From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f49.google.com (mail-wr1-f49.google.com [209.85.221.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id CCEE838E5E9 for ; Sat, 15 Aug 2026 19:54:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786823671; cv=none; b=ESfVHUmdnWSF8R7Sl0RsqRX4KuD3MWvh9NoZkB4H2Upujg0upPlEUL8QBBY043fUKf+Eh9ze45HCzg8tIlX5SSDx2yYCfzXWW+sbM0fIsGCmV5Ev1bNk5Naj8GOt/6ZFmBF6s/6o4ZkgPzZYBymqFYkEQSeOYDu9att9WJhvDv8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786823671; c=relaxed/simple; bh=ZqFiD5X6cNSsV1PnDFRH7z7+OROL124yaSLeOjzh3i0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: Content-Type:MIME-Version; b=uELahpM0w8EWvDGQH4X5b00SNsFOfEu4xRtCAGyQTmlG8mP3v7DxfSUAjil+TgdOx1OHBVF5Pco7fS990cv4oc5M9kJyjCS7k8NIARjvqGzwRH/GrQJbcOS+Kc6OBAfdDO+DlawAnKnxkgWbbPsl96BHniY+0lGjWf6ZhjKbdj0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GtDRMAWw; arc=none smtp.client-ip=209.85.221.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GtDRMAWw" Received: by mail-wr1-f49.google.com with SMTP id ffacd0b85a97d-47f502ff678so247192f8f.0 for ; Sat, 15 Aug 2026 12:54:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786823668; x=1787428468; darn=vger.kernel.org; h=mime-version:content-transfer-encoding:content-type:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=XxZBcoNm0rPU1Ur89x0ojWr5QvTqSdgFT80aSFgKz/A=; b=GtDRMAWwwfWj9oBGPmTO9lW95kR9d8aDViM9b5XI3UnAopRMZcq+sZ254/LAG7iyfD MNStywjHIkKOiGztnVBnmX6VeuQ+PQSOO4uxg4IoF7Mppex0DErBfSetG54VDfzcglnV zVzjqyffkgZzHFSg0PXWeT9/XbuAqAP19+sR5A4jb7rw96JM7rlssfeYsfRnB4Uu38Iv OmcS+PFDyvRn+RDLm8ihAdcbxV+hStBHhMSO0XhyQx+3thPnDqbWS+0FuLGNHqw6ioh1 R1EPAwlKXTfGaUhw51tx9EImpr7Omegl8My18noTRHT3ZnEAkuBixETBrdG7qKfJZs8v 4Htg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786823668; x=1787428468; h=mime-version:content-transfer-encoding:content-type:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=XxZBcoNm0rPU1Ur89x0ojWr5QvTqSdgFT80aSFgKz/A=; b=bW0wu00skfWjgMX9RI710F0ELPlI9bd4akv/krKESNf4UdeEHiJf9ZPIdXipD4P5Qs m0+YK0ZjgRBBj5NGVNf4BiivWvmronM79B6/+BssRFUKK23ihm4ySbcUIUNfNgcAOJMs MOki4J3ZjvStPX7OFyYlSOW2G4SIxfSJXi3sA5LzQVjGiqKucHbX0muxCk0YPFzj+K/9 8rtwN4FqkYwn0pfgQzkUDR7kQp1WaWDRbMEpjwsWep3s++lZWNQ8dwx+glR/tXd24HHV kfYey2td9YH36HxRPEWfbjx5Fd+4vHTsxJwTWayZE/mzhw1RO0ya/FzZlMKBnTaFD1fF Hl7A== X-Gm-Message-State: AOJu0Yy5Quq5CBHv+WjL+/Vo+T8d8GLaUu82zWF8V6ufKGv9uGj9ILsn Og/L7Cf7KLI6W21u8gmjvCFas6XZD0ipIRHsLz/pDhVij7ouJGWCBFrP X-Gm-Gg: AR+sD13rwAXpbrRBtF0XoXXYUE1JBljirKZTQYZDPQY0TiJhXi7d0dY7u5JqEKzkVGL Re0Adx1Ec0DSZVKRG7JBd46JxaHou7CJ+TketioigvFV793YEpFNSTD8mydavDZj90yF2yrIsry /sd3bDUkYjZvb6HHbk6A6wXeHMAz4309QTAKE+AQzYZU8Pe7lAsSswjffmPpzPgHzFMGyiM8y5m ANPqEQyMoYUhsmELCd41aBVCDVzE6KgJ8fWCRBK6VW4N06AJmMJ/MTzevI3xx07n9o6/Nrg3hwg 8VINsIzox5MB3UBzctan3abXGemMGSYaiRs6N7/udfqfBAVPA5U7ReNMtv1F7rsAbU5r3k0Urx1 letVbi24i2V80TYiZ4Uz4LMJMgHFjrBdpt8CZmqiHx2V/jjj9NPWBjIZwvT59BwT2o63+hOE2tf wPbrymQNz2+mPrEHgYrD0pHIBX2V9IdGeALsklFUrWSgzayg8iayeokt+Vaa9MeMGOOKfmS2qRj TAq4mzrNd1BSAoelXwRCTckIa2yyCHNdEB6PUYHOw== X-Received: by 2002:a05:600c:1385:b0:496:c249:ddb1 with SMTP id 5b1f17b1804b1-499879759bbmr105883175e9.4.1786823667999; Sat, 15 Aug 2026 12:54:27 -0700 (PDT) Received: from [127.0.0.1] (ip-109-193-028-127.um39.pools.vodafone-ip.de. [109.193.28.127]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-499899bff2csm133743775e9.7.2026.08.15.12.54.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 15 Aug 2026 12:54:27 -0700 (PDT) From: Marek Czernohous To: nouveau@lists.freedesktop.org, dri-devel@lists.freedesktop.org Cc: linux-kernel@vger.kernel.org, Danilo Krummrich , Lyude Paul , David Airlie , Simona Vetter Subject: [PATCH 2/3] drm/nouveau: cancel the DP IRQ work before freeing the connector Date: Sat, 15 Aug 2026 21:54:20 +0200 Message-ID: <178682366002.3748010.4096452389040554615@gmail.com> X-Mailer: python-smtplib In-Reply-To: <178682366001.3748010.7798811159846779765@gmail.com> References: <178682366001.3748010.7798811159846779765@gmail.com> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 From: Marek Czernohous nouveau_connector_destroy() tears the two nvif events down and then frees the connector, but never cancels the work the IRQ event queues: nvif_event_dtor(&nv_connector->irq); nvif_event_dtor(&nv_connector->hpd); kfree(nv_connector->edid); ... kfree(connector); nouveau_connector_irq() queues that work unconditionally: schedule_work(&nv_connector->irq_work); return NVIF_EVENT_KEEP; A DP IRQ arriving just before nvif_event_dtor() therefore leaves nv_connector->irq_work on the system queue past the kfree(). When it runs, nouveau_dp_irq() derives both nv_connector and connector from the work_struct and dereferences them, and goes on to take outp->dp.hpd_irq_lock. There is no cancel_work_sync() for irq_work anywhere in the driver, so nothing else covers this. Add it after the event teardown, where no further work can be queued, and before anything is freed. Reported by the Sashiko review bot as a pre-existing issue, in its review of an earlier nv04 FIFO series of mine, and confirmed against the source. Reported-by: sashiko-bot Link: https://sashiko.dev/#/patchset/20260812231330.705425-1-mczernohous@gmail.com?part=1 Fixes: 773eb04d14a1 ("drm/nouveau/disp: expose conn event class") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-5 Signed-off-by: Marek Czernohous --- drivers/gpu/drm/nouveau/nouveau_connector.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/gpu/drm/nouveau/nouveau_connector.c b/drivers/gpu/drm/nouveau/nouveau_connector.c index b0b0ad9a0c24..e49dcaa6d210 100644 --- a/drivers/gpu/drm/nouveau/nouveau_connector.c +++ b/drivers/gpu/drm/nouveau/nouveau_connector.c @@ -397,6 +397,7 @@ nouveau_connector_destroy(struct drm_connector *connector) struct nouveau_connector *nv_connector = nouveau_connector(connector); nvif_event_dtor(&nv_connector->irq); nvif_event_dtor(&nv_connector->hpd); + cancel_work_sync(&nv_connector->irq_work); kfree(nv_connector->edid); drm_connector_unregister(connector); drm_connector_cleanup(connector); -- 2.54.0