From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 99ABE38AC8B for ; Fri, 5 Jun 2026 01:17:27 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780622253; cv=none; b=BQukFtd0tMazpJiuD6sgS/hVyHHeS8jrsOJHPWQqArb6idx+/tTZVfz+chr2MWYzmGT22YShpFiOke+H6tBfPxq/ops5z96vkH7HefI6Lwejn4QGtKwCqle8BFrUQ2b8ZXbYJ4Hsm+4Pyge/Gqfb7IbrtD1jAVTPaihd/KDiX/I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780622253; c=relaxed/simple; bh=FoTL2eK6Xjm2tOtBLk83ox/ORpi+04NDmEvp/2RHE4I=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=YCyCLlCll7MV31DdcOirjlnMDXQXK5KCTiSWdU4FdKyiA3U1g2QQUVqIA+GBEmSyWupjpyZK6JfFPHZxHC+mG11b1SIuwCUqER2CrEPsvNZfgdu9v+FFzDZLKPihQa29WI3CcKWSFPMKGD+ISsVYo278ROqQ5WB+qSbLySpaf1U= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=A3xPGA2j; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=MXoipIBI; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="A3xPGA2j"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="MXoipIBI" Received: from pps.filterd (m0279869.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 6550JsvK528639 for ; Fri, 5 Jun 2026 01:17:26 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 230bGQ92X8rqHZh77BzSKjoSqIWkALpxCZRvN5mt1fE=; b=A3xPGA2jn6rXtOLO vGC5NxQlWf+yCtsh3OMLKSG5KksP9at1mijZM5x6dUL6DoMoPEe49s6JxmB0zXIO 0mUbj1S8ygnkrheDIFMHgt9558+F0VRIHrnZBNJiMNo/ox27tXg+WPXwHUbKsEOJ nTtiTerEbsys8jlO4tHXH68MMMQF9OEwYi+//WxX+7p3jzmzE9Pv6oNjIAZmhjkJ M4jtNQxmRrKYvVC5PTXp1tePlmR41nagezt8X6u5FKZzTxmEEo/+pvlnDDNvjCA0 7w3r5Ubw9zyWURwHWqtBZswW2QvYjjy/GIR4HSa8ean9brqGL2lhoVzSrnEdEaQQ +bRT6A== Received: from mail-pl1-f199.google.com (mail-pl1-f199.google.com [209.85.214.199]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4ekbgdtjup-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Fri, 05 Jun 2026 01:17:25 +0000 (GMT) Received: by mail-pl1-f199.google.com with SMTP id d9443c01a7336-2bf55c3f44aso19330975ad.0 for ; Thu, 04 Jun 2026 18:17:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1780622245; x=1781227045; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=230bGQ92X8rqHZh77BzSKjoSqIWkALpxCZRvN5mt1fE=; b=MXoipIBIQInp7UR93HQwIka5BcPiEAvm8Y0uIbacE348gvr6bYidEt3fvxOALO5bEm 32f0Nzz4d7OtD1Q8rSEa/FMrjaeYnRt1ukFahW9nKDntK8CpdzwKApJYwHxDAx1VK7WC FVqrZuywZ885+j/KG0BUEFEzyN88aalc54YnXIxDydZm4yRYTpYZXBK8Cv2fxMdZvwzS Do/82C5gpEriFIxSKnvtvIyorl195a4Kgqxdy6M6j4c+ME1nyKPiFeLBKdks+IrdXfYK 4QfqzWZxOhC1/5gY1oVpaWYhW4mCVwafSpSci+EMkREWCDPrUc8lDHM/EwN7FKwZepWt DGtQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780622245; x=1781227045; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=230bGQ92X8rqHZh77BzSKjoSqIWkALpxCZRvN5mt1fE=; b=r48WrdsQv/qMhBHYuyCQzaANrSk4eJ8r3pLq/lT/APouxYdz14xlLgGafUC33iieZ2 wNCek/b1yxXkviGo5krku1X8kqSzdyCFtUgOOxlpZJH9F5r8biZYqrkqscI9oknLVnfe /UfUwkWPtb/wo2vLZ4CA0TuQk1ZlMKHGCa1l/oRcdQIR906FQFLLLArwy7be0BpAI9zK fTGqcZV5Xc7u93gFkvgoOuOjFqTjM0FFZVAdukb+hKQVBg2ZJZ+BfXWTqZumx+lO0u66 vGvYj1DxEtpdI4fkZb2tOZ0SHjxDtagFNwxwkMgD40ST7sCAZKWmHXehZU8kWUokJotF iB0w== X-Forwarded-Encrypted: i=1; AFNElJ8D4TDEcnKiB0FQvQ7KBK/nSuwMfC5ONK0V/o1mKu+ahvJqXQ5mq2zRsRl5b6Emm7qlZJ4uNSDRyx1kr84=@vger.kernel.org X-Gm-Message-State: AOJu0Yzbp9SukVEdqwm7ADDZGQB3aK6BDpUa7vOWcsdk4HSvWA+Q4oue ZaoZFq5ZJlv9c0p2ei0o/f9YHYExyzrPyYNbIs8nBLrXlMAifxfwlVWF1JOt9ZdDb/JSx8vx8cg GZ1IGbLz4XJCfbdc/RfqVdZDFo9VnSWFB5/vpRBgvWs19d71SYSxXDR2DP0WXS2ah4fE= X-Gm-Gg: Acq92OHDw/VcERV98Zmydqlhs38NJNcumJ/ez615Z/yPeOumy6/NFYrjOdAdmn08f8x TwPctkfkb9b5ITJAxnXTi6qA38hkXM68BjnlSC7UJlFoj7CLZSEa5PCfJspdzdFMxafxP7HiByF JR+1C5AmJtLOMCejj/rf5P0HRhG7OQNFYT9fj4BT9zD+FJaL7uYspfkJjBjqMyUlWbSgnY2yxUB IDkhJP1xirEDHjq6N8nW0NapICVaI8MMD5PRcsBQewQvkzFansrVwDcGcbrwZ/25zyiRQpoHsb4 YPC3i8FbddwA2zklSr/Z7PXKDJqWu+1NX8QHjKNgL4jZnPLJtYyM18ip+qqhndJ3yAFLbLAjb0o 2kjtPvFRbw0YG/VgDJa2dQa+GSU+fww9m6Ri/9tv+5jEJnyVl/FqBzgr7/QmgSo5VkmPd+YrKeS eV9bOzMmcQDToxxvkjLfo9 X-Received: by 2002:a17:903:acf:b0:2c0:a858:8128 with SMTP id d9443c01a7336-2c1ec54c8f2mr4016745ad.1.1780622244793; Thu, 04 Jun 2026 18:17:24 -0700 (PDT) X-Received: by 2002:a17:903:acf:b0:2c0:a858:8128 with SMTP id d9443c01a7336-2c1ec54c8f2mr4016485ad.1.1780622244342; Thu, 04 Jun 2026 18:17:24 -0700 (PDT) Received: from [10.133.33.77] (tpe-colo-wan-fw-bordernet.qualcomm.com. [103.229.16.4]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2c16649ab01sm68952155ad.71.2026.06.04.18.17.21 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 04 Jun 2026 18:17:24 -0700 (PDT) Message-ID: <3896c47d-41c0-4b61-a115-c5d6ea282fa5@oss.qualcomm.com> Date: Fri, 5 Jun 2026 09:17:19 +0800 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] rpmsg: glink: fix deadlock in endpoint destroy during driver detach To: Vishnu Santhosh , Bjorn Andersson , Mathieu Poirier Cc: linux-arm-msm@vger.kernel.org, linux-remoteproc@vger.kernel.org, linux-kernel@vger.kernel.org, bjorn.andersson@oss.qualcomm.com, chris.lew@oss.qualcomm.com, Deepak Kumar Singh References: <20260604-rpmsg-glink-fix-deadlock-destroy-ept-v1-1-b8a54ad1e4fd@oss.qualcomm.com> Content-Language: en-US From: Jie Gan In-Reply-To: <20260604-rpmsg-glink-fix-deadlock-destroy-ept-v1-1-b8a54ad1e4fd@oss.qualcomm.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Proofpoint-GUID: PV5WlCzggKH6aweTfXLmwjc9H2xJ0WLz X-Proofpoint-ORIG-GUID: PV5WlCzggKH6aweTfXLmwjc9H2xJ0WLz X-Authority-Analysis: v=2.4 cv=a8cAM0SF c=1 sm=1 tr=0 ts=6a2223a5 cx=c_pps a=JL+w9abYAAE89/QcEU+0QA==:117 a=nuhDOHQX5FNHPW3J6Bj6AA==:17 a=IkcTkHD0fZMA:10 a=FelO9ux0wxsA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_glEPmIy2e8OvE2BGh3C:22 a=EUspDBNiAAAA:8 a=xBbfoKGClFlJqF7rv9oA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=324X-CrmTo6CU4MGRt3R:22 X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwNjA1MDAxMCBTYWx0ZWRfX+qKTbtsD2Qfw k6qzj9mvlMafWE6acc/Pl1LhPmLDRnX5pyW2tvLYmkwbhvIl5ItYgYtr5uG6P8tjCCui9fQyCdZ U39vDjFHjUkWRXbDAOBb2ONMuq/XdXZHQz2KiFvF9xp4JfiRbG7keLhZezFzSZunFdiAagOQfQp BVE6kx1SXUTONJOnVbgnWYMCqMlRpQXTwHsFYrqJbf9N9FZM7stDiLTjdhZNoI2LqEzczkGP0sm QkoHlMhT0SzgqIMDCd+9+84n2Urd4KTb121cplcu6BJvKafO0w8lQyEGSHJokfxfscOrDV11QVy 8pEGb8HNrsou/v/SIYBWM/BiG+FVtABH/ZNDIEzgrXktgQErmgxHnh6XlLxMNFx1mPw17ripncS kIWfPEGqFJ8oFsgkPmVDIZYUvpm1s0O/z+wumk5MIqv8wbuUYkLam+mRHAHQNocOL2f6QuwCkdp 3+Ly/bj/zGSRKJ5KMvA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1143,Hydra:6.1.125,FMLib:17.12.100.49 definitions=2026-06-04_07,2026-05-28_03,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 bulkscore=0 priorityscore=1501 phishscore=0 adultscore=0 impostorscore=0 lowpriorityscore=0 clxscore=1015 suspectscore=0 spamscore=0 malwarescore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2605210000 definitions=main-2606050010 On 6/4/2026 4:42 PM, Vishnu Santhosh wrote: > During driver detach, the device core holds the device mutex throughout > the driver's remove callback chain. When the rpmsg endpoint is > destroyed as part of that teardown, the GLINK endpoint destroy > implementation attempts to unregister the underlying rpmsg device. > That unregistration calls device_del(), which tries to re-acquire the > same device mutex already held higher up the stack, causing rmmod to > hang indefinitely. > > The deadlock manifests with the following call chain: > > [<0>] device_del+0x44/0x414  <- tries to acquire same mutex > [<0>] device_unregister+0x18/0x34 > [<0>] rpmsg_unregister_device+0x28/0x4c > [<0>] qcom_glink_remove_rpmsg_device+0x70/0xc0 > [<0>] qcom_glink_destroy_ept+0x58/0xbc > [<0>] rpmsg_dev_remove+0x50/0x60 > [<0>] device_remove+0x4c/0x80 > [<0>] device_release_driver_internal+0x1cc/0x228 <- acquires device mutex > [<0>] driver_detach+0x4c/0x98 > [<0>] bus_remove_driver+0x6c/0xbc > [<0>] driver_unregister+0x30/0x60 > [<0>] unregister_rpmsg_driver+0x10/0x1c > [<0>] fastrpc_exit+0x28/0x38 [fastrpc] > [<0>] __arm64_sys_delete_module+0x1b8/0x294 > [<0>] invoke_syscall+0x48/0x10c > [<0>] el0_svc_common.constprop.0+0xc0/0xe0 > [<0>] do_el0_svc+0x1c/0x28 > [<0>] el0_svc+0x34/0x108 > [<0>] el0t_64_sync_handler+0xa0/0xe4 > [<0>] el0t_64_sync+0x198/0x19c > > The rpmsg device unregistration inside endpoint destroy is redundant. > In both contexts where endpoint destruction is triggered: > > - Driver detach path: the driver core already tears down the rpmsg > device. > > - Channel close path: the rpmsg device is already unregistered before > endpoint destruction is reached. > > Remove the redundant unregistration to fix the deadlock. > Fixes: a53e356df548 ("rpmsg: glink: fix rpmsg device leak") Thanks, Jie > Co-developed-by: Deepak Kumar Singh > Signed-off-by: Deepak Kumar Singh > Signed-off-by: Vishnu Santhosh > --- > drivers/rpmsg/qcom_glink_native.c | 3 --- > 1 file changed, 3 deletions(-) > > diff --git a/drivers/rpmsg/qcom_glink_native.c b/drivers/rpmsg/qcom_glink_native.c > index 401a4ece0c9777398837d4427746fae0a5003e88..ab7ff3d2f56bf797592fc4227ce5b730bce72226 100644 > --- a/drivers/rpmsg/qcom_glink_native.c > +++ b/drivers/rpmsg/qcom_glink_native.c > @@ -1418,9 +1418,6 @@ static void qcom_glink_destroy_ept(struct rpmsg_endpoint *ept) > channel->ept.cb = NULL; > spin_unlock_irqrestore(&channel->recv_lock, flags); > > - /* Decouple the potential rpdev from the channel */ > - qcom_glink_remove_rpmsg_device(glink, channel); > - > qcom_glink_send_close_req(glink, channel); > } > > > --- > base-commit: ba3e43a9e601636f5edb54e259a74f96ca3b8fd8 > change-id: 20260416-rpmsg-glink-fix-deadlock-destroy-ept-5cc7aac522a0 > > Best regards,