From nobody Sat Jul 25 21:21:24 2026 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ACCE025A2B5 for ; Mon, 13 Jul 2026 13:01:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783947681; cv=none; b=m7CjB/lqbuP3Ycb5iX+LqWY1Fqvt8ki9PDEP1pB6rGIEyXfQLELHC7351Fkr6AR24N0sKLh1b+VORb5jjD+SVZxEtNkXpKKkbI3lzlzJD3QKZ405sZzDuWdV1G/RP8QGAcCHtGf7j8fSd1Zc8K7GEauesqXVvpU++0PlK6kPNY0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783947681; c=relaxed/simple; bh=WUcQk+W2gRvj9AKZJ+HKO8HCCnSIPe4j7rEN4B8rVs4=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=pJO8r8bj/V0//MeiqxMIhTh6hsXUYPDfMSAVHfv8jQUKxiPoUxDDaRP5mGGfth/OSbex9udBJBs/dGgqoag/Z2xBWPY7xWEPShZZNrtoJqnBOyeEP0CMQAdOk2dg7iQ50jzT1fzqQ2TnxiWh1HlcnvNj8FgulyN78Zb+4n66AQg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=H1KWDYoX; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=uFi4Jedc; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="H1KWDYoX"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="uFi4Jedc" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783947678; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=bIN4Uwhb8SwPUKKjdKqPp/oSbTdbYDS5rLSl3N5RmDg=; b=H1KWDYoXcdlgg1CZTSkY9NXlXHkd/M1nktvQHr81qZPAMx2oyJBHp/qMuywi7dxw/0+3aR TzT0NnElVmA23n+3xBVHinI9LqZuBqJ36jWPm4Fi4Xf/8IwJTI27xY2rHWy2PviveTlgdG U2mnKOVQDFbkb09YPWBXkWGhDoUFPa4= Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-461-cOIwU7iAO3Sqdfl3g5mh0g-1; Mon, 13 Jul 2026 09:01:16 -0400 X-MC-Unique: cOIwU7iAO3Sqdfl3g5mh0g-1 X-Mimecast-MFC-AGG-ID: cOIwU7iAO3Sqdfl3g5mh0g_1783947675 Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-c892143db7fso2983719a12.1 for ; Mon, 13 Jul 2026 06:01:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1783947675; x=1784552475; darn=vger.kernel.org; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=bIN4Uwhb8SwPUKKjdKqPp/oSbTdbYDS5rLSl3N5RmDg=; b=uFi4JedcFwnWXk/NWMpKysu/TshhIDD1BFwoNbXg/V6cckaSjubztQDXSKb0s98vd+ Q0DVuyYFB9U/Gml3XP2veYlVQo9VT4OaEcbrEtpdiMjPKpuMbT+YalDhUfqYEOlUe28z I0qEJFPGWkmYbyKSn9BwBOY0Ngln9TPlLmP//bwykn6faP2TMn5gyUPtRJjPD9ugk41O X8pfwngAVqaEzfW45w68hYs3+xRT3vXpETDrCutjmdAntG3Gsxr9RSDinp59U/RdaxEB WR9Yyy1JmGnmbIgIMo6r6SYbAs2V9pdYRxJAgrJuepM7c8eTNsXO+eahJxCbMPnBtEz3 gMuA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783947675; x=1784552475; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=bIN4Uwhb8SwPUKKjdKqPp/oSbTdbYDS5rLSl3N5RmDg=; b=b+QVD8UBmDUOxkuGBoxbGBWJH36kppOnKAk5jDyfxb2hiaLEQ2syFOqE9cZaizcR5Q C4ZDwI7RsWB1cv2ToRBn78maOQfOo3wdZvLCAMdPjwx/16myfQ5VVJAy9RwBG9yHFRGe g62va6MiYp+Lmy/EGe0itCzSoBw24OzMv+ppPLOOJUbP5PBovxyS00fs6FttSIM4eSzE yc2cXGy3bLJtJ99as9UznvMy8khij9m0FJZziouavrwP7dIGm7Fy2xNiqqIHany1xnHm dFX8GurxIVn0PWbVL28eohJF8bMbZBOtDr2O20EsGYHxdcKsifo3IKWNfJAUKKLnQZBp FXpg== X-Forwarded-Encrypted: i=1; AHgh+Ro6J4v6t0eq3+DnpmRa6MGm42WQAcmocQwk/66zymkUgbOab45pMuc+FToBf9p9bUiuBDt9CHOCcrE042k=@vger.kernel.org X-Gm-Message-State: AOJu0Yzz8fSHjzOjglWGN2P6cB3FDkx+1iQQpOS24QFz6QAq0tFEqQYO Q7ynGrZPRvIDOL2g4rPsiK2mqt084qH/eopdZpwJy2IzX8e5FxVocZsC9CpCWyH4bvv/Wkchss9 L8LfIWwzhbUKYfDD8GATPIvdWboqRJNcF2bOs9XoJJleLfhayvWt7M1Plh7YFGHlGDQ== X-Gm-Gg: AfdE7ckh5BBjW24iykjyRmDwYTqaw4jIwBJNvfR0M0um+xPjcb9cwTtM9a8HnU5xcy9 7rlDa99rjFD0fCEJDg3GtStypHzqQm5E1Sw4rW+Fe/uasQtA+wyqVFyz1CXSEa9nf4DvV1rKJpp aXgxK47ngk2hHJx4zescDUBp/G2ksawppGpDLwsYjkbC22PO9ZRLr5cD/mJoRzDwAdyl+pgddmQ 7I/yQGoe0G37CzVjmf38qLqUdmo603oEn5tEKazxhZB8eYX1aVNAxrpxgc0Z9CMGSRjtOtHSZ4D neePr92nuCRTnST9nR91EmT+4/C1/41/WwPxP+AyMgqssJt1bh3inUTH8ycm07K0QyoyVUTglwb QAlCOQ5xqEtK36dUtFRGNA9z55LjgPU0y14N9zoaUjF3e8J18 X-Received: by 2002:a05:6a00:1d90:b0:845:e9e8:6458 with SMTP id d2e1a72fcca58-84889703f26mr7907409b3a.20.1783947674919; Mon, 13 Jul 2026 06:01:14 -0700 (PDT) X-Received: by 2002:a05:6a00:1d90:b0:845:e9e8:6458 with SMTP id d2e1a72fcca58-84889703f26mr7907345b3a.20.1783947674363; Mon, 13 Jul 2026 06:01:14 -0700 (PDT) Received: from ryasuoka-thinkpadx1carbongen9.tokyo.csb ([126.143.164.49]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-84909673e32sm3183069b3a.56.2026.07.13.06.01.09 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 13 Jul 2026 06:01:13 -0700 (PDT) From: Ryosuke Yasuoka Date: Mon, 13 Jul 2026 22:01:00 +0900 Subject: [PATCH v2] drm/virtio: fix deadlock in display_info_cb by removing hotplug from dequeue worker Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-virtiogpu_syzbot-v2-1-2958fa37d46d@redhat.com> X-B4-Tracking: v=1; b=H4sIAAAAAAAC/2WNzQ7CIBCEX6XZs5gF0/pz8j1MYygs7R4sDSCxN n13sfHm8ZvJfLNApMAU4VItEChzZD8WULsKzKDHngTbwqBQNdjIs8gcEvt+et7j/O58Ep3VXY0 n54ytocymQI5fm/LWFh44Jh/m7SHLb/qTHfBflqWQArXGptTHGukayA467Y1/QLuu6wd/koZ6s QAAAA== X-Change-ID: 20260619-virtiogpu_syzbot-bdab508ffcd5 To: David Airlie , Gerd Hoffmann , Dmitry Osipenko , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , Dmitry Baryshkov , Javier Martinez Canillas Cc: dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, Ryosuke Yasuoka X-Mailer: b4 0.14.3 A probe-time deadlock can occur between the dequeue worker and drm_client_register(). During probe, drm_client_register() holds clientlist_mutex and calls the fbdev hotplug callback, which triggers an atomic commit that ends up sleeping in virtio_gpu_queue_ctrl_sgs() waiting for virtqueue space. The dequeue worker that would free that space calls virtio_gpu_cmd_get_display_info_cb(), which invokes drm_kms_helper_hotplug_event() -> drm_client_dev_hotplug(), attempting to acquire the same clientlist_mutex. Since wake_up() is only called after the resp_cb loop, the probe thread is never woken and both threads deadlock. Fix this by removing the hotplug notification from virtio_gpu_cmd_get_display_info_cb(). The display data (outputs[i].info) is still updated synchronously in the callback. For the init path, drm_client_register() already fires an initial hotplug when the client is registered, which picks up the connector state updated by display_info_cb. For the runtime config_changed path, add a wait_event_timeout() in config_changed_work_func() so that display_info_cb updates the connector data before the hotplug notification is sent. Also replace drm_helper_hpd_irq_event() with drm_kms_helper_hotplug_event() since virtio-gpu never calls drm_kms_helper_poll_init() and thus drm_helper_hpd_irq_event() always returns false without doing anything. Fixes: 27655b9bb9f0 ("drm/client: Send hotplug event after registering a cl= ient") Closes: https://syzkaller.appspot.com/bug?id=3Dd6dd6f86d3aaf7eebe7406e45c1c= 6e549453f224 Closes: https://syzkaller.appspot.com/bug?id=3D908bd910da5dd79b88de4cf7baf3= 76cc873a922e Suggested-by: Dmitry Osipenko Signed-off-by: Ryosuke Yasuoka --- I checked whether drm_helper_hpd_irq_event() is needed in virtio_gpu_init(), as Dmitry suggested. AFAIS, it is not needed because: 1. drm_helper_hpd_irq_event() is always a no-op in virtio-gpu. It returns false immediately probe_helper.c:1088 because dev->mode_config.poll_enabled is false =E2=80=94 virtio-gpu never calls drm_kms_helper_poll_init(). Even if it passed that gate, no virtio-gpu connectors set DRM_CONNECTOR_POLL_HPD. 1082 bool drm_helper_hpd_irq_event(struct drm_device *dev) 1083 { ... 1088 if (!dev->mode_config.poll_enabled) 1089 return false; 2. virtio_gpu_init() runs before drm_dev_register() and drm_client_setup(), so no DRM clients are registered yet. drm_kms_helper_hotplug_event() would iterate an empty client list. The initial hotplug is handled by drm_client_register(), which fires a hotplug callback to the newly registered client. By that time, display_info_cb has already updated the connector data. For the same reason, drm_helper_hpd_irq_event() in config_changed_work_func() was also a no-op. The actual runtime hotplug notification was always delivered by display_info_cb's call to drm_kms_helper_hotplug_event(). This patch replaces it with a direct drm_kms_helper_hotplug_event() call after waiting for the display info response. --- Changes in v2: - Dropped the work_struct approach from v1. - Instead, removed the hotplug calls from display_info_cb entirely, as suggested by Dmitry. - Added wait_event_timeout() in config_changed_work_func() so that the display info response is received before sending the hotplug notification. - Replaced drm_helper_hpd_irq_event() with drm_kms_helper_hotplug_event() in config_changed_work_func() since drm_helper_hpd_irq_event() is always a no-op in virtio-gpu (poll_enabled is never set). - No changes to virtio_gpu_init() =E2=80=94 drm_client_register() already handles the initial hotplug and hotplug event does nothing before DRM device/client has been registered. - Link to v1: https://lore.kernel.org/r/20260630-virtiogpu_syzbot-v1-1-0aa0= 6630750e@redhat.com --- drivers/gpu/drm/virtio/virtgpu_kms.c | 5 ++++- drivers/gpu/drm/virtio/virtgpu_vq.c | 3 --- 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/drivers/gpu/drm/virtio/virtgpu_kms.c b/drivers/gpu/drm/virtio/= virtgpu_kms.c index cfde9f573df6..b4329f28e976 100644 --- a/drivers/gpu/drm/virtio/virtgpu_kms.c +++ b/drivers/gpu/drm/virtio/virtgpu_kms.c @@ -49,7 +49,10 @@ static void virtio_gpu_config_changed_work_func(struct w= ork_struct *work) virtio_gpu_cmd_get_edids(vgdev); virtio_gpu_cmd_get_display_info(vgdev); virtio_gpu_notify(vgdev); - drm_helper_hpd_irq_event(vgdev->ddev); + wait_event_timeout(vgdev->resp_wq, + !vgdev->display_info_pending, + 5 * HZ); + drm_kms_helper_hotplug_event(vgdev->ddev); } events_clear |=3D VIRTIO_GPU_EVENT_DISPLAY; } diff --git a/drivers/gpu/drm/virtio/virtgpu_vq.c b/drivers/gpu/drm/virtio/v= irtgpu_vq.c index c8b9475a7472..e5e1af8b8e8a 100644 --- a/drivers/gpu/drm/virtio/virtgpu_vq.c +++ b/drivers/gpu/drm/virtio/virtgpu_vq.c @@ -840,9 +840,6 @@ static void virtio_gpu_cmd_get_display_info_cb(struct v= irtio_gpu_device *vgdev, vgdev->display_info_pending =3D false; spin_unlock(&vgdev->display_info_lock); wake_up(&vgdev->resp_wq); - - if (!drm_helper_hpd_irq_event(vgdev->ddev)) - drm_kms_helper_hotplug_event(vgdev->ddev); } =20 static void virtio_gpu_cmd_get_capset_info_cb(struct virtio_gpu_device *vg= dev, --- base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa change-id: 20260619-virtiogpu_syzbot-bdab508ffcd5 Best regards, --=20 Ryosuke Yasuoka