From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f50.google.com (mail-qv1-f50.google.com [209.85.219.50]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E35F6448D12 for ; Tue, 28 Jul 2026 14:17:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.50 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785248253; cv=none; b=FqEV2HF2e0V3byvhv+Yai8mX+aF9BSNRAM4LTxcvsUY9lBYrIE1qxXkIfZ9uWv3fy8VVOq+17fvvxax2bp87IdUsyLQFWMePccqfsbxykbE60GqqSCp1B0Q9wzX4fLNZJB64WoUaNw32bTB1ejEXLTc15EV/jvciDuTEnJX8eoY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785248253; c=relaxed/simple; bh=GMBJxU+iC6WYPC48enAZZXUKRSG2uG3jL/7OYe5qSQk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GZmsv/XtFUkBlTTDSXkAjKs2VQgYXTEwXSgSTG+V/Q+TjAkkOHdFOAWT6YNJTTOjUL6JFfTjzdZo9Eto0CqozCVEPNlc/4HyOBltVuT1nSdk4tgMWDLVt/IhkCxS1OWLM6ZrnQzffDXcTqJt/FCpp9EqXoyLHZbb8IVONOGzIN0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=bKWt3NQU; arc=none smtp.client-ip=209.85.219.50 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="bKWt3NQU" Received: by mail-qv1-f50.google.com with SMTP id 6a1803df08f44-8f29ec73064so29185946d6.1 for ; Tue, 28 Jul 2026 07:17:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785248251; x=1785853051; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=9sjhmtv/uEmlahFxE8xqef6JXqKOdBStYEX1wvTOt6Y=; b=bKWt3NQU9eBMs+ovVOEXVjZ24+tAwZmcPPyYyrOhmW51DNsdkM6UE3gROwhkgeJEJ3 WGoImBKa95a6+kF6YMUTGgAD74gUD621PwwwTh+9yqamT9TjEL+QVATJarNg7AzFY+Cy HqGZoK0lgS9fTiRz2JvbKg2SnHB9KDiqSLCDIviMHL7RPX+vFA5rVLhzyy5nm7B5kaHv wlIvK7ag2g5Uq1TChpECNI89+okR6AoXJli14NT58fz2hBh6arPxrLAtVrOPT/zpuud5 O7MGLkhK55zBLtdUqyvAtMs2nKg2cFZy7HcukHCqrlLMhFQVl3TIm129bHCQLCJeTkhw QvQg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785248251; x=1785853051; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=9sjhmtv/uEmlahFxE8xqef6JXqKOdBStYEX1wvTOt6Y=; b=E4JzN16mJBLQerylUY42dviDqZOOWxxYTBSLeNHML3kG6+9J3n8Smc40Fsf10GcNvu z0zRpsCbPuFM4bRQkLGH7IlATAxZF0ExDlJ6L5U+o33fOfsf1rURkxHmGICyFLDwaa9b gjKs/ym/M62nNQLbhFUfEENLd/VvvwUhaGjuFjHyCGspKVFS2e+I45VWM44rOLM30Kbb OLJPADSVHhsco30LVml97pd5+x2CnQOViCvlHGzW9vbuzOkWsuixKqiaOxbBejz3Z5DE Vichta4tVa7EkQqYzfQuznWZ5Ue//MQebIXNxcrjjX5OXqsmrO3Y5dnXgSS7LTMSWzVF lb2Q== X-Forwarded-Encrypted: i=1; AHgh+RqZdbTYMCUdVltWaoqbYfGI4fukQNXA1GWBxXUAgC1+dDiFSQpC4e18+jn6vDUqONN7ECNIx/5eBATlurw=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5SdYaxafCKSDbZU+rqHySvha7wkcCodo0UhH87ZaTdIp5EbGT zo/rJd2BeWi9tRRRsKslgB23V0szF1R8gly/GamYnxYAITYEWqZr9skl X-Gm-Gg: AR+sD10VgC7KTJkxzqv9ZSd6x3Au4Gc1BHkXO+4SBth8RZe16xlE6B0ofAEV3nIraiR lkccLeJ3pRzmIsNDjja1OpztAlg8PfHpHRdNiuHiu84iOr1KFi4P6aslscUMHrBp2u7chaWMvQ2 I4wBPnwUTwyVVgH+xRsUBUiyQmSWj9IhII6jbJ5efMOzbBGqV9DFBu+2tWpQOVQ0tAv823W6XMh xX5KMsQIxb29etCYAHUGeFfU++HsHrmokBBgQt6aUtF/0eYgrLGmamH9ry2uyBNeLCEq8YnbSBa 7vUcpWnot+R2O0GahSlWLOP3tw8q5hdwQZIrFw/mrU3VHNfNNw+o2XKztNaK1QhNyNCN+EYA6ST ZcHKJXXG5CXkOBhXYkcBAZyChOlq44wDdOZuvKOSufZDURgW9ubwLQ17YTtI0wPow59Py+JaU4z qrdU5QezADbMixby8OU4tO1SViUF57zoQVfpwkm5BKsKo5Z4pw9NcXmVFtLhKxpAZOyZQBjz8hu 5UKr9SM29dHa85j1WEK3NJ9amODrtp21lzUBBJW5OM= X-Received: by 2002:ad4:5aee:0:b0:8cc:ea95:2261 with SMTP id 6a1803df08f44-908172b02dfmr28914246d6.36.1785248250544; Tue, 28 Jul 2026 07:17:30 -0700 (PDT) Received: from LAPTOP-DPAKMOI4.it.purdue.edu (pal-210-106-74.itap.purdue.edu. [128.210.106.74]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-9081dd3b56esm85856d6.26.2026.07.28.07.17.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 07:17:30 -0700 (PDT) From: Yifei Gao To: Bin Du , Nirujogi Pratap , Mauro Carvalho Chehab , Sakari Ailus Cc: Sultan Alsawaf , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Yifei Gao Subject: [PATCH v3 2/2] media: amd: isp4: fix self-deadlock in isp4sd_pwron_and_init() error path Date: Tue, 28 Jul 2026 14:16:50 +0000 Message-ID: <20260728141659.62310-3-gyf161023@gmail.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260728141659.62310-1-gyf161023@gmail.com> References: <20260727183500.298036-1-gyf161023@gmail.com> <20260728141659.62310-1-gyf161023@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit isp4sd_pwron_and_init() holds ops_mutex through guard(mutex) for the whole function. On any initialization failure it jumps to the err_deinit label and calls isp4sd_pwroff_and_deinit(), which takes the same ops_mutex through its own guard(mutex). Because the guard in isp4sd_pwron_and_init() still holds the lock at err_deinit, the call re-acquires a non-recursive mutex held by the same thread and deadlocks on any initialization failure. The error path cannot simply drop the lock and keep calling the full teardown, because that teardown is not valid at the earlier failure points. In particular, pm_runtime_resume_and_get() drops the usage counter again on failure (via pm_runtime_put_noidle()), so no PM reference is held when it returns an error; calling pm_runtime_put_sync() unconditionally would underflow the usage count, and the teardown would also touch ISP MMIO while the device is not powered. This was previously masked by the deadlock, since the thread never reached the teardown body. Replace the single teardown call with staged labels that unwind only the resources actually acquired at each failure point. The error path no longer calls the locked isp4sd_pwroff_and_deinit(), which removes the deadlock, and each failure now skips the steps it never reached, keeping the runtime-PM count balanced and not accessing MMIO while unpowered. isp4if_start() and isp4sd_start_resp_proc_threads() already clean up after themselves on failure, so their resources are not unwound again. Fixes: 4e5e7a7ddb4a ("media: platform: amd: isp4 subdev and firmware loading handling added") Assisted-by: Claude:claude-opus-4-8 smatch Signed-off-by: Yifei Gao --- drivers/media/platform/amd/isp4/isp4_subdev.c | 28 +++++++++++++++---- 1 file changed, 22 insertions(+), 6 deletions(-) diff --git a/drivers/media/platform/amd/isp4/isp4_subdev.c b/drivers/media/platform/amd/isp4/isp4_subdev.c index 48deea79ce6c..868d1c74d35e 100644 --- a/drivers/media/platform/amd/isp4/isp4_subdev.c +++ b/drivers/media/platform/amd/isp4/isp4_subdev.c @@ -687,7 +687,7 @@ int isp4sd_pwron_and_init(struct v4l2_subdev *sd) if (ret) { dev_err(dev, "fail to power on isp_subdev ret %d\n", ret); - goto err_deinit; + goto err_module_disable; } /* ISPPG ISP Power Status */ @@ -697,7 +697,7 @@ int isp4sd_pwron_and_init(struct v4l2_subdev *sd) dev_err(dev, "fail to set performance state %u, ret %d\n", perf_state, ret); - goto err_deinit; + goto err_power_off; } ispif->status = ISP4IF_STATUS_PWR_ON; @@ -709,12 +709,12 @@ int isp4sd_pwron_and_init(struct v4l2_subdev *sd) ret = isp4if_start(ispif); if (ret) { dev_err(dev, "fail to start isp_subdev interface\n"); - goto err_deinit; + goto err_perf_restore; } if (isp4sd_start_resp_proc_threads(isp_subdev)) { dev_err(dev, "isp_start_resp_proc_threads fail\n"); - goto err_deinit; + goto err_stop_interface; } dev_dbg(dev, "create resp threads ok\n"); @@ -724,8 +724,24 @@ int isp4sd_pwron_and_init(struct v4l2_subdev *sd) isp_subdev->irq_enabled = true; return 0; -err_deinit: - isp4sd_pwroff_and_deinit(sd); + +err_stop_interface: + isp4if_stop(ispif); +err_perf_restore: + ret = dev_pm_genpd_set_performance_state(dev, ISP4SD_PERFORMANCE_STATE_LOW); + if (ret) + dev_err(dev, "fail to set performance state %u, ret %d\n", + ISP4SD_PERFORMANCE_STATE_LOW, ret); +err_power_off: + isp4hw_wreg(isp_subdev->mmio, ISP_SOFT_RESET, 0); + isp4hw_wreg(isp_subdev->mmio, ISP_POWER_STATUS, 0); + ret = pm_runtime_put_sync(dev); + if (ret) + dev_err(dev, "power off isp_subdev fail %d\n", ret); + ispif->status = ISP4IF_STATUS_PWR_OFF; +err_module_disable: + isp4sd_module_enable(isp_subdev, false); + msleep(20); return -EINVAL; } -- 2.43.0