From: Philipp Stanner <phasta@mailbox.org>
To: "Christian König" <christian.koenig@amd.com>,
phasta@kernel.org, "Danilo Krummrich" <dakr@kernel.org>
Cc: Sumit Semwal <sumit.semwal@linaro.org>,
Boris Brezillon <boris.brezillon@collabora.com>,
Alice Ryhl <aliceryhl@google.com>,
Daniel Almeida <dwlsalmeida@gmail.com>,
Gary Guo <gary@garyguo.net>,
Tvrtko Ursulin <tvrtko.ursulin@igalia.com>,
linux-media@vger.kernel.org, dri-devel@lists.freedesktop.org,
linux-kernel@vger.kernel.org
Subject: Re: [RFC PATCH] dma-fence: Fix races of fence callbacks versus destructors by locking
Date: Tue, 09 Jun 2026 13:39:09 +0200 [thread overview]
Message-ID: <ced850f9e421d6549c25c27d50a99111bddb2db2.camel@mailbox.org> (raw)
In-Reply-To: <1bb5efeb-a5d3-4d0b-ae69-8dc8620604d4@amd.com>
On Tue, 2026-06-09 at 12:53 +0200, Christian König wrote:
> >
> > // driver
> > dma_fence_signal(f); // revokes all accesses to our driver through backend_ops
> > // synchronize_rcu() now unnecessary \o/
> > cleanup(f); // We know that all accessors are gone
> > dma_fence_put(f);
>
> Yeah and exactly that doesn't work.
>
> Just think about the Nouveau case when you have your fences on a double linked list.
>
> When the fence lock is independent, e.g. have a separate lock for each fence then this lock can't protect this double linked list.
>
> So your cleanup path needs to take a lock which protects the list, but you then run into lock inversion.
static bool nouveau_fence_is_signaled(struct dma_fence *f)
{
struct nouveau_fence *fence = to_nouveau_fence(f);
struct nouveau_fence_chan *fctx = nouveau_fctx(fence);
struct nouveau_channel *chan;
bool ret = false;
rcu_read_lock();
chan = rcu_dereference(fence->channel);
if (chan)
ret = (int)(fctx->read(chan) - fence->base.seqno) >=
0;
rcu_read_unlock();
return ret;
}
AFAICT fctx->read() does not take f->lock. So where is the lock
inversion?
Again, ideally we can get to the point where no one except for the
fence subsystem itself has to take the lock manually anymore.
>
> > >
> > > So you are left with few options: Either the fence lock is external,
> > > which we don't want because that make the fence non-independent, or
> > > cleanup() defers work to irq_work or work_structs, which creates
> > > numerous lifetime issues.
> >
> > Yup, this is uncool and we want to avoid that.
> >
> > But these seem to be the options
> >
> > 1. Ensure proper synchronization
> > 2. Wait for a grace period in a hot path
> > 3. Defer cleanup() with some delay mechanism
> >
> > #1 is by far the cleanest approach. I still cannot see any downside,
> > and quite a few upsides.
> >
> > https://elixir.bootlin.com/linux/v7.1-rc6/source/drivers/dma-buf/dma-fence.c#L1025
> >
> > ^ is already racing with the signaled check.
>
> Yeah so what? That is just an opportunistic check.
What happens if someone signals the fence while the set_deadline()
callback is running?
P.
next prev parent reply other threads:[~2026-06-09 11:39 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-08 14:24 Philipp Stanner
2026-06-08 15:01 ` Boris Brezillon
2026-06-08 15:17 ` Philipp Stanner
2026-06-08 15:23 ` Danilo Krummrich
2026-06-08 15:30 ` Boris Brezillon
2026-06-08 15:30 ` Philipp Stanner
2026-06-08 16:16 ` Boris Brezillon
2026-06-09 8:02 ` Christian König
2026-06-09 8:54 ` Philipp Stanner
2026-06-09 8:43 ` Philipp Stanner
2026-06-09 8:47 ` Christian König
2026-06-09 9:00 ` Philipp Stanner
2026-06-08 15:07 ` Tvrtko Ursulin
2026-06-08 15:15 ` Philipp Stanner
2026-06-08 15:35 ` Christian König
2026-06-08 15:41 ` Philipp Stanner
2026-06-08 17:34 ` Christian König
2026-06-08 17:59 ` Danilo Krummrich
2026-06-08 18:32 ` Christian König
2026-06-08 18:39 ` Danilo Krummrich
2026-06-08 18:47 ` Christian König
2026-06-08 19:25 ` Danilo Krummrich
2026-06-09 8:17 ` Christian König
2026-06-09 5:52 ` Philipp Stanner
2026-06-09 10:26 ` Christian König
2026-06-09 10:42 ` Philipp Stanner
2026-06-09 10:53 ` Christian König
2026-06-09 11:39 ` Philipp Stanner [this message]
2026-06-09 13:19 ` Philipp Stanner
2026-06-09 13:34 ` Christian König
2026-06-10 14:25 ` Philipp Stanner
2026-06-10 15:15 ` Christian König
2026-06-11 8:35 ` Philipp Stanner
2026-06-11 9:14 ` Christian König
2026-06-11 9:50 ` Philipp Stanner
2026-06-11 11:06 ` Christian König
2026-06-09 13:36 ` Tvrtko Ursulin
2026-06-09 13:57 ` Philipp Stanner
2026-06-09 14:03 ` Christian König
2026-06-15 8:29 ` Properly synchronize dma_fence->signaled bit (Was: Re: [RFC PATCH] dma-fence: Fix races of fence callbacks versus destructors by locking) Philipp Stanner
2026-06-15 9:57 ` Christian König
2026-06-16 11:25 ` Philipp Stanner
2026-06-17 9:46 ` Christian König
2026-06-17 10:16 ` Philipp Stanner
2026-06-17 13:03 ` Christian König
2026-06-17 13:21 ` Philipp Stanner
2026-06-17 13:50 ` Gary Guo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=ced850f9e421d6549c25c27d50a99111bddb2db2.camel@mailbox.org \
--to=phasta@mailbox.org \
--cc=aliceryhl@google.com \
--cc=boris.brezillon@collabora.com \
--cc=christian.koenig@amd.com \
--cc=dakr@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=dwlsalmeida@gmail.com \
--cc=gary@garyguo.net \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=phasta@kernel.org \
--cc=sumit.semwal@linaro.org \
--cc=tvrtko.ursulin@igalia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®