From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f54.google.com (mail-wr1-f54.google.com [209.85.221.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E9853357CFB for ; Thu, 30 Jul 2026 08:04:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.54 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785398655; cv=none; b=IjLynpGOuuzW0Qie+MQrjfluvi3RBfWv7nJObtuCSMHSMRA+KG7zb1qZ07NtbcAjw4S8s9VhH78AT9B4dohD3TB8K5NDNX55MiIFnpn4IOcWWJn59wgKLyW1SSilSllXyybi8+tFLtJMj8W6ImlmikiK34o0DxlBeGjn/oUl8JI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785398655; c=relaxed/simple; bh=AcvVbARkhyKY+3HjaCxKYs/KqmBRm4b/3ud/DJmwl04=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=OMskBh+w6fr4Wv7BsczGIvIomyrXerL2Q9TtNunfHzJjnjlq/HydBAzv63f4gmihZ8x13tvN268+tKUdlK92w5I3+2KmiieoE37KoIScjDlwR4Yu1J6swRKDoCnO6TbXsxzDVphfUomEYkkt1Jm5pxyEEmOvVJX098zJHwO22PQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ifcfSqfw; arc=none smtp.client-ip=209.85.221.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ifcfSqfw" Received: by mail-wr1-f54.google.com with SMTP id ffacd0b85a97d-46f88060e8dso160081f8f.2 for ; Thu, 30 Jul 2026 01:04:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785398652; x=1786003452; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VrwtyRX2qDPBxX3r7OeFon4kOmzwfovTWycGAbMSmog=; b=ifcfSqfwOX/uy4Ujl4Bn4LSdZUJYfrDF7M7PXDuWCmJhgsObKTgIBXJaZyjT8Xg1AP 78Rf8K5EZnBxH8Tc9oKPYWB7wYyfH/CQ2vrJwv725uP7dQD5eTWGyuy5zxBgPmU4obka TOxeOJK8EfSdLMmTwHFECl5uevfi6qSYgNpJZL0Du5mFJellSCMKkvT+wWuUTMz0IjuH oaSMFkfVLZs91q9TkX0dEnFVyT1rj1I3iQUzw2kiBtYtkOcK+B/qzwK8uMuVxZEW9HXM r5CWBVeeERlbXRxNEuLg2Z5YxuDt3Ck0VvhhJbe+trdq9I3NqS+0llPAVVTdjip9MxQ5 W1LQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785398652; x=1786003452; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VrwtyRX2qDPBxX3r7OeFon4kOmzwfovTWycGAbMSmog=; b=ljxoyQek/ocPcTCbeLHOs6YCin2ZaY+YskIj1Z/qHjw+dKj10t+XxQHEwU+VrHu83i uGZ/MA4hHyKjapmUQJV049J6ZzwYWFYcgbK3/ZJm5iNegWigDfmKRwicIPzWZHt+C2MY 3lFxlX3+Q6Oq2bZBg8o45aC9BPINZ7Loma8yxmXcsIXstGt/KLRiPVBH6d4Tmnjnd7aI HrQQs0BiezBDy3jwf3AvqwjSr5IBAHo6vGGyCSjUCFj6dGxiVp8/Hv1YsazlSR4EujWD S0VOZ+CPWacY28l7BhwcDHaCUld7ADmi+trFK42V4SYEdQ6zWZCIs67DTvIgnkv49lU6 H7OQ== X-Forwarded-Encrypted: i=1; AHgh+RrAMEfFiSGkbgT2JpoO4jIEXu5XnYSOZBtyqjYs7cZd3nbljB2Xcy9vqXy+ffYf/kxn/0477LqQ0FvkVYc=@vger.kernel.org X-Gm-Message-State: AOJu0YxJ9bublw3X6svjUwx3SjYhGjn7rwbZnznNc4GnKHM/LlvO7Xhs WrANwi2OJUqApZWxG9Sop23Uc/+r8Hjo1pqEN+4eDdeIy/KmpUMA7pmo X-Gm-Gg: AR+sD11r7+qFsgQ6xoQRnWoflyA59B9u+2YiMuDT+G0UVrPwLlGlZjxGAAnjpeHh4ZP i3qZUW0RftXz5w1BJG1BrTsxardksNo+fzU0ocZ3fGTAIOyo38/vsH5QksUK8zAcvobg+pMXK06 +K3HboDYz0zZaEQuBczwrVZvX8BdSa0a1LkFMw/Uqh8ld2Jkq9+mf+wg2LkFYUTRy/UA2FkPTer StlD/wL1HWd0CM27F2EkQmykYj8zYsmSzL81TAU0LY0Asqol6bDtzRs2Q6blZgqlII+M5XiByO8 00Nc38+sfLHek3dSXNVU8nBov3rpUWYkO6kiIKJaaWybh5JKOg7qsNjAM6nXRmmneiKEaC/n5hl Xc52FwGthwgzald3CbAL1R0hpohRLdI0ouxjglD2xRezn206iu/kty45RwtTnyZcP6NafMNj+cy iI93zdi1Y4WoS79EDmsQfMN0GPv6QMRgxbSE1ENJu48cZv6jJP+vhD96v4Ox+rzvcWmKeGqSDwZ AYqXfZVd9s10kmjsoWpxo3LZ6qoeH9ZuQPjN3aFKG6p/qySw9hWSOEhC8ergPt3391toZWydnKO Ht68 X-Received: by 2002:a5d:5e82:0:b0:47f:6fbd:f23e with SMTP id ffacd0b85a97d-47fc8329a61mr1706891f8f.4.1785398651803; Thu, 30 Jul 2026 01:04:11 -0700 (PDT) Received: from OrangePi5-Plus.BB-HOME (20014C4E1B8A5A00BF2D55A7591B4173.dsl.pool.telekom.hu. [2001:4c4e:1b8a:5a00:bf2d:55a7:591b:4173]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fc88e4055sm3347685f8f.13.2026.07.30.01.04.10 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 01:04:10 -0700 (PDT) From: Igor Paunovic To: Tomeu Vizoso Cc: Oded Gabbay , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, linux-rockchip@lists.infradead.org, Guangshuo Li , Jiaxing Hu , Igor Paunovic Subject: [PATCH 1/2] accel/rocket: release the shared device's devres on teardown Date: Thu, 30 Jul 2026 10:03:53 +0200 Message-ID: <20260730080355.177422-2-royalnet026@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260730080355.177422-1-royalnet026@gmail.com> References: <20260730080355.177422-1-royalnet026@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit rocket_device_init() attaches its allocations to the shared "rknn" platform device via devres: devm_drm_dev_alloc(), devm_kcalloc() for the cores array and devm_mutex_init(). That device is registered at module init, never binds to a driver, and is only unregistered at module exit - so its devres list is not released for as long as the module is loaded. rocket_device_fini() only calls drm_dev_unregister(): it does not run the drm_dev_put() devres action or free any of the other entries. Every fini/re-init cycle therefore leaks the previous rocket_device (with its embedded drm_device and all drmm state, including the accel minor number), the cores array and the mutex devres node. The cycle is easy to trigger: unbind the last bound core and bind one again, or fail the first core's probe (-EPROBE_DEFER retries included). Observable symptom, RK3588 (Orange Pi 5 Plus): each unbind/rebind cycle of all three cores moves the accel node forward - /dev/accel/accel0 comes back as accel1, then accel2 - because every leaked drm_device keeps its minor pinned. Wrap the initialization in a devres group and release exactly that group wherever the device is torn down: on the rocket_device_init() error path, when the first core's rocket_core_init() fails, and when the last core is removed. Each fini now frees what the matching init allocated, and the accel minor is reusable again. Fixes: ed98261b4168 ("accel/rocket: Add a new driver for Rockchip's NPU") Signed-off-by: Igor Paunovic --- This applies on top of Guangshuo Li's pending fix, which it depends on: "accel/rocket: clear rdev on device init failure" https://lore.kernel.org/dri-devel/20260708062845.716487-1-lgs201920130244@gmail.com/ Verified on RK3588 (Orange Pi 5 Plus): with the patch, repeated unbind/rebind cycles keep /dev/accel/accel0 stable (previously the minor incremented on every cycle); normal three-core probe, runtime PM and a MobileNetV1 inference run via the Teflon TFLite delegate are unaffected. drivers/accel/rocket/rocket_drv.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/accel/rocket/rocket_drv.c b/drivers/accel/rocket/rocket_drv.c index 67e7f54..d29c5ee 100644 --- a/drivers/accel/rocket/rocket_drv.c +++ b/drivers/accel/rocket/rocket_drv.c @@ -24,6 +24,7 @@ */ static struct platform_device *drm_dev; static struct rocket_device *rdev; +static void *rdev_group; static void rocket_iommu_domain_destroy(struct kref *kref) @@ -163,14 +164,19 @@ static int rocket_probe(struct platform_device *pdev) if (rdev == NULL) { /* First core probing, initialize DRM device. */ + rdev_group = devres_open_group(&drm_dev->dev, NULL, GFP_KERNEL); + if (!rdev_group) + return -ENOMEM; rdev = rocket_device_init(drm_dev, &rocket_drm_driver); if (IS_ERR(rdev)) { int err = PTR_ERR(rdev); dev_err(&pdev->dev, "failed to initialize rocket device\n"); rdev = NULL; + devres_release_group(&drm_dev->dev, rdev_group); return err; } + devres_close_group(&drm_dev->dev, rdev_group); } unsigned int core = rdev->num_cores; @@ -190,6 +196,7 @@ static int rocket_probe(struct platform_device *pdev) if (rdev->num_cores == 0) { rocket_device_fini(rdev); rdev = NULL; + devres_release_group(&drm_dev->dev, rdev_group); } } @@ -213,6 +220,7 @@ static void rocket_remove(struct platform_device *pdev) /* Last core removed, deinitialize DRM device. */ rocket_device_fini(rdev); rdev = NULL; + devres_release_group(&drm_dev->dev, rdev_group); } }