mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: w15303746062  <w15303746062@163.com>
To: "Maarten Lankhorst" <maarten.lankhorst@linux.intel.com>
Cc: "Greg KH" <gregkh@linuxfoundation.org>,
	louis.chauvet@bootlin.com, hamohammed.sa@gmail.com,
	simona@ffwll.ch, melissa.srw@gmail.com, mripard@kernel.org,
	tzimmermann@suse.de, airlied@gmail.com,
	dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org,
	"Mingyu Wang" <25181214217@stu.xidian.edu.cn>
Subject: Re:Re: [PATCH 6.18.y] drm/vkms: Fix ABBA deadlock in vblank disable and timer callback
Date: Tue, 26 May 2026 19:16:23 +0800 (CST)	[thread overview]
Message-ID: <63508f34.98ff.19e640005c5.Coremail.w15303746062@163.com> (raw)
In-Reply-To: <9c4a68c4-43a3-4a9b-a131-9570174c8df3@linux.intel.com>


Hi Maarten,

>As far as I can tell, if it's just a bug affecting vkms, all you need to do
>is only a few commits:
>
>74afeb812850 ("drm/vblank: Add vblank timer")
>d54dbb5963bd ("drm/vblank: Add CRTC helpers for simple use cases")
>02e2681ffe1a ("drm/vkms: Convert to DRM's vblank timer")
>79ae8510b5b8 ("drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks()")
>3946d3ba9934 ("drm/vblank: Fix kernel docs for vblank timer")
>
>There's no need to convert all other drivers if it's only vkms that you're fixing.

Thank you very much for pointing out this precise dependency chain. It completely saved the backport effort. I have cherry-picked these 5 commits onto the 6.18.y branch, and they apply cleanly without pulling in the massive DRM core refactoring. 

This series completely resolves the Syzkaller RCU stall (soft lockup) I was observing in my local fuzzing environment. I have just submitted this 5-patch series to the list.

>But since you found this bug in one driver, it might be wise to check if others
>have the same bug and ask for backports for those too.

Following your suggestion, I conducted a static lock dependency audit across the drivers/gpu/drm/ subsystem in the 6.18.y tree, specifically looking for similar abuses of hrtimer_cancel paired with custom vblank/polling timers.

I audited the highly suspicious candidates, including:

1. i915/gvt (virtual display emulation: vblank_timer_fn vs intel_vgpu_clean_display)
2. xe (OA buffer polling: xe_oa_poll_check_timer_cb vs xe_oa_stream_disable)
3. msm (fence deadlines & devfreq: deadline_timer vs msm_update_fence)

Fortunately, these drivers are structurally safe from this specific ABBA deadlock pattern. They successfully avoid it either by heavily decoupling the timer callback from the lock context via workqueues (msm_fence and i915/gvt only use the timer to safely wake_up or queue work without holding mutexes/spinlocks), or by utilizing fine-grained locking where the cancel path and the timer callback do not contest the same lock (xe stream polling).

Therefore, it seems vkms was a unique legacy outlier in this regard. No further backports are needed for other DRM drivers for this specific vulnerability.

Thanks again for the roadmap and the thorough review.

Best regards,
Mingyu

      parent reply	other threads:[~2026-05-26 11:17 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-05-15 13:18 w15303746062
2026-05-15 15:09 ` Greg KH
2026-05-16  2:43   ` w15303746062
2026-05-16  9:51     ` Greg KH
2026-05-18  2:22       ` w15303746062
2026-05-25  8:55         ` Maarten Lankhorst
2026-05-25 13:16           ` [PATCH 6.18.y 0/5] drm/vkms: Backport generic vblank timer to fix ABBA deadlock w15303746062
2026-05-25 13:16             ` [PATCH 6.18.y 1/5] drm/vblank: Add vblank timer w15303746062
2026-05-25 13:16             ` [PATCH 6.18.y 2/5] drm/vblank: Add CRTC helpers for simple use cases w15303746062
2026-05-25 13:16             ` [PATCH 6.18.y 3/5] drm/vkms: Convert to DRM's vblank timer w15303746062
2026-05-25 13:16             ` [PATCH 6.18.y 4/5] drm/atomic: Increase timeout in drm_atomic_helper_wait_for_vblanks() w15303746062
2026-05-25 13:16             ` [PATCH 6.18.y 5/5] drm/vblank: Fix kernel docs for vblank timer w15303746062
2026-05-26 11:35             ` [PATCH 6.18.y 0/5] drm/vkms: Backport generic vblank timer to fix ABBA deadlock Sasha Levin
2026-05-26 12:06               ` w15303746062
2026-05-26 12:48                 ` Maarten Lankhorst
2026-05-26 12:50                   ` Sasha Levin
2026-05-26 12:59                     ` Maarten Lankhorst
2026-05-26 11:16           ` w15303746062 [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=63508f34.98ff.19e640005c5.Coremail.w15303746062@163.com \
    --to=w15303746062@163.com \
    --cc=25181214217@stu.xidian.edu.cn \
    --cc=airlied@gmail.com \
    --cc=dri-devel@lists.freedesktop.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=hamohammed.sa@gmail.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=louis.chauvet@bootlin.com \
    --cc=maarten.lankhorst@linux.intel.com \
    --cc=melissa.srw@gmail.com \
    --cc=mripard@kernel.org \
    --cc=simona@ffwll.ch \
    --cc=stable@vger.kernel.org \
    --cc=tzimmermann@suse.de \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®