From: Guenter Roeck <linux@roeck-us.net>
To: Niklas Schnelle <schnelle@linux.ibm.com>,
"Ionut Nechita (Wind River)" <ionut.nechita@windriver.com>,
linux-pci@vger.kernel.org, bhelgaas@google.com
Cc: helgaas@kernel.org, sebott@linux.ibm.com, bblock@linux.ibm.com,
lkml@mageta.org, alifm@linux.ibm.com, julianr@linux.ibm.com,
dtatulea@nvidia.com, mani@kernel.org, lukas@wunner.de,
kbusch@kernel.org, ionut_n2001@yahoo.com,
sunlightlinux@gmail.com, linux-kernel@vger.kernel.org,
stable@vger.kernel.org, intel-xe@lists.freedesktop.org,
matthew.brost@intel.com, michal.wajdeczko@intel.com,
piotr.piorkowski@intel.com
Subject: Re: [PATCH v10 0/2] PCI/IOV: Fix SR-IOV locking races and AB-BA deadlock
Date: Thu, 19 Mar 2026 12:25:24 -0700 [thread overview]
Message-ID: <fdf45531-3a62-49ec-bcc7-fb6dbaa01b2f@roeck-us.net> (raw)
In-Reply-To: <f17b03652a84be73c1d3a2cfea8a016dab99f8e0.camel@linux.ibm.com>
On 3/19/26 05:31, Niklas Schnelle wrote:
> On Wed, 2026-03-18 at 23:03 +0200, Ionut Nechita (Wind River) wrote:
>> From: Ionut Nechita <ionut.nechita@windriver.com>
>>
>> Hi Bjorn,
>>
>> This is v10 of the fix for the SR-IOV race between driver .remove()
>> and concurrent hotplug events. v10 adds a second patch to fix the
>> AB-BA deadlock between device_lock and pci_rescan_remove_lock that
>> was reported by Guenter Roeck (via Google's AI review agent) and
>> confirmed by Benjamin Block.
>>
>> The AB-BA deadlock:
>>
>> CPU0 (remove_store) CPU1 (unbind_store)
>> -------------------- --------------------
>> pci_lock_rescan_remove()
>> device_lock()
>> driver .remove()
>> sriov_del_vfs()
>> pci_lock_rescan_remove() <-- WAITS
>> pci_stop_bus_device()
>> device_release_driver()
>> device_lock() <-- WAITS
>>
>> Patch 2/2 fixes this by calling device_release_driver() in
>> remove_store() before pci_stop_and_remove_bus_device_locked(), so
>> that the driver is already unbound when pci_rescan_remove_lock is
>> acquired. Both paths then take locks in the same order: device_lock
>> first, then pci_rescan_remove_lock.
>>
>> Note: the concurrent unbind_store + hotplug-event case (where the
>> hotplug handler takes pci_rescan_remove_lock before device_lock)
>> remains a known limitation. This is a pre-existing issue that
>> Benjamin Block is addressing separately in:
>> https://lore.kernel.org/linux-pci/354b9e4a54ced67f3c89df198041df19434fe4c8.1773235561.git.bblock@linux.ibm.com/
>>
> --- snip ---
>>
>> Ionut Nechita (2):
>> PCI/IOV: Make pci_lock_rescan_remove() reentrant and protect
>> sriov_add_vfs/sriov_del_vfs
>> PCI: Fix AB-BA deadlock between device_lock and
>> pci_rescan_remove_lock in remove_store
>>
>> drivers/pci/iov.c | 9 +++++----
>> drivers/pci/pci-sysfs.c | 20 +++++++++++++++++++-
>> drivers/pci/probe.c | 11 +++++++++--
>> 3 files changed, 33 insertions(+), 7 deletions(-)
>>
>> --
>> 2.43.0
>
> Hi Ionut,
>
> For your awareness, I saw that this series has some findings on
> Google's new Sashiko AI reviewing tool[0]. At a quick glance the
> findings seem like at least reasonable concerns to me. I'm still
> looking at this independently also of course.
>
It is almost scary to see how many problems Sashiko is able to find.
The AB-BA deadlock that the second patch in the series tries to fix
was reported by a prototype version of it when running it on an LTS
backport.
Guenter
next prev parent reply other threads:[~2026-03-19 19:25 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-03-18 21:03 Ionut Nechita (Wind River)
2026-03-18 21:03 ` [PATCH v10 1/2] PCI/IOV: Make pci_lock_rescan_remove() reentrant and protect sriov_add_vfs/sriov_del_vfs Ionut Nechita (Wind River)
2026-03-18 21:03 ` [PATCH v10 2/2] PCI: Fix AB-BA deadlock between device_lock and pci_rescan_remove_lock in remove_store Ionut Nechita (Wind River)
2026-03-19 12:31 ` [PATCH v10 0/2] PCI/IOV: Fix SR-IOV locking races and AB-BA deadlock Niklas Schnelle
2026-03-19 19:25 ` Guenter Roeck [this message]
2026-03-19 20:27 ` Ionut Nechita (Wind River)
2026-03-24 17:07 ` Benjamin Block
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=fdf45531-3a62-49ec-bcc7-fb6dbaa01b2f@roeck-us.net \
--to=linux@roeck-us.net \
--cc=alifm@linux.ibm.com \
--cc=bblock@linux.ibm.com \
--cc=bhelgaas@google.com \
--cc=dtatulea@nvidia.com \
--cc=helgaas@kernel.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=ionut.nechita@windriver.com \
--cc=ionut_n2001@yahoo.com \
--cc=julianr@linux.ibm.com \
--cc=kbusch@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-pci@vger.kernel.org \
--cc=lkml@mageta.org \
--cc=lukas@wunner.de \
--cc=mani@kernel.org \
--cc=matthew.brost@intel.com \
--cc=michal.wajdeczko@intel.com \
--cc=piotr.piorkowski@intel.com \
--cc=schnelle@linux.ibm.com \
--cc=sebott@linux.ibm.com \
--cc=stable@vger.kernel.org \
--cc=sunlightlinux@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®