[PATCH] dmaengine: fsl_raid: don't invoke client callback under desc_lock

Rosen Penev posted 1 patch 6 days, 22 hours ago
drivers/dma/fsl_raid.c | 15 +++++++++++++--
1 file changed, 13 insertions(+), 2 deletions(-)
[PATCH] dmaengine: fsl_raid: don't invoke client callback under desc_lock
Posted by Rosen Penev 6 days, 22 hours ago
fsl_re_dequeue() holds re_chan->desc_lock while calling
fsl_re_desc_done(), which synchronously invokes the DMA client completion
callback via dmaengine_desc_get_callback_invoke(). If that callback
submits new work (e.g. fsl_re_tx_submit()), it tries to reacquire the
same desc_lock and deadlocks on the spinlock.

Collect completed descriptors into a local list under the lock, then
release the lock and invoke the callbacks before moving the descriptors
to the ack queue.

Fixes: ad80da658bbc ("dmaengine: Driver support for FSL RaidEngine device.")
Assisted-by: opencode:hy3-free
Signed-off-by: Rosen Penev <rosenp@gmail.com>
---
 drivers/dma/fsl_raid.c | 15 +++++++++++++--
 1 file changed, 13 insertions(+), 2 deletions(-)

diff --git a/drivers/dma/fsl_raid.c b/drivers/dma/fsl_raid.c
index 2d86f61105e5..bfaef6245695 100644
--- a/drivers/dma/fsl_raid.c
+++ b/drivers/dma/fsl_raid.c
@@ -162,6 +162,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
 	struct fsl_re_hw_desc *hwdesc;
 	unsigned long flags;
 	unsigned int count, oub_count;
+	LIST_HEAD(completed);
 	int found;
 
 	fsl_re_cleanup_descs(re_chan);
@@ -182,8 +183,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
 		}
 
 		if (found) {
-			fsl_re_desc_done(desc);
-			list_move_tail(&desc->node, &re_chan->ack_q);
+			list_move_tail(&desc->node, &completed);
 		} else {
 			dev_err(re_chan->dev,
 				"found hwdesc not in sw queue, discard it\n");
@@ -196,6 +196,17 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
 			 FSL_RE_RMVD_JOB(1));
 	}
 	spin_unlock_irqrestore(&re_chan->desc_lock, flags);
+
+	/* Invoke the client callbacks outside the channel lock. The callback
+	 * may submit new work which re-acquires desc_lock, so holding it here
+	 * would deadlock.
+	 */
+	list_for_each_entry_safe(desc, _desc, &completed, node) {
+		fsl_re_desc_done(desc);
+		spin_lock_irqsave(&re_chan->desc_lock, flags);
+		list_move_tail(&desc->node, &re_chan->ack_q);
+		spin_unlock_irqrestore(&re_chan->desc_lock, flags);
+	}
 }
 
 /* Per Job Ring interrupt handler */
-- 
2.55.0
Re: [PATCH] dmaengine: fsl_raid: don't invoke client callback under desc_lock
Posted by Frank Li 6 days, 13 hours ago
On Fri, Jul 17, 2026 at 10:30:10PM -0700, Rosen Penev wrote:
> fsl_re_dequeue() holds re_chan->desc_lock while calling
> fsl_re_desc_done(), which synchronously invokes the DMA client completion
> callback via dmaengine_desc_get_callback_invoke(). If that callback
> submits new work (e.g. fsl_re_tx_submit()), it tries to reacquire the
> same desc_lock and deadlocks on the spinlock.
>
> Collect completed descriptors into a local list under the lock, then
> release the lock and invoke the callbacks before moving the descriptors
> to the ack queue.
>
> Fixes: ad80da658bbc ("dmaengine: Driver support for FSL RaidEngine device.")
> Assisted-by: opencode:hy3-free
> Signed-off-by: Rosen Penev <rosenp@gmail.com>
> ---

Reviewed-by: Frank Li <Frank.Li@nxp.com>

>  drivers/dma/fsl_raid.c | 15 +++++++++++++--
>  1 file changed, 13 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/dma/fsl_raid.c b/drivers/dma/fsl_raid.c
> index 2d86f61105e5..bfaef6245695 100644
> --- a/drivers/dma/fsl_raid.c
> +++ b/drivers/dma/fsl_raid.c
> @@ -162,6 +162,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
>  	struct fsl_re_hw_desc *hwdesc;
>  	unsigned long flags;
>  	unsigned int count, oub_count;
> +	LIST_HEAD(completed);
>  	int found;
>
>  	fsl_re_cleanup_descs(re_chan);
> @@ -182,8 +183,7 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
>  		}
>
>  		if (found) {
> -			fsl_re_desc_done(desc);
> -			list_move_tail(&desc->node, &re_chan->ack_q);
> +			list_move_tail(&desc->node, &completed);
>  		} else {
>  			dev_err(re_chan->dev,
>  				"found hwdesc not in sw queue, discard it\n");
> @@ -196,6 +196,17 @@ static void fsl_re_dequeue(struct tasklet_struct *t)
>  			 FSL_RE_RMVD_JOB(1));
>  	}
>  	spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> +
> +	/* Invoke the client callbacks outside the channel lock. The callback
> +	 * may submit new work which re-acquires desc_lock, so holding it here
> +	 * would deadlock.
> +	 */
> +	list_for_each_entry_safe(desc, _desc, &completed, node) {
> +		fsl_re_desc_done(desc);
> +		spin_lock_irqsave(&re_chan->desc_lock, flags);
> +		list_move_tail(&desc->node, &re_chan->ack_q);
> +		spin_unlock_irqrestore(&re_chan->desc_lock, flags);
> +	}
>  }
>
>  /* Per Job Ring interrupt handler */
> --
> 2.55.0
>