From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from bali.collaboradmins.com (bali.collaboradmins.com [148.251.105.195]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BAE3F353A96 for ; Thu, 13 Aug 2026 10:57:13 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=148.251.105.195 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786618638; cv=none; b=iflZj+1JgBMXR/cy3HTRYO9wnASQ+1BdjRQlAD9e1lQtRODh5censKGXy1pU55cOPq3rs5tl6auo1IY8XVxJc0T92XmncvyPAJB3rx/4h2o2VNt0Fn0UFIMTJHPWWL46qQeuffnQdZJ+EGQ5P9271sWLLq6gZ8EUdEa//cWuY3o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786618638; c=relaxed/simple; bh=Errsu9GFDWfK0z5mH/zvEVz/71ISvAg4XKJzEn3gCLg=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=pFDcOHcsinYGe4uJ4YirVhrY/BGMRdaC/u6u6H2ALs4lUdDCoC4hFXWFqq+2TGrlsecV81qry/omOyq2KvxamCLpuVSANeBO/zSNyjHp9T0ZFxKu5U2KEJyDMRM3UqvsBCFg6CUrBLK9jrIrpuWQJSnyAdNeTMZA4IyUtVL6WtA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com; spf=pass smtp.mailfrom=collabora.com; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b=Qih0xgbN; arc=none smtp.client-ip=148.251.105.195 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=collabora.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=collabora.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=collabora.com header.i=@collabora.com header.b="Qih0xgbN" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=collabora.com; s=mail; t=1786618626; bh=Errsu9GFDWfK0z5mH/zvEVz/71ISvAg4XKJzEn3gCLg=; h=From:Date:Subject:References:In-Reply-To:To:Cc:From; b=Qih0xgbNBTmxBp68V8DmtIP9jKjPCIiINtC6T0KkagjjkxPQV3rCtLcnZHjC5t7rc QXQejYD18aeQHJ7jUmFfdLfX9zZgRKEZzDT2WE4JmbYYtlmCPlncD7MWyC+hVIdf2X Urdhu4b/pM3n9rUYKk6TDNPkJG3PwQndxn7G0i3ioqA6UkVPNLJNjhdq3ag/Qe+pU8 igC4FQaCSr8Px8yLHiYRN8TD+c69mjv6goVvhFgpqPz0g+SB87l16Lh/QplGDMfm1W YMe9+XaSuMHtO2sCAWZfm8V7EeolR8lMZ1MW9JdHKAm12sxrKsozrPGUNY1I5MIOe/ ss25BSLL6ia9g== Received: from fedora-21.home (unknown [100.64.0.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) (Authenticated sender: bbrezillon) by bali.collaboradmins.com (Postfix) with ESMTPSA id 9B53017E107E; Thu, 13 Aug 2026 12:57:05 +0200 (CEST) From: Boris Brezillon Date: Thu, 13 Aug 2026 12:57:03 +0200 Subject: [PATCH v3 05/17] drm/panthor: Flush the cleanup_wq in the unplug path Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Message-Id: <20260813-panthor-unplug-fixes-v3-5-3ed4e961bbe7@collabora.com> References: <20260813-panthor-unplug-fixes-v3-0-3ed4e961bbe7@collabora.com> In-Reply-To: <20260813-panthor-unplug-fixes-v3-0-3ed4e961bbe7@collabora.com> To: Steven Price , Liviu Dudau Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Boris Brezillon , sashiko-bot@kernel.org X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786618621; l=2353; i=boris.brezillon@collabora.com; s=20260429; h=from:subject:message-id; bh=Errsu9GFDWfK0z5mH/zvEVz/71ISvAg4XKJzEn3gCLg=; b=nc3euCWw3cScJh3kNrwZZq3PxRoduOjxqM6FMRqPfzIO7rRSDDrrGwK4tKS0USsiFrMDmVXnN l6jr8+sPL5KAlqtp5WJ2a5YN+oI4Y2uvq9bAW/Y0VNKpjUJ32/6iDfu X-Developer-Key: i=boris.brezillon@collabora.com; a=ed25519; pk=eN+ORdOgQY7d5U+0kA8h5bf67XdD8bhKbjD/TCHexSY= If we don't do that, we might face various UAFs, because the resource referenced by these work items might be gone by the time they get executed. In each subcomponent making use of the panthor_cleanup_wq, we add a flush_workqueue() at the end of the _unplug() function. Note that this assumes no more work items from this subcomponent gets queued after that point, which is not yet guaranteed, but this will be fixed in upcoming changes. Fixes: de8548813824 ("drm/panthor: Add the scheduler logical block") Fixes: 647810ec2476 ("drm/panthor: Add the MMU/VM logical block") Reported-by: sashiko-bot@kernel.org Closes: https://sashiko.dev/#/patchset/20260625-panthor-signal-from-irq-v5-0-8836a74e0ef9@collabora.com?part=2 Signed-off-by: Boris Brezillon --- drivers/gpu/drm/panthor/panthor_mmu.c | 6 ++++++ drivers/gpu/drm/panthor/panthor_sched.c | 6 ++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/gpu/drm/panthor/panthor_mmu.c b/drivers/gpu/drm/panthor/panthor_mmu.c index 0182b72f1932..0b862d3c3605 100644 --- a/drivers/gpu/drm/panthor/panthor_mmu.c +++ b/drivers/gpu/drm/panthor/panthor_mmu.c @@ -3365,6 +3365,12 @@ void panthor_mmu_unplug(struct panthor_device *ptdev) } } mutex_unlock(&ptdev->mmu->as.slots_lock); + + /* Ensure any pending job cleanup work are executed before returning, + * otherwise those might access objects that are gone if the work is + * executed after other components are unplugged. + */ + flush_workqueue(panthor_cleanup_wq); } static void panthor_mmu_release_wq(struct drm_device *ddev, void *res) diff --git a/drivers/gpu/drm/panthor/panthor_sched.c b/drivers/gpu/drm/panthor/panthor_sched.c index 5832dccfc093..f18b2e03f2fd 100644 --- a/drivers/gpu/drm/panthor/panthor_sched.c +++ b/drivers/gpu/drm/panthor/panthor_sched.c @@ -4074,6 +4074,12 @@ void panthor_sched_unplug(struct panthor_device *ptdev) sched->pm.has_ref = false; } mutex_unlock(&sched->lock); + + /* Ensure any pending group release work are executed before returning, + * otherwise those might access objects that are gone if the work is + * executed after other components are unplugged. + */ + flush_workqueue(panthor_cleanup_wq); } static void panthor_sched_fini(struct drm_device *ddev, void *res) -- 2.55.0