* [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues
@ 2026-02-03 6:55 Sumit Kumar
2026-02-03 6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
2026-02-03 6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
0 siblings, 2 replies; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03 6:55 UTC (permalink / raw)
To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar
This series fixes a deadlock in mhi_ep_reset_worker() where state_lock is
acquired twice, and adds missing lock protection for mhi_state accesses
in mhi_ep_handle_syserr() and mhi_ep_power_up() to prevent race conditions
and state machine corruption.
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
Sumit Kumar (2):
bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
bus: mhi: ep: Add missing state_lock protection for mhi_state accesses
drivers/bus/mhi/ep/main.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
---
base-commit: 6fa9041b7177f6771817b95e83f6df17b147c8c6
change-id: 20251113-reset_worker_deadlock-0223907f7c9d
Best regards,
--
Sumit Kumar <sumit.kumar@oss.qualcomm.com>
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
2026-02-03 6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
@ 2026-02-03 6:55 ` Sumit Kumar
2026-03-02 9:01 ` Manivannan Sadhasivam
2026-02-03 6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
1 sibling, 1 reply; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03 6:55 UTC (permalink / raw)
To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar
There is a potential deadlock scenario in mhi_ep_reset_worker() where
the state_lock mutex is acquired twice in the same call chain:
mhi_ep_reset_worker()
mutex_lock(&mhi_cntrl->state_lock)
mhi_ep_power_up()
mhi_ep_set_ready_state()
mutex_lock(&mhi_cntrl->state_lock) <- Deadlock
Fix this by releasing the state_lock before calling mhi_ep_power_up().
The lock is only needed to protect current MHI state read operation. The
lock can be safely released before proceeding with the power up sequence.
Fixes: 7a97b6b47353 ("bus: mhi: ep: Add support for handling MHI_RESET")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
drivers/bus/mhi/ep/main.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index cdea24e9291959ae0a92487c1b9698dc8164d2f1..73597de373ef7e0c428bcbc126d63a9a97f95144 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1093,6 +1093,7 @@ static void mhi_ep_reset_worker(struct work_struct *work)
mhi_ep_mmio_reset(mhi_cntrl);
cur_state = mhi_cntrl->mhi_state;
+ mutex_unlock(&mhi_cntrl->state_lock);
/*
* Only proceed further if the reset is due to SYS_ERR. The host will
* issue reset during shutdown also and we don't need to do re-init in
@@ -1100,8 +1101,6 @@ static void mhi_ep_reset_worker(struct work_struct *work)
*/
if (cur_state == MHI_STATE_SYS_ERR)
mhi_ep_power_up(mhi_cntrl);
-
- mutex_unlock(&mhi_cntrl->state_lock);
}
/*
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses
2026-02-03 6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
2026-02-03 6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
@ 2026-02-03 6:55 ` Sumit Kumar
2026-03-02 9:33 ` Manivannan Sadhasivam
1 sibling, 1 reply; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03 6:55 UTC (permalink / raw)
To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar
The mhi_cntrl->mhi_state field should be protected by state_lock to
ensure atomic state transitions. However, mhi_ep_handle_syserr() and
mhi_ep_power_up() access mhi_state without holding this lock, which can
race with concurrent state transitions and lead to state corruption.
Add proper state_lock protection in both functions around their mhi_state
accesses.
Fixes: fb3a26b7e8af ("bus: mhi: ep: Add support for powering up the MHI endpoint stack")
Fixes: f7d0806bdb1b3 ("bus: mhi: ep: Add support for handling SYS_ERR condition")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
drivers/bus/mhi/ep/main.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index 73597de373ef7e0c428bcbc126d63a9a97f95144..e9d14006453aa8b8999486a1cef17ca43f4cc4e1 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1113,7 +1113,9 @@ void mhi_ep_handle_syserr(struct mhi_ep_cntrl *mhi_cntrl)
struct device *dev = &mhi_cntrl->mhi_dev->dev;
int ret;
+ mutex_lock(&mhi_cntrl->state_lock);
ret = mhi_ep_set_mhi_state(mhi_cntrl, MHI_STATE_SYS_ERR);
+ mutex_unlock(&mhi_cntrl->state_lock);
if (ret)
return;
@@ -1148,7 +1150,9 @@ int mhi_ep_power_up(struct mhi_ep_cntrl *mhi_cntrl)
for (i = 0; i < mhi_cntrl->event_rings; i++)
mhi_ep_ring_init(&mhi_cntrl->mhi_event[i].ring, RING_TYPE_ER, i);
+ mutex_lock(&mhi_cntrl->state_lock);
mhi_cntrl->mhi_state = MHI_STATE_RESET;
+ mutex_unlock(&mhi_cntrl->state_lock);
/* Set AMSS EE before signaling ready state */
mhi_ep_mmio_set_env(mhi_cntrl, MHI_EE_AMSS);
--
2.34.1
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
2026-02-03 6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
@ 2026-03-02 9:01 ` Manivannan Sadhasivam
0 siblings, 0 replies; 5+ messages in thread
From: Manivannan Sadhasivam @ 2026-03-02 9:01 UTC (permalink / raw)
To: Sumit Kumar
Cc: Alex Elder, Greg Kroah-Hartman, mhi, linux-arm-msm, linux-kernel,
Veerabhadrarao Badiganti, Subramanian Ananthanarayanan,
Akhil Vinod
On Tue, Feb 03, 2026 at 12:25:01PM +0530, Sumit Kumar wrote:
> There is a potential deadlock scenario in mhi_ep_reset_worker() where
> the state_lock mutex is acquired twice in the same call chain:
>
> mhi_ep_reset_worker()
> mutex_lock(&mhi_cntrl->state_lock)
> mhi_ep_power_up()
> mhi_ep_set_ready_state()
> mutex_lock(&mhi_cntrl->state_lock) <- Deadlock
>
> Fix this by releasing the state_lock before calling mhi_ep_power_up().
> The lock is only needed to protect current MHI state read operation. The
> lock can be safely released before proceeding with the power up sequence.
>
While inspecting the code, I also found one instance where
mhi_ep_handle_syserr() was not locked. I've sent a patch to fix it. Please spare
some time to test it and give a tested-by tag.
> Fixes: 7a97b6b47353 ("bus: mhi: ep: Add support for handling MHI_RESET")
> Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
> ---
> drivers/bus/mhi/ep/main.c | 3 +--
> 1 file changed, 1 insertion(+), 2 deletions(-)
>
> diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
> index cdea24e9291959ae0a92487c1b9698dc8164d2f1..73597de373ef7e0c428bcbc126d63a9a97f95144 100644
> --- a/drivers/bus/mhi/ep/main.c
> +++ b/drivers/bus/mhi/ep/main.c
> @@ -1093,6 +1093,7 @@ static void mhi_ep_reset_worker(struct work_struct *work)
> mhi_ep_mmio_reset(mhi_cntrl);
You can also perform locking after mhi_ep_mmio_reset(). There is no need to
protect mhi_ep_mmio_reset().
- Mani
--
மணிவண்ணன் சதாசிவம்
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses
2026-02-03 6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
@ 2026-03-02 9:33 ` Manivannan Sadhasivam
0 siblings, 0 replies; 5+ messages in thread
From: Manivannan Sadhasivam @ 2026-03-02 9:33 UTC (permalink / raw)
To: Sumit Kumar
Cc: Alex Elder, Greg Kroah-Hartman, mhi, linux-arm-msm, linux-kernel,
Veerabhadrarao Badiganti, Subramanian Ananthanarayanan,
Akhil Vinod
On Tue, Feb 03, 2026 at 12:25:02PM +0530, Sumit Kumar wrote:
> The mhi_cntrl->mhi_state field should be protected by state_lock to
> ensure atomic state transitions. However, mhi_ep_handle_syserr() and
> mhi_ep_power_up() access mhi_state without holding this lock, which can
> race with concurrent state transitions and lead to state corruption.
>
> Add proper state_lock protection in both functions around their mhi_state
> accesses.
>
> Fixes: fb3a26b7e8af ("bus: mhi: ep: Add support for powering up the MHI endpoint stack")
> Fixes: f7d0806bdb1b3 ("bus: mhi: ep: Add support for handling SYS_ERR condition")
> Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
> ---
> drivers/bus/mhi/ep/main.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
> index 73597de373ef7e0c428bcbc126d63a9a97f95144..e9d14006453aa8b8999486a1cef17ca43f4cc4e1 100644
> --- a/drivers/bus/mhi/ep/main.c
> +++ b/drivers/bus/mhi/ep/main.c
> @@ -1113,7 +1113,9 @@ void mhi_ep_handle_syserr(struct mhi_ep_cntrl *mhi_cntrl)
> struct device *dev = &mhi_cntrl->mhi_dev->dev;
> int ret;
>
> + mutex_lock(&mhi_cntrl->state_lock);
> ret = mhi_ep_set_mhi_state(mhi_cntrl, MHI_STATE_SYS_ERR);
> + mutex_unlock(&mhi_cntrl->state_lock);
Ah, I sent my patch *before* seeing this one. But still this part is wrong and
will cause deadlock as callers were already holding 'state_lock'.
So drop this part in favor of:
https://lore.kernel.org/mhi/20260302085612.18725-1-manivannan.sadhasivam@oss.qualcomm.com
> if (ret)
> return;
>
> @@ -1148,7 +1150,9 @@ int mhi_ep_power_up(struct mhi_ep_cntrl *mhi_cntrl)
> for (i = 0; i < mhi_cntrl->event_rings; i++)
> mhi_ep_ring_init(&mhi_cntrl->mhi_event[i].ring, RING_TYPE_ER, i);
>
> + mutex_lock(&mhi_cntrl->state_lock);
> mhi_cntrl->mhi_state = MHI_STATE_RESET;
> + mutex_unlock(&mhi_cntrl->state_lock);
>
This looks fine.
- Mani
--
மணிவண்ணன் சதாசிவம்
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2026-03-02 9:34 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-02-03 6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
2026-02-03 6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
2026-03-02 9:01 ` Manivannan Sadhasivam
2026-02-03 6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
2026-03-02 9:33 ` Manivannan Sadhasivam
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®