From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A467525D53B for ; Fri, 31 Jul 2026 06:50:00 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785480602; cv=none; b=PfcI4jsVe60IwvmhGMjlrRHgUALrlkp7Xms75VZc0Quw6YDqAgqfCct6a1yBTutyS2udi0cWh/pu0s9aGgY3NHcrixGQV55JeohDnDG1i+OX1AhD1woMhOjdRYv9nBp6sEqedjHdFfmJlgP3+fIwrVIe+gzxm6I7plT9A067kdw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785480602; c=relaxed/simple; bh=xAZBv2VEwehc6rV3HJXkyBBhI3mtehVvRF2UKsJ3ZrI=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=TXvTROKzO5COcxCPG59Swb7sCbJdWfIgyswmGsLOSkLJ9DrNMQUFYJ/zucbM/hP/ZYjv7JEHGO4pDcYuBMPsQroeY7adXMntv2NFxjHQi43rDienOBUT+Xzad4JlPFfOgqYC2JBQ9mYOqom2/WWm+aKXTjA8o5R9Gf85fiiBxNg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=NH0FOPQR; arc=none smtp.client-ip=209.85.221.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="NH0FOPQR" Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-46f88060e8dso46555f8f.2 for ; Thu, 30 Jul 2026 23:50:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785480599; x=1786085399; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=894kL84WjsJ4NuY8JNzhxDjW08BYyE5HOdttjtE66tc=; b=NH0FOPQRcPQENlhvYHanINn/H/uhMOK6k4ovGOuVhKlqjrbIxE+R4XR6IJCI4gXfcN onkPHLzH2ckY8hAUBce18lIrTcE6SJ4luuK5hoxtC252vQQ6OMmnT52skRtKnUcjPJ2E z2kCrv1VqQtrmvGjfuaBh37sValCRWiM9Aahs5M/g00nFhpbpKlJ7FwiNfgC/pIvWYhP ceZBcrZsjTmT/xqdfGH6z4FzdAWdA77pLUpHxFYf2GnkYKqle+OvuNAv6clqUF76sMUF 4NVj2lJcK3njZ9ywcSdp8DTJjCXfsUKybv3iuta0KKPv5qPAUMMh4tq0briykQZpum5Y Rw8g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785480599; x=1786085399; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=894kL84WjsJ4NuY8JNzhxDjW08BYyE5HOdttjtE66tc=; b=M50LNKiIYaHBXBalO3J9Ab9GMJZJTPWqUliaZYINTcVX6QlVcS/x3MX8QVYxXD9Kge AJ0/SIxLLPuISsAXGVObH51yLt+m4fM4guCOi5JbR9GBKTYiskAj9MNmIWpqrXbKnlf8 LFhi5FiVWEdXRmtERZqpdKiV4VBwufmX2ZPAD0Tep2rpDWcXtTRlY4uGQZBJYJfMlWm+ iYtzDFXSy/Nn7Z3Gt/9fNWnNj7o/UFThrr0EG5nVAsF8GZrDsWvuCBZ2NVtje2/4Bsvz iIcUgVPQxvInKvfPSI5EJvnjs5w02RNRpE4PlQ0/ratc8WdMkgILnWHrJ9AlrSD64/vI D1zQ== X-Forwarded-Encrypted: i=1; AHgh+RoLpSd4jjOCAUTA4ojCuXsdj1hLMkL0Pz+5JKUokIq2b2vvbmHly1SWlYELWvzgSQvvMTv5LCQZwxcdeso=@vger.kernel.org X-Gm-Message-State: AOJu0Ywps2OpWy//fPHnGHi98I/QaJrZJ5EyEtbc2/Yvng1NctGQRY2i FQgfvK3T6+GB7MiHvvdRC2hBzItP4ClREvEQ3TVqzRvOM22uJt/eBqvh X-Gm-Gg: AR+sD122+rPHIYH8GASXPlUiczgy6d6dpu88ydgEvAMddv1whbL6//ljHZI3dWKKuVN 88oVJMb9givVpbhUylmvqD5OG1314e+V8dLQgpDoedxje2VvMUDYZJKjMo2exHibAusrSpSsANK sy5LoowQVhroZTNl8KAjkI0gIXimbRegeSzqiuR5ZHqUD3JMMM4Cm10La7GkjuP8F3uP/AhcaA1 d66hG8qbiVDwkKr1OCL2qnH8dE9d3lySVe0sHGSpAe9KX3tx4UJrHyqzmo63j3RjN4Dn8qN0A5t 9IVpPpHh4rx7Ihv9ohPxYHNFJgAtr75IEIGhirETeEUsH5x38ITzyyVozt2FXMVB3MT121X++Nd /bvsjjq53n3DALgyS0KoIP9QJr4BVY7i0TS4MLj+AwZngxYII786E2vLCDgEvoIGw6pGssO+omt vfWr+ISXiSMiD6YtHplP1pcFkGtFp9s3+XYhcCfs44F+eV4AqGbupo4s1PJZ4CiUczCS9nk7Ln0 OW4mXCRBvyBJ86+AapWefYiXTJTR+S9dnsIpp9dem8cdF9p3ELb9oRWZkgDdpbTOJMgLs5RYhjb +eo8 X-Received: by 2002:a05:6000:41f8:b0:47f:946b:d3fc with SMTP id ffacd0b85a97d-47fd2b35e88mr2250807f8f.2.1785480598679; Thu, 30 Jul 2026 23:49:58 -0700 (PDT) Received: from OrangePi5-Plus.BB-HOME (20014C4E1B8B8B0053881A2C61CA978D.dsl.pool.telekom.hu. [2001:4c4e:1b8b:8b00:5388:1a2c:61ca:978d]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd41e2abbsm1212753f8f.9.2026.07.30.23.49.57 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 23:49:58 -0700 (PDT) From: Igor Paunovic To: Tomeu Vizoso Cc: Oded Gabbay , Heiko Stuebner , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, linux-rockchip@lists.infradead.org, Guangshuo Li , Jiaxing Hu , Igor Paunovic Subject: [PATCH v2 2/2] accel/rocket: keep core slots stable across unbind and rebind Date: Fri, 31 Jul 2026 08:49:33 +0200 Message-ID: <20260731064933.12548-3-royalnet026@gmail.com> X-Mailer: git-send-email 2.53.0 In-Reply-To: <20260731064933.12548-1-royalnet026@gmail.com> References: <20260731064933.12548-1-royalnet026@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The shared rocket_device tracks bound cores with a single counter and uses it for three different jobs at once: find_core_for_dev() searches [0, num_cores), rocket_probe() inserts the new core at index num_cores, and rocket_remove() only decrements the counter without clearing the slot. This bookkeeping falls apart as soon as cores are unbound in any order other than strict reverse bind order: - unbinding core 0 shrinks the search range, so the still-bound core at the highest index can no longer be found: its runtime PM callbacks start failing with -ENODEV and a later unbind of it is silently ignored, skipping rocket_core_fini() entirely; - a subsequent bind then reuses the index of that still-live core and overwrites its slot while its IRQ handler (dev_id points into cores[]) and its DRM scheduler are still active; - rocket_open() unconditionally uses cores[0].dev, which after an unbind of core 0 is a stale pointer to an unbound device. Give the array a fixed capacity (max_cores, the DT core count already used to size the allocation) and make .dev the slot-liveness marker: probe takes the first free slot and clears it again if core init fails, remove clears .dev after rocket_core_fini() and warns if the core cannot be found, lookups iterate the full capacity, and rocket_open() and rocket_job_open() use only live slots. num_cores keeps counting bound cores for the last-core teardown check. Fixes: ed98261b4168 ("accel/rocket: Add a new driver for Rockchip's NPU") Signed-off-by: Igor Paunovic --- v2: - also clear the slot's .dev when rocket_core_init() fails: with .dev as the liveness marker a failed init left a half-initialised core visible to every lookup, and rocket_job_open()'s live-slot walk could write one entry past its num_cores-sized allocation (Jiaxing Hu) - check .dev in sched_to_core() so skipping never-initialised slots is explicit rather than implied by pointer inequality (Jiaxing Hu) - document the synchronous-probe assumption at the slot scan v1: https://lore.kernel.org/dri-devel/20260730080355.177422-3-royalnet026@gmail.com/ Unbinding a core that still has jobs in flight has further pre-existing issues (scheduler and open-file lifetime) that are out of scope for this bookkeeping fix. Verified on RK3588 (Orange Pi 5 Plus): out-of-order unbind/rebind sequences (including the previously corrupting unbind of core 0 with cores 1 and 2 still bound, followed by rebind) keep all three cores findable and functional, with MobileNetV1 inference via the Teflon TFLite delegate bit-identical to the stock driver. The new failure path was exercised by forcing rocket_core_init() to fail for core 2 with cores 0 and 1 already bound: the slot is released, the device comes up with the two remaining cores and inference passes bit-exact. drivers/accel/rocket/rocket_device.c | 2 ++ drivers/accel/rocket/rocket_device.h | 3 +++ drivers/accel/rocket/rocket_drv.c | 37 ++++++++++++++++++++++++++++++++---- drivers/accel/rocket/rocket_job.c | 13 +++++++------ 4 files changed, 45 insertions(+), 10 deletions(-) diff --git a/drivers/accel/rocket/rocket_device.c b/drivers/accel/rocket/rocket_device.c index 46e6ee1..8303f05 100644 --- a/drivers/accel/rocket/rocket_device.c +++ b/drivers/accel/rocket/rocket_device.c @@ -35,6 +35,8 @@ struct rocket_device *rocket_device_init(struct platform_device *pdev, if (!rdev->cores) return ERR_PTR(-ENOMEM); + rdev->max_cores = num_cores; + dma_set_max_seg_size(dev, UINT_MAX); err = dma_set_mask_and_coherent(dev, DMA_BIT_MASK(40)); diff --git a/drivers/accel/rocket/rocket_device.h b/drivers/accel/rocket/rocket_device.h index ce662ab..7fb6a9d 100644 --- a/drivers/accel/rocket/rocket_device.h +++ b/drivers/accel/rocket/rocket_device.h @@ -18,6 +18,9 @@ struct rocket_device { struct mutex sched_lock; struct rocket_core *cores; + /* Slot capacity (DT core count); slots with a NULL .dev are free. */ + unsigned int max_cores; + /* Number of currently bound cores. */ unsigned int num_cores; }; diff --git a/drivers/accel/rocket/rocket_drv.c b/drivers/accel/rocket/rocket_drv.c index d29c5ee..7d71a01 100644 --- a/drivers/accel/rocket/rocket_drv.c +++ b/drivers/accel/rocket/rocket_drv.c @@ -69,11 +69,21 @@ rocket_iommu_domain_put(struct rocket_iommu_domain *domain) kref_put(&domain->kref, rocket_iommu_domain_destroy); } +static struct rocket_core *rocket_first_live_core(struct rocket_device *rdev) +{ + for (unsigned int core = 0; core < rdev->max_cores; core++) + if (rdev->cores[core].dev) + return &rdev->cores[core]; + + return NULL; +} + static int rocket_open(struct drm_device *dev, struct drm_file *file) { struct rocket_device *rdev = to_rocket_device(dev); struct rocket_file_priv *rocket_priv; + struct rocket_core *core; u64 start, end; int ret; @@ -86,8 +96,14 @@ rocket_open(struct drm_device *dev, struct drm_file *file) goto err_put_mod; } + core = rocket_first_live_core(rdev); + if (!core) { + ret = -ENODEV; + goto err_free; + } + rocket_priv->rdev = rdev; - rocket_priv->domain = rocket_iommu_domain_create(rdev->cores[0].dev); + rocket_priv->domain = rocket_iommu_domain_create(core->dev); if (IS_ERR(rocket_priv->domain)) { ret = PTR_ERR(rocket_priv->domain); goto err_free; @@ -179,10 +195,21 @@ static int rocket_probe(struct platform_device *pdev) devres_close_group(&drm_dev->dev, rdev_group); } - unsigned int core = rdev->num_cores; + unsigned int core; dev_set_drvdata(&pdev->dev, rdev); + /* + * Take the first free slot: cores can unbind and rebind in any + * order. The scan-then-claim relies on platform probes running + * sequentially; revisit if the driver ever enables async probe. + */ + for (core = 0; core < rdev->max_cores; core++) + if (!rdev->cores[core].dev) + break; + if (WARN_ON(core == rdev->max_cores)) + return -ENXIO; + rdev->cores[core].rdev = rdev; rdev->cores[core].dev = &pdev->dev; rdev->cores[core].index = core; @@ -191,6 +218,7 @@ static int rocket_probe(struct platform_device *pdev) ret = rocket_core_init(&rdev->cores[core]); if (ret) { + rdev->cores[core].dev = NULL; rdev->num_cores--; if (rdev->num_cores == 0) { @@ -210,10 +238,11 @@ static void rocket_remove(struct platform_device *pdev) struct device *dev = &pdev->dev; int core = find_core_for_dev(dev); - if (core < 0) + if (WARN_ON(core < 0)) return; rocket_core_fini(&rdev->cores[core]); + rdev->cores[core].dev = NULL; rdev->num_cores--; if (rdev->num_cores == 0) { @@ -234,7 +263,7 @@ static int find_core_for_dev(struct device *dev) { struct rocket_device *rdev = dev_get_drvdata(dev); - for (unsigned int core = 0; core < rdev->num_cores; core++) { + for (unsigned int core = 0; core < rdev->max_cores; core++) { if (dev == rdev->cores[core].dev) return core; } diff --git a/drivers/accel/rocket/rocket_job.c b/drivers/accel/rocket/rocket_job.c index ac51bff..0d8e69e 100644 --- a/drivers/accel/rocket/rocket_job.c +++ b/drivers/accel/rocket/rocket_job.c @@ -276,8 +276,8 @@ static struct rocket_core *sched_to_core(struct rocket_device *rdev, { unsigned int core; - for (core = 0; core < rdev->num_cores; core++) { - if (&rdev->cores[core].sched == sched) + for (core = 0; core < rdev->max_cores; core++) { + if (rdev->cores[core].dev && &rdev->cores[core].sched == sched) return &rdev->cores[core]; } @@ -498,16 +498,17 @@ int rocket_job_open(struct rocket_file_priv *rocket_priv) struct rocket_device *rdev = rocket_priv->rdev; struct drm_gpu_scheduler **scheds = kmalloc_objs(*scheds, rdev->num_cores); - unsigned int core; + unsigned int core, n = 0; int ret; - for (core = 0; core < rdev->num_cores; core++) - scheds[core] = &rdev->cores[core].sched; + for (core = 0; core < rdev->max_cores; core++) + if (rdev->cores[core].dev) + scheds[n++] = &rdev->cores[core].sched; ret = drm_sched_entity_init(&rocket_priv->sched_entity, DRM_SCHED_PRIORITY_NORMAL, scheds, - rdev->num_cores, NULL); + n, NULL); if (WARN_ON(ret)) return ret;