From: Marc Kleine-Budde <mkl@pengutronix.de>
To: Andrea Daoud <andreadaoud6@gmail.com>
Cc: Heiko Stuebner <heiko@sntech.de>,
Elaine Zhang <zhangqing@rock-chips.com>,
kernel@pengutronix.de, linux-can@vger.kernel.org,
netdev@vger.kernel.org, linux-arm-kernel@lists.infradead.org,
linux-rockchip@lists.infradead.org,
linux-kernel@vger.kernel.org,
Alexander Shiyan <eagle.alexander923@gmail.com>
Subject: Re: Possible race condition of the rockchip_canfd driver
Date: Mon, 22 Sep 2025 10:50:23 +0200 [thread overview]
Message-ID: <20250922-eccentric-rustling-gorilla-d2606f-mkl@pengutronix.de> (raw)
In-Reply-To: <CAOprWott046xznChj7JBNmVw3Z65uOC1_bqTbVB=LA+YBw7TTQ@mail.gmail.com>
[-- Attachment #1: Type: text/plain, Size: 2318 bytes --]
On 20.09.2025 18:08:03, Andrea Daoud wrote:
> > On 18.09.2025 20:58:33, Andrea Daoud wrote:
> > > I'm using the rockchip_canfd driver on an RK3568. When under high bus
> > > load, I get
> > > the following logs [1] in rkcanfd_tx_tail_is_eff, and the CAN bus is unable to
> > > communicate properly under this condition. The exact cause is currently not
> > > entirely clear, and it's not reliably reproducible.
> >
> > Our customer is using a v3 silicon revision of the chip, which doesn't
> > this workaround.
>
> Could you please let me know how to check whether my RK3568 is v2 or v3?
Alexander Shiyan (Cc'ed) reads the information from an nvmem cell:
| https://github.com/MacroGroup/barebox/blob/macro/arch/arm/boards/diasom-rk3568/board.c#L239-L257
The idea is to fixup the device tree in the bootloader depending on the
SoC revision, so that the CAN driver uses only the needed workarounds.
> > > In the logs we can spot some strange points:
> > >
> > > 1. Line 24, tx_head == tx_tail. This should have been rejected by the if
> > > (!rkcanfd_get_tx_pending) clause.
> > >
> > > 2. Line 26, the last bit of priv->tx_tail (0x0185dbb3) is 1. This means that the
> > > tx_tail should be 1, because rkcanfd_get_tx_tail is essentially mod the
> > > priv->tx_tail by two. But the printed tx_tail is 0.
> > >
> > > I believe these problems could mean that the code is suffering from some race
> > > condition. It seems that, in the whole IRQ processing chain of the driver,
> > > there's no lock protection. Maybe some IRQ happens within the execution of
> > > rkcanfd_tx_tail_is_eff, and touches the state of the tx_head and tx_tail?
> > >
> > > Could you please have a look at the code, and check if some locking is needed?
> >
> > My time for community support is currently a bit limited. I think this
> > has to wait a bit, apologies :/
>
> No worries, I will debug myself, and hopefully send a PR if I found
> something out.
Great, I have a both a v2 and a v3 SoC here to test.
regards,
Marc
--
Pengutronix e.K. | Marc Kleine-Budde |
Embedded Linux | https://www.pengutronix.de |
Vertretung Nürnberg | Phone: +49-5121-206917-129 |
Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-9 |
[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]
next prev parent reply other threads:[~2025-09-22 8:50 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-09-18 12:58 Andrea Daoud
2025-09-19 19:03 ` Marc Kleine-Budde
2025-09-20 10:08 ` Andrea Daoud
2025-09-22 8:50 ` Marc Kleine-Budde [this message]
2025-09-27 16:26 ` Andrea Daoud
2025-09-28 17:47 ` Alexander Shiyan
2025-09-29 8:22 ` Marc Kleine-Budde
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20250922-eccentric-rustling-gorilla-d2606f-mkl@pengutronix.de \
--to=mkl@pengutronix.de \
--cc=andreadaoud6@gmail.com \
--cc=eagle.alexander923@gmail.com \
--cc=heiko@sntech.de \
--cc=kernel@pengutronix.de \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-can@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-rockchip@lists.infradead.org \
--cc=netdev@vger.kernel.org \
--cc=zhangqing@rock-chips.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®