From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C8C6A33BBBA for ; Thu, 11 Jun 2026 03:53:07 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781149989; cv=none; b=B0G39ab1khHC0ng3PLefIESicsA2R/TYusIbL/4lynMf/9gQ3zwwlN6khITPjqJ2eI4sSzh4nmL/DJFUYiZCy5BzBX3x10pvaJAMNNS17+v8cVF39ShtGt5quraKdGtX5xEEMj/ycDdc/h7tKqXrCOGtGIVCnZCVKF9GF0jBn5E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781149989; c=relaxed/simple; bh=RWGgQ+fIx5zEE7hIr/SdyaUnQQt8wM2jyEcHAPXGR1o=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=L1aL/cFlAVrSlrdIxq2Zz2vye8hmX4YIDhU4qGy/m7zgS4Rk7eLx+Vr+keb2WtkC0PMzAGPNF6GlztbuLaZhiFC8SxU9ur91ZJt5mIwBfcbicBY7GIfrNprdi/tS0ggyYtOBJqFpXEnBEmW1NYDtmeoHwbPihWfSdI0wR8HbDVA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=JgF/g1dl; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="JgF/g1dl" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-36bba9a1089so4470127a91.3 for ; Wed, 10 Jun 2026 20:53:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781149987; x=1781754787; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=twBxGuT7Vyeqc2tSt+1Cu5dVnnD709Tu79Udll0+igY=; b=JgF/g1dlR9yUXz5jMKZsKEYcnMC5+68CN3eLima2V0DYhYaINM1Zt8R8lwCRYnBwbe WjV2QtGy5wLuU6t3hu+tgoOmxlRWgj5C0hfhQ77XGvOIwm143HRAGTDbvOAp3opSZ7XW V5IHwvxNIzbaBRyft733gnZvA+Vjw4tzP8HlwZlR0sqyblbT0BeutQSNSgcUKmyUo0Yi FVsJQGQvqsQh5vqFWzhsC5IB0malOQ02002vk3HLzPhY8ZBbKAKRdapruJrJYlkm8gL0 iq+nRhH5bpvsofiFf8aCHb1MLmcjN4pnekudhCwby48iDN3v8iN52WYk1pcHOviXdRJw FB6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781149987; x=1781754787; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=twBxGuT7Vyeqc2tSt+1Cu5dVnnD709Tu79Udll0+igY=; b=mO2h27yiYp+A83gF4V2ZqX3LhBKk/EZ7e2oQqvGqtFpDLKL7bYcCsGJLpr+6N+80s/ 4EqRNQXGo/sAoulfedGJ4HslbB0tmj2/aODZebWZB3TJuJ3TSbORKau56tRRKoGlBbI/ cE0yop0ekY1h0hK20MMuE1Zk5haB7NaO5eMbg1wujetEn24MRBaXuokGKHhNPuHMYMvL 3MCYoYwz4iTWaocbmPynXcPhbjXCKUc/B3NneThtDU4z/ePZ49V2mNZf/GTxP8qwjDnC C4FPoG4UrG1Pyjun4+hk49/qDiZgaBQt9gRDL/cXpSodElahuXIOIP66tpTaEjBnuH/5 /xKQ== X-Forwarded-Encrypted: i=1; AFNElJ91bY8na+6dypQNRU1OAHyXpY2f80/Vyb+GNnvHS+StBXWPqy++CsXsKk8Uk4abF6mwdo14yN+HcmeCAX4=@vger.kernel.org X-Gm-Message-State: AOJu0Yz4sUY2YfyDtdz7F8mz62J2+mP3YeP/sYINFzIWjifLDgg4iAqR H4boITikSiQzEn/xM5weCRmZrOOtvLaBZK5NreSndvLlrW8B1ISoT9gB X-Gm-Gg: Acq92OHuw/0q4AsmAaKGnujw2Y1k0vzK6cF6ROfkjEjOdSE4nJrAInJ/9IIbufx2boV V2vSx0ygciLFKgfBm4cJxBeBKS51YG1y+Js0jaPt2XPYdZ7Quj1BCR/OqkUA1iJkLiCJgawhNE2 yAdnUmNaEl8AMiaMBPtLOhd57j+bk5kBb7+uKG1v0dfXUuxIs7lUOpVbEKVg/G4x1xBarwfP83D d88zzWDg7sOJQ5I5fVTTR/hJvZJOPshlTln+BuUSv9K+QzY1Kun0Lao7pZpBng9CcJYHk3P1HXU qvqSiwyPZw5Qg7BSc8B9/IKNCMliawxbTU8oiwW9/xPzJCXuOfg/NoUd+ximOYVgSdSCraCFr6r XcQ0GmTipaDX0nsO2ZhOmKxtICZp5erFBbRm/hvV2YMD1ptgMdLLhsk9+asCZ99VV3k8oAQuLLZ tsuocmMnckAnX8ga9D0Dr5bgL70SuOtDg0zsG/sdMEKNJ8wIxG4Ap8gGKFED8DybRPR3CSDobGp wF0zK9388g0U434yp3lU7n2TtxO4zIzNbW3kWNMJkpkpg== X-Received: by 2002:a17:90b:4984:b0:36c:e254:4d5 with SMTP id 98e67ed59e1d1-3779c569455mr1233425a91.4.1781149987152; Wed, 10 Jun 2026 20:53:07 -0700 (PDT) Received: from ryzen ([2601:644:8000:5b5d:7285:c2ff:fe45:8a32]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-377522a188asm910131a91.3.2026.06.10.20.53.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 10 Jun 2026 20:53:06 -0700 (PDT) From: Rosen Penev To: dmaengine@vger.kernel.org Cc: Vinod Koul , Frank Li , Zhang Wei , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , linux-kernel@vger.kernel.org (open list), linuxppc-dev@lists.ozlabs.org (open list:FREESCALE DMA DRIVER), llvm@lists.linux.dev (open list:CLANG/LLVM BUILD SUPPORT:Keyword:\b(?i:clang|llvm)\b) Subject: [PATCHv4 02/15] dmaengine: fsldma: drop desc_lock before invoking client callback Date: Wed, 10 Jun 2026 20:52:32 -0700 Message-ID: <20260611035245.13439-3-rosenp@gmail.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260611035245.13439-1-rosenp@gmail.com> References: <20260611035245.13439-1-rosenp@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit fsldma_run_tx_complete_actions() calls dmaengine_desc_get_callback_invoke() while still holding chan->desc_lock. If the client submits a new transaction from their completion callback, fsl_dma_tx_submit() tries to acquire the same non-recursive spinlock, causing a self-deadlock. Fix by extracting the callback info under the lock, removing the descriptor from ld_running, dropping the lock, then invoking the callback and running dependencies outside the lock. Assisted-by: opencode:big-pickle Signed-off-by: Rosen Penev --- drivers/dma/fsldma.c | 108 ++++++++++++++++++++++--------------------- 1 file changed, 55 insertions(+), 53 deletions(-) diff --git a/drivers/dma/fsldma.c b/drivers/dma/fsldma.c index 0e2f84862261..455d21d738de 100644 --- a/drivers/dma/fsldma.c +++ b/drivers/dma/fsldma.c @@ -496,16 +496,19 @@ static void fsldma_clean_completed_descriptor(struct fsldma_chan *chan) } /** - * fsldma_run_tx_complete_actions - cleanup a single link descriptor + * fsldma_run_tx_complete_actions - unmap and extract callback from a descriptor * @chan: Freescale DMA channel - * @desc: descriptor to cleanup and free + * @desc: descriptor to process * @cookie: Freescale DMA transaction identifier + * @cb: returned callback information * - * This function is used on a descriptor which has been executed by the DMA - * controller. It will run any callbacks, submit any dependencies. + * Unmap the descriptor if it has been submitted and extract its callback + * into @cb. The caller must invoke the callback and run dependencies + * after releasing chan->desc_lock. */ static dma_cookie_t fsldma_run_tx_complete_actions(struct fsldma_chan *chan, - struct fsl_desc_sw *desc, dma_cookie_t cookie) + struct fsl_desc_sw *desc, dma_cookie_t cookie, + struct dmaengine_desc_callback *cb) { struct dma_async_tx_descriptor *txd = &desc->async_tx; dma_cookie_t ret = cookie; @@ -514,49 +517,14 @@ static dma_cookie_t fsldma_run_tx_complete_actions(struct fsldma_chan *chan, if (txd->cookie > 0) { ret = txd->cookie; - dma_descriptor_unmap(txd); - /* Run the link descriptor callback function */ - dmaengine_desc_get_callback_invoke(txd, NULL); } - /* Run any dependencies */ - dma_run_dependencies(txd); + dmaengine_desc_get_callback(txd, cb); return ret; } -/** - * fsldma_clean_running_descriptor - move the completed descriptor from - * ld_running to ld_completed - * @chan: Freescale DMA channel - * @desc: the descriptor which is completed - * - * Free the descriptor directly if acked by async_tx api, or move it to - * queue ld_completed. - */ -static void fsldma_clean_running_descriptor(struct fsldma_chan *chan, - struct fsl_desc_sw *desc) -{ - /* Remove from the list of transactions */ - list_del(&desc->node); - - /* - * the client is allowed to attach dependent operations - * until 'ack' is set - */ - if (!async_tx_test_ack(&desc->async_tx)) { - /* - * Move this descriptor to the list of descriptors which is - * completed, but still awaiting the 'ack' bit to be set. - */ - list_add_tail(&desc->node, &chan->ld_completed); - return; - } - - dma_pool_free(chan->desc_pool, desc, desc->async_tx.phys); -} - /** * fsl_chan_xfer_ld_queue - transfer any pending transactions * @chan : Freescale DMA channel @@ -635,22 +603,23 @@ static void fsl_chan_xfer_ld_queue(struct fsldma_chan *chan) */ static void fsldma_cleanup_descriptors(struct fsldma_chan *chan) { - struct fsl_desc_sw *desc, *_desc; + struct fsl_desc_sw *desc; dma_cookie_t cookie = 0; dma_addr_t curr_phys = get_cdar(chan); int seen_current = 0; fsldma_clean_completed_descriptor(chan); - /* Run the callback for each descriptor, in order */ - list_for_each_entry_safe(desc, _desc, &chan->ld_running, node) { - /* - * do not advance past the current descriptor loaded into the - * hardware channel, subsequent descriptors are either in - * process or have not been submitted - */ - if (seen_current) - break; + /* + * Take descriptors one at a time from the front of the running + * queue. We re-read the list each iteration so that we don't + * chase a stale next pointer across the lock-drop below. + */ + while (!seen_current && !list_empty(&chan->ld_running)) { + struct dmaengine_desc_callback cb; + + desc = list_first_entry(&chan->ld_running, + struct fsl_desc_sw, node); /* * stop the search if we reach the current descriptor and the @@ -662,9 +631,42 @@ static void fsldma_cleanup_descriptors(struct fsldma_chan *chan) break; } - cookie = fsldma_run_tx_complete_actions(chan, desc, cookie); + cookie = fsldma_run_tx_complete_actions(chan, desc, cookie, &cb); - fsldma_clean_running_descriptor(chan, desc); + /* + * Remove from the running list before dropping the lock so + * that terminate_all cannot free this descriptor while we + * call into the client below. + */ + list_del(&desc->node); + + /* + * Prevent dma_run_dependencies() from calling + * fsl_chan_xfer_ld_queue() while we are not holding the + * lock. That would splice pending descriptors into + * ld_running before they have been completed by hardware. + * fsl_chan_xfer_ld_queue at the end of this function will + * re-evaluate the situation. + */ + chan->idle = false; + + /* + * Drop the lock before invoking the client callback, since + * the DMAengine API explicitly allows clients to submit new + * transactions from their completion callback. Otherwise + * we self-deadlock on chan->desc_lock. + */ + spin_unlock(&chan->desc_lock); + dmaengine_desc_callback_invoke(&cb, NULL); + dma_run_dependencies(&desc->async_tx); + spin_lock(&chan->desc_lock); + + chan->idle = true; + + if (!async_tx_test_ack(&desc->async_tx)) + list_add_tail(&desc->node, &chan->ld_completed); + else + dma_pool_free(chan->desc_pool, desc, desc->async_tx.phys); } /* -- 2.54.0