mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Yi Sun <yi.sun@intel.com>
To: Shuai Xue <xueshuai@linux.alibaba.com>
Cc: Vinicius Costa Gomes <vinicius.gomes@intel.com>,
	<dave.jiang@intel.com>, <dmaengine@vger.kernel.org>,
	<linux-kernel@vger.kernel.org>, <gordon.jin@intel.com>
Subject: Re: [PATCH 2/2] dmaengine: idxd: Fix refcount underflow on module unload
Date: Fri, 30 May 2025 13:58:03 +0800	[thread overview]
Message-ID: <aDlI69HGnflsD-ss@ysun46-mobl.ccr.corp.intel.com> (raw)
In-Reply-To: <78dd14f8-8344-49a4-95eb-14ff005c5ba5@linux.alibaba.com>

On 30.05.2025 13:39, Shuai Xue wrote:
>
>
>在 2025/5/30 11:06, Yi Sun 写道:
>>On 29.05.2025 10:04, Vinicius Costa Gomes wrote:
>>>Yi Sun <yi.sun@intel.com> writes:
>>>
>>>>A recent refactor introduced a misplaced put_device() call, resulting in
>>>>reference count underflow when the module is unloaded.
>>>>
>>>>Expand the idxd_cleanup() function to handle proper cleanup, and remove
>>>>idxd_cleanup_internals() as it was not part of the driver unload path.
>>>>
>>>
>>>'idxd_cleanup_internals()' frees a bunch of stuff. I would expect an
>>>explanation of when those things are being free'd now that removed that
>>>call.
>>>
>>
>>I believe the call to idxd_unregister_devices(), which is invoked at the
>>very beginning of idxd_remove(), already takes care of the necessary
>>put_device() through the following call path:
>>idxd_unregister_devices() -> device_unregister() -> put_device()
>>
>>Therefore, there's no need to add additional put_device() calls for idxd
>>groups, engines, or workqueues. While the commit message for a409e919ca3
>>states: "Note, this also fixes the missing put_device() for idxd groups,
>>engines, and wqs."
>>it appears that no such omission actually existed, this part of the flow
>>was already correctly handled.
>>
>>Moreover, this refcount underflow issue appears to be a a clear
>>regression. Prior to this commit, idxd_cleanup_internals() was not part of
>>the driver unload path. The commit did not provide a strong justification
>>for calling idxd_cleanup_internals() within idxd_cleanup().
>>
>>For reference, the both two related bugs produce nearly identical call
>>traces, and I think both are blocking issues.
>>
>>Thanks
>>    --Sun, Yi
>
>Hi, Sun, Yi
>
>idxd_pci_probe_alloc() {
>	rc = idxd_probe(idxd);
>	rc = idxd_register_devices(idxd);
>	if (rc) {
>		dev_err(dev, "IDXD sysfs setup failed\n");
>		goto err_dev_register;
>	}
>// ...
> err_dev_register:			<-
>	idxd_cleanup(idxd);
>}
>
>We use idxd_cleanup() when register devices failed to undo the
>idxd_probe(). idxd_probe() sets up idxd groups, engine and wqs and
>get reference counts by device_initialize().
>
>what's the difference between idxd_cleanup_internals() and
>idxd_unregister_devices()?

Hi Shuai,

Prior to the commit, I meant the function idxd_remove() did not invoke
idxd_cleanup() or idxd_cleanup_internals(), and it was able to handle
reference counts correctly via idxd_unregister_devices().

However, the code refactor introduced the use of the idxd_cleanup()
helper, which internally calls idxd_cleanup_internals(). This results
in a duplicate put_device() call, leading to a reference count underflow
issue.

Thanks
    --Sun, Yi

  reply	other threads:[~2025-05-30  5:58 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-05-29 15:34 [PATCH 1/2] dmaengine: idxd: Remove improper idxd_free Yi Sun
2025-05-29 15:34 ` [PATCH 2/2] dmaengine: idxd: Fix refcount underflow on module unload Yi Sun
2025-05-29 17:04   ` Vinicius Costa Gomes
2025-05-30  3:06     ` Yi Sun
2025-05-30  5:39       ` Shuai Xue
2025-05-30  5:58         ` Yi Sun [this message]
2025-05-29 16:56 ` [PATCH 1/2] dmaengine: idxd: Remove improper idxd_free Vinicius Costa Gomes
2025-05-30  0:24   ` Yi Sun
2025-05-30  1:07     ` Vinicius Costa Gomes
2025-05-30  1:42       ` Yi Sun

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=aDlI69HGnflsD-ss@ysun46-mobl.ccr.corp.intel.com \
    --to=yi.sun@intel.com \
    --cc=dave.jiang@intel.com \
    --cc=dmaengine@vger.kernel.org \
    --cc=gordon.jin@intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=vinicius.gomes@intel.com \
    --cc=xueshuai@linux.alibaba.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®