]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
drm/nouveau: Fix race in nouveau_sched_fini()
authorPhilipp Stanner <phasta@kernel.org>
Fri, 24 Oct 2025 16:12:22 +0000 (18:12 +0200)
committerPhilipp Stanner <phasta@kernel.org>
Mon, 27 Oct 2025 12:58:56 +0000 (13:58 +0100)
nouveau_sched_fini() uses a memory barrier before wait_event().
wait_event(), however, is a macro which expands to a loop which might
check the passed condition several times. The barrier would only take
effect for the first check.

Replace the barrier with a function which takes the spinlock.

Cc: stable@vger.kernel.org # v6.8+
Fixes: 5f03a507b29e ("drm/nouveau: implement 1:1 scheduler - entity relationship")
Acked-by: Danilo Krummrich <dakr@kernel.org>
Signed-off-by: Philipp Stanner <phasta@kernel.org>
Link: https://patch.msgid.link/20251024161221.196155-2-phasta@kernel.org
drivers/gpu/drm/nouveau/nouveau_sched.c

index e60f7892f5ce9aff0c5fa1908c1a0445891927ed..a7bf539e5d86d16ebbe22d4270ad703f90a73278 100644 (file)
@@ -482,6 +482,17 @@ nouveau_sched_create(struct nouveau_sched **psched, struct nouveau_drm *drm,
        return 0;
 }
 
+static bool
+nouveau_sched_job_list_empty(struct nouveau_sched *sched)
+{
+       bool empty;
+
+       spin_lock(&sched->job.list.lock);
+       empty = list_empty(&sched->job.list.head);
+       spin_unlock(&sched->job.list.lock);
+
+       return empty;
+}
 
 static void
 nouveau_sched_fini(struct nouveau_sched *sched)
@@ -489,8 +500,7 @@ nouveau_sched_fini(struct nouveau_sched *sched)
        struct drm_gpu_scheduler *drm_sched = &sched->base;
        struct drm_sched_entity *entity = &sched->entity;
 
-       rmb(); /* for list_empty to work without lock */
-       wait_event(sched->job.wq, list_empty(&sched->job.list.head));
+       wait_event(sched->job.wq, nouveau_sched_job_list_empty(sched));
 
        drm_sched_entity_fini(entity);
        drm_sched_fini(drm_sched);