From: Lizhi Hou <lizhi.hou@amd.com>
To: David Zhang <yidong.zhang@amd.com>, <quic_jhugo@quicinc.com>,
<karol.wachowski@linux.intel.com>, <max.zhen@amd.com>,
<ogabbay@kernel.org>, <dri-devel@lists.freedesktop.org>,
<linux-kernel@vger.kernel.org>
Cc: <sonal.santan@amd.com>, <mario.limonciello@amd.com>
Subject: Re: [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation
Date: Mon, 28 Sep 2026 14:06:16 -0700 [thread overview]
Message-ID: <c5da23b0-1552-b601-78e9-602e4140297d@amd.com> (raw)
In-Reply-To: <20260926013448.3840921-15-yidong.zhang@amd.com>
On 9/25/26 18:34, David Zhang wrote:
> This is part of the fix to align BO reservation locking and fence
> management with aie2.
>
> Fences published into BO reservation objects via dma_resv_add_fence()
> can outlive the hardware context (e.g. when a BO is exported as a
> dma-buf and imported by another process). Using hwctx->name for the fence
> timeline name risks a use-after-free once the hwctx is destroyed.
> Switch timeline name to dev_name() which is backed by the device that
> outlives any individual context.
>
> Additionally, allocate a unique fence context via
> dma_fence_context_alloc(1) for each job fence so that dma_resv_add_fence()
> does not evict a prior in-flight job's fence from a shared BO's
> reservation object when multiple jobs touch the same BO. Also guard
> hwctx_fini call in amdxdna_hwctx_destroy_rcu() against NULL ops.
Is this aie4 kernel submission specific? aie2 does not publish this fence.
If it does not fix any existing issue, please describe it clearly.
>
> The corresponding AIE4 command submission BO locking and fence
> attachment logic is implemented in a subsequent patch ("accel/amdxdna:
> Implement AIE4 command packet building and submission").
>
> Co-developed-by: Max Zhen <max.zhen@amd.com>
> Signed-off-by: Max Zhen <max.zhen@amd.com>
> Signed-off-by: David Zhang <yidong.zhang@amd.com>
> ---
> drivers/accel/amdxdna/amdxdna_ctx.c | 29 ++++++++++++++++++++++-------
> 1 file changed, 22 insertions(+), 7 deletions(-)
>
> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
> index 888e857ec558..6ca7774150d5 100644
> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
> @@ -25,7 +25,7 @@
> struct amdxdna_fence {
> struct dma_fence base;
> spinlock_t lock; /* for base */
> - struct amdxdna_hwctx *hwctx;
> + struct device *dev;
> };
>
> static const char *amdxdna_fence_get_driver_name(struct dma_fence *fence)
> @@ -39,7 +39,14 @@ static const char *amdxdna_fence_get_timeline_name(struct dma_fence *fence)
>
> xdna_fence = container_of(fence, struct amdxdna_fence, base);
>
> - return xdna_fence->hwctx->name;
> + /*
> + * Use device name rather than hwctx name: the fence is published into
> + * BO reservation objects via dma_resv_add_fence() and can outlive the
> + * hwctx (e.g. when a BO is exported as a dma-buf and imported by
> + * another process). The device outlives any individual context, so
> + * dev_name() is safe to call at any point during the fence's lifetime.
> + */
> + return dev_name(xdna_fence->dev);
> }
>
> static const struct dma_fence_ops fence_ops = {
> @@ -55,9 +62,17 @@ static struct dma_fence *amdxdna_fence_create(struct amdxdna_hwctx *hwctx)
> if (!fence)
> return NULL;
>
> - fence->hwctx = hwctx;
> + fence->dev = hwctx->client->xdna->ddev.dev;
> spin_lock_init(&fence->lock);
> - dma_fence_init(&fence->base, &fence_ops, &fence->lock, hwctx->id, 0);
> + /*
> + * Part of the fix to align BO reservation locking and fence
> + * management with AIE2: each job fence needs a unique context so
> + * dma_resv_add_fence() does not evict a prior job's fence from a
> + * shared BO's reservation object when two in-flight jobs touch
> + * the same BO. The corresponding AIE4 command submission locking
> + * and fence attachment is implemented in aie4_cmd_submit().
> + */
> + dma_fence_init(&fence->base, &fence_ops, &fence->lock, dma_fence_context_alloc(1), 0);
> return &fence->base;
> }
>
> @@ -81,13 +96,13 @@ static void amdxdna_hwctx_release_expanded_heap(struct amdxdna_hwctx *hwctx)
> static void amdxdna_hwctx_destroy_rcu(struct amdxdna_hwctx *hwctx,
> struct srcu_struct *ss)
> {
> - struct amdxdna_client *client = hwctx->client;
> - struct amdxdna_dev *xdna = client->xdna;
> + struct amdxdna_dev *xdna = hwctx->client->xdna;
>
> synchronize_srcu(ss);
>
> /* At this point, user is not able to submit new commands */
> - xdna->dev_info->ops->hwctx_fini(hwctx);
> + if (xdna->dev_info->ops->hwctx_fini)
> + xdna->dev_info->ops->hwctx_fini(hwctx);
This seems unrelated. Please remove from the patch.
Lizhi
>
> amdxdna_hwctx_release_expanded_heap(hwctx);
> kfree(hwctx->name);
next prev parent reply other threads:[~2026-09-28 21:06 UTC|newest]
Thread overview: 27+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-26 1:34 [PATCH V0 00/21] accel/amdxdna: Kernel submission and PM for AIE4 David Zhang
2026-09-26 1:34 ` [PATCH V0 01/21] accel/amdxdna: Rename NPU3 firmware files David Zhang
2026-09-26 1:34 ` [PATCH V0 02/21] accel/amdxdna: Remove mmap for doorbell David Zhang
2026-09-26 1:34 ` [PATCH V0 03/21] accel/amdxdna: Add CERT firmware version support David Zhang
2026-09-26 1:34 ` [PATCH V0 04/21] accel/amdxdna: Upgrade firmware version to 6.0 David Zhang
2026-09-28 17:08 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 05/21] accel/amdxdna: Add NPU3 classic device support David Zhang
2026-09-26 1:34 ` [PATCH V0 06/21] accel/amdxdna: Add AIE version query to aie4_get_info David Zhang
2026-09-26 1:34 ` [PATCH V0 07/21] accel/amdxdna: Add get and set power_mode for AIE4 David Zhang
2026-09-28 18:39 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 08/21] accel/amdxdna: Restore power mode override on AIE4 hardware start David Zhang
2026-09-28 18:48 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 09/21] accel/amdxdna: Add clock, DPM frequency, and resource info queries for AIE4 David Zhang
2026-09-26 1:34 ` [PATCH V0 10/21] accel/amdxdna: Add context switch hysteresis with debugfs control David Zhang
2026-09-26 1:34 ` [PATCH V0 11/21] accel/amdxdna: Refactor AIE4 hardware initialization sequence David Zhang
2026-09-26 1:34 ` [PATCH V0 12/21] accel/amdxdna: Decouple AIE4 doorbell and MSI-X notification transport hooks David Zhang
2026-09-28 20:16 ` Lizhi Hou
2026-09-26 1:34 ` [PATCH V0 13/21] accel/amdxdna: Implement AIE4 kernel queue lifecycle and memory layout David Zhang
2026-09-26 1:34 ` [PATCH V0 14/21] accel/amdxdna: Fix fence timeline name and context allocation David Zhang
2026-09-28 21:06 ` Lizhi Hou [this message]
2026-09-26 1:34 ` [PATCH V0 15/21] accel/amdxdna: Prepare for AIE4 command submission David Zhang
2026-09-26 1:34 ` [PATCH V0 16/21] accel/amdxdna: Implement AIE4 command packet building and submission David Zhang
2026-09-26 1:34 ` [PATCH V0 17/21] accel/amdxdna: Finalize runtime PM before acquiring dev_lock on removal David Zhang
2026-09-26 1:34 ` [PATCH V0 18/21] accel/amdxdna: Implement AIE4 suspend and resume David Zhang
2026-09-26 1:34 ` [PATCH V0 19/21] accel/amdxdna: Link SR-IOV VFs for power management sequencing David Zhang
2026-09-26 1:34 ` [PATCH V0 20/21] accel/amdxdna: Implement runtime suspend and resume support David Zhang
2026-09-26 1:34 ` [PATCH V0 21/21] accel/amdxdna: Add stub hwctx_config for AIE4 David Zhang
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=c5da23b0-1552-b601-78e9-602e4140297d@amd.com \
--to=lizhi.hou@amd.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=karol.wachowski@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=mario.limonciello@amd.com \
--cc=max.zhen@amd.com \
--cc=ogabbay@kernel.org \
--cc=quic_jhugo@quicinc.com \
--cc=sonal.santan@amd.com \
--cc=yidong.zhang@amd.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®