mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues
@ 2026-02-03  6:55 Sumit Kumar
  2026-02-03  6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
  2026-02-03  6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
  0 siblings, 2 replies; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03  6:55 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
  Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
	Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar

This series fixes a deadlock in mhi_ep_reset_worker() where state_lock is
acquired twice, and adds missing lock protection for mhi_state accesses
in mhi_ep_handle_syserr() and mhi_ep_power_up() to prevent race conditions
and state machine corruption.

Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
Sumit Kumar (2):
      bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
      bus: mhi: ep: Add missing state_lock protection for mhi_state accesses

 drivers/bus/mhi/ep/main.c | 7 +++++--
 1 file changed, 5 insertions(+), 2 deletions(-)
---
base-commit: 6fa9041b7177f6771817b95e83f6df17b147c8c6
change-id: 20251113-reset_worker_deadlock-0223907f7c9d

Best regards,
-- 
Sumit Kumar <sumit.kumar@oss.qualcomm.com>


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  2026-02-03  6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
@ 2026-02-03  6:55 ` Sumit Kumar
  2026-03-02  9:01   ` Manivannan Sadhasivam
  2026-02-03  6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
  1 sibling, 1 reply; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03  6:55 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
  Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
	Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar

There is a potential deadlock scenario in mhi_ep_reset_worker() where
the state_lock mutex is acquired twice in the same call chain:

mhi_ep_reset_worker()
  mutex_lock(&mhi_cntrl->state_lock)
    mhi_ep_power_up()
      mhi_ep_set_ready_state()
        mutex_lock(&mhi_cntrl->state_lock)  <- Deadlock

Fix this by releasing the state_lock before calling mhi_ep_power_up().
The lock is only needed to protect current MHI state read operation. The
lock can be safely released before proceeding with the power up sequence.

Fixes: 7a97b6b47353 ("bus: mhi: ep: Add support for handling MHI_RESET")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
 drivers/bus/mhi/ep/main.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index cdea24e9291959ae0a92487c1b9698dc8164d2f1..73597de373ef7e0c428bcbc126d63a9a97f95144 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1093,6 +1093,7 @@ static void mhi_ep_reset_worker(struct work_struct *work)
 	mhi_ep_mmio_reset(mhi_cntrl);
 	cur_state = mhi_cntrl->mhi_state;
 
+	mutex_unlock(&mhi_cntrl->state_lock);
 	/*
 	 * Only proceed further if the reset is due to SYS_ERR. The host will
 	 * issue reset during shutdown also and we don't need to do re-init in
@@ -1100,8 +1101,6 @@ static void mhi_ep_reset_worker(struct work_struct *work)
 	 */
 	if (cur_state == MHI_STATE_SYS_ERR)
 		mhi_ep_power_up(mhi_cntrl);
-
-	mutex_unlock(&mhi_cntrl->state_lock);
 }
 
 /*

-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses
  2026-02-03  6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
  2026-02-03  6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
@ 2026-02-03  6:55 ` Sumit Kumar
  2026-03-02  9:33   ` Manivannan Sadhasivam
  1 sibling, 1 reply; 5+ messages in thread
From: Sumit Kumar @ 2026-02-03  6:55 UTC (permalink / raw)
  To: Manivannan Sadhasivam, Alex Elder, Greg Kroah-Hartman
  Cc: mhi, linux-arm-msm, linux-kernel, Veerabhadrarao Badiganti,
	Subramanian Ananthanarayanan, Akhil Vinod, Sumit Kumar

The mhi_cntrl->mhi_state field should be protected by state_lock to
ensure atomic state transitions. However, mhi_ep_handle_syserr() and
mhi_ep_power_up() access mhi_state without holding this lock, which can
race with concurrent state transitions and lead to state corruption.

Add proper state_lock protection in both functions around their mhi_state
accesses.

Fixes: fb3a26b7e8af ("bus: mhi: ep: Add support for powering up the MHI endpoint stack")
Fixes: f7d0806bdb1b3 ("bus: mhi: ep: Add support for handling SYS_ERR condition")
Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
---
 drivers/bus/mhi/ep/main.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
index 73597de373ef7e0c428bcbc126d63a9a97f95144..e9d14006453aa8b8999486a1cef17ca43f4cc4e1 100644
--- a/drivers/bus/mhi/ep/main.c
+++ b/drivers/bus/mhi/ep/main.c
@@ -1113,7 +1113,9 @@ void mhi_ep_handle_syserr(struct mhi_ep_cntrl *mhi_cntrl)
 	struct device *dev = &mhi_cntrl->mhi_dev->dev;
 	int ret;
 
+	mutex_lock(&mhi_cntrl->state_lock);
 	ret = mhi_ep_set_mhi_state(mhi_cntrl, MHI_STATE_SYS_ERR);
+	mutex_unlock(&mhi_cntrl->state_lock);
 	if (ret)
 		return;
 
@@ -1148,7 +1150,9 @@ int mhi_ep_power_up(struct mhi_ep_cntrl *mhi_cntrl)
 	for (i = 0; i < mhi_cntrl->event_rings; i++)
 		mhi_ep_ring_init(&mhi_cntrl->mhi_event[i].ring, RING_TYPE_ER, i);
 
+	mutex_lock(&mhi_cntrl->state_lock);
 	mhi_cntrl->mhi_state = MHI_STATE_RESET;
+	mutex_unlock(&mhi_cntrl->state_lock);
 
 	/* Set AMSS EE before signaling ready state */
 	mhi_ep_mmio_set_env(mhi_cntrl, MHI_EE_AMSS);

-- 
2.34.1


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker()
  2026-02-03  6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
@ 2026-03-02  9:01   ` Manivannan Sadhasivam
  0 siblings, 0 replies; 5+ messages in thread
From: Manivannan Sadhasivam @ 2026-03-02  9:01 UTC (permalink / raw)
  To: Sumit Kumar
  Cc: Alex Elder, Greg Kroah-Hartman, mhi, linux-arm-msm, linux-kernel,
	Veerabhadrarao Badiganti, Subramanian Ananthanarayanan,
	Akhil Vinod

On Tue, Feb 03, 2026 at 12:25:01PM +0530, Sumit Kumar wrote:
> There is a potential deadlock scenario in mhi_ep_reset_worker() where
> the state_lock mutex is acquired twice in the same call chain:
> 
> mhi_ep_reset_worker()
>   mutex_lock(&mhi_cntrl->state_lock)
>     mhi_ep_power_up()
>       mhi_ep_set_ready_state()
>         mutex_lock(&mhi_cntrl->state_lock)  <- Deadlock
> 
> Fix this by releasing the state_lock before calling mhi_ep_power_up().
> The lock is only needed to protect current MHI state read operation. The
> lock can be safely released before proceeding with the power up sequence.
> 

While inspecting the code, I also found one instance where
mhi_ep_handle_syserr() was not locked. I've sent a patch to fix it. Please spare
some time to test it and give a tested-by tag.

> Fixes: 7a97b6b47353 ("bus: mhi: ep: Add support for handling MHI_RESET")
> Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
> ---
>  drivers/bus/mhi/ep/main.c | 3 +--
>  1 file changed, 1 insertion(+), 2 deletions(-)
> 
> diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
> index cdea24e9291959ae0a92487c1b9698dc8164d2f1..73597de373ef7e0c428bcbc126d63a9a97f95144 100644
> --- a/drivers/bus/mhi/ep/main.c
> +++ b/drivers/bus/mhi/ep/main.c
> @@ -1093,6 +1093,7 @@ static void mhi_ep_reset_worker(struct work_struct *work)
>  	mhi_ep_mmio_reset(mhi_cntrl);

You can also perform locking after mhi_ep_mmio_reset(). There is no need to
protect mhi_ep_mmio_reset().

- Mani

-- 
மணிவண்ணன் சதாசிவம்

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses
  2026-02-03  6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
@ 2026-03-02  9:33   ` Manivannan Sadhasivam
  0 siblings, 0 replies; 5+ messages in thread
From: Manivannan Sadhasivam @ 2026-03-02  9:33 UTC (permalink / raw)
  To: Sumit Kumar
  Cc: Alex Elder, Greg Kroah-Hartman, mhi, linux-arm-msm, linux-kernel,
	Veerabhadrarao Badiganti, Subramanian Ananthanarayanan,
	Akhil Vinod

On Tue, Feb 03, 2026 at 12:25:02PM +0530, Sumit Kumar wrote:
> The mhi_cntrl->mhi_state field should be protected by state_lock to
> ensure atomic state transitions. However, mhi_ep_handle_syserr() and
> mhi_ep_power_up() access mhi_state without holding this lock, which can
> race with concurrent state transitions and lead to state corruption.
> 
> Add proper state_lock protection in both functions around their mhi_state
> accesses.
> 
> Fixes: fb3a26b7e8af ("bus: mhi: ep: Add support for powering up the MHI endpoint stack")
> Fixes: f7d0806bdb1b3 ("bus: mhi: ep: Add support for handling SYS_ERR condition")
> Signed-off-by: Sumit Kumar <sumit.kumar@oss.qualcomm.com>
> ---
>  drivers/bus/mhi/ep/main.c | 4 ++++
>  1 file changed, 4 insertions(+)
> 
> diff --git a/drivers/bus/mhi/ep/main.c b/drivers/bus/mhi/ep/main.c
> index 73597de373ef7e0c428bcbc126d63a9a97f95144..e9d14006453aa8b8999486a1cef17ca43f4cc4e1 100644
> --- a/drivers/bus/mhi/ep/main.c
> +++ b/drivers/bus/mhi/ep/main.c
> @@ -1113,7 +1113,9 @@ void mhi_ep_handle_syserr(struct mhi_ep_cntrl *mhi_cntrl)
>  	struct device *dev = &mhi_cntrl->mhi_dev->dev;
>  	int ret;
>  
> +	mutex_lock(&mhi_cntrl->state_lock);
>  	ret = mhi_ep_set_mhi_state(mhi_cntrl, MHI_STATE_SYS_ERR);
> +	mutex_unlock(&mhi_cntrl->state_lock);

Ah, I sent my patch *before* seeing this one. But still this part is wrong and
will cause deadlock as callers were already holding 'state_lock'.

So drop this part in favor of:
https://lore.kernel.org/mhi/20260302085612.18725-1-manivannan.sadhasivam@oss.qualcomm.com

>  	if (ret)
>  		return;
>  
> @@ -1148,7 +1150,9 @@ int mhi_ep_power_up(struct mhi_ep_cntrl *mhi_cntrl)
>  	for (i = 0; i < mhi_cntrl->event_rings; i++)
>  		mhi_ep_ring_init(&mhi_cntrl->mhi_event[i].ring, RING_TYPE_ER, i);
>  
> +	mutex_lock(&mhi_cntrl->state_lock);
>  	mhi_cntrl->mhi_state = MHI_STATE_RESET;
> +	mutex_unlock(&mhi_cntrl->state_lock);
>  

This looks fine.

- Mani

-- 
மணிவண்ணன் சதாசிவம்

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-03-02  9:34 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-02-03  6:55 [PATCH 0/2] bus: mhi: ep: Fix state_lock protection issues Sumit Kumar
2026-02-03  6:55 ` [PATCH 1/2] bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() Sumit Kumar
2026-03-02  9:01   ` Manivannan Sadhasivam
2026-02-03  6:55 ` [PATCH 2/2] bus: mhi: ep: Add missing state_lock protection for mhi_state accesses Sumit Kumar
2026-03-02  9:33   ` Manivannan Sadhasivam

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®