:14:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784790871; cv=none; b=KEL2yljBPhunSLVYP4XPAk2leu+YUk20uXFbEOqwKkRX5omXBLl9gp0eDoLt6Iz3fenXRIGyl4KEgWqOnw+CGwycLTJhW7L0aJ0t1BkA0nDVvHs3XCyynU/aosM8taUfOecXqtjyutz0aGcluyxB9FQX2prAyNmw5BE51cKyO7s= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784790871; c=relaxed/simple; bh=Ss7JoXFHGRd2zbqTCRzWmOflLq0kyEcVLwZZBHbcE04=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=pY+rSGhgI0v+KtZAYFXVz6aoRRoY9f6yX7mBQIuISxX/gLrYBXZDJF9yh0FTl/pj2aalM22xl5TOruEyNbxvIayCOqHBQBCTeW6eR38y20PT9H78czxwWT+7cb9DAJxGv0WD9rIthVnwsKMi/i/L3n6rB45KuP1CBzIjFK+4HjM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linaro.org; spf=pass smtp.mailfrom=linaro.org; dkim=pass (2048-bit key) header.d=linaro.org header.i=@linaro.org header.b=aR+OcKvM; arc=none smtp.client-ip=209.85.167.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linaro.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linaro.org Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=linaro.org header.i=@linaro.org header.b="aR+OcKvM" Received: by mail-lf1-f53.google.com with SMTP id 2adb3069b0e04-5b0115b9e17so276080e87.0 for ; Thu, 23 Jul 2026 00:14:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1784790866; x=1785395666; darn=lists.linux.dev; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:from:to:cc:subject:date:message-id:reply-to:content-type; bh=bFo0mK2Twky9T7qEB2bTUDQtTh7rdNsTlOuaha0+uKE=; b=aR+OcKvMVs+mryMNDuUqPUTR2hB1KTI8qE7uqb7F84Dx9FEUh7PzJ6072UgdPnMHO+ K8NOWc//trPLz6jVbF26xP3A9zFLPhad+QD8pp9ZCrlHbPpueYs1zvMzZ2KWZ3KzKoQM kkJ9BCIjfiWQsb1hg/KghCiTpNxGH8V9S9QkDSz2hTmqeC/7pYAUrG3lxlbd+4Ri08Yp seDI+TzOUGyxbvP3WKoS34kfWnI6xJqpuhoqu/pmd1hkgGoZDGBq8MssPmWuf0JgdEYn GFFTyMc3cLZOhSLMS/yXYTUP46/77pfDe7sHOrLSlMsD2pkr/xMoMFgOn8X8bYX75/gw lnTA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784790866; x=1785395666; h=in-reply-to:content-transfer-encoding:content-disposition :content-type:mime-version:references:message-id:subject:cc:to:from :date:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bFo0mK2Twky9T7qEB2bTUDQtTh7rdNsTlOuaha0+uKE=; b=R/G12Q1VtCQgq8q/E0byOetgLj/RgJd3B7h14tgLJJmLlFF+jGIvt3q/9VNydhOwI2 Q4KxXF8tyfR+qc6tsHVP0z6gfOcKFQsEGDJFI1cQCAx4xSMfzXQN7WE+hormDDk8Lk57 ovq3OAxvWsczxnbsWds8MHwZGo1oX8dQUc32J3uKbi4QscsFTYUYKjkaq6gfSkG01npH lKjcIPF2YRUd5ccg0+vN28duFrPZphxdxOpEq5G7g7IVtsqAjvBj8ri0J/Xc61jCPgNc chbaRUr2qc9TXcPqb/w+0vYzdvbJJ9ntFDG263ZlP7d9fv/aCqLXN7DkeJleqAIj8mN9 0rNg== X-Forwarded-Encrypted: i=1; AHgh+RqxSG/PqLoTyGZYgWNtgj7Jaj7unDsOnM2q7ynYqCD5JLhrgyOxni7uv7xTA+tE/9mtONSeI/IjVUNIU1nTfA==@lists.linux.dev X-Gm-Message-State: AOJu0YybiR6xxkfn2unx5xN5ohe8NXOL3ZvuhP3sFWb89UqvzTMVGYm8 nSgVQjFgO4ctwkGeRYmxTQXhAsQZMLxQgIlujOY7VN1Eyj7+fKg0TMdYMQ3CnKydCpM= X-Gm-Gg: AR+sD10qC0QYPI0+wPiRb76X9BlMyIZBJH01I1hFi0zrXOlt/9yOYRY3MzBHnaBEsfs B5xE7ZQ91BbDuzNwlmqqHUXQpb4d3BYgA/Etg80+1btMaHSzIJWMS++/ZnSheHC96R2zAzd5Vx1 WDsMYH3zJ7gBdchGWCRW3sHb5yeUhZxaifiRSLiISvmPTmwOoyMIovkIiy8BbxjASIewQu02CYL Fy/xQKgRPBLHpLOtmMBg8nlDPjJgUxp81+MWsJE+FaadwdaL+KMlwDjEMm9MwOIXc+rSMf67KaC TkThUWM3JzKylaX8+ZnZceAwPa9sZV8FPqTO4+DuMZXBomMsNgDTExX1Tg2mfhmOU+uO8x7VkHO 0fkAGTcSa8WHpv3brzxR0f10xav14nQNLCgIWey7n+lP9ELxp7Z1MH+qHvyUW5fRa3XOq4sZulN KPcIAHgD0Z17okNPKox5tV3VIbyy4eaw== X-Received: by 2002:a05:6512:3e2a:b0:5ae:af98:497f with SMTP id 2adb3069b0e04-5b2b2e4995cmr317702e87.7.1784790865836; Thu, 23 Jul 2026 00:14:25 -0700 (PDT) Received: from nuoska (78-27-71-225.bb.dnainternet.fi. [78.27.71.225]) by smtp.gmail.com with ESMTPSA id 2adb3069b0e04-5b2a9f4d42esm844102e87.79.2026.07.23.00.14.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 23 Jul 2026 00:14:25 -0700 (PDT) Date: Thu, 23 Jul 2026 10:14:23 +0300 From: Mikko Rapeli To: Dmitry Osipenko , stable@vger.kernel.org Cc: Ryosuke Yasuoka , David Airlie , Gerd Hoffmann , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , Dmitry Baryshkov , Javier Martinez Canillas , dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org Subject: Re: [PATCH v2] drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker Message-ID: References: <20260713-virtiogpu_syzbot-v2-1-2958fa37d46d@redhat.com> Precedence: bulk X-Mailing-List: virtualization@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: Hi, adding stable@vger.kernel.org In Yocto distro, this change released in v7.2-rc4 seems to fix quite severe qemu boot hangs seen with 6.18 stable kernels. Details in https://bugzilla.yoctoproject.org/show_bug.cgi?id=16217 Please apply this to to 6.18 and other stable trees. Cheers, -Mikko On Mon, Jul 13, 2026 at 07:31:14PM +0300, Dmitry Osipenko wrote: > On 7/13/26 16:01, Ryosuke Yasuoka wrote: > > A probe-time deadlock can occur between the dequeue worker and > > drm_client_register(). During probe, drm_client_register() holds > > clientlist_mutex and calls the fbdev hotplug callback, which triggers an > > atomic commit that ends up sleeping in virtio_gpu_queue_ctrl_sgs() > > waiting for virtqueue space. The dequeue worker that would free that > > space calls virtio_gpu_cmd_get_display_info_cb(), which invokes > > drm_kms_helper_hotplug_event() -> drm_client_dev_hotplug(), attempting > > to acquire the same clientlist_mutex. Since wake_up() is only called > > after the resp_cb loop, the probe thread is never woken and both threads > > deadlock. > > > > Fix this by removing the hotplug notification from > > virtio_gpu_cmd_get_display_info_cb(). The display data (outputs[i].info) > > is still updated synchronously in the callback. > > > > For the init path, drm_client_register() already fires an initial > > hotplug when the client is registered, which picks up the connector > > state updated by display_info_cb. > > > > For the runtime config_changed path, add a wait_event_timeout() in > > config_changed_work_func() so that display_info_cb updates the connector > > data before the hotplug notification is sent. Also replace > > drm_helper_hpd_irq_event() with drm_kms_helper_hotplug_event() since > > virtio-gpu never calls drm_kms_helper_poll_init() and thus > > drm_helper_hpd_irq_event() always returns false without doing anything. > > > > Fixes: 27655b9bb9f0 ("drm/client: Send hotplug event after registering a client") > > Closes: https://syzkaller.appspot.com/bug?id=d6dd6f86d3aaf7eebe7406e45c1c6e549453f224 > > Closes: https://syzkaller.appspot.com/bug?id=908bd910da5dd79b88de4cf7baf376cc873a922e > > Suggested-by: Dmitry Osipenko > > Signed-off-by: Ryosuke Yasuoka > > --- > > I checked whether drm_helper_hpd_irq_event() is needed in > > virtio_gpu_init(), as Dmitry suggested. AFAIS, it is not needed because: > > > > 1. drm_helper_hpd_irq_event() is always a no-op in virtio-gpu. > > It returns false immediately probe_helper.c:1088 because > > dev->mode_config.poll_enabled is false — virtio-gpu never calls > > drm_kms_helper_poll_init(). Even if it passed that gate, no > > virtio-gpu connectors set DRM_CONNECTOR_POLL_HPD. > > > > 1082 bool drm_helper_hpd_irq_event(struct drm_device *dev) > > 1083 { > > ... > > 1088 if (!dev->mode_config.poll_enabled) > > 1089 return false; > > > > 2. virtio_gpu_init() runs before drm_dev_register() and > > drm_client_setup(), so no DRM clients are registered yet. > > drm_kms_helper_hotplug_event() would iterate an empty client list. > > The initial hotplug is handled by drm_client_register(), which fires > > a hotplug callback to the newly registered client. By that time, > > display_info_cb has already updated the connector data. > > > > For the same reason, drm_helper_hpd_irq_event() in > > config_changed_work_func() was also a no-op. The actual runtime hotplug > > notification was always delivered by display_info_cb's call to > > drm_kms_helper_hotplug_event(). This patch replaces it with a direct > > drm_kms_helper_hotplug_event() call after waiting for the display info > > response. > > --- > > Changes in v2: > > - Dropped the work_struct approach from v1. > > - Instead, removed the hotplug calls from display_info_cb entirely, as > > suggested by Dmitry. > > - Added wait_event_timeout() in config_changed_work_func() so that the > > display info response is received before sending the hotplug > > notification. > > - Replaced drm_helper_hpd_irq_event() with drm_kms_helper_hotplug_event() > > in config_changed_work_func() since drm_helper_hpd_irq_event() is > > always a no-op in virtio-gpu (poll_enabled is never set). > > - No changes to virtio_gpu_init() — drm_client_register() already > > handles the initial hotplug and hotplug event does nothing before DRM > > device/client has been registered. > > - Link to v1: https://lore.kernel.org/r/20260630-virtiogpu_syzbot-v1-1-0aa06630750e@redhat.com > > --- > > drivers/gpu/drm/virtio/virtgpu_kms.c | 5 ++++- > > drivers/gpu/drm/virtio/virtgpu_vq.c | 3 --- > > 2 files changed, 4 insertions(+), 4 deletions(-) > > > > diff --git a/drivers/gpu/drm/virtio/virtgpu_kms.c b/drivers/gpu/drm/virtio/virtgpu_kms.c > > index cfde9f573df6..b4329f28e976 100644 > > --- a/drivers/gpu/drm/virtio/virtgpu_kms.c > > +++ b/drivers/gpu/drm/virtio/virtgpu_kms.c > > @@ -49,7 +49,10 @@ static void virtio_gpu_config_changed_work_func(struct work_struct *work) > > virtio_gpu_cmd_get_edids(vgdev); > > virtio_gpu_cmd_get_display_info(vgdev); > > virtio_gpu_notify(vgdev); > > - drm_helper_hpd_irq_event(vgdev->ddev); > > + wait_event_timeout(vgdev->resp_wq, > > + !vgdev->display_info_pending, > > + 5 * HZ); > > + drm_kms_helper_hotplug_event(vgdev->ddev); > > } > > events_clear |= VIRTIO_GPU_EVENT_DISPLAY; > > } > > diff --git a/drivers/gpu/drm/virtio/virtgpu_vq.c b/drivers/gpu/drm/virtio/virtgpu_vq.c > > index c8b9475a7472..e5e1af8b8e8a 100644 > > --- a/drivers/gpu/drm/virtio/virtgpu_vq.c > > +++ b/drivers/gpu/drm/virtio/virtgpu_vq.c > > @@ -840,9 +840,6 @@ static void virtio_gpu_cmd_get_display_info_cb(struct virtio_gpu_device *vgdev, > > vgdev->display_info_pending = false; > > spin_unlock(&vgdev->display_info_lock); > > wake_up(&vgdev->resp_wq); > > - > > - if (!drm_helper_hpd_irq_event(vgdev->ddev)) > > - drm_kms_helper_hotplug_event(vgdev->ddev); > > } > > > > static void virtio_gpu_cmd_get_capset_info_cb(struct virtio_gpu_device *vgdev, > > > > --- > > base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa > > change-id: 20260619-virtiogpu_syzbot-bdab508ffcd5 > > > > Best regards, > > Appled to misc-fixes, thanks! > > -- > Best regards, > Dmitry